Menu

Showing posts with label Software. Show all posts
Showing posts with label Software. Show all posts

SpyWare24



Prevent hackers from spying and accessing your actions on a computer. Most Anti Virus programs out there try to find specific elements in spy programs to identify them. The problem is, there are millions of viruses and spy programs out there. By finding common features of these spy programs and viruses, we're able to detect the vast majority of them. We have designed it so it knows where to look, and what to do. Nitrous Anti Spy has the ability to tell you every dynamic link library, system task, and thread process currently active on your machine, showing the file location of the active program. Along with this, it has the ability to stop the current process.

Nitrous Anti Spy also comes along with a port scanner and a firewall. These utilities locate open ports on your machine, as well as monitor other commonly used ports. NAS has a database of ports used by hackers and the common Trojan spy programs out there. Nitrous Anti Spy also can show you what files load on startup, as well as a built-in registry editor.

Nitrous Anti Spy comes along with all these advanced features, but do you want to know the best part? Nitrous Anti Spy does not conflict with other Anti Virus programs. Use them as you normally do, and run NAS on the side. NAS is designed to allow a user to scan a file that he has downloaded or found that he is not familiar with. NAS does not auto scan any file opened; NAS does not load on startup and does not make any changes to your INI files or Registry. Nitrous Anti Spy does nothing secret. You, the user, have full control of this program. Nitrous Anti Spy also can update its virus databases, as well as check for new program updates.
 

Here is a more in-depth description of Nitrous Anti Spy's Features:


Easy to use interface:



  • Easy way to select what type of scans (deep search or standard).
  • Easy Setup - Simple installer and fully customizable scan list.
  • Able to add specific files, one at a time, or directory at a time.
  • Able to remove certain files that the user does not wish to scan.
  • Able to add recommended files, or all files.
  • Displays how many files are in the scan list.
  • Displays how many infected files are found.
  • Displays how big each file being scanned is.
  • Displays the progress of each file, as well as the overall scan progress.
  • Able to delete, mark read, mark read-write access to files.



Special Added Features:



  • Includes an Internet Firewall/Port Monitor.
  • Includes a Registry Scanner.
  • Includes a Startup file scanner.
  • Includes a Port Scanner on your local machine.



System Task Monitor:


Monitors all programs running, giving the file location.
Displays ALL program windows and DLL Threads in use by the Windows OS.

Ability to scan the selected program.


System INI Scans:


Ability to scan your INI files that are used during bootup.
Ability to clean the INI files if they contain an infected file.


Virus Database view and Information:


Displays a certain number of viruses/Trojans detected.
Displays information about certain keywords used in virus detection.


Upgraded Features:


Scan Code for Standard Search has been upgraded to 3x faster than the original.
Deep Search can now stop during the file in progress.
Detailed File Progress window.
Easier to use interface.
Professional Update feature, including BUILD checking to ensure the latest EXE version.
New database code.
More added definitions as well as modified old ones.


Other Important Information:


Runs on Windows 95, 98, ME. (Untested for Windows NT/2000)
Gives the user full control of the program.
Easy to use interfaces.
Ability to exit a directory scan faster than the previous version.
Ability to update its virus databases, as well as the EXE itself.
Simple, quick, and professional Setup.

Spyware Removal



Spyware Removal is a web site that design to give you relevant information, and methods on how to block spyware.

It will also give you information relevant to security and malware.

Spyware also pronounces spyware is a piece of software that design to spy and steal information from an infected device.

The spying methods of spyware can be recording keystroke to steal private password and other sensitive information.

Spyware Removal


Spyware can also be used to track your online activity for statistics and to recommend you on sites that are like the one you using.
It can also use to force you with unwanted home page and an unwanted popup that may cause your system to be slow.

Know that: unwanted popup may include sexual and pills materials.

Another type of spyware can be a Trojan that may install on your system and do all kind of stuff to your system.

Like open a backdoor, download more malware into your computer and so on.

The best way to fight spyware is to install antivirus software, anti-malware software and run them on a regular basis.

Keep them update with new file definition.

I also recommended using some tools that not required installation, more about it in this article.


Malware worth money:

Another aspect that needs to be taken into consideration in related to spyware is that there is a lot of money involved in this field.

The stolen information can be sold for a high price to someone that needs it and know how to use it.

Think what a database of 1 million users with emails, phone number and address can do for a company that sends spam messages.

To prevent infection and to be able to use spyware removal tools you have to be a security-aware user.

We all read or hear on the news about hacker hacking into organization stealing sensitive data, most of the time that data can be related to us, a user that uses the hack site.


Spyware removal as the human virus:

Like in real life, when we have a virus we need to take medicine to be cure from that virus. Like in real life. We can immune our self for some of the viruses, by getting a vaccine on a regular basis. Preventing, not 100%, the infection of that virus. Most of the time, if the vaccine is good and we do get ill by that virus, it is much easier for our body to fight that virus and the illness can be easy for us.

Also for spyware, we can use some tools that we can install on our system. We can also make a non-install spyware removal arsenal tools that we can use on a regular basis.

Let me give you a tip, and that is probably the best tip that you can get in related to the malware in general and spyware, in particular, think before acting, let me explain to you why.


Think before act:

First, you need to understand spyware like any other type of malware is a file, a file that when it runs it starts doing something that can be flag as problematic if no one runs this file it can’t harm your system.

Spyware can be attached to another legit file. For example, you can download the game from some ware and spyware can be attached to one of the executable game files.  Once this file runs the spyware will also start running and start doing what it designs to do – infecting your system.

Spyware can be hiding in images, in URL and can be sent over by emails and social network.

So to think before act means when you thinking to press on an image that was sent to you look if the image is a link.

Right-click it and copy the link. Check in google if that link is a legit site, a document or a malicious site that may install spyware into your system.


Antivirus software:

Antivirus software, using some sort of algorithm to try and identify if the file is legit, a type of malware or Potentially Unwanted Program (PUP), there are 2 main scanning methods that antivirus using.


Database signature:

The first is against a database that contains the signature of files known as malware. Every antivirus vendor holds a signature of files that represent malware. Then they classifying them into a signature. Using this method it can flag a new variant of know malware as malware.

In the old days, you used to generate a signature for the file. Then the antivirus scanner just compares the current scanning file against signatures in its database. If it gets a match it flags the file as malware.

Due to the fact that every bit of change to the file changes its signature, this technique was less officiant.

So, the classification method was created. In this method, the created signatures are from parts in the file. Most of the malware share common code between more than one type of malware. It also true to a new variant of the same malware.


Heuristic scanning:

The easiest way to understand heuristic scanning is to think about a list of common function to all malware. Then give each function a number that represents its danger level. Now when scanning a file, if the score it gets is more than a selected number flag it as malware.

A basic example will say that if the file is using a file packer we can rise to the score. If the file tries to copy itself to another file, we can also raise the score.

file packer is common in malware, as they encrypt the real file.

The big disadvantage that the heuristic method has is a false positive. Means we flag files as malware even if they were not malware. Modern antiviruses are managed to reduce it to zero false positives nowadays.


Antimalware software:

It started as a sidekick tool to Antivirus, with the changes in the security terms, and the new variants of viruses or alike, a new term create malware, the general term that under it contain viruses, Trojan, spyware, rootkit, adware and more.

Antimalware supposed to be a full security tool. Due to its name, it needs to find and remove all types of malware. Including Trojans, viruses, spyware, adware, worms, rootkits, phishing, etc.

With that in mind today antivirus and antimalware scan, find and remove all types of malware. You are covered by both of them. The cool thing is that they can live together on the same device.

If you ask me, use both.

This is like getting another opinion about your problem. Let them both scan your system in trying to find malware that can hard your system

Arsenal tools to have:

We need some tools in the out arsenal to fight spyware and other types of malware. To start with we need to understand what we have out there.

We have to types of tools, we have free tools that give you basic features and paid tools that can give you some additional features.

There is some free antivirus that you can download from the internet. These tools will give you the option to scan files, delete infected files, free updates, and real-time monitoring to catch virus as they come in.

Same goes to anti-malware tools. There are free that you can download, and install, most of the free version does not include real-time protection in them.

Other than Antivirus and Antimalware there are some other tools that you need to know about. They are tools that do not require installation and can be run on demand. You can download them from the internet and use them.

Put them on a USB disk, an example, to check other computers that you have and run them from the USB device.

Mobile devices:

With the rise of mobile devices like tablets and smartphones it was just a matter of time till we can find malware to mobile devices.

They are here for quite a long time and they are here to stay. As today everyone uses its device for a lot of task from payments, banks, social account and more.

The devices are getting stronger from the hardware perspective and use in a home network and connected to other devices, like your home PC.

A mobile device is another option to malware writer to spread the malicious code, in mobile devices they can steal sensitive information, spread to other devices, use it to enter block locations and more.

Today we look on vulnerabilities as options to use for spreading malware and hacking into devices. Mobile devices have a lot of tools and games that still need to be investigated. This is probably the next step in security.

Today, you can download free antivirus for your mobile device. You should do it if you haven’t done it yet. It is important to make your device as secure as possible. There is a lot of private information on phone devices.

The same role applies here as in your local PC, awareness, and thinking. We all use our mobile for email, social and other online activities, we need to think before we do.

Emails:

Emails are one of the most used methods to spreads spyware and other types of malware. It can be useful to target organizations by sending email to list of users in that organization. If one of the users will press the link in the email the entire organization can be infected.

Using that the attacker can gain access into sensitive organization data, like customers, user data central database and so on.

One of the stronger security methods that are in use and include machine learning technique is the email spammer.

That base on all kind of parameters can flag emails as spam. Automatically delete them or send them into the spam/junk folder in your email.

Facebook:

We all know Facebook the bigger social network. This social network knows a lot of information about people, due to the fact that people share all their life in that network.

The thing before the act is real relevance to Facebook. You have to remember that everything you send online stays online, and can be used to identify you.

In Facebook, you need to verify that you apply all the security option that you have to make your account safe from hackers, and spammers.

they can use your account to spam your wall and friends and to spread malware.

You also need to be aware that pressing on images in Facebook can lead to a phishing site that can be used to hack your account. No, I do not say that you should not press on images or links. Just think before you press.


Ask yourself:


Do you know the user that sent you the link?

How many users press this link?


If you move your mouse on the link see what is the target site it is pointing.

LinkedIn, Twitter, Instagram, and other social networks:
What true for Facebook is true for other social networks. Images may contain phishing links and links may be phishing.

The best way is to check the link before you click on it.

There are a lot of shorten URL services, that let you take a long URL and make it short.

A lot of users post short URL to save characters, so do phishing URLs.

If you were unsure about a URL you can use an un-short URL service to see what the real site is. Most of the services are free to use and you can find them on the internet with a small search.

As an example, I found out that some of the links lead to sexual content.


File downloading:

File downloading is something that we do on a daily basis. Actually, when we go into a website, we are downloading HTML, CSS and JavaScript files that represent the site we are in.

An antivirus with real-time monitoring should check each file we download to see if it contains malicious code.

In case of downloading a compressed file (like zip, rar, etc.) I will recommend you to let your antivirus scan the file and the files inside it to verify that it does not contain some sort of spyware.

P2P networks like torrents:

I am not going to write a lot about it. Just make sure your antivirus software is installed and up to date. That will ensure that you are covered in the case of malware. It will give you more protection against spyware or other malware in the downloaded file.

Make sure the P2P software you are using is updated to the latest version. The latest version supposed to be included with the last fix and patches.

Public WiFi environment – your loved coffee shop:

Today we have free WIFI almost everywhere. We all like to connect our laptop, table, and smartphone to that free WIFI. We need to remember that public networks can be used by everyone.

What if some of the users that use it are hackers. What if he uses a sniffing tool to catch passwords over the network. My recommendations are to reduce the use of the public network to enter the sensitive account, like your bank account.

Data backup:

To close all this long article, I would like to mention backup. Yes, we all know about it, and if we lose our data once we start doing it!

Backup is important to do as part of our weekly task. We all take a ton of pictures, write articles and another thing that we need to backup in case something happens. Keep in mind that even after using spyware removal it may be too late if your files were changed by the spyware.

In the case of mobile devices. You can configure automatic backup to one of the cloud services. The imported thing is that we make another copy of our data.

Online backup can use one of the cloud services. Starting with the free account and depending on your needs pay for more. It can also be used from your local computer. Using a tool that can sync and upload files that had been changed. You can also upload the files manually from time to time.

Offline backup is using an external device like a USB hard drive. Copy the data to that hard drive, you can also find a tool to automate the process of this process. Keep in mine. You will also have to transfer your file from your mobile device into the external hard disk.

In general, it is highly recommended to make a backup of your data. In a case of a problem like spyware other malware or even an electrical fault, your data may be damaged or deleted. With a regular data backup process, you can save your data! Keep that in mine.

Conclusion:

As a conclusion to this article;

I would like to mention that there are spyware, malware and other malicious that may harm your device. Using some of the free tools, like antivirus and antimalware to protect your system is a must.

But always be aware as awareness of what you are pressing on, installing and using it up to you.

Hope you enjoy the article and other articles on our spyware removal website.

Please share with us all your thought, recommendations and comments.

If you like it or it helps you please share it with your friend on your social network.

Spector Pro spyware


1. Will Spector Pro work on my PC?


Yes, as long as you are running Windows XP, Windows Me, Windows 98, Window 2000 or Windows NT 4 or above and have a Pentium-based CPU running at 150 MHz or faster.

(NOTE: Spector 2.x supports Windows 95 - for more information. click here)

2. How much memory is appropriate for Spector Pro?


Spector Pro will run with 32M of memory, but we suggest 64M of memory or more for optimal performance.

3. How much disk space does Spector Pro take?


This depends on many factors, such as how frequently you set Spector Pro to save your screen snapshots, whether you save in full color or 4-bit grayscale. It also depends on how heavily you use your PC.

4. How does Spector Pro protect my child from Internet pedophiles?


It provides a great deterrent and allows you to be aware that such activity has been attempted.

One of the biggest deterrents to pedophiles is getting caught. If a pedophile has an online conversation with your child, Spector Pro will record that conversation.

Further, if a pedophile suspects that he/she is being recorded, they will quickly move on to another target. As more and more people use Spector Pro, pedophiles will begin to notice, and most likely stop going after children, at least on the Internet.

5. Is Spector Pro like the Internet filtering programs?


No. We at SpectorSoft do not believe that filters are very effective. They too often don't catch the web sites you want to stay away from, and they often prevent you from visiting completely legitimate sites.

When people know they may be watched, they are much more careful about what they do.

6. Can I use Spector Pro and an Internet filtering program at the same time?


Yes.

7. Will Spector Pro work with my other PC applications besides the Internet?


Yes. Spector Pro records PC activity for all of your applications, including word processors, spreadsheets, financial programs, databases, communications, and even games. If you are concerned about how much time your employees are spending playing games at work, you'll be able to see exactly how they are spending their time with Spector Pro.

8. Am I allowed to install this software on somebody else's computer?


You may only install Spector Pro, Spector or eBlaster on a computer that you own.

Before you install the software, you must agree to use it only on a computer you own.

9. Can I use the information recorded with Spector as evidence in a court of law?


SpectorSoft cannot guarantee that you will be able to use the recordings in a court of law. A judge determines the admissibility of evidence on a case by case basis.

10. Should I inform my employees or others that they are being monitored?


Yes.

11. But, if I tell them, I'm afraid they will try to circumvent the software.


That is why Spector Pro has a super Stealth feature.

When installed in Stealth mode, Spector Pro does not show up as an icon, does not appear in the Windows system tray, does not appear in Windows Programs, does not show up in the Windows task list, cannot be uninstalled without the Spector Pro password which YOU specify, and Spector Pro does not slow down the operation of the computer it is recording.


12. Does Spector Pro come with a money-back guarantee?


If Spector Pro does not perform as advertised, please notify us within 72 hours of purchase. Assuming you have notified us within 72 hours of purchase, if we are unable to resolve the issue within 3 days of your notifying us, we will refund your purchase price in FULL.

13. How easy is Spector Pro to install and use?


We have designed Spector Pro to be very easy to install and use. Installation should take less than two minutes. After that, you click on the Record button to start recording PC and Internet activity and a Playback button to review recorded activity. If you want to get more sophisticated, Spector Pro makes that easy too with simple menus and online help.

14. I would like to purchase and download Spector Pro on the computer I am currently using, but install it on another computer. Is this possible?


Yes, as long as the other computer is owned by you. Please do not install Spector Pro on a computer you do not own, as you may violate state or local law by monitoring the activities of property that does not belong to you.

When your purchase is complete you will be given a download link and serial number. This will allow you to download and install Spector Pro from any computer connected to the internet. Alternatively, you can save the Spector Pro installation file to a CD-R and then use the CD to install on another computer.

Please note that the software license for Spector Pro allows for one installation per purchase. If you would like to install Spector Pro on more than one computer, you may click here to add licenses anytime or call our office toll-free at (888) 598-2788 during operating hours and ask for multiple license pricing.

15. What is the difference between Spector Pro and eBlaster? Which product is right for me?


Let's assume that you are a parent who wants to monitor the Internet activity of your children and that you will be installed on the computer your children use.

If you have access to this computer frequently, and can check the computer for a few minutes once or twice a day to see what your children have been doing online, then Spector Pro is probably the more appropriate product for you because it will be able to SHOW you in EXACT detail what they have been doing. (E-mails, chat conversations, instant messages, web sites visited, keystrokes typed, applications launched -- additionally, Spector Pro will continuously take snapshots of what is on the computer screen and allowing you to play back these snapshots at your convenience.)

 you want to see basic reports of the web sites they are visiting and transcripts of their chat sessions, then eBlaster is likely the more appropriate product for you.

That is because eBlaster records chat conversations, keystrokes typed and the names of web sites visited and can notify you via e-mail as frequently as every 30 minutes. So, if you are at work for many hours a day while your children are home from school using the Internet, then you can automatically be notified via e-mail what they are doing.

Many of our customers choose to get BOTH Spector Pro and eBlaster because they want the convenience of the detailed screen snapshots that Spector Pro provides.

For a detailed comparison chart of all SpectorSoft Products and their Features, click here.

16. I know Spector Pro works for a dial-up connection. I have a cable modem. Will Spector Pro still work?


Yes. Spector Pro works independently of how you connect to the Internet. Whether your connection is with AOL, via modem dial-up, using a cable modem or DSL, or simply using a proxy server or local area network connection, Spector Pro is guaranteed to work.

17. How soon can I get Spector Pro?


Spector Pro is available now for immediate electronic download.

Using our secure server, you can purchase, download, install and begin using Spector Pro in less than 10 minutes, even if you download using a 28K modem!


DNS Made Easy Suffers from DDOS Attack



DNS has restored services and mended customer relationship since being a victim to a denial of service attack at a 50Gbps.

It still remains unclear who the hacking culprits are and for what reason they interfered with DNS Made Easy’s System.  One forecasted reason is that hackers with a possible grudge with the DNS Made Easy Website may have hired a botnet to flood DNS Made Easy with endless and worthless traffic.

Lasting up to eight hours, the company said that 1.5 hours of actual downtime was experienced at the time of the attack.

Just after the first sign of attack carriers such as Level3, Tata, Tinet, GlobalCrossing, and Deutsche Telekom supported DNS Made Easy to block the hackers.  The size of the attack was so large that it immediately infested the core of the network with junky traffic.

DNS Made Easy is known for its specialization in global IP Anycast enterprise DNS services thus it would not be expected that such an attack would be pointed towards the company.  Many network security companies including The SANS Institute’s Internet Storm Center are eager to learn more about this attack and its cause.

According to a study done by DDoS mitigation experts, the most forceful attacks recorded in 2009 hit 49Gbps.  Experts stated that the most common attacks ranging from 1-4 Gbps.

New Ultra DDI Offered by Neustar


Neustar Inc. announced a new way to easily integrate internal DNS, DHCP, and IPAM (IP Address Management) operations.

The new service called Neustar Ultra DDI (DNS, DHCP, IPAM) managed service consists of networking equipment using Infoblox appliances in addition to issue resolution, hardware lifecycle replenishment, software updates and equipment replacements. Neustar gurus conduct 24/7 monitoring and upgrading of backend DNS and DHCP operations while viewing approximately fifty health and usage parameters for proactive infrastructure management and case response. Neustar also keeps a database of important DNS and DHCP data points to allow trending and preparing for future growth and governance.

“Neustar exists to simplify network complexity,” said Alex Berry, senior VP of Neustar’s Internet Infrastructure Services (IIS) group. “DNS and DHCP are the linchpins for unifying networks and enhancing communications and it is becoming increasingly time- and labor-intensive for our customers to juggle multi-vendor management and network troubleshooting on their own. More customers are realizing that it simply makes good business sense to trust Neustar. We have built a sterling reputation in delivering and managing the core services underlying IP network infrastructures.”

Developing on the growth of Neustar’s December 2009 announcement, in which a strategic alliance with Infoblox was announced, the Ultra DDI solution delivers top DNS, DHCP and IP Address Management (IPAM) solutions to enterprise, public sector and service provider industries. With Ultra DDI, clients are enabled to use Neustar’s deep expertise in managed DNS services via Infoblox’s appliance-based systems allowing for high performance, reliability, and security as well as a significant decrease in operating costs.

“Infoblox and Neustar are rightfully regarded as leaders in their respective markets – and the collaboration between our two companies has resulted in an unparalleled service combination,” added Kevin Dickson, VP of Product Management at Infoblox. “We are excited that our relationship continues to mature, and this launch marks the next point of that evolution.”

Prevent Man-In-The-Middle (MITM) Attacks with DNSSEC

New Jersey-based Comodo has now taken over Portland-based DNS.com, a provider of domain names and internet security services. Dan Kimball, the CEO of DNS.com will now work with Comodo after the transition takes place.  The financial terms of the acquisition will not be revealed. 
 DNS is a provider of secure domain name system services to other businesses and Comodo is a security tools provider for the enterprise market.

Prevent Man-In-The-Middle (MITM) Attacks with DNSSEC



The DNS query load for VeriSign was around 62 billion every day on average for the 2nd quarter of 2010. This was a sixteen percent hike from the 1st quarter this year. Annually, the daily average saw an increase of twenty-eight percent.
With all this growth there has been great industry progress in implementing DNSSEC (Domain Name System Security Extensions). DNSSEC is a suite of Internet Engineering Task Force details for verifying particular sorts of data given by the DNS as utilized on IP systems. It is a lot of augmentations to DNS which give to DNS customers starting point confirmation of DNS information, validated disavowal of presence, and information trustworthiness, but not availability or confidentiality and therefore helps protect users against DNS cache and Man-In-The-Middle (MITM) attacks.
 In July 2010, Verisign joined with the United States Department of Commerce and the Internet Corporation for Assigned Names and Numbers (also known as ICANN) to assist the deployment of DNSSEC at the roots of the domain name system.
Forrester Research conducted a new study for VeriSign that showed how timely the implementation of DNSSEC is.  ‘DNSSEC Ready for Prime Time’ was based on the polling of approximately 300 IT decision makers and identified that DNS attacks are very common and has made DNS security a top priority for all businesses and organizations. Forrester also found 51% of all respondents experienced DNS related attacks such as ‘man in the middle’ attacks.
A problem that the Forrester study identified was the lack of awareness many IT decision makers had regarding DNSSEC. Only 43 percent of study respondents knew about DNSSEC and the issues it could provide solutions for. However, of the respondents that were aware of DNSSEC, 90% said they would implement the technology within 1.5 years.

Equinox Expands Solutions for Customers in the Middle East with Infoblox Network Infrastructure Solutions

(PRWeb) Equinox International, a leading technology provider in the Middle East with a complete portfolio of solutions to meet the mission-critical objectives of enterprises and service providers, today announced it has expanded its portfolio to include Infoblox DNS, DHCP, and IP address management (DDI) solutions. Through terms of the recently expanded agreement, Equinox is authorized to distribute all Infoblox DDI and NCCM solutions in Egypt and serve as a reseller in the Middle East region.

This expansion builds upon the success Equinox has already achieved selling in Egypt and the Middle East Infoblox’s network configuration and change management (NCCM) solution: the Infoblox NetMRI product, which was recently added to the Infoblox solution set when Infoblox acquired Netcordia in May 2010.

Equinox’s solutions allow clients to manage their networks smarter, decrease the total cost of ownership and increase the availability and robustness of their infrastructures. Further, Equinox delivers consistently high levels of customer service to its 40 plus clients throughout the Middle East and North Africa (MENA) region. Working closely with key partners such as Cisco, NetScout, and Infoblox, allows Equinox International to offer an unrivaled level of expertise and experience in the multifaceted industry of IT.

Infoblox network infrastructure automation solutions, which include the Company’s NCCM and DDI product lines, among others, provide the foundation for next-generation networks by automating many manual and often-error prone tasks while boosting resiliency and network visibility.

“Infoblox is excited to announce its expanded agreement with Equinox in the Middle East, one of the strongest and respected IT companies in the region,” said Dirk Marichal, Infoblox Vice President of Sales in the EMEA and the Middle East. “Equinox has been successful bringing the NetMRI solution to this market and the synergistic value proposition of Infoblox’s NCCM and DDI solutions – both eliminate many manual and often error-prone network tasks with advanced automation and management tools – make this a natural complement for customers.”

“We have seen an increasing demand for highly resilient, manageable and scalable DDI solutions over the past couple of months”, said Mr. Samer Haqoun, Equinox’s Chief Technical Officer. “When Infoblox acquired Netcordia, bringing together two very strong technologies and corporate entities, we knew this would be the best combination to help meet the rising demand and we can confidently deliver the standard of quality solutions our customers expect.”

Infoblox Network Infrastructure Automation Solutions

With unparalleled reliability, scalability and security, Infoblox solutions help organizations deliver essential network services, such as domain name resolution (DNS), IP address assignment and management (DHCP/IPAM), network change and configuration management (NCCM), among others.
In addition to reliable delivery of these network services, Infoblox offers unparalleled manageability of the services and associated data (i.e. DNS records, associated MAC addresses, etc.) with its “single-pane-of-glass” graphical user interface that provides visibility into essential information for tracking IP devices, users and network assets.
Infoblox solutions, which leverage Infoblox Grid™ technology – a unique real-time data distribution technology – and the “single-pane-of-glass” GUI, are essential to the daily operation of many enterprise IP-based networks.

BlueCat Networks Opens New HQ in Amsterdam in Response to Rapid Advances and Demand for IPAM, DNS, and DHCP Solutions



 BlueCat Networks recently announced that in response to the rapidly growing demands of IPAM, DNS, and DHCP solutions in Europe, it has opened a new headquarter location in Amsterdam, Netherlands.

The office in Amsterdam is responsible for being a mediator between BlueCat Networks European channel partners and distributors as well as resellers to ensure that BlueCat Networks market share will increase further.

The new office is located at Johannes Verhulststraat 156A, 1071NP Amsterdam and the contact number is +31 20 754 64 85.

The former Manager for EMEA and APAC at Tipping Point, Paul Couturier is the new Vice President for the Amsterdam startup.  He has over 20 years of international IT sales and management experience and is fluent in English, French, Dutch, Italian, and German.  He has proven his capabilities with past companies such as Siemens, HP, and 3Com and is well equipped with qualifications to run the European segment of BlueCat Networks.

“Despite the global recession, worldwide demand for BlueCat’s IPAM and DNS/DHCP solutions continues to grow rapidly, and the new Amsterdam office is a direct result of BlueCat’s expansion in Europe,” said Paul Couturier, Vice President, Europe for BlueCat Networks. “One of several new BlueCat offices opening worldwide in 2010, the Amsterdam headquarters will lead BlueCat’s aggressive marketing activities in Europe,” Couturier continued. “This office will provide all the local support and knowledge our growing number of European channel partners require to ensure they can easily access the resources and training they need to grow their customer base and maximize sales.”


DHCP based IP Address Management Solution Extends Policy Management at Alepo


(TCPIPWorld.com) Alepo Technologies Inc. focuses on BSS/OSS solutions for next-generation services and it has just launched a comprehensive policy management solution with a DHCP-based IP address, which is designed particularly for service providers.  The new IP Address Management (IPAM) solution is developed to flawlessly integrate with other network elements offering centralized and complete policy management solution.

Overtime as the 4G technologies develop towards complete IP-based networks it is undeniable that a centralized policy solution is becoming more in demand.  Aleppo's IPAM solution is the first of its kind and features a built-in AAA client, allowing service providers to directly manage IP address policies through a centralized system.

The new IPAM solutions are flexible because it is built on an SOA-based platform and thus is available to all network elements via web service API’s.  This allows service providers to easily integrate it with their existing systems while emerging into the new technologies at the same time.

Brandon Johnson, Director of Operations at Aleppo said, “In the evolving 4G network environment, we’ve seen a clear demand for more advanced features from a policy management solution.”  He believes that including Aleppo's new solution to existing infrastructure will amplify and streamline the aptitude of the policy management solution.

As today’s business customers increasingly use internet communications in a sophisticated way, the need to set up virtual private networks (VPNs), web hosting and email servers increase also.  By offering IPAM management services as a value-added service, businesses can increase their revenues by enhancing the quality of service.  Residential customers will also benefit from this service because the static IP addresses will ensure better quality for online gaming as well as guarantee consistent quality for VoIP or other web-based services.

Johnson said, that value-added services not only increase customer satisfaction but they will also increase the average revenue per user.  Both businesses and residential customers will now have a safe and secure online experience due to the static IP addresses and overall the experience will be more personalized.

Border Gateway Protocol


Border Gateway Protocol:


Border Gateway Protocol is generally used when routing a very large interior network, binding multiple interior networks together or for interdomain routing across the Internet because of its robustness and scalability. Because of the size and importance of the networks generally interconnected with BGP securing the protocol from attacks is always a good idea. There are many ways of securing BGP on many different platforms. Because of the popularity of Cisco routers on the Internet, I will be using their command line for any configuration examples.


Port filtering: 


Since BGP peers communicate over TCP port 179 its always a good idea to filter communications over this port to your trusted peer addresses only over the interfaces they will be communicating across. The filtering can be done on a firewall or perimeter router.
Authenticating peers: One of the most basic forms of security with BGP is peer authentication. You can simply configure an MD5 key in your neighbor statement causing each segment sent on the TCP connection between the two peers to be verified.

        Example:
        router bgp 510
        neighbor 132.45.78.3 remote-as 320
        neighbor 132.45.78.3 password SecureMyBGP123

Hard code the BGP version: 


The most common version of BGP running today is BGP version 4, however by default BGP will negotiate BGP version with their peer. If you are already sure that the router(s) you will be peering with will be running BGP version 4 it's easy to set this option with a neighbor statement and it can save some network recovery time if your router did fall under attack.

        Example:
        router bgp 510
        neighbor 132.45.78.3 remote-as 320
        neighbor 132.45.78.3 password SecureMyBGP123
        neighbor 132.45.78.3 version 4

   

Route filtering: 


With the size of Internet routing tables it's particularly important to make use of route filtering on BGP speaking routers. Incoming routes on external BGP speaking routers are the most important but it can also be important to filter incoming routes on your internal BGP networks as well as outgoing routes on both. This can control the spread of any routing anomalies from one network to another. With BGP you can make use of both the distribute-list or prefix-list in your neighbor statement but not both for the same peer. You can also make use of both access control lists or prefix lists although the better alternative as far as CPU usage goes would be the prefix list. In this example, we will create a prefix-list that will only accept routes with a prefix greater than /8 and less than /16 and then apply this to our neighbor as an inbound distribute-list.

        Example:
        router bgp 510
        neighbor 132.45.78.3 remote-as 320
        neighbor 132.45.78.3 password SecureMyBGP123
        neighbor 132.45.78.3 version 4
        neighbor 132.45.78.3 distribute-list netpolicefilter in
        !
        !
        ip prefix-list netpolicefilter seq 10 permit 0.0.0.0/0 ge 8 le 16

Null0 (pit bucket) routes: 


Previously we showed an example of route filtering using neighbor statements and prefix lists but sometimes the same thing can be accomplished with a less CPU intensive process. Null0 routes will drop any traffic matching the route and not having a longer (more specific) match in the routing table into the pit bucket immediately. This process is called "Black Hole Filtering". The example below would ensure that any traffic destined for network 131.50.24.0/24 was sent directly to the pit bucket unless a longer match is found in the routing table.

        Example:
        router bgp 510
        neighbor 132.45.78.3 remote-as 320
        neighbor 132.45.78.3 password SecureMyBGP123
        neighbor 132.45.78.3 version 4
        neighbor 132.45.78.3 distribute-list netpolicefilter in
        !
        !
        ip prefix-list netpolicefilter seq 10 permit 0.0.0.0/0 ge 8 le 16
        !
        !
        ip route 131.50.24.0 255.255.255.0 null 0

Logging neighbor changes: 


Although things like connection, hardware, and bandwidth problems can cause frequent up/down conditions with a BGP peer it could also be a sign of a DoS attack on the network. Changes in BGP neighboring router status can be logged with a simple neighbor command if you have logging setup properly in your router. It's always a good idea to timestamp logs and check them frequently.

        Example:
        router bgp 510
        neighbor 132.45.78.3 remote-as 320
        neighbor 132.45.78.3 password SecureMyBGP123
        neighbor 132.45.78.3 version 4
        neighbor 132.45.78.3 distribute-list netpolicefilter in
        neighbor 132.45.78.3 log-neighbor-changes
        !
        !
        ip prefix-list netpolicefilter seq 10 permit 0.0.0.0/0 ge 8 le 16
        !
        !
        ip route 131.50.24.0 255.255.255.0 null 0

What is a VPN?



The term VPN is very popular in the IT world today and it gets thrown around quite often as a method interconnecting data networks. I'm sure some of you have been sitting in a meeting and heard the phrase "we'll just use a VPN" and had no idea what they were talking about. To be quite frank, is a Network and Security Engineer for many years now I've heard the question "What about using a VPN?" way too often by someone that didn't really didn't even know what it was. If you do know about VPNs then this article is probably not for you. However, if you don't know what a VPN is or know very little about them then I think this article can offer you some insight into the world of Virtual Private Networking.

The most common function of a VPN is to connect multiple private networks securely across an unsecured public network like the Internet. A private network, in this case, would be a network in which the traffic is not freely accessible by the public. If we break down the meaning of Virtual Private Network in the instance explained above it would be as follows. The two endpoints of this "network" are private networks that are seamlessly connected across a public network in which neither private network knows about, creating a "Virtual Private Network" between them.

The VPN came about mostly due to companies expanding their businesses geographically. Expansion across the country and even the world made logistics a nightmare for many companies open to the global market. The need for fast, secure and reliable connectivity to maintain their business needs became greater and greater. Prior to VPN technology, internetwork connectivity had to be maintained by expensive leased lines that generally grew in cost when they grew in distance. Many companies resorted to remote access dial configurations to a central location with 800 numbers that could roll over multiple telephone lines. Of course, the cost to maintain the lines and the charge for the 800 number was also expensive. With the popularity of the Internet growing it was only a matter of time before technologies that could leverage a preexisting worldwide network and build secure network connectivity would emerge.

Since most companies already relied on the Internet for email and web access they generally had a readily available connection at most sites they could use for LAN to LAN (Local Area Network) VPN connectivity. Sometimes the bandwidth (speed) of the connection might have to be upgraded in order to carry the extra data but it would still be less expensive than having to add an extra connection for the company data alone, not to mention the extra expense of the dedicated circuit depending on where it would terminate geographically. In some cases where a remote office was too small to have its own dedicated circuit, they might have used dialup internet for these functions but that's ok, you can build Client to LAN VPNs over those dialup connections as well. These scenarios are becoming more popular and replacing a lot of older technologies like frame-relay that used to power large enterprise network WANs (Wide Area Network).

Security is, of course, a concern when private network traffic is using a public network as a transit medium so generally, VPNs are built between networks using an encrypted VPN tunnel. There are many forms of VPNs that could be classified in the layers of the OSI (Open Systems Interconnection Reference Model) but I won't go that in depth here since that is out of the scope of this beginners document.

In this document, I will classify them into two categories: Encrypted and Non-Encrypted VPNs.

Simple VPN

Graphical Example Of A Simple Encrypted VPN

 Encrypted VPN: An encrypted VPN will secure the traffic that is being sent across an unsecured public network by using various types of encryption mechanisms. IPSec is the most popular form of encrypted VPN tunnel in use today when building a secure VPN tunnel over the Internet.


Non-Encrypted VPN: 

A non-encrypted VPN would mean that either the data flowing across the VPN is not secured at all or is being secured by means other than data encryption. MPLS (Multi-Protocol Label Switching) VPNs use route segregation across a virtual connection between the two private networks to secure the routing of the traffic between only them across the public network. A GRE (Generic Routing Encapsulation) tunnel can be used as well in order to hide a global network from the private endpoints and even encapsulate multiple protocols inside of TCP/IP that normally couldn't be routed over an all IP network. This type of tunnel could actually be encrypted by a higher layer protocol like SSL (Secure Socket Layer) as well.

So we've seen that VPNs can save money by reducing circuit costs between remote offices and headquarters but VPNs can also be used by companies that have recently acquired by another company and the two networks now need to be integrated. This is particularly handy for networks that need to merge quickly or that have great geographic boundaries. Both of these types of networks would be considered an Intranet VPN. What if multiple companies form a partnership and need to share certain valuable network resources with one another? An Extranet VPN could be used in this specific type of situation. Another use for a VPN is to support mobile or home users that need to access network resources away from the office.

With the security, reliability, scalability, and ease of management available in many forms of VPNs today its no wonder their popularity continues to grow. One thing is certain, no matter how many different ways there are to set up a VPN the goal of seamless network connectivity regardless of the geographic location and the quicker return ROI (Return on investment) of the software/equipment versus traditional leased lines remain the same. Hopefully, the next time you're in a position where the term VPN is brought up as a viable solution you will have a little better understanding behind the concept of Virtual Private Networking.

DoS Denial of Service and Access attacks.


DoS (Denial of Service) attacks:


The main purpose of a DoS attack is slow down or disable a system such that the services the system offers become unavailable to its users. These type of attacks are generally caused by exhaustion of the system's resources or by exploiting a known vulnerability (bug) on the system that stops it from functioning in a normal manner. A simple example of this would be sending so much garbage traffic to a system that legitimate traffic could not process similarly to phone lines being tied up from too many telephone calls at once. More complex versions of these attacks are known as DDoS or Distributed Denial of Service attacks where multiple devices launch the attack on the system at the same time.

Access attacks: 

The main purpose of an access attack is to gain access to unauthorized (protected) system resources such as data or to simply take over control of an interior network system to perform the illegal activity. An access attack can often follow a Denial of Service attack but generally attacks of this nature with reconnaissance of some type in order to expose system exploits and exploitable systems. Amazingly enough, the most common threat when considering an access attack is Social Engineering. Social Engineering is the most effective and the hardest access attack to control because it involves the manipulation of people. An example of Social Engineering would be a hacker gaining access to a system by learning a valid username and password from someone through the art of deception.

IE:

Claiming to be someone that one would trust, even though in reality they are not.
Some of the methods discussed previously can be used in order forcefully obtain access to unauthorized data and unfortunately, it could be yours. Fortunately, however, most major networks of the more prominent companies that one might do business with are generally secured from most threats that we've talked about by means of physical equipment security, monitoring, data encryption, and constant updating. Obviously, a threat to these type of systems always exists but is much less likely due to the vast amount of money and time spent by these companies in order to protect their networks and their customer's information. This should make you feel somewhat more comfortable but wait a minute, what about your system? Now, we will talk about some things that you can do in order to protect yourself a little better.

1: Perhaps one of the most important things that you should remember is to never give out any of your personal information to someone unless you have gone through means to verify their identity. This includes your email and any usernames and passwords that could lead to the discovery of your other personal information. As we discussed previously Social Engineering is the leading cause of unauthorized access attacks. Phishing, banding or carding is a very popular form of private information theft. This is when you might receive what appears to be a legitimate email or instant message claiming that you need to "update your account information" or something similar and provides a link to a site to input this data in order to steal it. The link is often masked such that it appears to come from this legitimate source and the site it sends you to also looks legitimate because they've matched the source code to the actual site in question. The best thing to do in this instance is called the customer support number that would come on your real statement. Most major organizations will never ask you this information outside of initial signup. Most companies will have a specific email address that you can forward such scams available on their website. This type of attack can also come via a phone call, so in this case, I would suggest that you disconnect the call and contact the customer support department directly with the phone number listed from a statement to inquire about the situation.

2: Be careful what type of information that you send via email. Where you send it is important but what you send is also important. Email by default is sent with clear text. An experienced hacker that might be sniffing or intercepting traffic to a service provider (man-in-the-middle attack) can easily read anything sent across standard email. There are some methods for encrypting email like Entrust http://www.entrust.com/ (digital certificates) and PGP http://www.pgp.com/ (pretty good privacy) that can be used when properly configured but your best bet is to never send any personal information via email.

3: Make sure you are doing business with a company that you know to be secure. Generally, you won't have problems when dealing with major companies like Wal-Mart or Gap but you should still read their privacy and security policies such that you have a good understanding of the information that they collect and what they do with it, as well as the means that they use to secure their transactions. If a site doesn't have this information readily available then I would not recommend doing business with them. Most private web transactions are secured with SSL or Secure Socket Layer encryption. This is the primary standard for encrypting web transactions and it is approved by the Internet Engineering Task Force. You will know that your connection is secured if you look in the address field of your browser and see https:// in front of the web address. Note: The Sin https which signifies that the session is secured with SSL.

4. Use strong passwords. Typically you will want to use at least 8 characters, use a mix of letters and numbers, do not use complete words, do not use sequential numbers, do not use your username and try not to use any personal information that could be guessed by someone like your birthday.

Here is a link to a Microsoft document on generating strong passwords complete with a link to a page to check your password strength: http://www.microsoft.com/athome/security/privacy/password.mspx

Here is a link to a document on generating strong passwords on the SANS site: http://www.sans.org/rr/whitepapers/authentication/1636.php

Its also never a good idea to store passwords or cache them on your local system. If your system is somehow compromised, then so are your account passwords.

5. If you are using a wireless network, secure it. Wireless networks can be easily sniffed out remotely by "war drivers" or even your neighbor. Change any default settings like the SSID that might be easily guessable. Disable remote administrator to the router and password protect local administration. Use MAC address filtering to only allow your trusted connections to the router. Enable the strongest encryption available on your router. Here is an article I wrote previously on securing a wireless network when using one of the more common Linksys wireless G routers. http://www.computernetworkinghelp.com/content/view/31/2/

6. Use a personal firewall to protect your computer from traffic originating from the outside world. IE: Traffic that you didn't initiate a request to come to you.

7. Use virus software and keep it up to date. Remember, if your virus definitions are old the software is all but useless. Scan your email in real-time (upon download or prior to opening attachments). Scan your drive regularly. It's also a good idea to never open attachments from unknown sources. Virus software relies on matching patterns a virus must exist before an updated pattern can be created so there is always a chance of becoming infected even if your software is up to date.

8. Use spyware removal software and keep it up to date. Remember, if your spyware removal definitions are old the software is all but useless. Scan your drive regularly. Spyware can not only be annoying but also dangerous in some cases.

If you follow the simple steps listed above you will be better protected against identity theft and personal fraud. I hope you've enjoyed the article and learned a thing or two along the way.

Hackers - Is your private information safe?


With the growth of the Internet over the past few years and the Internet shopping boom its no wonder that identity theft statistics have risen to new levels as well. Global Internet usage has grown some 182% from 2000-2005 per Nielsen/NetRatings accumulated worldwide. Between January and December of 2005 alone, more than 685,000 consumer fraud and identity theft complaints were reported to the Federal Trade Commission's Sentinel Complaint Database.

Since the database was launched in 1997 almost 3 million complaints have been registered there. In the 2005 statistics, 37% of those 680,000 complaints were said to be identity theft cases. Some of the more significant identity theft complaints included credit card fraud (26%), phone or utilities fraud (18%), bank fraud (17%), employment fraud (12%), government documents/benefits fraud (9%), and loan fraud coming in at (5%).

As you can clearly see the theft of personal information is a major problem and is getting worse every day. If you are doing business over the Internet the odds increase that you could fall prey to an Internet predator and become a victim of these type of malicious acts. There are, however, some things that you can do to protect yourself from these crimes which we will discuss later in this document but for now, we will discuss the term "hacker" and some of the methods used by these "hackers".


What is a hacker?


In the general media, the term "hacker" describes a person that thrives on performing malicious acts with computer systems in order to gain public popularity with his or her peers. This might be someone that gains access to unauthorized computer systems via their extensive knowledge of their operating systems by means of finding exploits (bugs) in the code and using them to their advantage. Perhaps a person intends to disable computer systems by means of DoS (Denial of Service) attacks such that the resources are no longer available to the users making legitimate requests to the systems. We will discuss these types of attacks later on in this document in more detail.

In reality "hackers" are generally considered the good guys and would be someone that spent a vast amount of time learning about and building computer security systems. The term "cracker" would be what you would use to describe a person that would perform the types of malicious activity that we discussed previously. However, in the rest of this document, we will use the more widely known term of "hacker" as an equivalent of the real term "cracker" to avoid confusion.

One of the most famous network hacking attacks in history was the 1994 attack of Tsutomu Shimomura's computer network by the famous hacker Kevin Mitnick on Christmas day. By using various types of Denial of Service and access attacks on the network Kevin Mitnick was able to gain control of Shimomura's system. This was what you would call a "structured attack" because of the expertise required in order to perform the attack. Another type of "structured attack" that some of you might remember is the February 7-11 2000 attacks where web heavyweights like eBay, Amazon, and CNN among others drastically slowed down and even denied access completely for hours at a time by use of Distributed Denial of Service attacks.

The more common types of attacks are the unstructured kind. Often these attacks start from within a network by a person that has no idea what they've ever done. These type of attacks can also be executed by a "Script-Kiddy". A "Script-Kiddy" is a person that uses pre-made hacking scripts coded by a professional hacker and has little to no real knowledge of what they're doing. Some of these hacking tools require no more than the input of the address of the target host and a push of a button. This threat is very real due to the vast amount of hacking tools (scripts) readily available for download on the web like winnuke, SATAN, NMAP, and Naptha. More complex hacking tools like Trinoo, TFN, TFN2K and Stracheldraht (used in the Feb 2K attacks) can also be found fairly easily but require more in-depth knowledge in order to use effectively.  In order to break these attacks down for simplicity, we can put them in two main categories.

What is the Role of a Data Recovery Company in Salvaging Your Relationship with Your Customers?

In this age, the information age, data is the driving force of many businesses, especially internet-based businesses.  Data is frail as it is subject to lose due to computer viruses,  mechanical failure, back-up failure, physical damage to media storage devices, hard drive crashes, natural disasters, and human error. When these unintended and often unpreventable disasters happen, data is lost and service to your customers is compromised.  Thus, the role of a data recovery company is to salvage your data and to protect your customer relationships from being damaged as a result of lost or damaged data.

Flawed thinking amongst many business owners is that the services of a data recovery company will not be needed if a systematic back-up process is used. Some companies leave it up to individual
computer users to back-up their data on a regular basis.  Some back-up their servers periodically throughout the day, and some use automated back-up services.

While backing up data regularly diminishes the possibility that a data recovery company will be required, dependably think about the reality that even the best back-up frameworks bomb occasionally. Also, if back-ups are kept onsite, rather than offsite, the original data source and the back-ups are subject to lose in case of fires or natural disasters. While numerous entrepreneurs and PC clients know this, it doesn't generally appear to be handy to back-up information frameworks and to store the back-ups offsite.  Indisputably, storing back-ups offsite is a good idea; however, in practice, it rarely happens. More often, companies that experience crashes of data systems end up wishing they had an up-to-date back-up and they end up relying upon a data recovery company to salvage what they can.

One way to resolve the problem of impractical offsite back-up storage is to employ the services of an automated, off-site back-up a company such as backup.com. Such services generally require a
small monthly fee that is very reasonable considering that they totally eliminate the need for onsite back-up media. They enable you to choose important data files that need to be backed up
regularly and to schedule the occur automatically. Moreover, the back-ups are saved to an off-site server so they are secured in a location separate from the original data source.

The main things to consider when selecting an automated,  offsite are cost,  reliability,   accessibility,   and security. Some automated, offsite back-up services encrypt data prior to it being transmitted via the internet to a data storage center to ensure secure transmission.  passwords that authorize your access to the data which is made available through internet access twenty-four hours a day, every day of the year. Immediate, easy access to the backed up data is essential so that you can restore your data files anytime in the event of a catastrophe.

Using an automated, offsite back-up service does diminish the possibility of lost data, but it does not guaranty that the services of a data recovery company will never be needed.  Even
the best and most professional back-up services fail occasionally. For this reason, it is best for you, as a  business an owner,  to  be  forward-looking  and  proactive  by  finding  and
analyzing data recovery service providers and to identify a  data recovery company that will efficiently and effectively meet  your needs for data recovery if your business is so unfortunate as  to
experience a catastrophic event that results in lost  or  damaged data.

Do not wait for strikes to find a data recovery company. In the wake of a disaster, you will not have the time or the drive to effectively evaluate and choose a data recovery company that you can confidently rely upon.   Choosing an automated, off-site back-up service and a data recovery company should be a priority for you regardless of what phase of business planning you are in.

Copyright Christopher J. Enders. Are you at the end of your rope, fed up and confused by all the scrambled internet marketing the advice you're getting? Whether you are new to internet marketing,
or a website owner  who  wants  to  make  more  money  from  your website, learn the proven strategies that  will  sky-rocket  your

E-mail Privacy Mythology




Many people believe that e-mail privacy is inherent and guaranteed, psychologically equating it with the postal system.  E-mail systems were a crucial tool in creating the Internet, and actually, predate the Internet in existence.  While the ability to access your personal e-mail messages is secured with a password, this is insufficient to guarantee legitimate security. There are additional security considerations when using laptops to access e-mail systems.

As more people find the need to transmit sensitive information through the internet, the need for e-mail privacy becomes more apparent.

The e-mail message is perpetually exposed to unauthorized access as it travels along this unprotected Internet from the composer to the reader. If routers between the source and destination of an e-mail message are compromised, potentially any e-mail message passing through that router could be accessed.

Unencrypted e-mails should be regarded as the postcard, in that anyone who receives it can read it. Intelligence agencies screen unencrypted e-mails with ease and conduct these screens regularly.

Some e-mail you may send and receive could be considered company property. It is unwise to associate personal e-mails of any kind with a company address.

When using laptop notebooks to send and receive e-mail, you may often be using someone else’s network. You must be aware if using a wireless network if the network is encrypted. If the network is not properly encrypted any e-mail you send or receive is accessible to any skilled person within the wireless signal range. Even when using secure networks, everything you send and receive is going through their system. It is imperative that one uses TLS encryption when sending mail, and to use a send mail server other than the foreign network. When reading e-mail on someone else’s network, you must make sure your mail server supports SSL and use the encrypted access only.

If you delete an e-mail you must not have the misconception that the existence of the e-mail is gone forever. This is not the case as most electronic documents are backed up and recoverable, and most e-mails are backed up on a remote server at some point in time.

For more information about Laptop Security visit Security4Laptops.com.

Security4Laptops.com is your definitive guide to using mobile devices with the privacy and security necessary in this modern work-a-day on-the-go world.

Article Source: http://EzineArticles.com/?expert=Tom_Pitts

Make Linux recognize your widescreen in VMWare



Because of XFree86, Linux does not support the "autofit guest", or arbitrary resizing option that will snap the VMWare window to the resolution of the guest operating system if you have the VMWare tools installed. This can be a real pain if you're trying to use a widescreen display and you want the window to fill out the screen. In my particular situation, I was using a Toshiba laptop with a 15-inch widescreen display that would display a maximum of 1280x768 at 60 Hertz. The only default resolution that I could get to work through the VMware-config-tools.pl utility was 640x480 without scroll bars. Obviously, this wasn't acceptable so I decided to play with some manual mode line configurations in Linux to get my screen where I wanted it.

The hardware I will be using in this example is a Toshiba Satellite M55-S331 with a 15-inch widescreen display. The software is Windows XP Professional with the Intel Graphics Media Accelerator Driver, VMWare Workstation version 5.5.1 and the guest OS is CentOS 4.3 Final, with VMWare tools installed and working correctly.

NOTE: 

Before we begin to make absolutely sure that you know what you're doing. Monitors can be easily damaged by incorrect driver configurations so USE THESE INSTRUCTIONS AT YOUR OWN RISK!!! Computernetworkinghelp.com is not responsible for any damage that might occur if this article is misused.



Part One: Figuring out the proper mode line configuration.


First things first, we need to find the maximum resolution that our display is capable of running. In this case, based on the hardware and the software installed, it was 1280x768 at 60 Hz.

Next, we need a mode line calculator to figure out a setting to start out with, I use the XFree86 calculator on this site online:

Since I needed a nice fitting window with my XP start menu showing and no scroll bars I knew that I needed to go smaller than the max of 1280x768. I plugged in multiple settings with smaller resolutions at the proper refresh rate until I found the rather odd resolution that I needed, which is 1264x678 at a 60Hz refresh rate. You will also have to play around to get the proper fit based on your equipment, software, and drivers.

So I have my resolution and refresh rate and I need to plug these into the mode line calculator in order to get the proper settings for my display. Take a look at the screenshot in Figure 1-A below:

Mode Line Calculator

Once I have the proper fields filled in with my requirements I click on the calculate button and get the screen below in Figure 1-B:

Mode Line Result


Part Two: Manually editing the configuration file.

Now, that I have the proper configuration information for my new mode line I will need to manually configure the new data into /etc/X11/xorg.conf and then restart the Virtual Machine. So first we need to open up /etc/X11/xorg.conf into a text editor and add the mode line. Find the (Section "Monitor") portion of the file and below that, you will see the default mode line configurations. I added my new mode line directly below the default mode line for 1280x800 resolution but you can plug this line in anywhere inside of the mode line configuration area. See the new mode line that I added, highlighted, in the screenshot in Figure 2-A below:


Mode Line Edit


Now that you've added your mode line you will need to find the (Subsection "Display") portion of the file by scrolling down towards the bottom. Here I edit the default setting which was 1024x768 in this case and change them all to 1264x678 except for the first one (VGA setting) which I leave at 640x480. You can see an example of the portions that I changed to 1264x678 in the highlighted section of the screenshot in Figure 2-B below:

Mode Line Display

Once you've completed the edits you can reboot your virtual machine and the new display resolution will be used. I must again stress the fact that I'm only using this as an example to help you figure out the settings for your specific case. These are dependant upon many things including the hardware, host operating system, drivers, VMWare version and the guest operating systems and drivers.

Monitors can be easily damaged by incorrect driver configurations so USE THESE INSTRUCTIONS AT YOUR OWN RISK!!!



what is a WLAN (Wireless Local Area Network)?



So you're ready to build a wireless LAN in your home? 

So you're ready to build a wireless LAN in your home? Not sure where to begin? I think I can help out a little.

First off, what is a WLAN (Wireless Local Area Network)?


Its a group of networked devices in close physical proximity of each other connected by means of wireless communications.

Wi-Fi is a marketing term used to describe products that conform to the 802.11 wireless communications standard. Most 802.11 wireless networking equipment that can be purchased on the market today will be Wi-Fi certified.

The three popular wireless standards today are 802.11a, 802.11b, and 802.11g. 802.11a is typically more expensive and used primarily in the business world.

802.11a

802.11a runs on a higher frequency than 802.11b and that makes the range a little shorter and more difficult for the signals to penetrate walls and other obstacles. 802.11a runs up to 54 Mbps in speed and signals in a regulated 5 GHz range.

802.11b

802.11b is more suitable for home networks because the range is greater than 802.11a and the signals are less easily obstructed but only runs at speeds around 11 Mbps.

802.11g

802.11g is the newer standard that combines some of the attributes of both 802.11a and 802.11b. 802.11g supports speeds up to 54 Mbps but unlike 802.11a it uses the 2.4 GHz frequency for greater range more like 802.11b. Unfortunately, lots of household appliances also use this range making signal interference more common on this unregulated signal frequency. 802.11g has backward compatibility with 802.11b such that an 802.11g wireless router or access point would allow connections from 802.11b devices as well as 802.11g devices.


Now, what's all this mean to you?


When selecting a base device (wireless router or access point) for your home network you will want to find something that is Wi-Fi certified and based on either the 802.11b or 802.11g standard. Depending on the speed you require and the amount of money that you want to spend.


One of the most common questions about wireless networking has to do with security. Out of the box, a wireless network is very un-secure. Now transactions you might have online with the bank or when purchasing items at an online store with your credit card would still be secured (most times) by the institution's website by means of SSL (Secure Socket Layer) encryption. However, e-mail, instant messages, and other similar communications are sent in clear text by default and would be easily readable by someone close enough to connect to an unsecured WLAN.

When WLANs began to gain popularity a few years ago wardriving became a common practice by some techies. This is the practice of driving or walking around with wireless networking equipment and snooping the wireless traffic in the neighborhood. Often times this would lead to the theft of computer resources like internet access from unsuspecting people with unsecured wireless networks. Various methods of wireless security protocols like WEP were introduced in order to mathematically encrypt or scramble the traffic making it unreadable by a human. WEP is still vulnerable by a skilled network cracker by running programs like airsnort to break the encryption keys but this takes lots of time and traffic and would not be very likely in a home networking environment.

There are several pieces of equipment related to a WLAN:


Wireless Network Adapters

A Wireless Network Adapter is a device that has a built-in radio transmitter and receiver (transceiver). They are also referred to as a NIC or Network Interface Card. Commonly they come as PCI or USB type adapters for desktop type devices or as a PCMCIA type of card for laptop computers. Many laptop computers today have embedded Wi-Fi chips inside of them allowing the computer to connect to wireless networks without the need for an extra component. A Wireless Network Adapter is a critical component to any wireless network as you will need it to connect your end devices (desktop computer, laptop, server, printer, etc) to your WLAN.

Wireless Access Points

A Wireless Access Point is a device that allows centralized communication between multiple wireless devices. Often referred to as a "base station" an access point can be used in wireless networks where there is already a pre-existing broadband router for Internet access, to connect multiple wired LANs or on wireless-only LAN without an exit point.

Wireless Routers

A Wireless Router is also a device that allows centralized communication but also allows for Internet connection sharing and often times firewall protection as well.

That covers the basics of WLAN protocols and equipment. Most network equipment configures differently so it's tough to do any type of overview without targeting specific equipment so in my next article I will cover configuring and securing a Linksys WLAN.

What is a DMZ?



"DMZ" is short for demilitarized zone and is a military term meaning "is an area, usually the frontier or boundary between two or more military powers (or alliances), where military activity is not permitted, usually by a peace treaty, armistice or other bilateral or multilateral agreement." In the world of computer networking and security, the term DMZ refers to a network zone that sits between the internal (trusted network) and external (untrusted network). The external or untrusted network is typically the Internet (or an extranet) and the internal or trusted network would be the corporate intranet.

What is the purpose of a DMZ?

The main purpose of a DMZ is to separate hosts that need to be accessed from an external network from the internal network. This is useful for companies that need to offer information and services to external users like Web, DNS, Mail and FTP access to the outside world. In this case, the hosts on the internal network can initiate communication with the hosts on the DMZ network and hosts from the external network can initiate communication with hosts on the DMZ network. However, in most cases, hosts from the external network cannot initiate communications with hosts on the internal network and hosts on the DMZ network cannot initiate communications with hosts on the internal network.

What this means is that if a host on the Internal network needs to access a web page for example on a server that resides on the DMZ or external network the traffic is allowed out and traffic returning from these hosts is allowed back in because the session was initiated from the internal network. However, if a host on the DMZ or external networks tried to access a resource on the internal network directly it would fail or if a host on the DMZ was somehow compromised by an attacker the limited data on that host would be vulnerable but the internal network would still be safe. The DMZ would be a dead end to an attacker.

Access to the DMZ

Access to the DMZ is typically limited to a per destination address and, or per port basis. This is typically controlled by a device called a firewall. In the realm of computer networking security, a firewall is a device that prevents communications forbidden by a network security policy to take place while allowing approved traffic to flow. There are several common types of firewalls including proxy, packet filtering and stateful. Stateful firewalls are the most common and robust type of firewall in use today. By maintaining "state" tables the firewall can track allowed connections in and out of a firewall interface and allow traffic from less trusted networks to return to more trusted networks if the connection was originated by the more trusted network.


To get a better understanding of how this works, take a look at the drawing of a typical single DMZ design utilizing three firewall interfaces to separate the external, DMZ and internal networks in figure 1-A below:

Typical DMZ


Based on this design the firewall can allow limited access to the DMZ from the internal and external networks by making use of connection states and security rules based on the network security policy, while still providing protection to the internal network from potential threats directed from the two less trusted networks.

There are many different security designs that can utilize a DMZ. Some designs incorporate multiple DMZs with different levels of protection. Some of those multi-DMZ designs have tiered communications between the external network to one DMZ, then from that DMZ to another DMZ and then from that DMZ to an inside resource. Although this isn't the most secure design it can sometimes be a requirement in order to provide certain services from the internal network to the external network through several tiers of secured communications. An example of this type of design might be the external network accessing a web server front end application from DMZ1, the web server on DMZ1 then accesses a back end database server on DMZ2 over a secured port and finally this database server on DMZ2 accesses the internal network domain.

Obviously anytime there is a design like this in place there is the possibility of the internal network being compromised from the external network via the hosts and paths through the firewall along the way, however, there are many methods of identifying and thwarting such an attack prior to the internal network being compromised. Hardening the DMZ servers by limiting access specific to the services they offer, stripping off any services that are not required for it to function properly, keeping the operating systems and software patched for the newest vulnerabilities and exploits and also by blending a mixture of IDS (Intrusion Detection Systems) and IPS (Intrusion Prevention Systems) to help detect and thwart potential attacks to these servers.

Keep in mind that the key to any secure network perimeter design is both the security policy and the network topology and it is critical that they are kept in mind when trying to deploy any type of network security devices into your network.

I hope you've enjoyed this article and look for a new article on designing a secured DMZ soon.