Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

Sunday, October 2, 2011

8 URL Expanders to View and Investigate Shortened Links


Several years ago, I have posted the presentation devoted to the URL shorteners, and offered there some examples of when and how they can be potentially useful for the Internet users. However, there are opposite cases, when you get short URL might hide spam link or direct you to the fishing sites in order to capture personal information, or even worse, can redirect you to malicious web sites containing dangerous malware, which is unhealthy to your computer.

If you are not sure, what can be hiding behind the short URL, and you want to expand it to the real URL address, which will allow you to make more informative decision, if you want to go there, as usual you can get help from the free Web services. These services will uncover the original links, when you submit the questionable shortened URL.

Image and video hosting by TinyPic

This is a short list, selected by the platform.

Web-based Services

  1. LongURL.
  2. URL  X-ray.
  3. Clybs.

Firefox Plugins

LongURL Mobile Expander.
Google Chrome Plugins

  1. Tactical URL Expander.
  2. ChromeMUSE. This plugin presents the possibility to expend the short URL, or shorten the real URL, working both ways.
  3. Miniscurl Universal URL Shortener/Expander. The same as previous service, can offer both links shortening and expansion.

Android Smart Phones

Long URL Expander.

Image and video hosting by TinyPic


Monday, May 16, 2011

Free Download Microsoft Security Intelligence Report (Volume 10)

The Security Intelligence Report (SIR) is an investigation of the current threat landscape.
It analyzes exploits, vulnerabilities, and malware based on data from over 600 million systems worldwide, as well as internet services, and three Microsoft Security Centers. Data is collected by a number of different Microsoft teams partly compromised of those who work on MS Security Essentials products, Internet Explorer’s Smartscreen filter and the Malicious Software Removal Tool. This year the 10th edition of this semi-annual SIR report expands on information gathered on an international level including data specific to 117 countries. This type of reports is published by
Microsoft twice a year, and data collection time for the latest report is from July 2010 to December 2010.

Image and video hosting by TinyPic

A fresh security report pointed out that with the way online fraud is becoming more diverse, social networks have become a breeding ground breeding ground for cyber criminals. Safety reported that in 2010 social network “phishing” attacks grew by 1200%. Phishing attacks typically posing as legitimate messages to attract Internet users to click on malicious links, buy rogue software, or disclose personal information.

According to Microsoft statistics, the use of social networking phishing attacks accounted for in December 2010 84.5% of the total number of phishing attacks compared in terms of early 2010 this figure was only 8.3%.

The Report outlines the emergence of two distinct types of cybercriminal. The first is a highly sophisticated, well-informed individual who pursues high-value opportunities with large payoffs. The second is an individual skilled at exploiting social relationships to con a small amount of money from a large amount of people.

Image and video hosting by TinyPic


At present the most prevalent methods include the use of rogue security software, phishing using social networking as the lure and adware (software that automatically plays, displays or downloads advertisements). The majority (six out of ten) of these methods use malware – corrupt software disguised as a marketing campaign or product promotion that appears legitimate. Criminals use this malware to make money through tricking users with pay-per-click schemes, false advertisements or fake security software for sale.

Additionally, rogue security software, or scareware, has quickly become one of the most common ways for cybercriminals across the globe to acquire money and private information from unassuming computer users. This software, such as Win32/FakeSpypro, appears similar to legitimate security software giving a false sense of protection, and, if trusted and clicked by the user, downloads itself and compromises systems. In 2010, Microsoft protected nearly 19 million systems from rogue security software. The top five types of rogue security software were responsible for 70 percent, or approximately 13 million, of those detections.

“While criminals work to evolve their attack methods, Microsoft and the industry will continue to collaborate with partners and customers to improve security and privacy and increase awareness. A combined effort helps to protect the broader online community from these threats and develop more secure software solutions to prevent criminals from reaping the benefits,” says Graham Titterington, Principal Analyst for Ovum.

Security have suggested that computer users should update the software, the use of reliable security software, do not click or open the link not sure whether or document security.

Image and video hosting by TinyPic




Sources and Additional Information:


Tuesday, June 29, 2010

Clipperz spells as Online Password Manager

Clipperz is a free and anonymous online password manager. The highest available security encryption within the browser guarantees that no one except you can read or fetch your personal data. The service is solely web based, and there is no need to install software on your Hard Drive or mobile devices.

If you have multiple sites you need to enter your password, or you need to fill countless online forms, yo will enjoy the convenience of Clipperz “direct logins”, allowing to access all web services with just one click.

Clipperz is not just a password manager, it’s a personal online vault for any kind of sensitive data, from burglar alarm codes to confidential notes you would like to preserve securely for convenient anytime and anyplace access.

But what happens if your Internet is down? How you will be able to access your information, stored on the remote server? Not a problem. With just one click you can dump all your encrypted data from Clipperz servers to your hard disk and create a read-only version of Clipperz to be used when you are offline and for backup purposes. The read-only version is as secure as the read-and-write one and will not expose your data to higher risks since they both share the same code and security architecture.

One more, and significant, advantage of the service is its compatibility to the most popular data saving formats. There is no need to start you database “from scratch”, as Clipperz lets you quickly import passwords and sensitive data from:
  • other password managers (Roboform, Keepass and PasswordPlus)
  • popular file formats (Excel and CSV)
And, finally, Clipperz online password manager is free and completely anonymous. Therefore the account creation process is straightforward: simply choose a username and a passphrase and you are ready to go! No email address or any other personal information is required.

 Image and video hosting by TinyPic

Tuesday, June 2, 2009

Dangerous Email File Attachments You Should Be Aware Of

http://www.pcmech.com/article/email-file-attachments-you-should-not-open/It is easy to catch flu, if you do not make necessary precautions. It is easy to infect your computer with unwanted disease, like virus or less destructive, but nevertheless very annoying malware. Rich Menga’s recommendations on how to handle certain file attachments are simple and straightforward: never open them. But the expectations that people would follow this advice would be unreasonable, taking in account the amount of video, audio, and other types of information being exchanged between computer users.


Being far from the anti-virus paranoia, I would definitely think twice before opening, even thou I am personally equipped with heavy arsenal of anti-virus, anti-trojan, and all other anti-tools. It is always easier to prevent infection than to clean your computer after.

Among the email attachment extensions that should not be opened at all, or if completely necessary, should be open in the special secure environment, are:

Very Dangerous File Formats

.reg Possible Windows registry attack

.chm Possible compiled Help file-based virus

.cnf Possible SpeedDial attack

.hta Possible Microsoft HTML archive attack

.ins Possible Microsoft Internet Comm. Settings attack

.jse Possible Microsoft JScript attack

.lnk Possible Eudora *.lnk security hole attack

.ma_ Possible Microsoft Access Shortcut attack

.pif Possible MS-Dos program shortcut attack

.scf Possible Windows Explorer Command attack

.sct Possible Microsoft Windows Script Component attack

.shb Possible document shortcut attack

.shs Possible Shell Scrap Object attack

.vbe or .vbs Possible Microsoft Visual Basic script attack

.wsc .wsf .wsh Possible Microsoft Windows Script Host attack

.xnk Possible Microsoft Exchange Shortcut attack

.scr Possible virus hidden in a screensaver

.bat Possible malicious batch file script

.cmd Possible malicious batch file script

.cpl Possible malicious control panel item

.mhtml Possible Eudora meta-refresh attack

Deny all other double file extensions. This catches any hidden filenames.

Dangerous File Formats

.EXE, .COM

Most email servers outright ban the use of sending .EXE files and there is a strong reason of doing so since executable Windows files can easily lead to the most severe consequences to your computer. Even if you do not see the negative effect immediately, you cannot be sure that the installed possible software spy/terrorist has not started its destructive activities. If you need to test the file badly for some reason, open it in a virtual machine environment. And if it blows that up, no big deal because you can just kill the session and create another one.

.ZIP, .RAR, .ARJ

These extensions (and some other) represent the archives. Everything can be compressed – from innocent document to virus bomb. While many security specialists recommend directing these files into trash bin right away, I would not be so conservative. It all depends… Just review the content of the archive before opening it.

.PDF, .DOC, .XLS

These document files formats are considered absolutely safe in our communication world. However, it is not absolutely true assumption. Microsoft Office files may contain hidden elements anything from simple macro viruses (relatively harmless but annoying) to full-blown malicious code. To play absolutely safe, you can open the documents at Google Docs instead of opening them on your own PC.

.WMV, .ASF, .ASX, .MOV

WMV is Windows MediaVideo. ASF is Advanced Systems Format. ASX as Advanced Stream Redirector format. MOV is the Apple Quicktime Movie format.

All of these are video formats, and of them routinely contain malware. You should be careful opening this sort of files from unfamiliar (or even familiar) sources. If you are suspicious on the possible infection, but you still want to be sure, you can upload it to YouTube as a private video and watch it that way. That way, no malware code will be launched on you computer.

.DLL

Dynamic Link Library. Can be used for a variety of tasks associated with a program. DLLs typically add functions to programs. Some contain executable code; others simply contain functions or data but you can't tell by looking so all DLLs should be scanned.

.MSI, .MSP

Microsoft Windows Installer Package and Microsoft Windows Installer Patch. Both files contain code and might carry the same threat as executable package.

Safe File formats

Any image (BMP, GIF, JPG/JPEG, TIF/TIFF)

To the best of my knowledge there is no malicious code that can be executed from a static image format.

HTML formatted email

Both local and web based email clients have become "smart" enough not to load images, or any other "bad" stuff, automatically.

Audio files (MP3, WAV)

I have never received a virus or been infected with malware from a static audio file.

And finally if you receive an email with an unknown to you file attachment, make search to understand what is that, and only than decide whether to open it or not.
Related Posts Plugin for WordPress, Blogger...