Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Friday, November 09, 2007

Browser Exploit Prevention

NoScript for Firefox.

Experts agree that Firefox is safer with the NoScript Firefox extension, which provides extra protection for Firefox, and other mozilla-based browsers.

This is a free open source addon makes Firefox which allows JavaScript and Java execution only for trusted domains of your choice and made even safer through preemptive whitelist-based JavaScript/Java/Plugins blocking.

You have the option to block Flash and other potentially harmful plugins.

Click for larger image

It offers many useful features which you have complete control over.

Browser based anti-XSS - Cross-Site Scripting vulnerabilities allow someone to insert their own malicious code from one site into another, which can lead to identity theft etc.

You have the ability to enable or disable Java/Javascript for Trusted Sitesusing either the NoScript status bar or the contextual menu.

There is an installation video that is well worth watching before considering deploying this tool.

Watch the video here.

Download NoScript here

http://noscript.net/faq covers general FAQ, installing, uninstalling, migrating, updates, troubleshooting, XSS, tips and tricks

LinkScanner Lite

When you start to install this utility, you have the option to use the full Pro version for 15 days, after this it will revert to the Lite version.

Also on the installation window there is the option to participate in the Community Intelligence Network. This is optional and is explained on the install window.

The installation adds a BHO (Browser Helper Object)which is necessary for the program to function.

After installation it is necessary to reboot your computer.


The Pro version gives you Websearch results inspection, On-demand url scanning, Always-on exploit blocking, Internet connectivity monitor and Real-time site risk analysis. The Lite version will give you Websearch results inspection and On-demand url scanning.

This program analyzes sites in real time to detect a wide range of online threats including malicious content, phishing, social engineering and targeted software exploits.

You have the Link Scanner Console which resides in the Taskbar, simply right click the icon and you can open the Console.

Enter a URL, checkmark the ‘Automatically advance to the page if it is Safe’ and scan.

Exploit Prevention Labs say that LinkScanner Lite and LinkScanner Pro scan individual pages in real time, knowing that malicious hackers can hop from site to site, temporarily infecting them.
LinkScanner integrates with Google, Yahoo and MSN to check the search results and can warn you of exploits, hacked pages, malicious sites and phishing/fraud scams.

Enter a search term into a search engine and the results displayed will have symbols beside them.

Hold your cursor over the icons and a description will appear, click the icon and you will be taken to a definition page giving further information about the site and the reason for the rating.

The simplest method to check any link is to right-click the link and select Quickscan with LinkScanner. You will get a full report as to whether the site is safe or not.

NoScript and LinkScanner also bolster your Firewall defences.

Download LinkScanner Lite here

Comprehensive User Guide here

Friday, June 08, 2007

RoboForm Automated Password Manager

RoboForm is an award-winning automated password manager and
web form filler with some serious Artificial Intelligence
that completely automates password entering and form
filling..

This is what it does:

AutoSave passwords in browser.

AutoFill passwords to login form.

Fill personal info into online forms.

Save offline passwords & notes.

Generate Secure Random Passwords.

Encrypt passwords and personal data using AES, Blowfish,
RC6, 3-DES or 1-DES algorithms.

All personal info is stored on your computer only.

Backup & Restore, Print your passwords.

It has NO ADWARE, NO SPYWARE.
Works under Windows as an add-on to IE-based browsers.
Works with Netscape, Mozilla, Firefox under Windows.

Memorizes your passwords and Logs You In automatically.

Fills long registration and checkout forms with one click.

Encrypts your passwords to achieve complete security.

Generates random passwords that hackers cannot guess.

Fights Phishing by filling passwords only on matching web
sites.

Defeats Keyloggers by not using keyboard to type passwords.

Backs up your passwords, Copies them between computers.

Synchronizes passwords between computers using GoodSync.

Searches for keywords in your passwords, notes and Internet.

Portable: RoboForm2Go runs from USB key, no install needed.

PDA-friendly: sync your passwords to Pocket PC and Palm.

Neutral: works with Internet Explorer, AOL/MSN, Firefox.

IE 7 and Vista are now supported.

Download Roboform here:
http://www.roboform.com/

Comprehensive Tutorials here:
http://www.roboform.com/tutorials.html

Watch it on Windows Media Player here

Monday, April 23, 2007

Securing Your Computer System

Today, more and more people are using their computers for
everything from communication to online banking and
investing to shopping. As we do these things on a more
regular basis, we open ourselves up to potential hackers,
attackers and crackers. While some may be looking to phish
your personal information and identity for resale, others
simply just want to use your computer as a platform from
which to attack other unknowing targets. Below are a few
easy, cost-effective steps you can take to make your
computer more secure.

1. Always make backups of important information and store
in a safe place separate from your computer.

2. Update and patch your operating system, web browser and
software frequently. If you have a Windows operating
system, start by going to www.windowsupdate.microsoft.com
and running the update wizard. This program will help you
find the latest patches for your Windows computer. Also go
to www.officeupdate.microsoft.com to locate possible
patches for your Office programs.

3. Install a firewall. Without a good firewall, viruses,
worms, Trojans, malware and adware can all easily access
your computer from the Internet. Consideration should be
given to the benefits and differences between hardware and
software based firewall programs.

4. Review your browser and email settings for optimum
security. Why should you do this? Active-X and JavaScript
are often used by hackers to plant malicious programs into
your computers. While cookies are relatively harmless in
terms of security concerns, they do still track your
movements on the Internet to build a profile of you. At a
minimum set your security setting for the “internet zone”
to High, and your “trusted sites zone” to Medium Low.

5. Install antivirus software and set for automatic
updates so that you receive the most current versions.

6. Do not open unknown email attachments. It is simply
not enough that you may recognize the address from which it
originates because many viruses can spread from a familiar
address.

7. Do not run programs from unknown origins. Also, do not
send these types of programs to friends and coworkers
because they contain funny or amusing stories or jokes.
They may contain a Trojans horse waiting to infect a
computer.

8. Disable hidden filename extensions. By default, the
Windows operating system is set to “hide file extensions
for known file types”. Disable this option so that file
extensions display in Windows. Some file extensions will,
by default, continue to remain hidden, but you are more
likely to see any unusual file extensions that do not
belong.

9. Turn off your computer and disconnect from the network
when not using the computer. A hacker can not attack your
computer when you are disconnected from the network or the
computer is off.

10. Consider making a boot disk on a floppy disk in case
your computer is damaged or compromised by a malicious
program. Obviously, you need to take this step before you
experience a hostile breach of your system.

To your safety and security online

cotojo

Add to Technorati Favorites

Thursday, April 12, 2007

Phishing For Your Identity

Who hasn't received an email directing them to visit a
familiar website where they are being asked to update their
personal information? The website needs you to verify or
update your passwords, credit card numbers, social security
number, or even your bank account number. You recognize
the business name as one that you've conducted business
with in the past. So, you click on the convenient "take me
there" link and proceed to provide all the information they
have requested. Unfortunately, you find out much later
that the website is bogus. It was created with the sole
intent to steal your personal information. You, my friend,
have just been "phished".

Phishing (pronounced as "fishing") is defined as the act
of sending an email to a recipient falsely claiming to have
an established, legitimate business. The intent of the
phisher is to scam the recipient into surrendering their
private information, and ultimately steal your identity.

It is not at easy as you think to spot an email phishing
for information. At first glance, the email may look like
it is from a legitimate company. The "From" field of the e-
mail may have the .com address of the company mentioned in
the e-mail. The clickable link even appears to take you to
the company's website, when in fact, it is a fake website
built to replicate the legitimate site.

Many of these people are professional criminals. They
have spent a lot of time in creating emails that look
authentic. Users need to review all emails requesting
personal information carefully. When reviewing your email
remember that the "From Field" can be easily changed by the
sender. While it may look like it is coming from a .com
you do business with, looks can be deceiving. Also keep in
mind that the phisher will go all out in trying to make
their email look as legitimate as possible. They will even
copy logos or images from the official site to use in their
emails. Finally, they like to include a clickable link
that the recipient can follow to conveniently update their
information.
A great way to check the legitimacy of the link is to
point at the link with your mouse. Then, look in the bottom
left hand screen of your computer. The actual website
address to which you are being directed will show up for
you to view. It is a very quick and easy way to check if
you are being directed to a legitimate site.

Finally, follow the golden rule. Never, ever, click the
links within the text of the e-mail, and always delete the
e-mail immediately. Once you have deleted the e-mail, empty
the trash box in your e-mail accounts as well. If you are
truly concerned that you are missing an important notice
regarding one of your accounts, then type the full URL
address of the website into your browser. At least then
you can be confident that you are, in fact, being directed
to the true and legitimate website.

Add to Technorati Favorites