Monday, October 31, 2011
Friday, August 19, 2011
Clear Cookies
Clear your IE cookies. Start>Settings>Control Panel>Internet Options>General. Under Temporary Internet Files, click on Delete Cookies. Then click Delete Files.
Reset System Restore
- Go to Start>Run, type SYSDM.CPL and press Enter.
- Select the System Restore tab.
- Check "Turn off System Restore on all drives" and click Apply.
- Now uncheck the same option and click OK.
Turn back on any malware prevention tools we might have had you switch off.
Microsoft Updates
It is very important that you get all of the critical updates for your Operating System and Internet Explorer. Keeping your OS and browser up to date will help make you less susceptible to attacks by malware. Using Internet Explorer, please go to Microsoft's Windows Update and download all of the critical updates to help prevent possible re-infection.
Please ensure that you have already patched your system against these recent critical exploits:
Enable Windows Auto Update:
- Go to Start>Run, type WUAUCPL.CPL and press Enter.
- Make sure "Keep my computer up to date" is checked.
- Under settings, choose "Automatically download the updates, and install them on the schedule that I specify".
- Click on "OK".
Feel free to remove these tools and their folders:
- FixWareout
- Autoruns/Autocmd
- CleanUp! (uninstall from Add/Remove Programs)
This is a good time to set up protection against further attacks. You might want to read Tony Klein's "How Did I Get Infected In The First Place?". At the minimum, you need an antivirus that is continually updated, a good firewall, a spyware blocker such as Spyware Blaster, and a real time spyware program such as Spyware Guard to prevent spyware intrusions. I also recommend IE-Spyad, which places over 4,000 websites and domains in the IE Restricted list, thus helping prevent attempts to re-infect your system. All of these have no-strings-attached free versions available. However, be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use but often have malware in them.
Two more articles you may want to read at your leisure are "KRC Anti-Spyware Tutorial" and "Making Internet Explorer Safer".
The following is a list of free software we recommend:
Antivirus
AV software should be updated at least once a week for optimum protection. Here are some free AV programs available for personal use. NOTE: Do not install more than one AV program because they will conflict with each other. Only pick one.
- Kaspersky Antivirus
- BitDefender
- Avira PersonalEdition Classic
- Avast!
- AVG
A good firewall is the first-line of defense for your computer and will monitor incoming and outgoing traffic. NOTE: Microsoft's Firewall does not monitor outgoing traffic. If you are unfamiliar with how a firewall works, you can read "Understanding and Using Firewalls". Here are some free firewalls available for personal use:
- Sygate Personal Firewall
- ZoneAlarm
- Tiny Personal Firewall
- Sunbelt Kerio Personal Firewall
- Outpost Firewall PRO
These programs actively watch your computer for possible malware-related changes and help prevent them. You can run more than one of these at a time.Passive Malware Prevention Tools
These programs configure your computer to prevent known malware-related changes. You can have more than one of these at a time and they take up minimal resources.
- SpywareBlaster - Install & update SpywareBlaster with the latest definitions. After you have updated, click the button - enable protection for all unprotected items. Check regularly for updates.
- IE-Spyad - Extract to your desktop and double-click install.bat. Install options #2 and #4. IE-Spyad places more than 4,000 dubious domains in the IE Restricted list, which impairs attempts to infect your system. It prevents any downloads from the sites although you will still be able to connect to them. You can read more about it on it's homepage.
- MVPS Hosts File - extract and double-click the mvps.bat file. This will replace your current HOSTS file with one that will restrict known ad sites form serving you unsolicited advertisements, preventing your computer from connecting to those sites.
- McAfee SiteAdvisor - helps to warn you before you interact with a dangerous Web site. Works with both IE and Firefox.
Using an alternative browser can help prevent malware from being installed without your knowledge, but may not work on all websites.Alternative Miscellaneous
Here are some alternatives that are worth looking into if you use their features:
- Trillian - an Instant Messenger client that speaks multiple IM services (AIM, Yahoo!, ICQ, MSN, etc.)
- Miranda-IM - another Instant Messenger client with multiple IM capabilities.
- Desktop Weather - A taskbar weather program that is free and resource light.
Wednesday, July 13, 2011
Athena's Firewall Browser
Athena is proud to bring you powerful free tool to search your rulebases based on address or service ranges — the way your change requests are actually made. Other tools and device consoles allow for pattern matching against rules, but only Athena's Firewall Browser allows you to:
- Search rules and objects by IP addresses, object name, service or port
- View security rulebases, network and service object definitions
- Search on Cisco, Check Point and Netscreen firewalls from one location
Monday, January 24, 2011
GUI-based firewall configuration with KMyFirewall
Tuesday, January 18, 2011
Ayuda anti-malware para féminas
Procedimiento para profesionales con 'bichos' digitales
Sugiero optar por la versión libre de los programas indicados
Desinstalar todo antivirus que no sea Avira Antivir (descargar el antivirus avira y eventualmente reiniciar el equipo)
Luego descargar, instalar como administrador, actualizar, configurar y ejecutarlos en el orden dado
http://www.avira.com/es/avira-free-antivirus (primera opción si hay demasiados errores virales)
[En Vista y Siete desactivar el Windows Defender]
http://piriform.com/ccleaner
http://piriform.com./defraggler
http://www.malwarebytes.org/mbam.php
http://www.javacoolsoftware.com/spywareblaster.html
http://www.javacoolsoftware.com/spywareguard.html
http://www.superantispyware.com/
--------------------------
Eventualmente usar la última aplicación de Windows® Malicious Software Removal Tool
This tool checks your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps to remove the infection if it is found. Microsoft will release an updated version of this tool on the second Tuesday of each month.
Microsoft® Windows® Malicious Software Removal Tool (KB890830) x64
Microsoft® Windows® Malicious Software Removal Tool (KB890830).
=============================
Si hay conocimientos de usuario avanzado en ordenadores: http://free.antivirus.com/hijackthis/ Para evitar reinfecciones por medio de dispositivos USB: http://net-studio.org/eng/usb-firewall.html http://research.pandasecurity.com/Panda-USB-and-AutoRun-Vaccine/ (o mejor usar el KMV.exe de un francés.. no tengo el vínculo, por el momento) (En algunos casos para vacunar los dispositivos USB primero desactivar temporalmente el guardián de Avira antivir)
======================
Para recuperar los datos "perdidos" del USB flash memory Ejecutar cmd y en la ventana del command line interface (black box) ir al dispositivo USB (X la letra asignada al dispositivo) C:\Documentts and Settings\Usuarioactual> X: [Enter] [el simbolo mayor que sale diferente en este blog.. pero no interesa].. escribir sólo el texto en negrita X:\> attrib -r -s -h *.* /s /d =======================
Un sistema de navegación segura con alertas:
http://www.siteadvisor.com/download/windows.html
NO usar Internet Explorer!
- Usar Firefox
con extensiones WOT, Noscript, Adblock plus, etc.
Firefox extensions
(leer las instrucciones)
insanely-cool-add-ons-to-rock-your-firefox
Para diagnosticar los valores SMART (si el disco rígido está en orden)
CrystalDiskInfo
o cualquier software que analice y monitoree el estado de los discos
----------------
Java offline installer
----------------
Security
Saturday, February 20, 2010
Internet banking security
Use virtuabox.org!!
Monday, January 4, 2010
Seguridad Mejorada en Windows 2003 Server
Monday, October 12, 2009
Digital Security and Privacy for Human Rights Defenders
1.1 Security and Insecurity
Confusion is enhanced by the abundance of software, hardware andelectronic devices designed to make the storage and exchange of information easier. An average computer today contains millions of lines of complex code and hundreds of components which could malfunction and damage the system at any time. Users have to immerse themselves in concepts and technology that seem to be far removed from the real world. The security of your computer falls first and foremost upon your shoulders and requires some comprehension of how its systems actually work.The race to reap profits from the Internet has resulted in the appearance of numerous financial services and agencies. You can now book a flight, buy a book, transfer money, play poker, do shopping and advertise on the Internet. We have increased our capacity for getting more things done more quickly, yet we have also created a myriad of new information flows, and with them – new concepts of insecurity we do not yet know how to deal with. Marketing companies are building profiles of users on the Internet hoping to turn your browsing experience into a constant shopping trip. Personal information, collected by governments and social agencies, is then sold to data mining companies, whose aim is to accumulate as much detail as possible about your private life and habits. This information is then used in surveys, product development or national security updates. Our email accounts are cluttered with useless and unsolicited messages, causing a huge disruption to our work, the Internet connectivity and computer reliance.It appears that chaos has come to rule our digital world. Nothing is certain and everything is possible. Most of us just want to get on with writing our document or sending an email, without considering the outcomes of insecurity. Unfortunately, this is not possible in the digital environment. To be a confident player in this new age of information highways and emerging technologies, you need to be fully aware of your potential and your weaknesses. You must have the knowledge and skills to survive and develop.
Methods and trends of surveillance, censorship and electronic attack
ECHELON intercept station at Menwith Hill, England.
Source: www.greaterthings.com
Does anyone have the right to access our private information? In the aftermath of the 9/11 attacks in the USA, most governments seem to think they should have full control of our communications and the ability to monitor and access our computers. Many countries have implemented legislation and introduced the technology that increased their power of surveillance to previously unseen levels. The ECHELON project, for instance, is a global surveillance system, able to record and process telephone, Internet and satellite communications.I
n May 2001, the European Parliament’s Temporary Committee on the Echelon Interception System (established in July 2000) issued a report concluding that “the existence of a global system for intercepting communications . . . is no longer in doubt.” According to the committee, the Echelon system (reportedly run by the United States in cooperation with Britain, Canada, Australia and New Zealand) was set up at the beginning of the Cold War for intelligence gathering and has developed into a network of intercept stations around the world. Its primary purpose, according to the report, is to intercept private and commercial communications, not military intelligence.1
The right to freedom of expression and information has also been attacked and suppressed on the Internet. The ability to access information from any Internet connection point on Earth, regardless of where this information is stored, has resulted in many governments –not ready or willing to provide this type of freedom to their citizens– scrambling to restrict such free access. Huge resources have been poured into developing country-specific filtering systems to block the Internet information, deemed inappropriate or damaging to the local country’s laws and ‘national morale’.
In China, a system known as the “Great Firewall” routes all international connections through proxy servers at official gateways, where the Ministry for Public Security (MPS) officials identify individual users and content, define rights, and carefully monitor network traffic into and out of the country. At a 2001 security industry conference, the government of China announced an ambitious successor project known as “Golden Shield.” Rather than relying solely on a national Intranet, separated from the global Internet by a massive firewall, China will now build surveillance intelligence into the network, allowing it to “see,” “hear” and “think.” Content-filtration will shift from the national level to millions of digital information and communications devices in public places and people’s homes. The technology behind Golden Shield is incredibly complex and is based on research undertaken largely by Western technology firms, including Nortel Networks, Sun Microsystems, Cisco and others.2
These filters undermine our ability to take advantage of the Internet and to cross geographical boundaries in our quest for learning and communication. They are also in breach of several articles in the Universal Declaration of Human Rights (UDHR) guaranteeing every person rights to privacy and free expression. Significantly, these systems were developed only after the growth and potential of the Internet as the global information exchange was noticed. They were not part of the original idea behind the development of the Internet.
I have witnessed such Internet-based filtering repeatedly. In the days following the attacks on the New York Trade Centre, while working for a global computer company, I had an urge to explore the obscure world of religious fundamentalism. After browsing through certain extremists websites, I was approached by two of the company’s security guards who asked me why I was looking for that particular information. At first, I was dumbfounded – how did they find out? Then I asked the guards who gave them the right to question me. The next day, a company memo banned all staff from visiting websites that contradicted “the organisation’s ethics and policy’”.
The debate about controlling the Internet and information flows for the purposes of countering terrorism is outside the boundaries of this manual. It has to be said, however, that such practices have reduced freedom of expression, association and privacy all over the world, in direct contravention of the UDHR. Governments have installed systems to monitor their citizens on the scale far beyond the measures to fight terrorism. Information on human rights, freedoms of the media, religion, sexual orientation, thought and political movements, to name just a few, has been made inaccessible to many.
...“The Uzbekistan government has reportedly ordered the country’s internet service providers (ISPs) to block the website www.neweurasia.net, which hosts a network of weblogs covering Central Asia and the Caucasus. The government’s decision to block all national access to www.neweurasia.net is believed to be the first censoring of a weblog in Central Asia...”3
... “The Socialist Republic of Vietnam regulates access to the Internet by its citizens extensively, through both technical and legal means. According to the study by the OpenNet Initiative (ONI), the Vietnamese state attempts to stop citizens from accessing political and religious material deemed to be subversive along various axes. The technical sophistication, breadth, and effectiveness of Vietnam’s filtering are increasing with time, and are augmented by an ever-expanding set of legal regulations and prohibitions that govern on-line activity. Vietnam purports to prevent access to the Internet sites primarily to safeguard against obscene or sexually explicit content. However, the state’s actual motives are far more pragmatic:
while it does not block any of the pornographic, it filters a significant fraction - in some cases, the great majority - of sites with politically or religiously sensitive material that could undermine
Vietnam’s one-party system...”4
Encryption has become one of the last resorts of privacy on the Internet. It enables us to make our messages and communications unreadable to all but the intended party. A layer of encryption was even built into the Internet structure to allow for secure financial transactions (SSL). When this system began to be applied for securing other, non-financial, information, it was met with strong opposition inmany countries. At first, the US government tried to ban all SSL encryption of the complexity higher than they could decrypt. In 2000, Britain, in her turn, introduced the Regulation of Investigatory Powers Act (RIP) which made no provisions for one’s right to encrypt information, but stated that a user must surrender his passwords when asked to do so by the investigative forces or face 6-month imprisonment. In 1998, the government of Singapore passed the Computer Misuse Act that allowed the country’s security services to intercept email messages, decrypt encoded messages and confiscate computers without a warrant in the course of investigations5.
Some countries, like Turkmenistan have banned encryption altogether. A world-wide monitoring system, like ECHELON (or any other), will probably collect all encrypted emails for further inspection, simply because they were encrypted in the first place. Any attempt at privacy will therefore be seen as an intention to hide something.
Specific threats faced by human rights defenders Human rights defenders often become targets of surveillance and censorship in their own country. Their right to freedom of expression is often monitored, censored and repressed. Often they are facing heavy penalties for continuing their work. The digital world has been both a blessing and a curse for them. On the one hand, the speed of communications has brought them closer to their colleagues from around the world, and the news of human rights violations spreads around within minutes. People are being mobilised via the Internet, and many social campaigns have moved online. The negative aspect of the widespread use of computers and the Internet lies in over reliance on complex technology and the increased threat from targeted electronic surveillance and attacks. At the same time, the defenders in poorer countries who do not have computers and/or access to the Internet have found themselves left out of global focus and reach – another example of the imbalance caused by the digital divide. Over the years, HRDs have learnt to operate in their ownenvironment and have developed mechanisms for their own protection and prevention of attacks. They know their countries’ legal systems, have networks of friends and take decisions based on everyday wisdom.
Computers and Internet, however, constitute a whole new world to discover and understand. It is their lack of interest or capacity to learn about electronic security that has lead to numerous arrests,
attacks and misunderstandings in the HR community. Electronic security and digital privacy should become not just an important area for comprehension and participation, but also a new battleground in the struggle for the worldwide adherence to the principles of the UDHR.
Emails do not arrive at their destination, Internet connection is intermittent, computers are confiscated and viruses damage years of work. These problems are commonplace and familiar. Another common phenomenon is the increasing attention of those in power to online publishing. The authorities are actively searching through Internet news sites, blogs and forums – with swift retribution in cases when “undesired” material originating from a HRD is discovered. Take the case of Mohamed Abbou, who is serving a 3,5 year prison term in Tunisia for publishing online an article that compared Tunisian prisons to Abu Ghraib6. In China, 48 journalists are in prison because of their Internet-related activities7.
Human rights defenders need to secure their work by learning about the technology and concepts of the computer and Internet operations. This will make them more effective in protecting themselves and in promoting the rights of those they try to defend.
1 European Parliament, Temporary Committee on the Echelon
Interception System (2001) Report on the Existence of a Global System
for the Interception of Private and Commercial Communications (ECHELON
interception system), May 18, 2001. (2001/2098(INI)) (adopted July 11,
2001) Available at http://www.fas.org/irp/program/process/prechelon_en.pdf
2 Privacy International – Privacy and Human Rights Report 2004 – The Threats to Privacy
3 http://www.newseurasia.net July 6th, 2006
4 Internet Filtering in Vietnam in 2005-2006: A Country Study
http://www.opennet.net/studies/vietnam
5 Reporters sans frontières – Annual Report 2006, Internet
6 Front Line http://www.frontlinedefenders.org/news/2081
7 Reporters sans frontières – Annual Report 2006, Internet
civisec.org & Citizen Lab
The Citizen Lab is an interdisciplinary laboratory based at the Munk Centre for International Studies at the University of Toronto, Canada focusing on advanced research and development at the intersection of digital media and world politics.
We are a "hothouse" that combines the disciplines of political science, sociology, computer science, engineering, and graphic design.
Our mission is to undertake advanced research and engage in development that monitors, analyses, and impacts the exercise of political power in cyberspace.
The Citizen Lab's ongoing research network includes the Information Warfare Monitor and the OpenNet Initiative and ONI Asia, and benefits from collaborative partnerships with
academic institutions, NGOs, and other partners in all regions of the world.
The Citizen Lab developed the psiphon censorship circumvention software, and continues to provide "red team" research, threat analysis, and support for open source development for Psiphon Inc.
PDF link available here
The New, New Internet: Deibert Interview on Cybersecurity
Posted Aug 28, 2009 in Citizen Lab News by ProfD.
Read an interview with Citizen Lab Director Ron Deibert on cyber security policies and the GhostNet investigation here
Wednesday, September 30, 2009
la censura en internet
http://www.zensur.freerk.com/index-es.htm
Tor - sistema anónimo de comunicación por Internet.
http://tor.eff.org
Torpark - navegador seguro construido en base al Firefox Deer Park, utilizando la red Tor.
http://www.torrify.com
Scatterchat - Cliente (programa de software) de mensajería instantánea segura.
http://www.scatterchat.com
PGP/GPG - Software de cifrado.
http://www.pgpi.org
http://www.gnupg.org
Thunderbird+GPP - Cliente (programa de software) de correo electrónico construido con cifrado GPG (GNU Privacy Guard).
http://www.portableapps.com
Ultrasurf - Navegación segura en Internet.
http://www.ultrareach.com
Freegate - Acceso cifrado a Internet.
http://www.download.com/3000-20-10415391.html
Peacefire - Herramienta de elusión de la censura.
http://www.peacefire.org/
http://es.wikipedia.org/wiki/Freenet
http://freenetproject.org/
http://sourceforge.net/projects/anonym-os/
http://kaos.to/cms/projects/re.....ivecd.html
http://www.openbsd.org/es/
http://en.wikipedia.org/wiki/Anonym.OS
Saturday, August 8, 2009
IE Enhanced Security Configuration not enabled
Caution on Internet Explorer about Enhanced Security Configuration
(copy the link res://iesetup.dll/softAdmin.htm
in the address bar of Internet Explorer)
Internet Explorer Enhanced Security Configuration is an option that is provided in Windows Server 2003 operating systems and above. You can use it to quickly enhance Internet Explorer security settings for all users.
- Close all instances of Internet Explorer.
- Click Start, point to Administrative Tools, and then click Server Manager.
- If a User Account Control dialog box appears, click Continue.
- Under Security Summary, click Configure IE ESC.
- Under Administrators, click On (Recommended).
- Under Users, click On (Recommended).
- Click OK.
- To disable IE ESC, click Off for both Administrators and Users, and then click OK.