Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Sunday

Security of your Android phone with Kaspersky

From today onwards we will take a look at some of the premium/ commercial security Applications for Android phones. It is Kaspersky Internet Security for Android. It is relatively less expensive than other commercial security apps. I am  not comparing one app with another but letting you find out more about the App that you choose to install. This app is also available as a freeware with less features.

 Installing the App

You will see a green hexagonal icon with "internet security" written under it after installation.

Friday

Security of your computer with Kaspersky

Let us look at paid computer security software. Kaspersky has been rated best among them. There are several versions of Kaspersky for Home users to choose from according to your needs. These software are available for your Windows computers, Windows Phones, Android phones, IOS devices and Mac computers. In fact there are Multi device licenses which allow you to install 5 different software on 5 devices in your home. In this article we will look at Kaspersky Internet Security for Windows computers in details and also compare it's features with other versions of Kaspersky for Home users.

Monday

Computer games for Kids - things to be aware of

Computer games can become a staple diet for the children of today. We often are aware of and take care that children do not over consume junk food and ruin their health. It is obvious in case of the food because we can also eat that which we allow our children to eat. But it is not the case with the computer games that we allow children to play.

I would like the parents to be aware of the games that you allow your children to play, because the games can impact their minds, and can make them addicted to them before you realize. Often parents can not spend time with their children to accompany in the computer games nor they are aware of what the games are about. I think as responsible parents you should invest some time to learn what your children are playing, and how it may or may not impact them.

The same question was faced by me, as a non gaming person myself, I though computer games to be a time wasting activity and was never much interested in.

I had to share my computer with my 5 year old nephew to let him play computer games online and offline, who within a span of an year became proficient in computer games, that I had to concede my inability in helping to get around a particular game he was playing. Moreover when he seemed knowledgeable in games that had theft, robbery and violence in the gameplay, I became a little concerned.

As a society we allow and do not allow a certain things. For example we do not go and steal someones vehicles or crash them, but how come children are exposed to such ideas in computer games?

Let me put it this way. In course of talking to our children do we ever mention stealing, crashing, shooting and so on. We do not talk about them because we do not do such things nor do we think about them. So something that we don't do, nor we intend to ourselves nor allow our children to do them, then how come we allow children to engage in simulations of such things.

I feel upto a certain age children should be kept away from even the ideas of those things which would put them in harms way. That is where I decided to look at the games that I had installed on my computer and online games that I was allowing my nephew to play.

I would make a list of the games that I came across, and put them in perspective so that you can make an informed judgement whether to let your children play them or not.

Tuesday

Virus Removal Guides site is gone

One fine morning I got tired of the Virus Removal Guides Blog. Although it was the blog with maximum number of posts compared to my other blogs, and has maximum viewership. I felt that it was time for it to go.

Some of the events that triggered this decision are as following.

There was no internet connection at my place for more than 2 months now. The broadband Internet connection was disrupted due to the feud between the Municipal Corporation and the Internet Service Provider. I was offline for more than a month, after which I resumed basic connectivity using a mobile broadband connection with limited data throughput.

I noticed that the site http://comprolive.com/remove was displaying an error with a message having connection denied to the database. This made the site as well as the back end inaccessible for days.

I contacted the Web Hosting Provider but there was no real help coming from them in identifying the cause.

After logging in my web hosting account, I noticed that there was a maximum allocated space of 300 MB for the MySQL database. Although my account can have a maximum of 50 such databases, and I had been using only 5 MySQL databases, the maximum allocated size was not increased unless I had to pay extra 50 dollars per year to expand the database to 1000 MB. I did that and my site resumed.

However even after the database space upgrade my troubles did not end. I was unable to even simple tasks on the site to write a new article, as that would result into allocated memory size exceed error. So I resumed to write on one of my dormant Blogger blogs (security.comprolive.com) You can read my latest articles on this blog now.

Another disturbing thing that I observed was that even without being able to write anything on the site, the database space seemed to be automatically filling up. I recorded an increase of 13 MB of filled up space just within two days.

This made me worried, there was something wrong with the Joomla installation 1.5.9 which my site was using. I was waiting for years hoping that the Web hosting provider would upgrade the Joomla some day, but they didn't. I even posted my question on the forum on their site, but got no reply about How to upgrade/ update the Joomla 1.5.9 to the latest versions.

So you will continue to listen from me on this blog.

The Email address support@comprolive.com and pr@comprolive.com are no more functional. If you have been trying to contact me on the above email addresses the mail would bounce. Please contact me on my gmail ID sanjayrajure@gmail.com

D Link routers at hacking risk

A vulnerability researcher named Craig Heffner has found out that some of the D-Link ethernet and wireless broadband routers  can be logged into via their web interface using a certain text string as a browser user agent.

It is being guessed that this particular backdoor was created and left intentionally by the software developers at D-Link as a feature that may come handy some day.

Saturday

Beware of fake GooleToolbarNotifier.exe

Google settings notification (GoogleToolbarNotifier.exe) Toolbar Notifier protects your Google search settings and notifies you if a website or program attempts to change your default search settings. Google Toolbar notifier is installed in your computer as part of Google Toolbar for your browser. Google Toolbar can be downloaded from toolbar.google.com .
The Google Toolbar is installed in the folder
%ProgramFiles%\Google\Google Toolbar along with other folders and files - see report

Whereas the Toolbar notifier is found in its own sub folder located at
%ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

Friday

A proposal for a banking solution to hacking

A banking solution to limit the damage from hacking of banking accounts.

I think there is a simple but effective solution for limiting the financial losses caused to a person's bank account in case it has been hacked through internet or through the hacking of his debit card/ ATM card etc.

The traditional way of withdrawing money was to go to a bank personally, fill up the withdrawal form, and submit it to the clerk along with your bank passbook. This method requires the account holder to be physically present in the bank, and hence is the most secure and effective against any modern types of banking fraud.

Sunday

Essentials of Home Computers

I have been working on computers and connected to internet since 1999 when a friend of mine started an Internet Shop or a Net Cafe in Koregaon Park in Poona where the Rajneesh Ashram or Osho Commune was located. We had 15 computers in the shop connected to the internet, all running on Windos XP Sp2. We had antivirus programs on them, but hundreds of clients using the computers for browsing the internet, and watching every conceivable thing, the computers were abound to crash with viruses and I was the one who would try to detect and remove them everyday. It went for almost a year.

Thursday

Creating secure passwords

Creating secure passwords that would not be easily detected, and still be able for you to remember is a difficult task. I try to give some tips on making secure and yet memorable passwords. For that, first you have to create an algorithm (a pattern) of your own. Then you use that pattern to create a password for yourself. I will tell you how to create a simple algorithm(a pattern).

Let us suppose we need to change our passwords once a month. Then we can choose to use the names of each month in the passwords.
For example we use "september" as our password.
But how to make it secure?
For that you can mix it with some numbers. Make your unique choice of numbers , for mixing in the name. Say for example 1,2,3
Now we have a name, and some numbers.
Now there is one more thing we can do to make it strong is to mix capital and small letters.

So here are some possible combinations for a password.

sEp1tEm2bEr3 (see, this password contains september, and 123)
Sept123embeR
sepTEMber123

If you look closely each password has a definit cyclic pattern. So all that you need to remember is the pattern of your choice and the name and numbers you mixed in it. So you need not remember the whole password.

Now as you can see, this password is pretty strong and you should still be able to remember it easily. You can create a lot of passwords by using the combinations of the names you easily remember, and the numbers you choose. You can choose a single pattern of your choice for all your passwords and create different passwords using a combination of different names and numbers.

These are the simpler passwords. You can get help of an automatic password generating program to help you to create longer and more secure passwords (but difficult to memorize)

SourceForge has one such program called PW Gen which is distributed under GPL general public license. You can download and use if freely. It helps you to create 32bits to 2048 bits long passwords. It means 6 characters long to 342 characters long password which includes A-Z, a-z,0-9, and all special characters like /?-+ etc
Create passwords as complex according to your needs.
Link To PW Gen
Link T0 SourceForge

Safe Browsing Tips

The most dreaded threat to your computer is being take over by hackers, who use your computer without your knowledge to attack and harm other computers while your computer is connected to internet. FBI reports that there are above 1 million home computers in US alone which are being used remotely by the hackers called Bot-herders, without the consent or express knowledge of the owners of those computers.
You can take a small precautionary measure to protect yourself while Online by using a Limited Account on windowsXP. If you are using XP, and if you are the only user, or if you are the main user then probably your account is an Administrative Account. To check what type of account you have, Go to Control Panel > User Accounts > (Look at the Icon of Your Account) , it is either Computer Administrator, or Limited Account.
If you use an Administrative Account which is the default account type then you have the privilage of Installing new programs. But Unfortunately this Privilage becomes your weakness/drawback while you are using internet. When you are browsing different sites, some malware can creep in as temperory Internet files and remain there waiting for a chance to be executed. Once it is executed, normally when you boot your computer again, it spreads in your computer by making new entries in registry, copying its DLL files and executables in different locations on the hard disk and modifying your default home page.
These entries are preserved by windows system restore therefore whenever you have a Trojan or a Worm you have to disable system restore temperorily to remove its traces.
If you are using a limited account, then the infection will be contained to the user account only, and will not affect the whole computer.
It is a good practice to delete all computer generated files, temporary internet files, cookies etc at the end of your online session at least at the end of the day or before you shut your computer. This way you remove any lurking malware in it.
If you already have a Limited User Account then just Log In and use it while you are accessing internet. Otherwise create a new one.
Start > Control Panel (Switch to classic View) > User Accounts > Create a new Account > Type a name for the new account -Next > Pick an account Type (Limited) > Create Account
Once the account is created, it should appear in the User Accounts window, with Limited Account written under it. Use this Account for accessing internet from now on.
You can switch between your Administrative and User Account easily without having to Log Off one account. Click on Log Off > Switch User and Choose the account to Log In. This can be handy if you need to access your Administrative account for installing softwares, or for any other reason. But remember your Clipboard does not work in between switching the accounts. It means you can not copy something in the clipboard in one account and then paste it in another account. For that you can copy the files in the Shared Folder. This is the location of shared folder on your hard disk.
Click on Start > My Computer > doubleClick Shared Documents.
This is the common place where you can copy any files, or documents that you want to access from both accounts.
You will need to do some house-keeping before you can start using your Limited Account.
Some of the programs that you have installed in Administrative Account may not seem to appear in the programs menu of the Limited Account, and some those appear may not seem to open at all.
If you see that a program that you had installed is not appearing in the menu, Click on Start > My Computer and doubleClick on the disk icon, C,D, etc to browse to the location the program was installed. For Example Ccleaner does not appear in my Limited Account. So I doubleClick on C > Program Files > CCleaner

Once you are in the folder of the program, doubleClick on the Icon of the program to see if the program opens executes runs. If it opens then close that program for the time being. Then Click on the Icon again to select it, right click on it and select Send To > Desktop (create shortcut) from the menu. It will create a shortcut on you Limited Account desktop, from where you will be able to access the program.

What about the programs that are not working ?

You can install new program (probably) while in the Limited Account. Try to run a installation file , if it runs then create a new folder for it. Otherwise it would overwrite the installation that you had done form the Administrative Account. I had to install Privoxy, because it would not run on my Limited Account. So I had to download it from the site and run the setup program. I created a new folder called Privoxy2 and installed the program in that folder.

I had to configure my browsers, both IE7 and Firefox to use the proxy server at 127.0.0.1 on port 8118. Privoxy really makes your Browsing Transparent. You can view each file as it is being rquested, you can immediately block any file by editing the default page of privoxy. You will be surprised to see how many files get downloaded just for advertising purposes. Privoxy blocks them all

Common steps to remove virus

These are several steps you need to use in several cases in removing a trojan or a worm manually. You may need to take one or more of these steps as advised in the manual removal writeups. The steps are explained in detail and is useful when you need to take these steps

How to Boot in Recovery Console in winXP
If you are having trouble to access registry tools, and task manager, then you will be unable to end the running processes of the virus, and detete them from hard disk. In such a situation booting from a cd helps which does not give the virus executables a chance to run.

First see that your computer BIOS setting allows you to boot from your cd. Then insert windows installation disk in the drive bay and restart the computer. As the computer detects the cd , it asks you to press any key to boot from the cd. If you do so, it starts detecting hardware and then present you with an option to start installation or start Recovery console. Press R to start Repair console.

On the next screen you will be asked to choose the windows installation to repair. If you have installed windows XP on C drive and it is the only installation on your disk then it will be listed as
1 C:\windows\system
type 1 at the prompt and press Enter to repair this installation
It will prompt for administrative password. Type it and press Enter.

You will be taken to C:\windows

Now you can look into the root directory and the system directories for the virus files and delete them. But you should know the exact names and the locations of the files before you come to this place, because there is no search function available in the Recovery Console.
Type cd.. to go back a level. Type cd to enter the folder. Type dir to display the file in the current directory. Type delete to delete a file, this command does not give confirmation. Type dir to confirm that the file is no more.

Changing the hidden and read only attributes of a virus file.

If you locate a file present in the specified directory and run delete command and still if it does not get deleted means the file has a read only and a hidden attribute.

Type dir press Enter (suppose you are in the same directory)
It will display -RH etc attributes before its name. R means read only and H means hidden file.
So type
attrib -R press Enter
attrib -H press Enter
To remove its read only and hidden attributes.

Now the you can use the delete command to delete the file.

After you are able to locate and delete the virus files, type Exit, press Enter , and take out the cd from the cd bay to allow the computer to restart normally.

(You are limited to only C drive (the root drive), and the system folders, in other folders acess is denied)


How to Enable Task Manager and Registry Editor using a script


Sometimes the virus may have disabled your task manager and the registry Editor may refuse to open. Even the Start > Run window may not appear. In that case you can create a small script by pasting the following VBScript code in notepad, save it on hard disk and execute it to re enable all the tools.

Open Notepad and copy and paste the following:

On Error Resume Next
Set shl = CreateObject("WScript.Shell")
Set fso = CreateObject("scripting.FileSystemObject")
shl.RegDelete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools"
shl.RegDelete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr"



Save this file with .VBS extension.
While saving enter the name in double quotes and select all files from the save as type in notepad.
For the ease of use, save the file on desktop.
for example "regtool.vbs"
When the file is saved as a vbs file then the file icon changes as a VBScript script file
Double click on the file name to execute it

It will enable the registry Tools


How to Use UnHookExec tool from Symantec
(to reset these registry values to their default settings)

As part of their routine, many worms and Trojans make changes to the registry. Some of them change one or more of the shell\open\command keys. If these keys are changed, the worm or Trojan will run each time that you run certain files.
For example, if the \exefile\shell\open\command key is changed, the threat will run each time that you run any .exe file. This may also stop you from running the Registry Editor to try to fix this.They may also change a registry value so that you cannot run the Registry Editor at all.
Symantec Security Response has created a tool to reset these registry values to their default settings.


Read More about the tool on this link
symantec security response

Download It from here
UnHookExec.inf

Download the file UnHookExec.inf and save it to your Windows desktop.
(If you cannot connect to the Internet from the infected computer, download to an uninfected computer then save it either to a floppy disk or cd, dvd. Then take the disk and insert it in the disk drive of the infected computer.)

Note: The tool has a .inf file extension

Locate the download file, either on the Windows desktop or the floppy disk
Right-click the UnHookExec.inf file and click install. (This is a small file. It does not display any notice or boxes when you run it.)



How To End/Kill a Process

(Below is a short clip showing how to end a process)


(Sometimes you will be asked to kill a process)
It means open Task Manager
by pressing ctrl+alt+delete keys
Then click on Processes Tab
Locate the process in the displayed processes
If found click on it once then press the End Process Button
or right click on it and select delete from the popup menu.
Close the Task manager by pressing
the X button on the top right corner.


How To disable System Restore
(when you are asked to disable system restore temporarily, follow the steps below. Do not forget to Enable System again once your virus cleaning is over, most instructions forget to tell you that.)
Disable System Restore in Windows ME

Click on Start > Settings > Control Panel.
Double-click 'System',
then click on the 'Performance' tab.
Click 'File System'
then click the 'Troubleshooting' tab.
Select 'Disable System Restore'
and click 'Apply'.
Restart your system.

Disable System Restore in Windows XP
(Below is a short video clip showing how to disable/enable system restore)


Click on start > all programs > Accessories > System Tools > System Restore
Click on System Restore settings.
Check the box:Turn off system restore on all drives.
press apply. press ok.


How To enable System Restore

Enable System Restore in Windows ME


Click on Start > Settings > Control Panel
Double-click 'System'
then click on the 'Performance' tab
Click 'File System'
then click the 'Troubleshooting' tab.
Deselect or Uncheck 'Disable System Restore'
and click 'Apply'.
Restart your system.

Enable System Restore in Windows XP



Click on start > all programs > Accessories > System Tools > System Restore
Click on System Restore settings.
UnCheck the box:Turn off system restore on all drives.
This will start system restore monitoring all your drives/partitions
press apply press ok


How to boot in safe mode


In windows XP if you restart the computer and press F8 while rebooting the computer may not display safe mode boot option. For that Turn computer off. Then Turn it on after two minutes. Press F8 while booting, keep tapping F8 key several times so that you do not miss the exact point of pressing the key. It should open a menu, select boot in safe mode

There is also an options from msconfig window in winXP. Click on start > run. Type msconfig. Press Ok. The system configuration window opens. Click on BOOT.INI Tab. At the bottom of the Tab, you will see a checkbox /SAFEBOOT. If you check the box. Press apply. Press close. Press Restart. Now the computer will Reboot directly in safe mode. Use this option if you are having difficulty in using the other method.

Once you are through your work in safe mode, come back to msconfig window and Uncheck the /SAFEBOOT box. Otherwise each time your computer will take you to the safe mode. If you uncheck the safeboot option then you will be able to boot normally after restart.



How to search and delete files from hard disk


-First View Hidden Files (In WindowsXP)

click on start > control panel > Folder options
click on View Tab.
In Advanced Settings.
Locate hidden files and folders
Select the radio button in front of
Show hidden files and folders.
press ok.

-Now start search

Click on start > search
clik on All files and Folders
(copy and paste the names to be searched in the search box. You can search for many names at once separated by comma.)
click on more advanced options.
Check the boxes in front of
-Search system folders
-Search hidden files and folders
-Search subfolders

click search. Delete the files if found.
To delete a file. Select by clicking on it once and
press delete button on the keyboard or rightClick
and select delete from the menu.

How to open windows registry


Click Start > Run.
Type regedit
Click OK.
The Registry Editor opens

How to make a registry backup

Assuming that you have opened the registry Editor
Click on File > Export
Give the file a name
And click Save
It saves a copy of registry in My Documents folder by default

How to restore registry using backup


In rare cases if after editing the registry your computer seems to have more problems than before. Then Open the registry editor again and Press File > Import
Select the file that you had saved before. Click on Open. This will copy the backup file to your registry to restore it to its original status. Remember to close all
other applications while Importing/Restoring registry, as the open programs keep some registry keys open and therefore can not be overwritten


How to delete Keys from the registry

Important: It is strongly recommended that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only

Assuming that you have already opened registry Editor

Navigate registry subkeys

Click on the Plus sign before the name of the key in the left panel to expand it further
Or you can doubleClick on the name to expand it

Delete a key

To delete a key. Select in by clicking on it once.
Then press delete key on the keyborad.
Or right click on it to display a menu and
select delete from it.
Press Yes to confirm.

Easy way to find a subkey

Click on Edit > Find
Type the name to be searched and click on Find Next
Select the entry if found. Right click and select delete
Press F3 to search for next entry
Continue till you finish searching through the registry

Also if you have problem locating the long subkeys copy and paste the last portion of the key, the one within curley braces, copy the part with the curley braces and Paste it in Edit > Find window, and click on Find Next. That will be easier way to identify the keys. Press F3 to search for next entry. Continue till you finish searching through the registry

You can search for only one name in the registry at a time, unlike in the search options on the hard disk where you can search for many names separated by a comma. Therefore you have to repeat searching in the registry for each name separately

Close the registry Editor when Done
How To edit the Win.ini file

WARNING: The following steps instruct you to remove the text from the run= line of the Win.ini file. If you are using older programs, they may load at startup from one of these lines. If you are sure that the text contained in these lines is for the programs that you normally use, then we suggest that you do not remove it

If you are running Windows 95/98/Me, follow these steps
Click Start > Run. Type the following
edit c:\windows\win.ini
and then click OK
(The MS-DOS Editor opens.)

NOTE: If Windows is installed in a different location, make the appropriate path substitution.

In the [windows] section of the file, look for a line similar to:

run=[TROJAN FILE NAME]

Note: [TROJAN FILE NAME] refers to the file name detected during the scan.

If this line exists, delete everything to the right of run=

Click File > Save. Click File > Exit


How To edit the System.ini file

If you are running Windows 95/98/Me, follow these steps: Click Start > Run. Type the following:

edit c:\windows\system.ini
and then click OK
(The MS-DOS Editor opens)

NOTE: If Windows is installed in a different location, make the appropriate path substitution

In the [boot] section of the file, look for a line similar to

shell = Explorer.exe [TROJAN FILE NAME]

Note: [TROJAN FILE NAME] refers to the file name detected during the scan

If this line exists, delete everything to the right of Explorer.exe

When you are done, it should look like

shell = Explorer.exe

Click File > Save. Click File > Exit

Featured Post

Creating Games in Scratch for ICSE Class 6

An Introduction to Creating Games in Scratch  for ICSE Class 6 Hello friends, I hope you have already read the previous post on An Int...