Articles by "General Security"
Showing posts with label General Security. Show all posts
Cpdemy is a knowledge driven hive dedicated to producing great how-to, tips and tricks, awesome tutorials on Photoshop, Wordpress, Blogger, SEO

In this in dept tutorial, you will learn everything you need to know about the types, symptoms, protection, prevention, detection and removal of malware (computer virus, ransomware, spyware, adware, rootkits, trojan horse, worms, etc..).

Everything explained in an easy way.


What is Malware?

Malware short for "malicious software" is software that is specifically designed to damage or disrupt a system, steal information (spy on you), or destroy data.

Malware is a broad term used to describe many different types of malicious programs.


Malware Types

Common Malware types are:

· Computer Virus - A computer virus is a malware that surreptitiously enters into a system that is capable of copying itself and spreading to other computers. Viruses can perform harmful activities on an infected PC such as corrupting the system or destroying data.

· Spyware  - secretly monitors your activities and gathers your information through your Internet connection without you knowing about it.

· Adware - shows unwanted advertisements on your computer and generate revenue for its creator. These advertisements are often in the form of annoying pop-ups (windows).

· Rootkit - is a collection of tools (programs) that are designed to remotely access or control a computer or network without being detected. Rootkits are difficult to detect because they are activated before your system's Operating System has completely booted up.

· Trojan Horse - (also known as a "Trojan") disguises itself as a normal file or program to trick users into downloading and installing malware.

· Worm - is capable of copying itself and spreading to other computers. It uses networks to spread itself and causes harm by using a lot of bandwidth (this makes your internet slow) or possibly deleting files or sending documents via email. Worms can also install backdoors on computers. The difference between a worm and a computer virus is the way they spread – worms spread across networks and viruses attach themselves to various programs and executable codes.

· Ransomware - prevents or limits users from accessing their system or data. It forces its victims to pay the ransom through certain online payment methods in order to grant access to their system, or to get their data back.

· Keylogger - runs in the background and records every keystroke you make (everything you type on your keyboard). These keystrokes can include usernames, passwords, credit card numbers, and other sensitive and personal data. The keylogger will share this information with its creator.

· Botnet - (also known as a zombie army) is a network of malware infected computers which are controlled by the creator of the botnet (cybercriminal). Each computer functions as a "bot" because it's infected with a specific type of malware. A botnet can be used to send spam emails, transmit malware, perform DDoS attacks and perform other malicious tasks.

· Rogueware - often pretends to be security software such as antivirus and anti-malware software, but can also pretend to be other software such as system cleaners. This type of malware is simply misleading (fake) software that asks users to pay money for removing fake problems and threats. When a PC is infected with Rogueware, the Rogueware will give warnings in an aggressive (annoying) way and if you want to try to remove these so-called problems or threats (found by the rogueware), you will probably be redirected to the payment page where you will need to purchase the so-called software to remove the (fake) problems and/or threats.
Malware Symptoms (Signs)
Some Malware symptoms (signs)are:

· Computer, programs and internet connection run slower than usual

· Your web browser often freezes (hangs or unresponsive)

· Annoying unwanted pop-up windows and ads appear

· System or programs regularly crash

· Hard drive continues to have excessive activity — even when you don't use it

· Sudden increase of disk space on your hard drive

· Unusual high network activity when not using your web browser

· Your web browser's home page has been changed

· A new toolbar is placed at top of your web browser

· You want to open a website, but you are sent (redirected) to another (different) website

· Unusual messages appear

· Unusual programs start automatically

· Your antivirus program and/or its shields and update function is turned off (disabled)

· Your friends are receiving strange (weird) messages and/or emails from you (which you didn't sent)

· You're blocked from getting access to your system and get forced to pay money (ransom) to regain access again

· You are unable to access the Windows Control Panel, Task Manager, Registry Editor or Command Prompt

· Your computer automatically plays music

· There are new unknown icons on your desktop

· Your computer restarts (reboots) by itself (turns automatically off and on)
Malware Protection

Believe me, the BEST malware protection is YOU.

You can have the best malware protection on your computer, but even the best anti-malware (antivirus) software can fail to detect new malware.

Malware threats have grown significantly in the past decade. These threats grow so fast, that antivirus programs take too long to catch up with malware (even the best programs).

Therefore, the best protection is yourself.

You might be wondering:

What exactly do I mean?

Well, if you do any of the following:

· Use illegally downloaded software on your computer

· Install "free" software without checking it out first (reviews).

· Click on "OK", "Yes", "Continue" or "Run" when a pop-up window appears and asks you to install unknown software.

· Click on links in emails you don't trust.

· Download and open email attachments you don't trust.

· Ignore security warnings from Windows or your antivirus program

· Never update your operating system (Windows) and software

· Don't use antivirus software

· Use an unsecured web browser

Then there's a good chance that your computer will get infected with malware.

There's no better malware protection than yourself, so pay attention with everything you do online and offline.

Anti-Malware (Antivirus) Software

You should always use antivirus software on your computer – even when antivirus programs can't protect you 100% against all malware.

Still, It's better to have some protection than no protection at all. And a good antivirus software can protect you against most known malware.

You should always install and use only one (1) antivirus program on your computer.

The use of multiple antivirus programs on a PC is a very bad idea! Why?

· They might attack each other: because one of them might think that the other one malware is because it's monitoring your system (same like spyware or other malware) and then it will attempt to block and remove it. (Just like having different species of dogs to protect your home. lol)

· They will fight over malware:
when one of them detects, removes and places malware in quarantine, then they other program might also detect the same malware (even when the other program already has it in quarantine) and then it will also try to remove the malware and place it in quarantine. Then you will keep getting the same notifications about this malware over and over again.

· They will make your system slow: Because antivirus programs are always running in background, they use a lot of your system memory to perform system scans and other related tasks. So your system will become slower when using two antivirus programs.

There are so many free and paid antivirus programs out there that it's difficult to choose one.

If you are looking for a good paid antivirus program, then Bitdefender and Kaspersky are good options. Bitdefender and Kaspersky always have very high scores in antivirus tests (AV-tests), like AV-TEST and AV-Comparatives.

If you are looking for a good free antivirus program, then the free versions of Bitdefender and Kaspersky are good options.
Extra Anti-Malware Software
You can use additional free anti-malware software and services together with your current antivirus program, like:

· Malwarebytes: free version doesn't offer real-time protection, but can be used for scanning and removing malware. The paid version offers real-time protection.

· Bitdefender Anti-Ransomware Tool is a free security tool that can protect against existing and emerging ransomware attacks. Can be used with your current antivirus software.

· RansomFree by Cybereason is a free security tool that can protect against existing and emerging ransomware attacks. Can be used with your current antivirus software.

· ESET Online Scanner: is a second opinion scanner for scanning and removing malware.

· Norton Power Eraser: is a second opinion scanner for scanning and removing deeply hidden and difficult to detect malware.

· Kaspersky TDSSKiller:
detects and removes the following malware Rootkit.Win32.TDSS, bootkits and rootkits.

· Emsisoft Emergency Kit: contains a collection of programs that can be used without installation to scan for malware and clean infected computers.

· AdwCleaner: is a removal tool for adware, toolbars, PUPs (Potentially Unwanted Programs) and Hijackers (Hijack of the browser's homepage).

· VirusTotal: is a free online service that analyzes suspicious files and URLs and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware. It uses different antivirus engines, website scanners, file and URL analysis tools and user contributions.

· Windows Defender Periodic Scanning (Windows 10 only): scans your PC periodically for malware and will remove the malware it finds. It's intended to offer an additional line of defense to your existing antivirus program's real-time protection. You can also perform manual scans with this feature.

· Kaspersky Virus Removal Tool: is a second opinion scanner for scanning and removing malware.

If you think your system is infected with malware or you don't trust a file, then you can use the above mentioned programs to scan for malware and try to remove malware.

The good thing about malware scanners is that you can use them alongside your current antivirus software. Which means you get the chance to use another antivirus program on your system without any problems.
Malware Prevention Tips

You can prevent malware by following these tips:

· Keep your operating system and software always up-to-date

· Use a firewall (Windows firewall is enough).

· Always take security warnings from Windows or your antivirus program seriously. Never ever ignore security warnings!

· Don't download and use pirated software.

· Never click on "OK", "Yes" or "Run" when a pop-up window appears and asks you to download and install unknown software.

· Never click to fast on "Next", "Install", "OK", etc... when installing software, because you might install extra unwanted third-party software (like toolbars). If you see extra offers, then uncheck all their checkboxes.

· Always download software from the official link or from a trusted website.

· Don't click on links in emails from unknown senders.

· Don't download and open email attachments – unless you can verify the source.

· Check free software before downloading and installing it onto your computer. Just Google the software first and look for reviews or forums.

· Use a secure and safe web browser like Google Chrome or Mozilla Firefox and keep it updated.

· Disable or uninstall Java if you don't need it.

· Disable or uninstall Adobe Flash Player if you don't need it. You can also disable Flash Player in your web browser.

· Don't click on links you don't trust, but first check the link. When you go with your mouse-cursor on the link, then you can see at the bottom left corner of your browser window the REAL location the link is pointing to. You can also check the link using VirusTotal.com.

· Never download "codecs" or "players" to watch videos online. If you can't play the video online in your secure web browser then there's something wrong with the video or website.

· When you insert a USB flash drive or external hard drive from someone else into your PC, then scan it first with your antivirus program before opening or copying anything.

· If you want to take risks, then at least install VirtualBox on your PC, then install a operating system, like Linux (Linux Mint or Ubuntu) as a virtual machine in VirtualBox and do your risky things in there. But remember that also this is NOT 100% safe.

· Don't use a Windows administrator account for daily use, but use a standard account instead. If malware or a hacker gets access to your system, then the malware or hacker has the same rights of whatever account you're using. So if you use an administrator account and malware or a hacker takes control of your system, then the malware or hacker can do anything he, she or it wants and have full control of your system, but if you use a standard account then they can only do things that don't require administrator permission, so he or she can't change important system settings or install malware, and malware can't install itself unless you enter the administrator password.

· Microsoft recommends that you disable SMB1 on Windows for security reasons


Malware Detection & Removal

I will show you step by step how to detect and remove (get rid of) malware from your infected PC in a few different ways using anti-malware software and free online scanners (malware removal tools).

The good thing about malware scanners is that you can use them alongside your current antivirus software. Which means you get the chance to use another antivirus program on your system without any problems.
Important Tips!

1. Create a system restore point. If something goes wrong you can restore the mistake with a system restore point.

2. Always scan your PC with multiple malware scanners to get more complete detection coverage, because some programs may detect malware that others might miss.

3. Always double check the results of each scan and make sure that nothing important is selected for removal. Even malware scanners can make mistakes and sometimes see something harmless as a threat.
Recommended Solution
If your computer is infected with malware (computer virus, spyware, rootkit, trojan horse, worm, etc..), and you want to be 100% sure that your system will be clean, then the best solution is to reinstall Windows or restore a system image backup that's 100% clean.

Why?
Well, if your antivirus (anti-malware) software detected malware, then you will never know for sure if that's the only piece of malware that has infected your system.

Malware can nestle itself deeper into your system and hide itself, so that it can't be discovered by your security software and it can also open doors to other malware.

Now:

I know that most people don't want to reinstall Windows or don't have a system image backup, so that's why I will show you step by step how to remove malware from your infected PC in a few different ways.

Step 1: Enter Safe Mode with Networking

If you think your computer has a malware infection, then boot Windows into "Safe Mode with Networking".

Booting into "Safe Mode with Networking" will only load the minimum required programs and services.

This mode may also prevent Malware from loading automatically when Windows starts.

This is important because it helps to remove Malware easier since it's not running and active.

How to start Windows in "Safe Mode with Networking" in Windows XP, Vista & 7

1. Start your PC and keep tapping on the F8 key repeatedly until a menu appears.

2. When the "Advanced Boot Options" menu appears, select "Safe Mode with Networking".

3. Press Enter.
How to start Windows in "Safe Mode with Networking" in Windows 8 & 8.1Method 1

1. Start your PC and keep tapping on the F8 key repeatedly until a menu appears.

2. When the "Advanced Boot Options" menu appears, select "Safe Mode with Networking".

3. Press Enter.

Method 2

1. Click on the Start menu button.

2. Click on the power button.

3. Hold the Shift key down while clicking on "Restart".

4. When the options menu appears, click on "Troubleshoot".

5. Click on "Advanced options".

6. Click on "Startup Settings".

7. Click on "Restart" to restart your PC.

8. When the Startup settings menu appears, press the 5 key of your keyboard for "Safe Mode with Networking".

How to start Windows in "Safe Mode with Networking" in Windows 10

1. Click on the Start menu button.

2. Click on the power button.

3. Hold the Shift key down while clicking on "Restart".

4. When the options menu appears, click on "Troubleshoot".

5. Click on "Advanced options".

6. Click on "Startup Settings".

7. Click on "Restart" to restart your PC.

8. When the Startup settings menu appears, press the 5 key of your keyboard for "Safe Mode with Networking".


Step 2: Delete Temporary Files

Deleting your temporary files can speed up the scanning process and also free up disk space.

You don't need to install any extra software, because Windows has a built-in tool called "Disk Cleanup".

1. Open Windows Disk Cleanup.

Three ways to open this tool:

· Go to the Windows searchbar and search for cleanup and click on "Disk Cleanup".

· Press the Windows + R key on your keyboard, enter cleanmgr.exe, and click on "OK".

· Open Windows Explorer or File Explorer (Windows 10), right-click on the (C:)drive, choose "Properties" and click on "Disk Cleanup" (General tab).

2. Select the Windows drive (when asked for and if not already selected).

(C:) is the default installation location for Windows.

3. Click on "OK".

The tool will now calculate how much disk space you will be able to free on your system drive.

4. Select the type of files you want to delete. I always select everything.

5. Click on "OK".

6. Click on "Delete Files".

This may take a while. The time it takes depends on how many files need to be deleted. When it's finished the tool will close by itself.


Step 3: Full System Scan with Your Antivirus Software

Look:

Your antivirus program may missed the malware that has infected your PC the first time.

But:

Antivirus companies update their virus definitions hourly, daily or weekly, so it's possible that the malware that has infected your PC has been added in the last update.

First update your antivirus software and then run a full system scan with the program.

Step 4: Kaspersky TDSSKiller

Kaspersky TDSSKiller detects and removes the following malware:

· malware family Rootkit.Win32.TDSS

· bootkits

· rootkits

You can download the latest official version of Kaspersky TDSSKiller here.


1. Open TDSSKiller.

2. Accept the "End User License Agreement".

3. Accept the "KSN Statement".

4. Click on "Change parameters".

5. Select "Detect TDLFS file system".

6. Click on "OK".

7. Click on "Start scan".

TDSSKiller will now scan for malware.

This scan will only take about 30 seconds till a minute.

When the scan is completed it will show you the results of the scan.

8. If malware is detected, then click on "Continue" to remove the infections.
Step 5: Malwarebytes

Malwarebytes detects and removes all kinds of malware like computer viruses, spyware, rootkits, trojan horse, worms, and more.

You can download Malwarebytes here.

When you install Malwarebytes it will automatically enable a two week trial version of the premium version, but if you don't want the two week trial, then you can easily disable it in the settings.

Enable 'Scan for rootkits'

1. Open Malwarebytes.

2. Click on "Settings" (located at the left side).

3. Click on "Protection" (located at the top).

4. Go to "Scan Options".

5. Turn on "Scan for rootkits".



Note: You will only have to change this setting once.

Remove Malware

1. Open Malwarebytes.

2. Click on "Scan Now".

Malwarebytes will first look for updates and then it will scan for malware.

This may take a while (about 20 till 30 minutes).

When the scan is completed it will show you the results of the scan.

3. If malware is detected, then click on "Remove Selected" to remove the infections.

Malwarebytes may ask you to restart your PC.
Step 6: Kaspersky Virus Removal Tool

Kaspersky Virus Removal Tool is another tool for removing malware.

You can download Kaspersky Virus Removal Tool here.

1. Open Kaspersky Virus Removal Tool.

2. Accept the "End User License Agreement".

3. Click on "Change parameters".

4. Select (check) "System drive" and click on "OK".

5. Click on "Start scan".

Kaspersky Virus Removal Tool will now scan for malware.

This may take a while (about 30 till 45 minutes).

When the scan is completed it will show you the results of the scan.

6. If malware is detected, then click on "Continue" to remove the infections.
Step 7: ESET Online Scanner
ESET Online Scanner is one of the best free online second opinion scanner that can be used for scanning and removing malware.

You can download ESET Online Scanner here.

Click on "SCAN NOW" to start the download of this tool.

1. Open ESET Online Scanner.

2. Accept the "Terms of Use".

3. Choose between:

· Enable detection of potentially unwanted applications

· Disable detection of potentially unwanted applications

4. Click on "Scan" to start the scanning process.

This may take a while (about 30 till 45 minutes).

When the scan is completed it will show you the results of the scan.

5. If malware is detected, then choose one of the following options:

· Select the threats you want to delete and click on "Clean selected".

· Click on "Clean all".

6. Now you will have the following (optional) option: "Delete application's data on close".

7. Click on "Finish".


Step 8: Emsisoft Emergency Kit

Emsisoft Emergency Kit contains a collection of programs that can be used without installation to scan for malware and clean infected computers.

You can download Emsisoft Emergency Kit here.

1. Open Emsisoft Emergency Kit.

2. Click on "Malware Scan".

Emsisoft may ask you to detect potentially unwanted programs (PUPs).

Emsisoft Emergency Kit will now scan your computer for malware.

When the scan is completed it will show you the results of the scan.

3. If malware is detected, then choose one of the following options:

· Quarantine selected

· Delete selected
Step 9: Windows Defender Periodic Scanning (Windows 10 only)

Windows Defender Periodic Scanning will periodically scan your PC for malware and will remove malware it finds. It's intended to offer an additional line of defense to your existing antivirus program's real-time protection. You can also perform manual scans with this feature.

Enable Windows Defender Periodic Scanning


1. Open "Settings".

2. Open "Update & Security".

3. Click on "Windows Defender" (left sidebar).

4. Go to "Limited Periodic Scanning" and turn it on.

Perform a Manual Scan with Windows Defender

1. Go to the Windows notification area in the taskbar.

2. Right-click on the Windows Defender icon and choose "Open".

3. Go to "Scan options" and select "Full".

4. Click on "Scan now".

Windows Defender will now scan your system.

This may take a while.

When the scan is completed it will show you the results of the scan.

5. If malware is detected, then you can check the results and choose to apply the action(s).
That's it. I hope your PC is clean and that you've learned enough about malware.

Please if this post was helpful, leave a comment

Reference: Easytechguide
Cpdemy is a knowledge driven hive dedicated to producing great how-to, tips and tricks, awesome tutorials on Photoshop, Wordpress, Blogger, SEO

We all know that the internet is an immeasurable source of information. Not just information that you are looking for, but your personal information is also stored within the endless web. It is for this reason that if you are not using a VPN, you should be.


A VPN, or virtual private network, is a kind of middle man between the internet itself and a private user, such as a company or individual. They work by creating a kind of secure pathway through the internet. Any information about you and your internet activity is encrypted by the VPN, so no one can see anything passed between you and your internet destination.

But if you are thinking that you are not a criminal and have nothing to hide from, you are missing the big picture. 

Enhanced Security:
Back in March 2017, the United States government removed a protection provided by the FCC that had prevented your ISP from selling your personal data to third parties. As most of us have limited options as far as which ISP we can use, this puts us at a disadvantage, where our ISPs can release our internet behavior and preferences to the highest bidder. They will sell where you live, where you shop, and can even sell what sites you like to look at. You ISP has access to your entire internet user experience. With a VPN, your data will be encrypted as it leaves your computer, so your ISP will not see what you are doing online.

Better User Experience:
A VPN can enhance your user experience when you are traveling the world. Whether you want to watch an international sporting in real time, or you want to be able to stream videos that are not accessible to your region, a VPN can help you get around the location issues you may suffer from. Some countries have a censorship protocol in effect as well, deliberately blocking you from certain internet destinations. A VPN can cut through the censorship and allow you to voyage through the internet as you would like.

Protection:
While you may be not be doing anything criminal or concerning online, other internet users are not as trustworthy as you may be. Online criminals are interested in acquiring your data. With a rise in identity theft, you will want to ensure that you are doing everything that you can to keep your information safe. Having a VPN for every computer or device in your home will also keep your family’s information safe, no matter what their internet habits may be.

Stop the Creepy Ads:
I cannot tell you how many times I have looked at something on a search engine only to find that exact thing advertised on a completely different website days later. It is a disturbing advertising method, reminding you of things you may want to buy, but also telling you that your online history is remembered. Because of the VPN’s encryption abilities, these cookies will not hang around to remind you of things you have looked at.

Cloak your Searches:
If you are a researcher of any variety, whether it is for personal or professional interest, some things that you look up may be off-putting if someone got a hold of them. Together, perhaps your searches would look like you were up to something seedy and have you flagged by your ISP. Really, what you are reading on the internet should be your business and not theirs. A VPN will cloak your IP address, making your searches untraceable.

Make Public Wi-Fi Safer:
If you are out and about a lot, you may find yourself on the Wi-Fi of your local coffee shop. Public Wi-Fi is not going to encrypt your information, leaving you open to any other user who knows how to eavesdrop onto a connection. Unfortunately, this is a skill that intermediate-level hackers have, making your information more vulnerable than you may realize it is. Having a VPN on your computer already is going to keep your information encrypted for you, not matter where you are using the internet.

Take the Stress out of Downloads:
Whether you download torrents regularly or once in a while, it is still risky to participate in P2P file sharing. There are many authorities out there who do not like users to share videos or music files between one another. A VPN will encrypt your IP address so you can P2P share without detection.

While VPNs are by no means perfect, they can help keep your information protected while you are using the internet. Even the lightest internet users out there are vulnerable to having either hackers take their information or have their ISP track their information and sell it to the highest bidder. Using a VPN will not just keep your information safe, but will give you an added peace of mind while you are online.

Reference:
Cpdemy is a knowledge driven hive dedicated to producing great how-to, tips and tricks, awesome tutorials on Photoshop, Wordpress, Blogger, SEO


The internet as we know very well is full of threats and each day new threats, such as malware (computer viruses, ransomware, spyware, adware, rootkits, trojan horse, worms, etc..) arise.

Also hackers (phishing, identity theft, etc.) are a real threat online and all these threats can cause serious damage to your computer and even your personal life.

Fortunately, there are some things you can do to better protect your computer, home network, internet connection, and online activities against viruses (and other malware) and hackers.

Computer & Internet Security Tips

The best computer and internet protection is yourself and you will have to watch out with everything you do, online and offline. These tips will help you to better protect yourself from viruses (and other malware) and hackers.


1. Use a genuine version of Microsoft Windows. 
Using pirated/cracked versions of Windows can bring you many disadvantages, such as:

· No official and commercial support from Microsoft.

· Windows could be modified by a hacker to spy on you.

· No official versions and updates. Updates are very important!

· Windows could work slow because of the hacks done to make it genuine.

· Malware (computer viruses, spyware, trojan horse, worms, rootkits, etc...) pose a unstoppable threat.

Tip: if you don't want to buy a genuine version of Microsoft Windows, then I recommend using a alternative free operating system, such as Linux Mint or Ubuntu (both are quickly installed and easy to use).


2. Use a Firewall
A firewall is software or hardware that helps screen out hackers and malware that try to reach your computer over the Internet. Windows comes with a (software) firewall built-in, but you must be sure that it's turned on.


3. Use Antivirus Software – no matter how careful you are. 
No matter how smart you think you are, you can still benefit from antivirus software on your Windows PC. You can see antivirus software as your final layer of protection. Even one of your favorite websites can one day be infected with malware and antivirus software can protect you against it.

Two examples of good free antivirus programs are Bitdefender Free and Kaspersky Free, but if you're looking for more features, then the paid versions of Bitdefender and Kaspersky are good options. Bitdefender and Kaspersky always have very high scores in antivirus tests (AV-tests). They're always in the top for many years now.

4. Keep Windows and software always up-to-date
Updates may include important patches to fix security vulnerabilities and this prevents attackers from exploiting security holes.


5. Always take security warnings from Windows, antivirus software and your web browser seriously. 
If you ignore security warnings from Windows, antivirus software and your web browser, then your system may likely get infected with malware.


6. Don't use a Windows administrator account for daily use, but use a standard account instead. 
If malware or a hacker gets access to your system, then the malware or hacker has the same rights of whatever account you're using. So if you use an administrator account and malware or a hacker takes control of your system, then the malware or hacker can do anything he, she or it wants and have full control of your system, but if you use a standard account then they can only do things that don't require administrator permission, so he or she can't change important system settings or install malware, and malware can't install itself unless you enter the administrator password.


7. Don't download, install and use pirated/cracked software. 
This is a very important part, pirated/cracked software could infect your PC with malware. The crack (piece of software used to crack the software to make it look genuine) might actually be disguised malware.


8. Always download software from a trusted source, like the official website of the maker of the software. 
Nowadays when you want to download software you have to be very careful before you click on any "Download" button or link, because you never know what you may end up with! You might be downloading and installing crapware or adware.


9. Pay attention when installing software. 
Never click to fast on "Next", "Install", "OK", etc. when installing software, because you might install extra unwanted third-party software (like toolbars). If you see extra offers, then uncheck all their checkboxes.


10. Never click on "OK", "Yes" or "Run" when a pop-up window appears to ask you to download and install unknown software. 
Malware will sometimes try to trick you in installing even more malware. Example: a pop-up window appears with a warning message, like "Your Windows computer could be at risk! Install the repair tool to clean and protect your system...." and when you click on "Secure now", "OK", "Yes" or "Run" then your system gets infected.


11. Check free software before downloading and installing it onto your computer. 
Software could just be Malware disguised as software, so always Google the software first and look for reviews or forums that talk about this software.


12. Don't download and open email attachments from a suspicious email – unless you can verify the source. 
Many computer viruses are delivered through an email attachment. Attachments that contain viruses are either executable programs (file types: .com, .exe, .vbs, .zip, .scr, .dll, .pif, .js) or macro viruses (file types: .doc, .dot, .xls, .xlt). And if you don't trust a file or link, then you can also check it using VirusTotal.com.


13. Disable or better yet, uninstall Java if you don't need it. 
Java has a lot of security vulnerabilities which are constantly being exploited in cyber attacks. Java vulnerabilities are one of the biggest security holes on your computer. It needs constant patching (security updates). 
Recently, Java has made a lot of updates which has really reduced its vulnerability.


14. Disable or uninstall Adobe Flash Player if you don't need it (disable also in your web browser)
Like Java, Adobe Flash Player has also a lot of security flaws which are being exploited in cyber attacks. You should also disable it in your web browser, because browser plugins are a favorite target for malware and cyber criminals because they are generally full of unpatched or undocumented security holes that cyber criminals can use to take complete control over vulnerable systems.

15. When you insert a USB flash drive or external hard drive from someone else into your PC, then scan it first with your antivirus program before opening or copying anything. 
It's always good practice to scan someone's USB flash drive or external hard drive for malware when you use it on your PC, because USB plug-and-play devices are the easiest method to infect computers.


16. Never click on unknown links or links that look suspicious. 
Links can bring you to malicious websites that will infect your PC or they can bring you to a fake login page and when you type your login information into this fake login page then hackers will have this information also. So when you get an email with a link in it, then don't just click on it. Same counts for links on unknown websites. If you are curious about a link, then you could check the link (URL) at VirusTotal.com.


17. Never download "codecs" or "players" to watch videos online. 
If a website wants to install video codecs or a media player, then don't allow it. It's not worth the risk. Most likely you can find the video on YouTube or another video website anyway.


18. Disable macros and ActiveX in the Microsoft Office suite – Word, Excel, PowerPoint, etc... 
These are bits of software that cyber criminals often use to spread malware and infect computers.


19. Enable the "show file extensions" option in Windows and always verify file extensions before clicking on them. 
Cyber criminals are very good at camouflaging files to make them look harmless. The purpose is to trick you into clicking on them and launch a malware infection that will take over your system. Change your Windows settings to show file name extensions, so you will avoid clicking on shady file extensions, like .jpg.exe (.jpg isn't dangerous, because it's an image format, but combined with .exe it's malware).


20. Disable AutoPlay on your PC. 
AutoPlay is a Windows feature that allows you to quickly open digital media from USB flash drives, External hard drives, CDs and DVDs with designated software. Malware can use this feature to start running automatically and gain access to your computer.


21. Don't keep Wi-Fi and Bluetooth on – unless you're actively using it. 
Cyber criminals can use both of these connections to attack and compromise your devices.


22. Secure your home network. 
· Keep your router's firmware up-to-date.

· Change your router's default IP address.

· Change your router's default administrator password and username.

· Encrypt your Wi-Fi network with WPA2 or WPA encryption (WPA2 is the strongest). Don't use WEP encryption.

· Disable UPnP (Universal Plug and Play).


23. Be careful when using a public, shared and free Wi-Fi network. 
· Use a VPN (Virtual Private Network).

· Don't do things that require your bank account information, credit card information or other personal, important and sensitive information, like online banking or online shopping.

· Don't share files with personal, important and sensitive information, because they might get intercepted by someone.

· Disable network discovery, file and printer sharing and public folder sharingin Windows.

· Visit only websites that use HTTPS encryption, so that you will have a more private and secure connection to that website. Example: https://www.facebook.com.


24. Don't use too many web browser extensions (add-ons / plugins). 
Web browser extensions are just part of the problem. Any form of browser integration can create security holes.


25. Disable Windows PowerShell if you don't use it. 
Windows PowerShell is a tool that's much more powerful than the Command Prompt. There are many types of malware (like ransomware), who abuse PowerShell to plant and execute malware deep in the victim's system.


26. Create regular backups of all your important files. 
Ransomware is a type of malware (malicious software) designed to block access to a computer system until a sum of money is paid. If this happens you will also lose access to all of your files (documents, etc...). Paying the ransom will not guarantee that you will get access to your system and/or files again. Ransomware is one of the world's fastest growing types of malware. So having a backup of your files is very important.


27. When providing answers to security questions for your online accounts, add a short word (that only you know) to the end of your answer. 
Social media can usually provide answers to common security questions. Adding a short word to the end of your answer can help prevent hackers (who have your personal information) from knowing the answer. Example word "meek", so if your mother's maiden name is Johnson, then enter something like Johnsonmeek (e.g. Mother's maiden name: Johnsonmeek).


28. Disable SMB1 on Windows. 
Microsoft recommends that you disable SMB1 for security reasons – especially for WannaCrypt, Petya (also known as Petwrap) and other ransomware, because they also use this to attack the Windows operating system.

29. Be wary of emails asking for confidential information – especially financial information. 
A legitimate organisation, like a bank will never ask for sensitive information like your password, bank account, or credit card by email. When you have any doubts, visit the main website of the organisation in question, get their phone number and give them a call or visit their office.


30. Never leave your computer, tablet or phone unattended in public. 
If your device gets stolen, then someone has not only your device, but maybe also your personal information (e.g. usernames, passwords, etc...). All it takes is someone with more than basic computer knowledge to get to your personal data.


31. Use strong passwords for your online accounts. 
Passwords protect your online accounts, so it's important to use strong passwords. A strong password is a combination of numbers, uppercase letters, lowercase letters and other characters.

If you are having trouble with creating and remembering multiple strong passwords, then use a password manager, like LastPass, KeePass, 1Password or RoboForm.


32. Never use the same password for multiple accounts. 
If you use the same password for multiple online accounts and someone obtains your password in one way or another, then he or she will have access to all of your online accounts that use the same password.

Your password can get compromised by a phishing attack or in a data breach. Data breaches happen more often than you might think – even with big sites, such as Linkedin, Twitter, Yahoo, MySpace and Tumblr. If you want to check if you have an account that has been compromised in a data breach, then visit https://haveibeenpwned.com, type your email address or username and click on the "pwned?" button. If your account is "pwned!", then you will have to act fast and change your passwords on all accounts that use the same password as the account that has been "pwned!".

If you are having trouble with creating and remembering multiple strong passwords, then use a password manager, like LastPass, KeePass, 1Password or RoboForm.


33. Use two-factor authentication for your online accounts (email, social media, etc...). 
Two-factor authentication (also known as 2-Step verification) is an extra layer of security for your online accounts designed to ensure that you're the only person who can access your accounts – even if someone else knows your passwords.


34. Cover up your laptop's webcam. 
Hackers can access webcams through malware. If your computer gets infected with malware, then that malware could contain executable code that can turn on your webcam and watch and/or record you.

If you want to be absolutely sure nobody is watching and recording you, then cover your webcam with tape, a peel-off sticker, or something else that can obscure the lens but can be removed easily when you actually want to use your webcam.


35. Don't post a photo of your airline boarding pass on social media (and don't just throw it away either). 
The barcode of a boarding pass contains information about you, such as your name, future travel plans and frequent flyer account.

Someone can take a screenshot of your boarding pass, go to a website that can read and decode the data stored in the barcode of your boarding pass and view your information.

With this information a hacker can get access to your frequent flyer account and reset the PIN number that you use to secure your frequent flyer account, change seats and even cancel any future flights.

When the flight is over and you're home or at your accommodation, then burn the boarding pass or toss it in a paper shredder.


Conclusion:
As already stated above, the security tip you would likely implement right now. I hope this helps you. 
Leave a comment if you have any other relevant tip and it would be added to this post.

Reference(s): 















Cpdemy is a knowledge driven hive dedicated to producing great how-to, tips and tricks, awesome tutorials on Photoshop, Wordpress, Blogger, SEO



Sometime ago, I spent some time chatting with Mike Dahn who is the co-founder of the BSides information security conferences globally. He’s also organizer of BSides San Francisco and is well known and respected in information security circles.

We had a really informative chat and I’ve posted the video interview below. You know you’re chatting with someone who spends a lot of time thinking about a subject when they’re able to provide insights that are concise and are highly effective – ideas that can have a significant impact if overlooked or implemented.

During our conversation I asked Mike how “we can all be more secure”. We stopped filming for a few minutes and agreed….that is a really big question. He told me he knew what many vendors could do to be more secure – and so I filmed his response.
What Mike said is that “the best way to secure data is to get rid of it“.

If you’re new to systems administration, security or WordPress administration, you may not understand the value of this advice. So I’m going to expand on what Mike said because I think it’s something that is overlooked by many of us and can be a major risk reducer when trying to secure your website or your systems.
Anything you store needs to be protected.

Storing data you don’t absolutely need is a potential liability and a source of risk. Here are a few things that you may currently store on your WordPress site or in other areas of your organization that you may be able to get rid of or take offline, reducing risk:

Backups
We’ve seen many customers use WordPress plugins that store backup files on the server. Sometimes, catastrophically, the backups even end up in publicly accessible web directories. These should be backed up to an external storage system that is secure, or ideally taken completely offline. You don’t need your backups online until you need to perform a disaster recovery and that is (hopefully) a rare occurrence.

One compelling reason to take your backups offline is the rise in ransomware which encrypts both your web server (or workstation) and your backups. If your backups are offline, ransomware can’t encrypt it and your backups remain safe.

Credit Card Data
Never, ever store any data related to credit cards. In the interview Mike mentions “tokenization”. If you want to give your customers the ability to “store” their card information with you so they can perform repeat transactions, the way to do this securely is to pass the card data to a processor like Authorize.net (owned by Visa) and have them store the card data. They give you a unique ID or token which you can use to perform future transactions.

By tokenizing credit card data, you avoid having to store it and there is no card data on your site for an attacker to steal.
User Personally Identifiable Information (PII)
Only store what you absolutely must. Don’t collect information you only think you “might” use. Collect the data you have to and discard everything else.

For example, I’ve seen many online forms that ask for physical address information. Leave this out if you can because it’s one more piece of sensitive PII that you need to protect and it introduces additional liability into your organization if you are hacked.

Leave it to the (real) experts
While it’s tempting to store data on your own servers, companies like Visa in the credit card example above have much more stringent compliance requirements and have a larger team of security professionals than you do. So if you are able to outsource storage of data to a company that has a proven track record of excellence in data security, do that rather than reinventing secure data storage as a small team.

Delete old data

  • Another way to get rid of data so that you don’t have to protect it is to remove old data you no longer need. This may include:
  • Inactive user accounts
  • Old backups
  • Archived copies of your site stored on the server
  • Draft posts and pages
  • Inactive plugins and themes on your WordPress site
  • Websites that are still active but don’t receive any traffic or aren’t used
  • Old database instances that aren’t used anymore
  • Old database tables no longer used
  • Backup files or old files – for example if you made a copy of wp-config.php for WordPress and called it wp-config.php.old you definitely need to delete that because it contains your database credentials and is publicly visible on your site!

The Interview with Mike
This was filmed outside the BSides security conference in San Francisco. As always we welcome your feedback and insights in the comments below. Please share this to help promote good security practices in the WordPress community.




By Mark Maunder   

Originally posted in Wordfence 
Cpdemy is a knowledge driven hive dedicated to producing great how-to, tips and tricks, awesome tutorials on Photoshop, Wordpress, Blogger, SEO





Please share this to help promote good security practices in the WordPress community.


If you know how your site was compromised please describe how the attackers gained access.

The answers were free form text, so we manually categorized the answers. If the respondent expressed any doubt in their answer, we categorized them as uncertain.


Most Site Owners Don’t Know

Of the 1,032 survey respondents who answered this question, 61.5% didn’t know how the Attacker compromised their website. That is a not a huge surprise given that the large majority of respondents cleaned their sites themselves, but it is troubling. It is impossible to be confident that you have cleaned your site completely or that the vulnerability doesn’t still exist without knowing how the site was compromised in the first place.

For the site owners who did figure out how the attackers entered, here is what the breakdown looks like:


In the balance of this post we’re going to focus primarily on the top two risks. Because if you can protect yourself against plugin vulnerabilities and brute force attacks, you are accounting for over 70% of the problem.


Plugins Are Your Biggest Risk

Plugins play a big part in making WordPress as popular as it is today. As of this writing there are 43,719 plugins available for download in the official WordPress plugin directory. That is an incredible selection of plug and play software. But you obviously need to be careful with them, as plugin vulnerabilities represented 55.9% of the known entry pointsreported by respondents.

Some tips for avoiding plugin vulnerabilities:

Keep them updated

Reputable plugin authors fix vulnerabilities very quickly when discovered. By keeping them up to date you insure that you benefit from fixes before attackers can exploit them. We recommend that you check for updates at least weekly. In addition we recommend that you pay attention to the alerts generated by Wordfence scans. Wordfence alerts you when your plugins need to be updated.




Don’t use abandoned plugins



You are relying on the plugin developer to insure that their code is free of vulnerabilities. If they are no longer providing updates there is a high likelihood that there are vulnerabilities that have not been fixed. We recommend avoiding plugins that have not been updated in over 6 months. For plugins you have already installed we recommend you conduct an audit at least quarterly to make sure none of your plugins have been abandoned by their authors.



Only download plugins from reputable sites




If you are going to download plugins somewhere other than the official WordPress repository, you need to make sure the website is reputable. One of the easiest ways for attackers to compromise your website is to trick you into loading malware yourself. An attacker will do this by setting up a website that looks legitimate and getting you to download a compromised or ‘nulled’ plugin.



Use these tips to help determine whether a site is a reputable source or not:

· Eye Test – Is the site itself professionally designed and uses clear language to describe the product? Or does it look like it was thrown together quickly by a single individual?

· Company Information – Does the site belong to a company with the company name in the footer?

· TOS and Privacy Policy – Do they have terms of service and a privacy policy?

· Contact Info – Do they provide a physical contact address on the contact page or in their terms of service?

· Domain Search – Google the domain name in quotes e.g. “example.com“. Do you find any reports of malicious activity. Add the word ‘theme’ or ‘plugin’ next to the quoted domain name in your search and see what that reveals.

· Name Search – Do a Google search for the name of the plugin and see if any malicious activity is reported. Add the phrase “malware” or “spyware” to the search which may reveal forums discussing a malicious version of the theme being distributed.

· Vulnerability Search – Do a search for the theme or plugin name or the vendor name and include the word “vulnerability”. This will help you find out if any vulnerabilities have been reported for the product you’re interested in or for the vendor. If they have fixed the vulnerability in a timely manner, that usually indicates they are a responsible vendor who is actively maintaining their product when problems arise.


Brute Force Attacks Are Still A Big Problem

A brute force attack is a password guessing attack. The attacker needs to both identify a valid username on your website and then guess the password for that username. Despite the availability of methods and technology that are 100% effective, this type of attack is still a huge problem, representing 16.1% of known entry points in our survey.

Some tips for avoid a hack via brute force attack:

Use Cellphone Sign-in

Also referred to as two factor authentication, this approach requires the user to not only know their password, but to have possession of their cell phone as well. This technology is 100% effective in preventing brute force attacks. Wordfence premium includes this feature today.

Don’t Use Obvious Usernames

The most obvious usernames to avoid are ‘Admin’ and ‘Administrator’, they are the most common usernames attempted in brute force attacks. Also avoid using your domain name, company name and the names of people who are writing for your blog or are listed elsewhere on your website.

Enable Login Security in Wordfence

The free version of Wordfence provides a long list of login security features. By making sure they are enabled, you benefit from the following features:

· Enforce strong passwords

· Locking users out after a defined number of login failures

· Locking out users after a number of forgot password attempts

· Locking out invalid usernames

· Preventing WordPress from revealing valid usernames in login errors

· Preventing username discovery through author scans

· Immediate blocking of IPs that try to sign in as a defined list of usernames.


Other Steps to Secure your Site

Keeping everything up-to-date is key. There are no serious known vulnerabilities in the current version of WordPress core. There are however, a large number of known vulnerabilities in older WordPress versions. So keeping WordPress core up-to-date is very important. The WordPress team responds quickly when an issue is reported and so should you.

Many of our respondents indicated that their hosting account was compromised in some way. Make sure that you have a strong password policy for your CPanel account and any other server or hosting related accounts. Also ensure that you remove any applications on your server, like phpmyadmin, that aren’t absolutely necessary. If you don’t, you will have to maintain them too and ensure they’re updated and secure. Each application is another endpoint that can be attacked. The less you have to protect, the lower your risk.

Secure your workstation by keeping your operating system and applications up-to-date. Running an old vulnerable web browser, or an old version of Flash or Adobe reader can make you vulnerable to phishing attacks that can compromise your workstation. Once you workstation is compromised, an attacker can easily install a keyboard logger to capture usernames and passwords. They will gain access to much more than your WordPress website.

Store passwords securely. Do not store them in plaintext in a document online that may be compromised. You can use a product like 1Password which provides an encrypted ‘vault’ to store your passwords in.

Finally, as we’ve said before, delete any old data you don’t need from your website. This includes backup files you don’t need, log files, applications you don’t use or anything else you don’t need on your site. Old data is one more possible entry point that needs to be protected and if you can remove it, you reduce risk.

Conclusion

Knowledge is power, and this survey data allows us to focus on what matters most. We hope that you take the opportunity to make improvements in how you select and manage plugins on your website. We also hope that you review your approach to brute force attack protection. Small investments in these areas will pay big security dividends. Stay safe!

Please share this to help promote good security practices in the WordPress community.

Original Post by Wordfence