Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

How to protect your account from Phishing attacks


Phishing is a form of social engineering technique used by hackers to gather sensitive information such as usernames, passwords and credit card details by posing as a trustworty person/organization. Since most online users are unaware of the techniques used in carrying out a phishing attack, they often fall victims and hence, phishing can be very effective.
With the dramatic increase in the number of phishing scams in the recent years, there has also been a steady rise in the number of people being victimized. Lack of awareness among the people is the prime reason behind such attacks. This article will try to create awareness and educate the users about such online scams and frauds.
Phishing scams usually sends an email message to users requesting for their personal information, or redirects them to a website where they are required to enter thier personal information. Here are some of the tips that can be used to identify various phishing techniques and stay away from it.

Identifying a Phishing Scam

 
1. Beware of emails that demand for an urgent response from your side. Some of the examples are:
  • You may receive an email which appears to have come from your bank or financial organization stating that “your bank account is limited due to an unauthorized activity. Please verify your account asap so as to avoid permanant suspension”. In most cases, you are requested to follow a link (URL) that takes you to spoofed webpage (similar to your bank website) and enter your login details over there.
  • In some cases, phishing emails may ask you to make a phone call. There may be a person or an audio response waiting on the other side of the phone to take away your credit cards details, account number, social security number or other valuable data.
2. Phishing emails are generally not personalized. Since they target a lagre number of online users, they usually use generalized texts like “Dear valued customer”, “Dear Paypal user” etc. to address you. However, some phishing emails can be an exception to this rule.
3. When you click on the links contained in a phishing email, you will most likely be taken to a spoofed webpage with official logos and information that looks exactly same as that of the original webpages of your bank or financial organization. Pay attention to the URL of a website before you enter any of your personal information over there. Even though malicious websites look identical to the legitimate site, it often uses a different domain or variation in the spelling. For example, instead of paypal.com, a phishing website may use different addresses such as:
  • papyal.com
  • paypal.org
  • verify-paypal.com
  • xyz.com/paypal/verify-account/
 

Tips to Avoid Being a Victim of Phishing

 
1. Do not respond to suspicious emails that ask you to give your personal information. If you are unsure whether an email request is legitimate, verify the same by calling the respective bank/company. Always use the telephone numbers printed on your bank records or statements and not those mentioned in the suspicious email.
2. Don’t use the links in an email, instant messenger or chat conversation to enter a website. Instead, always type the URL of the website on your browser’s address bar to get into a website.
3. Legitimate websites always use a secure connection (https://) on those pages which are intended to gather sensitive data such as usernames and passwords, account numbers or credic card details. You will see a lock icon Picture of the Lock icon in your browser’s address bar which indicates a secure connection. On some websites like paypal.com which uses an extended validation certificate, the address bar turns GREEN as shown below.
HTTPS Address Bar


In most cases, unlike a legitimate website, a phishing website or a spoofed webpage will not use a secure connection and does not show up the lock icon. So, absence of such security features can be a clear indication of phishing attack. Always double-check the security features of the webpage before entering any of your personal information.
4. Always use a good antivirus software, firewall and email filters to filter the unwanted traffic. Also ensure that your browser is up-to-date with the necessary patches being applied.
5. Report a “phishing attack” or “spoofed emails” to the following groups so as to stop such attacks from spreading all over the Internet:
You can directly send an email to spam@uce.gov orreportphishing@antiphishing.org reporting an attack. You can also notify the Internet Crime Complaint Center of the FBI by filing a complaint on their website: www.ic3.gov.

Your Facebook Friends as CAPTCHAs

Web applications often use CAPTCHAs to ensure that real human beings and not bots are using the system. These CAPTCHAs are mostly a combination of words that are distorted enough so that only human eyes can read and solve them.
Facebook is however taking a more social approach to CATCHA solving.

Traditional CAPTCHAs are often hard to solve and therefore Facebook is experimenting with social authentication where you don’t have to recognize letters but images - they’ll show you a few pictures of your friends and ask you to name the person in those photos.


ALSO SEE: NEW FACEBOOK PROFILE LAYOUT HACK

Check working of your antivirus ??


Most of pc are now affected with virus and we all are using different type of antivirus but still our pc is not secure so to check proper functioning of our antivirus there is a simple trick

To Check if your AntiVirus is Working :

  • Open Notepad.
  • Now Copy this code in the text file….

    X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

  • Then save it with the name fakevirus.exe

Now, If the File got Detected Immediately .. It means your Antivirus is working Properly.

Info : This test virus was developed by the European Institute for Computer Anti-Virus Research (EICAR) to provide an easy (and safe!) way to test whether your anti-virus software is working, and see how it reacts when a virus is detected. It is supported by most leading vendors, such as IBM, McAfee, Sophos, and Symantec/Norton.

Register username for your facebook profile and pages


Untitled-1In twitter you have profile url like www.twitter.com/technowit which is simple and can  easily be remembered. Its simplicity also helps in promoting any product as it prevents going on twitter copying and pasting the profile address. Any person can easily type it whenever needed.

The same can be done with facebook. In twitter the its asked during the registration itself but in facebook it has to be selected afterwards.
You can select username for your facebook profile and also pages that you have created.As I told earlier selecting any username shorts the address and can also be easily remembered.
Its really easy to select the username. Login to your facebook account and visithttp://www.facebook.com/username/. There you will be asked to select username for both the username profile and pages.
Just select and save it.

for Technowit

Remember once you have saved the username then their is no turning back that is you can't change it afterwards. If you have any question then visit  Facebook Help center

Protect Your Email from SPAM



Email Spam is basically technique of sending abusive and unwanted emails to people who are not willing to receive it. Like someone has launched a website he will send thousands of emails to thousands of people. This will lead to flooding the email IDs.People spam for many purposes like for increasing their website traffic, for increasing the sale of their products etc. This has been declared illegal in many parts of the world. Many malicious hackers infect computers with viruses and worms and it is called zombie networks. Then these infected computers are used by Malicious Hackers for spamming.

How to protect yourself from SPAM?

1:) You should use SPAM filters to protect from SPAM for example spam fighter.

2:) Don’t reply to the email which looks suspicious to you.

3:) Give your email ID to trustworthy websites for signing for newletters.

4:) If you want to post your email ID post in this format emailaddress(at)yoursite.com or emailaddress[at]yoursite.com

What to Do When Your Email Account is Hacked?


It can be a real nightmare if someone hacks and takes control of your email account as it may contain confidential information like bank logins, credit card details and other sensitive data. If you are one such Internet user whose email account has been compromised, then this post will surely help you out. In this post you will find the possible ways and procedures to get back your hacked email account.

For Gmail:

It can be a big disaster if your Gmail account has been compromised as it may be associated with several services like Blogger, Analytics, Adwords, Adsense, Orkut etc. Losing access to your Gmail account means losing access to all the services associated it with too. Here is a list of possible recovery actions that you can try.
Step -1: Try resetting your password since it is the easiest way to get your account back in action. In this process Google may ask you to answer the secret question or may send the password reset details to the secondary email address associated with your compromised account. You can reset you password from the following link
If you cannot find success from the Step-1 then proceed to Step-2.
Step-2: Many times the hacker will change the secret question and secondary email address right after the account is compromised. This is the reason for the Password Reset process to fail. If this is the case then you need to contact the Gmail support team by filling out the account recovery form. This form will ask you to fill out several questions like
1. Email addresses of up to five frequently emailed contacts
2. Names of any 4 Labels that you may have created in your account
3. List of other services associated with your compromised account
4. Your last successful login date
5. Account created date
6. Last password that you remember and many more…
You need to fill out this form as much accurately as possible. It is obvious to forget the dates of last login, account creation and similar terms. However you need to figure out the closest possible date/answers and fill out this form. This is your last chance! The more accurate the information filled out in the recovery form, the more the chances of getting your account back. You may reach the account recovery page form the following link

For Yahoo and Hotmail:

Unfortunately for Yahoo/Hotmail there is no second option like filling out the form or contacting the support team. All you need to do is either answer the secret questions that you have setup or reset the password using the secondary email option.
To initiate the password reset process just click on the Forgot password link in your login page and proceed as per the screen instructions.
I hope this post will help you recover the lost account. 

Know Whats Hidden Inside that Short URL!


These days, we see a lot of “Short” URLs on the net. People use several URL shorteners to shorten lengthy URLS for ease of use. But a short URL won’t tell us where we are going. If some one have shorted a URL of a malware site.. we won’t know that we are been tricked until we visit that site! That’s why we should know where we are going!
If you use Twitter, you might have noticed that everyone use short URLS. Even if we use a long URL, Twitter will automatically shrink it. But nobody knows where these URLS will take you until that page loads in your browser. Because of this problem, recently, Twitter got some big spam and phishing attacks. Some used short URLS to direct you to a false Twitter login page which will steal your login details and use your account to send more spam!
Recently few bloggers introduced a system which will help you to extract the short URL and tell you where that URL will direct you! KnowURL.com supports almost all the URL shortening sites like bit.ly and tinyurl. Now you can learn where your heading before you step into trouble.
To use this service, simply put your short URL in the given text field and click on “Show URL”. After that they will reveal the true identity of your link within few seconds!
Now, don’t forget to watch where you are going before you bump right into a trap! So, what do you think? Isn’t this tool really useful?


How to Make a Good Password













Creating a Strong Password

Before we begin, you must be clear on one big truth: there is no such thing as a perfect password. A committed hacker can crack any password, given enough time and the right "dictionary" or "brute force" tools. But just like breaking into a car, if the protection is strong enough, the hacker will become discouraged and give up before the protection fails.

How Hackers Crack Passwords

Hackers use one of two major techniques: password recovery (an administrator's technique), and "brute force" repetition. The password recovery tries to fool your computer system into trusting the hacker as a legitimate administrator. Brute force is simply repetitve attempts at your password, up to hundreds of attempts per minute, to crack it.

"Brute Force" Repetition

Hackers often use software tools called "brute force dictionaries"...software that quickly recombines English dictionary words with thousands of varying combinations of spellings. (Yes, much like a Hollywood safecracker movie scene, but slower and less glamorous.)
Brute force dictionaries always start with simple letters "a", "aa", "aaa", and then eventually moves to full words like "dog", "doggie", "doggy". These brute force dictionaries can make up to 50 attempts per minute in some cases. Given several hours or days, these dictionary tools will overcome any password. The secret is to make it take days for your password!

The Password Challenge: "How Can I Make It Tough to Crack, But Easy to Remember?"

Indeed, how does one balance these two contrary objectives? A long password of cryptic characters will be strong, but so frustrating to remember. Yet a short-and-easy password will get cracked within minutes by a good hacker.

Gratefully, there are some helpful tips to create a strong-yet-memorizable password. The idea behind these next five password suggestions is to turn an easy-to-remember phrase into a cryptic word that will discourage hackers.

6 Tips to a Strong Password

1) Make your password long – 6 characters is OK, 10 characters is good, and 15 characters is excellent. 15 is really desirable for high-level security, because 15 is a special number in Microsoft Windows. At 14 characters and less, Windows passwords are scrambled as “hashes” (encrypted into unseen scrambled characters), and stored in hidden Windows system files. It is possible for a gifted hacker to access those stored hashes and unscramble your passwords. However, MS Windows no longer stores hashed passwords at 15 characters and longer. Yes, it is annoying to type 15 characters just to log into your account, but some situations may merit the effort. For example: you are the chief financial officer of a company, or you are the master sergeant for a military unit

2) Start designing the password with a memorable meaningful phrase..then make it complex by adding numbers and special characters. Here is how you do it:

    1. Pick a word or multi-word phrase that is meaningful to you.
    2. Mix one or two letters to be upper case.
    3. Then change one or two letters to be numbers.
    4. Then for the sneaky twist: insert one or two non-alphabetic characters. The beginning or end of the password is easiest for memorization purposes. Examples include: .(period), !,*, %, &, or #.
    5. 3) Change your password every 4 weeks. Many employers serious about protecting their data will require their employees to change their password on a regular basis, once a month at minimum. It is a good practice to do the same on your home computer where you keep private financial information.

      4) Do not store your password on paper or with storage software Please avoid password-keeper programs that claim to make your life easier. It is the opinion of this writer that password products do not offer enough protection for your login information should your computer get hacked. It is better to memorize a password whenever possible. Never keep your passwords on a piece of paper under the keyboard or in your wallet. Do not keep them in your PDA either; if you must store your passwords at all, keep the passwords’ hints instead. For example, as an alternative to storing “Dexter2Gouda” use “puppy’s name, age and favorite snack”.

      5) Use different passwords for your different computer accounts. As annoying as it is to remember them all, please do create a different password for your email, for your online banking, for your eBay and your PayPal. Should one of your passwords ever be compromised, at least the hacker will not be taking over all of your accounts.
    6. Advanced Tips for Designing Strong Passwords:


        • If you frequently login to various websites and keep re-using the same password for all of them, check out Nic Wolff’s clever password generator utility here:http://angel.net/~nic/passwd.html
        • The idea behind Nic Wolff's utility is to have one “master password” to secure all your other passwords, no matter how many of them you have!
        • Although the mathematical encryption is complex, the Master Password itself is easy to use. The whole Wolff Master Password process is explained in a short movie tutorial created by InfoWorld’s Jon Udell here:
          These utilities are free and none of the passwords you generate with these scripts is transmitted or stored anywhere.
          6) use spaces one of the working method found by me is to use spaces at the last of your password. you can set any number of password behind your password it depend upon u.this is going to protect your account from phishing etc
          Good luck with keeping your private information private! We can never completely stop hackers or car thieves, but we can certainly make these scoundrels work for it if they want to hack our accounts.







Now share your desktop via internet

If you are looking for an efficient, easy and free way to connect securely to a computer at another physical location to take control of its screen, mouse and keyboard, CrossLoop enables you to do just that.. for Free. CrossLoop enables you to see the screen and control the mouse and keyboard on a remote computer using an encrypted connection which utilizes the Blowfish 128 bit algorithm. All that needs to be done is download the CrossLoop application and run it at both computers that shall take part in the process.

The host, that is the computer that sends it screens to the other computer, has to setup an access code and the computer that wants to join has to enter that access code to be able to establish the connection. A random access code is generated when you click on the Host tab. This service is really worth it.. do give it a try..


Link: http://www.crossloop.com/

How to find IP Address and Location of an Orkut Profile User

First Step, Create a Blog. I would use blogger in this example, but you may use any blog which allows embedding HTML and JavaScript Codes. Don't use a popular blog which gets many hits because it would be hard to track the user of the Orkut ProfileCreate a StatCounter Account and "Add new Project". Setup is very simple you just need your blog address and access rights.Install the StatCounter code in your blog, you have two methods one is in the StatCounter Website and other is manually embedding the code. For both you have to click Install Code after you have successfully added the project.Your Code would look something like this.

Code corrupted. Insert fresh copy.
You have to install that in your blog as in the illustration below.Now the final step. You just have to compose a convincing enough message for your target to click on (Not very hard eh!). It can be through Scrap or Community whatever way you can get through. If you cannot contact or get the person to click on the link then this method would not work.Once he/she click it, a detailed record would come up in the StatCounter Website.
If the target has been harassing you or doing something illegal, you may contact the police and get more details from the ISP. Now you all know it! :)
~~The End~~