Showing posts with label Google. Show all posts
Showing posts with label Google. Show all posts

Monday, November 4, 2013

How To Stop Your Face From Appearing in Ads?

Imagine Your Face in Google Ads


When it comes to developers of popular free tools, Google is king. Yet the tradeoffs for using tools like YouTube, Gmail and Google+ are becoming clearer. For instance, starting November 11, Google will be able to include Google+ users' faces, names and comments in ads. Configured as a default, the policy is one that users must opt out of if they do not want their images projected in marketing messages.

Here's exactly how to stop your face from appearing in what are being called "adver-dorsements" (at least for now, until Google+ changes again):

  • Navigate to Shared Endorsements in Google+ settings.
  • Uncheck the box next to "Based upon my activity, Google may show my name and profile photo in shared endorsements that appear in ads."

Understand that this will not stop your network from being able to see those companies and brands that you have liked (or in Google+ language, plus-one'd).

If this makes you uncomfortable, simply stop hitting +1 and do not leave any reviews on Google products.  

Tuesday, October 8, 2013

How Much Information You Are Leaving Online?

Do you ever feel like you're being followed?

Perhaps that's because you are. While it may not be the boogeyman who's hot on your trail, there are many groups of watchers who have made it their business to know as much about you as possible.

Each day, we are tracked by the 'smart' systems, mobile apps, personal communication devices and other surveillance platforms that have become commonplace in our daily lives. In an effort to educate more people about the data trails they are leaving behind (and the companies, data bureaus and marketers who are sniffing out that trail).


How comprehensive profiles Google is capable of building based on all the information we voluntarily share?



How valuable your online information is to burglars?


Notice all they can get off of *your* social network sites...and those of your friends, family and co-workers. Be aware of what you put out there!

For those of you in charge of or influencing your company privacy policies, consider how you are gathering and sharing your customers' data. Are you doing so in a manner that is transparent and compliant?

Monday, August 5, 2013

Beware - Trojans on Google Play Infected Up to 25,000 Devices

Malicious Apps were designed to send text messages to premium numbers

Researchers at Russian anti-virus company Doctor Web recently uncovered three malicious Android apps on Google Play that install the Android.SmsSend Trojan, which sends text messages to premium numbers without the user's permission.

All three apps, which are audio players and a video player that displays adult content, were uploaded by a Vietnamese developer called AppStore Jsc.

According to Doctor Web, the apps have been installed between 11,000 and 25,000 times.

Each app asks the user for permission to download additional content, such as adult video clips in the case of the video app -- but that download the installs the Trojan.

"The program covertly sends short messages to the short number 8775 which is specified in the malware's configuration file," Doctor Web notes.

"It is noteworthy that this Trojan really does enable a user to view adult video clips. Apparently, the attackers implemented this feature to avoid unnecessary suspicion."

Sunday, July 7, 2013

Hackers can control almost all Android phones

NINETY-nine per cent of all Android devices are vulnerable to hacking or being completely taken over remotely by cyber criminals

This is the claim of a study by BlueBox security, a mobile security company which claims it has discovered a flaw in the operating system of almost all Google phones and tablets (which runs on the operating system Android) that allows hackers to modify its code in a way that "turns any legitimate application into a malicious Trojan" virus.

The company claims this vulnerability exists on any Android phone or tablet released over the last four years, affecting approximately 900 million devices.

According to the researchers the issue is central to Google's open source operating system and so far only one device has been patched.

The way it works:

Rather than creating a malicious app, cyber criminals wait for legitimate apps to be approved for sale and then go in and modify the code after and create an exploit that allows them to take over people's phones via the app.

This flaw would allow hackers to access your passwords, credit card information, emails, any information you store on your phone.

So what can I do about this?

  • Do not allow apps from unkown sources. To do this go to Settings, Security and untick "allow unknown sources".
  • It's recommended that users update their operating system to the latest version.
  • if you have any apps which store your personal information such as credit card or PayPal information (like eBay, Amazon or Etsy), you should remove this information immediately.
  • Remove any personal information from your phone (do you have your credit card pin stored in your notes?

Friday, June 21, 2013

5 Easy Ways To Secure Android Devices

Here are some basic steps anyone can take -- including enterprise workers -- to improve security on their personal Android BYOD devices

Android isn't exactly the preferred mobile OS in most enterprises, thanks to security concerns. Even as Google's open source platform dominates the mobile consumer market, it lags far behind Apple's iOS in the enterprise, based on activation numbers from mobile device management vendors such as Good Technology and Citrix.

But Android is a presence in the enterprise. Citrix reports that 35% of the devices it activated in Q4 through its cloud-based mobile management platform were running on Android. Even Good Technology's lowball activation figure of 23% in Q4 means nearly one in four new enterprise mobile devices on its MDM platform are Androids.  

As any IT pro can tell you, it's the unmanaged devices you have to watch out for. The personal smartphones employees use to access work data often fly under the radar screen -- that's what sparked the BYOD revolution. Most enterprises no longer fight BYOD, but try to manage it to one degree or another. And even if an enterprise approves the use of Android devices, not all are using MDM vendors or security platforms such as Samsung's SAFE and KNOX. 

1. Always lock your Android device: A no-brainer, but too often ignored because someone doesn't want to go through the hassle of typing in a four-digit PIN to unlock their phone. If that device is lost or stolen, it's an open book -- a book contains personal or work information. In addition to using a PIN, you can secure any device running Android 4.0 or newer versions by using Face Unlock.

This security feature hasn't exactly been air-tight -- it could be fooled with a photograph -- but reportedly Google is rolling out an improved version. Still another way to lock an Android device is a pattern lock, in which you access the device by drawing a specific pattern on the touchscreen. Again, this isn't optimal: Patterns can be detected on the touchscreen by holding it at the right angle, though there's a "secure wipe" feature that limits the number of access attempts.

Bottom line: When it comes to securing your hardware, something is better than nothing.

2. Install antivirus software: People are so used to everything being on their mobile devices these days that some assume they're automatically protected from viruses and malware. Such naivete would be touching if it weren't so dangerous to your enterprise.

Sadly, while Google reportedly now does a better job policing its Play apps store, the sheer number of apps (more than 700,000) mean some nasty malware is going to sneak in and await download from a trusting mobile device owner, who may work for your enterprise.

Further, there are many sketchy websites out there, loaded up with viruses ready to infect an unsuspecting visitor.

3. Always use encryption: Encrypting data makes it impossible for someone else to read what's on your Android device. An Android owner can do this by merely going to Settings, Location & Security, Data Encryption. There's also an option that allows users to encrypt files saved to the phone's memory card.

4. Never download apps from unsolicited emails and texts: Mobile devices are more "personal" and less formal than computers to many users, so some let their guard down and will out of curiosity follow links from mystery emails and texts ("it must be from one of my many social media friends!"). 

This is an extremely unsafe and unnecessary practice. Not only should apps not be downloaded from third-party sites, they shouldn't be downloaded until the user reads a review of the app. Two minutes of research can save a lot of problems down the road.

5. Always check apps permissions: What makes Android versatile -- developers and manufacturers can roll their own versions -- also makes it dangerous. That's because apps developers are free to mess with the permissions, so Android apps can come with wildly different rules for what the app can do on a device.

That may include sharing and sending data from an Android. This is the last prevention step a user can take to control what an app can do to their phone and data. It's worth spending the extra time.


Wednesday, February 13, 2013

In-House App Stores is MUST for Enterprise?

A Do-it-Yourself Approach to Ensuring Mobile Security

As personal mobile devices become ubiquitous in corporate networks - even in organizations without official bring-your-own-device policies - IT and security personnel are implementing new approaches to prevent malware and ensure data integrity. 

One approach beginning to take root is the creation of in-house corporate app stores, where organizations offer users access to custom-built, secure applications designed specifically for that organization, along with access to approved public apps for smart phones, tablets and other personal devices.

Tackling Application Insecurity

With malware infesting the authorized commercial app stores, including the two largest - Google Play for Android and to a lesser extent, the Apple iOS App Store - corporate security and IT executives are exploring new strategies to limit the use of unauthorized applications on devices connected to corporate networks.

Because of the rapid growth in the use of personal devices for work-related tasks, IT departments generally do not permit users to install any application on corporate computers but many companies still have not yet established similar policies for personal devices. 

Companies that opt for a private app store can minimize much of that risk by requiring users to select only from applications that are certified by their employer as safe.

Any suggestions or ideas?

Friday, November 2, 2012

NIST Drafts Guidance on Securing Smart Phones & Tablets

3 Key Facets of Mobile Device Security

Securing mobile devices - whether employee or enterprise owned - has become vital for many organizations and government agencies as the devices increasingly take the place of PCs and laptops.

The National Institute of Standards and Technology has issued a draft of guidance that defines the fundamental security components and capabilities needed to help mitigate risks involved in using the latest generation of mobile devices.

Andrew Regenschied, one of the co-authors of Special Publication 800-164 (Draft): Guidelines on Hardware-Rooted Security in Mobile Devices, says many mobile devices lack a firm foundation from which to build security and trust. 
These guidelines are intended to help designers of next-generation mobile phones and tablets improve security through the use of highly trustworthy components, called roots of trust, that perform vital security functions.
On laptop and desktop systems, Regenschied explains, roots of trust are implemented in a tamper-proof separate security computer chip. But the power and space constraints in mobile devices have led manufacturers to pursue other approaches, such as leveraging security features built into the processors these products use. NIST says the guidelines focus on three security capabilities to address known mobile device security challenges: device integrity, isolation and protected storage.

According to NIST, a tablet or phone supporting device integrity can provide information about its configuration and operating status that can be verified by the organization whose information is being accessed. Isolation capabilities can keep personal and organization data components and processes separate. That way, NIST says, personal applications should not be able to interfere with the organization's secure operations on the device. Protected storage keeps data safe using cryptography and restricting access to information.

To achieve the security capabilities, the guidelines recommend that each mobile device implement three security components that can be employed by the device's operating system and applications:

  • Roots of trust, which combine hardware, firmware and software components to provide critical security functions with a very high degree of assurance that they will behave correctly;
  • An application programming interface that allows operating systems and applications to use the security functions provided by the roots of trust; and
  • A policy enforcement engine to enable the processing, maintenance and policy management of the mobile device. NIST is seeking comments on the draft guidance.

Those with suggestions should submit them to 800-164comments@nist.gov by Dec. 14.

Sunday, February 26, 2012

Google Chrome to offer easy-way to construct stronger passwords

Google Password Generator in the Works

Google is in the process of developing a tool to help users generate strong passwords for the various and sundry Web sites for which they need to register and authenticate. The password-generator is meant to serve as an interim solution for users while Google and other companies continue to work on widespread deployment of the OpenID standard.

The tool that Google engineers are working on is a fairly simple one. For people who are using the Chrome browser, whenever a site presents them with a field that requires a password, Chrome will display a small key icon, letting the users know that they could allow Chrome to generate a password for them.
"Detecting when we are on a page that is meant for account sign up will be most of the technical challenge. This will likely be accomplished via heuristics (i.e. there is an account name field and two password fields). If we determine that this is a signup page, then we will add a small UI element to the password field. If the user clicks on this element, we will pop up a small dialogue box next to field asking the user if they would like Chrome to manage this password for them," the project page on Chromium Projects says.
"If they accept the prompt then we pop up a small box which is prepopulated with what we think is an acceptable random password. The reason we don't just choose a password for them is that many sites have requirements (e.g. must have one digit, must be alphanumeric, must be between 6 and 20 characters) some of which may be contradictory between sites.

So we will choose a default generator that will work on most sites, but users may need to change our password if it doesn't work. We can skip this for sites that have 'pattern' set on the password field. Long term we can hopefully also gather some aggregate information from UMA users about the form of passwords they generated so that this whole process can be skipped for the vast majority of sites."
Password management has become a major pitfall for many users in recent years as the number of sites that require authentication has exploded. As users have been required to register with more and more sites and services, including mobile apps and games, many of them have naturally tended to re-use passwords and use weak or easily guessable ones.

This has been a boon for data thieves who, after stealing a database of usernames and passwords from one retailer or Web site, find that they often can compromise any number of other accounts belonging to those victims simply by re-using the passwords.

A variety of services and products have emerged to help address the problem of password generation and management, including applications that will generate random passwords or store existing passwords in an encrypted form. But the problem has persisted.

Google's password generator, which is in the development stage, won't be able to protect users in every scenario. It's meant for use in situations where users are signing up for a new service or need to set a new password. In situations where a user is simply signing in to an existing account, it won't be of use. It also may not protect against a majority of phishing sites.
"Any website that has autocomplete turned off will not be able to be protected. Going by current phishing attacks, this means that 40-70% of phishing pages can't be protected against. Once this feature is rolled out we probably want to see if we can get around this problem. Maybe we can get users to re-authenticate to the browser before logging into such sites," the Google documentation says.

Tuesday, February 7, 2012

Ten little things to secure your online presence

Life online can be a bit of a minefield, especially when it comes to avoiding malicious hacker attacks.

Here’s some basic advice on the tools and tricks you can implement immediately to secure your identity and online presence.

You’ve all heard the basic advice — use a fully updated anti-malware product, apply all patches for operating system and desktop software, avoid surfing to darker parts of the Web, etc. etc.

Those are all important but there are a few additional things you can do to secure your online presence and keep hackers at bay. Here are 10 little things that can provide big value:

1. Use a Password Manager

Password managers have emerged as an important utility to manage the mess of creating strong, unique passwords for multiple online accounts. This helps you get around password-reuse (a basic weakness in the identity theft ecosystem) and because they integrate directly with Web browsers, password managers will automatically save and fill website login forms and securely organize your life online.

Some of the better ones include LastPass, KeePass, 1Password, Stenagos and Kaspersky Password Manager. Trust me, once you invest in a Password Manager, your life online will be a complete breeze and the security benefits will be immeasurable.

2. Turn on GMail two-step verification

Google’s two-step verification for GMail accounts is an invaluable tool to make sure no one is logging into your e-mail account without your knowledge. It basically works like the two-factor authentication you see at banking sites and use text-messages sent to your phone to verify that you are indeed trying to log into your GMail. It takes a about 10-minutes to set up and can be found at the top of your Google Accounts Settings page. Turn it on and set it up now.

While you’re there, you might want to check the forwarding and delegation settings in your account to make sure your email is being directed properly. It’s also important to periodically check for unusual access or activity in your account. You can see the last account activity recorded at the bottom of GMail page, including the most recent IP addresses accessing the account.

3. Switch to Google Chrome and install KB SSL Enforcer

With sandboxing, safe browsing and the silent patching (auto-updates), Google Chrome’s security features make it the best option when compared to the other main browsers. I’d also like to emphasize Google’s security team’s speed at fixing known issues, a scenario that puts it way ahead of rivals.

Once you’ve switched to Chrome, your next move is to install the KB SSL Enforcer extension, which forces encrypted browsing wherever possible. The extension automatically detects if a site supports SSL (TLS) and redirects the browser session to that encrypted session. Very, very valuable.

4. Use a VPN everywhere

If you’re in the habit of checking e-mails or Facebook status updates in coffee shops or on public WiFi networks, it’s important that you user a virtual private network (VPN) to encrypt your activity and keep private data out of the hands of malicious hackers.

The video above explains all you need to know about the value of VPNs and how to set it up to authenticate and encrypt your web sessions. If you use public computers, consider using a portable VPN application that can run off a USB drive.

5. Full Disk Encryption

The Electronic Frontier Foundation (EFF) has made this a resolution for 2012 and I’d like to echo this call for computer users to adopt full disk encryption to protect your private data. Full disk encryption uses mathematical techniques to scramble data so it is unintelligible without the right key.

This works independently of the policies configured in the operating system software. A different operating system or computer cannot just decide to allow access, because no computer or software can make any sense of the data without access to the right key. Without encryption, forensic software can easily be used to bypass an account password and read all the files on your computer.

Here’s a useful primer on disk encryption and why it might be the most important investment you can make in your data. Windows users have access to Microsoft BitLocker while TrueCrypt provides the most cross-platform compatibility.

6. Routine Backups

If you ever went through the sudden death of a computer or the loss of a laptop while travelling, then you know the pain of losing all your data. Get into the habit of automatically saving the contents of your machine to an external hard drive or to a secure online service.

Services like Mozy, Carbonite or iDrive can be used to back up everyone — from files to music to photos — or you can simply invest in an external hard drive and routinely back up all the stuff you can’t afford to lose. For Windows users, here’s an awesome cheat sheet from Microsoft.

7. Kill Java

Oracle Sun’s Java has bypassed Adobe software as the most targeted by hackers using exploit kits. There’s a very simple workaround for this: Immediately uninstall Java from your machine. Chances are you don’t need it and you probably won’t miss it unless you’re using a very specific application. Removing Java will significantly reduce the attack surface and save you from all these annoying checked-by-default bundles that Sun tries to sneak onto your computer.

8. Upgrade to Adobe Reader X

Adobe’s PDF Reader is still a high-value target for skilled, organized hacking groups so it’s important to make sure you are running the latest and greatest version of the software. Adobe Reader and Acrobat X contains Protected Mode, a sandbox technology that serves as a major deterrent to malicious exploits.

According to Adobe security chief Brad Arkin says the company has not yet been a single piece of malware identified that is effective against a version X install. This is significant. Update immediately. If you still distrust Adobe’s software, you may consider switching to an alternative product.

9. Common sense on social networks

Facebook and Twitter have become online utilities and, as expected, the popular social networks are a happy hunting ground for cyber-criminals. I strongly recommend against using Facebook because the company has no respect or regard for user privacy but, if you can’t afford to opt out of the social narrative, it’s important to always use common sense on social networks.

Do not post anything sensitive or overly revealing because your privacy is never guaranteed. Pay special attention to the rudimentary security features and try to avoid clicking on strange video or links to news items that can lead to social engineering attacks. Again, common sense please.

10. Don’t forget the basics

None of the tips above would be meaningful if you forget the basics. For starters, enable Windows Automatic Updates to ensure operating system patches are applied in a timely manner. Use a reputable anti-malware product and make sure it’s always fully updated.

Don’t forget about security patches for third-party software products (Secunia CSI can help with this). When installing software, go slowly and look carefully at pre-checked boxes that may add unwanted crap to your machine. One last thing: Go through your control panel and uninstall software that you don’t or won’t use.

Monday, August 8, 2011

Researcher discovered ABB-branded transformer running an electricity substation

SCADA equipment Google-able

Most SCADA protocols do not use encryption or authentication, and they don't have access control built into them or into the device itself. This means that when a PLC has a web server, and is connected to the internet, anyone who can discover the internet protocol (IP) address can send commands to the device, and the commands will be performed.

If that RTU or PLC has large motors connected to it, pumping out water or chemicals, the equipment could be turned off. If it was a substation and the power re-closer switches were closed, we could break it open and create an [electricity] outage for an entire area or city. The bottom line is you could cause physical damage to whatever is connected to that PLC.

While SCADA security has been an issue for decades, as legacy systems have been connected to the internet and remote technologies have emerged, with the emergence of Stuxnet, a worm that spreads via holes in Windows, but specifically targets Siemens SCADA systems and uses other sophisticated methods. Experts theorise that Stuxnet was designed to sabotage Iran's nuclear development program.

However, Stuxnet has raised awareness in the general public and within companies running critical infrastructure systems, and scared some of them enough to beef up their security. Stuxnet created an interest in the community to learn more about vulnerabilities and SCADA systems. We've seen direct impact in our customers being able to get funding to secure their SCADA systems.

While Stuxnet appears to have run its course and had minimal impact, SCADA systems are at risk from vulnerabilities and exploits in general, the US ICS-CERT (Industrial Control System Computer Emergency Response Team).

Not only are Supervisory Control and Data Acquisition (SCADA) systems used to run power plants and other critical infrastructure lacking many security precautions to keep hackers out, operators also sometimes practically advertise their wares on Google search, according to a demo held yesterday during a Black Hat conference workshop.

Monday, July 4, 2011

Hole in Google Chrome that granted unauthorised access to gmail accounts

Web extensions to become a new attack vector

A penetration tester has exploted a hole in Google Chrome that granted unauthorised access to gmail accounts.

WhiteHat Security researcher Matt Johansen identified the vulnerability in a Chrome OS note-taking application. He disclosed the hole to Google which patched it and gave him US$1000 as part of its Chromium security initiative.

Johansen told Reuters he intercepted data travelling between a Chrome browser extension and the Google cloud. Google has not yet revealed details of the security hole which Johansen plans to release at the Black Hat conference in Las Vegas this year.

Google extensions, written by third party software developers, were a ripe target for attack because they were granted more privileged access rights to Google cloud data than what the browser offered to web sites.

WhiteHat security detailed in a 2007 research paper a series of web application security vulnerabilities that could also be used to attack web browser extensions in Chrome and Mozilla FireFox.

Chrome OS director Caesar Sengupta said there are "significant benefits to security" by storing apps within the browser.

Tuesday, June 7, 2011

Google E-mail Hacked by China?

China denies any role in an alleged hack

Google on June 1 alleged that Chinese hackers attacked the Gmail accounts of several hundred U.S. officials, including military personnel, in an effort to obtain passwords and monitor the accounts.

Google says it detected and stopped the phishing campaign, which aimed to take users' passwords and monitor their e-mail activity. The White House's National Security Council is looking into Google's allegations and says it's working with the FBI to investigate the situation.

Google, meanwhile, offers these tips to its customers:
  • Enable two-step user verification.
  • Use a strong password for Google that you do not use on any other site.
  • Enter your password only into a proper sign-in prompt on a https://www.google.com domain.
  • Check your Gmail settings for suspicious forwarding addresses or delegated accounts.
  • Watch for the red warnings about suspicious account activity that may appear on top of your Gmail inbox.
  • Review the security features offered by the Chrome browser.
Please refer here for further details.

Sunday, March 20, 2011

Sharing some Information Security Resources

Latest Information Security whitepapers

Web 2.0 Security Summit (Webcasts, March 16, 2011 or afterward on demand)

Hear from OWASP, SonicWALL, Accenture, Websense, Aberdeen Group, Fortinet and other security visionaries as they look into the new paradigm of web 2.0 security threats, the issues of privacy, and practical tips on how to prevent large scale data leaks from happening to you.

Register: http://bit.ly/fElMev

Social Networking and Security Risks (White Paper)

The popularity of social networking sites has reached astonishing levels. How protected is your company against risks from these platforms?

Download: http://bit.ly/gmPIDv

The Big Shift to Cloud-based Security (White Paper)

Keeping IT systems secure and running within regulatory compliance mandates seems next to impossible. There are many reasons for this — but fortunately, several recent technological trends show that it doesn't have to be this way.

Download: http://bit.ly/hrUzHV

How to Protect Your Organization against Advanced Persistent Threats (White Paper)

This paper outlines the evolution of APTs, explains the motivation behind them, and determines best practices for defending against these threats.

Download: http://bit.ly/e1HHrv

Security for Google Apps Messaging and Collaboration Products (White Paper)

Read this whitepaper to get a comprehensive look at the security controls, processes and technologies that we have implemented in Google Apps.

Download: http://bit.ly/g6NS4h

Friday, January 14, 2011

Google Sandboxes Flash Player

Chrome's 'dev' build for Windows now blocks Flash attack code from infecting PCs

Google has introduced a sandbox version of Adobe’s Flash Player in order to protect users from Flashbased attacks. According to tech news site Computer World, Google has been working with Adobe to transfer Flash Player to the sandbox that comes with Google’s Chrome web user. Users, especially those with PCs running Windows XP OS, have been facing a number of security threats through holes found in Adobe’s Flash Player. The move is set to help protect them from potential attacks exploiting those vulnerabilities by containing the platform in a sandbox and not on the system.

The Windows version of the Chrome web browser with the sandboxed Flash Player is already available for developers, with the public version in the works as well. Peleus Uhley, Adobe’s platform security strategist, said in a statement: The interfaces to open-source browsers are completely different from, say, Internet Explorer, and we had to restructure Flash Player to put it in a sandbox

Monday, November 15, 2010

New Android Bug Lets Spoofed Apps Run Wild

Spoofed Android apps can bypass security permissions

Google has always a lot of control over its products in the hands of its users, and Android OS is probably on of the best examples. When downloading an application, the user is shown just what said application needs to run properly. If the user doesn’t want the app to have access to certain things it requires, you simply don’t download it. Well, it seems that isn’t the case anymore, as there’s now a new bug in town, and it doesn’t need your stinkin’ permission.

A new bug found in Android can allow those with malicious intent to make a spoof application that seems harmless, only to find out that it can roam free on your handset, and download other, more dangerous applications to steal your personal data, without any permission by the user. Tricky tricky.

Intel security researchers Jon Oberheide and Zach Lanier have created such an application. It looks harmless – an Angry Birds add-on pack that after downloaded, will install a handful of programs that will track your location, steal your contacts, and give the hacker the option to send pay-per-texts. While this isn’t the first time we’ve seen this kind of hack attack, it will certainly be unsettling to most users, especially if this bug isn’t fixed pronto.

Refer here to read more details on Forbes.

Tuesday, September 14, 2010

Google Instant may end-up infecting your machine

Malicious Search Suggestions with Google Instant

Google launched its streaming search engine yesterday called Google Instant, which provides people with instant, real-time search results, and also opens the doors to search engine optimisation (SEO) poisoning and other problems.

The problem comes from hackers who create malware or fake antivirus programs and then manage to poison Google's search results in order to get their software high on the list. This is often called blackhat SEO, as it will use traditional SEO tactics but for malicious reasons.All search engines, but Google in particular, are at risk of blackhat SEO and that is not a new problem.

However, because Google Instant literally searches for everything as you type, you could be forced into a situation where you are unwittingly searching for rogueware. “As a test, I thought I'd search for 'antivirus' and see what suggestions came up. Lo and behold, Antivir Solution Pro, a well-known rogueware infection was amongst the suggested search terms,”
said Sean-Paul Correll, threat researcher at Pandalabs and founder of the Malware Database.

For those who are not familiar with the rogueware, they may consider it legitimate, download and install it, resulting in their computer being infected. The fact that the rogueware was second on the list of suggested terms makes this a worrying possibility, as it amounts to Google's search engine recommending malware. It is also interesting to note that the fourth suggested search term is for the removal of that same rogueware.

Monday, August 16, 2010

SEO Poisoning Attack

A Look Inside How It Works

One of the biggest risks that users run across during their everyday Internet browsing at the moment is from what security researchers call search engine optimization poisoning or SEO poisoning. Criminal hackers are taking advantage of our blind trust in popular search engines such as Google and Bing to trick us into clicking into malicious links.

The bad guys use blackhat SEO techniques to boost the page rankings of their bogus sites. As these higher ranked sites start breaking into the top ten and top 20 results of a popular search term, users are lured into trusting the links.

Capitalizing on anything from the Haiti earthquake to Mel Gibson’s rants to the World Cup, these hackers use the links to bait users and then reel them in with malicious downloads. They unwittingly click into a malicious link due to their trust in the search engine. Channel Insider examines just how SEO poisoning is carried out by these bad guys and how common it is to see malicious links within legitimate search results.

Step 1: Compromise legitimate web sites
These will be used to form the foundation of the attack.

Step 2: Create SEO-friendly fake pages related to popular search topics on compromised sites
In the past year hackers have taken advantage of user curiosity about the Olympics, the Haiti earthquake, Corey Haim's death, the World Cup and Mel Gibson's recent craziness to formulate their SEO poisoning attacks.

Step 3: Use Google Hot Trends to search for popular terms
Hackers leverage the hottest search terms and then stuff their fake pages with additional relevant key phrases that track well with the most common way users phrase their searches.

Step 4: Crosslink with other SEO poisoned pages to boost page rankings
Hackers work on scale, with a web of hundreds of crosslink pages to ensure that their malicious sites make it to the top of the page rankings for any given search term.

Step 5: Cloak malicious content from spiders and security researchers
The reason SEO poisoning attacks have been difficult to stymie is because the hackers are shielding their attacks from search engine detection and security do-gooders. Poisoned pages serve up an alternative non-malicious page with relevant keywords and links to other poisoned pages when crawlers view a page and direct traffic to non-malicious content when it doesn't come from a search engine.

Step 6: Deliver payload
If traffic does come from a website, hackers will serve up the bad content. Right now, researchers report that the bulk of SEO poisoning attacks are used to send users to a fake AV scan page to convince them to install bogus AV 'scareware.'

SEO Poisoning By The Numbers
Symantec found that on average 115 of the 300 most popular search terms contained at least 10% malicious links.

SEO Poisoning By The Numbers
Users have a 1 in 3 chance of coming across a malicious link via searches, according to Symantec.

SEO Poisoning By The Numbers
Typically, 15 links out of the first 70 results were malicious for search terms that were found to be poisoned, according to Symantec researchers.

Thursday, June 17, 2010

Hackers use Google trending topics to spread malware

Ensure you have up-to-date virus protection


The Google trends are once again a mix of hot trends, including the Gulf Oil Spill, Michael Jackson, Miley Cyrus, Microsoft and Microsoft Kinect.

Unfortunately, those who are searching for more information on a trending topic are being lured in by hackers who don't provide anything more than an unhealthy dose of malware, a term used for malicious software.

By using clever SEO (Search Engine Optimization) techniques, websites are created that look as if they are filled with information on news topics such as the Gulf oil crisis or supposed pictures of Miley Cyrus in the buff. Unfortunately, the sites can cause a virus to attack your computer and will provide you with absolutely none of the information you are looking for.

Pop-up warnings that inform you that your computer is in danger of facing security issues will often show up when you land on these spammy sites. The warnings are not real and if you click on them, you will download dangerous software on your computer.

There is often a fee for these services and that will threaten the safety of your credit card information as well as your computer if you use it to pay for these fake services.

It is important to have up-to-date virus protection on your computer to help protect against malware.