My Pages

Showing posts with label trojan. Show all posts
Showing posts with label trojan. Show all posts

Friday, 19 August 2016

Security consultant might just be a guard

Seeking and loathing
On one of the dating app haunts that I sometimes ply, I came upon an elaborate profile in general terms, but something stood out that I decided not to ignore.
The young man had stated that he was a security consultant with a major bank. Now, having seen thousands of profiles, some angry, some demure, many empty and quite a few demonstrative of angst, insecurities, inadequacies and dare I say prejudices, I have been tempted to write a guide to useful dating profiles.
Then again, it is not like I have been entirely successful in my quest for companionship through dating apps or websites. However, what you do see on my profile in the main will be what you get. I rarely mince words and sometimes my old-fashioned self, requiring correctness, politeness, comportment and much else gets in the way of simple engagement.
Can we talk for a minute?
Yet, I thought to engage this young fellow to illustrate a looming risk in telling strangers on dating sites such unnecessary detail as to whether you own your homes, have a car, have the greatest job on earth and other puffery that is of no particular relevance than a possible endangerment.
I started with ‘Let me humour you …’, to have a high profile job at your age must be commended, however, in putting it out there, you create a vulnerability profile around yourself that can be exploited by nefarious people or organisations. Whilst they might not come for you, they can go for close contacts around you besides the possibility of you being a Trojan horse into your banking organisation.
Just over an hour after I sent the message, I got the response, “Try and social engineer me, just try.” The young fellow had missed the point. And so I responded.
Missing the point entirely
Social engineering is passé and that is mostly for low hanging fruit. As a security consultant, you have access and knowledge that ordinary users will not have. You have a nickname you have used on this site that will probably be the same on others.
Your picture appears here and simple Internet tools can be used to match your picture possibly to an identity on Facebook or LinkedIn and after that, they only have to build a vulnerability profile that they can exploit without you knowing that you are being stalked online.
In closing, I said, “We technical people have to be careful that either our of carelessness or hubris, we expose our organisations to more harm than we are willing to admit our acts of wilful stupidity cause.”
Unlearning arrogance
I was blocked. Blocked probably because he thought I was attacking him or he felt that he was too good to be taking advice on issues where he is supposed to be the expert.
A simple example of the silliness of putting such a risk intensive role online in forums like a dating site is for someone to go around saying they are secret agents. Others would either go for the agent or go for people around that agent to gain access acquaintances to whom some connection can compromise the resolve of the agent.
Then again, there is a know-it-all syndrome that I have observed amongst certain young people who have created an incapacity to learn or be advised, they are single-mindedly impervious to any instruction and rapidly chart a course to perdition.
Probably maybe
An alternative response would have been to acknowledge that there was a point being made borne of other experiences and that could be used to improve oneself. It is a question of attitude.
Suffice it say that the said nickname appeared on other sites, but for the fact that one, I have nothing to prove and two, I am not malevolent. It would have been an interesting exercise to create the profile I told him of and send it to him, but honestly, it would have been a waste of time in any case.
When I relayed the tale to a friend, he suggested the fellow might have been in security as a security guard. Not once did I contemn him, but his reaction belies that great possibility, he has keys to doors and not keys to data.


Tuesday, 3 February 2009

Your mum inadvertently uses your computer

A text for help

It was an SMS which was a half-panic text about his computer being infected by a virus and inquiring about what he had to do. Please can you advice? It ended, indicating a sense of calmness in the midst of the turmoil that could lose you your data in an instant.

Well, I hope my magnanimity in sharing this event is shared by my friend because it might well be my first real computer-usage related blog.

In fact, I really should have written much in this area since I wrote so much along these lines in my Masters programme and I do have 21 years of experience behind me.

However, stemming from a series of conversations with my friend about his computer and protecting himself from embarrassing situations, I have knocked up this little piece and it pertains mainly to Microsoft Windows systems.

If anything, it makes it safe for your mum to use your computer when you happen not to be around to prevent her seeing things she should not and you trying to explain yourself out of the impossible.

Updating an antiviral dosage

In times past you needed to protect your computer from viruses [PCHelpForum] [Wikipedia] [DirectoryM] that could destroy or mangle your data – you cannot scrimp on this – you MUST install an antivirus utility and always keep it up to date.

There are free offerings like AVG [AVG (Download)] or subscription offers from Symantec, McAfee or some other outfit, it is your first line of defence.

It is generally inexcusable to have an unlicensed operating system especially if you use the ubiquitous Microsoft Windows because its popularity lends to people finding ways to exploit its vulnerabilities – software is NOT perfect workmanship, it is generally a work in progress.

There are critical and security updates as well as service packs, you must always ensure your system is fully patched. Enable the reminders in your installed applications so you get informed when something needs to be updated – this also goes for drivers of devices installed in your system.

Pull up the drawbridge

People would always want to attack your system which is most probably always connected to the Internet, preventing that from happening requires that you enable your firewall [Wikipedia]. Your firewall is like a drawbridge with a sentry that check who goes there before allowing access.

You can make it more restrictive ask it to prompt for programmes trying to access the Internet which are not the usual email to Internet browser applications.

Your firewall must always be ON.

Gifts of suspect providence

So, they cannot get on your computer through the means of viruses or by your firewall and they try a Trojan horse [Wikipedia]. You visit a suspect site and inadvertently download some software or you receive a silly email that promises you a winning for a competition you did not enter – you double-click on some file and your computer grinds to a halt.

Meanwhile, the inadvertently installed programme is harvesting your usernames, passwords and even keystrokes then sending that information out to a computer where the malevolent can attempt to access your emails, bank accounts and do something so despicably evil with your personal details.

This is called malware [Wikipedia] and neither your antivirus application nor your firewall can handle this – you need a spyware [Wikipedia] remover and this is where Spybot – Search & Destroy [Safer Networking – (Download)] [AOL Video – (Tutorial)] is going to be your best friend.

What had happened was that a spyware programme masquerading as an antivirus toolkit needed an update had installed on his system and hijacked the Microsoft Security Centre giving the impression his antivirus was out of date.

Deceptive Antivirus

One look at the malware called Antivirus 2009 [SpyWare.com] [Wikipedia] leaves me both disgusted at the malevolent intend and impressed with the social engineering qualities the programme contains that the unsuspecting would have handed over all their information without knowing what had happened.

Through going to his Control Panel he was able to see that the Microsoft Security Centre was fine but being cloned and interfering with the normal operation of his system.

He downloaded Spybot – Search & Destroy which thoroughly searched through his system and completely removed every trace of the malware and any other suspect material.

Things you cannot share with mum

Finally, if you have been visiting places you cannot tell your mum about the built-in ability of Internet browsers to remove cached data would not suffice, it still leaves copious amounts of data that any smart guy can check to see where you have been as your face goes redder than beetroot.

To save your blushes you should get CCleaner [FileHippo (Download)] [YouTube – (Tutorial)] and run it regularly on your system – it rids your computer of any traces of where you have been, cleans your computer registry of obsolete or invalid data and offers a clean interface for removing applications.

These are not necessarily endorsements of the products mentioned but they are tools I have used for years to keep both myself and my computers out of trouble.

Maybe I should stick to writing my regular kind of blogs.