Friday, August 1, 2008

Spam - The Internet's Biggest Virus

We all know that virus's cause our computers to crash, and unfortunately at times rendering them completely unusable. That's why we have virus shields and scanners that can take care of these mechanical viruses for the most part. Well there is a virus that has long been attacking the internet itself, and it is not mechanical-it is completely organic and it has a brain. This virus is called a spammer.

Spammers.. viruses? No way, you think... they just send out unsolicited Emails and are extremely annoying.

In the most general sense a virus is a bad thing that is constantly adapting in order to continue attacking, and a vaccine is a good thing that is constantly adapting to mitigate attacks from viruses. If you think about it, web services all over the internet (Google, Spam filters, etc.) are constantly having to adapt and change rules and algorithms to keep spammers on edge-but somehow they manage to get through. Spammers are more than just annoying marketers (or wannabes) that want to fill up your Email inbox.

I often wonder: Are spammers slowly destroying the internet?

Here are my thoughts on that question. Social media and many other web 2.0 services on the internet (social bookmarking/networking, blogs, etc.) are in fact good things. They allow people to express opinions, share useful resources, share lesser-known knowledge, etc. and on the other end of the spectrum other people are able to read opinions, gain more knowledge, visit useful resources, and so on. But as time goes on the amount of genuine content is being far out-weighed by crap content produced by spammers in an attempt to trick search engines, trick users (to gain money), etc.

For example, hundreds (maybe thousands?) of blogs are created each day, but how many actually end up being genuine blogs, and not spam-generated blogs, re-produced content, blogs created for the sole purpose of getting links, etc. Lets look at social bookmarking. There are so many fake accounts are there all linked to one specific person in an attempt to send their website to the top of the rankings. Social networking is the same way along with every other web service/idea both new and old-all are getting plagued by spammers.

However, in the midst of the darkness among all these negatives, there is in fact a light that emerges. I'm a positive thinker, so after giving this subject some thought, I got to thinking about the life expectancy of the so called spam content being mass produced on a daily basis. Not very long. Most spammers probably give it a try for a few days or weeks only to find that their strategies take a lot longer-which narrows down the number of actual spammers that pose a threat to honest bloggers, social networkers/bookmarkers, etc.

So the answer to my question above (Are spammers slowly killing the internet?), I think would have to be a big NO. Search engines are getting better and better at finding the real content and weeding out the crap, and the one's who usually stick around are genuine web users who are producing valuable content-valuable content meaning real content (someone's opinion may not seem valuable but it is in fact useful to the overall internet if it is genuine).

If this issue has ever bothered you, such as having thoughts run through your head such as, I'm never going to get a good search engine ranking because there is way too much competition, don't worry about it because although the numbers tell you there is a rising amount of competition in any certain niche (hard to find a non-saturated niche these days-if you go strictly by the numbers), you have to stop and think of how much actual competition there is. Most people enter a market (many of which are spammers looking for the money) and give up within a few weeks, if not a few days... but their websites, blogs, etc. remain so while it may seem like there is competition, you will actually surpass them very quickly just by being an honest web user that is persistent in whatever niche you are trying to attract traffic within.

The question for this article:

Have you ever felt overwhelmed by competition in a certain niche (whether you were trying to sell something, or just make a blog that will build a readership) but didn't stop to think how much of that competition was dry spam that isn't going anywhere?

Learn to make money online the right way, exactly how I do it. This blog focuses on profits earned via blogging and certain affiliate programs. Observe this blog as a live case study and discover insightful tips to help you with your own ventures.

Blogging HQ - Discover Proven Ways to Make Money Online.

Friday, July 25, 2008

Antivirus Comparisons - How to Choose the Best Antivirus Software Product

Years ago it used to be important that you had some antivirus software on your machine. With the Internet, it is now imperative. Viruses can spread extremely quickly thanks to email, file sharing and chatrooms. To protect yourself you will want the best products available to you. Here is how to carry out antivirus comparisons to make sure you are using the best product.

First you should visit the websites of companies that carry out antivirus software reviews. Virus Bulletin and AV-Comparatives specialise in this type of software and both have a respected position in the industry. You can also visit the websites of computer magazines or buy them from a newsstand.

These reviews will concentrate on how effective the software is at doing its job: finding and eliminating viruses. Narrow your search down to the top performing products. But there are a lot more factors that will affect your choice. The first of these are speed and stability.

Find user reviews online that discuss how the software has performed on people's computers. Has it adversely affected the speed of the computer or are their conflicts with other software? Once you have carried out this bit of research, download a trial version. Any problems with stability will now show up before you actually spend money on the product.

Use the trial to evaluate other features such as ease of use and the graphical user interface. This type of software is very advanced but some manufacturers have succeeded in making it very easy to use. Others still have a way to go.

Another feature that many people ask for is a 'set and forget' option. This allows you to set the software to automatically perform scans and pick up updates. You should evaluate this process with the free trial.

When you are carrying out antivirus comparisons, don't be afraid to put several products on free trial. Just be aware that most antivirus software is incompatible. You have to remove one before you can install another.

Learn more about free virus software by visiting http://www.top-antivirus-software.com. Can free antivirus programs be better than paid? The results are surprising.

Thursday, July 17, 2008

Usability & Security - Unlikely Bedfellows?

With an ever increasing online population - 41 million users in the UK alone - computer security and user authentication have never been more vital. Unusable security is expensive as well as ineffective. According to Password Research, two-thirds of users had to reset their passwords/PINs three or more times in the last 2 years. With each password reset estimated at £35 in help desk costs (source: Mandylion research labs), it's easy to see how expensive an affair this can be.

Passwords

Passwords are by far the most widely used method of authentication. We're all having to remember more usernames and passwords by the day. It comes as no surprise then that over half of us use the same password for everything from work to banking to ecommerce, which is known to be poor security practice. More worryingly, 21% of people revealed their passwords in exchange for a bar of chocolate (source: Infosecurity Europe)! Clearly it's not all about making systems secure but making them usable too.

Passwords have long been considered insufficient within the security industry. Bill Gates even called for an end to passwords 2 years ago (source: CNET news). As that day still seems a long way away, let's consider what we can do to make the best of a bad bunch.

What you can do

As a website owner, you can make your customers' lives easier, and your site more secure by adhering to the following guidelines:

* Use e-mail addresses as usernames - Don't ask site visitors to create separate usernames as this increases the number of items they have to remember.
* Allow passphrases rather than just passwords - Passphrases are just like passwords but longer, being entire phrases instead of single words. They're typically 20-40 characters in length, an example use being Wi-Fi security. A sample passphrase would be 'PASSphrase1234567890'. Phrases provide context and are easier to remember than words in isolation. Passphrases are also harder to crack than passwords.

Helping users remember their passwords

To help your users choose secure passwords that are memorable, try suggesting some of the following tips to them:

* Use a passphrase instead of a password, if the system permits.
* If not, take a phrase and use the first letter of each word to make up a password that's easy for them to remember but difficult for others to guess. For example the phrase 'my favourite sweet in the world has to be chocolate' becomes 'mfsitwhtbc'.
* Then replace some of the letters with capital letters and throw in numbers and symbols to increase the password strength. For example use '1' or '!' for an 'i', '4' or '@' for an 'a' and so on. The above sample password 'mfsitwhtbc' then turns into 'Mfs!twht6c', which is much stronger.

Do your users have one password that they use for everything and want to keep it that way? They can have an easy life and be security-conscious. Here's how: Advise them to append an additional word/number at the end of the universal password to make it longer and more secure. The add-on can be related to the application/site they're on, so it's easy to remember and yet unique.

Here's an example - let's say the universal password is 'password' (which it should never be of course!). This is of course a rather weak password in terms of security. For a florist's site they can turn it into 'p@ssw0rdfl0wers' (for 'passwordflowers') and for e-mail it can be 'p@ssw0rdem@1l' (for 'passwordemail'), both of which are much more secure than the initial choice and unique to the respective sites. With just a few modifications, the new password 'p@ssw0rdfl0wers' becomes very secure.

Encourage your users to find out how secure their passwords are by checking their password strength on sites like Security Stats, Password Meter and Microsoft's Password Checker.

What's the future?

Passfaces

Should passwords disappear then what'll replace them? An alternative is a system called 'passfaces' that utilises our innate ability to recognise faces with speed and accuracy. Users are required to correctly select their pre-chosen faces from a random set in order to gain access. Passfaces has already been implemented by a number of websites.

Random number generators

Some online banking customers are being sent chip-and-pin card readers to add a layer of security. A lot of banks and large corporations are using tokens such as random number generators in addition to passwords to increase security.

Biometrics

Another alternative is biometrics where a person's physical or behavioural characteristics such as fingerprint, iris or voice are used for authentication. Examples include laptops with built-in fingerprint readers and the new biometric passports in the UK.

These approaches aren't solutions in themselves but will have to consider the human as being central to the whole authentication process in order to succeed.
In a nutshell

Traditionally, security has been considered more important than usability. In reality, security measures only succeed when users' needs are taken into consideration. Contrary to popular belief, security and usability can and should go hand in hand. Let's hope whatever replaces passwords is designed with usability in mind so we don't have to lose ours!

This article was written by Mrudula Kodali. Mru's crazy about improving online user experiences - so crazy that she works for Webcredible ( http://www.webcredible.co.uk ), an industry leading user experience consultancy, helping to make the Internet a better place for everyone.

Saturday, July 12, 2008

Scanning the Box

This article provides details on the scanning phase of any penetration test (blackbox, whitebox, gray box). Let's start from defining the types of scan we can use while performing a penetration test.

Scanning the box means performing the scan on the target to blueprint its security measures and than to penetrate into the box.

Types of scan we can perform on the selected target:

1. OS Scan (OS fingerprinting)

2. Port Scan ( Service detection)

3. Vulnerability scan (finding the hole)

Let's discuss the above types in detail:

OS Scan (OS fingerprinting):

When we are performing a pen-test we need to detect what OS is being running on the remote machine so what we can search for its related critical patches and vulnerabilities. OS fingerprinting is also known as banner grabbing.Banner grabbing and operating system identification - can also be defined as fingerprinting the TCP/IP stack. Banner grabbing is the process of opening a connection and reading the banner or response sent by the application

Following are the two techniques used to detect OS fingerprint:

a. Active Stack fingerprinting

b. Passive Stack fingerprinting

Active stack fingerprinting:

Active stack fingerprinting is the most common form of fingerprinting. It involves sending data to a system to see how the system responds. It's based on the fact that various operating system vendors implement the TCP stack differently, and responses will differ based on the operating system. The responses are then compared to a database to determine the operating system. Active stack fingerprinting is detectable because it repeatedly attempts to connect with the same target system.

Passive stack fingerprinting:

Passive stack fingerprinting is stealthier and involves examining traffic on the network to determine the operating system. It uses sniffing techniques instead of scanning techniques. Passive stack fingerprinting usually goes undetected by an IDS or other security system but is less accurate than active fingerprinting.

Port Scan (Service detection):

Port scanning is used to gather information about a test target from a remote network location. Specifically, port scanners attempt to locate which network services are available for connection on each target host by probing each of the designated (or default) network ports or services on the target system.

In a broad approach Port scanning is the process of identifying open and available TCP/IP ports on a system. Port-scanning tools enable a hacker to learn about the services available on a given system. Each service or application on a machine is associated with a well-known port number. For example, a port-scanning tool that identifies port 80 as open indicates a web server is running on that system. Hackers need to be familiar with well-known port numbers.

Vulnerability scanning (finding the hole):

The primary distinction between a port scan and a vulnerability scan is that vulnerability scan attempt to exercise (known) vulnerabilities on their targeted systems, whereas port scan only produce an inventory of available services. That said the distinguishing factors between port and vulnerability scan are often times blurred.It is the automated process of proactively identifying vulnerabilities of computing systems in a network in order to determine if and where a system can be exploited and/or threatened. While public servers are important for communication and data transfer over the Internet, they open the door to potential security breaches by threat agents, such as malicious hackers. Vulnerability scanning employs software that seeks out security flaws based on a database of known flaws, testing systems for the occurrence of these flaws and generating a report of the findings that an individual or an enterprise can use to tighten the network's security. Vulnerability scanning typically refers to the scanning of systems that are connected to the Internet but can also refer to system audits on internal networks that are not connected to the Internet in order to assess the threat of rogue software or malicious employees in an enterprise.

Tools available for Scanning the BOX

Port Scanners: de-factor for port scanning is NMAP some more tools are available for port scanning are net cat, advance port scanner, super scan etc

Vulnerability scanners: de-facto standard for vulnerability scanning is Nessus some more tools are available for vulnerability scanning are GFI Languard, SARA, Shadow security scanner etc.

Tuesday, July 1, 2008

Spy Scanners - Don't Compromise your Privacy

Spies, spyware, internet parasites are among what they are usually called. These are scouts that monitor your web activities. The work undercover to check on your surfing patterns, spending habits, items bought, they extract email addresses, hijack browsers, steal credit card information. These are just some of the things a spyware is capable of.

A spyware is mainly an information hungry parasite determined to gather data from a user or surfer without him knowing it.

The information gathered by these parasites are then sent to the originator without the users consent. Most often, the information gathered by the spyware are used to generate ads and pop-ups on the user’s PC.

Spywares and Adwares aside from being a nuisance and an invasion of privacy can also jeopardize the optimal performance of your PC. They can eat up unused disk spaces and position themselves in an inconspicuous location in your hard drive. They can also eat the bandwidth, crash your system and oftentimes inflict themselves in the Registry or in the memory of your computer.

Spyware and Adwares have become very rampant nowadays. Prevent yourself from being a victim of these by:

* Being careful of Freeware and Shareware Downloads

- Some of these downloads are tagged with spywares which may be unknown to the user. Refrain from downloading sharewares and freewares from unknown sources.

* Installing a good spyware/adware scanner and removal software

- There are a number of spyware scanner and/or removal softwares in the market today. A good spyware scanner can effectively locate all spywares installed on your PC and a good spyware removal tool can effectively remove all the spywares detected.

Spy Scanners are programs designed to detect spies in your PC. A good spy scanner can effectively search through the most unnoticeable embedded files that spy on you.

Most Spy scanners include a spyware removal function. Other spy scanners do not entail spyware removal features but display the logs of the spyware detected in your PC. The information in the logs contains the location and nature of the spywares.

For spy scanners with no built-in spyware removal functions, a manual deletion of the spyware files could also be done since the location and the file type is specified in the logs. Some Spy scanner products on the market today have spyware scan available for non-paying users and the removal tool available only for paying users.

Spy Scanners when installed can be chosen to run on demand or periodically.

-------------------------------------------------------------------
Gina Marie Capatar is a Technical Writer by profession and writes articles for http://www.isnare.com, also accepts freelance writing jobs. feel free to drop by http://www.isnare.com or email her at gcapatar@gmail.com

Tuesday, June 17, 2008

The Importance of IT Alerting and IT Incident Handling

In the Information Technology industry, immediate notification of critical events is essential. The Internet never sleeps, and neither do customers or employees in this age of global business and commerce. IT services must be available 24 hours a day, 7 days a week, without exception. When a computer or email server goes down, it can mean the difference between a corporation closing that $1 million dollar deal or losing it, or between a small business making its 100th sale or losing it. In any business or organization that contains more than a handful of people, enterprise email and communications are essential tools that must be available at all times. Electronic shopping carts and informational websites also must have near-zero downtime in order to be successful and effective.

So how can IT professionals ensure that they are notified the instant an error occurs on one of their systems? IT alerting is the answer. A notification service can contain a database with all IT employees contact information, including email, home phone, cell phone, work phone, and instant message screen name. These individuals can be divided into groups and scenarios can be created based on what type of event occurs. Then, when an incident does occur, the appropriate person can be notified based on the severity of the event. If multiple servers go down and a company's main revenue-generating service becomes unavailable, then most like the Chief Technology Officer and his team as well as Customer Service, the CEO and other executives should be notified. If a single email server goes down or becomes overloaded, then only a lower IT technician would be notified in order to fix the relatively small problem.

IT incident handling can be made much simpler using a reliable notification service. If a major IT incident occurs, then IT professionals need to be reached no matter what time of day, no matter where they are. It is not guaranteed that an IT expert will be located in front of his computer, able to receive email, when an emergency occurs. That is why robust, customizable notification service is necessary-to be able to send a voice and text message to the IT professional at all of his or her contact points, including email, cell phone, home phone, work phone, instant message screen name, or BlackBerry PIN, and also to get word back from the employee in response to the message. This guarantees the fastest possible reaction to an unforeseen event.

Learn more about IT Alerting and IT Incident Handling

Wednesday, June 11, 2008

Web Applications Penetration Testing - Security Measures - Security Assessment

1. Introduction

What is a web application? Why web applications are the first target for hackers? Why vulnerabilities occur in web applications? How we can make a web application a cure portal. As I understand a web application is a portal available on internet for the general public who can easily make use of it positively for different purpose or for the reason the web application exists. You must be aware, web applications are the easy target for hackers to gain access because it is publicly available, and a hacker needs to know only the name of the organization which he wants to hack. Vulnerability is the weakness or lack of control exists in the application. Vulnerabilities can be due to insecure programming in web applications, lack of access control places or configured, miss configuration of applications and server or due to any other reason, there is no limit.

There are many ways to harden your web application or your web server we will discuss this in a while. Let's see what are the key requirements which makes up a web application live?

a. Web Server

b. Application content displayed

c. And or databases

These are the key components of any web application.

Web server is a service which runs on the computer and serves of web content/application content. This server typically listen on port 80(http) or on port 443(https). There are many web servers which are freely available or commercial including top contributors

a. I.I.S by Microsoft

b. Apache by Open source community

c. Tomcat etc

Application content is what you see on the website, it can be dynamic or static, dynamic content containing web applications are at more risk as compare to static content containing web applications. Dynamic content containing web applications uses database to store the changing content. This database can be one of the following types.

a. MySql Server

b. SQL Sever

c. Oracle Server

d. MS Access or any other

We have discussed a lot on web application architecture now I will show you how to perform penetration on web application (what we say a Pen-test).

2. Information Gathering

Any pen-test can not be accomplished without performing the information gathering phase. This is the phase which is the heart of pen test, there are many ways to do information gathering lets discuss here.

a. Hacking with Search engines.

I would not list specific search engine which can be used in information gathering phase, there are lots of search engine which are more power full from which secret/confidential information can be gather. There are techniques which you can use to gather information on the target.

b. For example

You can use 'inurl:' in search engines to know what are the complete site map of the web portal, you can also use intitle: admin to gain access to the admin panel of the web portal, you can use inurl: Admin filetype: asp or aspx in order to search for admin login pages or simply you can lock for login page for any portal.

c. You can also look for the email address of the technical staff, email address shows the user id for that specific person

d. You can also use archives for more info to gather. This is the short list of the techniques, to explain more I would be writing a book

3. Attacks

Here I will explain you what are the major attacks which hackers use on web applications or the attacks which are dangerous for web applications. We will only discuss application level vulnerabilities and attacks.

a. Miss configuration? If you are a technical person your priority would be availability of your server, you should be asked by your senior management for the 100% up time of your server, this is the point where technical staff left security holes in the configuration just to make it live or in order to give 100% up time as directed. This miss configuration may lead to the compromise of the complete server.
Examples: default passwords, default settings for server, weaker passwords.

b. SQL Injection? A very high rated attack which can lead to complete web server compromise or complete administrative level access to hacker. SQL is a query language which programmers use for query the content from database in dynamic web applications. Many times a less experienced programmer left bugs in applications which if attacker discovered can be very harmful. SQL injection attacks occurs due weakness in input validation, insecure programming or due to insecure web application architecture. SQL inject can be used to by pass logins, gain admin level access, can be very harmful if a hackers gain access to admin logins. SQL Injection 'UNION' attack is commonly used in dynamic web applications penetration testing. There is more stuff which can be written on sql injection, I think this info is more than enough at this stage.

c. CSS/XSS (Cross site scripting)
XSS/CSS is a client side vulnerability which can be used in phishing attacks. Many hackers use XSS in order to gain secret information which can be credit card numbers, login passwords, private information and more. As XSS runs on client's browser hackers use to insert scripts in order to gather information from user. If XSS used in phishing attack it can be highly rated vulnerability.

4. Be Cure

To be cure complete assessment of web application should be performed in order to test the application and make it bug free, continuous testing should be maintained. Input validation should be implemented. Default configurations should be removed or changed, secure database connectivity should be maintained and in last directory listing on every directory should be turned off, file permissions should be reviewed, access rights need to be maintained.

5. Summary

This is the short article to develop awareness on web application security, what are the holes which can be used by hackers to do security breaches. These days there is a war on survivability of web applications. Is cure being long live?

article by Raheel Ahmad, CISSP