Proactive IT security
 

Beveiligingscentrum

Bedreigingsniveau

Threat level: low

» Over dit bedreigingsniveau

Laatste artikelen - Security terms

An approach to an organization's risk factors (part 3)

In this third and final part of our article series about risk factors, we will examine Human attack factors and Physical factors.

» Meer info

An approach to an organization's risk factors (part 2)

The previous article discussed different procedures and systems that could be invoked in order to mitigate risk. In subsequent parts we will examine areas at risk, starting with Electronic factors.

» Meer info

An approach to an organization's risk factors (part 1)

The aim of this type of initial risk analysis is to identify potentially vulnerable points that may be exploited if they are not sufficiently secured.

» Meer info

Denial of Service attacks against secure web sites

The special feature that THC-SSL-DOS offers, is that a DoS attack against a secure web server can be performed from one computer or just a few computers.

» Meer info

Secure tokens turn insecure

Even organizations, which presumably are more security conscious than most, have vulnerabilities that may be exploited by an attacker who has sufficient resources and determination at her disposal.

» Meer info

No access to your data unless...

Blocked access to important information - particularly if adequate backup routines are not in place - may be disastrous for the person who becomes the victim of ransomware.

» Meer info

Spam botnet Rustock beheaded

Bots and botnets comprise one of the biggest threats to the Internet and its users. However, recent news report of a success story: beheading the spam botnet Rustock.

» Meer info

Shamelessly exploiting disasters

In previous security articles, we discussed the fact that cybercriminals use big events to spread malware. Not surprisingly - nevertheless disgusting - the recent events in Japan have inspired shameless exploitations by cybercriminals.

» Meer info

Malicous cold calls with high success probability

According to a posting 15 November on the blog belonging to the UK based organization Get Safe Online, one in four UK web users have been targeted by so-called cold calls.

» Meer info

Ways to use botnets

This article will not go in depth with regard to how the different botnets function technically. We shall rather examine some of the ways botnets may be used, study one successful method used for fighting this threat, and finally discuss the idea of botnets used for benign purposes.

» Meer info

A cunning new phishing technique - Tabnabbing

Over the years new ingenious words for security issues have come up. We have seen the neologisms pharming, vishing, clickjacking and slurping, just to mention some. This week a new one was born - tabnabbing. Which turns out to be more scary than most.

» Meer info

Effective social engineering scares

Malicious programs do increasingly rely on social engineering techniques to be able to propagate and successfully execute. Gone are the days when a tempting file name in an email sufficed. In this security article we shall examine variants of one of the more successful social engineering schemes.

» Meer info

Malicious identity production

Identity theft is a term, which has become familiar during the latest years. More exotic - until recently - has been identity production with malicious intent. A new version of Koobface does exactly that - automatically.

» Meer info

You're bad. No, I'm not!

The vendors of security software have the following simple task: Detect and remove as much malicious software as possible without erroneously defining benign software as malware. Unfortunately, this is not as simple as it seems.

» Meer info

A security issue? Oops - not!

Security organizations are in constant battle with malware authors, trying to protect end users from being infected by "bad stuff". As we shall see in this week's security article, some undesirable side effects unfortunately occur from time to time.

» Meer info

DOS events

The title of this week's security information does not refer to the celebration of an anniversary for the legacy PC operating system DOS. It is another of those neologisms that pop up continuously.

» Meer info

Slurping - a security issue often overlooked

Slurping is not only a method for quenching your thrist. It is also used as a term for a particular kind of security issue, that is often overlooked.

» Meer info

Happy (?) anniversary, Malware!

Compared to the relatively innocent scheme of malware in the early age, it has changed into an activity for "geeks" that caused major problems for individuals and organizations, and further into an industry dominated by criminals.

» Meer info

SPIM – a new threat to the Internet community?

Several users of the instant message service MSN messenger have recently been attacked by so-called ”SPIM” This has led some to believe that they have been attacked by an MSN-worm or a virus, which mission is to damage their computer.

» Meer info

Smishing - another ingenious play with the phishing term

Most of those working with security, and probably greater parts of the general public are aware of the term phishing at what it means. You ...

» Meer info

Spear phishing - targeted attacks against an organization

The usual phishing attempts are targeting random individuals, while the specialized spear phishing attacks are aimed against a particular organization.

» Meer info

Pump and Dump Spam

Don’t you hate spam...? Spammers get smarter every time and try new ways to get your attention and to avoid spam filters.

» Meer info

"VISHING" - new technology gives old criminal activities new life

"Vishing" is combined of the two terms "Voice over IP" and "Phishing", and is exactly that: Using the increasing use of Voice over IP to trick someone revealing personal information, with the intent to commit fraud.

» Meer info

Image spam – an exploding threat

The spam problem is growing faster than ever and the spammers are getting increasingly sophisticated. The number of spam has grown with more than 40 % since April and the latest form of spam is so-called image spam.

» Meer info

Look out for ransomware

Hackers that encrypt your files and demand money in order decrypt them are an increasing threat in the world of IT criminality.

» Meer info

Zombies and targeted attacks – a challenge to overcome?

One of the most prevalent and fastest increasing threats against IT security is the rise of zombie computers and botnets. Not only do they spread extremely fast, they are also able to do immense damage that can easily lead to large costs.

» Meer info

Constant Reboot: Hardware, Virus or… Rootkit?

Security Information Week 12, 2006

» Meer info

Wat is eigenlijk phishing?

De meeste organisaties beschouwen phishing als de meest toenemende bedreigingen van computerbeveiliging van 2006. De Gartner Group schat het verlies van de US banken en creditcard instanties dat direct te wijten was aan phishing, in 2003 op 1.2 miljard dollar.

» Meer info

Look out for Greyware!

During the last few months the number of so called Greyware has increased massively. Greyware reefers to antispyware utilitites that force themselves into the users' machines by scaring the users and by auto-installing programs.

» Meer info

Keyloggers – an invisible danger

The threath of keyloggers is a rapidly growing danger in the world of IT security.

» Meer info

The threat of Phishing and Pharming

Security Information Week 15, 2005

» Meer info

"You ain't seen nothing yet" - or - The Warhol worm and worse

It is hardly controversial to claim that the end of February and beginning of March 2004 was the worst period ever regarding the sheer number of new mailicious programs threatening the Internet community. New variants of Bagle, MyDoom and Netsky were spread daily - sometimes even more than once per day. 

» Meer info

A new e-mail hoax

Security Information  Week 39, 1999 Recently a new e-mail hoax has been spreading quite aggressively. Subject of the e-mail is !!!WARNING -- DESPITE-virus!!! -FMBW. The body of the ...

» Meer info

Norman's acquittal in Norway's Supreme Court

In April 1999 Norman was acquitted in the Supreme Court of Norway. This ruling has been noticed and commented upon by news agencies and magazines all over the world.

» Meer info

How to prevent crackers to break into your system

Security Information  Week 6, 1999All the time reports are published about famous and not-so-famous organizations which have had their networks and computers compromized by crackers. ...

» Meer info

What a hacker may know about your systems

Security Information  Week 10, 1999A person who is interested in breaking in to an organization's computers wants to know as much about these computers as ...

» Meer info

The so-called HTML viruses

Security Information  Week 1, 1999 The computer magazines as well as other papers have recently published articles about a "new" kind of viruses - the so-called ...

» Meer info

Latest blog entries

The insecurity paradox

2011-08-29
The formula here attempts to explain a paradox in security analysis: If it is true that security is only as strong as its weakest link, why are not those who use insecur...
meer informatie >>

The 10 most insecure passcodes

2011-06-16
Earlier this week I read an extremely interesting and impressing blog item by Daniel Amitay: Most Common iPhone Passcodes. Amitay has analyzed more than 200 000 passcodes used in an app with a similar...
meer informatie >>

Purchasing and downloading outdated software

2011-05-23
Last week in the "JoshMeister On Security" blog, the topic was about Apple's Mac App Store, and the fact that software available from this store may not be the latest version. The blog's aut...
meer informatie >>