9/15/09
Test Computer for Installed KeyLoggers
Today’s keyloggers are smart. They have the capabilities to hide themselves deep into your software applications and operate from there. And they are easy to install and control for a remote person, thanks to some careless attitude of many of the victims.
How to check, if your computer already has a Keylogging Software installed?
Many of the Security Software suites available today are able to detect most of the common keylogging software. As soon as some keylooger is attempted to be installed on your system, your security suite warns you about that and you can take appropriate action.
But, are you sure that your security software is capable of identifying keylogging activities? There is a simple test software available from Zemana, which lets you simulate a keylogger on your computer. You can download it absolutely free and run it on your computer. If your security software is able to detect it, then you may be confident about the effectiveness of that against keyloggers, otherwise it is time to have a second look at your choice of security software.
My Testing of Zemana
I have been using Norton 360 on my Laptop and it was not able to intercept this keylogging simulator software. But at the same time, I am also using KeyScrambler, which encrypts the data you enter through your keyboard. I was happy to note that all the text, which Zemana Keylogging Simulator could cpature was the encrypted text and not the actual keystrokes.
Thus, KeyScrambler was actually performing its job quite effectively and I was protected against such Keylogging activities.
Nice tool, and I recommend you to give it a try to test, if any keylogger is installed onto your system. You never know, when huge surprise start staring on your face.
Download Zemana Keylogging Simulator Test
4/23/08
10 Anti-Phishing Firefox Extensions
The damage caused by phishing attacks ranges from loss of access to your web account to identity theft. Once the personal information is obtained, the phishers may use one’s details to steal money, create fake accounts etc.
One popular way to combat phishing attacks is to maintain a list of known phishing sites and to check web sites against the list. This hack highlights 10 anti-phishing Firefox extensions that can be used to mitigate the risk of being a victim of a phishing attack.
PhishTank SiteChecker - SiteChecker blocks phishing web sites based on data from the PhishTack community. When you visit a web site known to PhishTank as a phishing web site, SiteChecker will display a block page instead of the phishing web page. Download PhishTank SiteChecker.
Google Safe Browsing - Google Safe Browsing alerts you if a web page that you visit appears to be asking for your personal or financial information under false pretences (phishing web sites). By combining advanced algorithms with reports about misleading pages from a number of sources, Google Safe Browsing is often able to automatically warn you when you encounter a page that’s trying to trick you into disclosing personal information. Download Google Safe Browsing.
WOT -WOT helps you steer clear of online fraud and phishing web sites, by allowing you to see web sites reputations on your browser. By knowing the reputation of a web site, it becomes easier to avoid accessing phishing web sites. The reputations are taken from testimonies contributed by the WOT community. Download WOT.
Verisign EV Green Bar - This extension adds extended validation certificate support to your browser. When you access a secure web site, the address bar turns green and displays certificate owner and certification authority. This extension is extremely useful to determine whether a web site is phony. Download Verisign EV Green Bar.
iTrustPage - iTrustPage prevents Internet users from filling out untrustworthy web forms. When visiting a web site that has a web form, iTrustPage computes the TrustScore for the form page. When the score is high, iTrustPage deems the web page as trustworthy; otherwise it is untrustworthy. Download iTrustPage.
Finjan SecureBrowsing - Finjan SecureBrowsing checks links in search results and websites and warns you of potentially malicious links. It performs real-time code analysis of the current content on each web page. It detects potentially malicious code and undesirable behavior. Each link is marked as safe (green) or potentially dangerous (red). Download Finjan SecureBrowsing.
FirePhish - FirePhish warns you whenever you surf to a site which is known as a phishing site or has suspicious characteristics. Download FirePhish.
CallingID Link Advisor - CallingID Link Advisor verifies that links you see are safe before you follow them. When the mouse is placed over any link, a risk assessment and the full details of the site owner are displayed, helping you decide whether the site is trustworthy. CallingID Link Advisor also warns you of links to sites that are known as phishing sites. Download CallingID Link Advisor.
SpoofStick - SpoofStick makes it easier to spot a spoofed website by prominently displaying only the most relevant domain information. Download SpoofStick.
TrustBar - TrustBar allows users to assign a favorite name or logo for each web site. This makes it easy to detect fake, cloned sites, from phishing, spoofing, pharming and other attacks. Download TrustBar.
3/27/08
Phishing Countermeasures
Just as successful phishers have turned to a distributed, multi-tiered system of attacks, so must institutions and consumers rely on a distributed, multi-tiered and layered defense in order to protect themselves. There is no silver bullet solution to defeat phishing; instead, a variety of technical and social techniques must be employed.
User Education
One key element of the war on phishing, and of information security in general, is consumer education. After all, if potential victims could be convinced to inspect email headers, to verify URLS, and not to reveal their personal and financial information to phishers, then the problem would just go away. However, education is not a sufficient answer in itself; con men have been running the same scams via Internet, telephone, and postal mail for ages. Yet many consumers are eager to learn how to protect themselves from online fraud. Savvy ones will learn if they are taught how to protect themselves. User education can be an inexpensive yet high-profile way to decrease fraud while convincing customers that their trust is important to a business.
Email Authentication
An important technical countermeasure to phishing is for businesses to implement an email authentication technology like SenderID or Domain Keys Identified Mail (DKIM) on their email systems. Since no authentication is supported by Simple Mail Transfer Protocol (SMTP), the dominant standard for email transmission, it is very easy for attackers to send spoofed email messages that appear to have originated from a legitimate domain. Designed to combat this, DKIM is an email authentication system that can verify the domain of an email sender and the message integrity. SenderID is an extension to SMTP that allows email servers to identify and reject forged addresses based on entries in DNS records. In essence, using DKIM and SenderID discourages phishing because they make it difficult for a spammer’s email server to masquerade as a legitimate email server, such as that of a bank or other financial institution. Since DKIM and SenderID are complementary technologies, it is ideal for businesses to implement both if possible.
Consumer Reporting
Phishing threatens every company and consumer who uses the Internet, and because of this, many users are eager to help by reporting suspected hoaxes. This is often the most successful method of identifying phishing sites. Potentially targeted companies should make it easy for consumers to report phishing and other methods of Internet scams: every company should have a link on its home page to a web form where anyone can easily report suspected fraud. In addition, every company should have a publicized email account that allows users to easily forward possible phish emails.
Anti-phishing Solution Deployment
Institutions must be proactive in order to defend their brand, reputation and customers from the threat of phishing. There are many components to an anti-phishing solution, including preventing the establishment of cousin or mock domains, detection and analysis of attacks, and technical and physical shutdown of phishing sites. Some solutions try to prevent phishing from occurring by authenticating and filtering email. Others filter web content through consumer products such as browser toolbars. Most anti-phishing solutions rely on an Internet data center that collects, analyzes, and responds to threats. Many rely on consumers to report phishing email and phishing web sites, and then target those email and web servers for shutdown. Anti-phishing solutions must offer this full range of services in order to defeat a phishing attack in a timely manner.
Phishing
This form of fraud has become an unfortunate and thriving economic reality. Online phishing can be traced back as far as 19961 and has escalated swiftly: the number of unique phishing web sites detected by the Anti-Phishing Working Group rose to 55,643 in April 2007, a massive jump from March’s 20,8712. Similarly, PhishTank (a collaborative clearinghouse for data and information about phishing) received 53,263 submissions of suspected phishing sites in May 2007, of which 43,789 were verified.3 A more accurate measurement of phishers’ activities is the number of corporate brands attacked. According to the MarkMonitor Brandjacking Index™, a quarterly report that measures the effect of online threats to brands, the number of brands phished each month reached an all-time high of 229 in March 2007.
Phishing is a serious threat not only to consumers and companies but also to the general perception of the Internet’s suitability for business transactions. A recent poll of 2,120 American adults conducted by the Wall Street Journal and Harris Interactive confirmed online businesses’ worst fears: 30 percent of those polled said they limit online transactions, and 24 percent limit online banking transactions.
Of particular cause for alarm is the growing threat presented by the Phish Gang, a formidable twist on the standard phishing scheme that has garnered tremendous amounts of money for its perpetrators. They are clearly not an average group of thieves, but rather a sophisticated international crime syndicate that has a talented IT staff. By exploiting high-availability practices to achieve system redundancy and horizontal scaling, and relying on a geographically dispersed system, the Phish Gang has developed a methodology that makes them very difficult to defeat using standard anti-phishing measures. Ironically, their success relies on many of the information technology best practices that legitimate companies use to ensure business continuity.
The Typical Phish
In a typical phishing attack, the perpetrator sends out enormous amounts of spam (unsolicited commercial email) including links to fraudulent web sites that are under the control of the attackers. This means that the first step of a successful phishing attack is to evade recipients’ spam filters. Anyone with an email account has been inundated by spam in recent years, and phishers rely on the fact that as spam filters analyze billions of emails a day, dangerous ones can slip by. The phishing email must look legitimate enough that the victim believes it is a genuine communication from a legitimate business. In addition, the phishing email has to entice the victim to act on it (and hand over personal information), perhaps by reporting a fake transaction that needs to be cancelled or requesting account maintenance. Thus, phishing is not purely a technology problem: it is a combination of social engineering and technology prowess. Though phishers rely on technology to carry out their attacks, consumers must take the bait
and then voluntarily provide sensitive information for attacks to succeed.
When a victim is persuaded to act by a phishing email, he connects to a fake web site by clicking on a link in the email. A web browser window opens and takes him either directly or through a series of redirects to the spoofed (fraudulent) web site. Once the victim arrives at the web site, he is presented with a web page that looks like a legitimate company page; usually these pages contain mock corporate logos, privacy policies, and links to report fraud. The victim then fills in his personal information, which is transmitted to the attackers or stored in a text file on the server. Typically, the attacker sells the information to other criminals who then engage in fraudulent transactions.
The fake web site is normally hosted on a compromised web server, one which has been exploited by the phishing attacker for this purpose. The attacker may also use rapidly provisioned free web space, such as that provided by a social networking site, which is usually untraceable; although that is becoming less common. The URL pointing to the fake web site usually contains some wording that impersonates the organization being attacked. For example, if the attacker has compromised the server at http://www.site.com, he may then send victims to http://www.site.com/bankname.com where "bankname" represents the institution being impersonated. This fools naive users, who quickly scan the URL for "bankname" and when they see it, decide that the link is legitimate.
There are a number of variations on this theme. Phishers may use the IP address of the server to further confuse victims. They may also go so far as to register fake domain names, which are typically a variation of the legitimate institution’s domain name, such as securesite.com, and then create a sub-domain that typically includes a variation of the legitimate institution’s domain name, such as: http://www.bankname.securesite.com/.
Recently study shows that Phish Gang has employed several techniques that make them more difficult to defeat than other phishers. In an elaborate, multi-tiered scheme, they use the stolen credentials of their victims to register multiple domain names at multiple registrars. These domain names are usually short and meaningless, such as "342egt.info". The gang then hosts their own authoritative DNS servers using wildcard "A" records to provide name-to-IP service for each of the fraudulently registered domain names. The IP addresses used (and there may be upwards of 100 at a time) point to multiple compromised PCs. These PCs are part of a botnet, which act as proxy connections to a handful of servers that host phish pages of up to 20 fake web sites at a time.
Challenges Presented by Phishing
The difficulty of preventing this technique is that each layer of the phisher’s infrastructure (DNS, proxy server, back-end server) contains redundancies and variations. The advantage to phishers of implementing a distributed architecture is that attacks can continue unfettered when any one element of the system is shut down: a traditional phishing site can be defeated by removing the hosting web site or domain, but Latest Phish sites share hosts and domains; if one is removed, the site automatically switches to another.
It is extremely difficult to track Phish attacks all the way through to the back-end server. The rapid cycling through domain names and IP addresses makes them appear to be always on the move and leaves much of the international security community in a quandary; the Phish Gang seems to be able to bring up countless combinations of multiple tiers in their attacks. This matrix of sites provides a robust system with many levels of failover. If a domain server is taken down, then name-to-IP services failover to another domain server. If a proxy server running on a compromised host is taken down, then the proxy services failover to another compromised host. Although they will typically only be using 10 to 20 such hosts at a time, the Phish Gang is known to be in control of a multitude of compromised web servers, which are commissioned as needed.
To defeat site-blacklisting techniques such as those employed by PhishTank, Google, and many other anti-spam and anti-phishing services, the Phish Gang uses large numbers of slightly varied URLs to draw victims to their fraudulent web site, such as these:
http://welcome23.bank.com.cbibsweb168st.342egt.info/confirm/submit.do/
http://welcome24.bank.com.cbibsweb59121j.342egt.info/confirm/submit.do/
http://welcome22.bank.com.cbibsweb146121k.342egt.info/confirm/submit.do/
http://welcome24.bank.com.cbibsweb574721a.342egt.info/confirm/submit.do/
MarkMonitor has seen as many as 5,000 unique URLs targeting a single organization within a one-month period. This high number indicates that approximately 50 percent of all active phishing URLs during a given period can be attributed to the Phish Gang. As long as a single URL can still be resolved to a single IP address the attack is still fully functioning and dangerously harvesting information. Many combinations of URLs, domains, DNS servers, compromised hosts providing proxy services, and back-end servers can exist.
The Phish Gang has evolved—now, the initial spam email they send to their victims is likely to contain random text followed by a GIF image containing the actual phishing message. Spam filters currently lack an effective means to analyze this GIF image and thus are ineffective. Many analysts estimate that between one third and one half of all phishing email can be traced back to the Phish Gang.
Unfortunately, the successful sophisticated techniques employed by the Phish Gang have motivated other phishers to emulate their methods. These copycats use similar tactics, such as registering bogus domains and using large numbers of variations of URLs. These attacks are much more difficult to defeat and represent an increased threat to consumers and institutions doing business on the Web.
It is difficult, if not impossible to distinguish between the Phish Gang’s attack on a bank and a copycat’s attack on an online payment service, as shown by the URLS each used:
Bank
http://session-05856.bankname.com.kitrt.cn/corporate/onlineservices/TreasuryMgmt/
http://session-101101156.bankname.com.dllet.bz/corporate/onlineservices/TreasuryMgmt/
http://session-101101186.bankname.com.dllet.bz/corporate/onlineservices/TreasuryMgmt/
Online Payment Service:
http://www.onlinepaymentservicename.com.156254.oagty79a.com/cmd-confirm/login.php
http://www.onlinepaymentservicename.com.177461.aaasjpa0.com/cmd-confirm/login.php
http://www.onlinepaymentservicename.com.306716.oagty79a.com/cmd-confirm/login.php
How to Change JKS KeyStore Private Key Password
Use following keytool command to change the key store password >keytool -storepasswd -new [new password ] -keystore [path to key stor...
-
AIX Environment Procedures The best way to approach this portion of the checklist is to do a comprehensive physical inventory of the server...
-
Address Resolution Protocol (ARP) provides IP-to-MAC (32-bit IP address into a 48-bit Ethernet address) resolution. ARP operates at Layer 2 ...