Saturday, June 4, 2011
2011 Computer Security Incidents Have Made Headlines
February 2011 HB Gary hack attack by the group known as Anonymous.
March 2011 RSA hack stole token data, (attackers were reportedly advanced persistent threats).
April 2011 Sony hack data theft reportedly involving information related to 77 million accounts and 2.2M credit cards.
April 2011 Epsilon victimized by a hack attack, email addresses stolen.
WikiLeaks related attacks perpetrated by the group known as Anonymous.
April 2011 Ritz-Carlton Hotel customers data stolen in a hack attack.
April 2011 Amazon Web Services cloud outage (non-availability).
May 2011 Lockheed Martin (details were not disclosed).
May 2011 Woodside Petroleum (Australia's largest oil company said attacks were coming from everywhere).
May 2011 Public Broadcasting (a phony news story and lists of reporters accounts and passwords were posted to a PBS site.)
May 2011 A New York Congressman reported a lewd photo had been mailed when his Twitter account was hacked.
Hacking is a type of directed attack typically executed by an external human using tradecraft methods to exploit accessible vulnerabilities and inflict damage. Protection methods are usually applied to limit the damage inflicted during an attack, limit the duration of an attack or deter an attacker. The effectiveness of any protection measures in use is clearly at issue when a successful attack occurs. Forensic tools and methods are used to analyze attacks allowing lessons learned to be captured and documented. Data theft is often motivated by financial gain, focused on credit card data for sale to fraudsters or email addresses for sale to spammers.
Non-availability incidents occur for any number of reasons, often not involving malicious activity. Such incidents can grow as related resources cascade into failure, a phenomena with potentially wide spread impact.
The Internet is often used to deliver the attack. The nature of giant public networks facilitate anonymity while being reliable and predictable.
The list does not include a huge number of incidents based on malicious code that have become common events or the large number of incidents involving sensitive, typically government, sites that never make it into the press.
The rapidly evolving sophistication of hacking attacks is a cause for concern. State sponsored activity involving "Advanced Persistent Threats" is emerging from behind the curtains as a valid concern for enterprises worldwide. The press in not likely to suffer from a shortage of material for their headlines for the remainder of 2011.
The incidents mentioned are from press articles that can usually be found in the publisher's archives. A search using the name of the victim and "hack" can often find a no cost article.
Thursday, May 5, 2011
Important Reasons To Use Web Security
The term internet security refers to methods that are being used to help provide some protection for any data or information for the computer from an unauthorized person. Today this is becoming more and more of a serious matter. Anyone who uses the internet for whatever reason should always take this into consideration. People who use the internet should be fully aware of all the problems that come from this issue.
One of the more common ways that most people use for protection of important information is encryption of data. This encryption of data is something that deals with wrapping up any and all original information that is to becoming an unintelligible form which can then be decoded with the use of various methods. This encrypted form is known as a cipher text.
A password is commonly used as so to provide some protection from any illegal access of any data, securing the entire system. The construction of these passwords should always be created in a way so to prevent others from ever being able to guess it. There are quite a lot of methods that are used as internet protection.
One is the firewalls, which is a software that can filter any illegal access to a network. This should always have some proper configuration and will be combined with the proxy firewall for added security.
All computers will need to be protected from the many viruses that exist. There are several of them, such as worms, Trojan horse, and several others that can infect your computer from any files that are downloaded over the internet. The viruses are nothing more than programs which are installed alone and will run whenever host program runs and will then cause an attack.
One popular method is with the use of ScanSafe. ScanSafe is a provider that has a great track record and is proven to be quite effective for identifying any and all threats as this is very important to protect and also manage any web access. The company offer one of the best means of protection for your computer anytime you are on the internet, as it offers you very effective web security than most other existing solutions that are available.
For more information about Scansafe or Cloud Computing visit Ancoris who are are a authorised Google Apps Reseller.
Wednesday, March 30, 2011
How to Get Paid for Translation Work
This is the dread of every translator and what you too will experience if you are not careful. But there are ways you can avoid this.
First of all you should always check the reputation of a new translation customer before accepting any work from them. The best place to check this is on Proz.com's BlueBoard. Without a membership you can see the company's overall score, but not the comments submitted by other translators. If you have no membership and want to see the comments from other translators, you can invest 20$ into your "wallet", where each $1 investment entitles you to permanent access to the comments concerning one customer. Translatorscafe.com is another good site, although also restricted to non-members, and translationpayments.com is fully and freely accessible.
If you place your hopes on a contract it will only work if properly formulated and applicable in the country where the customer is registered. Since the translation industry has become so globalised this can be a rare luxury. And even if you do write up a solid contract with a customer in its own country, if they do not want to pay you will probably find it very difficult to exact payment from them. You will need to prove that your translation was not faulty, that they assigned you the work, there will be legal fees, and generally the entire headache might not be worth it. Not to mention that there are some sharks out there who have a very fancy looking website but who are in the habit of transferring it to a new name and changing the company name in the header every time they decide to press the reset button and run away from those they owe payment to.
If you do get stuck in the trap, the best response is to remain polite but keep calling them, plead them, and perhaps make up some story how you have mouths to feed, etc. Appealing to their sympathy should generally yield better results than hostile threats over the phone. If the first approach fails, then you can resort to the latter.
If you do get burned make sure to report it on all the translation payment reputation forums to protect others and make it more difficult for such companies to operate.
If you are fortunate to work for a reliable translation company and it looks like payment is in the bag, there are many ways you can receive the payment. One obvious one is by bank transfer, but the fees for such payment can be rather high - not only for the sender but also for you, the recipient. Furthermore, sometimes an intermediary bank is required, and although they are not supposed to charge anything, often they do.
Very common in the translation industry now is to get paid by PayPal.com or Moneybookers.com. These fees are generally low (unless the payment is made from different continents) and the transfer is immediate. It is easy to set up these online accounts and they can be hooked up to your bank account and/or you can order a credit card and withdraw your money through any bank machine. But be aware that these are not actual banks, with a physical headquarters you can come complain to, so make sure to remember your password and secret security questions. If you forget the latter you may have a problem accessing your account. With PayPal you can also arrange for payment by credit card. The system designs a fancy "Buy Now" button for you and your customer is directed from your website to PayPal's secure online payment system - at no cost to you!
These are the most common forms of payment, but such services are not necessarily available in all countries. In which case you might try WesternUnion, although Unistream charges significantly lower fees - so check them out first. But most customers will not want to pay by these means. You will probably need to offer an exotic language combination for them to accept such forms of payment.
Further details:
Getting paid for translation work
Email to 16,000 translation companies
Friday, March 4, 2011
Tracking IP Addresses With A Reliable IP Geolocation Database
However, internet protocol addresses are no longer attached to a particular location these days; and is indeed a big challenge for those who want to want to locate people by internet protocol. For various reasons, a lot of proxies are now being used to make it difficult to locate the exact location of a visitor to a website. This is not only seen as a concern; but a situation that may lead to a lot of confusion when it comes to tracking IP addresses. Accessibility to quality and consistent data is also affected by this development, and the only way out is to own a reliable IP country database.
One issue that must not be compromised when considering an IP city database is reliability. Anyone serious about tracking IP addresses should know that he/she requires more than generalized information. Although a reliable database may not be able to provide some personal information of an internet protocol address; it should at least be able to pin-point the exact location of the address. Any effort not capable of providing adequate information relevant to your search should be treated as inconsequential; and should be discontinued as soon as possible.
Business and profit are inseparable; that is why you need accurate data of people who visit your website always. The importance of this kind of information can be better appreciated from the perspective of meeting the tastes of customers. The customer base will definitely improve when their needs are treated with top-most priority; and this requires owning a quality IP country database. When this is taken care of, you can design your website to meet their needs.
Remarkably, no business can succeed without satisfying the needs of customers; this is one reason tracking IP addresses will benefit you in the long run!
A good site to actually see how accurate IP Geolocation works is at http://www.trackipaddresses.com/. Check out their features and learn more how precise position profiling of online visitors could help businesses and other online ventures. For more information, Visit Track IP Addresses!
Sunday, February 13, 2011
A Smart Way to Secure Multiple Websites
Extended validation certificate were designed to increase the magnitude of ecommerce security and for increased protection against phishing attacks. The address bar displays a green color bar and your website is visibly guaranteed and more trusted than with other certificates. By taking these steps, ecommerce merchants can increase the trust and purchase conversion rate with their customers and create long-term income.
If you are looking for an executable online security solution involving several websites, EV Multi Domain SSL Certificates (MDCs) are a reputable choice. A single EV Multi-Domain SSL can secure multiple websites. And the best part is that the green address bar displayed for visitors of all websites secured with one certificate, creating their trust in your websites and assuring trusted and secure transactions of the highest levels.
Multi Domain EV SSL Certificates (EV MDCs) allow you to secure up to 2500 different domains or sub-domains with a one certificate. EV technology adds an additional layer of trust to your online transactions by changing the address bar to green every time a customer enters the certified region of your web position.
Some of the key benefits of EV MDCs:
- SGC enabled - tough coding
- 128-bit to 256-bit cryptography
- Full enterprise marker
- $250,000 warranty
- Site Accolade
- Express livery
- Installation draw
- 99.9% browser identification rank
- Supports wandering devices
- Includes 30-day issuance shelter
A multi domain certificate is important for organizations that feature multiple unique domains hosted on a single server. This saves you time and money by providing a high level of trust, reliance and guarantee.
Comodo SSL Certificates
Comodo provides the maximum level of protection at unmatched prices. As the second largest provider of business-validated certificates, Comodo ensures that millions of transactions are safely performed every day.
ComodoSSLStore.com is one of the largest global SSL certificate providers. We buy SSL certificates in large quantities and pass the savings on to you. To learn more about Comodo SSL Certificates visit http://comodosslstore.com/
Tuesday, February 1, 2011
Cost-Effective Firewall Solutions For Small Business
This is a cringe-worthy response: I'm a big believer in proactive IT, and security is one of those areas, along with backups, that get neglected because of cost. Because there is no immediate value-add to security (indeed, the effect of good security is invisible), many companies choose to invest that money elsewhere, reasoning that they can't afford an effective firewall appliance like a Sonicwall or an ASA.
Given today's recession, many small businesses have to cut operating costs, and sadly firewalls are an area that may not be as immediately necessary as others. The saddest part, however, is that there are open-source solutions out there that make perfectly serviceable firewalls for nothing but the cost of an outdated PC or virtual machine.
IPCop - Cost Effective Firewall
IPCop, the example we'll use in this article, is an open-source OS based on Linux that is designed to act as a firewall and router. Unlike a vanilla Linux distro running iptables, IPCop goes far beyond simple add and drop rules; it has features one might expect from a more advanced firewall appliance, including intrusion detection, VPN services, and traffic shaping capability. IPCop was designed for this very application (cost-effective firewall solution) and as such it is made for the small business network admin in mind: The entire OS is run through a stylish web interface, allowing easy administration of the IPCop firewall from any web-accessible machine, and the installation is straightforward and full of easy-to-understand directions.
IPCop is one of a number of distros, like Smoothwall, which aim to be full-featured firewalls for small business. Unlike Smoothwall and others, however, IPCop is completely free, thus making the insertion of an IPCop instance in your network both a painless and extremely cost-effective solution, especially where a dedicated hardware firewall appliance is an expense your business simply cannot afford.
IPCop Disadvantages
IPCop does have its disadvantages, of course, especially when compared to a more robust appliance like a Cisco ASA. It lacks the fine granularity of IOS, for example, and some of the more advanced ACLs and command-line magic the IOS performs is beyond the scope of the IPCop instances. That said, however, IPCop comes very close to the performance of an entry-level ASA, and many of the functions an ASA provides are duplicated effectively in IPCop's web interface.
Linux Distro
The title of this article, however, is not "Best firewall appliance". We're here to talk about cost-effective firewall solutions, and in that regard a Linux-based distro is unbeatable. While it does require some spare hardware, the system requirements are quite sparse, and so the implementation cost is minimal at best (and the software is, of course, open-source and free). In fact, even disregarding the price, I am willing to put forth the semi-controversial idea that IPCop may be as good as a dedicated firewall device in a small business setting; many of the functions it provides are more than suitable for a small business network.
That said, no network should be without security; the cost of a firewall appliance, though prohibitive, need not stop a small business from implementing security solutions. With open-source, free solutions like IPCop, a network admin can insert a firewall into his network infrastructure at little to no cost, immediately making his network more secure and giving him the power and functionality of a dedicated firewall appliance at a fraction of the price.
LearnComputer! (learncomputer.com) offers instructor-led local, online and onsite Networking courses for companies and individuals. Sign up for an upcoming Networking course with LearnComputer! today and learn the skills you need to succeed in your career!
Monday, January 17, 2011
Information Security Awareness Crucial to Combat Cybercrime in European Union
Recently, Europol, EU's law enforcement agency released a report highlighting the threats posed by cybercrime. According to the report, the dynamic nature of cybercrime makes it inevitable for all stakeholders such as law enforcement agencies, academic institutions, Internet service providers, financial institutions and Internet security firms to collaborate with each other and enhance information security awareness among the people. The collaboration may facilitate information sharing, development of technical tools and promote research and development to counter cybercrime.
Crime has evolved as an organized activity and criminals are using a combination of online and offline channels to perpetuate crime. The growth of crime has led to the creation of illicit markets for selling stolen information such as social security numbers, credit card numbers, bank account numbers, names, date of birth and contact details. European Union countries must make efforts to create awareness among Internet users against sophisticated crime mechanisms such as social engineering techniques, data breaches, online solicitation, installation of botnets, and abuse of unsecured wireless connections. Internet users must be made aware of the risks involved in online payment transactions and downloads from suspicious sites and unsolicited e-mails.
The organized cybercrime syndicates have clearly defined specialists for code writing, Internet hosting, launching phishing attacks, pharming and hacking among many others. Countries need to create a strong force of information security professionals to deal with the constantly evolving crime in the Internet environment. The all-pervasive nature of Internet facilitates criminals in initiating crime from any part of the world. Businesses worldwide are forced to spend considerable resources to deal with cybercrime. Organizations can streamline Internet infrastructure by availing services such as penetration testing, security auditing, ethical hacking, and vulnerability assessment. Such services may help in proactive protection against dynamic threats in the IT environment.