<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>GamSec - the IT Security Blog</title>
	<atom:link href="http://gamsec.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://gamsec.wordpress.com</link>
	<description>Technology is great but we still need to protect ourselves</description>
	<lastBuildDate>Tue, 23 Jun 2009 09:23:37 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='gamsec.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/3e867eeae828c48232d857fcd39c217e?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>GamSec - the IT Security Blog</title>
		<link>http://gamsec.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://gamsec.wordpress.com/osd.xml" title="GamSec - the IT Security Blog" />
	<atom:link rel='hub' href='http://gamsec.wordpress.com/?pushpress=hub'/>
		<item>
		<title>There&#8217;s no I in Team &#8211; but there&#8217;s an I in Security</title>
		<link>http://gamsec.wordpress.com/2009/06/23/theres-no-i-in-team-but-theres-an-i-in-security/</link>
		<comments>http://gamsec.wordpress.com/2009/06/23/theres-no-i-in-team-but-theres-an-i-in-security/#comments</comments>
		<pubDate>Tue, 23 Jun 2009 09:23:37 +0000</pubDate>
		<dc:creator>Nello</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[users]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://gamsec.wordpress.com/?p=140</guid>
		<description><![CDATA[How many times have you heard the saying there&#8217;s no i in team? Must be hundreds of times &#8211; in sports, in movies, at work, practically everywhere. This is one of my favorite quotations, even because I believe that a successful result is never the outcome of the efforts put in by one person only. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=140&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<blockquote><p>How many times have you heard the saying <em>there&#8217;s no i in team</em>? Must be hundreds of times &#8211; in sports, in movies, at work, practically everywhere. This is one of my favorite quotations, even because I believe that a successful result is never the outcome of the efforts put in by one person only.</p></blockquote>
<p>In my opinion, in the technology world it should be quite the same but unfortunately this is not always the case. Vendors and developers should be more in touch with the users because it is in the interest of both, that the users are kept secured and that they are provided with the necessary tools to do this.<br />
<span id="more-140"></span><br />
My recent post about the <a href="http://gamsec.wordpress.com/2009/06/11/critical-security-patch-released-was-it-too-late/">Microsoft security patches released</a> a couple of weeks ago, proved to be popular with the GamSec followers and as expected it raised concerns amongst the users. I think that technology is not flawless &#8211; but then again, there&#8217;s no such thing as a flawless system. Unfortunately, businesses are only looking at increasing turnover and maximizing profits and one option for this is to release products at a very low price. What happens here? They need to see where to cut the quality if they want to cut the price &#8211; with the prevailing victim normally being security. Why? Well, features are what attract the public &#8211; so they cannot be reduced, packaging is what hits the eye &#8211; so this cannot be reduced either, what are we left with? security!<div id="attachment_141" class="wp-caption alignright" style="width: 160px"><img src="http://gamsec.files.wordpress.com/2009/06/securitysoftware.jpg?w=150&#038;h=71" alt="We need secure technology - its up to us to get it!" title="securitysoftware" width="150" height="71" class="size-thumbnail wp-image-141" /><p class="wp-caption-text">We need secure technology - its up to us to get it!</p></div></p>
<p>Who would be the victim of this? As always, the user &#8211; but only until users start looking around them and notice that the security threat is actually present, and start demanding that the products that are released are indeed secure enough. What happened when car accidents were becoming more fatal? Seatbelts and Airbags were introduced and nowadays are a compulsory feature in all vehicles. Now that the victims of fraud or identity theft are increasing will we see the equivalent of airbags and seatbelts for technology? and who will be the provider of these?</p>
<p>Well, technically the provider should be the developer of the software &#8211; but why is it that we always need to have victims before actually stepping up and taking concrete actions? Can&#8217;t we be proactive and start anticipating &#8216;fatalities&#8217; rather than simply reacting to them?</p>
<p>That would be the ideal world, however its up to us &#8211; as users &#8211; to push the industry towards this &#8216;ideal world&#8217;. It will take time and will take effort, but I believe that developers will be &#8216;forced&#8217; to make their products secure if people start giving security much more prominence when gauging the advantages of software before they purchase it.</p>
<p><em>There&#8217;s no i in team</em> &#8211; but <strong>there is an i in security &#8211; therefore its up to &#8216;me&#8217; to push for a securer online environment</strong>. Next time you&#8217;re buying a software, compare the security that it provides &#8211; might be more expensive at first but will save you money in the long run!</p>
<br />Posted in Security Tagged: Security, Software, technology, users, vulnerabilities <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gamsec.wordpress.com/140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gamsec.wordpress.com/140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/gamsec.wordpress.com/140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/gamsec.wordpress.com/140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/gamsec.wordpress.com/140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/gamsec.wordpress.com/140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/gamsec.wordpress.com/140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/gamsec.wordpress.com/140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/gamsec.wordpress.com/140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/gamsec.wordpress.com/140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/gamsec.wordpress.com/140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/gamsec.wordpress.com/140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/gamsec.wordpress.com/140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/gamsec.wordpress.com/140/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=140&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gamsec.wordpress.com/2009/06/23/theres-no-i-in-team-but-theres-an-i-in-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3ce969f036c163176d21cd83cdd21856?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Nello</media:title>
		</media:content>

		<media:content url="http://gamsec.files.wordpress.com/2009/06/securitysoftware.jpg?w=150" medium="image">
			<media:title type="html">securitysoftware</media:title>
		</media:content>
	</item>
		<item>
		<title>Facebook Usernames &#8211; a week later</title>
		<link>http://gamsec.wordpress.com/2009/06/19/facebook-usernames-a-week-later/</link>
		<comments>http://gamsec.wordpress.com/2009/06/19/facebook-usernames-a-week-later/#comments</comments>
		<pubDate>Fri, 19 Jun 2009 12:37:31 +0000</pubDate>
		<dc:creator>Nello</dc:creator>
				<category><![CDATA[News & Info]]></category>
		<category><![CDATA[copyright]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[profile]]></category>
		<category><![CDATA[social networks]]></category>
		<category><![CDATA[trademark]]></category>
		<category><![CDATA[username]]></category>
		<category><![CDATA[users]]></category>

		<guid isPermaLink="false">http://gamsec.wordpress.com/?p=132</guid>
		<description><![CDATA[The Facebook Username saga is still ongoing. It&#8217;s been a week since Facebook gave users the opportunity to choose their preferred username to make it easier for them to refer their profile to their friends. Although it seems to be a good idea even though I did mention a few hitches that might be encountered [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=132&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<blockquote><p>The Facebook Username saga is still ongoing. It&#8217;s been a week since Facebook gave users the opportunity to choose their preferred username to make it easier for them to refer their profile to their friends.</p></blockquote>
<p>Although it seems to be a good idea even though <a href="http://gamsec.wordpress.com/2009/06/12/facebook-usernames-who-will-benefit/">I did mention a few hitches that might be encountered in a previous post</a> &#8211; and quite frankly I am not convinced as to whether these flaws in the system were exploited &#8211; and I guess only time will tell. </p>
<p>A week after I must say that I was surprised to read that the Facebook servers did not fail after the huge number of hits that were expected. I guess the geographical factor did influence this because people from different time-zones didn&#8217;t access it at the same time. I didn&#8217;t wait all night next to my machine to reserve my preferred username &#8211; but by the time I remembered about it (late afternoon), the username I wanted was still available! Should I consider myself lucky?<br />
<span id="more-132"></span><br />
 <div id="attachment_134" class="wp-caption alignright" style="width: 160px"><img src="http://gamsec.files.wordpress.com/2009/06/facebook-logo.png?w=150&#038;h=150" alt="What in a username?" title="facebook-logo" width="150" height="150" class="size-thumbnail wp-image-134" /><p class="wp-caption-text">What in a username?</p></div>Whilst many people have already forgotten about the username, the Facebook people are probably starting to realize what they&#8217;ve done and the hefty workload that they inflicted on themselves. They added a feature to an already-successful social network and this feature has triggered a lot of extra workload on them &#8211; counting the increase in customer queries, more system usage (and proneness to failures) and most of all legal inquiries into trademarks and copyrights.</p>
<p>I think that the Facebook team was somewhat short-sighted in this regard because to be honest, I never needed a Facebook username. Lets face it, does anyone advertise their profile? Facebook (like any social-network) is all about finding people that you know but possibly lost contact for some time &#8211; so if you lost contact with these persons, how are you going to send them your new vanity Facebook profile link? They&#8217;re more likely to type your name in the search box and find your profile without ever using your username.</p>
<p>Well, thats business I guess. More features might mean more flexibility for the users, but in reality, for a feature to be good it needs to be useful. Quite frankly, I see no difference in my Facebook usage or contacts between today and a week or two ago. Is it just me? Did your username make any difference for you?</p>
<br />Posted in News &amp; Info Tagged: copyright, facebook, profile, social networks, trademark, username, users <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gamsec.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gamsec.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/gamsec.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/gamsec.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/gamsec.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/gamsec.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/gamsec.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/gamsec.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/gamsec.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/gamsec.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/gamsec.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/gamsec.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/gamsec.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/gamsec.wordpress.com/132/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=132&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gamsec.wordpress.com/2009/06/19/facebook-usernames-a-week-later/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3ce969f036c163176d21cd83cdd21856?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Nello</media:title>
		</media:content>

		<media:content url="http://gamsec.files.wordpress.com/2009/06/facebook-logo.png?w=150" medium="image">
			<media:title type="html">facebook-logo</media:title>
		</media:content>
	</item>
		<item>
		<title>Instant Messengers: Pain or Gain?</title>
		<link>http://gamsec.wordpress.com/2009/06/16/instant-messengers-pain-or-gain/</link>
		<comments>http://gamsec.wordpress.com/2009/06/16/instant-messengers-pain-or-gain/#comments</comments>
		<pubDate>Tue, 16 Jun 2009 13:12:16 +0000</pubDate>
		<dc:creator>Nello</dc:creator>
				<category><![CDATA[Instant Messengers]]></category>
		<category><![CDATA[Online Security]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[chat]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[ICQ]]></category>
		<category><![CDATA[Instant Messenger]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[mIRC]]></category>
		<category><![CDATA[password]]></category>

		<guid isPermaLink="false">http://gamsec.wordpress.com/?p=127</guid>
		<description><![CDATA[50 years ago, nobody had imagined that by clicking a button and typing some text we would be able to communicate with someone across the globe. All this has been made possible through the Internet. The Internet is an evolving world but the elements held within it are also evolving quite rapidly. Taking chatting as [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=127&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<blockquote><p>50 years ago, nobody had imagined that by clicking a button and typing some text we would be able to communicate with someone across the globe. All this has been made possible through the Internet.</p></blockquote>
<p>The Internet is an evolving world but the elements held within it are also evolving quite rapidly. Taking chatting as an example, initially this was done through mIRC or ICQ which were quite primitive tools. You&#8217;d go into what was called a channel and start chatting with your peers from across the globe.<br />
<span id="more-127"></span><br />
Nowadays we have Instant Messengers which are more sophisticated and more appealing pieces of software which we use to communicate with each other at any time. Whilst the advantages of this communication method are endless, we still need to be careful to make sure that what we say remains between us and the intended recipient. </p>
<p>Why am I saying this? Well, because the same way that you might be overheard in a conversation, you might also be &#8216;overheard&#8217; while chatting online. What are the threats:</p>
<p>1. On-lookers: people might walk by your machine and see what you&#8217;re typing<br />
2. Unattended machines: you might leave your machine unattended and unlocked and people might have a quick look at the open conversation window or the chat histories<br />
3. Interception: the data being sent and received (containing the chat messages) might be intercepted<br />
4. Key-logging: viruses/trojans might plant a key-logger on your machine and the attacker will be able to view everything you are typing<br />
5. Hacking: your account might be accessed by a hacker who would then be able to impersonate you in the online world</p>
<p><div id="attachment_128" class="wp-caption alignright" style="width: 140px"><img src="http://gamsec.files.wordpress.com/2009/06/instant-messengers.jpg?w=130&#038;h=150" alt="You can increase the gain by avoiding the risk" title="instant-messengers" width="130" height="150" class="size-thumbnail wp-image-128" /><p class="wp-caption-text">You can increase the gain by avoiding the risk</p></div>These are the most critical risks that we go through when using Instant Messengers, but how can we avoid them?</p>
<p>1. Always lock your machine when unattended<br />
2. Avoid storing chat history &#8211; whilst this might be useful, its better if you only take note of the important things you need to remember then compiling (inadvertently) a dossier of company&#8217;s (or personal) secrets which you chatted about<br />
3. Use a complex password and change it frequently<br />
4. Do not accept files from persons you don&#8217;t know and always scan them (using a reliable and updated anti-virus) for any viruses before opening</p>
<p>Apart from the above, there are also software packages that you could use and which would protect you against most of the above threats &#8211; but these will be discussed in future posts. For the time being, the above should be a good initial background of how to avoid some risks whilst instant messaging. </p>
<br />Posted in Instant Messengers, Online Security Tagged: anti-virus, chat, hacker, Hacking, ICQ, Instant Messenger, Internet, mIRC, password <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gamsec.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gamsec.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/gamsec.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/gamsec.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/gamsec.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/gamsec.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/gamsec.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/gamsec.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/gamsec.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/gamsec.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/gamsec.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/gamsec.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/gamsec.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/gamsec.wordpress.com/127/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=127&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gamsec.wordpress.com/2009/06/16/instant-messengers-pain-or-gain/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3ce969f036c163176d21cd83cdd21856?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Nello</media:title>
		</media:content>

		<media:content url="http://gamsec.files.wordpress.com/2009/06/instant-messengers.jpg?w=130" medium="image">
			<media:title type="html">instant-messengers</media:title>
		</media:content>
	</item>
		<item>
		<title>What has the Internet brought us to?</title>
		<link>http://gamsec.wordpress.com/2009/06/15/what-has-the-internet-brought-us-to/</link>
		<comments>http://gamsec.wordpress.com/2009/06/15/what-has-the-internet-brought-us-to/#comments</comments>
		<pubDate>Mon, 15 Jun 2009 13:32:26 +0000</pubDate>
		<dc:creator>Nello</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[risks]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://gamsec.wordpress.com/?p=122</guid>
		<description><![CDATA[The Internet has been one of the most important &#8216;inventions&#8217; in the history of man. Not only has it brought the world onto one platform but also changed the way that we think and act, but how long will this ever-changing world continue growing? I think that only time will tell but from the looks [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=122&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<blockquote><p>The Internet has been one of the most important &#8216;inventions&#8217; in the history of man. Not only has it brought the world onto one platform but also changed the way that we think and act, but how long will this ever-changing world continue growing?</p></blockquote>
<p>I think that only time will tell but from the looks of it, the Internet is here to stay and grow even bigger. The Internet has made an impact on research, studies, opportunities, communication, business, negotiation &#8230; you name it &#8211; the Internet does it. Have our ancestors ever thought that with a couple of clicks they can get in contact with someone across the globe? Definitely not! Sometimes I wonder what would they say if they had to be here now.<br />
<span id="more-122"></span><br />
Its an undisputed fact that the Internet brought a massive count of advantages and provided feasible and rapid solutions to a number of problems, however it also brought some risks. Whilst the Internet has substituted most of the manual stuff &#8211; it also substituted manual crimes. Whilst before for someone to steel a person&#8217;s money the burglar had to break into their home, nowadays using the Internet people are being defrauded every hour. Whilst before for someone to be impersonated, one needed to go the extra mile to look like the victim &#8211; nowadays one only needs to stay in the comfort of their home and adopt someone else&#8217;s identity from behind a monitor. Unfortunately, these are the disadvantages of change and development and its not only in the Internet that these happen. Before we didn&#8217;t have powerful cars, nowadays people get killed because of the high-power vehicles they operate.</p>
<p>What can we do about it? Well, for starters, we need to be careful. The same way that our parents always thought us not to take candy from strangers &#8211; we also need to make sure not to trust the strangers that we meet online. The same way that we don&#8217;t visit places that could pose danger to us (e.g. high-risk areas for theft), we shouldn&#8217;t trust an online shop without knowing that its secure. In the coming days, we&#8217;ll be looking at some aspects that threaten our security (both online and offline) and identifying ways to protect ourselves against them &#8211; whilst comparing them to real-life situations which we already cater for.</p>
<p><div id="attachment_123" class="wp-caption alignleft" style="width: 160px"><img src="http://gamsec.files.wordpress.com/2009/06/winlock.jpg?w=150&#038;h=103" alt="Point 1: Lock your screen if you&#39;re leaving your desk" title="winlock" width="150" height="103" class="size-thumbnail wp-image-123" /><p class="wp-caption-text">Point 1: Lock your screen if you're leaving your desk</p></div>Just as a preliminary point, the same way that we lock our house before leaving it unattended &#8211; we need to lock our computer so that nobody can gain access to it. This goes for both a password and also locking the screen if we&#8217;re leaving our desks.</p>
<p>This is just the beginning and whilst some might find it stupid, many have fallen victims of data or identity theft because they left their machine accessible and unattended in their own office. More pointers to come in the following posts &#8230; </p>
<br />Posted in Security, Tips &amp; Tricks Tagged: data, identity theft, Internet, password, risks, Security, technology, threats <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gamsec.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gamsec.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/gamsec.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/gamsec.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/gamsec.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/gamsec.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/gamsec.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/gamsec.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/gamsec.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/gamsec.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/gamsec.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/gamsec.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/gamsec.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/gamsec.wordpress.com/122/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=122&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gamsec.wordpress.com/2009/06/15/what-has-the-internet-brought-us-to/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3ce969f036c163176d21cd83cdd21856?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Nello</media:title>
		</media:content>

		<media:content url="http://gamsec.files.wordpress.com/2009/06/winlock.jpg?w=150" medium="image">
			<media:title type="html">winlock</media:title>
		</media:content>
	</item>
		<item>
		<title>Facebook Usernames: Who will benefit?</title>
		<link>http://gamsec.wordpress.com/2009/06/12/facebook-usernames-who-will-benefit/</link>
		<comments>http://gamsec.wordpress.com/2009/06/12/facebook-usernames-who-will-benefit/#comments</comments>
		<pubDate>Fri, 12 Jun 2009 14:05:00 +0000</pubDate>
		<dc:creator>Nello</dc:creator>
				<category><![CDATA[News & Info]]></category>
		<category><![CDATA[.com]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[social networks]]></category>
		<category><![CDATA[URL]]></category>
		<category><![CDATA[username]]></category>

		<guid isPermaLink="false">http://gamsec.wordpress.com/?p=116</guid>
		<description><![CDATA[One of the most popular and fast-emerging social networks is undoubtedly Facebook. Many individuals and businesses are using this network to keep in touch with friends or get their business known worldwide. Whist Facebook carried a lot of advantages, many have noticed that it does not have a username authentication mechanism. In reality, those who [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=116&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<blockquote><p>One of the most popular and fast-emerging social networks is undoubtedly Facebook. Many individuals and businesses are using this network to keep in touch with friends or get their business known worldwide. </p></blockquote>
<p>Whist Facebook carried a lot of advantages, many have noticed that it does not have a username authentication mechanism. In reality, those who want to register a Facebook account and login would use their email address and password rather than a standard username-password combination.</p>
<p>The news is that now Facebook, starting tomorrow 13th June at 6.01am CET, will be giving users the ability to register their own username. Whilst this is a great idea, I cannot imagine the chaos that there will be with people staying awake purely to register their desired domain.<br />
<span id="more-116"></span><br />
Now you&#8217;re thinking, <em>&#8220;who&#8217;s that crazy to stay awake to register a facebook username?&#8221;</em> Well, prepare yourself to be surprised. Just imagine how many people have become rich by buying a .com domain name with the name of a company and then sold it to this same company for thousands (if not millions) of dollars!</p>
<p><div id="attachment_117" class="wp-caption alignleft" style="width: 127px"><img src="http://gamsec.files.wordpress.com/2009/06/fb.gif?w=117&#038;h=150" alt="Who will get to your username first?" title="fb" width="117" height="150" class="size-thumbnail wp-image-117" /><p class="wp-caption-text">Who will get to your username first?</p></div>The Facebook username will eventually be integrated into the URL and therefore many might find it convenient to have the company name in their company page URL. I can imagine people registering names of companies that they know use Facebook. Whilst Facebook has made it clear that you will only be able to register only one domain name for your profile and page, it also stated that you won&#8217;t be able to transfer it. That&#8217;s fine, but what&#8217;s holding you from selling the whole &#8216;profile&#8217;? You won&#8217;t need to transfer the domain, you just sell the login details for that particular page and make quite some money thanks to Facebook&#8217;s newly discovered username system.</p>
<p>I don&#8217;t want to sound harsh, but I think that Facebook is going to create a way for people to make money off its network without investing a penny. I sincerely hope that this doesn&#8217;t happen, but if this happens, you cannot say that you weren&#8217;t warned! One thing is for sure, I won&#8217;t be sating awake to register the <a href="http://www.facebook.com/pages/GamSec-The-IT-Security-Blog/85703083639">GamSec</a> domain &#8211; I leave it to the content to attract the audience!</p>
<br />Posted in News &amp; Info Tagged: .com, business, domain, facebook, Internet, password, social networks, URL, username <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gamsec.wordpress.com/116/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gamsec.wordpress.com/116/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/gamsec.wordpress.com/116/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/gamsec.wordpress.com/116/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/gamsec.wordpress.com/116/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/gamsec.wordpress.com/116/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/gamsec.wordpress.com/116/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/gamsec.wordpress.com/116/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/gamsec.wordpress.com/116/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/gamsec.wordpress.com/116/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/gamsec.wordpress.com/116/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/gamsec.wordpress.com/116/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/gamsec.wordpress.com/116/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/gamsec.wordpress.com/116/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=116&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gamsec.wordpress.com/2009/06/12/facebook-usernames-who-will-benefit/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3ce969f036c163176d21cd83cdd21856?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Nello</media:title>
		</media:content>

		<media:content url="http://gamsec.files.wordpress.com/2009/06/fb.gif?w=117" medium="image">
			<media:title type="html">fb</media:title>
		</media:content>
	</item>
		<item>
		<title>Critical Security Patch Released &#8211; Was it too late?</title>
		<link>http://gamsec.wordpress.com/2009/06/11/critical-security-patch-released-was-it-too-late/</link>
		<comments>http://gamsec.wordpress.com/2009/06/11/critical-security-patch-released-was-it-too-late/#comments</comments>
		<pubDate>Thu, 11 Jun 2009 08:53:43 +0000</pubDate>
		<dc:creator>Nello</dc:creator>
				<category><![CDATA[Internet Browsers]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Excel]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[users]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[Word]]></category>

		<guid isPermaLink="false">http://gamsec.wordpress.com/?p=108</guid>
		<description><![CDATA[Its been since October 2003 that Microsoft have started the tradition of releasing patches for its software products every second Tuesday of every month. The most recent of the series was June 9th which saw a record release of patches. Looking on the bright side, quite a few patches have been fixed through this group [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=108&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<blockquote><p>Its been since October 2003 that Microsoft have started the tradition of releasing patches for its software products every second Tuesday of every month. The most recent of the series was June 9th which saw a record release of patches.</p></blockquote>
<p>Looking on the bright side, quite a few patches have been fixed through this group release, but my question would be &#8211; how many users were vulnerable and prone to attacks before this date? Last Tuesday&#8217;s release had no less than 10 security patches including one for a critical hole found in Internet Explorer 8. This means that before this, everyone using Internet Explorer 8 was an easy prey for hackers. And what tells us that there aren&#8217;t more of such holes?<br />
<span id="more-108"></span><br />
I&#8217;m pretty sure that the answer to the above question will probably come on Tuesday 14th July and in every second Tuesday of the subsequent months. Microsoft has been organizing hacking contests where a number of hackers from around the globe try to exploit any possible vulnerabilities in the software so that Microsoft could then have it fixed. Unfortunately, the above critical security hole was identified way back in March and Microsoft took 3 months to issue the fix. This means that during these 3 months, the flaw had been identified and could have been &#8216;made public&#8217; &#8211; whilst IE 8 users were vulnerable.<div id="attachment_109" class="wp-caption alignright" style="width: 160px"><img src="http://gamsec.files.wordpress.com/2009/06/ie8_logo.jpg?w=150&#038;h=150" alt="Is your browser making you vulnerable?" title="ie8_logo" width="150" height="150" class="size-thumbnail wp-image-109" /><p class="wp-caption-text">Is your browser making you vulnerable?</p></div></p>
<p><strong>What was the flaw?</strong><br />
Out of the 8 Internet Explorer Patches that were released, the most important one was to fix a hole which permitted remote code execution which was made possible when the user views a specially-crafted website. This meant that hackers would be able to run codes on the user&#8217;s machine (for their own intent and purposes) simply because the user viewed a particular website or websites. </p>
<p><strong>What else was released?</strong><br />
Quite a number of other patches were released particularly revolving around Microsoft Office products Word and Excel. The flaw was similar to the above but the possibility of remotely running codes would derive from the user accessing a specially-crafted word or excel file &#8211; making it somewhat more difficult.</p>
<p><strong>My concern as a user</strong><br />
Whilst I understand that no code is perfect and that patches would always be required, my main concern is that such flaw was quite critical and a user could easily fall prey to such attacks considering that some users view hundreds of website each day &#8211; why did Microsoft take 3 months to release it? If it was so critical as described, couldn&#8217;t they have moved away from their <em>second-Tuesday of the month</em> tradition and release it once the fix was completed in order to reduce the possibilities of the users falling victims of such attacks?</p>
<br />Posted in Internet Browsers, Patches Tagged: browser, Excel, Hacking, IE, Internet Explorer, Microsoft, Microsoft Office, Patches, Security, users, vulnerabilities, website, Word <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gamsec.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gamsec.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/gamsec.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/gamsec.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/gamsec.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/gamsec.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/gamsec.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/gamsec.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/gamsec.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/gamsec.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/gamsec.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/gamsec.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/gamsec.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/gamsec.wordpress.com/108/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=108&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gamsec.wordpress.com/2009/06/11/critical-security-patch-released-was-it-too-late/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3ce969f036c163176d21cd83cdd21856?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Nello</media:title>
		</media:content>

		<media:content url="http://gamsec.files.wordpress.com/2009/06/ie8_logo.jpg?w=150" medium="image">
			<media:title type="html">ie8_logo</media:title>
		</media:content>
	</item>
		<item>
		<title>Identify a scam using your common sense</title>
		<link>http://gamsec.wordpress.com/2009/06/10/identify-a-scam-using-common-your-sense/</link>
		<comments>http://gamsec.wordpress.com/2009/06/10/identify-a-scam-using-common-your-sense/#comments</comments>
		<pubDate>Wed, 10 Jun 2009 08:26:12 +0000</pubDate>
		<dc:creator>Nello</dc:creator>
				<category><![CDATA[Email Scams]]></category>
		<category><![CDATA[chain letters]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[hoax]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[lottery]]></category>
		<category><![CDATA[prize]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[victims]]></category>
		<category><![CDATA[website]]></category>

		<guid isPermaLink="false">http://gamsec.wordpress.com/?p=99</guid>
		<description><![CDATA[The world is full of strange people, but the Internet is even worse. It didn&#8217;t take much time for crooks to understand that the Internet has given them the ability to gain a worldwide accessibility to possible victims to their scams. Unfortunately, some people use such useful resources to their own advantage and to the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=99&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<blockquote><p>The world is full of strange people, but the Internet is even worse. It didn&#8217;t take much time for crooks to understand that the Internet has given them the ability to gain a worldwide accessibility to possible victims to their scams. Unfortunately, some people use such useful resources to their own advantage and to the detriment of others.</p></blockquote>
<p>Who has never found a link on a website saying that you&#8217;re the 999,999,999th visitor and you&#8217;ve won a million dollars? Who never received an email saying that you&#8217;ve won a lottery asking you to contact them so that you retrieve your prize money? Every Internet user have come across these circumstances and unfortunately, many have fallen victims.<br />
<span id="more-99"></span><br />
As a matter of fact, with some common sense and thinking you&#8217;d realize that what you&#8217;re reading cannot be true! How can you win a lottery without ever participating in it? How can you go into a website, and every time you visit you&#8217;re the 999,999,999th visitor? Many don&#8217;t realize this and unfortunately continue by submitting their personal details to these persons and end up losing their hard-earned money instead of getting the hefty prize money. <div id="attachment_100" class="wp-caption alignleft" style="width: 151px"><img src="http://gamsec.files.wordpress.com/2009/06/scam.jpg?w=141&#038;h=150" alt="Everyone could fall victim to a scam ... even you!" title="scam" width="141" height="150" class="size-thumbnail wp-image-100" /><p class="wp-caption-text">Everyone could fall victim to a scam ... even you!</p></div></p>
<p>I thought I&#8217;d share an interesting website with you. <a href="http://www.hoax-slayer.com/">Hoax-Slayer.com</a> is an excellent reference point if you want to know whether an email you received is a scam or not. All the top email scams are listed ranging from the famous Nigerian Army Official to some of the most common compassionate chain letters. Whilst this website doesn&#8217;t give any guarantee that it has all scam emails included, it is a good focal point for who needs to verify the legitimacy of an email that they&#8217;ve received.</p>
<p>Personally, I&#8217;d suggest that you keep the following in mind if you receive such an email:<br />
1. You can never win a lottery if you didn&#8217;t participate in it<br />
2. No stranger is going to come to YOU to help him get the money out of the country<br />
3. Companies have their own domain and won&#8217;t use a yahoo (or similar) email address<br />
4. How could a stranger have your email address to inform you that your machine is hacked?<br />
5. No bank will ask you to submit your account details via email</p>
<p>The above are only the tip of the iceberg but I&#8217;m sure that knowing these you&#8217;ll be able to identify legitimate from non-legimiate emails. At the end of the day, nobody will give  you free money &#8211; if you really want to make a profit out of these emails, <strong>delete them</strong>!</p>
<br />Posted in Email Scams Tagged: chain letters, email, Hacking, hoax, Internet, lottery, prize, scam, victims, website <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gamsec.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gamsec.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/gamsec.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/gamsec.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/gamsec.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/gamsec.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/gamsec.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/gamsec.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/gamsec.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/gamsec.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/gamsec.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/gamsec.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/gamsec.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/gamsec.wordpress.com/99/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=99&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gamsec.wordpress.com/2009/06/10/identify-a-scam-using-common-your-sense/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3ce969f036c163176d21cd83cdd21856?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Nello</media:title>
		</media:content>

		<media:content url="http://gamsec.files.wordpress.com/2009/06/scam.jpg?w=141" medium="image">
			<media:title type="html">scam</media:title>
		</media:content>
	</item>
		<item>
		<title>Detecting intrusions and being prepared</title>
		<link>http://gamsec.wordpress.com/2009/06/08/detecting-intrusions-and-being-prepared/</link>
		<comments>http://gamsec.wordpress.com/2009/06/08/detecting-intrusions-and-being-prepared/#comments</comments>
		<pubDate>Mon, 08 Jun 2009 08:52:01 +0000</pubDate>
		<dc:creator>Nello</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[applications]]></category>
		<category><![CDATA[attackers]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[intrusion]]></category>
		<category><![CDATA[port]]></category>
		<category><![CDATA[TCP/IP]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[UDP]]></category>
		<category><![CDATA[users]]></category>

		<guid isPermaLink="false">http://gamsec.wordpress.com/?p=94</guid>
		<description><![CDATA[Hacking has been one of the most popular subjects with the readers of this blog. With the issue being of worry to the vast majority of Internet users, I felt that it is time to start exploring some software products that would help you identify any intrusions into your system. Going back to an article [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=94&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<blockquote><p><a href="http://gamsec.wordpress.com/tag/hacking/" target="blank">Hacking </a>has been one of the most popular subjects with the readers of this blog. With the issue being of worry to the vast majority of Internet users, I felt that it is time to start exploring some software products that would help you identify any intrusions into your system. </p></blockquote>
<p>Going back to an article from last week entitled <em><a href="http://gamsec.wordpress.com/2009/06/02/are-you-being-hacked/" target="_blank">Are you being hacked?</a></em> we started exploring the <a href="http://www.foundstone.com/us/resources-free-tools.asp" target="_blank">Foundstone</a> Website which provides us with quite a few useful tools. In this article, we&#8217;ll be exploring a few of the most useful and simple tools and see how these can help us identify any wrongdoings that are happening on our system.<br />
<span id="more-94"></span><br />
The first product is <a href="http://www.foundstone.com/us/resources/proddesc/fport.htm" target="_blank">FPort</a>. This software indicates any open UDP and TCP/IP ports and subsequently maps them to the respective application that is using them. This means that, if you identify a port that is opened by an application which you haven&#8217;t initiated or which you don&#8217;t know anything about you can then close the respective port through your firewall hence terminating the application.</p>
<p><a href="http://www.foundstone.com/us/resources/proddesc/attacker.htm" target="_blank">Attacker </a>is another interesting product which could easily be used in conjunction with FPort. This time, the software is given a number of ports to monitor (the technical term is listen). When a connection or data arrives to that port, the software will notify you so that you can then investigate further. Again, if you find that the port is being used for something dodgy, you will then be able to close the port through your firewall and avoid any connection or data coming in through that particular port. <div id="attachment_95" class="wp-caption alignright" style="width: 110px"><img src="http://gamsec.files.wordpress.com/2009/06/firewall_logo.jpg?w=100&#038;h=101" alt="A firewall is a must if you want to keep the world out of your business!" title="firewall_logo" width="100" height="101" class="size-full wp-image-95" /><p class="wp-caption-text">A firewall is a must if you want to keep the world out of your business!</p></div></p>
<p>In the previous articles I&#8217;ve mentioned that when a machine is hacked, there are normally changes to some files. <a href="http://www.foundstone.com/us/resources/proddesc/filewatch.htm" target="_blank">FileWatch </a>is the software that would notify you if changes are made to any files from a list provided by the user. This software is able to send emails reporting changes or even make phone calls to a particular number if any such changes occur. </p>
<p>Above we&#8217;ve explored three very important software products that might be very useful in identifying any intrusion into our machine. Whilst these are mostly used for monitoring, the real action will then be taken through your firewall &#8211; which is why I stressed on the importance of having a good firewall installed on your machine. </p>
<p>Next topic will actually be the firewall and how to make sure that its configured correctly. We&#8217;ll be looking at how to turn off these ports &#8211; if any of the above tools indicate anything dodgy. </p>
<br />Posted in Hacking, Security, Software Tagged: applications, attackers, blog, firewall, hacker, Hacking, Internet, intrusion, port, Software, TCP/IP, tools, UDP, users <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gamsec.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gamsec.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/gamsec.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/gamsec.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/gamsec.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/gamsec.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/gamsec.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/gamsec.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/gamsec.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/gamsec.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/gamsec.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/gamsec.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/gamsec.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/gamsec.wordpress.com/94/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=94&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gamsec.wordpress.com/2009/06/08/detecting-intrusions-and-being-prepared/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3ce969f036c163176d21cd83cdd21856?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Nello</media:title>
		</media:content>

		<media:content url="http://gamsec.files.wordpress.com/2009/06/firewall_logo.jpg" medium="image">
			<media:title type="html">firewall_logo</media:title>
		</media:content>
	</item>
		<item>
		<title>Battle of the Browsers!</title>
		<link>http://gamsec.wordpress.com/2009/06/05/battle-of-the-browsers/</link>
		<comments>http://gamsec.wordpress.com/2009/06/05/battle-of-the-browsers/#comments</comments>
		<pubDate>Fri, 05 Jun 2009 14:33:17 +0000</pubDate>
		<dc:creator>Nello</dc:creator>
				<category><![CDATA[Internet Browsers]]></category>
		<category><![CDATA[applications]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Mozilla]]></category>
		<category><![CDATA[Opera]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[user]]></category>

		<guid isPermaLink="false">http://gamsec.wordpress.com/?p=85</guid>
		<description><![CDATA[One of the main elements for Internet users is the browser. Whilst before this term was synonymous with Internet Explorer, nowadays we have quite a few players in the field and people are spoilt for choice. With Internet Explorer and Mozilla Firefox leading the field, what exactly are people looking for when choosing their default [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=85&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>One of the main elements for Internet users is the browser. Whilst before this term was synonymous with Internet Explorer, nowadays we have quite a few players in the field and people are spoilt for choice.</p>
<p>With Internet Explorer and Mozilla Firefox leading the field, what exactly are people looking for when choosing their default browser? What are the features that are necessary? and what security do these browsers give the users? </p>
<p>The answers to the above questions could be hundreds and mostly depends on what the user need from the browser and how he/she uses the Internet. If its a home user who only uses the browser to access webmail and check out the news, then simplicity is a must &#8211; but if its for a high end user who needs a number of toolbars, then flexibility would be the key!<br />
<span id="more-85"></span><br />
<strong>Internet Explorer</strong><br />
This is one of the most common browsers &#8211; not for functionality but because many desktop computers use a Microsoft operating system which incorporates Internet Explorer in it &#8211; although the trend is changing (mostly because of the increasing prices of proprietary operating systems). Recently we&#8217;ve witnessed the release of Internet Explorer 8 which, I must say, was quite a good step. It includes private browsing whilst adding some more security for the user &#8211; it also inherited the tab feature from its predecessor but which came in too late compared to Firefox and Opera. The main drawbacks are that it is quite slow during the installation and not to mention the high resource usage.<div id="attachment_89" class="wp-caption alignleft" style="width: 160px"><img src="http://gamsec.files.wordpress.com/2009/06/ie7-vs-firefox-2-0-vs-opera-9-20-2.png?w=150&#038;h=150" alt="Who&#39;s winning the race?" title="ie7-vs-firefox-2-0-vs-opera-9-20-2" width="150" height="150" class="size-thumbnail wp-image-89" /><p class="wp-caption-text">Who's winning the race?</p></div></p>
<p><strong>Mozilla Firefox</strong><br />
As any OSX Product, it is very reliable and solid. Being open-source means that more toolbars are created with full compatibility are available, and whilst 3rd party applications are risky (for security reasons), this browser blends them seamlessly into the interface making you believe that these are built-in features. Speed is one of its main virtues whilst it lacks on user-friendliness (to a certain extent). This is mainly due to the fact that it has so many functions which might become confusing for the standard user. Crashes are not very often &#8211; although I&#8217;ve experienced an increase in crashes when using it over a Vista platform &#8211; but the main drawback is that if one tab crashes, all other tabs do the same &#8211; but there is always the session restore function which might come in very handy.</p>
<p><strong>Opera</strong><br />
Another free browser which is increasing in popularity but still not very common with the end user. Unfortunately, it lacks some essential features such as ad-blocking or private browsing, in addition to being relatively slow when compared to Mozilla Firefox. On the other hand, it has an excellent browsing history and synchronization whilst it doesn&#8217;t put a lot of burden on old computers.</p>
<p><strong>Writer&#8217;s Choice</strong><br />
Allow me to give my personal opinion on this. I am personally a fan of open-source because I believe in knowing whats going on in your machine. I have used all the above but I couldn&#8217;t walk away from the Mozilla Firefox browser. In principle, I think that due to its flexibility it is much safer &#8211; even looking at the amount of security fixes that Microsoft issues (I wouldn&#8217;t be the first one to install a Microsoft browser exactly after the release). In addition, it offers much more customization because more developers are inclined at developing add-ins for this browser rather than for the proprietary Internet Explorer.</p>
<p>Opera has improved a lot over the years, however it lacks in speed and flexibility, making Firefox the ideal choice for every type of user.</p>
<br />Posted in Internet Browsers Tagged: applications, browser, computer, firefox, Internet, Internet Explorer, Microsoft, Mozilla, Opera, Security, user <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gamsec.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gamsec.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/gamsec.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/gamsec.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/gamsec.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/gamsec.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/gamsec.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/gamsec.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/gamsec.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/gamsec.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/gamsec.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/gamsec.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/gamsec.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/gamsec.wordpress.com/85/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=85&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gamsec.wordpress.com/2009/06/05/battle-of-the-browsers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3ce969f036c163176d21cd83cdd21856?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Nello</media:title>
		</media:content>

		<media:content url="http://gamsec.files.wordpress.com/2009/06/ie7-vs-firefox-2-0-vs-opera-9-20-2.png?w=150" medium="image">
			<media:title type="html">ie7-vs-firefox-2-0-vs-opera-9-20-2</media:title>
		</media:content>
	</item>
		<item>
		<title>How to remove the MSN Virus?</title>
		<link>http://gamsec.wordpress.com/2009/06/04/how-to-remove-the-msn-virus/</link>
		<comments>http://gamsec.wordpress.com/2009/06/04/how-to-remove-the-msn-virus/#comments</comments>
		<pubDate>Thu, 04 Jun 2009 09:44:25 +0000</pubDate>
		<dc:creator>Nello</dc:creator>
				<category><![CDATA[Viruses and Trojans]]></category>
		<category><![CDATA[anti-spyware]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[attackers]]></category>
		<category><![CDATA[IM]]></category>
		<category><![CDATA[Instant Messaging]]></category>
		<category><![CDATA[links]]></category>
		<category><![CDATA[Messenger]]></category>
		<category><![CDATA[MSN]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://gamsec.wordpress.com/?p=80</guid>
		<description><![CDATA[One of the major threats for Internet users are viruses and trojans. I&#8217;m quite sure that at some point, every Internet user fell victim of a virus or trojan &#8211; the difference is that some knew about this and removed it, whilst some others didn&#8217;t and kept it spreading. Attackers are normally trying to find [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=80&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<blockquote><p>One of the major threats for Internet users are viruses and trojans. I&#8217;m quite sure that at some point, every Internet user fell victim of a virus or trojan &#8211; the difference is that some knew about this and removed it, whilst some others didn&#8217;t and kept it spreading.</p></blockquote>
<p>Attackers are normally trying to find the best platform to spread their virus as much as possible and what better than using the latest Internet trend? That means, Instant Messaging! I, for one, receive tens of messages from people who are on my MSN contacts list saying that they have a picture of me and inviting me to click a link. Luckily for me, I&#8217;ve never clicked on any of these links but I&#8217;m pretty sure that many would click even for the sake of being curious.<br />
<span id="more-80"></span><br />
The MSN Virus has spread quite a lot and many users are effected by this. The problem is that the actual victim won&#8217;t realize anything because these messages are sent to the people on his/her contact list automatically. At this point, its very useful to notify that person about what happened so that he/she may attempt to remove the virus.</p>
<p>Unfortunately, uninstalling and re-installing MSN Messenger won&#8217;t work because the file would still remain on your machine. In fact, you&#8217;ll need to take further steps to get rid of this virus. Here are some tips to avoid this virus:</p>
<p><div id="attachment_81" class="wp-caption alignleft" style="width: 122px"><img src="http://gamsec.files.wordpress.com/2009/06/msn.jpg?w=112&#038;h=150" alt="Tell your friend that he/she is infected!" title="msn" width="112" height="150" class="size-thumbnail wp-image-81" /><p class="wp-caption-text">Tell your friend that he/she is infected!</p></div>1. Never click on a link without asking the sender what it is. If your friend confirms that he/she sent the link, then go ahead and click it, otherwise just close the window and ignore the link.<br />
2. Always inform your friends if you receive a link from them but NEVER click on it<br />
3. Use an anti-virus software and keep it constantly updated<br />
4. Make sure that you always have the latest release of the Instant Messenger</p>
<p>What if you are the victim of this virus? How to remove it:<br />
What happens is that at some point you have actually clicked on a link which led you to a seemingly legitimate website. What happened here was that you tried to log in &#8211; but in reality you were only giving away your username and password to the attackers. </p>
<p>Once they obtain your credentials, they would use an automated system to log into your account (although it would remain as offline for others) and submit the same link to everyone on your contacts list &#8230; and the cycle continues. </p>
<p>At this point, the best thing to do is:<br />
1. Run a thorough virus-check to ensure that your machine is not infected<br />
2. More importantly, change your MSN Password so that the attacker&#8217;s system won&#8217;t be able to log into your account again<br />
3. Continuously upgrade both the anti-virus and anti-spyware software</p>
<p>Its good to notice that there are more than one MSN Virus. This only resolve the problem for one of them but since most IM-related viruses work in the same way, this could be the solution.</p>
<p>If you&#8217;ve tried the above without success, submit more details about the message that your machine is sending others and I&#8217;ll try to help you out with a solution.</p>
<br />Posted in Viruses and Trojans Tagged: anti-spyware, anti-virus, attackers, IM, Instant Messaging, links, Messenger, MSN, password, trojan, virus <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gamsec.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gamsec.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/gamsec.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/gamsec.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/gamsec.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/gamsec.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/gamsec.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/gamsec.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/gamsec.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/gamsec.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/gamsec.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/gamsec.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/gamsec.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/gamsec.wordpress.com/80/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gamsec.wordpress.com&amp;blog=7889738&amp;post=80&amp;subd=gamsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gamsec.wordpress.com/2009/06/04/how-to-remove-the-msn-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3ce969f036c163176d21cd83cdd21856?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Nello</media:title>
		</media:content>

		<media:content url="http://gamsec.files.wordpress.com/2009/06/msn.jpg?w=112" medium="image">
			<media:title type="html">msn</media:title>
		</media:content>
	</item>
	</channel>
</rss>
