Welcome Guest ( Log In | Register )

Computer Security, From NUK's Blog
nuk
post Mar 29 2005, 10:34 AM
Post #1


Frank Discussion
**********

Group: Member
Posts: 5,858
Joined: 20-January 05
Member No.: 2,232



I posted this yesterday to my blog and THOUGHT I also posted it here last night. It seems to have vanished so I am re-posting. I don't think it got deleted because Jason asked me to post it here:) One of those mysteries on the net, but hopefully it will go into the ether this time:)

If you are in the IT field, you have suffered extreme tortue by probably having to go to a few lectures or conferences on security. A dreary subject made all the worse by speakers who want to talk the *theories* of secured computing and a bunch of blah. Or vendor propaganda. This won't be near as dull, I promise!

Security for your home computer(s) is generally an afterthought until a nightmare happens to some unfortunate person you know or yourself. Then, it is suddenly a SERIOUS consideration, after the fact! Let's try and stop big-time problems before you have to learn the hard way.

Viruses? You should be so lucky! Everyone gets hyper about viruses but they generally just cause hours of headaches or a re-install at the worst. How about something that doesn't wipe-out your data, but instead steals it and your bank account and your financial life gets hijacked? I'm talking the worst threat out there, KEYSTROKE LOGGERS.

These little progs run invisible to you and don't cause an effect on your PC experience like crappy adware and malware. They can be directly installed on to your PC by someone else like your Dad or the IT geeks at work to monitor everything you do 24/7. Checking that bank acct at work? How about doing a little Yahoo mail to your mistress? Good chance that pimply dork known as the *network technician* is laughing his ass off at your private indiscretions or $2.87 bank balance. He's got your logins and passwords and he might decide to embarass you one day or even blackmail your ass. Say you're not that stupid to do this? Well, consider yourself one of the few. I have a keystroke logger in a corporation of a couple of hundred PCs and the employees of this corp have signed a statement acknowledging that those PCs are for WORK primarily and they ARE monitored. Plenty of employees still just do whatever the hell they feel like, seemingly oblivious to the fact they are monitored. A few got fired for spending 7.9 hours out of 8 watching porn streams and it took only about a week before married clowns are back sending emails to their action on the side or checking their bank accts. Duh!
So, unless you're the whole IT at where you work, forget about doing things with your ecurrencies or bank accts or anything you wouldn't want someone else having their hands on! Think your company is too small and no one there knows crap about computers so they aren't monitoring? Think again! I've put keystroke loggers on plenty of Mom and Pop style small businesses and showed them how to read the daily reports! I have seen my *efforts* I was paid for bring down people ranging from accounting temps to CEO's making mid-six figures to public officials like sheriffs and govt officials. DON'T BE STUPID!

OK, we got the #1 area where you can get seriously hosed at-your workplace-out of the way. Ignore the above at your own risk, Mr. or Mrs. It-Only-Happens-To-Other-Idiots! Let's secure your home PCs since that is the ONLY place you'll be doing anything financially or private, RIGHT? I thought so.

We are going to assume you are using Windows XP. Don't tell me about that stupid old saying about what *ass-u-me* really means. I ASSUME your intelligent enough to realize that around 90% of peeps out there are using Windows and that version would be XP. Mac and linux users, you know you have to use Windoze at times whether you want to or not so just shut up and listen for a while:)

You ARE using XP with Service Pack 2, RIGHT? You have Automatic Updates turned ON, RIGHT?Unless you have a funky custom application you use, get SP2. It's free. Contrary to what you may read, almost everyone who uses the standard stuff benefits from SP2 over not having it. I have installed SP2 on several thousand PCs since it came out in production, serious-as- hell-can't-go-down environments. Get it already! OK, maybe it won't run your 15 year old copy of WordPerfect for DOS. Move on.

1. If you are using IE as your main web browser, WHY? Do you enjoy all the bugs and serious security problems/updates? Get the Firefox browser (similar to IE) that is more secure, easier and better:
http://www.mozilla.org/products/firefox/
It has an option to automatically check for updates Think that might be something you would want to do? Hell yes! Even this much more secure browser will have holes discovered and upgrades so make sure you are using the latest and greatest, not something that three months had a problem.

2. Never go online without some sort of proxy. Proxies are a *middleman* between your PC and the big bad Internet. This goes *double* if you are browsing a lot of hyip or doubler sites. You trust those kind of admins with your information? I don't. One of the most popular options is the Metropipe tunnel (VERY secure - no one can see you at all). Metropipe is more then a proxy, its a tunnel...nothing in and nothing out of the secure tunnel.
http://metropipe.net
Easily configured to use with Firefox. Not that hard with IE if you follow instructions.
There are plenty of others that aren't expensive services. Stay away from the *free anonymous proxy servers* How do you know they are anonymous? How do you know they aren't what is called a *honeypot* that someone is using to gather your information(passwords people, passwords)from? Don't get cheap here. For $10 or less a month, you knock-out one huge privacy problem.

3. Use an encrypted(scrambled as opposed to plain old text anyone can read) and/or anonymous paid email service:
http://mailvault.com- free last I checked
http://www.safe-mail.net- same as above
http://katzglobal.net- not free but cheapo
This is getting real serious about security now! If you are doing the hanky-panky with your neighbor and you're married, this is a MUST. Don't leave evidence or your IP address around that is a great trail right back to you and your PC.

4. Get and use Roboform. It encrypts your ids and passwords so that if you got a keylogger, you are still protected! As a lot of keyloggers are accidently downloaded from websites, you might get one through your defenses. RoboForm or ShortKeys protects you even if you are infected.
http://roboform.com
They have a free trial version and I think u can use it with 10 logins/passwords forever. Excellent!

5. Firewall! If you are using DSL or broadband, you might not be aware that your router(that box that your connections go into) has a built-in firewall. It is not much to speak of but better than nothing if you use it. Make sure you pay attention to the instructions that came with your router about CHANGING THE DEFAULT PASSWORD!
Sorry, but leaving it as *admin* or *linksys* is an open-door to trouble.

Windows XP SP2 has a firewall. It's made by Microsoft so it's a half-ass firewall. If you don't like Windows constantly chiding you about not having it on, turn it *on* Some firewalls don't work with it *on* so you will need to read the instructions that come with the firewall you are going to get to better your security! Running two firewalls at the same time is usually a problem, BUT not a problem with

Agnitum! Excellent firewall and it will also run with XP's still on.
http://agnitum.com

Norton's or Macafee's firewalls? Don't get me started on how weak they are. ZoneAlarm is free and likely better than those two, but not near the toughness of Agnitum.

6. I use AVG anti virus. They have a free version.
http://www.grisoft.com/us/us_index.php
Let's put it this way: ANY antivirus is better than none. Most are about the same JUST KEEP THEM UPDATED! Stay away from *all-in-one* solutions that combine firewall, antivirus, spyware,etc. They may be simple and easy but don't cut it when you are surfing the dangerous wilds of doubler and hyip admins and using ecurrencies that people love to steal.

7. Spyware/malware/keystroke loggers/hijackers.
Too many to list. AdAware and Spybot are two real popular and free ones. I am probably the only dude that thinks that Webroot's SpySweeper is a clunker. As far as the paid ones, it is very popular but I find it to be very slow and misses too much. If you want to pay and get industrial-strength on spyware's sorry asses, go with Computer Associates' PestPatrol. For $30, it's worth it. Whether you are going the free or paid route, KEEP THEM UPDATED!

Last thing and this should be obvious: don't use the same login and password for progs you are in, gold accts, bank accts, etc.! Don't let a BAD THING like one login and password getting compromised turn out to be ALL your logins and passwords compromised! You got RoboForm now, you don't have to write down or remember this stuff!

How do you protect yourself from a stealin' egold or intgold employee on the inside from taking your money? Sorry, but that's always a possibility so make sure you don't let ecurrency linger in your accts. Get it the hell out of there ASAP!

Whew, security is a serious topic with a lot of areas to cover! I may have to charge *double* for this column. I hope you noticed one recurring theme here and that is whatever you have and use, KEEP IT UPDATED! New bad stuff appears daily and something a week out of date doesn't get the job done.

Do the above and you seriously will mimimize the chances of your egold acct getting emptied or someone deciding they would like to use your identity to open numerous credit card accts and buy some plasma TVs. And when your friends' ask about how secure it is to use a credit card on the net, ask them how secure is it to give your cc to some teenager in a restaurant or a convenience store clerk? Life is full of security risks, you just have to decrease the risks as much as realistically possible and accept that it will never be 100% fool-proof. It takes technology *experts* 6 hours of lecture time to make that basic point.
NUK
Go to the top of the page
 
+Quote Post

Posts in this topic
- nuk   Computer Security   Mar 29 2005, 10:34 AM
- - WTF   Yeah, I read your blog this morning. Thanx fo...   Mar 29 2005, 10:50 AM
- - investress   Tell me NUK how secure am I with my ZoneAlarmSecur...   Mar 29 2005, 03:23 PM
|- - nuk   QUOTE(investress @ Mar 29 2005, 04:23 PM)Tell...   Mar 29 2005, 06:25 PM
- - ASFx   I also really like webroot spy sweeper http://www...   Mar 29 2005, 06:51 PM
- - dantheman   I like the Avast Firewall + Antivirus Scanner. It...   Mar 29 2005, 07:00 PM
- - Student   ok... got the tunneler & the SSL bar... not su...   Mar 30 2005, 11:12 PM
|- - nuk   Yes. Tell Norton to shut up. Yes you can. ...   Apr 1 2005, 01:22 PM
- - investress   What do you say about a router with a hardware fir...   Mar 31 2005, 06:23 AM
|- - nuk   QUOTE(investress @ Mar 31 2005, 07:23 AM)What...   Apr 1 2005, 01:16 PM
- - RoleConfusion   huh metropipe now is cheap. 10% off if you pay wit...   Mar 31 2005, 10:15 AM
- - investress   Just buy it on your own   Mar 31 2005, 01:47 PM
- - RoleConfusion   QUOTE(investress @ Mar 31 2005, 01:47 PM)Just...   Mar 31 2005, 02:12 PM
- - Student   Sure wish metropipe's live support was open, l...   Apr 1 2005, 12:58 PM
|- - nuk   QUOTE(Student @ Apr 1 2005, 01:58 PM)Sure wis...   Apr 1 2005, 01:08 PM
|- - FinallyRetire   QUOTE(Student @ Apr 1 2005, 03:58 PM)Sure wis...   Apr 1 2005, 02:17 PM
|- - Mckinlie   QUOTE(FinallyRetire @ Apr 1 2005, 02:17 PM)I ...   Apr 1 2005, 03:15 PM
||- - FinallyRetire   QUOTE(Mckinlie @ Apr 1 2005, 06:15 PM)Do you ...   Apr 1 2005, 03:23 PM
||- - nuk   QUOTE(Mckinlie @ Apr 1 2005, 04:15 PM)Do you ...   Apr 1 2005, 03:35 PM
|- - Student   QUOTE(FinallyRetire @ Apr 1 2005, 03:17 PM)I ...   Apr 2 2005, 04:50 PM
- - RoleConfusion   i'm not able to download through the link they...   Apr 1 2005, 01:18 PM
|- - hynds   I'm using Symantec antivirus + Bitdefender pro...   Apr 13 2006, 01:10 AM
|- - urich   QUOTE(hynds @ Apr 13 2006, 11:10 AM) 1870...   Apr 19 2006, 04:02 AM
- - Student   Saved by NUK ! Thanks dude..   Apr 1 2005, 01:51 PM
- - ASFx   MMG did not get hacked. A moderator got his passw...   Apr 1 2005, 02:21 PM
|- - nuk   QUOTE(ASFx @ Apr 1 2005, 03:21 PM)MMG did not...   Apr 1 2005, 03:32 PM
- - investress   Tell me NUK how secure is proxy chaining?   Apr 1 2005, 03:59 PM
|- - nuk   QUOTE(investress @ Apr 1 2005, 04:59 PM)Tell ...   Apr 1 2005, 04:19 PM
- - oNLooKER   I've been an affiliate with MetroPipe for awhi...   Apr 1 2005, 05:51 PM
|- - FinallyRetire   QUOTE(oNLooKER @ Apr 1 2005, 08:51 PM)Am deci...   Apr 1 2005, 08:39 PM
|- - oNLooKER   QUOTE(FinallyRetire @ Apr 2 2005, 12:39 PM)MP...   Apr 1 2005, 08:42 PM
- - dantheman   Nuk, and other guys who have used tunellers.. oth...   Apr 1 2005, 08:56 PM
|- - nuk   QUOTE(dantheman @ Apr 1 2005, 09:56 PM)Nuk, a...   Apr 1 2005, 09:16 PM
- - investress   I was just googling and found some site where ser...   Apr 2 2005, 02:00 AM
|- - nuk   QUOTE(investress @ Apr 2 2005, 03:00 AM)I was...   Apr 2 2005, 12:30 PM
- - shoeb   Thanks Nuk for the detailed info. I would also l...   Apr 2 2005, 05:50 AM
- - Student   I'm gonna sound pretty dumb here but is MSN ...   Apr 2 2005, 04:39 PM
- - alexeow   Nice article, NUK.   Apr 2 2005, 05:30 PM
|- - Spacewebs   Very interesting thread you've started here, N...   Apr 2 2005, 06:21 PM
|- - nvisage   QUOTE(Spacewebs @ Apr 2 2005, 06:21 PM) 2...   Jan 30 2006, 09:23 PM
|- - vmax   QUOTE(nvisage @ Jan 30 2006, 09:23 PM) 10...   Apr 7 2006, 06:52 AM
|- - $ Maker   QUOTE(nvisage @ Jan 31 2006, 03:23 PM) 10...   May 19 2006, 02:30 AM
|- - minnow   QUOTE($ Maker @ May 19 2006, 05:30 A...   Jun 27 2006, 02:03 AM
- - investress   Thanks for your oppinion about proxify.com NUK I r...   Apr 2 2005, 07:22 PM
- - RoleConfusion   anybody know why i can't go to yahoo messenger...   Apr 5 2005, 10:31 AM
|- - nuk   QUOTE(moyeav @ Apr 5 2005, 11:31 AM)anybody k...   Apr 5 2005, 11:00 AM
- - cubchai   anybody uses *nix here? any tips on *nix's sec...   Apr 5 2005, 10:58 AM
|- - mssarath   QUOTE(cubchai @ Apr 5 2005, 11:58 AM)anybody ...   May 12 2005, 09:44 AM
- - dantheman   How many IP's are available per Metropipe / Se...   Apr 5 2005, 09:59 PM
- - mssarath   beautiful thread NUK   May 12 2005, 08:49 AM
- - WAEL ABBAS   hi all i want to know what is the different betw...   Jun 1 2005, 03:41 PM
|- - WAEL ABBAS   QUOTE(WAEL ABBAS @ Jun 2 2005, 02:41 AM) i u...   Jun 23 2005, 03:33 PM
||- - Miracle   QUOTE(WAEL ABBAS @ Jun 24 2005, 05:03 AM)i us...   Jul 9 2005, 11:59 AM
|- - mssarath   QUOTE(WAEL ABBAS @ Jun 1 2005, 04:41 PM)hi al...   Aug 6 2005, 01:44 AM
- - WAEL ABBAS   thanks   Jul 13 2005, 07:10 PM
|- - Miracle   QUOTE(WAEL ABBAS @ Jul 14 2005, 08:40 AM)than...   Jul 19 2005, 04:08 AM
- - shankey   hey nuk, I read the first post of this topic today...   Jul 27 2005, 10:34 PM
- - moneyman   Are you sure that your firewall doesn't block ...   Jul 27 2005, 11:05 PM
- - jayzee   what firewall program are you using? Make sure fi...   Jul 27 2005, 11:59 PM
- - hope333   QUOTE(WAEL ABBAS @ Jun 23 2005, 04:33 PM)i us...   Aug 9 2005, 07:58 AM
- - viperguy   Wh00t Metropipe accepts e-gold That's cool...   Aug 14 2005, 04:31 AM
- - cashsick   just a few question regarding computer securities...   Aug 14 2005, 09:01 PM
- - Marlena   I'm pretty sure if you download a keylogger yo...   Aug 15 2005, 01:25 PM
- - lamode   ive heard roboform before, and i was thinking to u...   Aug 20 2005, 11:41 AM
|- - Mutual Fund Admin   QUOTE(lamode @ Aug 21 2005, 03:41 AM)ive hear...   Aug 24 2005, 04:32 AM
- - Marlena   Try http://www.primedius.com for a proxy--might be...   Aug 21 2005, 05:44 PM
|- - lamode   thank you marlene for suggestions , i looked at so...   Aug 22 2005, 11:36 AM
- - midnightsun   Great thread Nuk. Thanks for the information. ...   Sep 18 2005, 09:53 AM
|- - Daisuke   hi Nuk the secure-tunnel thing seen nice i feel l...   Oct 3 2005, 07:55 PM
- - edgar   thanks a lot   Nov 5 2005, 04:30 AM
- - kelvin888   Mozilla is a package that include a browser and em...   Dec 7 2005, 04:58 AM
|- - nuk   QUOTE(kelvin888 @ Dec 7 2005, 05:58 AM)Mozill...   Dec 14 2005, 07:17 AM
|- - ASFx   QUOTE(nuk @ Dec 14 2005, 07:17 AM)Make sure y...   Dec 14 2005, 12:10 PM
- - surfbacon   QUOTE(nuk @ Mar 29 2005, 02:34 PM).... 3. Us...   Dec 16 2005, 06:28 AM
|- - nuk   QUOTE(surfbacon @ Dec 16 2005, 07:28 AM)What ...   Dec 16 2005, 07:06 AM
|- - surfbacon   Thanks for the info, NUK. Do you think that a PGP...   Dec 16 2005, 10:52 AM
|- - nuk   QUOTE(surfbacon @ Dec 16 2005, 11:52 AM)Thank...   Dec 16 2005, 08:30 PM
- - surfbacon   I was looking at an autosurf to try, but noticed t...   Dec 20 2005, 04:33 PM
- - Sincere.   Great info and research - thanks!   Jan 7 2006, 02:32 PM
|- - nuk   This is my latest configuration for security right...   Jan 9 2006, 04:16 PM
- - offshorefreedom   What's your next recommendation for Spyware, m...   Jan 29 2006, 03:36 AM
- - powerstar   wheres the link to your blog?   Mar 1 2006, 08:31 PM
- - geoseban   after i ran Panda,i can no longer copy/paste from ...   Apr 14 2006, 11:04 AM
- - OnlineAffiliateReview   Great Post! Thank you so much for the informa...   Apr 25 2006, 03:48 PM
- - optimist1419   If all you are running is basic anti-virus, you ne...   Apr 30 2006, 08:10 AM
- - gon2hunt   I use symantic anti virus and adAware and if i get...   May 3 2006, 08:51 AM
|- - bryian99   QUOTE(gon2hunt @ May 3 2006, 08:51 AM) 20...   May 13 2006, 08:31 AM
- - Hungry Hyippo   after i ran Panda,i can no longer copy/paste from ...   May 10 2006, 04:13 PM
- - pat139   Read your blog...interesting and informative on co...   Jun 8 2006, 07:12 PM
- - Indyan   I run Kaspersky Internet Security Suite + Webroot ...   Jul 5 2006, 05:29 AM
- - msfng522   Easy to made money online   Jul 5 2006, 08:58 PM
- - Mochu   Kasperskys communicats are torment for me. I can d...   Aug 31 2006, 03:59 PM
- - eiranis   I suggest the use of avast, has many functions lik...   Aug 31 2006, 06:59 PM
- - rob2v   Indyan its good i am use outpost firewall   Sep 30 2006, 07:35 AM
- - defellas   i have used f-secure and it works perfectly for me...   Oct 3 2006, 08:31 PM
- - twinklebell   i used to use mcaffee...real bag of crap.my e-gold...   Oct 17 2006, 05:02 AM
- - CactusMan   Kaspersky Anti-virus and Kerio Personal Firewall h...   Nov 4 2006, 01:32 PM
- - flowerpower   Well this is like Hebrew for me, it is hard to und...   Nov 21 2006, 01:47 PM
- - texas97   Wow! really nice thread here abt security. i ...   Nov 23 2006, 01:06 AM
- - D'arcy   thanks, this's very useful   Dec 15 2006, 06:20 AM
2 Pages V   1 2 >


Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Skin designed by IPB Forum Skins

MMG Sponsors



Advertise on MMG Today!


Advertisement

Your ad here



WeeklyDividend.com - Let Your Capital Grow






Advertisement


Message Boards and Forums Directory