Saturday, January 21, 2012

Severe Malware Alert 1/21/12 - Be wary of fake Adobe updates & PDF's.

In the past few days I've seen a pattern of infected PC's with the same symptoms.  After doing some digging on the last few machines and asking the owners a few questions, I've confirmed that there has been a very wide spread virus hitting your mailboxes and favorite websites this week.  It is either disguised as an Adobe program update (Flash, Distiller, Acrobat Reader) or is an attached exe on an e-mail with a PDF logo so you think you're simply opening a PDF, (e.g. ESTORNO5540452C.PDF.exe).

To avoid this type of infection,
1) NEVER click a window saying you need to update program xyz, even if it looks legit.  To update that program, you can open it up yourself and have it check for updates directly, usually under the "File" or "Help" menus.  Or go to their website and download the new version.

2) NEVER open an .exe file from ANYONE. Also even if it may look like a word or PDF file because of the icon, it still may be an exe.  Always check the end of the name.

Other than that, keep your Anti-Virus up to date, your Anti-Malware up to date, and your Windows up to date.

~Matthew

Tuesday, January 3, 2012

25 "Worst Passwords" Of 2011 Revealed

If you see your password below, STOP!
Do not finish reading this post and immediately go change your password — before you forget. You will probably make changes in several places since passwords tend to be reused for multiple accounts.
Here are two lists, the first compiled by SplashData:

1. password
2. 123456
3.12345678
4. qwerty
5. abc123
6. monkey
7. 1234567
8. letmein
9. trustno1
10. dragon
11. baseball
12. 111111
13. iloveyou
14. master
15. sunshine
16. ashley
17. bailey
18. passw0rd
19. shadow
20. 123123
21. 654321
22. superman
23. qazwsx
24. michael
25. football

Last year, Imperva looked at 32 million passwords stolen from RockYou, a hacked website, and released its own Top 10 “worst” list:
1. 123456
2. 12345
3. 123456789
4. Password
5. iloveyou
6. princess
7. rockyou
8. 1234567
9. 12345678
10. abc123

If you’ve gotten this far and don’t see any of your passwords, that’s good news. But, note that complex passwords combining letters and numbers, such as passw0rd (with the “o” replaced by a zero) are starting to get onto the 2011 list. abc123 is a mixed password that showed up on both lists.
Last year, Imperva provided a list of password best practices, created by NASA to help its users protect their rocket science, they include:
  • It should contain at least eight characters
  • It should contain a mix of four different types of characters – upper case letters, lower case letters, numbers, and special characters such as !@#$%^&*,;” If there is only one letter or special character, it should not be either the first or last character in the password.
  • It should not be a name, a slang word, or any word in the dictionary. It should not include any part of your name or your e-mail address.
Following that advice, of course, means you’ll create a password that will be impossible, unless you try a trick credited to security guru Bruce Schneier: Turn a sentence into a password.
For example, “Now I lay me down to sleep” might become nilmDOWN2s, a 10-character password that won’t be found in any dictionary.
Can’t remember that password? Schneier says it’s OK to write it down and put it in your wallet, or better yet keep a hint in your wallet. Just don’t also include a list of the sites and services that password works with. Try to use a different password on every service, but if you can’t do that, at least develop a set of passwords that you use at different sites.
Someday, we will use authentication schemes, perhaps biometrics, that don’t require so much jumping through hoops to protect our data. But, in the meantime, passwords are all most of us have, so they ought to be strong enough to do the job.

Saturday, December 10, 2011

Is your WiFi secure? Odds are not in your favor.

  Over the past decade we have seen large advancements in WiFi security, yet there are still a large amount of computer users that aren't taking advantage of these necessary changes. Also contrary to some belief, companies such as cable providers who set up the hardware, do not secure it for you.  As a courtesy to my clients, I always check their wireless network setup to make sure it's secure, and I would say approximately one out of every three networks are easily accessed by intruders.  Possibly more disturbing than that, is nearly 100% of the time, someone within range has either a network with no security, or easily bypassed methods such as "WEP" or "MAC Address Filtering".   So I'd thought I'd share with you why and how to properly secure your wireless network.  If you are afraid to take this task on by yourself, I do offer remote support and house calls within 30 miles of White Lake, MI.

Two Steps To Determine If Your Wireless Network Is Secure (Windows 7)
  1. Check the encryption method: Left-click the wireless connection icon near your computers clock on the taskbar, it looks like signal bars on a cell phone, then right click on the wireless network you're connected to, select "Properties".  If "Encryption Type" is anything other than "AES", you do not have a secure wireless network.
  2. Check password strength: On the same window, check the box that says "Show Characters", Windows may pop up a window to authorize the change.  The password must be over 20 characters in length, and contain both numbers, letters and some special characters such as commas, parenthesis, periods, etc..., if it does not, you do not have a secure wireless network.
Why should you be concerned about having a secure network?
  I know some of you may be thinking, "I trust my neighbors", or "I  don't have anything anyone wants anyway". Well I have one word for you, "Wardriving".  If you haven't heard of it, people actually drive around towns, looking for unsecured networks.  Once they have access, they can do a number of malicious activities such as
  • Copying and/or deleting shared files from your hard drive, photos, resumes, personal information, internet history.
  • Intercepting your passwords as you log into your online accounts (facebook, banks, e-mail)
  • Stealing bandwidth which in turn, slows down your internet.
  • Using your internet for illegal activities such as downloading pirated music and movies, which you could be held responsible for.
"My brother/friend/salesman/says my current setup is fine".
I've heard a few people insist their networks were safe, so I was happy to demonstrate how they were misinformed.  The important thing here is that you don't need to know much about computers to crack these methods, there are programs out there that automate nearly the entire process!  These are some standard scenarios with the type of security, and how soon an amateur hacker can gain access.

  • Open Network (No Security): ~5 Seconds
  • Mac Filtering:  add 15 Seconds to all methods
  • WEP 64-Bit: 60 seconds or less
  • WEP 128-Bit: 20 seconds to 5 minutes
  • WPA (TKIP): 15 to 20 minutes (Pro Hacker) | 7-12 Hours (amateur via bruteforce) 
  • WPA2 Personal: Very secure network, no records of outside hackers being able to crack when passwords are strong.
So how do you make sure you're secure?
It all comes down to two things, using WPA2(AES) encryption to prevent the code crackers, and a 20+ character strong password/key to prevent the bruteforce hackers.  Check your routers manual to make sure it supports WPA2 with AES, if it doesn't, it's time to upgrade.