Showing posts with label threats. Show all posts
Showing posts with label threats. Show all posts

Thursday, October 22, 2009

Caution! Rise in Scareware Tactics - Rough Security software

Rogue security software, also dubbed scareware, is an "ongoing threat" that is impacting largely users from English-speaking markets, according to findings from a year-long study by Symantec.

Released Tuesday, Symantec's report on rogue security software noted that 250 rogue security programs launched some 43 million attempts to prompt user installation between July 2008 and June 2009.

Read also: Fake 'Conflicker.B Infection Alert' spam campaign drops scareware

Further analysis on the top 50 most reported scareware was carried out between July and August this year, during which Symantec found that 38 of the programs had been detected prior to Jul. 1, 2008.

"The continued prevalence of these programs emphasizes the ongoing threat they pose to potential victims, despite efforts to shut them down and raise public awareness," the security vendor said in the report.

The five most commonly reported rogue security applications during the study were SpywareGuard 2008, AntiVirus 2008, AntiVirus 2009, Spyware Secure and XP AntiVirus.

For more info read ZDNet Asia Security Blog.........

Friday, October 16, 2009

Recession hit Cyber-crime just doesn't pay like it used to.

Recession hits Cybercrime! With botnets everywhere, DDoS attacks get cheaper $30 will buy a one-day DDoS attack now!

Security researchers say the cost of criminal services such as distributed denial of service, or DDoS, attacks has dropped in recent months. The reason? Market economics. "The barriers to entry in that marketplace are so low you have people basically flooding the market," said Jose Nazario, a security researcher with Arbor Networks. "The way you differentiate yourself is on price."

Criminals have gotten better at hacking into unsuspecting computers and linking them together into so-called botnet networks, which can then be centrally controlled. Botnets are used to send spam, steal passwords, and sometimes to launch DDoS attacks, which flood victims' servers with unwanted information. Often these networks are rented out as a kind of criminal software-as-a-service to third parties, who are typically recruited in online discussion boards.

DDoS attacks have been used to censor critics, take down rivals, wipe out online competitors and even extort money from legitimate businesses. Earlier this year a highly publicised DDoS attack targeted U.S. and South Korean servers, knocking a number of Web sites offline.

Are botnet operators having to cut costs like other businesses in these troubled economic times? Security researchers don't know if that's been a factor, but they do say that the supply of infected machines has been growing. In 2008, Symantec's Internet sensors counted an average of 75,158 active bot-infected computers per day, a 31 percent jump from the previous year.

DDoS attacks may have cost hundreds or even thousands of dollars per day a few years ago, but in recent months researchers have seen them going for bargain-basement prices.

Nazario has seen DDoS attacks offered in the US$100-per-day range, but according to SecureWorks Security Researcher Kevin Stevens, prices have dropped to $30 to $50 on some Russian forums.

And DDoS attacks aren't the only thing getting cheaper. Stevens says the cost of stolen credit card numbers and other kinds of identity information has dropped too. "Prices are dropping on almost everything," he said.

While $100 per day might cover a garden-variety 100MB/second to 400MB/second attack, it might also procure something much weaker, depending on the seller. "There's a lot of crap out there where you don't really know what you're getting," said Zulfikar Ramzan, a technical director with Symantec Security Response. "Even though we are seeing some lower prices, it doesn't mean that you're going to get the same quality of goods."

In general, prices for access to botnet computers have dropped dramatically since 2007, he said. But with the influx of generic and often untrustworthy services, players at the high end can now charge more, Ramzan said.

Tuesday, August 11, 2009

Tamiflu not suitable for Children: TV Personality's daughter 'almost died'

pa.press.net
Health Secretary Andy Burnham has defended giving swine flu drug Tamiflu to children as TV presenter Andrew Castle said his daughter "almost died" after taking it.

Mr Burnham was confronted by Castle on GMTV after research cast doubt that the anti-viral drug's benefits outweighed its side-effects.

The presenter said: "I can tell you that my child - who was not diagnosed at all - she had asthma, she took Tamiflu and almost died."

Fatal Consequences

Castle said his daughter, Georgina, had a severe reaction, "respiratory collapse" and "suffered very heavily" after being "just handed" the drug without having been properly diagnosed.


All this is in the light of last week, when a 2 yr old child died of Meningitis, after being wrongly diagnosed as having Swine Flu. She and her parents were dismissed and turned away by off-hand, hospital, medical staff.

Sympathy on Offer

Mr Burnham sympathised with Castle, saying it must have been "very worrying", but maintained that the current advice being given to parents to treat swine flu with Tamiflu, remained unchanged, despite the wave of severe doubts and criticisms coming from consultants and specialists alike.

Given that swine flu had a "disproportionate effect" on children, he maintained that Tamiflu was "our only line of defence" or, the only line of defense being considered. A policy that puts children in as much danger from the cure as from the disease.

Specialists Warn against Tamiflu

On Monday, Oxford University researchers made a serious announcement that children should NOT be given the anti-viral drug to combat swine flu. They urged the Department of Health to urgently rethink its policy on giving the drug to youngsters affected by the current flu pandemic.

The study, published in the British Medical Journal (BMJ), warned that Tamiflu can cause severe vomiting in some children, which can lead to dehydration and the need for emergency hospital treatment.


Cure worse than Disease

The researchers stated strongly that children should NOT be given the drug if they have a mild form of the illness. In such cases the cure is worse than the disease. They urged parents and GPs to remain vigilant for signs of complications and to avoid 'off the shelf' solutions and knee-jerk reactions.

Wednesday, July 22, 2009

Chinese News Sites Go Down After Reporting on Government Scandal

The Namib Desert a source of wealth and minerals as well as stunning beauty and mystery!

Two of China's most popular technology news Web sites went offline Tuesday, after carrying news reports that linked the son of China's president to a corrupt African deal.

The technology news sections disappeared for several hours from major Chinese portals Sina.com.cn and NetEase.com early Tuesday afternoon, when they started redirecting viewers to general news pages.

Both tech sections had carried reports on a state-owned company accused of bribing Namibian officials in the last day, but those reports were missing when the Web pages reappeared.

The suspensions appeared to be a government penalty against the companies for reporting on a sensitive political anti-government issues.

Media Censorship - "I'm impressed by the bravery of Sina and Netease in attempting to report this at all," said Rebecca MacKinnon, a Hong Kong-based expert on the Internet in China, in an online message. Clearly, the threats and intimidation being meeted out is having an effect in the media's self-censorship.

The Golden Children - Information on top leaders' children has always been off-limits in Chinese media, though the Internet has made it more difficult to control discussions on such topics, MacKinnon said.

Internet Police - Chinese police heavily patrol the Internet, and Internet companies run rigorous screening to prevent sensitive information from appearing on user forums or in search results on their sites. Companies can be punished if that process fails to catch certain political or pornographic content.

"This is not particularly surprising or different from long-standing censorship patterns," MacKinnon said.

NetEase story canned - A story posted on the NetEase tech page the night before its suspension cited English broadcaster BBC as saying that Nuctech, a Chinese company, was suspected of bribery in a deal to provide scanners for airports and ports in Namibia.

The BBC report had said Namibian authorities wanted to question Hu Haifeng, the former company president and son of Chinese president Hu Jintao, but did not suspect him in the case.

The NetEase story was careful not mention Hu, but it said that Namibia wanted to question "relevant" Nuctech executives.

Sina's article blocked - Sina's tech page carried a similar article the next morning, hours before the sites went down. After the tech sections returned to the portals, visiting the URLs of the scandal reports returned messages that they could not be found or had been deleted.

An employee who answered the phone at NetEase Tuesday said its tech section was down for tests. Sina did not respond to a request for comment.

Big Brother Tsinghua - Nuctech's parent company, Tsinghua Holdings, controls a range of other technology companies including Chinese PC maker Tsinghua Tongfang.

Thursday, April 30, 2009

Death comes to Queen's day: Serious security breaches


5 die and 13 are injured by a lone 'maniac' during Queen's Day

I have just witnessed the most apalling scenes at the Netherland's Queen's day celebration. It was disrupted and brought to a sudden and tragic end with the breakdown of weak security measures, quickly followed by poor crisis and incidence response measures. A complete abomination from a security risk and threat analysis, and from a public safety viewpoint. The time taken to respond and control the situation was woefully inadequate. If this had been a real incident, 'carnage' would have resulted. Whoever was responsible for the risk and threat assessment on this, is in the wrong business.

The incident today showed a complete lack of awareness for current threat reduction, vulnerability mitigation and crisis response management, prevalent in the rest of the world today. The arrogance and naivity inherent in providing this level of security to the NL Royal Family and the surrounding crowds, is both negligent and incompetent.

The ease by which a lone driver was able to breach the weak security measures was shocking but the response provided, during and following the incident was severely incompetent. If this had proved to be a real attempt to assasinate the Dutch Royal family by a cynical and trained group, then it would have been highly successful to a frightening degree and would have faced no serious resistance from the surrounding security forces.

Even following the incident there were no guns drawn; the car was not isolated to protect the Royal family and the surging crowd; there were no signs of protecting or rapid removal of the 'targets'; any anti-explosion measures were ignored; the 'containment' measures were non-existant, it was a dangerously embarassing and highly volatile situation that could have been easily exploited to a devastating effect.

I have studied the counter-terrorist measures of the Israelis, the South Afrikaans and the UK. I was online to the authortities in NY, both during the aftermath and the months following 9/11, offering support and advice.

The UK's own Royal Family has been at the centre of a number of attacks going back over several decades and have been a target of many such maniacs.

In 1974 a gunman tried to abduct Princess Anne as she and her first husband, Captain Mark Phillips, were being driven along the Mall in London after a charity film show. Would-be kidnapper Ian Ball forced the car to a halt and brandished a pistol. I had the pleasure of meeting the police detective that took 2 bullets for Princess Anne on this occasion and I have to say that he was a most modest and self-effacing man. The stuff that 'heroes' are made of.

Having spent the last 30 years of my life studying such incidents, with specific concern for the impact and consequences inflicted on civilian and security agencies. The effect of trauma on the victims, witnesses and spectators alike. It is with this close scrutiny of rare but extreme events and incidents perpetrated on the UK mainland by the IRA and others, that I am appalled at how easily the security today was compromised and how easily the Dutch Royal family could have been assailed and possibly assasinated. The transfer of trauma will be on an enormous scale.

When are the Netherland authorities going to realise that they have become a target for terrorism. Partly because they have proclaimed to the world that they are setting themselves up as the centre of justice for the war against international terrorists, organised criminals, sadistic dictators and mass murderers of all kinds.

Do not be mistaken, I applaude the Dutch in their stance against the evil that is so freely conducted. The establishment of the International Criminal Court against mass murderers wherever and however they manifest themselves, is a good and honourable achievement, even if it is somewhat tainted by the smell of the additional revenues that this will bring to local law firms and the other spin-off benefits that the NL authorities encourage. Unfortunately, in the eyes of the bad guys this also makes the NL a 'legitimate' target and by association the Duth people via the Dutch Royal family and other symbols of the 'establishment'.

The incident today was shocking and unbelieveable for a country that believes this sort of behaviour can only be perpetrated on them by others. I thought the world had already learned this harsh lesson. The US and the UK have certainly learned that the biggest threat comes from 'home grown' terrorist groups. Who else knows your weaknesses better than your close family and who else can get close to you to do you damage?

Let's not forget the victims in all this, and I offer them heart-felt condolenses to the victims of this incident and their families, they did not deserve this, no-one does. It will take them many years to rationalise this but clearly, they expected more protection from their guardians than was on offer today and they should demand better protection for the future. Substantial measures that go beyond the hype and rhetoric of politicians.

I also hope and pray that the NL authorites can contain the wave of xenophobia and the right-wing, anti-foreigner lobby that will spring up in the wake of this incident. Queen's day is already a symbol of white, Christian, conservative NL. There were few oriental or coloured faces on show in Apeldoorn. Marginalised and excluded from these occasions, it is easy for extremists to build on this 'pro-white' image and to corrupt the minds of the young people in NL. We must prevent this kind of backlash and counter-strike mentality that drives sectarianism and terrorism alike.

There are many serious questions here, and hard lessons to be learned. I hope everyone is open to them. The future is full of uncertainty and we need to be strong and determined to prevent terrorism and anti-social behaviour gaining ground. We have to be proactive and smart about it, not reactive and emotional. We need to address the cause of exclusion and dysfunction in this society and give the victims of this a voice to express themselves in a reasonable and rational manner. Otherwise they will find other ways to crash the party and express themselves in a dysfuntional way.

What is certain about the future, is that the 2010 Queen's day will be very different, perhaps more secure and less relaxed than previous years. The end of a dream, a childlike naivity and an optimistic but distorted perception of liberal NL. This may be a sad thing to propose but it is a more realistic approach, a practical sign of our times and the price we pay for the defense of civilisation, eternal vigilance.

Friday, April 17, 2009

Four Tele-commuting Security Mistakes


  1. Careless use of Wi-Fi and accessing unsecured open networks
  2. Letting family and friends use work-issued devices and attaching unauthorised peripherals
  3. Altering or deleting security settings to view Web sites that have been blocked by the company
  4. Leaving a work-issued device in an unsecured place or public location
Security is a good mind-set to adopt

For more information and assistance, speak to your IT Helpdesk and Security personnel . They have a range of proven and tested (approved) tools, which are closely aligned with simple operating procedures and guidelines to help you reduce the potential impact of threats and vulnerabilities. The effective use and implementation of these, is up to you.

Remember to check with the security guys regularly. There is always something new going on in their world that will directly affect your business world.

If in doubt give the Security doctor a shout!

As with most things, it is always easier to find security issues and threats before they escalate into a crisis. A mild infection can be treated quickly and effectively if brought to their attention early but, if left untreated, there is always the risk of cross-infection to other members of staff, with the potential loss of a limb or vital organ.

In your business world, it is your server, applications and your data that keeps you alive! You don't want to lose any of these or even break the arterial chain that holds them together.

3 Security Flaws in Google Docs?

Security Analysts find 3 Flaws in Google Docs!

1) One of the flaws allows images to be accessible even if a document has been deleted
2) The second problem allows users to see all versions of an image that's been modified
3) A third problem is perhaps the most serious of all; It appears to allow people who once had access to someone's Google Docs to still get access even if access rights have been changed. Details of this one have not been released yet.

Click on the dragon for more details

Thursday, February 26, 2009

SWOT Analysis

SWOT Analysis is a well-known method for describing a business or business propositions in terms of those factors that can have the maximum impact. The business owner does this analysis in order to improve the current position of the business. The Strengths and Weaknesses of the business are considered to be the internal aspects of a business, such as the quality of the product or the managerial skills. Whereas the Opportunities and Threats are the external factors, like the development of a completely new market or the arrival of new competitors.

The strengths and weaknesses of a business can be found in the following:

Management sector: The over dependence of an employee on a manager or an owner is one of the major weaknesses in a business that often leads to the requirement of more managers. This area needs to be worked upon in order to reduce the expense of the organization and to improve the business.

The work force: The difficulty in finding skilled staff as well as the employee turnover has to be handled efficiently to help a business grow successfully.

Sales: The strength of sales, how dependent your sales are on external factors, and cyclical sales are some of the factors that affect the business.

Financial: The factors affecting the financial condition of your business determine its strengths and weaknesses. The major aspects related to finance are the flow of cash, time to collect on invoices, and the ease of obtaining loans.

Operations: Strengths and weaknesses are also determined by the internal efficiency as well as the speed of manufacture and delivery of goods.

Opportunities and threats are found in the following categories:

Threats posed by the new rivals in the market: A new entrant in the market, selling a similar product or service, is considered to be one of the greatest threats, as you might not have a patent that could put a brake on new competitors.

Bargaining power of suppliers: Suppliers can pose a major threat for the business as they might force you to take large deliveries. Many times they are also difficult to find, or the supply may not be available.

Customer influence: There are some businesses that rely on a handful of customers, which include a lot of late payers. In addition, many customers bargain for lower prices. In such cases, the business tends to either face the threat of loss of customers or of being unprofitable.

Substitution: People often get bored using a particular brand of product and tend to opt for a change. The market usually has a number of similar products of similar quality. So the major threat is that people might try a product other than yours, and eventually end up substituting your product with it.

You can use two methods to grade these strengths, weaknesses, opportunities or threats, namely, pictorial and numerical.

If you opt for the pictorial way, you need to first create four sectors on a writing pad, putting the titles Strengths, Weaknesses, Opportunities and Threats in each sector, and a large question mark in the center. Now place each of the SWOTs in each sector, with the most problematic factors being farthest away from the question mark, and the better factors closer to it. The closer the display is bunched towards the center of the grid, the better the shape of your business.

However, if you pick the numerical method of assessment, you need to rate each item from 1 to 5 according to how important each is to your business. In this rating, 5 is considered to be the most important. Besides, each factor should also be rated from A to E according to its impact on the business, where E would indicate the highest impact. Then, check how many Es and 5s you end up with. If there are bad factors then you need to change or work on them. And, if there are strengths and opportunities, then it is important to build upon those factors. This would help to boost your business.