Monday, June 16, 2008
Problems with WEP
The WEP protocol standardizes the production of hardware and software that use the IEEE 802.11 protocol. To secure data, WEP uses the RC4 algorithm to encrypt the packets of information as they are sent out from the access point or wireless network card. RC4 is a secure algorithm and should remain so for several years to come. However, in the case of WEP, it is the specific wireless implementation of the RC4 algorithm, not the algorithm itself, that is at fault.
The following section will show in detail how WEP is cracked. On a busy corporate network, a wardriver can capture enough data to break your WEP encryption in about two to six hours. Breaking a home user's encryption might take longer (up to two to four weeks), since the flux of data is often much lower. Nevertheless, we recommend that you use WEP when possible, not just as a minor security barrier, but also because it serves as a gentle warning (akin to a login banner disclaimer on a network) that your network is private, rather than shared with the entire community. Also, some products (such as Windows XP) automatically associate with the strongest wireless signal by default. Using WEP prevents your neighbors from inadvertently sucking up your bandwidth, or from unknowingly browsing the Web using your home IP address!
Wednesday, June 04, 2008
Understand and participate in forensics.
First things first—computer crime is increasing and our ability to cope with the complexity of the networks and software applications that are being created is decreasing. Now, this is most certainly a generalization, but it holds true for many of the clients and companies we see every year. Another truth is that given enough time, energy, and incentive, just about any network can be hacked. If you can accept these basic truths, the time you spend planning and training in areas such as computer forensics will seem less like a waste of time and more like an investment.
Computer forensics is about collecting and analyzing data so it can be used and presented in court. Without proper forensic techniques, you are likely to destroy valuable data or render it inadmissible because it was improperly obtained, collected, or stored. Without evidence, you can't prosecute offenders, properly terminate employees for inappropriate behavior, or seek damages when corporate espionage hits home.
DMZ : Demilitarized Zone
Also called the free-trade zone or the neutral zone, this is an area in your network that allows a limited and controlled amount of access from the public Internet. The DMZ often hosts the corporation's Web and File Transfer Protocol (FTP) sites, email, external Domain Name Service (DNS), and the like. This network segment usually lies between the internal corporate network and the public Internet.
Wednesday, May 07, 2008
What does antivirus software do?
New viruses are discovered daily. The effectiveness of antivirus software is dependent on having the latest virus profiles installed on your computer so that it can look for recently discovered viruses. It is important to keep these profiles up to date.
More information about viruses and antivirus software can be found on the CERT Computer Virus Resource page
http://www.cert.org/other_sources/viruses.html
What is NAT?
Using NAT masquerading, one or more devices on a LAN can be made to appear as a single IP address to the outside Internet. This allows for multiple computers in a home network to use a single cable modem or DSL connection without requiring the ISP to provide more than one IP address to the user. Using this method, the ISP-assigned IP address can be either static or dynamic. Most network firewalls support NAT masquerading.
Wednesday, February 27, 2008
CAPTCHA! Gmail bot detector system cracked
Google's free e-mail services and a highly-desirable gmail.com domain—one that is unlikely to be blacklisted by anybody's spam filters—are just two of the features that induced spammers to crack the CAPTCHA and have bots do all the work. On the upside, it apparently wasn't easy—Websense says that it required two bot hosts to crack instead of just the one that recently cracked Windows Live Mail's CAPTCHA (Websense believes that the same group was involved with both). It also believes that the two hosts are required because the first host may fail at cracking the code the first time around (and possibly time out), but the second host may also be required to check the work of the first. Additionally, only one in every five CAPTCHA-breaking requests on Gmail succeeded. Still, a 20 percent success rate is relatively high when you consider that spambots are trying to register hundreds (or thousands) of e-mail addresses at a time.
The CAPTCHA test—Completely Automated Public Turing test to tell Computers and Humans Apart—is one we're all familiar with. When signing up for new services, we are often asked to decipher a series of letters and numbers embedded in an image that is supposed to be difficult for computers to read. But, while the CAPTCHA has worked well in the past, hackers are getting better at programming computers with the ability to read them.
Read More
Tuesday, February 26, 2008
Securing Wireless Networks
As the name suggests, wireless networks, sometimes called WiFi, allow you to connect to the internet without relying on wires. If your home, office, airport, or even local coffee shop has a wireless connection, you can access the network from anywhere that is within that wireless area.
Wireless networks rely on radio waves rather than wires to connect computers to the internet. A transmitter, known as a wireless access point or gateway, is wired into an internet connection. This provides a "hotspot" that transmits the connectivity over radio waves. Hotspots have identifying information, including an item called an SSID (service set identifier), that allow computers to locate them. Computers that have a wireless card and have permission to access the wireless frequency can take advantage of the network connection. Some computers may automatically identify open wireless networks in a given area, while others may require that you locate and manually enter information such as the SSID.
What security threats are associated with wireless networks?
Because wireless networks do not require a wire between a computer and the internet connection, it is possible for attackers who are within range to hijack or intercept an unprotected connection. A practice known as wardriving involves individuals equipped with a computer, a wireless card, and a GPS device driving through areas in search of wireless networks and identifying the specific coordinates of a network location. This information is then usually posted online. Some individuals who participate in or take advantage of wardriving have malicious intent and could use this information to hijack your home wireless network or intercept the connection between your computer and a particular hotspot.
What can you do to minimize the risks to your wireless network?
Change default passwords - Most network devices, including wireless access points, are pre-configured with default administrator passwords to simplify setup. These default passwords are easily found online, so they don't provide any protection. Changing default passwords makes it harder for attackers to take control of the device (see Choosing and Protecting Passwords for more information).- Restrict access - Only allow authorized users to access your network. Each piece of hardware connected to a network has a MAC (media access control) address. You can restrict or allow access to your network by filtering MAC addresses. Consult your user documentation to get specific information about enabling these features. There are also several technologies available that require wireless users to authenticate before accessing the network.
- Encrypt the data on your network - WEP (Wired Equivalent Privacy) and WPA (Wi-Fi Protected Access) both encrypt information on wireless devices. However, WEP has a number of security issues that make it less effective than WPA, so you should specifically look for gear that supports encryption via WPA. Encrypting the data would prevent anyone who might be able to access your network from viewing your data .
- Protect your SSID - To avoid outsiders easily accessing your network, avoid publicizing your SSID. Consult your user documentation to see if you can change the default SSID to make it more difficult to guess.
- Install a firewall - While it is a good security practice to install a firewall on your network, you should also install a firewall directly on your wireless devices (a host-based firewall). Attackers who can directly tap into your wireless network may be able to circumvent your network firewall—a host-based firewall will add a layer of protection to the data on your computer
Tuesday, December 11, 2007
Clean your Windows registry
CleanMyPC Registry Cleaner 3.50 - The Most Popular Registry Cleaner
- PC runs much slower than when you first bought it
- PC crashes for no apparent reason
- You keep receiving error messages and don't know why
Solution: You need a Reliable Registry Cleaner!
CleanMyPC™ Registry Cleaner can clean your Windows registry, tune up your PC and keep it in peak performance!
The Windows registry is a database repository for information about a computer's configuration. The registry keep growing when you use Windows. As it does so, it attracts obsolete and unnecessary information, and gradually becomes cluttered and fragmented. With the growing of the registry, it can degrade the performance of the whole system and cause many weird software problems. To keep your computer in top performance, it is recommended to periodically clean your Windows registry with a reliable and efficient Registry Clean
CleanMyPC Registry Cleaner scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry, your system will run faster and error free. The backup/restore function of the tool let you backup your whole Windows Registry so you can use it to restore the registry to the current status in case you encounter some system failure. Besides above, the startup and BHO organizer feature let you manage your startup and IE BHO items with ease, and you can control the programs started with Windows and IE more handy with this feature!
In short, CleanMyPC Registry Cleaner help you get rid of the bloat in Windows registry and achieve a cleaner, faster system.
The latest version adds the registry defrag/compact and privacy eraser features.
Main Registry Cleaner Features:
- Automatic Registry Scanning and Cleanup
- Backup and Restore the full Registry
- Registry Defrag and Registry Compact
- Tracks Eraser feature for privacy protection
- Startup Organizer
- IE BHO Organizer
- Improve system performance
- Remove Trojan which utilize startup items and IE BHO
Sunday, November 18, 2007
Protecting Portable Devices: Data Security.
Although there are ways to physically protect your laptop, PDA, or other portable device (see Protecting Portable Devices: Physical Security for more information), there is no guarantee that it won't be stolen. After all, as the name suggests, portable devices are designed to be easily transported. The theft itself is, at the very least, frustrating, inconvenient, and unnerving, but the exposure of information on the device could have serious consequences. Also, remember that any devices that are connected to the internet, especially if it is a wireless connection, are also susceptible to network attacks (see Securing Wireless Networks for more information).
What can you do?
- Use passwords correctly - In the process of getting to the information on your portable device, you probably encounter multiple prompts for passwords. Take advantage of this security. Don't choose options that allow your computer to remember passwords, don't choose passwords that thieves could easily guess, use different passwords for different programs, and take advantage of additional authentication methods (see Choosing and Protecting Passwords and Supplementing Passwords for more information).
- Consider storing important data separately - There are many forms of storage media, including floppy disks, zip disks, CDs, DVDs, and removable flash drives (also known as USB drives or thumb drives). By saving your data on removable media and keeping it in a different location (e.g., in your suitcase instead of your laptop bag), you can protect your data even if your laptop is stolen. You should make sure to secure the location where you keep your data to prevent easy access.
- Encrypt files - By encrypting files, you ensure that unauthorized people can't view data even if they can physically access it. You may also want to consider options for full disk encryption, which prevents a thief from even starting your laptop without a passphrase. When you use encryption, it is important to remember your passwords and passphrases; if you forget or lose them, you may lose your data.
- Install and maintain anti-virus software - Protect laptops and PDAs from viruses the same way you protect your desktop computer. Make sure to keep your virus definitions up to date (see Understanding Anti-Virus Software for more information).
- Install and maintain a firewall - While always important for restricting traffic coming into and leaving your computer, firewalls are especially important if you are traveling and utilizing different networks. Firewalls can help prevent outsiders from gaining unwanted access (see Understanding Firewalls for more information).
- Back up your data - Make sure to back up any data you have on your computer onto a CD-ROM, DVD-ROM, or network (see Good Security Habits and Real-World Warnings Keep You Safe Online for more information). Not only will this ensure that you will still have access to the information if your device is stolen, but it could help you identify exactly which information a thief may be able to access. You may be able to take measures to reduce the amount of damage that exposure could cause.
Authors: Mindi McDowell, Matt Lytle
Thursday, October 25, 2007
Packet Sniffing
When people communicate via IM, they do not realize their communication is probably hopping around numerous times through various networks and routers. On any network segment along this path, someone can use a packet-sniffing tool to intercept such communications. However, scanning through a large number of packets to extract something useful is very difficult. Thus, attackers also employ communication filters, software to detect and identify specific types of communication currently underway. When attackers get access to some wire, they attach a network device to that network segment. Next, they install a communication filter to capture packets that contain specific strings or patterns, such as the "password" keyword. If a pattern in the filter matches traffic from the wire, that packet is recorded for subsequent analysis. Flat, unswitched local area networks are particularly vulnerable to sniffing attacks because every packet traveling between two hosts is broadcast to all nodes on the network segments to which each host belongs. Thus, a sniffing device or program could be connected to any port or installed on any machine on the same segment. A few years ago, switching technology became sufficiently inexpensive to be widely accepted as a standard LAN building block. In many installations, switches replaced broadcast hubs and were used to micro-segment LANs into numerous virtual segments. Switches also establish point-to-point channels between pairs of hosts as they initiate conversations. This alleviates the problem of sniffing but does not eliminate it completely (especially if attackers can access the switch itself). In the real world it is at least difficult, if not impossible, to gain access to ISP facilities and install sniffers there. Therefore, the biggest source of sniffing threats stems from LANs and public facilities. Cable modem technology is particularly prone to sniffing-based attacks, because all users on a cable segment can see (and therefore sniff) all traffic on that segment. Companies or organizations that support remote access for cable modem-based users should definitely use more secure implementation, preferably those based on IPSec. Because so much information used in popular messaging software now takes the XML format using the HTTP protocol, traffic vulnerability to sniffing is actually on the rise. The latest trend is to convert everything to XML formats. Unfortunately, this also means that using HTTP without SSL or TLS is tantamount to sending information in clear text from the hacker's perspective. This explains why sniffer attacks are both insidious and potentially very dangerous because they can decode and reveal lots of sensitive information. To prevent information leaks, you can't rely on communication programs that use no encryption mechanisms; you must use IPSec or VPN solutions to secure communications both on the local network and for all remote access. If IM services are deployed for business purposes, use applications similar to Microsoft Exchange Server 2000, which enables you to operate your own IM server that might or might not interact with the rest of the world. As a matter of security policy and user education, users should also be coached on which types of communication and file transfer are appropriate using IM outside organizational boundaries—if indeed such use is permitted at all.
Wednesday, October 17, 2007
Using Caution with Email Attachments
Why can email attachments be dangerous?
Some of the characteristics that make email attachments convenient and popular are also the ones that make them a common tool for attackers:- Email is easily circulated - Forwarding email is so simple that viruses can quickly infect many machines. Most viruses don't even require users to forward the email—they scan a users' computer for email addresses and automatically send the infected message to all of the addresses they find. Attackers take advantage of the reality that most users will automatically trust and open any message that comes from someone they know.
- Email programs try to address all users' needs - Almost any type of file can be attached to an email message, so attackers have more freedom with the types of viruses they can send.
- Email programs offer many "user-friendly" features - Some email programs have the option to automatically download email attachments, which immediately exposes your computer to any viruses within the attachments.
What steps can you take to protect yourself and others in your address book?
Be wary of unsolicited attachments, even from people you know - Just because an email message looks like it came from your mom, grandma, or boss doesn't mean that it did. Many viruses can "spoof" the return address, making it look like the message came from someone else. If you can, check with the person who supposedly sent the message to make sure it's legitimate before opening any attachments. This includes email messages that appear to be from your ISP or software vendor and claim to include patches or anti-virus software. ISPs and software vendors do not send patches or software in email.Save and scan any attachments before opening them - If you have to open an attachment before you can verify the source, take the following steps:
- Be sure the signatures in your anti-virus software are up to date.
- Save the file to your computer or a disk
- Manually scan the file using your anti-virus software
- Open the file
Consider additional security practices - You may be able to filter certain types of attachments through your email software or a firewall.
Wednesday, October 10, 2007
Excel 2007and Excel Services 2007 involving calculation
So what, specifically, are the values that cause this display problem? Of the 9.214*10^18 different floating point numbers (floating point) that Excel 2007 can store, there are 6 floating point numbers (using binary representation) between 65534.99999999995 and 65535, and 6 between 65535.99999999995 and 65536 that cause this problem. You can’t actually enter these numbers into Excel directly (since Excel will round to 15 digits on entry), but any calculation returning one of those results will display this issue if the results of the calculation are displayed in a cell. All other calculation results are not affected.
fixes for this issue in Excel 2007 and Excel Services 2007 are available for download from the following locations:
Excel 2007: http://download.microsoft.com/download/6/1/3/61343075-aa12-4152-a761-fccc16d6cef4/office-kb943075-fullfile-x86-glb.exe
64-bit Excel Services 2007: http://download.microsoft.com/download/c/d/c/cdcccd84-86cd-4199-b01c-1df2dac66534/office-kb943076-fullfile-x64-glb.exe
32-bit Excel Services 2007: http://download.microsoft.com/download/c/d/c/cdcccd84-86cd-4199-b01c-1df2dac66534/office-kb943076-fullfile-x86-glb.exe
KB Articles have been posted as well:
Excel 2007: http://support.microsoft.com/default.aspx/kb/943075/
Excel Services 2007: http://support.microsoft.com/default.aspx/kb/943076
Monday, October 01, 2007
Registry Clean Expert: Fix&Backup registry

The Windows registry is a database repository for information about a computer's configuration. The registry keep growing when you use Windows. As it does so, it attracts obsolete and unnecessary information, and gradually becomes cluttered and fragmented. With the growing of the registry, it can degrade the performance of the whole system and cause many weird software problems.
Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry, your system will run faster and error free. The backup/restore function of the tool let you backup your whole Windows Registry so you can use it to restore the registry to the current status in case you encounter some system failure. Besides above, the startup and BHO organizer feature let you manage your startup and IE BHO items with ease, and you can control the programs started with Windows and IE more handy with this feature!
In short, Registry Clean Expert help you get rid of the bloat in Windows registry and achieve a cleaner, faster system..
Feature highlights include:
- Scan Windows registry and find incorrect or obsolete information in the registry.
- Fix the obsolete information in Windows registry with this Registry Cleaner and boost your Windows performance.
- Make backups for Windows Registry.
- Restore Windows Registry from previous backup.
- Manage the programs started when Windows starts up with the Startup Organizer.
- Manage the IE BHOs with BHO organizer.
- Remove Spyware, Adware and Trojan hidden in your startup items and BHOs.
- Registry Compact and Registry Defrag.
- Built-in Tracks Eraser for privacy protection.
- A user-friendly interface makes it easy for anyone to use Registry Clean Expert.
Thursday, September 27, 2007
Use Strong Passwords.
Your living space has doors and windows, and perhaps most of the time they’re locked. For each lock that uses a key, chances are that each key is different. You know to lock up and not to share the keys with strangers, and probably not with most of your friends. You should not hide keys under the mat or in a flowerpot on your front porch.
Passwords for computers are much the same. For each computer and service you use (online purchasing, for example), you should have a password. Each password should be unique and unrelated to any of your other passwords. You shouldn’t write them down nor should you share them with anyone, even your best friends.
A password can also be complicated. Most schemes let you use any combination of letters, both upper and lower case, and numbers; and some also let you use punctuation marks. Lengths can vary. You can create a password to be as complicated as you want. The key (no pun intended) is to be able to remember this password whenever you need it without having to write it down to jog your memory.
Like the thief at your door, computer intruders also use trial-and-error, or brute-force techniques, to discover passwords. By bombarding a login scheme with all the words in a dictionary, they may “discover” the password that unlocks it. If they know something about you, such as your spouse’s name, the kind of car you drive, or your interests, clever intruders can narrow the range of possible passwords and try those first. They are often successful. Even slight variations, such as adding a digit onto the end of a word or replacing the letter o (oh) with the digit 0 (zero), don’t protect passwords. Intruders know we use tricks like this to make our passwords more difficult to guess.
Just like the front door key, even a complicated password can be copied and the copy reused. Remember the earlier discussion about information on the Internet being in the clear? Suppose that really strong password you took a long time to create – the one that’s 14 characters long and contains 6 letters, 4 numbers, and 4 punctuation marks, all in random order – goes across the Internet in the clear. An intruder may be able to see it, save it, and use it. This is called sniffing and it is a common intruder practice.
The point is that you need to follow the practice of using a unique password with every account you have. Below is a set of steps that you can use to help you create passwords for your accounts:
- The Strong test: Is the password as strong (meaning length and content) as the rules allow?
- The Unique test: Is the password unique and unrelated to any of your other passwords?
- The Practical test: Can you remember it without having to write it down?
- The Recent test: Have you changed it recently?
In spite of the SUPR tests, you need to be aware that sniffing happens, and even the best of passwords can be captured and used by an intruder.
You should use passwords not only on your home computer but also for services you use elsewhere on the Internet. All should have the strongest passwords you can use and remember, and each password should be unique and unrelated to all other passwords. A strong password is a password that is longer than it is short, that uses combinations of uppercase and lowercase letters, numbers, and punctuation, and that is usually not a word found in a dictionary. Also remember that no matter how strong a password is, it can still be captured if an intruder can see it “in the clear” somewhere on the Internet.
Wednesday, August 29, 2007
Norton Internet Security 2008
Norton internet security 2007 is a very useful internet security utility that will protect your computer while you surf online.
The chaos and rapid growth of the world wide Web have created the perfect environment for malicious and damaging entities that threaten your PC and your identity. The important documents stored in your computer must be protected from hackers and other virtual prowlers. With Norton Internet Security, you will be able to enjoy your computer with confidence, knowing that viruses and spyware will be either blocked or removed. All kinds of malicious programs will be removed automatically, including the damaging side effects.
Key Technologies
- Antispyware
- Antivirus
- Two-Way Firewall
- Advanced Phishing Protection
- Intrusion Prevention
- Rootkit Detection
Features
- improved performance delivers faster starts and scans.
- One click access to expert support.
- Network security monitoring helps protect your wireless network.
- Norton Identity Safe delivers enhanced i dentity theft protection.
- Works quietly in the background.
- Protection for up to 3 PCs per household
- Blocks identity theft by phishing Web sites
- Protects against hackers
- Detects and eliminates spyware
- Removes viruses and Internet worms automatically
- Protects email and instant messaging from viruses
- Prevents virus-infected emails from spreading
- Rootkit detection searches underneath the operating system using patented technology
- Includes protection updates and new product features as available throughout the renewable service period
- On-going Protection option automatically renews your subscription
- Need antispam or parental controls?
Go to Norton Internet Security 2008
Monday, August 27, 2007
Update Salfeld Child Control 2007
Give children an “allowance” of time
Child Control 2007 keeps track of the time your kids spend in front of the computer. Once their time is up, the computer automatically shuts down and won’t start up again—something any kid can understand. Our experience has shown that Child Control 2007’s verdict is accepted without arguments—there is no debate and no discussion. Another way of looking at it: “Child Control gives your kids back time that they are then free to spend in other ways.”
Safety on the Internet
It isn’t always easy to watch your young ones’ every move on the computer—and it’s even harder to follow what they’re doing on the Internet. Child Control 2007 can also help you here, by automatically shutting the door on their Internet connection once their allotted time is used up. Parents can easily regulate how many hours a day each child can spend on the Internet, and even specify the precise hours of the day when the gate to the worldwide online community will be available.
The Dark Side of the Internet
Sure, you can find any number of sites that are useful for learning, reference, and games. Then there are the other ones that are clearly inappropriate for children and teens. Some parents also worry about their children ending up on one of these sites by accident, or as the result of a dare. These fears can be quickly put to rest by Child Control 2007, which has already made a name for itself in Internet monitoring.
Control Internet access using filters
Child Control lets you activate filters to block all websites oriented toward violence or sex. You can also filter out specific words that may appear on various websites. Alternatively, you can limit access to only the websites that you specify. In that case, your kids will only be able to access these sites, and all others will be off-limits. In the 2007 version, parents can also limit their kids’ stay on certain sites to a specified time, so that eventually they will have to put their online games away and get back to their homework.
System Requirements
Our products use very few system resources and can easily be run on older PC's. Software programs listed here can be run on all current Windows platforms (Windows 95(b), 98, ME, NT, 2000, XP, XP SP2 (home und professional). Resource usage is relatively light: a Pentium II, Celeron, or AMD Athlon/Duron running at 266 MHz or above; a mouse; VGA (800x600 or higher); 64MB RAM; and 5 MB free disk space per application are sufficient.
Download the trial version : Salfeld Child Control 2007
Visit Site : www.salfeld.com
Friday, August 24, 2007
Microsoft Windows Vista Weather Gadget vulnerability
The Windows Vista Weather gadget contains a vulnerability that may allow and attacker to execute code.
Gadgets are mini-applications designed to provide the user with information or utilities. Windows Vista treats gadgets similar to the way Windows Vista treats other executable code. Gadgets are written using HTML and script, but this HTML is not located on an arbitrary remote server as web pages are. HTML content in the Gadget is downloaded first as part of a package of resources and configuration files and then executed from the local computer. This download process is similar to applications (.exe files) downloaded from the Internet.
Today, the Windows Vista Sidebar hosts Gadgets built from HTML, JavaScript, and potentially ActiveX controls, and because Gadgets are HTML, they are subject to Cross-site Scripting style bugs. These bugs are extremely serious because script in the Sidebar is capable of running arbitrary code in the context of the locally logged-on user.This document outlines some of the secure programming best practices that should be considered when building Windows Vista Sidebar Gadgets.
Never Trust Input
This is the same advice we have given for years, and it still holds true for Sidebar Gadgets. Many Gadgets read, manipulate, and then display untrusted data, such as that coming from an XMLHttpRequest object or an ActiveX control. All such input needs to be validated.
Validate Untrusted Input
There is no replacement for a good input checker. You should build a function or functions that include regular expressions to verify that the input is correctly formed, and if it is not, you should reject the data. Below is a loose example that only allows numbers, brackets, dashes, and spaces between 6 and 14 characters long.
More Information MS07–048
Monday, August 06, 2007
What is Phishing and Pharming?
Avoiding Social Engineering and Phishing Attacks
What is a social engineering attack?
To launch a social engineering attack, an attacker uses human interaction (social skills) to obtain or compromise information about an organization or its computer systems. An attacker may seem unassuming and respectable, possibly claiming to be a new employee, repair person, or researcher and even offering credentials to support that identity. However, by asking questions, he or she may be able to piece together enough information to infiltrate an organization's network. If an attacker is not able to gather enough information from one source, he or she may contact another source within the same organization and rely on the information from the first source to add to his or her credibility.What is a phishing attack?
Phishing is a form of social engineering. Phishing attacks use email or malicious web sites to solicit personal, often financial, information. Attackers may send email seemingly from a reputable credit card company or financial institution that requests account information, often suggesting that there is a problem. When users respond with the requested information, attackers can use it to gain access to the accounts.How do you avoid being a victim?
- Be suspicious of unsolicited phone calls, visits, or email messages from individuals asking about employees or other internal information. If an unknown individual claims to be from a legitimate organization, try to verify his or her identity directly with the company.
- Do not provide personal information or information about your organization, including its structure or networks, unless you are certain of a person's authority to have the information.
- Do not reveal personal or financial information in email, and do not respond to email solicitations for this information. This includes following links sent in email.
- Don't send sensitive information over the Internet before checking a web site's security policy or looking for evidence that the information is being encrypted (see Protecting Your Privacy and Understanding Web Site Certificates for more information).
- Pay attention to the URL of a web site. Malicious web sites may look identical to a legitimate site, but the URL may use a variation in spelling or a different domain (e.g., .com vs. .net).
- If you are unsure whether an email request is legitimate, try to verify it by contacting the company directly. Do not use contact information provided on a web site connected to the request; instead, check previous statements for contact information. Information about known phishing attacks is also available online from groups such as the Anti-Phishing Working Group (http://www.antiphishing.org/phishing_archive.html).
- Install and maintain anti-virus software, firewalls, and email filters to reduce some of this traffic (see Understanding Firewalls, Understanding Anti-Virus Software, and Reducing Spam for more information).
What do you do if you think you are a victim?
- If you believe you might have revealed sensitive information about your organization, report it to the appropriate people within the organization, including network administrators. They can be alert for any suspicious or unusual activity.
- If you believe your financial accounts may be compromised, contact your financial institution immediately and close any accounts that may have been compromised. Watch for any unexplainable charges to your account (see Preventing and Responding to Identity Theft for more information).
- Consider reporting the attack to the police, and file a report with the Federal Trade Commission (http://www.ftc.gov/).