Remote Tech Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 9 July 2010

General security Measures

Posted on 18:06 by Unknown
General security
  • Choosing and Protecting Passwords
  • Understanding Anti-Virus Software
  • Understanding Firewalls
  • Coordinating Virus and Spyware Defense
  • Debunking Some Common Myths
  • Good Security Habits
  • Safeguarding Your Data
  • Real-World Warnings Keep You Safe Online
  • Keeping Children Safe Online

Choosing and Protecting Passwords

Passwords are a common form of authentication and are often the only barrier between a user and your personal information. There are several programs attackers can use to help guess or "crack" passwords, but by choosing good passwords and keeping them confidential, you can make it more difficult for an unauthorized person to access your information.

Why do you need a password?

Think about the number of personal identification numbers (PINs), passwords, or passphrases you use every day: getting money from the ATM or using your debit card in a store, logging on to your computer or email, signing in to an online bank account or shopping cart...the list seems to just keep getting longer. Keeping track of all of the number, letter, and word combinations may be frustrating at times, and maybe you've wondered if all of the fuss is worth it. After all, what attacker cares about your personal email account, right? Or why would someone bother with your practically empty bank account when there are others with much more money? Often, an attack is not specifically about your account but about using the access to your information to launch a larger attack. And while having someone gain access to your personal email might not seem like much more than an inconvenience and threat to your privacy, think of the implications of an attacker gaining access to your social security number or your medical records.
One of the best ways to protect information or physical property is to ensure that only authorized people have access to it. Verifying that someone is the person they claim to be is the next step, and this authentication process is even more important, and more difficult, in the cyber world. Passwords are the most common means of authentication, but if you don't choose good passwords or keep them confidential, they're almost as ineffective as not having any password at all. Many systems and services have been successfully broken into due to the use of insecure and inadequate passwords, and some viruses and worms have exploited systems by guessing weak passwords.

How do you choose a good password?

Most people use passwords that are based on personal information and are easy to remember. However, that also makes it easier for an attacker to guess or "crack" them. Consider a four-digit PIN number. Is yours a combination of the month, day, or year of your birthday? Or the last four digits of your social security number? Or your address or phone number? Think about how easily it is to find this information out about somebody. What about your email password—is it a word that can be found in the dictionary? If so, it may be susceptible to "dictionary" attacks, which attempt to guess passwords based on words in the dictionary.
Although intentionally misspelling a word ("daytt" instead of "date") may offer some protection against dictionary attacks, an even better method is to rely on a series of words and use memory techniques, or mnemonics, to help you remember how to decode it. For example, instead of the password "hoops," use "IlTpbb" for "[I] [l]ike [T]o [p]lay [b]asket[b]all." Using both lowercase and capital letters adds another layer of obscurity. Your best defense, though, is to use a combination of numbers, special characters, and both lowercase and capital letters. Change the same example we used above to "Il!2pBb." and see how much more complicated it has become just by adding numbers and special characters.
Longer passwords are more secure than shorter ones because there are more characters to guess, so consider using passphrases when you can. For example, "This password is 4 my email!" would be a strong password because it has many characters and includes lowercase and capital letters, numbers, and special characters. You may need to try different variations of a passphrase—many applications limit the length of passwords, and some do not accept spaces. Avoid common phrases, famous quotations, and song lyrics.
Don't assume that now that you've developed a strong password you should use it for every system or program you log into. If an attacker does guess it, he would have access to all of your accounts. You should use these techniques to develop unique passwords for each of your accounts.
Here is a review of tactics to use when choosing a password:
  • Don't use passwords that are based on personal information that can be easily accessed or guessed.
  • Don't use words that can be found in any dictionary of any language.
  • Develop a mnemonic for remembering complex passwords.
  • Use both lowercase and capital letters.
  • Use a combination of letters, numbers, and special characters.
  • Use passphrases when you can.
  • Use different passwords on different systems.

How can you protect your password?

Now that you've chosen a password that's difficult to guess, you have to make sure not to leave it someplace for people to find. Writing it down and leaving it in your desk, next to your computer, or, worse, taped to your computer, is just making it easy for someone who has physical access to your office. Don't tell anyone your passwords, and watch for attackers trying to trick you through phone calls or email messages requesting that you reveal your passwords
If your internet service provider (ISP) offers choices of authentication systems, look for ones that use Kerberos, challenge/response, or public key encryption rather than simple passwords  Consider challenging service providers that only use passwords to adopt more secure methods.
Also, many programs offer the option of "remembering" your password, but these programs have varying degrees of security protecting that information. Some programs, such as email clients, store the information in clear text in a file on your computer. This means that anyone with access to your computer can discover all of your passwords and can gain access to your information. For this reason, always remember to log out when you are using a public computer (at the library, an internet cafe, or even a shared computer at your office). Other programs, such as Apple's Keychain and Palm's Secure Desktop, use strong encryption to protect the information. These types of programs may be viable options for managing your passwords if you find you have too many to remember.
There's no guarantee that these techniques will prevent an attacker from learning your password, but they will make it more difficult.

 

Understanding Anti-Virus Software

Anti-virus software can identify and block many viruses before they can infect your computer. Once you install anti-virus software, it is important to keep it up to date.

What does anti-virus software do?

Although details may vary between packages, anti-virus software scans files or your computer's memory for certain patterns that may indicate an infection. The patterns it looks for are based on the signatures, or definitions, of known viruses. Virus authors are continually releasing new and updated viruses, so it is important that you have the latest definitions installed on your computer.
Once you have installed an anti-virus package, you should scan your entire computer periodically.
  • Automatic scans - Depending what software you choose, you may be able to configure it to automatically scan specific files or directories and prompt you at set intervals to perform complete scans.
  • Manual scans - It is also a good idea to manually scan files you receive from an outside source before opening them. This includes
    • saving and scanning email attachments or web downloads rather than selecting the option to open them directly from the source
    • scanning media, including CDs and DVDs, for viruses before opening any of the files

What happens if the software finds a virus?

Each package has its own method of response when it locates a virus, and the response may differ according to whether the software locates the virus during an automatic or a manual scan. Sometimes the software will produce a dialog box alerting you that it has found a virus and asking whether you want it to "clean" the file (to remove the virus). In other cases, the software may attempt to remove the virus without asking you first. When you select an anti-virus package, familiarize yourself with its features so you know what to expect.

Which software should you use?

There are many vendors who produce anti-virus software, and deciding which one to choose can be confusing. All anti-virus software performs the same function, so your decision may be driven by recommendations, particular features, availability, or price.
Installing any anti-virus software, regardless of which package you choose, increases your level of protection. Be careful, though, of email messages claiming to include anti-virus software. These messages, supposedly from your ISP's technical support department, contain an attachment that claims to be anti-virus software. However, the attachment itself is in fact a virus, so you could become infected by opening it .

How do you get the current virus information?

This process may differ depending what product you choose, so find out what your anti-virus software requires. Many anti-virus packages include an option to automatically receive updated virus definitions. Because new information is added frequently, it is a good idea to take advantage of this option. Resist believing email chain letters that claim that a well-known anti-virus vendor has recently detected the "worst virus in history" that will destroy your computer's hard drive. These emails are usually hoaxes.  You can confirm virus information through your anti-virus vendor or through resources offered by other anti-virus vendors.
While installing anti-virus software is one of the easiest and most effective ways to protect your computer, it has its limitations. Because it relies on signatures, anti-virus software can only detect viruses that have signatures installed on your computer, so it is important to keep these signatures up to date. You will still be susceptible to viruses that circulate before the anti-virus vendors add their signatures, so continue to take other safety precautions as well.

Understanding Firewalls

When anyone or anything can access your computer at any time, your computer is more susceptible to being attacked. You can restrict outside access to your computer and the information on it with a firewall.

What do firewalls do?

Firewalls provide protection against outside attackers by shielding your computer or network from malicious or unnecessary Internet traffic. Firewalls can be configured to block data from certain locations while allowing the relevant and necessary data through . They are especially important for users who rely on "always on" connections such as cable or DSL modems.

What type of firewall is best?

Firewalls are offered in two forms: hardware (external) and software (internal). While both have their advantages and disadvantages, the decision to use a firewall is far more important than deciding which type you use.
  • Hardware - Typically called network firewalls, these external devices are positioned between your computer or network and your cable or DSL modem. Many vendors and some Internet service providers (ISPs) offer devices called "routers" that also include firewall features. Hardware-based firewalls are particularly useful for protecting multiple computers but also offer a high degree of protection for a single computer. If you only have one computer behind the firewall, or if you are certain that all of the other computers on the network are up to date on patches and are free from viruses, worms, or other malicious code, you may not need the extra protection of a software firewall. Hardware-based firewalls have the advantage of being separate devices running their own operating systems, so they provide an additional line of defense against attacks. Their major drawback is cost, but many products are available for less than $100 (and there are even some for less than $50).
  • Software - Some operating systems include a built-in firewall; if yours does, consider enabling it to add another layer of protection even if you have an external firewall. If you don't have a built-in firewall, you can obtain a software firewall for relatively little or no cost from your local computer store, software vendors, or ISP. Because of the risks associated with downloading software from the Internet onto an unprotected computer, it is best to install the firewall from a CD or DVD. If you do download software from the Internet, make sure it is a reputable, secure website. Although relying on a software firewall alone does provide some protection, realize that having the firewall on the same computer as the information you're trying to protect may hinder the firewall's ability to catch malicious traffic before it enters your system.

How do you know what configuration settings to apply?

Most commercially available firewall products, both hardware- and software-based, come configured in a manner that is acceptably secure for most users. Since each firewall is different, you'll need to read and understand the documentation that comes with it to determine whether or not the default settings on your firewall are sufficient for your needs. Additional assistance may be available from your firewall vendor or your ISP (either from tech support or a website). Also, alerts about current viruses or worms  sometimes include information about restrictions you can implement through your firewall.
Unfortunately, while properly configured firewalls may be effective at blocking some attacks, don't be lulled into a false sense of security. Although they do offer a certain amount of protection, firewalls do not guarantee that your computer will not be attacked. In particular, a firewall offers little to no protection against viruses that work by having you run the infected program on your computer, as many email-borne viruses do. However, using a firewall in conjunction with other protective measures (such as anti-virus software and "safe" computing practices) will strengthen your resistance to attacks.

 

Coordinating Virus and Spyware Defense

Using anti-virus and anti-spyware software is an important part of cyber security. But in an attempt to protect yourself, you may unintentionally cause problems.

Isn't it better to have more protection?

Spyware and viruses can interfere with your computer's ability to process information or can modify or destroy data. You may feel that the more anti-virus and anti-spyware programs you install on your computer, the safer you will be. It is true that not all programs are equally effective, and they will not all detect the same malicious code. However, by installing multiple programs in an attempt to catch everything, you may introduce problems.

How can anti-virus or anti-spyware software cause problems?

It is important to use anti-virus and anti-spyware software. But too much or the wrong kind can affect the performance of your computer and the effectiveness of the software itself.
Scanning your computer for viruses and spyware uses some of the available memory on your computer. If you have multiple programs trying to scan at the same time, you may limit the amount of resources left to perform your tasks. Essentially, you have created a denial of service against yourself. It is also possible that in the process of scanning for viruses and spyware, anti-virus or anti-spyware software may misinterpret the virus definitions of other programs. Instead of recognizing them as definitions, the software may interpret the definitions as actual malicious code. Not only could this result in false positives for the presence of viruses or spyware, but the anti-virus or anti-spyware software may actually quarantine or delete the other software.

How can you avoid these problems?

  • Investigate your options in advance - Research available anti-virus and anti-spyware software to determine the best choice for you. Consider the amount of malicious code the software recognizes, and try to find out how frequently the virus definitions are updated. Also check for known compatibility issues with other software you may be running on your computer.
  • Limit the number of programs you install - Many vendors are now releasing packages that incorporate both anti-virus and anti-spyware capabilities together. However, if you decide to choose separate programs, you really only need one anti-virus program and one anti-spyware program. If you install more, you increase your risk for problems.
  • Install the software in phases - Install the anti-virus software first and test it for a few days before installing anti-spyware software. If problems develop, you have a better chance at isolating the source and then determining if it is an issue with the software itself or with compatibility.
  • Watch for problems - If your computer starts processing requests more slowly, you are seeing error messages when updating your virus definitions, your software does not seem to be recognizing malicious code, or other issues develop that cannot be easily explained, check your anti-virus and anti-spyware software.

Debunking Some Common Myths

There are some common myths that may influence your online security practices. Knowing the truth will allow you to make better decisions about how to protect yourself.

How are these myths established?

There is no one cause for these myths. They may have been formed because of a lack of information, an assumption, knowledge of a specific case that was then generalized, or some other source. As with any myth, they are passed from one individual to another, usually because they seem legitimate enough to be true.

Why is it important to know the truth?

While believing these myths may not present a direct threat, they may cause you to be more lax about your security habits. If you are not diligent about protecting yourself, you may be more likely to become a victim of an attack.

What are some common myths, and what is the truth behind them?

  • Myth: Anti-virus software and firewalls are 100% effective. 
    Truth: Anti-virus software and firewalls are important elements to protecting your information.  However, neither of these elements are guaranteed to protect you from an attack. Combining these technologies with good security habits is the best way to reduce your risk.
  • Myth: Once software is installed on your computer, you do not have to worry about it anymore. 
    Truth: Vendors may release patches or updated versions of software to address problems or fix vulnerabilities. You should install the patches as soon as possible; some software even offers the option to obtain updates automatically. Making sure that you have the latest virus definitions for your anti-virus software is especially important.
  • Myth: There is nothing important on your machine, so you do not need to protect it. 
    Truth: Your opinion about what is important may differ from an attacker's opinion. If you have personal or financial data on your computer, attackers may be able to collect it and use it for their own financial gain. Even if you do not store that kind of information on your computer, an attacker who can gain control of your computer may be able to use it in attacks against other people (see Understanding Denial-of-Service Attacks and Understanding Hidden Threats: Rootkits and Botnets for more information).
  • Myth: Attackers only target people with money. 
    Truth: Anyone can become a victim of identity theft. Attackers look for the biggest reward for the least amount of effort, so they typically target databases that store information about many people. If your information happens to be in the database, it could be collected and used for malicious purposes. It is important to pay attention to your credit information so that you can minimize any potential damage.
  • Myth: When computers slow down, it means that they are old and should be replaced. 
    Truth: It is possible that running newer or larger software programs on an older computer could lead to slow performance, but you may just need to replace or upgrade a particular component (memory, operating system, CD or DVD drive, etc.). Another possibility is that there are other processes or programs running in the background. If your computer has suddenly become slower, you may be experiencing a denial-of-service attack or have spyware on your machine.

Good Security Habits

There are some simple habits you can adopt that, if performed consistently, may dramatically reduce the chances that the information on your computer will be lost or corrupted.

How can you minimize the access other people have to your information?

You may be able to easily identify people who could, legitimately or not, gain physical access to your computer—family members, roommates, co-workers, members of a cleaning crew, and maybe others. Identifying the people who could gainremote access to your computer becomes much more difficult. As long as you have a computer and connect it to a network, you are vulnerable to someone or something else accessing or corrupting your information; however, you can develop habits that make it more difficult.
  • Lock your computer when you are away from it. Even if you only step away from your computer for a few minutes, it's enough time for someone else to destroy or corrupt your information. Locking your computer prevents another person from being able to simply sit down at your computer and access all of your information.
  • Disconnect your computer from the Internet when you aren't using it. The development of technologies such as DSL and cable modems have made it possible for users to be online all the time, but this convenience comes with risks. The likelihood that attackers or viruses scanning the network for available computers will target your computer becomes much higher if your computer is always connected. Depending on what method you use to connect to the Internet, disconnecting may mean disabling a wireless connection, turning off your computer or modem, or disconnecting cables. When you are connected, make sure that you have a firewall enabled.
  • Evaluate your security settings. Most software, including browsers and email programs, offers a variety of features that you can tailor to meet your needs and requirements. Enabling certain features to increase convenience or functionality may leave you more vulnerable to being attacked. It is important to examine the settings, particularly the security settings, and select options that meet your needs without putting you at increased risk. If you install a patch or a new version of the software, or if you hear of something that might affect your settings, reevaluate your settings to make sure they are still appropriate.

What other steps can you take?

Sometimes the threats to your information aren't from other people but from natural or technological causes. Although there is no way to control or prevent these problems, you can prepare for them and try to minimize the damage.
  • Protect your computer against power surges and brief outages. Aside from providing outlets to plug in your computer and all of its peripherals, some power strips protect your computer against power surges. Many power strips now advertise compensation if they do not effectively protect your computer. Power strips alone will not protect you from power outages, but there are products that do offer an uninterruptible power supply when there are power surges or outages. During a lightning storm or construction work that increases the odds of power surges, consider shutting your computer down and unplugging it from all power sources.
  • Back up all of your data. Whether or not you take steps to protect yourself, there will always be a possibility that something will happen to destroy your data. You have probably already experienced this at least once— losing one or more files due to an accident, a virus or worm, a natural event, or a problem with your equipment. Regularly backing up your data on a CD or network reduces the stress and other negative consequences that result from losing important information (see Real-World Warnings Keep You Safe Online for more information). Determining how often to back up your data is a personal decision. If you are constantly adding or changing data, you may find weekly backups to be the best alternative; if your content rarely changes, you may decide that your backups do not need to be as frequent. You don't need to back up software that you own on CD-ROM or DVD-ROM—you can reinstall the software from the original media if necessary.

Safeguarding Your Data

When there are multiple people using your computer and/or you store sensitive personal and work-related data on your computer, it is especially important to take extra security precautions.

Why isn't "more" better?

Maybe there is an extra software program included with a program you bought. Or perhaps you found a free download online. You may be tempted to install the programs just because you can, or because you think you might use them later. However, even if the source and the software are legitimate, there may be hidden risks. And if other people use your computer, there are additional risks.
These risks become especially important if you use your computer to manage your personal finances (banking, taxes, online bill payment, etc.), store sensitive personal data, or perform work-related activities away from the office. However, there are steps you can take to protect yourself.

How can you protect both your personal and work-related data?

  • Use and maintain anti-virus software and a firewall - Protect yourself against viruses and Trojan horses that may steal or modify the data on your own computer and leave you vulnerable by using anti-virus software and a firewall. Make sure to keep your virus definitions up to date.
  • Regularly scan your computer for spyware - Spyware or adware hidden in software programs may affect the performance of your computer and give attackers access to your data. Use a legitimate anti-spyware program to scan your computer and remove any of these files. Many anti-virus products have incorporated spyware detection.
  • Keep software up to date - Install software patches so that attackers cannot take advantage of known problems or vulnerabilities . Many operating systems offer automatic updates. If this option is available, you should turn it on.
  • Evaluate your software's settings - The default settings of most software enable all available functionality. However, attackers may be able to take advantage of this functionality to access your computer. It is especially important to check the settings for software that connects to the internet (browsers, email clients, etc.). Apply the highest level of security available that still gives you the functionality you need.
  • Avoid unused software programs - Do not clutter your computer with unnecessary software programs. If you have programs on your computer that you do not use, consider uninstalling them. In addition to consuming system resources, these programs may contain vulnerabilities that, if not patched, may allow an attacker to access your computer.
  • Consider creating separate user accounts - If there are other people using your computer, you may be worried that someone else may accidentally access, modify, and/or delete your files. Most operating systems (including Windows XP and Vista, Mac OS X, and Linux) give you the option of creating a different user account for each user, and you can set the amount of access and privileges for each account. You may also choose to have separate accounts for your work and personal purposes. While this approach will not completely isolate each area, it does offer some additional protection. However, it will not protect your computer against vulnerabilities that give an attacker administrative privileges. Ideally, you will have separate computers for work and personal use; this will offer a different type of protection.
  • Establish guidelines for computer use - If there are multiple people using your computer, especially children, make sure they understand how to use the computer and internet safely. Setting boundaries and guidelines will help to protect your data.
  • Use passwords and encrypt sensitive files - Passwords and other security features add layers of protection if used appropriately (see Choosing and Protecting Passwords and Supplementing Passwords for more information). By encrypting files, you ensure that unauthorized people can't view data even if they can physically access it. You may also want to consider options for full disk encryption, which prevents a thief from even starting your laptop without a passphrase. When you use encryption, it is important to remember your passwords and passphrases; if you forget or lose them, you may lose your data.
  • Follow corporate policies for handling and storing work-related information - If you use your computer for work-related purposes, make sure to follow any corporate policies for handling and storing the information. These policies were likely established to protect proprietary information and customer data, as well as to protect you and the company from liability. Even if it is not explicitly stated in your corporate policy, you should avoid allowing other people, including family members, to use a computer that contains corporate data.
  • Dispose of sensitive information properly - Simply deleting a file does not completely erase it. To ensure that an attacker cannot access these files, make sure that you adequately erase sensitive files
  • Follow good security habits - Review other security tips for ways to protect yourself and your data.
--------

Real-World Warnings Keep You Safe Online

Many of the warning phrases you probably heard from your parents and teachers are also applicable to using computers and the internet.

Why are these warnings important?

Like the real world, technology and the internet present dangers as well as benefits. Equipment fails, attackers may target you, and mistakes and poor judgment happen. Just as you take precautions to protect yourself in the real world, you need to take precautions to protect yourself online. For many users, computers and the internet are unfamiliar and intimidating, so it is appropriate to approach them the same way we urge children to approach the real world.

What are some warnings to remember?

  • Don't trust candy from strangers - Finding something on the internet does not guarantee that it is true. Anyone can publish information online, so before accepting a statement as fact or taking action, verify that the source is reliable. It is also easy for attackers to "spoof" email addresses, so verify that an email is legitimate before opening an unexpected email attachment or responding to a request for personal information
  • If it sounds too good to be true, it probably is - You have probably seen many emails promising fantastic rewards or monetary gifts. However, regardless of what the email claims, there are not any wealthy strangers desperate to send you money. Beware of grand promises—they are most likely spam, hoaxes, or phishing schemes. Also be wary of pop-up windows and advertisements for free downloadable software—they may be disguising spyware
  • Don't advertise that you are away from home - Some email accounts, especially within an organization, offer a feature (called an autoresponder) that allows you to create an "away" message if you are going to be away from your email for an extended period of time. The message is automatically sent to anyone who emails you while the autoresponder is enabled. While this is a helpful feature for letting your contacts know that you will not be able to respond right away, be careful how you phrase your message. You do not want to let potential attackers know that you are not home, or, worse, give specific details about your location and itinerary. Safer options include phrases such as "I will not have access to email between [date] and [date]." If possible, also restrict the recipients of the message to people within your organization or in your address book. If your away message replies to spam, it only confirms that your email account is active. This may increase the amount of spam you receive
  • Lock up your valuables - If an attacker is able to access your personal data, he or she may be able to compromise or steal the information. Take steps to protect this information by following good security practices . Some of the most basic precautions include locking your computer when you step away; using firewalls, anti-virus software, and strong passwords; installing appropriate patches; and taking precautions when browsing or using email.
  • Have a backup plan - Since your information could be lost or compromised (due to an equipment malfunction, an error, or an attack), make regular backups of your information so that you still have clean, complete copies (seeGood Security Habits for more information). Backups also help you identify what has been changed or lost. If your computer has been infected, it is important to remove the infection before resuming your work (see Recovering from Viruses, Worms, and Trojan Horses for more information). Keep in mind that if you did not realize that your computer was infected, your backups may also be compromised.

Keeping Children Safe Online

Children present unique security risks when they use a computer—not only do you have to keep them safe, you have to protect the data on your computer. By taking some simple steps, you can dramatically reduce the threats.

What unique risks are associated with children?

When a child is using your computer, normal safeguards and security practices may not be sufficient. Children present additional challenges because of their natural characteristics: innocence, curiosity, desire for independence, and fear of punishment. You need to consider these characteristics when determining how to protect your data and the child.
You may think that because the child is only playing a game, or researching a term paper, or typing a homework assignment, he or she can't cause any harm. But what if, when saving her paper, the child deletes a necessary program file? Or what if she unintentionally visits a malicious web page that infects your computer with a virus? These are just two possible scenarios. Mistakes happen, but the child may not realize what she's done or may not tell you what happened because she's afraid of getting punished.
Online predators present another significant threat, particularly to children. Because the nature of the internet is so anonymous, it is easy for people to misrepresent themselves and manipulate or trick other users. Adults often fall victim to these ploys, and children, who are usually much more open and trusting, are even easier targets. The threat is even greater if a child has access to email or instant messaging programs, visits chat rooms, and/or uses social networking sites

What can you do?

  • Be involved - Consider activities you can work on together, whether it be playing a game, researching a topic you had been talking about (e.g., family vacation spots, a particular hobby, a historical figure), or putting together a family newsletter. This will allow you to supervise your child's online activities while teaching her good computer habits.
  • Keep your computer in an open area - If your computer is in a high-traffic area, you will be able to easily monitor the computer activity. Not only does this accessibility deter a child from doing something she knows she's not allowed to do, it also gives you the opportunity to intervene if you notice a behavior that could have negative consequences.
  • Set rules and warn about dangers - Make sure your child knows the boundaries of what she is allowed to do on the computer. These boundaries should be appropriate for the child's age, knowledge, and maturity, but they may include rules about how long she is allowed to be on the computer, what sites she is allowed to visit, what software programs she can use, and what tasks or activities she is allowed to do. You should also talk to children about the dangers of the internet so that they recognize suspicious behavior or activity. The goal isn't to scare them, it's to make them more aware.
  • Monitor computer activity - Be aware of what your child is doing on the computer, including which web sites she is visiting. If she is using email, instant messaging, or chat rooms, try to get a sense of who she is corresponding with and whether she actually knows them.
  • Keep lines of communication open - Let your child know that she can approach you with any questions or concerns about behaviors or problems she may have encountered on the computer.
  • Consider partitioning your computer into separate accounts - Most operating systems (including Windows XP, Mac OS X, and Linux) give you the option of creating a different user account for each user. If you're worried that your child may accidentally access, modify, and/or delete your files, you can give her a separate account and decrease the amount of access and number of privileges she has.
If you don't have separate accounts, you need to be especially careful about your security settings. In addition to limiting functionality within your browser (see Evaluating Your Web Browser's Security Settings for more information), avoid letting your browser remember passwords and other personal information (see Browsing Safely: Understanding Active Content and Cookies). Also, it is always important to keep your virus definitions up to date (seeUnderstanding Anti-Virus Software).
  • Consider implementing parental controls - You may be able to set some parental controls within your browser. For example, Internet Explorer allows you to restrict or allow certain web sites to be viewed on your computer, and you can protect these settings with a password. To find those options, click Tools on your menu bar, select Internet Options..., choose the Content tab, and click the Enable... button under Content Advisor.
There are other resources you can use to control and/or monitor your child's online activity. Some ISPs offer services designed to protect children online. Contact your ISP to see if any of these services are available. There are also special software programs you can install on your computer. Different programs offer different features and capabilities, so you can find one that best suits your needs. The following web sites offer lists of software, as well as other useful information about protecting children online:
    • GetNetWise - http://kids.getnetwise.org/ - Click Tools for Families to reach a page that allows you to search for software based on characteristics like what the tool does and what operating system you have on your computer.
    • Yahooligans! Parents' Guide - http://yahooligans.yahoo.com/parents/ - Click Blocking and Filtering underRelated Websites on the left sidebar to reach a list of software.

Read More
Posted in Security Tips | No comments

Thursday, 8 July 2010

System Administration Tips

Posted on 10:25 by Unknown
System Administration Tips

Here you will learn some basic network administration tips, how to secure your computer network, basic troubleshooting guide, it management tools, security measures and basic network troubleshooting tips. The administration of a computer network is a very responsible task of the network administrators. There are certain administration tips if followed, the management becomes easy. Being a network administration you should know the basic network technologies such as TCP/IP, Ethernet, cabling system, basic network hardware, software, directory services and some basic network troubleshooting techniques.

Always document your network resources and configurations such as network hardware and software inventory, computers, basic network configurations, logon scripts. Also take a complete backup of your server’s data and manage the resources of network server in such as way that simultaneous access to the server does not affect the performance of the server.
Keep your network software inventory up to date and assure that you have these utilities such as data recovery tools, backup utilities, troubleshooting tools, TCP/IP ports and performance monitoring tools and up-to-date antivirus software

  

Make your network administrator’s password complex and also train an assistant network administrator. Keep an up-to-dated network security tool such as GFI LanGuard, which can prevent your network from any kind of internet or external security attack. Put a strict restriction in the server room and only authorized persons should be allowed to enter in the server room. Regularly take back of your critical data on other hard disks and write backup data on the CDs. After installing and configuring your server, take an image of your whole hard disk, with a good utility such as Norton Ghost. Always get ready an updated disaster recovery and fault tolerance plans. Do not leave the serve room unattended there must be someone responsible person present every time in the server room. Besides these general tips I have also provided list of the information tips

 

Following are the basic tips for administering a computer network.

1. If you are preparing a new system, make sure that you are using the best installation source such as an installation CD. After installing the operating system, also install up-to-date antivirus program such as Norton antivirus, Trend Micro, McAfee, Panda Antivirus or any other antivirus program of your choice.
2. After completing the installation process of all the networking computers, test your network for the performance, speed and security.
3. Keep your network design simple and segment your network in different sections so that it would be easy to isolate a faulty component of the network.
4. Regularly upgrade your network computers with the latest antivirus definitions, software patches and other security measures.
5. Purchase a planned hardware for your network and make a documentation of your hardware and software inventory.
6. Only install the required software applications on your server and networking computers. Any kind of unauthorized software or web based application can become source of viruses and other malicious codes from the internet.
7. Define network IP address, crate user accounts, create user material and keep the resources closer to the user.
8. Train your IT staff as well as all the users and warn them about any unauthorized activities.
9. Administer the access to the internet and put a tight security restriction on the unauthorized internet usage and block all the unwanted ports and web based application access.
10. Secure your gateway computer or proxy server as much as possible because gateway is directly exposed to the internet.
11. Mirror your hard disk.
12. Structure your network.
13. Being a network administrator, always research and test new network technologies and trends.

Also you must know the basic network technologies and troubleshooting tips. Do research and make a plan before setting up a network for your organization or clients. Always fill your resource kit with the data recovery software, backup utilities, up-to-dated antivirus programs, cable testers, cable cutter, cable connectors and other network security and troubleshooting tools. Also, keep yourself upgraded with the latest networking knowledge networking certifications such as MCSE, CCNA, CCNP, Network+, and Server+. Share your knowledge with your colleagues, IT managers and also reply the various networking troubleshooting and management related questions in the different forums on the internet. Hopefully this tutorial will provide you the basic understanding and insight of how to administer a computer network.


Read More
Posted in Windows Tips | No comments

Basic Security Tips

Posted on 10:12 by Unknown

Basic Security Tips

This basic Network Security Guide provides useful security tips and methods to secure your network such as installing a updated antivirus program, email scanning programs, network monitoring tools, internet access policy and other security prevention methods. Network security is a very important aspect of a computer network. Minor security vulnerability can result in a heavy loss of the critical data of your server and other client computers. Keeping the computer as well as network secure, is the big responsibility of the network administrator and the security specialists. There are lot of security measures and prevention methods which I will discuss in this section. Typically a computer network can be attacked by a number of ways such as virus attacks, unauthorized access, cryptography attacks and a number of other security threats.
A network security threat can be prevented if you have an updated antivirus program, regularly scan all the network devices, emails, open ports, server and client computers. It’s the responsibility of the network administrators to check and deploy the missing security patches in all the network computers. They should also remove the unnecessary network shares, users accounts, wireless access points and restrict the access too the network users. There should be proper training of the network users, network administrators and IT managers about the vulnerable things that cause a network to be attacked. A network administration of an organization should be highly skilled person and have much experience in network/system administration as well as dealing with the security issues.
Security Threats
There are a number of security threats that can be the cause of a network security attack. Main security threats are denial of service, distributed denial of service, viruses, Trojan horses, spywares, malwares, unauthorized access to the network resources and data, accidental deletion of the files and the uncontrolled internet access.
Virus Attack
A computer virus is a small program or an executable code that when executed and replicated, perform different unwanted and harmful functions for a computer and a network. Viruses can destroy your hard disks and processors, consume memory at a very large scale and destroy the overall performance of a computer or network. A Trojan is a malicious code that performs harmful actions but it cannot be replicated. Trojan can destroy systems’ critical data. A computer worm is a program that replicates to all network and destroy useful data. The viruses, malware, adware and Trojan horses can be prevented if you have an updated antivirus program with the latest pattern files.
Security policy
Being a network administrator, you should implement a security policy in your network and educate your network users and other employees about the security threats.
Email scanning
Email is a big source of a virus and malicious code. You should have installed an email scanning and monitoring program. You should also have a tight security policy at your proxy server and should block the unnecessary ports and web applications.
Unauthorized Access
Access to the network resources and data should be allowed only to the authorized persons. Every shared folder and resources in your network should have been accessed only by the authorized persons and should also be scanned and monitored regularly.
Accidental deletion of the files
What will you do if you accidentally delete your organization’s critical data? This is a question, which every network administrator and security specialists thinks of and wants answer. Few days before I read on internet news site that a computer technician accidentally deleted a financial company’s $ 10 billions records. To avoid the big troubles like this for you and for your company, you should have excellent data recovery software in your software inventory. Many data recovery tools are good enough to recover every piece of data if the hard disk is not physically badly damaged.
Network Monitoring Tools
You must have a good network monitoring tools to detect various suspicious things and monitor the various activities in your network such as network traffic, open ports, useless shared folders. GFI LanGuard Network security scanner is a good scanning and monitoring tool and it checks for all the possible methods, which a hacker can use to attack your network.
Internet Access Control
Internet can be a big source of viruses and the major security attacks, if you are unable to implement a tight security policy in your network, if you have a old definition anti virus program and if your haven’t put any check on your network user’s activity. Your gateway or proxy server, which is directly exposed to the internet should have very tight security, updated antivirus program and network monitoring tools.
Information Theft and cryptography attacks
Another threat to a network is to loss of the important information and this loss can be prevented, if you good encryption methods such as 128 bit security or 256 bit security encryption methods. In this way, your data when transferred through FTP programs, can be encrypted and can’t be read or use.
Unauthorized application installations
Another virus and security attack prevention method is to install only the authorized software applications to your network server and your all client computers. Nobody should be allowed to install any kind of program which can cause security threats such as songs or video programs, codec, gaming software or other web based applications.
Security Conclusion:
I tried to point out the major security threat prevention methods also provided the solutions to avoid them. There are a number of ways, which guarantee for the safety and security of your network.
I have summarized the all these method as below.
1. Perform regular network security testing.
2. Don’t provide more or unwanted access to any network user.
3. Must have an updated antivirus program.
4. Operating system should be regularly updated. If you have windows based operating system you can update it from the Microsoft website.
5. Keep inventory of your network resources such as devices and software applications.
6. Regularly scan TCP/IP services
7. Turn off your computer when you are away and don’t leave your computer unattended.
8. Put a strong network and system administrator password.
9. Implement a strong security policy.
10. Use a switched network, so that you can identify the problem very quickly.
Read More
Posted in Security Tips | No comments

common security issues for non-technical computer users

Posted on 10:04 by Unknown


General information
  • Why is Cyber Security a Problem?
  • Guidelines for Publishing Information Online
  • Understanding Internet Service Providers (ISPs)
General security
  • Choosing and Protecting Passwords
  • Understanding Anti-Virus Software
  • Understanding Firewalls
  • Coordinating Virus and Spyware Defense
  • Debunking Some Common Myths
  • Good Security Habits
  • Safeguarding Your Data
  • Real-World Warnings Keep You Safe Online
  • Keeping Children Safe Online
Attacks and threats
  • Dealing with Cyberbullies
  • Understanding Hidden Threats: Corrupted Software Files
  • Understanding Hidden Threats: Rootkits and Botnets
  • Preventing and Responding to Identity Theft
  • Recovering from Viruses, Worms, and Trojan Horses
  • Recognizing and Avoiding Spyware
  • Avoiding Social Engineering and Phishing Attacks
  • Understanding Denial-of-Service Attacks
  • Identifying Hoaxes and Urban Legends
  • Avoiding the Pitfalls of Online Trading
Email and communication
  • Understanding Your Computer: Email Clients
  • Using Caution with Email Attachments
  • Reducing Spam
  • Benefits and Risks of Free Email Services
  • Benefits of Blind Carbon Copy (BCC)
  • Understanding Digital Signatures
  • Using Instant Messaging and Chat Rooms Safely
  • Staying Safe on Social Network Sites
Mobile devices
  • Protecting Portable Devices: Physical Security
  • Protecting Portable Devices: Data Security
  • Using Caution with USB Drives
  • Securing Wireless Networks
  • Cybersecurity for Electronic Devices
  • Defending Cell Phones and PDAs Against Attack
Privacy
  • How Anonymous Are You?
  • Protecting Your Privacy
  • Understanding Encryption
  • Effectively Erasing Files
  • Supplementing Passwords
Safe browsing
  • Understanding Your Computer: Web Browsers
  • Evaluating Your Web Browser's Security Settings
  • Shopping Safely Online
  • Browsing Safely: Understanding Active Content and Cookies
  • Understanding Web Site Certificates
  • Understanding Internationalized Domain Names
  • Understanding Bluetooth Technology
  • Avoiding Copyright Infringement
Software and applications
  • Understanding Patches
  • Understanding Voice over Internet Protocol (VoIP)
  • Risks of File-Sharing Technology
  • Reviewing End-User License Agreements
  • Understanding Your Computer: Operating Systems

Read More
Posted in Security Guidelines, Security Tips | No comments

Today New MM 6.6 Service Pack 4 is released & available in the follg link.

Posted on 05:37 by Unknown
Pl download it & upgrade in ur all systems. Becoz, many validations incorporated for MO Videsh & NPS etc is available.

PTC Download
Read More
Posted in | No comments

Monday, 5 July 2010

KIND ATTENION SYSTEM ADMINISTRATORS

Posted on 10:27 by Unknown
Dear Comrades,
  
                                   An extract from the recent quote in our NFPE Blogspot is quoted below:

BABU TARAPADA MUKHERJEE IN HIS HISTORIC SPEECH AT LAHORE CONFERENCE OF ALL INDIA POSTAL AND  RMS UNIONS ON 09.10.1921 , STATED:
                                    ___________________________________________

"TAKE IT FROM ME, BROTHERS, THAT PETITIONS AND MEMORIALS AND SUPPLICATIONS WILL COUNT FOR NOTHING SO LONG AS YOU DO NOT ORGANISE YOUR SELF IN A MANNER TO CONVINCE  THE GOVERNMENT THAT YOU WILL NO LONGER STAND NONSENSE"
                        ________________________________________________________
LET US ORGANISE IN SUCH A WAY THAT       FROM JULY13th ONWARDS THE ENTIRE     POSTAL AND RMS OFFICES COME TO A STANDSTILL



                                     Yes Comrades we have to make this historic event happen on 13th July 2010. Let this 13 July 2010 strike of postal employees be a resounding success and let us engrave it in the history of the Postal employees’ movement in their fight against the draconic economic policies of the Government which has a severe impact on the Postal Services.
                           In this context I have been frequently been contact over email and mobile phone about the progress on the demand of System Administrator’s after serving the strike notice.  To all of you, one fact you have to remember that the Department and the Government will understand only one language that is our united movement which has culminated into an indefinite strike. Only after a united movement we can expect some progress on the demand. Hence don’t have any illusion that our Union leaders are having a magical stick and just by swinging the stick everything will happen. Only our tempo to agitate will strengthen their hands. Hence everything is in your hands and each and every individual has to contribute. First ask yourself that what you have contributed and then ask about others.
                      Recently I had the opportunity to speak to our newly elected Secretary-General Com.Krishnan when he came to Chennai to participate in the Felicitation function of the outgoing Secretary-General Com.K.Ragavendran. During that interaction our NFPE-P3 General Secretary Com.K.V.Sridharan was also present. For those who are asking about progress and updates about the System Administrator’s demand here it is as follows.

1.    ACCENTURE HAS SUBMITTED ITS PROPOSAL ON IMPLEMENTING TECHNOLOGY IN OUR DEPARTMENT.
2.    ACCORDINGLY FUNDS HAVE BEEN ALLOTTED TO GO AHEAD WITH THE PROPOSAL GIVEN BY ACCENTURE.
3.    THE ALLOCATIONS OF FUNDS AND GOING AHEAD WITH THE PROPOSAL IS AWAITING A FORMAL APPROVAL FROM GROUP OF MINISTERS AS THE FUND OF MORE THAN 2000 CRORES IS NOT WITHIN THE POWERS OF THE NODAL MINISTRY.
4.    PROPOSAL FOR CREATION OF SYSTEM ADMINISTRATORS CADRE WITH GAZETTED RANK IN PAY BAND 2 WITH GRADE PAY RS.5400 is already sent to by DOP for Finance Ministry clearance.
5.    AFTER CLERANCE FROM FINANCE MINISTRY IT WILL GO TO DEPARTMENT OF PERSONNAL AND TRAINING (DOPT) FOR FRAMING RECRUITMENT RULES.


Now comrades, in the recent meeting with the Member (Technology) by the newly elected officer bearers of NFPE Federation the above information was revealed. The entire process is in the final phase and it is expected to be completed within two months. Still the Member (Technology) Mr.Samant repeats what he said in the Delhi Seminar
“The contributions of the existing System Administrators will not go unrecognized”

No details has been revealed by the Member (technology) about the following aspects
1.    Whether the existing System Administrators will find a place in the newly created cadre ?
2.    How many Posts will be created ?
3.    What is the actual meaning about the Member (tech) saying that we will not be unrecognized ?

                   Above questions still remain unanswered. As unanimously decided in our Seminar the Ball is rolling in the direction in which we all wished, but whether we will be benefited out of that still remains a BIG question.
      I request our comrades to bear this in your mind and participate intensively in the upcoming strike.  Department may have hidden plans about massive outsourcing of the jobs of the System Administrators.
      DO NOT RESORT TO MASSIVE REVERTING FROM SYSTEM ADMINISTRATORS TO PAs. Our leaders are also having an opinion that such a measure is not advisable as it will be like quitting the struggle in the middle. Hence whatever comes let us struggle till the end. Only our whole-hearted struggle till the end will render success. It will be tough journey and there will be many occasions where we may have to enter into tough fight with the department. HENCE DON’T LOOSE HEART. WE WILL UNITEDLY FIGHT FOR OUR JUSTICE. AFTER ALL IT WAS OUR OWN DEMOCRATIC DECISION IN OUR DELHI SEMINAR TO STRUGGLE TILL THE END.

WITH REVOLUTIONARY GREETINGS AND RED SALUTE TO ALL THE FIGHTING SYSTEM ADMINISTRATORS.

R.SENTHIL KUMAR
SYSTEM ADMINISTRATOR
TAMIL NADU CIRCLE

NOTE: WHO EVER IS NOT RECEIVING THIS EMAIL PLEASE SEND A TEST MAIL QUOTING YOUR CIRCLE NAME AND DIVISION. THOSE WHO RECEIVE THIS EMAIL PLEASE FORWARD TO YOUR COLLEAGUES WHO ARE ALSO SYSTEM ADMINISTRATORS OF DOP AND IF Y OU HAPPEN TO HAVE A LOCAL BLOG WEBISTE PLEASE PUBLISH THIS EMAIL FOR EVERYONE TO VIEW
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • How to watch online TV?
    I know we all are busy with our daily work, we do not have to time to tally our accounts or do our regular work also. Some times we want to ...
  • Pen Drive Recovery Tool
    Find below the Online recovery tool for the Transcend pendrives. A very good tool to recover the data or format the corrupted pendrives. 1) ...
  • GDS COMMITTEE IMPLEMENTATION ORDERS RELEASED BY DIRECTORATE TODAY
    GDS COMMITTEE IMPLEMENTATION ORDERS RELEASED BY DIRECTORATE TODAY POSTAL DIRECTORATE ISSUED ORDERS TODAY FOR IMPLEMENTING THE GDS COMMITTEE ...
  • Commands in Windows Vista
    Windows Vista Command Line List and Reference The list of commands available in the command line shell for Windows Vista is similar to that ...
  • Speednet Communication problem
    At the very outset, confirm the following and then proceed with further instructions. • Login to www.indiapost.gov.in/spc site and confirm t...
  • Top 10 security enhancements in SQL Server 2005
    As database systems continue to be more widely used to back stores of networked applications, it is increasingly necessary to focus on secur...
  • IMPORTANT WEBSITES
    Links to some useful websites India Post: Speed Post Track http://www.indiapost.gov.in/Speednew/Track.aspx PIN C...
  • MailStore Home- Keep all your mails in one place
    We have been  using computers  for quiet some time and of course emails too.  You might have created  number  of email accounts with various...
  • Indian Acronyms and Abbreviations
    A A.A.F. – Auxiliary Air Force A.A.O.U. – Asian Association of Open Universities A.C.D. – Asian Co-operation Dialogue A.D.B. – Asian Develop...
  • Net Monitor
    Net Monitor is a good software to use in our local training centers, this software allows us to see screens of computers connected to the n...

Categories

  • Computer Guidelines
  • Customer Care
  • DB Tools
  • Drivers
  • Entertainments
  • FAQ
  • For System Administrators
  • FTP
  • General Informations
  • General Knowledge
  • Guidelines
  • Hardwares
  • Health Tips
  • Internet Tips
  • Latest Software Updates
  • Network Trouble shooting
  • Printer Trouble shooting
  • Printing Tips
  • Recovery Tips
  • Registry Tips
  • Registry Tools
  • Security Guidelines
  • Security Tips
  • Software Tips
  • Softwares
  • SQL
  • Technology
  • Tips and Tricks
  • Tools
  • Trouble shooting
  • Useful Softwares
  • Utilities
  • Virus Solutions
  • Websites
  • windows 7
  • Windows Server
  • Windows Tips
  • Windows Vista
  • Windows XP FAQ

Blog Archive

  • ▼  2011 (138)
    • ▼  May (32)
      • Indian Acronyms and Abbreviations
      • Put all your Emails on a USB Drive for Offline Access
      • What is the difference between Cc and Bcc?
      • BSNL 3G Data Card Now at Rs. 1600
      • General Knowledge Questions and Answers
      • 5 Tips to Improve Your Windows 7 System’s Speed
      • SYS Informer v.1.0 Free ( PC Total Info)
      • 7Burn - Burning Studio v.2.0 Free
      • Steganography
      • Screen Resolution Changer
      • MailStore Home- Keep all your mails in one place
      • 5 Simple Tips to Fix a Slow Computer
      • Password Recovery Magic Products with Serial
      • Hiren’s Boot CD 13.2
      • Prime Minister and Council of Ministers - India ( ...
      • Put all your Emails on a USB Drive for Offline Access
      • Best Features of Google Chrome
      • What is the difference between Cc and Bcc?
      • Any Folder as a Photo Folder
      • SQL 2008 Express Editions and Service Packs
      • Put all your Emails on a USB Drive for Offline Access
      • Why Do We Love Skype?
      • Procedure for Schedule Backup in SQL 2008 Express ...
      • How to Make EXE Files Using Notepad
      • How to Protect your Data ?
      • Error in Opening database - Tables ( SQL 2000)
      • Icons, task bar disappears and Windows Explorer do...
      • Tips for Strong Password
      • Disable Network Search by XP
      • How To Change the Default Backup Path in SQL Server
      • How to Manually Uninstall SQL Server 2005
      • XP Services-Not Needed for All
    • ►  April (24)
    • ►  March (29)
    • ►  February (15)
    • ►  January (38)
  • ►  2010 (241)
    • ►  December (55)
    • ►  November (40)
    • ►  October (21)
    • ►  September (35)
    • ►  August (39)
    • ►  July (23)
    • ►  June (5)
    • ►  May (2)
    • ►  April (12)
    • ►  March (4)
    • ►  February (2)
    • ►  January (3)
  • ►  2009 (26)
    • ►  December (5)
    • ►  November (3)
    • ►  October (4)
    • ►  September (5)
    • ►  August (3)
    • ►  July (5)
    • ►  June (1)
Powered by Blogger.

About Me

Unknown
View my complete profile