<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber-Smarty.com</title>
	<atom:link href="http://cyber-smarty.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://cyber-smarty.com</link>
	<description>Helping You to be Secure and Smart - Online</description>
	<lastBuildDate>Sat, 31 Jul 2010 05:59:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Secure Online Transactions Through SSL/TLS</title>
		<link>http://cyber-smarty.com/2010/06/ssl-tls-certificate/</link>
		<comments>http://cyber-smarty.com/2010/06/ssl-tls-certificate/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 08:47:08 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Cyber Awareness]]></category>
		<category><![CDATA[Online Shopping]]></category>
		<category><![CDATA[ssl certificates]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=204</guid>
		<description><![CDATA[Interent transactions today are highly vulnerable to exploitation by cyber criminals. Online transactions in the current situation must be dealt very sensitively and sensibly in order to avoid any kind of data theft. The Secure Sockets Layer (SSL) enables encryption of sensitive data during online transactions through advanced encryption methods and validation processes. Encryption of [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Interent transactions today are highly vulnerable to exploitation by cyber criminals. Online transactions in the current situation must be dealt very sensitively and sensibly in order to avoid any kind of data theft. The Secure Sockets Layer (SSL) enables encryption of sensitive data during online transactions through advanced encryption methods and validation processes. Encryption of data makes it very difficult for unauthorised people to view the information during data transmission, thus making your online transaction highly secure.</p>
<p style="text-align: justify;">Almost all websites online are using SSL/TLS for securing their online transactions with their clients. All the popular browsers are having mechanism to identify the certificate and validate it. When you are visiting a secure site the browser will display a &#8220;lock&#8221; icon in its status bar. The internet address of a secured site begins with https://  rather than http://, where &#8216;s&#8217; represents that the site is using a secure server. In the absence of any of the above indicators, it is recommended to avoid doing online tranasaction within the site.</p>
<p style="text-align: justify;"><strong>Data encryption and SSL/TLS Process</strong><br />
An authenticated website for online transaction gets its SSL/TLS certificate from an Certified Authority (CA) like Verisign. The certificate is installed in the web server hosting the authenticated site.</p>
<ul style="text-align: justify;">
<li> When a user tries to access this authenticated site through his web browser, it sends a web page request to the web server.</li>
<li> The server now responds with the SSL certificate.</li>
<li> Web browser first verifies the validation of certificate, then encrypts the key seed of the session using SSL Public key and sends it to the server.</li>
<li> Server sends an indication that all the future transmissions are encrypted.</li>
<li> Then the communication between server and the browser in encrypted format follows until the connection closes.</li>
</ul>
<p style="text-align: justify;"><strong>Importance of SSL certified sites</strong><br />
Internet today can be called as wild west. This has become a major obstacle for the growth of ecommerce and online transactions. Making secure online transactions in these conditions majorly requires privacy and identity assurance. SSL/TLS certificate ensures both to the user. The encrypted format of data ensures safety from cyber criminals who try to steal the information during transactions. Identity assurance is another major feature of SSL/TLS certificate. This certificate is hard to obtain for ordinary or <a href="http://cyber-smarty.com/2010/05/beware-of-spoofed-websites/">illegitimate websites</a>. However, working with a website certified by an established CA is also important.</p>
<p style="text-align: justify;"><strong>The credibility of SSL/TLS certificate</strong><br />
As mentioned earlier SSL/TLS certificates are not easier to obtain. These are operated by Certified Authorities. Certified Authority (CA) usually will be an well established entity. New comers must have to undergo significant barriers to enter into SSL/TLS certificate market and to be included into the webbrowser&#8217;s trusted &#8220;root&#8221; SSL/TLS certificates list. Thus, if it is an established CA that provides credibility for a SSL/TLS certificate, it is a secure and reliable browser that gives credibility to the CA.</p>
<p style="text-align: justify;"><strong>How to validate a website for SSL certificate?</strong><br />
As SSL/TLS certificates are not easy to obtain, cyber criminals use different methods in web programming to create one of their own. However, we can validate a SSL certificate claimed by a website using few simple steps:</p>
<ol style="text-align: justify;">
<li> Open the URL in a website and make sure that the URL starts with &#8220;https://&#8221; rather than &#8220;http://&#8221;</li>
<li> When the website is loaded in the browser look for the lock icon. The
<div id="attachment_206" class="wp-caption alignleft" style="width: 152px"><img class="size-full wp-image-206  " title="lock-icon" src="http://cyber-smarty.com/wp-content/uploads/2010/06/lock-icon.jpg" alt="" width="142" height="40" /></dt>
</dl>
</div>
<p style="text-align: justify;">lock icon is situated in the upper-right corner for Safari; in lower-right corner for Firefox and IE. The lock icon is situated in the right end corner of the address bar for Google Chrome. However, a lock icon doesn&#8217;t necessarily mean that the site is SSL certified.</p>
</li>
<li>In order to validate the SSL certificate click on the lock icon of the browser which displays a pop up window of the page info. Click on view certificate option for further details. This will show further details of the organization and the CA who issued the certificate. Check on the expiry date of the certificate by selecting <strong>Validity</strong> &#8211; &gt; <strong>Not After</strong>.<br />
<table style="height: 299px;" border="0" width="594">
<tbody>
<tr>
<td>
<div class="mceTemp mceIEcenter">
<dl id="attachment_209" class="wp-caption aligncenter" style="width: 210px;">
<dt class="wp-caption-dt"><a href="http://cyber-smarty.com/wp-content/uploads/2010/06/valid-certificate.jpg"><img class="size-medium wp-image-209" title="valid-certificate" src="http://cyber-smarty.com/wp-content/uploads/2010/06/valid-certificate-300x228.jpg" alt="" width="200" height="250" /></a><p class="wp-caption-text">Valid SSL Certificate</p></div></td>
<td>
<p><div id="attachment_210" class="wp-caption aligncenter" style="width: 210px"><a href="http://cyber-smarty.com/wp-content/uploads/2010/06/invalid-certificate.jpg"><img class="size-medium wp-image-210  " title="invalid-certificate" src="http://cyber-smarty.com/wp-content/uploads/2010/06/invalid-certificate-254x300.jpg" alt="" width="200" height="250" /></a><p class="wp-caption-text">Invalid SSL Certificate</p></div></td>
</tr>
</tbody>
</table>
</li>
<li>Always use high security browsers while doing online transactions. As these high security browsers have emerged after the development of the Extended Validation (EV) standard established by the CA/Browser forum, they can perfectly recognize between a valid and non-valid SSL certificate. IE 7+ and Mozilla Firefox 3+ versions are examples of high security web browsers.
<p><div id="attachment_211" class="wp-caption alignleft" style="width: 210px"><img class="size-full wp-image-211 " title="error-msg-firefox" src="http://cyber-smarty.com/wp-content/uploads/2010/06/error-msg-firefox.jpg" alt="" width="200" height="78" /><p class="wp-caption-text">Warning  message in Firefox</p></div>
<p>Many web browsers block the webpage from loading and give an warning message when they find a website with suspicious or invalid SSL certificate.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2010/06/ssl-tls-certificate/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beware of Spoofed Websites Online</title>
		<link>http://cyber-smarty.com/2010/05/beware-of-spoofed-websites/</link>
		<comments>http://cyber-smarty.com/2010/05/beware-of-spoofed-websites/#comments</comments>
		<pubDate>Wed, 12 May 2010 14:17:32 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Cyber Awareness]]></category>
		<category><![CDATA[Online Shopping]]></category>
		<category><![CDATA[online spoofing]]></category>
		<category><![CDATA[spoofed sites]]></category>
		<category><![CDATA[spoofing]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=195</guid>
		<description><![CDATA[Website spoofing is one of the deceptive snare used by cyber criminals for phishing. Internet is still a highly vulnerable place for transactions. Cyber-criminals keep finding different ways to exploit a user online. The only way to survive them is through conventional awareness and credible preventive measures. What are Spoofed Websites? A spoofed website is [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Website spoofing is one of the deceptive snare used by cyber criminals for <a href="http://cyber-smarty.com/2009/10/technical-tips-to-prevent-phishing/">phishing</a>. Internet is still a highly vulnerable place for transactions. Cyber-criminals keep finding different ways to exploit a user online. The only way to survive them is through conventional awareness and credible preventive measures.</p>
<p style="text-align: justify;"><strong>What are Spoofed Websites?</strong><br />
A spoofed website is usually a replica of a legitimate website. Almost all the features of  this site replicate the existing legitimate site including logos, fonts, colors, structure, etc. In few cases, even the URL of the spoofed site is almost close to the URL of the legitimate site so that it is easier for them to trick its visitor.</p>
<p style="text-align: justify;"><strong>Techniques used in spoofing:</strong></p>
<ul style="text-align: justify;">
<li><strong>URL Redirection: </strong>URL redirection is possible through web programming to refer a URL to another URL. Many big companies like Google, Microsoft, etc., use them for legitimate business purposes. However, this has become a <a href="http://cyber-smarty.com/2009/10/social-responses-to-prevent-phishing/">phishing</a> tool for cyber criminals.They use a legitimate looking URL (www.domain.com, for example). However, when a visitor tries to visit the site, it actually redirects him to a spoofed site (www.phisher.com). It is possible for the user to identify redirecting URLs by monitoring location bar of his browser.</li>
</ul>
<ul style="text-align: justify;">
<li><strong>URL Cloaking:</strong> A legitimate looking URL is used to mask the URL of a spoofed site, by using &#8216;@&#8217; symbol. Using @ symbol was originally intended as a way to include a username and password in the URL. When a user tries to open the legitimate looking URL, <strong>www.bank-domain.com@phisher.com</strong>, for example, it actually redirects him to the <a href="http://cyber-smarty.com/2009/09/phishing-types-and-precautions/">phishing</a> site <strong>www.phisher.com</strong>, rather than <strong>www.bank-domain.com</strong>.</li>
</ul>
<ul style="text-align: justify;">
<li><strong>URL Masking:</strong> A illegitmate / <a href="http://cyber-smarty.com/2009/10/technical-tips-to-prevent-phishing/">phishing</a> site is concealed behind the text of URL of a legitimate site. Web programming has enough attributes to support masking of a URL easily.A user gets an email from phisher containing a link to a legitimate site (www.domain.com, for example). However, the link is the mask of a spoofed site (www.phisher.com). The deception actually happens in the status bar of the browser. When you hover mouse over a link the status bar should show where the link will guide you to. The deceptive link is so well hidden that the user cannot find it even in the status bar on hovering mouse over the link. This is generally done using javascript.</li>
</ul>
<ul style="text-align: justify;">
<li><strong>Typo Scamming:</strong> Typos are inevitable when you are typing out on your keyboard. Cyber criminals use this as an advantage and register web addresses that resemble the name of a popular and legitimate site. These URLs are slightly differentiated by adding, excluding, or rearranging letters.For example, web address of a legitimate site <strong>www.bankm.com</strong> is differentiated as
<ul>
<li>www.ban<strong>m</strong>k.com</li>
<li>www.ba<strong>k</strong>m.com</li>
<li>www.bankm<strong>-online</strong>.com</li>
</ul>
</li>
</ul>
<p style="text-align: justify;"><strong>Why beware of spoofed sites?</strong><br />
Spoofed websites are actual sources of phishing. The main job of the phisher is to convince the visitor that his spoofed site is legitimate. From then on it is the visitor who will be submitting his information to the phisher, unknowingly though. It can be his bank username and password, or any such information that is of economical value.</p>
<p style="text-align: justify;">Cyber criminals also use spoofed websites to deploy malware into the visitors PC thus making it as a part of their botnet.</p>
<p style="text-align: justify;"><strong>Precautions to take to avoid being a victim of spoofed sites</strong></p>
<ul style="text-align: justify;">
<li> Avoid using sites that do not have <span style="color: #ff6600;"><strong><a href="http://cyber-smarty.com/2010/06/ssl-tls-certificate/">SSL/TLS certificate</a></strong></span> while you are banking, buying, selling, transferring money or using credit/debit cards online.</li>
<li> Make it a habit of <a href="http://cyber-smarty.com/2010/06/ssl-tls-certificate/">checking the SSL/TLS validity</a> every time you visit a site before making financial transactions, by clicking on the lock icon.</li>
<li> Never click a hyperlink to get to a website for financial transaction unless you are CERTAIN that it is a legitimate link.</li>
<li>Just type out the URL yourself, use credible search engine results or copy paste it from your records.</li>
<li> Do not use same <a href="http://cyber-smarty.com/2010/02/protecting-yourself-online-with-strong-passwords/">username / password</a> for all your online logins.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2010/05/beware-of-spoofed-websites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Secure Your PC from Being a Part of Botnet</title>
		<link>http://cyber-smarty.com/2010/03/secure-your-pc-from-botnet/</link>
		<comments>http://cyber-smarty.com/2010/03/secure-your-pc-from-botnet/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 14:33:02 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Cyber Awareness]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[cybercrime awareness]]></category>
		<category><![CDATA[mariposa]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=181</guid>
		<description><![CDATA[The recent Mariposa scam which revealed the compromising of 12.7 million computers shows the extent and severity of botnet problem. Mariposa is only one of them; there are many more such botnets like conficker, kraken, srizbi, Zeus, Zdbot, etc which have compromised millions of computers that are connected to internet today. And these in turn [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">The recent <a href="http://cyber-smarty.com/2010/03/mariposa-botnet-busted/">Mariposa scam</a> which revealed the compromising of 12.7 million computers shows the extent and severity of botnet problem. Mariposa is only one of them; there are many more such botnets like conficker, kraken, srizbi, Zeus, Zdbot, etc which have compromised millions of computers that are connected to internet today. And these in turn are actively trying to infect more and more computers every day. An article from BBC saying that up to a quarter of PCs connected online are part of botnets, tells us how grave the situation is.</p>
<p style="text-align: justify;"><strong>Basics about Bots and Botnets</strong><br />
The term bot is related to the word robot. A computer system is first infected by a Trojan virus or any such malware; then the hackers, who are creators of this malware, take over the controls of the system and remotely operate it for their use. Since, the infected computers are obeying the controls of the hacker, these are also called bots or zombies.</p>
<p style="text-align: justify;">A single bot is of not much use to the hacker. Thus, he first tries to increase the number of zombies by spreading the malware via the infected PC. Thus, the network of bots increases and forms a botnet. A typical botnet contains a few hundreds or a couple thousands of computers. However, there are a few botnets that contain millions of infected PCs. All of them serving to the key master – the creator of the botnet.</p>
<p style="text-align: justify;"><strong>How/where are they used?</strong><br />
The primary risk of having/using a PC-turned-bot is putting all your credible information (like bank accounts, credit card numbers, passwords, financial information or any such sensitive data) available for the hacker to exploit. Bots also send spam, viruses, spyware to other computers on internet in order to spread their botnet. These are automated processes and do not require commands from the hacker each and every time.</p>
<p style="text-align: justify;">Botnets are also used to perform other tasks online like creating email spam, clickfraud, spamdexing, launching of denial-of-service (DoS) attacks, fast flux, access number replacements, etc.</p>
<p style="text-align: justify;"><strong>How to check if your PC is a part of botnet</strong><br />
Your PC Internet connection &#8211; turning inexplicably slow either while browsing or while checking mails can be a symptom of botnet infection. The malware used in botnet infection are specially designed to hide themselves even during carrying out the automated processes. Thus, it is hard to trace them down sometimes even with an antivirus installed in your PC. However, Prevx suggests a small technique using which you can check if your PC is part of a botnet follow when your internet becomes slow. The process is as follows:</p>
<ol style="text-align: justify;">
<li>Close all your browsers and email software (like Thunderbird, Outlook, etc)</li>
<li>Open Task Manager: <em>Press CTRL+ALT+DEL at a time and      then select <strong>Task manager</strong> from the Window.</em></li>
<li>Open <strong>Networking</strong> tab and observe the      graph or <strong>Network Utilization </strong>percentage<strong> </strong>below the graph. If it is showing more than usual percentage, then it might indicate that your PC is infected.</li>
</ol>
<p style="text-align: justify;">If the above is true in your case, the next steps to do will be:</p>
<ul style="text-align: justify;">
<li>Immediately pull off from the internet by disconnecting the LAN cable.</li>
<li>Use a rescue disk (like Norton antivirus rescue disk) and scan your computer thoroughly.</li>
<li>Replace your antivirus immediately with a superior one and run thorough scan (because it is already proved that the existing one is ineffective).</li>
<li>Reconnect PC to the internet and update your MS Windows, antivirus database, browser, adobe reader, and other vulnerable applications that are installed on your PC.</li>
</ul>
<p><span id="more-181"></span><br />
<strong>Related Links:</strong><br />
<a href="http://www.alwayson.co.uk">Unified communications</a></p>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2010/03/secure-your-pc-from-botnet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ideal NTFS Formatting in Windows</title>
		<link>http://cyber-smarty.com/2010/03/ideal-ntfs-formatting-in-windows/</link>
		<comments>http://cyber-smarty.com/2010/03/ideal-ntfs-formatting-in-windows/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 06:21:20 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Computer maintainance]]></category>
		<category><![CDATA[ntfs formatting]]></category>
		<category><![CDATA[system maintainance]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=176</guid>
		<description><![CDATA[The advanced features of NTFS (New Technology File System) like recoverability in the event of a system failure, file compression, security controls for files, EFS (Encryption File System), Disk Space Quota management, etc., has made it preferable over FAT file system. Unless in situations like using multiple-boot configuration &#8211; NTFS is an ideal file system [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">The advanced features of NTFS (New Technology File System) like recoverability in the event of a system failure, file compression, security controls for files, EFS (Encryption File System), Disk Space Quota management, etc., has made it preferable over FAT file system. Unless in situations like using multiple-boot configuration &#8211; NTFS is an ideal file system to use for your hard drive.</p>
<p style="text-align: justify;"><strong>Before Formatting an NTFS volume</strong><br />
For better performance of your NTFS volume it is essential to evaluate which type of files will be stored in the volume and how big they will be. This is to decide whether to use the default cluster size for the NTFS partition or manually configure it. Clusters are units in which files of a file system are managed. Choosing an ideal cluster size not only saves the disk space but also improves the performance of the volume.</p>
<p style="text-align: justify;"><strong>Choosing a Cluster size</strong><br />
The default cluster size values of NTFS formatting in Windows NT/2000/XP are as follows:</p>
<table style="text-align: justify;" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td width="268" valign="top"><strong>Size   of Logical Volume (Drive Size)</strong></td>
<td width="268" valign="top"><strong>Default   Cluster Size</strong></td>
</tr>
<tr>
<td width="268" valign="top">&lt; 512 MB</td>
<td width="268" valign="top">512 Bytes</td>
</tr>
<tr>
<td width="268" valign="top">&gt; 512 MB to 1GB</td>
<td width="268" valign="top">1 KB</td>
</tr>
<tr>
<td width="268" valign="top">&gt; 1GB to 2GB</td>
<td width="268" valign="top">2 KB</td>
</tr>
<tr>
<td width="268" valign="top">&gt; 2 GB <strong>*</strong></td>
<td width="268" valign="top">4 KB</td>
</tr>
</tbody>
</table>
<p style="text-align: justify;"><em>* greater than 2 TB is not supported in Windows NT due to limitations of MBR</em></p>
<p style="text-align: justify;">A manual partition can be assigned cluster size values as 512 bytes, 1KB, 2KB, 4KB, 8KB, 16KB, 32KB, 64 KB. However a cluster size more than 4 KB does not support compression on volumes (You might have seen that the default cluster size is not exceeding 4 KB in the above table).</p>
<p style="text-align: justify;">If you are going to use your HDD for saving regular working documents like xls, doc, etc., it is good to use small cluster size so that disk space is not wasted. However, if you will be saving large multimedia files than it will be good to use large cluster size. This will help in improving performance of the Logical Volume.</p>
<p style="text-align: justify;"><strong>Maximum sizes in NTFS</strong><br />
NTFS has certain limits for file size, volume size and number of files per volume. The limits, according to Microsoft, are as follows…</p>
<ul style="text-align: justify;">
<li>The maximum size of an NTFS volume is 256 Terabytes minus 64KB (<em>Thus, even a PC with 1TB of disk space can be formatted into single NTFS volume without any issues</em>).</li>
<li>The maximum size of a file you can store in an NTFS volume is 16Terabytes minus 64 KB.</li>
<li>The maximum number of files you can store in a NTFS volume are 4,294,967,295. However, if the number of files is exceeding 300,000, it is recommended to disable automatic short-file name generation <em>(use this link to find the procedure <strong>http://support.microsoft.com/kb/210638</strong>)</em>.      This will speed up file and folder access of the system.</li>
</ul>
<p><span id="more-176"></span><br />
<strong>Related Links:</strong><br />
<a href="http://www.jdidata.com/JDi/index.asp">Claims management software</a><br />
<a href="http://www.systemid.com/barcode_printers">Barcode printer</a><br />
<a href="http://www.apseratech.com">Wan optimization</a></p>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2010/03/ideal-ntfs-formatting-in-windows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers who created botnet with 12.7 million computers busted</title>
		<link>http://cyber-smarty.com/2010/03/mariposa-botnet-busted/</link>
		<comments>http://cyber-smarty.com/2010/03/mariposa-botnet-busted/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 06:29:11 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Major Developments]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[mariposa]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=179</guid>
		<description><![CDATA[Spanish police working with the FBI and other police forces have arrested three suspects for running world’s biggest computer hacking scam through a bots network called Mariposa. This is a crucial win for security experts over hackers and a relief to millions of people who use internet everyday. The network of mariposa botnet is spread [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Spanish police working with the FBI and other police forces have arrested three suspects for running world’s biggest computer hacking scam through a bots network called Mariposa.</p>
<p style="text-align: justify;">This is a crucial win for security experts over hackers and a relief to millions of people who use internet everyday. The network of mariposa botnet is spread around 190 countries infecting over 12.7 million computers. These included computers of the US Fortune 1000 companies to computers of major banks. Spanish police reported the recovery of details like bank account details, credit card numbers, usernames, passwords, etc., of over 800,000 people. The amount of loss due to this botnet network is yet to be determined.</p>
<p style="text-align: justify;">Mariposa is a Spanish word for butterfly. It was announced as a new botnet by Defence Intelligence in May 2009. This bot is known to spread through crucial vulnerabilities in Internet Explorer as well as contaminated USB sticks. It is very hard to nab creators of botnet as these criminals operate disguising the source of their Internet traffic or through an infected computer (called zombie) belonging to another person. It seems that it is the blunder made by one of the operators of mariposa – forgetting to conceal their IP address – that helped Spanish police to catch this gang.</p>
<p style="text-align: justify;">The infected computers still remain tainted. The worst part is that most of the owners are still not aware that their computer is a botnet. Use a reliable, robust and updated version of antivirus solution in your PC to detect any traces of botnet.</p>
<p>Read more about <a href="http://cyber-smarty.com/2010/03/secure-your-pc-from-botnet/">Botnet and PC security</a> here.<br />
<span id="more-179"></span><br />
<strong>Related Links:</strong><br />
<a href="http://www.alwayson.co.uk">Unified communications</a></p>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2010/03/mariposa-botnet-busted/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Protecting Yourself Online with Strong Passwords</title>
		<link>http://cyber-smarty.com/2010/02/protecting-yourself-online-with-strong-passwords/</link>
		<comments>http://cyber-smarty.com/2010/02/protecting-yourself-online-with-strong-passwords/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 07:57:09 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Cyber tips]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=171</guid>
		<description><![CDATA[The concept of having a password for any system is similar to a key for home. The key for home is essential in order to lock and protect personal belongings from others who are not authenticated or desired to enter home. Today, due to globalization and Internet revolution, a person may have several online properties [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">The concept of having a password for any system is similar to a key for home. The key for home is essential in order to lock and protect personal belongings from others who are not authenticated or desired to enter home. Today, due to globalization and Internet revolution, a person may have several online properties or accounts that are as important as properties physically existing at home. Those may be e-mails, portal, website subscriptions, network servers, databases, online banking accounts, credit cards, etc. Strong passwords for these helps in having a secure and strong lock just like lock to home.</p>
<p style="text-align: justify;">Most people, who are new to the online world, have lack of knowledge on setting up a strong password for their online accounts. But the increasing cyber crime can easily trace the passwords. And the results can be as terrible as the attack on Microsoft&#8217;s Hotmail and other web-based email services. A recent survey on these missing passwords revealed that many of the accounts had easy-to-guess passwords and the most frequently used password among these was &#8220;123456&#8243;.</p>
<p style="text-align: justify;">Some general methods that attackers use for identifying a victim&#8217;s password include:</p>
<ul style="text-align: justify;">
<li>Guessing—The attacker tries to log on using the user&#8217;s account repeatedly by guessing probable or expected words and phrases like their children&#8217;s names, their birth city, and local sports teams.</li>
<li>Online Dictionary Attack—The attacker utilizes an automated program, which consists of a text file of many words. The program frequently tries to log on to the target system by testing a different word present in the text file on each attempt.</li>
<li>Offline Dictionary Attack— It is similar to the online dictionary attack, the attacker extracts a copy of the file in which the hashed or encrypted copy of user accounts and passwords are saved and runs an automated program to find out what password is used for each account. This type of attack can be finished very quickly if the attacker gains a copy of the password file.</li>
<li>Offline Brute Force Attack—This is a modified form of the dictionary attacks, and designed to discover passwords, which are not present or available in the text file used in those attacks. Even though a brute (very strong) force attack can be tried online, because of network bandwidth and latency they are generally attempted offline utilizing a copy of the target system&#8217;s password file. In a brute force attack, the attacker utilizes an automated program, which produces hashes or encrypted values for all possible passwords and analyzes them with the values in the password file.</li>
</ul>
<p style="text-align: justify;">Microsoft suggests that the use of strong passwords can slow or sometimes break the various attack methods. This shows the importance of having a strong password.</p>
<p style="text-align: justify;"><strong>Creating a Strong password:</strong></p>
<p style="text-align: justify;">Passwords are case-sensitive and may be as long as 127 characters. A strong password:</p>
<ul style="text-align: justify;">
<li>Should never consist of user name.</li>
<li>Should be minimum of eight characters long.</li>
<li>Should compulsorily include both lower case and uppercase alphabets (minimum one from each group is suggested).</li>
<li>Should consist of minimum one number (0 to 9).</li>
<li>Should consist of at least one symbol. (Eg: *, ^, $, #)</li>
</ul>
<p style="text-align: justify;">A string, which has all the above characteristics, is known as strong password. A complex password should not be something, which is difficult to remember. Forgetting a strong or complex password, which is difficult to remember, is as harmful as getting attacked by a weak password.</p>
<p style="text-align: justify;">The password created must be easier to remember but difficult for anybody to guess. It can also be a favorite phrase or quotation or mixture of two words. Substitutes for alphabets can also be used to satisfy the above criteria for a strong password. For example ‘a’ in password can be substituted with ‘@’, similarly ‘i’ can be replaced with ‘!’; and ‘o’ with ‘0’ or ‘()’.</p>
<p style="text-align: justify;">It is a good practice if password is changed periodically like monthly or quarterly.</p>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2010/02/protecting-yourself-online-with-strong-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why Internet is Wild West Today?</title>
		<link>http://cyber-smarty.com/2010/01/why-internet-is-wild-west-today/</link>
		<comments>http://cyber-smarty.com/2010/01/why-internet-is-wild-west-today/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 06:06:06 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Cyber Awareness]]></category>
		<category><![CDATA[cybercrime awareness]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=168</guid>
		<description><![CDATA[Today almost every user browsing Internet is at risk. The increase in threats related to social networking sites, banking security, botnets, and attacks targeting users, businesses, and even applications made Internet a risky landscape. Many industry consultants and analysts refer Internet as ‘Wild West’ because of its huge insecurity, where nobody or no website can [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Today almost every user browsing Internet is at risk. The increase in threats related to social networking sites, banking security, botnets, and attacks targeting users, businesses, and even applications made Internet a risky landscape. Many industry consultants and analysts refer Internet as ‘Wild West’ because of its huge insecurity, where nobody or no website can be trusted. Every year, cyber crime costs billions of dollars to repair systems hit by attacks and loss in productivity because of disruptions. According to the Federal Bureau of Investigation (FBI), consumers and businesses lost $5.8 billion in 2009 due to cyber crime.</p>
<p style="text-align: justify;"><strong>Risks increased exponentially</strong><br />
Today, any user can get affected by cyber threats through browsing, searching or merely visiting legitimate sites than ever before in the Internet history. Malicious web links are sprouting at a rapid pace. According to CA Internet Security Business Unit (ISBU), 78% of threats came from online interaction during the first six months of 2009. IBM’s ‘X-Force 2009 Mid-Year Trend and Risk Report’, states that there was more than 500% increase in new malicious web links in the first six months of 2009. The vulnerability towards the threats seems to have reached the peak point. In the first half of the year 2009 alone, nearly 3,240 new vulnerabilities were discovered.</p>
<p style="text-align: justify;"><strong>New threats</strong><br />
With the evolution of web based communities and explosion of Internet services, users are spending more time online and engaging in social networking activities on the Internet than ever before. This is resulting in new threats that exploit these services and communities. When a reputed website hosts third-party content, users often let down their guard while following hyperlinks in the third-party content or installing applications offered by them. Malware authors follow social networking buzz and the most popular activities online to attack the users. They are always ready to exploit significant and popular news stories to trap the netizens. Thus many people become victims of cyber traps.</p>
<p style="text-align: justify;">The attackers are constantly upgrading their tools to attack the unwary users. This criminal activity is scaling new peaks constantly. According to IBM, the SQL injection attacks almost doubled from first quarter to second quarter of 2009. Through SQL attacks, malicious code is injected into genuine web sites to infect the visitors.</p>
<p style="text-align: justify;">For the past few years, Botnets are the primary tools for many cyber criminals. They are always a challenge to the cyber security professionals as it is very difficult to track them down. Botnets can launch almost every type of cyber attack including data exfiltration, sophisticated espionage, and spam.</p>
<p style="text-align: justify;"><strong>Targeted attacks</strong><br />
Although targeted attacks were rare earlier, they are seen often these days. Apart from the common people, top management of companies, governments, industries and even journalists are being targeted for private information. Emails with Malware attachments is the popular and preferred method for targeted attacks. According to CA (ISBU), 17% of the infections are distributed through E-mail. There is also an increase in attacks targeting client software using Adobe products including Flash and Acrobat Reader.</p>
<p style="text-align: justify;">Criminals are adapting more effective methods to target online banking system. Trojans are the result of new tactics that go beyond the simple key logging-with-screenshots efforts, which prevailed earlier. CA (ISBU) reported that Trojans were the most common threats representing 71% of the total infections in the first half of 2009. When it comes to Phishing, IBM says that 66% of the phishing attacks targeted financial industry and 31% targeted online payment in the first half of 2009.</p>
<p style="text-align: justify;">Over the years, Internet security issues have been growing. Initially, virus was the only problem. Later with the explosion of Internet, many newer threats have evolved increasing the security vulnerability such as malicious domains or untrusted web sites, presence of malicious content on trusted sites, including popular search engines, blogs, bulletin boards, personal Web sites, mainstream news sites and online magazines. Today you are in a high-risk zone as soon as you are online. It is always advisable to be alert while you are browsing.</p>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2010/01/why-internet-is-wild-west-today/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How safe is a Remote Backup Service?</title>
		<link>http://cyber-smarty.com/2009/12/how-safe-is-a-remote-backup-service/</link>
		<comments>http://cyber-smarty.com/2009/12/how-safe-is-a-remote-backup-service/#comments</comments>
		<pubDate>Tue, 22 Dec 2009 10:04:16 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Cyber Awareness]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/2009/12/how-safe-is-a-remote-backup-service/</guid>
		<description><![CDATA[There are many service providers who offer online back up services. Some of them are Mozy, BackupandShare.com, Citadel Remote Backup, SafeCopy Backup, Iron Mountains, ElephantDrive, Xdrive, Genie Online Backup, AT&#38;T Online Vault, Carbonite, eSureIT, iBackup. These are only a few to name. Remote back up service are mostly suitable for individuals and small businesses. However, [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">There are many service providers who offer online back up services. Some of them are Mozy, BackupandShare.com, Citadel Remote Backup, SafeCopy Backup, Iron Mountains, ElephantDrive, Xdrive, Genie Online Backup, AT&amp;T Online Vault, Carbonite, eSureIT, iBackup. These are only a few to name.</p>
<p style="text-align: justify;">Remote back up service are mostly suitable for individuals and small businesses. However, any of them trying these services without a good broadband connectivity as well as a high performing system – will for-sure visit the hell on earth.</p>
<p style="text-align: justify;">In fact many people and many companies have been relying on some of the services mentioned above. The security of backing up data online is also questioned when services of even bog companies like Google and Twitter are being hacked.</p>
<p style="text-align: justify;">Many of Remote backup services, for example – Mozy, encrypts the files that are to be backed up, in your PC itself so that they are not easily accessible even when steals them in mid of the back up process. In addition, some services even scramble the encrypted data through a SSL connection. This is the same mechanism that is used by online merchants to move credit card information.</p>
<p style="text-align: justify;">What if the data is accessed at the data centers by their employees? Well, there are some services that offer remedy for this too. When they are encrypting the data on your PC, the encryption key will be given by yourself so that decrypting and encrypting can be done by none other than you.</p>
<p style="text-align: justify;">However, there are certain precautions that are required to be taken up before opting for a service.</p>
<ul>
<li style="text-align: justify;"> Ensure that the service providers are firm at their policies.</li>
<li style="text-align: justify;"> Use strong passwords or encryption keys for files that carry vital or sensitive data.</li>
<li style="text-align: justify;"> Try to add an extra protection like password protecting your documents or using some third party applications to pre-encrypt your data.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2009/12/how-safe-is-a-remote-backup-service/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Lurks Within Pirated Versions of Popular Movie Downloads</title>
		<link>http://cyber-smarty.com/2009/12/malware-lurks-within-pirated-versions-of-popular-movie-downloads/</link>
		<comments>http://cyber-smarty.com/2009/12/malware-lurks-within-pirated-versions-of-popular-movie-downloads/#comments</comments>
		<pubDate>Fri, 11 Dec 2009 11:35:51 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Secure Downloading]]></category>
		<category><![CDATA[cybercrime awareness]]></category>
		<category><![CDATA[downloading]]></category>
		<category><![CDATA[Spam Awareness]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=162</guid>
		<description><![CDATA[Now-a-days cyber criminals are using popular events, current developments and even movie premieres to attract people who seek free or pirated content and exploiting. A recent online scam which promises viewers to download the recent “Twilight – New Moon” movie is found to install malware in PCs. The entire process of this scam is as [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Now-a-days cyber criminals are using popular events, current developments and even movie premieres to attract people who seek free or pirated content and exploiting.</p>
<p style="text-align: justify;">A recent online scam which promises viewers to download the recent “<strong>Twilight – New Moon</strong>” movie is found to install malware in PCs.</p>
<p style="text-align: justify;">The entire process of this scam is as follows…</p>
<ul style="text-align: justify;">
<li>Viewers are lured with the text websites, chat rooms      and blogs that read: “Watch New Moon Full Movie.” Comment posts with      related keywords are also used simultaneously to attract more search      engines.</li>
<li>Search results for the movie then link users to      stolen images from the movie itself, convincing the fan that the movie is      only one click away.</li>
<li>When they click on the “movie player” they are told      to install a &#8220;streamviewer&#8221;.</li>
<li>The streamviewer, however, installs malware on the      user’s computer.</li>
</ul>
<p style="text-align: justify;">Don’t get enticed by such scams to get downloads without verifying if the sources are genuine or not. It can turn up to be more hectic not only in terms of cost but also in terms of toil and time. And the entire accountability will fall upon none other than you.</p>
<p style="text-align: justify;"><strong>Courtesy:</strong> PCTools.com</p>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2009/12/malware-lurks-within-pirated-versions-of-popular-movie-downloads/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why Should We Run Windows Updates Regularly?</title>
		<link>http://cyber-smarty.com/2009/11/why-should-we-run-windows-updates-regularly/</link>
		<comments>http://cyber-smarty.com/2009/11/why-should-we-run-windows-updates-regularly/#comments</comments>
		<pubDate>Fri, 27 Nov 2009 08:53:46 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Computer maintainance]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=153</guid>
		<description><![CDATA[Security updates are delivered on the second Tuesday of each month, which is called “Patch Tuesday”, but security updates can be delivered whenever a software update is required to prevent an exploit targeting Windows users. Windows Update can be configured to install updates automatically, to ensure that a computer is always up-to-date and not vulnerable [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;"><a href="http://cyber-smarty.com/wp-content/uploads/2009/11/win-update.JPG"><img class="alignleft size-full wp-image-155" title="win-update" src="http://cyber-smarty.com/wp-content/uploads/2009/11/win-update.JPG" alt="win-update" width="151" height="154" /></a>Security updates are delivered on the second Tuesday of each month, which is called “Patch Tuesday”, but security updates can be delivered whenever a software update is required to prevent an exploit targeting Windows users. Windows Update can be configured to install updates automatically, to ensure that a computer is always up-to-date and not vulnerable to computer worms and other malware.</p>
<p style="text-align: justify;"><strong>Why to update systems with patches given by Microsoft?</strong><br />
The windows <a href="http://cyber-smarty.com/2009/09/should-i-migrate-to-windows-7/">operating system</a> we use in the computer is fundamentally made up of millions of lines of programming code. For example, Windows Vista is made of about fifty million lines of code. Errors are inevitably made, while typing out these 50,000,000 lines, thus making the software vulnerable.</p>
<p style="text-align: justify;">Hackers try to exploit these vulnerabilities created by the mistakes in the software. They use the hacked computer to send spam, steal passwords of the owners/users in order to take over their identities and make online purchases.</p>
<p style="text-align: justify;">In order to repair these errors, Microsoft regularly releases updates/patches for its products. These updates automatically take care of the vulnerable part of the code by repairing or replacing it with safer one.</p>
<p style="text-align: justify;"><strong>Quick Facts:</strong><br />
As of 2008, Windows Update has about 500 million clients, processes about 350 million unique scans per day, and maintains an average of 1.5 million simultaneous connections to client machines. On Patch Tuesday, the day Microsoft typically releases new software updates, outbound traffic can exceed 500 gigabits per second. Approximately 90% of all clients use automatic updates to initiate software updates, with the remaining 10% using the Windows Update web site. The web site is built using ASP.NET, and processes an average of 90,000 page requests per second.</p>
<p style="text-align: justify;"><strong><span style="text-decoration: underline;">How to perform windows update &#8211; for Dummies:</span></strong><br />
There are many ways through which you can update your windows manually.</p>
<ul>
<li>Go      to all programs in start menu and find “Windows Update” and click on it.      <em><strong>(OR)</strong></em></li>
<li>Right      click on “My Computer”. Go to “Automatic Updates” tab. Click on “Windows      Update Website”. <em><strong>(OR)</strong></em></li>
<li>Open      “Internet Explorer“. Type <strong>windowsupdate.microsoft.com</strong> in the address bar and hit Enter.</li>
</ul>
<p style="text-align: justify;">All the above steps will direct you to Windows update site of Microsoft. Click on “Express” button. The site will provide all the recommended updates for your computer. Click on ‘<strong>Review and Install Updates</strong>’ and then on ‘<strong>Install Now</strong>.’</p>
<p style="text-align: justify;"><strong>Precautions while performing windows updates:</strong></p>
<ul style="text-align: justify;">
<li>Log      in as Administrator into your system.</li>
<li>Make      sure there is no interruption in power or internet while updates are going      on. That may make things messy for later updates.</li>
<li>Some      updates require restarting of your computer. Make sure you save and close      all your work and applications before you start installation process.</li>
<li>Use      Internet Explorer only as updates don’t work on other browsers.</li>
</ul>
<p style="text-align: justify;"><strong>PS:</strong> The above mentioned process is for people without much idea on “windows updates”.</p>
<p><span id="more-153"></span><br />
<strong>Related Links:</strong><br />
<a href="http://www.jdidata.com/JDi/index.asp">Claims management software</a></p>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2009/11/why-should-we-run-windows-updates-regularly/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
