Pages

Is the 'Printer' Virus Simply A Low Risk Malware or Is There More To It?

It was a fine Monday morning, but the office printers were not so fine! Printers started to behave erratically, spewing out pages with garbled text, till the paper ran out of stock. Soon the Internet buzzed with the news of a new printer virus, affecting businesses largely in the US, India, Europe, and South America. Even before analysts set themselves to their tasks, it was clear that this new virus is an innovation of yet another group of cyber criminals.

The creativity of malware writers seems to have touched new heights, with the discovery of 'Print Bomb'. Basically the printer bomb 'Trojan.Milicenso', is a new variant of an old Trojan, but the authors have modified it, just enough in its new avatar, causing it to discharge print outs by sending enormous print jobs to print servers.

The Trojan, once downloaded on the users' PC, drops a copy of executable 'Adware.Eorezo as.spl' file- Windows Printer Spool File- in the Windows printer spool directory. The spool directory includes copies of files that printers are supposed to print. It is to be noted that, even though there is a provision for users, to specify a custom spool directory, most PCs are configured by default to windows spool directory. Thus printers attached to computers, infected by this Trojan automatically print the contents of the .spl file, until the paper runs out.

On a quick analysis, it looks like a case of low risk malware that serves up advertisements by using resources and causing networks to slow down. But did it end there?

Delving a little deeper, it turned out that this Trojan 'Trojan.Milicenso', achieves its end by installing a "dropper executable", which creates a DLL file in the system folder. A DLL or dynamic link library is nothing but a group of programs. These programs could be commanded to perform communication with devices such as printers. In this case, the DLL was leveraged by the Trojan, to communicate with a printer. And the malware authors were careful enough to heavily encrypt the DLL file, making analysis hard; a proof, of increasing levels of professionalism, among cyber criminals.

Talking about, Adware.Eorezo, it redirects users to a French-language website, which is being lightly neglected, as a boon to paper salesmen. While this highly encrypted malware is being seen as red herring, in some quarters, that takes away the investigators attention from its lethality, and tries to fool experts into discarding it as low risk malware. And there are reasons that substantiate this line of thinking towards this 'still-to-be-understood' malware, which put in a nut shell, are:

- It is highly encrypted
- Uses multiple detection/check routines to disable detection and prevent analysis
- It exploits intimate details of OS
- It uses data files as executables

And while the limelight is still not off the printer virus episode, a new variant of the Trojan is already floating, modified further in the design of its executables, to avoid detection. The malware authors never seem to give up their ways. Hence, protection emerges as the only way out.

Talking about security solutions, to such malware and virus attacks, Cyberoam Unified Threat Management appliances offer comprehensive security to small, medium and large enterprises through multiple security features integrated over a single platform. It is the first UTM that embeds user identity in the firewall rule matching criteria, offering instant visibility and proactive controls over security breaches and eliminating dependence on IP Addresses. Its, Layer 8 [Identity-based security] Technology platform makes security simple, yet highly effective. Cyberoam, with its Extensible Security Architecture (ESA) and multi-core technology carries the ability to combat future threats for organizations' security. To read more about Cyberoam and the solutions it offers, visit http://www.cyberoam.com/


View the original article here

Enhance Your Family Computer's Protection With a Wireless N Router

The invention of computers and later on the establishment of the internet facilities have played a great role in improving the living standards of families. The internet has been one of the most reliable resource materials in the world today. Internet surfing is usually very fun and appealing especially while doing research on the internet. However as much as internet surfing is fun; it exposes the computing systems to different threats. These threats may include computer virus, botnets and even system hackers. Computing threats usually cause a great impact on the computer systems such that they cause a complete breakdown of the systems. This in turn results to loss of data and files saved in the computer. However with a Wireless Router device you can be able to protect your computing system and thus all your files are secured.

Computer crimes have recently been on the rise especially involving organizational computer systems. This is a situation whereby technicians corrupt the computing systems of other people and gain access to personal documents. This can be very risky especially in situations where the information saved in the files is highly sensitive. Data files such as integrity files require to be handled with high level privacy in order to protect the contents in the files. Security routers such as Wireless N routers are used to protect computing systems from hackers. Routers require being highly efficient and as such choosing the best router to protect your system is equally important.

Wireless routers play an equally important role of ensuring that Wi-Fi devices are used to connect to the internet without causing any damage to the devices. The security router acts as a firewall shield whose main role is usually to keep off threats from attacking the device. Wireless routers or 3G Router is highly advantageous while shielding the devices in that it does not require any manual settings. The router automatically sets itself according to the configuration of the operating system in the computer. Wireless N routers are used to shield all devices that are compatible with the Wi-Fi network devices. Such devices include iPods, gaming consoles, laptops and personal computers. Protecting these devices only requires the user to turn on the wireless router in their computing systems.

Wi-Fi router protection devices offer exclusive services to internet users. Some of the services include frequent updates on your internet and security reports. These reports are usually offered through the real time reporting feature in the devices. Users are frequently updated on the possible threats that their wireless routers have been able to keep off from attacking their systems. Setting up wireless N routers is usually a fastened and easy step to undertake. The first step includes making a subscription on the most convenient package for your system. Packages vary in terms of price and services offered in the package. Common packages in wireless routers include parental control packages, Anti-virus packages and intrusion prevention packages. Configuration of the wireless N router device in your system is usually aided by an internet based GUI.

Wi-Fi router devices are a vital requirement in family computers. This is due to the fact that these computers are used by several users and therefore are more prone to threats. The WIFI N Router comes with an internally built Anti-Virus software that also enhances their efficiency. These devices are also easily compatible with 3G internet.

NetGenie was established to provide quality and affordable WIFI Router for home and businesses of every kind. It also offers a wide range of products and services related to, Online Safety for Kids, Parental Control Router and many more.


View the original article here

How to Save Money on SSL Certificates

Any web site that exchanges personal information with the site users, such as an e-Commerce site, places themselves and their site users at risk of being hacked unless they use the Secured Socket Layer (SSL). SSL enables a secured, encrypted, connection between your web server and the user's browser.

SSL also requires an SSL certificate, which is purchased from Certificate Authorities who are in the business of verifying the identities of web site operators.

Given the environment we are dealing with, an internet populated by hackers and infested with malware and exploits, the costs of SSL certificates are well worth it. However, if you operate many sites that require SSL the costs can addup. Since Certificate Authorities charge per year, the costs will only accumulate over time.

How can you save money on SSL Certificates?

Consider the level of site verification that you need

When you purchase an SSL certificate you can choose between basic "Domain Validated" Certificates and Enhanced Verification (EV) certificates.

Both types are "signed" by a third party Certificate Authority. This means that a site visitor's browser receives information required to check with the third party Certificate Authority and verify that the message was sent from the actual site owner.

However, the Domain Validated certificates only verify that the site is owned by the sender of the certificate. They do not consider the other factors such as the integrity and reliability of the site owner. The Certificate Authorities go through a much more rigorous verification process to ensure that the site visitor is not dealing with a dangerous situation.

Now, you know that you are reliable and on the level so you might want to save some money and go with the cheaper basic certificates. However, there are hacking techniques that can compromise Domain Name Servers to obtain fake Domain Validated certificates and redirect users to another site.

In addition, consider that that the point of these certificates is to assure the site user. Consider the value the EV certificates have in building customer trust and confidence. How do you put a price tag on that?

If your site is important to your business and accessible through the public internet you should go for the SSL certificates that offer the highest level of verification.

Comparison Shopping

One of the benefits of the internet is that it is very easy to comparison shop. If you do, you will find that the price of SSL certificates vary widely. The oldest and largest Certificate Authority, VeriSign, is relatively expensive.

Many other Certificate Authorities offer comparable certificates at lower prices. Verisign SSL certificates start at over $200 while there are comparable certificates available for under $50.

Consider Long Term Discount Plans

Certificate Authorities will discount the annual cost if you sign-up for multiple years. If you are a "going concern" this option could save you some money.

Do you have sub domains?

If your web sites need SSL for sub domains you can save money with a Wildcard SSL. One wildcard SSL can be purchased that will cover a site and all its sub sites.

For example, you can apply one wildcard SSL that covers peanutbutter.com, crunchy.peanutbutter.com and smooth.peanutbutter.com.

Do you have multiple domains and host names?

Unified Communications (UC) SSL certificate can be applied to multiple domains and host names. A single UC SSL certificate can be used for a primary domain and up to 99 alternate names. For example, Microsoft Exchange and Microsoft Live servers operators find they can save a lot of money with UC SSL Certificates.

Isn't free the best price?

You may notice that there are free SSL Certificates available. These are tempting because they offer the same secured, encrypted communication provided by other Certificates.

What's the catch? There is one of two possibilities.

Either it is being offered for a limited trial period or it is an "unsigned SSL Certificate".

You can always go with a trial offer without harm, but you need to be looking at your long term solution.

However, beware of the unsigned SSL Certificate. If used in the wrong situation they can be penny wise and very pound foolish.

Unsigned SSL Certificates do not do the third party verification. They still leave the site visitor open to some scams where hackers trick users into thinking they are connected to one site and they are actually communicating with another

Unsigned SSL Certificates, like Domain Verified Certificates are best deployed on internal, intranet sites. They are great for test labs and sites inside your corporate firewall, but if you are dealing with the public on the web the risks are too great.

Carefully consider your needs, then compare SSL certificates offered by the Certificate Authorities for one that is most appropriate for your site. Whenever appropriate use UC and Wildcard certificates.


View the original article here

Who Do You Trust? Firewalls


View the original article here

Are You a Victim of DNSChanger Virus?

If you are among those who think they are affected by DNSChanger virus, do not panic. There are measures that you can take so that you can successfully sail through the problem.

Why is there so much fuss about DNSChanger?

The DNSChanger virus has been designed by cyber criminals to redirect users through fraudulent servers for the purpose of accessing private or confidential data. A DNS (Domain Name System) is essentially a free Internet service that converts the domain name into the numeric Internet Protocol (IP). There are chances that you may also unknowingly download this virus from illegitimate sites.

A very interesting thing to note here is that this virus actually surfaced in the year 2007 and since then it has gone on to affect 40 lakh computers worldwide. The DNSChanger Virus is so deadly that once it finds a way into your system, it will paralyze the antivirus software already installed in your computer. Moreover, it will also prevent you from visiting any website and download the best antivirus protection software that you can use to protect yourself from future virus attacks.

How to Identify the DNSChanger Virus?

You can only secure your computer system from DNSChanger Virus only if you are aware about the various signs that you are infected. A large number of experts and cyber security firms have devised very important tools or websites through which you can detect whether your computer has been infected or not in a very hassle free manner. Here are links of the various websites that offer free diagnostic checks against this nasty malware:

Malware Check: dns-ok.us

DNSChanger Working Group: dcwg.org

FBI: forms.fbi.gov/check-to-see-if-your-computer-is-using-rogue-DNS

McAfee: mcafee.com/dnscheck

How to Remove DNSChanger Virus?

If it is detected that your system has been affected by the DNSChanger malware, then the very first step that you must take is to take the backup of all the critical files in an external hard drive or a pen drive. After taking the back up, you will be required to reformat your system. However, if in case, you are lucky enough to escape from this virus, then you must ensure that you take more precautions to protect yourself from future attacks. You can certainly avoid this situation by getting excellent antivirus protection and scanning the computer on a regular basis. It will be also best to call out the Internet provider and request them to get your DNSChanged.

So, if you have been lucky enough to not have been affected by DNSChanger Virus, then you must not waste time, make sure you have a best antivirus software installed, scan your computer on a regular basis before this virus spells doom for you.

Get the best anti-virus protection software download from reliable websites and protect your system from malicious programs. There are many websites available on the Internet to download free anti virus software.


View the original article here

Related Posts Plugin for WordPress, Blogger...