Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Cyber Bullying - The Evil Side of Technology

Friday, July 10, 2015
What is Cyber Bullying?
It is the utilization of technology in any of its forms, to harass, intimidate, threaten, or harm an individual with an intention to do so. It can happen in several forms, both small and huge. And the repercussions it has on the lives of its victims can be just as varied.
How does it work?
It can be directly launched, or indirectly carried out. The former involves direct messages and letters or calls to the victim, while the latter involves passive bullying, by involving a proxy or an accomplice. The proxy or the accomplice might be involved either knowingly or unknowingly.
Why do people get into the practice of Cyber Bullying?
The ways of the human mind are many and twisted. Psychologists have researched and tried to explain a great many number of human behaviors. But this is a grey area, and the reasons why human beings engage in any harmful or victimizing activities vary from case to case. And so it is with cyber bullying too.
But like most acts of passive terrorism, cyber bullying is motivated by repressed anger, anxiety, hatred, frustration, and general negativity. There are some cyber bullies who engage in this wrong deed merely because it gives them a sense of power, or turns out to be a form of entertainment. These kinds of people are borderline psychopaths, say psychologists.
However, all said and done, the motive behind each case of cyber bullying is unique, and needs to handled or dealt with on a case to case basis, instead of being considered as a generality. It is one of the important things to remember.
What are the consequences of Cyber Bullying?
It can leave scars that last a lifetime. The victim can be affected in any manner, depending upon their constitution and tolerability. Sometimes, victims are not even aware of how the experience affected them, until the effects surface years, or decades later. Some of the common effects of traditional bullying, on the victim, include -
• Anxiety and depression
• Inability to trust
• Paranoia and other disorders
• Fear of technology
• Self harming
• Suicide
These are just a few prevalent examples. There are several other traumas that cyber bullying could cause.
What can you do to help?
The most effective way anyone can help to stop or reduce traditional bullying is to report any case of this wrong doing, and to raise today's kids in the right manner.

Read more ...

Digital Privacy in 30 Seconds

Friday, July 10, 2015
In the technology business, I'm what's known as an "early adopter." I'm the guy who gets the new device or software early on, eager to see how it works and whether it's an improvement on existing products. I've picked some winners (flat screen monitors) and losers (BlackBerry). Friends and family know to consult me before buying new gadgets since at the very least I've investigated them, even if I haven't used them myself.
Of course, technical challenges go with the "early adopter" territory. Years of trying to make early-release versions of software and hardware play nice with other products has left me adept at figuring things out quickly. And that, in turn, makes me the "techie" kid in the family to my parents.
So when my father emailed me the other day asking how to deal with the latest shocking news about digital privacy threats, I had an answer for him immediately.
Inactivity is Golden... to Data Bankers
You can avoid some of the worst digital privacy threats in 30 seconds if you want to. Read on and I'll show you how.
But first, let's define the scope of the challenge. Imagine you receive a diagnosis of a deadly disease. You're in shock and afraid for your future and your family. You go to the Internet and search for your diagnosis, so you can learn as much as possible as quickly as you can. Why not? Seventy-two percent of U.S. internet users look up health-related information online.
A few moments later, as you continue your internet knowledge quest, you notice strange advertisements popping up alongside the articles you're reading. Obscure medicines. Miracle cures. Hospital groups specializing in your disease. Oh, and ads for funeral services, as well. (I'm not making that up: It has actually happened.)
"What the?!"... you sputter, indignant.
Welcome to the brave new world of targeted advertising, where people are using your misfortune for profit... if you let them.
You DIDN'T Consent to THAT
In April 2014, a researcher at the University of Pennsylvania designed software to analyze the top 50 search results for nearly 2,000 common diseases, linking to over 80,000 web pages. The results were startling: 91% of the pages passed on your request to outside companies. Medical websites are "basically calling up everybody in town and telling them that's what you're looking at," as researcher Tim Libert puts it.
That's because these websites make what are known as "third-party requests." You, the first party, submit a search term ("pancreas") to a website, the second party. The website then passes that information along to data-mining companies who assemble that information in real time and follow you across the web, using it to send advertising tailored to you... which would be nice, maybe, if you were searching for shoes, but not now.
There are no laws governing their use of your personal information. Zero, zip, nada.
This isn't always intentional. Many developers who design websites use tools like Google Analytics and social media "share" buttons on their sites because they're free and handy. Most users, on the other hand, have no idea that these little bits of code share information about their searches with third parties.
A Simple Solution
I don't get those sorts of advertisements - and not just because I'm healthy as far as I know. In fact I hardly see any ads, and those that I do are random.
That's because when I surf the web, a little applet called Privacy Badger is active on my browser. I also use other apps like AVG Privacy Fix and Disconnect. They block the tracking code that the third-party data miners use to track me and generate ads for me. They install in seconds and require no settings or maintenance.
Just to be safe, I've also set my browser to delete all third-party "cookies" (bits of tracking code) every time I close it. I've set my Google account not to save my search history. And if I'm really doing something delicate, like searching for information on the National Security Agency, I use incognito mode.
I've been doing this for a while now, and it hasn't affected my internet experience at all... except, of course, I don't get hassled by companies trying to make money off my privacy.
You're only a few clicks away from joining me.
Ted joined The Sovereign Society in 2013. As an expat who lived in South Africa for 25 years, Ted specializes in asset protection and international migration. Read more of what he has to say about offshore living here.

Read more ...

The Multi-Layered Onion of Computer Security

Friday, July 10, 2015
As most are probably aware, corporate and home networks are typically connected to the Internet 24 x 7, exposing them to the vast array of malevolent software circulating on the Internet.
Because of this, companies design and continuously improve upon network/IT Security architectures which utilize a layered approach to provide security for their networks and computing environments.
To paraphrase (OK... plagiarize) the immortal dialogue between Shrek and Donkey:
Shrek: For your information, there's a lot more to IT SECURITY than people think.
Donkey: Example?
Shrek: Example? Okay, er... IT SECURITY... is... like an onion.
Donkey: It stinks?
Shrek: Yes... NO!
Donkey: Or it makes you cry.
Shrek: NO! LAYERS! Onions have layers. IT Security has layers. Onions have layers... you get it? Both have layers!
Donkey: Oh, both have layers... You know, not everybody likes onions... CAKES!
Everybody loves cakes! Cakes have layers!
So, take your pick. Whether you choose the onion or cake analogy, a well designed IT Security architecture consists of multiple layers to frustrate and prevent would be hackers from getting into the network to wreak their havoc and compromise confidential data.
To mitigate potential risks to the health of corporate networks and IT environments, most companies use several security layers to help protect against known and unknown viruses and denial of service attacks.
Some of these layers include:
• Firewalls to limit access to/from the Internet
• Intrusion Detection/Prevention system to guard against and distribute alerts of potential attacks against the network
• Vulnerability scanning of critical servers for known vulnerabilities
• File attachment blocking - specific attachment types are blocked from being delivered to end users - based on best practices as determined by anti-virus vendors.
• Bi-directional scanning of Email for known viruses
• Scanning of workstations and file servers for known viruses - both real-time as files are being opened or saved, and on a periodic basis by doing a full disk scan
• Scanning of web sites for potential malware and, if detected, denied access
• Periodic penetration testing to insure perimeter measures are effective
• Black hole DNS - known "bad" websites cannot be accessed
There is always a window of opportunity that exists between the time a misguided techie releases their creation into the wild and the time it takes for the Anti-virus vendors to identify it and release new pattern files to their subscribers. That is why a majority of companies block specific types of files from being automatically delivered to recipients.
Contrary to what some folks believe, most IT departments do not try to prevent users from getting their jobs done! They do, however, try to take appropriate steps to minimize the risk to their entire network and, therefore, all the users, by utilizing the different layers of the security onion.
After all is said and done, end users provide the final layer of protection. Each user is the "heart of the onion." Regardless of the steps taken to protect the corporate IT infrastructure, IT departments ultimately rely on an informed and educated user population to be aware of the dangers presented by unsolicited Email, file attachments, embedded links, and web sites they access.
Without an informed/educated end-user population, companies' and individual users' confidential/personal information is at risk.
Does your company have a security awareness campaign to inform and educate the heart of your security onion? It should!

Read more ...

Truecrypt: Essential for the Hard Drive Data Security

Friday, July 10, 2015
Data safety and security is a huge concern in the modern day IT era, mainly because crimes like data stealing, and data breaching is rising at an alarming rate. Generally, data safety brings the idea of data Internet security. Thus, a lot is being done to keep online data encrypted. But even the data on your computer hard drives and external hard drives needs encryption security. Hard drive encryption straight away reminds of TrueCrypt. This article talks how whole drive encryption software can keep your data secured.
Data Encryption is Imperative for Security
Data encryption is very much pivotal for the protection of the data stored on the hard disk drives of computers used by individuals, government organizations or corporate houses. Rise in data breaching or stealing is possibly the major cause of concern considering that one must encrypt the file of every each and every sensitive piece of information. Nowadays, for everything you have the password system, for instance, password for the computer or password for your user accounts.
But passwords are efficient in keeping the data safe until the time the data is on the hard drive of your computer or server or till the password is not hacked. But if somehow the data can be stolen physically or online, or the password gets hacked, then the password security gets useless. In such a scenario, only encryption can save your information. Encrypted data is always safe even if it's right there in the hands of the wrong persons. That is because the encrypted data is never in a readable format, and thus no one will be able to read it or find sense in it. Thus, apart from using passwords, one must get the whole hard drive encrypted.
Thus, individual and corporate users must use a tool to get their data encrypted because the requirement of data security can't be ignored. If your data in your hard drives has encryption security, then you get the right security coverage and also the assurance that now your data is no more easily accessible.
TrueCrypt- Still Safe to Use
When the talk is about whole disk encryption, TrueCrypt is a highly popular software. Within a short span of time, especially after the release of Window 8, it flourished in the market as a pioneer tool of its type. This cross-platform tool also supports OS X and Linux along with Windows. Millions of people chose this tool because of its security effectiveness, easy interface and cross-platform usability. Although, operating systems come with the inbuilt encryption tool, still this whole disc encryption tool is high in demand because it easily overcomes the challenges that other encryption processes put on the application systems.
It stands tall to the expectation of the users on parameters like cost and charges, performance implications, and key management issues. Many users and businesses give a second thought to data encryption considering the aspects mentioned above. But this hard drive encryption tool is a freeware utility, and it is highly reliable which gets showed up from the market demand for this website.
You will be astonished to know that despite its official call off by its owners, people still want the software back. As a result of that there occurred the urgency to conduct an audit of this data encryption tool. TrueCrypt is a too good tool to pull its shutter down. Its owners officially announced that they are no more releasing updates for the software, and thus it is no more safe to use. But on users' demand, NCC Group, an information security consultancy group, conducted an audit of the tool to find out its vulnerabilities and the chances of its safe usage.
Users of this whole-disk encryption tool will be happy to learn that the audit findings reveal that the tool doesn't have as such any severe security flaws.
Conclusion
As it is officially no more safe for use so, it's better not to use it for a while. However, the NCC group audit report is confirming that the tool has no as such security flaws, and it is safe to use. So soon the tool might become officially available for use once again. But till that happens better use other alternative options like VeraCrypt and CipherShed. This freeware has the same TrueCrypt code.
Russell Winters is an ardent technician associated with Qresolve pc security support with wide experience of fixing issues with PCs, laptops, tablets and smartphones. With a strong track record of devising effective ways of computer security and system security, she has so far helped thousands of users across the globe. Her writings on tech issues are the reflection of her in-depth interest and command she carries as a laptop support technician. Her blogs and articles have been rated high for their lucid style and easy to understand language.

Read more ...

RoboForm Tutorials: Managing "Search Box" and Using It

Friday, July 10, 2015
Growing online threats and malicious programs may steal your private information and use it for fraudulent purposes. You will require installing a smart password application to prevent theft of passcodes and personal information. Read the tutorial below to know how you can use the application's 'Search Box' in an efficient manner.
There are plenty of free password managers available in the market today, but selecting the one that can meet you requirements is a difficult task. Most of such applications lack form filler support and may put your entire personal details section in danger. RoboForm is a smart yet effective passcode management program that comes with specialized tools and features to handle your crucial personal details. The tool can work as a form filling software and can complete multiple forms in a few minutes, to ensure a safer and faster online experience. You might have read reviews about this password application, but they may not contain details about its 'Search Box.'
Read this article to know more about the application's search box and learn a few tips to use it efficiently:
What is 'Search Box' and How You Can Use It?
The Search Box is located between the 'RoboForm' button and 'Logins' button on the application's toolbar. If you're not using any browser windows, then you can reveal the search box by moving the mouse over the application's taskbar icon. Alternatively, you can also manage the visibility of the feature by navigating to Options -> General -> Auto show/hide Search Box.
The feature is easy to use, and you can simply find the matching passcode entry, Identity, Safenote, or other matching files by typing a word or a sentence. The application will showcase the search results within a few minutes and you can select the desired entry from the list. Additionally, the feature will also showcase the possible actions you can perform with a respective enter.
Pressing the Enter key will apply the first action in the list and execute it to produce the desired results. Alternatively, you can also use the up-down arrow buttons or mouse cursor to select another search choice and their respective actions.
Read below to understand more about this feature and learn using it an efficient manner:
1. Default Action
After you select an item in the Search Box, its default action will get executed. You can change the action by selecting your desired entry from the list that appears. The following components of the application will have the respective actions set, by default:
• Default action for 'Passcards' is 'Login.'
• Default action for 'Bookmarks' it is 'Go To.'
• Default action for 'Safenotes and Contacts' is 'Edit.'
• Default action for 'Identities' is 'Fill Forms.'
• Default action for 'Search Engines and SearchCards' is 'Search.'
2. Alternative Actions
The feature allows you to perform the right-click command to change the default actions assigned to a particular application component. You will require right-clicking the item in the search box list, and then selecting an alternative action to get applied to the desired search result entry. The feature will come handy while performing various actions using a simple click. If you wish to edit the 'Passcard' entry, then you can right-click it and select 'Edit' from the menu that appears. Right-clicking the entry will give alternative action choices to the user, and you can select the same depending on your requirements.
3. Finding Passcard, Safenote, Identity by Name
You can type anything in the search box, and it will represent the matching Passcards, Safenotes, and Identity names. Once you have typed a string, it will scan the entire application to look out for possible matches that may contain the string fully or even as a part of their name. Typing less than three characters in the search box will display Passcard, Safenote and Identity names beginning with the typed sequence.
4. Search for String in File Contents
If you think that the search query you're entering is unable to showcase the desired results, then modify it by making a few adjustments. Type a word in the search box and select the "Search 'word' in RoboForm Files" option to narrow your search results. The application will now search for the specific word in the bodies of all RoboForm files and thus present the list of entries containing the relevant details.
5. Query Search Engine
For Yahoo
• Type a sentence or a phrase in Search Box.
• Select the "Search 'phrase' in Yahoo" option or simply press the 'F3' key.
• The application will search the typed phrase in Yahoo search engine.
For Google
• Enable the "Search 'phrase' in Google" option or "Any other search engine" option by navigating to Options -> Search.
• Type a sentence or a phrase in Search Box.
• Press the 'F6' key to search the typed phrase in Google.
Conclusion
The password application can help in ensuring complete security of your valuable data and information. The 'Search' feature of the application facilitates the form filler process by displaying the matching names or keywords in the search results. There are plenty of free password managers available over the web, but they may not fulfill the requirements of a user looking for a passcode filling software. You can browse to the official website of the application to know more about the feature.
Russell Winters is an ardent technician associated with Qresolve remote computer support with wide experience of fixing issues with PCs, laptops, tablets and smartphones. With a strong track record of devising effective ways of internet security and system security, she has so far helped thousands of users across the globe. Her writings on tech issues are the reflection of her in-depth interest and command she carries as a laptop support technician. Her blogs and articles have been rated high for their lucid style and easy to understand language.

Read more ...

A New Kind of Ransomware Is Hurting Small Business

Friday, July 10, 2015
Criminals have stolen valuable assets and kidnapped people for ransom for thousands of years. As society became more sophisticated and technologies advanced so did criminals. It isn't a surprise that the Internet has brought supersized new opportunities for the bad guys. One of the newest opportunities is crypto-ransomware.
Crypto-ransomware became much more prevalent in 2014, but this isn't the kind of ransomware you may be used to hearing about. Just a few years ago, ransomware relied on tricking computer users with phony warnings like the computer is infected, pay this fee to clean up "viruses" that aren't really on your computer or scaring the computer user saying he must avoid fines from police for a crime he didn't commit.
The new form of cyber crime can stop a business instantly by using malware to freeze all the files and documents until a ransom is paid. Symantec's latest report says it is one of the fastest growing threats to small and mid-sized businesses on the Internet.
Criminals use malware to encrypt the information on the hard drive then hold a victims files, photos and other information on the computer hostage. They demand payment to receive a key to unlock the files. The cost can be steep. It is usually $300 to $500 in bitcoins, enough in U.S. currency to severely harm a small or mid-sized business. Even after the ransom is paid there is no guarantee the files will be de-encrypted.
Symantec in their 2015 Internet Security Threat Report stated ransomware attacks grew 113 percent in 2014, driven by more than a 4,000 percent increase in crypto-ransomware attacks. Ranosmware attacks more than doubled in 2014 from 4.1 million in 2013 to 8.8 million. Crypto-Ransomware expanded from 8,274 in 2013 to 373,342 in 2014. That's 45 times more crypto-ransomware in the threat landscape within a one-year span.
Small and mid-sized businesses should be concerned
Symantec's report stated 2014 was a year of far-reaching vulnerabilities, faster attacks, files held for ransom, and far more malicious code than in previous years. Nearly one-million new viruses are discovered every day. They say 60 percent of all targeted attacks struck small and mid-sized businesses. Just as alarming, a recent Palo Alto Network study stated that 52% of malware in 2013 focused on evading security making it more difficult to guard against an attack.
It is no wonder small and mid-sized businesses are targeted. They often have fewer resources to invest in security, and many are still not adopting best practices to protect their valuable information. This puts not only the business, but their business partners and customers at higher risk. Every organization, small to large, is vulnerable.
Steps to avoid a crypto-ransomware attack
A criminal must find a way to get into a computer network to provoke an attack. It sounds pretty simple, keep the bad guy out and, generally, you won't have to deal with these kind of malicious attacks. All of your protection efforts should be focused on keeping thieves away. Here are steps you can take to prevent this kind of attack beyond the standard anti-virus and firewall protection:
  • Employee Training - Every business should establish a culture of best practices for information security. Unfortunately, employees can be the weak link in the security chain. Every employee must be trained in the basics of protecting a business from a cyber attack.

  • Password Protection - Implement a password protection policy that includes changing passwords every 30 to 90 days and mandates employees don't use them outside of work. Employees can and do use their login and password information outside of work. Once a criminal gets this information he can use it to gain access to the business.

  • Monitor the Dark Web for stolen credentials - This is a step most businesses are missing. Stolen credentials like email login and password often appear in places thieves trade stolen information for weeks, months and, even, years before an attack occurs. Finding this information on the Dark Web and correcting the problem when it appears can prevent an attack from happening.

  • Intrusion detection and protection software - Many are heuristic in nature, they anticipate and quarantine suspected viruses and malware that traditional anti-virus protection may miss.

  • Back up your files daily - This will allow a business to overcome a crypto-ransomware attack quickly. A professional tech can clean up the network getting rid of the malware and then installing the backed up files. What the criminal is hoping is you aren't regularly backing up your files and you will have no choice but to pay the ransom.
We live in a rapidly changing world. It is important for a business to keep up, too
Taking preventative measures is a lot less expensive than dealing with crypto-ransomware, data breach or other types of cyber crime. Criminals are constantly finding new and inventive ways to steal your money, employee and customer information, trade secrets and/or just to take the business down. Don't become a victim. Implement the recommended steps today.
Warren Franklin has been involved in the information security arena for over ten years. His company, Franklin Risk Management Services, focuses on protecting businesses from a data breach, business identity theft or other criminal activities. To learn more about the Dark Web and proactive steps to protect your business go to http://franklinriskmanagement.webplus.net/cyberid-sleuth.html or email: warren@franklinrms.com

Read more ...

When Your Website Gets Hacked, Whose Fault Is It?

Friday, July 10, 2015
Many website owners are livid when their websites are defaced or hacked into and a message is put up by the hackers. The panic causes them to get angry and scared at the same time. Who could it be? Why me? How did they enter? What did I miss? Whose fault is it? are all common questions that come up when an incident occurs. This article discusses the possible reasons which caused your website to be compromised and how to deal with them.
Your Designer
Many website designers claim to know a lot about designing and website development, but simply know how to copy designs and layouts and make them fit in with your website. While trying to put in transitions and effects to your website elements, they most often copy code or boilerplate templates from free websites or previous projects. These code snippets have rarely been tested and no due diligence has been done to ensure their integrity. Many a time even prominent encoded malware is slipped into the code, which very few designers really understand.
Your Coder / Programmer
Just like the design aspect, even many coders and programmers are known to lift code from various sample websites, to match the taste of their client. Little do they realize that they are exposing their work to direct threats which are constantly waiting for easy prey. Code for menu's, slideshows, sidebars, contact forms and even chat applications could be laced with malicious code, which may either give control of the website and hosting account to an outsider or cause some automated scripts to run on the website. A client of ours was very surprised that all enquiries from his contact form were visible on a business forum. When he tested out the form, he realized that the form was auto-posting the results to the forum and suspected that the coder had played mischief. When he contacted the coder, the coder admitted to having used a free contact form script due to some special features. When a security professional inspected the code, he discovered that not only were the contacts being posted to the forum, but they were also being copied to an obscure email address.
Your Template
All of us are drawn into template based systems, due to their quick setup turnaround time and ease of use. But many people don't want to pay the template designers for their efforts and would prefer to buy pirated or nulled versions of the same paid templates. There is always a price for cutting corners and in this case, the price can be quite large. Those who distribute nulled versions for free often want some quid pro quo and add their own code or scripts to the templates, so that they also benefit from you using the template. Popup ads, banners, redirects, silent copying of your content and even mass mailing scripts are all part and parcel of using a stolen template.
The CMS System
The CMS System that you use also plays an important part in ensuring that your website content remains safe. Numerous vulnerabilities are found everyday across various open source and paid CMS systems. Not patching these vulnerabilities and not applying frequent updates to them increases your chances of being attacked by serial attackers who are specifically targeting your type of website system.
Your Hosting Company
It is also possible that the systems of your Hosting Company is infected and the malware or virus is spreading through their network. Although the chances of this are low, this can be easily determined by inspecting the logs of the hosting account. If the damage was done through a super user, then it is necessary to get the entire server and network checked up.
Your Own Fault
More often than not, the website owner or webmaster or admin is at fault for doing or not doing something at the right time and right place. Setting permissions too loosely, using plan text passwords in code and even allowing users to upload to a system folder are all ways in which the admin is responsible for getting the website into trouble.
If you are planning to buy Unlimited Hosting space, check out HostingXtreme's plans. Our value for money web hosting prices are unmatched. To know more visit our website.

Read more ...

When Your Email Account Gets Hacked, Whose Fault Is It?

Friday, July 10, 2015
Most of us have got our email accounts or social networking accounts hacked at some point of time. But what was the real reason for this? Was it our fault? Could we have prevented these intrusions? Till we don't try and investigate, we will never know and will never be able to correct it if it happens in the future. This article discusses the possible causes of your email account being compromised and how you could prevent this.
Your Own
99.9% of the times, email hacking can be attributed to the email account owner itself. Either knowingly or unknowingly they have revealed their password to an unknown person or spammer or hacker, who has used their login credentials to access their account. Phishing scams are the simplest way of getting a password i.e. by simply fooling the user into giving their password, by portraying that they are required to enter their login credentials into a website, to access some service or facility. The victim himself provides the username and password to the phisher and gets himself into trouble. Using password expiry systems, 2 factor authentication and alternate systems of authentication, you can avert this security breach.
Your Website Programmer
Badly coded websites can sometimes give access to your email accounts very easily. One of the simplest and silliest ways of getting your email account compromised is by using the username and password in the submission code of the web form. Newbie programmers sometimes, to make things easier for themselves, put in the email account login credentials in plan text in the source code of the web form. You don't need to be Einstein to figure out a password and how to access the email account. As a best practice, a separate email account may be given only for authentication of web forms which send out mail. This email account can be kept separate from actively used ones, so that even if it is compromised, your real data is protected.
The System Administrator
Bad password security practices on the part of your webmaster or system administrator is also a cause for password theft and a compromised account. Setting simple passwords or maintaining user passwords in a plain text file are all silly yet simple ways for your email security to be compromised. Setting up password age, password complexity standards and even login alerts, the system administrator can prevent these things from happening.
Your Mail Service Provider
When none of the above seem to be true, it is time to question your mail service provider. If there are other users on the same service or server who are facing a similar issue, it is time to bring this to the notice of your mail service and ask them to investigate into the matter. It is very possible that their mail servers or systems are compromised and a trojan or malware inside their system is causing account to be hacked and send out mail. A good way of identifying this is to ask for the logs of your account and to determine from the logs, what is going wrong and where. If the problem keeps recurring, it's time to change to a safer provider.
Unlimited hosting plans at HostingXtreme come with a free domain name, if taken annually. Our Reseller Hosting plans also offer value-for-money and the best quality of service. To know more visit us at our website.

Read more ...

The Fight Against Cyber Threats Requires a Dose of Common Sense

Friday, July 10, 2015
It is widely understood that common sense is not common. It is more frustrating when the approaches used by some organizations to prevent cyber attacks from enterprise assets lack the application of common sense. This article documents recent studies on the frequencies at which several large organizations scan their networks to identify vulnerabilities and improve their security posture. While zero-day attacks (malware introduced into the cyber space for which counter measures have not been developed) constitute about 13% of all the vulnerabilities (Ponemon Institute, 2014); the remaining 87% are well known and countermeasures exist for preventing them. The article also identifies some of the complacencies of some organizations in fighting cyber threats, and offers some suggestions for protecting the information and communication systems that support both government and private organizations from cyber attacks.
Current tools that merely alert the IT staff to respond to information on cyber threats are inadequate to address the massive volume and sophistication of modern cyber threats. Therefore intelligent cyber security solutions that can predict and stop threats on the networks are needed to address the limitations of traditional threat management tools. Current efforts to secure the cyber space have resulted in generating large public databases of vulnerabilities at NIST and Symantec. However, access to vulnerabilities databases is just the first step in managing threats to the networks, but it will not reduce the frequency and damages caused by cyber attacks unless network administrators are equipped with automated security tools. Those efforts to secure the cyber space are not being helped because several organizations and consumers are slow to apply published security updates.
Alarming statistics from market surveys: Published reports from recent studies by two independent market research organizations on the frequency of full-network active vulnerability scans (a.k.a. credential scanning) provide some very disturbing statistics. The 2015 Cyberthreat Defense Report on 814 organizations by the CyberEdge Group and the 2014 survey of 678 US IT Practitioners by the Ponemon Institute, LCC arrived at very similar results about the complacency of several organizations. Their findings show the following active scanning frequencies: Daily: 4%; Weekly: 11%; Monthly: 23%; Quarterly: 29%; Semi-annually: 19%; and Annually: 14%. A large number of organizations scan their networks to be compliant with Government regulations with little attention to risk management. The reports show that about 38% of those organizations scan their networks monthly. Several organizations that claim to perform continuous scanning actually perform passive scanning which does not provide a detail picture of the vulnerabilities of the network elements. Even the latest directive from the White House to government agencies to tighten security controls in response to the hack of the Office of Personnel Management (OPM) recommend that the agencies patch any security holes in response to the list of security vulnerabilities provided by the Department of Homeland Security every week. (Lisa Rein, The Washington Post, June 16, 2015).
The need to focus on automation instead of relying on human capital: Scanning the networks generates a huge amount of vulnerabilities that must be analyzed in order to gain intelligence about the network otherwise known as Situational Awareness. Merely publishing the most vulnerable nodes and alerting the system administrator to respond is not effective. It makes no sense to expect the human brain to process over 300 vulnerabilities and apply necessary countermeasures daily without expecting a brain freeze. Instead of lamenting on the shortage of personnel or cybersecurity experts, a significant amount of resource need to be devoted to process automation. Rather than rely on humans to perform penetration testing after the vulnerabilities have been identified, tools that automatically generate possible attack paths and prevent attacks on enterprise assets should be the focus.
Defense in Depth: The concept of defense indepth is widely understood by cybersecurity professionals and should be applied. To protect or harden each node on the network, it is critical to employ at least five strategies. I) Employ up-to-date anti-virus software that can disinfect both known and unknown malware. 2) Control the use of certain devices (such as disabling the blue tooth on your laptop) in public especially at air ports and Coffee shops; 3) Encrypt the hard drive and the media to protect stored data (lessons from Sony and OPM); 4) Control applications to prevent un-trusted changes (e.g. SQL injection); and 5) Patch management to ensure that the system is running the most current software. Defending in Depth is also called Host Based Access Control in certain quarters. Once the host has been protected, diligent attempts should be made to defend the network (i.e., connected nodes).
Concluding Remarks
Almost every week, we read about the vulnerabilities of the government and private networks and the significant cost to the economy, intellectual property and privacy of individuals. Many established companies and government agencies expend significant amount of resources to develop and deploy cybersecurity tools, yet the attacks continue. Why, one may ask. While we all understand that the problem is hard, there are some basic steps that we need to take to address the issue. Weekly scanning of the network assumes that the hacker does not attempt to penetrate the network less often. Are we comfortable to allow the hackers to roam the network for a week? Controlling access to critical assets require more than 2 or even 3-factor authentication. Encrypting the data with very strong encryption algorithm to make it very difficult for the thieves to use stolen data makes sense. Instead of lamenting on the shortage of cybersecurity professionals (which is true), focus on intelligent automation to reduce the level of effort for performing several mundane tasks. Those steps are what this author call common sense approaches.
The author is the President and Technology Director of SEGMA Technologies, Inc. in Silver Spring, MD with a focus on developing Predictive Threat Management software for cybersecurity and text analytics for Business Intelligence. He is the author of Building Survivable Systems and Blueprint for a Crooked House.
To combat the current cyber attacks on enterprise networks, organizations are encouraged to scan their networks on a regular basis to identify the vulnerabilities and apply published countermeasures. A significant number of the vulnerabilities (87%) used by the attackers to exploit networks are well known. To protect enterprise assets, reduce delays in detection of breaches, and the duration of Advanced Persistent Threats (APTs), periodic vulnerability scans are critical. In addition, automated tools need to be employed to extract intelligence from the vulnerabilities and reduce the load on system administrators.

Read more ...

5 Ways to Get Your WordPress Website Hacked

Friday, July 10, 2015
WordPress is constantly under threat from various people on the internet. These are some pretty certain ways in which you can get your WordPress website into trouble - ways that you wouldn't want to experiment with, if you had a serious business website. This article deals with 5 ways by which your website maybe compromised.
Plugins
Incompatible or exploit ridden plugins are a very common cause for having your WordPress website hacked. Plugins are provided by the WordPress community which allows people to make scripts and code snippets and offer them to everyone on WordPress. Many of these scripts and plugins are not properly maintained and updated by their coders. This means that flaws or vulnerabilities found in future versions of WordPress or of the plugin, may go undetected, uncorrected or unpatched. You may install a plugin without the knowledge that it is vulnerable to certain threats. Before you install a plugin, you should first ensure that it is compatible with your version of WordPress and then check how often it is updated. Another good indicator of the plugins safety would be its rating or reviews. Bad plugins and ones with vulnerabilities will often be flagged by the community of WordPress users.
Themes
Themes are also in the same list when it comes to WordPress security. WordPress Themes are freely available from the WordPress website and also from private third party providers. Paid themes are also available at a premium from various online services. WordPress themes comes with 2 types of problems. The first issue is when free themes contain a vulnerability which is not patched or a theme which is not updated regularly. Unsuspecting users will download the exploited WordPress theme and make their websites susceptible to attacks. The second part is a more drastic and overt flaw i.e. the use of Hashed or Nulled or Pirated WordPress themes which contain subtle redirects, popup or banner ads, phishing code, mass mailing viruses or other trojans which can severely affect the security of the website or hosting account.
Copied Scripts
Scripts or bits of code which have been copied from other websites, without verifying the security or integrity of the code, are also a sureshot way of getting your website hacked. Copying code for slideshows, gallery scripts or even menu items is common place amongst today's web designers. What they don't realize is that all the flaws and bugs that were in the original template have been copied over into their clients website verbatim. For a hacker to do massive damage across multiple sites, all he needs to do is to identify the sites using that code and then mass attacking them one by one.
Hashed or Pirated Templates
Just like the old pirated movie CDs and DVDs used to contain malware and spyware, many template breakers who have successfully cracked a paid template want something in return for their effort. The quid pro quo is often control of your website. Using pirated templates which are otherwise paid or proprietary can often lead to unwanted scripts or hidden code that maybe planted in the files to take advantage of your website.
Incorrect Permissions
Setting permissions higher than what you require can lead to your website files being written by anyone and everyone who can open your website. This means that all your files are openly editable and can be manipulated by an outsider to incorporate their code or script into yours.
Get WordPress Hosting with our unlimited hosting plans at HostingXtreme. We offer a free domain name with every hosting plan taken annually. To know more visit our website.

Read more ...