Security etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
Security etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster

20 Ekim 2011 Perşembe

avast Internet Security 2012

Avast is well known for their free antivirus software, but they've also expanded their product line to include Internet security software.

While it's certainly not a bad transition, avast Internet Security 2012 emerged only with average results during our tests. In fact, due to it's lackluster firewall, avast came in towards the end our list this year. Without a solid firewall, we can't consider avast an effective Internet security suite.

TOP FEATURES
Nice User Interface
Lite Resource Usage
Good Real-time Protection
On the plus side, avast has adequate real-time protection as well as decent scanning functions. Email protection and anti-phishing were only average, but they've got a nice user interface with plenty of easy-to-use settings. We just hope to see better performance to go along with those nice options in the future.

For overall Internet security, avast Internet Security 2012 isn't going to cut it this year. With a poor firewall, average real-time protection, and questionable technical support, we're forced to send avast to the back of the line.

AVG Internet Security 2012

VG has come a long way through their well known free antivirus software. They've since branched out and created a worthy Internet security suite.

While their free antivirus software has served many consumers over the years, it serves only as light protection, since it lacks firewall software, download protection, and several other critical features.

A more heavy-duty Internet security suite was needed sooner or later, and this year AVG comes out with a respectable product: not perfect, but respectable.

The features that didn't stand up to our rigorous tests included: IM protection, anti-phishing, and AVG's inconsistent customer support.

TOP FEATURES
Good real-time protection
Adequate firewall
Nice user interface
On the plus side, AVG's durable antivirus engine proved top-notch. Their real-time protection proved to be as good as their best competition. The firewall for AVG Internet Security 2012 was not as strong as we'd like to see but reasonably secure.

The manual and USB scanning were thorough, although AVG doesn't automatically prompt for an automatic scan of USB drives. Even still, the majority of our malware threats were easily detected and cleaned.

Their customer support is set up via a third party company, which can make serious technical support somewhat confusing.

Despite some issues and being outmatched at some tasks when you compare antivirus software performance head-to-head, AVG Internet Security 2012 proves itself a worthy competitor and a very reasonable choice to secure your PC.

Kaspersky Internet Security 2012

Kaspersky continues to grow as a household name every year, and for good reason. Over the years, they've completely rebuilt what it means to be an antivirus engine, while increasing the overall user experience.

The top testing labs around the world have given Kaspersky high awards and certifications:

West Coast Labs
Anti-Malware
OPSWAT
Virus Bulletin
AV-Comparatives
AV-Test

Kaspersky Internet Security 2012 is just as strong as ever when it comes to antivirus and firewall protection, but they still aren't as refined as some of their competitors when it comes to overall usability.

For one thing, their user interface is still full of nagging issues that should have been easily fixed, but weren't.

Protection against zero-day threats, and emerging viruses is strong according to tough, independent testing around the world. Their firewall is top-notch, and their cloud-based antivirus protection is on the move.

However, there are several holes in certain key areas that could make or break your final decision about Kaspersky Internet Security: their antiphishing scored lower than even Internet Explorer's in some tests. Their social network protection isn't as holistic as it could be. And their tech support is rife with problems.

We still like Kaspersky for its sheer protection power, but it's sliding back on our list this year due to some missteps that are too much to ignore.

BitDefender Internet Security 2012

BitDefender comes through again this year with another excellent antivirus software. BitDefender Internet Security 2012 continues to be that same great antivirus protection but with a new an improved user interface.

How well does BitDefender Internet Security 2012 actually protect your computer? Let's put it this way: all of the top testing labs in the world have given BitDefender high scores for excellent real-time antivirus protection, resource usage, and virus removal. They put BitDefender through the ringer, and it keeps coming up strong.

Our system resource tests showed BitDefender to be light to average when scanning your system. We found no significant system drain.

We like the new, clean user interface. It's much easier to use and find any information you need.

Customer service continues to be a problem with BitDefender, but they provide adequate self-help options that will satisfy most people.

Overall, BitDefender remains one of our top choices yet again this year. Why? It's light, it's easy to use. It's stable. And most importantly, it has one of the best records for protecting your computer against viruses and other malware.

14 Ekim 2011 Cuma

Shore up your system

In addition to using good anti-virus tools, there are steps you can take to protect yourself and your computer.

To combat viruses, worms and similar threats:

Switch to a non-Microsoft email program. Many mass-mailing worms are written specifically to exploit vulnerabilities in Outlook Express and Microsoft Outlook. You can guard yourself against such threats by using an alternative email client such as Thunderbird or Eudora.
Beware attachments! Never open an email attachment from someone you don't know. Don't open attachments from people you do know, unless you're expecting the attachment. Don't open attachments directly from within your email: save them to your desktop first and open then from there. Before you open any attachment, right-click it and choose the anti-virus scanning option from the pop-up menu (most anti-virus programs add such an option when you install them).
Turn the reading/preview pane off. Most email programs display part of an email in a viewing pane beside the list of received email. Switch this viewing pane off. Sometimes your system can get infected merely by displaying code in this window.
Run a full system anti-virus scan weekly, at a minimum.
To keep adware and spyware off your system:

Pay for software instead of opting for the free, advertising supported version.
Avoid surfing on the fringe. Porn sites, crackz and warez (pirated software), file swapping and other on-the-edge sites are havens for unscrupulous people.
Use a non-Microsoft browser. Internet Explorer has proved itself to be hideously susceptible to attack and infestation. One of the best defences against a variety of threats is to use an alternative browser, such as Firefox. It's free from the Mozilla Foundation, the same organisation which also offers the freeware email client, Thunderbird. Use the two together, or install the Mozilla Suite which combines browser, email, chat and Web editor.
Never, ever click OK on a pop-up window or dialog box when you're browsing without reading it thoroughly. Use the close box to close such windows.
Use safe emailing practices.
To avoid phishing scams:

Never click on links in email you receive from an unknown source or from a known source seeking financial or sensitive information. Instead, type the address directly into your browser. Links in email can be dummied to look as if they're taking you one place when they are, in fact, taking you somewhere else.
If you have any doubt whatsoever about an email apparently from your bank or other financial institution, either go directly to the bank's Web site or get on the phone and speak to someone at the bank directly.
Be sceptical of any email which asks you to update your log-in details or other sensitive information.
Never click any link in spam.

To manage spam:

Never open spam email.
Never buy anything advertised in spam, even it seems like a really good deal. If you wonder why spammers indulge in a process which seems tailor-made to infuriate potential customers, it's because some people actually buy spam goods.
Never divulge more information on Web site forms than is absolutely necessary.
Always read a site's privacy policy before you sign up or purchase goods.
Don't get hijacked:

Use a non-Microsoft browser.
Never click OK on pop-up windows online without reading them thoroughly.
Adjust your browser's settings to prevent ActiveX and JavaScript programs from running.
To keep others from prying:

Set up multiple logons for your family PC and use a password on each log on.
Always use strong passwords. Not sure what constitutes a strong password? Visit Web Passwords Made Easy

Pack your toolkit

That daunting list of threats may leave you feeling demoralised, certainly weary. The good news is you don't have to fight the onslaught on your own. There are some handy software tools you can use to help secure your system. Keep in mind, though, that even with excellent software defences installed you'll need to keep your guard up.

While some good security tools are free, be prepared to spend money on securing your computer. This is one area where it doesn't pay to be penny pinching.
So, what should you pack in your security and privacy toolkit? Here's a good starting list:

Anti-virus software. There are some useful free anti-virus tools, but over the years they have not proved to be the best line of defence. You're better off going with one of the well-known products with a proven track record, such as PC-Cillin, Norton AntiVirus 2005, Eset NOD32, and Kaspersky Anti-Virus. Make sure your anti-virus software protects your email and guards against Web site threats, as well as monitoring your system for infection from other sources.

Use your anti-virus program's update feature at least a couple of times each week. (Click the image to see a full-sized screenshot.)

Anti-spyware and anti-key-logging software. When it comes to anti-spyware tools, adopt the boots-and-braces approach. Because of the rapid proliferation of spyware threats, no software program can keep up with the flow, so it pays to install at least two anti-spyware programs. The good news is, two of the best tools available are free, Spybot Search & Destroy and Ad Aware. Note, though, that the freeware version of Ad Aware is significantly less aggressive than the commercial version. If you're really worried about spyware (and you should be), buy a copy of Ad Aware SE Professional or the equally good Spy Sweeper 3.0.

If you use Internet Explorer, a risky activity in itself, install the free BHODemon as well, to stop unwanted programs installing within IE.

A spam blocker. Top choices are Ella, EmailProtect and Norton AntiSpam. If you use Microsoft Outlook as your email client, upgrade to version 2003 if possible; it has very good built-in junk mail handling. Thunderbird email also has decent junk filters.
A firewall. A firewall monitors incoming and outgoing traffic between your computer and the Internet, and prevents any unauthorised activity. It's your best defence against being turned into a zombie, and can also trap the activity of spyware and key loggers. Windows XP has a built-in firewall which has been vastly improved with Service Pack 2. Still, it doesn't do a complete job of monitoring traffic, so you should install a third-party scanner instead (don't use two software firewalls concurrently). Check out Outpost Firewall Pro and BlackICE PC Protection. If you have a high-speed, always-on connection, you should consider using a hardware firewall in conjunction with your software firewall. Many cable/DSL routers have a hardware firewall built in.
If you share your computer with others or keep sensitive information on an easily accessible desktop or notebook computer, add password protection to your data. Darn! Passwords is an excellent and affordable password manager which will let you protect your passwords, PINs, serial numbers, account numbers and more.

Your entire toolkit should cost no more than $200, and probably much less than that as it's likely you already have at least some of these tools installed. If you're starting from scratch, you can reduce the cost by buying one of the security suites, such as Norton Internet Security or PC-Cillin. Each of these combines anti-virus, firewall, and anti-spam components with additional features such as anti-spyware or parental controls.

Viruses and worms

Viruses used to be the biggest bogey on the Internet. These days, they seem to take a back seat to spyware and spam and phishing scams. But don't let that shift lead you to regarding viruses lightly: get infected with a nasty virus and you'll know the definition of computer hell.

A virus is a small program that infects other code and then replicates. Some viruses also delete or corrupt other files, change computer settings and, in the worst cases, render your computer unusable.

Worms are also self replicating, but they do it alone without attaching to another program as viruses do. The most common form of worm is called a mass-mailing worm. Such a worm uses email to replicate itself. When activated, it may scan your entire computer system for email addresses and then email itself to those addresses. The worm may also place one of the addresses it uncovers into the "From:" field of the infected email, making it seem like it came from a completely different source (a technique known as spoofing the address).

Adware, spyware and key loggers

Adware is software which displays advertising while you use it. Many very useful free utilities and applications use the adware model to raise money. Most adware updates the ads displayed through an Internet connection; some tracks your computer usage in order to target the advertising to your interests.

Spyware is software installed without your knowledge or consent which tracks you while you use the computer and the Internet. Spyware may come piggybacking on other "legitimate" software or it may be installed via a Web site, when you unwisely click a pop-up dialog box to clear it from your screen.

Look for the padlock at the bottom of your browser's window before entering sensitive data online, and double-click the padlock to ensure the site's security certificate is in order.

As you might guess, the line between adware and spyware is sometimes measured in nanometres. Things get particularly nasty when spyware not only tracks your usage in order to target advertising, but also to gather personal information about you. In its most pernicious form, spyware may install a key logger on your computer. The key logger lurks hidden on your system and keeps track of every single thing you do, including everything you type. With a key logger active on your system, your security and privacy is completely compromised.

Phishing

Phishers use email and Web sites to try to reel in your private information, including bank account and credit card numbers, PINs and site passwords.
Of course, if you received an email saying "hand over your bank account details", you'd hit the Delete key before you blinked. But what if that email appeared to come from a bank with which you have online access? And what if the email said "There's a problem with your account, if you don't log in and fix the problem we'll suspend account access within 3 days"? And what if, on clicking the link supplied in the email, you found yourself, apparently, at your bank's Web site?

In that case, you might well think the email was on the up and up and complete the log in, in the process handing over your account number and password. Within minutes, the phisher can be working on making you poorer and sullying your credit record.

Telltale signs of a phishing scam: poor grammar and a fake Web address. (Click the image to see a full-size screenshot.)

That's how phishers work. They fake – spoof – email addresses, email content and Web sites, right down to using the same graphics, wording and other components you find on the legitimate sites. By using some sneaky coding techniques, they can mask Web addresses, fake the padlock security icon on secure pages, and make it difficult, indeed, to spot the fraud.

Spam

We all know spam is a nuisance, but does it rate as a security threat?

Well, apart from the complete invasion of privacy caused by having pornographic spam splattered all over your inbox (and your children's inboxes), the answer is…yes. Many spam emails contain Web bugs – invisible graphics containing tracking code designed for the same purposes as spyware. In addition, the sheer volume of spam and the frustration of having to deal with it may lead to incautious behaviour. That is particularly the case when spam is used as the delivery method for a virus or spyware or phishing scam. An unthinking click in the wrong email and, bam!, you've granted entry to the scammers.

Browser hijacking

Browser hijacking is the use of programming tools, in the form of scripts, to modify your browser's default settings. This may be as trivial as adding a new link to your favourites or bookmarks, or as unconscionable as changing your home page persistently via a combination of scripting, registry changes and auto-running programs.

What's the point of hijacking? To bring you back, over and over, to a site or a site's sponsor, in the hope of boosting business. The site to which you are hijacked may also house spyware, and the more often you end up on the site trying to close in-your-face pop-ups and escape, the more chance you'll accidentally install that spyware.

A beginner's guide to Internet security

Do you ever get the feeling your computing life has degenerated into a constant battle against viruses and spam, spyware and hackers…and you're on the losing side?
You're not alone.
While the past twenty years have seen computers evolve in extraordinary fashion, the safety of the average computer user has been on a downwards spiral for at least the past decade.
Blame it on the popularity and affordability of the humble PC, which has put power into the hands of the many; blame it on the Internet, which connects everyone with everyone else; blame it on the alignment of the planets. No matter who or what you blame, there's no getting around it: computing now is a riskier proposition than it was in the good old days of the '80s and early '90s.
In those ancient times, sighting a real live virus was cause for commotion, and spyware was unheard of. All you needed to do to compute safely was to use anti-virus software and make backups. These days, if your only security tool is an anti-virus program, you're leaving yourself wide open to the vast majority of security risks and privacy threats.
So, should you throw up your hands in defeat and take the PC to the tip? Not on your life. All you need to defeat the forces of evil at their own game is a bit of savvy, a small collection of tools and some commonsense. This article will provide you with the first two and we'll even throw in some guidelines for applying your own good sense.

6 Ekim 2011 Perşembe

Anti-virus Packages

Virus protection software is packaged with most
computers and can counter most virus threats if the
software is regularly updated and correctly maintained.
The anti-virus industry relies on a vast network of users to
provide early warnings of new viruses, so that antidotes
can be developed and distributed quickly. With thousands
of new viruses being generated every month, it is essential
that the virus database is kept up to date. The virus
database is the record held by the anti-virus package that
helps it to identify known viruses when they attempt to
strike. Reputable anti-virus software vendors will publish
the latest antidotes on their Web sites, and the software
can prompt users to periodically collect new data.
Network security policy should stipulate that all
computers on the network are kept up to date and, ideally,
are all protected by the same anti-virus package—if only
to keep maintenance and update costs to a minimum. It is
also essential to update the software itself on a regular
basis. Virus authors often make getting past the anti-virus
packages their first priority.
Security Policies
When setting up a network, whether it is a local area
network (LAN), virtual LAN (VLAN), or wide area
network (WAN), it is important to initially set the
fundamental security policies. Security policies are rules
that are electronically programmed and stored within
security equipment to control such areas as access
privileges. Of course, security policies are also written or
verbal regulations by which an organization operates. In
addition, companies must decide who is responsible for
enforcing and managing these policies and determine how
employees are informed of the rules and watch guards.
Security Policy, Device, and Multidevice Management
functions as a central security control room where security
personnel monitor building or campus security, initiate
patrols, and activate alarms.
What are the policies?
The policies that are implemented should control who
has access to which areas of the network and how
unauthorized users are going to be prevented from entering
restricted areas. For example, generally only members of
the human resources department should have access to
employee salary histories. Passwords usually prevent
employees from entering restricted areas, but only if the
passwords remain private. Written policies as basic as to
warn employees against posting their passwords in work
areas can often preempt security breaches. Customers or
suppliers with access to certain parts of the network, must
be adequately regulated by the policies as well.
Who will enforce and manage the policies?
The individual or group of people who police and
maintain the network and its security must have access to
every area of the network. Therefore, the security policy
management function should be assigned to people who
are extremely trustworthy and have the technical
competence required. As noted earlier, the majority of
network security breaches come from within, so this
person or group must not be a potential threat. Once
assigned, network managers may take advantage of
sophisticated software tools that can help define,
distribute, enforce, and audit security policies through
browser-based interfaces.

Security Tools

Security Tools
After the potential sources of threats and the types of
damage that can occur have been identified, putting the
proper security policies and safeguards in place becomes
much easier. Organizations have an extensive choice of
technologies, ranging from anti-virus software packages
to dedicated network security hardware, such as firewalls
and intrusion detection systems, to provide protection for
all areas of the network.
Top Ten Security Tips
1. Encourage or require employees to choose
passwords that are not obvious.
2. Require employees to change passwords every
90 days.
3. Make sure your virus protection subscription
is current.
4. Educate employees about the security risks of
e-mail attachments.
5. Implement a complete and comprehensive
network security solution.
6. Assess your security posture regularly.
7. When an employee leaves a company, remove
that employee’s network access immediately.
8. If you allow people to work from home, provide
a secure, centrally managed server for remote
traffic.
9. Update your Web server software regularly.
10. Do not run any unnecessary network services.

Threats to Data

As with any type of crime, the threats to the privacy
and integrity of data come from a very small minority
of vandals. However, while one car thief can steal only
one car at a time, a single hacker working from a basic
computer can generate damage to a large number of
computer networks that wreaks havoc around the world.
Perhaps even more worrisome is the fact that the threats
can come from people we know. In fact, most network
security experts claim that the majority of network
attacks are initiated by employees who work inside the
corporations where breaches have occurred. Employees,
through mischief, malice, or mistake, often manage to
damage their own companies’ networks and destroy data.
Furthermore, with the recent pervasiveness of remote
connectivity technologies, businesses are expanding to
include larger numbers of telecommuters, branch offices,
and business partners. These remote employees and
partners pose the same threats as internal employees,
as well as the risk of security breaches if their remote
networking assets are not properly secured and monitored.
Whether you want to secure a car, a home, a nation, or
a computer network, a general knowledge of who the
potential enemies are and how they work is essential.
Who are the enemies?
Hackers
This generic and often over-romanticized term applies to
computer enthusiasts who take pleasure in gaining access
to other people’s computers or networks. Many hackers
are content with simply breaking in and leaving their
“footprints,” which are joke applications or messages on
computer desktops. Other hackers, often referred to as
“crackers,” are more malicious, crashing entire computer
systems, stealing or damaging confidential data, defacing
Web pages, and ultimately disrupting business. Some
amateur hackers merely locate hacking tools online and
deploy them without much understanding of how they
work or their effects.
Unaware Staff
As employees focus on their specific job duties, they often
overlook standard network security rules. For example,
they might choose passwords that are very simple to
remember so that they can log on to their networks easily.
However, such passwords might be easy to guess or crack
by hackers using simple common sense or a widely
available password cracking software utility. Employees
can unconsciously cause other security breaches including
the accidental contraction and spreading of computer
viruses. One of the most common ways to pick up a virus
is from a floppy disk or by downloading files from the
Internet. Employees who transport data via floppy disks
can unwittingly infect their corporate networks with
viruses they picked up from computers in copy centers or
libraries. They might not even know if viruses are resident
on their PCs. Corporations also face the risk of infection
when employees download files, such as PowerPoint
presentations, from the Internet. Surprisingly, companies
must also be wary of human error. Employees, whether
they are computer novices or computer savvy, can make
such mistakes as erroneously installing virus protection
software or accidentally overlooking warnings regarding
security threats.

An Introduction to the Key Security Issues

With the explosion of the public Internet and e-commerce, private computers, and computer networks, if not
adequately secured, are increasingly vulnerable to damaging attacks. Hackers, viruses, vindictive employees
and even human error all represent clear and present dangers to networks. And all computer users, from the
most casual Internet surfers to large enterprises, could be affected by network security breaches. However,
security breaches can often be easily prevented. How? This guide provides you with a general overview of the
most common network security threats and the steps you and your organization can take to protect
yourselves from threats and ensure that the data traveling across your networks is safe.

30 Eylül 2011 Cuma

How to shop online more safely

These tips can help you determine that you're shopping at a secure and trustworthy website.
Look for signs that the business is legitimate

Buy from reputable stores and sellers. Here are some ways to check:

Find out what other shoppers say. Sites like Epinions.com or BizRate have customer evaluations which can help you determine a company's legitimacy.

Look for third-party seals of approval. Companies can put these seals on their sites if they abide by a set of rigorous standards such as how personal information can be used. Two seals to look for:

If you see the seals, click them to make sure they link to the organization that created them. Some unscrupulous merchants will put these logos on their websites without permission.
Look for signs that the website protects your data

On the web page where you enter your credit card or other personal information, look for an "s" after http in the web address of that page (as shown below). (Encryption is a security measure that scrambles data as it traverses the Internet.)

Also make sure there is a tiny closed padlock in the address bar, or on the lower right corner of the window.

Image of green address bar in Internet Explorer

Use a filter that warns you of suspicious websites

Find a filter that warns you of suspicious websites and blocks visits to reported phishing sites. For example, try the SmartScreen Filter included in Internet Explorer.

11 tips for social networking safety

Social networking websites like MySpace, Facebook, Twitter, and Windows Live Spaces are services people can use to connect with others to share information like photos, videos, and personal messages.

As the popularity of these social sites grows, so do the risks of using them. Hackers, spammers, virus writers, identity thieves, and other criminals follow the traffic.

Read these tips to help protect yourself when you use social networks.

Use caution when you click links that you receive in messages from your friends on your social website. Treat links in messages on these sites as you would links in email messages. (For more information, see Approach links in email with caution and Click Fraud: Cybercriminals want you to 'like' it.)

Know what you've posted about yourself. A common way that hackers break into financial or other accounts is by clicking the "Forgot your password?" link on the account login page. To break into your account, they search for the answers to your security questions, such as your birthday, home town, high school class, or mother's middle name. If the site allows, make up your own password questions, and don't draw them from material anyone could find with a quick search. For more information, see:

What was the name of your first pet?

What is screen scraping?

Take charge of your online reputation

Don't trust that a message is really from who it says it's from. Hackers can break into accounts and send messages that look like they're from your friends, but aren't. If you suspect that a message is fraudulent, use an alternate method to contact your friend to find out. This includes invitations to join new social networks. For more information, see Scammers exploit Facebook friendships.

To avoid giving away email addresses of your friends, do not allow social networking services to scan your email address book. When you join a new social network, you might receive an offer to enter your email address and password to find out if your contacts are on the network. The site might use this information to send email messages to everyone in your contact list or even everyone you've ever sent an email message to with that email address. Social networking sites should explain that they're going to do this, but some do not.

Type the address of your social networking site directly into your browser or use your personal bookmarks. If you click a link to your site through email or another website, you might be entering your account name and password into a fake site where your personal information could be stolen. For more tips about how to avoid phishing scams, see Email and web scams: How to help protect yourself.

Be selective about who you accept as a friend on a social network. Identity thieves might create fake profiles in order to get information from you.

Choose your social network carefully. Evaluate the site that you plan to use and make sure you understand the privacy policy. Find out if the site monitors content that people post. You will be providing personal information to this website, so use the same criteria that you would to select a site where you enter your credit card.

Assume that everything you put on a social networking site is permanent. Even if you can delete your account, anyone on the Internet can easily print photos or text or save images and videos to a computer.

Be careful about installing extras on your site. Many social networking sites allow you to download third-party applications that let you do more with your personal page. Criminals sometimes use these applications to steal your personal information. To download and use third-party applications safely, take the same safety precautions that you take with any other program or file you download from the web.

Think twice before you use social networking sites at work. For more information, see Be careful with social networking sites, especially at work.

Talk to your kids about social networking. If you're a parent of children who use social networking sites, see How to help your kids use social websites more safely.

23 Eylül 2011 Cuma

DDoS attacks

All statistical data presented in this report were obtained using Kaspersky Lab’s botnet monitoring system and Kaspersky DDoS Prevention.
The quarter in figures

The most powerful attack repelled by Kaspersky DDoS Prevention in Q2: 500 Mbps
The average power of the attacks repelled by Kaspersky DDoS Prevention: 70 Mbps
The longest DDoS attack in Q2: 60 days, 1 hour, 21 minutes and 9 seconds
The highest number of DDoS attacks against a single site in Q2: 218.

DDoS and protests

Distributed denial-of-service attacks are no longer being carried out simply to make a profit. Cybercriminals are increasingly targeting government resources or the sites of big companies to show off their skills, demonstrate their power or, in some cases, as a form of protest. These are exactly the sort of attacks that get maximum publicity in the media.

The most active hacker groups in the second quarter of 2011 were LulzSec and Anonymous. They organized DDoS attacks on government sites in the US, the UK, Spain, Turkey, Iran and several other countries. The hackers managed to temporarily bring down sites such as cia.gov (the US Central Intelligence Agency) and www.soca.gov.uk (the British Serious Organized Crime Agency (SOCA)). This shows that even government sites safeguarded by specialist agencies are not immune to DDoS attacks.

Attacking government sites is a risky business for hackers because it immediately attracts the attention of law enforcement authorities. In Q2 of 2011, for example, more than 30 members of Anonymous were arrested on suspicion of launching DDoS attacks on government sites. More arrests are likely to follow as authorities continue their investigations. However, not all those involved are likely to be convicted because participation in the organization of a DDoS attack is still not considered illegal in many countries.

One big corporation subjected to a major attack was Sony. At the end of March, Sony brought legal action against several hackers accusing them of breaching the firmware of the popular PlayStation 3 console. In protest at Sony’s pursuit of the hackers, Anonymous launched a DDoS attack that crippled the company’s PlayStationnetwork.com sites for some time. But this was just the tip of the iceberg. According to Sony, during the DDoS attack the servers of the PSN service were hacked and the data of 77 million users were stolen. Whether or not it was done intentionally, the DDoS attack by Anonymous served as a diversionary tactic for the theft of huge volumes of data and which, at the end of the day, affected Sony’s reputation.
DDoS attacks on social media

The second quarter of 2011 is likely to be remembered by Russian Internet users for the series of attacks on LiveJournal. The resource is popular with a variety of people, with housewives, photographers, pilots and even politicians posting blogs on the site. According to our botnet monitoring system, the mass attacks on LiveJournal began by targeting journals of a political nature, in particular, that of the anti-corruption and political activist Alexey Navalny.

Our botnet monitoring system has been tracking a botnet named Optima which was used in the DDoS attacks on LiveJournal. In the period between 23 March and 1 April Optima received commands to attack the anti-corruption site http://rospil.info, http://www.rutoplivo.ru and http://navalny.livejournal.com as well as the furniture factory site http://www.kredo-m.ru. On certain days only http://navalny.livejournal.com was attacked. At the beginning of April the botnet received a command to attack a long list of LiveJournal addresses mostly belonging to popular bloggers who cover a wide range of subjects.

The Optima botnet has been known on the market since late 2010. From the type of code used, it is safe to say that Optima bots are developed by Russian-speaking malware writers and they are mostly sold on Russian-language forums. It is difficult to determine the size of the botnet because it is highly segmented. However, our monitoring system has recorded instances of the Optima bots that attacked LiveJournal receiving commands to download other malicious programs. This suggests the Optima botnet includes tens of thousands of infected machines because such downloads are considered unprofitable for small botnets.

The motive for the attacks on LiveJournal remains unclear as nobody has yet claimed responsibility. Until the cybercriminals behind the attacks are identified, it will be difficult to say whether the attacks were ordered or just a show of force.

DDoS attacks on social media are becoming more frequent because these services allow the immediate exchange of information between tens of thousands of users. Blocking this process, even if it is just for a short time, can only be achieved with the help of DDoS attacks.

We expect to see a further growth in these types of attack in the future.
Commercial DDoS attacks

Ordinary criminals also continue to make active use of DDoS attacks. However, information about attacks that aim to extort or blackmail organizations is rarely made public and when it is, it is usually related to the subsequent criminal investigation.

In April, a court in Dusseldorf handed down a sentence to a cybercriminal who tried to blackmail six German bookmakers during the 2010 World Cup. The culprit used the familiar routine of: intimidation, a trial attack on the victim’s site, and a message containing a ransom demand. Three of the six offices agreed to pay off the attacker. According to the bookmakers, a few hours of website downtime can result in the loss of significant sums – 25-40,000 euros for large offices and 5-6,000 euros for smaller offices. Surprisingly, the scammer only demanded 2000 euros. He received money in U-cash vouchers – a method which had already been used by the author of the well-known GpCode Trojan program. The court sentenced the defendant to nearly three years in prison – the first time in German legal history that someone has been imprisoned for organizing a DDoS attack. Such attacks are now classified by the country’s courts as computer sabotage and are punishable by up to 10 years in jail.

In June, the Russian judicial system also addressed the subject of DDoS attacks. On 24 June, a Moscow court sanctioned the arrest of Pavel Vrublevsky, the owner of ChronoPay, Russia’s biggest Internet payment service provider. Vrublevsky was accused of organizing a DDoS attack against competitor firm Assist in order to undermine its chances in a tender for a lucrative contract to process payments for Aeroflot, Russia’s largest airline. Sources close to the investigation said Vrublevsky was also considered the owner of the Rx-Promotion affiliate network which specializes in spreading pharmaceutical spam.

What to do

The first thing to do is make sure that the antivirus database is up-to-date and scan your computer. If this does not help, antivirus solutions from other vendors may do the job. Many manufacturers of anti-virus solutions offer free versions of their products for trial or one-time scanning – we recommend you to run one of these products on your machine. If it detects a virus or a Trojan, make sure you send a copy of the infected file to the manufacturer of the antivirus solution that failed to detect it. This will help this vendor faster develop protection against this threat and protect other users running this antivirus from getting infected.

If an alternative antivirus does not detect any malware, it is recommended that you disconnect your computer from the Internet or a local network, disable Wi-Fi connection and the modem, if any, before you start looking for the infected file(s). Do not use the network unless critically needed. Do not use web payment systems or internet banking services under any circumstances. Avoid referring to any personal or confidential data; do not use any web-based services that require your screen name and password.
How do I find an infected file?

Detecting a virus or Trojan in your computer in some cases may be a complex problem requiring a technical qualification; however, in other cases that may be a pretty straightforward task – this all depends on the degree of the malware complexity and the methods used to hide the malicious code embedded into the system. In the difficult cases when special methods (e.g. rootkit technologies) are employed to disguise and conceal the malicious code in the system, a non-professional may be unable to track down the infected file. This problem may require special utilities or actions, like connecting the hard disk to another computer or booting the system from a CD. However, if a regular worm or simple Trojan is around, you may be able to track it down using fairly simple methods.

The vast majority of worms and Trojan need to take control when the system starts. There are two basic ways for that:

A link to the infected file is written to the autorun keys of the Windows registry;
The infected file is copied to an autorun folder in Windows.

The most common autorun folders in Windows 2000 and XP are as follows:
%Documents and Settings%\%user name%\Start Menu\Programs\Startup\
%Documents and Settings%\All Users\Start Menu\Programs\Startup\

There are quite a number of autorun keys in the system register, the most popular keys include Run, RunService, RunOnce и RunServiceOnce, located in the following register folders:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\]

Most probably, a search at the above locations will yield several keys with names that don’t reveal much information, and paths to the executable files. Special attention should be paid to the files located in the Windows system catalog or root directory. Remember names of these files, you will need them in the further analysis.

Writing to the following key is also common:
[HKEY_CLASSES_ROOT\exefile\shell\open\command\]

The default value of this key is “%1" %*”.

Windows’ system (and system 32) catalog and root directory are the most convenient place to set worms and Trojans. This is due to 2 facts: the contents of these catalogs are not shown in the Explorer by default, and these catalogs host a great number of different system files, functions of which are completely unknown to a lay user. Even an experienced user will probably find it difficult to tell if a file called winkrnl386.exe is part of the operating system or foreign to it.

It is recommended to use any file manager that can sort file by creation/modification date, and sort the files located within the above catalogs. This will display all recently created and modified files at the top of the catalog – these very files will be of interest to the researcher. If any of these files are identical to those occurring in the autorun keys, this is the first wake-up call.

Advanced users can also check the open network ports using netstat, the standard utility. It is recommended to set up a firewall and scan the processes engaged in network activities. It is also recommended to check the list of active processes using dedicated utilities with advanced functionalities rather than the standard Windows utilities – many Trojans successfully avoid being detected by standard Windows utilities.

However, no universal advice can be given for all occasions. Advanced worms and Trojans occur every now then that are quite difficult to track down. In this case, it is best to consult the support service of the IT security vendor that released your antivirus client, a company offering IT assistance services, or ask for help at specialized web forums. Such web resources include www.virusinfo.info and anti-malware.ru (Russian language), and www.rootkit.com and www.gmer.net (English). Similar forums designed to assist users are also run by many antivirus companies.

What if my computer is infected?

Unfortunately, it may happen occasionally that the antivirus installed in your computer with its latest updates is incapable of detecting a new virus, worm or a Trojan. Sadly but true: no antivirus protection software gives you a 100% guarantee of complete security. If your computer does get infected, you need to determine the fact of infection, identify the infected file and send it to the vendor whose product missed the malicious program and failed to protect your computer.

However, users on their own are typically unable to detect that their computer got infected unless aided by antivirus solutions. Many worms and Trojans typically do not reveal their presence in any way. By way of exception, some Trojans do inform the user directly that their computer has been infected – they may encrypt the user’s personal files so as to demand a ransom for the decryption utility. However, a Trojan typically installs itself secretly in the system, often employs special disguising methods and also covertly does its activity. So, the fact of infection can be detected by indirect evidence only.
Symptoms of infection

An increase in the outgoing web traffic is the general indication of an infection; this applies to both individual computers and corporate networks. If no users are working in the Internet in a specific time period (e.g. at night), but the web traffic continues, this could mean that somebody or someone else is active on the system, and most probably that is a malicious activity. In a firewall is configured in the system, attempts by unknown applications to establish Internet connections may be indicative of an infection. Numerous advertisement windows popping up while visiting web-sites may signal that an adware in present in the system. If a computer freezes or crashes frequently, this may be also related to a malware activity. Such malfunctions are more often accounted for by hardware or software malfunctions rather than a virus activity. However, if similar symptoms simultaneously occur on multiple or numerous computers on the network, accompanied by a dramatic increase in the internal traffic, this is very likely caused by a network worm or a backdoor Trojan spreading across the network.

An infection may be also indirectly evidenced by non-computer related symptoms, such as bills for telephone calls that nobody made or SMS messages that nobody sent. Such facts may indicate that a phone Trojan is active in the computer or the cell phone. If unauthorized access has been gained to your personal bank account or your credit card has bee used without your authorization, this may signal that a spyware has intruded into your system.

20 Eylül 2011 Salı

Famous Hackers

Steve Jobs and Steve Wozniak, founders of Apple Computers, are both hackers. Some of their early exploits even resemble the questionable activities of some malicious hackers. However, both Jobs and Wozniak outgrew their malicious behavior and began concentrating on creating computer hardware and software. Their efforts helped usher in the age of the personal computer -- before Apple, computer systems remained the property of large corporations, too expensive and cumbersome for average consumers.

Linus Torvalds, creator of Linux, is another famous honest hacker. His open source operating system is very popular with other hackers. He has helped promote the concept of open source software, showing that when you open information up to everyone, you can reap amazing benefits.

Richard Stallman, also known as "rms," founded the GNU Project, a free operating system. He promotes the concept of free software and computer access. He works with organizations like the Free Software Foundation and opposes policies like Digital Rights Management.

On the other end of the spectrum are the black hats of the hacking world. At the age of 16, Jonathan James became the first juvenile hacker to get sent to prison. He committed computer intrusions on some very high-profile victims, including NASA and a Defense Threat Reduction Agency server. Online, Jonathan used the nickname (called a handle) "c0mrade." Originally sentenced to house arrest, James was sent to prison when he violated parole.
Kevin Mitnick
Greg Finley/Getty Images
Hacker Kevin Mitnick, newly released from the Federal Correctional Institution in Lompoc, California.

Kevin Mitnick gained notoriety in the 1980s as a hacker who allegedly broke into the North American Aerospace Defense Command (NORAD) when he was 17 years old. Mitnick's reputation seemed to grow with every retelling of his exploits, eventually leading to the rumor that Mitnick had made the FBI's Most Wanted list. In reality, Mitnick was arrested several times for hacking into secure systems, usually to gain access to powerful computer software.

Kevin Poulsen, or Dark Dante, specialized in hacking phone systems. He's famous for hacking the phones of a radio station called KIIS-FM. Poulsen's hack allowed only calls originating from his house to make it through to the station, allowing him to win in various radio contests. Since then, he has turned over a new leaf, and now he's famous for being a senior editor at Wired magazine.

Adrian Lamo hacked into computer systems using computers at libraries and Internet cafes. He would explore high-profile systems for security flaws, exploit the flaws to hack into the system, and then send a message to the corresponding company, letting them know about the security flaw. Unfortunately for Lamo, he was doing this on his own time rather than as a paid consultant -- his activities were illegal. He also snooped around a lot, reading sensitive information and giving himself access to confidential material. He was caught after breaking into the computer system belonging to the New York Times.

It's likely that there are thousands of hackers active online today, but an accurate count is impossible. Many hackers don't really know what they are doing -- they're just using dangerous tools they don't completely understand. Others know what they're doing so well that they can slip in and out of systems without anyone ever knowing.

Hackers and the Law

In general, most governments aren't too crazy about hackers. Hackers' ability to slip in and out of computers undetected, stealing classified information when it amuses them, is enough to give a government official a nightmare. Secret information, or intelligence, is incredibly important. Many government agents won't take the time to differentiate between a curious hacker who wants to test his skills on an advanced security system and a spy.

Laws reflect this attitude. In the United States, there are several laws forbidding the practice of hacking. Some, like 18 U.S.C. § 1029, concentrate on the creation, distribution and use of codes and devices that give hackers unauthorized access to computer systems. The language of the law only specifies using or creating such a device with the intent to defraud, so an accused hacker could argue he just used the devices to learn how security systems worked.

Another important law is 18 U.S.C. § 1030, part of which forbids unauthorized access to government computers. Even if a hacker just wants to get into the system, he or she could be breaking the law and be punished for accessing a nonpublic government computer [Source: U.S. Department of Justice].

Punishments range from hefty fines to jail time. Minor offenses may earn a hacker as little as six months' probation, while other offenses can result in a maximum sentence of 20 years in jail. One formula on the Department of Justice's Web page factors in the financial damage a hacker causes, added to the number of his victims to determine an appropriate punishment [Source: U.S. Department of Justice].

Hacking a Living
Hackers who obey the law can make a good living. Several companies hire hackers to test their security systems for flaws. Hackers can also make their fortunes by creating useful programs and applications, like Stanford University students Larry Page and Sergey Brin. Page and Brin worked together to create a search engine they eventually named Google. Today, they are tied for 26th place on Forbes' list of the world's most wealthy billionaires [source: Forbes].­

­Other countries have similar laws, some much more vague than legislation in the U.S. A recent German law forbids possession of "hacker tools." Critics say that the law is too broad and that many legitimate applications fall under its vague definition of hacker tools. Some point out that under this legislation, companies would be breaking the law if they hired hackers to look for flaws in their security systems [source: IDG News Service].

Hackers can commit crimes in one country while sitting comfortably in front of their computers on the other side of the world. Therefore, prosecuting a hacker is a complicated process. Law enforcement officials have to petition countries to extradite suspects in order to hold a trial, and this process can take years. One famous case is the United States' indictment of hacker Gary McKinnon. Since 2002, McKinnon fought extradition charges to the U.S. for hacking into the Department of Defense and NASA computer systems. McKinnon, who hacked from the United Kingdom, defended himself by claiming that he merely pointed out flaws in important security systems. In April 2007, his battle against extradition came to an end when the British courts denied his appeal [Source: BBC News].

In the next section, we'll look at some famous and notorious hackers.

Hacker Culture

Individually, many hackers are antisocial. Their intense interest in computers and programming can become a communication barrier. Left to his or her own devices, a hacker can spend hours working on a computer program while neglecting everything else.

Com­puter networks gave hackers a way to associate with other people with their same interests. Before the Internet became easily accessible, hackers would set up and visit bulletin board systems (BBS). A hacker could host a bulletin board system on his or her computer and let people dial into the system to send messages, share information, play games and download programs. As hackers found one another, information exchanges increased dramatically.

Some hackers posted their accomplishments on a BBS, boasting about infiltrating secure systems. Often they would upload a document from their victims' databases to prove their claims. By the early 1990s, law enforcement officials considered hackers an enormous security threat. There seemed to be hundreds of people who could hack into the world's most secure systems at will [source: Sterling].

There are many Web sites dedicated to hacking. The hacker journal "2600: The Hacker Quarterly" has its own site, complete with a live broadcast section dedicated to hacker topics. The print version is still available on newsstands. Web sites like Hacker.org promote learning and include puzzles and competitions for hackers to test their skills.

When caught -- either by law enforcement or corporations -- some hackers admit that they could have caused massive problems. Most hackers don't want to cause trouble; instead, they hack into systems just because they wanted to know how the systems work. To a hacker, a secure system is like Mt. Everest -- he or she infiltrates it for the sheer challenge. In the United States, a hacker can get into trouble for just entering a system. The Computer Fraud and Abuse Act outlaws unauthorized access to computer systems [source: Hacking Laws].

Hackers and Crackers

Many computer programmers insist that the word "hacker" applies only to law-abiding enthusiasts who help create programs and applications or improve computer security. Anyone using his or her skills maliciously isn't a hacker at all, but a cracker.

Crackers infiltrate systems and cause mischief, or worse. Unfortunately, most people outside the hacker community use the word as a negative term because they don't understand the distinction between hackers and crackers.­

­Not all hackers try to explore forbidden computer systems. Some use their talents and knowledge to create better software and security measures. In fact, many hackers who once used their skills to break into systems now put that knowledge and ingenuity to use by creating more comprehensive security measures. In a way, the Internet is a battleground between different kinds of hackers -- the bad guys, or black hats, who try to infiltrate systems or spread viruses, and the good guys, or white hats, who bolster security systems and develop powerful virus protection software.

Hackers on both sides overwhelmingly support open source software, programs in which the source code is available for anyone to study, copy, distribute and modify. With open source software, hackers can learn from other hackers' experiences and help make programs work better than they did before. Programs might range from simple applications to complex operating systems like Linux.

There are several annual hacker events, most of which promote responsible behavior. A yearly convention in Las Vegas called DEFCON sees thousands of attendees gather to exchange programs, compete in contests, participate in panel discussions about hacking and computer development and generally promote the pursuit of satisfying curiosity. A similar event called the Chaos Communication Camp combines low-tech living arrangements -- most attendees stay in tents -- and high-tech conversation and activities.

In the next section, we'll learn about hackers and legal issues