Layout Image
  • Computer Club
  • Training and Support
    • Computer Training and Support
    • Meeting Times and Location Maps
      • Caloundra Technology Education Centre
      • Yandina Technology Education Centre
      • Buderim/Maroochydore Technology Education Centre
    • Free Internet Tutorials
      • Kawana Library
  • Members Only
    • Membership Signup
    • Members Home Page
    • Members Bits’N'Bytes Ezine
    • Members Forum
    • Members Free Windows PC Software
      • Members Free Graphics Software
      • Members Free Internet Software
      • Members Free Multimedia Software
      • Members Free Office Software
      • Members Free PC Security Software
      • Members Free System Maintenance Software
    • Members Computers For Seniors
    • Members Open Office Tutorials
    • Members Macintosh Tutorials
    • Members Gimp Tutorial Videos
    • Members Website Design Group
  • Interests Supported
    • Linux Operating Systems
    • Apple Mac Operating Systems
    • DIY Website Design and Marketing
    • Graphics & Digital Image Manipulation (Including Slide Shows)
    • Digital Video Editing
    • Internet Use
  • Blogs and Articles
    • All SCCC Blogs
    • Audio and Sound
    • Open Office
    • Computer Security
    • Linux
    • Health and Environmental Effects of Technology
    • Home Entertainment
    • General Computer Help
    • Computers
    • Computer Tutorials
    • Buying and Selling on Ebay
  • Club Events Calendar
  • Join Club
    • Membership Fees and Details
  • Club Links
    • Club Sponsors
    • Members Website Links
  • Contact Us

Archive for Computer Security

Hacking, the good, the bad and the ugly

By Peter Daley · Comments (1)
Sunday, July 31st, 2011

by Peter Daley

 

Hacking as an activity is now wide spread and International, as our society has become more and more dependent on everything being controlled by computers. Hacking has become a much more influential activity for the good, the bad and the ugly in our society.

 

I know the media constantly portrays hacking as an evil activity, but I quote from Wikipedia here, a hacker is by definition, "A person who enjoys exploring the details of programmable systems and stretching their capabilities, as opposed to most users, who prefer to learn only the minimum necessary."

 

Our world wide infrastructure is so tied to computers that hacking can now be used as powerful tool for intelligence, construction or destruction of our industrial or communications infrastructure. Western countries complain about the Chinese, or the Russians hacking their systems. The West have their own special unites dedicated to hacking Russian, and Chinese systems. They're all just as bad as each other, they are all constantly trying to break into each others sensitive systems. World wide, given an opportunity, any country will use hackers to gain an advantage, commercially, politically, or militarially. Corporations are constantly using hacking to improve their commercial advantage. The News of the World mobile phone hacking scandal is a good example of this. (Read my blog on mobile phone hacking here, http://sccc.org.au/archives/1602)

 

Hackers have been trying to find ways to break chip based industrial control systems for years. It ended up that the West and Israel secret services handed them the information they needed to do this on a platter. This story would make a best seller, or a great movie. The West and Israelis wanted to stop the Iranian nuclear program, or at least slow it down. They went to the big industrial chip makers and got what was secret or proprietary back door information to control industrial chips. In this case, the industrial centrifuges that where being used by the Iranians to concentrate uranium for their nuclear programs. They then went away and developed a very effective virus called Stuxnet. It was released into the Iranian enrichment plant control systems and it did what is was designed to do, it destroyed large numbers of the Iranian centrifuges.

 

They were very pleased with themselves, and gave themselves a pat on the back. Job well done they thought. Except that now they had opened Pandora's box and provided what hackers have wanted for years, back door industrial chip information to enable them to make viruses, and Trojans to control, disrupt, or destroy industrial control systems. By back engineering the Stuxnet virus which now is in the wild, thanks to the West and the Israelis, any government, criminal group, corporation, or hacker with some skill can create their own variation on Stuxnet.

 

This means that previous viruses will look like child's play. This technology can potentially be used to shut down power plants (nuclear, coal or hydro), electricity grids, water supply systems. Also, industrial plants or anything using industrially control chips can be a targeted. There have already been instances where Stuxnet variations may have been used to shut down, or disrupt Nuclear power plants and other industrial systems in a number of countries. No one is admitting that Stuxnet or a variation may have been the cause of these mysterious shut downs, or disruptions to Nuclear power plants in the USA, or Japan recently.

 

Well there you have it, and we are consider ourselves to be Intelligent. We're like children playing with fire.

 

Now we have hacker groups that are saying they are using their skills for the benefit of humanity by standing up to what they consider to be corporate imperialism. A splinter group of hacker group “Anonymous” have now focused on multinational Corporate food giant Monsanto.

 

Below is a text transcript of a video message they posted on the Internet.

 

——————————————————————————-

 

To the free-thinking citizens of the world:

 

Anonymous stands with the farmers and food organizations denouncing the practices of Monsanto We applaud the bravery of the organizations and citizens who are standing up to Monsanto, and we stand united with you against this oppressive corporate abuse. Monsanto is contaminating the world with chemicals and genetically modified food crops for profit while claiming to feed the hungry and protect the environment. Anonymous is everyone, anyone who can not stand injustice and decides to do something about it. We are all over the Earth and here to stay.

 

To Monsanto, we demand you STOP the following:

 

- Contaminating the global food chain with GMO's.
- Intimidating small farmers with bullying and lawsuits.
- Propagating the use of destructive pesticides and herbicides across the globe.
- Using "Terminator Technology", which renders plants sterile.
- Attempting to hijack UN climate change negotiations for your own fiscal benefit.
- Reducing farmland to desert through monoculture and the use of synthetic fertilizers.
- Inspiring suicides of hundreds of thousands of Indian farmers.
- Causing birth defects by continuing to produce the pesticide "Round-up"
- Attempting to bribe foreign officials
- Infiltrating anti-GMO groups

 

Monsanto, these crimes will not go unpunished. Anonymous will not spare you nor anyone in support of your oppressive illegal business practices.

 

AGRA, a great example: In 2006, AGRA, Alliance for a Green Revolution in Africa, was established with funding from Bill Gates and The Rockefeller Foundation.

 

Among the other founding members of, AGRA, we find: Monsanto, Novartis, Sanofi-Aventis, GlaxoSmithKline, Procter and Gamble, Merck, Mosaic, Pfizer, Sumitomo Chemical and Yara. The fact that these corporations are either chemical or pharmaceutical manufacturers is no coincidence.

 

The people of the world see you, Monsanto. Anonymous sees you.

 

Seeds of Opportunism, Climate change offers these businesses a perfect excuse to prey on the poorest countries by swooping in to "rescue" the farmers and people with their GMO crops and chemical pesticides. These corporations eradicate the traditional ways of the country's agriculture for the sake of enormous profits.

 

The introduction of GMOs drastically affects a local farmers income, as the price of chemicals required for GMOs and seeds from Monsanto cripples the farmer's meagre profit margins.

 

There are even many cases of Monsanto suing small farmers after pollen from their GMO crops accidentally cross with the farmer's crops. Because Monsanto has a patent on their brand of seed, they claim the farmer is in violation of patent laws.

 

These disgusting and inhumane practices will not be tolerated. Anonymous urges all concerned citizens to stand up for these farmers, stand up for the future of your own food. Protest, organize, spread info to your friends!

 

Say no to poisons chemicals in your food.
So no to GMO!

Say no to Monsanto!
We are Anonymous
We are legion
We do not forgive
We do not forget

Expect us

 

To back up their claims they provided these links.

 

Birth defects caused by Monsanto chemicals – Here

http://www.huffingtonpost.com/2011/06/07/roundup-birth-defects-herbicide-regulators_n_872862.html

 

Monsanto hired mercenary Blackwater to infiltrate anti-GMO groups – Here

http://www.digitaljournal.com/article/297701#ixzz1HDZcVpoj

 

Monsanto fined $1.5m for bribery In Indonesia – Here

http://news.bbc.co.uk/2/hi/business/4153635.stm

 

Monsanto Accused of Attempt to Bribe Health Canada for rBGH (Posilac) Approval – Here

http://www.ethicalinvesting.com/monsanto/news/10009.htm

 

Destruction of soil, air quality, groundwater contamination, deforestation – Here

http://www.washingtonpost.com/ac2/wp-dyn?pagename=article&contentId=A46648-2001Dec3

 

Corporate food giant Monsanto uses patents to bully small farmers and strangle competition – Here

http://www.examiner.com/sunset-district-libertarian-in-san-francisco/corporate-food-giant-monsanto-uses-patents-to-bully-small-farmers-and-strangle-competition#ixzz1R1zkI2qK

 

Farmer suicides in India – Here

http://www.independent.co.uk/environment/climate-change/indias-hidden-climate-change-catastrophe-2173995.html

 

—————————————————————————-

 

You can watch the video of the above transcript at Youtube here. http://www.youtube.com/watch?v=Q1A-DYK4M4Q&feature=player_embedded

 

Hacking as an activity has grown to be the good, the bad and the ugly computer power of the twenty first century, love it or hate it, it will be shaping our future.

 

© Peter Daley 2011

Comments (1)
Categories : Computer Security, Computers, Uncategorized

Freedom and Privacy being eroded by Technology!

By Peter Daley · Comments (0)
Monday, May 30th, 2011

Technology is becoming Big Brother’s surveillance tool. Everything we now do in modern society is being recorded and watched, whether you like it or not. Let’s look at the personal computer of the twenty first century, the mobile phone.

What can it do.

  1. It pulses every 8 seconds even if it is turned off, and from this pulse your location can be triangulated. The only why to stop this is to take out the battery and sim card.

  2. New phones will have a gyroscope built in so you can get those fancy games working well. This can be used to work out what you are physically doing at any point in time, walking running, driving, or cleaning the windows etc.

  3. Even if the mobile is turned off it can be used to take a picture, or record your conversations. Look up mobile phone hacking on youtube if you want proof.

  4. The latest edition it its armoury of detective tools is to not only triangulate where you are at any given time, but also to record that information for later analysis. These personal location tracking and recording tools add a whole new dimension to the mobile phone tracking armoury. http://www.guardian.co.uk/technology/blog/2011/apr/25/steve-jobs-responds-iphone-tracking

  5. Record all your keystrokes and SMS messages, plus send this info off somewhere unknown,  http://news.cnet.com/8301-13506_3-57333652-17/android-handsets-secretly-logging-keystrokes-sms-messages/?part=rss&subj=news&tag=2547-1_3-0-20&tag=nl.e703

This information was not volunteered to the public by Google, or Apple, but discovered by independent researchers. The big question is why two so called independent rival corporations had quietly installed personal location tracking, and recording tools on their phones. It is only by a chance discovery that it was revealed.

You buy a mobile phone to have convenient mobile communication, not to be a Big Brother tool for recording and watching every thing you do. Not only can this technology be used by governments, and corporations, but anyone who wants to do some basic research can get the tools to use it to gather your private information, and movements.

When you purchase a Mobile Phone it should come with a clear warning!

  • You may be tracked when using this device for government, or corporate use.

  • Your conversations may be recorded without your knowledge.

  • The device may take photographs without your knowledge.

  • Your psychical activities may be monitored at any time without your knowledge.

  • All your Keystrokes and SMS messages are recorded, and sent off to somewhere unknown.
  • It can be hacked easily so the manufacture accepts no responsibility for the loss of private information.

  • Use at your own risk as the radiation from mobile phones may affect your health.

 

Mobile Phone health risk Industry sponsored research says it has no effect except for a slight warming on the body tissue. Independent researcher indicates long term frequent use can potentially cause serious health problems. Read my previous article here on this subject http://sccc.org.au/archives/1574

The mobile is now being touted as a wallet to be used instead of cash, or credit cards.

http://www.ibtimes.com/articles/153830/20110528/google-wallet.htm

Governments and history change, with these technologies governments can impose total control over their citizens. There has already been numerous instances of a number of governments using this technology to track, and collect citizen‘s information, andat times pass on this intelligence to corporations the citizenswere protesting against.

You won’t be able to sneeze, or go to the toilet without the government knowing about it. In the machine verses human, I think the machine is winning!

© Peter Daley 2011

Comments (0)
Categories : Computer Security, Computers, Health and Environmental Effects of Technology

Investor Beware

By Peter Daley · Comments (0)
Tuesday, November 30th, 2010

Financial systems have changed dramatically with the advent of computer technology. It has allowed ease of access to your banking, and investment information. We now have the ability to deposit, and transfer funds instantly, and electronically.

 

Unfortunately, it has also allowed a lot of growth in corruption at high speed!

 

High speed trading, using super computers provides the big players with the ability to manipulate the market easily .  Market volume can appear to be high where in fact it can just be an enormous number of trades for small amounts of money. The use of super computers and sophisticated software has given the big banks, and investment houses great power. By using super high speed computation, and analyst of financial information they can influence the price of stocks, and shares at will.

 

In my opinion it has become a very uneven playing field for the small investor. It also appears that by the use of power, and money these large banking, and investment organization have been influencing politicians to remove a lot of the institutional checks, and balances that where put in place to protect everyone.

 

Have a look at this 60 Minutes program to get a lot of good information on what you are up against if you are a small investor.

 

How Speed Traders Are Changing Wall Street – 60 Minutes – CBS News
 

60 Minutes on CBS News: How Speed Traders Are Changing Wall Street – Steve Kroft Gets A Rare Look Inside the Secretive World of "High-Frequency Trading"

 

Another import issue that I have been seeing in stock, shares and commodities markets is more and more use of virtual products. The gold market is a case in point. Gold is commanding large amounts of money at present ,and investors are purchasing gold in large volume all over the world. The trouble is that the volume of gold that is being traded at present is 45 times more gold than is psychically available.

 

That means that if every one who purchased gold wanted their bars at once, only one in 45 could possibly get the purchased gold! Now the informative link below clearly defines what most people are actually purchasing is paper gold.

 

Here is a definition on Paper Gold from site https://www.igolder.com/glossary/paper-gold/

How can we have a system base on this virtual gold, and not the real thing?

How is this allowed to happen?

In my opinion lot of people are going to get burned if, and when the music stops.

If that is not bad enough here you have reports of a lot of fake gold bars in the system.

Fake gold bars out of tungsten a counterfeit story By MERLIN LAFLEUR, 2009/12/02

Gld ETF Warning, Tungsten Filled Fake Gold Bars :: The Market …

12 Nov 2009 … Gld ETF Warning, Tungsten Filled Fake Gold Bars :: The Market Oracle :: Financial Markets Analysis & Forecasting Free Website.

 

The only way I can see that this has been bought about is by our government officials, and politicians changing the legislation, and rules to suit those who run these markets. The politicians and government officials must have great retirement funds.

 

Mortgage Gate is another example on the creative use of computer technology by the corrupt. It has been used to manipulate the financial  system, and create financial havoc worldwide. If you wonder why your retirement funds, and superannuation have gone backwards here are some more examples of the creative use of computer technology to create mass fraud of epic proportions. Sell something ten or more times to different organization, and class it as an AAA investment.

 

The mortgage gate crisis and the coming wave of “Mulligan …

and here

http://www.zerohedge.com 21 Oct 2010 … The mortgage gate crisis and the coming wave of “Mulligan Mortgages”. … If you are suddenly being offered a new mortgage by your bank.

 

Computer technology has changed the way financial systems work, a lot of what is being offered for sale as an investment, or commodity is no longer real but a fictitious virtual item of no real value. So I would suggest that if you are investing in anything, you make sure you are really purchasing something of real value. A lot of this information is not provided by the main stream media, so you need to do your own research on your subject of interest.

 

Disclaimer

NOTE: This article is in no way intended as to convey any financial advice on behalf of the SCCC inc., or Peter Daley. It is for information purposes only.

 

©  Peter Daley 2010

Comments (0)
Categories : Computer Security

NoScript Essential to Web Surfing

By Peter Daley · Comments (0)
Sunday, January 24th, 2010

by Peter Daley

At present, the hacker black market is paying $100 per thousand hacked Australian computers. That's correct, there is a black market for hacked computers, and Australian computers are fetching top dollar, compared to other countries. Why do you think that Australian computers are getting top dollar? It's because we are easy targets as most of you don't take computer security seriously enough, plus being an affluent country, the hackers can make better money from a hacked Aussie.

 

You could argue the affluent part, depends on whether the banks get to your money before the hackers do ;-) You can secure your computer with all the modern, up-to-date security tools, but if you don't follow safe practices, you're very likely to get hacked or ripped off. It's just like driving a new car, with all the latest safety features, air bags and intelligent breaking systems, if you drive dangerously, you're more likely to crash and get injured. You need to use some common sense on the Internet, and stay away from sites that are notorious for hacking visitors computers, pornography, software cracks, copy violated music sharing and movie sites etc.

 

One other major new treats used by hackers is to break in though security holes in web browsers. This poses a serious threat to all operating systems Windows, Apple and Linux. This article reinforces what I have been trying to get across to everyone.

http://www.news.com/8301-10784_3-9929861-7.htm l?tag=nl.e703

 

They can use malicious scripts hidden in web pages to exploit vulnerabilities in any OS. The way to defend yourself against this sort of threat is to turn off all scripts. Unfortunately scripts are so wide spread that if you do this you can lose a lot web page functionality. Alternatively you can use the the Mozilla Firefox web browser downloadable from here,

 

http://www.mozilla.com

 

and install a Firefox Add-on called “NoScript”, this will effectively block all scripts in pages you visit. You then use NoScript to choose when to allow scripts.

 

Once Mozilla Firefox is downloaded and installed on your computer, and you are connected to the Internet, click on the menu item “Tools”, and in the pop down box, click “Add Ons”. When an “Add-ons” box appears, click on the “Get Add-ons” tab.

 

In the search box at the top left of this box, type in “Noscript” and click the “Search” button, then when the Noscript add-on description appears click  the “Add to Firefox” button. The software installation box will now appear, click the the install button. The NoScript extension will be installed. Once it is installed, you will need to shut down,and re-open the Firefox browser before NoScript will become active.

 

(When you re-open Firefox I suggest you read the information about NoScript that will appear in a tab window in Firefox.)

 

Now when you visit web pages a Noscript options button, and symbol will appear at the bottom right hand corner of the Firefox browser window. A yellow bar will also appear indicating how many scripts are in the page that are being blocked.

 

Blocking all the scripts will speed up your web surfing because you will not need to wait until the all the fancy stuff loads. It will also mean you will need to make wise decisions on when to allow scripts in web pages. I suggest not allowing any scripts in pages unless you really need the service. For instance, if you go to your web bank service with NoScript you will not be able to log in until you tell Noscript to “Allow the bank site”, by clicking on the NoScript Options button. So login boxes for services, plus Flash, Silverlight, and Java scripts will be blocked until you click the Noscript allow site, or temporary allow option, when visiting any site. If you use it with another Firefox Add-on WOT, (Web Of Trust) a web site rating service it can make those decisions easier to make.

 

Statistically 1 in 9 web sites are dangerous at present! If you think I am exaggerating look at the web site rating stat's at the bottom left hand corner of the WOT home page web site. So using NoScript wisely can give you a lot of protection!

 

© 2010 Peter Daley,

Comments (0)
Categories : Computer Security

What Wireless Security?

By Peter Daley · Comments (0)
Monday, January 4th, 2010

by Peter Daley

 

The statistics are pretty frightening, 70% of home, and small business wireless routers providing broadband connections, have no security on them. In reply to a previous blog I had written in a local newspaper, I was urged by a post to write an article on wireless security, after the person had this experience.

 

“I've recently started taking my laptop on the train in order to do some work. I decided to fire up a great bit of software called Network Stumbler. This software uses the wireless network card in my laptop to record the details of every wireless network it finds. In 10 minutes I passed by around 50 networks, 7 of which were completely unsecured.”

 

Look, you have been sold a pup. Computers where never intended to be used for financial transactions. I know, they are widely promoted to do this. Great for the banks and the IT industry, promoting it as a convenient way to improve your life style. They make money, but this technology is not certified, or made secure enough to do this safely.

 

Would you use an ATM provided by your local bank, if you knew it was not certified by the regulatory authorities, did not have proper security on it, or if it was purchased on the cheap from a foreign country in a manufacturing plant with no security clearance? Well what do you think your computer is!

 

Wireless systems are another good example of this. You're encouraged to ditch all those old fashioned wired connected devices, and go wireless. It just makes everything neater and accessible from anywhere. The truth is, that if you are using your computer for financial transactions of any kind, you should not use an in house wireless system. Use a cable to connect your computer to your broadband modem. If you're using wireless at present, turn off the wireless feature, and use a network cable connection. It's just a whole lot safer, as long as you follow my instruction in this blog on securing your broardband modem.

 

If you have some technical skill, or employ a professional to set up that wireless broadband router security correctly, it will be a lot safer. Even then, people with a good skill level can download the tools necessary to break in to most in house wireless systems fairly easily. Not that they would need to bother with downloading the tools, as most systems don't have any security!

 

Wireless War driving is a pastime in a lot of locations now. This is where someone sticks an aerial on their car, and drives around to see what wireless systems they can break into. They then infect the system to take control of it, gather personal information, banking info, or just use the victims computer to download or send files. Wireless hacks are local, not from the Internet.

 

If you're running a business with wireless systems in house, you need to take more care, because your financial info, client data, and commercial secrets are at risk. A wireless system is basically a radio station, transmitting and receiving information. To anyone who can detect, and connect to it, it's like opening all your doors and windows, and inviting them in. I have heard numerous stories where locals have bragged that they don't need to pay for a broadband connection, they just use their neighbours!

 

Often I am asked the question, why a person's Internet access charges have sky rocketed. Most likely because someone is using their in house wireless broadband connection, or they have a virus. Everyone needs to get up to speed on all these security issues, so you can protect yourself. As a community service in my previous blogs, I have put in a lot of effort to educating readers, and providing solutions to the increasing security threats.

 

If you insist on using wireless, read this blog on securing it. There are also heath concerns about using computer wireless technology, as it is working in a similar frequency band to mobile phones. Read this article.

 

The fact is, consumers should be demanding security, over features and convenience!

 

© 2010 Peter Daley,

Comments (0)
Categories : Computer Security, Health and Environmental Effects of Technology

Using Key Generators, and Cracks is just plain stupid!

By Peter Daley · Comments (0)
Sunday, October 25th, 2009

by Peter Daley

 

I have done numerous tutorials over the year in the club pointing out that using a key generator, or a software crack to make illegal use of software is just plain stupid. Firstly a person using these illegal tools are leaving themselves open to legal action. There is no doubt they are breaking the law. Secondly key generators and software cracks are almost always infected with malware of some sort. etc., a virus, or rootkit. Rootkits are so stealthy that they can't be detected by most anti-virus programs.

 

This sort of malicious software can place keyboard loggers onto a computer, and record all the persons user names and passwords for banking, email, social networking sites and ISP accounts. These malicious tools can also be used to pinch confidential information that is stored on the computer.

 

If anyone has encouraged a person to use one of these tools they have done them a great disfavour. If a person is using a computer for financial transactions of any kind and have used one of these tools they are taking a big risk. I would suggest they back up all their important files and re-install their operating system. After they have done this secure the new installation with a good firewall, anti-virus and anti-spyware program.

 

I would suggest they change all their banking account and log in account passwords etc. If you are going to the trouble to create a new password make sure it is actually going to protect you. Read my article, on how to create good secure password.

The Windows Operating system can only be used on the computer it was purchased with, and can't be install on any other computer. If you have a legal version of Windows installed on your computer you can constantly update it with the latest security patches. This means that legal patched versions of Windows are far more secure than a cracked illegal version. A pirated version of Windows is far more likely to have a virus, spyware or rootkit on it immediately upon installation, plus it can't be updated.

 

This is one of the reason so many machines were compromised by the Downup virus. These Windows machines did not have the latest Windows patches on them. One because people did not install Windows updates regularly or they were using an illegal version. They probably have seen themselves as being smart using the illegal version to save themselves a couple of hundred dollars, but if they are doing any logging into financial sites, or have important information on the computer the bad guys probably have recorded it.

 

If the commercial software does the job better than anything else, buy it, or alternatively look for a free legal software program that can do the job. There is just so much free legal software available that can do just about any job you could possibly need.

 

© Peter Daley 2009

Comments (0)
Categories : Computer Security

Wireless Security! You need to be a Secret Agent

By Peter Daley · Comments (0)
Friday, October 16th, 2009

By Peter Daley

 

Securing you wireless router is an adventure. You will need to be a bit secret agent, plus be willing to play the odds. Your tools will be some dice. You know the type they use to gamble at the casino, or you play board games with.

 

First of all secure your wireless router with a better password than the one supplied by the manufacturer which is usually admin / admin or admin / password. Read theses two previous blogs,

 

Even thought these blogs are about broadband modems and general password creation the info equally applies to wireless routers. If you don't secure the device first the rest of the security set up is a waste of time. You should just resign as a 007 agent now.

 

This is were your 007 skills come in. Go to the Diceware site,

 

http://world.std.com/~reinhold/diceware.html

 

This is where you hone your secret agent skills on using the dice to create a really good quality secret agent passphase.

 

Now play the odds, download the dicewarewordlist.pdf. This is your tool to create a really good WPA2 passphase. The passphase must be longer than 20 characters using a splattering of unusual characters. Most of you who actually attempted to put some form of security on your wireless router would be using 20 characters, or less dictionary word base passphase, and hackers are laughing. It has been know for many years that a WPA 20 characters, or less dictionary word base passphase is easily broken.

 

Now you take the dice, and dice word list into a room and close the curtains. Why the drawn curtains? Every secret agent worth his salt knows they they can now read what your typing from the reflections in the window. Also, don't leave your keys to your computer room lying around because they can now make key duplicates from a photograph. Boy, don't you know anything.

 

After you have created and memorized the secure paraphase key you can burn it, pulverize it in a mortar and petsal, and flush it down the toilet. Make sure you flush twice. Ok, a bit over kill for most of you. One flush is probably enough. Write into your secret code book because it going to be so complicated most of you won't remember it anyway. Don't store it in your computer.

 

Are you still with me secret agents. Now we have to enter the key into the WPA2 / AES wireless setting in your wireless device. Man this is all ridiculous, your telling me. I haven't finished yet!

 

Turn Off,

  1. Turn off Broadcasting your wireless SSID. Don't use the factory default SSID change the SSID wireless ID to a very unusual set of characters.

  2. Turn of DHCP auto IP address assignment and assign all your network IP addresses manually.

  3. Turn off WAN if you don't need it.

  4. Turn off high power wireless transmission, if you don't need it. If your leave these two things on you will have created a very powerful radio station transmitting your presents into the suburb. Not good for secrecy!

  5. Turn off your computer, wireless router, and broadband modem when not in use. This significantly lessons the opportunity for the bad guys can break in. It will also helps the planet and you hip pocket, by using less electricity, thus lessing the production of green house gases. Read my previous blog on this subject.

  6. Turn off the UPNP (Universal Plug and Play) feature. IMPORTANT also turn off UPNP in your Broadband modem as well if it is a separate device. NOTE: Xbox, video streaming, and VIOP devices may stop working when you do this. UPNP is really big break in vector for most wireless routers and broadband modems! Incidentally UPNP will be a big feature of the newest high speed wireless routers that will arrive soon!

     

    Turn On

     

  7. Make access to your wireless router more difficult by turning on access controls. This means that only a machine with a particular device MAC address, or IP address on your network has the ability to connect to your wireless router, to change the wireless router settings.

  8. Make sure the firewall is turned on and set to high if possible. If things stop working drop it a notch.

  9. Change the gateway address of your broadband modem form the standards factory addresses of, 192.168.1.254, 192.168.1.1, 192.168.0.1, 10.1.1.1, or 10.0.0.138, Use anything other than these numbers. These numbers make it so much easier for hackers to guess your network set up. Once you have done this enter the new gateway address into the wireless router.

 

If you have read this far you have earned your secret agent certificate.

 

Now you may see why I suggested in my previous blog to turn off you wireless router, and plug your computer directly into your broadband modem with a network cable. It is just simpler, faster, safer, and more reliable.

 

You don't need to go through the Diceware procedure, and only need need to do all of the above except for items 1 & 4 to secure your broadband modem, or yes plus the password creation bit. Ok! Isn't modern technology wonderful easy to use, and secure. Just network wire the place, it probably work out cheaper in the long run because you won't need to constantly upgrade to the latest wireless router.

 

A university recently created a concept virus for wireless systems. They let the virus go in wild in their local town and found the only thing that stopped it spreading further was the local river. Just like one person catching a cold, and then giving it to anyone who comes in close contact.

 

© 2008 Peter Daley

Comments (0)
Categories : Computer Security

Who is Spying on You!

By Peter Daley · Comments (0)
Friday, October 16th, 2009

By Peter Daley

Who could be spying on you over the Internet? Well lets see, governments, corporations, a competing business, data mining businesses, marketing organisations, and criminal gangs etc,. Spyware is all about commercial and personal information gathering. It can make big money, and is also useful for intelligence.

 

Spyware has become as an important an issue as virus infections, for Windows Computers. Spyware can collect personal information about your movements on the Internet, in it's most passive form, but can also collect much more sensitive personal or commercial information from your computer, such as credit card and bank account information, or commercial secrets. It can also be used to open doorways to allow much more malicious programs, viruses or Rootkits, into your commercial or private Internet connected computer.

 

So it is important to install a couple of good spyware scanners on you Windows computer, and run them through your computer once a week. Most people are not aware of how serious a problem this is for Windows computers, and some of the better spyware scanners can check for approx. 450,000 spyware items, and increasing. With these numbers, it is very common for one spyware tool to find spyware the other one missed.

Here are some suggested spyware scanners you can use. They are free, or can be upgraded to commercial versions if you want that extra protection.

NOTE: There are increasing numbers of malicious Spyware and Anti-virus programs out there. They're designed to trick you into installing them. They will pop up on you screen with a warning that they have found viruses, and spyware on your computer, and that you should download and install them to remove the spyware or viruses. After they're installed, they will ask you to get out your credit card and purchase the program before you can remove the detected viruses or spyware. If you do this, they will then have your credit card info, your money, plus control of your computer! Isn't the Internet a wonderful place? It is full of such ingeniousness and creativity!

At present, Spyware Doctor and Spyware Terminator are considered to be a couple of the best spyware detectors. (These have won Internet Oscars under the "Spyware Detection" category, just joking! Everyone has their favourites, and may suggest others.)

 

You can download a free working version of Spyware Doctor from Google.

 

Go to http://www.google.com or http://www.google.com.au and click on the "More" link at the top left of the Google page. A pop down box will appear, go down to the "Even More" item and click it. A "More Google Products" window will open. Now navigated down to the bottom right hand corner of this page, and click on the "Pack" item under the "Make your computer work better", heading. Now select the programs you want from the google pack. I suggest you select Spyware Doctor and one other for this exercise. The "Google Downloader” program will now be downloaded to your computer. Once it is downloaded, you will need to double click on the Google Updater program to download and install the selected programs.

 

Once Spyware Doctor is installed, open it and go to the "Smart Updater" button at the top Right-hand corner of the Spyware Doctor open window. When the updates are finished click the scan button and select “Full Scan”. A limited trial version and commercial version of Spyware Doctor can also be downloaded from,

http://www.spywaredoctor.com

 

Spyware Terminator can be downloaded from here, http://www.spywareterminator.com

 

Once you go through the process or downloading Spyware Terminator, update it, and run a full scan of your Windows computer.

 

Now you can't have both of these programs running at the same time, so you will have to decide which one is to be your primary protector, and disable the other. You then update it, and run it manually each week to check the other one hasn't missed anything.

 

The way to turn it off is to look for it's icon in the system tray. The system tray is the line of icons that appear at the bottom right corner of the task bar on your opening Windows screen. Right click it's icon, and select "Shut Down" for Spyware Doctor, or "Exit" for Spyware Terminator in the pop up list that appears. You can restart them by navigating to their icon on the desktop, or in the program menu list.

 

With all these programs you should read their help files, plus navigate through their settings or preferences, to make sure they're running at their full protection potential. (NOTE: In Vista you will need to right click on the program icon, and select “Run as Administrator”, in the popup list, to get them working fully.)

 

The next blog will be on two easy to use Rootkit scanners you can use in Windows. Read my previous blog on rootkits "What on earth is a rootkit", to get some background on rootkits.

 

I hope you installed and scanned your computer with the free extra anti-virus checker I suggested in the bottom of my previous blog "False Sense of Security".

 

My friends and I spend our time doing other things, we use Linux or Apple computers :-)

 

© 2009 Peter Daley

Comments (0)
Categories : Computer Security

ROOTKITS, nothing to do with a kit to improve your sex life!

By Peter Daley · Comments (0)
Monday, September 21st, 2009

By Peter Daley

For those of you with a sense of humour, this has nothing to do with a kit to improve your sex life, in fact it would probably have the opposite effect! So what are rootkits? They are super stealth hacks that are hidden from most virus checkers and spyware detectors. Trouble is, large numbers of computers using the Windows operating systems are being infected with rootkits. I do a lot of computer troubleshooting and repairs, and in the last few weeks, I have been finding an increasing number of computers infected with rootkits.

 

So you've been diligent, and kept your virus, spyware, and firewall up to date, but one of the family has decided to use one of the music sharing systems, or visited a site, and your computer has been hacked through your web browser. Hidden inside your confidently safe computer is a super stealth rootkit.

 

You can run your virus checker or spyware removal tools till the cows come home, you won't find anything. You need to run this special tool called rootkitrevealer. Most of you are going to find the information on the rootkitrevealer page, gobbledy gook. Read it if your feel you will understand some, or just cut to the chase, and go to the bottom of the page and download the Rootkitrevealer.zip file. It is a compress zip file, so save it onto your computer, and unpack it. Then run the Rootkitrevealer.exe file on you computer.

 

If you have no understanding off the last two lines in the above paragraph, you're in over your head, and should immediately stop all Internet banking on your home or work computers. Change your banking password immediately and stick to phone banking or psychically go to the bank. This type of basic security knowledge is essential to your banking and business security on the Internet. Most people's faith in computer security is unfounded, and based on poor information.

 

So you run Rootkitrevealer on you computer, (By the way, there are more steps involved to run rootkitrevealer on Vista, at present), and you get discrepancy results. What do they mean? The best I can tell you in brief, is to look to the end of discrepancy lines, and you may need to widen the column to see them, items like SAC, SAI are normal, as are entries that may refer to your virus checker name. eg Symantecs (Norton's anitvir), or Nero, a CD burning programme. Most clean computers will only have a few normal discrepancies as described above. The more discrepancies, the more likely the breach to your computer security. Most people will not have a clue what are normal discrepancies and what are abnormal. Anything over about 4 or 5 is suspicious.

 

All I can say is take a deep breath, and read this free book on stress management.

 

If you find any rootkits, getting rid of them is another story. Have you got all afternoon! I really feel that most of you out there should stop Internet banking and use phone banking or go psychically to the bank. I have been demonstrating the use of Rootkitrevealer to Sunshine Coast Computer Club members.

 

© 2007 Peter Daley

Comments (0)
Categories : Computer Security

First Line of Defence, or is it?

By Peter Daley · Comments (0)
Monday, September 21st, 2009

By Peter Daley

Your ADSL Broadband modem is your high speed gateway to the Internet. It is also your first line of defence against attack, so it should be secured. Isn't it already? NO. The vast majority of home and small business modems are being operated by their owners, thinking that it is secure and it ain't!

 

Imagine that every new model of a Toyota, Holden, or Ford Car built, was sold with the same set of keys. You would all be jumping up and down complaining. Anyone could have instant access to your new car. Hey, that's just crazy! Yes it is.

 

And yet every model of broadband ADSL modem is sent from the factory with the same user name and password, plus the supplied username and password is generally admin and admin, or admin and password. Now that's just crazy. Why? Because all a hacker has to do is detect what model modem you have, and they're into your network or computer. In actual fact, they don't even need to know what model, because different manufacturers use the same generic password. Plus most service providers may only supply a couple of different models of a particular brand, so If they find out which ISP you're using, they pretty well know what the password for your broadband modem will be.

 

This modem security issue could easily have been avoided by modem manufacturers generating a unique User Name & Password for every modem and sticking it under the modem, or in the supplied booklet! You would still be able to change it later.

 

Well, what can you do? Change the factory supplied username and password! The modem will be supplied with a small paper manual, or there will be a manual on the installation CD. Look for the item that refers to manual access, or manual set up, and follow the instructions for changing your username & password. If you're going to change this password, create one of those real random ones that everybody hates to try and remember. Don't use birthdays, pet names, 1234, or something simple. You have to make it complicated. Hackers have sophisticated tools that can crack simple passwords in seconds. So make is random, use some upper-case letters, numbers and symbols. Also, make it at least 12 characters or longer if possible. You don't need to remember it, stick it under the modem, or in a special password book. Some models will only allow you to change the password, but not the user name.

 

(This is important, the password and user name we want you to change is not the user name, (generally your email address) and password you have been supplied with by your ISP for accessing the Internet. This password and user name are also in the broadband modem. If you're seeing these entries, you're in the wrong place. Leave these entries alone, or you will lose access to the Internet!)

 

Another item to check while you're in there, is that your modem firewall it turned on. A firewall is a defence system built into modem, that monitors what systems are allowed to have access to and from the Internet. Think of it like a security guard on a building, watching who or what is allowed to enter or leave the building. It is a very big part of your Internet security and must be on a standard or high setting. If you set a firewall setting too high, you may lose Internet access. Consult your modem manual. If it is not on, you have probably already been hacked! I have come across seven ADSL modems in the last fortnight that had been hacked, and their firewalls had been turned off.

 

This means the hacker can not only have complete access to all your connected computers, but also potential to redirect you, or your staff, to malicious or counterfeit sites which look like your bank, but are not! They can also redirect traffic through your Internet account. This traffic can be lots of spam, virus attacks, terrorist or hacker communications. The hackers just love this because they can send all this malicious stuff anonymously. It's going through your Internet account so it is difficult to track.

 

Why would anyone want to do this to my computer? These days the hackers can make big money out of it. Crime gangs pay them good money to pilfer credit card information, bank user names and passwords, or send spam etc. It used to be just sport. "I can do this to poor unsuspecting saps". But now they can make good money doing what they enjoy. Isn't that everyone's dream! The IT industry just makes it easy for them.

 

© 2007 Peter Daley

Comments (0)
Categories : Computer Security
Next Page »

Recent Posts

  • Text in a Circle – Open Office
  • Radiation Cloud Detection Dunedin New Zealand 29th January 2012
  • Open Office Calc (Spreasheets) Adding Background Colour To Every Second Line
  • Fonts in Open Office
  • Brief large spike in local background radiation. What caused it?
  • Open Office Calc (Spreadsheet) Freeze Column Labels

Categories

Computer Help, Training and Support

Computer Club Locations and Times

Join the SCCC Computer Club Now

Sunshine Coast Computer Club
Copyright © 2012 All Rights Reserved
Website Design by Website Design Centre
Powered by WordPress