Pages

Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

Wednesday, July 01, 2015

DIY: ransomware and how to protect yourself

image: illustration of a ransomware window
FBI Ransomware, Trend Micro
***
Today my email had a surprise message. Trend Micro, my current antivirus, informed me that I should get an anti-ransomware tool. I thought "Great, another way to separate me from my money." But I still decided to check into it.

Turns out there is ransomware (also a way to separate you from your money) and it's use is growing. Ransomware typically
propagates as a trojan like a conventional computer worm, entering a system through, for example, a downloaded file or a vulnerability in a network service. The program will then run a payload: such as one that will begin to encrypt personal files on the hard drive. More sophisticated ransomware may hybrid-encrypt the victim's plaintext with a random symmetric key and a fixed public key. The malware author is the only party that knows the needed private decryption key. Some ransomware payloads do not use encryption. In these cases, the payload is simply an application designed to restrict interaction with the system, typically by setting the Windows Shell to itself, or even modifying the master boot record and/or partition table (which prevents the operating system from booting at all until it is repaired).(Wikipedia)
One prominent flavor is Cryptolocker which worked differently but still requires payment, usually via Bitcoin or a pre-paid cash voucer and within 3 days. Wikipedia notes that "It was estimated that at least US$3 million was extorted with the malware before the shutdown" in late 2014. More recent versions are CryptoLocker.F, TorrentLocker, and Cryptowall.

More information can be found at Microsoft's Malware Protection Center and Trend Micro's Security News. The site We Live Security gives some very good tips in 11 things you can do to protect against ransomware, including Cryptolocker.

Trend Micro offers a free anti-ransomeware tool for download and instructions for using the tool. And here's more information on how to protect yourself.

About email safety. Never click on a link or attachment unless you're sure who sent it. Look at the sender's address--if it's you (a spoofed address) or someone you've never heard of delete it. If the email looks like it's from your bank or credit card company, but the sender's address doesn't look right, go to company's site (bank or credit card) and look for information on what to do about phishing. Often you will find an email address for forwarding the email to. Let the company deal with the nasty, fraudulent thing. Then be sure to delete the original message.

Never, never, never just click on an attachment that has an *.exe file extension or one that has *.doc or *docx. Detach the document and virus check it before opening. Again, if the sender is unknown, just delete the email first. The only documents I'll open without checking are *.pdf and from a known sender.

On dealing with spam, forget about unsubscribing--you're just letting the spammer know that your email address is live. You can set up filters to keep the spam out. Although I don't filter (except porn and sex-related stuff) because it's fascinating to watch what the most recent hot topics are. It's easy enough to delete the spam after you've reviewed the subject lines.

While I was checking on ransomware, I came across this article at Tom's Hardware (a very useful site)--Report: Security Of U.S. Agencies In Dire State, Employee Logins Widely Leaked.

-- Marge


Monday, July 01, 2013

Hacking, cracking and just plain war

image: "You have been hacked," found at Udemy.com
***
Since hackers and hacking seem to be in the news more and more, I thought you might like a little information about the topic.

First of all, there are hackers and crackers, and an on-going controversy on which is which.  According to Wikipedia, in the computer security context, a hacker
...is someone who seeks and exploits weaknesses in a computer system or computer network. Hackers may be motivated by a multitude of reasons, such as profit, protest, or challenge.
On the other hand there is cracking -- modifying software
to remove or disable features which are considered undesirable by the person cracking the software, usually related to protection methods: (copy protection, protection against the manipulation of software), trial/demo version, serial number, hardware key, date checks, CD check or software annoyances like nag screens and adware.
A while back hackers were considered helpful, and functioned like ex-officio beta testers for the computer community, while crackers were considered malign.  The quote below is from a Wikipedia article discussing this continuing controversy:
Currently, "hacker" is used in two main conflicting ways
  1. as someone who is able to subvert computer security; if doing so for malicious purposes, the person can also be called a cracker.
  2. a member of the Unix or the free and open source software programming subcultures, or one who uses such a style of software or hardware development.
China and Korea have recently been fingered chief instigators in waging cyber war against the U.S. and European nations, as reported in this article in the New York Times, "Chinese Army Unit Is Seen as Tied to Hacking Against U.S."  The U.S. is not entirely victim here, as reported by Foreign Policy, an online magazine, in the article "Inside the NSA's Ultra-Secret China Hacking Group."  (The reader comments on this article are most interesting.)

If you find this topic of interest, there's are detailed instructions on "How to Hack: 12 Steps" at wikiHow.  Udemy offers a number of hacking courses.
***
image: meme by anonymous, found at memegenerator.net
***
I keep wondering if this post will qualify me for the NSA's watchlist.  No, wait...everyone is on that list.

-- Marge