Share


Share

Share it !



share/bookmark
Showing posts with label Understanding. Show all posts
Showing posts with label Understanding. Show all posts

Understanding Attacks on Corporate Networks


By now most of you have heard of corporate networks being attacked. These attacks typically originate from malicious individuals who are connected to thea Internet that we like to call hackers. Hacking in and of itself is not a bad thing. The true meaning of hacking in the modern sense of the word is: "one who is proficient at using or programming a computer; a computer buff."

Individuals who use their computer skills for illegal purposes have given the term hacker a bad reputation. This article focuses on the frequency and some methods of illegal activity on a corporate computer system from individuals with malicious intent.

Denial of Service

In February 2000 the most significant attack on corporate networks occurred - and you may recall this event: Yahoo!, eBay, Amazon and CNN were among the 4 largest victims of a denial of service attack that caused the websites to be unavailable for roughly 3 hours. A denial of service attack is caused by multiple machines sending network traffic to one particular website. The overwhelming amount of network traffic causes the website to become unavailable and thus incurring millions of dollars of losses as in the February 2000 incident. In that incident, the sites were down for only a few hours. Had they been unavailable for days or weeks, the financial losses could have bankrupt the organizations. There are roughly 4,000 denial of service attacks worldwide every 7 days. These attacks are against small countries, public organizations and home users; basically anyone connected to the Internet is a potential target.

Weak Security

Another method of network breaching is by gaining unauthorized access to a corporation through system vulnerabilities and bypassing weak security controls. The Computer Security Institute generates the Computer Crime and Security Survey every twelve months that summarizes responses from participating organizations across the United States. This year 503 organizations participated in the survey and approximately 125 of those participants stated that their organizations' website suffered unauthorized access and misuse in the past 12 months. Of those, 53% stated the attacks came from outside sources such as the Internet, 5% came from inside sources, 18% came from both inside and outside sources and an alarming 24% did not know where the source of the attack originated.

Many times each security breach costs an organization financially. It may be a soft-cost of having to reassign responsibilities to already overburden IT staff to fix the problem, or worse, it could publicly embarrass the organization resulting in the loss of customers and vendors. Another relevant statistic that the survey uncovered was the percentage of the participating organizations that experienced unauthorized use of computer systems. Out of the 503 respondents, 56% stated they experienced unauthorized access to their computer systems, 29% percent stated they had not and 15% stated they did not know. It should be known that many organizations do not report security breaches to law enforcement or any public reporting agency due to the possibility of corrupting their image. The statistics are only meant as a guideline, you can find more information at http://www.securedigitalsolutions.com




Attack Prevention There are just two simple methods to prevent external attacks on a corporate network: Prevention and Awareness. Both are key to promoting the healthy networks that our business depends on for day-to-day activities. Most corporations employ security professionals who are adept at following both legal and industry standards in developing network security programs.

Chad Boeckmann
CISSP, GSEC
http://www.securedigitalsolutions.com




Understanding LAN and WAN Networks


Did you check your email today? Perhaps you printed a document to your work printer but had a brief wait while your co-worker's documents printed first. Or maybe you just went online to update your social status. If you did, you just accessed a network. Whether from home, school, or work, most of us access a network at least once a day. Essentially, a network is a series of connected computers and computing devices that share information and resources. There are a variety of network types, but the most common of these are Local Area Networks (LAN) and Wide Area Networks (WAN). For individuals or businesses wishing to develop a networking strategy, understanding the differences and similarities between the two is vital.

Just as its name implies, a Local Area Network (LAN) is a network encompassing a smaller physical area. Typically, you will find LANs inside homes, or within a single business or school location. A LAN allows multiple computers to do such things as share peripherals like printers or faxes, and/or share and store information such as files and databases. This ability to share resources is particularly attractive to the home-user or small organization as it allows them to save both money and time by reducing hardware and software costs. Thanks to their limited geographic area, LANs are simpler and cheaper to maintain due to easier access to all network components. LANs also typically enjoy higher bandwidth, or data transmission rate, as a result of lower traffic. While LANs may be connected in a variety of ways, they trend more towards physical connectivity using cables.

Wide Area Networks (WAN) connect much larger geographic areas, from locations separated by a few blocks to ones around the world. In fact, the largest WAN in existence is the Internet itself. Essentially, a WAN is formed when you connect two or more LANs together. While WANs may be utilized by large companies, often with global offices, WANs are more often not owned by an individual entity, but shared (such as the Internet). Whereas LANs are often restricted to specific users, WANs are typically more open and available. As such, they are less likely to be used for sharing hp hardware resources and more often used for communicating and sharing information. For large businesses with multiple locations, WANs are useful in providing ease of access to information on Sun servers, for sharing database software/resources, as well as providing private internal email communication to even global workers. Given the open nature of WANs, its higher traffic and usual need to transfer data via telephone networks or leased lines, not only is bandwidth lower on WANs, but they are more vulnerable to security issues. Additionally, WAN can be more expensive to maintain due to its size and scope.

While both networks have already greatly helped individuals and organizations to save time, resources and money, the process continues to improve. Now, the trend for both networks is wireless LANs and WANs, which allow remote access with even less need for physical connections. With this technology, individuals and organizations find that their ease-of-access and sharing is even greater, as well as their ability to do work and communicate from almost any location, at any time.




Steve Oono is the VP of Sales for Mojo Systems. They are the leading industry provider of Sun servers, HP servers, IBM, Oracle, and Fujitsu hardware and servers. For more information, please visit http://www.gotomojo.com.




Understanding Computer Security Dangers in the Digital Wild West


Today, more than ever, criminals are targeting computer systems in an attempt to wreak havoc. Complacency and ignorance, regarding security issues, are computer hacker's best friends. Computer Repairs Brisbane understands these risks and can help you implement a risk mitigation strategy. Some of the methods used to collect information about a system, network, and its users are: foot printing, scanning, and enumeration.

Foot printing is the methodical gathering of information about a company or individual's intranet, extra-net, internet, and remote access usage. Hackers exploit publicly available information like the name, address, and contact information for the party who registered the domain by using who's services. They harvest employee, vendor, and location details from the company's website. With an employees first and last names, hackers are often able to guess their user-names. More investigation of the employee on social networks will reveal a date of birth, children, spouses, and pet's names, home addresses, and phone numbers. Unfortunately, these are the very things that many people use as passwords.

Scanning is the electronic equivalent of casing a home or business for easy access. A burglar will check for unsecured windows and doors. Hackers search for unsecured networks by using ping sweeps, port scanning, and active operating system detection tools. If a hacker can access an unsecured port, they can exploit known vulnerabilities in your operating system or other application software.

Enumeration techniques seek out information about the services running on the network. Cyber criminals use banner grabbing to watch the output from remote applications. Applications like telnet send user-names and passwords across the network in plain text. Given the fact that many people use the same user-names and passwords for access to many different systems, this compromise can be devastating.

These are just a few of the methods used by hackers to document, assess, and attack your systems. Let Computer Repairs Brisbane be your first line of defense. Our technicians have the knowledge and skills to help you protect your network by implementing border protections, intrusion response and detection systems, and will provide you with the information that you need to make informed security policies.




George Pettit is a journalist and president of Computer Repairs Brisbane Group (CRBG). He is often writing about computer viruses, malware, web development and similar topics.




A Guide to Understanding and Implementing Microsoft Windows Security


Today, Information Security is the most important thing to be taken care of while using the Internet.

Internet, Being a source of knowledge, learning and entertainment, it is also something that can be misused for malicious and destructive intent.

So what do I mean by "Securing Windows"?

Windows being the most widely used operating system, Its users are vulnerable to data theft, Identity theft and cracking. By taking some precautions and a few good practices, you can secure your Windows computer, easily and effectively.

Security is a big field altogether in the world of computers, there are huge corporations that only specialize in security. This article is for the type of security you can use for your home computer and not it is not for huge corporate setups, since they have a much larger perspective.

To begin with, let me summarize the points that I am going to cover in this article

Understanding Windows processes that run in the background.
Antivirus software, and sources of viruses
Firewall
Security tips and tricks

Understanding Windows Processes

Every software, application we install in our computer runs as a "process", it is a way that the computer can keep track of running software, close it, or even modify it in some cases.

So where can you see them?

You can see the processes by following these steps -

Right-click the taskbar down below, select "Task Manager"
Select the "Processes" tab

Or - You can also open Task Manager by pressing (CTRL+SHIFT+ESC)

Once you get there, you can see all the processes that are currently running on your computer. This gives you a detailed overview of what exactly is going on in your computer. You can see what process is running, and how much of your system memory are they using.

Here is a list of common Windows system processes that can be found there,

Ctfmon.exe

This is involved with the language/alternative input services in MS-Office. Ctfmon.exe will continue to put itself back into the system startup when you run the MS-Office apps as long as the Text Services and Speech applets in the Control Panel are enabled.

Explorer.exe

This is the Windows Shell - the desktop, taskbar, icons almost everything that you see in windows is controlled by this process

Svchost.exe

Svchost.exe (Generic Host Process for Win32 Services) is an integral part of Windows OS. It cannot be stopped or restarted manually. This process manages system services that run from dynamic link libraries (files with extension.dll). Examples for such system services are: "Automatic Updates", "Windows Firewall", "Plug and Play", "Fax Service", "Windows Themes" and many more.

Winlogon.exe

This controls the authentication of Windows users. It is one of the most important system processes.

Rundll32.exe

This program is part of Windows, and is used to run program code in DLL files as if they were within the actual program. DLL files are a part of the Windows programming.

Csrss.exe

This is the user-mode portion of the Win32 subsystem; Win32.sys is the kernel-mode portion. Csrss stands for Client/Server Run-Time Subsystem, and is an essential subsystem that must be running at all times.

When looking at the processes, you can also see the memory they are consuming, using the task manager process list, you can also close a non-responsive program.

From the security aspect, any Virus, Spyware will show up in this list, so this is a very important tool that you can use when you feel you have a virus or a spyware installed on your computer.

Sometimes you can directly say whether a process is running a virus or not, when you click on it, it will just 'slip' out of your mouse pointer and will change its position, these are the advanced viruses designed to evade from being manually removed.

Antivirus Software

Antivirus software is one of the first and foremost thing that you must install after getting a new system, or after you have re-installed your operating system.

Choosing the right anti-virus software is very important; it is very much dependent how fast your computer is. An Antivirus constantly scans your system's active processes and is vigilant, so as to prevent any threats. With thousands of viruses releasing every day, here are some things to note -

Prevention is better than cure, right?

Antivirus software priority - it should be the first thing you must install after getting a computer.

Never opt for 'Trial version', either purchase a full version, or use the free version with lesser features. The problem with trial version is, that once it is expired, it will stop protecting your system and trouble you with constant security alerts, which means, your computer is at risk while you are battling with security alerts.

Always keep your antivirus software updated, most of the antivirus softwares update automatically. However for some reason if they are not able to, update manually.

So why does it needs to be updated?

Companies that make these softwares release new virus Signatures or 'patterns' every week and in some cases even daily. The antivirus on your computer must learn about those new threats, so it downloads the new patterns from the server, while ensuring that you are protected from the latest viruses.

Virus Sources

There is no prime source of viruses, they can come up from just anywhere. However, here are some things you should be aware of -

EXE Files- Exe files are executable files that windows uses to execute or start any program, application or even a software.

Exe can contain viruses, even spyware designed to track your system, Always scan a file before opening it

Websites - Never accept a link from anyone whom you don't know. There are websites on the internet specially designed to compromise your computer, they may be in a form of internet chat, a forum, a game, or even music.

USB Flash Drives- we all share data, and use USB flash drives to carry our data with us. If you use your disk on an infected system, your disk will catch that virus, and will begin infecting every computer you insert it in. Always scan a USB flash drive before opening it.

Firewall

So what is a firewall?

In simple terms, It is an application that is designed to control and analyze the network traffic coming in and out of your computer.

It is like your pet dog that only allows certain people into your house, while preventing unauthorized people or intruders, at the same time alerting you at various occasions.

So why is a firewall important?

Everything that is in your computer needs to be protected. Your personal documents, photos, financial information, even your passwords. When your computer is connected to the internet, your data is susceptible to theft. Major corporations spend millions of dollars just on firewalls. According to a recent news report, Sony's Play Station was hacked, and a lot of data was leaked. This cost the company millions of dollars.

Taking little bit of care about your computer security and escalating it, can be very beneficial.

Does Windows have an in-built firewall?

For starters, newer versions of windows like the windows 7, has an amazing inbuilt firewall, also known as the windows firewall, It allows granular control over your systems' networking, even defining rules for applications that are installed in your computer.

Windows firewall also has different profiles like 'home network' and 'public network'. This allows easy one click configuration, wherein you change the settings depending on the location you are using.

When you're connected to a public network like a library or a coffee shops' wireless network, you may want to block all incoming connections and can select the public network profile.

At home or work, where you may be sharing files over the network, you can easily switch to the home network profile.

You can access windows firewall by - clicking the Start button clicking Control Panel, clicking Security, and then clicking Windows Firewall.

Make sure that your firewall is set to 'ON'

For advanced users, you can even install a free third-party firewall like "Comodo Firewall". It is one of the most advanced, and free firewalls that I have encountered and the one I personally use. This is however not recommended for basic users, since its configuration requires a very good understanding of the windows operating systems and its architecture, and about TCP/IP.

Security tips and tricks

Be cautious with your computer Administrator passwords, never store them anywhere, always memorize them, they are the key to your system. Someone who is trying to gain remote access to your system won't get through if he cannot guess your password. Try to include a combination of special characters, numbers and letters for your password.

Download softwares only from reputed websites, these include Cnet.com, FileHippo.com, Soft32.com.

These websites never host malicious softwares, and always scan them with an antivirus before hosting them.

Always scan your USB flash drives with your antivirus before opening it.Simply Right-click your disk in My computer, and select 'Scan with' - your antivirus

Run a full system scan every month. This will help removing any viruses that have crawled in.

Never turn off your anti-virus software or your firewall. Many a times people suggest turning them off.

If possible, get a security expert to analyze your computer once a month. A security expert will check your computer in great detail and will suggest you to remove any programs that may compromise your computer.

Windows update - Always use windows update and set it to automatic. Windows updates are critical system patches that escalate your system security or patch any vulnerability that was otherwise found by Microsoft security experts. Many people don't realize the significance of Windows Update,until they are infected.

User account control - User account control is a security feature in windows that should always be 'ON', it prevents the execution of malicious code.

Web Browser - Always update to a newer version of a web browser, they are better, faster and more secure. Because everything today is web-based, security of your web browser is the most important thing.

User Accounts - Always keep the guest account disabled, and create a new administrator account for yourself. Never use the default administrator account.

These are the basic steps that you can use to secure your Windows computer.




Geek-Assist.com is a leading provider of 24/7 online computer support services. Geek Assist also provides security consultation,to help users secure their computer against hackers, viruses, malware, and firewall configuration. Geek-Assist is currently solving hundreds of issues everyday while being one of the most affordable online computer support solutions. Call 888-408-5784 (toll free) Now, to get instant help. To visit geek assist online, click Here




Understanding Windows Web Security


With hundreds of thousands of viruses and trojans just waiting to infect your computer when given the right opportunity, do you really have any reason not to have some form of Windows Web Security?

The Internet is a technological marvel that allows unprecedented levels of communication, but many unscrupulous individuals use the technology to wreak havoc among Internet users by creating viruses and other malware. Protecting yourself against these threats should be your main priority, especially if you use your computer to conduct business online.

Many people do not understand the various types of malware and how they can negatively impact your PC performance, or even expose private data that has no business in the hands of others. Better understanding how these malware programs work will provide you with insight into the protection you need for your computer.

Two of the most common types of malware that affect computers today are viruses and trojans. Viruses are the most lethal to any computer since they can attach themselves to any executable file on your computer, replicate, and essentially destroy your system before you know what has happened. Preventing this type of replication and destruction should be your main priority, which is why an anti-virus is necessary.

Trojans are aptly named since they provide a back door into your computer's network that allows the hacker that spread the trojan the ability to access any personal information on your computer. While trojans do not operate the same as a virus in that they do not destroy your computer, they are just as bad since they provide a back door to personal information. This can be devastating if you have ever used your credit card or bank account online, since the hacker can gain access to that information.

Aside from viruses and trojans that can destroy your computer and leave paths for hackers to collect your personal information, you must also worry about spyware and adware installing themselves on your computer. These are less of a threat than viruses and trojans, but they can directly affect the performance of your computer, bogging it down and eating up precious processing time, causing your computer to respond very sluggishly. To top it off, these sorts of programs usually have some sort of feature that phones home, reporting your browser history and other private details you may not want revealed.

With so many threats to computers in the wild, you can see the benefit of having a secure anti-virus and spyware solution that will protect you when you need it most. When considering a solution for protection, you need to make sure your suite will protect against viruses, trojans, spyware, and adware, otherwise you are paying for a solution that does not have you 100% covered. In addition, an anti-virus suite that auto-updates with the latest virus definitions should be your top priority, so you know you are protected from the latest threats.

Windows web security can be difficult to understand with so many different threats out there, but with the proper anti-virus software installed on each computer in your home, it is something you should not have to worry about, as long as you keep the program up to date.




For more info and free downloadable Windows Web Security software take a look at the Windows Apps website.

Thanks!

Kevin




Understanding Computer Risk, Hackers, and Cyber-Terrorism


In today's environment, millions of people rely on computers to do business, homework, and to dispatch information to others. It is therefore very important to secure the information that we have on our computers. If you are using a computer exclusively, it is your duty to do all you can to reduce computer risks, prevent data loss, and to reduce computer abuse. In the business world, data protection is paramount because a company's data is fast becoming one of the most value asset that any company owns. Keeping your electronic data secure from hackers is therefore most important.

A computer security risk is any action, deliberate or otherwise that could cause lost of information, damage to critical software, or data corruption. Computer security risks also extend to program incompatibilities, or computer hardware obsolescence. Many instances of computer loss or computer damage are planned and are therefore not accidental. Any intentional breach in computer security is said to be a computer crime which is slightly different from a cyber crime. A cyber crime is really an illegal act perpetrated through the Internet, whereas a computer crime will be any illegal behaviour which involves the use of a computer.

There are several distinct groups of people involved in computer crimes and understanding who they are is important. The most popular form of criminal computer acts is broadly known as hacking. In this case, a person uses a network or the Internet to gain illegal access to a computer. Hackers too, have gained much notoriety over the last 10 years because they are seen as representing people who are in rebellion against the systems of society. Some of the more recent names assigned to people posing computer security risks are cracker, cyber-terrorist, cyber-extortionist, unethical employee, script kiddie and corporate spies.

The term hacker was actually used in reference to ordinary people with the ability to break into computer systems legally. However, with the wide-spread use of the Internet, a hacker has now become known for illegal actions. A hacker is defined as someone who accesses a computer or computer network unlawfully. They often claim that they do this to find leaks in the security of a network. Recent developments in computer programming have spawned the term Ethical Hacking. This is an IT-related term for posing as a thief to catch loopholes in your own computer systems. The term cracker has never been associated with something positive this refers to someone how intentionally access a computer or computer network for unlawful or unethical purposes.

A cyber-terrorist is someone who uses a computer network or the internet to destroy computers, websites, or systems for political reasons. The intention here is to cause harm to important systems such as a banking system or a military computer network in order to score political points. Unlike a regular terrorist attack, cyber-terrorism require highly skilled individuals, thousands of dollars to implement, and many months of planning. The term cyber extortionist is used to refer to someone who uses emails or other electronic communication media as an offensive weapon. As an example of this, a cyber-terrorist can access a web-based database, confiscate it, and erase other available copies. They can then demand a ransom for the release of this information.

They could carry out their illegal act by doing other things such as sending a company a very threatening email. The information they may have could be trade secrets, company data, or even personal information about one of the senior officers of the company. By demanding a ransom for not releasing such information through the Internet, they are participating in cyber-terrorism against the company or persons.

Many computer security risks are related directly to disgruntled employees. It is for this reason why many of the top companies in the USA have adopted sections of the Sarbanes-Oxley Act of 2002. Executives of each public company must take personal responsibility for the security of a company's data in addition to truthfulness in accounting practice. All stake-holders must be assured that the data which a company has about a person such as credit cards must be secure at all times. As the Internet grows, only time will tell what other measures will become necessary to reduce computer risk, thwart cyber-terrorism, and mitigate against the impact of hackers and crackers all over the globe.




Anthony writes technology and protecting your computer from online attacks, at: computer risks and writes on many other fascinating subjects as well. Visit him to learn the latest trends, in motivation, personal development. See his fast-rising working from home blog.




Understanding Computer Risk, Hackers, and Cyber-Terrorism


In today's environment, millions of people rely on computers to do business, homework, and to dispatch information to others. It is therefore very important to secure the information that we have on our computers. If you are using a computer exclusively, it is your duty to do all you can to reduce computer risks, prevent data loss, and to reduce computer abuse. In the business world, data protection is paramount because a company's data is fast becoming one of the most value asset that any company owns. Keeping your electronic data secure from hackers is therefore most important.

A computer security risk is any action, deliberate or otherwise that could cause lost of information, damage to critical software, or data corruption. Computer security risks also extend to program incompatibilities, or computer hardware obsolescence. Many instances of computer loss or computer damage are planned and are therefore not accidental. Any intentional breach in computer security is said to be a computer crime which is slightly different from a cyber crime. A cyber crime is really an illegal act perpetrated through the Internet, whereas a computer crime will be any illegal behaviour which involves the use of a computer.

There are several distinct groups of people involved in computer crimes and understanding who they are is important. The most popular form of criminal computer acts is broadly known as hacking. In this case, a person uses a network or the Internet to gain illegal access to a computer. Hackers too, have gained much notoriety over the last 10 years because they are seen as representing people who are in rebellion against the systems of society. Some of the more recent names assigned to people posing computer security risks are cracker, cyber-terrorist, cyber-extortionist, unethical employee, script kiddie and corporate spies.

The term hacker was actually used in reference to ordinary people with the ability to break into computer systems legally. However, with the wide-spread use of the Internet, a hacker has now become known for illegal actions. A hacker is defined as someone who accesses a computer or computer network unlawfully. They often claim that they do this to find leaks in the security of a network. Recent developments in computer programming have spawned the term Ethical Hacking. This is an IT-related term for posing as a thief to catch loopholes in your own computer systems. The term cracker has never been associated with something positive this refers to someone how intentionally access a computer or computer network for unlawful or unethical purposes.

A cyber-terrorist is someone who uses a computer network or the internet to destroy computers, websites, or systems for political reasons. The intention here is to cause harm to important systems such as a banking system or a military computer network in order to score political points. Unlike a regular terrorist attack, cyber-terrorism require highly skilled individuals, thousands of dollars to implement, and many months of planning. The term cyber extortionist is used to refer to someone who uses emails or other electronic communication media as an offensive weapon. As an example of this, a cyber-terrorist can access a web-based database, confiscate it, and erase other available copies. They can then demand a ransom for the release of this information.

They could carry out their illegal act by doing other things such as sending a company a very threatening email. The information they may have could be trade secrets, company data, or even personal information about one of the senior officers of the company. By demanding a ransom for not releasing such information through the Internet, they are participating in cyber-terrorism against the company or persons.

Many computer security risks are related directly to disgruntled employees. It is for this reason why many of the top companies in the USA have adopted sections of the Sarbanes-Oxley Act of 2002. Executives of each public company must take personal responsibility for the security of a company's data in addition to truthfulness in accounting practice. All stake-holders must be assured that the data which a company has about a person such as credit cards must be secure at all times. As the Internet grows, only time will tell what other measures will become necessary to reduce computer risk, thwart cyber-terrorism, and mitigate against the impact of hackers and crackers all over the globe.




Anthony writes technology and protecting your computer from online attacks, at: computer risks and writes on many other fascinating subjects as well. Visit him to learn the latest trends, in motivation, personal development. See his fast-rising working from home blog.




ST04-024: Understanding ISPs

ISPs offer services like email and internet access. In addition to availability, you may want to consider other factors so that you find an ISP that supports all of your needs.

An ISP, or internet service provider, is a company that provides its customers access to the internet and other web services. In addition to maintaining a direct line to the internet, the company usually maintains web servers. By supplying necessary software, a password-protected user account, and a way to connect to the internet (e.g., modem), ISPs offer their customers the capability to browse the web and exchange email with other people. Some ISPs also offer additional services. With the development of smart phones, many cell phone providers are also ISPs.

ISPs can vary in size—some are operated by one individual, while others are large corporations. They may also vary in scope—some only support users in a particular city, while others have regional or national capabilities.

Almost all ISPs offer email and web browsing capabilities. They also offer varying degrees of user support, usually in the form of an email address or customer support hotline. Most ISPs also offer web hosting capabilities, allowing users to create and maintain personal web pages; and some may even offer the service of developing the pages for you. Some ISPs bundle internet service with other services, such as television and telephone service. Many ISPs offer a wireless modem as part of their service so that customers can use devices equipped with Wi-Fi.

As part of normal operation, most ISPs perform backups of email and web files. If the ability to recover email and web files is important to you, check with your ISP to see if they back up the data; it might not be advertised as a service. Additionally, most ISPs implement firewalls to block some portion of incoming traffic, although you should consider this a supplement to your own security precautions, not a replacement (see Understanding Firewalls for more information).

Traditional, broadband ISPs typically offer internet access through cable, DSL, or fiberoptic options. The availability of these options may depend where you live. In addition to the type of access, there are other factors that you may want to consider: Author: Mindi McDowell Copyright 2004 Carnegie Mellon University. Terms of use US-CERT

View the original article here

ST05-018: Understanding Voice over Internet Protocol (VoIP)

With the introduction of VoIP, you can use the internet to make telephone calls instead of relying on a separate telephone line. However, the technology does present security risks.

Voice over internet protocol (VoIP), also known as IP telephony, allows you to use your internet connection to make telephone calls. Instead of relying on an analog line like traditional telephones, VoIP uses digital technology and requires a high-speed broadband connection such as DSL or cable. There are a variety of providers who offer VoIP, and they offer different services. The most common application of VoIP for personal or home use is internet-based phone services that rely on a telephone switch. With this application, you will still have a phone number, will still dial phone numbers, and will usually have an adapter that allows you to use a regular telephone. The person you are calling will not likely notice a difference from a traditional phone call. Some service providers also offer the ability to use your VoIP adapter any place you have a high-speed internet connection, allowing you to take it with you when you travel.

Because VoIP relies on your internet connection, it may be vulnerable to many of the same problems that face your computer and even some that are specific to VoIP technology. Attackers may be able to perform activities such as intercepting your communications, eavesdropping, taking control of your phone, making fraudulent calls from your account, conducting effective phishing attacks by manipulating your caller ID, and causing your service to crash (see Avoiding Social Engineering and Phishing Attacks and Understanding Denial-of-Service Attacks for more information). Activities that consume a large amount of network resources, like large file downloads, online gaming, and streaming multimedia, may affect your VoIP service.

There are also inherent problems to routing your telephone over your broadband connection. Unlike traditional telephone lines, which operate despite an electrical outage, if you lose power, your VoIP may be unavailable. VoIP services may also introduce problems for location-dependent systems such as home security systems or emergency numbers such as 911.

Author: Mindi McDowell Produced 2005 by US-CERT, a government organization. Terms of use US-CERTLast updated November 15, 2010

View the original article here

ST06-006: Understanding Hidden Threats: Corrupted Software Files

Malicious code is not always hidden in web page scripts or unusual file formats. Attackers may corrupt types of files that you would recognize and typically consider safe, so you should take precautions when opening files from other people.

An attacker may be able to insert malicious code into any file, including common file types that you would normally consider safe. These files may include documents created with word processing software, spreadsheets, or image files. After corrupting the file, an attacker may distribute it through email or post it to a website. Depending on the type of malicious code, you may infect your computer by just opening the file.

When corrupting files, attackers often take advantage of vulnerabilities that they discover in the software that is used to create or open the file. These vulnerabilities may allow attackers to insert and execute malicious scripts or code, and they are not always detected. Sometimes the vulnerability involves a combination of certain files (such as a particular piece of software running on a particular operating system) or only affects certain versions of a software program.

There are various types of malicious code, including viruses, worms, and Trojan horses (see Why is Cyber Security a Problem? for more information). However, the range of consequences varies even within these categories. The malicious code may be designed to perform one or more functions, including

interfering with your computer's ability to process information by consuming memory or bandwidth (causing your computer to become significantly slower or even "freeze")installing, altering, or deleting files on your computergiving the attacker access to your computer using your computer to attack other computers (see Understanding Denial-of-Service Attacks for more information)Author: Mindi McDowell Produced 2006 by US-CERT, a government organization. Terms of use US-CERT

View the original article here