Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Tuesday, September 30, 2008

Try Clipperz Password Manager

Clipperz is an online password manager where you have total control. You access it through a Master Password (Passphrase) that YOU create, should you forget it then you have a real problem as you are the only one who knows it, it isn’t stored which also means that it cannot be retrieved.

All the information that you enter into the browser window is fully encrypted and secure. Also, this is the first web-based application that has no knowledge of the users or their data.

Full details Click Here

Friday, July 11, 2008

Safer Surfing in 'Virtual' Environment

With normal surfing information is loaded from your hard drive and then through your browser where information is then written back to your computer, if it’s a malicious site then you will also have malware written to your drive.

What if you could use a ‘virtual area’ in which you can run your browser, email reader, instant messengers and programs in complete safety. The information is loaded from your hard drive into the 'virtual' environment, from there the read/write operations are carried out within the 'virtual' environment and never back to your computer.

Well..........you can........Full details Click Here


Thursday, December 13, 2007

Ten XP Services to Turn Off

As long as Microsoft Windows has been a network capable operating system, it has come with quite a few services turned on by default, and it is a good idea for any security conscious user of Microsoft products to shut down any of these that they are not using.

If you are running Microsoft Windows XP on your desktop system, you should consider turning off the following services, it may surprise you as to what is running without your knowledge.

IIS – Microsoft’s Internet Information Services provide the capabilities of a Webserver for your computer.

NetMeeting Remote Desktop Sharing — NetMeeting is primarily a VoIP and videoconferencing client for Microsoft Windows, but this service in particular is necessary to remote desktop access.

Remote Desktop Help Session Manager – This service is used by the Remote Assistance feature that you can use to allow others remote access to the system to help you troubleshoot problems.
Remote Registry – The Remote Registry service capabilities are frightening to consider from a security perspective. They allow remote users to edit the Windows Registry.

Routing and Remote Access – This service bundles a number of capabilities together. It is rare that any of them should be necessary for a typical desktop system such as XP, however, so they can all conveniently be turned off as a single service. Routing and Remote Access provides the ability to use the system as a router and NAT device, as a dialup access gateway, and a VPN server.

Simple File Sharing – When a computer is not a part of a MS Windows Domain, it is assumed by the default settings that all filesystem shares are meant to be universally accessible. In reality, we would only want to provide shares to very specific, authorized users. Simple File Sharing, which only provides blanket access to shares without exceptions, is not what we want to use for sharing filesystem resources. It is active by default on both MS Windows XP Professional and MS Windows XP Home editions. This cannot be disabled on XP Home. On XP Professional you can disable it by opening My Computer > Tools > Folder Options, clicking the View tab, and unchecking the Use simple file sharing (Recommended) checkbox in the Advanced settings.

SSDP Discovery Service – This service is used to discover UPnP devices on your network, and is required for the Universal Plug and Play Device Host service (see below) to operate.

Telnet – The Telnet service is a very old mechanism for providing remote access to a computer, most commonly known from its use in the bad old days of security for remote command shell access on Unix servers.

Universal Plug and Play Device Host – Once you have your “Plug and Play” devices installed on your system, it is often the case that you will not need this service again.

Windows Messenger Service – Listed in the Services window under the name Messenger, the Windows Messenger Service provides “net send” and “Alerter” functionality. It is NOT related to the Windows Messenger instant messaging client, and is not necessary to use the Windows Messenger IM network.

On your system, these services may not all be turned on, or even installed. Whether a given service is installed and running depends on whether you installed the system yourself, whether you are using XP Home or XP Pro, and from which vendor you got your computer if Windows XP was installed by the vendor.

With the exception of Simple File Sharing, all of the above listed services can be disabled from the same place. Simply click on the Start button, then navigate to Settings > Control Panel, open Administrative Tools, and from there open the Services window. To disable any service in the list, double-click on its entry in that window and change the Startup type/setting.

Generally, you should change services you are turning off for security purposes to ‘Manual’ and if your system is running smoothly you can then change the setting to ‘Disabled’. When in doubt about whether a given service is necessary for other services, check the Dependencies tab in the service’s settings dialog.

This is not a comprehensive list of everything running on your computer that you may want to turn off. It is simply a list of ten items that you do not need to have running, and constitute a security vulnerability if left running.

Most users will never have use for the services in this list, once the computer is up and running. Other services may be disabled without ill effect as well, though you should research each item in the complete services list before you disable it to ensure that you actually do not need it running.

Some of them are quite critical to the normal operation of your system, such as the Remote Procedure Call (RPC) service.

Every running but unused service on your machine is an unnecessary security risk. If a service is not important for authorized users and basic system functionality, turn it off.

I also turn the Windows Automatic Updates in Control Panel\ Administrative Tools\Services to MANUAL as they are nothing more than knee-jerk reactions to Microsoft’s usual bungling. I have seen PC’s with up to 1GB of these Hotfixes, Patches and Updates. All they do is slow down the computer to a crawl. Those that are actually necessary for the system WILL NOT have a Remove button on them in the Add-Remove Program.

Security hotfixes are necessary and you don’t want expose your PC to the Internet with an unpatched system. Hotfix itself is not a problem. The problem is the ‘Hotfix Uninstaller’. They do consume a lot of disk space over time. One great tool to remove all of these junk files is a utility called CCleaner.

Friday, November 09, 2007

Secunia Personal Software Inspector (Beta)

Make your PC safer with this utility from Secunia, a company that tracks known vulnerabilities in software and operating systems.

This is one of the most useful and important free tools that you can have running on Windows XP SP2, Windows 2000 and Windows 2003.

This tool examines all of the program files on your PC for information on specific software builds installed and can identify missing Windows patches and outdated, insecure applications on your PC.

After examination, the data collected is sent to Secunia’s secure servers (https://psi.secunia.com/) and matched matched against their Signature Files which then determines the precise applications installed on your system.

Secunia state that they have more than 4,700 different programs in their File Signatures engine.

Once the scan is complete, which only takes a few minutes, Secunia PSI will categorize each program as “Up-To-Date”, “Insecure” or “End-of-Life”.

Click images for larger view

The results table presents the name and version number of your installed application. Clicking on the file name or the green information button will take you to a summary page with further information. If there is a blue button this will link directly to the file that will update or patch your software, if available.

On the summary page you will also receive a link to Secunia’s advisory about why your version is not safe, and explanations of the multiple versions of a program that you may see listed, as well as available updates and download locations.

Although Secunia PSI is not perfect, and it is still in Beta version, it is fairly useful at keeping your computer programs up-to-date, which also aids in your system security.

Secunia’s privacy statement states that they store information about your software for up to 12 months, but it does not collect any personal data beyond version numbers.

Download Secunia PSI here.

Note: The free Secunia PSI is available for Private/Home Users ONLY

As with any program installation, Backup or create a Restore Point before making any changes.

Tuesday, October 16, 2007

Securing Mac PC’s

Macs are much more secure than Windows systems. In addition to having most unnecessary services disabled by default, Macs face very little threat from viruses, spyware, adware, and other malware, but this does not mean that Macs are immune from security threats though.

Apple computers need good security practice to remain secure just as Windows systems do. By configuring user accounts, assigning proper permissions, complex passwords, regularly updating Mac OS X and installed applications, ensuring the Mac’s built-in firewall is properly configured, and by following other steps reviewed here, users can help ensure they have taken steps to protect their systems from unwanted breaches.

Antivirus and antispyware options

Spyware on the Mac platform, however, is basically not an issue. Unlike the Windows OS, which is sometimes crippled by the never-ending onslaught, Macs are relatively immune from the threat. However, there are very few utilities exist to protect Macs from unwanted software and malware. Such offerings include SmithMicro Software’s Internet Cleanup and SecureMac.com Inc.’s MacScan.

Security efforts on the Mac, therefore, quickly turn to focusing on user account security. Once user accounts have been implemented and separate, complex passwords assigned to both user and local administrator accounts, users can take several steps to help ensure Mac OS X systems remain secure.

Software update

Keeping systems current with the latest security updates and patches is a necessity. The Mac’s Software Update feature is the equivalent of Windows Update. By configuring Software Update to automatically download and apply security updates, users can keep systems current and help protect Mac OS X from unwanted breaches.

To configure Software Update, users should follow these steps on Mac OS X version 10.4 systems:Open System Preferences. Double-click Software Update within the System section. Press the Update Software tab. Select the Check For Updates box.

Specify how often the Mac system should check for updates (options include Daily, Weekly, and Monthly). Weekly updates should be sufficient for most users.

If you want to review downloads before they install you should check the Download Important Updates In The Background box. When the box is checked, the Mac will notify you that important software updates have been downloaded and are awaiting installation.

If you want to review which software updates have been loaded you can check the Software Update’s Installed Updates tab. A window will appear listing installed updates, for which version number information also appears.

You can check for new updates at any time by pressing the Software Update’s Check Now button.

Application updates

In addition to ensuring Mac OS X remains up-to-date with the latest security patches and fixes, you should ensure that all installed applications remain current. For example, a number of Mac programs connect the Internet and other resources. Those programs must remain secure with the latest security patches. By regularly updating Web browsers, office applications, utilities, antivirus programs, and other software, users can help prevent common causes of system breaches.

IP Firewall

It is essential to familiarize yourself with the Mac OS X IP Firewall, known as IPFW. The built-in firewall offers a powerful tool for protecting against unwanted network access.

To enable Mac’s IP Firewall and reduce network threats, follow these steps:
Open System Preferences.
Double-click the Sharing option within the Internet & Network section.
Select the Firewall tab.
Press the padlock icon and enter an account username administrator password and press OK.
Ensure the firewall is enabled (press the Start button if the firewall is stopped).
Disable as many of the incoming network services as is practical within your operating environment.

To disable services (for which default options include Personal File Sharing, Windows Sharing, Personal Web Sharing, Remote Login — SSH, FTP Access, Apple Remote Desktop, Remote Apple Events, Printer Sharing, iChat Bonjour, iTunes Music Sharing, iPhoto Bonjour Sharing, Network Time and CVS), simply uncheck the respective checkbox. You can add new services using the supplied New button.

When enabling new incoming services, you must specify a port name - options include ICQ, IRC, Timbuktu, VNC, and Other - TCP port number, UDP port number, and a description.

Under Advanced Options you can choose to block all UDP traffic, enable firewall logging and trigger Stealth Mode. In Stealth Mode, uninvited traffic receives no response from the Mac system, which increases security by preventing the Mac from automatically responding to even simple attempts to learn whether it is online.

FileVault

To ensure Mac data remains secure you can take advantage of Apple’s FileVault feature, which is particularly important on laptops used by mobile users. FileVault automatically encrypts all the data within each user’s Home folder. Without knowing a user’s password, the 128-bit encryption makes it much more difficult for another user or hacker to access another Mac user’s files.
To enable FileVault, follow these steps:
Open System Preferences.
Double-click the Security icon within the Personal section.
Select Turn On FileVault (you’ll be prompted to set a Master Password for the system if one hasn’t already been assigned).

The Mac will present a warning message stating that files will be encrypted. Users must enter the administrator password to proceed. Once the password has been entered the Mac begins to encrypt the user’s Home Folder. This process can take some time depending upon the number and size of files stored within the Home Folder.

When complete, the Mac will present the login Window. You can then log back in to the Mac system and will find the Home Folder contents are now encrypted, as shown by a FileVault icon on the user’s login window.

Secure virtual memory

Virtual memory is the data the Mac stores on the hard drive when operations exceed available RAM.

By enabling Secure Virtual Memory you can prevent hackers from accessing information including passwords etc. from a user’s live swap file. While it sounds unlikely, the increase of unencrypted Wi-Fi hotspots has increased the chances of such a breach.

To enable Secure Virtual Memory, follow these steps:
Open System Preferences.
Double-click the Security icon from within the Personal section.
Press on the padlock to enable changes.
Supply a username and administrator password.
Check the box for Use Secure Virtual Memory.

Other recommendations

Mac users can also take further steps to help secure their system. In addition to disabling automatic login (the checkbox is accessed using the Security applet within System Preferences), you should disable fast user switching (accessed from the Accounts applet in System Preferences). When using new Macs, care should be taken to leave the UNIX-powered machine’s root account off.

To disable the root user account (if enabled), follow these steps:
Open the Mac’s Finder application.
Navigate to the Applications folder.
Open the Utilities folder.
Open NetInfo Manager.
Select Security from the top menu bar and select Authenticate.
Enter a username and administrator password and press OK.
Highlight Security from the menu bar.
Select Disable Root User.

File Shredders for Security

So you delete a file and it goes into your Recycle Bin, then you empty the Recycle Bin and it’s gone. You think so anyway. It isn’t. Windows simply removes the reference to the files, and with Recovery Software it is very easy to recover deleted items.

Use these programs with extreme caution, ensuring your PC is backed up first.

With these products you can safely shred confidential information. If you are replacing your PC or Hard Drive, would you leave any personal identification on it? Many people do, thinking that a reformat will wipe any sensitive data, yet most Recovery Software programs can easily recover these files. If it has been securely shredded it is almost impossible to recover depending upon the algorithm of the shredder.

File Shredder is a free program for Personal and Commercial use.It is a fast, safe and reliable utility.

You have the option to shred files or complete folders, along with 5 different algorithms:

Simple One Pass

Simple Two Pass

DoD 5520-22.M

Secure Erasing Algorithm with 7 Passes

Guttman Algorithm 35 Passes.

It has a Windows Shell Integration which means that you can right click any file or folder and select File Shredder which then gives you the option to Secure Delete, Remember to be deleted later or to Call Up the File Shredder which will open the program.

You will be asked for confirmation before shredding any items, they do NOT get shredded by adding them to File Shredder and you have the option to remove items before shredding is started.

You can also Shred Free Disk Space on your hard drive, which will shred unused or free space across the whole volume which includes previously deleted items. This option may take some time depending on which algorithm you choose and the speed of your PC.

The author of this program has issued it in the belief that everyone has the right to permanently remove private and confidential documents as a basic right to privacy.

File Shredder is compatible with Windows NT, 2000, XP, 2003 Server and Vista.

The download file is 1.2 mb and is available here.

There is another File Shredder from HandyBits, which is free for personal use only and again is compatible with Windows OS.

This shredder features simple drag&drop files or folders to the Desktop Icon, over writing data up to 15 times, Windows Shell Integration, Multi Language Support, Custom Backgrounds, a Drop Target Window which stays on top of other windows, Useful Tips and Online Help.

The download file is 1.55 MB and is available here

A word of caution.

Backup your system before making any changes.

Any files that are accidentally deleted to the Recycle Bin and subsequently deleted upon emptying the Recycle Bin can be recovered using a recovery program such as Recuva.

Once shredded using file shredders, they may well be beyond normal recovery methods.

Securing Your Wireless Network

Working from home while using a wireless local area network (WLAN) may lead to theft of sensitive information and hacker or virus infiltration unless proper measures are taken.

As WLANs send information over radio waves, someone with a receiver in your area could be picking up the transmission, therefore gaining access to your computer. They could load viruses on to your computer which could be transferred to other computers on your network.

Up to 75 per cent of WLAN users do not have basic security features installed, while 20 per cent are left completely open with the default configurations.

It is recommended that wireless router/access point setup be always done though a wired client.

You can setup your security by follow these steps:

Change default admin password on wireless router/access point to a secured password.

Change your WEP keys periodically.

Change the channel your router uses to transmit and receive data on a regularly basis.

Use encryption such as WEP and WPA. If equipment does not support at least 128-bit WEP encryption, consider replacing it.

Change the default SSID on your router/access point to a hard to guess name. Setup your computer device to connect to this SSID by default.

Setup router/access point not to broadcast the SSID. The same SSID needs to be setup on the client side manually. This feature may not be available on all equipment.

Block anonymous Internet requests or pings.

On each computer having a wireless network card, network connection properties should be configured to allow connection to Access Point Networks Only.

Computer to Computer (peer to peer) Connection should not be allowed. Enable MAC filtering. Deny availability to your wireless network for unspecified MAC addresses.

Mac or Physical addresses are available through your computer device network connection setup and they are physically written on network cards.

When adding new wireless cards / computers to the network, their MAC addresses should be registered with the router /access point.

Network router should have firewall features enabled and demilitarized zone (DMZ) feature disabled.

All computers should have a properly configured personal firewall in addition to a hardware firewall. You should also update router/access point firmware when new versions become available.

There is no guarantee of a full protection of your wireless network, but following these suggested tips can definitely lessen your risk of exposing to attackers aiming at insecure networks.

Monday, October 01, 2007

Simple and Safe File Encryption

Try this very simple and easy to use state-of-the-art encryption utility. Even for novice users this is the easiest and most reliable way to secure your data with strong encryption.

This product is multi-lingual, available in: English, French, Spanish, Italian, Portuguese, German, Dutch, Norwegian, Swedish and Danish languages. Just choose from the language list inside the program, and it will appear in the language preferred by you.

You can encrypt both standalone files and complete folders. The high level security is ensured by using the 128-bit key BlowFish algorithm.

You can build self-extracting encrypted and compressed archives and send them to others. The only thing a recipient needs to extract the encrypted files is the correct password.

You can add several files or folders to an encrypted EasyCrypto ZIP file. When you send this type of archive to someone, the recipient just needs to install EasyCrypto to extract the folders.

After you encrypt files, EasyCrypto automatically and securely wipes the originals.

You can encrypt and decrypt your files or folders from Windows Explorer integration. Simply select the files/folders you want to process, right click with your mouse and from the pop-up menu select encrypt or decrypt.

To avoid situations where you try to encrypt a file/folder already encrypted, or decrypt a file/folder which has not been encrypted, the program first checks the file/folder to check the status before processing.

Should your PC shut down or suffer power loss, your data remains intact. EasyCrypto copies the files before processing.

You can assign names for the passwords you use. For encrypting you just have to enter the assigned name rather than the password and confirmation each time. For decrypting, you will still need to enter the password.

Customize the program appearance to suit yourself, with a choice of 11 backgrounds.

Context sensitive tips are shown in the top section of the window. This will help you to use EasyCrypto in the simplest way.

In the Help menu you can get further support via the internet.

Click here to download

This program is Free for Personal use

Securing Mac's

Macs are much more secure than Windows systems. In addition to having most unnecessary services disabled by default, Macs face very little threat from viruses, spyware, adware, and other malware, but this does not mean that Macs are immune from security threats though.

Apple computers need good security practice to remain secure just as Windows systems do. By configuring user accounts, assigning proper permissions, complex passwords, regularly updating Mac OS X and installed applications, ensuring the Mac’s built-in firewall is properly configured, and by following other steps reviewed here, users can help ensure they have taken steps to protect their systems from unwanted breaches.

Antivirus and antispyware options

Spyware on the Mac platform, however, is basically not an issue. Unlike the Windows OS, which is sometimes crippled by the never-ending onslaught, Macs are relatively immune from the threat. However, there are very few utilities exist to protect Macs from unwanted software and malware. Such offerings include SmithMicro Software’s Internet Cleanup and SecureMac.com Inc.’s MacScan.

Security efforts on the Mac, therefore, quickly turn to focusing on user account security. Once user accounts have been implemented and separate, complex passwords assigned to both user and local administrator accounts, users can take several steps to help ensure Mac OS X systems remain secure.

Software update

Keeping systems current with the latest security updates and patches is a necessity. The Mac’s Software Update feature is the equivalent of Windows Update. By configuring Software Update to automatically download and apply security updates, users can keep systems current and help protect Mac OS X from unwanted breaches.

To configure Software Update, users should follow these steps on Mac OS X version 10.4 systems:Open System Preferences. Double-click Software Update within the System section. Press the Update Software tab. Select the Check For Updates box.

Specify how often the Mac system should check for updates (options include Daily, Weekly, and Monthly). Weekly updates should be sufficient for most users.

If you want to review downloads before they install you should check the Download Important Updates In The Background box. When the box is checked, the Mac will notify you that important software updates have been downloaded and are awaiting installation.

If you want to review which software updates have been loaded you can check the Software Update’s Installed Updates tab. A window will appear listing installed updates, for which version number information also appears.

You can check for new updates at any time by pressing the Software Update’s Check Now button.

Application updates

In addition to ensuring Mac OS X remains up-to-date with the latest security patches and fixes, you should ensure that all installed applications remain current. For example, a number of Mac programs connect the Internet and other resources. Those programs must remain secure with the latest security patches. By regularly updating Web browsers, office applications, utilities, antivirus programs, and other software, users can help prevent common causes of system breaches.

IP Firewall

It is essential to familiarize yourself with the Mac OS X IP Firewall, known as IPFW. The built-in firewall offers a powerful tool for protecting against unwanted network access.

To enable Mac’s IP Firewall and reduce network threats, follow these steps:
Open System Preferences.
Double-click the Sharing option within the Internet & Network section.
Select the Firewall tab.
Press the padlock icon and enter an account username administrator password and press OK.
Ensure the firewall is enabled (press the Start button if the firewall is stopped).
Disable as many of the incoming network services as is practical within your operating environment.

To disable services (for which default options include Personal File Sharing, Windows Sharing, Personal Web Sharing, Remote Login — SSH, FTP Access, Apple Remote Desktop, Remote Apple Events, Printer Sharing, iChat Bonjour, iTunes Music Sharing, iPhoto Bonjour Sharing, Network Time and CVS), simply uncheck the respective checkbox. You can add new services using the supplied New button.

When enabling new incoming services, you must specify a port name - options include ICQ, IRC, Timbuktu, VNC, and Other - TCP port number, UDP port number, and a description.

Under Advanced Options you can choose to block all UDP traffic, enable firewall logging and trigger Stealth Mode. In Stealth Mode, uninvited traffic receives no response from the Mac system, which increases security by preventing the Mac from automatically responding to even simple attempts to learn whether it is online.

FileVault

To ensure Mac data remains secure you can take advantage of Apple’s FileVault feature, which is particularly important on laptops used by mobile users. FileVault automatically encrypts all the data within each user’s Home folder. Without knowing a user’s password, the 128-bit encryption makes it much more difficult for another user or hacker to access another Mac user’s files.
To enable FileVault, follow these steps:
Open System Preferences.
Double-click the Security icon within the Personal section.
Select Turn On FileVault (you’ll be prompted to set a Master Password for the system if one hasn’t already been assigned).

The Mac will present a warning message stating that files will be encrypted. Users must enter the administrator password to proceed. Once the password has been entered the Mac begins to encrypt the user’s Home Folder. This process can take some time depending upon the number and size of files stored within the Home Folder.

When complete, the Mac will present the login Window. You can then log back in to the Mac system and will find the Home Folder contents are now encrypted, as shown by a FileVault icon on the user’s login window.

Secure virtual memory

Virtual memory is the data the Mac stores on the hard drive when operations exceed available RAM.

By enabling Secure Virtual Memory you can prevent hackers from accessing information including passwords etc. from a user’s live swap file. While it sounds unlikely, the increase of unencrypted Wi-Fi hotspots has increased the chances of such a breach.

To enable Secure Virtual Memory, follow these steps:
Open System Preferences.
Double-click the Security icon from within the Personal section.
Press on the padlock to enable changes.
Supply a username and administrator password.
Check the box for Use Secure Virtual Memory.

Other recommendations

Mac users can also take further steps to help secure their system. In addition to disabling automatic login (the checkbox is accessed using the Security applet within System Preferences), you should disable fast user switching (accessed from the Accounts applet in System Preferences). When using new Macs, care should be taken to leave the UNIX-powered machine’s root account off.

To disable the root user account (if enabled), follow these steps:
Open the Mac’s Finder application.
Navigate to the Applications folder.
Open the Utilities folder.
Open NetInfo Manager.
Select Security from the top menu bar and select Authenticate.
Enter a username and administrator password and press OK.
Highlight Security from the menu bar.
Select Disable Root User.

File Shredders for Security

So you delete a file and it goes into your Recycle Bin, then you empty the Recycle Bin and it’s gone. You think so anyway. It isn’t. Windows simply removes the reference to the files, and with Recovery Software it is very easy to recover deleted items.

Use these programs with extreme caution, ensuring your PC is backed up first.

With these products you can safely shred confidential information. If you are replacing your PC or Hard Drive, would you leave any personal identification on it? Many people do, thinking that a reformat will wipe any sensitive data, yet most Recovery Software programs can easily recover these files. If it has been securely shredded it is almost impossible to recover depending upon the algorithm of the shredder.

File Shredder is a free program for Personal and Commercial use.It is a fast, safe and reliable utility.

You have the option to shred files or complete folders, along with 5 different algorithms:

Simple One Pass

Simple Two Pass

DoD 5520-22.M

Secure Erasing Algorithm with 7 Passes

Guttman Algorithm 35 Passes.

It has a Windows Shell Integration which means that you can right click any file or folder and select File Shredder which then gives you the option to Secure Delete, Remember to be deleted later or to Call Up the File Shredder which will open the program.

You will be asked for confirmation before shredding any items, they do NOT get shredded by adding them to File Shredder and you have the option to remove items before shredding is started.

You can also Shred Free Disk Space on your hard drive, which will shred unused or free space across the whole volume which includes previously deleted items. This option may take some time depending on which algorithm you choose and the speed of your PC.

The author of this program has issued it in the belief that everyone has the right to permanently remove private and confidential documents as a basic right to privacy.

File Shredder is compatible with Windows NT, 2000, XP, 2003 Server and Vista.

The download file is 1.2 mb and is available here.

There is another File Shredder from HandyBits, which is free for personal use only and again is compatible with Windows OS.

This shredder features simple drag&drop files or folders to the Desktop Icon, over writing data up to 15 times, Windows Shell Integration, Multi Language Support, Custom Backgrounds, a Drop Target Window which stays on top of other windows, Useful Tips and Online Help.

The download file is 1.55 MB and is available here

A word of caution.

Backup your system before making any changes.

Any files that are accidentally deleted to the Recycle Bin and subsequently deleted upon emptying the Recycle Bin can be recovered using a recovery program such as Recuva.

Once shredded using file shredders, they may well be beyond normal recovery methods.

Friday, September 21, 2007

Securing Your Wireless Network

Working from home while using a wireless local area network (WLAN) may lead to theft of sensitive information and hacker or virus infiltration unless proper measures are taken.

As WLANs send information over radio waves, someone with a receiver in your area could be picking up the transmission, therefore gaining access to your computer. They could load viruses on to your computer which could be transferred to other computers on your network.

Up to 75 per cent of WLAN users do not have basic security features installed, while 20 per cent are left completely open with the default configurations.

It is recommended that wireless router/access point setup be always done though a wired client.

You can setup your security by follow these steps:

Change default admin password on wireless router/access point to a secured password.
Change your WEP keys periodically.

Change the channel your router uses to transmit and receive data on a regularly basis.

Use encryption such as WEP and WPA. If equipment does not support at least 128-bit WEP encryption, consider replacing it.

Change the default SSID on your router/access point to a hard to guess name. Setup your computer device to connect to this SSID by default.

Setup router/access point not to broadcast the SSID. The same SSID needs to be setup on the client side manually. This feature may not be available on all equipment.

Block anonymous Internet requests or pings.

On each computer having a wireless network card, network connection properties should be configured to allow connection to Access Point Networks Only.

Computer to Computer (peer to peer) Connection should not be allowed.

Enable MAC filtering. Deny availability to your wireless network for unspecified MAC addresses.

Mac or Physical addresses are available through your computer device network connection setup and they are physically written on network cards.

When adding new wireless cards / computers to the network, their MAC addresses should be registered with the router /access point.

Network router should have firewall features enabled and demilitarized zone (DMZ) feature disabled.

All computers should have a properly configured personal firewall in addition to a hardware firewall. You should also update router/access point firmware when new versions become available.

There is no guarantee of a full protection of your wireless network, but following these suggested tips can definitely lessen your risk of exposing to attackers aiming at insecure networks

Wednesday, September 19, 2007

Ad-Aware 2007 - Tutorial

This video will briefly show you how to use Lavasoft Ad-Aware.

It’s very simple and straightforward to use, but don’t rely solely upon one such program to keep the nasties out of your PC.

I regularly use CCleaner, SpybotS&D, MRU-Blaster and Advanced Windows Care.

Click here for Video Tutorial

Thursday, September 13, 2007

Skype Targeted With Worm

Skype, the VoIP (Voice over Internet Protocol) is considerably less secure than traditional telephone lines. Many people have switched to using Skype because of the savings they can make, and many have abandoned their traditional telephone lines altogether.

Skype was founded in 2002 and was bought by ebay in 2005 for US$2.5 billion. It has seen a steady rise in the number of subscribers to its service.

However, it still has many pitfalls, including the latest Worm called ‘W32/Ramex.A’.

It spreads through the peer-to-peer instant chat utility and is activated when a user clicks on a link within an instant message asking recipients to download a file.

It is very cleverly disguised within a jpeg image of soap bubbles, one of Windows default built-in wallpapers which has been embedded with a malicious executable code.

This code installs Spyware that can easily steal passwords and other personal information. It may also block users from visiting certain websites and stop programs from running or responding. It also connects to a remote server to download additional malicious code.

It is often titled ‘really funny’ or ‘look at this crazy photo sent to me’ with a clickable link. Once clicked, users who continue to download the file then have the risk of their machine becoming infected, and it then uses Skype’s application program to access files on the infected machine. The worm then attempts to replicate itself and then send out messages to recipients on the users contact list.

Ensure your anti-virus is up-to-date, windows updates are downloaded and installed, especially The Windows Malicious Software Removal Tool, which was last updated September 11th 2007. To remove the worm and its variants go to the link below and Download the file, save it to your Desktop (or location where you store downloaded files) and once the download is complete, select Run and the program will install.

You then have the option of a Quick Scan, Full Scan or Customized Scan.

Select Quick Scan and if any Malicious Software is found you will be prompted to run a Full Scan which may take several hours depending on your machines hard drive capacity but it’s worth it for the safety and security of your PC.

Download Here

Instant Messaging - Reducing The Risks

The internet has revolutionised the way in which we communicate with email replacing snail mail and the introduction of real-time Instant Messaging (IM).

The most popular and widely used IM services are MSN Messenger, Yahoo Messenger, AOL AIM, and ICQ. Regardless of which of these you may use, they all provide an interface for one-to-one communication or group conversations.

These programs however have opened up a whole new area for spammers and hackers to target. Using IM you can obtain the latest weather reports, movie listing etc, but you are dealing with a ‘chat robot’, also known as a ‘bot’. Now the software behind this can in some instances fool you into believing that the responses are from a real person, especially the more sophisticated versions used by hackers.

These IM programs are free to use, but are also extremely vulnerable to exploitation. They allow you to transfer files quite freely, which may already be infected with a destructive virus, Trojan horses or worms, and to have unencrypted chat sessions, which to many hackers is an open door. Some IM clients also allow peer-to-peer file sharing which potentially means that other users have access to the hard discs of other users.

Protecting yourself is a simple combination of common sense, vigilance and a few essential security tools, such as a firewall and real time anti-virus program.

Because IM is real-time, malicious attacks spread very quickly and can do an enormous amount of damage in a very short period of time.

The default security settings in IM programs are very low to make it easier to use, but this also leaves you more open to attacks. There’s also a new breed of IM worms. To your friends it appears as though they’re receiving a message from you, but the truth is the message is generated by a worm, and may contain a link to a Web site that automatically downloads another bit of malicious code.

IM is a prime target for online scams, identity theft and other predatory behavior.

These tips will help to make IM more secure:

Use a strong password and change it frequently.

Regularly update your IM software, operating system and security programs.

Do NOT enter any personal information.

Do NOT open any attachments or click on any web links sent to you by an unknown person.

If you know the identity of the person who sent you a link, hover your cursor over it to check that it is a legitimate link.

Be very careful of if a person on your allowed list starts sending odd messages, best advice is to shut down your IM program immediately.

Spim is spam sent over IM containing offensive language or links to web sites which cam also trigger an avalanche of pop-up ads, Spyware and Trojans.

There are ways to limit this, but the settings that enable you to do this mean that anyone not on your ‘buddy’ list will be blocked. This is a good thing, it protects you.

MSN Messenger: Once you’re logged in, click on Tools then Options, and select Privacy. Check mark the ‘Only people on my Allow List can see my status and send me messages’ box. The Privacy tab also allows you to add or remove people on the Allow List, as well as allowing you to see which other MSN users have added you to their contact list.

Yahoo Messenger: Click the Login menu and select Preferences. Select Privacy in the left pane of the Yahoo Messenger Preferences window, and tick the ‘Ignore anyone who is not on my Friend list’. To prevent spim through Yahoo, choose the ‘Do not allow users to see me online and contact me in the ‘When people see my ID on Yahoo Web sites’ section.

AOL Instant Messenger: Click My AIM, Edit Options, Edit Preferences to open the preferences window. Select Privacy in the left pane, and then tick the ‘Allow only users on my buddy list’ option under the ‘Who Can Contact Me’.

ICQ: Click the Main button, select Security and Privacy Permissions. Click Communication Events in the left pane, and then fill in the radio buttons under either the yellow check mark icon (this will limit these actions to users on your contact list) or the red X icon (which will prevent anyone from sending you these things). Click Spam Control in the left pane, fill in all the check boxes in the right pane, and select ‘All users’ next to the item labeled ‘Do not accept Multi Recipient Messages from’.

Friday, September 07, 2007

CoolWebSearch

This is a very nasty and insidious spyware/malware program. Spyware experts are now saying that the makers are borrowing code from other malicious programs to install rootkit like features on infected machines.

More recent versions of CWS spyware now have features similar to rootkits which allow the program writers to hide their files on Windows operating systems.

These new variants can hide their settings in the registry and also hide rootkit files in alternate data streams.

The software is usually installed on a machine by visits to malicious websites or emails using various ploys to get users to download and install the script.

Once installed, CoolWebSearch will hijack browsers and redirect users to some of the several bookmarks it imports. When you attempt to change your homepage back again it constantly overwrites it, it slows down general performance and causes Windows to freeze, crash or reboot, and can also make you victin to a Denial of Service (DOS) attack.

Getting rid of it is now much easier. TrendMicro have a free CoolWebSearch removal program

Use this utility to get rid of CoolWebSearch and it’s related programs.

Also download Spybot S&D and use its TeaTimer protection, which runs in the background and alerts you to any attempted registry changes.

If you are running Windows, also use Advanced Windows Care. Both of these programs will add a large number of changes to your Registry. This is nothing to be concerned about as the changes are necessary to stop any nasties from attching themselves to your pc and making changes you really don’t want.

Keep your anti-spyware up to date and if you click on any links that prompt you to download, read the EULA first.

Check for rootkits on your machine.

As with all programs, regular updates is essential to offer you greater protection.

More Email Dangers

The email Trojans are back in full swing.

Many of these will be titled ‘Office Antics’, ‘It Takes Guts to Say Jesus’, ‘Free Web Tools’ and many other eye catching subjects.

DO NOT open these emails as they contain a Trojan Downloader and if the link contained in the body is clicked a new window will open and you will be prompted to download a file.

Only trust emails from trusted sources, but also ensure that you have real-time anti-virus running. Even trusted sources can innocently pass on trojans and malicious code.

Virus Name: JS/Psyme also known as HTML/Mht@exp

Spreads through Web Browsing, Downloads Code from the internet, Exploits your system and/or Software vulnerabilities, and in extreme cases it can wipe your hard drive of all data.

Ensure your anti-virus is up-to-date. I recommend AVG Anti-Virus (freeware) which catches these Trojans and opens a ‘Threat Detected’ window.

If you are infected with this update your virus definitions file and reboot into Safe Mode, scan with anti-virus and also scan with ad-aware.

Email will read similar to this, with some variations:

Welcome Member,

We are so happy you joined ************

Member Number: 6257277682314
Your Temp. Login ID: user3795
Your Password ID: eq708

Please Change your login and change your Login Information.

Use this link to change your Login info: ******** (link removed)

Welcome,
***********
***********

These emails all follow the same format with a clickable link…….DO NOT click.

Surf Faster, Safer and Smarter with OpenDNS

OpenDNS is a safer, faster, smarter and more reliable way to navigate the Internet.

Based in San Francisco, OpenDNS operates a large distributed network that powers a new kind of Domain Name System service that provides all Internet users increased security, reliability and performance.

Features:
CacheCheck
Custom Image
Custom Message
Network Management
Network Shortcuts
Typo Corrections
Stats and Logs
Whitelist
Block Adult Sites
Block Phishing sites
Block Domains

Compatible with:
Windows Vista
Windows XP
Windows 2000
Windows ME
Windows 98
Windows Mobile 5
Mac OS X
Mac OS 9
Linux/Unix
Mobile: Palm OS 5, Win Mobile 5 (Smartphone & PocketPC), Nokia S60
Nintendo Wii
Network Forwarding

If you connect through a DSL, Cable or WiFi Router, you can change your router settings instead of your PC so everyone on your network can benefit from this.

Get started here

Monday, September 03, 2007

eCards and Postcards from Friends

From: BlueMountain.Com ufp@btconnect.com

Subject: You’ve received a postcard from a School mate!

Hi. School mate has sent you a postcard.
See your card as often as you wish during the next 15 days.

SEEING YOUR CARD

If your email software creates links to Web pages, click on your
card’s direct www address below while you are connected to the Internet:

http://**.***.***.**/?e3ca036e47840d8e117868911e6c3

Or copy and paste it into your browser’s “Location” box (where Internet
addresses go).

We hope you enjoy your awesome card.

Wishing you the best,
Webmaster,

BlueMountain.Com

At present there are millions of these being mass mailed on a daily basis, from ’schoolmates’, ‘friends’, ‘family members’, ‘your mate’ and many more.

Ensure that your Anti-Virus is up to date, and all system security patches have been downloaded.

NO Greeting Card company will ever ask you to DOWNLOAD anything, ecards are viewed online through a link in an email, but the links contained in these ‘cards’ prompt you to download.

In this particular case, if you click the link you are PROMPTED to DOWNLOAD or informed that your DOWNLOAD will start shortly.

It is important that you just delete these mails, many contain a Trojan Script…..but they will not zero your drive or boot sector as the rumours are saying.

As with all emails, if you don’t know the sender DELETE it.

How to ruin your PC

Fighting off Viruses

AVG Anti-Rootkit Free

Grisoft has developed quite a following with its free (for personal, non-commercial use) security applications, and for good reason.

Now there’s an anti-rootkit utility in AVG’s free software stable, too, and for users seeking a minimum of interaction, AVG Anti-Rootkit Free may very well be the Right Tool for the Job.

Grisoft makes its free AVG Anti-Rootkit application available for download. Users download the avgarkt.exe setup file, which features simple installation.

You may download a free version of AVG Anti-Rootkit here.

In keeping with the goal to make AVG Anti-Rootkit a very simple tool, the file features a simple .exe install file that triggers a setup wizard.

Users can select between a normal interface (which Grisoft recommends and sets as the default) or a low graphics interface (which is optimized for visually impaired users who rely on screen-reading programs).

Users must accept the AVG Anti-Rootkit Free license agreement before they can use the program to check their Windows system for stealth rootkit programs.

Next, users must specify the location of the AVG Anti-Rootkit Free installation files.

As with most software programs, users must specify the name of the Start Menu Folder. This is the name the AVG Anti-Rootkit application receives on the user’s Start menu.

Once users have specified all setup information, the free anti-rootkit utility installs itself.

Due to the way most anti-rootkit applications operate, it’s necessary to reboot Windows to enable proper operation. AVG’s free anti-rootkit application is no different. AVG’s setup utility gives users the option of rebooting immediately automatically or manually rebooting later.

AVG purposefully keeps its anti-rootkit interface simple. There are very few options for users to choose, thereby helping simplify the already confusing and complex world of rootkits.

AVG includes concise educational information aimed at helping regular (non-IT professionals) better understand the threat stealth rootkit programs present.

The Learn More tab lists information on what rootkits are and how users can protect their PCs from the stealth threats. There’s also a link to Grisoft’s site where additional computer security information is made available.

Users can check for AVG Anti-Rootkit Free updates using the third tab (About & Update). Clicking the About & Update tab also reveals the current version users have installed.

An interesting note, Grisoft informs users on this third tab why the AVG Anti-Rootkit uses random window titles. The reason is that AVG’s programmers wanted intentionally to change the name of the window the free anti-rootkit application uses to help thwart detection efforts rootkit hackers might program into their malware.

If users click the Check For New Version button found on the third About & Update tab, they are directed to Grisoft’s Web site. Here users will see whether the version they are using is current or whether updates must be downloaded.

The Search For Rootkits tab is the meat of the program and the reason users will download it in the first place.

Clicking the Search For Rootkits button triggers a search of stealth rootkit programs. The free AVG application tracks its progress in the progress bar at the menu’s bottom.

By default, the Search For Rootkits button only searches critical Windows directories on the root drive.

When no rootkits are found, AVG presents a congratulations window.

When rootkits are found, AVG displays those that are found (with information on the rootkit path and type). Users can then highlight the rootkit items in question and click the Remove Selected Items button to eliminate the offending files from their Windows systems.

With the In-Depth Search, however, AVG Anti-Rootkit searches for stealth rootkit files on all the hard drives and partitions within a system.

Just as with the simple rootkit search, the AVG Anti-Rootkit Free application tracks its progress as it works. Should users wish, they can terminate the search using the provided Stop button.

These are all the options a user can select when working with AVG’s free anti-rootkit program. By purposefully keeping the application easy to use, AVG engineers have created a free malware detection utility that’s the Right Tool for regular (personal) users seeking to check their systems for unwanted stealth software.

Download your copy here

Friday, August 24, 2007

Social networking and safety

Social networking sites are taking the internet by storm, largely because of their popularity with kids and teens. However, they are also attracting “groomers” who pretend to be kids in order to stalk young people and abuse them.

What exactly are social networking sites?

It’s a rather long name but it means sites which allow people to put up information about themselves such as interests, favourite music, photo galleries and diaries. People make friends by adding new contacts to their list of friends, giving them access to personal information and then chatting via instant message or email. Some sites even allow users to chat via webcam.

Popular social networking sites include MySpace, Bebo, Faceparty, Friendster, Orkut and MSN Spaces.

What are the dangers?

Making a fool of yourself.
If people put up pictures of themselves, or write personal diaries then they need to remember that, apart from their friends, there are other people who may use this information in a nasty way.

Child abusers making friends with kids.
If youngsters put lots of information about themselves on the Internet this gives “groomers” lots of ways of making friends with them (pretending to be kids themselves) and contacting them. If they put their school name and where they hang out then it’s easier to do this.

Bullying.
If a bully gets hold of a kid’s private pictures or diary then they can use this to be cruel and send round to others with unpleasant messages and so on.

Keeping you and your kids safe:

Don’t let young kids use social networking sites.
Many sites say you should be over 14 or even 16. Most parental control programs block these sites.

Don’t add unknown people to your friends list.
Only add people who are your “real” friends (not people you meet on the Internet) to your friends list or provide access to your area.

Don’t meet up with people you meet on the Internet.
If kids must do it, make sure an adult comes along, at least for the first time.

Remember that people aren’t always who they say they are.
The worst is that they may be child abusers “grooming” and so pretending to be kids in order to meet up, or they may be people who are bullies wanting to be unkind or even criminals who want to defraud you. If people are unpleasant you should be able to block them from contacting you.

Don’t put your personal information on your site.
Don’t put your address, mobile number, school name and things like where you hang out - people may use this against you.

Tell people what you are doing.
Kids should tell their parents about what is going on and who they are chatting with. Likewise, parents should be open so that kids feel comfortable talking about what goes on, so they have someone to turn to who won’t over-react.

Report abuse.
Find out how you can report bad behaviour on the site you are using or if it’s more serious to the authorities. Kids should talk to an adult they trust about bullying.

Top tips for kids

1.Tell your parents what you are doing.
If they understand it, they’ll be happier with you using the internet. Don’t give anyone your password, except maybe your parents.
2. Be careful with your mobile
Don’t send pictures that might embarrass you, even to your best friend. Someone can get hold of your camera and be nasty to you.
3. Don’t give anyone your school name
Don’t give your school name, address or phone number to people you communicate with on the internet.
4. Don’t meet up with internet friends
If you must, then take an adult with you. People are not always who they pretend to be.
5. Tell someone
Tell someone if people are saying things you don’t like or bullying you. If you don’t get help, ask advice from another adult.
6. Report it
Report bad behaviour to the website you are using.
7. Don’t let bullies win
Print off and save any messages and show someone like a parent or teacher and ask them to help. If the first person doesn’t help, then ask someone else.
8. Don’t respond to nasty emails
Don’t respond to nasty emails or messages. Block or ignore the sender.
9. Could it embarrass you?
Don’t put photos or things that might embarrass you on the internet.
10. Be nice even if they’re angry
Be as nice online as you are offline. If someone makes you angry don’t be angry back. Tell someone else or report it, but don’t get into a fight online.

Top tips for parents

1. Get involved
Open the lines of communication between you and your kids about what they are doing.
2. Don’t go overboard
Know the risks but don’t ban the internet outright, it’s a great tool. If you are over-anxious your kids won’t tell you what they are doing.
3. Agree on the ground rules
These will depend on the age of your children and the type of websites you are happy for them to view.
4. Put the computer in a main room
With your PC in a main room such as the living room, you will be able to keep an eye on what’s going on.
5. The internet is part of school life
Schoolwork these days often includes internet research and used safely the web represents an important learning resource.
6. Parental control software
Install software which is designed to block websites that are not suitable for kids.
7. Chat and instant messaging
If you are in the dark as to what these things are, then ask your kids to teach you.
8. Be careful about plagiarism and homework
The internet makes it very easy for kids to search the net and copy other people’s work. They need educating about the difference between research and plain copying.
9. Bullying on the internet
Be aware that this is a growing problem for kids particularly when using email, chat rooms or messageboards. Make sure you are there to listen if they need to talk.
10. Report abuse when you see it
Forums aimed at children are generally well-moderated and should respond to complaints.

Child abuse
The Child Safety and Online Protection Centre handle all child related reports. If you are in the UK then this is the best place to make reports. If it’s international (for example on a US website) then you should go to the Virtual Global Taskforce (VGT). The VGT is a partnership of international law enforcement agencies, working together to make the Internet a safer place. The VGT aims to identify, locate and help children at risk, to hold perpetrators appropriately to account, and help prevent child abuse around the world.

Internet Watch Foundation
The Internet Watch Foundation (IWF) works with Internet Service Providers, Police and Government to try to reduce the availability of illegal Internet content, particularly child abuse images. If you wish report the content of a particular site to the IWF, you can do so on their website at iwf.org.uk

AddThis Social Bookmark Button