Proaktiv IT-sikkerhet
 

Sikkerhetssenter

Nyeste artikler - Social engineering

An approach to an organization's risk factors (part 3)

In this third and final part of our article series about risk factors, we will examine Human attack factors and Physical factors.

» Mer Informasjon

An approach to an organization's risk factors (part 2)

The previous article discussed different procedures and systems that could be invoked in order to mitigate risk. In subsequent parts we will examine areas at risk, starting with Electronic factors.

» Mer Informasjon

An approach to an organization's risk factors (part 1)

The aim of this type of initial risk analysis is to identify potentially vulnerable points that may be exploited if they are not sufficiently secured.

» Mer Informasjon

Malicious images (codes)

The ease involved in creating QR codes that links to web pages implies that this will be a popular way to facilitate the propagation of malware for mobile devices.

» Mer Informasjon

The importance of typing correctly

Computers do what they are told. This may result in consequences that are funny as well as dangerous.

» Mer Informasjon

May we use your social network account, please

You should exercise extreme caution if you are allowing access to your social network account from any application.

» Mer Informasjon

Targeted attacks: More "Bang for the Buck"

Since the cybercriminals seem to shift from randomly directed mass attacks to more focused attacks, the total volume of spam will decrease.

» Mer Informasjon

Plug mouse into the computer - be compromised

It is almost impossible to protect completely against a targeted cyberattack against an organization.

» Mer Informasjon

Secure tokens turn insecure

Even organizations, which presumably are more security conscious than most, have vulnerabilities that may be exploited by an attacker who has sufficient resources and determination at her disposal.

» Mer Informasjon

The old dogs are still in learning mode

The web site (usually an infected site) that displays the message checks the browser visiting the site, and displays a warning message similar to the browser's real warning.

» Mer Informasjon

Dangerous images

Recent weeks have shown that images are used as a malware spreading technique; particularly images that appear after performing a Google image search.

» Mer Informasjon

The RTLO unicode hole - sequence manipulation as an attack vector

Do not rely on any file attachment or file on any device to be safe based on its file name.

» Mer Informasjon

Cybercriminals focus on new targets

Users of the operating system Mac OS X have so far been quite safe from malware infections compared to those who have chosen Windows as the operating system platform.

» Mer Informasjon

No access to your data unless...

Blocked access to important information - particularly if adequate backup routines are not in place - may be disastrous for the person who becomes the victim of ransomware.

» Mer Informasjon

Shamelessly exploiting disasters

In previous security articles, we discussed the fact that cybercriminals use big events to spread malware. Not surprisingly - nevertheless disgusting - the recent events in Japan have inspired shameless exploitations by cybercriminals.

» Mer Informasjon

Malware targeting the finance sector's customers

In our security article last week, we discussed cybercriminals who targeted financial institutions in an indirect way. However, the major bulk of malware aimed at the finance sector puts the finance sector's customers at peril. One obvious reason is that the average end user's system presumably is less secure than the systems used by the financial sector.

» Mer Informasjon

Indirect targeting of financial institutions

During the last weekend, The Wall Street Journal published information that intruders had penetrated computer systems controlled by the company that runs the U.S. Nasdaq Stock Market. Nasdaq handles around 19% if all stock trading in the U.S. The trading system itself should not have been compromised.

» Mer Informasjon

Personalized web advertisements - good or bad?

Advertisements (ads) on the web have become part of a multi-billion industry. These days it is almost impossible to read news on the web without being overwhelmed by a plethora of ads for everything from cars to diapers. However, it is presumably not optimal to display the car ads to children. Nor are most teenagers particularly interested in diapers. 

» Mer Informasjon

PlayStation 3 security fully compromised

Sony's PlayStation 3 (PS3) has been viewed as one of the most secure gaming devices. Applications and games from other sources than Sony could not be installed and run on PS3, and a firmware update early in 2010 disallowed using other operating systems than the one set up by Sony. All this is now changed.

» Mer Informasjon

Holiday - relax, have fun, meet family and friends... and be vigilant

Major events, happenings and in general all kind of things that create much notice, also leave in their wake a stream of malicious software.

» Mer Informasjon

Malicous cold calls with high success probability

According to a posting 15 November on the blog belonging to the UK based organization Get Safe Online, one in four UK web users have been targeted by so-called cold calls.

» Mer Informasjon

Communication consolidation or security nightmare

In recent months there have been lots of rumors about the upcoming email system closely integrated with Facebook. More detaileds about this have recently been disclosed by Facebook, and we will examine some aspects of the new offerings.

» Mer Informasjon

Privacy and security in Social networks - part III

This is the third article in a series about privacy and security in social networks.

» Mer Informasjon

Privacy and security in Social networks - part II

This is the second article in a series about privacy and security in social networks.

» Mer Informasjon

Privacy and security in Social networks - part I

This is the first article in a series, which will focus on security and privacy issues involved in participating in social networks.

» Mer Informasjon

Man-in-the-middle goes Mobile

The term Man-in-the-middle in a security context refers to an attack where someone/-thing is inserted between two endpoints and intercepts the communication between those. The intent is usually to obtain information and use this for illegitimate purposes. Recently the term Man-in-the-mobile, abbreviated as Mitmo, emerged.

» Mer Informasjon

Ways to use botnets

This article will not go in depth with regard to how the different botnets function technically. We shall rather examine some of the ways botnets may be used, study one successful method used for fighting this threat, and finally discuss the idea of botnets used for benign purposes.

» Mer Informasjon

Old dogs learn new tricks

Fake antimalware software has become an increasing problem for end users and corporations. The creators of these rogue applications are able to earn easy money and are constantly searching for new ways to exploit their victims. A new technique has recently been seen. We shall look at this in more detail in this security article, and attempt to point to some general considerations regarding this type of software and malware in general.

» Mer Informasjon

Self-protection from malware - part II

In the previous article in this series about self-protection, we discussed examples of attempts to trick you to expose yourself for malicious software. Infected web sites are currently the most used technique for propagation of malware. By increasing your own awareness of the techniques the cyber criminals use, you can avoid this exposure.

» Mer Informasjon

Self-protection from malware - part I

There are several levels where you can set up protection mechanisms in order to minimize the risk of falling victim to malware. Different protection mechanisms are needed depending on which danger situation we are discussing.

» Mer Informasjon

Malware infections by telephone

An interesting news item has appeared in several UK-based media lately. Several end users have received phone calls from someone who present themselves as security personnel. The caller informs that the computer is infected by malware and offers to help. Varying social engineering techniques are used to persuade the recipient to allow the use of remote access software in order to "fix the problem".

» Mer Informasjon

Første halvår 2010 - oversikt over sikkerhetshendelser

Vi vil i denne rapporten om sikkerhetshendelser i første halvår 2010, gå gjennom en del forskjellige saker og trender. Vi vil fokusere på dem Norman ser som mest betydningsfulle i de siste seks måneder.

» Mer Informasjon

A cunning new phishing technique - Tabnabbing

Over the years new ingenious words for security issues have come up. We have seen the neologisms pharming, vishing, clickjacking and slurping, just to mention some. This week a new one was born - tabnabbing. Which turns out to be more scary than most.

» Mer Informasjon

Effective social engineering scares

Malicious programs do increasingly rely on social engineering techniques to be able to propagate and successfully execute. Gone are the days when a tempting file name in an email sufficed. In this security article we shall examine variants of one of the more successful social engineering schemes.

» Mer Informasjon

Oppsummering av 2009 - spådommer for det kommende året

Desember er måneden for å se tilbake på året som nærmer seg slutt, og vi vil forsøke å oppsummere situasjonen sett fra et sikkerhetsselskaps perspektiv. Den mest betydningsfulle observasjonen hva gjelder aktivitetene til ondsinnet programvare (malware), er at forskjellige typer sosiale nettverk ble et hovedmål for forfatterne av ondsinnet programvare.

» Mer Informasjon

Holidays - preferred season for children and ...criminals

Major events, happenings and in general all kind of things that create much notice, also leave in their wake a stream of malicious software.

» Mer Informasjon

Malicious identity production

Identity theft is a term, which has become familiar during the latest years. More exotic - until recently - has been identity production with malicious intent. A new version of Koobface does exactly that - automatically.

» Mer Informasjon

Lots of free email accounts compromised

Earlier this month multiple tens of thousand passwords to free email accounts from Microsoft (Hotmail), Google (GMail) and Yahoo were compromised.

» Mer Informasjon

The first part of 2009 as seen through secure glasses

The time has arrived when it is useful to look back on the first half of this year, and attempt to sum up the situation seen from Norman as a security company's point of view.

» Mer Informasjon

Easy URLs - a good or bad system

The short URL functionality obviously has its merits. However, there are shortcomings and security issues that make the system in itself less secure than desired.

» Mer Informasjon

Do birds speak the truth?

The social network Twitter has become extremely popular in quite a short time. This time we will discuss this technological phenomenon from a sociological perspective, and use the most talked-about incident these days as a kind of case study - the swine flu.

» Mer Informasjon

GhostNet - a real espionage network

This week started with significant media attention about a report, which showed that several computers owned by governments and international organizations were compromized. This includes several embassies world-wide and a NATO computer.

» Mer Informasjon

Social engineering with a virtual twist

Social engineering in several forms has been discussed in numerous of our security articles. This time, we shall discuss it from a different angle - the traditional one, with a quite clever new twist.

» Mer Informasjon

"We told you so" - hindsight is usually correct

The need to apply security patches to operating systems and applications has been discussed several times in our security articles. Recent events show that this is a caution that cannot be repeated too often.

» Mer Informasjon

Program downloads from the Internet - a risky activity

The Internet offers a cornucopia of applications, movies, pictures, text - everything digital that can be imagined (and some not!). Navigating this is difficult and can even be hazardous in several ways.

» Mer Informasjon

Internet gaming - new opportunities for the (shady) visionary

The use of money involved in online gaming has traditionally been only as an entrance fee to buy the game itself (if it is not free). This no longer holds true.

» Mer Informasjon

Clickjacking - a new danger or an innovational new name?

A few weeks ago a new name started circulating in security writings - "clickjacking". Security organizations as well as web-based news agencies reported this as a  major, new threat.

» Mer Informasjon

Slurping – et sikkerhetsproblem som ofte blir oversett

Slurping er ikke bare en metode for å slukke tørsten. Det er også brukt som en betegnelse for en type sikkerhetsproblemer, som ofte blir oversett.

» Mer Informasjon

Usikre webservere – et økende sikkerhetsproblem

En ny retning innen skadevarespredning har fått økende popularitet blant de onde jentene: Ondsinnede nettsteder

» Mer Informasjon

SPIM – a new threat to the Internet community?

Several users of the instant message service MSN messenger have recently been attacked by so-called ”SPIM” This has led some to believe that they have been attacked by an MSN-worm or a virus, which mission is to damage their computer.

» Mer Informasjon

Smishing – nok en oppfinnsom vri på phiskebegrepet

De fleste som jobber med sikkerhet, og mest sannsynlig større deler av allmennheten, har hørt om begrepet phisking (phishing) og betydningen av det. Du finner ...

» Mer Informasjon

Spydphiske (Spear phishing) - målrettet angrep mot en organisasjon

De vanlige phiskeangrepene er rettet mot tilfeldige individer, mens de spesialiserte spydphiskeangrepene sikter på en bestemt organisasjon.

» Mer Informasjon

Finansinstitusjoner mer eksponert for hackerangrep og svindelforsøk

Større finansorganisasjoner blir i økende grad utsatt for hackerangrep, ondsinnet kode og svindelforsøk. I følge en fersk undersøkelse har antall organisasjoner som har blitt usatt for angrep økt med 78 % i løpet av det siste året.

» Mer Informasjon

”VISHING” – ny teknologi gir nytt liv til gammel kriminalitet

“Vishing" er en kombinasjon av de to begrepene "Voice over IP" and "Phishing", og er akkurat det: Utnyttelse av den økende bruken av IP-telefon for å lure noen til å avsløre personlig informasjon, med den hensikt å begå svindel.

» Mer Informasjon

The usage of child porn: a sad but true story…

Where in the past malware file names would have ‘interesting’ names such as “Anna Kournikova" or “Britney Spears Naked", many things happened but seeing a picture of the two aforementioned idols was not one of them.

» Mer Informasjon

Hva er egentlig phisking (phishing)?

De fleste sikkerhetsorganisasjoner regner phisking som en av de aller største truslene mot IT-sikkerheten i 2006. Gartnergruppen har regnet ut at de direkte kostnadene ved phiskingangrep på amerikanske banker og kredittkortselskaper var på hele 1,2 milliarder dollar i 2003.

» Mer Informasjon

Phishere endrer målgruppe

Phishere, også kalt identitetstyver, er tradisjonelt kjent for å angripe større finansielle institusjoner, men den senere tid har de begynt å endre metoder og målgrupper. I dag slår phisherne til mot alle former for organisasjoner.

» Mer Informasjon

The threat of Phishing and Pharming

Security Information Week 15, 2005

» Mer Informasjon

"You ain't seen nothing yet" - or - The Warhol worm and worse

It is hardly controversial to claim that the end of February and beginning of March 2004 was the worst period ever regarding the sheer number of new mailicious programs threatening the Internet community. New variants of Bagle, MyDoom and Netsky were spread daily - sometimes even more than once per day. 

» Mer Informasjon

An analysis of Sobig.F and its ability to harm Internet users around the world

In September 2003 Internet users and organizations experienced the most severe attack on the Internet infrastructure since the "Morris worm" in November 1988.  The outbreak of W32/Sobig.F caused major problems because of the huge amount of emails flooding the infrastructure.

» Mer Informasjon

A new e-mail hoax

Security Information  Week 39, 1999 Recently a new e-mail hoax has been spreading quite aggressively. Subject of the e-mail is !!!WARNING -- DESPITE-virus!!! -FMBW. The body of the ...

» Mer Informasjon

The major security risk: Users

Security Information  Week 9, 1999The IT department in an organization often uses vast resources to be updated on security risks associated with hardware and software ...

» Mer Informasjon

Deceitful patch to Internet Explorer

Security Information  Week 7, 1999Since January this year several users have received an e-mail apparently from Microsoft. The mail informs the receipient that the attachment ...

» Mer Informasjon

Where to get security information

Security Information  Week 12, 1999 On the Internet there are several sites which offer very good security information.  The different sites are of two kinds: Security sites ...

» Mer Informasjon

Quality control of information on the Internet

Security Information  Week 3, 2000The Internet is a cornucopia of information of every kind. One may find web pages dedicated to any thinkable of unthinkable ...

» Mer Informasjon

Nyeste blogg-innlegg [EN]

The insecurity paradox

2011-08-29
The formula here attempts to explain a paradox in security analysis: If it is true that security is only as strong as its weakest link, why are not those who use insecur...
mer >>

The 10 most insecure passcodes

2011-06-16
Earlier this week I read an extremely interesting and impressing blog item by Daniel Amitay: Most Common iPhone Passcodes. Amitay has analyzed more than 200 000 passcodes used in an app with a similar...
mer >>

Purchasing and downloading outdated software

2011-05-23
Last week in the "JoshMeister On Security" blog, the topic was about Apple's Mac App Store, and the fact that software available from this store may not be the latest version. The blog's aut...
mer >>