Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, February 16, 2009

Web Security

You are offering your IP address to the entire world at this very moment.

Make sure you are not offering access to your private data at the same time.


YOUR IP ADDRESS IS PUBLIC

Accessing the Internet is a security risk.

When you are connected to the Internet, an IP address is used to identify your PC. If you don't protect yourself, this IP address can be used to access your computer from the outside world.

A fixed IP address is a larger security risk.

If you're using a modem with a dial-up connection, you will get a new IP address every time you connect to Internet.

With an ADSL or cable connection users sometimes keep the same IP address for several months, this represents an increased security risk.

If you have a fixed IP address, you give potential Internet crackers all the time they need to search for entrances to your computer, and to store and share (with other crackers) information they might find about your unprotected private data.


Your Network Shares

Personal computers are often connected to a shared network. Personal computers in large companies are connected to large corporate networks. Personal computers in small companies are connected to a small local network, and computers in private homes often share a network between family members.

Most often networks are used to share resources like printers, files and disk storage.

When you are connected to the Internet, your shared resources can be accessed by the rest of the world.


A Common Windows Security Problem

Unfortunately, many Microsoft Windows users are unaware of a common security leak in their network settings.

This is a common setup for network computers in Microsoft Windows:

  • Client for Microsoft Networks
  • File and Printer Sharing for Microsoft Networks
  • NetBEUI Protocol
  • Internet Protocol TCP/IP

If your setup allows NetBIOS over TCP/IP, you have a security problem:

  • Your files can be shared all over the Internet
  • Your logon-name, computer-name, and workgroup-name are visible to others.

If your setup allows File and Printer Sharing over TCP/IP, you also have a problem:

  • Your files can be shared all over the Internet

Computers that are not connected to any network can also have dangerous network settings because the network settings were changed when Internet was installed.


Solving the Problem

For Windows 2000 users:

You can solve your security problem by disabling NetBIOS over TCP/IP:

  • Open Windows Explorer
  • Right-click on My Network Places
  • Select: Properties
  • Right-click on Local Area Network
  • Select: Properties
  • Select: Internet Protocol TCP/IP
  • Click on Properties
  • Click on Advanced
  • Select the WINS tab
  • Select Disable NetBIOS over TCP/IP
  • Click OK

If you get the message: "This connection has an empty......", ignore the message and click on YES to continue, and click OK to close the other setup windows.

You should restart your computer after the changes.

For Windows 95, 98, or ME users:

You can solve your security problem by disabling NetBIOS over TCP/IP:

  • Open Windows Explorer
  • Right-click on My Network Places
  • Select: Properties
  • Select: Internet Protocol TCP/IP
  • Click on Properties
  • Select the NetBIOS tab
  • Uncheck: Enable NetBIOS over TCP/IP
  • Click OK

You must also disable the TCP/IP Bindings to Client for Microsoft Networks and File and Printer Sharing:

  • Open Windows Explorer
  • Right-click on My Network Places
  • Select: Properties
  • Select: Internet Protocol TCP/IP
  • Click on Properties
  • Select the Bindings tab
  • Uncheck: Client for Microsoft Networks
  • Uncheck: File and Printer Sharing
  • Click OK

If you get a message with something like: "You must select a driver.........", ignore the message and click on YES to continue, and click OK to close the other setup windows.

If you still want to share your Files and Printer over the network, you must use the NetBEUI protocol instead of the TCP/IP protocol. Make sure you have enabled it for your local network:

  • Open Windows Explorer
  • Right-click on My Network Places
  • Select: Properties
  • Select: NetBEUI
  • Click on Properties
  • Select the Bindings tab
  • Check: Client for Microsoft Networks
  • Check: File and Printer Sharing
  • Click OK

You should restart your computer after the changes.

Monday, February 2, 2009

Catching Your Website Contents Thieves

I know the word "Thieves" is not new to us. Their activities did not start today but from the Stone Age by taking what did not belong to them without permission or by force. You will agree with me that as the technology is improving so their techniques get sophisticated. Online theft is not only in the area of credit cards or affiliate money or hacking to download secret or paid information but also website contents.

Why Website Contents?

Have you ever wondered why people visit some websites than others? What make them to come back and even introduce their friends, colleagues, etc to visit the sites? Do you think it is the website designs or image pictures? You will agree with me it is not flash or animated pictures but the answer is contents. Website content is the "King", it drives traffic to the site, makes visitors to come back and introduce others. Because some webmasters have known this, they go to any length to get good website contents. They steal contents (contents, graphics images, codes, video files, etc) from other people sites.

How To Catch Web Contents Thieves?

It may be difficult to start searching through million of websites to know whether your contents have been stolen, off course if you do, it may take you a month or more or you get frustrated. Search engines are the answer. Go to the popular search engines like Google.com, Yahoo.com, etc and following the steps below.

(a) Type your website name to search engine box. You will be able to know how many sites that link to you. Search through these site and see whether they have taken your contents without given reference to you.

(b) Type your company name to search engine box. Search through the sites that appear and find out whether they use your content without permission or reference to your site.

(c) Type your unique graphic name, for most Webmaster will just take image without editing the name.

(d) Type your article titles or headlines to search engine box and it will reveal the sites that are using your articles. Check whether they give reference to your website by linking to you.

How To Locate The Thieves?

(i) Using domain lookup: Who is? : Is a tool use to view the owner's or company's name, postal address, e-mail address and phone number of registered domain name. You can simply type Whois.com to a web browser address space and lookup for the owner of the offender website. Also, go to Google.com, type domain lookup in its search box. This takes you to many websites that enable sourcing the owner of domain name.

(ii) By checking the contact address, email address and phone number on the offenders website.

Contact The Offenders.

Having known their contact information? Contact them by sending mail or make call or both to let the offenders know that they have used your website contents without approval. Tell them to remove the contents or they should acknowledge you by putting your website link.

Protect your Website Contents.

(a) You can protect your contents by putting copyright on each page of your website.

(b) By using code or software that will prevent your graphic image from being saved.

Friday, January 30, 2009

6 Ways To Pick Better Passwords

Everyone who uses the internet must user usernames and passwords and that’s just the way it is. Whether it’s for email, instant messaging or any web site that has authentication of any type, passwords are par for the course.

Years ago most people would have only a handful of usernames and passwords to remember, but with the explosion of social media, online video/audio/photo/file storage and so on, many people have 15 or more.

The way most people get around this is to the use same username/password for all their accounts. This is stupid because if one system you use is compromised where your authentication information is found, all your stuff is then "in the open", so to speak.

I’ll cover how to choose passwords that can be different yet remembered by you easily in the list below.

1. Avoid repeating characters

Example: cccrazylikeafox

The "ccc" is the repeating set of characters. Don’t do this.

2. Use mixed case

Uppercase: CRAZYLIKEAFOX

Lowercase: crazylikeafox

Mixed case: CraZylIkeAfOX

3. Use mixed case letters and numbers

Example: 27CrAzylIkeAFox93

4. Use other characters (if allowed)

Example: 27-C_rA:zy#lIkeAF#

Note: Some web sites don’t allow this (but they all should).

5. Let a password manager choose the password

Example: Use KeePass Password Safe

Example screen shot:

image

Yes, the above is a crazy password, but that’s the whole point. With 183-bit quality it would be extremely difficult for anyone to find out what it is.

And obviously you should use the password manager software to remember it for you - encrypted, of course.

6. Use a random physical address

This actually does make for fairly good passwords.

Go to Google Maps, pick a town and state that you don’t live in (nor have you ever), type in a type of business and use its physical address as your password.

Example: I choose Boise, Idaho. I’ve never been there and have never set foot in that state. Then I type restaurant and find a place called Elmer’s. The physical address is 1385 S Capitol Blvd.

The password would be written as 1385SCapitolBlvdBoiseID.

According to KeePass Password Safe, this is a 114-bit quality password and well into the "green", which is pretty darned good. The fact it’s also 23 characters long and contains letters of mixed case and numbers also helps out quite a bit.

image

To note: You will remember this easier than trying to come up with random words and phrases, because more often than not there are time you have to commit physical addresses to memory just trying to get to places - so this is nothing new to you.

I will note again that if you choose to go with this method, pick locations you’ve never been to.

Was there anything I missed concerning better passwords?