I’m paranoid about the web, and with good reason.
The #1 way hackers get into computers today is through your web browser from an infected website. The battle for control of your computer has spread from e-mail and attachments. Another battlefront has opened up on your web browser. A large number of big-name sites have been hacked recently and nobody is completely sure just what the hackers made off with. Hackers use DNS spoofing to trick computers into coming to an infected website, so you can’t completely be sure that you ended up on the website you intended to visit. They also buy up common misspellings of big sites to catch anyone that makes a typo.
Hackers have been using SQL injection vulnerabilities to break into websites for years (it is in fact one of the primary ways hackers get into a server), and these vulnerabilities still go unpatched. Now they are infecting websites in order to set up complex computer/browser/plugin fingerprinting engines that detect vulnerable versions. These engines deliver attacks custom-tailored to infect the visitor’s computer with slimy botware. Take out the cookies, pop-ups, plugins and JavaScript and you’ve stripped your attack surface these engines can attack, down to just your web browser. But this makes browsing less user friendly and a lot more frustrating in the short term, and confusing for people who aren’t technical.
Of course, whenever someone starts talking about a really secure platform, the Mac fanboys jump right in to tell me how secure Apple MacOS is–never mind that the MacOS/Safari combo gets hacked every year (2007, 2008, 2009, 2010,2011) during PWN2OWN at CANSECWEST. Never mind that the hackers have now developed a crimeware kit for the Mac, which means Mac users will need to be on the lookout for a deluge of malware from now on.
With so much dangerous malware and so many threats, how do I stay secure online?
READ MORE: Browser inSecurity – How I Stay Protected Online
Thought your Mac was secure? Did you know it is possible to turn the battery into a dead brick, or worse, possibly make it overcharge? How about permanently infect your computer (at least until the battery is replaced)?
So you thought Mac OS X 10.7 “Lion” was secure, and rushed right out and bought it? Passware discovered that the logon password can be extracted from a Mac running OS X 10.7 Lion, even when the system is locked or asleep.
Blocking Russian and Chinese SPAM is actually fairly easy. Unless you communicate in Russian or Chinese, just delete any e-mail that contains any of the special characters either of those languages use. I’ll admit that Chinese is a bit harder, since there are over 3000 characters in their ‘alphabet’, but using the top 30 or 40 characters should block most of the SPAM.
Blocking Russian and Chinese SPAM from Outlook
RSA Security, maker of the SecureID two-factor authentication system used in many encryption systems and VPN/Remote Access products, was successfully attacked with an “Advanced Persistent Threat”. The APT involved a small number of e-mails specifically targeted to the individuals contacted (spear phishing), a bit of social engineering in the e-mail and finally a malcode exel spreadsheet attachment that exploits a 0-day Adobe Flash vulnerability, that Adobe has since patched.
The RSA CIRT team apparently caught it while ‘ongoing’. Read about it on the RSA blog. Surprisingly forthcoming about the ‘how they got in’, not so much about the ‘what was stolen’.
Recent Comments