Thursday, August 13, 2009

How To Prevent Attack Of File Binding

How to prevent attack of file binding?


Dear Friends,

We have told you what is file binding and now we are going to tell you how to prevent the attack of file binding as this will help you to know your file which you have collected from internet.

1. Always keep your anti virus updated.

2. Disable “ Hide Extension For Known File Types”

3. Use utility program like Registry Change Tracker.

4. Use a isolated folder in a different drive to stores downloads from internet

5. Always check the properties of the downloaded file before double click on it.


With Thanks

Urproblemmysolution Team

Saturday, August 8, 2009

How to understand your email id is spoofed




How to understand your email id is spoofed

Dear Friends,

We would request you to read it carefully as here you will find a point about a link on point no (2) and through that we have tried to tell you how to understand a dangerous link which is vulnarable to your computer as now a day the cyber criminals are not directly sending viruses due to strong antivirus programs but they are using links(url) to trap the netizens and spreading viruses and for that we would request you to read it be cautious.

Spoofed Email – Spoofing refers to email that appears to have been sent from someone other than the real sender. Virus writers and individuals who send junk email or "spam", typically want the email to appear to be from an email address that is not their own. Thus, the email cannot be traced back to the originator.

It is often impossible to know if you have received a spoof however to the careful observer there are several clues that help to separate a spoof from a legitimate communication.

Typically, you will know that your email has been spoofed if:

1) An email is from a commercial entity and the message requests that you provide your log in ID or your account will be suspended it is likely a spoofed email. Reputable commercial entities regularly contact their customers by email but they don't ask for log in ID because they already have it.

2) By highlighting links within the suspect email with the mouse cursor and to then looking at the status line at the bottom left of the screen. If the URL in the status line and the link your mouse is highlighting do not match up a spoofer is likely at work. Note that because JavaScript can be used to change the status line this method is not fool proof. Overall, this is a good technique because a lot of spoofers do not bother to use the JavaScript to change the status line.

3) You receive an email with a text file indicates a virus had been detected and removed/replaced

4) You receive a reply to an email from someone you never sent a message to

5) You receive an error message from a system administrator that you sent an infected file or that your message could not be sent to a particular user

6) You receive an email with a blank message.


With Thanks

Urproblemmysolution team

Tuesday, August 4, 2009

Fake SSL

Dear Friends,
Here is a good comment from one of our reader and we think that this will help our other readers to enrich their knowledge in this field and they will also be cautios in future by reading this. So thanks to Mr. Sitangshu for sharing his knowledge with us and as it is a good one we have decided to bring it before all of you in the main posting of our blog. Again thanks to Mr. Sitangshu and here is his comment for all:-


Blogger Sitanshu said...


There were some very interesting guidelines on this title. I still thought that you may like to mention to your visitors about "Trusted Sites".

Trusted Sites are those sites that have a trusted securities certificate. Companies like VERISIGN for example issue "Trusted Security Certificates". That certificate means that the site is protected by SSL (Secured Socket Layer). To obtain such a certificate "VERISIGN" company would thoroughly investigate the ownership and history of the site. Once the site has received such a certification, their clients could be rest assured that they are opening a "Original Site" and not a "Fake Site".

But the irony is that hackers have managed to find a flaw even with the way a browser could be fooled into clicking into a site that is not SSL certified.

During a MITMA (Man in the middle attack phase), an attacker could wait for a person to click on a site that has an SSL certfication. But that site is a bogus site (meaning the person sending the link inserted the trusted site certificate, but the really is not SSL certified" . It has a "Site name that contains a Proper SSL certified site name followed by a blank followed by the rest of the name which is "the complete fake site name".

FAKE SITE = GOOD SITE PARTNAME + NULL + FAKE SITE NAME

Browser stops reading at the NULL character

So when you click on the link with that kind of site name with a null character in the middle of the name followed by the fake site address, you are really conned into entering into a fake site that the browser could not catch. Here you start entering your personal data like credit card number etc. and you become a victim.

I tried explaining a difficult concept in a few words. For more clarity please visit this link on a recent news item...

http://www.msnbc.msn.com/id/32258426/ns/technology_and_science-security/

Please keep writing. We are all indebted to you and your blog.

Sitanshu

August 4, 2009 8:41 AM

Sunday, August 2, 2009

Microsoft's Guideline 2



What you should know about opening files from the Internet or e-mail

The most common way for computer viruses to spread is through files that you get from the Internet or e-mail. So before you download a file or click an e-mail attachment, consider:

Does that file have a virus?

You won't know unless you check. Make sure you have an antivirus program installed and that it is up to date and set to scan all incoming e-mail attachments and downloaded files. Keeping your antivirus program up to date improves its chances of catching the latest known virus.
If you do not have antivirus software installed, you should purchase and install an up-to-date antivirus program to help protect your computer. For a list of popular antivirus programs, see Microsoft Antivirus Partners (http://www.microsoft.com/security/partners/antivirus.asp).

What do you know about that e-mail attachment?

Before you open an e-mail message or attachment, consider:
Do you know and trust the sender of the e-mail message? If you get e-mail from a person or business you’ve never heard of before, you should be cautious.
Have you exchanged e-mail with this person before? If you get e-mail from someone you know but have never corresponded with, ask yourself if there is any reason you’re getting this message now—especially if the message has a file attachment or contains a link to a Web site.
Do you have any reason to expect e-mail from this person? If you are surprised to see e-mail from this person, be cautious about opening the message.
Does the message on the subject line make sense coming from the sender? If the subject line is just gibberish or nonsense, you’ll be safer if you delete the message.
If the answer to all of the questions above is no, it's probably best to delete the message.
If you know the sender of the message but the message looks suspicious, don't hesitate to send a message to the sender asking if they really sent the e-mail to you. It’s much easier to check before you open the message than it is to clean viruses off of your computer.

Can I trust every Web site?

Not every Internet neighborhood is safe. Be cautious of a Web site if

You were referred to the site by e-mail from someone you don’t know.
The site contains objectionable material, such as pornography.
The site makes offers that seem too good to be true. Is it just trying to lure you to the site?
You are asked to provide a credit card number but there is no indication that the Web site ensures its transactions is secure.
The site offers free membership but asks you to provide extensive personal information that does not seem necessary or that you do not want to provide.

More trustworthy sites tend to…
Be certified by an Internet trust organization such as BBBonline, TRUSTe, or WebTrust. Look for their logo on the site and click the logo to make sure it is authentic.
Provide a privacy statement that you can understand and that you are comfortable with.
Provide a way to contact the creator or organization—a physical location, phone number, e-mail address, or mailing address.
Have a clearly posted return policy (when applicable) that allows you to return the merchandise if you are not satisfied.
Offer proof of secure transactions, such as a statement that your credit card information will be encrypted, or a symbol in the browser status area that indicates the transaction is secure.

Is it safe to download that file?
You can help protect your computer by thinking carefully before you download a file.

Heed any warnings. When a Web site attempts to download a file to your computer, Internet Explorer will display a message about saving, running, or installing the file. If the message contains a yellow caution icon, then the file has been identified as a type that could pose a risk.
Make sure the message shows the file source (publisher name). If the publisher can't be identified, it is safer to delete the file unless you know for certain who created it.
Make sure you completely trust the Web site providing the file.
Make sure the file is something you requested or are expecting.

Consider the content. Picture, music, and plain-text files are less likely to be harmful. These file types have names that end with a three-letter extension such as .jpg, .gif, .mp3, or .txt. You should be very cautious with all other file types.

Microsoft's Guideline 1


How to Trust a Web Site.


How do you know which Web sites you can trust? Some Web sites request personal information that you would rather keep private, display advertisements you do not want to see, or expose your computer to software that contains viruses or other security threats. It's difficult to be completely certain, but there are a few key things to look for.

·
Is it certified by an Internet trust organization such as BBBonline, TRUSTe, or Web Trust?

Sites that display privacy certification logos have agreed to follow certain practices like providing a comprehensive privacy statement. If you read these statements, you should be able to determine what data the site collects and what the site does with that data (for example, share it with a third party or use it to display personalized advertisements). The certification does not mean that the site collects no data. It means that the privacy statement will tell you what data the site collects so you can decide if you want to use that Web site.

·
Is the site from an organization you know and already trust?

For example, it a vendor you have a positive ongoing relationship with or a widely recognized brand or institution that you trust? The site should provide a privacy statement or a Terms of Use statement. Reading these statements should make it clear what will happen when you use the site. If you are not comfortable with the terms or behaviors (for example, you do not want to be tracked or to see advertisements), do not use the site.

·
If you don't recognize the site, do you have other information to help you decide?

You should thoroughly research the site before using its services. Read the site's disclosures, ask friends and colleagues you trust, and search the Web for positive or negative articles about the site.

·
Does it ask you to provide sensitive personal data?

If you are asked to provide sensitive personal data (such as your password, social security number, credit card number, or bank information), only do so if there is a valid reason and if the site uses a secure method to collect this data. Look for a statement indicating this information will be encrypted or look for the golden padlock symbol in your browser status area to indicate that the information will be transferred using secure methods.

·
If it is a retail site, does it have a return policy?

When making a purchase on a Web site, verify that the site has a posted return policy and that the terms are acceptable to you.

Be cautious of a Web site if…

You were referred to the site by e-mail from someone you do not know.
The site contains objectionable material such as pornography.
The site makes offers that seem too good to be true. Are they just trying to lure you to their site?
You are asked to provide a credit card number without proof that the transaction is secure.
The site offers free membership but asks you to provide extensive personal information that does not seem necessary or that you do not want to provide.