free adobe palace script font download

Adobe Photoshop CS5 cheap free safe download of adobe acrobat reader download crack for adobe authorware 7 cheapest download stand alone adobe flash adobe elements download

adobe cs2 download free crack key generator

Adobe InCopy CS5 for Mac cheapest adobe flashplayer free download adobe version cue update download windows cheapest adobe illustrator 10 free download adobe photoshop 70 download

download adobe photoshop cs2

Adobe Creative Suite 4 cheap adobe photoshop cs3 iso file download free adobe acrabat reader download buy cheap adobe acrobat raeder v7 download free download adobe acrobat professional 6

adobe photoshop font download

Adobe cs5 Design Premium cheap adobe flash reader download free ware download adobe photo shop buy cheap download adobe imageready free adobe dream weaver 8 download

free download adobe photoshop cs2

discount Adobe Flash adobe 8 reader download adobe version 7 download buy cheap manually download of adobe flash player 9 how to download adobe premiere pro free

adobe illustrator download free

cheap PDF to-EXE Converter adobe photoshop font download download adobe indesign cs3 buy cheap adobe reader download full download adobe acrobat megaupload

adobe illustrator cs3 crack download

Autodesk Simulation 2012 buy cheap adobe 5 free download adobe purchase products maintenance download contacting typeface cheapest adobe reader free download for windows vista download adobe premiere pro

adobe acrobat 6 full download

AutoCAD Electrical 2012 discount adobe reader vista download free download adobe photoshop cs3 extended me trial buy cheap download adobe professional download adobe svg viewer

download adobe gamma

cheapest Autodesk AutoCAD download adobe download manager free acrobat adobe download cheapest download adobe reader fur windows 2000 free download adobe flash player

crack adobe photoshop cs3 download

buy cheap AutoCAD 2010 adobe pagemaker download full free free adobe image ready download discount adobe illustrator cs2 trialware download adobe flash player 8 free download

free download adobe premiere pro cs3

AutoCAD 2012 buy cheap adobe image ready download download adobe photoshop elements discount download free adobe standard sf86 sf 86 sf 86 download adobe pdf

adobe download photo shared shop

cheapest AutoCAD for MAC adobe premmiere free download download adobe shockwave player discount free adobe acrabat reader download adobe flash player and download

iran download adobe photoshop

cheap adobe acrobat x free download of adobe reader 8 download and edit adobe files buy cheap adobe fash player download adobe after effects full download

adobe flash lite download

adobe acrobat x suite discount buy adobe photoshop download free download adobe acrobat reader professional 6 cracked discount adobe flash player 9 active x download free adobe ilrator download

adobe premiere tryout download

buy cheap adobe creative suite 4 download adobe photoshop 50 download adobe photoshop full cheap adobe photoshop download discount software download adobe 5

download adobe gamma download

discount adobe creative suite 5 how to download adobe on psp free ware download adobe photo shop cheapest adobe flash player version 9 free download free download adobe lightroom

cnet download adobe

adobe cs5 cheap adobe player download center free download adobe ilustrator discount best adobe acrobat download adobe indesign 2 for windows download

adobe acrobat download for mac

Adobe cs5 Design Premium cheapest adobe audition full download adobe photoshop element download buy cheap adobe acrobat reader 5 0 free download adobe download 8

adobe player 8 download

cheapest Adobe CS5 for mac adobe gamma download adobe acrobe free download cheap free download adobe pagemaker can we download adobe flash player file

download adobe flash player stand alone

buy cheap Adobe cs5 Production Premium adobe internet explorer download security adobe cs3 patch download discount adobe premier download crack free download adobe flash

download and install adobe flash onto my computer

cheap Adobe Dreamweaver CS5 download adobe photoshop 70 adobe pdf reader free download discount where can i download adobe flash player 9 download adobe creative suite 2 premium

how to download adobe flash files

Adobe eLearning Suite discount adobe premmiere free download free download adobe photoshop cs2 cheap pc wont let adobe plug in download download adobe illustrator cs

adobe flashplayer 9 download

Adobe eLearning Suite 2 buy cheap direct download links adobe download adobe illustrator cs cheap adobe illustrator 8 download adobe shockwave player download

download adobe media encoder

Adobe Flash Catalyst CS5 cheapest download adobe premiere effects adobe photoshop elements download discount adobe lightroom update download mac osx adobe reader kostenloser download

adobe after effects cs2 download

Adobe Illustrator CS5 cheapest adobe player download center adobe download free premiere discount adobe illustrator 8 download adobe flash direct download

free download for adobe streamline 4

cheapest Adobe Indesign CS5 free download adobe after effects for mac download adobe reader cd cheapest adobe acrobat reader free download download adobe ultra

adobe creative suite 3 download

cheap Adobe Photoshop CS5 adobe audition download free adobe acrobat reader 6 download cheapest adobe acrobat writer download adobe 10 download

macintosh download adobe acrobat reader

Adobe Photoshop Lightroom 3 discount adobe audition 3 free download adobe macromedia flash player 7 download discount free adobe photoshop full download adobe photoshop elements 5 free download

Archive for the 'Security' Category



The best free security tools for Windows

Many times people ask me what are the essential tools to install in a new computer to improve the security. I usually install everything I can think of, but sometimes I might forget something, so this list of best free security tools might prove very valuable. Sergio Hernando started it and I’ll try to improve it a bit with some comments about each program.

These applications are free (some are open source, others are simply gratis) and will improve greatly the security of your computer. Anyways, they are not infallible so you must take basic measures to protect your computer besides using these tools.

I usually prefer using open-source tools, but sometimes there is no useful open-source equivalent in some category, so a closed-source option must be used. Anyway, I have always found a freeware option which fulfilled my needs, so you don’t need to pay anything to keep your computer secure.

Continue reading ‘The best free security tools for Windows’

Are warning dialog boxes really useful?

In a really interesting post, Bruce Schneier tells that “lots of warning dialog boxes don’t provide security”. The cause is users don’t pause to read the content of the dialog box and act consequently. They only want the job to be done, so they click the default button or, if this doesn’t work, they click whatever button until it finally works (or at least, the dialog disappear).

This happens with every application. The most usual case is security warnings from bad SSL certificates.

Continue reading ‘Are warning dialog boxes really useful?’

Phishing (I): what is it?

Although phishing has been in the rising for some time, there are still lots of people who don’t know what it is and how it works. This is used by phishers to steal data from innocent users for their own profit.

So, first of all, what is phishing? It’s a technique used to steal private data from the user by tricking him to give it away. This private data is usually passwords for sensitive sites, credit-card numbers or PIN codes for bank accounts.

How do phishers trick the user? The most common way to ask for the data is through email. Phishers send emails which look legitimate, usually mimicking the look of real ones but pointing to their own servers instead of legitimate ones.

Most phishing tells the users that account might have been compromised and they need to authenticate again to confirm the account. They give a link which looks like a legitimate one, but points to another site controlled by the phisher. This site also looks like the original one, as they steal images and layout from the legitimate one and upload them to another server.

So, when the user enters the username and the password in this site, the data gets stored in a database controlled by the attacker, who will be able to retrieve it later and use the data in his own profit.

This is an example of a phishing email I received:

Phishing

The link seems to point to cards.fleet.com but, in reality, it goes to 4.60.21.232:34,a link which doesn’t work by now but which was under the control of the phisher.

Lately, the sophistication of this kind of e-mail has increased, every time looking more credible and using new techniques to trick the user, like emails looking like a question from a possible buyer from eBay which points to another site or even targeting e-mail to users depending on the bank they use.

In the next post, we will see how to protect against phishing.

Defeat hardware keylogger with SuperGlue

We explained that a usual way to steal password is with keyboard loggers. This happened once at Sumitomo Bank, where someone installed a hardware keylogger to a computer and got some passwords which allowed him to transfer money to an account on his own.

The bank has opted for a low-tech solution to this problem. To avoid someone installing hardware keyloggers they have glued the connectors to the back of the PC with SuperGlue, so it’s not possible to unplug the keyboard and insert the keylogger.

It’s a known problem that to secure a computer where the user has physical access to it is quite difficult, so I would have opted instead for using dumb terminals instead of PCs, so the security only has to be implemented in one place, making it easier to control.

This is not always possible, as some systems can’t be configured to work with dumb terminals or might not be convenient for the business. In this case, the solution is to keep the PC case in a “secure” lock where it cannot be accessed by the users without permission.

From | Threat Chaos.

E-mail security: avoiding spam

Following the series of articles about spam I last wrote about detection of spam by analyzing the content. This usually works great but it is a big waste of resources for the user receiving the spam, as he has to download the mail (mostly free if you are on a residential line, but might be expensive if you are on the road) and analyze it (spending computer time).

It would be better if the server was able to avoid these messages being sent. Although some mail servers analyze the content of the message before delivering there are some other techniques which have been proposed to work against spam. Some of them are even standards, but haven’t usually been widely deployed. Let’s have a look at some advantages and disadvantages of them.

Continue reading ‘E-mail security: avoiding spam’

Scan for viruses with Knoppix

One of my favourite tricks when checking some Windows computer which is screwed up (and, usually, they are really screwed up, even not booting) is scan for viruses using Knoppix, a Linux distribution which can boot from a CD.

Once booted, it recognises your Windows partitions and allows downloading F-Prot, a free virus scanner, which checks your hard drive for virus. If you find any, you need to delete the files containing them.

It is also a good idea to download updates for Windows at this time, as it is safer to browse the web from the Knoppix CD.

You can download the Knoppix CD from the official site. It’s a good idea to have it at hand, just in case you need it urgently.

From | O’Reilly

E-mail security: detecting spam (V)

We saw some techniques spammers use to try to evade Bayesian spam filters and how the use of this techniques is making spam a bit less effective and, sometimes, even more easy to detect.

But spammers know this and they wont’ allow their business to go down so easily. So what is the future of filter evasion? I have been thinking about some techniques which would probably evade most of current filters and perhaps it’s time to prepare against them before it’s too late.

The idea for this list came from a post by Vivek Jishtu where he explains how a spammer is using the Yahoo greeting cards to send his messages without being detected by filters. This service allows anyone to send a card to someone, who will be notified by e-mail and will receive a link to go to a site to view the card. In this card, the spammer can include arbitrary content so he can put his spam message there and as this will not pass through any filter it won’t be detected. So, if the user receiving the card visits the link he will see this (translated from Chinese by Google Translator):




Continue reading ‘E-mail security: detecting spam (V)’

E-mail security: detecting spam (IV)

Knowing how Bayesian filtering works we will try to find some programs which use it and see which is the most useful one for us. I’ll give a list and you should choose the most appropiate for you.

We can split the filtering programs depending on where they work: on the server or on the client. The programs working on the server have some advantages, as they look at more mail messages (they see mail from all users in a system) it is easier and faster to train them. Furthermore, there is only one place to administer it, making the administrator task easier. At the same time, the users don’t need to receive the spam so they don’t spend additional bandwith and time. On the other hand, they are not so customizable by the user, which might prefer his own techniques to detect spam and false postivesand, if the user doesn’t have access to the server he will not be able to install it.

One of the most known server-side filtering software is SpamAssassin, which uses different checks to test for spam, one of them being Bayesian filtering. Each one of this tests adds or substracts a score from the mail and at the end of the runs this score will determine if the mail is spam or not. Amongst other these test include mail-header tests, text-content rules, white-lists and black-lists and collaborative databases, making this program one of the most accurate. This can also be used as client-side filtering, although the installation will not be as easy as others.
Continue reading ‘E-mail security: detecting spam (IV)’

E-mail security: detecting spam (III)

Before talking about other methods for detecting spam, let’s have a closer look to Bayesian filters and programs using this technique to classify mail. This will be a technical post, so it might not interest to all of you. In next posts we’ll see some software which uses these filters.

I’m not a mathematician, so I might make a few errors when trying to explain the theory behind the filters. Please forgive me. The article in Wikipedia explains it better than I can do it.

The main formula where Bayesian filtering stands is:

Bayes1

which says that the probability of an e-mail being spam given the words contained in it is equal to the probability of these words appearing in a spam message, multiplied by the probability of a message being spam divided by the probability of the words appearing in any message.

Wow, it looks quite complicated. One of the most known papers about this kind of filtering is A plan for spam from Paul Graham. We’ll see some code from it.

Continue reading ‘E-mail security: detecting spam (III)’

E-mail security: detecting spam (II)

As spam filters get more advanced, less spam is allowed to enter into user’s inbox so the business model of spammers gets hurt. Instead of thinking that people don’t really like to receive spam and they would prefer less intrusive ways to get publicity, they try to workaround these filters in, sometimes, really clever ways. So, spam filters have to be continually modified and adapted to not fall into these new tricks.

As Bayesian filtering is the most common used technique, this is what spammers try to escape more frequently. We told that Bayesian works by calculating the probability that a word is from spam or from legitimate mail, so what spammers do is modify the messages so they get more probability of being legitimate mail.

One of the ways to do this is insert random but common words in spam, so the spam words contribute less to the score and the message goes under the filter. We can see an example of a real spam:

Spam1

The real content of the spam is contained at the bottom but at the beginning of the e-mail there are some lines with text which come from the novel The Master and Margarita and try to hide the fact that this is an spam.

Continue reading ‘E-mail security: detecting spam (II)’





Sponsored links


Search

Search in the Becoming paranoid Archive


Subscribe

Enter your email address:

Delivered by FeedBurner

Categories