Showing posts with label Week 4. Show all posts
Showing posts with label Week 4. Show all posts

Tuesday, June 24, 2008

A review on a post on Internet Security from My E-Commerce blog

Reviewing post: "Spammer Agrees to $10 million settlement http://ecommerze.blogspot.com/search/label/Internet%20Security

When we type “Ryan Pitylak” in any search engine, there are many results about Anti-spam activists, affiliate marketing services, viral marketing, anti-spam services, and so on. Well, his name is blacklisted previously as he is known as “spam king” at year 2004.

The man who was tricking people by sending 25 million spam-mails a day, now is turning a new leaf. I had viewed his blog: http://ryanpitylak.blogspot.com and it showed that “Ryan Pitylak” is one of anti-spam community. He provides services in stopping spam from spammers. He also provides other services as I mentioned above.

Graham Cluley of Sophos (1 of IT Security Company) said, "Spammers like Pitylak have shown themselves to be prepared to break the law in their eagerness to pump out unwanted marketing messages. Some companies may feel uncomfortable about working with someone who has shown a history of behaving unethically, without caring about the consequences for other internet users."

I think that we should give opportunity to wrong-maker because everyone would make mistake. People may change to be better. Besides, his previous experience is worth to the organization who hires him as he can provide more efficient way to fight against spam.

Now, he set up his own company, Pitylak Security. I believe that the person who can learn from mistakes and correct those mistakes will be successful.

Friday, June 20, 2008

Phishing: Examples and its prevention

What is “Phishing”?

Phishing is pronounced like “fishing”, is a term used to describe a malicious individual or group of individuals scamming users by sending e-mails or creating web pages that are designed to acquire sensitive information, such as usernames, passwords and credit card details. Normally, PayPal, eBay and online banks are common targets.
How to identify a phishing e-mail?
a) Identify the company
These types of e-mails normally are sent out to thousands of different e-mail addresses. Actually, the person sending these e-mails has no idea who you are. If you have no affiliation with the company the company the e-mail address is supposedly coming from, it's fake. For example: the e-mail is coming from Citibank but you bank at a different bank.

b) Checking spelling and grammar
Improper spelling and grammar is almost always an obvious error.

c) No mention of account information
If the company really was sending you information regarding errors to your account, they would mention your account or username in the e-mail. In the eBay example, the e-mail just says "eBay customer", didn’t mention you username and account number, if this really was eBay they would mention your username.

d) Deadlines
E-mail requests an immediate response or a specific deadline.
For example: the requirement to log in and change your account information within 24 hours.

e) LinksMany phishing e-mails will hide the true URL. Normally, the URL list in the email is not related to the company URL. For eBay example: http://fakeaddress.com/ebay is not an eBay URL, just a URL with an eBay section. If you're unfamiliar with how a URL is structured.

Below are examples of what a phishing e-mail may look like:








How to prevent the phishing?

a) Keep antivirus up to date and use anti-spyware software
Most antivirus vendors have signatures that protect against some common technology exploits.
This can prevent things such as a Trojan. Besides, installing an active spyware solution such as Microsoft Antispyware.

b) Do not click on hyperlinks in e-mails
Do not click any hyperlinks in an e-mail, especially from unknown sources.

c) Take advantage of anti-spam software
Anti-spam software can help keep phishing attacks at a minimum. A lot of attacks come in the form of spam. You can reduce many types of phishing attacks by using anti-spam software such a Qurb.

d) Firewall

Use a desktop (software) and network (hardware) firewall. It can prevent some malicious code from entering your computer and hijacking your browser.

Thursday, June 19, 2008

The Threat of Online Security: How Safe is Our Data?

Nowadays, most businesses have move towards to online system. They have experienced some kind of security threat to their business.Since the Internet is a public system in which every transaction can be tracked, logged, monitored and stored in many locations, it is important for businesses to understand possible security threats to their business.

Security can divided to three concept.First is confidentiality.Confidentially allows only authorized parties to read protected information.Second is integrity.Integrity make sure that the data remains as is from the sender to the receiver.Third is availability which can ensures you have access and are authorized to resources.

There are many threats to e-commerce that may come from sources within an organization or individual. The followings are some of the potential security threats that can be found:

1. Tracking the shopper - It is one of the easiest and most profitable attacks, another name is social engineering techniques. These attacks involve observation of the shopper’s behavior, gathering information to use against the shopper.

2. Inquiring the shopper’s computer - Most of the users are no understand about the system that they are using. Additionally, software and hardware vendors, they want to ensure that their products are easy to install, then they will ship products with security features disabled. The confused user does not attempt to enable the security features.

3. Sniffing the network - Here, the attacker monitors the data between the shopper’s computer and the server. He collects data about the shopper or steals personal information, such as credit card numbers.

4. Using known server bugs - The attacker analyzes the site to find what types of software are used on the site. Then, the attacker proceeds to find what patches were issued for the software. In addition, he searches on how to utilize a system without the patch. He proceeds to try each of the exploits.Finally, the attacker finds a weakness in a similar type of software, and tries to use that to exploit the system. This is a simple, but effective attack.

How to safeguard our personal and financial data??


Nowadays, theft can also be committed through computer or internet. Therefore, the security of our personal and financial data is important. There are several steps to safeguard our personal and financial data.

The first step is setting up the username and password for logging into computer. After done, it will only access to the network. This can help us to keep away the unauthorized people from entering. But we must avoid using the password that can be easily figure out by others such as birth date and never use the automatic login that saves the password. The important thing is never write the information down, that means always keep the information in our mind. We are also encouraged to change the password frequently.

Generally, credit card information is needed for purchasing online when making the payment. It is essential for us to use the password protected to safeguard our credit card information. Sometimes, we will require entering the credit card verification codes rather than only entering the card numbers, holder’s name. These codes can be found on the back of the credit card. It used to make sure that the card is used only by the card’s holder.

Sometimes, we will receive the unsolicited e-mails from unknown senders. It is best to type in the web address and never clicks directly on the links. Moreover, never respond to the mails appearing from bank or other entity that request our personal information.

To protect our personal data from being stolen, anti-virus software, anti-spyware and firewalls can be used to safeguard the data. But we have to make sure the anti-virus software and anti-spyware are always up-to-date. Firewalls are installed especially for those who are always connected to the internet.

It is important for us to protect our personal and financial data before it has been stolen.