Monday, 14 April 2014

Browser Security: Most Effective Browsers Against Socially Engineered Malware

NSS Labs recently released the results and analysis from its latest Browser Security Comparative Analysis Report, which evaluated the ability of eight leading browsers -- Apple Safari, Google Chrome, Kingsoft Liebao, Microsoft Internet Explorer, Mozilla Firefox, Opera, Qihoo 360 Safe Browser, and Sogou Explorer -- to block against socially engineered malware (SEM). The use of social engineering to distribute malware continues to account for the bulk of cyber attacks against both consumers and enterprises, thereby making a browser's ability to protect against these kinds of attacks an important criterion for personal or corporate use.

Microsoft Internet Explorer continues to outperform other browsers. With an average block rate of 99.9 percent, the highest zero-hour block rate, fastest average time to block, and highest consistency of protection over time percentages, Internet Explorer leads in all key test areas.

Google Chrome remained in the top three, but its average block rate fell significantly to 70.7 percent, down from 83.17 percent in the previous test.

Cloud-based endpoint protection (EPP) file scanning provides substantial defenses when integrated with the browser. Kingsoft Liebao browser utilizes the same cloud-based file scanning system used by Kingsoft antivirus and had the second highest overall block rate at 85.1 percent, ahead of Chrome by almost 15 percentage points.



Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com



Google's Safe Browsing API does not provide adequate SEM protection. Apple Safari and Mozilla Firefox both utilize the Google Safe Browsing API and were the two lowest performing browsers in this latest test. Both also saw significant drops of around 6 percent in their average block rates -- Safari from 10.15 percent to 4.1 percent and Firefox from 9.92 percent to 4.2 percent.

Chinese browsers tested for the first time prove viable. This year, three browsers from China were included in testing for the first time, and Kingsoft's Liebao browser jumped ahead of Google Chrome with an overall protection rate of 85.1 percent. Sogou Explorer had the fourth highest average block rate at 60.1 percent.

Commentary: NSS Labs Research Director Randy Abrams
"Selecting a browser with robust socially engineered malware protection is one of the most critical choices consumers and enterprises can make to protect themselves. Microsoft's SmartScreen Application Reputation technology continues to provide Internet Explorer the most effective protection against socially engineered malware," said Randy Abrams, Research Director at NSS Labs. "This year NSS added three browsers from China. The Kingsoft Liebao browser displaced Chrome from second place by using a combination of URL filtering with the cloud-based file scanning technology that Kingsoft uses for their antivirus product. Sogou Explorer, another browser from China, was the only other tested browser to exceed 50 percent protection against socially engineered malware. Firefox and Safari failed to achieve five percent effectiveness and leave less technical users at considerable risk."

NSS Labs recommendations
Learn to identify social engineering attacks in order to maximize protection against SEM and other social engineering attacks.
Use caution when sharing links from friends and other trusted contacts, such as banks. Waiting just one day before clicking on a link can significantly reduce risk.
Enterprises should review current security reports when selecting a browser. Do not assume the browser market is static.

Friday, 11 April 2014

11 sure signs you've been hacked

11 sure signs you've been hacked

In today's threatscape, antivirus software provides little piece of mind. In fact, antimalware scanners on the whole are horrifically inaccurate, especially with exploits less than 24 hours old. After all, malicious hackers and malware can change their tactics at will. Swap a few bytes around, and a previously recognized malware program becomes unrecognizable.

To combat this, many antimalware programs monitor program behaviors, often called heuristics, to catch previously unrecognized malware. Other programs use virtualized environments, system monitoring, network traffic detection, and all of the above at once in order to be more accurate. And still they fail us on a regular basis.

[ Verse yourself in the 7 sneak attacks used by today's most devious hackers, 14 dirty IT security consultant tricks, 9 popular IT security practices that just don't work, and 10 crazy security tricks that do. | Learn how to secure your systems with the Web Browser Deep Dive PDF special report and Security Central newsletter, both from InfoWorld. ]

Here are 11 sure signs you've been hacked and what to do in the event of compromise. Note that in all cases, the No. 1 recommendation is to completely restore your system to a known good state before proceeding. In the early days, this meant formatting the computer and restoring all programs and data. Today, depending on your operating system, it might simply mean clicking on a Restore button. Either way, a compromised computer can never be fully trusted again. The recovery steps listed in each category below are the recommendations to follow if you don't want to do a full restore -- but again, a full restore is always a better option, risk-wise.

Sure sign of system compromise No. 1: Fake antivirus messages
In slight decline these days, fake antivirus warning messages are among the surest signs that your system has been compromised. What most people don't realize is that by the time they see the fake antivirus warning, the damage has been done. Clicking No or Cancel to stop the fake virus scan is too little, too late. The malicious software has already made use of unpatched software, often the Java Runtime Environment or an Adobe product, to completely exploit your system.

Why does the malicious program bother with the "antivirus warning"? This is because the fake scan, which always finds tons of "viruses," is a lure to buy their product. Clicking on the provided link sends you to a professional-looking website, complete with glowing letters of recommendation. There, they ask you for your credit card number and billing information. You'd be surprised how many people get tricked into providing personal financial information. The bad guys gain complete control of your system and get your credit card or banking information. For bad guys, it's the Holy Grail of hacking.

What to do: As soon as you notice the fake antivirus warning message, power down your computer. (Note: This requires knowing what your legitimate antivirus program's warning looks like.) If you need to save anything and can do it, do so. But the sooner you power off your computer, the better. Boot up the computer system in Safe Mode, No Networking, and try to uninstall the newly installed software (oftentimes it can be uninstalled like a regular program). Either way, follow up by trying to restore your system to a state previous to the exploitation. If successful, test the computer in regular mode and make sure that the fake antivirus warnings are gone. Then follow up with a complete antivirus scan. Oftentimes, the scanner will find other sneak remnants left behind.

Sure sign of system compromise No. 2: Unwanted browser toolbars
This is probably the second most common sign of exploitation: Your browser has multiple new toolbars with names that seem to indicate the toolbar is supposed to help you. Unless you recognize the toolbar as coming from a very well-known vendor, it's time to dump the bogus toolbar.

What to do: Most browsers allow you to review installed and active toolbars. Remove any you didn't absolutely want to install. When in doubt, remove it. If the bogus toolbar isn't listed there or you can't easily remove it, see if your browser has an option to reset the browser back to its default settings. If this doesn't work, follow the instructions listed above for fake antivirus messages. You can usually avoid malicious toolbars by making sure that all your software is fully patched and by being on the lookout for free software that installs these tool bars. Hint: Read the licensing agreement. Toolbar installs are often pointed out in the licensing agreements that most people don't read.

Sure sign of system compromise No. 3: Redirected Internet searches
Many hackers make their living by redirecting your browser somewhere other than you want to go. The hacker gets paid by getting your clicks to appear on someone else's website, often those who don't know that the clicks to their site are from malicious redirection.

You can often spot this type of malware by typing a few related, very common words (for example, "puppy" or "goldfish") into Internet search engines and checking to see whether the same websites appear in the results -- almost always with no actual relevance to your terms. Unfortunately, many of today's redirected Internet searches are well hidden from the user through use of additional proxies, so the bogus results are never returned to alert the user. In general, if you have bogus toolbar programs, you're also being redirected. Technical users who really want to confirm can sniff their own browser or network traffic. The traffic sent and returned will always be distinctly different on a compromised computer vs. an uncompromised computer.

What to do: Follow the same instructions as above. Usually removing the bogus toolbars and programs is enough to get rid of malicious redirection.

Sure sign of system compromise No. 4: Frequent random popups
This popular sign that you've been hacked is also one of the more annoying ones. When you're getting random browser pop-ups from websites that don't normally generate them, your system has been compromised. I'm constantly amazed about which websites, legitimate and otherwise, can bypass your browser's anti-pop-up mechanisms. It's like battling email spam, but worse.

What to do: Not to sound like a broken record, but typically random pop-ups are generated by one of the three previous malicious mechanisms noted above. You'll need to get rid of bogus toolbars and other programs if you even hope to get rid of the pop-ups.

Sure sign of system compromise No. 5: Your friends receive fake emails from your email account
This is the one scenario where you might be OK. It's fairly common for our email friends to receive malicious emails from us. A decade ago, when email attachment viruses were all the rage, it was very common for malware programs to survey your email address book and send malicious emails to everyone in it.

These days it's more common for malicious emails to be sent to some of your friends, but not everyone in your email address book. If it's just a few friends and not everyone in your email list, then more than likely your computer hasn't been compromised (at least with an email address-hunting malware program). These days malware programs and hackers often pull email addresses and contact lists from social media sites, but doing so means obtaining a very incomplete list of your contacts' email addresses. Although not always the case, the bogus emails they send to your friends often don't have your email address as the sender. It may have your name, but not your correct email address. If this is the case, then usually your computer is safe.

What to do: If one or more friends reports receiving bogus emails claiming to be from you, do your due diligence and run a complete antivirus scan on your computer, followed by looking for unwanted installed programs and toolbars. Often it's nothing to worry about, but it can't hurt to do a little health check when this happens.

Sure sign of system compromise No. 6: Your online passwords suddenly change
If one or more of your online passwords suddenly change, you've more than likely been hacked -- or at least that online service has been hacked. In this particular scenario, usually what has happened is that the victim responded to an authentic-looking phish email that purportedly claimed to be from the service that ends up with the changed password. The bad guy collects the logon information, logs on, changes the password (and other information to complicate recovery), and uses the service to steal money from the victim or the victim's acquaintances (while pretending to be the victim).

What to do: If the scam is widespread and many acquaintances you know are being reached out to, immediately notify all your contacts about your compromised account. Do this to minimize the damage being done to others by your mistake. Second, contact the online service to report the compromised account. Most online services are used to this sort of maliciousness and can quickly get the account back under your control with a new password in a few minutes. Some services even have the whole process automated. A few services even have a "My friend's been hacked!" button that lets your friends start the process. This is helpful, because your friends often know your account has been compromised before you do.

If the compromised logon information is used on other websites, immediately change those passwords. And be more careful next time. Websites rarely send emails asking you to provide your logon information. When in doubt, go to the website directly (don't use the links sent to you in email) and see if the same information is being requested when you log on using the legitimate method. You can also call the service via their phone line or email them to report the received phish email or to confirm its validity. Lastly, consider using online services that provide two-factor authentication. It makes your account much harder to steal.

Sure sign of system compromise No. 7: Unexpected software installs

Unwanted and unexpected software installs are a big sign that your computer system has likely been hacked.
In the early days of malware, most programs were computer viruses, which work by modifying other legitimate programs. They did this to better hide themselves. For whatever reason, most malware programs these days are Trojans and worms, and they typically install themselves like legitimate programs. This may be because their creators are trying to walk a very thin line when the courts catch up to them. They can attempt to say something like, "But we are a legitimate software company." Oftentimes the unwanted software is legally installed by other programs, so read your license agreements. Frequently, I'll read license agreements that plainly state that they will be installing one or more other programs. Sometimes you can opt out of these other installed programs; other times you can't.

What to do: There are many free programs that show you all your installed programs and let you selectively disable them. My favorite for Windows is Autoruns. It doesn't show you every program installed but will tell you the ones that automatically start themselves when your PC is restarted. Most malware programs can be found here. The hard part is determining what is and what isn't legitimate. When in doubt, disable the unrecognized program, reboot the PC, and reenable the program only if some needed functionality is no longer working.

Sure sign of system compromise No. 8: Your mouse moves between programs and makes correct selections
If your mouse pointer moves itself while making selections that work, you've definitely been hacked. Mouse pointers often move randomly, usually due to hardware problems. But if the movements involve making the correct choices to run particular programs, malicious humans are somewhere involved.

Not as common as some of the other attacks, many hackers will break into a computer, wait for it to be idle for a long time (like after midnight), then try to steal your money. Hackers will break into bank accounts and transfer money, trade your stocks, and do all sorts of rogue actions, all designed to lighten your cash load.

What to do: If your computer "comes alive" one night, take a minute before turning it off to determine what the intruders are interested in. Don't let them rob you, but it will be useful to see what things they are looking at and trying to compromise. If you have a cellphone handy, take a few pictures to document their tasks. When it makes sense, power off the computer. Unhook it from the network (or disable the wireless router) and call in the professionals. This is the one time that you're going to need expert help.

Using another known good computer, immediately change all your other logon names and passwords. Check your bank account transaction histories, stock accounts, and so on. Consider paying for a credit-monitoring service. If you've been a victim of this attack, you have to take it seriously. Complete restore of the computer is the only option you should choose for recovery. But if you've lost any money, make sure to let the forensics team make a copy first. If you've suffered a loss, call law enforcement and file a case. You'll need this information to best recover your real money losses, if any.

Sure sign of system compromise No. 9: Your antimalware software, Task Manager, or Registry Editor is disabled and can't be restarted
This is a huge sign of malicious compromise. If you notice that your antimalware software is disabled and you didn't do it, you're probably exploited -- especially if you try to start Task Manager or Registry Editor and they won't start, start and disappear, or start in a reduced state. This is very common for malware to do.

What to do: You should really perform a complete restore because there is no telling what has happened. But if you want to try something less drastic first, research the many methods on how to restore the lost functionality (any Internet search engine will return lots of results), then restart your computer in Safe Mode and start the hard work. I say "hard work" because usually it isn't easy or quick. Often, I have to try a handful of different methods to find one that works. Precede restoring your software by getting rid of the malware program, using the methods listed above.

Sure sign of system compromise No. 10: Your bank account is missing money
I mean lots of money. Online bad guys don't usually steal a little money. They like to transfer everything or nearly everything, often to a foreign exchange or bank. Usually it begins by your computer being compromised or from you responding to a fake phish from your bank. In any case, the bad guys log on to your bank, change your contact information, and transfer large sums of money to themselves.

What to do: In most cases you are in luck because most financial institutions will replace the stolen funds (especially if they can stop the transaction before the damage is truly done). However, there have been many cases where the courts have ruled it was the customer's responsibility to not be hacked, and it's up to the financial institution to decide whether they will make restitution to you.

If you're trying to prevent this from happening in the first place, turn on transaction alerts that send text alerts to you when something unusual is happening. Many financial institutions allow you to set thresholds on transaction amounts, and if the threshold is exceeded or it goes to a foreign country, you'll be warned. Unfortunately, many times the bad guys reset the alerts or your contact information before they steal your money. So make sure your financial institution sends you alerts anytime your contact information or alerting choices are changed.

Sure sign of system compromise No. 11: You get calls from stores about nonpayment of shipped goods
In this case, hackers have compromised one of your accounts, made a purchase, and had it shipped to someplace other than your house. Oftentimes, the bad guys will order tons of merchandise at the same time, making each business entity think you have enough funds at the beginning, but as each transaction finally pushes through you end up with insufficient funds.

What to do: This is a bad one. First try to think of how your account was compromised. If it was one of the methods above, follow those recommendations. Either way, change all your logon names and passwords (not just the one related to the single compromised account), call law enforcement, get a case going, and start monitoring your credit. You'll probably spend months trying to clear up all the bogus transactions committed in your name, but you should be able to undo most, if not all, of the damage.

Years ago you could be left with a negative credit history that would impact your life for a decade. These days, companies and the credit reporting agencies are more used to cyber crime, and they deal with it better. Still, be aggressive and make sure you follow every bit of advice given to you by law enforcement, the creditors, and the credit-rating agencies (there are three major ones).

Malware vector trifecta to avoid
The hope of an antimalware program that can perfectly detect malware and malicious hacking is pure folly. Keep an eye out for the common signs and symptoms of your computer being hacked as outlined above. And if you are risk-adverse, as I am, always perform a complete computer restore with the event of a breach. Because once your computer has been compromised, the bad guys can do anything and hide anywhere. It's best to just start from scratch.

Most malicious hacking originates from one of three vectors: unpatched software, running Trojan horse programs, and responding to fake phishing emails. Do better at preventing these three things, and you'll be less likely to have to rely on your antimalware software's accuracy -- and luck.

MCTS Certification, MCITP Certification

Microsoft MCTS Certification, MCITP Certification and over 3000+
Exams with Life Time Access Membership at http://www.actualkey.com

Saturday, 15 March 2014

If Microsoft gives away Windows Phone 8, will anyone take it?

In a bid to increase licensees and gain some badly needed market share, Redmond won't charge for its phone OS anymore.

Rumors and speculation have swirled on this for months, but now it's official: Microsoft is giving away Windows Phone for free, at least to a pair of Indian handset makers. If this can drive sales, it might become a worldwide policy, which could be the game-changer Microsoft needs and wants.

The Times of India first reported that Microsoft has waived Windows Phone licensing fees for Lava and Karbonn. Actually, the deal was somewhat telegraphed; last week, Karbonn announced that it was going to ship a dual-boot Android and Windows Phone device in June, and rumors of the deal were floating around at last month's Mobile World Congress.

The Times of India says Microsoft has been negotiating with Indian manufacturers since last year, and that the two manufacturers only agreed to make Windows phones when Microsoft waived the licensing fees.

"Free Windows Phone is part of a strategic partnership. For both Microsoft and us, it is an experiment. Windows Phone still doesn't have lot of appeal in the market but now that it doesn't have any license fee, it becomes easier for us to experiment with it," one unidentified executive told the Times.

If that sounds less than enthusiastic, you have to remember both Lava and Karbonn are already Google Android licensees and the phones that will run WP8 won't exactly be on the same level as the Lumia 928 or 1520. These will be cheap, low-end phones for India's mass market. It's a huge market – over one billion people.

So this can’t really be viewed as a bellwether for the U.S. or other mature markets. No offense to Lava and Karbonn, but they won’t be selling the equivalent to a Galaxy S5 to the kind of buyers Samsung and Apple cater to in the West.

It makes for a good experiment to see if the low-end market can drive demand and increase interest in Windows Phone. After all, IDC puts its market share at just 3.9%.

One thing about a product: if it’s good, you can sell it for a high price. If it’s bad, you can’t give it away. I personally like Windows Phone and I’m only using an iPhone because I felt the Nokia hardware was inferior, with terrible battery life. If that rumored HTC One running WP8 or a Galaxy model running WP8 ever emerge, I’m there.

So let’s see if Microsoft can give away it’s phone OS. It’s not like the company hasn’t given away products before to grab market share. True, it’s never given away an OS, but right now it’s not really selling it, either.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


Thursday, 13 March 2014

Twitter: Attack emails drop from 110 million per day to a few thousand

Adopting protocol called DMARC pays big dividends, says Twitter postmaster

There used to be a whopping 110 million attack messages per day spoofing the Twitter domain name as cyber-criminals blasted out fake Twitter e-mail at intended victims to try and fool them into opening dangerous malware-infested links and other scams. But by adopting a messaging authentication protocol called Domain-based Message Authentication, Reporting and Conformance (DMARC), Twitter has seen that number drop to a few thousand.
Lo and behold, it works!
— Twitter postmaster Josh Aberant about DMARC

“Lo and behold, it works,” says Josh Aberant, Twitter’s postmaster in charge of messaging.

DMARC first started about two years ago as a cooperative effort among Google, Microsoft, Facebook, and eBay’s PayPal unit, among others, to combat the scourge of spoofed e-mail that will mimic the domain names of well-known companies.

DMARC works by checking that e-mail truly originated from where it was supposed to. Organizations that support DMARC can monitor for fake e-mail and quarantine or block it. Aberant said Twitter, working with partners Agari and Message Systems, decided to block the bad e-mail that the DMARC protocol identifies.

+ ALSO ON NETWORK WORLD How to Implement DMARC in Your Organization | Google, Microsoft and others putting kibosh on phishing e-mails | How ADP and Facebook battle bad e-mail +

Aberant says he was shocked when he first saw monitoring that showed there were 110 million attack messages per day abusing the Twitter name.

By combining what’s called “DomainKeys Identified Mail” and the “Sender Policy Framework” with the “Authentication Failure Reporting Format,” DMARC represents the most comprehensive approach to preventing email abuse and protecting sender brands that the Internet industry has offered to date, according to Alec Peterson, chief technology officer at Message Systems.

Because DMARC is supported by the major Internet e-mail service providers, including Google, YahooMail, AOL and Microsoft, Twitter estimates about 90% of Twitter’s user base globally is covered under the DMARC filtering umbrella. Several Chinese ISPs have implemented DMARC as well. But Aberant would like to see more European telecommunications firms and those in the private sector join the DMARC effort to see the momentum build.

Twitter’s DMARC project, which took several months, involved working with a number of outside companies, the business partners such as Salesforce.com, to achieve a kind of “identity alignment” in messaging using the DMARC protocol, says Aberant.

Making sure DMARC authentication works properly means you have to “get a hold of the right people that manage the mail infrastructure,” he points out. Because Salesforce also happened to be using Message Systems, it was a fairly simple configuration change. But in other instances with business partners, the conversion to DMARC can be somewhat more demanding.


MCTS Certification, MCITP Certification

Microsoft MCTS Certification, MCITP Certification and over 3000+
Exams with Life Time Access Membership at http://www.actualkey.com

Saturday, 1 March 2014

Are You Too Old to Land a New IT Job?

Age really is just a number. If you're keeping current on new technologies and advancement, and show a willingness to keep learning and growing, there's no reason it should be an impediment to your job search.

Looking for a job or a promotion and worried that your age might be an impediment? Don't be. Age really is just a number, and especially in IT, that number isn't as important as your accomplishments, your adaptability and willingness to learn.

"It's about being able to demonstrate your accomplishments," says author, career search expert and consultant Rick Gillis. "Most IT firms want to know one of two things: Can you make them money or can you save them money? Then they'll want to hire you, regardless of your age," he says.

Nobody would hire a doctor, for example, who isn't using robotics in his practice, says Gillis. Staying current on new technologies, advancements and methodologies can keep your skill sets relevant and will help you avoid becoming one of those 'former masters of the universe' who've faded into obscurity and can barely turn on their computer, he says.

Too Old for IT

Stay Hip and Up on Tech

"You have to be current. That is key, especially in IT," Gillis says. "I find it disturbing when I speak to clients who are older and they aren't spending time studying, staying hip and up-to-date on new technology advances," he says.

"If you've been looking for a job for six months, you have to realize how much has happened in that time -- learn about emerging technology. Know the terminology. Be able to show that you've added to your knowledge and your skills," Gillis says, and be able to demonstrate how that knowledge and your skills have positively impacted previous employers.

As an example, Gillis cites a former client who was struggling to demonstrate his achievements while searching for a job. The client had one specific job for which he wrote nearly 10,000 lines of code for a bank, but couldn't point to a specific outcome, Gillis says.

"I advised him to take a personal inventory, to reach out to his contact and determine how to quantify what he did," Gillis says. "When we talked to his contact, we were told that the code he wrote was used by the bank to fix some significant security flaws with their ATMs that used to require a lengthy, expensive service call and two people to address," Gillis says.

"It turns out, my client saved the bank more than half a million dollars a year on this expense, and while it did take some time and digging to determine how to quantify his efforts, it was worth it," he says.

But adaptability and using relevant skills and knowledge is a two-way street, says Mike Capone, CIO at human capital management solutions firm ADP. Employers should constantly be looking at the knowledge and skills present in their workforce to see how those accomplishments can help further business goals and even to educate newer, younger or less experienced employees, Capone says.

Adaptability Knows No Age Limit

"Age, in and of itself, doesn't matter, but adaptability does," says Capone. "That's not always a skill you're born with, but it can be learned," especially if companies are tapping into their older employees' skills and knowledge to help educate the younger generation, he says.

To that end, Capone says, ADP makes sure to identify and reward good leadership and tap into older, more experienced employees' domain expertise, and linking them up with younger, newer employees.

"With our younger generation of workers, we force rotational assignments every 18 to 24 months to make sure they are gaining the knowledge and experience of some of our more seasoned people," says Capone. "It's like having that veteran player in the locker room, so to speak, but it's a mutually beneficial exercise. The younger folks keep the older workers current and up to date, while the more experienced folks bring a level of maturity to teams," he says.

"Mentoring is a two-way street, and even when I, as the CIO, am paired up with employees who are much younger and lower on the corporate ladder, I learn something every day," Capone says.

Regardless of the age of employees, companies need to think differently about their workforce to better reap the benefits of existing talents, experience, skills and knowledge, Capone says. Building up your talent pool to take advantage of relevant skills doesn't have to mean bringing in outside consultants or new employees; what you need could be right under your nose.

"It's about change management," Capone says. "And how you incorporate that into your day-to-day operations. Whether you're looking at employees who are 20 or 60, technology, business needs and skills change at a much faster rate right now than they did even five years ago.

It's incumbent on the leadership of the company to manage the talent and take advantage of the skills that you have and the competencies within the domain expertise you need to be successful," he says.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Wednesday, 19 February 2014

How to save your email archive from a service provider

When your service provider doesn't want you to leave them, how do you get your message archive back?

I recently fielded a query from a Network World reader, a one woman company, who has an email problem: Back around 2006 a computer tech set her up with a hosted exchange server so that she wouldn't lose email in the event of her computer failing, could sync her email with her iPhone, and could have webmail access. Everything was fine for eight years but, alas, the service provider has recently raised their fees from $8 per month to $35 per month.

My reader knows this is tantamount to gouging and that she can get the same service for considerably less (in fact, for nothing if she switches to Google's Gmail) but she has a problem: Tech support at the service provider told her that if she ends the service she'll lose all her archived email and they apparently (and not surprisingly) aren't at all interested in helping her beyond twisting her arm to stay with them.

So, the solution is simple: My reader just needs to make a copy of the contents her hosted exchange service and, as the saying goes, Bob will be her uncle. The answer to her problem is a tool called MailStore Home which works under Windows XP SP3, Vista, Windows 7, and Windows 8.

All she has to do is download, install, and run MailStore Home then, under "Archive Email," configure an email account profile for her provider, and run the profile.

With Gmail I discovered that I had to first get a minimal download completed before trying to archive everything (I know; that makes no sense but after that the archive process worked flawlessly). Downloading from a service like Gmail is not limited by your connection speed; as of writing 90,000 messages has taken something like five hours to download and process but I blame AT&T U-verse's crappy services around 3Mbps for my poor performance).

MailStore provides archiving for:
Internet mailboxes such as Gmail or Yahoo! Mail
Any POP3 and IMAP mailboxes
Microsoft Outlook XP, 2003, 2007, 2010, 2013
Microsoft Outlook Express and Windows Mail
Microsoft Exchange Server 2003, 2007, 2010 and 2013 mailboxes
Microsoft Office 365 (Exchange Online)
Mozilla Thunderbird and SeaMonkey
.EML and other email file formats

Along with that MailStore provides a fast indexing and search feature, the ability to open an archive with a single click, support for huge email archives, and a portable option that can be launched directly from a USB drive.

For business use there's MailStore Server priced at $190 and MailStore Service Provider Edition (price on application).

As an SME/enterprise tool this is a must have. I hope my reader is happy.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


Monday, 17 February 2014

IE10 under attack as hackers exploit zero-day bug

FireEye uncovers attacks emanating from a U.S. website just two days after Microsoft issued huge IE patch collection

FireEye today said it had discovered that attackers are actively exploiting a new, unpatched vulnerability in Internet Explorer 10 (IE10).

Microsoft confirmed the Milpitas, Calif. security company's report.

"Microsoft is aware of targeted attacks against Internet Explorer, currently targeting customers using Internet Explorer 10," a Microsoft spokesperson said via email. "We are investigating and we will take appropriate actions to help protect customers."

FireEye's disclosure came just two days after Microsoft patched every edition of IE with a large update that fixed 24 flaws, 15 of which applied to IE10. The IE update, which was not originally on this week's Patch Tuesday slate, was added at the last minute by Microsoft, which said it had completed testing of the repairs in time to make the cut.

The attack code, said FireEye, was hosted on a compromised website based in the U.S. The company called the exploit a "classic drive-by download attack," a term reserved for the most dangerous kind of browser-based assaults, one that only need entice people to a malware-infected site.

According to FireEye, the exploit sidesteps ASLR (address space layout randomization) using Flash ActionScript, an Adobe-owned scripting language most often used on sites that rely on Flash Player to execute content. ASLR is one of Windows' most important anti-exploit technologies.

"Upon successful exploitation, this zero-day attack will download a XOR-encoded payload from a remote server, decode and execute it," FireEye added.

FireEye said that it is "currently collaborating" with Microsoft's security engineers on researching the IE10 vulnerability and the related exploit.

IE10 has been on the downturn for the last four months. Starting in October 2013, Microsoft has been replacing IE10 with the newer IE11 on Windows 8 devices, including PCs and the tablets -- such as Microsoft's own Surface Pro 2 -- that run the full-featured Windows 8 and 8.1 rather than the subset-of-an-OS Windows RT.

Microsoft released IE11 for Windows 7 in November, at which point it was automatically pushed to those machines as a substitute for IE10.

Web metrics firm Net Applications estimated IE10 user share, a rough calculation of the percentage of all Internet users running a specific browser, at 9.3% in January. Most people running IE remain tied to 2009's IE8.

IE10, targeted by attackers exploiting a "zero-day" vulnerability, is on its way out as Microsoft pushes the newer IE11 to Windows 7 and Windows 8 users. Last month, IE10 accounted for about 16% of all versions of Internet Explorer used to browse the Web. (Data: Net Applications.)

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com