Showing posts with label Preventing. Show all posts
Showing posts with label Preventing. Show all posts

Computer Security - Preventing Social Engineering Attacks


Social Engineering in its basic form is hacker talk for manipulating computer users out of their username and password. Social engineering really goes beyond just usernames and passwords. A well planned social engineering attack can destroy companies. All of the most devastating information thefts have used some sort of social engineering attack. Social engineering is so effective because computer admins and security experts spend all their time patching systems and not training employees about information security. Information security goes beyond patching computers, it is a combination of physical security, computer/network policy and employee training.

This article will describe many of the common security flaws that information thieves take advantage off and how you can prevent them.

1. Web sites Information - Company web sites are the best place to start when gathering information. Often a company will post all their employees names, email addresses, positions and phone numbers for everyone to see. You want to limit the number of employees and phone numbers listed on a web site. Also, live active links to employee email addresses should be avoided. A common mistake is a company's email user name will be the same as their network logon, example: email address of jsmith@nocompany.com has a user name of jsmith for the network with the same password for email and the network.

2. Phone Scams - Scamming someone on a phone is very simple. Company employees need to be trained to be courteous but cautious when giving callers information over the phone. One hacking scam is a hacker will call a company posing as computer salesmen. The salesmen will ask the secretary what type of computers they have, do they have a wireless network and what type of operating systems they run. Hackers can use this information to plan their attack on the network. Train your employees to refer any IT related questions to Tech Support.

3. Outside Contractors - Outside contractors should have a security liaison to monitor their activities. Security liaisons should be briefed on what work the contractor is hired to perform, area of operation, identity of contractor and if the contractor will be removing items from the work site.

4. Dumpster Diving - The easiest way to get information about anyone is to go through their trash. Shredders should be used in all cases or shredding services should be hired. Also, the Dumpster should be in a secure location and under surveillance.

5. Secretaries - They are your first line of defense, train them to not let anyone into your building unless they are for certain whom they are. Security cameras should be place in the main entrance way and also on the outside of the building. A thief who is probing your network will test to see if he is challenged upon entering the building, cameras can help identify patterns and suspicious people.

6. NO PASSWORDS - Make it company policy that the tech department will never call you or email you asking for your username or password. If somebody does call and ask for a password or username red flags will go up every where.

7. LOG OFF - Social Engineering attacks get the hacker into the building and they will usually find many workstations where the user hasn't logged off. Make it company policy that all users must log off their workstations every time they leave it. If the policy is not followed then the employee should be written up or docked pay. Don't make a hacker's job any easier than it already is.

8. Training - Information security training is a must for any size company. Information security is a layered approach that starts with the physical structure of the building down to how each work station is configured. The more layers your security plan has the harder it is for an information thief to accomplish his mission.




Sign up for the most popular wireless networking news letter on the internet. Simple and Secure http://www.wirelessninja.com




Preventing Online Fraud


Nowadays, there are a lot of scams aiming at users of the online banking facility. There are several services which offer protection from identity thieves such as LifeLock. However, many identity thieves don't want to simply steal your identity information. They don't want to just take advantage of the good credit history by stealing your checking account. Instead, they want to steal your money. Many banks have take precautions on these cyber criminals by offering various types of online protection services. As an end-user, you have the most responsibility to protect your financial information. You must not solely rely on the bank to protect your financial information. You must take the initiative to look out for fraudsters on the internet. There are two common types of online frauds including keylogging and phishing. Phishing involves installing malware onto the computer while keylogging uses software to capture the keystroke you type onto the keyboard. Both methods will steal the login credentials of the end-user.

Keylogger software, also known as Trojan software is designed to be automatically installed in the user's computer through a virus. Keylogging software is dangerous because the fraudster will know every single word you type into the fields of the online banking login form. With the keylogging software, they can steal all your personal information such as account number, user ID, password and etc. To avoid becoming the victim of keylogging software, you can install the antivirus software on your computer. The antivirus software can detect and inform you about the Trojan software that is operating in the background. Once you detect the antivirus software, you can delete it. There are both free and commercial versions of the keylogger software. The commercial version of the keylogger software is better because it is equipped with a full range of features. You should constantly update your security patch.

In phishing, the internet fraudsters will attempt to request for personal information through email. Usually, the email will state the intention on doing business. The email will look as if it is from an important organization. The email will have similar appearance as the organization's email. The email will ask you to click on a link that redirect you to the login form and update the personal information in the online banking account. Normally, the link will lead to a different website that looks exactly like the bank website. No matter what email you receives, be sure not to click on the link in the email. If you click on the link in the email and type in your login information, they will be able to track your identity information. They can use the login information to access your online banking account. You must pay attention to the URL of the link. Some financial institutions will use watermarks. If you don't see the watermark at the login page, it is advised that you don't login. If you receive a phishing email, you must report it to your financial institution.

If you are not sure whether the request is valid, you can manually type in the web address of the URL listed in the phishing email. To protect yourself from online fraud, you must change the password frequently. You should change the password to your banking account every 6 months. You should never reveal the ID or password to your online banking account. You should not reveal the login credentials to other people. It is important that you only sign up with a financial institution that provides two factor authentications. When accessing the online banking account via a wireless network, you must make sure it is secure.




About the Author: Billy Horner, is a professional writer for the financial industry. Permission to reprint this article is granted if the article is reproduced in its entirety, without modification, including all information. Please include a hyperlink to: Banco Trasatlantico which provides offshore banking and banking blog.




Preventing Online Fraud


Nowadays, there are a lot of scams aiming at users of the online banking facility. There are several services which offer protection from identity thieves such as LifeLock. However, many identity thieves don't want to simply steal your identity information. They don't want to just take advantage of the good credit history by stealing your checking account. Instead, they want to steal your money. Many banks have take precautions on these cyber criminals by offering various types of online protection services. As an end-user, you have the most responsibility to protect your financial information. You must not solely rely on the bank to protect your financial information. You must take the initiative to look out for fraudsters on the internet. There are two common types of online frauds including keylogging and phishing. Phishing involves installing malware onto the computer while keylogging uses software to capture the keystroke you type onto the keyboard. Both methods will steal the login credentials of the end-user.

Keylogger software, also known as Trojan software is designed to be automatically installed in the user's computer through a virus. Keylogging software is dangerous because the fraudster will know every single word you type into the fields of the online banking login form. With the keylogging software, they can steal all your personal information such as account number, user ID, password and etc. To avoid becoming the victim of keylogging software, you can install the antivirus software on your computer. The antivirus software can detect and inform you about the Trojan software that is operating in the background. Once you detect the antivirus software, you can delete it. There are both free and commercial versions of the keylogger software. The commercial version of the keylogger software is better because it is equipped with a full range of features. You should constantly update your security patch.

In phishing, the internet fraudsters will attempt to request for personal information through email. Usually, the email will state the intention on doing business. The email will look as if it is from an important organization. The email will have similar appearance as the organization's email. The email will ask you to click on a link that redirect you to the login form and update the personal information in the online banking account. Normally, the link will lead to a different website that looks exactly like the bank website. No matter what email you receives, be sure not to click on the link in the email. If you click on the link in the email and type in your login information, they will be able to track your identity information. They can use the login information to access your online banking account. You must pay attention to the URL of the link. Some financial institutions will use watermarks. If you don't see the watermark at the login page, it is advised that you don't login. If you receive a phishing email, you must report it to your financial institution.

If you are not sure whether the request is valid, you can manually type in the web address of the URL listed in the phishing email. To protect yourself from online fraud, you must change the password frequently. You should change the password to your banking account every 6 months. You should never reveal the ID or password to your online banking account. You should not reveal the login credentials to other people. It is important that you only sign up with a financial institution that provides two factor authentications. When accessing the online banking account via a wireless network, you must make sure it is secure.




About the Author: Billy Horner, is a professional writer for the financial industry. Permission to reprint this article is granted if the article is reproduced in its entirety, without modification, including all information. Please include a hyperlink to: Banco Trasatlantico which provides offshore banking and banking blog.




 
Support : Creating Website | Johny Template | Mas Template
Copyright © 2011. Information Computer and Technology - All Rights Reserved
Template Modify by Creating Website
Proudly powered by Blogger