,

Your IP Address

what is my ip address?
Showing posts with label Computer Security. Show all posts
Showing posts with label Computer Security. Show all posts

Some Important Security Tips for Internet banking:

Universal Defense:
§  Never logon to Internet Bank by an email link. Remember Bank couldn’t send you email with logon link.
§  Never logon to your net bank account on public computer.
§  Check that the padlock at the bottom of the page shows which you are safe and secure websites.
§  Never answer to email that asks for your personal credit card/debit card or account number and password. No bank will ask you for these specifics in an email.
§  Always use your Bank Account through typing Bank sites directly. If you don’t know the bank site, go and contact your bank personally they provide you all the details.
§  If somebody call you as introduce them as Bank Employee and ask your bank account details, never expose them and report this to your bank personally.
§  If you fall casualty to an attack, act instantly to protect yourself. Alert your bank about the casualty.
§  Avoid opening you bank account on public computer or cyber café. If it’s so urgent then change the password immediately when you reach your home computer.
Password Related Tips:
§  Avoid you and your family name in password.
§  You login name and password should be different.
§  Avoid Dictionary words in language because Hacker can guess your password through firing dictionary attacks.
§  Make your password Lengthy. Your password should be eight or more than eight characters.
§  Avoid Sequences or repeated characters – “123456” or “2222222”.
§  Combine your passwords with Letters, numbers, as well as symbols. Use both upper and lower characters.
§  Use the whole keyboard in your password. Don’t use most common characters.
§  Don’t reveal your password to others.
§  Avoid using online password storage.
§  Never written down the password to some notes, if this notes is lost then it’s easy for somebody to guess your future password according to your past password.
§  Don’t use password which is similar to your computer or other social networking sites because it’s easy to steal password from your computer and social networking sites.
§  Upgrade your antivirus and browser to new one.
§  While doing net banking, change your browser type to “private browsing”. This will delete your all cookies and files from your computer. All leading browser have this facility such as Internet Explorer, Mozilla Firefox, as well as Apple Safari.
§  Follow the bank policy, change your password every time when they promoted or you change your password every 10 days.
Read more

Top 10 Password Crackers

#1
Cain and Abel : The top password recovery tool for Windows
UNIX users frequently smugly assert that the best free security tools support their platform first, as well as Windows ports are frequently an afterthought. They are usually right, but Cain and Abel is a glaring exception. This Windows-only password recovery tool handles an enormous variety of tasks. It can recover passwords through sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols.


#2
John the Ripper : A powerful, flexible, as well as quick multi-platform password hash cracker
John the Ripper is a quick password cracker, currently available for lots of flavors of Unix (11 are officially supported, not counting unique architectures), DOS, Win32, BeOS, as well as OpenVMS. Its primary purpose is to detect weak Unix passwords. It supports several crypt(3) password hash kinds which are most commonly found on various Unix flavors, as well as Kerberos AFS and Windows NT/2000/XP LM hashes.


#3
THC Hydra : A Fast network authentication cracker which support lots of services
When you must brute force crack a remote authentication service, Hydra is frequently the tool of choice. It can perform rapid dictionary attacks against more then 30 protocols, including telnet, ftp, http, https, smb, several databases, as well as much more.


#4
Aircrack : The fastest available WEP/WPA cracking tool
Aircrack is a suite of tools for 802.11a/b/g WEP and WPA cracking. It can recover a 40 through 512-bit WEP key once enough encrypted packets have been gathered. It can also attack WPA one or two networks using advanced cryptographic methods or through brute force. The suite includes airodump (an 802.11 packet capture program), aireplay (an 802.11 packet injection program), aircrack (static WEP and WPA-PSK cracking), as well as airdecap (decrypts WEP/WPA capture files).


#5
L0phtcrack : Windows password auditing and recovery application
L0phtCrack, also known as LC5, tries to crack Windows passwords from hashes which it can obtain (given proper access) from stand-alone Windows NT/2000 workstations, networked servers, primary domain controllers, or Active Directory. In some cases it can sniff the hashes off the wire. It also has numerous methods of generating password guesses (dictionary, brute force, etc). LC5 was discontinued through Symantec in 2006, but you can still get the LC5 installer floating around. The free trial only lasts 15 days, as well as Symantec will not sell you a key, so youll either need to cease using it or get a key generator. Since it is no longer maintained, you are likely better off putting forth effort Cain and Abel, John the Ripper, or Ophcrack instead.


#6
Airsnort : 802.11 WEP Encryption Cracking Tool
AirSnort is a wireless LAN (WLAN) tool that recovers encryption keys. It was developed next to the Shmoo Group and operates through passively monitoring transmissions, computing the encryption key when enough packets have been gathered. You may also be interested in the similar Aircrack.


#7
SolarWinds : A plethora of network discovery/monitoring/attack tools
SolarWinds has created and sells dozens of special-purpose tools targeted at systems administrators. Security-related tools include lots of network discovery scanners, an SNMP brute-force cracker, router password decryption, a TCP connection reset program, one of the fastest and easiest router config download/upload applications available and more.


#8
Pwdump : A window password recovery tool
Pwdump is able to extract NTLM and LanMan hashes from a Windows target, regardless of whether Syskey is enabled. It is also capable of displaying password histories if they are available. It outputs the data in L0phtcrack-compatible form, as well as can write to an output file.


#9
RainbowCrack : An Innovative Password Hash Cracker
The RainbowCrack tool is a hash cracker that makes use of a large-scale time-memory trade-off. A traditional brute force cracker tries all possible plaintexts one through one, which can be time consuming for intricate passwords. RainbowCrack uses a time-memory trade-off to do all the cracking-time computation in advance and store the results in so-called "rainbow tables". It does take a lengthy time to precompute the tables but RainbowCrack can be hundreds of times faster than a brute force cracker once the precomputation is finished.


#10
Brutus : A network brute-force authentication cracker
This Windows-only cracker bangs against network services of remote systems putting forth effort to guess passwords through using a dictionary and permutations thereof. It supports HTTP, POP3, FTP, SMB, TELNET, IMAP, NTP, as well as more.
Read more

Stop net send spammers...

If you are getting net send spam (unwanted message boxs) then you can stop this through right clicking "my computer" goto manage, goto services and applications > services, then locate the service called "messenger", go to its properties and disable it in the drop down menu and apply. This is not msn/windows messenger, this just block incoming net send messages through dos and will stop net send spammers. cheers
Read more

Testing Your System's Security

This is not really a tweak, but simply a list of websites, which offer online method security testing. If you have a firewall, you can see now if its secure enough.

Remember, hackers always get a way into your method if they want!

http://grc.com/

http://hackerwhacker.com/

http://scan.sygatetech.com/

http://www.testmyfirewall.com/

http://www.auditmypc.com/

http://www.iggyz.com/Test.html

http://online.securityfocus.com/cgi-bin/sfonline/links.pl?cat=43&offset=60

There are more, but I think this will be sufficient at the moment. Happy testing!
Read more

Setting Up & Using SpywareBlaster

The first thing you must do is download and install SpywareBlaster, you can download it from HERE.

SpywareBlaster doesn’t remove spyware/malware, it prevents it from installing in the first place. From the makers of SpywareBlaster:

Prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, as well as other potentially unwanted pests.
Block spyware/tracking cookies in Internet Explorer and Mozilla/Firefox.
Restrict the actions of potentially dangerous sites in Internet Explorer.

It is very simple to use and it’s FREE. First you must download and install it, you can download it from HERE. Once you have installed it you must update it and then set it to protect you from its database of spyware/malware.

To update it click on the icon it placed on your desktop, make sure you are connected to the net and select Updates, then click the button Check for Updates this will immediately download new updates to its database. Once they are finished downloading click Protection and under Quick Tasks click Enable All Protection, this sets all the new updates you just downloaded so which you are protected from them – THIS MUST BE DONE AFTER ANY NEW UPDATES.
Read more

Setting Up & Using Ad-Aware SE

The first thing you must do is download Ad-Aware SE Personal from HERE. Once you have downloaded and installed it you must update it and customize the scanning properties so that it scans more thorough.

Once its installed click on the icon on your desktop and open it to the main screen. You will must be online to update it, so if you are using a 56K connection you must first link to your ISP. Now click were it says “Check for updates now”, this will link you to Lavasoft’s servers and update your definitions. This is the same as updating your antivirus definitions.

Now that everything is up to date you must customize your scanning properties to get the best protection.

Now which you are at the main screen click the “Scan now button, this will take you to a screen that says Select a scan mode:, select "Customize" and check "Scan within archives" then "Proceed". Then select "Select" and check all of your drives, "Scan volume for ADS" should be checked now. Now just select "Next".

Ad-aware should now be scanning ALL of your drives for a know spyware/malware in its database. Once it has finished scanning it will give you list of everything that it found, REMOVE ALL THAT IT FINDS. Place your cursor on the list of items it finds and right click with your mouse and choose “select all then click “remove selected items. This will remove all spyware/malware from your pc. If Ad-aware prompts you to scan on your next reboot you should do so, this may happen because some spyware/malware is in use during the scan and could not be removed properly, Ad-aware will then schedule a boot time scan and remove these items on your next reboot.
Read more

Setting File permissions on XP Home

There's a tweak listed on the site for getting XP Pro security settings on XP Home. It's good, but I've found an easier way to set sharing permissions on folders. You can use the GUI instaed of the more complicated command line without having to go into safe mode.
1. Click on the start button
2. Then run
3. Type shrpubw
4. Chose the folder whose permissions you want to change and give the share a name
5. Click next, now you can chose custom if you want to have full options.

Quick Tip: In order to set file permission in windows XP Home, the file system must already be converted to NTFS. For more information on how to convert your file system, click here.
Read more

Setting Administrator password(The easy way)

Okay, Well this is very easy and does not involve rebooting or logging off, BUT it requires Administrative Access.

#1. Open up Command Prompt.

#2. mode in "net user Administrator (Password goes here)" (Without the quotes, And put in a password in place of the "(Password goes here)") So lets say you want to set the password to "computers", You would then mode in: net user Administrator computers Simple as that! And doesnt involve rebooting!

Happy tweaking!
Read more

Security Dump files tweak & disable dr.watson

Heed the following from PC Magazines site:

" Dump file. A dump file stores data from memory during a method crash and can be helpful when diagnosing problems, but such as a swap file, it can also expose a bunch of sensitive, unencrypted data. To prevent Windows from creating the file, go to Control Panel | System. Click on the Advanced tab and then the Settings button on the Startup and Recovery pane. Set the drop-down menu under Write debugging information to (none).

"Similarly, the debugging program Dr. Watson saves information when applications crash. To disable it, go to HKEY_local_machinesoftwareMicrosoftWindowsNT
CurrentVersion AeDebug and set the Auto string to 0. Then use Windows Explorer to go to Documents and Settings
All UsersShared DocumentsDrWatson. Delete User.dmp and Drwtsn32.log, the insecure logs the program creates."

Heed related advice from microsoft regarding Disable Dr.Watson first before the preceding Dr. Watson advice (go Google search.)

Back up with System Restore, as well as go ahead. As cautious as I am, I have gladly applied these tweaks, as well as followed related microsot advice on Dasrat Rai
Read more

Security Disabling services, Posix, and OS/2

Heed the following from Winguides website:

"Disable OS/2 and POSIX Subsystems (Windows 2000/XP)
To conserve method resources you may want to prevent the Windows session manager (SMSS) from loading optional subsystems, like OS/2 or POSIX. This tweak can be used to disable these optional subsystems.

"Warning: Make sure you use REGEDT32 to changes this value. Using Regedit may cause the method to crash.
Open your registry using REGEDT32 and get the key below.

"When the OS/2 and Posix sub-systems are enabled the value called "Optional" will be set to "Posix" or "OS2 Posix". To disable those sub-systems double-click on the "Optional" value and delete the "Posix" data in the window.

"Restart Windows for the change to take effect.

"Note: The benefits of not loading these subsystems can be increased memory and method resources."

Heed also the following from PC Magazines website:

" POSIX. Windows XP still ships with a subsystem called POSIX, which allows the use of Unix commands. Disabling POSIX prevents hackers from using Unix commands against your system. Go to Run and mode regedt32 (not regedit). Find HKEY_ local_machinesystemcurrentcontrolsetControlSession ManagerSubSystems and click on the multistring called Optional in the right-hand pane. By default, the multistrings value will be POSIX; delete that value and leave the space empty (but do not delete the Optional multistring). Then click on the actual POSIX multistring in the same pane. Note that it points to a file in your Windows System32 directory called Psxss.exe. Delete that file using Windows Explorer, use the Registry Editor to delete the POSIX string, as well as then reboot."

Always back up your registry, as well as set a System Restore point, before applying these tweaks.

Heed also, from PC Magazines website:

" Other services. Unless you need one of them, its a good idea to disable several services that may open up back doors to your system: NetMeeting Remote Desktop Sharing, Remote Desktop Help Session Manager, Remote Registry, Routing and Remote Access, SSDP Discovery Service, telnet, as well as Universal Plug and Play Device Host. Go to Control Panel | Administrative Tools and click on the services you do not need and select Stop this service in the left-hand pane."
Read more

Security Test for XP

Heres a great way to test your securty,works with windows NT, 2000 and XP. It has a wealth of infomation like open shares, services, etc. It is a great tool, enjoy: Click Here

Read more

Security Settings AKA Windows 2000 Style

Miss the old Windows 2000 style of setting security permissions?

Do this and you will get them all back.
Fire up Windows Explorer.
Go to Tools>Folder Options.
Hit the View tab. Scroll to the bottom.
un check Use Simple File Sharing (Reccomended) and voila!

This should work in Home version as well.
Read more

Reset Security on all folders


The problem is with using Windows Explorer to modify security settings globally on a partition, directories, as well as files. This is in fact a less than optimum process of applying security settings. A more appropriate process is to execute the following command line from the root of the partition:


(Note: If you are't at the root of the partition in question you need to set your default there: CD /D drive_name: )


Now the command line:
CACLS * /e /t /c /g Administrators:F System:F


(Note: If you see the message, Unable to perform a security operation on an object which has no associated security, you are executing this from a FAT partition. You need to set the default to an NTFS partition.)


This command will edit (/e) the ACLs, rather than replace them, as well as recursively apply them (/t) to subdirectories. CACLS will continue (/c) even when it hits an open file. Any number of ACCOUNT:PERM parameters may follow the grant (/g) switch. There is additional flexibility built into the CACLS command-its only limitation is the dearth of selections for PERM (permission levels) values.

Read more

Remove Shutdown button from Logon Screen

To remove the shutdown button from the logon screen in WinXP and 2K, use regedit and navigate to the following key:

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows
CurrentVersionpoliciessystem

change the value of the dword shutdownwithoutlogon to 0. exit regedit.

thats it!
Read more

Remote registry editing

Windows XP lets remote registry editing through running a service for it. Below are the step-by-step instructions to disable this security hole:

1. Goto your control panel (you can do this through clicking on your start menu)
2. Select administrative tools - services
3. On the right panel, get the service called "remote registry"
4. Right click on it and select properties
5. In the startup mode option box, select disable
6. Reboot you computer and repeat steps 1-4. You should see it will not be running anymore.
Read more

Protecting XP from intruders

There are several things one can do to protect against intruders. Of course the old adage applies here as well, locks keep honest people out; in other words, if they want in, they will keep putting forth effort and eventually will be able to get in through some kind of exploit. The following are some tips that is able to greatly slow them down and make it nearly impossible for them to get in. If you use file sharing or remote connections, dont make the local policy changes.

1. As it was mentioned before, set the Guest and Administrator account passwords. By default, the Guest account password is blank. Make it something difficult, like a combination of letters and numbers, preferably not based on dictionary words. Control PanelAdministrative ToolsComputer ManagementLocal Users and Groups Highlight User Account, right-click, set password.

2. Remove/Delete unused accounts, especially remote assistance accounts.

3. Disable the Guest account since you can not delete it.

4. Rename the Guest and Administrator accounts to different names. Remove the description of these accounts (in local users and groups). Control PanelAdministrative ToolsLocal Security PolicyLocal PoliciesSecurity Options Account: Rename Guest Account - Double click and rename the account Account: Rename Administrator Account

5. If you don't must link to your computer from a remote machine, be sure to turn off this functionality. Control PanelAdministrative ToolsLocal Security PolicyLocal PoliciesUser rights Assessment "Access this computer from the network" - remove all users and groups. This should be blank "Deny access to this computer from the network" - this should include all users and groups. Double click on the policy, click Add User or group, click Advanced, click Find Now, highlight all the accounts and click OK.

6. Turn off the Microsoft File sharing in Network Neighborhood if it is not going to be used.

7. Under System PropertiesRemote, Turn off Remote Desktop and Remote invitations.

8. Run a software firewall program.

9. Be sure to visit WindowsUpdate to get the latest hotfixes and security patches. There are a bunch of them.
Read more

Press Ctrl-Alt-Delete to Log In

I have not tested this with version of Windows XP besides XP Pro. It might work in Home Edition or other versions.

If you do this, then you will get the "Press Ctrl-Alt-Delete to begin" box when you turn on your computer, before it asks for your username and password. It also asks for you to press Ctrl-Alt-Del before you can unlock your computer if you lock it. This is done through default in Windows 2000 Server or Windows Server 2003.

To enable the Ctrl-Alt-Delete boxes, open Regedit and go to

HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionWinlogon

Create a new DWORD value and name it "DisableCAD"

The value should be set to "0"

Thats it! Now you can log off to see the change.

(You must disable the Welcome screen to get this)
Read more

Passwording Guest Account

After reading Joseph Doyles submission regarding this I would want to point out which you can set a Guest account password through simply doing this. This process is somewhat simpler in which you don't need to mess around with CMD.exe.

1. Make sure you are logged on as an Administrator.
2. Go to Start > Control Panel > Administrative Tools > Computer Management.
3. Select the "Users" folder under "Local Users and Groups".
4. Right click on the "Guest" account and click "Set Password". When a dialog comes up warning you of the possible consequences click "Proceed". You will then be given a dialog that lets you set a new password.

I have always considered security a top priority and considering the ease of doing this I would highly recommend that everyone sets a Guest account password. Even though the Guest account is disabled through default, why not do this just for the extra bit of security?

Local Users and Groups is not available in XP Home. A way to set a password for the guest account in Home and Pro: click start - run - type: cmd - in the command window type: net user guest * - hit Enter - you will be prompted for the password to use.
Read more

Must Do Security Settings

Go to Start - Run...

and then mode "gpedit.msc" and enter

now go to User Configuration - Administarative Templates - Start Menu and Taskbar

now double click "Do not keep history of recently opened documents" and click on "Enabled" thenk ok and there you have it

Read more

Managing your system with the Group Policy Editor


Warning: Prior to making changes with the group policy editor please use System Restore to make a known good Restore Point in case you encounter issues. TweakXP.com takes no responsibility for a problems that may occur from using the Group Policy Editor incorrectly.

Note: The group policy editor is not available to users of Windows XP Home Edition.

To access the Group Policy Editor follow these steps:

1. Click Start - Run.

2. Type "gpedit.msc" and press ENTER.

To understand navigation and available options click on the available options and read their descriptions. You can also get information on the Group Policy Editor through browsing for "Group Policy" in Help and Support.


Read more