RejZoR's little secrets

Little technology secrets for big everyday problems...

Subscribe to RSS feed

Posts tagged with "security"

Google's GMail double verification login

, , , ...

In theory, it's secure. However it's very unpractical and i have a much better idea on how to properly strengthen online accounts from my own experience.

SMS verification on demand only
Something Hotmail service is calling as "Disposable login". When you're on a public computer, you have to enter correct e-mail and the single use password will be sent to your phone via SMS. You can then log in using this one time use password. When session expires or you sign out, the same password cannot be used again. However at home it won't be bothering you with double verification because it's in most cases unnecessary and just makes it annoying to use. So in this case Hotmail's solution is much more flexible and user friendly while also keeping security at an appropriate level.

Critical account settings modification verification via SMS
What's more important is the account main settings lockdown. This means personal info, login password, account recovery features and so on should only be visible after verification via SMS and also be modifiable after SMS verification.

This way you can't just walk into an ongoing session and change or view critical login information.
Also this would pretty much eradicate any possibility of hijacking accounts.
What is the usual scenario when you get an account breach? The attacker quickly changes password and recovery settings. Even SMS settings that are otherwise available in most services can easily be modified just like that. When all this is done, the original user is pretty much fucked. It's a design failure to begin with.

But in my scenario, only way to hijack account would be to also steal your phone. There is no other way in doing it. Why? Here is a "live" scenario...

Attacker somehow manages to get inside your account and read your mails. As much as it sounds bad, it's even worse when you get locked outside of your own account. But in a SMS secured account settings, attacker will be able to read your mails indeed, but he won't be able to change your login password or recovery settings unless he can get the verification code from your phone.
So in this case he'll be able to read your mails but when he'll want to change the password, verification SMS will be sent to your phone. And without it he can't even access (view) critical account settings, let alone change them. And since SMS verification settings (phone number) is locked down with this feature he can't bypass SMS verification either. Since GMail offers IP logging you can rather quickly spot any unauthorized access to your account and change the password. Some data might leak from your e-mails but it's nowhere near as bad as losing control over your account and losing ALL your e-mails.

Downside of my SMS verification lockdown
Now the base idea is very secure and is pretty much impossible to bypass. But there is also a bad side of it. If you change your phone number before first changing it inside your account will result in locking yourself out. So in this case you have to be sure to first change phone number inside your account. Another problem is also a stolen or lost phone. But this is just a temporary problem. In such case you have to quickly contact your mobile service provider and disable the original SIM card remotely, making it useless (even pre-pay service users can do this by proving phone number ownership with the credit card sized frame to which SIM card was attached when they bought it). Then you have to request a new SIM card with the same phone number (but different PUK obviously). This way you regain control over your account access.

I hope someone from Google is reading this and that we can see this kind of level of security in their service very soon and that other providers will follow as well. Sure we have to give away phone number to "evil" Google that's collecting all our data, but with it, security of our accounts would skyrocket as well.

avast! 5.1.864 program update released!

, , , ...

So, this program was actually released last year (2010) hehe. Sounds so funny and we're talking about 1 single day timeframe, just with different year tag. Ok, enough of the nonsense. avast! guys were hard working even on the last day of 2010. I was working as well, which i didn't like too much, but they were working pretty much all the way till the end of the year. And here is the result. A major program update.

The most notable improvements are:
- boot-time scanner now available even in 64-bit Windows
- big improvements in the Behavior Shield
- improvements in the antirootkit engine
- improvements in the cleaning module
- stability/performance improvements in the Web Shield
- CommunityIQ improvements
- added support for sound packs
- minor improvements in the user interface
- minor fixes in the firewall

To break it down into few words, the most important changes are boot-time scanner for 64bit systems, massive improvements to Behavior Shield and performance improvements for Web Shield.
Boot time scanner for 64bit is a nice cleaning addition which was previously only available to the 32bit OS users. Code signing made this feature hard to implement under 64bit, but the avast! guys did it again and made it available even though OS itself kinda prevents such things on a core level.

Second thing is Behavior Shield. Ppl including myself were complaining a lot about Behavior Shield not doing much at all at any time. Well this has changed with avast! 5.1. Behavior Shield now works even on 64bit systems and is now covering wider area of the system. Before the version 5.1, it was pretty much only protecting against certain exploits and kernel level rootkits. Now, it's able to check for any kind of malware like behavior. It's set to "Allow" for the time being, so that avast! team can gather some hard data on system behavior and how everything works on a larger scale before they actually fully enablde this thing. However you can switch it to "Ask" mode yourself and get some action going. I've tested it and even though it's very basic in it's current form, it was already been able to protect or at least warn when something wanted to perform an unauthorized or suspicious system modification while not jumping up when system changes were done but in a good way by legit programs.
We'll see more of this feature in action when avast! 6.0 hits the "streets" sometime soon...

Third feature, even though not as significant but still important is the support for pipelining in Web Shield component which means that certain web browsers that use pipelining will now perform better (faster webpage rendering) even with avast! installed. Opera browser is one of them for example.

Stay tuned for more info regarding avast! 6.0 and enjoy this fine program update. This program update will be distributed automatically to all users over course of the following week, but if you want it now, you can update it manually through integrated updater. Happy New Year to everyone, especially avast! guys!

Get AVG Internet Security 2011 for 1 year free!

, , , ...

Just go to this link:
http://free.avg.com/ww-en/people-powered-protection-promo

Enter your e-mail address, enter who recommended it to you (a friend, me here on this blog, maybe someone else etc), enter CAPTCHA thingie and you're done. You can start using the AVG Internet Security 2011 package right away, it will function fully for 30 days in which time, you shoudl already recieve license key from AVG Technology to fully unlock a 1 year free version of AVG Internet Security 2011.

Just a side note, please don't overuse this promotion (like ordering 50 licenses for 1 person), but do recommend it to your friends as this seems to be the whole point of this promo.

Enjoy!

AVG Antivirus 2011 line released!

, , ,

AVG has been quite popular though up till now i wasn't really sure why. It had nothing special to offer compared to superior avast! Free and AVIRA Free. However that has dramatically changed with 2011 line of products. While their payable range of products have undergone smaller changes and upgrades, the FREE version got the biggest attention.

What's new in AVG Antivirus Free 2011?
- Cloud technology
- Identity Protection (IDP module, which is essentially a behavior blocker)
- AVG Social Networking Protection (real-time checking of services like Facebook)
- Full Anti-rootkit module

Now, i haven't tested it thoroughly, just a brief view before i had to leave for work. But from my past experience with IDP (when it was still operational as Norton Anti-Bot) and few tests of stand alone AVG Identity Protection i can tell that it's very effective against new unknown threats.

AVG in its last incarnation will be a really tough competition for avast! and AVIRA. It has it's initial glitches and annoying banner in the main interface but the features somehow make up for that.
Keep an eye on this one, i think it will perform pretty well in the upcoming tests...

AVG Antivirus Free download:
http://free.avg.com

AVG official webpage:
http://www.avg.com

Comodo Internet Security 5 released!

, , , ...



DOWNLOAD:
http://personalfirewall.comodo.com/free-download.html

Few days have passed, but still, Comodo has just released their latest CIS version, CIS5. I was never a total fan of their software as they do have good ideas, but their implementation is usually bad. However i have to say it's slightly better this time. If you're looking for a free alternative to many payable products or you want to use it in commercial environment, i think it's a good option.
Firewall has been very good for long time, GUI graphics as well, D+ showed some strong points, however it was very annoying in the past and their standard antivirus scan engine doesn't seem to be too advanced, or at least is often showing excessive number of false positives on pretty much random selection of files. Anyway, if you like what it offers or you're just plain curious (just make sure cats are in safe place wink ), give it a try and see how it works for you.

What's new in CIS5:

NEW! Extended spyware scanner and improved malware cleaning
NEW! Cloud Based Antivirus Scanning
NEW! Cloud Based Behavior Analysis
NEW! Cloud Based Application White-listing
NEW! Game Mode
IMPROVED! Application Control
IMPROVED! Default Deny re-engineered to improve application compatibility
IMPROVED! Application user interface

Cloud Based Infrastructure:
2011 family of products(Yes COMODO Firewall too!) are now armed with cloud based file rating technologies. The cloud computation, enabled by default, is used for a variety of purposes.(Do not be surprized if COMODO Firewall gives you a malware alert!!!).

With cloud computation;

* Cloud based Whitelisting: Safe files and trusted vendors are now easily identified. The concept of “Trusted Publisher” is now cloud based.
* Cloud based Anti virus: Malicious files are detected even if the users do not have an up-to-date antivirus product or an antivirus product at all.
* Cloud Based Behaviour Analysis: Zero-day malware can be detected INSTANTLY by COMODO’s cloud based behavior analysis system CIMA(Comodo Instant Malware analysis).


Extended Spyware Scanning
COMODO’s vision and focus has been about “keeping a clean computer clean” from early days. Now that We have achieved that COMODO is focusing on “cleaning an already infected computer”. This is why we extended the spyware scanning in COMODO Internet Security 2011 and COMODO Antivirus 2011 and now include a new spyware scanner which is capable of scanning the windows registry and computer disks for the signs of malware infection.
This new scanner is implemented to improve the detection and successful cleaning rate of already infected systems.

Game Mode
2011 family of products are now gamer friendly security applications. When they are put into the game mode, the operations that can interfere with users’ gaming experience such as alerts or resource intensive virus database updates, scheduled scans are suppressed.

Stronger and Smarter Application Control
2011 family of products have a highly smart application control mechanism which extends the functionality of the previous versions.
The new application control provides the users the ability to lockdown their computers such that only the known good applications can be executed.
The new sandbox introduces a new default application isolation level, partially limited, which improves the compatibility with many windows products.

Nowadays, a lot of malware come in other forms than standalone executables. For example, some come in the form of visual basic scripts while some come in the form of java binaries. When they come in such forms, they are executed by “interpreter” applications such as wscript.exe or java.exe etc.
2011 family of products can identify such applications heuristically and detect the real file behind the requests of “interpreters”.

Safer web browsing tips

, , , ...

Browsing and shopping a lot but you're never sure if the webpage is safe? There are few tools that can help you make slightly better decisions. Either when you're just browsing, trying to shop online or when searching through your favorite search engine.
It's recommended to use any kind of antivirus, even free ones are always good enough to do the job, especially avast!, MSE, AVG, AntiVir or Panda Cloud. I'm talking about webpage rating tools that are all free and can greatly improve security on today's rather hostile internet.

AVG LinkScanner
Pretty good tool that's checking webpages for known and unknown exploits. Unfortunately is not compatible with avast! prior version 6.0. So if you want to use AVG LinkScanner along with avast!, make sure you have the latest avast! (currently v6.0). If you're already using AVG Antivirus (even free one), you don't have to install this as it already comes with it. Highly recommended.

Symantec Safe Web Lite
This one is coming from a well known security vendor Symantec. The check does have a small delay, but i found their ratings to be very accurate. Also provides additional security ratings for web shops and pops up with a big warning when you visit a bad website. Highly recommended.

McAfee SiteAdvisor
Similar as Symantec, this one is from McAfee. Maybe not as accurate but can be quite useful as a second opinion tool.

PCTools Browser Defender
Another webpage rating, this time from PCTools. Search results seem to be quite reliable, however there seem to be few smaller glitches where results might clash. Icon says unsafe, when clicking it, it says it's safe. I've reported that and waiting for feedback from the PCTools.

Web of Trust (WOT)
Community based web rating webage. May not be exactly accurate but can be a good second opinion tool.

Now, these tools are not 100% protection, in fact they won't prevent you from visiting the webpage, they will just notify you about their security. But if i says UNSAFE, then pay attention and try to avoid that webpage. It just might save your computer. Or your credit card.
Be smart, browse safely bigsmile

Comodo Internet Security 4.0 Free

, , , ...


It has been some time since i last posted here and some time also passed since Comodo released their latest version of Comodo Internet Security version 4. As you all probably know, i'm a great fan of avast! Antivirus. It's free, works damn well and community is nice. It's just a nice package overall. I did a few runs of CIS before, in fact i did that since they started years ago. And i never quite liked it even though they wanted to show certain level of innovation with each release. Just to find out later it's rubbish. But not this one. They got rid of the useless HIPS no one ever wanted. And replaced it with a much smarter solution. A sandbox. And not just like others do it. They opted for a more unique approach which i must say actually works for a change. It works like this. If the application is trusted, it works in unrestricted mode. If the application is unknown, it automatically runs it in sandbox until tested to be safe. And sandbox is not a very slow emulated environment. Everything runs on host level with host performance. It's just that Comodo restricts certain stuff to the application run through sandbox.
And again, that proved to work really well. I've tested it today and results were incredible.
Scan engine is still rather bad and produces loads of false positives, but sandbox performed as intended.
I've loaded up lots of malware samples including those pesky Sality and Virut samples. And none of them got through. They were all sandboxed and restricted from doing any harm to the host system and i never really got many popups like in older versions. Just few here and there of which 3/4 were just Sandbox notifications that don't require any intervention.
After reboot i could just delete files by hand from desktop where i had the samples. There were some remaining files on the system, but they were not active and as such not a threat to the health of the system. There are also other changes, mostly related to GUI, but nothing drastic. Sandbox is the thing you want to have and use.

If you're looking for a free program that is finally almost fool proof, offers nice features and great level of protection and no licensing restrictions, CIS 4 is the thing you want. Yes, this means it can be freely used on ANY kind of system for as long as it's running Windows. It can be your laptop, home PC, your home office computer or your home business environment. Or even workstations in a large corporation if you decide for it. Unlike other free solutions, Comodo doesn't have any restrictions between home and commercial usage.

I still think avast! Antivirus is a great product, CIS4 is great alternative if you don't like avast! for whatever reason that might be. Or if you just want to experiment a bit.

CIS homepage (with web installer):
http://personalfirewall.comodo.com/

CIS standalone installers:
32bit: http://download.comodo.com/cis/download/installs/xml_binaries/cis/cis_setup_x86.msi
64bit: http://download.comodo.com/cis/download/installs/xml_binaries/cis/cis_setup_x64.msi

Comodo forum for help and tech support
http://forums.comodo.com

avast! 5.0 Antivirus released!

, , , ...



It took a while but we finally got it. The brand new avast! 5.0 Free Antivirus, avast! 5.0 Professional and avast! 5.0 Internet Security.

What's new in version 5?
Brand new interface is the most obvious thing. More settings and features for free version as well. All malware removal actions are automated now even for free version. Free version also gets the brand new Behavior Shield that helps detect new unknown malware, new rootkits and malware that is just plain hard to detect using traditional scan methods. There is also a separate PUP detection for Potentially Unwanted Programs and ultra fast high performance heuristics engine based on dynamic translation method which is the fastest emulation method available. Engine also sports generic unpacking capability to unpack modified and unknown packers.

Professional and Internet Security versions also offer sandbox, a virtualization technology where you can run any malware or suspicious program without risking system infection. Along with this there is also Script Shield that is analyzing executed scripts in browser Internet Explorer and advanced fully automated firewall in IS (that can also be fully manual for advanced users).

You can read more about it on brand new avast! web page with new fresh design, but unfortunately due too it's popularity, it has some problems loading today. Download of avast! is also VERY slow today so i will provide few download mirrors to mitigate this problem.

avast! 5.0 Free Antivirus download mirrors:
Download.com mirror (Official mirror)
SoftPedia mirror
FileFront Mirror
Windows Live SkyDrive mirror

Removal tools for Norton and McAfee security programs

, , , ...

There are many situations where you want to get rid of old security software completely.
This mostly involves trial versions that come pre-installed on laptops and PC's.
And most problematic two are Norton (Symantec) and McAfee.

So how to remove them properly? First try to uninstall them the usual way through Add Remove Programs and reboot the system as required by the uninstaller.
Then you have to download one of the following tools depending on what you need.

Norton (Symantec) Removal Tool
http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039?OpenDocument

McAfee Removal Tool
http://download.mcafee.com/products/licensed/cust_support_patches/MCPR.exe

These tools will help you clean all the remaining junk that you don't want on your system, especially if you're planning to install security software from other security vendors.

I hope this will help resolve many compatibility issues that ppl are having with unnecessary stuff that remains on your system even after their uninstallation.

avast! and Win32:Delf-MZG [Trj] detections everywhere

, , , ...

Late yesterday some technical problems happened with virus definitions which were solved pretty fast.
Detection in question was Win32:Delf-MZG [Trj] with definitions 3.12.2009 - 91203-0.
Please use avast! updater to update to 3.12.2009 - 91203-1 or later which resolves this issue.
If you encounter any popups during this process, just click "Ignore" and restore everything from Chest that was detected under this detection.

I'm sure ALWIL team feels sorry about this situation, but they did solved it pretty fast.
Such things can happen occasionally. No one is immune to this (it happened to almost everyone, even McAfee, Symantec and Trend Micro).

UPDATE and official ALWIL Software statement:
http://forum.avast.com/index.php?topic=51647

UPDATE 2 and help how to remedy the situation:
http://support.avast.com/index.php?_m=knowledgebase&_a=viewarticle&kbarticleid=376

UPDATE 3 and explanation what went wrong:
http://forum.avast.com/index.php?topic=51783.0