Showing posts with label awareness. Show all posts
Showing posts with label awareness. Show all posts

Friday, June 6, 2014

A Big Problem: Cryptolocker the Ransomware


Cryptolocker is back in the headlines, thanks to a coordinated effort to take down the computers and criminals that run the notorious "ransomware". But what is it? And how can you fight it?

Cryptolocker is ransomware: malicious software which holds your files to ransom

The software is typically spread through infected attachments to emails, or as a secondary infection on computers which are already affected by viruses which offer a back door for further attacks.
When a computer is infected, it contacts a central server for the information it needs to activate, and then begins encrypting files on the infected computer with that information. Once all the files are encrypted, it posts a message asking for payment to decrypt the files – and threatens to destroy the information if it doesn't get paid.

The authorities have won users a two-week window of safety
The National Crime Agency (NCA) announced yesterday that the UK public has got a "unique, two-week opportunity to rid and safeguard" themselves from Cryptolocker. The agency didn't go into more detail, but it seems likely that at least one of the central servers which Cryptolocker speaks to before encrypting files has been taken down.
The NCA has also taken down the control system for a related piece of software, known as GameOver Zeus, which provides criminals with a backdoor into users' computers. That back door is one of the ways a computer can be infected with Cryptolocker in the first place.
What that means is, until the window is closed – and the virus cycles to new servers – users who are infected with Cryptolocker won't lose their files to encryption. As a result, these users have the chance to remove the virus before it destroys data, using conventional anti-virus software. In other words, there has never been a better time to update the protection on your computer. 
But watch out – while the servers that control Cryptolocker are out of action, it's possible to be infected with it and not know. If you don't keep your computer clean, then at the end of the two-week period, you could be in for a nasty surprise.

Cryptolocker only infects PCs, but there are other types of ransomware
Cryptolocker is the name of one particular virus, which only infects Windows PCs, running XP, Vista, Windows 7 or Windows 8. So if you use an Apple computer, it can't affect you. Similarly, smartphones are safe from cryptolocker. 
Although it is the most famous example of ransomware, it's not the only one. Even in the two-week window, PC users may be infected with other types of ransomware, and Android and Mac OS users should carry on with their normal security precautions. Being safe from one type of malware doesn't mean you're safe from all of them.

If you've been infected by Cryptolocker, your files really are gone unless you have a backup
 
Some ransomware is little more than a confidence trickster, presenting a message asking for payment without having done anything to the user's files. Cryptolocker isn't like that: the software really does encrypt your files, to a strength which renders it unbreakable even by the fastest computers in the world – even if they had the entire lifetime of the universe to work on it.
 
That means you'll have to rely on any backups of your data to get it back. But it's important that you don't try and restore your data before you clear your computer of the infection, otherwise you could lose your backup, too.

Sometimes paying the ransom will work, sometimes it won't
Except, of course, there is another possibility. Some users hit with Cryptolocker report that they really did get their data back after paying the ransom – which is typically around £300. But there's no guarantee it will work, because cybercriminals aren't exactly the most trustworthy group of people. 
What's more, if the NCA really is bringing down the command and control servers, then the criminals may not be able to return the data, even if the ransom has been paid. There's also a whole load of viruses which go out of their way to look like Cryptolocker, and which won't hand back the data if victims pay. Plus, there's the ethical issue: paying the ransom funds more crime.

This article was originally posted on:

Thursday, August 2, 2012

Software Updates, why should I bother?


Why Update
Usually Software updates are released for four reasons:
  1. Patch a security vulnerability; 
  2. Fix bugs;
  3. Add new features;
  4. Pure marketing purposes.
Staying away from the fourth reason, I believe that the most important aspect to apply a software update is to patch security vulnerabilities. Hackers do exploit these security vulnerabilities in order to gain access to your workstation and ultimately compromise your confidential data (passwords, emails, bank accounts).
Usually, when any software is being created it goes through series of phases within its development life cycle (SDLC). Two important parts of this life cycle are quality assurance and user acceptance testing. Yet the best testing any software could get is the Wild Testing.
Wild testing is done when vendors release their software un-officially (leaks, test or evaluation versions) to be tested and reviewed by enthusiastic users.
When these users submit their feedback directly to the vendor or share their experience using social networking media such as Facebook and twitter or even write a detailed review on Cnet they are able to draw the software vendor / developer attention. The developer consequently fixes the problems reported. And therefore a bug free update is released.
Sometimes, the term software update is used instead of software upgrade, this happens when the developer company releases a new version of their software with added features that is didn’t exist in the previous release.  
Most software nowadays, given the proper permission from their operator, has the ability to periodically and automatically check for updates. Moreover you as an operator can configure this software to download and install updated seamlessly and on recurrent basis, without any further more intervention from your part.

Four Software updates that shouldn’t be missed:

1. Operating Systems
Operating systems provide a software platform on top of which other programs, called application programs, can run, examples of operating systems include windows 7, windows XP, ubentu, fedora, snow leopard, Lion, and most recently mountain lion released by apple a week ago.
Vulnerabilities are discovered within an operating system on daily basis, the vendor of that operating system tries to mitigate these vulnerabilities by releasing patches. Since these patches should be able to save the day, you should install updates as soon as you see a prompt to do so, or set the computer to install them automatically.

2. Web Browsers and Supporting Software
Since the internet service and browsing experience is always evolving the ability to keep your data secure becomes a greater challenge. Microsoft’s Internet Explorer and Apple ‘s Safari are updated the same way an operating system is updated, while Google’s Chrome and Mozilla Firefox are updated automatically. 
For an ultimate user experience, web browsers need supporting packages like Adobe Flash, Adobe Reader, Sun Java and Microsoft Silverlight. And therefore due to their popularity, they are often the target of malicious attackers. It is extremely essential to update these type of software as soon as you see an alert.

3. End User Applications
Every now and then applications downloaded from the internet inform their user than a newer software update is released and ready to be downloaded and installed. These software updates are there either to fix bugs within the application or to offer brand new feature: perhaps a new graphical user interface or even better processing speed. Keep in mind that although these updates may not be mandatory, but sometimes these updates fix undisclosed security vulnerabilities within the application. So whenever an application prompts you for an update. Go ahead and do it.


4. Anti-Virus/Anti-Malware Software
New threats are introduced to the information technology field every day. And so, in order immune your PC against these threats you should keep your Anti-Virus/Anti-Malware updated. Usually these protection software update themselves seamlessly without any user intervention. 





Finally, keeping all the software installed on your PC updated can sometimes be hectic, but if you consider the risks you are mitigating, it is definitely worth the hassle

Tuesday, June 26, 2012

Again! I’m Not Falling for That One!

From time to time I review my email junk folder to check if a legitimate message got stuck in there, and in order to keep myself updated of new techniques and methods utilized to scam people into disclosing their confidential information.
 
Recently I ran across an email message, apparently from paypal requesting me to update my records in order to continue using their services. 
Since I really don't have a paypal account yet, this email is definitely a scam.
 
Upon More Investigation, carefully following the link mentioned in the email in order to update my non existing records, I was redirected to a webpage that looks like the original Paypal.com website

  
The first thing that caught my attention was the address of this fake Paypal page was the URL of this page



I tried to login to this false paypal page using incorrect and offensive credentials, i was redirected to a "Session timed out" page, and of course the credentials I used where sent, stored (stolen) by the creators of this illegitimate page.

Note that, the first thing that a user should check before disclosing any confidential data is the correctness of the URL for the page requesting this information. 


Always look for the httpS.

 


I wonder how many people took the bait and were scammed by this scenario.
The good thing is that the Firefox browser started to alert people before accessing the false paypal webpage by displaying this message 



Finally, don't fall for these scams, exercise a keen sense of responsibility, awareness and an appropriate dose of suspicion before disclosing personal information.   

Monday, June 11, 2012

Suicide Ability: Update on the Flamer Virus

Being described as the largest, most sophisticated, most discreet,  and certainly the most complex virus ever created, The Flame virus shows more of its abilities before it disappears.

It has been Proven that Flame has a built-in feature called SUICIDE that can be used to uninstall the malware from infected computers. However, late last week, Flame’s creators decided to distribute a different self-removal module to infected computers that are still connected to the predefined servers and still under their control.

Compromised computers regularly contact their pre-configured control server to acquire additional commands. Following the request, the C&C (command and control) server sent them a file named browse32.ocx. This file can be summarized as the module responsible for removing Flamer from the compromised computer. “The Disinfector”

The module “browser32.ocx” has not been seen and recovered from the field, but instead it was captured in honeypots. Any client receiving this file would have had all traces of Flamer removed, including this module itself.The suicide feature and the browse32.ocx module are designed to prevent further forensic analysis.

Meanwhile, an important question remains unanswered, since C&C servers are able to execute a command that kills the flamer virus, aren’t they able to plant the seeds of a new undiscovered virus that will reside undetected for several years performing the same or even more damage that the current Flame virus.

For more info about the files and folders removed by this “browser32.ocx” read the following from Symantec.

Tuesday, June 5, 2012

Avoiding the Flame

After reading many articles and expert reviews about the Flame Virus I came up with the following summary

What is the Flame: Worm or Trojan
Flame is a complex attack toolkit, it is a TROJAN modified to have WORM like features, allowing it to replicate within local networks and removable media.
The initial entry point of Flame is still unknown – but once a system is infected, sKyWIper, another name for Flame virus, begins a sophisticated set of operations, including:
  • Running on Windows XP, Windows Vista and Windows 7 systems;
  • Scanning network resources;
  • Stealing information as specified;
  • Communicating to Control Servers over SSH and HTTPS protocols;
  • Detecting the presence of over 100 security products (AV, Anti-Spyware, FW, etc);
  • loading itself as a part of Winlogon.exe then injects to Explorer and Services;
  • Concealing its presence as ~ named temp files, just like Stuxnet and Duqu;
  • Attacking new systems over USB Flash Memory and local network;
  • Creating screen captures, Recording voice conversations;
  • Using SQLite Database to store collected information;
  • Utilizing PE encrypted resources;

Flame Complexity: Master Piece  
Flame is a huge package of modules accumulating up to 20 MB in size when fully deployed. Because of this, antivirus companies state that it is an extremely difficult piece of malware to analyze.
The reason why Flame is so big is because it includes many different libraries, such as for compression (zlib, libbz2, ppmd) and database manipulation (sqlite3).

Flame creation date: unknown
The developers of Flame were able to change the dates of creation of the files associated with this virus to 1992, 1994, 1995 and so on, but it’s very obvious that these dates are incorrect and they aim only to give false data to investigators.
Analyzers believe that the main Flame project was created in 2010, but is still undergoing active development to date. But there is big possibility that an earlier version of this virus existed before 2010.

Why the Name: Flame
Flame aka Flamer aka SKyWIper all different call signs for the same malware. The Flame virus consists of multiple modules, one main module is called Flame – as the picture indicates – The flame module is responsible for attacking and infecting additional computers, and this is mainly the reason behind this malware naming.
No one to claim the spoils
Although, no party has claimed responsibility for the creation and usage of this malware, but it is so obvious that it was not created by a group of hacktivists to send a certain message or anonymous hackers just for the lulz.
The complex anatomy of this malware along with the geographic spread of the targets leaves no doubt that great deal of resources were invested in the creation of this virus and that it was created by nation state in order to collect info on the operations of certain countries in the Middle East, including Iran, Lebanon, Syria, and so on. 
Here’s a map of the top 7 affected countries:
 
    
Stop the Flame: Update your Antivirus
In general, most of the recent malware are small in size to be easily hidden, usually between 100k and 700K, but in Flame's case things are totally different. The large size of the Flame malware is precisely why it wasn’t discovered two years ago. For who would doubt a nine megabytes ~ named temp file to be a malware database file.
Finally In order to remove this Malware follow one of the following links and install the appropriate removal tool / Antivirus:
  1. Mcafee Stinger
  2. BitDefender Flame Removal Tool
  3. AVG and Keep it updated

Friday, June 1, 2012

Six ways to secure your Facebook!

Facebook has become big part of our lives. It is integrated in our social and private life. Nevertheless, Facebook users still face an obstacle, an issue that will exploit their privacy. Security is an essential issue when it comes to social networking, and if you don't secure your Facebook, you are in trouble. Here are six ways to secure your Facebook.

1. Go to your "Account Settings" by clicking on the arrow in the top right corner of your Facebook and selecting "Account Settings". Next, select the "Security" tab on the left side of the page, this will take you to this page:



2. Click on the first item labeled "Secure Browsing" and check "Browse Facebook on a secure connection (https) when possible". Don't forget to save your changes.



3. Next click on "Login Notifications" and check either Email or Text message/Push notification or both.



4. Edit "Login Approvals" and check the box. This will send you a text message to your phone whenever a user attempts to login to your Facebook account from an unrecognized computer or browser.



5. Click on the "Facebook Ads" tab on the right left side of the page


Then click on "Edit third party ad settings" and "Edit social ad settings" set share to "no one" in both.



6. Finally, go to your "Privacy Settings" reachable from the top right corner by clicking on the arrow. Set the default sharing permission to "friends".

Thursday, May 24, 2012

Free Online Storage: Practical - But is it safe?

Who wouldn’t like to have his data available 24 /7, Accessible from everywhere using any computer or operating system?
How many times have you left home without your precious USB drive? Well worry no more because the internet has provided you with a solution!

Online Data Storage, with products like: Google Drive, iDrive, Sky Drive, and CX will give you the ability to stash your data on a virtual drive (cloud Storage) and access this data from approximately anyplace that has internet connection. 
Although online storage seems appealing and interesting but there are some concerns that should be taken into consideration when using these services.

Having tried many products myself I will try a more direct approach: 

PROS
  • Availability: Online storage provides users with access to their data virtually at any time, and anywhere.  
  • Free: Most online storage vendors provide free accounts for people to try their services. Using free accounts services users are granted between 5 and 25 GB of online storage.
  • Recovery: Storage drives can be used as backup drives, where users can upload their data and keep it available should they lose their original data.
  • Cross Platform: Since all that you need to access your data is an internet browser, and since nearly all platforms and operating systems are equipped with at least one browser. Users should have no difficulty accessing their files.
  • Sharing: After your files are uploaded to your cloud drive, it would be very easy to share a certain file with someone else, or even link it directly to your website.
 CONS
  • Downtime: Since we are talking about the free service provided from some vendors, there is no guarantee that your files will be available 24/7. Although most of online storage providers brag about their compliance with the  Five Nines Availability (99.999% available) there is no solid guarantee of ultimate availability.
  • Bandwidth Limitations: There are two drawbacks within this aspect
  1. First, in some “Internet Primitive Countries” Internet Service Providers assign limited bandwidth speed and limited quota to their users. So if a user exceeds his preassigned quota extra charges will apply. For example, here in Lebanon, it would take me around 66 minutes to upload a 100MB file to the internet. And around 17 minutes to download the same file.
  2. The second drawback is related to the online storage vendor: since it is a free account,  bandwidth limitation is more likely to be forced by the vendor.
  • Data Security:  this is the most interesting part of online data storage; we tend to convince ourselves that since the vendor claims that our data is safe and sound, then no one could access it. But this is not the case; I believe that the moment you agree to upload your data to the so called internet drive, you should be aware that your data might be compromised. Your Storage Drive account might be hacked, your password guessed, revealed or even stolen. These things usually do happen, and when they do you lose Confidentiality, Integrity and Availability of your Data. Moreover, who could guarantee that the vendor doesn’t disclose any of your data?  
Finally, Cloud Storage is effective in storing, sharing and managing data, but when it comes to information security there should be a big question mark around your virtual drive.

Sunday, May 13, 2012

Physical Information Security

A lot has been written on information security, how to protect your PCs, your email accounts, your bank accounts, and so on. But what about physical files, credit cards, even personal conversations. Social engineers do not always have to hack your PC to collect information, they can eavesdrop on conversations, sneak a look on your laptop especially when you are writing personal confidential information.
The key is to Protect your personal and confidential information at all times, whether in your PCs, in hard copies, or even in your mouths.
Below are some tips to ensure the security of your information.
    1. Work elevators: They are the gold mine for social engineers. People tend to discuss loudly work issues, personal stuff and other confidential information in the elevator. We should refrain from discussing such topics when there is a stranger in the lift.
    2. Coffee shops: We often tend to use our laptops in coffee shops and restaurants, and we often open personal or confidential files there. Remember, someone can be looking. You should be cautious when using your laptop in public areas. You can also use privacy filters to make sure only you can see what is on the screen.
    3. ATM machines: Make sure no one is standing close to you once to key your pin. It goes without saying that you should never share your pin; that is why it is called PERSONAL Identification Number
    4. Banks and government counters: Make sure that no one is looking when you are filling applications in banks or at government counters.  These applications may contain confidential and personal information that can be easily used by social engineers. Also make sure no one is close enough to hear your conversation with the clerk.
    5. Credit card payment: A car rental agency once asked me to take a photocopy of my credit card and process the transaction later! Be careful when paying with a credit card, and never accept such offers. Also remember to verify the amount on the slip before signing it. 
    6. Your office: It is a treasure of information. Make sure all confidential files are locked away, and unauthorized people are not admitted to the office space. Don’t leave your PC unlocked and unattended. Discard confidential files smartly by shredding them. (Always consider the environment by reducing the quantity of printed material, and recycling the shredded documents)

    Bottom line, caution handling confidential information should be a part of our life, not a task that we do once a week. Whether at home, at work, or in a public place, remember that personal information is for you only.

    Tuesday, May 8, 2012

    New Technology Protects your Storage Devices

    We previously discussed USB flash drive security and how to protect it. ThumbDrive has developed a new technology to prevent unauthorized access to the information stored on your USB by using a fingerprint authorization.


    This USB has some advantages and disadvantages. Aside from securing your data, the advantages of this USB is that you can configure it to grant access to at most three users. You can also partition the USB flash drive to divide the storage capacity into secured data and open or unsecured data. It is a small, easy to set up and easy to access USB with an interface that reads your fingerprint.

    Unfortunately, this USB has two major disadvantages, cost and storage capacity. Storage capacity is an essential issue when buying storage devices. The ThumbDrive flash drive is available in 16, 32, 64 and 128MB, which is relatively small compared to our day-to-day flash drives. The reason behind this issue is that the flash drive is mainly designed to hold confidential files, and these files are usually personal files, legal documents, and financial or accounting data that don’t require huge storage capacity. So capacity isn’t really an issue here. Another major disadvantage is cost. The ThumbDrive touch 16MB costs $160, 128 MB $465, which is really a major concern for the buyer.

    Another solution for securing sensitive data on your flash drive is by using the newly designed “Voicelok Voice Authenticating USB drive”. This USB uses “voicecode”, in other words, it uses voice recognition to secure your data. The USB’s software detects precise frequencies and shades in the user’s voice. The advantages of this flash drive is that its price is much more reasonable than the fingerprint flash drive and has a better storage capacity, around $46 for a 8GB USB. Unfortunately this USB is still not reliable as the reviews indicate.

    If you want my advice, the best solution is to check the “Lenovo ThinkPad USB Portable Secure Hard Drive”. The hard drive protects the data from unauthorized access by requiring the user to enter a code into the numeric pad located on the hard drive. It allows up to ten different users and an administrator. It has a huge storage capacity compared to the fingerprint flash drive and its price is perfect, $179 for 160GB and $219 for the 320GB. The size of the hard drive is similar to the size of any other normal hard drive.
    Paying a little extra money to protect your information that can cost you a lifetime is worth it. If you have sensitive information and don’t want it falling in the wrong hands, I suggest you go for reliable technology like fingerprint flash drives or the numeric pad hard drive.