Thursday, 8 December 2011
Tuesday, 6 December 2011
New Facebook Attack Aims to Infect PCs with Dorkbot Worm
New Facebook Attack Aims to Infect PCs with Dorkbot Worm
Facebook Attack Attempts to Infect PCs with the Dorkbot Worm Through the Social Network’s Chat System.
A new Facebook worm has its eyes on Windows PCs.This time, the idea is to infect users with the Dorkbot worm. Often spread via instant messaging, removable drives and compromised Websites, the Dorkbot worm opens a backdoor and allows remote access to an infected computer.
The Facebook attack appears to be spreading through the social network’s chat system. According to Sophos, a message that appears to come from a Facebook friend will include a link that may at first glance claim to point to Facebook.com, but in reality goes to a malicious site.
“Although an unsuspecting user may believe that they are clicking on a link to a JPG image, the truth is that they are downloading an executable file that attempts to download further code (another piece of malware) from the net and drops a .BAT batch file onto infected computers,” blogged Graham Cluley , senior technology consultant at Sophos. “The ultimate aim of all this malicious activity is to install the Dorkbot malware onto your Windows computer.”
Dorkbot has been known to spread via a variety of different social networks and instant chat systems in the past, Cluley told SecurityWeek. “Looks like the bad guys are using a variety of downloaders to initiate the attack on victims' computers, before ultimately taking them to Dorkbot,” he said.
Last week, security researchers discovered a separate worm on Facebook was infecting users with the notorious Zeus Trojan. In that case, the worm spread by sending direct messages that contained links to a screensaver of two women. If the user opened the screensaver, they would be hit with a flood of malware, including Zeus.
In response to the latest issue, Facebook spokesperson Frederic Wolens told SecurityWeek the company has numerous defenses in place to combat phishing and malware.
“We have internal systems in place configured specifically to monitor for variations of the spam and are working with others across the industry to pursue both technical and legal avenues to fight the bug,” he said. “Additionally, we are in the process of making changes to our Scan-and-Repair McAfee tool to help remove Dorkbot and its variants for users we have check-pointed.”
Sunday, 4 December 2011
Five hidden dangers of Facebook
Facebook claims that it has 400 million users. But are they well-protected from prying eyes, scammers, and unwanted marketers?
Not according to Joan Goodchild, senior editor of CSO (Chief Security Officer) Online.
She says your privacy may be at far greater risk of being violated than you know, when you log onto the social-networking site, due to security gaffes or marketing efforts by the company.
Facebook came under fire this past week, when 15 privacy and consumer protection organizations filed a complaint with the Federal Trade Commission, charging that the site, among other things, manipulates privacy settings to make users' personal information available for commercial use. Also, some Facebook users found their private chats accessible to everyone on their contact list--a major security breach that's left a lot of people wondering just how secure the site is.
In two words, asserts Goodchild: not very.
On "The Early Show on Saturday Morning," Goodchild spotlighted five dangers she says Facebook users expose themselves to, probably without being aware of them:
- Your information is being shared with third parties
- Privacy settings revert to a less safe default mode after each redesign
- Facebook ads may contain malware
- Your real friends unknowingly make you vulnerable
- Scammers are creating fake profiles
Below is an edited transcript of the interview.
Is Facebook a secure platform to communicate with your friends?
Here's the thing: Facebook is one of the most popular sites in the world. Security holes are being found on a regular basis. It is not as inherently secure as people think it is, when they log on every day.
Here's the thing: Facebook is one of the most popular sites in the world. Security holes are being found on a regular basis. It is not as inherently secure as people think it is, when they log on every day.
Certainly, there are growing pains. Facebook is considered a young company, and it has been around a few years now. It is continuing to figure this out. They are so young, they are still trying to figure out how they are going to make money. It is hard to compare this to others; we have never had this phenomenon before in the way [so many] people are communicating with each other--only e-mail comes close.
The potential for crime is real. According to the Internet Crime Complaint Center, victims of Internet-related crimes lost $559 million in 2009. That was up 110 percent from the previous year. If you're not careful using Facebook, you are looking at the potential for identity theft, or possibly even something like assault, if you share information with a dangerous person you think is actually a "friend." One British police agency recently reported that the number of crimes it has responded to in the last year involving Facebook climbed 346 percent. These are real threats.
Lately, it seems a week doesn't go by without some news about a Facebook-related security problem. Earlier this week, TechCrunch discovered a security hole that made it possible for users to read their friends' private chats. Facebook has since patched it, but who knows how long that flaw existed? Some speculate it may have been that way for years.
Last month, researchers at VeriSign's iDefense group discovered that a hacker was selling Facebook usernames and passwords in an underground hacker forum. It was estimated that he had about 1.5 million accounts--and was selling them for between $25 and $45.
And the site is constantly under attack from hackers trying to spam these 400 million users, or harvest their data, or run other scams. Certainly, there is a lot of criticism in the security community of Facebook's handling of security. Perhaps the most frustrating thing is that the company rarely responds to inquiries.
Do people really have privacy on Facebook?
No. There are all kinds of ways third parties can access information about you. For instance, you may not realize that, when you are playing the popular games on Facebook, such as FarmVille, or take those popular quizzes--every time you do that, you authorize an application to be downloaded to your profile that gives information to third parties about you that you have never signed off on.
No. There are all kinds of ways third parties can access information about you. For instance, you may not realize that, when you are playing the popular games on Facebook, such as FarmVille, or take those popular quizzes--every time you do that, you authorize an application to be downloaded to your profile that gives information to third parties about you that you have never signed off on.
Does Facebook share info about users with third parties through things such as Open Graph?
Open Graph is a new concept for Facebook, which unveiled it last month at its F8 conference. It actually is basically a way to share the information in your profile with all kinds of third parties, such as advertisers, so they can have a better idea of your interests and what you are discussing, so Facebook can--as portrayed--"make it a more personal experience."
Open Graph is a new concept for Facebook, which unveiled it last month at its F8 conference. It actually is basically a way to share the information in your profile with all kinds of third parties, such as advertisers, so they can have a better idea of your interests and what you are discussing, so Facebook can--as portrayed--"make it a more personal experience."
The theory behind Open Graph--even if it has not implemented it--is its whole business model, isn't it?
That is the business model--Facebook is trying to get you to share as much information as possible so it can monetize it by sharing it with advertisers.
That is the business model--Facebook is trying to get you to share as much information as possible so it can monetize it by sharing it with advertisers.
Isn't it in Facebook's best interest to get you to share as much info as possible?
It absolutely is. Facebook's mission is to get you to share as much information as it can so it can share it with advertisers. As it looks now, the more info you share, the more money it is going to make with advertisers.
It absolutely is. Facebook's mission is to get you to share as much information as it can so it can share it with advertisers. As it looks now, the more info you share, the more money it is going to make with advertisers.
Isn't there also a security problem every time it redesigns the site?
Every time Facebook redesigns the site, which [usually] happens a few times a year, it puts your privacy settings back to a default in which, essentially, all of your information is made public. It is up to you, the user, to check the privacy settings and decide what you want to share and what you don't want to share.
Every time Facebook redesigns the site, which [usually] happens a few times a year, it puts your privacy settings back to a default in which, essentially, all of your information is made public. It is up to you, the user, to check the privacy settings and decide what you want to share and what you don't want to share.
Facebook does not [necessarily] notify you of the changes, and your privacy settings are set back to a public default. Many times, you may find out through friends. Facebook is not alerting you to these changes; it is just letting you know the site has been redesigned.
Can your real friends on Facebook also can make you vulnerable?
Absolutely. Your security is only as good as your friend's security. If someone in your network of friends has a weak password, and his or her profile is hacked, he or she can now send you malware, for example.
Absolutely. Your security is only as good as your friend's security. If someone in your network of friends has a weak password, and his or her profile is hacked, he or she can now send you malware, for example.
There is a common scam called a 419 scam, in which someone hacks your profile and sends messages to your friends asking for money - claiming to be you--saying, "Hey, I was in London, I was mugged, please wire me money." People fall for it. People think their good friend needs help--and end up wiring money to Nigeria.
A lot of Web sites we use display banner ads, but do we have to be wary of them on Facebook?
Absolutely: Facebook has not been able to screen all of its ads. It hasn't done a great job of vetting which ads are safe and which are not. As a result, you may get an ad in your profile when you are browsing around one day that has malicious code in it. In fact, last month, there was an ad with malware that asked people to download antivirus software that was actually a virus.
Absolutely: Facebook has not been able to screen all of its ads. It hasn't done a great job of vetting which ads are safe and which are not. As a result, you may get an ad in your profile when you are browsing around one day that has malicious code in it. In fact, last month, there was an ad with malware that asked people to download antivirus software that was actually a virus.
Is too big a network of friends dangerous?
You know people with a lot of friends--500, 1,000 friends on Facebook? What is the likelihood they are all real? There was a study in 2008 that concluded that 40 percent of all Facebook profiles are fake. They have been set up by bots or impostors.
You know people with a lot of friends--500, 1,000 friends on Facebook? What is the likelihood they are all real? There was a study in 2008 that concluded that 40 percent of all Facebook profiles are fake. They have been set up by bots or impostors.
If you have 500 friends, it is likely there is a percentage of people you don't really know, and you are sharing a lot of information with them, such as when you are on vacation, your children's pictures, their names. Is this information you really want to put out there to people you don't even know?
Saturday, 3 December 2011
Password Protection: How to Create Strong Passwords
Every password you have is important. Every one. Here's how to make your passwords uncrackable.
We live in a password-driven world, where between four and 20 characters are the difference makers in whether you're able to access your data, communicate with friends, or make your online purchases. The problem is that passwords should be different everywhere you use them, and that can make it difficult to remember them all. And, if a password is truly strong, that makes it even more difficult. That's why we've put together this helpful password guide. Follow these tips and tricks to take total control of your terms for access.
Common Problems with Passwords
Use Different Passwords Everywhere
Why would you do this when it's so easy to just type "fido" at every password prompt? Here's why: If "fido" gets cracked once, it means the person with that info now has access to all of your online accounts. A study by BitDefender showed that 75 percent of people use their e-mail password for Facebook, as well. If that's also your Amazon or PayPal password and it's discovered, say good-bye to some funds, if not friends.
Why would you do this when it's so easy to just type "fido" at every password prompt? Here's why: If "fido" gets cracked once, it means the person with that info now has access to all of your online accounts. A study by BitDefender showed that 75 percent of people use their e-mail password for Facebook, as well. If that's also your Amazon or PayPal password and it's discovered, say good-bye to some funds, if not friends.
Remember the Underwear Meme
The saying goes like this: Passwords are like underwear. You should change them often (okay, maybe not every day). Don't share them. Don't leave them out for others to see (no sticky notes!). Oh, and they should be sexy. Wait, sorry, I mean they should be mysterious. In other words, make your password a total mystery to others.
The saying goes like this: Passwords are like underwear. You should change them often (okay, maybe not every day). Don't share them. Don't leave them out for others to see (no sticky notes!). Oh, and they should be sexy. Wait, sorry, I mean they should be mysterious. In other words, make your password a total mystery to others.
You can make your password sexy if you really want, however. I won't judge.
Avoid Common Passwords
If the word you use can be found in the dictionary, it's not a strong password. If you use numbers or letters in the order they appear on the keyboard ("1234" or "qwerty"), it's not a strong password. If it's the name of your relatives, your kids, or your pet, favorite team, or city of your birth, guess what—it's not a strong password. If it's your birthday, anniversary, date of graduation, even your car license plate number, it's not a strong password. It doesn't matter if you follow this with another number. These are all things hackers would try first. They write programs to check these kinds of passwords first, in fact.
If the word you use can be found in the dictionary, it's not a strong password. If you use numbers or letters in the order they appear on the keyboard ("1234" or "qwerty"), it's not a strong password. If it's the name of your relatives, your kids, or your pet, favorite team, or city of your birth, guess what—it's not a strong password. If it's your birthday, anniversary, date of graduation, even your car license plate number, it's not a strong password. It doesn't matter if you follow this with another number. These are all things hackers would try first. They write programs to check these kinds of passwords first, in fact.
Other terms to avoid: "god," "money," "love," "monkey," "letmein," and for the love of all that's techie, if you use "password" as your password, just sign off the Internet right now.
Saturday, 5 November 2011
THAKBEER

اللّهُ أكبر اللّهُ أكبر
اللّهُ أكبر
لا إلَهَ الا اللّه
اللّهُ أكبر اللّهُ اكبر
و لِلّه الحمدَ
اللّهُ أكبرُ كَبيِرَا
وَالحَمدُ لِلّهِ كَثِيرا
بُكرَةً وَأصْيِلا
لا إلَهَ الا اللّه
صَدَقَ وَعدَه
وَنَصَرَ عبده
وأعزَ جُنَده
وَهزم الأحْزَابَ وحْدَه
لا إلَهَ الا اللّه
وَلا نَعبُد الا أياه
مُخلِصِّينَ لَهُ الدّيِنَ
وَلوْ كَرِهَ الكَافِروُن
اللّهمَ صَلِّ على سيْدنَا مُحَمد
وَعَلى آلِ سيْدنَا مُحَمد
وَعَلى اصْحَابِ سيْدنَا مُحَمد
وَعَلى أنصَارِ سيْدنَا مُحَمد
وَعَلى أزوَاجِ سيْدنَا مُحَمد
وَعَلى ذُرِّيَةِ سيْدنَا مُحَمد
وَ سَلّم تَسْلِيماَ كَثّيرا
Subscribe to:
Posts (Atom)























































