Friday, December 28, 2007

Scammers target eBay names

Anti-scammer tips:

  • Use a different name on eBay than on your webmail. Scammers target an email name on gmail, hotmail, and similar online webmail apps.
  • If it sounds too good to be true, it's not true.

- Based on a blurb in the December 28th SANS emailed newsletter (not online yet). You can subscribe to get security "NewsBites" by email.

Software Patch Inspector

Secunia's Personal Software Inspector (PSI) is now in Release Candidate 1 (RC-1).

Of ZD Net's top 10 free security utilities you should be using, they say, "Number one is the Secunia Personal Software Inspector, quite possibly the most useful and important free application you can have running on your Windows machine."
http://content.zdnet.com/2346-12691_22-95490-1.html

The latest update features an improved look plus easier use by novices, yet advanced options can be turned on.

You can even track the results of your patching. Run, don't walk, and get Secunia's PSI now!

Wednesday, October 24, 2007

Non-Microsoft security updates

Several security updates came out recently for products other than Microsoft ones, although a couple apply only if you are using Internet Explorer version 7. If you have the following software, make sure you get the patches:

  • Adobe Acrobat 8
  • Adobe Reader 8.1.1
  • Apple Quicktime 7.2
  • Mozilla Firefox 2.0.0.8

Saturday, October 20, 2007

Malicious emails contain fake Youtube link

US-CERT says that new variations of the Storm Worm have been appearing in email messages as fake YouTube video links.

The emails arrive with headers such as, "LOL, that is too cool..."

The email claims to be a video of you that has been discovered. The message contains a fake link to youtube.com. The link acually sends you to a malicious website that downloads and runs malware.

Thursday, September 27, 2007

Adobe Reader vulnerable

Adobe Reader has a serious vulnerability that could be exploited by a maliciously created PDF. The flaw could be exploited to take control of computers. So far, Adobe has no patch for it

Until this vulnerability is patched, do not open a PDF file you get unless it's from a trusted source and you were expecting the file.

If the source is trusted but the file unexpected, contact the sender before opening the PDF.

Friday, September 14, 2007

Identifying hoaxes and legends

The US-CERT site has some excellent Cyber Security tips. A recent one is "Identifying hoaxes and urban legends". The article is in clear English, not geek language, and covers:
  • Why hoaxes are a problem
  • Types of chain letters
  • Deciding if an email is a hoax (or legend)

Wednesday, August 29, 2007

You need more than Windows Update

If you use Microsoft Windows, you are likely familiar with Windows Update, the free service that installs security patches, bug patches, and some enhancements to Windows. But you really need much more.

You need to get updates for other Microsoft prograns, such as Microsoft Office. You can do that by installing "Microsoft Update ".

Next, download and install the Secunia Personal Software Inspector and check for outdated programs and ones needing updates. Though in beta, it works well and is an eye-opener.

Don't put it off -- prote t your computer now!

Tuesday, August 21, 2007

Outdated programs risky

Many programs these days need updates, not just your operating system (e.g. Windows). As an example, today's Windows Secrets points to the following common programs:
  • Adobe Reader
  • Macromedia Flash
  • Apple Quicktime
  • Sun Java
  • Mozilla FireFox

Most of these programs default to checking for updates. But if you ignore the update message or if it only checks once a month, you can be way behind in plugging security holes (a.k.a. "vulnerabilities").

What can you do about that? One very big help is the free Secunia Personal Software Inspector (PSI). You can try it online first and download if it serves as an eye opener for you -- it did for me.

For one thing, I discovered old versions of Sun Java on my system. Any "point" version needs to be updated to its most recent one. For example, the only currently secure versions of Sun Java JRE are version 5 update 12 and version 6 Update 2 (also known as 1.5.0_12 and 1.6.0_02)

Personal information security

I got some new ideas on improving security of my personal information from tips emailed to me at work. Use the tips below to better protect your personal information:
  • When printing checks, print only your first initial and last name. A check forger will not know what first name to use.
  • Do not list your phone number on a printed check. Write it in by hand, but only when required.
  • Do not sign your credit cards, despite the instruction on the card to do so. If your card gets stolen, a signature is a great find for a forger. Instead, use pen to write on the signature line, "Require Photo ID." It helps.
  • Photocopy both sides of your driver's license, all credit cards, etc. If any get lost or stolen, you have a fast memory jog, including the emergency numbers to call.
  • Fill in only the required parts of an online form. The more information you reveal, the greater the chance of its misuse.

Thursday, August 16, 2007

Health by Google?

Google has ambitious plans in expanding its easy-to-use applications to Google Health. One thing that concerns me is the potential for harvesting of personal medical data.

Google can't be 100% attack-proof, no matter how security-conscious they are. So I'd expect that eventually a hacker would break into at least some people's health information.

Also, you give a doctor access to your online profile (medical history, medicines, allergies, operations, symptoms, etc.). So do they get a one-time password entry or would you have to change your password after every such access (yuk!)?