Friday, 3 April 2020

Zoom now considered a Malware but you can ACT now

Zoom has now been said to be the most used app, thanks to the effect of Covid-19 isolation. Most inexpensive and free app to use as you link with your loved ones and attend meetings especially for small businesses.
FBI announced on March 30 that it was investigating Lots of reported cases on video hijacking, also known as “Zoom-bombing”, where hackers infiltrate video meetings, shouting threats.

Zoom meetings can be accessed by a short number-based URL, which can be generated and guessed by hackers. Zoom has released guidelines in which account can stop or restrict unwanted guests from crashing video meetings(see below link). 

Zoom has also lied about its end to end encryption which secures communication so that it can only be read by the users involved. Zoom confirmed in a blogpost that end-to-end encryption was not currently possible on the platform and apologized for the “confusion”.

Zoom has also been called out for its in-app surveillance feature. This feature would allow employers to check if employees are really tuned into a work meeting or if students are really watching a classroom presentation remotely.

Link 

Secure your Zoom

Credit: The guardian


Wednesday, 11 March 2020

SMB wormable bug leak in Microsoft

-Bug is tracked as CVE-2020-0796. It impacts SMBv3, and described as wormable. It was announced in some security feeds, but it isn't included in the March 2020 Patch Tuesday. This does not mean there is a hack on the internet for it. Microsoft has published an advisory on how to disable SMBv3 compression until a patch is ready, you can get this fromthe below link;

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/adv200005

For understanding & controlling SMB inbound and outbound traffic in general, check out the link below;

https://support.microsoft.com/en-us/help/3185535/preventing-smb-traffic-from-lateral-connections


Monday, 9 November 2015

Is your Android Vulnerable?

It's no news that every week a new hack on android devices is published. Of recent is a vulnerability (Stagefright Bug) that can infect an android device via text message. Though google has released a patch for this but the question is has your phone manufacturer released its own patch for this across it various models?
So find this out, you can run the one-click solution to determine if your android device is at risk and its a form of education for 22 known vulnerability for androids. The free one-click solution (VTS for Android) can be found on Google Play store and its designed by Nowsecure .
Download now, check and get informed.

Source: hackernews

Beware: Malware without Recovery

As a result of a Coding mistakes by the creator of malicious program (Power Worm) that encrypts data means anyone hit by it will not be able to recover files.
This so usual because ransomware decrypt files when victims have paid a substantial fee but this variant of Power Worm destroys keys that could help recover any data that it scrambled.
Power Worm infects Microsoft Word and Excel files but its latest update goes after many more types of data files it finds on a victim's machine.
Security researcher believes the errors arose when the creator tried to simplify the decryption process. They tried to make it use just one decryption key but mangled the process of generating it. As a result, there is no key created for the files it encrypts when it compromises a computer.
So what that means is if you have been affected by this ransomware, your only option is to restore from a back-up.

So have you back-up your data today?

Source: BBC

Tuesday, 20 October 2015

Replica Malicious Browser replaces Google Chrome

Security researchers have uncovered an Adware that replaces your Google Chrome browser with a dangerous copy of Chrome and you will never notice any difference while browsing.
The adware is dubbed "eFast Browser," it works by installing and running itself in place of Google Chrome
The efast browser does all kinds of malicious activities like:
-Generates pop-up, coupon, pop-under and other similar ads on your screen
-Placing other advertisements into your web pages
-Redirects you to malicious websites containing bogus contents
-Tracking your movements on the web to help nefarious marketers send more crap your way to generating revenue
Having this installed on your machine may lead to serious privacy issues or even identity theft.

Removing it can be done by uninstalling suspicious plugins or add-on's or resetting your browser to default.

Source:http://thehackernews.com/2015/10/malware-chome.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed:+TheHackersNews+(The+Hackers+News+-+Security+Blog)&_m=3n.009a.1100.af0ao07bvz.mp0&m=1

Friday, 13 June 2014

Watch WorldCup Free on your PC

Download Bluestack app player(google it) Install on your PC. Ensure your PC has the current VGA driver if not goto your manufacturer site to download the latest one. Once installed left click on the bluestack icon and click restart, once it comes up click on the search icon at upper left and search for OnlineHD TV and download from google playstore. Once installed, Woola you have multiple online streaming stations at your finger tips. Good luck.

Thursday, 2 January 2014

Make free call on Facebook

It's a cool feature on facebook messenger {you may need to update} that allows free calls that don't eat into your precious credit - just data if you're not on Wi-Fi. There are other solutions such as Skype and Vonage, but Facebook has all of your friends in one convenient place.

Initiating a call is easy by just tapping the "i" button in the top-right corner of chat with another user. The user on the other end will receive a push notification to accept or refuse the call. If your contact doesn't have Facebook Messenger open or lurking in the background of their device, you can leave them a voice message to pick up later.

It's worth noting calls can be made cross-platform, Android to iPhone, or vice versa.

Friday, 6 September 2013

Weakness in car system

Hackers Find Weaknesses in Car Computer Systems - ClaimsJournal.com http://tinyurl.com/mnljjmq shared via www.newshog.co

Saturday, 10 August 2013

Hacking Windows phone

http://thehackernews.com/2013/08/hacking-windows-phone-wifi-tool-download.html?m=1

Friday, 15 March 2013

HP LaserJet Security Flaw

Critical vulnerability discovered in certain LaserJet Pro printers could give remote attackers access to sensitive data. Homeland Security’s Computer Emergency Response Team recently issued a vulnerability note warning that HP LaserJet Professional printers contain a telnet debug shell which could allow a remote attacker to gain unauthorized access to data.
This flaw was discovered by a Germany security expert, Christoph von Wittich. He detected the vulnerability during a routine network scan of his company's corporate network. He said the vulnerability could also be used for a denial-of-service attack. "As long as the printer is not connected to the Internet, this vulnerability should not cause much trouble for the end user,".

Marked as CVE-2012-5215 (VU#782451, SSRT101078), vulnerability affected 12 printer models including HP LaserJet Pro P1102w, P1102w, P1606dn, M1212nf MFP, M1213nf MFP, M1214nfh MFP, M1216nfh Multifunction Printer, M1217nfw Multifunction Printer, M1218nfs MFP, M1219nf MFP, CP1025nw, and CP1025nw.


Users are advised to download updated firmware for printers impacted by the bug from the company’s Support Center site.


Monday, 18 February 2013

Repair Corrupt Microsoft Word

This are file that when you open comes out with gibberish words which are really strange to read. So how do you fix them, but note they is not mean all corrupt doc. will open with this methods.

The steps are below;
First ensure you are using the right program to read it i.e use Adobe reader to read pdf, MS Excel to open xls, MS Word to open doc, MS PowerPoint to open ppt files etc.

Second: If the first step is ok, then the next option is to open your MS Word program,do not try to open the corrupt file. Once the program is running, goto file > open > browse to the corrupt file then click it, then at the bottom left where you have the open tab, click on the down arrow and select open and repair. Then click on the it after selecting it.

Third: If the first two does not repair the file , then download Openoffice, note this is a large file to download. Once downloaded, run it on your system to install it. After the installation, start the program from the list of programs installed on your system, then select file > open > browse to your doc, then click on open, to open it. Once opened , save the doc with Save as Microsoft 1997/2000 doc.

Fourth : This option can either help or destroy the file, so this done at your risk. Download WordRepair , it does a good job of opening corrupted Word files, but you lose all your formatting, and hence it is the last on this list.

Portable tools to have handy

You never know when you would need them, but having them on you can be your first or best line of defence against rootkit or malwares. When a machine won’t allow you to install applications, this portable apps might be the only way to remove rootkits.
Before you run a scan on a machine, it’s always best to reboot the machine in Safe Mode. This can be done by restarting your system and tapping the F8 key until the Safe Mode menu appears. When that menu appears, select Safe Mode With Networking.

1. Rkill : is a program that attempts to terminate known malware processes so that your normal security software can then run and clean your computer of infections. When RKill runs it will kill malware processes and then removes incorrect executable associations and fixes policies that stop us from using certain tools. When finished it will display a log file that shows the processes that were terminated while the program was running.
As RKill only terminates a program's running process, and does not delete any files, after running it you should not reboot your computer as any malware processes that are configured to start automatically will just be started again. Instead, after running RKill you should immediately scan your computer using some sort of anti-malware or anti-virus program so that the infections can be properly removed.

2. Combofix : It scans your computer for known malware, and when found, attempts to clean these infections automatically. In addition to being able to remove a large amount of the most common and current malware, ComboFix also displays a report that can be used by trained helpers to remove malware that is not automatically removed by the program.

3. Kaspersky TDDSKiller :   Kaspersky focuses only on the TDSS rootkits (Rootkit.Win32.TDSS, Tidserv, TDSServ, or Alureon).  Kaspersky’s TDSSKiller can also remove the Sinowa, Whistler, Phanta, Trup, and Stoned rootkits.

4. BitDefender Rootkit RemoverBitdefender cleans infections with Necurs (the last rootkit standing). New rootkit definitions are added as they become known; because of this, you will want to make sure you check the Bitdefender site and download a new version of the tool frequently. I personally use this last, when cleaning a system.

Friday, 7 December 2012

Malware Stealing Passwords from File-Sharing Sites

The threat in question has been described as malware which employs some password recovery instruments in order to steal passwords that its victims store in their browsers.

The company found out that a number of PASSTEAL malware versions use social engineering lures like variants disguised as key generators for paid apps. TrendMicro team identified “WebBrowserPassView” and “PasswordFox” as two of the password recovery instruments within PASSTEAL. In the meantime, security experts warn about the possibility that people who have developed PASSTEAL could also be using other recovery instruments.

Most people use the same password across various websites, which can certainly help them to remember it, but this still increases the risk of data theft. Of course, for better security, Internet users are recommended to use various login credentials for their accounts and create strong and easy-to-remember passwords. The experts also recommend users to use features offered by the browsers that can help protect private information. For instance, Mozilla Firefox has a master password feature which enables encryption in order to prevent password recovery instruments to easily access account data stored in browsers.

People who are recommended to especially watch out for password stealing malware like PASSTEAL are those who share passwords across many Internet accounts, and those who forget that password sharing is a bad idea.

 

Friday, 16 November 2012

Google Warns against Sophos Antivirus

Tavis Ormandy, one of Google’s security experts, claimed he revealed a few serious security vulnerabilities in Sophos Antivirus, so it shouldn’t be used at important computer systems. The security expert claims that Sophos makes easy mistakes and fails to issue patches quickly. He published a report where several flaws were mentioned that were caused by the company’s poor development practices and coding standards. Sophos didn’t respond fast enough to his warning, which only made things worse.

For instance, it turned out that Sophos’ on-access scanner could be used to launch a worm by targeting a firm receiving an attack email through Outlook. The vulnerabilities were all tested on a Mac, but the expert believes that wormable remote root can affect all platforms that run Sophos.

Tavis Ormandy made a conclusion that users who install Sophos Antivirus expose their computers to considerable risk. Unless Sophos doesn’t improve its security in the nearest future, its deployment may cause considerable risk to global networks and infrastructure. Ormandy pointed out that he gave Sophos 2 months to address the problem before he published the report.

Of course, Sophos was not happy about 30-pages report saying that it fails to do its job. It replied that lots of flaws had been fixed and the company hadn’t seen the fixed flaws being exploited in the wild. Sophos announced the release of further fixes in the end of November. However, Sophos believes it would take half a year to release a patch that fixes a single line of code, while Ormandy says two months. The security expert admits that the company is working with good intentions, but is still ill-equipped to address the flaws he alone revealed in his spare time.

Password Method That Chase Hackers Away

1. DISCARD THAT DICTIONARY : If your password can be found in a dictionary, you might as well not have one. Hackers will often test passwords from a dictionary or aggregated from breaches. If your password is not in that set, hackers will typically move on.
2. NEVER USE THE SAME PASSWORD TWICEWe are all guilty of this, where we tend to use the same password across multiple sites, a fact hackers regularly exploit. While cracking into someone’s professional profile on LinkedIn might not have dire consequences, hackers will use thesame password to crack probably your e-mail or where more valuable financial and personal data is stored.
3. COME UP WITH A PASSPHRASE The longer your password, the longer it will take to crack. Ideally a password of at least 14 characters will make it uncrackable by an attacker in less than 24 hours. Because longer passwords tend to be harder to remember, consider a passphrase, such as a favorite movie quote, song lyric, or poem .
4. JAMMING ON YOUR KEYBOARD For sensitive accounts, you can randomly jam on your keyboard, intermittently hitting the Shift and Alt keys, and copy the result into a text file which he stores on an encrypted, password-protected USB drive.
5. STORE YOUR PASSWORDS SECURELYDo not store your passwords in your in-box or on your desktop. If malware infects your computer, you’re toast. You can store your password file or a password hint file on an encrypted USB drive for which would have a complex password to access. then you can copy and paste those passwords into accounts so that, in the event an attacker installs keystroke logging software on the computer, they cannot record the keystrokes to the password.Just try to keep it off the internet
6. A PASSWORD MANAGER: Password-protection software lets you store all your usernames and passwords in one place. Some programs will even create strong passwords for you and automatically log you in to sites as long as you provide one master password. LastPass, SplashDataand AgileBits offer password management software for Windows, Macs and mobile devices. But consider yourself warned:  it still lived on the computer itself. “If someone steals the computer, you’ve lost the passwords.
7. USE DIFFERENT BROWSERS: Use different Web browsers for different activities “Pick one browser for ‘promiscuous’ browsing: online forums, news sites, blogs — anything you don’t consider important,”. “When you’re online banking or checking e-mail, fire up a secondary Web browser, then shut it down.” That way, if your browser catches an infection when you accidentally stumble on an X-rated site, your bank account is not necessarily compromised. As for which browser to use for which activities, a study last year by Accuvant Labs of Web browsers — including Mozilla Firefox, Google Chrome and Microsoft Internet Explorer — found that Chrome was the least susceptible to attacks.
8. SHARE CAUTIOUSLY  Whenever possible, never register for online accounts using your real e-mail address. You could use a “throwaway” e-mail address, like those offered by 10minutemail.com. Users register and confirm an online account, which self-destructs 10 minutes later.
Truth: “At some point, you will get hacked — it’s only a matter of time,” warned Mr. Grossman. “If that’s unacceptable to you, don’t put it online.”

Gotten from : Yahoo Business

Friday, 19 October 2012

Tools for a Safe PC

1. Microsoft EMET
 Enhanced Mitigation Experience Toolkit: a free tool from Microsoftwhich help Windows users enhance the security of commonly used applications, either third-party vendor or Microsoft's. EMET allows users to force applications to use one or both of two key security defenses built into Windows Vista and Windows 7 —  ASLR and  DEP.
- DEP (Data Execution Prevention) : is designed to make it harder to exploit security vulnerabilities on Windows
- ASLR(Address Space Layout Randomization):  makes it more difficult for exploits and malware to find the specific places in a system’s memory that they need to do their dirty work.

EMET can force individual applications to perform ASLR on every component they load, whether the program wants it or not. Please note that before you install EMET, you’ll need to have Microsoft’s .NET platform   at least a 4.0 .Net Framework should be installed. And while it does technically work on Windows XP (Service Pack 3 only), XP users cannot take advantage of mandatory ASLR and some of the other notable protections included in this tool.
To proceed with EMET, download the program and install it. To wrap EMET’s protection around a program i.e. Internet Explorer — launch EMET and click the “Configure Apps” button in the bottom right corner of the application window. Selecting the “Add” button in the next box that brings up a program selection prompt; browse to C:\Program Files\Internet Explorer, and then add the “iexplore.exe” file. It should be okay to accept all of the defaults that EMET adds for you.
While you’re at it, add the rest of your more commonly used, Internet-facing apps. But go slow with it, and avoid the temptation to make system-wide changes. Changing system defaults across the board – such as changing ASLR and DEP settings using the “configure system” tab – may cause stability, slowness and bootup problems which can cause the application to crash.


2. Sandbox 
If you’re looking to add extra layers or protection, consider purchasing a license to Sandboxie, which forces your programs to run in a protective sandbox that prevents said programs from making changes to the computer. This is effective when you are not sure of what you are abount to run or install. Avast Antivirus also provide a free form of sand-box which you can set certain applications, but it comes with the antivirus when installed.

3. Combofix is a malware removal tool that is extremely good at extracting difficult-to-banish malware and rootkits, malicious tools that attackers can use to burrow deep into an infected system. If a virus scan says you have some version of “TDSS” on your system, or you have an infection that comes back no matter what tools you use, try TDSSkiller. Other handy removal tools include Malwarebytes and Superantispyware


 4.OpenDNS : You can consider changing your router’s default DNS servers to those maintained by OpenDNS. The company’s free service filters out malicious Web page requests at the domain name system (DNS) level. DNS is responsible for translating human-friendly Web site names into numeric, machine-readable Internet addresses. Anytime you send an e-mail or browse a Web site, your machine is sending a DNS look-up request to your Internet service provider to help route the traffic.
Most Internet users use their ISP’s DNS servers for this task, either explicitly because the information was entered when signing up for service, or by default because the user hasn’t specified any external DNS servers. By creating a free account at OpenDNS.com, changing the DNS settings on your machine, and registering your Internet address with OpenDNS, the company will block your computer from communicating with known malware and phishing sites. OpenDNS also offers a fairly effective adult content filtering service that can be used to block porn sites on an entire household’s network. This will be discussed later explicitly.


Tips from Krebsecurity



Monday, 15 October 2012

DomainSite to Check the Status of WhoIsHosting

Have you tried find who is hosting your site, how fast your website load ( efficiency of your web host), to determine if a site is down,how many other website is hosted on thesame I.P or check the integrity of your site and many more information you seek about a particular site?

There are a number of sites to check for this information, but i will only be discussing five (5) site which i personally like using but it also depends on the information  seek . I will start my most often used ;

1. Intodns :
 This shows the status of a site especially effective when troubleshooting on a particular site. It displays three range of colours  ( Red: Error, Blue: Average but not too important, Green : OK ) to depict the status of a setting from MX Records, Missing Nameservers, Recursive Queries, NS records from your nameservers etc. Its free to use

2. yougetsignal
This is another beautiful site (huh). It has tools to check open ports on your site, identify external IP address, find out who is emailing you, reverse email and ip domain lookup. Its free also

3. blamestella
This site has some unique features and its interface is very attractive which is very unusually to other DNS tool site. The site show the response time of your site ( this can be used to determine the efficiency of your webhost) , Size of the homepage, Platform of Server, Website Content, Vendor and many more. Signup to get better features.

4. DomainTools
This is the most commonly used DNS Lookup Site,  It displays Domain Servers, Website owner Address, Contact mail,. It also has the ability to Registrar History, NS History:
IP History, Whois History, but to get the full information on this you need to have an account with them.

5. Whois :
 Not much information is displayed but its quite effective. It shows similar domains to the site, Expirztion date of registration for the site, Name servers and whois.

Other Informations;
1. SiteUpOrDown
This an effective site to determine if a site is down or up.

2. SpamDistributor
To determine if your IP is a registered spam distributor. funny thing is you may not be the culprit, your ISP is mostly responsible for this. so if any list comes with a red mark, then you need to start taking drastic steps by informing your ISP about this.



Thursday, 27 September 2012

Tips to Speeding up Outlook

Is your Outlook configured as a Startup Application on your System? How long does it take to load it contents thereby slowing your work down.
Here are settings you can configure on your outlook, to speed up the boot time.

1: Repair with Scanpst

Scanpst is a effective tool that scans through your data file and look for data inconsistencies and errors. Scanpst comes mostly with the outlook during installation, locating it may be difficult, but searching through your C drive with the filename Scanpst.exe will make it easy. Before you run it ensure you backup your PST files because the tool can cause PST files to become unusable.

2: Download complete items

When you connect Outlook with either IMAP or POP3 (Messaging protocols), you should set your Outlook to download the complete message (instead of just the header). Doing this will prevent Outlook having to sync with the server every time you click on a new item (as it will already be in the data file.) On outlook 2007, you can do this from Tools - Send/Receive Settings - Define Send/Receive Group - Then click edit from the dialogue box that appears.

3: Reduce your published and shared calendars

The more you share, the more you drag the Outlook. The more data Outlook has to share and pull down from the Internet, the slower it will performs. Just know that the more data you have to push and pull, the slower your connection will be.

4: Archive your Inbox

Lots of people wait for their entire outlook to boot for mails 2 years ago to the current date, which can be time consuming and causing serious issues, especially when using PST files. Instead of just letting your Inbox grow out of proportions, set up an auto archiving so that your Inbox retains only a part of those mails. Better still leave only at most two month mail and archive the rest. Once you archive, you create a new data file, reducing the strain given to Outlook against the weight of an oversize PST or OST file.

5: Reduce add-ins or plugins

We install alot of programs, but what we do not know is that they end up installing other stuffs for other applications usage i.e Adobe or Foxit reader Plugins for Outlook. This can cause Outlook to slowdown. To find out what add-ins you have installed in Outlook 2007, go to tools - then Trust Center, on resulting window click on addins at the right side to list all add-ins available to Outlook. To disable , double click on the active plugins then click go below. From what comes up you can then decide which to disable by unchecking it.

6: Use Cached Exchange Mode

If you use Cached Exchange Mode in Outlook, you effectively take the data file from the server (PST) and cache it on your local machine (OST). This can go a long way toward speeding up your Outlook experience because Outlook doesn’t have to read its data file across a network. Instead, all it has to do is read the locally stored data file. This option only available when connecting Outlook with an Exchange server.

7. Regular Update of Windows

Make sure you allow Windows update even though updates for Microsoft Office are also hidden. Allowing the updates to happen can resolve issue with a patch to Outlook in resolving speed issue or security holes.

8: Compressing your PST file

Doing this will keep the size of that file under control.. One of the issues is that even when you delete email from your Inbox, the size of the PST file may remain the same. If you’re using Outlook 2007, goto Tools - Account Settings - Click on Data Folders - Then Settings, a dialogue box opens then click on compact now. The size of your data file, depends on how long the process can take .

9: Disable RSS

By default, Outlook will sync RSS feeds from Internet Explorer to the RSS reader in Outlook. If you have a lot of RSS feeds bookmarked in IE, that syncing could easily bring Outlook to slowdown. Disable this feature.On outlook 2007, goto Tools - Option - Other - Advance Option, look for Sync RSS feed on the list, then uncheck it.


Tips from TechRepublic

Tuesday, 31 July 2012

Portable Security Applications

Portable apps makes the work easier for Network Admins on the move, which are saved into your flash.  Below are some apps i consider a must have in my opinion;

1. Omziff : This is an encryption utility that can encrypt, split, and securely delete files (according to DOD standards), create file hashes, and generate random passwords. 

2. RemoveFakeAntiVirus: As the name implies removes any fake antivirus. This particular tool can be run as a portable app or, with the help of some scripting, can be saved on a drive and run on schedule or at bootup. Wonder why the designer choose a more obvious name?

3. Eraser portable: is a secure data removal tool that can remove data from a drive with multiple wipes, pattern writing, and you can instruct to shutdown or reboot a system.

4. Smaniff:   enables you to capture TCP/IP packets traveling on a network adapter and view the packets between source and destination making it easier for to troubleshoot the network but of course on every host individually.

5.Startup Lite: A very effective tool to disable apps that automatically runs once your syatem comes up.

6. BleachBit : for freeing up hard disk space and guarding privacy. This tool works effortlessly to free cache, delete cookies, clear Internet history, shred temporary files, delete logs, and discard various types of junk you may not have known was on a system.

 7. Kaspersky rescue-disk:  The is my best rescue CD. This is downloaded as an ISO image, but you can install it to flash drive to boot from USB.  

This is just my list, but you can make suggestions on what can be added.