Monday, December 16, 2013

Microsoft wages on Windows XP disaster


windows-xp-countdown

Microsoft is forecasting a huge increase in cybercrime and exploits from the unsupported Windows XP software next year.  Support for Windows XP will be ending on April 8, 2014, so the software will be vulnerable to attacks and cybercrime.

Windows XP was released in September 2001, the 12-year old operating system is outdated and expiring.
Microsoft won’t issue patches or other security fixes for its operating system.  So, if an attacker develops an exploit code, they can take advantage of the vulnerable Windows XP software.

Windows XP will essentially have a ‘zero-day’ vulnerability forever!

Within the last year, Windows XP was targeted 45 times.


windows-infection


Hackers are sure to “bank” on the zero-day XP attacks, a migration strategy should be taking place, now.
With less than four months from now, the anticipated rate of infection for Windows XP is 66%.  There are 34% of all Windows on PCs still using Windows XP.  And with a two-month stall in decline, it is apparent the OS will be running on a quarter of PCs come April.

Now is the time to upgrade.  Either install Windows 7 or 8 on your PC or maybe it’s time to get a new PC all together.  Check out our store for great deals on computers and other hardware or take a look at our monthly specials.


References:

Zero day forever–move away from Windows XP, now – PC World
http://www.pcworld.com/article/2046839/zero-day-forever-move-away-from-windows-xp-now.html

Microsoft bets on Windows XP disaster – Computer World
http://www.computerworld.com/s/article/9244757/Microsoft_bets_on_Windows_XP_disaster

Friday, December 13, 2013

Are you being explotied?

Software exploits are attack techniques managed by attackers to quietly install malware.  Trojans or backdoors are fastened into computers without requiring social engineering to trick victims into manually running a malicious program.

Malware installation through an exploit would be invisible to users and gives attackers an obvious advantage.

Exploitation Targets

Here are some applications most targeted by attackers through exploitation:
  • Web browsers (Microsoft Internet Explorer, Google Chrome, Apple Safari, Mozilla Firefox and others).
  • Plug-ins for browsers (Adobe Flash Player, Oracle Java, Microsoft Silverlight).
  • The Windows operating system itself – notably the Win32 subsystem driver – win32k.sys.
  • Adobe Reader and Adobe Acrobat
The most dangerous exploit attack is remotely installing code into the operating system.  Downloading or running vulnerable software increases the chance of your system becoming infected with malware.

While PDF’s are the most common document files, they can be dangerous if obtained from an unreliable source.  Adobe has extended the file format to maximize its data exchange functionality by  granting scripting and the embedding of various objects into files.  This can be exploited by an attacker.



pdf-security



Another target is the Adobe Flash Player.  This plug-in is used for playback of content on various browsers.  The Adobe Flash Player is updated regularly and notifies you when it’s time to upgrade.  Most vulnerabilities are of Remote Code Execution (RCE) which indicates that attackers use susceptibilities for remotely executing malicious code on a victim’s computer.

Java is also a popular browser plug-in attractive to attackers.  More than three billion devices are using this platform.  Java is vulnerable to malicious attacks and is one of the most dangerous components.  When you use Java on Windows, its security settings can be changed using the control panel applet.  Latest versions of security settings allow you to configure the environment more accurately.


Windows operating systems itself can be used by attackers to remotely execute code.  The figure below shows the number of patches the each components have received during 2013.



patches
This shows Internet Explorer fixed the greatest number of vulnerabilities.  More than a  hundred vulnerabilities have been fixed in the course of fourteen updates.

internet-options

Windows Operating System

Newer versions of Microsoft Windows – i.e., Windows 7, 8, and 8.1 have built-in mechanisms which help protect users from destructive actions delivered by exploits.  Features became available with Windows Vista was upgraded in the most recent operating system versions.


Operating-system-updates

http://www.hyphenet.com/blog/2013/12/13/are-you-being-explotied/



This shows Internet Explorer fixed the greatest number of vulnerabilities.  More than a  hundred vulnerabilities have been fixed in the course of fourteen updates.




internet-options

Windows Operating System

Newer versions of Microsoft Windows – i.e., Windows 7, 8, and 8.1 have built-in mechanisms which help protect users from destructive actions delivered by exploits.  Features became available with Windows Vista was upgraded in the most recent operating system versions.

Operating-system-updates


http://www.hyphenet.com/blog/2013/12/13/are-you-being-explotied/

 

Windows Operating System

Newer versions of Microsoft Windows – i.e., Windows 7, 8, and 8.1 have built-in mechanisms which help protect users from destructive actions delivered by exploits.  Features became available with Windows Vista was upgraded in the most recent operating system versions.





All operating systems or programs used are studied by attackers for vulnerabilities.  Their intent is to exploit for financial gain.  Adobe, Google, and Microsoft are all taking steps to make these attacks more difficult to achieve.

To protest yourself, change your system settings for a more secure application and keep your software up-to-date.

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.

References:

Exploit Protection for Microsoft Windows – We Live Security
http://www.welivesecurity.com/2013/12/13/exploit-protection-for-microsoft-windows/

Thursday, December 12, 2013

Disconnected Computers are still at Risk for Cyberthreats


air-gap-malware

Are we really aware of the cyberthreats faced with our computers?  Don’t click on the bothersome floating advertisement, never open mail from suspicious senders, don’t trust your friends sending you a message containing just a link.

Being tricked into installing malware on your own computer is just a click away.  You think you need a new version of Flash because your computer tells you so.  So you click, install, then realize something is funny about the download process.

What do you do then?  Frantically turn your computer off, hoping you just stopped what ever invasion your computer is experiencing?  If your computer is infected with a virus or malware, disconnecting it from the Internet is the first step of security you should take.  But is it enough?

German computer scientists have come up with a prototype for building “covert channels” between computers using the machines’ speakers and microphones.  This potentially defeats high-security measures that rely on the “air gap” between computers.

malware-airgap

The air gap is a network security measure that ensures a secure computer network is physically isolated from unsecured networks.  Sometimes the air gap is not completely literal, and dedicated cryptographic devices can tunnel packets over questionable networks while avoiding pack rate or size variation.
Dan Goodin from Ars Technica explains:

“The proof-of-concept software — or malicious trojans that adopt the same high-frequency communication methods — could prove especially adept in penetrating highly sensitive environments that routinely place an ‘air gap’ between computers and the outside world. Using nothing more than the built-in microphones and speakers of standard computers, the researchers were able to transmit passwords and other small amounts of data from distances of almost 65 feet. The software can transfer data at much greater distances by employing an acoustical mesh network made up of attacker-controlled devices that repeat the audio signals.”

Research has shown that computers which were unplugged from networks and had their Wi-Fi and Bluetooth cards removed, were infected with malware that used high-frequency transmissions.
Hackers are “jumping the air gap” and worrying even military officials.

“If you take a cybernetic view of what’s happening [in the Navy], right now our approach is unplug it or don’t use a thumb drive,” retired Navy Capt. Mark Hagerott, a cybersecurity professor at the U.S. Naval Academy, said at a recent defense conference. But if hackers “are able to jump the air gap, we are talking about fleets coming to a stop.” – Geoffrey Ingerson of Business Insider

“Acoustical networking as a covert communication technology is a considerable threat to computer security,” the scientists wrote in their paper. However, they said such audio snooping could be prevented using “a software-defined lowpass filter” or a “detection guard” that analyzes audio to identify hidden messages. – Hanspach and Goetz, German scientists

System devices designate security levels as low side (unclassified) and high side (classified).  I’m sure the military has much more interesting information in their computers, but just the thought that nothing can stop computer invasion is scary.

What’s your take on this?  Please leave your comments below!

Be sure to follow us on Twitter at @hyphenet or “Like” us on Facebook to stay up-to-date on the latest computer security threats.

References:

Even Disconnected Computers May Face Cyberthreats – NPR
http://www.npr.org/blogs/alltechconsidered/2013/12/03/248576739/even-disconnected-computers-may-face-cyber-threats
December 4, 2013

Wednesday, December 11, 2013

By 2015 One in Four Cloud Providers will be gone

cloud-computing

Gartner research firm is predicting a considerable unification in cloud services and estimates around 25% of the top 100 IT service providers in the groundwork will not be around by 2015.

“One in four vendors will be gone for whatever reason — acquisition, bankruptcy,” said William Maurer, a Gartner analyst.

We are in the era of buyer beware with cloud, there’s no safety net.

Large vendors are a safer option because of the costs cuts.

It is said, there is a 50% perceived risk of using cloud-based solutions. 33% saw “somewhat” of a risk, and 12% express the sense of a small risk.

Gartner also predicts that a segment of organizations using cloud services will reach to 80% by the end of the year.


Cloud Computing

Cloud computing services used to be viewed as an alternative for large enterprises. The rapid rate of technology and evolution over the past 12 months show it is inevitable around cloud migration.
Solutions for security, privacy, and data sovereignty are a concern.

OffShoring

Cloud has some parallels with the migration of offshoring. Risks and challenges around offshoring build angst and political heat.  The idea of companies data streaming to other countries shows concern for security.

Offshoring  to other countries is an alternative method used for resources very popular with technical and administrative service support.

Due to many concerns, the lack of onshore skills, costs, and the need to rebuild controls,  a new “normal” has come with a considerable bulk of IT and business processes migrated offshore.

Offshoring may be the help Cloud services need to stay afloat.

If your not aware of what Cloud Computing is here is an Infographic to help you out.


cloud-computing-infographic
Source link via : Mashable.com

Be sure to follow us on Twitter at @hyphenet or “Like” us on Facebook to stay up-to-date on the latest computer security threats.


References:

Cloud debate now about speed and sophistication – CIO
http://www.cio.com.au/article/533970/cloud_debate_now_about_speed_sophistication/

One in four cloud providers will be gone by 2015 – ComputerWorld
http://www.computerworld.com/s/article/9244694/One_in_four_cloud_providers_will_be_gone_by_2015

Tuesday, December 10, 2013

Tech Support Scams Still Evolving


tech-support-scam

The ESET tech support have been running into customers who think they’ve been getting help from ESET or it’s partners but it turns out they have been tricked by scammers.

Customers are receiving calls from an “ESET 3rd party tech support rep” who says their computer had been corrupted and needed to be fixed.

Also, customers are getting calls from “Microsoft”, informing them that a notification had been received concerning a virus infection on their PC, offering his services to help.  Scammers are installing cracked versions of ESET’s software and other software while retracting information from your computer, along with taking their money.

Here is an example of the dialogue from these scammers:

Scammer: Hello, we are calling you because we see your computer has a lot of infections and is approaching a system crash.  If you let me remote in I can assist with removing the infections to save your computer for only $300.00.

User: Well that’s odd, I typically use  and their support for issue like this.

Scammer: We are 3rd party support for , so we can support you.

User: “Oh that’s great!” or “Let me call  first.”

A customer said he was told to ‘press Windows R’ (Runs the Command) and then type ‘inf location virus’ into the dialog box.  “inf” is a search term for C:\\Windows\Inf, which contains files used in installing the system.


inf-copy


A company called Speak Support offering “Mac® Technical Support” misused the internet utility ping in hope of convincing a potential victim that he has no active protective software on his system.

The phony tech asked the customer to open a terminal window and used ping from the command line to query a site called protection.com.  This is what shows up:

wilbur:~ davidharley$ ping protection.com
PING protection.com (72.26.118.81): 56 data bytes
Request timeout for icmp_seq 0
Request timeout for icmp_seq 1
Request timeout for icmp_seq 2
Request timeout for icmp_seq 3
Request timeout for icmp_seq 4
Request timeout for icmp_seq 5
Request timeout for icmp_seq 6
Request timeout for icmp_seq 7
Request timeout for icmp_seq 8
Request timeout for icmp_seq 9
Request timeout for icmp_seq 10
^C
--- protection.com ping statistics ---
10 packets transmitted, 0 packets received, 100.0% packet loss
The ^C shows where I got bored with counting timeouts and terminated the request.

Here’s how to contact ESET if you’re a customer with malware-related problems:
  • If you’ve received specific information about support from your local distributor when you bought the product, that’s the first place to look.
  • Go to http://www.eset.com  and check out the resources on the Support tab. This tab will offer a number of options, including a search facility, access to the ESET Knowledgebase, a form that enables you to contact Customer Care to submit a specific case, and a link to contact pages for ESET’s offices around the world.
  • You can also get there via the help and support facility in the product itself.

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.

References:

Tech Support Scammers: Talking to a Real Support Team – We Live Security
http://www.welivesecurity.com/2013/11/22/tech-support-scammers-talking-to-a-real-support-team/
November 22, 2013

Tech support scam update: still flourishing, still evolving – We Live Security
http://www.welivesecurity.com/2013/10/29/tech-support-scam-update-still-flourishing-still-evolving/
October 29, 2013

Monday, December 9, 2013

Buy of the Week: HP LaserJet Pro 200 Color Printer M251nw for only $199 + tax!

hp-laserjet-pro-200-color-printer-m251nw
The HP LaserJet Pro 200 color M251nw is the perfect color laser printer that fits into the smallest spaces!
The M251nw offers fast printing, easy Wi-Fi direct connection, and a touch screen control panel.

Specifications for the HP LaserJet Pro 200 Color M251nw

Product Description HP LaserJet Pro 200 color M251nw – printer – color – laser
Printer Type Workgroup printer – laser – color
Weight 41.4 lbs
Localization English, French, Spanish / Canada, Mexico, United States, Latin America (excluding Argentina, Brazil, Chile)
Max Media Size (Standard) Legal, A4
Min Media Size (Custom) 3 in x 5 in
Max Media Size (Custom) 8.5 in x 14 in
Print Speed Up to 14 ppm – black normal – Letter A Size (8.5 in x 11 in)
Up to 14 ppm – color normal – Letter A Size (8.5 in x 11 in)
Max Resolution ( B&W ) 600 x 600 dpi
Max Resolution ( Color ) 600 x 600 dpi
Image Enhancement Technology HP ImageREt 3600
Interface USB 2.0, LAN, Wi-Fi(n), USB host
AirPrint Enabled Yes
Preview Screen Size 3.5″
Processor 750 MHz
RAM Installed ( Max ) 128 MB ( 128 MB )
Language Simulation PCL 5C, PostScript 3, PCL 6
Media Type Envelopes, transparencies, labels, plain paper, glossy paper, photo paper, heavy-weight paper, cards, bond paper, recycled paper
Total Media Capacity 150 sheets
Monthly Duty Cycle (max) 30000 pages
Recommended Monthly Volume 250 – 1500 pages
Networking Print server – Ethernet, Fast Ethernet, IEEE 802.11b, IEEE 802.11g, IEEE 802.11n
Printer Features HP ePrint
Power AC 120 V
System Requirements SunSoft Solaris 8, SunSoft Solaris 9, Microsoft Windows XP SP2 or later, HP-UX 11, Red Hat Fedora Core 9, Red Hat Fedora Core 10, Ubuntu 8.10, Ubuntu 9.04, SuSE Linux 11, Apple MacOS X 10.6, Debian GNU/Linux 5.0, Red Hat Enterprise Linux 5, Apple MacOS X 10.5, Microsoft Windows Server 2003 SP3 or later, SuSE Linux 10.3, Linux Linpus 9.4, Ubuntu 8.04, Microsoft Windows Vista (32/64 bits), Ubuntu 9.10, Red Hat Fedora Core 11, Red Hat Fedora Core 12, Debian GNU/Linux 5.0.1, Ubuntu 10.04, Microsoft Windows 7 (32/64 bits), Microsoft Windows Server 2008 (32/64-bits), Apple MacOS X 10.7 Lion, Linux Linpus 9.5, SuSE Linux 11.1, SuSE Linux 11.2, Ubuntu 8.04.1, Ubuntu 8.04.2, Debian GNU/Linux 5.0.2, Debian GNU/Linux 5.0.3
Manufacturer Warranty 1 year warranty

Call (619) 325-0990 to order a HP LaserJet Pro 200 color M251nw printer today!

Buy of the Week offer valid through December 14th, 2013.
Note: Shipping and taxes apply.
Looking for something else? Check out our monthly deals or contact us to get a quote on the product you’re searching for.

Tuesday, December 3, 2013

India seeks help from the US to monitor Web chats

India’s government plans on using the U.S. to help decrypt data sent via messaging services to aid in cyber-crime investigations.

India-United-States
http://www.hyphenet.com/blog/india-seeks-help-us-monitor-web-chats/

 The U.S. is the leader in monitoring phone calls, web chats, and everything else that can be under surveillance.  India is requesting the United States’ help in unraveling messages from online chat services to gain an upper hand in cybercrime for their investigations.

It is noted the Indo-US Police Chiefs conference will take place on Wednesdays at India’s Union Home Ministry.  The conference will focus on online messaging services like Viber, Whatsapp, Slype, and Webchat, which challenges security agencies to intercept and monitor conversations.

India is requesting the U.S. share its knowledge and information on the technology used to do so.

The Asian economic giant has been pressuring  chat services to share their decryption keys, but have not seen any changes.

“The availability of their Web servers in India is required for legal interception of communications in real-time for timely action by security and intelligence agencies,” the India ministry said in its note. “The communication over these services is encrypted, and the encryption-decryption technologies available with the service providers will be required by security agencies even if the facility for lawful interception of these communications is extended to security agencies in India. The technology in use by U.S. agencies may be an area of co-operation.”

In November 2008, there was a terrorist attack in Mumbai.  The Indian government said the terrorist were able to organize the attacks throught mobile phones and  Internet messages.

india-national-security-agencys-spying-list
http://www.hyphenet.com/blog/india-seeks-help-us-monitor-web-chats/

BlackBerry has set up a server in India to assist the government’s demand for tracking communications.  The device tracks messages sent to and from all BlackBerry devices.

The Indian Union Home Ministry expressed great displeasure to the U.S.  because of service providers like Microsoft, Google, Facebook and Twitter, have not agreed to the request for information of e-mail contents to aid in the investigations.

According to The Economic Times, India’s Intelligence Bureau Chief Asif Ibrahim called for the establishment of an “Indo-American Alert, Watch and Warn” network to help ease  cybercrime investigations between law enforcement agencies and other corporations.

Service providers currently take between 15 to 80 days to respond to India’s request for Internet log data.  There’s no guarantee that the information required to fight cybercrime will be provided at all.

For India’s Nation Investigation Agency (NIA): cooperation from companies would mean accessing, monitoring, and call interception data from all organizations.  For India’s people: privacy fears, self-censorship, and  paranoia will consume their thoughts while their personal conversations are being collected.

What do you think about surveillance programs tapping into internet traffic to counteract terrorist attacks?  Is it invading our privacy or protecting our people?

Leave your comments below!

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

References:
Analysis: NSA’s data grab ought to boost privacy concerns – USA Today
http://www.usatoday.com/story/cybertruth/2013/10/30/nsas-data-grab-should-boost-privacy-concerns/3315789/
October 30, 2013
India agency petitions for monitoring system – ZDNet
http://www.zdnet.com/in/india-agency-petitions-for-monitoring-system-7000005762/
October 15, 2013
India to seek US help in monitoring Web chats – ZDNet
http://www.zdnet.com/in/india-to-seek-us-help-in-monitoring-web-chats-7000023867/
December 3, 2013