Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Saturday, 3 January 2009

Update Vulnerable Programs

Secunia is a respected security service provider that tracks vulnerabilities in more than 20,000 applications and operating systems. To find information about the latest vulnerabilities, you could subscribe to Secunia's mailing lists, but if you want to know whether there are known security issues for the software installed in your computer, install Secunia Personal Security Inspector.

The Windows application scans your computer and it lists the insecure programs, information about vulnerabilities and links to the patches. In most cases, Secunia provides direct links to the latest updates, so they are easy to download and install. To find more information about security problems and to list all the software from your computer that needs to be updated, switch to the advanced interface.


Secunia collected data from 20,000 users of the software and found at least one vulnerability in 98.09% of the cases. "By insecure program it is understood, that there is a newer version of the program available from the vendor that corrects one or more vulnerabilities, but the user has yet to install the secure version. A vulnerability in a program can be exploited by hackers to anything from compromising a PC, to automatically install trojans/viruses, to sniff out private information (passwords, credit cards information, etc)."

Not all applications include auto-update and users have to manually update to the latest versions. Google is one of the companies that thinks it's important to update software without any user intervention, that's why most Google software has an auto-update feature or is integrated with Google Update.

Secunia's software focuses on updates that solve security problems. More comprehensive solutions for updating your software include UpdateStar, FileHippo Update Checker and Appget, but none of them is very reliable.



Thursday, 24 July 2008

Force Gmail to Always Use Secure Connection

Gmail rolls out a new option that lets you set the https version as default. If you go to the Settings and select "always use https", Gmail will automatically redirect to the secure version. Until now, you had to manually type https://mail.google.com in the address bar, bookmark the address or use a Greasemonkey script.


"If you sign in to Gmail via a non-secure Internet connection, like a public wireless or non-encrypted network, your Google account may be more vulnerable to hijacking. Non-secure networks make it easier for someone to impersonate you and gain full access to your Google account, including any sensitive data it may contain like bank statements or online log-in credentials. We recommend selecting the 'Always use https' option in Gmail any time your network may be non-secure," explains Google.

Read, for example, David Pogue's post about Wi-Fi eavesdropping. "All Jon needed [to read my mail] was a packet sniffing program; such software is free and widely available. (He used a Mac program called Eavesdrop.) It sniffs the airwaves and displays whatever data it finds being transmitted in the public hot spot."

Https is typically used for sites that deal with sensitive data, so you'll see it when you authenticate to sites like Google or Facebook and when you use your mobile banking account, PayPal, Google AdWords and a handful of similar sites. The benefit is that the connection between your browser and the remote servers is encrypted and nobody could capture the sensitive data.

"We use https to protect your password every time you log into Gmail, but we don't use https once you're in your mail unless you ask for it (by visiting https://mail.google.com rather than http://mail.google.com). Why not? Because the downside is that https can make your mail slower. Your computer has to do extra work to decrypt all that data, and encrypted data doesn't travel across the internet as efficiently as unencrypted data," says the Gmail blog.

In addition to the worse performance, Google also mentions that the mobile application could show errors if you don't enable 'Always use secure network connections (slower performance)' in the app's settings section. If you use Firefox, don't forget to disable the Greasemonkey scripts that redirect Gmail to the secure version and to deactivate the similar option from Firefox extensions like Better Gmail and CustomizeGoogle.

The good news is that you don't need a similar setting for other Google applications if you use the navigation bar: Google automatically links to the secure versions of Google Calendar, Google Docs, Google Reader and Google Sites. If you don't see the new option in Gmail's settings, you have to wait until Gmail enables it in your account.


Monday, 7 July 2008

Find Who Has Access to Your Gmail Account

After years of testing, Gmail has finally added a very useful security feature: tracking open sessions. If you log in to Gmail from more than one computer and you forget to sign out, you'll be able to see the list of locations where your account can still be accessed.


Until now, the only solution when you forgot to log out from Gmail after using a public computer was to change your password. Otherwise, anyone could access your account without knowing the password. Now you can sign out remotely from all the locations where your Gmail account is still open.

If you click on "Details" in Gmail's footer, you'll find a lot of interesting information about your sessions. "The top table, under Concurrent session information, indicates all open sessions, along with IP address and access type -- which refers to how email was retrieved, for example, through iGoogle, POP3 or a mobile phone. The bottom table, under Recent activity, contains my most recent history along with times of access. I can also view my current IP address at the very bottom of this window, where it says This computer is using IP address...".


This could be useful if you want to find whether someone else has access to your account: you'll be able to find the IP address and the date of the most recent activity in your account.

Gmail's blog mentions that this feature is currently being rolled out in the new version of Gmail, so you may not see it right now. Google AdSense, PayPal and orkut are three other services that show the time of your last login so you can protect against abuse, but Gmail's new feature is much more advanced.

Among the things you can do to protect your Gmail account, it's a good idea to sign out after reading your email, not to select "remember me" when you log in from a public computer and to choose a good password that should remain secret.

Friday, 23 May 2008

Google Anti-Malware Diagnostic Pages

ZDNet's security blog points to an update to Google's malware warnings. Like McAfee SiteAdvisor, now each web site has a special diagnostic page that lists answers to four questions:

1. What is the current listing status?
2. What happened when Google visited this site?
3. Has this site acted as an intermediary resulting in further distribution of malware?
4. Has this site hosted malware?

Here's, for example, the diagnostic page for google.com: http://www.google.com/safebrowsing/diagnostic?site=google.com, which lists some interesting facts.

"Of the 274621 pages we tested on the site over the past 90 days, 4 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 05/22/2008, and the last time suspicious content was found on this site was on 03/13/2008. Malicious software includes 4 scripting exploit(s), 4 trojan(s). Successful infection resulted in an average of 10 new processes on the target machine. Malicious software is hosted on 4 domain(s), including 58.65.239.0, truemaybe.com, abc-powers.com. 5 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including xtraff.biz, x-traffic.ws, smartvideochannel.com."

Despite all of these findings, google.com is not listed as suspicious, probably because the domain is whitelisted or the suspicious content is not very significant. It's likely that the domains listed above are from Google's search results, so that means the anti-malware system doesn't respect robots.txt.

Sunday, 20 April 2008

Google Phishing Warning

After flagging search results that distribute malware, Google will also show warnings for web pages used for phishing. Most of these pages are active one or two days before they are taken down by hosting providers, but some of them could be indexed by search engines. While the latest versions of Internet Explorer, Firefox and Opera have anti-phishing protection, a new security layer still have some usefulness.

"Warning - phishing (web forgery) suspected. The site you are trying to visit has been identified as a forgery, intended to trick you into disclosing financial, personal or other sensitive information," mentions the page displayed by Google instead of the search result.


Google also has a Safe Browsing API "that enables client applications to check URLs against Google's constantly updated blacklists of suspected phishing and malware pages." The API is used by Firefox and Google Desktop.