Showing posts with label Phishing. Show all posts
Showing posts with label Phishing. Show all posts

Sunday, September 26, 2010

How to Stop Bom Sabado Worm? Here is the way!

Everyone whose orkut account has been affected with the Sabado Worm, can use this simple trick to get out of this issue. People whose account is not yet affected, please follow the below steps to keep this worm away from your accounts.

The worm injects a hidden iframe containing a malicious javascript [do not click this] http: //tptools. org/ worm . js [do not click this], which steals the user cookie which contains the password in an encoded form. Even though the attacker does not get to know your password, they can login to your account using your credentials by impersonating the cookie to fool the identification system. 



So a trivial solution is to diable javascript, another solution is to disable iframes or u can take an advanced measure by blocking the domain http : // tptools . org / by editing your hosts file and redirecting it to a safe address, say 127.0.0.1 go to C:>windows>system32>driversetc There is a file named %u2018hosts%u2019. It is a read-only file. Go to it's properties and un-check the read-only option and edit it with you favourite editor. add this line at the end of it 127.0.0.1 tptools.org save it. and then restart your network interface. ( in simple words, just reconnect your internet connection ). Bingo!! the worm%u2019ll became useless!!!! 

Friday, September 24, 2010

Orkut is attached by Bom Sabado Worm!!!

In a major XSS (cross-site scripting) attack this week, Google owned Orkut was flooded with "Bom Sabado" scraps.

The word "Bom Sabado" means "Good Saturday" in Portuguese, which is the also the official language of Brazil, one of the last remaining Orkut bastions in the world.

The worm seems to be posting scraps with the text "Bom Sabado" and also adding affected users to new Orkut groups. Such XSS attacks have targeted Orkut in the past too.

Experts have advised users to avoid logging on to Orkut till Orkut engineers fix the hole and also not to click on any suspicious links. Orkut had just last month announced new updates to the website.

Earlier this week, the popular microblogging website Twitter was also at the receiving end of an XSS exploit. The attack, which emerged and was shut down within hours Tuesday morning, involved a XSS flaw that allowed users to run JavaScript programs on other computers.

Earlier on Sep 2010, the most popular social networking hub with more than 500 million users, Facebook, also faced networking glitches due to an outside technical problem. It was Facebook's most tragic outrage in its history.

Sunday, September 5, 2010

A Strong Password Isn't The Strongest Security

Make your password strong, with a unique jumble of letters, numbers and punctuation marks. But memorize it, never write it down. And, oh yes, change it every few months. These instructions are supposed to protect us. But they don’t!

Some computer security experts are advancing the heretical thought that passwords might not need to be “strong,” or changed constantly. They say onerous requirements for passwords have given us a false sense of protection against potential attacks. In fact, they say, we aren’t paying enough attention to more potent threats.


Here’s one threat to keep you awake at night: Keylogging software, which is deposited on a PC by a virus, records all keystrokes — including the strongest passwords you can concoct — and then sends it surreptitiously to a remote location.

“Keeping a keylogger off your machine is about a trillion times more important than the strength of any one of your passwords,” says Cormac Herley, a principal researcher at Microsoft Research who specializes in security-related topics. He said antivirus software could detect and block many kinds of keyloggers, but “there’s no guarantee that it gets everything.”

After investigating password requirements in a variety of settings, Mr. Herley is critical not of users but of system administrators who aren’t paying enough attention to the inconvenience of making people comply with arcane rules. “It is not users who need to be better educated on the risks of various attacks, but the security community,” he said at a meeting of security professionals, the New Security Paradigms Workshop, at Queen’s College in Oxford, England. “Security advice simply offers a bad cost-benefit tradeoff to users.”

One might guess that heavily trafficked Web sites — especially those that provide access to users’ financial information — would have requirements for strong passwords. But it turns out that password policies of many such sites are among the most relaxed. These sites don’t publicly discuss security breaches, but Mr. Herley said it “isn’t plausible” that these sites would use such policies if their users weren’t adequately protected from attacks by those who do not know the password.

Mr. Herley, working with Dinei FlorĂȘncio, also at Microsoft Research, looked at the password policies of 75 Web sites. At the Symposium on Usable Privacy and Security, held in July in Redmond, Wash., they reported that the sites that allowed relatively weak passwords were busy commercial destinations, including PayPal, Amazon.com and Fidelity Investments. The sites that insisted on very complex passwords were mostly government and university sites. What accounts for the difference? They suggest that “when the voices that advocate for usability are absent or weak, security measures become needlessly restrictive.”

Donald A. Norman, a co-founder of the Nielsen Norman Group, a design consulting firm in Fremont, Calif., makes a similar case. In “When Security Gets in the Way,” an essay published last year, he noted the password rules of Northwestern University, where he then taught. It was a daunting list of 15 requirements. He said unreasonable rules can end up rendering a system less secure: users end up writing down passwords and storing them in places that can be readily discovered.

“These requirements keep out the good guys without deterring the bad guys,” he said.

Northwestern has reduced its password requirements to eight, but they still constitute a challenging maze. For example, the password can’t have more than four sequential characters from the previous seven passwords, and a new password is required every 120 days.

By contrast, Amazon has only one requirement: that the password be at least six characters. That’s it. And hold on to it as long as you like.

A short password wouldn’t work well if an attacker could try every possible combination in quick succession. But as Mr. Herley and Mr. FlorĂȘncio note, commercial sites can block “brute-force attacks” by locking an account after a given number of failed log-in attempts. “If an account is locked for 24 hours after three unsuccessful attempts,” they write, “a six-digit PIN can withstand 100 years of sustained attack.”

Roger A. Safian, a senior data security analyst at Northwestern, says that unlike Amazon, the university is unfortunately vulnerable to brute-force attacks in that it doesn’t lock out accounts after failed log-ins. The reason, he says, is that anyone could use a lockout policy to try logging in to a victim’s account, “knowing that you won’t succeed, but also knowing that the victim won’t be able to use the account, either.” (Such thoughts may occur to a student facing an unwelcome exam, who could block a professor from preparations.)

Very short passwords, taken directly from the dictionary, would be permitted in a password system that Mr. Herley and Stuart Schechter at Microsoft Research developed with Michael Mitzenmacher at Harvard.

At the Usenix Workshop on Hot Topics in Security conference, held last month in Washington, the three suggested that Web sites with tens or hundreds of millions of users, could let users choose any password they liked — as long as only a tiny percentage selected the same one. That would render a list of most often used passwords useless: by limiting a single password to, say, 100 users among 10 million, the odds of an attacker getting lucky on one attempt per account are astronomically long, Mr. Herley explained in a conversation last month.

Mr. Herley said the proposed system hadn’t been tested and that users might become frustrated in trying to select a password that was no longer available. But he said he believed an anything-is-permitted password system would be welcomed by users sick of being told, “Eat your broccoli; a strong password is good for security.”

Wednesday, August 11, 2010

Gmail makes changes to it account!

Google has made some updates to the Gmail experience with a heavy focus on contacts. The company says that out of all of the feedback it gets about Gmail, most of it is about improving the contacts experience. 


New contacts features include:


Keyboard shortcuts (go to Contacts and hit "?" for the full list)
Sort by last name (look under "More actions")
Custom labels for phone numbers and other fields
The ability to undo changes you've just made
Automatic saving
Structured name fields, so you can adjust titles, suffixes, and other name components
A bigger, more prominent notes field
In addition to these, Google has slightly altered the look of Gmail. Mail, Contacts, and Tasks links have been moved to the top left. Compose Mail is now a button rather than a link. A smaller header area puts the first message in your inbox higher on the screen. Finally, the select all, none, read, unread, and starred links that used to be above messages are now in a drop-down menu, next to the archive button. 


The features has been rolled out in everyone's account. The company also says that Google Apps users will have to wait because they're working on making domain-specific features work well with the new interface. The company seems to be paying more attention to the security piece as well. The users are asked to verify their alternate email account and the phone number to overcome several attempts to hack the Google account across the globe.


I am excited to see the new changes. It looks like my favorite Gmail would become my favorite email account for ever! :)

Friday, January 22, 2010

Electronic Clearing System of the Income Tax Department, India hacked: Hacker Diverted around Rs 15 crore

The Electronic Clearing System (ECS) of the Income Tax (I-T) Department has been hacked into, jeopardising the functioning of department across Mumbai. On Wednesday, three days after the incident, the I-T department handed over the investigation to the Central Bureau of Investigation (CBI).

Sources revealed that the ECS of the I-T department, which facilitates tax refunds of Mumbaikars has been hacked into. It is believed, the hacker also managed to divert crores of rupees from the system. Following this incident, the entire system that processes income tax payment has been shut down since Monday. To prevent further damage, the department has now changed the passwords of all the senior officers with access to the ECS.

Chief Commissioner of Income Tax, R K Singh confirmed the report, stating, “The matter has been transferred to Central Bureau of Investigation (CBI).”

According to I-T sources, the incident came to light last week when an additional commissioner level officer discovered unauthorised remittance made from his section. The officer informed his seniors about it and investigations revealed the ECS had been hacked into.

“It seems that more than Rs 15 crore has been siphoned off from the ECS. Investigations are on to ascertain the total amount,” an officer from the I-T Department said requesting anonymity.

ECS system of the I-T was launched recently to clear the refunds of taxpayers in bulk and cut down the tedious paperwork. Sources said that the department has cleared the refunds of one lakh more assesses in a short span of a month through ECS.

“The remittance was made by computers. Now, to check the source and officer who has cleared the refunds, one has to manually go through the entire process which will take a really long time,” said an assessing officer from the I-T department.

In a parallel inquiry, the investigation wing of the I-T is also on a trail of bogus PAN cardholders. Sources said a businessman from suburban Mumbai had filed an income tax return with the help of bogus PAN card. The I-T official got suspicious and found that the card was made in the name of two boys. I-T officials interrogated the boys who revealed that they never applied for any PAN card.

Further inquiries revealed that their father’s employers had managed the fake PAN cards in the name of boys. The I-T officials then approached the local police, but police refused to register the offence. Inquiries are still on in the matter.

I-T payment system has been shut down since Monday following the incident

Sunday, January 17, 2010

China tried to hack India's computers: NSA

Chinese hackers have tried to penetrate computers in the offices of National Security Adviser M K Narayanan, a British paper on Monday quoted him as saying.

Narayanan said his office and other Government departments were targeted on December 15, the same date that US defence, finance and technology companies, including Google, reported cyber attacks from China.

"This was not the first instance of an attempt to hack into our computers," Narayanan told The Times in an interview, adding the would-be hackers sent an e-mail with a PDF attachment containing a Trojan virus.

The virus, which allows hackers to download or delete files, was detected and officials were told not to log on until it was eliminated, Narayanan said.

"People seem to be fairly sure it was the Chinese. It is difficult to find the exact source but this is the main suspicion. It seems well founded," he told The Times, adding that India was cooperating with the US and Britain to bolster its cyber defences.

The Chinese government has denied any role in the attacks, with a foreign ministry spokeswoman saying: "Hacking in whatever form is prohibited by law in China."

Narayanan said that while he expected China to be an increasingly high security priority for India, the main threat still came from militants based in Pakistan.

He said Islamabad had done nothing to dismantle militant groups since the 26/11 Mumbai attacks, and criticised Britain for accepting its excuse that such groups were beyond its control.

"The British are still blinkered on this. We believe Pakistan's policy of using terror as a policy weapon remains," Narayanan said, adding India is anxious to prevent an attack from Pakistan during the Commonwealth Games in October.

"From Pakistan's point of view, it's important to disrupt the Games so you can claim that India is not a safe place," Narayanan said

Wednesday, January 13, 2010

Google threatens to leave China

Google has threatened to close its operations and offices in China after hacking of email accounts of many human rights activists.

In a statement on its blog on Tuesday, the world's second biggest corporate said it has detected in December "a highly sophisticated and targeted attack on our corporate infrastructure originating from China that resulted in the theft of intellectual property from Google.''

The main goal of the attackers was access the Gmail accounts of Chinese human rights activists, the statement said. But they didn't succeed as "only two Gmail accounts appear to have been accessed, and that activity was limited to account information (such as the date the account was created) and subject line, rather than the content of emails themselves,'' Google said.

But independent of this attack, Google said it has "discovered that the accounts of dozens of US, China and Europe based Gmail users who are advocates of human rights in China appear to have been routinely accessed by third parties.

"These accounts have not been accessed through any security breach at Google, but most likely via phishing scams or malware placed on the users' computers.''

The Mountain View-based company said it has made "infrastructure and architectural improvements that enhance security for Google'' and urged users to deploy anti-virus and anti-spy ware programmes. These attacks, Google said, have forced it to "review the feasibility of our business operations in China.''

The company, which had agreed to censor of Google.cn at its launch in 2006, said it was "no longer willing to continue censoring our results on Google.cn.''

Google said it will soon hold discussions the Chinese soon whether it can operate an unfiltered search engine. "We recognize that this may well mean having to shut down Google.cn, and potentially our offices in China,'' the blog warned.

Sunday, July 12, 2009

Microsoft confirmed another zero-day vulnerability!!!

Microsoft confirmed another zero-day vulnerability on Monday in a set of software components that ship in a wide variety of the company's products.

The vulnerability resides in Microsoft's Office Web Components, which are used for publishing spreadsheets, charts and databases to the Web, among other functions. The company is working on a patch but did not indicate when it would be released, according to an advisory.
"Specifically, the vulnerability exists in the Spreadsheet ActiveX control and while we've only seen limited attacks, if exploited successfully, an attacker could gain the same user rights as the local user," wrote Dave Forstrom, a group manager who is part of Microsoft's Security Response Center, in a blog post.

An ActiveX control is a small add-on program that works in a Web browser to facilitate functions such as downloading programs or security updates. Over the years, however, the controls have been prone to vulnerabilities.
The new flaw comes just a day before the company is set to release its monthly patches, including one for another zero-day vulnerability revealed earlier this month. That problem lies with the Video ActiveX control within Internet Explorer and is currently being used by hackers in drive-by download attempts.

In cases of especially dangerous vulnerabilities, Microsoft has deviated from its patching schedule and issued one out of cycle.

Microsoft said that the flaw could allow an attacker to execute code remotely on a machine if someone using Internet Explorer visits a malicious Web site, a hacking technique known as a drive-by download. Web sites that host user-provided content or advertisements could be rigged to take advantage of the vulnerability.

"In all cases, however, an attacker would have no way to force users to visit these Web sites," the advisory said. "Instead, an attacker would have to persuade users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker's Web site."

Microsoft issued a list of affected software, which includes Office XP Service Pack 3, 2003 Service Pack 3, several versions of Internet Security and Acceleration Server and Office Small Business Accounting 2006, among others.

Until a patch is ready, Microsoft said one option for administrators is to disable Office Web Components from running in Internet Explorer and has provided instructions.

Tuesday, May 5, 2009

Why do people write viruses???

Every time when reports of a big new virus or other malware attack hits media, my mind will be out for an answer for the question: Why do people write viruses?

I answer as succinctly as I can, but the question is a deep and complex one. Why do people burglarize homes? Why do people tag buildings with graffiti? Why do they post anonymous hatred on online message boards? Why do they play video games? These questions may sound like they have nothing to do with one another, but you might be surprised how their answers are all related to the topic at hand.

TechRepublic offered an interesting analysis of this issue a month ago but it slipped by me. Fortunately I stumbled upon it this weekend and hope you'll give it a read in order to help shed a little light on a surprisingly complex issue.

So why do people write viruses (and I'll use that term loosely throughout this post as a descriptive for any kind of malware)?

TechRepublic plays it down a bit, but my #1 answer to the question is always the obvious one: For the money. In the old days, a virus designed to erase your hard drive or fill your computer screen with garbage was just a prank (more on that later) but those viruses are quite rare these days. Nowadays, the vast majority of viruses have far more practical ends: They make your PC send spam, they harvest financial information, turn computers into zombies, and extort money out of you directly if you want it deleted. All of these have direct and quantifiable financial goals: Spam is paid for by the message (or the millions of messages) sent. Personal data can be sold on the black market for use in identity theft. It's business, pure and simple -- bad business, to be sure, but all about the cash at the end of the day.

Several of the items on the TechRepublic list get at a secondary reason for virus-writing: They do it because they can. It's the same reason people jump out of planes or drive at insane speeds: It's a thrill, and for a certain subset of programmers, there's a thrill, a laugh, or a power-trip to be had from causing as much damage as possible -- and getting away with it. While most virus writers don't want attention (which can bring serious prison time in the end), a few do, and some underground hackers get off on the notoriety.

Sabotage -- whatever the motivation -- is another common theme in malware creation. Any political issue -- whether it's a presidential election or a Microsoft vs. open source legal spat -- tends to be ground zero for hacker attacks. Denial of service attacks are commonly launched against websites owned by those with opinions unpopular in the hacker community. And that's where your machine comes in: Hackers compromise it with malware to turn it into a DoS zombie.

So, getting the picture? Viruses and other malware are going to be with us forever because they're a digital version of human nature.

Sunday, May 3, 2009

Hackers: We can now steal data via electrical outlet!!

A few years ago, the idea of using nothing more than a standard electrical outlet to hack into sensitive computer systems would be the stuff of Hollywood - and far-fetched, eye-rolling Hollywood at that.

I can almost picture the scene: A wily Justin Long taps a few keys on his laptop and we watch the signal race through the power grid to his target, where a hapless government employee types his password into the ultra-secure computer at headquarters. Back with Long, we watch the password show up on his computer screen, as if by magic, thanks to his nifty hacking skills.

It sounds ridiculous.

But it turns out, well, it's basically a reality.

At the Black Hat USA conference later this month, hackers are preparing to unveil their methodology to steal information typed on a computer keyboard using nothing more than the power outlet to which the computer is connected.

The technique behind the exploit isn't as wildly high-tech as you might think, though. Old-fashioned electrical properties are the key to the trick. Here's how it works (in simple terms): When you type on a standard computer keyboard, electrical signals run through the cable to the PC. Those cables aren't shielded, so the signal leaks via the ground wire in the cable and into the ground wire on the computer's power supply.

The attacker connects a probe to a nearby power socket (perhaps in the vacant office next door or a hotel room across the hall), detects the ground leakage, and converts the signal back into alphanumeric characters. So far, the attack has proven successful using outlets up to about 15 meters away.

If you've got a wireless keyboard or are working on a laptop unplugged from the wall, which would make this attack useless, fret not: The hackers have a method for eavesdropping on you too. A simple laser beam -- better than a laser pointer, but not by much -- can be pointed a shiny object on the table where the computer sits, and the beam's reflection is captured by a receiving system. The vibration of that reflection caused by the striking of keys can be analyzed and, as with the electrical outlet system described above, reconstructed into words, since every key produces a unique vibration pattern. All this technique requires is a direct line of sight to the PC and a few hundred dollars worth of equipment.

Be safe out there, folks than be sorry...

Wednesday, March 18, 2009

Protecting your computer makes good sense!!!

It can delete important data or programs from your hard disk. It can constantly display annoying pop-up ads. It can slow your computer to a crawl or stop it from functioning. It can even help computer thieves steal your sensitive information and your identity.

It's malware — malicious software. And unless you take steps to prevent it from attacking your computer, you can be a victim of viruses, spyware, and adware. What's even more frustrating is that these programs can be so well-hidden on your computer that you can't find and remove them without the help of an anti-malware program. And in extreme cases, you may have to completely clean your hard disk and reinstall your operating system to rid yourself of these pests.

  • Viruses can infect your computer and spread to your friends

A virus is a program that inserts itself into other programs, documents, or email attachments. If you open a document or click a link or attachment in an email, you may download a virus. Once a computer is infected, a virus can do intentional damage, from slowing down a computer by overloading its memory, to destroying important data or programs. The virus may attempt to infect other computers by emailing or instant messaging itself to everyone in your address book.

  • Spyware can lurk in other software

Spyware is software that gathers information about you without your knowledge or consent. It "records" what you do with your computer (such as the web sites you visit) by tracking everything you type on your keyboard. Some spyware can even gather email addresses, passwords, and credit card information and transmit it to the company or persons that produced the spyware. The data may then be sold to other companies that use it to display their ads to you, or used by criminals to steal your identity. Spyware is often hidden in other software that is downloaded from the Internet.

  • Adware is more than annoying

Adware is software that displays advertising, such as pop-up ads, as you surf the Web. Some adware double as spyware and also collect your personal information without your consent. Like spyware, adware can be installed when you download a program from the Internet or install software from disks. Adware may not disclose its behavior before you install it or may not clearly identify itself as the source of ads.

Thursday, March 12, 2009

How to Protect Your PC

Use anti-virus software and keep it up-to-date

If you haven't installed anti-virus software on your computer, do it now. Anti-virus software can detect many — but not all — forms of malicious software before they have a chance to affect your computer. When you purchase anti-virus software, look for one that includes anti-spyware. Most anti-virus software can automatically download updates for you. Check to make sure your software is downloading updates correctly.

Keep all your software up-to-date

You can prevent many problems by regularly checking for and installing updates for your programs, including your operating system, browser, messaging software, and other software. Many programs include a feature that automatically checks for updates. Be wary of clicking links in emails claiming to have updates for your software; it is safer to type the address of the web site into your browser’s Address bar to visit the site directly.

Check your security settings

Most operating systems (such as Windows XP) have a built-in firewall and other safeguards to prevent unauthorized access to your computer. Check your operating system to make sure it's set up so that your computer is protected. Install any security updates or patches for your operating system promptly.

Be careful opening email attachments

Consider turning off the feature in your email programs that automatically opens attachments. If you receive an attachment you aren't expecting, do not open it. Before you open any email attachment — even if it's from someone you trust — scan it using anti-virus software. Most of the online mail service providers automatically scans all email attachments for viruses.


Don't install unfamiliar programs

Think carefully before installing or running new software, such as freeware or shareware programs available online. Only download software from a source you trust. Do not install software if you cannot verify that it's from a trusted source. Make sure you know what the software will do and how it will affect your computer. Malicious software (like viruses and spyware) often masquerade as legitimate and even useful programs. For example, you might be tempted to download a program that claims to keep your computer clock synchronized with an official clock. But if that program contains adware or spyware, it could also display advertising pop-ups whenever you're online or keep track of where you go on the Internet.

Be wary of pop-up and email warnings

Don't believe every warning you read — especially pop-up warnings that you see while you're surfing the Web. Unscrupulous companies use pop-up ads to display false warnings about your computer. Ignore them.

Do NOT click any button in the pop-up (such as a "Close" or "No" button) or the Close box that may appear in the upper-right corner of the pop-up. Closing a pop-up in that way might actually install a virus or other malicious software on your computer. To close a pop-up ad, press Ctrl-W (if you're using a Windows computer) or Command-W (on a Mac computer). You may receive an email warning that claims to be from a computer "expert" warning you of a virus. These are usually hoaxes. Do not follow the steps described in any email unless you're sure the threat is real.

Monday, March 2, 2009

How do I get rid of viruses, adware, or spyware?

If you suspect that your computer is infected with a virus or other malicious software, remove it as soon as possible.

Unlike other software, malware can't be completely removed using your operating system's Add/Remove Programs feature. Some bits of malware may still be hiding on your hard drive, doing its damage behind the scenes. To get rid of malware, use software specifically designed to find and delete it.

Many solutions are available for ridding your computer of malicious software. You can find these programs by searching the Web for virus protection. I would advice Symantec Endpoint Protection as a good anti virus. Whatever software you choose, be sure to keep it up-to-date.

In some extreme cases, anti-virus programs may not be able to remove all malware. It may be necessary to reformat your hard drive and reinstall its operating system. If you're using a laptop computer, installing the operating system from the partition backup may not completely remove malware. Instead, be sure to get installation disks for your operating system from your hardware vendor and use those to reinstall your operating system.

Thursday, February 26, 2009

How do I safeguard my password?

Choosing a strong password is just one part of protecting your online account. You should also follow these tips to keep it safe:

* Your ID and password are confidential information. No one will never ask you for your password in an unsolicited phone call or email. Do not respond to any message that asks for your password.

* Do not write your password down. If you must write it down, keep it safe away in a place only you can access. Treat it as if it were cash.

* Change your password if you suspect something is amiss. Change your passwords frequently to keep it much more safer.

* Verify your online account information. From time to time, make sure your information is accurate and that no one has changed your data. If you suspect someone knows the answer to your secret question and any other information asked on the Sign-In Problems page, change them as soon as possible.

* Use care with automatic sign-in. If you check Remember my ID on this computer when you sign in to online account, you're still signed in even after you close your browser.

This feature can be a convenience for you: When you return to the online account, you don't have to re-enter your password. (If you're away from your computer for a while, you may be asked to re-enter your password.)

Do not check the Remember my ID on this computer box if you use a shared computer.

To change the setting of this feature, click the Sign out link on your online account page, and then sign in again, but do not check the Remember my ID box.

* Read the fine print. Before saving your password on any browser, plug-in, or program, thoroughly read the security documentation for that program or service. Depending on the program, your passwords may be available to anyone who uses that computer.


Saturday, January 24, 2009

How do I choose my password?

Your password is more than just a key to your online account. If your password falls into the wrong hands, someone can easily impersonate you while online, sign your name to online service agreements or contracts, engage in transactions, or change your account information. So, choose your password carefully and then keep it safe from others.

A password is like a toothbrush: Choose a good one and don't share it. A password can be any length, and can contain spaces, symbols, or numbers. With so many options, you should be able to come up with a password that's easy for you to remember but impossible for someone else to figure out. A password is a secret that only you should know.

Here are some tips for choosing a strong password — one that is difficult to guess.

* Choose a password you'll remember. It should be memorable for you (so that you don't have to write it down or leave it in the open), but difficult for others to guess.
* Avoid using a word. Avoid a complete word from a dictionary (English or otherwise) or a name.
* Use at least 7 characters. The more characters your password contains, the harder it is for someone to guess it. A long but simple password can be safer than a short, complex one — and often easier to remember.
* Use a combination of capital and lowercase letters, numbers, and standard symbols (! @ # $ % ^ & *). Your Yahoo! password is case-sensitive, which means that a capital letter A is different from a lowercase a.
* Don't use personal information that someone could easily figure out. Avoid a password based on information easily obtained about you (like your birthday, your child or pet's name, phone number, license plate number, employer, school name, automobile brand, or street name). Don't use a password you already use for another account, such as your bank account PIN. And don't use your user name in any form (such as reversed, capitalized, or doubled).
* Avoid the obvious. Don't make it easy for attackers by repeating a digit or letter (like "111111" or "FFFFFF") or any other common sequence of characters (like "123456"). Stay away from obvious passwords such as "test" or "password." When you change your password, change several characters; don't just append a number like "2" to the end. And make sure anyone watching you enter your password can't guess it as you type (such as a password typed using a single hand, like "qwerty").
* Put a new spin on a familiar phrase. Pick a favorite phrase or lyric for your password. To shorten it, substitute letters with a number or a standard symbol or remove vowels. For example, "fredsboy" can be made into "Fr3d$boy." Shorten "two tickets to paradise" to "2Tickets2Paradiz," or combine "cat" and "dog" into "cAt!Do8."
* If you use a password generator, be careful. Make sure you can identify and trust the creator of a password management or generator program. Never share any personal information unless you trust the company or person you're working with. Online password-generator programs can help you create a random password that is generally harder to crack but also more difficult to remember.

Protect your privacy by choosing a strong password!!!

Wednesday, December 24, 2008

Things to know about phishing…

Phishing is like fishing personal details…

Phishing is a new way of getting personal information through fake pages which is most similar to the original page. The victim will enter his/her personal information on the fake page and will end up in big loss like identity theft money loss etc.


How to identify Phishing pages?


There are several ways to identify the fake pages.

1. First and for most is to upgrade your browser to the latest one which the service provider offers. Internet Explorer version 7 has the in built capacity to identify the fake page. If you happened to logging to a fake page, the browser will give you a warning message stating that it may be a phishing attempt.


2. Look into the address bar properly.If you check your address bar you will come to know whether it is a fake page or an original page. Fake page will not have the correct site address that you tried to log in. The fake pages are normally hosted from a free site hosting pages which will be mentioned in the address bar. But little more advanced hackers will host a website which has the address similar to the targeted site. So it is always better to type in the address of the site to which you have to take a look.

3. Don’t follow the links which is in an Email.You should never follow a link in an Email send to you. Always remember that hackers use email as a medium to carry their fake pages to their victims. You may find some wonderful offer from your bank or from your Email provider. Never click the link that contained in that email. Because we may not know, if it is a fake page. If you are interested in the add type the address of the site in the address bar and navigate through your site to see if an offer is made by them. If yes apply for that with confident.


4. Don’t provide personal information.Never provide your personal information in any of the social networking sites. Hackers normally target those sites to collect the contact of their victims.

So beware of phishers and be safe always…

Monday, February 4, 2008

Computer viruses are small software programs that are designed to spread from one computer to another and to interfere with computer operation. A vir

Computer viruses are small software programs that are designed to spread from one computer to another and to interfere with computer operation.

A virus might corrupt or delete data on your computer, use your e-mail program to spread itself to other computers, or even erase everything on your hard disk.

Viruses are often spread by attachments in e-mail messages or instant messaging messages. That is why it is essential that you never open e-mail attachments unless you know who it's from and you are expecting it.

Viruses can be disguised as attachments of funny images, greeting cards, or audio and video files.

Viruses also spread through downloads on the Internet. They can be hidden in illicit software or other files or programs you might download.

To help avoid viruses, it's essential that you keep your computer current with the latest updates and antivirus tools, stay informed about recent threats, and that you follow a few basic rules when you surf the Internet, download files, and open attachments.

Once a virus is on your computer, its type or the method it used to get there is not as important as removing it and preventing further infection.


Search The Fire Seal

Random Post: I'm feeling lucky!!!