Your Ad Here

amazon

Showing posts with label antivirus. Show all posts
Showing posts with label antivirus. Show all posts

Friday, 20 March 2009

IMPORTANT : DNSchanger threat

The DNSchanger threat is not new, but it has resurfaced and is still annoying and dangerous. To completely comprehend the severity of this threat, it is important to understand the what, how and why of DNS.

So, ... what is the DNS? DNS is geek speak for Domain Name System. This is a means of changing the meaningful names of websites, such as www.bbc.co.uk, into a numerical value understandable to the various networking equipment that constitute the infrastructure of any network, even the biggest network namely the internet. Essentially it is a database that is used to identify the elements of the network with the intention of discovering the destination, and the best route to this destination, for requests made. There is much more to DNS than can be dealt with by a blog, however, in this instance you now have enough information to understand the threat.

DHCP Is geek speak for Dynamic Host Configuration Protocol. When a computer is connected to a network or Wireless access point, It will require some settings to make it work, such an IP address, Gateway address and DNS server address. These elements are only some of the many that need to come together to permit working on a network. With the exception of Wireless, there are 2 ways of ensuring that the computer obtains these settings, namely static and dynamic. Static addresses are entered manually and are changeed manually, whereas dynamic addresses are not. In order to obtan the dynamic addresses, the newly attached computer must first be set to obtain these dynamically by enabling DHCP. Once this is done, the computer will then send a DHCP request to the DHCP server on that network. After various handshakes and authentications, the server issues all the details for the computer to use. This is called a DHCP lease. The computer is now configured to use all the proper addresses in ordser to work on the network. In an ideal world at least.

How is it done? DNSchanger is a trojan that installs itself onto a computer or other network device and waits for DNS and DHCP requests. When this trojan detects that a DHCP request has been made, it responds before the DHCP server can and issues a false DHCP lease. False because it sets up incorrect routes and destinations by claiming to be the DNS server. When the computer then requests a website, it is directed by the false DNS to go elsewhere. This is usually a website that closely matches the website that was initially requested. Some are so convincing that most people are fooled by them, however, if you scrutinize these sites, you will always discover something odd that gives it away.

Why is it done? These websites are desinged to log and grab all the details you enter, and thereby grant the malicious of this world access to your accounts. These websites are called phishing websites, and they fish for your personal data.

Keep your system and all anti-malware (anti-virus, anti-spam, etc.) completely up to date and also make a note of the following address range. DNS settings with this address range being used should be considered suspicious.

The range 85.112.0.0 to 85.127.255.254 possibly indicate a compromised computer.

Periodically, run a full antivirus scan with the latest definitions to ensure you remain safe.

As always ... be cautious and use your common sense.

Sunday, 15 March 2009

Dangerous Software : Peer to Peer

Believe it or not, but peer-to-peer software is probably one of the most dangerous items of software you could possibly run on your computer. With this type of software the risk is not only in downloading material that has a copyright on it, but in either intentionally or unintentionally serving the same software. So, if caught, you will be prosecutable on three different counts, namely acquiring illegal software, owning illegal software and distributing illegal software. Each carries with it its own penalty.

But more importantly, peer-to-peer (or P2P, as the industry knows it) runs on insecure lines and protocols which could be intercepted by crackers (the proper term for those intent on gaining access to your system or information). P2P software is usually the easiest way for a cracker to gain entry into an other secure network. One particular way of doing this is by incorporating scripts which are tagged onto the files downloaded by the P2P user who is usually unaware of this malicious addition. This addition is usually, though not empirically, referred to as the payload. Once the payload has been downloaded all that remains is for it to be activated. Once activated, the script "phones home" and then the rest is history, so too is your data and your security. If you are connected to the network at you place of employment you should receive a hostile visit from your local System Administrator (SysAdmin). If you do this on your home computer, you may not realize for some time that your computer has been compromised. Sure, the use of an antivirus and antispyware is a very good first step, however, many compromises do not appear as spyware or a virus. Furthermore, as mentioned before, no antivirus protects you against all computer viruses running rampant on the internet.Likewise for spyware.

If you have been compromised, you will need an entirely new arsenal at your disposal, such as rootkit revealers and hidden process detectors. You may think that you do not use any P2P software, but SKYPE is just that and only secondly is it a way of making telephone calls on the internet. While you are phoning someone you are using very little bandwidth, but SKYPE uses the remainer of your bandwidth by making your computer a SUPERNODE. Nodes are essentially computers that are used to offer the quickest path between two computers that wish to transfer files to from one to the other. SUPERNODES are similar except that they are used by many computers to transfer files to many computers. In geek speak, your computer has become a hub, which means all incoming data will be broadcast on all connections made to your computer. Suddenly, your bandwidth diminishes, your storage space is reduced, your memory is clogged up and you experience a dramatic drop in the performance of your computer which only drops more as time passes. Does this sound familiar? I sincerely hope not! Yet if it does, You will need to perform the following in the following order to have anyhope of regaining control:
1) Disconnect your computer from all networks immediately,
2) Backup your data completely because you may lose it or have to proceed to step 6 below,
3) Remove ALL P2P software completely,
4) Run full antivirus and antispyware scans, and particularly not if anything odd happens (such as not completing the full scan, parts of the antivirus not working, or anything else).
5) Restart MS Windows system in safe mode and do step 4 above again,
6) Wipe your Hard Disk Drive and reinstall, from scratch, your operating system and non P2P software. Although this is here given as the final option and last resort, it is infact the best option from the start, however, it may not always be the most practical option.

The simplest solution is to avoid P2P software entirely. There is no safe P2P software, even if you use encryption. For further reading visit
http://www.roseindia.net/community/spyware/dangers_of_peer_to_peer_systems.shtml


Remember to always be cautious, and exercise common sense! This alone will make a huge difference.

Sunday, 8 March 2009

Minimum requirements for safer computing

Upon purchasing your computer, it is likely that you were told to invest in a good solid anti-virus and firewall package. It is even likely that you were told to download some form of spyware or malware removal tool. All these are the standard bits of advice given, and they are good, but undeniably not comprehensive enough.

The first thing you should remember is that any computer is only as safe as the latest updates and upgrades. For starters, keep your operating system fully patched with the latest updates. Do the same for the anti-virus, firewall and anti-spyware. These are usually divided into types of downloads, namely definition updates and engine upgrades. The former contains the actual signatures/definitions the the software uses to scan the computer for malicious software, and the latter includes bits code used to enhance the performance and functionality of the software that will search for malicious code. Thus, only by keeping both completely up to date, do you stand any chance of keeping yourself safe.

However, antivirus, firewall and antispyware alone will not guarantee that you will be safe from malicious code. Furthermore, no single antivirus package will provide you with protection from all the viruses on the internet. Installing a second antivirus onto the computer is always an option, but I would not recommend doing this because you will waste system resources and possibly cause your computer to enter into a nonrecoverable state. The same applies to firewalls and anti-spyware. Some reputable antivirus vendors do online scans of your computer for virus signatures. One such example is Panda Security, but other exist and here you need to exercise caution and only consider reputable vendors.

So what else can you do to secure yourself? Well, ... a great many things, but first and foremost you should remove ALL software that you are no longer using or ever will use. These programs that are no longer being used are also no longer being updated, which make them a serious security risk to you. Any software you use should be the latest version available, or at the very least a version that is still being supported by the manufacturer.

Most computers also run services and servers that are normally unnecessary and may safely be turned off or removed without altering your computing experience. If you are uncertain about which of these are not required then make Google your very best friend. Many of these services and servers are used to compromise your computer.

To complete the minimum requirements for safer computing, do the following:
  • ensure that ALL user accounts have a complex alphanumeric password
  • disable the guest and all unused accounts
  • never use the administrator account unless it is specifically required to make system wide alterations
  • periodically (usually once a week for daily users) FORCE updates on all software on your computer
  • NEVER open emails from origins unknown and especially NEVER open attachments BEFORE scanning them with an antivirus
  • Disable all autoruns and scripting (such as javascript)
Obviously there is always more you can do, but for now lets deal with things in bitesize chunks.

Always be cautious and use common sense!