Showing posts with label CyberSecurityTip. Show all posts
Showing posts with label CyberSecurityTip. Show all posts

Tuesday, October 03, 2017

Cycber Security Awareness Month


October is National Cyber Security Awareness Month (NCSAM).  The 2017 Cyber Security Awareness Month marks the seventh anniversary of the campaign.  It is also European Cyber Security Awareness Month (ECSM) https://cybersecuritymonth.eu/  and in Canada, https://www.getcybersafe.gc.ca/index-eng.aspx 

  Stop | Think | Connect

With that in mind, consider the following suggestions not only during Cyber Security Awareness month but every day:

    Stop:  Before you click that formatted link in your email, search results or social media account, mouse over the link to ensure the URL matches the description.

    Think:  Whether it is email, Facebook, Twitter, an online forum or other online media, instead of spouting off the first reply that comes to mind when you disagree, think before you click the send button.  Remember that your online reputation can follow you in "real life".

    Connect:  When you connect to the Internet, ensure your device software as well as any apps or third-party software are up to date.

Each week, Malwarebytes Labs will focus on a theme and provide helpful articles, useful tips, and valuable analysis so that you can increase awareness and spread the word. This week’s theme: simple steps to online safety. The first:  National cybersecurity awareness month: simple steps to online safety | Malwarebytes Labs


Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Friday, October 31, 2008

Cyber Security Awareness Tip of the Day Roundup

As my contribution to Cyber Security Awareness Month, I have been providing a new "tip of the day". Friends at Freedomlist and LandzDown forums provided some excellent tips that I shared. This "roundup" post provides the opportunity to extend my grateful appreciation to them for their contributions.


October 31, Tip of the Day Roundup:

A lot of information has been included this month on how to "Protect Yourself Before You Connect Yourself" by taking simple and effective steps. The information has been provided not only by me and my forum friends but also by educational, security and private organizations.

As a finale to the question I posed in September: "How can I protect myself before I connect?", the tip today is a roundup of tips. Of course, if I had discovered the other lists before beginning this project, I could have simplified this project considerably. ;)

To review the collection of tips provided this month at Security Garden, just click this link: Cyber Security Awareness Tip of the Day.

In addition to the tips provided by SANS and US-CERT, I thought you might enjoy the tips from Who's Watching Charlottesville even though they didn't seem to catch on that October has 31 days.







Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Thursday, October 30, 2008

Cyber Security Awareness Tip of the Day: October 30

Laptop usage is no longer restricted to the business person who travels frequently. Instead, laptops are rapidly replacing desktop computers not only in business and on college and university campuses but also for home use. With that in mind, the tip today is from Case Western Reserve University:

October 30 Tip of the Day:

"A few tips for protecting laptops and data include:

  • Never leave your laptop unattended in a public area
  • Buy a locking cable for your laptop. The cables are available for purchase at the bookstore, through Case Protective Services, or online.
  • Make sure you have a screensaver password
  • Don't keep sensitive data on a laptop. Instead, keep it on a central or department file server, and wipe your disk free space after you delete working copies from the hard drive.
  • Back up data on a regular cycle, and practice recovery from backup"

The complete article is available at "Case offers tips, programs during Cyber Security Awareness Month"







Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Wednesday, October 29, 2008

Cyber Security Awareness Tip of the Day: October 29

As parents and other adults in a position of influence with children, we teach our children to follow the "Golden Rule" -- treat others as you would like to be treated.

Due to a feeling of anonymity sitting at a keyboard, both adults and children alike often forget about the "Golden Rule". Cyber Ethics is treating others online as you would like to be treated.

October 29 Tip of the Day:

Teach your children proper Cyber Ethics. Everyone needs to remember that words typed on the computer and post online can be more damaging than spoken words. You can apoligize for spoken words and in time the hurt will be forgotten. Written words, even though an apology is rendered, remain as a record for all to see. They attract a much larger audience than a traditional person-to-person confrontation.








Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Tuesday, October 28, 2008

Cyber Security Awareness Tip of the Day: October 28

When purchasing a cell phone, PDA or computer accessories like keyboards, mice and other peripherals, many people look for models that are Bluetooth enabled. Bluetooth is a method of wireless networking these devices without wires or cables.

October 28 Tip of the Day:

Protect yourself before you connect your Bluetooth devices.

"How can you protect yourself?

  • Disable Bluetooth when you are not using it - Unless you are actively transferring information from one device to another, disable the technology to prevent unauthorized people from accessing it.

  • Use Bluetooth in "hidden" mode - When you do have Bluetooth enabled, make sure it is "hidden," not "discoverable." The hidden mode prevents other Bluetooth devices from recognizing your device. This does not prevent you from using your Bluetooth devices together. You can "pair" devices so that they can find each other even if they are in hidden mode. Although the devices (for example, a mobile phone and a headset) will need to be in discoverable mode to initially locate each other, once they are "paired" they will always recognize each other without needing to rediscover the connection.

  • Be careful where you use Bluetooth - Be aware of your environment when pairing devices or operating in discoverable mode. For example, if you are in a public wireless "hotspot," there is a greater risk that someone else may be able to intercept the connection (see Securing Wireless Networks for more information) than if you are in your home or your car.

  • Evaluate your security settings - Most devices offer a variety of features that you can tailor to meet your needs and requirements. However, enabling certain features may leave you more vulnerable to being attacked, so disable any unnecessary features or Bluetooth connections. Examine your settings, particularly the security settings, and select options that meet your needs without putting you at increased risk. Make sure that all of your Bluetooth connections are configured to require a secure connection.

  • Take advantage of security options - Learn what security options your Bluetooth device offers, and take advantage of features like authentication and encryption."
From Understanding Bluetooth Technology








Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Monday, October 27, 2008

Cyber Security Awareness Tip of the Day: October 27

It is Monday morning and the weekend is already a distant memory. You either managed to take some deserved R&R time, avoiding even the most mundane of tasks or your weekend was packed with family activities, leaving no time for those same mundane tasks -- like checking your computer for needed security updates.

Although keeping your computer software updated has been included in previous posts, in view of the seriousness of the recent Out-of-Band Critical Update MS08-067, please consider this additional information.

The following is what has been reported that TrojanSpy:Win32/Gimmiv.A gathers from infected computers:
  • User Name
  • Computer Name
  • Network Adapters / IP Addresses
  • Installed com objects
  • Installed programs and installed patches
  • Recently opened documents
  • Outlook Express and MSN Messenger credentials
  • Protected Storage credentials
There is NO patch for operating systems that have reached "end of life" support. That means that only Windows 2000, XP, Windows Server 2003, Vista and Windows 7 (Beta) can be patched. Note further that on Windows 2000, XP, and Windows Server 2003 systems, the code can be run without authentication. This is not the case on Vista (or Windows 7 Beta) where authentication is needed.

There are no visual effects informing about the infection. It has been confirmed that the exploits can download a malicious .exe automatically. The most likely methods being used are drive-by downloads and fake codec Web sites.


October 27 Tip of the Day

Get the patch at Microsoft Update: http://update.microsoft.com/



References:







Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Sunday, October 26, 2008

Cyber Security Awareness Tip of the Day: October 26

Do you "Google"? According to Security Garden blog analytics, over 90% of visitors who come here as a result of search results, arrived via Google search results. Such overwhelming results leads to the tip today being a two-for-one!

October 26 Tip(s) of the Day:

1) If you see a warning as illustrated below in Google search results, pay attention and, by all means, do not go there. Even if it is a site you have been too before and it was "perfectly safe" does not mean that it is now. It may be the site or the host server that has been infected.


Additional information is available in Malware? We don't need no stinking malware!

2) The second tip for today is to exercise caution with Google's "Sponsored Links" which can lead to malicious sites and infections. Microsoft MVP Mike Burgess demonstrates what he regularly finding in Is Security overwhelmed by Malware?


References
:








Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Saturday, October 25, 2008

Cyber Security Awareness Tip of the Day: October 25

At lunch the other day, I read an interesting story at SecureWorks, about an undercover FBI operation for tracing the identity and locations of cyber criminals involved in identity theft. (See DarkMarket: FBI Sting Closes E-Doors)

As frequently happens when reading one article, I followed a link from that article to the National Cyber Forensics Training Alliance where I eventually ended up at the Internet Crime Complaint Center (IC3), a partnership endeavor with the FBI.

I don't suppose that it surprises regular Security Garden readers that this path led to the . . .

October 25 Tip of the Day

As stated at IC3, "Internet crime schemes that steal millions of dollars each year from victims continue to plague the Internet through various methods." The IC3 resents a set of "preventative measures that will assist you in being informed prior to entering into transactions over the Internet."

See Internet Crime Prevention Tips








Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Friday, October 24, 2008

Cyber Security Awareness Tip of the Day: October 24

I received a link to another helpful document from my friend Eric the Red at LandzDown Forum. This is particularly timely for parents considering investing in a family gift for the approaching Holidays.

October 24 Tip of the Day

Follow the simple steps for configuring your Windows Vista computer accounts, updates and more in the SANS Reading Room document, Windows Vista: First Steps.

This illustrated guide is ideal for the home user.








Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Thursday, October 23, 2008

Cyber Security Awareness Tip of the Day: October 23

Over and over you hear the same thing -- be sure to keep your system updated with all security patches, have a software firewall and up-to-date anti-virus software. With so many vendors now providing "security suites", do you need an anti-malware software as well? As the saying goes, I don't like keeping all my eggs in one basket. It is the same with security software.

October 23 Tip of the Day:

Particularly if you use a security suite, have another vendor's software on board as part of your security package. There are a number of anti-malware software programs to chose from that are "free for personal use". Although there are others to select from, below are a few to select from:








Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Wednesday, October 22, 2008

Cyber Security Awareness Tip of the Day: October 22

While many people have been hurt financially during the recent unstable economic situation, I have heard other people considering investments in stocks that may have been out of their reach before but are affordable now.


October 22 Tip of the Day

In this electronic age, stock transactions can be conducted anytime and by anyone. Before you invest, investigate! Links below are provided for researching brokers, checking if the investment is registered, and more.

See Online Investing for tips on how too invest wisely online.


References:

Federal Trade Commission (FTC): Identity Theft
FINRA 's BrokerCheck
SEC: EDGAR database
SEC: Investor Information
SEC: Online Complaint Center
SEC: U.S. Securities and Exchange Commission
Securities Industry: Self-regulatory Organizations (including FINRA, Amex, and Nasdaq)
Your State: Securities Regulator








Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Tuesday, October 21, 2008

Cyber Security Awareness Tip of the Day: October 21

After a number of fairly lengthy tips, I mentioned to Eric the Red at LandzDown that it was time for something more straight-forward. He came through with an excellent tip for today.


October 21 Tip of the Day:
"If you are browsing from your workplace machine make sure that you have read the corporate policy and procedure for Information Security, you may find that you may be in breach of the rules if you visit social networking sites or post something that appears to be a corporate statement. It's not worth losing your job by being ignorant of the policy."








Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Monday, October 20, 2008

Cyber Security Awareness Tip of the Day: October 20

Everyone who reads the "Terms of Service" (TOS) or End User License Agreement (EULA) before installing every software, raise your hand. Be honest now. (I think a few hands just went down.)

October 20 Tip of the Day

It is difficult to follow the find print but you are checking the "I agree" button or the installation would not complete. Instead of clicking past the license agreement, consider EULAlyzer™ 1.2 by Javacool Software. You will not get legal advice with EULAlyzer but it does provide the benefits below, as described by Javacool:

"EULAlyzer can analyze license agreements in seconds, and provide a detailed listing of potentially interesting words and phrases. Discover if the software you're about to install displays pop-up ads, transmits personally identifiable information, uses unique identifiers to track you, or much much more.

The Benefits

  • Discover potentially hidden behavior about the software you're going to install
  • Pick up on things you missed when reading license agreements
  • Keep a saved database of the license agreements you view
  • Instant results - super-fast analysis in just a second
And with additional features like the EULA Research Center, which optionally allows users to anonymously submit license agreements they scan to help us to further improve the program, everyone can be a part of the effort to make something that used to be so tedious, so easy."







Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Sunday, October 19, 2008

Cyber Security Awareness Tip of the Day: October 19

There has been a lot of discussion regarding "clickjacking" -- a form of cross-site scripting -- recently. The latest version of the Firefox add-on NoScript provides protection against this vulnerability. Changes were made to the Adobe Flash Player Clipboard API to prevent potential ‘Clipboard attacks’.

A little-known feature is the ability to configure Flash Player's global and website settings. Microsoft MVP Donna Buenaventura posted instructions on how to configure Flash Player settings. I used Donna's instructions to create today's tip of the day.

October 19 Tip of the Day

Use the On-line Settings Manager, illustrated below, to configure Flash Player settings. Go to the Adobe Website Storage Settings panel to make the changes to the settings.

Although the changes are made via the on-line manager, the settings are only stored on your computer.


1. Global Privacy Settings panel -- specify whether websites must ask your permission before using your camera or microphone.

Recommended:
  • Always Deny
  • Always Ask
2. Global Storage Settings panel -- specify the amount of disk space that websites you haven't yet visited can use to store information on your computer, or to prevent websites you haven't yet visited from storing information on your computer.

Recommended:
  • Move slider all the way to the left, resulting in "None"
  • Uncheck "Allow 3rd party Flash content to store data"
    (Permission will be requested if a website with flash content needs space.)
3. Global Security Settings panel -- View or change your security settings

Recommended:
  • Always Deny
4. Global Notifications Settings panel -- Specify if and how often Flash Player should check for updated versions

Optional:
  • If you are lax in checking for updates, retain the default setting.
  • Uncheck if you do not want updates checked automatically.
5. Website Privacy Settings panel - View or change the privacy settings for websites you have already visited

Recommended:
  • Always Deny
    or
  • Delete all sites
6. Website Storage Settings panel -- View or change the storage settings for websites you have already visited, or to delete information that any or all websites have already stored on your computer

Recommended:
  • Move slider all the way to the left, resulting in "None"








Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Saturday, October 18, 2008

Cyber Security Awareness Tip of the Day: October 18

Reading Steve Riley's Internet Explorer security levels compared reminded me of some excellent advice from Microsoft MVP Mike Burgess that I wanted to share regarding settings in Internet Explorer.

October 18 Tip of the Day

Enhance the security of your computer by resetting a few options to harden the Internet Zone.

Example: Set "Launching programs and files in an IFrame" to Disable
See Adding Sites to the Restricted Zone









Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Friday, October 17, 2008

Cyber Security Awareness Tip of the Day: October 17

The first Tip of the Day related to the manner of sharing information at social networking sites. Because social networking sites like MySpace, Facebook, Twitter, or Windows Live Spaces and the like are popular, additional safety thoughts are in order.

October 17 Tip of the Day

From Microsoft, 10 tips for social networking safety:

Social networking Web sites like MySpace, Facebook, Twitter, and Windows Live Spaces are services people can use to connect with others to share information like photos, videos, and personal messages.

As the popularity of these social sites grows, so do the risks of using them. Hackers, spammers, virus writers, identity thieves, and other criminals follow the traffic.

Read these tips to help protect yourself when you use social networks.

  1. Use caution when you click links that you receive in messages from your friends on your social Web site. Treat links in messages on these sites as you would links in e-mail messages. (For more information, see Approach links in e-mail with caution.)

  2. Don't trust that a message is really from who it says it's from. Hackers can break into accounts and send messages that look like they're from your friends, but aren't. If you suspect that a message is fraudulent, use an alternate method to contact your friend to find out. This includes invitations to join new social networks.

  3. To avoid giving away e-mail addresses of your friends, do not allow social networking services to scan your e-mail address book. When you join a new social network, you might receive an offer to enter your e-mail address and password to find out who else is on the network. The site might use this information to send e-mail messages to everyone in your contact list or even everyone you've ever sent an e-mail message to with that e-mail address. Social networking sites should explain that they're going to do this, but some do not.

  4. Type the address of your social networking site directly into your browser or use your personal bookmarks. If you click a link to your site through e-mail or another Web site, you might be entering your account name and password into a fake site where your personal information could be stolen.

  5. Be selective about who you accept as a friend on a social network. Identity thieves might create fake profiles in order to get information from you. This is known as social engineering.

  6. Choose your social network carefully. Evaluate the site that you plan to use and make sure you understand the privacy policy. Find out if the site monitors content that people post. You will be providing personal information to this Web site, so use the same criteria that you would to select a site where you enter your credit card.

  7. Assume what you write on a social networking site is permanent. Even if you can delete your account, anyone on the Internet can easily print the information or save it to a computer.

  8. Be careful about installing extras on your site. Many social networking sites allow you to download third-party applications that let you do more with your personal page. Criminals sometimes use these applications in order to steal your personal information. To download and use third-party applications safely, take the same safety precautions that you take with any other program or file you download from the Web. For more information, see Before you download files, help protect your computer.

  9. Think twice before you use social networking sites at work. For more information, see Be careful with social networking sites, especially at work.

  10. Talk to your kids about social networking. If you're a parent of children who use social networking sites, see How to help your kids use social Web sites more safely.








Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Thursday, October 16, 2008

Cyber Security Awareness Tip of the Day: October 16

Yesterday's Tip of the Day was directed toward the younger children in the house. When your children get a bit older, they are going to be IM'ing (Instant Messaging). It is important to set guidelines for your children and to also lock down their account so only friends known to them are added to their contact list.

October 16 Tip of the Day

Be sure your tweens and teens understand the rules of the road when using instant messaging. Review the 10 tips for safer instant messaging from Microsoft for the entire family:

Communicating by using an instant messaging (IM) program has some of the same security and privacy risks as e-mail, but there are a few unique dangers that you should be aware of.

  1. Never open pictures, download files, or click links in messages from people you don’t know. If they come from someone you do know, confirm with the sender that the message (and its attachments) is trustworthy. If it's not, close the instant message. See 5 steps to help avoid instant message viruses for more information.

  2. Be careful when creating a screen name. Each IM program asks you to create a screen name, which is similar to an e-mail address. Your screen name should not provide or allude to personal information. For example, use a nickname such as SoccerFan instead of BaltimoreJenny.

  3. Create a barrier against unwanted instant messaging. Do not list your screen name or e-mail address in public areas (such as large Internet directories or online community profiles) or give them to strangers.

    Some IM services link your screen name to your e-mail address when you register. The easy availability of your e-mail address can result in your receiving an increased number of spam and phishing

  4. Never provide sensitive personal information, such as your credit card numbers or passwords, in an IM conversation.

  5. Only communicate with people who are on your contact or buddy lists.

  6. If you decide to meet a stranger that you know only from IM communication, take appropriate safety precautions. For example, do not meet that person alone, (take a friend or parent with you), and always meet and stay in a public place, such as a cafe.

  7. Don't send personal or private instant messages at work. Your employer might have a right to view those messages.

  8. If you use a public computer, do not select the feature that allows you to log on automatically. People who use that computer after you may be able to see and use your screen name to log on.

  9. Monitor and limit your children's use of IM. One way to do this is to sign up for Windows Live OneCare Family Safety. If you use Windows Vista, it comes with parental controls built-in.

    For more information, see How Windows Vista can help you protect your kids online.

  10. When you're not available to receive messages, be careful how you display this information to other users. For example, you might not want everyone on your contact list to know that you're "Out to Lunch."
For more information, read Control Your Online Status Using Windows Messenger and Set Your Online Status.








Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Wednesday, October 15, 2008

Cyber Security Awareness Tip of the Day: October 15

Several years ago my daughter and her family were relocated to another state. When they lived nearby and were first learning about the computer and the Internet, my granddaughters would take turns sitting on my lap while I helped them navigate kid-friendly websites. I wish then I knew about the ALA Great Websites for Kids.

October 15 Tip of the Day

Create a bookmark folder of safe, kid-friendly websites. Here's a starter list:







Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Tuesday, October 14, 2008

Cyber Security Awareness Tip of the Day: October 14

This is the second Tuesday of the month -- which happens to be the day that Microsoft releases the Security Bulletins, referred to many people as "Patch Tuesday". As of the Advance Notice published last Thursday, Microsoft indicated the plan is to release eleven new security bulletins today.

That leads to the . . .

Tip of the Day for October 14

Keep your software programs up to date with the latest security patches.

Microsoft recommends turning automatic updating. If you prefer to "set it and forget it", then that is indeed the best setting for your family computer. I am one of those people who wants control of what gets installed on my computer and when. So even though I have all of the security updates installed, I still look at the updates and check the box giving permission to download and install them.

See Understanding Microsoft Updates if you are unsure of what your update settings are or how to check.









Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Monday, October 13, 2008

Cyber Security Awareness Tip of the Day: October 13

If you followed the Atrivo (Intercage) Takedown, it is also likely that you also read Microsoft MVP Mike Burgess' reports about the thousands of suspended domains. The IP addresses for those suspended domains were in the MVPS Hosts file. As a result, with the MVPS Hosts file, access was blocked.

For those unfamiliar, Mike defines the Hosts File as follows:
"The Hosts file contains the mappings of IP addresses to host names. This file is loaded into memory (cache) at startup, then Windows checks the Hosts file before it queries any DNS servers, which enables it to override addresses in the DNS. This prevents access to the listed sites by redirecting any connection attempts back to the local (your) machine. Another feature of the HOSTS file is its ability to block other applications from connecting to the Internet, providing the entry exists."
October 13 Tip of the Day:

Block access to undesirable sites with the HOSTS File.



MVPS HOSTS File Information:
Visit the Hosts News blog: http://msmvps.com/blogs/hostsnews/default.aspx








Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...