Tuesday, October 03, 2017
Cycber Security Awareness Month
October is National Cyber Security Awareness Month (NCSAM). The 2017 Cyber Security Awareness Month marks the seventh anniversary of the campaign. It is also European Cyber Security Awareness Month (ECSM) https://cybersecuritymonth.eu/ and in Canada, https://www.getcybersafe.gc.ca/index-eng.aspx
Stop | Think | Connect
With that in mind, consider the following suggestions not only during Cyber Security Awareness month but every day:
Stop: Before you click that formatted link in your email, search results or social media account, mouse over the link to ensure the URL matches the description.
Think: Whether it is email, Facebook, Twitter, an online forum or other online media, instead of spouting off the first reply that comes to mind when you disagree, think before you click the send button. Remember that your online reputation can follow you in "real life".
Connect: When you connect to the Internet, ensure your device software as well as any apps or third-party software are up to date.
Each week, Malwarebytes Labs will focus on a theme and provide helpful articles, useful tips, and valuable analysis so that you can increase awareness and spread the word. This week’s theme: simple steps to online safety. The first: National cybersecurity awareness month: simple steps to online safety | Malwarebytes Labs
Friday, October 31, 2008
Cyber Security Awareness Tip of the Day Roundup
October 31, Tip of the Day Roundup:
A lot of information has been included this month on how to "Protect Yourself Before You Connect Yourself" by taking simple and effective steps. The information has been provided not only by me and my forum friends but also by educational, security and private organizations.
As a finale to the question I posed in September: "How can I protect myself before I connect?", the tip today is a roundup of tips. Of course, if I had discovered the other lists before beginning this project, I could have simplified this project considerably. ;)
To review the collection of tips provided this month at Security Garden, just click this link: Cyber Security Awareness Tip of the Day.
In addition to the tips provided by SANS and US-CERT, I thought you might enjoy the tips from Who's Watching Charlottesville even though they didn't seem to catch on that October has 31 days.
- SANS Institute: Security Awareness Tip
- SANS Internet Storm Center: Cyber Security Awareness Daily Topics
- US-CERT: Cyber Security Tips
- Who's Watching Charlottesville: Cyber Security Tips: A tip a day for 30 days
Thursday, October 30, 2008
Cyber Security Awareness Tip of the Day: October 30
October 30 Tip of the Day:
"A few tips for protecting laptops and data include:
- Never leave your laptop unattended in a public area
- Buy a locking cable for your laptop. The cables are available for purchase at the bookstore, through Case Protective Services, or online.
- Make sure you have a screensaver password
- Don't keep sensitive data on a laptop. Instead, keep it on a central or department file server, and wipe your disk free space after you delete working copies from the hard drive.
- Back up data on a regular cycle, and practice recovery from backup"
The complete article is available at "Case offers tips, programs during Cyber Security Awareness Month"
Wednesday, October 29, 2008
Cyber Security Awareness Tip of the Day: October 29
Due to a feeling of anonymity sitting at a keyboard, both adults and children alike often forget about the "Golden Rule". Cyber Ethics is treating others online as you would like to be treated.
October 29 Tip of the Day:
Teach your children proper Cyber Ethics. Everyone needs to remember that words typed on the computer and post online can be more damaging than spoken words. You can apoligize for spoken words and in time the hurt will be forgotten. Written words, even though an apology is rendered, remain as a record for all to see. They attract a much larger audience than a traditional person-to-person confrontation.
Tuesday, October 28, 2008
Cyber Security Awareness Tip of the Day: October 28
October 28 Tip of the Day:
Protect yourself before you connect your Bluetooth devices.
From Understanding Bluetooth Technology"How can you protect yourself?
- Disable Bluetooth when you are not using it - Unless you are actively transferring information from one device to another, disable the technology to prevent unauthorized people from accessing it.
- Use Bluetooth in "hidden" mode - When you do have Bluetooth enabled, make sure it is "hidden," not "discoverable." The hidden mode prevents other Bluetooth devices from recognizing your device. This does not prevent you from using your Bluetooth devices together. You can "pair" devices so that they can find each other even if they are in hidden mode. Although the devices (for example, a mobile phone and a headset) will need to be in discoverable mode to initially locate each other, once they are "paired" they will always recognize each other without needing to rediscover the connection.
- Be careful where you use Bluetooth - Be aware of your environment when pairing devices or operating in discoverable mode. For example, if you are in a public wireless "hotspot," there is a greater risk that someone else may be able to intercept the connection (see Securing Wireless Networks for more information) than if you are in your home or your car.
- Evaluate your security settings - Most devices offer a variety of features that you can tailor to meet your needs and requirements. However, enabling certain features may leave you more vulnerable to being attacked, so disable any unnecessary features or Bluetooth connections. Examine your settings, particularly the security settings, and select options that meet your needs without putting you at increased risk. Make sure that all of your Bluetooth connections are configured to require a secure connection.
- Take advantage of security options - Learn what security options your Bluetooth device offers, and take advantage of features like authentication and encryption."
Monday, October 27, 2008
Cyber Security Awareness Tip of the Day: October 27
Although keeping your computer software updated has been included in previous posts, in view of the seriousness of the recent Out-of-Band Critical Update MS08-067, please consider this additional information.
The following is what has been reported that TrojanSpy:Win32/Gimmiv.A gathers from infected computers:
- User Name
- Computer Name
- Network Adapters / IP Addresses
- Installed com objects
- Installed programs and installed patches
- Recently opened documents
- Outlook Express and MSN Messenger credentials
- Protected Storage credentials
There are no visual effects informing about the infection. It has been confirmed that the exploits can download a malicious .exe automatically. The most likely methods being used are drive-by downloads and fake codec Web sites.
October 27 Tip of the Day
Get the patch at Microsoft Update:
References:
Sunday, October 26, 2008
Cyber Security Awareness Tip of the Day: October 26
October 26 Tip(s) of the Day:
1) If you see a warning as illustrated below in Google search results, pay attention and, by all means, do not go there. Even if it is a site you have been too before and it was "perfectly safe" does not mean that it is now. It may be the site or the host server that has been infected.
2) The second tip for today is to exercise caution with Google's "Sponsored Links" which can lead to malicious sites and infections. Microsoft MVP Mike Burgess demonstrates what he regularly finding in Is Security overwhelmed by Malware?
References:
Saturday, October 25, 2008
Cyber Security Awareness Tip of the Day: October 25
As frequently happens when reading one article, I followed a link from that article to the National Cyber Forensics Training Alliance where I eventually ended up at the Internet Crime Complaint Center (IC3), a partnership endeavor with the FBI.
I don't suppose that it surprises regular Security Garden readers that this path led to the . . .
October 25 Tip of the Day
As stated at IC3, "Internet crime schemes that steal millions of dollars each year from victims continue to plague the Internet through various methods." The IC3 resents a set of "preventative measures that will assist you in being informed prior to entering into transactions over the Internet."
See Internet Crime Prevention Tips
Friday, October 24, 2008
Cyber Security Awareness Tip of the Day: October 24
October 24 Tip of the Day
Follow the simple steps for configuring your Windows Vista computer accounts, updates and more in the SANS Reading Room document, Windows Vista: First Steps.
This illustrated guide is ideal for the home user.
Thursday, October 23, 2008
Cyber Security Awareness Tip of the Day: October 23
October 23 Tip of the Day:
Particularly if you use a security suite, have another vendor's software on board as part of your security package. There are a number of anti-malware software programs to chose from that are "free for personal use". Although there are others to select from, below are a few to select from:
Wednesday, October 22, 2008
Cyber Security Awareness Tip of the Day: October 22
October 22 Tip of the Day
In this electronic age, stock transactions can be conducted anytime and by anyone. Before you invest, investigate! Links below are provided for researching brokers, checking if the investment is registered, and more.
See Online Investing for tips on how too invest wisely online.
References:
Federal Trade Commission (FTC): Identity Theft
FINRA 's BrokerCheck
SEC: EDGAR database
SEC: Investor Information
SEC: Online Complaint Center
SEC: U.S. Securities and Exchange Commission
Securities Industry: Self-regulatory Organizations (including FINRA, Amex, and Nasdaq)
Your State: Securities Regulator
Tuesday, October 21, 2008
Cyber Security Awareness Tip of the Day: October 21
October 21 Tip of the Day:
"If you are browsing from your workplace machine make sure that you have read the corporate policy and procedure for Information Security, you may find that you may be in breach of the rules if you visit social networking sites or post something that appears to be a corporate statement. It's not worth losing your job by being ignorant of the policy."
Monday, October 20, 2008
Cyber Security Awareness Tip of the Day: October 20
October 20 Tip of the Day
It is difficult to follow the find print but you are checking the "I agree" button or the installation would not complete. Instead of clicking past the license agreement, consider EULAlyzer™ 1.2 by Javacool Software. You will not get legal advice with EULAlyzer but it does provide the benefits below, as described by Javacool:
"EULAlyzer can analyze license agreements in seconds, and provide a detailed listing of potentially interesting words and phrases. Discover if the software you're about to install displays pop-up ads, transmits personally identifiable information, uses unique identifiers to track you, or much much more.
The BenefitsAnd with additional features like the EULA Research Center, which optionally allows users to anonymously submit license agreements they scan to help us to further improve the program, everyone can be a part of the effort to make something that used to be so tedious, so easy."
- Discover potentially hidden behavior about the software you're going to install
- Pick up on things you missed when reading license agreements
- Keep a saved database of the license agreements you view
- Instant results - super-fast analysis in just a second
Sunday, October 19, 2008
Cyber Security Awareness Tip of the Day: October 19
A little-known feature is the ability to configure Flash Player's global and website settings. Microsoft MVP Donna Buenaventura posted instructions on how to configure Flash Player settings. I used Donna's instructions to create today's tip of the day.
October 19 Tip of the Day
Use the On-line Settings Manager, illustrated below, to configure Flash Player settings. Go to the Adobe Website Storage Settings panel to make the changes to the settings.
Although the changes are made via the on-line manager, the settings are only stored on your computer.
1. Global Privacy Settings panel -- specify whether websites must ask your permission before using your camera or microphone.
Recommended:
- Always Deny
- Always Ask
Recommended:
- Move slider all the way to the left, resulting in "None"
- Uncheck "Allow 3rd party Flash content to store data"
(Permission will be requested if a website with flash content needs space.)
Recommended:
- Always Deny
Optional:
- If you are lax in checking for updates, retain the default setting.
- Uncheck if you do not want updates checked automatically.
Recommended:
- Always Deny
or - Delete all sites
Recommended:
- Move slider all the way to the left, resulting in "None"
Saturday, October 18, 2008
Cyber Security Awareness Tip of the Day: October 18
October 18 Tip of the Day
Enhance the security of your computer by resetting a few options to harden the Internet Zone.
Example: Set "Launching programs and files in an IFrame" to DisableSee Adding Sites to the Restricted Zone
Friday, October 17, 2008
Cyber Security Awareness Tip of the Day: October 17
October 17 Tip of the Day
From Microsoft, 10 tips for social networking safety:
Social networking Web sites like MySpace, Facebook, Twitter, and Windows Live Spaces are services people can use to connect with others to share information like photos, videos, and personal messages.
As the popularity of these social sites grows, so do the risks of using them. Hackers, spammers, virus writers, identity thieves, and other criminals follow the traffic.
Read these tips to help protect yourself when you use social networks.
- Use caution when you click links that you receive in messages from your friends on your social Web site. Treat links in messages on these sites as you would links in e-mail messages. (For more information, see Approach links in e-mail with caution.)
- Don't trust that a message is really from who it says it's from. Hackers can break into accounts and send messages that look like they're from your friends, but aren't. If you suspect that a message is fraudulent, use an alternate method to contact your friend to find out. This includes invitations to join new social networks.
- To avoid giving away e-mail addresses of your friends, do not allow social networking services to scan your e-mail address book. When you join a new social network, you might receive an offer to enter your e-mail address and password to find out who else is on the network. The site might use this information to send e-mail messages to everyone in your contact list or even everyone you've ever sent an e-mail message to with that e-mail address. Social networking sites should explain that they're going to do this, but some do not.
- Type the address of your social networking site directly into your browser or use your personal bookmarks. If you click a link to your site through e-mail or another Web site, you might be entering your account name and password into a fake site where your personal information could be stolen.
- Be selective about who you accept as a friend on a social network. Identity thieves might create fake profiles in order to get information from you. This is known as social engineering.
- Choose your social network carefully. Evaluate the site that you plan to use and make sure you understand the privacy policy. Find out if the site monitors content that people post. You will be providing personal information to this Web site, so use the same criteria that you would to select a site where you enter your credit card.
- Assume what you write on a social networking site is permanent. Even if you can delete your account, anyone on the Internet can easily print the information or save it to a computer.
- Be careful about installing extras on your site. Many social networking sites allow you to download third-party applications that let you do more with your personal page. Criminals sometimes use these applications in order to steal your personal information. To download and use third-party applications safely, take the same safety precautions that you take with any other program or file you download from the Web. For more information, see Before you download files, help protect your computer.
- Think twice before you use social networking sites at work. For more information, see Be careful with social networking sites, especially at work.
- Talk to your kids about social networking. If you're a parent of children who use social networking sites, see How to help your kids use social Web sites more safely.
Thursday, October 16, 2008
Cyber Security Awareness Tip of the Day: October 16
October 16 Tip of the Day
Be sure your tweens and teens understand the rules of the road when using instant messaging. Review the 10 tips for safer instant messaging from Microsoft for the entire family:
Communicating by using an instant messaging (IM) program has some of the same security and privacy risks as e-mail, but there are a few unique dangers that you should be aware of.
For more information, read Control Your Online Status Using Windows Messenger and Set Your Online Status.
- Never open pictures, download files, or click links in messages from people you don’t know. If they come from someone you do know, confirm with the sender that the message (and its attachments) is trustworthy. If it's not, close the instant message. See 5 steps to help avoid instant message viruses for more information.
- Be careful when creating a screen name. Each IM program asks you to create a screen name, which is similar to an e-mail address. Your screen name should not provide or allude to personal information. For example, use a nickname such as SoccerFan instead of BaltimoreJenny.
- Create a barrier against unwanted instant messaging. Do not list your screen name or e-mail address in public areas (such as large Internet directories or online community profiles) or give them to strangers.
Some IM services link your screen name to your e-mail address when you register. The easy availability of your e-mail address can result in your receiving an increased number of spam and phishing- Never provide sensitive personal information, such as your credit card numbers or passwords, in an IM conversation.
- Only communicate with people who are on your contact or buddy lists.
- If you decide to meet a stranger that you know only from IM communication, take appropriate safety precautions. For example, do not meet that person alone, (take a friend or parent with you), and always meet and stay in a public place, such as a cafe.
- Don't send personal or private instant messages at work. Your employer might have a right to view those messages.
- If you use a public computer, do not select the feature that allows you to log on automatically. People who use that computer after you may be able to see and use your screen name to log on.
- Monitor and limit your children's use of IM. One way to do this is to sign up for Windows Live OneCare Family Safety. If you use Windows Vista, it comes with parental controls built-in.
For more information, see How Windows Vista can help you protect your kids online.- When you're not available to receive messages, be careful how you display this information to other users. For example, you might not want everyone on your contact list to know that you're "Out to Lunch."
Wednesday, October 15, 2008
Cyber Security Awareness Tip of the Day: October 15
October 15 Tip of the Day
Create a bookmark folder of safe, kid-friendly websites. Here's a starter list:
- ALA Great Websites for Kids
- Cartoon Network
- Crayola
- Disney
- EGO
- National Geographic Kids
- Nick Jr
- PBS Kids
- Sesame Street
Tuesday, October 14, 2008
Cyber Security Awareness Tip of the Day: October 14
That leads to the . . .
Tip of the Day for October 14
Keep your software programs up to date with the latest security patches.
Microsoft recommends turning automatic updating. If you prefer to "set it and forget it", then that is indeed the best setting for your family computer. I am one of those people who wants control of what gets installed on my computer and when. So even though I have all of the security updates installed, I still look at the updates and check the box giving permission to download and install them.
See Understanding Microsoft Updates if you are unsure of what your update settings are or how to check.
Monday, October 13, 2008
Cyber Security Awareness Tip of the Day: October 13
For those unfamiliar, Mike defines the Hosts File as follows:
"The Hosts file contains the mappings of IP addresses to host names. This file is loaded into memory (cache) at startup, then Windows checks the Hosts file before it queries any DNS servers, which enables it to override addresses in the DNS. This prevents access to the listed sites by redirecting any connection attempts back to the local (your) machine. Another feature of the HOSTS file is its ability to block other applications from connecting to the Internet, providing the entry exists."October 13 Tip of the Day:
Block access to undesirable sites with the HOSTS File.
MVPS HOSTS File Information:
- The MVPS HOSTS file: http://www.mvps.org/winhelp2002/hosts.htm
- Download: hosts.zip: http://www.mvps.org/winhelp2002/hosts.zip
- How To: Download and Extract the HOSTS file: http://www.mvps.org/winhelp2002/hosts2.htm
- HOSTS File - Frequently Asked Questions: http://www.mvps.org/winhelp2002/hostsfaq.htm
- HOSTS file update notices: http://www.mvps.org/winhelp2002/updates.htm



