Gets Latest Technology Updates And Tips

Find Latest Technology Tips, computer and Internet world. Including Reviews and Previews Of Latest Technology and Gadgets, software , Websites and More.....

The Advancement of the Keylogger

Sunday, June 19, 2011

A keylogger is a program that runs in your computer’s background secretly recording all your keystrokes. Once your keystrokes are logged, they are hidden away for later retrieval by the attacker. The attacker then carefully reviews the information in hopes of finding passwords or other information that would prove useful to them.  For example, a keylogger can easily obtain confidential emails and reveal them to any interested outside party willing to pay for the information.



Keyloggers can be either software or hardware based.  Software-based keyloggers are easy to distribute and infect, but at the same time are more easily detectable.  Hardware-based keyloggers are more complex and harder to detect.  For all that you know, your keyboard could have a keylogger chip attached and anything being typed is recorded into a flash memory sitting inside your keyboard. Keyloggers have become one of the most powerful applications used for gathering information in a world where encrypted traffic is becoming more and more common.

As keyloggers become more advanced, the ability to detect them becomes more difficult. They can violate a user’s privacy for months, or even years, without being noticed.   During that time frame, a keylogger can collect a lot of information about the user it is monitoring.  A keylogger can potential obtain not only passwords and log-in names, but credit card numbers, bank account details, contacts, interests, web browsing habits, and much more.  All this collected information can be used to steal user’s personal documents, money, or even their identity. 

A keylogger might be as simple as an .exe and a .dll that is placed in a computer and activated upon boot up via an entry in the registry. Or, the more sophisticated keyloggers, such as the Perfect Keylogger or ProBot Activity Monitor have developed a full line of nasty abilities including:

·         Undetectable in the process list and invisible in operation
·         A kernel keylogger driver that captures keystrokes even when the user is logged off
·         A remote deployment wizard
·         The ability to create text snapshots of active applications
·         The ability to capture http post data (including log-ins/passwords)
·         The ability to timestamp record workstation usage
·         HTML and text log file export
·         Automatic e-mail log file delivery

All keyloggers are not used for illegal purposes.  A variety of other uses have surfaced.  Keyloggers have been used to monitor web sites visited as a means of parental control over children. They have been actively used to prevent child pornography and avoid children coming in contact with dangerous elements on the web.  Additionally, in December, 2001, a federal court ruled that the FBI did not need a special wiretap order to place a keystroke logging device on a suspect’s computer. The judge allowed the FBI to keep details of its key logging device secret (citing national security concerns). The defendant in the case, Nicodemo Scarfo Jr., indicted for gambling and loan-sharking, used encryption to protect a file on his computer. The FBI used the keystroke logging device to capture Scarfo’s password and gain access to the needed file.

How can Possible write emails now but automatically send them later?

Friday, June 17, 2011
















Yes, this is possible but it does depend on the email program you use. Unfortunately, you didn’t tell us anything at all about your computer or software setup so we lack a starting point.

However, we can tell you that all full versions of Outlook from 2000 onwards had this ability. In Outlook 2007 and 2010, for example, create a new email in the usual way (click New).

Now click the diagonal-pointing arrow at the bottom right of the Options group within the Message tab. In the Message Options dialogue box, click to tick the ‘Do not deliver before’ box then use the two dropdown menu options alongside to set the required delivery date and time, then click Close. Now compose your message and click Send – the message will be sent to the Outbox folder. It will stay there until the scheduled date and time and can be edited or deleted in the meantime.

Microsoft’s various free email programs (Outlook Express, Windows Mail and Windows Live Mail) have a Send Later option on the File menu, but it is nowhere near as flexible. Indeed, using this Send Later option merely places the email in the Outbox folder ready for sending the next time you synchronise your emails – so doesn’t provide what you want.

If you don’t have a commercial version of Outlook, and don’t wish to pay to upgrade, then consider Thunderbird: this is a free email application from the same developers that make the popular Firefox browser. Like Firefox, it can be augmented with any number of add-ons, including ones that will schedule email deliveries. To do the job you want we’d recommend the Send Later 3 add-on to go with it.


How to Remove Any Virus From Your Computer

Friday, March 4, 2011



A computer virus is an executable program. Depend on the nature of a virus, it may cause damage of your hard disk contents, and/or interfere normal operation of your computer.
By definition, a virus program is able to replicate itself. This means that the virus multiplies on a computer by making copies of itself. This replication is intentional; it is part of the virus program. In most cases, if a file that contains virus is executed or copied onto another computer, then that computer will also be "infected" by the same virus.

How to Remove viruses, worms, and Trojan horse:-


  1. Download, install and update Anti-Virus Software.
     
    • There are many 'no cost' versions of antivirus software available. My personal favorite is AVG Anti-Virus. You can download AVG Anti-Virus here. For instructions on how to install AVG Anti-Virus - go here.
       
  2. Disconnect from the Internet.
     
    1. Open Internet Explorer - clear your cookies and cache.
       
    2. To delete cookies in IE: Tools >> Internet Options >> on the General tab choose Delete Cookies. You will be asked 'Delete all cookies in the Temporary Internet Files folder? Click OK.
       




  • To delete the cache in IE: Tools >> Internet Options >> on the General tab choose Delete Files. Be sure to place a check in the box that says 'Delete all offline content'. Click OK
     
    • Restart the computer in Safe Mode.
     
    • OPTIONAL: If you are using Windows ME or Windows XP or Vista, disable System Restore.
     
    • Sometimes viruses can hide in System Restore files in which case turning off off system restore will delete those files. (Warning: If you disable System Restore you will remove all previous restore points, which means that you will no longer have the option of restoring the computer to a date when the computer was last functioning normally.)
     
    • Run a full system scan on the computer. This might take some time depending on how much data the anti-virus software needs to sift through. Be patient, let the software do it's job.
    • If you find that the anti-virus software is having trouble removing a virus you might need to run MSCONFIG and figure out which startup process is responsible for loading the infected file.
         
    •   After all viruses have been quarantined or removed, reboot the computer.




    All About Spam Buster

    Wednesday, March 2, 2011




    Spam, Nobody likes it.  Nobody wants it.  No, we aren’t talking about the canned meat, but those unsolicited, unwanted, irrelevant, or even inappropriate messages that hit our email in mass quantities.  While most mailboxes have some type of spam filtering software built into their system, they never seem to do a very good job of catching what you want them to catch, and letting through what you want them to let through.  Therefore, it becomes increasingly important to turn to some type of additional spam filtering product.  One such filtering system, designed for Outlook and Outlook Express users, is receiving rave reviews for its superior detection and low rate of false positives (i.e,. what you want to get through does).


    Cloudmark Desktop, formerly known as SpamNet and SafetyBar, uses a unique community-based filtering process.  This community-based filtering system relies on users to report any new spam.  Within minutes of a spammer being reported, they are placed on a blacklist.  At that point, no other member will receive that particular spam.  Cloudmark also applies the same basic process to phishing email scams. 

    What is interesting is how Cloudmark creates a digital reputation model of reporting spam.  Each user starts with a neutral reputation. A user’s reputation will rise if they are among the first to identify undesirable content.  On the flip side of the coin, a user’s reputation falls when they falsely reports spam.  The result is a system that is automated, highly scalable and resistant to tampering.

    An added bonus is that because the software doesn’t depend upon the user to configure its settings, it installs in minutes and is easy to use.  Cloudmark blocks over 98% of spam from reaching your inbox and boasts over one million users worldwide.

    The cost of program is $39.95 for a one-year subscription.  The subscription is renewable annually.  For those wanting to test drive the product, a free 15-day trial period for either your Outlook or Outlook Express is available.

    About Encryption and Making Your System Secure

    What does encryption do for me?




    Encryption and cryptographic software has been used in many different ways to make systems more secure.  This article discusses only a few ways that such software can make your system more secure, including:

    1) Encrypting your email

    2) Encrypting your files

    To programs are mentioned that will help encrypt information. There are many more programs out there that will help, but these programs are good and a good place to start as any. They have the added benefit of both being free with source code available.

    Will encryption stop people from accessing my information?

    Encryption simply makes it harder for people to gain access to important information, like passwords or sensitive information in a file. The first thing you should know about encryption is that the algorithm that is used to encrypt can be simple or more complex and that affects how securely what you have encrypted is protected.  Encryption systems have been broken when the method of encryption is understood by hackers and is easy to break. 

    Why bother to encrypt my email?

    It should be noted that email is far less secure than paper mail for two very good reasons:  first, electronic data can be accessed easily over an Internet and secondly, electronic data is really simple to copy. There is a very good chance that someone has snooped around in your email despite your best intentions to stop it.

    How do I go about encrypting my email?

    There are many programs out there that can help you encrypt your email.  A very popular one is PGP (Pretty Good Privacy) or its Gnu offshoot GPG.  

    PGP (http://www.pgpi.org/) self-describes itself this way: This "is a program that gives your electronic mail something that it otherwise doesn't have: Privacy. It does this by encrypting your mail so that nobody but the intended person can read it. When encrypted, the message looks like a meaningless jumble of random characters. PGP has proven itself quite capable of resisting even the most sophisticated forms of analysis aimed at reading the encrypted text."

    Why bother to encrypt my files?

    The answer to this boils down to what you store on your computer.  If you have financial data with important information like social security numbers, email addresses, account numbers and passwords, then you open yourself up to losing very valuable information.  Most corporate Internet security employees will attest to the widespread theft of very valuable information. As long as you are connected to the Internet you are vulnerable.

    How do I go about encrypting my files?

    AxCrypt File Encryption Software  (http://axcrypt.sourceforge.net/) Self-described as "Free Personal Privacy and Security for Windows 98/ME/NT/2K/XP with AES-128 File Encryption, Compression and transparent Decrypt and Open in the original application."

    How To Securing Your Computer System?

    Today, more and more people are using their computers for everything from communication to online banking and investing to shopping.  As we do these things on a more regular basis, we open ourselves up to potential hackers, attackers and crackers.  While some may be looking to phish your personal information and identity for resale, others simply just want to use your computer as a platform from which to attack other unknowing targets.  Below are a few easy, cost-effective steps you can take to make your computer more secure.



    1.                  Always make backups of important information and store in a safe place separate from your computer.
    2.                  Update and patch your operating system, web browser and software frequently.  If you have a Windows operating system, start by going to www.windowsupdate.microsoft.com and running the update wizard.  This program will help you find the latest patches for your Windows computer.  Also go to www.officeupdate.microsoft.com to locate possible patches for your Office programs.
    3.                  Install a firewall.  Without a good firewall, viruses, worms, Trojans, malware and adware can all easily access your computer from the Internet.  Consideration should be given to the benefits and differences between hardware and software based firewall programs.
    4.                  Review your browser and email settings for optimum security.  Why should you do this?  Active-X and JavaScript are often used by hackers to plant malicious programs into your computers.  While cookies are relatively harmless in terms of security concerns, they do still track your movements on the Internet to build a profile of you.  At a minimum set your security setting for the “internet zone” to High, and your “trusted sites zone” to Medium Low.
    5.                  Install antivirus software and set for automatic updates so that you receive the most current versions.
    6.                  Do not open unknown email attachments.  It is simply not enough that you may recognize the address from which it originates because many viruses can spread from a familiar address.   
    7.                  Do not run programs from unknown origins.  Also, do not send these types of programs to friends and coworkers because they contain funny or amusing stories or jokes.  They may contain a Trojans horse waiting to infect a computer.
    8.                  Disable hidden filename extensions.  By default, the Windows operating system is set to “hide file extensions for known file types”.  Disable this option so that file extensions display in Windows.  Some file extensions will, by default, continue to remain hidden, but you are more likely to see any unusual file extensions that do not belong.  
    9.                  Turn off your computer and disconnect from the network when not using the computer.  A hacker can not attack your computer when you are disconnected from the network or the computer is off.
    10.              Consider making a boot disk on a floppy disk in case your computer is damaged or compromised by a malicious program.  Obviously, you need to take this step before you experience a hostile breach of your system. 

    What are Intrusion Detection Systems?

    Intrusion Detection System (IDS) are a necessary part of any strategy for enterprise security. What are Intrusion Detection systems?  CERIAS, The Center for Education and Research in Information Assurance and Security, defines it this way:-



    "The purpose of an intrusion detection system (or IDS) is to detect unauthorized access or misuse of a computer system. Intrusion detection systems are kind of like burglar alarms for computers. They sound alarms and sometimes even take corrective action when an intruder or abuser is detected. Many different intrusion detection systems have been developed but the detection schemes generally fall into one of two categories, anomaly detection or misuse detection. Anomaly detectors look for behavior that deviates from normal system use. Misuse detectors look for behavior that matches a known attack scenario. A great deal of time and effort has been invested in intrusion detection, and this list provides links to many sites that discuss some of these efforts"(http://www.cerias.purdue.edu/about/history/coast_resources/intrusion_detection/)

    There is a sub-category of intrusion detection systems called network intrusion detection systems (NIDS).  These systems monitors packets on the network wire and looks for suspicious activity. Network intrusion detection systems can monitor many computers at a time over a network, while other intrusion detection systems may monitor only one.

    Who is breaking into your system?


    One common misconception of software hackers is that it is usually people outside your network who break into your systems and cause mayhem.  The reality, especially for corporate workers, is that insiders can and usually do cause the majority of security breaches. Insiders often impersonate people with more privileges then themselves to gain access to sensitive information.

    How do intruders break into your system?


    The simplest and easiest way to break in is to let someone have physical access to a system.  Despite the best of efforts, it is often impossible to stop someone once they have physical access to a machine. Also, if someone has an account on a system already, at a low permission level, another way to break in is to use tricks of the trade to be granted higher-level privileges through holes in your system. Finally, there are many ways to gain access to systems even if one is working remotely. Remote intrusion techniques have become harder and more complex to fight.


    How does one stop intrusions?



    There are several Freeware/shareware Intrusion Detection Systems as well as commercial intrusion detection systems.

    Open Source Intrusion Detection Systems

    Below are a few of the open source intrusion detection systems:

    AIDE (http://sourceforge.net/projects/aide) Self-described as "AIDE (Advanced Intrusion Detection Environment) is a free replacement for Tripwire. It does the same things as the semi-free Tripwire and more.  There are other free replacements available so why build a new one? All the other replacements do not achieve the level of Tripwire. And I wanted a program that would exceed the limitations of Tripwire."

    File System Saint  (http://sourceforge.net/projects/fss) - Self-described as, "File System Saint is a lightweight host-based intrusion detection system with primary focus on speed and ease of use."


    Snort  (www.snort.org) Self-described as "Snort® is an open source network intrusion prevention and detection system utilizing a rule-driven language, which combines the benefits of signature, protocol and anomaly based inspection methods. With millions of downloads to date, Snort is the most widely deployed intrusion detection and prevention technology worldwide and has become the de facto standard for the industry."

    Commercial Intrusion Detection Systems


    If you are looking for Commercial Intrusion Detection Systems, here are a few of these as well:

    Tripwire
    http://www.tripwire.com

    Touch Technology Inc (POLYCENTER Security Intrusion Detector)
    Http://www.ttinet.com

    Internet Security Systems (Real Secure Server Sensor)
    http://www.iss.net


    eEye Digital Security (SecureIIS Web Server Protection)
    http://www.eeye.com

    What is Spyware? and How to infect your computer.


    I just had, by mistake, a plug-in called Intelligent Explorer attach to my browser. What a nightmare!  I have another article on this topic, but this brings home a point.  Spyware or adware items are continually infecting computers. Most computers have no protection from them. Most frightening is the frequency of them.  From the InfosecWriters web site, "According to a 2004 survey by America Online and the National Cyber Security Alliance, 91% of users questioned were familiar with the term spyware. Only 53% believed their computers were infected, but a scan found that 80% of their PCs had some type of spyware installed on them."  It goes on to say, “...The average number of spyware components per computer was 93 with one computer having well over a thousand."

    What is Spyware?



    Butte College (www.bctv.butte.edu/support/spyware.html) offers this definition:

    “The term ‘spyware’ is broadly defined as any program that gets into your computer without permission and hides in the background while it makes unwanted changes to your user experience.
    Spyware is generally not designed to damage your computer. The damage it does is more a by-product of its main mission, which is to serve you targeted advertisements or make your browser display certain sites or search results.
    At present, most spyware targets only the Windows operating system (Internet Explorer).”

    To be fair, spyware can be harmless, for example tracking cookies don’t do much. While such things infringe on your privacy, they don't really harm anything. Others, however, are extremely dangerous.

    So what do you do about it?

    No spyware program seems to do everything, but there are a lot of goods solutions out there that can help. Here is a list of some of the top Spyware tools to look at:


    1) Try Ad-Aware 6.0 Professional from LavaSoft (there is also a free version with less functionality)

    2) Spybot Search & Destroy from PepiMK Software


    3) Xoftspy form Pareto Logic

    4) Spyware Guard from Javacool Software is a free program
    5) Pest Patrol (now part of Computer Associates by acquisition)

    6) McAfee Anti-Spyware

    One thing is for certain: you do need to take spyware seriously.  For some reason, too many people out there think anti-virus solutions are the end-all solution. They are not. 

    And, when all else fails?

    Finally, as drastic as it seems,  if your computer has been infected with a large number of spyware programs, the only solution you may have is backing up your data, and performing a complete reinstall of the operating system.