If there is one thing that you do not want to read as a web browser user or browser manufacturer it is that your browser has been exploited at a security conference while others have not. The Pwn2Own security conference is a competitive gathering of security experts who try to successfully compromise computer systems using [...]
Security
- Author: Jack Wallen
- Comments: 2
Use a secure shell configuration file for easier use
If you’ve ever used secure shell you know that it can get a little daunting with all of the command options available. But did you know you can make this task much easier with the help of secure shell user configuration files? With these files (unique to each user) you can configure secure shell to [...]
- Author: Jack Wallen
- Comments: 8
Get to know Linux: AppArmor
You’ve heard that Linux is a very secure operating system. You’ve heard it’s practically immune to viruses (practically being the key word). You’ve heard it’s tough to crack. These are all true…and with good reason. Linux is such a strong operating system for two primary reasons – by design and with the help of security [...]
- Author: Martin Brinkmann
- Comments: 6
Avira Antivir 10 Personal Download Available
The popular antivirus software Avira Antivir has been updated and it now offered on the developer’s homepage for download. Avira Antivir 10 Personal is provided in several editions including a free edition with limited functionality. Antivir 10 Free, often also called Antivir 10 Personal, includes the antivirus, anti-malware, anti-spyware and anti-rootkit modules but lacks features [...]
- Author: Jack Wallen
- Comments: 3
Bitdefender: Linux antivirus made simple
We’ve covered a few Linux antivirus tools here on Ghacks (see “Install Avira Antivirus on Linux” or “Rescue that infected Windows drive with Trinity Rescue” or the articles covering ClamAV). All of those solutions are solid, but none of them offer the Windows-like ease of use that Bitdefender offers. Now, before you begin this journey [...]
- Author: Jack Wallen
- Comments: 11
Q7z: Front end for Linux 7-Zip
Compression is compression is compression. Right? Wrong. There are some compression utilities that eek out every drop of space possible. On the Linux operating system the standard is gzip or bunzip2. But if you’re looking for one of the highest compression ratios to be found you might want to turn your sites to 7-Zip. 7-Zip [...]
- Author: Martin Brinkmann
- Comments: 11
Facebook Password Reset Confirmation Scam
Popular software programs and online services are more likely to be targeted by malicious users than less popular services. Facebook is currently the most popular social networking service on the Internet and security experts are noticing increased attacks on the network and its users. Several security companies are currently warning their users about a widespread [...]
- Author: Martin Brinkmann
- Comments: 5
Giganews VyprVPN Free For Diamond Account Owners
Giganews VyprVPN is a virtual private network that is run by the same company that is providing one of the most reliable Usenet services on the Internet. I have been with Giganews for a very long time and never looked back. Since the announcement of the new vpn service Giganews Diamond account owners were able [...]
- Author: Jack Wallen
- Comments: None
Create a bootable CD of PloP Linux
PloP Linux is one of those small in size but large in features Live distributions that could, at some point, save your skin. It offers tons of tools to help you out of just about any situation and, because of the necessity to build the live version, allows you to add whatever tool you need. [...]
- Author: Martin Brinkmann
- Comments: 8
AVG Anti-Virus 9
The guys over at giveaway of the day are offering the popular antivirus software AVG Anti-Virus 9 today. The security program offers several additional features over its free counterpart (named AVG Anti-Virus 9 Free or AVG 9 Free) which will be the focus of this review. AVG 9 Free offers the core features that one [...]
- Author: Martin Brinkmann
- Comments: None
Mozilla Account Manager
The Mozilla Account Manager project aims to simplify the login connection process to websites and services by implementing a new protocol “that sites can use to define their account-and-session management features” that integrates with the web browser. The Account Manager is described as an evolution of the password manager that is integrated in Firefox and [...]
- Author: Jack Wallen
- Comments: 9
Rescue that infected Windows machine with Trinity Rescue
Sticking with our current theme of rescuing, we will now focus our magnifying glass another another useful Linux tool – Trinity Rescue Kit.TRK is another live Linux distribution, but with a different spin. Instead of being a live CD who’s purpose is to do just about everything, Trinity wants to really only do two things: Recover [...]
- Author: Martin Brinkmann
- Comments: 3
Twitter Starts Scanning Direct Links To Improve Security
Twitter has been targeted by users with malicious intents ever since it started to become increasingly popular. One of the biggest problems up to yesterday were direct messages which one Twitter user could send to another. Links posted in those direct messages were not scanned by Twitter before they were send out, only after they [...]
- Author: Martin Brinkmann
- Comments: 7
Microsoft Security Updates March 2010
Microsoft yesterday released security patches for Windows and Office products on their monthly Patch Tuesday. A total of two security bulletins have been released by Microsoft that patch flaws in Microsoft Excel, Windows Movie Maker and Microsoft Producer 2003. The severity of both security bulletins has been rated as important. Attackers can exploit the issues [...]
- Author: Jack Wallen
- Comments: 10
Install Avira Antivir on Linux
In yesterday’s post (see “Scan a Windows drive for viruses using Linux“) in which I mentioned the Avira Antivir software. This piece of software is a commercial, cross-platform anti-virus solution that offers both a GUI and a command line interface. For this article we will only deal with the command line version of the tool. [...]
- Author: Jack Wallen
- Comments: 28
Scan a Windows drive for viruses using Linux
Recently I came into a client who had a Windows XP machine that contained a nasty little virus that rendered the machine nearly unusable. When the machine would boot the CPU was pegging out at 100%, causing the GUI to be nearly unresponsive. I attempted to run AVG, Avast, Malwarebytes – but all for naught. [...]
- Author: Martin Brinkmann
- Comments: 24
How To Disable Microsoft SpyNet In Windows 7
Microsoft SpyNet is a service connected to Microsoft’s security products Windows Defender and Microsoft Security Essentials. The service collects information from users of the two products and makes the findings available to all other users of Microsoft SpyNet. Windows Defender has been integrated into Windows 7 by Microsoft. The program is automatically running after installation [...]
- Author: Martin Brinkmann
- Comments: 22
Comodo Internet Security 4 Download
Comodo has released Comodo Internet Security 4 Free and Pro yesterday. The free version which we will be concentrating our review on combines one of the best Windows software firewalls with antivirus protection. Version 4 adds sandboxing to the application. Sandboxing basically allows the computer user to run files in a closed environment so that [...]
- Author: Martin Brinkmann
- Comments: 6
Pure Networks Security Scan
Is your computer network secure? That is the question that the online tool Pure Networks Security Scan tries to answer by running a series of tests that determine how well a computer network is protected. The security test is limited to Microsoft’s Internet Explorer and used to sell the networking software Network Magic. The latter [...]
- Author: Jack Wallen
- Comments: 7
Creating a VPN tunnel between Ubuntu and Sonicwall
Yesterday I walked you through the process of connecting to a Microsoft PPTP VPN (see my article “Connecting to a Microsoft VPN with Linux“). That article used a simple GUI tool to allow you to create your VPN tunnel. Unfortunately there is no magic support you can add to the Network Manager Applet to add [...]
- Author: Martin Brinkmann
- Comments: 6
Dr.Web CureIt Antivirus Software Review
There is no antivirus software that will catch all viruses. Even the best security applications do not have a perfect detection rate which means that it can happen that a virus slips past them and infects the computer system. There are a few options to cope with this problem like sandboxing, using virtual machines or [...]
- Author: Martin Brinkmann
- Comments: 4
Microsoft Releases Blue Screen Rootkit Detection Tool
Last month’s Microsoft security updates have caused some controversy over a single patch in the pack that was first thought to cause blue screen on some computer systems. It later turned out that the patch was not responsible for the blue screens but a rootkit that had altered some files of the operating system. The [...]
- Author: Jack Wallen
- Comments: 6
Connecting to a Microsoft VPN with Linux
One of the Achilles heels of the Linux operating system is connecting to a VPN. Due to it’s natural ability to network, one would think connecting to a VPN would be a simple task. In some cases it is. In some cases it certainly is not. This is completely dependent upon the type of VPN [...]
- Author: Martin Brinkmann
- Comments: 4
New Internet Explorer Vulnerability Confirmed
Microsoft have confirmed a new Internet Explorer security vulnerability which is affecting only pre-Windows Vista operating systems like Windows XP meaning that users running Windows 7, Windows Vista, Windows Server 2000 and Server 2008 R2 are not affected by the issue. The vulnerability is not exploited currently according to Microsoft’s information and it is not [...]
- Author: Jack Wallen
- Comments: 4
Clean up your system with Bleachbit
You never know what is dirtying up your Linux system. Your Bash history, temporary files, usage history, clipboard, free disk space…there’s always a chance something is there that you don’t want. But how do you go through it all? Do we really have the time to actually sift through our machines daily or weekly to [...]
- Author: Martin Brinkmann
- Comments: 4
Adobe Fixes Adobe Download Manager Vulnerability
A security vulnerability in Adobe Download Manager was discovered this month besides the recently discovered security vulnerabilities in Adobe Reader, Adobe Acrobat and Adobe Flash which had also been discovered and fixed by Adobe. We have posted information about the security vulnerability in the forum but not here on the blog. Adobe has now updated [...]
- Author: Martin Brinkmann
- Comments: 11
Adobe Still Offering Insecure Adobe Reader Version
If you are a Ghacks regular you have without doubt noticed that Adobe has published an update for Adobe Reader and Adobe Acrobat yesterday that fixes two security vulnerabilities that affect Adobe Reader and Acrobat 9.3 and earlier. The update that has been provided updates both products to version 9.3.1. One would think that this [...]
- Author: Martin Brinkmann
- Comments: 4
Please Rob Me Demonstrates The Dangers Of Location Based Services
Location based services can be helpful to the user, no question about that. They are most often implemented and used in mobile devices who are able to return the location of the owner to the network where these information can get utilized in several ways from locating the nearest post office, restaurant or atm to [...]
- Author: Martin Brinkmann
- Comments: 5
What The Internet Knows About You
Most Internet users know that a website they visit can access various information about the computer system used to make the connection. This includes the screen resolution, operating system, IP address and web browser among other things. But those are not the only information that can be gathered when users visit a website. What would [...]
- Author: Martin Brinkmann
- Comments: 7
Adobe Reader And Acrobat Get Yet Another Security Update
Adobe Reader and Adobe Flash seem to be two of the most targeted software programs by malicious software and hackers besides the Microsoft Windows operating system and Internet Explorer. It is rare that a month passes by without yet another update that fixes a security vulnerability in Adobe Reader or Acrobat. Today a critical vulnerability [...]
- Author: Martin Brinkmann
- Comments: None
Whitelist Hash Database Frontend
The National Software Reference Library has been initially be designed to aid computer forensics experts in the investigation of crimes that involve computers. It basically consists of a list of nearly 40 million files and hashes that are used to alleviate the process of determining evidence by excluding files from the investigation that are found [...]
- Author: Martin Brinkmann
- Comments: 8
Malware Cause For Blue Screens After Recent Windows Update
Reports about blue screens began to appear on the Internet shortly after the release of this month’s security patches for the Windows operating system. Especially Windows XP users seemed to have been affected by the crashes which were first thought to be linked to the update. Microsoft addressed the issue shortly after reports began to [...]
- Author: Martin Brinkmann
- Comments: 2
European Payment Cards Security Problem
A recently released technical paper entitled “Chip and pin is broken” by security researchers Steven Murdoch, Saar Drimer, Mike Bond and Ross Anderson demonstrates a man in the middle attack that lets criminals use stolen payment cards without knowing the pin. This is obviously a serious security problem as banks have always claimed that the [...]
- Author: Martin Brinkmann
- Comments: 2
Adobe Flash Player Security Update
Microsoft is not the only company that has released security updates in the last days. Adobe has also identified a security vulnerability in Adobe Flash Player version 10.0.42.34 and earlier that “could subvert the domain sandbox and make unauthorized cross-domain requests”. This vulnerability has received a critical rating which is the highest rating a vulnerability [...]
- Author: Martin Brinkmann
- Comments: 2
Microsoft Addresses Windows Restart Issues
Some Windows users have reported restart issues installing the February security updates for their operating system. A recent blog post at the Microsoft Security Response Center suggests that the problems occurred for the users after installing the patch MS10-015. Jerry Bryant, the Senior Security Communications Manager, states that Microsoft has not yet ” confirmed that [...]
- Author: Martin Brinkmann
- Comments: 3
The Cleaner
The Cleaner was back in the days one of the few solid programs to clean malicious software from a Windows computer system. It somehow seems to have lost its appeal to many users even though the developer’s claim that it is the fastest anti-virus solution with best virus detection rates available for the Windows operating [...]
- Author: Martin Brinkmann
- Comments: 9
The Phishing Flow Chart
Phishing is a serious problem on today’s Internet even with phishing protections in email clients, web browsers and security software in place as those security solutions only deal with already reported phishing scams and sites and not new ones. Internet users therefor need to know about phishing and how to identify phishing emails from safe [...]
- Author: Martin Brinkmann
- Comments: 4
Microsoft Security Updates February 2010
Microsoft has released a total of 14 security updates on yesterday’s patch day. The updates are, as usual, for several Microsoft software products including the Microsoft Windows operating system and Microsoft Office. Five of the updates have received a critical rating by Microsoft, the highest security rating. Seven were ranked as important which is the [...]
- Author: Jack Wallen
- Comments: None
Serious auditing with Lynis
If you want to do a thorough system security audit on a Linux machine what do you use? Cobble together a few of the pre-installed tools? Search through the numerous locations for a tool that might give you enough information to determine if your system is safe? Or, do you open up a terminal window [...]
- Author: Martin Brinkmann
- Comments: 15
What Is paypal.112.2o7.net
If you are a very observant – or cautious – PayPal user you might have noticed that several connection requests are made that are to other domains that are not paypal.com when you visit the website of the online payment processor. This can be extremely worrying to users considering that malicious software and attackers also [...]
- Author: Martin Brinkmann
- Comments: 3
Mozilla Promises Better Virus Scanning After Virus Faux Pas
Mozilla performs antivirus scans on add-ons that are added by developers to the add-on repository. These add-ons are then offered as experimental add-ons until they pass a human review which adds them fully to the add-on directory. It came to light today that two add-ons that have been offered at the add-on repository had been [...]
- Author: Jack Wallen
- Comments: 2
Quick and easy Linux security
You’ve just set up your Linux desktop. Naturally you want it to be as secure as possible. You’ve heard the rumors that, out of the box, Linux has outstanding security. Is it true? Do you really want to take a chance with that? Most likely not. But what can you do? There are tons of [...]
- Author: Martin Brinkmann
- Comments: 2
Avira Most Phished Brands January 2010
Phishing is still one of the biggest threats that users face on the Internet these days. Many security programs and web browsers offer phishing protection but these only catch the known phishing attacks which means that users still have to cope with the unknown attacks until they are identified by the applications. Avira has published [...]
- Author: Martin Brinkmann
- Comments: 16
Opera NoScript Alternative BlockIt
Regular readers know that I would make the switch away from Firefox to either Google Chrome or Opera if those web browsers would support both NoScript functionality and Last Pass. NoScript is a security add-on for Firefox that blocks scripts from being loaded when the website loads. The user has afterwards the option to enable [...]
- Author: Martin Brinkmann
- Comments: 6
How Unique Is Your Web Browser’s Fingerprint?
Servers can identify various technical information about a connecting web browser and computer system including the screen resolution, user agent that includes the operating system, web browser version, plugins that are installed or the user’s timezone. The Electronic Frontier Foundation has published an interesting theory that it is possible to track web browsers based on [...]
- Author: Martin Brinkmann
- Comments: 3
Avira Malware File-Extension Statistics
Malware is a generic term for trojans, viruses, worms, keyloggers, rootkits and other malicious code. The Avira blog has posted an interesting statistic about the malware that gets distributed by urls either in emails, on websites or other ways. Most computer users probably associated file types like exe as dangerous when they encounter them on [...]
- Author: Martin Brinkmann
- Comments: 1
Online Armor++ Review
Online Armor++ is an all in one Internet security suite that normally retails for $59.99. It offers all the security modules one would expect for a security suite including a software firewall, antivirus and antimalware protection or email protection.
- Author: Jack Wallen
- Comments: 4
Further control of Linux files with ACL
If you read my article “Get to know Linux: File permissions” you know that it’s possible, out of the box, to control who can access a file and what they can do with it. This helps to make Linux a fairly secure system. But did you know you can take even further control of that [...]
- Author: Martin Brinkmann
- Comments: 12
Study Suggests That Google Toolbar Transfers Data Even In Disabled State
The Google Toolbar is a web browser add-on that is currently available for Mozilla Firefox and Microsoft Internet Explorer. The toolbar is an official Google application that provides quick access to several Google services and features like translating web pages or sharing websites with friends. Everyone knows that the Google Toolbar transfers data to Google [...]
- Author: Martin Brinkmann
- Comments: 4
Secunia Online Software Inspector
Keeping software and the operating system up to date is a dead given for expert computer users and part of their computer maintenance schedule. These users know how to check for updates and install them as soon as they are released on their systems to protect the system from exploits. Inexperienced users on the other [...]
