Here's my latest article published at SearchSecurity.com about Spear Phishing. Write any questions you might have in the comments. Hope you like it.
http://searchsecurity.techtarget.com/tip/Spear-phishing-examples-How-to-stop-phishing-from-compromising-users
Pages
Wednesday, September 14, 2011
Monday, September 12, 2011
Sunday, July 17, 2011
Stop Malware Before It Strikes!!
With the ever increasing threat of mass malware being installed on your PC how can we protect ourselves from being susceptible from attack? When people think of protection against malware they normally think of anti-virus/anti-spyware software. The problem with anti-virus software is twofold: First it’s a very reactive approach that waits for an attack to happen before reacting, and secondly its detection rate on malware is exponentially getting lower.
In order for malware to be installed on a system there normally needs to be a vulnerability open to allow the malicious software access. So if we know where we’re vulnerable we could potentially stop the bulk of malware from being installed in the first place. The majority of threats being exploited from the internet are surprisingly not on the operating system level, but at the application/plug-in level.
So now that we know what the problem is how do we proactively stop malware from being exploited on our system? Two companies are offering free tools that can scan your workstations for installed application/plug-ins that are vulnerable to known threats, and link you to the patches needed for remediation.
These two companies are Secunia and Qualys, and the links to their free software is below. These free tools allow you to take a proactive approach to fighting malware by fixing the unpatched exploits mass malware is using to infect the majority of systems today.
http://secunia.com/vulnerability_scanning/personal/
https://browsercheck.qualys.com/
This is by no means an end all be all way to stop malware from being installed, but it sure helps. Proactively using these tools coupled with anti-virus will give you the best protection from being infected by malware.
In order for malware to be installed on a system there normally needs to be a vulnerability open to allow the malicious software access. So if we know where we’re vulnerable we could potentially stop the bulk of malware from being installed in the first place. The majority of threats being exploited from the internet are surprisingly not on the operating system level, but at the application/plug-in level.
So now that we know what the problem is how do we proactively stop malware from being exploited on our system? Two companies are offering free tools that can scan your workstations for installed application/plug-ins that are vulnerable to known threats, and link you to the patches needed for remediation.
These two companies are Secunia and Qualys, and the links to their free software is below. These free tools allow you to take a proactive approach to fighting malware by fixing the unpatched exploits mass malware is using to infect the majority of systems today.
http://secunia.com/vulnerability_scanning/personal/
https://browsercheck.qualys.com/
This is by no means an end all be all way to stop malware from being installed, but it sure helps. Proactively using these tools coupled with anti-virus will give you the best protection from being infected by malware.
Saturday, May 14, 2011
Privacy? What's that? Can I have some?
With the latest privacy debacle involving Google and Apple phones sending out the location of WI-FI hotspots near users, it makes us notice that the line between privacy is now completely blurred. Have we the consumer allowed our privacy to be taken or has it been stolen from us by greedy companies? The answer to that is a two-edged sword.
We the consumer are constantly looking for the newest, shiniest, most trendiest toy, whether it be software or hardware, and this has allowed vendors to take privileges in a way that they might not have taken if we weren't so hungry for it.
I agree that companies should be made much more transparent on the way they operate, but in the long run does the average user actually care? Both these companies said that they had no plans on the using the data besides for location services at this time. At this time? What does that mean? When will they be using it and what for?
These companies realize that we the consumer have short term memories, especially when we see what cool things their new toys can do. We have to look long term here and make them accountable for what they're doing, otherwise we'll continue to give our privacy away zombies looking for the next big thing.
Just because they're not using the data right now in an inappropriate way, this also depends on your definition of inappropriate, we should as the consumer know when our information is being siphoned from our pockets. Having the ability to opt-in to programs like this would be a way to at least notify the consumer of their intentions.
I hope we see some major changes in this process in the near future.
We the consumer are constantly looking for the newest, shiniest, most trendiest toy, whether it be software or hardware, and this has allowed vendors to take privileges in a way that they might not have taken if we weren't so hungry for it.
I agree that companies should be made much more transparent on the way they operate, but in the long run does the average user actually care? Both these companies said that they had no plans on the using the data besides for location services at this time. At this time? What does that mean? When will they be using it and what for?
These companies realize that we the consumer have short term memories, especially when we see what cool things their new toys can do. We have to look long term here and make them accountable for what they're doing, otherwise we'll continue to give our privacy away zombies looking for the next big thing.
Just because they're not using the data right now in an inappropriate way, this also depends on your definition of inappropriate, we should as the consumer know when our information is being siphoned from our pockets. Having the ability to opt-in to programs like this would be a way to at least notify the consumer of their intentions.
I hope we see some major changes in this process in the near future.
Tuesday, May 10, 2011
Defense In Depth: The Onion Approach
Here's a link to my latest article. Hope you like it.
http://enterpriseitsecuritymag.com/defense-in-depth-the-onion-approach/
Phones Required To Receive Emergency Alerts From President
The President and other local emergency crews will now have the ability to broadcast alerts to your cell phone if you're within a certain area in NYC. These alerts are designed for emergency response to disasters or potential terrorist activity in the area. This was in direct response to the Osama Bin Laden killing, and possible revenge attacks to New York.
Part of me doesn't like having the government being able spam citizens with text messages, but another part of me saw the damage of 9/11 personally. I can see where this would be useful, but I'm still concerned that the government, if given an inch, will take a mile.
I'm also concerned about what this mobile phone "chip" is and what it will be able to track. If anyone has any information on this please let me know.
http://newyork.cbslocal.com/2011/05/10/national-emergency-alert-system-set-to-launch-in-nyc/
Part of me doesn't like having the government being able spam citizens with text messages, but another part of me saw the damage of 9/11 personally. I can see where this would be useful, but I'm still concerned that the government, if given an inch, will take a mile.
I'm also concerned about what this mobile phone "chip" is and what it will be able to track. If anyone has any information on this please let me know.
http://newyork.cbslocal.com/2011/05/10/national-emergency-alert-system-set-to-launch-in-nyc/
Thursday, May 5, 2011
Enterpriseitsecuritymag.com just launched
I would like to announce that the May issue of Enterprise IT Security is finally out and ready to download!
You will be able to read a lot of interesting articles written by professionals.
We also encourage you to take part in the contest prepared in cooperation with Nordic Information Security Group AB.
Visit the website at http://enterpriseitsecuritymag.com
For more information concerning the contest please contact:
kinga.polynczuk@software.com.pl
lukasz.koska@software.com.pl
Enjoy reading!
You will be able to read a lot of interesting articles written by professionals.
We also encourage you to take part in the contest prepared in cooperation with Nordic Information Security Group AB.
Visit the website at http://enterpriseitsecuritymag.com
For more information concerning the contest please contact:
kinga.polynczuk@software.com.pl
lukasz.koska@software.com.pl
Enjoy reading!
Subscribe to:
Posts (Atom)



