Friday, April 13, 2012

How to react to scare tactic posts and chain letters.

                                                        photo courtesy of www.freepixels.com
Today I received an email from a friend of mine that read something like this:
URGENT - PLEASE READ - NOT A JOKE
PASS THIS ON!
IF A PERSON CALLED SIMON ASHTON (SIMON25@HOTMAIL.CO.UK) CONTACTS YOUTHROUGH EMAIL DON'T OPEN THE MESSAGE. DELETE IT BECAUSE HE IS AHACKER!!

TELL EVERYONE ON YOUR LIST BECAUSE IF SOMEBODY ON YOUR LIST ADDSHIM THEN YOU WILL GET HIM ON YOUR LIST. HE WILL FIGURE OUT YOUR IDCOMPUTER ADDRESS, SO COPY AND PASTE THIS MESSAGE TO EVERYONE EVEN IFYOU DON'T CARE FOR THEM AND FAST BECAUSE IF HE HACKS THEIR EMAIL HEHACKS YOUR MAIL TOO!!!!!.....
Anyone-using Internet mail such as Yahoo, Hotmail, AOL and so on..This information arrived this morning, Direct from both Microsoft andNorton. Please send it to everybody you know who has access to theInternet. You may receive an apparently harmless e-mail titled 'MailServer Report'
If you open either file, a message will appear on your screen saying:'It is too late now, your life is no longer beautiful.'
Subsequently you will LOSE EVERYTHING IN YOUR PC,And the person who o sent it to you will gain access to your name,e-mail and password.
This is a new virus which started to circulate on Saturdayafternoon.. AOL has already confirmed the severity, and the antivirus software's are not capable of destroying it .
The virus has been created by a hacker who calls himself 'life owner'..
PLEASE SEND A COPY OF THIS E-MAIL TO ALL YOUR FRIENDS, And ask themto PASS IT ON IMMEDIATELY!


According to Snopes ( http://www.snopes.com/computer/internet/hackermail.asp ) this is just another installment in a long-running hoax, and in fact, is made via a simple template (rather like that old game Mad Libs) 


Unless the person includes a malicious file along with their email (NEVER open attachments from people you don't know), such as a worm or virus, the person really has no way of accessing your computer via this method unless you have not activated your firewall.  Though if you have not activated your firewall or other intrusion detection software, e-mail hackers are the least of your worries.

The only thing a person can really do via server-side email clients, such as Hotmail, Yahoo or AOL is tell whether the email has been opened or not by embedding a simple image file, often a 1x1 pixel blank image that is stored on a server that reports access, and then watch their access logs to see who actually opened the image file.  This simply tells the hacker which email addresses are active and thus they can then sell your email address to spammers and advertisers as "valid".

This is the reason most server-side email clients (and even client-side email clients such as Outlook)  block image downloads by default, allowing you to view images only from trusted sources.  It isn't to protect your computer, it's to protect your e-mail address from unwanted spam.

Even though this email is a hoax, it does serve a very useful purpose.  It brings attention to the real threats out there and makes the public at large more aware of the real vulnerabilities that may be lurking in their computer system.  

A simple list of good computing practices can virtually eliminate any worries you may have about your online life.



  • 1. Make sure the firewall built into your operating system is active at all times.  (never turn it off)
  • 2. Make sure your operating system is up-to-date.
  • 3. Invest in a good "active scan" virus protection system such as McAfee, Kaspersky, Norton or AVG and keep it updated.
  • 4. Invest in a good "active scan" malware program such as Malwarebytes, and keep it updated.
  • 5. Backup your hard drive at least once a month, or use an active backup service to either an external hard drive or cloud.  If you should ever have to reformat or even replace your hard drive, you won't lose your data.
  • 6. Clean and defrag your hard drive at least once a month.  You can also invest in a free program from IOBit called "Smart Defrag" which will defragment your computer whenever it is idle.
  • 7. Never EVER open attachments or click on links in email from people you don't know.  Even if it is from someone you do know, if it looks suspicious, don't click it!!



These are just a few simple steps to a happier, healthier computer, and in most cases, a worry-free online experience for you.  


Tuesday, August 16, 2011

Should I turn my computer off when I'm not using it?

                                                        photo courtesy of www.freepixels.com
Q: Should I turn my computer off when I'm not using it?
A: Yes, but probably not for the first reason to spring to mind.


     Most people these days are more conscious of the energy their household is consuming, for both environmental and economical reasons.  But turning your computer off (and indeed unplugging those nasty little "wall warts") has not only energy benefits, but network and security benefits as well.

     In this day and age of "Always On" broadband connections, the concept of "always on" seems to have carried over to the power switch in the mind of most computer users these days.  Most of us think nothing of leaving a room with the computer running, even when we turn the overhead light off and intend to be gone for long periods of time.  The problem with this is that the digital underworld have noticed this trend too.

     Who is using your computer when your not home?

     Have you ever heard the acronym "DDOS"?  This stands for Distributed Denial Of Service attack, and is become the most common form of denial of service attack on the web today.

     We won't go into the long and boring details of exactly what a denial of service attack is, suffice it to say that it is simply a method in which an attacker floods the communications ports of a chosen server with junk traffic, causing the real traffic to get lost in the flood.   This means that during a DOS attack, legitimate users are essentially blocked from getting in.  Imagine a flash-mob outside the door to your favorite resturant. They have no intention of actually ordering anything, but thier presence clogs the entrance so you can't get in to buy either.

     So what is the difference between a denial of service attack and a distributed denial of service attack?  Well, a simple DOS is usually someone flooding one system from another system, but a distributed attack comes from many computers at the same time.  The client is embedded on numerous systems on the internet and triggered to activate simultaneously. 

     DDOS clients are often embedded into trojans and other malware.  Often the unsuspecting computer user will download these without ever knowing it, either by downloading a program that they think is something else, connecting to an infected webpage, clicking on a popup that say's "YOUR COMPUTER HAS VIRUSES" (It didn't but if you click on something like that it will), or by simply failing to turn on your Windows firewall or by turning off your virus detection program.  (an unprotected open port is a hackers dream).

     Even if you have done everything right though, firewall on, virus program running, many of these malware programs can infect your computer without you ever knowing it, and many can go undetected by virus scanners.  You won't know your infected until your computer slows to a crawl and you start digging around in your hard drive to know the reason why.  There are literally millions of infected computers on the internet today who's owners have no idea they have malware on their systems, and a likely majority of those systems are infected with a DDOS client just waiting to be activated by the hacker that put them there.

     So now a hacker has distributed his DDOS client to a whole host of computers.  If your computer is infected, and you don't know it, and you leave your computer turned on and on the internet 24/7, you have just provided someone with a method of attack.  As someone said on Twitter recently "There are plenty of kids out there that leave daddy's laptop turned on all the time".

    So why should you turn your computers off when not in use?
  1. Save Electricity
  2. Save Money
  3. Save the planet
  4. Prevent hackers from getting into your computer while your away
  5. Prevent hackers from USING your computer while your away
     You also don't necessarily have to "flip the switch" every time you walk away either.  Most operating systems have built in "Power Settings" which will automatically turn your computer off if not used for a specified period of time.  For example, I use Windows 7 on one computer and Windows XP on another.  Both of these will turn themselves completely off if not used for 1 hour.

In Windows 7, this can be found in the Control Panel under System and Security > Power Options.

     DDOS attacks are only ONE example of the myriad of methods hackers use.  Some hackers attempt to break into your system to garner your personal information, others to send spam and other malicious emails. Ironically enough, the most effective methods of securing your computer consist of just plain common sense.  Good "Cyber-hygiene" as it were.

  1. Invest in a good active virus scanner such as McAfee Virus Scanner
  2. Keep your operating system up-to-date.  When your OS askes to update files, let it!
  3. Invest in a good Malware scanner such as SAS Super Anti Spyware, Malwarebytes and/or Microsoft Security Essentials
  4. Turn your computer off when not in use.
  5. Scan your computer at least once a week.
  6. Never store credit card information online or in "auto complete" fields.
  7. Never store important personal documents (such as scans of your drivers license, social security card, etc.) online or on your hard drive. Use a USB flash-drive instead.
      Simple steps to protect yourself, your family, and the internet from those who have other ideas for your stuff.