Monday, March 30, 2009

Shared Web Hosting - What to Go For

There's a colossal flood of data out there on the Internet concerning how to choose the best web hosting. The nice thing is that there's really only a small number of completely vital elements that you will really have to fully grasp. In this piece I'm going to promptly outline some of the critical elements that you will need to contend with.

Please don't pay to much attention to the dramatic headlines. A lot of the adverts you are going to see about web hosting will contain attractive headline numbers. What you're hunting for is a realistic and well rounded web-host. These striking headlines are really not going to show you a thorough overview of what's on offer. You're going to need to dig a little bit deeper to uncover the dependable info you're going to need before committing to anything.

Confirming the good reputation of the web hosting company is a vitally important topic to attempt to consider. Trading on the Net is pretty simple. Almost anybody could have a go. In the context of these realities it is quite easy to realize why there are a few shady operations out there on the Net. A really first class technique for verifying the dependability of the hosting service provider is to see how long their company has been doing business.

Please be clear that the thing you're really in need of is excellent value. The cheapest price will probably not provide you with the best value. The thing you're really in need of from a web hosting firm is a first-rate blend of a variety of components that will give proper value.

As I mentioned in the opening section of this piece, this has only been a basic outline of a few of the key items with regard to the topic of how to choose the best web hosting. There are just a tiny number of other absolutely crucial factors that you will have to be aware of.

To learn about those other things right now please go to web hosting advice now. For the best tips http://info.answertrain.com/WebHostingAdvice.html

Tuesday, March 3, 2009

Computer Security in a Down Economy

Cybercrime is on the rise as the economy falls deeper into recession. Recent reports have highlighted the increased threat to business IT systems as well as home computer users as more and more people look for ways to illegally gain access to cash. It is estimated that the number of scams and mal-ware programs has tripled in the last six months since the stock market drop in September 2008

There are a number of different ways that you can become a victim of cybercrime these days. Below are the most commonly used attacks and recommendations for keeping your computer safe.

Phishing

Phishing quickly became the most popular form of cyberhacking geared toward individual users. We become the victims of phishing attacks when we follow false warnings supposedly released by familiar institutions. These false warning come in the form of pop-ups on websites but are most often embedded as links inside spam email that comes to our inbox.

Safeguard: The best way to avoid being the victim of phishing is to be very discerning as you surf the web. Do not click on anything that you are not certain is what you are looking for. When receiving emails, hover your mouse over the link and read the URL. The text may say "Confirm your Bank of America user name and password here" but the URL may go to a 100 character address that is clearly not an authorized bank URL. Delete these messages immediately.

Cyberhijacks

Cyberhijacks occur when criminals access username and password information and then use it to enter accounts traditionally. These 'hijackers' can get this information in a variety of ways including social engineering attacks, system theft and phishing emails. Your information thus becomes hijacked and out of your control when this happens. This is a cybercrime often targeted at government agencies and law enforcement.

Safeguard: Avoid sharing your personal information, including usernames and passwords verbally, even if you are at work and seemingly in a safe environment. Don't safe your passwords and other vital information in your email or other programs that can be easily hacked or accessed by others. Never write down passwords and change your passwords regularly.

Trojans

Trojans are a type of cyberhijack where programs 'steal' your system, typically without the user knowing, and access personal information. Trojans infect a computer through tainted email, bad websites and even online banner ads.

Safeguard: Common sense is your friend. Be selective and aware of sites you are going to and banners you are clicking. If it doesn't look like a trusted service or banner, then assume it isn't and avoid clicking. Don't assume emails from your bank are real. Access your online account directly from the web address you know to be correct rather than through a recent email. Also, always make sure your system security features are up-to-date with the latest version and set appropriately to allow you freedom to work without compromising your laptop or system.

Social Network Scams

Social networks like Facebook and MySpace are becoming common areas for online criminals to create fake identities and networks in which to springboard phishing emails and other attacks to thousands of people. Others are simply scoping out online profiles for information they can use to gain access to you or your information. These sites try to cut out false IDs but that is a daunting and difficult task that does not keep up with the growing number of cyber criminals.

Safeguard: Only become friends with people you truly know and trust. Do not forward emails or requests to others unless you know the individual personally. Do not post sensitive information on your social network profile and do not upload sensitive documents to an online source. That information can be used in against you in court. It can also be used to gain access to your life. Be smart about what you say about yourself online.

This may sound paranoid. It may even sound cynical. But in these difficult times, people are pushed to do desperate things. It is better to be careful and concerned then be careless and cyberhacked.

~Colleen Welch, 2009

Colleen Welch is a frequent writer for Ascensha of Beaverton.

Protect your computer systems and boost your IT security by contacting Ascensha, a Oregon tech support company.

Tuesday, February 24, 2009

Printer Security is Not Worth Worrying About - Right?

When looking at enterprise security, we commonly refer to and consider firewalls, Intrusion Prevention Systems (IPS), Virtual Private Networks (VPN), encryption and authentication. When we think of securing our data, we think of securing critical servers and databases. Rarely do we think of printers. Billions of dollars are spent worldwide on security each year, but how much did your organization spend on securing their printers this last 12 months? If you answered zero, you would be in the vast majority.

Printers have come a long way since their widespread adoption in the late 1970's and early 1980's. Back in the day, each printer was connected to an individual system and could only process a single print job at a time. Today, printers have matured into multi-functional devices that bare little resemblance to their distant origins. Printers in the 21st century perform dozens of tasks including, but not limited to, printing, scanning, photocopying, faxing and even emailing documents. What most users, and even system, network and security administrators do not realize is what really goes on inside a printer and what functionality they truly have. Most users still think of the printers of 30 years ago; unintelligent devices that only possess the ability to print documents. This view is far removed from the truth.

When discussing printers in this article, we are not only talking about the behemoths you see in most large enterprises, but also your low-end multifunctional printers you now find common in regular households. Rare is it to find a printer, no matter how small, that only performs the single task of printing. Most, at a very minimum, provide faxing or scanning and with these come increased memory requirements. Scanning a full document in preparation to print, scanning a document to be saved as a PDF or similar file, or scanning a document to allow faxing all require the ability to buffer the data within the device. A buffer is basically a region of memory that allows the storing of temporary data. Printers use this buffer to store a digital version of the document you are printing, scanning or faxing. Depending on the device, this buffer can range from a small piece of Random Access Memory (RAM) to a Hard Disk Drive like the type found in your desktop or laptop computer. In larger enterprise printers, this buffer is not the only memory store found within the printer. A larger, non-volatile memory area is provided to store semi-permanent or permanent information. For example, some printers allow scanning of a document and saving it within the printer as a PDF. The user may then connect to the printer as if it were a network drive, or via a web page, and download their document.

So where are we going with all this? The leakage or theft of sensitive and confidential corporate information. Large enterprises may have developed and implemented data retention and destruction policies but rarely do these include, or even mention, printers. Companies look at hardcopies of documents, CD's, DVD's and workstation, laptop and server hard drives when developing their data destruction policies. While it is clear they identify hard drives as a source of sensitive information, rarely do they consider the hard drives contained within their printers, if they even know of their existence. Printers are also commonly overlooked when security policies, procedures and guidelines are developed and implemented. Little time, if any, is spent looking at printer security or the implications of not securing the corporate printers. All the more disturbing this becomes when you contemplate the common types of documents that pass through printers in a corporate environment. Depending on the industry or the department within the organization, documents can vary from sensitive financial records, personal customer data or detailed network diagrams, to name a few.

To understand how sensitive data is leaked via a simple printer to the outside world, it requires an understanding of the corporate environment, security controls within that environment, and the general flow of information between users, printers and file systems that house restricted data.

In the ideal, secure corporate environment, a user has restricted access to files that pertain to his or her job function. The files reside on a secure server within the corporate network and are protected by strong access control policies requiring a user to authenticate before being allowed access to files. In our example, a user requires a sensitive financial document for a meeting he is about to attend. The user authenticates to the server, access to the file is authorized by the access control policies set on the file and the user opens the file in Microsoft Word. He clicks on the print icon and sends the document as a print job to his nearest printer. With this simple act, we have taken a secure document that very limited users have access to, and have created two copies that are no longer protected by any form of access control. The first is the obvious; the paper copy our user requires for their meeting. The second is a copy housed in the buffer on the printer. In the ideal world, our user will keep the printed copy safe at all times and follow the organization's data destruction policy and destroy the copy of the document when they no longer require it. As for the virtual copy created on the printer, the user has no real control over this, nor probably knows it even exists. If we are lucky, the document is overwritten when the next print job comes through, but this is very dependent on the brand and model of printer and how the printer was initially set up by the administrator.

Slightly different to the straight printing of documents, scanning of documents or receiving faxes on a multifunctional printer writes documents to non-volatile areas of memory, usually a hard disk drive. If documents are not manually removed, they will remain there indefinitely, often long forgotten by the original user that scanned the document or received the fax.

In either of these scenarios, improper disposal of a decommissioned printer could have catastrophic consequences for a company. Leased printers may be returned to the leasing company for resale. Purchased printers are discarded in the trash or sold at auction or online via auction sites such as eBay. Either way, countless sensitive documents could pass into the hands of nefarious individuals. While the leaking of some documents could financially affect organizations, leaking personal information pertaining to hundreds or thousands of customers or clients could have reputation ramifications that could destroy a company.

Most organizations do not realize the full potential of their printers or the functionality they have available. While much functionality is non-security related, these functions have considerable impact on the security of the data within an organization and need to be understood and addressed. These include, but are not limited to:

1. The ability to copy files to Windows or Unix SMB file servers
2. The ability to email scanned files to a user
3. Functionality that allows printers to receive faxes and then forward the fax onto predefined users via multiple methods, such as email or as another fax, and
4. The ability to store files which have been scanned, printed, emailed or uploaded locally on the printer

While the previous data leakage scenarios have been accidental in nature, data remaining on printers could be the target of an educated attacker, one that understands the value of data residing on printers and who has the ability to compromise that data. While organizations invest hundreds of thousands of dollars to secure their network, dividing networks and systems into zones of trust with firewalls, Intrusion Prevention Systems and other network access control points, have they rarely considered where printers are logically placed within the network. In most cases, they are located amongst the users, or in some organizations, even on the server networks. Some organizations do not even have zones of trust and the printers exist amongst users, servers and even Internet accessible systems. In the worst case scenarios, the printers may even be Internet accessible themselves. Printers are not seen as critical devices, and as such, are not secured in their own zone of trust where access to management interfaces is not accessible except to trusted printer administrators. By limiting access to these interfaces, compromise of the data housed on these printers becomes exceedingly difficult.

While most printers have the capability to authenticate both printer administrators or normal printer users, the majority of the time, this functionality is disabled or left in its default state; disabled. Five minutes on Google and an attacker will be able to find the default password to almost any printer. Once administrator access is gained to a printer, it takes little time and even less ability to make changes to settings that could be catastrophic to an organization. While it would be little but annoying to find yourself locked out of your printer, or the interface changed to another language so no-one could control the printer, if the attacker was to redirect your printing or copy documents to a location outside the internal network, depending on the contents of the file, it could be the ruin of an organization.

So how does an organization protect itself against attacks against printers and leakage of sensitive data?

A few simple steps:
1. Disable unnecessary functionality. If any function within the printer is not required within your business, disable it. The less services or functions a printer has running, the less avenues of attack or leakage the printer has.
2. Add printers to your data retention and disposal policies. Make sure all memory inside printers is disposed of via secure destruction or secure wiping when printers are decommissioned.
3. Ensure data is overwritten immediately after printing. This requires the printer in use to support this functionality, but if your data is highly sensitive, this should be a priority when looking at new printers.
4. Print from memory rather than hard disk drive if available.
5. Use the secure printing option, if available, so printouts do not start before you reach the printer and enter your password. How often have you hit print, walked to the printer and your printout is no-where to be seen, only to turn up lying on a table days or even weeks later?
6. Examine where printers are logically located within the network. Printer management interfaces should be restricted and only accessible from defined management IP's. Ensure printers are never accessible from the Internet. Assess whether some or all printers should be located within their own zone of trust.
7. Use the inbuilt security within the printer to restrict who has access, what access they have and where they may access from.

Securing printers should be an integral part of securing your data. Security policies should exist that address the risks and define how printers should be secured. Develop printer security guidelines and procedures for implementation of new printers and follow these standards to ensure all printers are secured and do not become a high risk to your organization. By securing your printers, you are contributing to your overall layered security model and protecting your organization's critical data along with its reputation.

David Morrison is a security consultant with Sense of Security. Sense of Security is the premier provider of IT Security and Risk Management Solutions in Australia, and is the trusted provider to many of Australia's leading organizations.

Saturday, February 7, 2009

Personal Fraud Continues to Strike Many Unsuspecting Victims - Know How to Spot a Risky Situation

According to the Australian Bureau of Statistics, 1 in 4 people are targeted by internet fraud each year and a whopping 800,000 people fall victim to these scams.

It is becoming increasingly important for consumers to be aware of the many ways that they can be defrauded. Fraudsters are becoming ever more cunning as they continue to find new ways to prey on and catch out innocent and unsuspecting customers.

Some of the most common types of personal fraud to be aware of include:

* Credit or bank card fraud - the unauthorised use of a credit or bank card.
* Identity theft - the theft and fraudulent use of personal details or documents such as passports, tax file numbers and drivers' licences, all of which can be used to conduct business or open new accounts in another person's name.
* Lottery - usually a scam by which a person is told that they have won a lottery that they didn't enter. The "winner" is then asked to provide personal information in order to prove their identity and/or send a fee or bank account details in order to get the prize.
* Phishing and related scams - a fraudulent request whereby the fraudster pretends to be from a business or a bank and asks the consumer to confirm various personal details such as bank account numbers and credit card details. This can be done through a variety of mediums such as post, in person, calling your landline or mobile telephone, with email and instant messaging usually the most common.
* Financial advice - unsolicited fraudulent financial advice can include offers such as investment seminars, real estate scams, share promotion or telemarketing or other similar tactics.
* Advance fee fraud - an unwelcome request to transfer money into a person's bank account. It is usually accompanied by an elaborate or dramatic story which concludes with requesting the respondent's assistance and account details in order to facilitate the transfer of a large sum of money. This request is normally coupled with a promise of a commission or fee for the respondent's assistance with the transaction but instead funds are illegally withdrawn from the respondent's account.

There are some simple practices that you can employ that will help to keep your personal details safe and minimise the risk of falling victim to personal fraud. Some such practices include:

1. Use a locked mailbox to send and receive all mail
2. Purchase and use a shredder when throwing away documentation such as financial statements, pre-approved credit applications and any tax related forms of correspondence.
3. When using popular public networking sites like Facebook and MySpace limit your personal information disclosure as your details can be easily extracted from these platforms and used to steal your identity for criminal purposes.
4. If and when you receive credit cards from your financial institution sign them as soon as you receive them.
5. Regularly monitor your bank and credit card statements for any incorrect transactions or any irregular debits and promptly report these to the relevant organisation.
6. Avoid using public computers, especially for accessing financial information, as they may contain viruses that can capture your personal banking details.
7. Install and regularly update security software on your personal and work computer such as personal firewalls, virus and anti-spy protection.
8. Generally speaking, it is best to ignore any spam email that is generated from unfamiliar addresses.
9. Change your various electronic passwords regularly. This includes PINs, online banking logins and email account passwords.
10. Keep your wits about you and logically assess the details of the request or offer before providing your details to any unfamiliar third parties. If necessary, seek professional advice.

As the world moves to using the computer and the internet for more and more aspects of life - from communicating and banking to shopping and searching - fraudsters are constantly developing more sinister and devious ways to capture unsuspecting targets along with still utilising the more traditional methods. Subscribing to the common adage of "If it seems too good to be true, it probably is" could serve you well here. Ask yourself seriously, if it is actually probable that you are the sole heir to a $33 million African fortune, for example.

If you suspect that you may have unfortunately fallen victim to an act of personal fraud please contact us on 1300 QUINNS or click here to submit an online enquiry. Additionally, please do not hesitate to contact us if you would like more information on how to better protect yourself from becoming a victim of personal fraud. We can help you to ensure that you have the correct procedures in place to protect you and your family's hard earned money.

The Quinn Group is an integrated, accounting, legal, and financial planning practice offering expert advice to help you achieve your business and personal goals. With more than 15 years' professional experience, we are committed to building long-lasting relationships with our clients by providing superior service in a timely and cost-effective manner. For more free advice please visit Tax Lawyers.

Thursday, January 29, 2009

How to Monitor Children's Internet Activity

Now days it can be very important to learn how to monitor children's internet activity. There are so many areas on the internet where children can meander, many times by accident, and they can be exposed to graphics, text, or video imagery which can be disturbing. Another red flag are chat rooms that children can stumble onto. With the amount of sickening predatory behavior that exists, it's very important learning how to monitor children's internet activity in order to keep kids safe.

1. Computer in the family room.

One relatively easy way to monitor activity is placing the computer in the family room, where usage can be observed. Many times parents will place computers in bedrooms or dens, isolated areas where there can be little observation. By keeping at least one computer in the main room, children are forced to be more careful and parents can keep an occasional eye on usage.

2. Internet History.

You can bring up your "cookies" function, or internet history tab, to reveal the websites which have been visited by your children. The downside of this, is that other people in the family - their internet history will get mixed in and it could be unclear which sites your children have visited. Another thing is that internet history can be cleared or erased. It's pretty easy, even children can figure out how to clear cookies.

3. Online Child Monitoring Software.

Perhaps the best way on how to monitor children's internet activity is by simply downloading monitoring software off the net. Here's how this works: You basically turn the software "on", when you know child use is going to occur. The software acts invisible and tracks all the activity that goes on. Messages, chat rooms visited, pictures downloaded, and so forth. You can turn the software off after child use and later backtrack to see if any disturbing areas of the internet have been visited by your child.

Here is the BEST child monitoring software that you can download immediately. Check it out at - http://spyhead.blogspot.com/

This is the best way on how to monitor childrens internet activity, safely and invisibly. Keep your child safe with this monitoring software - http://spyhead.blogspot.com/

Monday, January 19, 2009

What is Cyber Terrorism?

The Government and the specialist of IT security have affirmed a substantial increase in the cyber crimes in the current situation. There is growing need amongst the officials concerning the intrusions which are conducted by the cyber terrorists or other terrorist organizations. This happens due to the potential loopholes in the security system as a whole.

But, what is Cyber Terrorism? Cyber terrorism is defined as the terrorist acts which are committed with using computer resources and cyberspace. A cyber terrorist is a person who frightens or compels the Government for fulfilling his or her social or political intentions. This is done by launching an attack through the computer networks. A common method of such attacks is the spreading of false propaganda on the internet about a possible terror attack at the time of holidays or some festivals. Sometimes this attack is actually carried out.

The e-commerce statistics show that if the internet is down for a single day the losses rise to billions of dollars. Not only is e-commerce affected but, the banking sector, authorizations of credit cards and other communication avenues are also affected. The list is endless. The amount of unfathomable information which is hampered is immeasurable. But, the amount of cyber terrorism correspondingly gets increased with the rise in the value of computer infrastructure. Leave aside the fiscal implications; the psychological impingement caused due to the turmoil is more damaging to the economy. The augmented reliance of the business houses, society and even the government on the internet, makes it the prime target for the terrorists for creating nuisance in the economy and the overall lives of the people.

There are some other methods too which are used by the cyber terrorists such as hacking which is channelized towards certain individuals or families. This is done by network groups which have the intention of troubling people and demonstrate their power. The primary intention of all such crimes is ruining the daily lives of the people, robberies and blackmailing etc. Cyber Terrorism is a big stigma on the society and hence, urgent measures are required for preventing it.

Sparsh MIC is one of the leading IT companies in India. We specialize in web design and development, IT solutions, web hosting, IT offshoring and custom software solutions. Visit us to see our profile at http://www.sparshmic.com.

Monday, January 5, 2009

Why You Won't Find a High Anonymity Proxy on the Free Proxy Lists

If you are looking for a high anonymity proxy to allow you to surf in private and protect your identity online then it can be tempting to just latch on to one of the many free proxy lists and simply use one of them. In practice this is often a very frustrating experience as these free proxies are often completely overloaded and extremely slow. Now I don't know about you but I have no real yearning for the days of surfing the web down a 28.8k modem but the reality can be very similar using one of these free proxies.

The reason is not very difficult to see, bandwidth is expensive and running a fast secure proxy server is an extremely costly business. To offer this service for free obviously will quickly use up lots of badnwidth and server resources.

Have you ever wondered why these people supply free proxy servers ?

I mean it's very generous of them to supply a valuable resource like this but you must wonder why they are incurring this expense for no gain. Well the answer is surprisingly simple - the vast majority of these so called anonymous proxies are either hacked or misconfigured servers and the real owners have no idea that they are being used like this. In fact often the first time the administrators realise their mistake is when they see their network statistics or bandwidth charges - ouch !

Now of course it is possible that you are willing to overlook this fact and still happily use the free proxy servers but don't expect speed and certainly don't expect any level of anonymity. These servers are usually inheritently insecure and in fact often the proxy service is actually installed by hackers or identity thieves in order to intercept passwords and logins. Just remember all your data is going through one place with a proxy server, the administrator has potentially complete access to everything that goes down that connection.

In fact the problem is far from being a high anonymity proxy server these free proxies are just about the most insecure way of surfing the web. Sure, you'll protect your identity from the web server you visit but not from anyone else and maybe you are really unlucky and pick one of the free hacked proxies run by Eastern European Hacking groups !

To see which software I use to protect my web browsing - you can read about Identity Cloaker here.

If you want to read about some of my thoughts on using anonymous proxies and general privacy issues on free speech please visit my new blog here Anonymous Surfing Proxies

Surf safely, protect your privacy,

Jim