Showing posts with label Attack. Show all posts
Showing posts with label Attack. Show all posts

Monday, 4 July 2016

Stand and Deliver

A switch back to security issues with today’s post. Specifically, a look at Ransomware, what it is and how to protect against it.

What is Ransomware?

Ransomware is a type of malware (or virus) that can be installed on a computer without knowledge or the intention of the user. Typically, it takes the form of a Trojan, entering a system through, a downloaded file or a vulnerability in an online service. Its aim is to restricts access to the infected computer system in some way, sometimes completely. Then it will demand that the user pays a fee (a Ransom) to the perpetrators to have the restriction removed.


Have Ransomware attacks not ended?

Things did seem to quiet down, however there has been a measured increase in detection of new threats. Kaspersky Lab Detected a 14% Increase in New Ransomware Modifications in the first quarter of 2016.

Are only PCs at risk?

Originally, this was the case. However, it did not take long for attacks to migrate from traditional targets to mobile devices. These infections work in much the same way, locking out a user until a fee is paid.

What can I do to protect myself?

Vigilance is the key. Avoid sites where pirated content is provided. Pirated downloads may have been modified to harbour hidden viruses and malicious content.  Avoid sites that stream pay for view content for free. Again for the same reasons as above. And also in this vain, think before clicking on a link.

Next, ensure you keep your anti-virus software up to date. At one time there was little defence against Ransomware, but now most credible anti-virus systems deal well with legacy attacks. I say legacy attacks as new malware is always been developed and there is always the risk of attacks before fixes become available. 

Finally, take regular off line back-ups.  Ransomware plays on a weakness that we are all afraid of losing all our precious content. Knowing that many of us would rather pay than suffer that fate. Having a good back-up policy removes this risk. If you become infected you can simply ‘flatten’ a machine and restore from back-up. 


Related Posts



Will Hogarth

CTO @ VGS Media

Will Hogarth is a long time geek, writer, and long distance triathlete, with extensive experience in most areas of the IT World. Will is a former games developer, DBA and project manager, but unlike most geeks he has a passion for the outdoors and a life of adventure.

Links


Thursday, 12 May 2016

You call that a Password

In my last post I eluded to the need for people to use strong passwords. I have received so much communication on the subject that I decided to dedicate this week’s post to the world of passwords.

I’ve worked in IT for quite some time now, and the amount of times I have sat at someone’s locked machine and had to think – ‘Now what would XXX use as their password, just to have gained access a few minutes later. Too many people are in the habit of using the obvious. 

A recent analysis of a large sample of passwords reviled that people still used simple to crack password to protect their systems. I am referring to passwords such as: 123456, password, qwerty (3 of the most commonly used passwords out there.) After that people tend to use names, their own, their spouses, their children, even their pets. Then the next group are people that use the sporting alliances for their passwords. All it takes is a little knowledge for even the most primitive of hacker too guess these. And most hacking tools would gain access almost instantly. 

Technology users need to adopt safe password protocols.

Strength

As I have said, a strong password is one that cannot be easily guessed, or hacked by a brute force attack in an acceptable amount of time. That means no words likely to be found in a dictionary, no common names, no dates of birth, and nothing too short. 

Passwords should be of a reasonable length, be a random mixture of lower and uppercase letters, utilise numbers and symbols. Although some systems limit the complexity, you should always try to adhere to this rule.

If stumped, try out one of the many on line password generators.

Variety

Do not use just one or two passwords to secure all your systems. It may be a no-brainer, but so many people fall into this group. If a hacker cracks one password, then they will have access to your whole digital life. Just think about it.

Do not make it easy for them. Use a different password for every instance where you need to use one. You may think this may make your life hell, we are all so connected these days, we access countless secure systems. Don’t worry about this, check out the section on TOOLS.

The Week Link

Quite often we, as users, are the weakest link in the whole security chain. To mitigate the risk your yourself post, you should follow a couple of rules.
  1. Never write a password down, just in case you forget it. Anyone may see this in passing.
  2. Do not share your password with others. If someone needs to be on your machine, you should log them on yourself. Then watch them until they have completed their task at hand.
  3. Decline invitations from your browser to remember your passwords. Doing this is just the same as having just one password for all systems. As, when someone manages to gain access to your machine, all they have to do is fire up your favourite browser to gain access to all your on-line accounts.


Tools

The thought of remembering dozens of completely different passwords may fill you with dread. However, if you are not the sort of person that is predisposed to remembering random collections of gibberish, there are tools out there designed to do this for you. 

Relying on a single system is not ideal, however it could be the compromise you are looking for. One word of warning though is: Research the merits and pitfalls of any such systems you intend to adopt prior to their implementation.

After reading this, if the digital life fills you with fear, don’t worry. Just take the steps outlined and they will help keep you safe in an ever growing digital world. Alternatively, if you would like more advice on security in the digital age, or are interested in a digital security audit, please feel free to get in touch with us here at VGS Media.


Friday, 6 May 2016

Securing the Smart Home

As the world of the Internet of things (IoT) and more homes embrace Smart Home technologies, it is obvious that security will become a growing concern, and even a growing issue if left to manage itself. When a home is connected to the internet it can become a target for hackers.

So, the question is, as always, what can occupants of a Smart Home do to protect themselves against the unwanted attentions of potential hackers?



  • Stick to reputable brands: The Smart Home is an emerging market place, and companies new to the market (or who are just dabbling with the market) may not provide as secure a product set as those who are more established. That is not to say that innovation is not good for a growing technology trend, but consumers’ must take care to evaluate their options.
  • Ensure that any updates are regularly applied: Like all things IT, as and when any vulnerabilities are identified, providers of equipment work quickly to build in protection against that vulnerability. Ensuring your equipment’s software and/or firmware are always kept up to date will protect you against those known security risks.
  • Always change the default password settings: Many people stick with the default passwords on devices. This is a major flaw, as all it takes for the hacker to gain access to your devices, and then you home, is to guess what those devices are, and then they are in.
  • Always use a strong password: A strong password is one that cannot be easily guessed, or hacked by a brute force attack in an acceptable amount of time. That means no words likely to be found in a dictionary, no common names, no dates of birth, and nothing too short.
  • Ensure you router is secure: After all your router is the gateway to your network. A poorly configured router makes it so much easier for cyber criminals to gain access to your devices. Also note, the above recommendations on passwords, equally apply to the router.
  • Take professional advice: Finally, if you are going to dive in to the world of the Smart Home, consider taking professional advice. Companies who specialise in the designing and installation of Smart Home systems are more likely to be aware of the risks than the every-day member of the public. Plus, they may even surprise you of what you can achieve on your budget.

If you want to find out more about Smart Homes, Home Automation, or even the security risks around the various technology sets, feel free to get in touch with us here at VGS media.

web: media.vgs.global




Wednesday, 9 December 2015

(All so) Public Wi-Fi

Wi-Fi connectivity is more abundant than ever before. With the popularity of hotspots in cafes, bars, airports, in fact just about everywhere, it has never been easier to get on line.  So much so, that is somewhere doesn't offer a free hotspot – you feel like you should complain. How stingy. 

The train is not due for 30 minutes. So, just time for quick coffee and just time to pay a bill, check how your eBay action is going and log in to your web mail to see if that parcel you ordered has been dispatched. Right?

Wrong!!!

Public Wi-Fi spots are not just popular with legitimate users, they are also popular with criminals, with HACKERS.

Picture this…
  • You are in Zippy Coffee Shop waiting for you train
  • A quick browse for Wi-Fi and you find the Zippy open connection.
  • A couple of clicks and you're connected, on-line and up and running

So, here’s the problem…

  • You know nothing about that connection, does it even belong to the coffee shop.
  • In this case it is the wireless signal of a hacker enjoying his Americano, 2 tables away.
  • You have just connected to his laptop and are browsing through his shared connection.
  • Everything you type he’s intercepting
  • Your on-line bank login
  • Your eBay user ID
  • Your web-mail details 
  • Now, as you leave Zippy Coffee Shop none the wiser the hacker has everything he needs to rip you off

This is call a Man in The Middle attack (MITM)



So do you need to avoid Public Wi-Fi all together?

No … Although you should never do more than browse. Wait until you have a secure connection before visiting those sites that require you to log in, such as banks, eBay etc.

If you need to connect to work, go via a VPN services. VPN stands for virtual private network, and there are many services out there that you can use with apps for smartphones and computers. Ask your IT administrator, if your organisation offers this type of secure connection.




Will Hogarth

CTO @ VGS Global

Wednesday, 2 December 2015

Gone Phishing

Phishing (fish´ing) (n.) is the act of sending an email to a user falsely claiming to be a legitimate enterprise. The aim of such contact is to scam the user into surrendering private information that will be used for identity theft or to steal money from intended victims.

A phishing email will normally direct the user to visit a website where they are asked to update personal information, such as a password, credit card, social security, or bank account numbers, that the legitimate organization already has. The website, however, is a fake and will steal any information the victim enters on the page.



To protect against these scams, it is best to familiarise yourself with a few techniques of identifying potential threats.

  • Salutation: A lot of phishing scam emails are mass sent, and as a result they quite often use generic salutations, such as Dear Customer, Dear Member, or even a simple Hello. If you think about it. Companies, where you have an account already know you so are more likely to call you by your preferred name.
  • Spelling and Grammar: Scammers are not known for their keen eye for competent skills with the written language. Whereas the larger organisation they pretend to be, would normally employ staff to produce professional looking copy, to send to the customers.
  • From who: The ‘from’ email address may state it is from a legitimate organisation, but hovering over or clicking on this address (depending on email client) will show the full actual email address. So that the email stating it is from Facebook.com could actually be from facebook@xyz.com. Not the same thing. Also check the ‘from’ closely for slight misspelling, is it from manager@facebook.com or manager@faceboook.com?  Scammers quite often register domains with similar URLs to legitimate organisations.
  • Links: you should not click on a link without being 100% sure of its legitimacy. A link may read one thing, but when you hover over the link it is revealed as a link to a totally different web site.  If not 100% sure. Go to the site by typing the URL into your browser for that company rather than using the link.
  • Threats: A lot of scam emails will include a threat as part of your emails, such as: “Account will be closed.” Or “System will no longer work.” Legitimate organisations will very rarely threaten you in this way.
  • Another ‘from’ Point: Quite often the from address may have you as the sender. You did not send yourself this email … It’s a scam
  • Too good to be true: Instead of a threat the email may be for an offer that is too good to be true. A rule of thumb is that any offer that is too good to be true, is too good to be true. You don’t have a long lost African prince uncle that has left you his fortune.
  • Passwords and Pin Number: Organisations will not ask for your passwords or pin numbers by email. These are yours, not theirs. So, never divulge them.


Finally…

If you suspect that the security of one of your on-line systems has been compromised due to a phishing scam, take action immediately. Go to the site, log in and change your security data. Alternately get in touch with the company direct by telephone and explain your concerns. They will help you rectify the situation.




Will Hogarth
CTO @ VGS Global