Content

Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

"Need Help" Threats On Popular Social Networking Sites !!

0 comments
If you're on Facebook, Twitter, myspace or any other social networking site, you could be the next victim. It will come to you as a friendly package..it starts with a friend updating his or her status and slowly raveled his/her cruel intentions. FBI alerts..!!
That's because more cyberthieves are targeting increasingly popular social networking sites that provide a gold mine of personal information, according to the FBI. Since 2006, nearly 3,200 account hijacking cases have been reported to the Internet Crime Complaint Center, a partnership between the FBI, the National White Collar Crime Center and the Bureau of Justice Assistance.

It starts with a friend updating his or her status or sending you a message with an innocent link or video. Maybe your friend is in distress abroad and needs some help.All you have to do is click.

When the message or link is opened, social network users are lured to fake Web sites that trick them into divulging personal details and passwords. The process, known as a phishing attack or malware, can infiltrate users' accounts without their consent.
Once the account is compromised, the thieves can infiltrate the list of friends or contacts and repeat the attack on subsequent victims. Social networking sites show there is ample opportunity to find more victims; the average Facebook user has 120 friends on the site.

"Security is a constant arms race," said Simon Axten, an associate for privacy and public policy at Facebook. "Malicious actors are constantly attacking the site, and what you see is actually a very small percentage of what's attempted."
As some social networking sites experience monstrous growth, they are becoming a new -- and extremely lucrative -- frontier for cybercrime. Facebook says it has 300 million users, nearly the size of the U.S. population, and it continues to attract users outside the college student niche. From February 2008 to February 2009, Twitter, a micro-blogging site where users post 140-character messages known as tweets, grew 1,382 percent to more than 7 million users.

"They [cybercriminals] are very adept to using social engineering," said Donald DeBold, director of threat research for CA, an Internet security company. "Your friend is in trouble traveling in another country, 'I lost my wallet. I need help.' They exploit the curiosity aspect out of human nature."

A few decades ago, malicious software and viruses were usually the result of a prank, but Internet security experts say today's attacks are profit-driven. A study from the Indiana University in 2005 discovered that phishing attacks on social networks operated with a 70 percent success rate. These users had fallen for the scam, opened the foreign link and released personal information.

Cybercriminals are employing phishing and malware attacks for a number of reasons, including trying to redirect users to sites where profit is fueled by the number of visitors. They also try to elicit private information like passwords and bank account numbers to perform scams.

Early this year, Twitter experienced several phishing attacks in which a Web page that looked identical to the widely recognized light blue Twitter page was a hoax. The company warned users to double-check the URL to ensure they were visiting the correct site.

The Internet Crime Complaint Center received more than 72,000 complaints about Internet fraud in 2008 that were referred to law enforcement agencies for further investigation. These cases involved financial losses amounting to $264.6 million, an increase from 2007. Each person lost an average of $931.

"Most of us would want to help a friend in need, but if it's an online friend, and they want you to wire money, you should double-check," FBI spokesman Jason Pack said.

Security experts said it makes sense that cybercriminals are turning to social networking sites. Personal information is abundant on sites like Facebook and MySpace. Each time users give out valuable information like birth dates or addresses, they could be providing hints about their password, security experts say.

The American Civil Liberties Union has expressed concern about the information visible through Facebook quizzes and applications.

"They'll have access to all that information, so they can sell it, they can share it, they can do an awful lot with it," Chris Calabrese, legislative counsel for privacy-related issues with the ACLU, told CNN.com in September.

Many Internet security experts consider the first virus attack on the PC to have occurred in 1986. By the early 1990s, viruses transmitted on floppy disks became ubiquitous. When the World Wide Web became widely available that same decade, viruses, worms and malware became problems in e-mail accounts, frustrating users who clicked on messages thought to be legitimate.

In the new millennium, the most common form of malware attack has become known as drive-by downloads. While surfing on Google or Yahoo, spyware or a computer virus is automatically and invisibly downloaded on a computer, requiring no user interaction for the computer to be infected.

"We are on the verge from shifting from the Web being the No. 1 victim of infecting to social network," said Mikko H. Hypponen, chief of research technology at F-Secure Corp. His company sells anti-virus software and malware protection programs. "It's going to get a lot worse before it gets better."

Social networks are fighting the aggressive attacks from cybercriminals. Most sites have information pages dedicated to educating users about the risks of Internet scams. Users can become a fan of "Facebook Security" and receive updates on how to protect their accounts. One of the most common pieces of advice given by security experts is to change passwords frequently.

Facebook has also developed complex automated systems that detect compromised accounts. They spot and freeze accounts that are sending an unusually high number of messages to their friends. Company security officials said Facebook is a closed system, which can be helpful in erasing phony messages from all accounts.

At News Corporation's MySpace.com, the company creates blacklists of phony accounts to prevent people from clicking on a faulty link. Hemanshu Nigam, first chief security officer for MySpace, said the firm warns about suspicious links and educates users about the harm phishing and malware attacks can bring.

"We are prepared for them," he said.

Here are few easy steps How to protect yourself against scams:
(Information provided by FBI and Internet security experts)

1. Change your passwords frequently

2. Adjust Web site privacy settings

3. Be selective when adding friends

4. Limit access to your profile to contacts you trust

5. Disable options such as photo sharing

6. Be careful what you click on

7. Familiarize yourself with the security and privacy settings

8. Learn how to report a compromised account

9. Use security software that updates automatically



Source: cnn.com
Read more »

Top 10 Ways To Destroy ' The Internet '

0 comments
WHILE swimming in the endless sea of news, blogs, social networks and mindless ballyhoo - one has to wonder how to make it stop.

The internet seems to be all-powerful and indestructible - but in theory it can be destroyed in a number of outlandish ways. check out how could you do that ...

1. Cut the cables

To destroy the internet, a strategic starting point would be to destroy the undersea cables that connect every continent.
You could use submarines with giant scissors - but the cables are not that difficult to destroy. Earthquakes, fishing trawlers and shark bites have been known to cause breaks.

2. Cyber war

Cyberspace could become the battlefield of choice for countries wishing to gain the upper hand in an international arena.
Nations could deploy armies of hackers instead of armed military forces to disrupt communications, launch unstoppable viruses and take out sections of the internet. When two superpowers go to cyberwar, the cost will not be in blood, but in 404's.

3. Subvert DNS

Security researcher Dan Kaminsky last year stumbled across a vulnerability in the Domain Name System (DNS) that had the potential to destroy the internet's foundations.
The security flaw allowed hackers to potentially reroute users to any website or block access.
According to Securosis analyst Rich Mogull: "You'd have the internet, but it wouldn't be the internet you expect. (Hackers) would control everything."

4. Eliminate the hardware

Destroying the hardware that allows internet access would be improbable, but not impossible.
This would mean that every single online communications system would have to go down.
One way would be disabling electronics with an electromagnetic pulse (EMP) within a 10km radius. It's not effective on a worldwide scale, but if the idea can be manipulated for a global EMP then it might be feasible

5. Censorship

Both the internet and the World Wide Web were designed as open forums for free ideas and expression, but countries have pushed to censor objectionable materials.
Countries such as China have implemented strong censorship in an attempt to neutralize political opposition. This is dubbed "The Great Firewall of China".
Although censoring the internet only affects parts of the global community, it destroys the idea on which the network was created

6. Botnets

A botnet is the name given to a collection of infected computers (or "zombies") that automatically distribute malicious software, viruses, spam and trojans in an attempt to infect other computers.
The Conficker worm came from a particularly nasty botnet estimated to have burrowed its way into almost nine million computers worldwide. It had the potential of producing 10 billion articles of spam per day

7. Spam

Spam is an inevitable consequence of the internet with advertisers, marketers and Nigerian scams all trying to exploit users.
Spammers all over the world use thousands of zombie computers and in 2007, SophosLabs found that over a quarter of the world's spam originated in the US.
Not only is spam incredibly annoying, it may be used to transmit viruses, trojans and malicious software with the intent of corrupting more computers, turning them into zombies

8. Unstoppable virus

Similar to the scenes in Terminator 3, a self-replicating computer virus with the potential to distribute itself globally and become invulnerable to destruction may not only spell the end of the internet, but the end of humanity

9. Hack the servers

Internet service providers (ISPs) link customers to the world wide web. If they were taken down systematically, many people would lose online access.
This would essentially starve the web of users, content and traffic..


10. Switch off

Switching off means that if everyone connected to a system that accesses the world wide web turns off, it would become a barren wasteland of unclicked hyperlinks and unwatched videos.
So instead of viewing technology galleries you might actually be doing your work


Visit 13above for more fun

Read more »

Jessica Biel Tops Brad Pitt - Internet’s Most Dangerous Search This Year

0 comments

Actress Jessica Biel has overtaken Brad Pitt as the most dangerous celebrity to search in cyberspace, according to Internet security company McAfee Inc.

For the third consecutive year, McAfee surveyed which A-list celebrity was the riskiest to track on the Internet after Pitt topped the list last year and Paris Hilton came in first in 2007.

Biel, 27, who shot to fame in the TV show “7th Heaven” and most recently starred in “Easy Virtue,” was deemed the most dangerous, with fans having a one-in-five chance of landing at a website that has tested positive for online threats, such as spyware, adware, spam, phishing, and viruses.

“Cybercriminals are star watchers too — they latch onto popular celebrities to encourage the download of malicious software in disguise,” McAfee’s Jeff Green said in a statement.

“Consumers’ obsession with celebrity news and culture is harmless in theory, but one bad download can cause a lot of damage to a computer.”

“Every day, cybercriminals use celebrities’ names and images, like Kim Kardashian and Rihanna, to lure surfers searching for the latest stories, screen savers and ringtones to sites offering free downloads laden with malware,” the statement added.

Coming second in the list for the second year running was pop star Beyonce, with McAfee finding that putting “Beyonce ringtones” into a search engine yielded a dangerous website linking to a distributor of adware and spyware.

Actress Jennifer Aniston was third, with more than 40 percent of the Google search results for “Jennifer Aniston screensavers” containing nasty viruses.

Young Hollywood stars Miley Cyrus, Ashley Tisdale and Lindsay Lohan all edged out Heidi Montag and Jessica Alba who appeared on last year’s list.

They also ranked higher than other young personalities including “Twilight” stars Robert Pattinson who came 30th and Kristen Stewart who was 20th, the Jonas Brothers, Taylor Swift, Lauren Conrad, Vanessa Hudgens and Zac Efron.

Megan Fox and Angelina Jolie tied as the eighth most dangerous celebrities on the Web while newlyweds Tom Brady and Gisele Bundchen came in fourth and sixth respectively.

However, President Barack Obama and First Lady Michelle Obama, who have featured on most celebrities list this year, were not at the top of risky public figures to search.

The Obamas ranked in the bottom-third of this year’s results, at No. 34 and No. 39 respectively.

Brad Pitt came 10th in the list this year.


Visit 13above For More Fun

Read more »

Conficker Virus Started Sending Spam From Infected PCs

0 comments
ONE of the world's biggest computer worms has activated and is now sending spam from personal computers.

The malicious software known as Conficker is slowly starting weeks after being dismissed as a false alarm, security experts said.

Conficker, also known as Downadup or Kido, is quietly turning thousands of PCs into servers of email spam and installing spyware, they said.

The worm started spreading late last year, infecting millions of computers and turning them into "slaves" that respond to commands sent from a remote machine that controls an army of computers known as a botnet.

Many feared it would wreak havoc on April 1, but instead the worm mutated to make it harder to catch.

Its unidentified creators started using infected machines for criminal purposes in recent weeks by loading more malicious software onto a small percentage of computers under their control, said Vincent Weafer, a vice president with Symantec Security Response.

"Expect this to be long-term, slowly changing," he said. "It's not going to be fast, aggressive."



What the worm does ?

Conficker installs a second virus, known as Waledac, that sends out email spam without knowledge of the PC's owner, Mr Weafer said.

It also installs a fake anti-spyware program so users would be led to believe their computer's safe.

"This is probably one of the most sophisticated botnets on the planet. The guys behind this are very professional. They absolutely know what they are doing," said Paul Ferguson, a senior researcher with Trend Micro.

He said Conficker's authors likely installed a spam engine and another malicious software program on tens of thousands of computers since April 7. The worm will stop distributing the software on infected PCs on May 3 but more attacks will likely follow.

"We expect to see a different component or a whole new twist to the way this botnet does business," said Mr Ferguson.

Viruses that turn PCs into slaves exploit weaknesses in Microsoft's Windows operating system. The Conficker worm is especially tricky because it can evade corporate firewalls by passing from an infected machine onto a USB memory stick, then onto another PC.

The Conficker botnet is one of many such networks controlled by syndicates that authorities believe are based in eastern Europe, Southeast Asia, China and Latin America.



What you can do ? 

First of all, make sure your PC has the latest patch from Microsoft and update your security software. If you cannot access your anti-virus maker's website, your PC may already be infected.

In general, you should always be careful when clicking on unknown links. Use LinkScanner to find out if a link leads to dangerous content, and be wary of pop-up windows prompting you to install software such as antivirus or video player updates.

You may also read the US Department of Homeland Security's recommendations at www.dhs.gov, or find out more on Wikipedia


Visit 13above For More Fun

Read more »

Top 10 Halloween Costumes For The Financial Crisis

0 comments
Forget werewolves and vampires. With markets melting and 401(k)s dwindling, people are much more afraid of going broke. This Halloween, give revelers a real shot of terror with a costume that reflects the tough times.

1. AIG Executive

You'll need a fluffy robe and a respectable manicure.

Accessories:

--Spa slippers
--Clay facial mask
--Fluffy slippers
--AIG "Hi My Name Is..." sticker badge

2. Cowboy Capitalism

Dress up in a business suit but with a cowboy hat and boots. Sport a black eye.

Accessories:

--Adult beverage in a brown bag

3. Dow Jones Industrial Average

Paint a large piece of cardboard with a downward plunging arrow and write "DJIA" across your chest.

Accessories:

--A teddy bear
--A case of the shakes

4. Fannie Mae and Freddie Mac

A guy and a gal dress up as drunken sailors in the style of Raggedy Ann and Andy.

Accessories:

--Bottles of booze
--Toy houses

5. Financial Bailout

Gear up in red and gold as the Hammer and Sickle Superhero. You'll need: a headband, tights and a cape.

Accessories:

--A bucket labeled $700 billion and stuffed with cash.

6. Golden Parachute

Put on a jumpsuit (preferably gold). Then spray-paint a trash bag gold and attach parachute strings.

Accessories:

--Affix giant dollar sign to chest
--Safety goggles or golden superhero mask, depending on taste
--Play money tucked into belt and pockets.

7. Lehman CEO Dick Fuld

Climb into your Skeletor costume. Put on a golden parachute.

Accessories:

--"Blame the Shorts" button
--Golden handcuffs

8. Mortgage-Backed Security

Strap a small, plastic child's play house on your back.

Accessories:

--Wrap two bike chains across your chest
--Makeup to turn face black and blue

9. Treasury Secretary Hank Paulson

Get a sharp looking suit, bald cap, rimless spectacles.

Accessories:

--Toy bazooka

--Assistant Secretary Neel Kashkari "mini me" doll.

10. Underwater Mortgage

Make a diorama of a house with a hole in the bottom for your head. Paint fish and furniture floating in the windows. Wear a snorkel and diving mask

Accessories:

--Life preserver labeled "foreclosure relief plan"



Visit 13above For More Fun

Read more »

Computer Virus Has Experts On High Alert

0 comments
SOME 10 million computers infected by the mysterious Conficker worm are waking up and "calling home" as instructed by an unknown master controller who used April Fool's Day as the trigger.

Australia's computer response team, AusCERT, was on high alert yesterday as global IT experts monitored regional - first past the dateline - activity, seeking clues to the malware's author and the feared attack plans.

"Infected computers are trying to find a way to call home, but at this stage nothing malicious is happening," said AusCERT senior information security analyst Zane Jarvis.

"We're seeing hosts do the look-up for IP addresses of sites like google.com or microsoft.com, but nothing is responding and they're not getting any IP addresses."

Mr Jarvis said there had been an increase in local network traffic, with infected machines apparently programmed to do standard Domain Name Server requests for a set period, then "go to sleep" for 90 minutes or so before starting again.

"It's possible that the controller will wait for all the attention to die down, and then do something when everyone stops watching," he said.

Also known as Downadup, the malware exploits a vulnerability in Microsoft Windows systems that allows a remote hacker to take control of infected machines.

Microsoft issued a patch to fix the bug last October, and people who regularly update their software are protected, but an estimated 9-15 million computers worldwide may have been compromised.

Security analysts are particularly worried because they don't know what the mystery attacker has in mind.

Threats range from financial fraud and identity theft on a grand scale, to massed armies of computers being used to launch denial-of-service attacks.

IT security vendors such as Symantec are monitoring the situation, and plan to issue updates if any suspicious new activities are detected.

McAfee's regional technical services director, Michael Sentonas, expected more network traffic overnight as users in Europe and North America came online.

"The biggest unknown is whether some dangerous functionality will be unleashed," he said.

Mr Sentonas warned that publicity over the threat had spawned a large number of "rogue websites" offering fake removal tools which people were downloading free of charge.

"Unfortunately, these so-called anti-virus detection and cleanup tools actually download other malicious content, creating a never-ending cycle of threats to your machine," he said.

"Rather than doing a search for free tools on Google or Yahoo!, my advice is always to deal with reputable vendors _ all of which offer free tools and advice."

Late yesterday, the US-based SANS Internet Storm Center maintained its ``green'' internet safety rating, with director Marcus Sachs saying that while "over the next 24 hours Conficker will change the way it communicates, we don't expect much of anything else to happen".
source : http://www.australianit.news.com.au/


Visit 13above For More Fun

Read more »

Largest Virus Threat Awaited (9 Million +)

0 comments
MILLIONS of computers around the world could go into meltdown on April 1 because of a deadly virus.

The Windows worm called Conficker could give a hacker unrestricted access to every infected machine on the planet.

And the aggressive bug could be hiding on your PC at home right now, waiting to kick in.

For the hackers, it’s like having a virtual army at their fingertips.

The criminals behind it have the power to launch a tidal wave of junk emails, bringing computers grinding to a halt.

They could also plunder information, including your bank details.

But the truth is that the best techie brains in the business just don’t know exactly what the hackers have in mind.

Infected:

Virus expert Mikko Hypponen, from the firm F-Secure, said: “It is scary thinking about how much control a hacker could have over all these computers. They would have access to millions of machines.”

Microsoft, who developed the Windows computer operating system, have slapped a £175,000 bounty on whoever is responsible, so far without success.

The sophisticated Conficker bug — also known as Downadup or Kido — targets systems via the web and can be spread on memory sticks.

More than nine million computers were infected at the bug’s peak last month.

And if Conficker is still on your system come Wednesday, you could be in trouble.

Once inside your PC, it sets up files and starts downloading information from a controlling “boss” server.

Finding that website and the mastermind behind it all is like looking for a needle in a haystack.

That is because the bug creates hundreds of bogus addresses every day to put investigators off the scent.

The infected PCs then form a network and “talk” to each other, updating and evolving.

The bug even attacks anti-virus software and other files on your computer to strengthen its position.

And it resets “restore” points, making recovery of your old system even harder.

The first of three Conficker strains was discovered in November last year.

A second, more aggressive strain followed in December and a third this month. This contains the all-important April 1 trigger.

Trigger :

To avoid infection, Windows users must download a special free update “patch” from the Microsoft website. But that isn’t enough — you also need good anti-virus software too.

Many businesses around the world are thought also to be at risk after failing to update systems.

Graham Cluley, from computer security firm Sophos, warned: “Microsoft did a good job of updating people’s home computers.

“But the virus continues to infect businesses that have ignored the update.”

He also stressed the need for strong passwords on your computer, adding: “If users are using weak passwords — 12345, QWERTY etc — then the virus can crack them.”

F-Secure’s Mikko warned potential problems with Conficker would be highlighted wildly before April 1.

But he said he didn’t foresee an attack, despite the fears and mystery surrounding the problem.

He said: “There’s always hype — just think of previous cases.

“There is not going to be a ‘global virus attack’. We don’t know what they are planning to do, if anything.

“I think the machines that are already infected might do something new on April 1.”

Let’s hope, for everyone’s sake, that it turns out to be an April Fools’ Day hoax.


TEST your system’s safety for free by attempting to go to f-secure.com. If you can’t, you can download the patch at microsoft.com to disinfect your PC.



Read more »

Top 7 Biggest Internet Threats !

0 comments
The internet is filled with threats real and imagined, from malicious hackers to government censors.

Beyond the hacks and cracks — and in celebration of Sunshine Week — we've compiled a brief list of some of the biggest public and private threats facing the internet.

1. Warrantless Government Monitoring : Following the Sept. 11 terror attacks, the practice of wiretapping all internet traffic began in the United States with the Bush administration, and is now being defended in court by the Obama administration. All of the nation's major internet service providers are accused of funneling Americans' online traffic to the National Security Agency without warrants.

2. Private Censorship : From the mundane to the frightening, the examples run rampant. Wikipedia, the world's most trafficked online reference tool, is subject to shameful spin from trusted names of news organizations to the not so trustworthy engines of commerce. Among the examples, The Boston Globe enhanced the biography of a columnist while deleting information about his alleged plagiarism. Diebold excised an entire section critical of the company's voting machines.

3. Government Censorship : Reporters Without Borders reported last week that 12 nations — China, Burma, North Korea, Vietnam, Egypt, Iran, Syria, Saudi Arabia, Turkmenistan, Uzbekistan, Cuba and Tunisia restrict internet access and often prosecute users for what they post online.

Even in democratic countries, censorship rears its ugly head. On Thursday, a secret blacklist surfaced detailing 2,395 webpages the Australian government is planning to filter from the internet. While about half of them dealt with illegal pornography, the remainder did not. Some of the sites were about gambling, dentists and even dog kennels.

In December, Wikipedia couldn't be edited by users in Britain. The entire site was put on a blacklist because it linked to the 1976 album cover of Virgin Killer by the Scorpions, which featured a nude young girl.

In the United States, a federal judge last year blocked WikiLeaks from operating in the country for a week after the renegade site posted allegedly stolen documents detailing individuals' Swiss bank accounts.

4. Deep Packet Inspection : Several U.S. internet service providers, including giants like Comcast and Cox Communications, have started inspecting the contents of internet packets, a practice (.pdf) allowing them to monitor, filter and ultimately control the traffic that passes through their pipes. In addition, online advertising services like NebuAd are paying ISPs to let it eavesdrop on web users via DPI.

5. ISP Tiered Pricing : Major ISPs, including AT&T, Time Warner and Comcast have moved or are gravitating toward pricing services based on the amount of bandwidth individuals use. Theoretically, the plans could unlock the internet door to low-income users. But we suspect the plans are designed to increase profits for ISPs as bandwidth use skyrockets — all of which may have a chilling effect on internet usage.
6. Recording Industry Association of America Proposes "Three-Strikes" Policy : The record labels are pushing for ISPs to ban service to customers the RIAA claims are file-sharing copyrighted music. Overseas, industry groups like the International Federation of the Phonographic Industry are pursuing similar efforts.

7. Digital Millennium Copyright Act Abuses : Unwarranted YouTube takedown notices by misguided copyright holders comes immediately to mind — including assertions by Universal Music that it need not consider whether a video, under the DMCA, makes a "fair use" of the copyrighted works in question. Google says 57 percent of takedown notices it received were sent by business targeting competitors and 37 percent were not valid copyright claims.

Note : Tell us what you think are the most threatening threats to the internet...


Visit 13above For More Knowledge

Read more »
My Ping in TotalPing.com My Zimbio