Share


Share

Share it !



share/bookmark

NCSA Study Shows Many Computers Lack Antivirus Protection


Even with the scads of information available, even with the numerous antivirus options available to consumers, and even though internet users are inundated with offers for antivirus and anti spyware programs, it seems that some people prefer to take their chances when it comes to infecting their computers. According to the second annual AOL/National Cyber Security Alliance (NCSA) Online Safety Study, fewer than 60 percent of survey participants had antivirus protection software installed on their computers, and those who do fail to update it more than once a week.

Studies show that anywhere from 200 to 600 new viruses and other online infections are released each month, and the NCSA reports that 23 percent of Americans are each month affected by phishing attacks. Additionally, 81 percent of protected computers are not fully protected - very few users have the necessary trio of updated antivirus software, spyware protection, and a secure firewall. According to the survey, however, 83 percent of participants thought themselves secure from online infections.

Viruses, spyware, adware, and other malware all have the potential to pose a serious threat to your computer, not only to the hardware itself but to your personal information and identifying details. A good antivirus security suite should be able to detect and cure viruses, spyware, adware, worms, trojans, malicious code, malware, and keyloggers, all of which can do grave damage to your computer. Updating your software daily and scanning regularly for any unfamiliar or suspicious files on the computer, including archives, email, and instant messages, is also a necessary step in catching and preventing infection.

Due to the sheer number and variety of online threats, it's difficult to keep track of them specifically by name. However, the basic threats you should watch out for are as follows:

Spyware: A program that gathers personal information logged in your computer by noting your internet browsing habits and recording your keystrokes and passwords. It can also hijack your browser settings, redirect your search queries, and transfer any noted information to third parties for the purpose of identity theft.
Virus: Viruses infect the files on the computer and spread by replicating themselves. A virus can also be spread by email, and will automatically mail itself to people in the address book of the account it infects. Though worms and Trojans are not technically viruses, they often fall into the subcategory of "virus." A worm is a piece of software that replicates itself via security holes in networks, infecting vulnerable machines by copying itself and spreading to any other connected, unprotected computer. A Trojan horse is a program that masquerades as a benign application, but actually will damage your computer if you try to run the program.
Adware: Adware generates revenue by displaying advertisements on your screen, offering links to follow that take the user to the advertised website. Third parties then collect money for every hit on that site. Some adware programs gather personal information about you and select ads to display based on your browsing habits.


To be fair, the age of the browser might have something to do with the high instance of computer infection.The NCSA states that homes with children are more likely to have their computers infected by spyware or adware. In fact, more than 69 percent of homes with children under 18 were infected. But don't blame it all on the kids - 58 percent of child-free households had their fair share of spyware and adware infection.

With so many viruses, spyware, and other malware clamoring to infect your computer, it is essential to have in place the necessary preventative tools to catch and eliminate online infections. The fact that so many new threats are released on such a regular basis is not an accident - hackers and the writers of malicious code are targeting those who mistakenly think that using only a firewall or updating once a month will keep their computers safe. Persistence and diligence in keeping your software, updates, and antivirus protections software current can help ensure your information and computer access remain yours and yours alone.




http://home.stopsign.com




UAC Standard User Behavior

This security setting determines the behavior of the elevation prompt for standard users

The options are: Prompt for credentials: An operation that requires elevation of privilege will prompt the user to enter an administrative user name and password. If the user enters valid credentials the operation will continue with the applicable privilege. Automatically deny elevation requests: This option results in an access denied error message being returned to the standard user when they try to perform an operation that requires elevation of privilege. Most enterprises running desktops as standard user will configure this policy to reduce help desk calls.

Default: Prompt for credentials (home) / Automatically deny elevation requests (enterprise)


View the original article here

How Safe Is Your Computer Data?


As recently as December 2007, a New Zealander was subject to an FBI investigation on world-wide cyber crime which also resulted in Dutch authorities imposing strong penalties on companies using his malicious software.

Managing data security is unavoidable in today's business environment and is a critical task for many. But what has all of this got to do with the small business owner?

Perhaps the cost of your laptop or your office personal computers does not amount to that much in the grand scheme of things. Have you ever stopped and wondered how long it would take to replace the data that you stored on them; or what damage losing customers' sensitive data would have on your business.

I recall an ex-colleague at a large, international accounting and consulting firm whose laptop was stolen from his car. He stored valuable information about several blue-chip clients' projects he was working on his hard drive. Not only did he lose the only copies that the firm had (which meant that weeks of work was lost) but he potentially put the firm at serious risk of bad publicity and losing major clients.

How well do you protect your computer hardware and data? How much would it cost to replace them? The following are just a few tips to help protect you.


Use Anti-Virus software and keep it software up-to-date. Hundreds of new viruses are discovered each month. You are not just protecting yourself when using virus software, but also others you communicate with.
Always use a Firewall - A firewall is an "internal lock" for information on your computer. Many computer operating systems already have firewalls installed and you must activate them. There are many other firewalls available to download or buy that help you secure your computer.
Learn the risks & rules associated with sharing files or your internet connection. You can be exposed to danger via e-mail, file-sharing, a broadband connection or a wireless connection
Disconnect from the net when idle. If you're not using your net connection, (when you go to bed as an example) turn it off. It's much harder to hack your computer when it is not connected. This is especially important if you have a high-speed connection.
Use strong, unique passwords and don't share them with anyone & back up your data frequently
Take immediate action if you think you have been hacked or infected by a virus and contact your ISP

Protecting your information can be a major deal for a small business owner but using the proper tools can ease the burden significantly. Such efforts will dramatically reduce the chance of a major security breach and also the costs and damage to your company's reputation that such an event causes.




Mark Gwilliam, FCCA, uses his international experience to coach small business owners on how to run successful businesses. He combines his natural enthusiasm for sharing his knowledge with his proven ability to provide practical down-to-earth solutions for his clients. He has written several books and owns several companies which offer small business owners integrated business solutions. He writes several business articles in his weekly newsletters "The Bizness" and "Successful Marketing Strategies". To read these and to have access to more tools and resources to turbo charge your business, visit his sites at http://www.mark-gwilliam.com and http://www.themarketingdude.com




Secret Passage

Network and security administrators sometimes evoke images of the Little Dutch Boy from Hans Brinker who stuck his finger in the dike to plug a leak, except for network and security administrators every time they plug one leak a new one springs up. They implement file attachment filters and antivirus scanning on the corporate email servers only to have users access web-based email like Hotmail and sidestep the security. Every time administrators think they have the network locked down some other method of entry pops up- instant messaging, wireless devices, USB hard drives, etc..

Some of these things can be eliminated through firewall or content filtering rules to deny users access to sites that pose a potential security risk. Other things are harder to control except through strict policies and procedures specifically prohibiting certain actions or technologies from the company network and then monitoring and policing to enforce compliance.

Many companies have already addressed the issue of wireless device security. Initially many companies and individuals jumped onto the wireless networking bandwagon for the convenience of being able to wander un-tethered by network cables or being able to deploy more workstations without having to run network wiring through the walls and ceiling. However, many of those wireless networks used no security whatsoever and the ones that did used WEP encryption which proved to be barely better than having no security. This is still a serious problem for many wireless networks, but wireless security has improved drastically.

Douglas Schweitzer, author of Incident Response and columnist for Processor.com, says “There's no denying that wireless networks can help to increase worker productivity and often produces a considerable ROI for organizations with large, mobile workforces. However, it is important to note that there are significant risks involved from any unprotected wireless network. To mitigate these risks, organizations interested in deploying wireless networks should consider a defense-in-depth (layered approach) to security that involves both procedural and physical components such as policies and intrusion detection/prevention. Used in conjunction with firewall and anti-virus, network security administrators can successfully lock down their wireless networks.”

So, now we come to the administrator with all 10 fingers already occupied plugging different holes in the dike: malware, spam, denial-of-service attacks, USB devices, web-based email, etc. and thinking that the network is relatively secure and along comes remote access.

Whether it’s a business partner that needs remote access to the company network in order to facilitate work or company employees or executives that need to access the company network from their home computers in order to remain productive during “off” hours, remote access can create a number of security risks for your otherwise secure network.


View the original article here

Critical Linux Flaws

Last week three new vulnerabilities were announced by Polish security firm iSec Security Research in the latest Linux kernel which could allow an attacker to elevate their privileges on the machine and execute programs as the root administrator.

These are just the latest in a series of serious or critical security vulnerabilities discovered in Linux over the past few months. The board room at Microsoft is probably getting some amusement, or at least feeling some relief, from the irony that open source is supposed to be more secure and yet these critical flaws continue to be found.

It misses the mark though in my opinion to claim that open source software is more secure by default. For starters, I believe that the software is only as secure as the user or administrator who configures and maintains it. Although some may argue that Linux is more secure out of the box, a clueless Linux user is just as insecure as a clueless Microsoft Windows user.

The other aspect of it is that the developers are still human. Out of the thousands and millions of line of code that make up an operating system it seems fair to say that something might get missed and eventually a vulnerability will be discovered.

Therein lies the difference between open-source and proprietary. Microsoft was notified by EEye Digital Security about the flaws with their implementation of ASN.1 eight months before they finally announced the vulnerability publicly and released a patch. Those were eight months during which the bad guys could have discovered and exploited the flaw.

Open source on the other hand tends to get patched and updated much faster. There are so many developers with access to the source code that once a flaw or vulnerability is discovered and announced a patch or update is released as quickly as possible. Linux is fallible, but the open source community seems to react much quicker to issues as they arise and respond with the appropriate updates much quicker rather than trying to bury the existence of the vulnerability until they get around to dealing with it.

That said, Linux users should be aware of these new vulnerabilities and make sure they stay informed of the latest patches and updates from their respective Linux vendors. One caveat with these flaws is that they are not exploitable remotely. That means that to attack the system using these vulnerabilities requires the attacker to have physical access to the machine.

Many security experts agree that once an attacker has physical access to a computer the gloves are off and almost any security can be eventually bypassed. It is the remotely exploited vulnerabilities- flaws that can be attacked from systems far away or outside of the local network- that present the most danger.

For more information check out the detailed vulnerability descriptions from iSec Security Research to the right of this article.


View the original article here

Computer Security - 7 Tips to Keep Your PC Safe From Internet Attacks


When it comes to PC safety, many of us live in a world of complete ignorance about the dangers out there on the internet. We simply don't think we will be the victim of a cyber attack, but without a doubt it will happen eventually.

Unfortunately, much of the well-meaning advice we get on the subject of internet security is still not enough to combat the cyber-crime that is becoming more widespread. The best we can do is take preventative steps to make the baddies job more difficult.

It happens to the most security-conscious of us...

Even though many of us could be highly vigilant and never open electronic mail attachments from folks we don't know, and look to make sure an ecommerce site is safe before entering our bank card info it can still happen.

The fact is, nobody is completely safe online, but taking computer security seriously is a big help.

There is little doubt that spyware and adware, malware, and insidious virus assaults make any pc with internet access vulnerable to attack. But, not all web security breaches are instantly apparent. As a matter of fact, most people are often unsuspecting that their seemingly safe browsing session is fraught with hidden dangers.

Now that you understand the scale of the problem, here are seven pointers to assist you to surf the Internet safely and protect your PC from attack.

1. Protect yourself from ID theft.

When making a purchase on an ecommerce site, make sure that the page where you enter your personal info is secure, as specified by "https" in the URL shown in the browser address bar. And never download ''warez' and cracked software as you can guarantee they contain trojans that will spy on you and steal your private information.

Obviously, the most ridiculous thing you could ever do is download a cracked antivirus program or some other computer security program as it will contain exactly the things that it is supposed to protect you from. Always buy computer software from a reputable source or you are just asking for trouble.

2. Be careful before you click on an email link.

Many cyber-criminals impersonate respectable companies, and send out a "phishing" e-mail that asks you to click on an email link. By no means click on email links unless you are sure of the source. Usually you can just hover over an email link to see the actual internet address it goes to, but not always. If it looks suspicious, then don't click on it as it will more than likely send you to a website that is designed to steal your financial details.

3. Update anti-virus, anti-spy ware, and firewall software often.

The worst part is, hackers and others who engage in cyber-crime seem to forever be one jump ahead of the latest computer security software. In the case that your computer protection is outdated, you're vulnerable so keep it up to date. Most software can be configured to do this automatically, which is a good thing for those who are forgetful or too busy to check for the latest security updates.

4. Use an internet browser and computer operating system that has good security features.

Make certain your browser settings provide you with optimal privacy and security, and make sure that you update your operating system regularly to reap the benefits of the latest security patches. Many browsers now block malware and you can also install software that will integrate with your browser to protect you whilst surfing.

5. Use secure online passwords at all times.

For example, create a single password for every site you go to, and keep them in a secure place. Use letters, numbers and other symbol mixtures in an effort to outmaneuver automated password detection programs. The harder your password is to guess the more safer you will be,so don't be lazy and skip this vital point. There are some open-source password keepers that will create and store all your passwords in case you forget them.

6. Make sure you do regular backups.

In the case your PC ever does get a virus infection or a worm, your important data could also be lost. Be sure that you regularly back up any important data and store them in a safe place. It might take a little setting up but you will be glad that you did if ever disaster strikes and your valuable data is corrupted or destroyed.

7. Be geared up for all eventualities.

If something does go wrong, such as your computer being hacked or contaminated with a virus, or for those who by chance reveal private data, plan a course of action to remedy the situation and stop further problems in the future. Like they say, prevention is better than cure.

Conclusion

Protecting your financial and private info from all the threats in cyberspace can appear to be an impossible mission. Thankfully you can find many software vendors who make it their business to supply individuals and companies with robust computer security solutions.

They will help to keep your computer secure from the many threats which stem from the modern bandits of our time, who infest the internet and make safe computing more and more difficult for us innocent surfers.




To find out how to protect your computer from internet attacks and allow you to surf the internet in safety please visit PCRegistryMedic.com for advice on many aspects of safe computing




How Do I Patch My PC?

Question: How Can I Keep My Computer Patched and Up To Date?

When it comes to weight management, there are a thousand "solutions", but one mantra seems to be at the crux of the successful ones: "eat right and exercise". No matter how you slice it, "eat right and exercise" is a part of staying healthy and watching your weight.

Similarly, in computer security there may be a thousand security tools to help protect your computer, but one mantra that keeps coming up is to "keep your PC patched and updated". Sounds simple enough.

So, how do you do it? You're not a computer expert or technical guru. So, how can you keep your computer patched and up to date?

Answer: There are a few different things that you can, or should, do to make sure your computer is kept up to date and has the necessary patches to keep it safe from known vulnerabilities. You should configure Automatic Updates in Windows to make sure you are getting the Critical updates as soon as possible. You should also check the Windows Update site or use Microsoft Update periodically to make sure you get other, non-critical updates. Lastly, you can use the free Microsoft Baseline Security Analyzer (MBSA) tool to scan your computer and identify any missing patches or other security issues. Use Automatic Updates: Automatic Updates provide a method to ensure that your Windows computer gets at least the Critical updates. Things like feature changes and device driver updates won't come automatically with Automatic Updates, but at least your computer will be protected against the vulnerabilities most likely to compromise its security.

To configure Automatic Updates in Windows XP with SP2, click Start | Control Panel | Security Center, then click on Automatic Updates.

To enable Automatic Updates, click the radio button next to Automatic (recommended). You can choose how often and at what time Automatic Updates should check for new data from Microsoft. You can also select what to do with the data. You can opt to only be notified about new updates, or you can be notified and have new updates downloaded, but not installed until you do it yourself manually.

The whole point is that it is supposed to be "automatic" though, so most home users should simply select Automatic and choose a day or time that is convenient. If your computer is on 24/7 on a broadband connection, I recommend setting it to download late at night while you're sleeping, like 3am.

Periodically Visit the Windows Update Site: Automatic Updates is great for Critical patches, but every so often you need to check to see if there are other updates you need. At least once a month, you should check the Windows Update site to see what you're missing. To get to the site from Windows XP, click on Start | All Programs | Windows Update. You can choose between the Express option, which only downloads high-priority updates, or the Custom option, which will show you all available updates for Windows and let you choose which ones to install.

Windows Upate, as its name implies, is Windows-centric. It only scans for and notifies you regarding updates to the Windows operating system. Microsoft has introduced a new, more comprehensive update program as well, called Microsoft Update. If you haven't already installed it, you should see a link or notice somewhere on the Windows Update page where you can learn more.

Microsoft Update will let you know about patches and updates not only for the Windows operating system, but all Microsoft products including Office and other Microsoft applications. It won't update your other, non-Microsoft products, but at least it provides 'one-stop shopping' to update your Microsoft software.

Check Your System With Microsoft Baseline Security Analyzer (MBSA): Microsoft has a free tool called MBSA, or Microsoft Baseline Security Analyzer. The tool, among other things, will scan your system and identify known flaws or vulnerabilities that are not patched. The report it provides you includes links to the necessary information so that you can download and install the updates as well.

MBSA also analyzes other security concerns on your computer such as whether or not there are accounts with no password, or whether all of the user accounts have full Administrator access privileges. It may be a bit 'techie' for many home PC users, but the information is good to know and the price is right since the tool is free.

The report generated quickly identifies which findings are Critical and which findings are not a major concern. It also lets you know the areas where your PC security meets or exceeds Microsoft's baselines standards, which is nice to know as well. You can click here for more details about the MBSA tool.


View the original article here