Pages

Friday, November 23, 2007

Steganos offers free desktop encryption


Safe One protects up to 2GB of sensitive data

I used some Steganos' freebies in a past but never valued them to the degree so I can recommend them. This time, I want to bring your attention to the new Steganos Safe One product, a freeware version of Steganos Safe for consumers and small businesses.

The privacy software provides protection for up to 2GB of sensitive data by creating two 1GB virtual drives which can store encrypted versions of the data.

According to the company, you can use various portable devices, such as iPod, USB sticks, digital cameras and PDAs that can be used as keys to open the Steganos "safe". The program also features a fully integrated password generator to help users produce secure passwords with a built-in multilingual dictionary.

Steganos PicPass allows users to utilize images as a personalized password by memorising their exact sequence. I have experimented with personalized images about a month ago but did not accept it for my passwords, yet. Personalized images is a new way to password protect your data.

"Steganos Safe One offers users real peace of mind, secure in the knowledge that their privacy is protected without them having to spend anything to do so. "

Steganos Safe One is now available for download. The Steganos Safe One supports Windows XP for the x64 processor architecture, and encrypts data with 256 bit AES. Not bad at all!
http://www.steganos.com/us/products/home-office/safe-one/overview/

Monday, October 22, 2007

* Certified are getting paid less!


I found a small article written by Tessa Parmenter. She noted that his week, Foote Partners LLC released a study revealing unbelievable information: the average premium pay for uncertified workers INCREASED over those who are certified. They have seen the average premium pay for uncertified workers increase 8% and decrease 2.3% for certified engineers in the past year.

http://itknowledgeexchange.techtarget.com/networkhub/you-mean-i-wont-get-paid-more-for-getting-this-cert/?track=NL-81&ad=610275&asrc=EM_USC_2423108&uid=5617007


What can I say? Certainly, there are some exclusions (CCIE, CISSP, J2EE...) but every rope has the end! Read my previous posting about certifications in details.

Friday, September 21, 2007

* "Thank You" letter for your Friday enjoyment


Thanks to my son who send me this "jewel" of a "Thank You" letter. I feel that I need to share it with you for a good Friday laugh. He interviwed the guy for a LAN Admin position. On the question what's the difference between the HUB and the SWITCH. He answered: "Hub is just a hub, and the switch it's like a car with a green and red light..." Well, below is a copy of his "Thank You" letter receved just next day over e-mail. I did not correct anything... Njoy! :-)


Dear Mr. YYYYY,

It was very enjoyable to speak with you and your team about the LAN Administrator position at Department of Labor. I think I was too nervous for some technical questions that you and you team asked me such as: how can you joint your server to the domain? The answer should be: go to command prompt then type: DCPROMO then server name. Another question you asked me what if user are not able to see your server? The correct answer should be at the logging window right click on the check box below your user ID change it to the correct server. Then what is the maximum speed of the switch? The correct answer should be 1000 Mbps. I know I get lost this morning from place to place. However, I know that I should have done a better job than what I did this morning. I also know that I am out of your consider about the job you want to hire that's fine with me. I just want to tell you that my brain was shut down this morning (I need a cup of café in the morning) those questions are within my knowledge, and I did do it well. If I have another change I would have done a lot better job.
I appreciate the time you took to interview me; I am very interested in working for you and looking for ward to hearing from you about the second Interview.

Sincerely Yours,
YYYYYY YYYY

Friday, August 10, 2007

* How to hack unencrypted wireless session


Recently, I came across the information about unsecured WiFi connections. I am sure you are familiar with this scenario when you turn your laptop on in some of the buildings or neighborhoods, and your wireless card can find at least 2-3 unsecured wireless connections. Unfortunately, most of them are the result of the default configurations of the wireless router being pre-configured by the manufacturers and used by inexperienced consumers. While I can understand why they do it this way (for non-IT customers), it leads to a wide-open gate for hackers and this is not news, what is interesting is how easily Web app sessions can be hijacked on these networks.

Infamous Robert Graham, the CEO of Errata Security (I have the links to his web site in our Information Security Index), described the “man in the middle” attack. Robert hijacked a GMail session of a volunteer and showed how easily he could grab cookies and IP addresses and take over a session.

The attack is actually quite simple. First Robert needs to be able to sniff data packets and in our case the open Wi-Fi network at the convention fulfilled that requirement.

1. To ran the “Ferret” utility to copy all the cookies flying through the air

2. To clone the cookies into a browser with a home-grown tool called “Hamster”.

3. The attack can hijack sessions in almost any cookie-based web application (ex: Google’s Gmail, Microsoft’s Hotmail and Yahoo Mail).

4. Since those programs just uses cookies, getting the IP addresses and user names and passwords are not required.

How to protect your session? Hey, just use the SSL from the beginning instead of a pure HTTP session:

https://mail.google.com/mail/ instead of the http equivalent will be a good remedy.

Tuesday, July 31, 2007

* My War with the SPAM


Spam hurts.
Spam drives us crazy.
Spam consumes resources on your web site, in your mail box, the traffic on the Internet, and a disk space on your ISP's servers.
Spam kills our precious time when we want to read the e-mails from legitimate senders but forced to read pure junk and delete the stream of offers to buy drugs, to play online casino, to work as the representative of a foreign company, to get the guaranteed cash, to catch the virus of Trojan horse program (hidden behind the text/link of image), to meet hot singles in your area, or porn crap.
How to fight SPAM?

I began with collecting the links to the informational sites that offer knowledge and resources on fighting the spam nightmare. You can find one here, too:
http://www.rtek2000.com/Tech/I-SecureLinks3.html

Reading through the numerous web pages , articles, blogs, and forums, I found that the first source of the spam to my e-mail box is my own e-mail address that can be scanned from any web site where I posted it by the e-mail harvesting programs freely available on the Internet. As far as I know, those programs were designed by the folks who did not want to spam but rather get the attention to their products. So, the simplest way to distribute the news about a particular product was to e-mail to a large number of cyber citizens. It is how the spamming started!

Now, the spamming is extended to the wide range of services, and the millions of affiliates who want to make a buck by selling the product or service need the customers who want to buy. You may ask me, how come I am getting e-mails with a garbage text in it; it's not the offer to buy anything, it's a junk! Well, thanks to the search engines (and particularly, to their "crawlers" or "spiders") that scan not only web sites pages but also the folders that contain e-mails. By sending the garbage-like text in e-mails with the keywords embedded in the text, the spammers hope to raise their web sites' popularity level through the search engine ranking. Particularly the spam that I am getting these days is about 60% of this kind.

I have seen several ways of packaging spam messages: Plain text, Image files, Document files, and lately PDF files.

So, how to protect your e-mail address from being harvested? There were numerous discussions on the web. I have participated in several of them. The common conclusion: there is no way to completely hide the e-mail address. I used to implement various JavaScript-based solutions that may protect against simple harvesting programs, however, as the countermeasures become more complicated, the "harvesters" become more sophisticated. My latest solution is to use the small image of my e-mail address being loaded thought the CSS code (cascading styles sheet method). It greatly reduces the chances to be harvested, however, it does not guarantee 100% protection because there are some programs that can use the character recognition in the image. Don't think it's done manually! Those programs do it automatically!

The biggest problem with the spammers lays in the area of blogging. If you happened to have the blog site of forum, you must clean your blogs from literally hundreds of spamming messages in every corner of your site! If you don't manage one, you are lucky because it is a real nightmare. The automated programs that specialize in breaking through the web site security rules using the weaknesses in the software design can post automated messages within seconds!
To be honest, I gave up on the forums completely by locking it up from posting but I still have to clean it up regularly (less often, at least). It is a very time-consuming task to tweak the web site's files, apply patches, or complicated solutions that in the end only temporarily protect against the stream of spam.

I have decided to concentrate on fighting the e-mail spam. The second step after getting some background on spamming was to identify the domains that are sending the spam. It is not a simple task taking into account that when the spammers send e-mails they rarely specify their real e-mail address but rather the link to their web site. The only way to find out the real sender is to look in the message header, and to grab the IP address from the top of the message. So, I have collected the IP addresses in the text file, day after day spending precious minutes for the purpose of identifying the biggest spammers in the world.

Well, I do not suggest you to repeat it. First of all, it's not the pleasant procedure. Second of all, there are many anonymizer-type of the programs that can hide your real IP address and to substitute it with a random IP address taken from the text file. The only what drives me up in my efforts is the revenge when I will be able to filter the most of the junk and redirect it to the trash can where it belongs.

After collecting the information from my e-mails, I have identified the high-level IP addresses (like 88.xxx.xxx.xxx, 89.xxx.xxx.xxx, etc). Then, using the WHOIS service, I have identified the countries that are originators of the spam e-mails. I realized that I have no customers in China, for instance, who order my products using English-based pages, so I can filter all of them out. Using similar approach, I have set the web site filters accordingly, so the domains that I have identified could not access my web sites.

You won't believe what happened. I have reduced the spam by 80% instantly!!

I felt that the victory is close but I did not expect the problem that I have faced really soon.

My sales dropped by 80%... No, it's not because I have filtered spam but (as I discovered later) because the Google's PR (page rank) of my web pages dropped from PR6 to zero. I began to investigate what happened. My guess that I have prevented the Google's spider to crawl my web site unfortunately was the correct one. The Google's spiders were in my filter-out range. It took me about two months of hard work in optimizing my web site, adding more pages, sending begging e-mails to Google until I have re-instated my position in the search engine.

Moral? Be careful when you implement the filtering!

I have changed my strategy after that and I filter only on the e-mail level, not the web site level. I have the long list of spammers (http://www.800-security.com/tech/SPAMaddresses.txt) that I am updating weekly. So, you can use it at your own discretion. Please keep in mind that the more filters I apply then the less information will be shown in the file. One quick suggestion: filter the e-mails that contain the .tr, .pl, .br, .ma, .th, .ru, .jp, .ch domains in the message header.

I am going to show which filters I used on the top of the text file soon. So, keep monitoring!

To finish my story, I want to point you to a very useful web site:
http://www.projecthoneypot.org/

See the Top 25 Countries Where Spam Servers Are Located.
I utilized a freely available technique to "honeypot" the spammers. So, now I can see how many of the "harvesters" were fooled by my program (oh, the sweet revenge!) as well as I see the updated in a real time list of the biggest spammers in the words by precise IP address. It gives me the opportunity to adjust my filters.

Am I getting the spam now? Yes. But it is 10-12 a day but not 80-120 as it used to be.

Happy fighting!

Thursday, June 21, 2007

Russian Hackers...again




Russian hackers hijack Italian sites to serve exploits blog posted by Ryan Naraine at ZDNET.COM demonstrated again that the war between hackers and security companies is an ongoing event and I doubt that it will be over in the nearest future. Yes, the law enforcement measures were improved across the entire world in the places where we could not expect earlier (China, Malasya). However, the creativity of those who design the malicious software is often above the creativity of those who design the countermeasures. Apparently, Russia is a good source of hackers (as well as the programmers). I would be especially careful to hire the Russian programmers to lower the cost of development if they still live in Russia. You can easily get your financial information stolen by those programmers who may build and hide a back door into your system.

The problem is that the most of the countermeasures are reactive even if some of the vendors
claim that their software includes intelligent engine that can recognize the new malicious program. None of the vendors will ever admit that those "intelligent engines" are good in the lab and on the paper (especially, the marketing) but fail in the field. Could they be sophisticated enough, they would prevent the attacks that involve several components including even the tiny proxy server that after being downloaded serves as a door to download the information stealer(the WebAttacker/MPack exploit toolkit).


While there is no guarantee that the latest-greatest software and OS patches installed on PC will protect you at 100%, it is still important at least to lower the risk of infection. Another countermeasure is to avoid browsing unknown web sites as much as possible. Is it possible? I think so.


While you are reading this article, I recommend you to follow the suggestion of the the blog and to run the Secunia’s free software inspector to scan your machine to look for weak spots.

Sunday, June 10, 2007

* New struggle for current MCSEs


For those who are MCSE 2003, Microsoft has some good news.
Yes, the endless struggle for being certified by Microsoft AND being current MCSE or MCP has entered into a new phase: http://www.microsoft.com/learning/exams/70-649.mspx
What bothers me that the Microsoft Marketing department, well in advance before the final release of Windows 2008 server, already offers the new certification in the run for more revenue that the new certification will generate. The product is not there, yet, but the certification is already there (beta).

Why to offer beta certification? It's pure simple. If you want to try passing the beta for free, you will obviously have to learn the product that was not released to the general public. And this IS the goal. Along with the money current MCSEs will pay for the exam (not the beta) later, Microsoft will achieve the goal to have more ambassadors of a new server operating systems, the ambassadors who will push it to their network environment...

Get your money ready, MCSEs!

Friday, June 8, 2007

* MAC security vs. Vista

About a week ago, I had a conversation with some of my friends regarding the bullet-proof operating systems. One of them informed us that one of the Government organization decided to replace Windows-based workstation and to use Steve Jobs' MACs because they like UNIX kernel are not penetrainable due to the security architecture and required permissions from the kernel to use any external program. While I agreed on the kernel itself, I disagreed that MAC is a bullet-proof OS. The problem with any OS that it's not only kernel itself but the whole bunch of other files that participate in various services, supporting applications, and much more.
I liked MAC for a sleek interface and performance but not for the price tag. Also, Vista offers the same grade of a quility screen images and comparable performance. To support my statement, I sent them the link to the following article where the number of security problem were addressed:
http://www.crn.com/software/199701019?pgno=3
"If you look at the number of found vulnerabilities in Windows XP (28) vs. Vista (11) this year, Vista wins again. If that seems like a lot, don't forget Mac OS X has had 101 in the same time period".
No matter what the OS is being used and level of the security applied, the weakest link is always the end-user.

Monday, May 21, 2007

This is London... and Estonia.

One more story to prove that the credit card industry is still very vulnerable (and as a result, we are too).

http://www.thisislondon.co.uk/news/article-23395784-details/Britain's+biggest+credit+card+fraudsters+jailed+for+over+five+years+each/article.do

When the PCI standard will be a norm for every company that processes and stores credit card numbers? And how many new government regulations are required to make the online shopping safe? There are so many new technologies and solutions to improve the safety of the online transactions (like "use once" credit card numbers) ... so, when can we say that the online shopping is relatively safe? Why the adoption of new technologies is so slow?

Reading weekly SANS e-mails, I see more and more cases when the online crooks are getting jailed. However, killing several roaches does not destroy their colony. The online theft became an attractive business, and the story above proves it. Want to get the lifestyle of the kings? Steele or buy several credit card numbers, and enjoy your travels in the first class seats!

The vulnerability of the corporate networks is an issue that was discussed 1000 times online, in the press, and even on TV. While the online security is important for every company that has connectivity to the Internet, the companies that process credit card transactions must have double security. The protection must cover wide range of attacks including the DoS.

I was not surprised to read about the latest DoS attack on the Estonia's government and non-government sites (banks, newspapers) by the Russian hackers when Estonia removed a Soviet war memorial statue in the capital city of Tallinn. Ethnic Russians protested the statue's removal with riots and protests broke out on April 27. If you don't know, in the middle of the 20th century the Russians occupied three Baltic countries and made them the tree Soviet Republics (of 15 total). Since then, there is a mix of Russians and Estonians, Litanies, and Latvians who had to co-exist together for more than 60 years quietly hating each other. Since the republics became the separate countries again (after the fall of the Soviet Union), the nationalists in those countries began the movement for the clean country. Even the well respected people who contributed a lot for the prosperity of the countries were dismissed and forgotten only because they were Russian descent.

While I can understand the basis for that hate, I don't approve any nationalists who do separate people only by their nationality. There are thousands of decent people who have a different descent but take pride to be a part of the country, and contribute as much as they can; and there are some that hate the country they live in, ignore the traditions, and even plot the disasters. Then, I would weed them out.
It relates not only to those 3 Baltic countries but to the U.S. as well. Who knows how many Al-Qaeda cells are hidden inside of our country? Who knows how the sophisticated equipment and advanced skills in the cyber security will be used? We are the same vulnerable as Estonians not only from outside but from inside...