Showing posts with label keylogger. Show all posts
Showing posts with label keylogger. Show all posts

Saturday, 13 December 2008

Firefox: Most Risky App to Businesses in New Study

The good old FF browser gets little love when it comes to security

Firefox has its plate full when it comes to security. It has grown a substantial enough market share to place it in a strong second after Microsoft. This gives it a high profile and leaves it a desirable target to be exploited by hackers and malware writers. Worse yet, it has less money to fund security efforts that Microsoft, and according to some experts, less focus as well.

While small market share browsers like Opera and Chrome have built a reputation on their security (with Safari, being a noticeable exception, have a reputation for insecurity), Firefox continues to plod along in a day to day fight, trying to remain a secure platform while dealing with the challenges of browser celebrity.

Perhaps for this reason, Bit9, an application whitelisting firm that helps employers block employee access to certain apps, placed Firefox on the top its list of most vulnerable apps. The remaining spots on the list were filled out with more familiar names, with two through twelve respectively being: Adobe Flash & Acrobat; EMC VMware Player, Workstation, and other products; Sun Java Runtime Environment; Apple QuickTime, Safari, and iTunes; Symantec Norton products; Trend Micro OfficeScan; Citrix products; Aurigma and Lycos image uploaders; Skype; Yahoo Assistant; and Microsoft Windows Live Messenger.

The Bit9 study looked at several factors in ranking vulnerability. One factor was how popular the applications were. Another factor was how many known vulnerabilities existed, and how severe they were. Lastly, it looked at how hard patching was for the particular application.

In order to make the list, programs hand to run in Windows and not be centrally updatable via services such as Microsoft SMS and WSUS. Many say that the survey was unfair to Apple products because it kept easier patched Microsoft applications off the list.

In some ways, though Bit9's list is a useful benchmark. It aptly points out that many networks have Firefox installations running on machines, without the system administrator being fully aware of the instance of these installs. Thus, despite the fact that most of the vulnerabilities looked at have been patched, the installs may not receive these patches immediately, until the employee upgrades to the next edition of the browser.

The study's conclusions only marginally apply to the consumer market. However, when it comes to the business market, the study argues that picking or allowing employees to run Firefox, even with its security plug-ins, is a ticket to the IT danger zone as malware increasingly targets application layer targets such as Firefox.

Security in Recession

With the National Bureau of Economic Research in the United States announcing last week that the U.S. has officially been in recession since Dec. 2007, IT budgets are highly likely to be strictly controlled both in the U.S. and in other parts of the world. I had a conversation with a friend over the weekend, and he asked me if I expect redundancies in the IT Security industry, as companies could no longer afford to have dedicated security personnel on their books.

To be honest, yes I think there will be. However, I also think that the overall IT security industry will continue to grow in 2009 - bad guys are not going away anytime soon, and a lot of their existing scams work really well in this economic climate. Companies who choose to think otherwise may well end up regretting it in the long term, and here are my thoughts on why:

At the end of the day, security boils down to risk management. The three core values every organization needs to protect are often shown in the acronym CIA (Confidentiality, Integrity, Availability). Different organizations prioritize on different areas, but I think when it comes to economic downturn, confidentiality, and availability are obviously the most affected.

In terms of confidentiality, we are talking about an organization’s private data being protected. I’m based in Ireland, where 17,000 people had their jobs slashed in November. This is a drop in the ocean compared to other countries, particularly the half a million employees who lost jobs in the U.S. Insider threats have long been one of the largest risks facing organizations, especially in the case of the so-called “disgruntled employee.” With large number of employees made redundant, having their salaries cut, etc., there are a lot of incentives for these same employees to engage in data theft.

When people feel hard done by their employers, they are more likely to relax their morals. In these cases they may no longer consider taking confidential company information outside of the company as stealing. They feel an entitlement to this information, after all, they’ve put years of work into helping the company grow. The very fact that there are so many Data Leak/Loss Prevention (DLP) solutions on the market should give you an idea of just how big this problem is - and I think the risk of Data Theft/Loss is going to increase in the current climate

Which brings us to the other big factor - Availability. Almost every company is currently engaged in examining their costs, and reducing them wherever possible. Whether it is in terms of head count or even simply lowering all of the thermostats in their buildings by five degrees (my hands are going blue typing this), a lot of companies are walking a very fine line trying to keep afloat for the next two to three years - even the smallest misfortune could tip the ship.

This is where malware comes in. The recent WORM_DOWNAD.A attack was quite successful in infecting unpatched Windows machines, with a quite a few companies having thousands of machines infected by the threat. Cleaning a threat like this costs a lot of money - a company may need to pay their IT staff overtime to fix the problem, or they may have to bring in external contractors. That’s not where the real loss is, however. Picture a company of 4000 employees. Now picture all of those employees being unable to use their machines for three hours while the systems are being cleaned, patched and tested. That is 12000 man-hours of work which that company is paying for, and getting nothing in return. To put it another way, that’s about 6.5 employees’ salaries for the year which sums up to around 200-250K. There are very few companies that have that kind of money to burn at the moment.

So, to any organization thinking of cutting their security budgets, think long and hard about weighing the short term savings with the potential losses. I wish I could say that there won’t be companies that would go under because of a malware attack in the next couple of months - but optimism is not exactly in large supply at the moment.

Thursday, 11 December 2008

Remove Antivirus 360 - Antivirus 360 Removal Instructions

We have bought you something that most of you have been pulling your hair out over. Those annoying fake anti spyware programs that claim to be real. They fake scan your system and "find" spyware on your PC that you can only remove if you purchase the software to then find out it does not work.

Well get rid of it now with our steps.......

Antivirus 360 is latest rogue anti-spyware program which uses scare tactics to promote itself using terrible false scan results, pop-ups, security alerts e.t.c.
Antivirus 360 uses Vundo Trojan in order to install itself on your computer without any informing and approval. Once installed Antivirus 360 will configure itself to run automatical scan each time you turn on your computer. Once you turn on your computer, Antivirus 360 will say that it is seriously infected with different types of malware. Moreover, Antivirus 360 states that legitimate Windows files are “dangerous threats”. And the only way to remove all detected trash is to purchase licensed version of this pseudo-security software. Also Antivirus 360 may put your data and privacy on risk. So we recommend you to remove Antivirus 360 manually or using our removal tool (Spyware Doctor + antivirus).



How to remove Antivirus 360 manually:
It's possible to remove Antivirus 360 manually , but you have to be very experienced in dealing with registry entries, program files and .dll files.


The files to be deleted:

* %Program Files%\A360\av360.exe
* %UserProfile%\Desktop\Antivirus 360.lnk
* %UserProfile%\Start Menu\Antivirus 360\Help.lnk
* %UserProfile%\Start Menu\Antivirus 360\Registration.lnk
* %UserProfile%\Start Menu\Antivirus 360\Antivirus 360.lnk
* %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 360.lnk


Remove registry entries:

* HKEY_CURRENT_USER\Software\13376694984709702142491016734454
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “13376694984709702142491016734454″

Please be careful because manual removal of Antivirus 360 may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries.