Mostrando entradas con la etiqueta security. Mostrar todas las entradas
Mostrando entradas con la etiqueta security. Mostrar todas las entradas

domingo, 26 de diciembre de 2021

2021 Is Coming to its End: Time for the Yearly Backups!

 This year has only a few days left.  That means I have to complete the yearly backups.

I still remember the old days, when backups were not fun at all. I mean, I had to format my Windows computer every 6 months and thus, having backups was vital because eventualities would occur regularly.

Right now, although I keep my backing up practice (which I highly recommend to everyone), I haven't had the need to restore from them in years.  In fact, I even have cloned images of my Linux systems that I place on different computers. Thus, if anything happens, I just insert a live USB and install my system with all the configurations.  I keep the files on different media.

Tomorrow I will do the backup of the latest files and I will be ready for next year.

On a different note, I found this image.  That penguin looks familiar! 馃槣  I guess you can find Linux everywhere now! 


 

 


lunes, 21 de marzo de 2016

Security: antiX 15.1 and MX-15 Devs Now Sign their ISO Files

After the hacking of Linux Mint's site, other Linux developers have been thinking about an extra layer of security to ensure that what the end user downloads is actually what the original developers uploaded.

In the case of antiX and MX-15, this new security layer has taken the shape of signed ISO files.  This way, users can verify if their downloads are the real ones of if they have been tampered somehow.

This represents a little more complication for the end user, of course.  He or she will have to import the signature and then check that the ISO file matches that signature.  That, in turn will translate in seeing messages like:

Good signature from "aaaaaaa"
WARNING: This key is not certified with a trusted signature!
There is no indication that the signature belongs to the owner.

This will disturb some, of course. I can almost hear some people complaining that this is too complicated and that the messages are annoying or scary.  They may even argue that devs shouldn't bother users so much with their inconvenient ideas.

I guess they are the kind of people that will leave their cars open and already started, the front doors of their houses unlocked, and their children unattended because doing all that is extremely inconvenient.

Security and comfort don't seem to go side by side all the time.

viernes, 26 de febrero de 2016

Learning from the Hacking of Mint

Recently, Linux Mint experienced a security breach.  What can we learn from it?

1.  Security is always an issue. It doesn't matter what you do, you always have to be alert.

2.  Convenience tends to get in the way of security: the more convenient something is, the less secure it tends to become.

3.  Transparency and honesty are the best way to handle security issues.  Ignoring them or denying them only increases their negative impact (and reduces one's credibility.)

4.  Security cannot be fully automated. A responsible person must always be in charge.  Those who think that automatic face or fingerprint recognition are the best security tools must think who is in charge of programming and calibrating such devices... and how secure the process leading to that automated recognition actually is.  Also, these days it is way easier to steal someone's face with the help of Facebook, latex masks and 3-d printers than stealing a good password.

5.  The person in charge of security must act promptly once security is compromised.  Any delay is unforgivable.

Now, specifically, what measures could other distros take to make their sites safer?  Here are some:

a- Signing the final iso files.
b- Signing checksums.
c- Keeping such signatures in a very secure server.
d- Using HTTPS (SSL).

Those are some thoughts.  Any others will also be welcome.

domingo, 11 de mayo de 2014

The Good Ol' Antivirus is Dead??

According to the Wall Street Journal, Symantec has declared antivirus software dead.  Woah!  That's a pretty strong claim, especially considering that Symantec is attributed the invention of commercial antivirus software.

What's the problem?

Basically, that they got tired of the endless mouse-catching game antivirus is in.  We have to face the truth: malware is usually a step (or many) ahead of antivirus software.

Thus, what they will be doing now is assuming that the computers are compromised to then try to minimize the damage.

This forces us to make a series of interesting observations:

1.  No matter the antivirus you use, your computer will be eventually assimilated into a cyber criminal's network.

Now, this observation is seriously flawed.  First, the main problem is not the computer; it is the OS.  Guess which OS are they talking about (without saying it, of course)?      

2.  If companies will focus on minimizing potential damages caused by malware, that means some damage will have to be done first.

No, it doesn't necessarily mean that, right?  It is about distracting criminals with fake information and knowing how and why they enter a specific computer network.

Well, maybe they could figure out ideas for tightening security so that damages do not occur.  But what does "tightening security" mean?

Maybe  adding new features to their software to help the user?

And why not going a step beyond that and we add features to the hardware, too?

Yes!  We could have something called "Secure" Boot enabled by default "to prevent" breaches!  The problem is that the so called "Secure" boot has never been secure in the first place.  I've seen how computers with that and running Windows 8 have been easily hijacked but not so easily fixed.

Also, "Secure" (I always prefer to call it "restricted") boot is causing a much greater damage than those it seeks to prevent: now you can't even control your hardware but others can.  You pay for hardware and others are the ones who can actually use it.  Of course, they have your best interests at heart.   

Of course, there are alternatives to this.  Why not using a safer OS to begin with?  That could create a truly competitive market that would force Microsoft to get their act together and actually design a secure OS.  Will that be Windows 10, maybe?

martes, 26 de marzo de 2013

¡Felicitaciones Hispalinux!

Hoy le铆 con mucho agrado que la agrupaci贸n Hispalinux formul贸 una queja ante la Comisi贸n Europea (por medio de su oficina en Madrid) por la forma en que Microsoft forz贸 el uso de UEFI y Restricted Boot con Windows 8.

Aunque Microsoft insista en que todo es legal y que es por el bien de los usuarios, ya est谩 m谩s que visto que el Restricted Boot (al que les gusta llamar "Secure" sin razones de peso) solamente le aporta seguridad a la empresa de Redmond...le aporta la seguridad de que va a ser mucho m谩s dif铆cil instalar otro sistema operativo en esos equipos.

Agradezco a Hispalinux por su valor.  Espero que les vaya bien en esta batalla legal y que la Comisi贸n Europea analice seriamente la cuesti贸n.  ¡Felicitaciones Hispalinux!



 

jueves, 7 de marzo de 2013

Browsers, Operating Systems, and Pwn2Own

This is bad news.

Apparently, Microsoft's Internet Explorer 10, Google Chrome, and Mozilla Firefox fell prey at the famous hacking contest Pwn2Own .


The worst part is that they were beaten on the very first day of the contest.

No, that is not the worst part.

Actually, the worst part is this:

Bekrar’s IE10 hack bypassed all of the protections built into Windows 8 and IE and allowed code to be executed without crashing the browser.

So, it is not even 6 months after the launching of Windows 8 with its powerful "secure boot" and it was hacked on the first day?  Let's remember: "secure boot" was so necessary that it was mandatory for Windows 8 to run.

And what about Linux?  It is not present in this contest since 2008.  The reason given in 2011? "Because it is not a widespread system."  I guess the fact that it wasn't hacked in 2008 had nothing to do with that. 

Now...there are some points to ponder about Windows 8.

1.  If it took hackers one day to bypass all of Windows 8's security features, was it true then that "secure" (let's call it "restricted" until it actually becomes secure) boot was so secure as they told us? It had been hacked previously, too.

2.  What's going to happen now?  Will Microsoft actually patch Windows 8 or they will simply keep that information secret? 


jueves, 28 de febrero de 2013

Good-bye Passwords! Hello Disaster!


According to this article, Paypal will soon adopt a new technology that will enable people to use, instead of those lousy, lowly, easy-to-hack passwords, that person's fingerprint.

Is this something to be cheered or looked forward with joy?

I mean, right now cyber criminals can give you lots of headaches if they get one of your passwords.  Can you imagine what they can do if they get your very fingerprints? You'll use them also as passwords, don't forget.

During my Windows days, I got my Paypal account hacked and used for a small transaction.  When I discovered it, I contacted Paypal and they, very professionally, after having investigated the issue, corrected the situation.  But I was required to change my password, obviously.

What are they going to do in similar cases now?  Will they ask people to change their fingerprints?   :P

I don't have any problems with my passwords.  Linux takes care of them very well.  Why would I like to give my fingerprints to strangers all over the world?

This takes the idea of "no privacy over the Web" to a brand new level!

It seems that laziness and ignorance, combined with technology, are causing some parts of our brains to go dormant.  We have smart phones, smart watches, soon smart glasses...but no smart minds. When will they invent an app to wake up our brains? 


viernes, 6 de abril de 2012

Apple Malware and Security



Yesterday, I read an interesting article about "Flashback" malware infecting about half a million Apple computers.

While this is not new--Apple computers have been infected with malware before--, the article mentioned three elements that made the infections possible:

1. Apple's software management
When Oracle detected the problem, they issued a vulnerability fix. This fix, however, did not reach Apple users immediately because Apple keeps a tight control of its software. The official fix by Apple was issued two months after Oracle's. Two months is quite a long time, and even if you think it isn't, please remember that not all users apply updates as soon as they are ready. Maybe this is why 500,000 Apple computers are still infected. Of course, half a million computers may seem a very modest botnet compared to Windows botnets, which this year may reach about 10% of all Windows systems according to a Damballa Threat Report, but it is still a lot of computers.

2. Naivete of computer users
According to the article, the malware disguised itself as a Flash Player update. This means something like "If you want to watch this video, you must install this Flash Player update first." When users "updated" their Flash Player, they got a Flashback infection instead. Until when will computer users be easy victims of such social engineering tricks? The problem I see is that the current tendencies in computing are actually making users more and more naive. Now they just want to use the computer without thinking. That is horribly dangerous from my perspective. Any activity a person does without thinking is dangerous. If you don't want to use your brain, someone will use his/hers and will take advantage of you. If you don't want to take my word, then take a snapshot of the computer's wallpaper of any of your friends, attach any stupid error window message to it, then secretly replace the actual wallpaper with your creation, and see what happens when your friends see it.



At least one of them may fall for it because more and more people are being trained not to use their heads when they get near a computer. That is sad.



3. Overconfidence of users about their systems


Owners of Apple computers tend to believe they are immune to viruses and malware, so they take little precautions when being online. This is also true about Linux users. Again, a system may be rock solid, but the weakest part of security systems is the individual responsible for the security. If you believe that Microsoft, A/V companies, Apple, or Tux are the main, or the sole responsible for your computer security, you are the Achilles Heel of your system. That responsibility is yours!

Some systems may be stronger than others, but you must keep an eye open and learn about your system.

s谩bado, 2 de abril de 2011

I Just Got Fooled!


After a hard work's day, I came home and started browsing the Web. Then, I stumbled upon an article about a major security hole found in Linux Kernel that worried me quite a bit .

I asked some fellow Mepis users about that and the security status of Mepis...

One of them kindly pointed out some details of such article:

Archive Category: Humor
Keyword Tags: kernel security hole fooled you


Yes. I have been fooled and the whole web knows about it! :P

Still, there's something I like a lot about this prank...

You see, it's great to have an OS whose security flaws end up being for the most part either pranks or FUD. I'd be running around like crazy while trying to find patches and updates to protect my old OS a couple of years ago. Right now, even though I'm embarrassed because I was fooled so easily, I'm very happy as well because with Linux, security is real and what the rest of the world considers imminent PC threats are just chances to develop my sense of humor now.

jueves, 17 de marzo de 2011

Eight Questions about Windows 8



Windows Vista/7 has not gotten widespread yet and there's already noise about its successor, momentarily labeled "Windows 8."

Among all the new features it will have (according to rumors), we can list these:

- Aero will be gone with the Wind.

- Win 8 will make the most of your Live ID Passport whatever.

- Win 8 will run in devices as small as a phone and as big as the Batcomputer.

Now, I (and probably not just me) have a couple of questions about features I'd like to see in Windows 8:

1. Will it be safer by any chance or it will let legacy viruses and malware run? I mean, what good will the new OS be if old Win XP viruses break havoc in its guts?

2. Will it treat its legitimate users as that or it will treat them as potential pirates as its predecessors do?

3. Will it play fair with costumers or it will hide important information from them, like data collecting and so?

4. Will it play fair with other OSs or will invent "hard drive problems" to prevent installation of other choices?

5. Will it call infections "WINDOWS INFECTIONS" instead of "computer infections"? WOW! That'd be nice!

6. Will it be a real innovation or it will be "Seven with lipstick"?

7. Will it include digital coupons to make its warranty effective right in Microsoft's own stores as its predecessors include digital signatures and activation codes or it will rely on 3rd. party technicians who just know about formatting and reinstalling?

And maybe the most important...

8. Will it be worth its price or it will be another expensive Service Pack as Vista/7 was of Vista?

I really hope Microsoft's developers are seriously working on these eight issues for the benefit of most computer users...it's the least they could do, isn't it?

s谩bado, 12 de marzo de 2011

Zombie attack: University Network Collapsed!


I survived my first week of this new semester at the university! However, the network during this first week went from slow and unstable to totally useless. It seems it didn't survive the first week of classes!

What happened? Nobody quite knew until Mechatotoro told me. A zombie computer started sending spam and caused a networking collapse.

Now, let me correct my words. It was not a zombie computer. It was a zombie WINDOWS XP computer. Why do I make the distinction? Because in the same office, there was a computer running Mandriva Linux and it was the only one that was clean.

At this point some might be thinking "But XP is an old OS! That's what you get when you rely on old technology!"

Is that so? There was a Windows 7 computer in that office, too. Was it any better than XP? Not quite. You can read Mechatotoro's account here.

Again, we are talking about Windows flaws, not about computer problems. The computers were in perfect shape.

So, could we say that Windows 7 is actually a more secure system than XP? The case in this office clearly shows what system is superior (and it does not come from Microsoft.)

Also, where was the "great support" from Microsoft? As far as I know, the university had to solve the problem on its own even if the computers had original copies of Windows.

Maybe it's about time users got smart and instead of sheepishly accepting Windows security flaws as "computer problems", started nagging Microsoft until this company actually released some secure OS version or at least took full responsibility for the flawed systems they ask so much money for.

mi茅rcoles, 6 de octubre de 2010

Planning to Migrate to Linux? BEWARE!!!


As more noise in favor of GNU/Linux is heard, some people might feel tempted to replace their solid, green-red-blue-and-yellow Windows system with an unknown, shady, black-and-white Linux penguin. Some of these users, thinking they are about to enter the Promised Land, fail to fully consider the disastrous consequences that abandoning the firm, old Windows tradition may cause.

In this light, I found appropriate to let these naive migrants know a number of issues to consider before they take the leap to their doom. These issues are based on empirical, but honest observation and may bring upon me the deepest animosity among GNU/Linux fans...even so, I'm determined to continue. The truth will be by my side.

Dear Windows user, before you migrate to Linux, make sure you understand some of the side-effects that may come after you take your experimental Linux pill:


1. Your computer may become dull or stop working:

Windows is a happy, efficient world where computers respond promptly and just work. They work and work even when you don't know. They work as zombies and botnets, sending spam mail (in the best of the cases) for some hacker out there who rightfully earned control over them. Just last year, there was an estimate of twelve million zombies. That is four times the whole population of a small country like mine. Imagine! A whole country made of zombies!!! That is a happy country! Windows is a happy world in which you (if you're a hacker) command and computers react. They react promptly to Trojans, worms and malware of all forms under the sun. If you install Linux and use it as your main OS, your computer may stop reacting to the Trojans, worms and malware that took cyber-criminals a lot of time and effort to design. Of course, if you engage into irresponsible security behavior, your PC may still be responsive to them, but not as it was with Windows. Are you sure you want a dull computer like that? Who wants a computer that fails to respond to malware by default? What? Your computer has never been part of a botnet, you say? Are you sure? Then, why is it that some users complain that their PCs still download updates regardless of their preferences? They are part of the biggest botnet in the world, that's why!

2. You will be totally unprotected:
Yes. It is not a mistake. Installing Linux will drag you away from computer protection. Windows users are protected by a very strong, fortified system of placebos: the solid support from Microsoft (that usually ignores or denies the problems, but after a considerable number of users complain, gives in and releases the patches), the A/V technologies (that are always playing catch-up with the malware), and Windows Security Essentials (that are pretty similar to A/Vs, but create a much better placebo effect because they come right from Microsoft). In contrast, once you install Linux, the only responsible for your protection will be yourself...and the penguin, that by the way, is armored to its teeth (yes! that bird has teeth and uses them to gnaw malware as fish!) Why would you want to take care of your own security as the Robin of a Bat-penguin if the placebo system will let you relax making you think that it is on charge (even if it isn't)?

3. Your world will go upside down:
Beware! Great danger here! After getting acquainted with Linux, you may discover some awful truths that will make your world shatter like broken Windows. For example, you may discover that you were paying for features Open Source gives you for free! Also, you may realize that some hardware manufacturers innocently make Linux installation and support harder...but who cares? That benefits indirectly our old friend! Your printer or scanner don't work? It is your fault for choosing to install an OS that is not proprietary and therefore has no proprietary drivers. You may then realize a horrible truth: companies don't care about customer satisfaction with their product...they just care about their policies. What's to them that you cannot use your hardware? You bought it already, silly person! You may also realize that all the hardware improvements your OS demanded from you were totally unnecessary. Linux could give life to that old computer you had sitting on a corner collecting dust. Imagine if all those old computers that people sent to the trashcan were still working perfectly...yes...much less pollution and a greener world. Forget the thought. All of us will die anyway, so let's keep littering and let our traditional OS tell us we need to replace our computers when we actually don't need to! That is part of life!

4. Your rights will be severed:

Linux is not just Ubuntu. This is a hard concept to grasp and it might blow your mind. Yes, Windows is Windows regardless if it is 3.11, 95, 98, 2000, ME (Wow! This is such a jewel!), XP, Vista (Another little gem!), or Vista/7. They all are Windows, full of the friendly features you cannot miss (BSODs, system crashes, freezes, etc.). What about Linux? Ubuntu? Naaah! Ubuntu is just ONE Linux flavor and all Linux flavors behave quite differently. With Windows, things are simple: if your Windows doesn't work, you have a dead computer. Simple and nice. With Linux, things are so complicated! If Ubuntu doesn't work, then there is Mandriva. If Mandriva doesn't work, then you could try Mint. No? What about Mepis? What did you say? All of them worked fine but but you don't like them? You can fully customize them as you want. No time for that? Then try Fedora, PCLinuxOS, Debian, OpenSuse, Sabayon, Pardus, Arch, Slackware, Red Hat, Puppy, Knoppix, Elive, Unity...and the list goes on! Why does Linux have to make things so complex? Who wants so many options plus the total freedom to choose? Doesn't that crazy penguin know that it is much better to tell users what they need or want and limit the choices to 5 options most (reducing them progressively, too)? That is the RIGHT way of doing things because your right is to be kept on a nice leash (as your computer, crippled by design, is)! Freedom is for free people and in this happy world being free means being sad...and alone. Therefore, Linux brings sadness! Get Linux, get ready for a very sad life!

I could continue mentioning the dangers of the learning process (remember: learning makes sick brains!) that embracing that obnoxious penguin may also bring about, but I'm done for now. I will just sit down and wait for GNU/Linux fans to start tearing me apart rabidly. Hopefully, dear Windows user, you will think twice before falling for Linux.

mi茅rcoles, 15 de septiembre de 2010

Stay Protected with Windows...Nah!!! Now .DLLS??!!

This is a short list of vulnerabilities you must pay attention to on a daily basis if you intend to keep your Windows system secure (enough):

1. E-mail viruses
2. Internet viruses
3. Macro viruses
4. Rootkits
5. Spyware
6. Ransomware
7. USB viruses
8. Beacons
9. Pdf exploits
10. flash exploits

You have them all covered, you say? Great! Now, what happens if your very system files become part of the problem? Let's say, your .DLL files?

Did you know that your dynamic library files (.Dll), used vastly by Windows OS and windows applications are now being hijacked? Did you know that your Windows system can download unwanted .dlls from sources you did not ask it to? This problem is listed as KB 2269637

Did you know that this problem affects the powerful Windows Seven as well as Vista and XP? However, it affects just a few applications nobody uses, such as:


1. Adobe Dreamweaver
2. Adobe Photoshop
3. Adobe Illustrator
4. Avast!
5. BS Player
6. Camtasia Studio
7. Corel Draw
8. Daemon Tools
9. Google Chrome & Google Earth
10. Intervideo WinDVD
11. iTunes
12. Microsoft Office Powerpoint
13. Microsoft Office Word (with its acclaimed .docx!)
14. Microsoft Virtual PC
15. Microsoft Windows Mail & Live Mail
16. Microsoft Media Encoder
17. Mozilla Firefox (fixed in version 3.5.12 & 3.6.9)
18. Nullsoft Winamp
19. Nvidia Driver
20. Oracle Java

This is by no means a full list. Interestingly enough, open source applications have responded more quickly to fix the vulnerability. Anyway, there is a very simple process to auto-audit your system and find its vulnerable applications. Needless to say, you must first grab a copy--the latest copy--of DLLHijackAuditKit. Then, you must follow a series of simple steps listed on Metasploit, like:

1. Download the DLLHijackAuditKit v2 and extract it into a local directory on the system you would like to test.

2. Browse to this directory and launch 01_StartAudit.bat as an Administrator. The Administrator bit is important, as it will allow the script to kill background services that are spawned by the handlers and prevent UAC popups.

3. After the audit script completes (15-30 minutes), switch to the Process Monitor window, and access File->Save from the menu. Save the resulting log in CSV format to the local directory with the name "Logfile.CSV".

4. Launch 02_Analyze.bat as an Administrator. This will scan through the CSV log, build test cases for each potential vulnerability, try them, and automatically create a proof-of-concept within the Exploits directory should they succeed.

5. Identify the affected vendor for each generated proof-of-concept and ask them nicely to fix their application. Send them the calc.exe-launching PoC if necessary.


What? This is for techies you say? These are the EASY instructions with the newest version of the software! Well, if what you want is a list of applications with the problem, then take a look here, but keep in mind that the list there is not extensive either.

To protect yourself, you can follow the "easy" steps Susan Bradley describes in her article here, for example:

Based on my reading and testing, thus far, simply downloading patches to fix the problem might break some of my critical business applications. If you use the DLL patch process offered by Microsoft in MS Security Advisory 2264107 (more on that below), do so on a separate test PC first and then look for problems with your apps. If you do run into a problem, look for updates for your software and consider disabling WebClient Service, if possible (discussed below).

Security expert HD Moore has two DLL-fix recommends in his blog, but home users may find them difficult to implement.

First, check that your local firewall is preventing outbound Server Message Block (SMB) file processes. To do this, see whether the local firewall lets you block traffic through ports 135 and 445. But be careful: if you have a peer-to-peer home-network environment, you may need these ports.

Another method is to check your DSL- or cable company–supplied router's firewall settings. See whether you can adjust it to specifically block ports 135–139 and port 445. On my Linksys router, the port-filtering section lets me control up to five different ranges of ports.

Moore's second recommendation is to disable the WebClient Service, which will then block the Webdav vulnerability. (WebClient lets Windows apps create, access, and change Web-based files.) But this, too, should be done with caution — it might disable services such as Skydrive and JungleDisk. To turn off WebClient, go into Control Panel, Administrative Tools, and then Services. Scroll toward the bottom and click WebClient. On the WebClient control windows, find Startup type and select Disabled.


Whoa! Did you get it??!!

But don't fear, my friend! Microsoft won't let you fall! You just have to download and apply a patch to your already ragged and fully patched system. Here is the explanation by Microsoft. However, as with everything in life, you must brace yourself and pray that the patch won't break any of your important applications:

If you want to test Microsoft's DLL-blocking solution, go to MS Support article 2264107 and scroll down to the Update Information subsection and find the update for your specific platform. Install it and reboot your computer.

Now you're ready for step two: go to the Fix it for me subsection in article 2264107 and click the Fix it button. Clicking the button automatically creates a Registry entry that blocks "nonsecure DLL loads from WebDAV and SMB locations."

Should one of your applications stop working after the fix, you can try the following tweak to the Registry:

* Click Start and Run, then type in regedit and click OK or hit the Enter key. Scroll down the Registry list to HKEY_LOCAL_MACHINE and expand the tree below it.

* Now, navigate down the tree through SYSTEM, CurrentControlSet, Control, and Session Manager (circled in yellow in Figure 4).

* Click on Session Manager and look for CWDIllegalInDllSearch in the list to the right (also circled in yellow in Figure 4). Double-click it.

* In the Edit DWORD Value window that pops up, change the Value data from 2 to 1 and try again. If you still have problems with an app, change it to 0 and push that vendor to fix their application.


Great! This is a piece of cake! :P

I definitely agree with Joany, a fellow Mepis user who let us know about this situation in the Mepis Forum: How can Windows fanboys still say that Linux is hard?? Does that mean that following all these steps just to check if your system is at risk (which probably is) and then to fix it is actually simple??

Give me a break!

jueves, 9 de septiembre de 2010

I Got My First Beacon!


Hey, who'd have said it? Today I used a public computer powered by Windows Seven (with its updated antivirus); I inserted my USB stick there and in doing so I got my first beacon!!

If you don't know what a beacon is, please read this post: "On Computers, Cookies, and Beacons."

Wow! The computer was infected with a virus that not only created an autorun.inf file pointing to a special folder in which the virus was hidden, but also gave me as a nice Children's Day present a small file with a code...

Surely enough, none of the three elements could be removed because it lacked the corresponding permissions.

What was left for me to do then? Well, changing their permissions with a couple of clicks and then to place all those files together into a compressed folder for my brother's Outstanding USB Virus Collection Version 2.0

What antivirus did I use? None!

How did I find them? Because I was using Linux. Had I used Windows, probably those files would be invisible and both the virus and my first beacon would be right now working together to send I-don't-know what-important-information to I-don't-know-who.

I really don't like that idea. If you use Windows, please be careful. Double check your USB sticks or don't use them in a public computer. Better yet, try Linux to check their contents after using them in another computer.

lunes, 23 de agosto de 2010

Windows Users: Zeus Is after Your Money!!!!


These two months have been such a tough period of time for Windows users! Last month, the menace of W32.Stuxnet worm, which spreads through USB devices, was discovered targeting industrial manufacturing plants...
Now, the newcomer this month is the newest version of Zeus, a trojan and keylogger which apparently contains Windows-like anti-piracy technology (??!!) and has already emptied $1 million from bank accounts in the United Kingdom! Wow! It seems that now even Greek gods want to compete with Microsoft for the money that Windows users may have!
This Zeus trojan (as paradoxical it may sound...The Greek God being a Trojan??!! Oh, well!) can be obtained, according to the article, by either visiting a legitimate Web site that is secretly hosting the malware, or a site designed to host the malware, or a legitimate site hosting the malware in an advertisement. It also mentions that the primary attack came through malicious advertisements, including ads delivered by Yahoo's Yieldmanager.com. That's bad advertising indeed! Then, Zeus acts as a keylogger and a password stealer, but it also does more than that: it tests the victim machine for each exploit it knows in order to get a successful infection.
Ah, but there's more: "When the user accesses his or her bank Web site, the Trojan transfers the log-in ID, date of birth, and a security number to the command-and-control server. Once the user accesses the transactional section of the bank Web site, the Trojan receives new JavaScript code from the outside server to replace the original bank JavaScript used for the transaction form.

When the user interacts with the transaction form for legitimate business, the Trojan works behind the scenes to manipulate the transaction. First it checks the account balance and if it is over a certain amount it will determine how much to steal within a limit so as not to trigger automatic fraud detection alarms."


Dear Windows user: it's time you seriously consider doing your online banking safely. Are you afraid installing GNU/Linux on your PC will bring Microsoft's wrath on you and your family for three generations? How about a nice Linux Live CD, then? GNU/Linux doesn't bite, you know? Even if it did, it can't be compared to realizing someday you were a victim of Internet criminals. Are you willing to wait until someone empties your account to act?

viernes, 13 de agosto de 2010

Noise about Linux


After the FUD article published not long ago by Ken Hess for PC World, Katherine Noyes, from the same magazine, has come up in defense of Linux. She wrote two articles:

1. Is Linux Really Harder to Use?


2. Why Linux is More Secure than Windows

Also, in terms of security, it's interesting to see how Windows advocates keep saying "Windows is safe. Just download MS Security Essentials..."

The executable installer for XP is 11 MB and for 7/Vista is 7 MB. I don't really know if that covers the full download or that will act as a downloader for heavier files...

Anyway, it would also be interesting to investigate why those "essentials", being so essential, are not included with Windows to begin with. Why does MS make acquiring those vital security tools the user's responsibility? Is it really that hard to include them with the mastedon-size and voracious resource-eating OS they currently promote? If they can't even include "security essentials" in their DVDs, what are those media filled with? Letters to Santa Claus?

I don't know! :P

domingo, 8 de agosto de 2010

On Computers, Cookies, and Beacons


Some people still surf the Web without thinking at all about their privacy. Firefox does its best to offer solutions that let users surf and at the same time protect their identity. However, Internet spying on users is becoming more and more difficult to prevent.

This article provides very useful information about one of the latest trends used by companies to spy on Web surfers and collect information about them: Beacons.

According to the article, Beacons are small files stored in a computer. They consist of a single code that stores data about specific user. For example, in the case of the woman in the article,

The file consists of a single code— 4c812db292272995e5416a323e79bd37—that secretly identifies her as a 26-year-old female in Nashville, Tenn.The code knows that her favorite movies include "The Princess Bride," "50 First Dates" and "10 Things I Hate About You." It knows she enjoys the "Sex and the City" series. It knows she browses entertainment news and likes to take quizzes.

Now, wasn't that the same as a cookie?

Not really. Cookies are text files that keep track of the websites a person visits, so they are much more limited and open to scrutiny. See the difference?

We don't stand much a chance with the increase of these tracking technologies. I don't want to sound paranoid, but did you read about Samy Kamkar, the hacker who successfully tracked online one computer with an error margin of 9 meters?

domingo, 18 de julio de 2010

Test how secure your PC is!


Is your computer hidden from hackers?

Is your computer giving away too much information online about you?

Can you tell how safe your firewall is?


You can run a simple test online so that you know the answers to the questions above! The Gibson Research Corporation designed a very handy page called Shields UP! that will help you a lot.

First, you will see this page. Click on PROCEED:



Then, choose any of the options they give you. I recommend you:

File Sharing

Common ports

All service ports


That's it! The chosen test will run and then you will be presented the results as in the following image (these are the actual results for my machine):



Hey! I really like it when they called my machine's security behavior "very cool!"

Also, it feels good to read "All attempts getting any information from your computer FAILED."

Finally, the part of "this is VERY UNCOMMON for a Windows networking-based PC" made me smile (that's why I chose Linux!) and that of "this computer appears to be VERY SECURE" is like music to my ears! I should read it aloud a couple more times! ^__^

Please visit Shields UP here and check your computer, too.

lunes, 5 de julio de 2010

Cloud Computing: The New Wave!


Currently, it seems Cloud Computing is becoming a hot issue.

What is cloud computing? Basically, it is storing your information in remote servers (the cloud.) Using such servers could be free or users may also have to pay a fee for the service. That depends on "the cloud" users choose.

Cloud computing gives you the advantage that you don't have to store your information yourself (no more piles of CD or DVD back-ups in your house or your office). Also, it lets you access your data from anyhwere in the world (at least in theory. In reality you need a fast web connection first).

Storing information or even using online document-creating tools (like Google Docs) may be very convenient. In fact, Microsoft also wanted to jump into the train with Office 2010.

However, a fellow Mepis user recently mentioned on the Mepis Forum the article "Office 2010's Web tools raise security questions," by Yardena Arar. The author stated that "security experts say Office 2010's Web-connectedness could present new opportunities for snoops and hackers."

In short, Arar said that the potential problems with Office 2010 refer to two of its new features: SkyDrive and PowerPoint Broadcast. She described both features as follows:

"The former lets you easily share documents with colleagues, either via Office desktop apps or the new Office Web Apps. And with a simple Web link, anyone with a free Windows Live account can now run a PowerPoint 2010 slideshow, viewable by any remote user with a desktop browser."

According to her, problems arise when a a user, probably clueless about security, makes a mistaken use of such features, which along with their relatively low security (only passwords or web links), could result in unintentionally disclosing private information.

Can you imagine? A PowerPoint presentation about a company's new market strategies being disclosed to all SkyDrive accounts because a clueless person did not know how to use or disable Office 2010's web features?

The former is true not just for Microsoft Office 2010. Any form of cloud computing involves a degree of risk and a possible violation of privacy. If the servers are kept in the USA, for example, thanks to the Patriot Act, the government may ask the server keepers to show them all the information stored without notifying the actual owners of the documents.

Experts say Cloud Computing is the future of computers. I agree with them. In fact, many people have been using some sort of cloud computing already, be it online e-mail or photo album publishing. However, storing your information in servers that do not belong to you will always pose a risk in terms of privacy and security. Remember, you will be letting total strangers keep your valuable data. Is that what you really want?

viernes, 2 de julio de 2010

Coming Soon: Windows 7 Service Pack1!!


It's interesting to see how many Win7 users are eagerly waiting for SP1 since January. Finally, it seems that the long awaited Service Pack will arrive (according to some) on July 7 (whoa! that means the seventh day of the seventh month...mythical!!! Probably the Earth will stand still in awe!)

What I don't like is the game the guys at Microsoft play with their loyal users. SP-1 was originally expected at the beginning of this year, but while their users waited faithfully since last year, Microsoft let a third-party company, LeeLo Soft, create Quick Fix, a 463 Kb tool to fix 21 commonly reported bugs on Windows 7!

Why making their users wait if those 21 bugs were already there and could be solved in less than 500 Kb? Unless you have sold your soul to..., the answer should be clear: Releasing a Service Pack so soon would have hurt the credibility of Win7. Users would have thought their new system was not as good as they were told.

Anyway, it's not the first time Microsoft support service lets their users down. Actually, that happens quite often, with the Redmond giant usually blaming someone else before addressing the problems. Remember the bug of the batteries that started in June, 2009? The thread is so long that it had to be split into several parts and has reached PART 10 already!!! (one user in part 10 was so angry and fed up with waiting that threatened to migrate to Ubuntu while another advised others to downgrade!)

Now that Microsoft will at last release Win7 SP-1, hopefully those bugs will be properly addressed...or more people will downgrade or better yet, upgrade to Linux! The problem is that in March they said that the first Service Pack would bring only minor fixes. They're at their game again: Windows Seven is so powerful that the Service Pack will just address minor bugs (SP-1 is only from 3 to 4 Gbs, so get ready for a big download that will solve minor bugs, pirates!)

Win7 users: pray that Microsoft is not using with you the same "wait for help" strategy they are using now with poor XP users. They are under a massive attack currently and Microsoft's tech support has failed them (and still many hesitate to migrate to Linux claiming lack of tech support!)

Nah, that happened because XP is old and about to die. Why would Microsoft do that to Windows 7 users? Well, Windows 8 is on the way...