Showing posts sorted by relevance for query malware. Sort by date Show all posts
Showing posts sorted by relevance for query malware. Sort by date Show all posts

April 22, 2012

Mozilla Blocks Java Support in Firefox

Mozilla this week began blocking outdated versions of a Java plug-in in Firefox for some Mac users after calling the threat posed by the Flashback malware “evident and imminent.”
The move came two weeks after Mozilla disabled unpatched versions of Oracle’s software on Firefox for Windows.

December 13, 2011

Internet Explorer more secure than Mozilla Firefox, Says Study

The Microsoft is much much happy now as they have a second position in their hands. Microsoft's Internet Explorer does a better job protecting systems from attackers who already have gained some degree of access than Mozilla's Firefox, and Google's Chrome trumps both of them, according to a new browser security study from Accuvant.

They came up with those results by analyzing the security features of the three most popular web browsers, but have decided not to employ the usual metrics: numbers of patched vulnerabilities, the severity of the flaws and the time it took for the developers to fix them.

As for the raw details, Accuvant's study didn't just focus on the sheer number of published vulnerabilities that a browser has at the time of testing. Rather, Accuvant presumed that a browser vulnerability is going to be exploited in some fashion by a third-party: The security testing, therefore, focused on the strength of a browser's anti-exploitation measures after-the-fact—"the software with the best anti-exploitation technologies is likely to be the most resistant to attack and is the most crucial consideration in browser security," Accuvant wrote.


While Google's Chrome browser won the day in Accuvant's research, the browser didn't sail through with a perfect score. Accuvant noted that Chrome, along with the other two browsers in the test, failed to adequately offer up strong enough URL blacklisting to pass Accuvant's examinations—a daily comparison of roughly 6,000 malware-related URLs against either Microsoft's URL Reporting Service or Google's Safe Browsing List.

"Gathering intelligence about malware URLs is generally performed by running honeypots and spamtraps, and harvesting URLs from malware captured in the wild. Since no authoritative source exists, it is likely that each organization gathering data is getting one part of the overall picture," Accuvant wrote. "Based on Accuvant's analysis, no party is performing this data collection comprehensively."

And while all three browsers employ address space layout randomization (ASLR), data execution prevention (DEP) and stack cookies (GS), Firefox does not implement sandboxing (the separation of running programs), plug-in security and Just-In-Time hardening (preventing javascript located on websites from compiling code that can be run on the target system).
That said, Chrome's apparent excellence in sandboxing, plug-in security, JIT hardening, and Address Space Layout Randomization, among other features, was enough to win it top honors. But Mozilla isn't letting Accuvant have the last word regarding the security of its browser.

December 3, 2011

Online Security: 11 Tips to be Followed

Billions of dollars will be spent online over the course of this month and, unfortunately, there are those that will be looking to steal some of it. Make sure you will not be a victim.

There is many reason in the world to shop online. The bargains are there. The selection is mind-boggling. The shopping is secure. Shipping is much fast during the festive season. Even returns are pretty easy, with the right e-tailers. Shopping has never been easier or more convenient for consumers.

But what about the bad guys who lay in wait? ECrime Report for 2011 indicates that use of phishing attacks (where thieves attempt to swindle you out of your sign-in credentials and even credit card info by pretending to be a real website, or even an online bank) is down, as much as eight percent since the second quarter and 11 percent since the third quarter of last year. That's great news—except the same report says sites with malware (malicious code aimed at compromising your privacy) has increased by 89 percent since the second quarter.

Stay calm. While somewhat alarming, these stats should not keep you from shopping online. You simply need some common sense and practical advice. Follow these basic guidelines and you can shop online with confidence. Here are 11 tips for staying safe online, so you can start checking off items on that holiday shopping list.

1) Use Familiar Websites
Start at a trusted site rather than shopping with a search engine. Search results can be rigged to lead you astray, especially when you drift past the first few pages of links. If you know the site, chances are it's less likely to be a rip off. We all know Amazon.com and that it carries everything under the sun; likewise, just about every major retail outlet has an online store, from Target to Best Buy to Home Depot. Beware of misspellings or sites using a different top-level domain (.net instead of .com, for example)—those are the oldest tricks in the book. Yes, the sales on these sites might look enticing, but that's how they trick you into giving up your info.

2) Look for the Lock
Never ever, ever buy anything online using your credit card from a site that doesn't have SSL (secure sockets layer) encryption installed—at the very least. You'll know if the site has SSL because the URL for the site will start with HTTPS:// (instead of just HTTP://). An icon of a locked padlock will appear, typically in the status bar at the bottom of your web browser, or right next to the URL in the address bar. It depends on your browser.


Never, ever give anyone your credit card over email. Ever.

3) Don't Tell All
No online shopping store needs your social security number or your birthday to do business. However, if crooks get them, combined with your credit card number for purchases, they can do a lot of damage. The more they know, the easier it is to steal your identity. When possible, default to giving up the least amount of information.
4) Check Statements

Don't wait for your bill to come at the end of the month. Go online regularly during the holiday season and look at electronic statements for your credit card, debit card, and checking accounts. Make sure you don't see any fraudulent charges, even originating from sites like PayPal. (After all, there's more than one way to get to your money.)

If you do see something wrong, pick up the phone to address the matter quickly. In the case of credit cards, pay the bill only once you know all your charges are accurate. You have 30 days to notify the bank or card issuer of problems, however; after that, you might be liable for the charges anyway.
5) Inoculate Your PC
Swindlers don't just sit around waiting for you to give them data; sometimes they give you a little something extra to help things along. You need to protect against malware with regular updates to your anti-virus program. PCMag recommends Webroot SecureAnywhere Antivirus (4.5 stars, Editors' Choice, $39.95 direct), which has extras to help fight ID theft, or at the very least the free Ad-Aware Free Internet Security 9.0 (4.5 stars, Editors' Choice).
6) Use Strong Passwords

We like to beat this dead horse about making sure to utilize uncrackable passwords, but it's never more important than when banking and shopping online. Our tips for creating a unique password can come in handy during a time of year when shopping around probably means creating new accounts on all sorts of e-commerce sites.

7) Think Mobile
The National Retail Federation says that 5.7 percent of adults will use their mobile devices to do comparison shopping before making a purchase. (And 32.1 percent will comparison shop online with a computer, as well.) There's no real need to be any more nervous about shopping on a mobile device than online. The trick is to use apps provided directly by the retailers, like Amazon, Target, etc. Use the apps to find what you want and then make the purchase directly, without going to the store or the website. (For more complete information, be sure to also read our tips for shopping safely on a mobile device.)

8) Avoid Public Terminals
Hopefully we don't have to tell you it's a bad idea to use a public computer to make purchases, but we still will. If you do, just remember to log out every time you use a public terminal, even if you were just checking email.

What about using your own laptop to shop while you're out? It's one thing to hand over a credit card to get swiped at the checkout, but when you must enter the number and expiration date on a website while sitting in a public cafe, you're giving an over-the-shoulder snooper plenty of time to see the goods. At the very least, think like a gangster: Sit in the back, facing the door.

9) Privatize Your Wi-Fi
If you do decide to go out with the laptop to shop, you'll need a Wi-Fi connection. Only use the wireless if you access the Web over a virtual private network (VPN) connection. If you don't get one from your employer, you can set up a free one with AnchorFree Hotspot Shield, if you're willing to put up with the ads, or pay $4.99 a month or $44.99 a year to skip the ads. There's even an iOS app version of Hotspot Shield, but that will cost you $.99 per month or $9.99 a year after the first seven days.

Now it is not a good time to try out a hotspot you're unfamiliar with. Stick to known networks, even if they're free, like those found at Starbucks or Barnes & Noble stores that is powered by AT&T. Look for the network named "attwifi," then open a browser to click into the "walled garden" to get final access. You can also find free Wi-Fi at McDonalds, Panera Bread, and FedEx Office locations, not to mention libraries and local cafes.

10) Count the Cards
 Gift cards are the most requested holiday gift every year, and this year will be no exception. Stick to the source when you buy one; scammers like to auction off gift cards on these sites with little or no funds on them.



11) Know What's Too Good to Be True
Once again, McAfee has compiled a Twelve Scams of Christmas list, all things to be aware of while shopping. The "coupon scam" offers of a free product with purchase, in particular an iPad (a very coveted gadget at any holiday) or even holiday job offers. Many of these "offers" will come in via social media. Beware even of your friends, who might innocently forward such a thing. Be very wary even if you get a message from friend claiming he or she has been robbed, especially a friend overseas looking for money to be wire transferred, unless you absolutely can confirm it by talking to him or her personally. Skepticism in most cases can go a long way toward saving you from a stolen card number.

December 21, 2011

Mozilla & Google seal new Firefox search deal

Mozilla and Google today said that they had struck a new search deal that will provide "significant revenue" to the maker of Firefox.


 "We're pleased to announce that we have negotiated a significant and mutually beneficial revenue agreement with Google," Mozilla said today in a statement. "This new agreement extends our long-term search relationship with Google for at least three additional years."

Under the deal, Mozilla will continue to offer Google as the default search engine in Firefox, which now controls about a quarter of the browser market. 

"Mozilla has been a valuable partner to Google over the years and we look forward to continuing this great partnership in the years to come," said Alan, Google's head of search.

Mozilla declined to provide details of the new contract, citing confidentiality requirements. Later, a spokesman refused to say whether the deal was comparable to the previous agreement.
In 2010, the last year for which Mozilla has released financial statements, the Google contract generated 84% of Mozilla's $123 million in revenues, or approximately $103 million.
Google's contribution to Mozilla's bottom line in 2009 was about $89 million, or 86% of the browser maker's annual income.

The Mozilla-Google deal expired last month, but Mozilla did not alter Firefox's default search provider or the browser's start page, which displays Google's search page.

Questions about Mozilla's dependence on Google have been raised since the latter launched its own Web browser, Chrome, in September 2008. According to Internet metrics firms
StatCounter, in November 2011, Chrome owned a 25.7% share of the global browser usage market to edge into second place ahead of Firefox's 25.2%.

Last week a research testing company accused Google of attempting to quash Firefox using a triple-threat campaign to deny it revenues, withhold anti-malware services and -- through a Google-sponsored report -- claim that Chrome is significantly safer.
Google denied the second and third charges, and with the announcement today, has made the first moot.

Mozilla has made only minor steps to wean itself from Google. In October, the open-source organization launched a customized edition, dubbed "Firefox with Bing," that uses Microsoft's Bing search as the default engine.



As recently as two weeks ago, Mozilla declined to confirm that it had renewed the lucrative Google contract, saying then only that it was still negotiating with its browser rival.
Because of Mozilla's financial disclosure timetable, the impact of the new contract won't be apparent until the fall of 2013, when Mozilla issues revenue numbers for 2012.

November 23, 2011

Fake "VIRUS ALERT" !

Fake Virus Alerts Floating in the Web 


Sophos is warning office workers about an unusual twist on virus alert tactic on the people. The emails warn of recent incidents of corporate data theft 7 instruct users to click on a link which is of course the actual malware payload.

November 24, 2011

GOOGLE OPERATING SYSTEM FOR PERSONAL COMPUTERS

Google is developing as a business. Google Inc. is an American multinational public corporation invested in Internet search,cloud computing, and advertising technologies. Google hosts and develops a number of Internet-based services and products, and generates profit primarily from advertising through its AdWords program.The company was founded by Larry Page and Sergey Brin, often dubbed the "Google Guys", while the two were attending Stanford University as PhD candidates.


Google is developing an operating system (OS) for personal computers, in a direct challenge to market leader Microsoft and its Windows system.
Google Chrome OS will be aimed initially at small, low-cost netbooks, but will eventually be used on PCs as well. It is an open source, lightweight operating system that will initially be targeted at netbooks.

December 5, 2011

The Personal Computer Is Dead


The PC is dead. Rising numbers of mobile, lightweight, cloud-centric devices don't merely represent a change in form factor. Rather, we're seeing an unprecedented shift of power from end users and software developers on the one hand, to operating system vendors on the other—and even those who keep their PCs are being swept along. This is a little for the better, and much for the worse.

The transformation is one from product to service. The platforms we used to purchase every few years—like operating systems—have become ongoing relationships with vendors, both for end users and software developers. I wrote about this impending shift, driven by a desire for better security and more convenience, in my 2008 book The Future of the Internet—and How to Stop It.

For decades we've enjoyed a simple way for people to create software and share or sell it to others. People bought general-purpose computers—PCs, including those that say Mac. Those computers came with operating systems that took care of the basics. Anyone could write and run software for an operating system, and up popped an endless assortment of spreadsheets, word processors, instant messengers, Web browsers, e-mail, and games. That software ranged from the sublime to the ridiculous to the dangerous—and there was no referee except the user's good taste and sense, with a little help from nearby nerds or antivirus software. (This worked so long as the antivirus software was not itself malware, a phenomenon that turned out to be distressingly common.)

Choosing an OS used to mean taking a bit of a plunge: since software was anchored to it, a choice of, say, Windows over Mac meant a long-term choice between different available software collections. Even if a software developer offered versions of its wares for each OS, switching from one OS to another typically meant having to buy that software all over again.

That was one reason we ended up with a single dominant OS for over two decades. People had Windows, which made software developers want to write for Windows, which made more people want to buy Windows, which made it even more appealing to software developers, and so on. In the 1990s, both the U.S. and European governments went after Microsoft in a legendary and yet, today, easily forgettable antitrust battle. Their main complaint? That Microsoft had put a thumb on the scale in competition between its own Internet Explorer browser and its primary competitor, Netscape Navigator. Microsoft did this by telling PC makers that they had to ensure that Internet Explorer was ready and waiting on the user's Windows desktop when the user unpacked the computer and set it up, whether the PC makers wanted to or not. Netscape could still be prebundled with Windows, as far as Microsoft was concerned. Years of litigation and oceans of legal documents can thus be boiled down into an essential original sin: an OS maker had unduly favored its own applications.

When the iPhone came out in 2007, its design was far more restrictive. No outside code at all was allowed on the phone; all the software on it was Apple's. What made this unremarkable—and unobjectionable—was that it was a phone, not a computer, and most competing phones were equally locked down. We counted on computers to be open platforms—hard to think of them any other way—and understood phones as appliances, more akin to radios, TVs, and coffee machines.

DMCA.com The Techbay | All Rights Reserved.

Designed by "mintJelly"