Latest Post
Showing posts with label SECURITY. Show all posts
Showing posts with label SECURITY. Show all posts

How to Create a Strong Password?

imagesWe must follow the following criteria while creating a Strong Password:
The password must be a minimum of 8+ characters. The password must have 1 number , 1 special character, 1 Upper Case character.
A very simple example is : P@ssw0rd. It fullfills all the criteria's. The 'a' is replaced by a special character @. The 'P' is of upper case. The 'o' is replaced by the numeral 0.
Well, you can now convert your regular password into a Strong Password by following a few changes like the example I have mentioned above for the simple password - P@ssw0rd.
Make the first character Upper Case.
* Change all 'a' in the password to the special character @.
* Change all 's' in the password to the special character $.* Change all 'l' in 

the password to the special character !.
* Change all 'o' in the password to the numerical 0.
* Change all 'i' in the password to the numerical 1.

Secure Website Not opening!


Extract From BSNL Page:
Secured Web Sites Not Opening.
If you cannot view or access secured web pages (those beginning with an https:// URL) you may experience any of these symptoms:

* You cannot get into hotmail and yahoo email accounts.
* Cannot view secured web sites
* Cannot do a windows update
* Cannot get into bank web sites.

As ISP, we do not block any site and this problem may be due to changes/corruption in the settings of your computer/browser.

To resolve this problem, there are many ways. Try one by one and check whether you are able to solve your problem.

1. Steps to reset a .dll file required to view secured web sites.

a. Click Start
b. Click Run
c. Type regsvr32 softpub.dll Please make sure the spacing is proper
d. Click OK. A pop-up should display the message Dll Register Server in softpub.dll Succeeded.
e. Click OK.

Do the same with 

start – run – type regsvr32 Wintrust.dll – OK – OK
start – run – type regsvr32 Initpki.dll – OK – 
OK

start – run – type regsvr32 urlmon.dll – OK – OK 

When you are all done type exit to quit Command Prompt. Make sure you have the latest version of the browser.

2. Restore your browser to Default Settings.
a. Open internet explorer.
b. Click on Tools.
c. Click on Internet Options.
d. Click on Advanced tab.
e. Click on Restore Defaults and then Click on OK.


3. Reset the Security Zones to the default settings

a. Open Internet Explorer, click on Tools, Click on InternetOptions, and then click the Security tab.
b. Click Internet, and then click DefaultLevel.
c. Click LocalIntranet, and then click DefaultLevel.
d. Click Trustedsites, and then click DefaultLevel.
e. Click Restrictedsites, and then click DefaultLevel.
f. Click Apply.
g. On the Privacy tab, click Default, and then click Apply.


4. Look for third-party firewall or anti virus programs
Make sure that any third-party firewall or anti virus programs that are installed on your computer are configured correctly and are not preventing you from connecting to Web sites. Scan for worms, viruses, and spyware. They can cause these sort of problems. You can use AVG for viruses and worms, and both Adaware and Spybot S&D for spyware/adware. All three are available as free downloads. 

5. Check the Cipher Strength.
Open IE and click HelpAbout Internet Explorer and look at the Cipher Strength. It should be 128 bit. If the Cipher Strength is anything less then 128-bit, download and install the Internet Explorer High Encryption Pack.

6. Delete Cookies and Delete files.
Delete CookiesDeleteFiles and ClearHistory in ToolsInternetOptionsGeneral tab. (Deleting Cookies may delete some stored Internet passwords.) Check the Deleteall off-line content checkbox.

7. Clear the Secure Sockets Layer (SSL) state and the AutoComplete history
a. On the Tools menu in Internet Explorer, click InternetOptions, and then click the Security tab.
b. Click the Content tab.
c. In the Certificates section, click ClearSSLState, and then click OK.
d. In the Personalinformation area, click AutoComplete.
e. In the Clear AutoComplete history area, click ClearForms, and then click OK.
f. Click ClearPasswords, and then click OK three times.
Verify that the date and time settings on your computer are correct: Because SSL certificates have an expiry date. If the date on your computer isn't correct, it may prevent you from connecting to secured sites.



8. Turn off the pop-up blocker

Internet Explorer SP2 includes the ability to block pop-up windows. This new feature may block some Web pages. To turn off the Pop-Up Blocker, follow these steps: 
a. On the Tools menu in Internet Explorer, click InternetOptions, and then click the General tab.
b. Click the Privacy tab.
c. In the Pop-Up Blocker section, click to clear the Block pop-ups check box.
d. Click Apply.
e. Click OK.

9. Configure the security settings for the Trusted sites zone in Internet Explorer
Note Only add the site that you trust as a trusted site. If you are not sure about a Web site, do not add the Web site to the Trusted sites list. 
a. On the Tools menu in Internet Explorer, click InternetOptions, and then click the Security tab.
b. Click Trustedsites, and then click DefaultLevel
c. Add any SSL-secured (128-Bit) Web sites to the Trusted sites zone. To do this, follow these steps:

  • Click Sites.
  • Type the URL of the site in the Add this Web site to the zone box.
  • Click Add, click OK, and then click Apply.

10. Use System Restore to Return Your Computer to a Previous State
Before going in for restoring your system to a previous date by following the steps mentioned below, remember that you will lose all the information /files /applications /programs stored after that date.
Start - All Programs - Accessories - System Tools - System Restore

11. Create a new user profile
In certain situations, you may not be able to search Web sites if your Windows user profile is damaged. To troubleshoot this, log on to the computer as another user and try to connect to a Web site. If you can connect to SSL- secured (128-Bit) Web sites when you are logged on as a different user, your user profile may be corrupted. In this situation, back up the information and settings that you want from your profile (for example, the My Documents and Favorites folders), and then delete the damaged profile.

To delete a user profile, follow these steps: 

a. Log on to the computer as Administrator or as a member of the Administrators group.
b. Click Start, click Run, and then type sysdm.cpl.
c. Click the Advanced tab, and then under User Profiles, click Settings.
d. In the Profiles stored on this computer list, click the user profile that you want to delete, and then clickDelete.
e. Click Yes when you are prompted to confirm the deletion.
f. Click OK two times.
g. Log off the computer as Administrator, and then log on as the user. Windows XP will then create a new profile for the user.

If you are not able to open, in spite of trying the above-mentioned procedures, it is better to uninstall & reinstall your browser/OS

Protect Your Password

Password protection is a priority.

Today advanced hardware makes it easy to crack passwords. In such a scenario, what should users do to prevent hackers? Geeta Padmanabhan has the lowdown


If you thought your clever password was something no one could hack, well, you are in denial. Consultancy firm Deloitte reports that 90 per cent of user-generated passwords are vulnerable to hacking. What, even my traditional (clever) combo of eight characters complicated by numbers, letters and symbols? Yes.

Last year, Zappos.com lost names, email-IDs, phone numbers and partial credit card numbers of 24 million customers. LinkedIn admitted its user passwords were “compromised”. Some 400,000 Yahoo email-ID passwords were hacked last July. In 2011, 77 million passwords were stolen from Sony’s PlayStation Network. GoDaddy's passwords were breached. FBI, NBC-sites, 112 Indian government sites found their “secure” passwords “exposed”. If it's any consolation, Taliban sites were successfully attacked too. Just check out what services like “iFramers” do to hacked websites.

RE-USING PASSWORDS

How did our passwords get so susceptible? Longer passwords infused with @, *, % symbols are difficult to remember, so we pick a small subset from them — and they get cracked. We slip-up by re-using passwords. Credit-checking firm Experian found that the average user has 26 password-protected online accounts but uses only five different passwords. Deloitte says 10,000 most common passwords access 98 per cent of all accounts. When you key in the same password for online banking and Warhammer, a security breach at the gaming site compromises the bank account password.
Even long passwords aren't safe, says Ashwini Rao, researcher at Carnegie Mellon University. Sentence-like/phrase-like passwords such as “abiggerbetterpassword” and “thecommunistfairy”, postal addresses, email IDs and URLs also make for less secure passwords now, she says.
Blame it on advances in password-cracking hardware. “It's called a brute-force attack,” says techie Mahesh, explaining its nuances. “Powerful computers/laptops try every possible permutation-combination to find the “right” one, no intelligence involved.” Creep! Our eight-character password, created from the 94-character keyboard is one of 6.1 quadrillion possible combinations. “A dedicated password-cracking machine employing virtualisation software and high-powered graphics-processing units can crack any eight-character password in 5.5 hours,” the Deloitte report said. Nefarious, says Mahesh. “A computer working alone may not be able to dig, say, military networks. So a zombie machine, could be yours, is roped in for the hack job. It's a small percentage of your CPU; you pay for unlimited time, so how will you know? Hey! “Wait,” he says. “There is also crowd hacking, where hackers share the power of thousands of machines to infiltrate the target. At no cost.”
Help! Twitter and Adobe re-set thousands of passwords after “embarrassing” goof-ups. Google alerts you on unusual mob-phone activity. It also wants you to insert Yubikey, a smart-chip embedded tiny key that goes into the USB drive, unlocks and automatically logs onto all your accounts without asking for a password. Yubikey works on Windows/Mac/Linux/iPad/Firefox/Chrome, and is waterproof, crush-safe, needs no battery or clients software/drivers. With a simple touch the YubiKey sends a one-time-password (OTP) as if typed. The unique passcode is verified by a YubiKey compliant app. Fine. “Things like YubiKey are definitely more secure as they support random passwords and provide two-factor authentication,” says Mahesh. “Corporates use them on a day-to-day basis because they are mandatory, but you will use it a lot less since it's optional.” You could lose it, you need to insert it, and always type in a master password to access websites. Too much!
“Multi-layer authentication” is possible. You log onto your credit card issuer’s site, type in your username/password, send another code/password to smartphone, and go online. Not terribly convenient! Password vaults or password safes (paid tools) offer you a central place to store all your passwords, encrypted and protected by — you guessed it — a password or token. These, presumably, are not easily cracked. Firefox can save user names and passwords for online services like banking.
Go for poor grammar and spelling, says Ashwini Rao. Hurray! Since “brute” searches for proper combo-words and grammar, you hoodwink it by staying outside the dictionary. She suggests phrases such as “Pineapplesi$nise”, “Exitingplan$isafoot”, that is, if you can memorise the deliberate mistakes. Try “eat cake at 8!” or “car_park_city?” (Idontnohowtospal.com). The high-tech crowd touts a biometric solution, but it has its hiccups. Smartphones ask you to connect nine dots — easy, many combos, visual/tactile (touch to remember). Connecting fewer dots generates more combinations.

FOLLOW GOOD PASSWORD PRACTICES

Never share your password. Avoid using non-secure networks at public places to send private information. Change password after using a non-secure network, change it frequently. Never store your password in a program. “I use Lastpass — a password manager and form-filler,” says Mahesh. “and a secure operating system like Linux. All codes are out in the open, so it is easier to review.” Mmmm... will you consider becoming a hacktivist? If you do, let me know.
Source : the Hindu

Why more teens are quitting Facebook

 

Google: Government request to remove content worrying
The company regularly receives requests from governments and courts around the world to hand over user data.

NEW DELHI: Search engine giant Google has raised concerns about consistent demands by governments and law enforcement agencies across the world to remove content that is critical of them. 


The US-based firm, which offers services like search, email, ads and mapping, said over the last four years, "one worrying trend has remained consistent: governments continue to ask us to remove political content". 

 
The company regularly receives requests from governments and courts around the world to hand over user data. 
In a blogpost, Google legal director Susan Infantino said, "Judges have asked us to remove information that's critical of them, police departments want us to take down videos or blogs that shine a light on their conduct, and local institutions like town councils don't want people to be able to find information about their decision-making processes." 

 
Between January and June this year, Google received 3,846 government requests to remove 24,737 pieces of content, an increase of 68 per cent over the second half of 2012. 


These officials often cite defamation, privacy and even copyright laws in attempts to remove political speech from Google's services. 

 
Google said it has received 93 requests to take down government criticism and removed content in response to less than one third of them during the first half of 2013. Four of the requests were submitted as copyright claims. 

In the past too, Google has said the number of such requests are on the rise with growing usage of its services every year. 

 
"While the information we present in our Transparency Report is certainly not a comprehensive view of censorship online, it does demonstrate a worrying upward trend in the number of government requests, and underscores the importance of transparency around the processes governing such requests," she said. 
 
Tech firms, including Facebook, Twitter and Yahoo, have been seeking to release more information on Government data requests, in the belief that this would reassure their customers. 

 
These companies have also expressed "serious" concerns about monitoring of content by government agencies and they have also beefed up encryption (security) of user data to protect privacy of their consumers. 
 

INTERNET CRIME

Internet Crime Prevention Tips

Internet crime schemes that steal millions of Rupees each year from victims continue to plague the Internet through various methods. Following are preventative measures that will assist you in being informed prior to entering into transactions over the Internet:
  • Auction Fraud
  • Credit Card Fraud
  • Debt Elimination 
  • Employment/Business Opportunities
  • Escrow Services Fraud
  • Identity Theft
  • Internet Extortion
  • Investment Fraud
  • Lotteries
  • Nigerian Letter or "419"
  • Phishing/Spoofing
  • Ponzi/Pyramid
  • Reshipping
  • Spam
  • Third Party Receiver of Funds
  • DHL/UPS

Auction Fraud

  • Before you bid, contact the seller with any questions you have.
  • Review the seller's feedback.
  • Be cautious when dealing with individuals outside of your own country.
  • Ensure you understand refund, return, and warranty policies.
  • Determine the shipping charges before you buy.
  • Be wary if the seller only accepts wire transfers or cash.
  • If an escrow service is used, ensure it is legitimate.
  • Consider insuring your item.
  • Be cautious of unsolicited offers.

Credit Card Fraud

  • Ensure a site is secure and reputable before providing your credit card number online.
  • Don't trust a site just because it claims to be secure.
  • If purchasing merchandise, ensure it is from a reputable source.
  • Promptly reconcile credit card statements to avoid unauthorized charges.
  • Do your research to ensure legitimacy of the individual or company.
  • Beware of providing credit card information when requested through unsolicited emails.
  • Beware of handing over your credit card to shop keeper or bill collector to  swipe it on the machine, try to swipe it by yourself or you are closely watching the swipe to avoid Skimming fraud.

Debt Elimination

  • Know who you are doing business with — do your research.
  • Obtain the name, address, and telephone number of the individual or company.
  • Research the individual or company to ensure they are authentic.
  • Contact the Better Business Bureau to determine the legitimacy of the company.
  • Be cautious when dealing with individuals outside of your own country.
  • Ensure you understand all terms and conditions of any agreement.
  • Be wary of businesses that operate from P.O. boxes or mail drops.
  • Ask for names of other customers of the individual or company and contact them.
  • If it sounds too good to be true, it probably is.

Employment/Business Opportunities

  • Be wary of inflated claims of product effectiveness.
  • Be cautious of exaggerated claims of possible earnings or profits.
  • Beware when money is required up front for instructions or products.
  • Be careful when the job posting claims "no experience necessary".
  • Do not give your social security number when first interacting with your prospective employer.
  • Be cautious when dealing with individuals outside of your own country.
  • Be wary when replying to unsolicited emails for work-at-home employment.
  • Research the company to ensure they are authentic.
  • Contact the Better Business Bureau to determine the legitimacy of the company.
  • Try to read the details in Rozgar Samachar/ Employment News for every vacancy in the Govt. department. Do not get lured of Govt. job advertisements, which demands money at any stage.
  • If any advertisements/person which is not registered placement service agency, asking to deposit security money/ or any amount for getting the job, research carefully, as it could be fake.

Escrow Services Fraud

  • Always type in the website address yourself rather than clicking on a link provided.
  • A legitimate website will be unique and will not duplicate the work of other companies.
  • Be cautious when a site requests payment to an "agent", instead of a corporate entity.
  • Be leery of escrow sites that only accept wire transfers or e-currency.
  • Be watchful of spelling errors, grammar problems, or inconsistent information.
  • Beware of sites that have escrow fees that are unreasonably low.

Identity Theft

  • Ensure websites are secure prior to submitting your credit card number.
  • Do your homework to ensure the business or website is legitimate.
  • Attempt to obtain a physical address, rather than a P.O. box or maildrop.
  • Never throw away credit card or bank statements in usable form.
  • Be aware of missed bills which could indicate your account has been taken over.
  • Be cautious of scams requiring you to provide your personal information.
  • Never give your credit card number over the phone unless you make the call.
  • Monitor your credit statements monthly for any fraudulent activity.
  • Report unauthorized transactions to your bank or credit card company as soon as possible.
  • Review a copy of your credit report at least once a year.
  • Banks never asks your account details on phone or through website, so beware of any one calling himself as the bank's representative asking to give details.

Internet Extortion

  • Security needs to be multi-layered so that numerous obstacles will be in the way of the intruder.
  • Ensure security is installed at every possible entry point.
  • Identify all machines connected to the Internet and assess the defense that's engaged.
  • Identify whether your servers are utilizing any ports that have been known to representinsecurities.
  • Ensure you are utilizing the most up-to-date patches for your software.

Investment/ Good opportunities Fraud

  • If the "opportunity" appears too good to be true, it probably is.
  • Beware of promises to make fast profits.
  • Do not invest in anything unless you understand the deal.
  • Don't assume a company is legitimate based on "appearance" of the website.
  • Be leery when responding to investment offers received through unsolicited email.
  • Be wary of investments that offer high returns at little or no risk.
  • Independently verify the terms of any investment that you intend to make.
  • Research the parties involved and the nature of the investment.
  • Be cautious when dealing with individuals outside of your own country.
  • Contact the Better Business Bureau to determine the legitimacy of the company.

Lotteries

  • If the lottery winnings appear too good to be true, they probably are fake.
  • If you have not opted for any Lottery, winning call is absolutely false.
  • Be cautious when dealing with individuals outside of your own country.
  • Be leery if you do not remember entering a lottery or contest.
  • Be cautious if you receive a telephone call stating you are the winner in a lottery.
  • Beware of lotteries that charge a fee prior to delivery of your prize.
  • Be wary of demands to send additional money to be eligible for future winnings.
  • It is a violation of federal law to play a foreign lottery via mail or phone.
  • If any winning call asking you to deposit money in any bank account so you could get your due, be wary do not answer these call, inform police.

Nigerian Letter or "419"

  • If the "opportunity" appears too good to be true, it probably is.
  • Do not reply to emails asking for personal banking information.
  • Be wary of individuals representing themselves as foreign government officials.
  • Be cautious when dealing with individuals outside of your own country.
  • Beware when asked to assist in placing large sums of money in overseas bank accounts.
  • Do not believe the promise of large sums of money for your cooperation.
  • Guard your account information carefully.
  • Be cautious when additional fees are requested to further the transaction.

Phishing/Spoofing

  • Be suspicious of any unsolicited email requesting personal information.
  • Avoid filling out forms in email messages that ask for personal information.
  • Always compare the link in the email to the link that you are actually directed to.
  • Log on to the official website, instead of "linking" to it from an unsolicited email.
  • Contact the actual business that supposedly sent the email to verify if the email is genuine.

Ponzi/Pyramid

  • If the "opportunity" appears too good to be true, it probably is.
  • Beware of promises to make fast profits.
  • Exercise diligence in selecting investments.
  • Be vigilant in researching with whom you choose to invest.
  • Make sure you fully understand the investment prior to investing.
  • Be wary when you are required to bring in subsequent investors.
  • Independently verify the legitimacy of any investment.
  • Beware of references given by the promoter.

Reshipping

  • Be cautious if you are asked to ship packages to an "overseas home office."
  • Be cautious when dealing with individuals outside of your own country.
  • Be leery if the individual states that his country will not allow direct business shipments from the United States.
  • Be wary if the "ship to" address is yours but the name on the package is not.
  • Never provide your personal information to strangers in a chatroom.
  • Don't accept packages that you didn't order.
  • If you receive packages that you didn't order, either refuse them upon delivery or contact the company where the package is from.

Spam

  • Don't open spam. Delete it unread.
  • Never respond to spam as this will confirm tothe sender that it is a "live" email address.
  • Have a primary and secondary email address - onefor people you know and one for all other purposes.
  • Avoid giving out your email address unless youknow how it will be used.
  • Never purchase anything advertised through anunsolicited email.

Third Party Receiver of Funds

  • Do not agree to accept and wire payments forauctions that you did not post.
  • Be leery if the individual states that hiscountry makes receiving these type of fundsdifficult.
  • Be cautious when the job posting claims "noexperience necessary".
  • Be cautious when dealing with individualsoutside of your own country.

DHL/UPS


  • Beware of individuals using the DHL or UPS logoin any email communication.
  • Be suspicious when payment is requested by moneytransfer before the goods will be delivered.
  • Remember that DHL and UPS do not generally getinvolved in directly collecting payment fromcustomers.
  • Fees associated with DHL or UPS transactions areonly for shipping costs and never for other costsassociated with online transactions.
  • Contact DHL or UPS to confirm the authenticityof email communications received.

 
Copyright © 2014. wopostbank - All Rights Reserved
Proudly powered by Blogger