Showing posts with label cyber crime. Show all posts
Showing posts with label cyber crime. Show all posts

Monday, November 5, 2012

Study finds 25 percent of Android apps to be a security risk

PCWorld - According to a new report from Bit9—a security vendor with a focus on defending against advanced persistent threats (APT)—there is a one in four chance that downloading an Android app from the official Google Play market could put you at risk. Bit9 analyzed 400,000 or so apps in Google Play, and found over 100,000 it considers to be on the shady side.

Does that mean that the sky is falling, and everyone with an Android smartphone or tablet should abandon it immediately? No. The research by Bit9 illustrates some issues with app development in general, and should raise awareness among mobile users to exercise some discretion when downloading and installing apps, but it’s not a sign of any urgent crisis affecting Android apps.

The report from Bit9 isn’t about apps that contain malware, or are even overtly malicious for that matter. Bit9 reviewed the permissions requested by the apps, and examined the security and privacy implications of granting those permissions. The reality is that many apps request permission to access sensitive content they have no actual need for. 

More

Monday, October 29, 2012

Data breach victims could get damages from careless firms


PCWorld - How federal courts define the damages people suffer from data breaches is broadening dramatically, leaving unprepared companies at greater risk of big payouts in class-action lawsuits, lawyers from a prominent law firm say.

Until a couple of years ago, courts would routinely dismiss lawsuits stemming from data breaches, such as the latest in South Carolina, unless the victims could show specific damages. Judges have since widened their view and are awarding class-action status to lawsuits that can show actual damages or a real possibility of future damages.

The latter would make companies liable for steps taken to prevent financial harm, such as insurance to cover the costs associated with identity theft.

Jeffrey Vagle, a lawyer with Pepper Hamilton, described as a "sea change" in judges' thinking. "Courts are starting to pick up on the fact that the data that can get out there can cause serious harm, maybe not immediately, but sometime in the near future," Vagle said.

Examples include a case in which a laptop containing unencrypted personal data of Starbucks employees was stolen. While there was no evidence that the data was misused, the Ninth Circuit Court ruled in 2010 that the risk alone was enough to warrant a lawsuit, Vagle and colleague Sharon Klein said in a Client Alert published on the law firm's website.

More

Tuesday, September 4, 2012

Time to Give Java the Boot?

Analysis: The programming language has become one of the weakest links in a PC’s and Mac's defenses against external threats, and is slowly -- and rightly -- being abandoned.



PCWorld - Java, the programming language designed to make the web fun and interactive, has become one of the weakest links in a PC’s and Mac's defenses against external threats. Consider the most recent Java vulnerability, a weakness currently being exploited by malware distributors: When Oracle, Java's maker, released an emergency update to fix the software, security analysts reported that even the hot-off-the-presses code contains additional vulnerabilities.

But the most recent security problems with Java are far from unique. Security firm Sophos, for example, blames underlying Java vulnerability for attacks by the Flashback malware last April that infected one out of five Macs.

The risks don't outweigh the rewards, security experts say. “I'd say 90 percent of users don't need Java anymore,” says Dominique Karg, the founder and chief hacking officer of AlienVault, a security software company. “I consider myself a ‘power user’ and the last and only time I realized I had Java installed on my Mac was when I had to update it.”

If you own a PC you know that nagging feeling of insecurity when you're asked to update your Windows PC for the umpteenth time. It may only be moderately disruptive, but it’s a monthly reminder that your computer, and the personal information contained therein, remains a target for criminals.

More

Friday, August 10, 2012

With Gauss tool, cyberspying moves beyond Stuxnet, Flame


kaspersky5
There is enough evidence that this is closely related to Flame and Stuxnet, which are nation-state sponsored attacks. We have evidence that Gauss was created by the same "factory" (or factories) that produced Stuxnet, Duqu and Flame.


CNET - Kaspersky Lab finds Gauss, a spying malware that collects financial information and resembles Flame. Components are named after famous mathematicians.

Gauss, a new "cyber-espionage toolkit," has emerged in the Middle East and is capable of stealing sensitive data such as browser passwords, online banking accounts, cookies, and system configurations, according to Kaspersky Lab. Gauss appears to have come from the same nation-state factories that produced Stuxnet.

According to Kaspersky, Gauss has unique characteristics relative to other malware. Kaspersky said it found Gauss following the discovery of Flame. The International Telecommunications Union has started an effort to identify emerging cyberthreats and mitigate them before they spread.

In a nutshell, Gauss launched around September 2011 and was discovered in June. Gauss, which resembles Flame, had its command and control infrastructure shut down in July, but the malware is dormant waiting for servers to become active. Kaspersky noted in an FAQ:

Among Gauss' key features:
  • Gauss collects data on machines and sends it to attackers. This data includes network interface information, computer drive details and BIOS characteristics.
  • The malware can infect USB thumb drives using the vulnerabilities found in Stuxnet and Flame.
  • Gauss can disinfect drives under certain circumstances and then uses removable media to store collected data in a hidden file.
  • The malware also installs a special font called Palida Narrow.
More

Monday, April 23, 2012

Web could vanish for hordes of people in July, FBI warns




CNET - If your computer is infected with the DNSChanger virus, your summertime Internet activities will be seriously curtailed — as in buh-bye. But a special Web site can help you fix the problem.

The FBI is warning that hundreds of thousands of people could lose their Internet connections come July, unless they take steps to diagnose and disinfect their computers.

The problem is related to malware called DNSChanger that was first discovered way back in 2007 and that has infected millions of computers worldwide.

In simple terms, when you type a Web address into your browser, your computer contacts DNS (or Domain Name System) servers to find out the numerical Internet Protocol (IP) address of the site you’re trying to reach, and then it takes you there. DNSChanger fiddled with an infected machine’s settings and directed it to rogue servers set up by a crime ring — servers that handed out addresses to whatever sites the ring chose.            More

Wednesday, April 18, 2012

You Got Hacked! What Now?





PCMag.Com - The phone rings. It’s your sweetheart, in tears. Why, oh why, did you change your status on Facebook to Single? Are you moving to Dubuque? Facebook says you live in Dubuque.

First things first; offer all necessary reassurance that you’re not breaking up and moving away. Then face the facts—you’ve been hacked.

The evidence might come out in other ways. Your friends may ask why you sent them that stupid email ad for Viagra. You may find one day that you simply can’t log in to your email or social media account. It’s an awful feeling, but you can recover.

How Did It Happen?

It’s conceivable that a cyber-criminal mastermind targeted you personally for a hack attack. A “spear-phishing” email message specially crafted using your personal information might have tricked you into connecting with a malicious site. Or perhaps an active hacker in some Moscow basement exploited a vulnerability in your OS.

Yes, these scenarios are conceivable, but they’re almost inexpressibly unlikely. You’re special, of course, but you’re not that special. It’s much more likely that you just weren’t careful, or weren’t lucky. Perhaps you logged in to your email from a public computer without taking proper precautions. Maybe you shared your password with a friend who’s turned out not to be such a friend after all. A valid website that’s been compromised by injected malware can infest your system with a data-stealing Trojan, and that doesn’t require any personal attention from cyber-spies.   More

Monday, April 2, 2012

The Future is Now – The Dark Side and Hacktivism




TechNewsWorld - Understand that the Dark Side is greatly motivated by social and political interests that are difficult to predict and not necessarily useful in forming strategic or tactical defense plans. This understanding will help organizations craft strategic decisions about layered protections in all verticals exposed to the Internet.

We live in times when technology is exceeding the understanding of educational institutions and corporations. A highly social Web and a bad economy is making the Dark Side — the Internet underworld where cybercrime and hacking run rampant — overwhelming.

Hacktivism is the new, hip thing; it has become a hobby for people with higher-than-average computer knowledge. The movement is led by an elite few who have a deep, lifelong knowledge of computers, and it includes senior Fortune 100 corporate executives and highly placed governmental employees, as well as the ranks of the unemployed.

The elite world of hacktivism is at the center of the Internet’s Dark Side. While governmental agencies are looking for the individuals responsible for various acts of hacktivism, they struggle with using their tried-and-true methods to move up the food chain to identify hacktivist leaders.

What is not well understood is that these layers cannot be penetrated by the standard law enforcement methods that were once effective in collapsing organized crime groups.

Hacktivism exists because the Internet is an open society that has no boundaries in which normal legal process can be applied without taking significant and draconian action, like direct control of the systems that keep the Internet alive. The traditional legal requirements for evidence are hampered by the very void in which the elites live.           More
              

Sunday, March 4, 2012

FBI Chief Calls Cyberthreats Public Enemy No. 1




Cyberattacks in various forms — cybercrime, terrorist acts committed via computers and cybattacks from foreign states — will soon be the United States’ most serious threat, according to FBI Director Robert Mueller. He urged the private sector to help by sharing information with law enforcement. His remarks were made at the RSA Conference in San Francisco.

In the near future, cyberthreats will be the leading threat to the United States, FBI Director Robert Mueller warned in a speech on Thursday at the RSA Conference in San Francisco.
Traditional crime, from mortgage and healthcare fraud to child exploitation, have moved online, while terrorists have become increasingly cyber-savvy, Mueller said.

Meanwhile, law enforcement is also confronting hacktivists, organized crime, hostile foreign nations spying on the U.S. and online and mercenary hackers.

Law enforcement needs to take lessons learned from fighting terrorism and apply them to cybercrime, he stated.

While the FBI has built up substantial expertise to deal with cyberthreats, it needs help from the private sector, Mueller said, repeating his often-made call for companies to be forthright about reporting data breaches.

“With cyberterrorism, there are fewer high-impact targets that likely have sophisticated defenses,” Tim Keanini, chief technology officer at nCircle, told TechNewsWorld. “Cybercrime, on the other hand, has become an actual business model with countless targets.”

Cybercrime “has had magnitudes more bite than cyberterrorism for a long time now,” mused Randy Abrams, an independent security consultant.

The Rise of the Terrorist in Cyberspace

Terrorist organizations are using the Internet to grow and connect with each other, and they are doing so openly, Mueller said.           More

Wednesday, February 22, 2012

Why Anonymous is Winning Its War on Internet Infrastructure





“To our hacker allies, our fellow occupiers, our militant comrades all over the world, the time for talk is over: it’s time to hack and smash, beat and shag.”

Forbes - The call to arms issued last week by the international hacker group Anonymous was accompanied by a frenzy of online hacking. Attackers took down the websites of a tear-gas manufacturer in Pennsylvania, the Nasdaq and BATS stock exchanges and the Chicago Board Options Exchange. A few days later they hacked into websites owned by the Federal Trade Commission and the Bureau of Consumer Protection.

The messages they left behind—about their opposition to everything from the Anti-Counterfeiting Trade Agreement, a controversial new treaty for enforcing intellectual property rights, to violent suppression of democracy protestors in the Middle East—had the air of giddy jubilation.

“Guess what? We’re back for round two,” the hackers wrote in reference to their attack on the FTC websites, their second such raid on the agency in less than a month. “With the doomsday clock ticking down on Internet freedom, Antisec has leapt into action. Again. Holy deja vu hack Batman! Expect us yet?”

Comic posturing aside, the hackers seemed amazed by their success: A barely organized ragtag “team of mayhem,” as one Anonymous offshoot dubbed itself, was knocking down the Web infrastructure built by major corporations  and large government agencies as if it were nothing but paper backdrops in a school play.                   More

Monday, February 6, 2012

Anonymous eavesdrops on FBI conference call





New Scientist - Hacktivist group Anonymous has posted online a recording of a conference call between the US Federal Bureau of Investigation and Scotland Yard – in which detectives both sides of the Atlantic discuss their progress in apprehending Anonymous’s hacktivist brethren.

The call, posted on Youtube (until Google removes it) but also circulating as an MP3 file, highlights the utter insecurity of telephone conference call systems, in which people simply dial in unseen and can listen in without speaking or otherwise making their presence known. All they need enter is a meeting code that is distributed with low security beforehand – something easily gleaned from an accidentally forwarded email, printout, or a hacked email account.                     More

Wednesday, January 25, 2012

Hackers Breached Railway Network, Disrupted Service



Hackers attacked computers at an an unidentified railway 
company, disrupting railway signals for two days in 
December, according to a government memo obtained
by Nextgov.


Forbes - According to the memo, train service on the unnamed railroad located in the Pacific Northwest “was slowed for a short while” on Dec. 1, and rail schedules were delayed about 15 minutes after the interference. The next day, shortly before rush hour, a “second event occurred,” but this one did not affect schedules, NextGov reports.

An investigation determined that hackers — possibly from overseas — had penetrated the system from three IP addresses, according to the memo, which did not name the country from which the hack occurred.

“Some of the possible causes lead to consideration of an overseas cyberattack,” the memo said.

Information stating that a targeted attack occurred was sent out on Dec. 5, along with alerts listing the three IP addresses, to several hundred railroad firms and public transportation agencies, in addition to unnamed partners in Canada.

A DHS spokesman acknowledged the breach in a statement to Threat Level.

“On December 1, a Pacific Northwest transportation entity reported that a potential cyber incident could affect train service,” said spokesman Peter Boogard in a statement. “The Department of Homeland Security (DHS), the FBI and our federal partners remained in communication with representatives from the transportation entity in support of their mitigation activities and with state and local government officials to send alerts to notify the transportation community of the anomalous activity as it was occurring.”

A DHS official added that after more in-depth analysis of the incident, it did not appear to be a targeted attack aimed at the railway and halting service, but was more of a random incident that simply hit the transportation entity. He would not elaborate.               More

Tuesday, January 17, 2012

More evidence of malware from China – New version of Sykipot malware targets DoD



 

More evidence of malware from China attacking the US Department of Defense has been discovered by AlienVault.

According to AlienVault’s Lab manager Jaime Blasco a new version of the Sykipot trojan attempts to compromise DoD smart cards used with ActivIdentity’s ActivClient. These smart cards are standard authentication devices for “identifying active duty military staff, selected reserve personnel, civilian employees, and eligible contractor staff,” comments Blaise.

Earlier versions of the trojan, traces of which were found as long ago as 2006, had been used to open a backdoor into infected PCs. This new version, which may have been in use since March 2011 (a date embedded in the malware’s code), uses a keylogger to steal the smart card PIN number in a smart card proxy attack. “When a card is inserted into the reader”, says Blasco, the malware acts as the authenticated user and can access sensitive information. The malware is then controlled by the attackers and then told what – and when – to steal the appropriate data”, he said.

Earlier versions of Sykipot were found to use command and control servers based in China. AlienVault has discovered Chinese characters in a small snippet of code in the new version, further suggesting a Chinese origin. Like the earlier version, the new Sykipot uses a spear phishing email campaign to target specific users. It attempts to persuade the user to click a link from where the infection is effected.              More

Monday, December 19, 2011

Hackers With a Conscience? Ideological Attacks Complicate Cyber Defense



In the pre-Anonymous world when life was simpler, most cyber attacks were opportunistic in nature, carried out by cyber criminals who just wanted to make a quick buck.
Today, Corporate America is scrambling to shift its virtual shields in response to a sweeping change in the motive behind cyber attacks that is being been driven by the rise of “hacktivist” groups like Anonymous.

The evolution toward ideologically-motivated cyber strikes has changed the type of attacks companies need to be on guard for and shoved onetime happy-go-lucky companies into the crosshairs of powerful digital adversaries.

“They are looking at technology as a means to get out a human-rights message,” said Dave Marcus, director of security research for McAfee Labs. “They see themselves as Robin Hoods and champions of lots of different things.”

Anonymous Creates Headaches

The stakes are high. Failure to protect against an attack can do serious reputational and financial damage to companies, especially those that rely on websites to interact with consumers and customers.                      More

Thursday, December 8, 2011

8 Out of 10 Software Apps Fail Security Test





Desktop and web applications remain a wasteland of bugs and holes that only a hacker could love, according to a report released Wednesday by a company that conducts independent security audits of code.

In fact, eight out of 10 software applications fail to meet a security assessment, according to a State of Software Security report by Veracode. That’s based on an automated analysis of 9,910 applications submitted to Veracode’s online security testing platform in the last 18 months. The applications are submitted by both developers — in the government and commercial sectors — as well as companies and government agencies wanting an assessment of software they plan to purchase.


The company examined commercial and government applications for more than 100 different flaw types, and found that applications created by the government fared worse when it came to cross-site scripting and SQL injection flaws, while commercial applications were more often marred by remote-execution flaws. About 75 percent of government web applications had cross-site scripting issues. Cross-site scripting flaws allow an attacker to inject malicious code into a vulnerable web application to obtain sensitive data from users.

“Government is doing worse for cross-site scripting, which is a bad place to be doing worse for,” said Chris Wysopal, co-founder and chief technology officer at Veracode.

As for SQL injection flaws, 40 percent of government applications contained these flaws. While the prevalence of SQL injection flaws has gone down 6 percent overall in the last two years in the apps market as a whole, it has remained even in government applications, indicating that government apps have made no improvement in this regard. SQL injection flaws allow an attacker to breach a backend database through a web site, usually in order to obtain information from the database.

Veracode says the bad grade for government might be due to the fact that a lot of government applications are built with Cold Fusion, a programming language that has a higher incident of cross-site flaws than C, C++, Java and PHP, the languages more prevalently used in commercial-sector software, Wysopal said. The use of Cold Fusion also suggests that government developers may be less-skilled overall than other developers and don’t have the same pressures to build secure software that commercial developers have.         More

Tuesday, December 6, 2011

Top Hacker Disasters of 2011: Five Critical Lessons for Businesses



Fox Business - This year is already being called “The Year of the Hack,” due to the unprecedented number of damaging attacks against major companies like Sony, RSA Security, Google (GOOG: 624.82, -0.83, -0.13%) and even the U.S. government. It’s hard to remember a time when businesses faced as many online threats as they do today.

From hacktivist groups like Anonymous, corporate and state-sponsored cyber espionage and organized crime and rogue hackers, every business, regardless of its size, is finding itself in the cross hairs of cyber attacks.

Why is so much hacking happening now? The answer is simple: More valuable information is stored online now than ever before, and at the same time, many companies have been lax about IT security.

Most of this year’s high-profile attacks should have been prevented. It’s the job of every business owner to learn valuable lessons about why these companies were hacked and how they could have prevented it.

Here is a recap of 2011’s significant hacks with important tips for businesses:

RSA Security, hacked in March 2011:

RSA, best known for its SecurID tokens, was severely jeopardized by a clever cyber attack earlier this year. The attackers used social engineering (just another term for “con”) to trick RSA employees into opening a spoofed, or fake, email and downloading an infected Excel spreadsheet. This attack gave the hackers access to the computer network and from there, they stole SecurID tokens and used them to hack military contractors.

Key Lesson No.1: Protect Critical Data. RSA should not have had its SecurID token secrets online. What valuable information does your business store in online databases? Many executives don’t know, and classifying business data should be near the top of their chief information security officer’s (CISO) to-do list. Business owners should thoroughly examine the information they store online and store critical data offline or behind strict network segmentation.

Key Lesson No.2: Segment Your Network. The attack on RSA used employees to get inside the company. Employee training isn’t reliable, therefore it’s more important for businesses to safeguard their network by segmenting the network so if one employee’s PC is infected it can’t spread laterally through the entire system.

Sony, hacked April to June 2011

The attack on Sony made news for weeks as the company was attacked by LulzSec and the Playstation network shut down. All told, the damage to Sony from these attacks reportedly more than $170 million.             More

Thursday, October 27, 2011

How secure is HTTPS today? How often is it attacked?



This is part 1 of a series on the security of HTTPS and TLS/SSL

HTTPS is a lot more secure than HTTP! If a site uses accounts, or publishes material that people might prefer to read in private, the site should be protected with HTTPS.

Unfortunately, is still feasible for some attackers to break HTTPS. Leaving aside cryptographic protocol vulnerabilities, there are structural ways for its authentication mechanism to be fooled for any domain, including mail.google.com, www.citibank.com, www.eff.org, addons.mozilla.org, or any other incredibly sensitive service:

1.  Break into any Certificate Authority (or compromise the web applications that feed into it). As we learned from the SSL Observatory project, there are 600+ Certificate Authorities that your browser will trust; the attacker only needs to find one of those 600 that she is capable of breaking into. This has been happening with catastrophic results.

2.  Compromise a router near any Certificate Authority, so that you can read the CA’s outgoing email or alter incoming DNS packets, breaking domain validation. Or similarly, compromise a router near the victim site to read incoming email or outgoing DNS responses. Note that SMTPS email encryption does not help because STARTTLS is vulnerable to downgrade attacks.

3.  Compromise a recursive DNS server that is used by a Certificate Authority, or forge a DNS entry for a victim domain (which has sometimes been quite easy). Again, this defeats domain validation.

4.  Attack some other network protocol, such as TCP or BGP, in a way that grants access to emails to the victim domain.

5.  A government could order a Certificate Authority to produce a malicious certificate for any domain. There is circumstantial evidence that this may happen. And because CAs are located in 52+ countries, there are lots of governments that can do this, including some deeply authoritarian ones. Also, governments could easily perform any of the above network attacks against CAs in other countries.

In short: there are a lot of ways to break HTTPS/TLS/SSL today, even when websites do everything right. As currently implemented, the Web’s security protocols may be good enough to protect against attackers with limited time and motivation, but they are inadequate for a world in which geopolitical and businesses contests are increasingly being played out through attacks against the security of computer systems.                       More

Friday, September 16, 2011

Cyber attacks are becoming lethal, warns US cyber commander


Cyber attacks are escalating from large-scale theft and disruption of computer operations to more lethal attacks that destroy systems and physical equipment, according to the head of the US Cyber Command.

 

“That’s our concern about what’s coming in cyberspace – a destructive element,” General Keith Alexander told a conference on cyber warfare, according to the Washington Times.

Alexander, who is also the director of the National Security Agency (NSA), said that future computer-based combat is likely to involve cyber strikes that cause widespread power outages and even physical destruction of machinery.

The potential for cyber attacks to do this, he said, is illustrated by the electrical power outage in the Northeast US in 2003 caused by the freezing of software that controlled the power grid after a tree damaged two high-voltage power lines, and the destruction of a water-driven electrical generator at Russia’s Sayano-Shushenskaya dam in 2009 that was caused by a computer operator remotely starting the generator while one of the dam’s turbines was being serviced.      
More

Free Internet Security for Small Businesses




PCWorld - Are you looking to cut expenses for your small business or organization? You can save some cash by replacing those annual antivirus subscriptions with free equivalents. Though most free tools are restricted to home or personal use, a few are also available for businesses at no charge. We’ll look at what the various freebies offer, and explain how to get started using them.

For Protection Against Multiple Malware Threats: Comodo Internet Security

Comodo Internet Security (CIS) provides a sturdy package for blocking viruses, spyware, rootkits, botnets, worms, and other malware.

CIS goes beyond the basic malware protection that you get with a lot of freebies, offering a built-in firewall to guard against hackers and intrusions. Windows comes with a free native firewall, but using CIS’s third-party alternative provides more-advanced configuration options. In addition its consistent interface is useful if different versions of Windows run on your network, since the native firewall differs from one Windows version to another.

When we reviewed Comodo’s free product in late 2010, we liked how well it blocked new malware, though we found that it had a few drawbacks in other respects. Still, it managed a an overall rating of 3.5 stars–a solid mark.

The program’s Defense+ feature analyzes and manages executable files to protect critical system files and to prevent malware from causing harm. It also has automatic sandbox functionality, which runs unknown files in an isolated environment so they can’t do any damage if they turn out to contain malware.

Comodo’s SecureDNS service conducts malicious-website filtering to block phishing, malware-carrying sites, and other known dangerous websites before they can infect you. This DNS-based service is similar to OpenDNS, which we’ll discuss later.

Comodo Internet Security (CIS)

Unlike many free antivirus products, Comodo Internet Security (CIS) offers a firewall component.

CIS lets you adjust an array of advanced settings governing heuristics levels and other general scanning settings, as well as customizable “scanning profiles.” The Firewall and Defense+ features are highly customizable, too. You can fine-tune the protection by using rules, policies, definitions of trusted files/networks, and other settings.

Comodo Internet Security (CIS) Computer Security Policy.
Comodo Internet Security’s Computer Security Policy manager.

CIS’s configuration management is very convenient for running on multiple PCs. Just configure one PC, export the configuration file, and import it to the others. All settings are backed up, including scanning profiles, security policies, and password protection.

If you want to give CIS a try, download it from the Comodo site. Just prior to installing it, make sure that you have completely uninstalled any existing antivirus program and rebooted Windows to prevent any conflicts. You should also disable Windows Firewall if you choose to install Comodo Firewall when installing CIS. During the installation, the setup program will ask you whether you want to enable SecureDNS. If you plan on using OpenDNS (discussed later), don’t enable SecureDNS.

Once you’ve installed CIS, go through all of the screens and settings, and configure it to your liking. The default settings are best for most situations; for full protection, however, you may want to consider enabling cloud scanning and rootkit scanning in the Scanner Settings of the Antivirus component. Also, discover and configure the security policies settings of the Firewall and Defense+ components.

To reduce unnecessary Internet traffic when you use CIS on multiple PCs, install the Comodo Offline Updater (available at no charge from Comodo’s site) to one PC, so that it can download Comodo’s virus database updates. Then configure each of the other CIS installations on your network to check for updates from that PC instead of from the Comodo server.

To change the update server that CIS checks, select the More tab, click Preferences, and select the Update tab. Then add to the list the IP address or host name of the PC that you installed the Comodo Offline Updater on. Consider keeping the Comodo server enabled but in the number two position, in case you encounter a problem with your PC.

Comodo Internet Security (CIS) update server preferences.

Changing the update server used to download virus signatures.You should also consider setting a password for CIS and locking down the configuration so that other users can’t change any settings. To do this, open CIS, select the More tab, click Preferences, and select the Parental Control tab.

Next: Microsoft Security Essentials and OpenDNS…

Friday, September 9, 2011

Software Pirates Plague Android Developers


Forbes - Software pirates cost Android developers serious money, according to a study released Thursday.

A survey of 75 Android developers conducted by location-based services specialist Skyhook found that 27% of developers see piracy as a ‘huge’ problem.

Another 26% of those surveyed see piracy as ‘somewhat’ of a problem. 53% of developers say Google is too ‘lax’ when it comes to patrolling the Android Market, Google’s alternative to Apple‘s App store.                More

Thursday, September 1, 2011

Energy Grid: Safe From Cyber Attack?



Towers carrying electrical lines in San Francisco, Calif. The smart grid that overlays power systems may be vulnerable to cyber attacks. Click to enlarge this image. Getty Images


THE GIST
  • The smart grid promises more efficient energy use but may be more vulnerable to attacks.
  • The nation’s electric utilities are now catching up when it comes to protecting the grid.
  • Some cyber attacks on the grid have already occurred.
 
Discovery News - As the 9/11 anniversary approaches, experts wonder if the United States could withstand a breach of its power network, or whether the so-called “smart grid,” which promises more efficient energy use, is more vulnerable to cyber attacks than the old one. The answers are yes and yes.

When it comes to protecting against hackers, the nation’s electric utilities are about where the financial and telecommunications industries were a decade ago, according to Andy Bochman, Energy Security Lead for IBM’s Rational division, which focuses on smart-grid security software.

Bochman says the electrical sector has been late in the game when it comes to embracing information technology that focuses on security, but is catching up.

NEWS: Cyber-Security System Mimics Human Immune Response

“We are now at a sustained back-and-forth between the powers that are trying to attack these systems, and forces aligned to defend them,” Bochman said.

While that statement may sound a bit like a sci-fi plot, the reality is that utilities across the country have seen a big increase in deliberate attacks, as well as inadvertent screw-ups that have thrown thousands of customers into the dark.

In a study released in April of electrical utilities by McAfee, the computer security firm, and the Center for Strategy and International Studies in Washington, utility industry executives from 14 nations found that things are getting worse.

DNEWS VIDEO: A hacker explains why hacking isn’t the same thing as cyber crime. 

“One of the more startling results of our research is the discovery of the constant probing and assault faced by these crucial utility networks. Some electric companies report thousands of probes every month. Our survey data lend support to anecdotal reporting that militaries in several countries have done reconnaissance and planning for cyberattacks on other nations’ power grids, mapping the underlying network infrastructure and locating vulnerabilities for future attack,” the report stated.

Could a Stuxnet-type virus, which pretty much destroyed one of Iran’s nuclear power plants, happen in the United States? Some similar, but less dangerous events, already have:

•In April 2009, The Wall Street Journal reported that that cyber spies had infiltrated the U.S. electric grid and left behind software that could be used to disrupt the system. The hackers came from China, Russia and other nations and were on a fishing expedition to map out the system, the paper reported.                    More