Showing posts with label protection. Show all posts
Showing posts with label protection. Show all posts

Friday, June 6, 2014

A Big Problem: Cryptolocker the Ransomware


Cryptolocker is back in the headlines, thanks to a coordinated effort to take down the computers and criminals that run the notorious "ransomware". But what is it? And how can you fight it?

Cryptolocker is ransomware: malicious software which holds your files to ransom

The software is typically spread through infected attachments to emails, or as a secondary infection on computers which are already affected by viruses which offer a back door for further attacks.
When a computer is infected, it contacts a central server for the information it needs to activate, and then begins encrypting files on the infected computer with that information. Once all the files are encrypted, it posts a message asking for payment to decrypt the files – and threatens to destroy the information if it doesn't get paid.

The authorities have won users a two-week window of safety
The National Crime Agency (NCA) announced yesterday that the UK public has got a "unique, two-week opportunity to rid and safeguard" themselves from Cryptolocker. The agency didn't go into more detail, but it seems likely that at least one of the central servers which Cryptolocker speaks to before encrypting files has been taken down.
The NCA has also taken down the control system for a related piece of software, known as GameOver Zeus, which provides criminals with a backdoor into users' computers. That back door is one of the ways a computer can be infected with Cryptolocker in the first place.
What that means is, until the window is closed – and the virus cycles to new servers – users who are infected with Cryptolocker won't lose their files to encryption. As a result, these users have the chance to remove the virus before it destroys data, using conventional anti-virus software. In other words, there has never been a better time to update the protection on your computer. 
But watch out – while the servers that control Cryptolocker are out of action, it's possible to be infected with it and not know. If you don't keep your computer clean, then at the end of the two-week period, you could be in for a nasty surprise.

Cryptolocker only infects PCs, but there are other types of ransomware
Cryptolocker is the name of one particular virus, which only infects Windows PCs, running XP, Vista, Windows 7 or Windows 8. So if you use an Apple computer, it can't affect you. Similarly, smartphones are safe from cryptolocker. 
Although it is the most famous example of ransomware, it's not the only one. Even in the two-week window, PC users may be infected with other types of ransomware, and Android and Mac OS users should carry on with their normal security precautions. Being safe from one type of malware doesn't mean you're safe from all of them.

If you've been infected by Cryptolocker, your files really are gone unless you have a backup
 
Some ransomware is little more than a confidence trickster, presenting a message asking for payment without having done anything to the user's files. Cryptolocker isn't like that: the software really does encrypt your files, to a strength which renders it unbreakable even by the fastest computers in the world – even if they had the entire lifetime of the universe to work on it.
 
That means you'll have to rely on any backups of your data to get it back. But it's important that you don't try and restore your data before you clear your computer of the infection, otherwise you could lose your backup, too.

Sometimes paying the ransom will work, sometimes it won't
Except, of course, there is another possibility. Some users hit with Cryptolocker report that they really did get their data back after paying the ransom – which is typically around £300. But there's no guarantee it will work, because cybercriminals aren't exactly the most trustworthy group of people. 
What's more, if the NCA really is bringing down the command and control servers, then the criminals may not be able to return the data, even if the ransom has been paid. There's also a whole load of viruses which go out of their way to look like Cryptolocker, and which won't hand back the data if victims pay. Plus, there's the ethical issue: paying the ransom funds more crime.

This article was originally posted on:

Friday, July 6, 2012

Securing Mobile Devices


Mobile devices are without doubt people's greatest friends. Whether it is a Ipod, an Ipad , a Blackberry, an Android phone, or even a symbian phone these devices accompany us wherever we go.
People usually underestimate the security flaws of their mobile phones, although current mobile phones have the same computing power of a normal PC, people fail to treat them with equal importance.

Here are seven Tips to Secure Data stored on your Mobile Device 

I. Use the PassCode
Nowadays, nearly all mobile devices are manufactured with the ability to set access control passcodes that prevent unauthorized access to the confidential data stored on these devices.

Choose a strong passcode that is easy for you to remember but hard for others to guess, and for God sake don’t use your birthday or your girlfriend birthday (even though u should always remember that date). Use a mixed combination of letters and numbers.

Security tip: Don’t use consecutive numbers and letters because they are very easy to be guessed and surprisingly commonly used.
Grid pattern locks work fine, and fun to use, but beware that they leave finger smudge marks on the mobile touch screen especially when using a protective layer shield. This smudge makes it easier to guess your pattern.

Recent mobile devices offer device encryption for their files and data, whether for their own internal memory or their multimedia memory card. Using device encryption is the best method to protect your data from being stolen through plugging your phone to a PC to transfer data. 

II. Careful Use of Wireless Networks
Mobile phones can be set up to connect to available public WIFI networks automatically; this improper setup allows the mobile phones to shake hands with an insecure environment that might compromise your data.

So when you are not connected to a trusted wireless network, turn off the WIFI ability on your phone.

Moreover, Bluetooth communication could be exploited to spread mobile malware and eventually leak confidential data from your mobile. It is imperative to turn of the Bluetooth service when not using it.
Security Tip: Recent phones have the option to automatically turn off Bluetooth when it is gets idle for 5 minutes, use it.


III. Applications Access and permissions
Apps installed on mobile phones have the ability to access sensitive data stored on the phone itself. In general when you initially setup an application on your mobile device it requests special access, like accessing your contacts and storing them in the cloud, tracking your location, and sending you push notifications.

Usually people have the tendency to accept these modifications without thoroughly reading their content and assessing their risks. You should setup the permission level of each application depending on the level of sensitivity of your stored data.

Note that:
- You can disable push notifications by changing the settings in your device options.
- You can deactivate location based services by turning them off from your device menu. This option will stop your phone from broadcasting your GPS location regardless of the app using it. 

IV. Backup your Data
Backing up your data is the most effective way to prevent data loss, Data loss could be the result of lost or stolen phone, damaged memory card, bad application setup leaking data or even human error by messing with phone options.

Copy your data from your mobile phone to your PC or Laptop, schedule routinely backup notification in order to keep your backup copy updated.

Security tip: remember to encrypt your backup copy. Recent mobile management application enables you to utilize encryption as part of the synchronization process.

V. Firmware updates
Similar to your PC operating system, Your Smartphone should be updated in order to overcome any newly known exploits that could compromise security.

Firmware upgrades is not only limited to security issues but also to performance enhancement of you mobile experience.

Security Tip: Commit to using firmware that is certified by the vendor of your mobile Device. Tampered (Custom made) firmware might contain malicious codes that compromise your information security


VI. Remote Device Access
Many of the recent mobile phones and smart devices give u the ability to wipe its data remotely. You should exercise that option if your phone gets lost or stolen.

Moreover, you can setup your phone to automatically wipe itself clean of any personal data should the PIN guarding your phone is entered incorrectly for a certain number of attempts.

Security Tip: Don’t forget to remove your media card before sending your phone to any repair station.


VII. Sensitive Financial Data
Storing Financial Data on the phone is a big mistake; mobile phones are easily stolen or lost. I know people that used to store credit card numbers on mobile phones; others store ATM pin codes. People should really understand that it is much easier to lose data from smart mobile devices than losing their own wallets. For a start you will directly notice a missing wallet, but you will only find out a theft of sensitive info such as credit card number only when it is used or billed.

Remember: You should be always aware of shoulder surfers that scan around in order to catch you enter your PIN or passcode.

Finally, good judgment and cautious behavior are key factors to prevent data leak or loss caused by mobile devices.


Saturday, May 12, 2012

A Disaster in The Making part 2

While I was having a presentation by one of the Middle East leading firms in providing Disaster Recovery and Business Continuity solutions, I was able to take the following picture using my phone

I just wonder: how could any one buy this vendor so called “end to end” solution! and pay a huge amount of cash, while they fail to present a good and SAFE image of what they are selling.

Business Continuity is not always about having the latest servers and backups, but also it is about the level of awareness and maturity.

Tuesday, May 8, 2012

New Technology Protects your Storage Devices

We previously discussed USB flash drive security and how to protect it. ThumbDrive has developed a new technology to prevent unauthorized access to the information stored on your USB by using a fingerprint authorization.


This USB has some advantages and disadvantages. Aside from securing your data, the advantages of this USB is that you can configure it to grant access to at most three users. You can also partition the USB flash drive to divide the storage capacity into secured data and open or unsecured data. It is a small, easy to set up and easy to access USB with an interface that reads your fingerprint.

Unfortunately, this USB has two major disadvantages, cost and storage capacity. Storage capacity is an essential issue when buying storage devices. The ThumbDrive flash drive is available in 16, 32, 64 and 128MB, which is relatively small compared to our day-to-day flash drives. The reason behind this issue is that the flash drive is mainly designed to hold confidential files, and these files are usually personal files, legal documents, and financial or accounting data that don’t require huge storage capacity. So capacity isn’t really an issue here. Another major disadvantage is cost. The ThumbDrive touch 16MB costs $160, 128 MB $465, which is really a major concern for the buyer.

Another solution for securing sensitive data on your flash drive is by using the newly designed “Voicelok Voice Authenticating USB drive”. This USB uses “voicecode”, in other words, it uses voice recognition to secure your data. The USB’s software detects precise frequencies and shades in the user’s voice. The advantages of this flash drive is that its price is much more reasonable than the fingerprint flash drive and has a better storage capacity, around $46 for a 8GB USB. Unfortunately this USB is still not reliable as the reviews indicate.

If you want my advice, the best solution is to check the “Lenovo ThinkPad USB Portable Secure Hard Drive”. The hard drive protects the data from unauthorized access by requiring the user to enter a code into the numeric pad located on the hard drive. It allows up to ten different users and an administrator. It has a huge storage capacity compared to the fingerprint flash drive and its price is perfect, $179 for 160GB and $219 for the 320GB. The size of the hard drive is similar to the size of any other normal hard drive.
Paying a little extra money to protect your information that can cost you a lifetime is worth it. If you have sensitive information and don’t want it falling in the wrong hands, I suggest you go for reliable technology like fingerprint flash drives or the numeric pad hard drive.

Wednesday, May 2, 2012

Ten Ways to Protect And Safeguard Your PC

Since the use of computers has become an integrated part of our lives, information security has become a greater challenge; here are the Ten Commandments to protect and safeguard your PC:

  • Keep your operating system updated (install patches and service packs). If you are using Microsoft Windows turn ON Automatic Update.
  • Keep your third party applications updated especially your web browsers. New web browser exploits are discovered regularly and can severely impact your PC. 

 2- Use an Antivirus / Anti-Spy / Anti-Adware
  • There are many good and free anti-malware applications that are free and can be downloaded and installed easily. I personally use AVG (free and effective)
  • Usage of anti-spy and anti-adware application will help you preserve your identity and privacy while using the internet. I personally use two: Spybot Search and destroy, and Lavasoft Ad Aware.
  • Keep your antivirus definitions updated or else you will be vulnerable to multiple types of threats that your current antivirus cannot detect.
  • Full scan your PC periodically.
  • Don’t panic: sometimes anti-spy-adware applications generate false positive alerts where for example some legitimate browser cookies are flagged as adware and scheduled for deletion.

 3- Use Windows firewall 
  • Although many professionals consider Windows firewall to be dumb and bypass-able, there is no reason why you shouldn’t utilize this extra free, built-in feature in your windows (Available on all Windows versions from XP and up)
  • Use third Party firewall to increase your defense against internet attacks, I personally use:  Zonealram

 4- Turn on the popup blocker
  • Pop-ups are usually used for advertising purposes they appear to grab your attention and redirect you from one website to their own. But not all pop-ups are used for advertising purposes; others are planted with malicious intent. Some use these programs to distribute adware, spyware and more dangerous types of malware (Trojans and even Rootkits)
  • Recent Browsers give you the ability of blocking Pop-ups, and the option of choosing which sites are allowed to pass pop-ups
  
 5- Suspicious Mails are not to be Opened 
  • Never open emails that look or feel suspicious to you or not known to you, Use the “Mark as Phishing – Scam – Spam- Junk” option that most email providers utilize.
  • Some malicious Emails contain links that direct users to malicious websites that aim to harvest usernames and passwords of social media websites such as Facebook and Twitter or financial websites.
  • Never communicate your confidential data via email. Confidential data includes but not limited to usernames, passwords, addresses, telephone numbers, and social security number. Note that: Legitimate companies will never ask you to share your credentials via email.

  6- Caution When downloading Software
  • Exercise extreme caution when downloading applications and software from the internet because these applications could carry different types of malware.
  • Cracks and serial number generators are hosts to many kinds of malicious codes that most of the times can’t be detected by antivirus applications.

7- Usage of USB and External Storage Devices 
  • Transferring data from one PC to another using an external storage media without the proper information security measures could lead to virus infections, data loss and data theft.
  • Disable auto run functionality in windows, although most antivirus software perform an activity monitor over files trying to slip into your pc from an external storage, but mistakes do happen.
  • Always scan the USB memory sticks, mp3 players, iPods, and Mobile phones memory cards before browsing its content. Always: better safe than sorry.
  • Don’t compromise your data; don’t use your semi full 500 GB External Hard Disk that contains “Your Lifetime Data Backup” as a transfer media to copy small files less than 8 GB from one PC to another. Get a memory card for this task – 8 GB sticks are currently cheap easy to handle, easy to carry and protect.

 8- Back-up Data
  • Perform periodical backup of your data, and please taking a copy of your “important files” To your D: drive (which is the same primary drive, but another partition) is not considered backup.
    Backup should be done on an External media such as USB drive or Hard Disk; I personally keep two backup copies on two different media storages. 

9- System Restore – Time Machine
  • Use Windows System Restore to create restore point before doing any major change to your operating system. If something goes wrong you can use this option to restore windows to a previous saved point.
  • Similar to System Restore on Windows, time machine works on OS-X. Backup is done seamlessly provided the designated drive is connected. And restore option allows users to restore from multiple points simultaneously.

10- Password Protection
  • Passwords are unique strings of characters that users provide in conjunction with a User ID, to gain access to an information resource.
  • Passwords should be at least eight characters long including upper and lower case letters along with digits and punctuation characters.
  • Should not be a word in any language
  • You shouldn’t reveal your password in an email message.
  • You shouldn’t talk about or HINT the format of your password in front of others.

 It is not hard to protect and safeguard your Data and PC, you just have to exercise some attention, and run the extra mile

Sunday, April 22, 2012

Scams: The Story Never Ends

Last week, I received 2 missed calls from an unknown number, When I called the number back a voice with an accent said "hi sir, this is Etisalat (The main mobile operator in UAE), congratulations you won AED500,000. Please turn off your phone, and get your sim out and read the last 3 digits on it, they should read 639 (apparently all Etisalat sims end with this number) and call me back" - I said ok, and closed.

He made another missed call after 5 min, he said did you check, I confirmed and said that I should receive my gift. Here I asked why do you make missed call, and not call, if you are from Etisalat, he said they are calling me, but it's is an issue in the network (Etisalat is suddenly having problems with my sim only).

He asked for my name, and nationality, I gave fake ones, he said that they opened an account with my name in Dubai Islamic Bank and gave me an account number. And then he said, one more thing is needed, I have to go to the nearest supermarket, buy AED2,000 worth of Etisalat vouchers to verify that I'm an Etisalat user.

I started laughing and told him, I will get them later, he said no, now, you have 15 min, you are on the air on the radio and people are listening to me as I speak.
I ended the call by threatening them, and I called the police who took the number and promised to take action.

Surprisingly, I was telling this story to a friend, and he told me that he fell for it, and after giving them the pins for the vouchers, they asked for another set of AED2,000 and another one ( they turn greedy once they capture a prey)
They ripped him AED 6,000 and you know what happened.

 Again, spotting scams requires a little bit of awareness and questioning. I hope that this post saves some people from getting conned.

Thursday, April 19, 2012

Certified and Validated

In this post, I will elaborate more on HTTPS. We previously discussed the term phishing in this blog. To summarize, phishing is an attempt to manipulate or trick a person into providing confidential information to an individual that is not authorized to receive such information. To protect yourself from phishing, recent web browsers have developed a way for checking if a website is valid or not.

Web browsers trust HTTPS websites based on certificate authorities which come pre-installed in their software. Examples of certificate authorities are “Microsoft” and “VeriSign”. In the example below, the bank's web site is verified by "VeriSign, Inc."

Always look for the green address bar. Recent web browsers show a green address bar in order to tell the user that this web site is legit and trustworthy. Its purpose is to give more confidence to the user and ensure them that they are visiting a trusted web site.

This issue plays an important role in Information Security. Next time you visit a web site make sure you look for the green address, especially web sites that ask for important and private information and web sites for payment transactions. To reassure yourself, check the certificate to know if this site is validated.

Saturday, April 14, 2012

Cookies, should we really like them

What are Cookies?
Cookies are small, mostly circular pieces of sweets, that are fun to... Oops Sorry!

Cookies are small, often encrypted text files that are stored silently on a user's computer. These files are designed to carry a little amount of data specific to a particular client and website. Cookies are automatically created when a browser loads a website, allowing a server to deliver a custom made page to a particular user every time this user goes back to the same website.

Cookies Expiry Periods
The expiry time of a cookie is assigned when the cookie is originally created. Some cookies are deleted or purged when the current browser window is closed (Session cookie), but others can be made to last for a longer period of time (Persistent cookie). Yet some can last for one year or even more.

Are Cookies Secure enough?
Internet security and privacy is of huge concern. Cookies do not in themselves present a threat to privacy, since they can only be used to store information that the user has volunteered or that the web server already has. But the existence of cookies poses an inherent risk of being abused

Cookies are NOT viruses, nor are they malicious; using a plain text format, they are not compiled pieces of code so they cannot be executed nor are they self-executing. Accordingly, they cannot make copies of themselves and spread to other networks to execute and replicate again. Unable to perform these functions, they are not classified as Malware. However, breaches of browser security can allow tracking cookies to be placed. These cookies can be used to follow users from one site to another, forming comprehensive profiles. Users consider this to be a violation of privacy, and in the wrong hands this information can potentially be exploited for questionable purposes. For that reason several anti-malware products flag cookies as candidates for deletion after standard virus and/or spyware scans.

Cookies can be exploited
Several malicious activities could be associated with the existence of cookies much like: Network eavesdropping, publishing false sub-domain – DNS cache poisoning, and Cross-site scripting. (More on these attacks in later posts)

Traffic on a network can be intercepted and read by computers on the network other than the originator (Especially over unencrypted open Wi-Fi). This traffic includes cookies sent on ordinary unencrypted HTTP sessions. When network traffic is not encrypted, attackers can read the communications of other users on the network, including HTTP cookies as well as the entire contents of the conversations.

How to live with cookies
Due to the fact that many of the largest and most-targeted websites use cookies by default, cookies usage is almost inevitable. Websites like Facebook, YouTube, Gmail, and many others require the usage of cookies for best performance and presentation. Even search settings require cookies for language settings.

Here are some tips you can use to ensure worry-free cookie-based browsing:
  • Most modern browsers support different levels of cookie acceptance, expiration time and ultimately deletion. Change your browser settings “Cookie Settings” to your preference.
  • When sharing PC access, you should make sure to set your browser to purge browsing data every time the browser is closed.
  • Don’t use other's / Public wireless networks especially when communicating sensitive information over the internet.
  • Use Https rather than Http when available.
  • Use a capable and updated anti-malware software.
  • Routinely back-up your computer to prevent data loss.
  • Make sure your browser is updated: security patches are applied when you update your browser.
Finally you should acknowledge that Cookies are widely used and can't really be avoided. If you wish to enjoy your internet surfing experience by navigating to “cookie creating websites” you should have a clear understanding of how cookies operate, and how to protect them from being abused. After all you are responsible of taking the necessary security measures to ensure your information security.

Tuesday, April 10, 2012

Look for the S in The HTTP

We are all familiar with the word HTTP, Hyper Text Transfer Protocol. It is an application protocol that functions as a request/response protocol in the client/server computing model. Basically, most of what you see in your browser is transferred to your computer over HTTP. Our topic is not about HTTP and its functions, it is about HTTP and security.

Some of us are familiar with HTTPS, Hyper Text Transfer Protocol Secure. As you can see, the letter ‘S’ stands for secure. The ‘S’ comes from SSL/TLS protocol, which provides communication security over the Internet. A combination of HTTP and SSL/TLS produces HTTPS. The main objective of HTTPS is to provide a secure connection over an insecure network. Not all pages have HTTPS since it is very expensive. Pages that communicate personal data like passwords and credit cards use the HTTPS.

A page who’s URL begins with “https://” means that this page is secured and the current connection between you and the server is secured, since it provides an encrypted communication and secure identification. Payment transactions on the Internet often use HTTPS communication in order to prevent any third part interception.
You can now easily differentiate between HTTP and HTTPS. HTTP starts with “http://” :

It is an unsecured connection that is subject to third party interception, which can allow attackers to gain access to sensitive information. On the other hand, HTTPS starts with “https://”  
It is a secured connection that is designed to resist attacks or interception or even eavesdropping.

To conclude, always look for the ‘S’ in HTTP when providing secure and confidential data, this will ensure that this page is secure and nothing is suspicious about it. In my next post I will address more about HTTPS.