Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, January 27, 2025

bench3

Cybersecurity and Windows: Importance and Awareness

In today’s digital age, computers and operating systems play an essential role in connecting people, businesses, and institutions. Among them, Microsoft Windows remains the most widely used operating system globally, powering billions of devices. However, as the digital landscape grows, so do cyber threats targeting Windows users. Understanding the importance of cybersecurity and fostering awareness is crucial for safeguarding personal data, corporate assets, and national security.


The Intersection of Windows and Cybersecurity

Microsoft Windows has become a prime target for cybercriminals due to its widespread adoption. Its versatility and compatibility make it essential for personal, professional, and enterprise environments, but this popularity also makes it attractive for malicious actors.

Cybersecurity is the practice of protecting systems, networks, and programs from digital attacks. In the context of Windows, it involves securing the operating system, applications, and data from threats such as viruses, ransomware, phishing, and unauthorized access.


Why Cybersecurity is Critical for Windows

  1. High Target Value: With a dominant market share, Windows systems are a preferred target for hackers. Breaches can lead to massive data leaks and financial losses.
  2. Diverse User Base: Windows is used by individuals, businesses, government agencies, and educational institutions, making its security critical for multiple sectors.
  3. Complex Ecosystem: Windows devices run a wide variety of software and connect to numerous networks, increasing the attack surface for vulnerabilities.
  4. Evolving Threats: Cyber threats are constantly advancing. New malware, ransomware, and zero-day exploits specifically designed for Windows systems appear daily, requiring proactive measures.

Common Cybersecurity Threats on Windows

  1. Ransomware: Malware that encrypts user data and demands payment for its release. High-profile ransomware attacks have paralyzed businesses and government agencies.
  2. Phishing Attacks: Cybercriminals use fake emails or websites to steal sensitive information such as login credentials or financial details.
  3. Zero-Day Exploits: These vulnerabilities are exploited before they are discovered and patched, leaving Windows systems exposed.
  4. Spyware and Keyloggers: These programs secretly record user activity and steal sensitive information.
  5. Trojan Horses: Malware disguised as legitimate software that grants attackers unauthorized access to a device.

Importance of Cybersecurity Awareness

1. Protecting Sensitive Data
Personal data such as passwords, financial details, and medical records can be stolen and misused, leading to identity theft and financial fraud. For businesses, customer data breaches can damage reputations and result in costly legal penalties.

2. Maintaining System Integrity
Compromised systems may lead to operational downtime, loss of productivity, and even irreparable damage to hardware or software.

3. Preventing Financial Loss
Ransomware attacks, fraud, and data recovery costs impose significant financial burdens on individuals and organizations.

4. Mitigating National Security Risks
Governments rely heavily on Windows-based systems for administration and defense. Cyberattacks targeting these systems can disrupt critical infrastructure and pose serious security risks.


Best Practices for Windows Cybersecurity

  1. Keep Windows Updated
    Regularly update your Windows operating system to ensure you receive the latest security patches. Microsoft frequently releases updates to address vulnerabilities.

  2. Use Antivirus Software
    Install and maintain reputable antivirus software that can detect, quarantine, and remove malicious programs.

  3. Enable Windows Firewall
    The built-in Windows Defender Firewall provides an additional layer of protection against unauthorized access and malicious traffic.

  4. Use Strong Passwords
    Create complex passwords that combine letters, numbers, and symbols. Avoid reusing passwords across multiple platforms.

  5. Enable Multi-Factor Authentication (MFA)
    Adding an extra layer of verification, such as a mobile authentication app or a fingerprint scan, reduces the risk of unauthorized access.

  6. Backup Data Regularly
    Regularly back up critical files to secure, offline locations. This ensures data recovery in case of ransomware or hardware failure.

  7. Avoid Suspicious Links and Attachments
    Exercise caution when clicking on links or downloading attachments from unknown sources, as they may contain malware or phishing attempts.

  8. Educate and Train Users
    Awareness is the first line of defense. Teach employees and users about cybersecurity risks, safe practices, and how to recognize suspicious activity.

  9. Enable BitLocker Encryption
    For Windows users, BitLocker provides disk encryption to protect data even if the device is stolen or accessed without authorization.

  10. Monitor Activity
    Use tools like Windows Event Viewer and third-party monitoring software to keep track of system activity and detect unusual behavior.


Promoting Cybersecurity Awareness

  1. Campaigns and Workshops
    Organize cybersecurity awareness campaigns in schools, workplaces, and communities to educate people about the importance of digital safety.

  2. Collaborating with Experts
    Engage cybersecurity professionals to conduct audits, provide training, and implement robust security measures.

  3. Utilizing Resources
    Make use of Microsoft’s security resources, such as their Security Baseline and Defender Security Center, for guidance on staying protected.

  4. Celebrating Cybersecurity Awareness Month
    October is recognized globally as Cybersecurity Awareness Month a perfect time to highlight digital safety through initiatives and events.


Conclusion

In a world where digital connectivity is essential, cybersecurity for Windows is not optional—it is a necessity. By adopting proactive measures, staying informed about emerging threats, and fostering a culture of cybersecurity awareness, individuals and organizations can safeguard their systems and data.

Cybersecurity is a shared responsibility. When we all do our part to protect Windows systems, we create a safer, more secure digital environment for everyone. Remember: staying safe online begins with awareness, preparation, and the will to act.

Read More

Sunday, February 26, 2017

bench3

Samsung Releases Secure Folder on Galaxy Smart Phones

Following the recent appearance of the Secure Folder APK for the Galaxy S7 and Galaxy S7 edge, Samsung has officially made the Secure Folder app available from the Galaxy Apps store. 

Secure Folder is supported by the S7 and S7 edge on Android 7.0 Nougat, and Samsung says more devices will be supported soon. The new Galaxy A (2017) devices already support Secure Folder, so it will be devices like the Galaxy S6 and Galaxy Note 5 that will receive support in the future once they get updated to Nougat.

For those wondering what Secure Folder does, it is basically a more user-friendly version of Samsung’s KNOX security solution that lets you create a separate, private space for all your important apps and data. Anything you do inside Secure Folder – creating a document, taking pictures, or making notes – will not be visible during normal operation, which means no one other than you will be able to access this data. Since Secure Folder creates a separate entity for apps used inside, you can have two WhatsApp accounts on a single device, and similarly have two accounts in apps that might not otherwise have support for multiple accounts.

Secure Folder can be downloaded from the Galaxy Apps store if your S7 or S7 edge is running Nougat, and also from our APK archive. Not every region has Nougat on Samsung’s current flagships yet, but the company is slowly and surely getting around to global coverage so it shouldn’t be long before you are able to start using Secure Folder.

The app uses Samsung’s Knox security features to lock the files within, only making them accessible through a passcode or biometric security. 

The only caveat is that you’ll need to be running Android 7.0 Nougat to use Secure Folder, which may or may not be available depending on your carrier of choice. Assuming you’ve got that set, Secure Folder is available now to download from Galaxy Apps. 
Read More

Sunday, December 21, 2014

Nazrin Jahan

Five Ways to Secure your E-Mail

Concerns have been raised after hackers exposed months of e-mails of Sony employees The Sony hack, the latest in a wave of company security breaches, exposed months of employee e-mails. Other hacks have given attackers access to sensitive information about a company and its customers, such as credit-card numbers and e-mail addresses. One way hackers can sneak into a company is by sending fake e-mails with malicious links to employee inboxes.

Here are five simple steps to make your e-mail more secure and limit the harm a hacker can cause:

1. ARCHIVE EARLY & OFTEN

Most corporate e-mail systems allow people to set up regularly scheduled archiving so that e-mails are moved off of the server after a certain number of days.

You can still check archived e-mails on your work computer, but they are no longer easily accessible on websites outside the office or on your phone. That limits hackers’ ability to access those e-mails too. You can make exceptions for e-mails that you want to keep in your active inbox, and they won’t be archived.

2. GET ORGANISED

As e-mails come into your inbox, deal with them. Sort them into folders. This segments your data, requiring an attacker to know which folder to go to, or to take multiple steps to search for wanted information.

Paired with archiving, it also ensures that what the hacker does compromise is limited and known for any future damage assessment. Sensitive information can also be removed from your inbox. For example, delete an e-mail and save what you need to your hard drive or an external drive.

Five Ways to Secure your E-Mail

3. KEEP WORK AND PERSONAL MAILS SEPARATE

Don’t use your work e-mail for personal e-mail or activities online. That limits details a hacker can glean about you to conduct more sophisticated attacks targeting you as the entryway into your company’s system.

For example, hackers can learn about your shopping habits or personal hobbies and use those to send a phishing e-mail that appears to come from websites you bought goods from or read frequently.

Phishing messages route you to a fake address and allow hackers to gain access to your system.

4. DON’T CLICK ON UNEXPECTED LINKS

If you receive an e-mail with a link or attachment you weren’t expecting, send the person a separate e-mail asking whether the first e-mail was legitimate.

For links from companies such as banking institutions, hover your cursor over the hyperlink or right—click to show the link’s final destination. Before you click, make sure the address that pops up when you hover over the link matches where the hyperlink says you’ll be sent.

If unsure, use a new window and physically type in the website’s address to conduct your business.

5. IF YOU SEE SOMETHING, SAY SOMETHING

If your e-mail is acting up or a link or attachment strikes you as strange, forward it to your IT department as quickly as possible. Your attention and fast response may prevent someone else at your company from making a mistake. Source: The Hindu

The group responsible for the Sony Pictures hack has apparently sent a new message that mocks the FBI for its investigation into the devastating cyberattack.

An email claiming to be from Guardians of Peace, the group that took credit for last month's attack on Sony's systems, was sent to journalists early Saturday. The email, titled "The data you are interested in," included a link to a Pastebin page with a so-called "Christmas gift" message taunting the law enforcement agency that on Friday officially named North Korea as the source of the hack.

"The result of investigation by FBI is so excellent that you might have seen what we were doing with your own eyes," reads the message, which then links to a YouTube video. "We congratulate you success. FBI is the BEST in the world."

Read More

Saturday, June 23, 2012

bench3

Steps To Reset All User Permissions To Default

This article will explain how to change the user permission on Windows (Vista and Windows 7) to its default settings.

Use this method only if you have accidentally changed some user permission on your Windows machine . I can't change the permissions back because it tells me that I do not have access to certain folders.

It is very important that if you have created System Restore points try to restore your system back to previous dates on which your system worked without the above mentioned problem.

To reset system permissions, follow the steps:

  • You will need to run ‘Subinacl Tool’ to reset the permission to normal.  Download subinacl.msi from the following link, and save it on the desktop.

(http://www.microsoft.com/downloads/details.aspx?FamilyID=e8ba3e56-d8fe-4a91-93cf-ed6985e3927b&displaylang=en#AffinityDownloads)

  • On the desktop, double-click subinacl.msi to install the tool.
  • Select C:\Windows\System32 as the destination folder.

This step assumes that Windows is installed in C:\Windows. If Windows is installed elsewhere, select the appropriate path to .\System32.

  • Open Notepad.
  • Copy the following commands and then paste them into the opened Notepad window.

subinacl /subkeyreg HKEY_LOCAL_MACHINE /grant=administrators=f
subinacl /subkeyreg HKEY_CURRENT_USER /grant=administrators=f
subinacl /subkeyreg HKEY_CLASSES_ROOT /grant=administrators=f
subinacl /subdirectories %SystemDrive% /grant=administrators=f
subinacl /subkeyreg HKEY_LOCAL_MACHINE /grant=system=f
subinacl /subkeyreg HKEY_CURRENT_USER /grant=system=f
subinacl /subkeyreg HKEY_CLASSES_ROOT /grant=system=f
subinacl /subdirectories %SystemDrive% /grant=system=f

  • In Notepad click File, Save As, and then type: reset.cmd
  • In Notepad click Save as type, and then select All Files (*.*).

Steps To Reset All User Permissions To Default

  • Save the reset.cmd file to your desktop, and close Notepad.
  • Double-click the reset.cmd file to reset the Windows Update permissions. If this gives you any error message, then right click on reset.cmd and choose “Run As Administrator” as shown in the below screen shot. And if you are asked with any question, give Yes to continue.

Steps To Reset All User Permissions To Default 2

This step may take several minutes, so please be patient. When the permissions have been reset, you will be prompted with "Finished, press any key to continue."

  • Press any key to complete the installation.

Check if you have the right permissions to all the folders for all users.

This works for Windows 7 as well as Vista. How do I restore security settings to the default settings?
http://support.microsoft.com/kb/313222

For more information you may check the article given below. The article given is for Windows XP updates, but still holds good for Windows Vista as well as Windows 7.

http://support.microsoft.com/kb/968003

Read More

Sunday, June 10, 2012

bench3

How To Block a Website for free Without Third Party Software

It is easy to block a website on a computer using any software or just by changing the dns server and making few settings but if you don’t want to use any additional software or service then too you can block websites on your Windows machine. All you will require for this is :

1. A windows machine.

2. A text editor (notepad will do).

3. A web browser .

Just follow the steps given below to block a particular website.

1. Navigate to the C:\WINDOWS\system32\drivers\etc

2. Find the file named “HOSTS”

3. Open it using notepad.

4. Under “127.0.0.1 localhost” Add 127.0.0.2 www.orkut.com , and that site will no longer be accessible.

5. Done!

example :

- www.orkut.com will not be accessible anymore.

If you want to add more sites then just increment the IP address by one and add it to the list. i.e.

127.0.0.3 www.yahoo.com

127.0.0.4 www.msn.com

127.0.0.5 www.google.com

You can use this trick to block popup sites as well or any other advertising site.

Read More

Saturday, June 9, 2012

bench3

Remove Popup-Nag in "Avira AntiVir PE Antivirus

Avira AntiVir PE Antivirus is an free entry-level antivirus that can be used to eliminates many forms of malware, including worms, rootkits and costly dialers.

Avira AntiVir Personal is good and free, except that it always pops up and displays annoying nag advertisement screen which persuades users to upgrade to paid premium edition of Avira product.

The notification message, or rather the pop-up ads, of free edition of Avira Anti-Virus product displayed whenever auto-updater runs to update the anti-virus signature database, which is a daily routine. Thus, the upgrade to Avira AntiVir Premium or Avira Premium Security Suite pop-up notifier window is shown everyday from notification area (system tray).

How to Remove Popup-Nag in "Avira AntiVir PE Antivirus

Method 1: Using Group Policy Editor

Disallow or Disable avnotify.exe From Running or Executing with Local Group Policy Editor

Note! Local Group Policy Editor is only included in some Windows versions. Thus, it works only Windows 2000, Windows XP Professional, Windows Vista Business, Enterprise and Ultimate Edition and Windows 7 Professional, Enterprise and Ultimate Edition.

  • Run GPEdit.msc.
  • Navigate to User Configuration > Administrative Templates > System.
  • Double click on Don’t run specified Windows applications setting.
  • Click on Enabled radio button if it’s not yet enabled.
  • Click on Show button.
  • Type in avnotify.exe in the Value column.

Remove Popup-Nag in Avira AntiVir PE Antivirus

  • Click OK when done.

Method 2: (Using Safe Mode)

If the above method did not work for you, try this (Will also work for Windows XP Home and Windows XP Professional)

  • 1. Boot into Safe Mode (tap F8 repeatedly after you restart the computer)
  • 2. Log in using the Administrator account
  • 3. Go to C:\Program Files\AntiVir PersonalEdition Classic\avnotify.exe
  • 4. Right-click avnotify.exe-> properties-> security-> advanced
  • 5. Under the Permissions folder you will see all of the users. Start with the first user….
  • 6. Edit-> Traverse Folder / Execute File-> deny-> ok
  • 7. Now perform step 6 for all of the other users-> apply-> yes/ok-> close all open windows
  • 8. Reboot the computer into Normal Mode (start-> shutdown-> restart)

Method 3: (Using Local Security Policy) Also Works with windows XP Pro:

1. Start-> Control Panel

2. Administrative tools-> Local security policy

3. Click on Software Restriction Policy-> Action (at the top)-> create new restriction policies

4. Right-click additional rules (on the right side)-> new path rule

5. Click Browse and navigate to c:\program files\Antivir\ and double-click avnotify.exe-> set the security level to Disallowed-> apply-> ok

Read More

Thursday, May 24, 2012

bench3

How to Stop a Phishing Filter On Internet Explorer

Microsoft helps protect you from phishing sites by providing a phishing filter within Internet Explorer. A phishing website attempts to scam users out of their personal and financial data through official-looking websites. The phishing filter runs in the background and warns you if a site you visit may be a phishing site.

However, if you don't want to frequently see warning pop-ups, you can turn the phishing filter off. You can easily turn it back on again if you need to.

Steps To Stop Phishing Filter On Internet Explorer :

  • Open an Internet Explorer window. The Microsoft phishing filter applies to Internet Explorer only.
  • Click "Tools" in the menu bar of your browser.
  • Choose "Phishing Filter." Select "Phishing Filter Settings."
  • Locate "Security" under the list of phishing filter options.
  • Click "Disable Phishing Filter." Press "OK" to save your changes.

You can also create a list of acceptable websites by going into the phishing filter settings. This will help prevent pop-ups on frequently visited sites.

Unless you're a new Internet user or are visiting questionable sites often, turn the phishing filter on to help warn you about possible scam sites.

Read More

Tuesday, May 22, 2012

bench3

Prevent Accidental Printing Copying Or Forwarding Confidential Documents

Often, users need to share confidential documents to collaborate efficiently. For example, a user might e-mail a document to another user for review. However, when the document is copied from your protected shared folder or intranet, you lose control of the document. Users might accidentally copy, forward, or print the document, where it can be found by a user who shouldn’t have access.

There’s no perfect solution to protect electronic documents from copying. However, the Windows Rights Management Services (RMS) client, built into Windows Vista and Windows 7, enables computers to open RMS-encrypted documents and enforce the restrictions applied to the document. With an RMS infrastructure and an application that supports RMS, such as Microsoft Office, you can:
  • Allow a user to view a document but not save a copy of it, print it, or forward it.
  • Restrict users from copying and pasting text within a document.
  • Make it very difficult to open the document using a client that does not enforce RMS protection.
Windows 7 provides built-in support for using RMS to protect XML Paper Specification (XPS) documents. To use RMS, you need an RMS infrastructure and supported applications in addition to Windows Vista or Windows 7.
Read More

Friday, May 18, 2012

bench3

Microsoft Security Essentials Pros and Cons

Microsoft Security Essentials (MSE) has become the world's second most popular security package in less than two years since its 2009 launch.

MSE is one of the simplest and easiest to use anti-malware tools around. It's quick, unobtrusive and works without slowing your PC down.

Malware is caught quickly, and the default actions work well for most users. It's a small download, and keeps itself up-to-date. And above all, it's free – with no need to register or re-register.

If you're not running anti-virus software, you really have no excuse. MSE is free, simple to use and has been tested by independent anti-malware certification bodies. With Microsoft regularly updating MSE there's really no excuse to not run anti-malware tools, when they're as good as this – and especially when they're free.

Available for Windows XP (Service Pack 2 and higher), Windows Vista and Windows 7, and in both 32- and 64-bit form, Microsoft Security Essentials is part of the Genuine Windows programme, and can only be used on consumer PCs.

Microsoft Security Essentials Pros and Cons

Small businesses do have an exemption, and can run it on up to 10 machines; any more than that and you need to use Microsoft's Forefront Endpoint Protection tools. It's a small download, the latest beta version is 9MB for 32-bit machines, and 11MB for 64-bit.

There's no obvious slowdown when it runs, and all you see is a tiny task bar icon that shows whether your PC is protected or not. Right-click to launch a settings tool and to run scans – with a choice of quick, full or custom.

Installation is quick and easy. Once installed, a small icon in the task bar is the only sign that MSE is installed and running, and it changes colour depending on the risk to your PC.

Green is, of course, good and yellow means that it's time to run a scan. And if it is Red, it is critical…

MSE will automatically run a quick scan once a week, although we'd recommend changing the default 2am on Sunday to a time when your PC is likely to be turned on.

You can limit the amount of CPU that MSE will use for a scan (the default is 50%), and you can also make sure it won't scan if you're using your PC. We'd recommend leaving real-time protection on - it won't use too much power or add significant latency to downloads, and will reduce the risk of downloading malware inadvertently.

Other tools built into MSE let you tune it to exclude specific files and locations from scanning, as well as specific file types and even specific processes. You're better off not changing these settings, since it's impossible to predict how malware may disguise itself or what zero-day attacks they might use. A custom scan will check specific files, folders, or drives, while a full scan will check everything on your PC. We'd suggest sticking with quick scans for everyday operation, which look for common malware and check system files.

The advanced options in MSE's Settings tab enable you to include removable drives in scans, to protect flash drives as well as your system disks. You can turn off archive scanning (although we'd recommend leaving it on, since it's able to detect malware wrapped in several layers of zip compression). Other options enable you to set system restore points automatically before making system changes, including deleting, running or quarantining detected malware.

You're also able to set how long MSE will keep quarantined files before automatically deleting them. Use the History tab to see and remove quarantined malware, with links to online information about the malware so you can decide whether to delete a file or not.

Why Microsoft Security Essentials is Free?

So how can Microsoft give a tool like this away for free? While it doesn't advertise it, MSE is part of Microsoft's Forefront suite of security tools, based on the Forefront Endpoint Protection client used on enterprise desktops. When MSE detects malware it reports back to Microsoft, giving the company a wider view of the security landscape than it would get from just its enterprise security software. With millions of free copies of MSE, Microsoft's paying customers get a more responsive and more secure set of tools, and we all get better security.

The reporting system Microsoft uses is its Active Protection Service (previously known as SpyNet). You can choose whether to be part of it, but if you don't, you won't get full protection from MSE, since it won't detect and alert you if unknown software has been download or is being run.

Basic membership gives you additional protection in return for sending Microsoft details of downloaded and detected software, while Advanced membership sends more details, including how the software runs, what filenames it uses and where it installs.

The process should be anonymous, but there is a slim possibility that personal information could accidentally be sent back as part of reporting malware behavior – something to consider when signing up for the Active Protection Service.

Finally, MSE may not have all the features of other security suites out there, but that's really not that important – especially when widespread use of MSE should help make it a safer internet for everyone.

Read More

Monday, April 23, 2012

bench3

Steps To Delete Facebook Account Completely

Here is a check list of items to go through in order to ensure the success of deleting your Facebook account.

Remove all applications and Facebook Connect Websites. Well, you may be asking, why is it important to remove (disconnect) all connected websites and services. It is because, when they try to use your Facebook account, your account can automatically be activated.

You might be using external third party applications within Facebook, example iPhoto, Zerply, etc also you would have linked your Facebook account to external website while commenting on articles or for using it for web based authentications all these applications can reactivate your Facebook account if you happen to use them knowingly or unknowingly since they are linked to your Facebook account automatically.

Steps To Delete Facebook Account Completely

The first step would be to remove and delink all these applications from your Facebook account. Here is how u can do that.

  • Login into Facebook and click on Account setting
  • On the top right hand corner. Click Privacy Settings.
  • At the bottom of Privacy Setting you’ll see “Apps And Websites” click on “Edit Your Settings”
  • Under “Apps you use” Click on “Edit Settings”
  • Remove all the applications and websites that access your Facebook account.

Once you have disconnected all the linked websites and services from your Facebook account, you can proceed to deleting your Facebook Account.

Deleting Your Facebook Account

Warning! Facebook account once deleted, cannot be activated on the same name or email, please use these steps on caution.

  • Once you’ve take the steps above you can follow the instruction given in Remove Facebook Account and then the following given below if that is not successful.
  • The first step would be to email Facebook directly. Send an email to privacy@facebook.com and request that Facebook deletes your account.
  • Wait  for a week to get an email response from Facebook confirming that your account has been permanently deleted.
  • If you don’t hear from Facebook within a week, email them again. This time, email Facebook at privacy@facebook.com , but also send an email to support@facebook.com and one to info@facebook.com
  • Finally, attempt to log in to your account once you get an email from Facebook. If you’re unable to log in and don’t get a message asking you to reactivate your account, your Facebook account has been permanently deleted.
Read More

Wednesday, April 18, 2012

bench3

7 Tips to improve Internet Security

Internet security is a branch of computer security specifically related to the Internet, often involving browser security but also network security on a more general level as it applies to other applications or operating systems on a whole. Its objective is to establish rules and measures to use against attacks over the Internet.

The Internet represents an insecure channel for exchanging information leading to a high risk of intrusion or fraud, such as phishing. Different methods have been used to protect the transfer of data, including encryption.

The first internet security level is to be cautious in all dealings and understand that many people out there are not as honest as we would like them to be.

7 Tips to improve Internet Security

Here are 7 Tips to Improve Your Internet Security:

1. Use unique and strong passwords for important accounts.

2. Keep your computer's software updated and protected.

3. Don't open email attachments with suspicious file extensions like •.exe, •.vbs, .pif,or .zzx .

4. Avoid cyber cafes for online shopping/net banking and work.Many cyber cafes have poor security mechanisms. All that you type may get recorded, captured and mailed to hackers

5. Do NOT click on banners and advertisements which say "You have caught a virus,click here for a full system scan" or "You are a Winner". These may be viruses or spyware in disguise.

6. Don't disclose personal information like Mother's Name, Date Of Birth, Credit Card and PAN on chat lines or message boards.

7. Be cautious of whom you befriend on social networks like Facebook, Orkut and Twitter.

Take time to understand the site security settings so that you know what you are sharing with others.

Avoiding giving away personal information of any kind is very important on the Internet. Besides secured pages, you should avoid giving out information about yourself. Also, if you are on a website that looks dubious, you should definitely avoid clicking on anything. This is the type of behaviour that a conscious Internet surfer has in order to avoid problems.

You should definitely be a conscious Internet surfer as many times this will save you a lot of trouble. Money and data loss or even identity theft are the risks associated to Internet security breaches.

Avoiding Internet security problems is not as hard as you might think. You should be aware of the risks and act accordingly. However, you should avoid becoming paranoid because this will make you get a lot of programs that can annihilate one another.

Read More

Friday, March 30, 2012

bench3

List Of Windows 7 Built-In or Predefined Groups

Windows 7 also provides groups, which you use to grant permissions to similar types of users and to simplify account administration. If a user is a member of a group that has access to a resource, that user has access to the same resource. You can give a user access to various work-related resources just by making the user a member of the correct group.

Although you can log on to a computer with a user account, you can’t log on to a computer with a group account. Because different Active Directory domains or local computers might have groups with the same name, groups are often referred to by Domain\GroupName or Computer\GroupName (for example, Technology\GMarketing for the GMarketing group in a domain or on a computer named Technology).

Windows 7 uses the following three types of groups:

  • Local groups: Defined on a local computer and used on the local computer only. You create local groups with Local Users And Groups.
  • Security groups: Can have security descriptors associated with them. You use a Windows server to define security groups in domains, using Active Directory Users And Computers.
  • Distribution groups: Used as e-mail distribution lists. They can’t have security descriptors associated with them. You define distribution groups in domains using Active Directory Users And Computers.

As with user accounts, group accounts are tracked using unique SIDs. This means that you can’t delete a group account and re-create it and then expect that all the permissions and privileges remain the same. The new group will have a new SID, and all the permissions and privileges of the old group will be lost.

When you assign user access levels, you have the opportunity to make the user a member of the following built-in or predefined groups:

  • Administrators: Members of this group are local administrators and have complete access to the workstation. They can create accounts, modify group membership, install printers, manage shared resources, and more.

Because this account has complete access, you should be very careful about which users you add to this group.

  • Backup Operators: Members of this group can back up and restore files and directories on the workstation. They can log on to the local computer, back up or restore files, and shut down the computer. Because of how this account is set up, its members can back up files regardless of whether the members have read/write access to the files. However, they can’t change access permissions on the files or perform other administrative tasks.

Backup Operators have privileges to perform very specific administrative tasks, such as backing up file systems. By default, no other group or user accounts are members of the operator groups. This is to ensure that you grant explicit access to the operator groups.

  • Cryptographic Operators: Members can manage the configuration of encryption, IP Security (IPSec), digital IDs, and certificates.
  • Event Log Readers: Members can view the event logs on the local computer.
  • Guests: Guests are users with very limited privileges. Members can access the system and its resources remotely, but they can’t perform most other tasks.
  • Network Configuration Operators: Members can manage network settings on the workstation. They can also configure TCP/IP settings and perform other general network configuration tasks.
  • Performance Log Users: Members can view and manage performance counters. They can also manage performance logging.
  • Performance Monitor Users: Members can view performance counters and performance logs.
  • Power Users: In earlier versions of Windows, this group is used to grant additional privileges, such as the capability to modify computer settings and install programs. In Windows 7, this group is maintained only for compatibility with legacy applications.
  • Remote Desktop Users: Members can log on to the workstation remotely using Terminal Services And Remote Desktop. Once members are logged on, additional groups of which they are members determine their permissions on the workstation. A user who is a member of the Administrators group is granted this privilege automatically. (However, remote logons must be enabled before an administrator can remotely log on to a workstation.)
  • Replicator: Members can manage the replication of files for the local machine. File replication is primarily used with Active Directory domains and Windows servers.
  • Users: Users are people who do most of their work on a single Windows 7 workstation. Members of the Users group have more restrictions than privileges. They can log on to a Windows 7 workstation locally, keep a local profile, lock the workstation, and shut down the workstation.

In most cases, you configure user access by using the Users or Administrators group. You can configure user and administrator access levels by setting the account type to Standard User or Administrator, respectively. While these basic tasks can be performed using Control Panel’s User Accounts page, you make a user a member of a group by using Local Users And Groups under Computer Management.

Read More

Tuesday, February 28, 2012

bench3

What Is CopyRight All About | Restricted Acts

Copyright is a right granted by law that gives the creators of literary, dramatic, musical or artistic works the ability to control ways their work is used and to earn a fair reward for that use. In the case of authors and publishers it provides a means for them to earn a living by writing and publishing.

In addition to written, musical or artistic works the law also protects sound recordings and films (CDs, videos and DVDs) as well as computer software and broadcasts.

Copyright are exclusive rights granted to the author or creator of an original work, including the right to copy, distribute and adapt the work. Copyright does not protect ideas, only their expression or fixation. In most jurisdictions copyright arises upon fixation and does not need to be registered. - Wikipedia

      Copyright is part of a family of intellectual property (IP) rights recognized under UK law. Other forms of IP that enjoy legal protection include Designs, Patents and Trademarks. Copyright law in the UK is automatic and work is legally protected the moment it is created in material form, e.g. written down or recorded. The legal owner in the first instance is the creator (author) of the work. The main exception to this is when the work is created in the course of employment and in these cases the copyright usually belongs to the employer. Copyright protection in the UK generally lasts for 70 years following the death of the author.

      Rights granted by copyright law

      The UK legislation governing copyright is the Copyright, Designs and Patents Act 1988. The law was amended by the Copyright and Related Rights Regulations of 2003 to comply with EU Directive 2001/29/EC.

      The law sets out specific rights that only the author of the work has the right to do. These rights can be placed into two distinct groups; economic and moral.

      Economic rights are:

  • the right to make a copy

  • the right to distribute copies (publish)

  • the right to rent or lend

  • the right to perform or exhibit to the public

  • the right to transmit or broadcast

  • the right to adapt

      Moral rights are:

  • the right of paternity - to be identified as the owner

  • the right of attribution - to not have the work falsely attributed

  • the right of integrity - to object to any usage that damages reputation

    These nine rights are alternatively known as ‘restricted acts’ as they are acts that only the owner can authorize. The copyright owner can manage and exploit their rights by either licensing them or by assigning the rights to a third party. By assigning the rights the advertisement feature owner gives up control of them on an exclusive basis whereas licensing them allows them to authorize restricted acts on a non exclusive basis.

Read More

Monday, February 27, 2012

bench3

Strong Passwords are the First Line of Defence

Strong passwords are the first line of defence against unauthorized access to your information assets.

Here are some of the tips you need to consider before setting up your password.

• Strong password are at least 8 characters long

• Never write or store passwords in a readable format

• They should contain at least 3 of the following: upper case letters, lower case letters, numbers, special characters

• Do not use password saving features in any application or software. This would defeat the purpose of having a password

• Do not repeat any of the last 5 passwords

• Your password should not contain a dictionary word, your username, child's name, pet's name, birthdays, abc 123, password1, etc.

Strong Passwords are the First Line of Defence

For more information on creating a strong password, please read my other post on the Do’s And Don’ts While Creating A Password | Importance of Passwords

Here is what you can do to create a strong password.

  • Start with a sentence or two, just like this,

Complex passwords are safer

  • Remove the spaces between the words in the sentence.,

Complexpasswordsaresafer

  • Turn words into shorthand or intentionally misspell a word.

ComplekspasswordsRsafer

  • Add length with numbers. Put numbers that are meaningful to you after the sentence.

ComplekspasswordsRsafer2011

Test your password with a password checker: A password checker evaluates your password's strength automatically. Try Microsoft's secure password checker.

Read More

Thursday, January 5, 2012

bench3

Most Essential Email Etiquettes

Email has become the most widely used medium of communication within the business world and is becoming increasingly critical to the success and productivity at work. Hence, it is essential to ensure that every email is purposeful and meaningful to both the sender and the receiver.

We are pleased to share with you some simple and useful tips that you need to keep in mind regarding professional e-mail conduct. We have categorised the tips into two broad sections for your ready reference.

Composing Email

1. Use the subject field to indicate content and purpose, this helps to clarify what your message is about and may help the recipient prioritize reading your email.

2. Just like a written letter, be sure to start your email with a greeting. (e.g. Dear, Hello, Hi, Sir, Madam).

3. Your e-mail message reflects you and your company, so traditional spelling, grammar, and punctuation rules apply.

4. Write clear, short paragraphs and be direct and to the point, professional alike see their email accounts as business. Clearly identify the recipients, need. to be mark in ‘To’ and ‘CC’. Include the address in ‘TO’ for those you would like a response from. Include the address in ‘CC’ for those whom you need to inform.

5. Don't use BCC to keep others from seeing who you copied; it shows confidence when you directly CC anyone receiving a copy.

6. Do use BCC, however, when sending to a large distribution list, so recipients will not have to see a huge list of names.

7. Try to use one recipient in ‘TO’, multiple recipient may create confusion among all.

8. Use Bold/Underline sparingly and only when on the matter that needs to be highlighted, avoid using Capital Letters. Use brackets to explain the topic with Italic font format, e.g. Tomorrow (1 January 2012).

9. Include Name, Department, Company, Address and official contact number in your email signature.

Responding/Replying of Email

1. Use ‘Reply to All’ carefully, only if it is very important to use.

2. Remove the recipient not require in your reply.

3. Try to respond within a reasonable period, though "reasonable" will depend on the recipient's expectations and the subject being discussed.

4. Make sure your reply contains all responses requested in an email, to avoid multiple emails.

Some final tips

Remember that e-mail is not private.  E-mail is considered company property and can be retrieved, examined, and used in a court of law. You might also inadvertently send something to the wrong party, so always keep the content professional to avoid embarrassment.

Finally do not forget the value of face-to-face or even voice-to-voice communication. E-mail communication is not appropriate when sending confusing or emotional messages. Please feel free to post your comments on this page if you require any clarification.

Read More

Tuesday, December 27, 2011

bench3

Remove Rogue Security Software | Win 7 Anti-Spyware 2011 And Fake Anti-Virus

Rogue security software, also known as "scareware," is software that appears to be beneficial from a security perspective but provides limited or no security, generates erroneous or misleading alerts, or attempts to lure users into participating in fraudulent transactions.

How does rogue security software get on your computer:

Rogue security software designers create legitimate looking pop-up windows that advertise security update software. These windows might appear on your screen while you surf the web.

The "updates" or "alerts" in the pop-up windows call for you to take some sort of action, such as clicking to install the software, accept recommended updates, or remove unwanted viruses or spyware. When you click, the rogue security software downloads to your computer.

Rogue security software might also appear in the list of search results when you are searching for trustworthy antispyware software, so it is important to protect your computer.

If your PC is infected with such a Rogue security software,for example, Win 7 Anti-Spyware 2011 malware or something similar, let us see how to get rid of it, and free your PC from the awful clutches of this insidious malware (and many others).

Win 7 Anti-Spyware 2011 is just one of many fake antivirus applications like Antivirus Live, Advanced Virus Remover, Internet Security 2010, Security Tool, and others that hold your computer hostage until you pay their ransom money. They tell you that your PC is infected with fake viruses, and prevent you from doing anything to remove them.

This particular virus goes by a lot of names, including XP Antispyware, Win 7 Antispyware, Win 7 Internet Security 2011, Win 7 Guard, Win 7 Security, Vista Internet Security 2011, and many, many others. It’s all the same virus, but renames itself depending on your system and which strain you get infected with.

Fake Antivirus 2009 Messages vary from a fake Google Tips area displayed when visiting the Google homepage saying that "Google recommends you activate Antivirus 2009", to a simple line of text toward the top of your browser telling you that an infection was found.

Remove Win 7 Anti-Spyware 2011 Fake Anti-Virus

If you aren’t familiar with this one, it’s time to take a look at the face of an awful scam. If you are infected, read below on how to remove it.

Once a PC is infected, it’ll display this very official-looking window, which pretends to scan your PC and find things that are infected, but of course, it’s all a lie.

The really crazy thing is that it pops up a very realistic looking Action Center window, but it’s actually the virus.

Remove Win 7 Anti-Spyware 2011 And Fake Anti-Virus

Removing Rogue Fake Antivirus Infections (General Guide)

There’s a couple of steps that you can generally follow to get rid of the majority of rogue antivirus infections, and actually most malware or spyware infections of any type. Here’s the quick steps:

Those are the rules that normally work. Note that there are some malware infections that not only block safe mode, but also prevent you from doing anything at all. In most of such cases, we recommend you backup your files and install Windows from scratch and follow the below steps to protect yourself from rogue security software's in future.

To help protect yourself from rogue security software:

  • Install a firewall and keep it turned on.
  • Use automatic updating to keep your operating system and software up to date.
  • Install antivirus and antispyware software such as Microsoft Security Essentials and keep it updated. For links to other antivirus programs that work with Microsoft, see Microsoft Help and Support List of Antivirus Vendors.
  • If your antivirus software does not include antispyware software, you should install a separate antispyware program such as Windows Defender and keep it updated. (Windows Defender is available as a free download for Windows XP and is included in Windows Vista.)
  • Use caution when you click links in email or on social networking websites.
  • Use a standard user account instead of an administrator account.
  • Familiarize yourself with common phishing scams.
Read More

Tuesday, December 20, 2011

bench3

How To Set Up a Wireless Router or WiFi Access Point

A Wireless router is a device that performs the functions of a router but also includes the functions of a wireless access point and a network switch. They are commonly used to allow access to the Internet or a computer network without the need for a cabled connection.

Thus, a Wireless router can function in a wired LAN (local area network), a wireless only LAN (WLAN), or a mixed wired/wireless network.

To make the most of their security planning, enterprises need to focus on threats that pose the greatest risk.

Most current wireless routers have the following characteristics. Also we will see how to Set Up a Wireless Router or WiFi Access Point:

  • LAN ports which function in the same manner as the ports of a network switch
  • A WAN port to connect to a wide area network, typically one with Internet access. External destinations are accessed using this port. If it is not used, many functions of the router will be bypassed.
  • A wireless antenna allows connections from other wireless devices (NICs (network interface cards), wireless repeaters, wireless access points, and wireless bridges, for example), usually using the Wi-Fi standard.

Some wireless routers also include a DSL or cable modem in addition to their other components.

Wireless router or access point brings convenience because you’re not tethered to a wired connection. Setting up a wireless router or access point depends on the software that comes with the router or access point.

Warning: Wireless networks offer great potential for exploitation for two reasons; they use the airwaves for communication, and wireless-enabled laptops are ubiquitous. Wireless networks are vulnerable in a myriad of ways, some of the most likely problems being rogue access points (APs) and employee use of mobile devices without appropriate security precautions, but malicious hacking attempts and denial-of-service (DoS) attacks are certainly possible as well.

Wireless connections are more complicated to set up than wired connections. You’re basically setting up a radio transmitter that broadcasts to little radios attached to your PCs. You need to worry about signal strength, finding the right signal, and even entering passwords to keep outsiders from listening in.

How To Set Up a Wireless Router or WiFi Access Point

Wireless transmitters, known as Wireless Access Points (WAPs), come either built into your router or plugged into one of your router’s ports. The setup software is different on every model, but it requires you to set up these three things:

  • Network name (SSID): Enter a short, easy-to-remember name here to identify your particular wireless network. Later, when connecting to the wireless network with your computer, you’ll select this same name to avoid accidentally connecting with your neighbor’s wireless network.
  • Infrastructure: Choose Infrastructure instead of the alternative, Ad Hoc.
  • Security: This option encrypts your data as it flies through the air. Turn it on using the recommended settings.

Some routers include an installation program for changing these settings; other routers contain built-in software that you access with Windows’ own Web browser.

As you enter settings for each of the three things, write them on a piece of paper. You need to enter these same three settings when setting up your PC’s wireless connection.

Read More

Saturday, December 17, 2011

bench3

Apply a Digital Signature To Word Documents

Normally, you sign a (paper) check to authenticate its validity to the recipient (and, in due course, to your bank). Similarly, you can apply a digital signature to a Word document to authenticate its validity.

A digital signature is a mathematical scheme for demonstrating the authenticity of a digital message or document. A valid digital signature gives a recipient reason to believe that the message was created by a known sender, and that it was not altered in transit. Digital signatures are commonly used for software distribution, financial transactions, and in other cases where it is important to detect forgery or tampering.

Digital signatures can be used to authenticate the source of messages. When ownership of a digital signature secret key is bound to a specific user, a valid signature shows that the message was sent by that user. The importance of high confidence in sender authenticity is especially obvious in a financial context.

Apply a Digital Signature To Word Documents

The following article will explain you how to apply a Digital Signature to the word document.

To apply a digital signature to a document, follow these steps:

  • Finalize the document, and save any unsaved changes to it.
  • Click the Office Button, click or highlight Prepare, and then click Add A Digital Signature. Word displays the Sign dialog box, shown here.
  • In the Purpose For Signing This Document text box, type a description of why you’re signing the document.
  • If your computer has two or more digital IDs installed, and the Signing As group box shows the wrong signature, click the Change button, choose the correct certificate in the Select Certificate dialog box, and then click the OK button.
  • Click the Sign button. Word closes the Sign dialog box, applies the digital signature, and then displays the Signature Confirmation message box, shown here, warning you that changing the document will render your signature invalid.
  • Select the Don’t Show This Message Again check box if you can dispense with this message box in future, and then click the OK button. Word closes the message box and displays the Signatures pane, shown here.
  • Close the document. (You don’t need to save changes—Word has already saved them for you.)

Although messages may often include information about the entity sending a message, that information may not be accurate.

A digital ID you create yourself via the Create A Digital ID dialog box is useful only for testing. It has no authentication and is worthless in the real world.

Read More

Friday, December 16, 2011

bench3

How To Remove Sensitive or Personal Information From Word Document

If you are worried about sensitive data in your Microsoft Word document you can encrypt or (and) password protect the document to keep it secure. In case if you are not opting for password protection and encryption, It is good that you Remove Sensitive or Personal Information From Word Document.

This is very useful if you have to store your documents in a shared location, such as a network folder or even on home computer so that you can protect your personal privacy to avoid physical or financial jeopardy.

In the past few years, several major governments have embarrassed themselves by releasing files that inadvertently contained information they weren’t supposed to, such as hidden revision marks or metadata in Word documents.

Before you distribute a document, you may want to remove sensitive or personal information from it for security.

Word’s Document Inspector helps to make sure you don’t join the governments in the red-face parade.

To run the Document Inspector and remove such information, follow these steps:

1. If the document contains unsaved changes, click the Save button on the Quick Access Toolbar (or press CTRL-S) to save it.

How To Remove Sensitive or Personal Information From Word Document

2. Click the Office Button, highlight or click Prepare, and then click Inspect Document. Word displays the Document Inspector (see Figure below).

Remove Sensitive or Personal Information From Word Document

3. Select the check box for each type of data that you want to scan the document for:

  • Comments, Revisions, Versions, And Annotations These four items are easy to miss when you’re finalizing a document, as revision marks can be hidden, and comments and annotations may appear only as hard-to-see markers in the text.

Versions are a bit different: Word 2007 doesn’t support versions, but a Word document created in an earlier version of Word may contain them.

A version in this sense is a different edit of the same document. You can store multiple versions in the same document file and switch from one to another.

  • Document Properties And Personal Information: A document can contain information such as your name, your manager’s name, and custom document properties.
  • Custom XML Data: The document may contain XML tags and mappings that you don’t want to share outside your company.
  • Headers, Footers, And Watermarks: If you’re working in Draft view or Outline view, it’s easy to forget to check the headers or footers in a document. You may also need to remove a watermark such as DRAFT before distributing a document.
  • Hidden Text: Hidden text is often useful for hiding boilerplate items that don’t apply to the current document, for inserting extra information that can be added only if required, and other such purposes. Normally, it’s best to remove all hidden text before distributing a document.

Use the Document Inspector to identify hidden content or metadata that you might want to remove before distributing a document.

4. Click the Inspect button. Word inspects the document for the items whose check boxes you selected, and displays the results, providing a Remove All button for each category found.

5. Click any of the Remove All buttons to remove all instances of those items.

6. If necessary, click the Reinspect button to reinspect the document.

7. Click the Close button. Word closes the Document Inspector dialog box.

8. Double-check your document to make sure that removing the items hasn’t had unintended consequences. If all is well, save the document.

Microsoft Word documents can often unintentionally contain confidential or embarrassing information, because the document metadata can include tracked changes, comments and author information that you don’t want clients and partners to see. It is best practice that you run Document Inspector when finalizing your Word documents. Also on a safer side, Do regularly encrypt Word documents.

Read More

Monday, December 12, 2011

bench3

Securing Access to Files and Folders On Windows | Understanding NTFS Permissions

NTFS permissions control access to NTFS files and folders. This is based on the technology that was originally developed for Windows NT. Ultimately, the person who owns an object has complete control over the object. You configure access by allowing or denying NTFS permissions to users and groups.

On NTFS partitions, you can specify the access each user has to specific folders or files on the partition based on the user ’ s logon name and group associations. Access control consists of rights and permissions. A right (also referred to as a privilege) is an authorization to perform a specific action.

To understand the Difference Between FAT And NTFS File System, follow this location, FAT And NTFS File.

Permissions are authorizations to perform specific operations on specific objects. The owner of an object or any user who has the necessary rights to modify permissions can apply permissions to NTFS objects. If permissions are not explicitly granted within NTFS, then they are implicitly denied. Permissions can also be explicitly denied, which then overrides explicitly granted permissions.

Securing Access to Files and Folders On Windows  Understanding NTFS Permissions

The following sections describe design goals for access control as well as how to apply NTFS permissions and some techniques for optimizing local access. Let ’ s take a look at design goals for setting up security.

Design Goals for Access Control

Before you start applying NTFS permissions to resources, you should develop design goals for access control as a part of your overall security strategy. Basic security strategy  suggests that you provide each user and group with the minimum level of permissions needed for job functionality. Some of the considerations when planning access control include the following:

  • Defining the resources that are included within your network — in this case, the files and folders residing on the file system
  • Defining which resources will put your organization at risk, including defining the resources and defining the risk of damage if the resource was compromised
  • Developing security strategies that address possible threats and minimize security risks
  • Defining groups that security can be applied to based on users within the group membership who have common access requirements, and applying permissions to groups as opposed to users
  • Applying additional security settings through Group Policy if your Windows 7 clients are part of an Active Directory network
  • Using additional security features, such as Encrypted File System (EFS), to provide additional levels of security or file auditing to track access to critical files and folders

After you have decided what your design goals are, you can start applying your NTFS permissions.

Normally, NTFS permissions are cumulative, based on group memberships if the user has been allowed access. This means that the user gets the highest level of security from all the different groups they belong to. However, if the user had been denied access through user or group membership, those permissions override the allowed permissions. To know more on how to Setting NTFS Permissions In Windows, follow this link: Setting NTFS Permissions.

Read More