Archive - Security Category

Small security warning

Saturday, February 7th, 2009

troll_2

Okay, well anyone ever receive links that go like this www.[big site like google].something.something.tld ? Well, in the past I have been able to avoid these links, but yesterday I was pretty tired and randomly clicked a link like that. Never click links that look like that, they are generally shock sites or do something damaging to your computer. Mine was specifically youtube.on.nimp.org/watch?v=Zll_jAKvarw. (DO NOT GO HERE UNLESS YOU ENJOY FIREFOX VIOLENTLY SHAKING AROUND AND GRAPHIC SHOCK IMAGES) It’s the first time I ever fell for that trick, but be advised that these exist. I have had friends IM me about receiving links like this asking me if it’s a virus or similar, so I know not everyone knows about these type of sites, and I just want to get the word out a little more.

Always scan links, no matter what site you’re on, these type of links may be posted and disguised as true links. Hover your mouse over any link you see and check to make sure it is a legitimate link. Internet trolls love to post these kinds of sites. Avoid them.

If you still end up on one of these sites, kill FireFox or whatever browser you’re using with either killall or ctrl-alt-delete end process. (Yes, it works on any OS just so long as you have a vulnerable browser, apparently it has never been fixed by Mozilla)

Want to see some reactions to going to on.nimp? Check this video out http://www.youtube.com/watch?v=Kui6cCu6tfA (This is a real youtube link :) ) I knew exactly what it was so my reaction wasn’t near as interesting. Basically I went to the site, then I killed firefox, with no facial reaction or anything like that.

I kind of laughed at myself afterwards though, even me knowing everything about troll tricks on computers, still ended up getting trolled. Everyone’s human, right?

Comodo Internet Security Review

Monday, February 2nd, 2009

1176739790comodo13c2970cd3Well, I’m a long time ZoneAlarm user. I just recently pulled a switch to the comodo security suite. Instantly, I’m greeted with dialogs just like I would expect from ZoneAlarm. However, Comodo takes it a step further. It seems to monitor every little thing a program does, from modifying any little registry value in windows, to internet access attempts. Why didn’t I try out Comodo sooner? Well, I was under the impression that ZoneAlarm was awesome, and there couldn’t be something better. Well, I was wrong, dead wrong in fact. I see that comodo does virus scans, updates automatically, secures internet, and monitors programs very closely. Many say that Comodo is less resource heavy as well.

Here’s the real kicker, Comodo is free! ZoneAlarm Pro is not. The regular ZoneAlarm doesn’t come with nearly as many features as the free version of Comodo does. I think I have just found my new favorite software firewall and antivirus. Anyone not running something like ZoneAlarm or Comodo needs to go get one of the two now. No matter how savvy you think you are, there are a lot of strange things on the internet that could trick you, and Comodo or ZoneAlarm will block such things.

In conclusion, Comodo gets my vote now, ZoneAlarm is good, but I don’t think it’s as good as Comodo even in the “pro” version.

Properly Securing Your Website

Wednesday, January 21st, 2009

lock_down_computerOwn a website? Ever think about security? If not, well you’re asking for trouble.

These are the best things you can do to secure your website properly

  • Use random generated passwords 32-64 characters in length.
  • Research your particular software and/or plugins for vulnerabilities at all times by visiting milw0rm and packetstorm on a regular basis.
  • Optionally, you may want to install some kind of spam filter if possible on your software.

Own your server? You’ll probably want to do this as well, on top of the list above.

  • Do periodic software updates on your server, change the ports that certain services run on, such as FTP and SSH since these are common targets.
  • Disable root login.
  • Set ServerTokens to “Prod” in Apache.
  • Run software that automatically bans an IP after a certain amount of failed login attempts.
  • Again, for all passwords on the server use 32-64 char random generated passwords, including the host control panel if you have one.

Just searching around reveals to me that there are far too many insecure websites out there, that could easily enough become fairly secure by following at least some of these methods. You can never be too secure, there are new vulnerabilities found every day, and there is no shortage of malicious users out there ready to deface your website or gain root login to your server for the fun of it. There are many more tactics out there for security, but these are some of the better tactics that will deter most people. Be careful out there.

Thanks go out to nukeit.org