Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Friday, November 28, 2008

You Have a Security Problem - Remove Antivirus 2009 Quickly and Easily

If you've seen a message popup on your computer claiming that "You have a security problem", then you absolutely do have a problem - it is called Antivirus 2009 and it is a rogue antispyware program.

What you are experiencing is the slick attempts of Antivirus 2009, which are designed to get you to purchase their bogus software. And while there are a large number of manual fixes and claims that completely free tools like Ad-Aware or Search and Destroy can clean this nasty little spyware from your computer, the reality is that you are going to need a lot more than that to rid your computer of this spyware nuisance.

This is the reality of spyware threats today. They are becoming smarter and smarter and more difficult to remove. What makes Antivirus 2009 so difficult to remove is the fact that the software has the ability to recreate itself after a reboot. This means that you can manually delete the files, folders, registry entries, etc. all day long and every time you reboot it will be right back there again, hammering you with popups and continually downloading additional spyware by the minute.

Having said that - there is a way that you can remove it rather quickly and rather easily, without the need to post any logs to forums and without having to do any manual intervention that quite frankly, most people don't feel comfortable doing. While it might not be the answer you want to hear it is the answer you need to hear - invest a small amount of money in a proven, top of the line antispyware software.

Most spyware removers out there will allow you to scan your computer for free to determine how infected your computer really is, however this is where the freebies end. Yes, there is software that will allow you to clean your computer for free, but the reality is that these programs are nowhere near as effective as software that you might have to pay a few bucks for. I mean, if the totally free software were so effective then antispyware vendors that require you to pay for the full version and clean your computer would go out of business right?

What computer users are starting to realize more and more however, is that the freebies simply don't work. What usually happens is that users think they can get away with using a totally free software, but after they have spent countless frustrating hours trying to clean their computer, they come to the realization that they need something better and that in order to get it, they are going to have to invest a few dollars and this is exactly what happens with Antivirus 2009 as well.

Because Antivirus 2009 has the ability to recreate itself and due to the fact that totally free antispyware software does not have the ability to stop this recreation which is the root of the infection, users find themselves in a vicious loop and can never completely remove it unless they get their hands on a proven spyware removal tool. I am sure you might already know how frustrating it is to see "You have a security problem" over and over again.

But what users also fail to realize is that this isn't going to be the only time they get infected with spyware if they don't have antispyware software running on their computer that is actively monitoring for threats in real time.

So spending money now on antispyware software with highly effective real time protection will not only clean your computer from current infections, but it will block future attempts at infection before they actually make it onto your computer - saving you from the frustrations of having to deal with spyware infections every other week or more.

So if Antivirus 2009 has gotten hold of your computer and you are seeing unending popups claiming that "You have a security problem," the best thing you can do is invest in proven and effective antispyware software and if not, be prepared to spend countless hours now and in the future fighting a new breed of highly efficient spyware infections.

Thursday, November 27, 2008

Installing a NTP Server

NTP or Network Time Protocol servers are network devices that are designed to distribute accurate time to network time clients and other network infrastructure. This article describes how to configure and install NTP server systems on a network and discusses the advantages and disadvantages of various reference clock options.

NTP servers are generally supplied as 1U high rack mountable network devices. They obtain an accurate time from an external time reference, such as GPS or radio, and provide an accurate timing resource for a computer network. NTP or Network Time Protocol is a protocol designed for distributing time to client computers over an IP network. The protocol is UDP based and as such requires the TCP/IP network infrastructure to be installed.

Hardware Installation

Stratum 1 NTP time servers rely on an external timing reference to obtain accurate time. Various external timing references are available. Options may vary with the installations regional location.

GPS (Global Positioning System) is a popular timing reference. The advantages of a GPS reference are that it is highly accurate and can be utilised anywhere in the world. A typical GPS NTP server installation can synchronise to within a few microseconds of UTC time. The disadvantage of GPS is that ideally a roof-mounted external antenna is required with a good view of the sky. The maximum cabling distance between an NTP server and GPS antenna is governed by the quality of coax utilised. Relatively low-quality coax, such as RG58 can be used to around 50m. Higher quality coax, such as LMR200 can be utilised to around 80m. Very high quality coax, such as LMR400 can be utilised to around 200m. Additionally, GPS amplifiers can be used to amplify the GPS signal and extend cable runs. It is also good practise to install a surge suppressor to externally mounted GPS antennas, to protect against the possibility of damage caused by lightning strikes.

Local radio time references are available in many countries. Radio time references tend to be local to the country of origin and maybe neighbouring countries. The advantage of radio is that generally a good signal can be obtained indoors, close to the NTP server installation. However, radio time services are less accurate than GPS and reception areas are regional. A typical radio NTP server installation can synchronise to within a few milliseconds of UTC time. A number of factors can affect radio reception, including: locating the radio antenna underground or in a basement; locating the antenna inside a metal cage (including metal cladding) and locating the antenna close to electrically noisy equipment.

A number of regional radio time references are available including: WWVB, Colorado, US; DCF-77, Frankfurt, Germany and MSF-60, Rugby, UK. The DCF-77 time transmission is available throughout Central and Western Europe. The MSF-60 time signal is available throughout the British Isles and much of North-West Europe.

NTP Server Configuration

For a minimal installation, NTP servers are extremely easy to install. They ideally need to be provided with a static IP address. DHCP is not a good option since the IP address is leased and can change periodically. The device then needs to synchronise its internal reference time with the selected external timing reference. Synchronisation can take as long as 30 minutes depending on the drift of the local battery-backed clock when the device was powered down. Once synchronised, the NTP server can provide precise time to network time clients and other network devices and infrastructure.

Many other configuration options are available on an NTP server: authentication options are available for secure installations; IP address restrictions can be specified; status reporting functions such as 'syslog' as well as precision and status information.

NTP Client Configuration

Many operating systems such as Microsoft Windows 2000/XP/2003 and Vista have built in SNTP client functionality. The standard NTP distribution is available for LINUX, Free BSD and UNIX operating systems; Novell also has a NTP compliant NLM available. Many network infrastructure devices, such as Cisco routers and switches can also be synchronised using NTP. Essentially, a network time client only needs to be pointed to the IP address or DNS name of a NTP server in order to synchronise time.

NTP and SNTP

SNTP or Simple Network Time Protocol is a simplified version of NTP that is generally used by small computers and micro-controllers. SNTP provides a subset of NTP functionality for computers that do not require the precise synchronisation ability of NTP. SNTP and NTP are however completely interchangeable. SNTP clients can synchronise to NTP servers and vice-versa. The client software supplied by Microsoft with Windows 2000 and XP is a SNTP rather than an NTP implementation.

Summary

NTP servers are extremely easy to install and configure. However, a little thought needs to be given to selecting the correct external timing reference for your region and to antenna installation.

Seven Common DoS Attack Methods

Hackers have an armory of methods to pass Denial of Service (DoS) attacks. The following seven sections emphasize the degree of the quandary faced by organizations trying to battle the DoS threat. TippingPoint provides solutions to battle these common methods of DDoS attacks:

<> Vulnerabilities
<> Zombie Staffing
<> Attack Tools
<> Bandwidth Attacks
<> SYN Floods
<> Established Connection Floods
<> Connections-Per-Second Floods

Method 1 : Vulnerabilities

Attackers can effort to collide a service or fundamental operating system in a straight line through a network. These attacks immobilize services by exploiting shock absorber spread out and other accomplishment dodge that exist in defenseless servers. Vulnerability attacks do not want widespread resources or bandwidth to commit; attackers only need to know of the survival of a susceptibility to be able to develop it and cause widespread injure. Once an attacker has control of a vulnerable service, request, or operating system, they abuse the opening to immobilize systems and in the end crash an whole network from within.

Method 2 : Zombie Conscription

The same vulnerabilities used to collide a server allow hackers to change vulnerable PCs into Distributed Denial of Service zombies. Once the hacker develop the susceptibility to increase manage of the system, they plant a backdoor into the system for later use in commiting DDoS attacks. The Trojan or similar disease provides a trail into the system. Once the attacker has the path, they tenuously control the network, making the server a "Zombie" that waits for the given attack authority. Using these zombies, attackers can send a huge number of DoS and DDoS attacks with secrecy. Viruses can also be used for Zombie conscription. For instance, the MyDoom bug was designed to convert PCs into Zombies that attacked SCO and Microsoft at a prearranged time programmed into the virus. Other viruses fit backdoors that let hackers to open coordinated attacks, rising the sharing of the attacks across networks around the sphere. The following figures detail how attackers make and begin these attacks against a network.

Method 3 : Attack Tools

Through zombie recruitment, hackers use secret communication channels to contact and manage their zombie military. They can choose from hundreds of off-the-shelf backdoor programs and tradition tools from websites. These tools and programs begin these attacks to penetrate and control networks as zombie armies to pass additional attacks from within. Once they have the zombie systems, they can use other tools to send a solitary command to all zombies concurrently. In some cases, commands are carried in ICMP or UDP packets that can go around firewalls. In other cases, the zombie "phones home" by making a TCP link to the master. Once the relation is created, the master can manage the Zombie.

The tools used to attack and control systems comprise:

<> Tribe Flood Network (TFN) : Spotlight on Smurf, UDP, SYN, and ICMP reverberation apply for floods.
<> Tribe Flood Network 2000 (TFN2K) : The updated version of TFN.
<> Trinoo : Focuses on UDP floods. Sends UDP packets to chance purpose ports.
The size is configurable.
<> Stacheldraht : Software tool that focuses on TCP, ACK, TCP NULL, HAVOC, DNS floods, and TCP packet floods with random headers.

DDoS Protection tools are growing both in terms of covert channel completion and in DDoS flooding methods. New tools exploit random port numbers or work across IRC. Further, smarter tools cleverly mask flooding packets as lawful service requests and/or bring in a high degree of chance. These improvements make it more and more hard for a port-filtering device to divide attack packets from lawful traffic.

Method 4 : Bandwidth Attacks

When a DDoS attack is opened, it can often be detected as a important change in the arithmetical work of art of the network transfer. For example, a typical system might consist of 80 percent TCP and a 20 percent mix of UDP and ICMP. A change in the arithmetical mix can be a signal of a new attack. For example, the Slammer maggot resulted in a rush of UDP packets, whereas the Welchi worm shaped a flood of ICMP packets. Such surges can be DDoS attacks or so-called zero-day attacks ==> attacks that develop secret vulnerabilities.

Method 5 : SYN Flood

One of the majority common types of DoS attacks is the SYN Flood. This assault can be launched from one or more attacker equipment to put out of action access to a target server. The attack use the device used to found a TCP connection. Every TCP link requires the conclusion of a three-way handclasp before it can pass data:

<> Connection Request : First packet (SYN) sent from the supplicant to the server, preliminary the three-way handclasp
<> Request Acknowledgement : Second packet (SYN+ACK) sent from the server to the requester
<> Connection Complete : Third packet (ACK) sent from the supplicant back to the server, implementation the three-way handshake

The attack consists of a flood of unacceptable SYN packets with spoofed source IP addresses. The spoofed source address causes the target server to react to the SYN with a SYN-ACK to an unwary or absent source machine. The aim then waits for an ACK packet from the source to total the link. The ACK never comes and ties up the connection table with a awaiting connection ask for that by no means completes. The bench will rapidly fill up and devour all obtainable capital with invalid requests. While the number of link entries may differ from one server to another, tables may fill up with only hundreds or thousands of requests. The result is a denial of service since, once a table is full, the target server is unable to service lawful requests. The difficulty with SYN attacks is that each request in separation looks benign. An unacceptable ask for is very difficult to differentiate from a lawful one.

The complexity with SYN assault is that each request in separation looks caring. An invalid request is very hard to differentiate from a lawful one.


Method 6 : Established Connection Flood

An Recognized Connection Flood is an development of the SYN Flood attack that employs a array of zombies to commit a DDoS attack on a aim. Zombies found apparently lawful connections to the end server. By using a large number of zombies, each creating a large number of connections to the target, an attacker can make so many connections that the aim is no longer able to believe to lawful link requests. For example, if a thousand zombies make a thousand connections to a end server, the server have got to run a million open connections. The result is similar to a SYN Flood attack in that it devour server funds, but is even more difficult to sense.

Method 7 : Connections Per Second Floods

Connections Per Second (CPS) Flood attacks flood servers with a high rate of connections from a apparently valid source. In these attacks, an attacker or army of zombies attempts to drain server resources by rapidly setting up and ripping down TCP connections, perhaps begining a request on each link. For example, an attacker strength use his zombie army to frequently obtain the home page from a target web server. The resulting load makes the server tremendously lethargic. visit DDoS Protection

Wednesday, November 26, 2008

Internet Security - How To Avoid Being Infected With Spyware

Spyware is more than just annoying - it can cause other programs to not work properly and can cause your computer to become quite unstable. Not to mention the privacy issues it brings up.

Spyware is often installed without your knowledge or consent and in many cases can't be removed from your computer without specialized software tools. When the people that distribute it need to resort to tricking you into installing it, there's obviously very little there to warrant your trust.

The first line of defense against spyware is to be careful installing software. Know what's being downloaded. A large percentage of freeware or shareware programs have spyware embedded in them. Sometimes that's disclosed in the user agreement, but often not.

Check for "spyware free" guarantees on software you download. Obviously, anyone can say something is spyware free even when it isn't, but if a website has gone to the trouble to say so, it is more likely to be safe than if they hadn't.

How can you tell if you have spyware on your system? You may see pop-up advertisements even when you aren't browsing the web. Your homepage may have been changed without your consent. New toolbars are installed on your web browser which you didn't request. Your computer may be sluggish or mysteriously reboot on its own. Though, the last effect is usually a virus.

If you do get infected with spyware, there are ways to get rid of it. A number of companies make software designed to get rid of it. These programs will scan your computer and check through their database of known spyware for any matches. These databases get updated frequently as new forms of spyware are found.

Some of these programs are free while others will cost. The paid versions sometimes have additional features, such as automatic scheduled scans. None of them are 100% foolproof however, so it's a good idea to run more than one of them.

Some kinds of spyware are notoriously difficult to get rid of. They may make changes to your Windows files that help them hide from the scanners. On occasion, you may need to delete them manually to be sure they're gone.

Obviously, this is something that you should only attempt if you are quite knowledgeable. You wouldn't want to remove something that is critical for your computer to operate.

Once the spyware has been removed from your system, you should run scans on a regular basis to keep it clean. Whether you do this manually or use a program that does it automatically on a schedule is up to you (and your pocketbook).

And, of course, beware those tempting looking free offers. You may get more than you bargained for.

Folder Guard

Folder Guard® is a powerful computer security software that you can use to control access to files, folders, and other Windows resources, such as Control Panel, Start Menu, and so on. You can use Folder Guard to lock your personal files and folders with passwords, to stop other users from peeking into your records. You can even completely hide your private folders from virtually all applications, and such folders would remain invisible until you enter a valid password. You can also protect sensitive system files from modification or destruction, disable access to the removable drives, restrict access to Control Panel, and more.



Why should you choose Folder Guard:

Folder Guard lets you password protect your files and folders.

You can protect with password virtually any folder or file, allowing only the authorized users to open the protected files or folders. You can protect an unlimited number of files and folders, each with its own password, or you can use the Master Password of Folder Guard to unprotect them all at once.

Folder Guard can hide your personal folders from other users.

You can set up Folder Guard to hide your private folders (or make them appear empty). The folder would be hidden from virtually any program, including Windows Explorer, Office, MS-DOS programs, etc.

Folder Guard can restrict access to Control Panel, Start Menu, Desktop, etc.

You can set up Folder Guard to allow only certain users to change the computer settings with Control Panel, while denying that to other users. You can control access to various settings of Start Menu, Desktop, Taskbar, and other Windows resources. You can remove the Run and Search commands on the Start menu, hide specific drives, lock the Internet settings, and more.

Folder Guard can protect access to the floppy, CD-ROM and other removable drives

You can configure Folder Guard to allow or deny access to the removable drives, restricting the user's ability to run or install unauthorized programs on your computer.

Folder Guard is suitable for a wide range of the computer security tasks.

You can stop other users of your computer from peeking into your personal files. You can protect the system files and folders from destruction by cyber-vandals. You can allow specific users to run a program while deny it to others. You can allow users to use the removable drives to store their documents while prevent them from running unauthorized programs from the removable disks. The possibilities are endless:

How to:

* Hide folders from prying eyes
* Hide files without encrypting them
* Lock files and folders with passwords
* Use Quick Start Wizard of Folder Guard
* Restrict access to Control Panel and other resources
* Set up user-specific restrictions
* Prevent users from installing unauthorized programs
* Prevent users from running programs from the removable disks
* Prevent users from reformatting local drives
* Disable the CANCEL button on the Windows Me/9x login window
* Restrict downloading programs from the Internet with Internet Explorer
* Restrict downloading programs from the Internet with Opera browser

Folder Guard protects your files without encrypting them.

There is no risk of losing your documents if you lose your encryption key: with Folder Guard all your files remain intact, without modification of any kind.

Folder Guard lets you quickly enable or disable the protection via a "hot key".

You can choose a specific keyboard combination as the hot key of Folder Guard, to be able to quickly enable or disable the protection of your computer. Of course, the "hot key" is protected with your password, too, only you can use it!

Folder Guard can operate in the "stealth mode".

You can set up Folder Guard to operate in the stealth mode, to hide its own files and shortcuts from being seen by other users. You would still be able to control Folder Guard via the "hot key".

Folder Guard supports easy recovery in case of emergency.

If you forget your password, or experience other problems, simply use the Emergency Recovery Utility (free download) to quickly restore access to your protected folder.

Folder Guard works with drives of any format.

If your computer can handle it, Folder Guard can protect it. You don't have to format your hard drive with the NTFS file system: Folder Guard can protect files and folders on both NTFS and FAT/FAT32 disks.

Folder Guard runs on a wide range of Windows platforms.

From Windows 2000 to Windows XP to Windows Vista and later, with all service packs and hotfixes, all are supported by at least one of the available editions of Folder Guard.

Folder Guard is easy to use.

Folder Guard sports one of the most intuitive user interfaces, that makes it easy to use for both novice users and computer professionals.

Folder Guard "speaks" plain English.

You don't have to be a computer professional to understand how to use Folder Guard. The Quick Start Wizard can guide you through the steps necessary to set up the password protection of your personal folders. Folder Guard Advisor warns you about situations that may require your attention and offers possible workarounds. Folder Guard User's Guide describes its commands and operation in plain English, without "pseudo-techno" or "geeky" talk. (And it does not baby-sit you either).

Folder Guard is not a toy.

Folder Guard is used by large corporations and small businesses, schools and police departments, universities and correctional facilities, libraries and hospitals (to name a few).

Folder Guard is widely used.

Hundreds of thousands of copies of Folder Guard have been downloaded by computer users from virtually all countries of the world.

Folder Guard offers the best value for the money.

None of our competitors offers a product that would come close to Folder Guard.

Folder Guard is flexible.

Although Windows lets you restrict access to folders located on a NTFS drives, it cannot hide them. With Folder Guard, you can not only restrict access to, but also hide folders, or make them look empty. Unlike Windows, Folder Guard lets you protect only some files within a folder, and keep the rest of the files visible and accessible, if you wish. Or, you can protect files and folders each with its own individual password, and then unlock them separately from each other (Windows cannot do that).

Folder Guard can be used with other disk tools.

You can designate your anti-virus and other disk maintenance tools to be the "trusted" programs, to make them able to work with your protected disks without restrictions.

Folder Guard is extensible.

You can fine-tune the access rules to the files and folders of your computer by creating appropriate filters.

Folder Guard will save you hours of learning time.

You don't have to learn how to use the Group Policies, user groups, Access Control Lists, privileges, and other built-in security features of Windows, because Folder Guard does the hard work for you: its visual and intuitive user interface lets you manage the restrictions with ease.

Folder Guard is actively maintained.

Since its first release back in 1997, we've been continuously extending, enhancing, and improving Folder Guard. Now in version 7.92, Folder Guard gives you more power than ever.