Posts

Apple MAC Fake Virus Alert

Similar to the windows fake AV alerts, MAC users have now been targeted with a fake AV scam. After visiting an infected site, the software scans the users hard disk and reports on viruses found. Users are then given the opportunity to purchase remedial AV software, thus parting with credit card information. The trick here is that is can masqurade as the legitimate MAC Defender application making the users less suspicious about the warnings. Apple Mac users have been adviced to disable a setting in the Safari browser that allows "safe" files to be automatically installed. Full details on removing and preventing this malware can be found here. Apple MAC Malware Removal

Fortinet FortiToken simplifies 2-factor authentication

Image
Fortinet have delivered a solution for 2-factor authentication within their Version 4 FortiOS. Customers with the Fortigate UTM platform can make use of the solution by upgrading their systems to V4 MR3. This is a free upgrade for customers with maintenance. The only chargeable component are the tokens themselves. Traditionally 2-factor authentication required some form of middleware solution which intercepted the logon details to verify the token one time password. This middleware is included in the FortiOS and therefore minimises implementation and up front costs. The offering works with Fortinet's IPSec and SSL VPN remote access (also included within the FortiOS).

Sony makes the right call

The Playstation network has been down since about 20th April now. The full consequences of the attack may take some time to manifest, however the commitment to ensuring security since the attack has been foremost in Sony's agenda. The difficulty here is that although what has happened may be relatively clear, the how and who may be less obvious and because of this Sony need to take extra care when restoring the services as they cannot afford another similar incident. The fact that they may be offering a reward for information relating to the identity of the attackers proves that whoever did this were skilled enough to hide their tracks well. With enough digging, many clever breaches can be traced due to the smallest fragment of information in the logs or other data leading to clues. There is claim that information pertaining to the group Anonymous has been located on the systems, however Anonymous have denied the incident and apparently say they may have been framed. If the o...

Application Control In The Workplace Using the Fortigate UTM

Image
Whether you are a small or enterprise size business, controlling internet application usage can become a major productivity not to mention security issue. With the ever growing number of applications available to users the problems escalate. Facebook, Instant Messenger and online gaming to name a few are difficult to manage with traditional Firewalls. Typically, for example Port 80 may be allowed for users to access the internet, howvever many of these applications use Port 80 to "get out" on. Also most applications are able to port hop and find open ports to use, making allowing or blocking a difficult if not impossible task. Fortinet offer a solution to this by integrating Application Control into their UTM appliances. Regardless of the Application or Port Fortinet are able to inspect the traffic and pinpoint applications being used. Depending on the application type there are several actions which can be taken with multiple levels of configuration and granularity. A...

UPS Delivery Scam

Out of the blue I received the famous UPS delivery emails. Dear customer. The parcel was sent your home address. And it will arrive within 7 business day. More information and the tracking number are attached in document below. Thank you. © 1994-2011 United Parcel Service of America, Inc. Attached was a rar file pertaining to be the delivery information. Knowing of the scam and also that I had not ordered anything I saved the rar file into a virtual machine and took a peek with notepad. Pretty much all of it was random ASCII except for the legible text "United Parcel Service document.exe". Knowing this was a virus I submitted it to an online virus scanner to verify the content. The abrieviated version of the output is outlined as follows. W32/Agent.OUH!tr It displays the following fake warning message: Danger! Harmful viruses detected on your computer... It deletes the following various registry keys It creates the following new registry entries It tries to download files f...

Free Anti-Virus, Anti Spyware, Firewall and URL Filter Solution From Fortinet

Image
If you are looking for a free anti-virus product, there are a few to choose from, however the Forticlient suite offers many additional features beyond a standard Anti-Virus product. Fortinet are the world leaders in the Unified Threat management arena and have a client in their portfolio. There is a premium version for the enterprise and a standard version free for download. The image shows the features and a download link is provided below. Download

Microsoft Telephone Call Scam Still Rearing It's Head

A colleague of mine called me this week to report he had received a call from a foreign sounding gentleman from Microsoft. The man seemed to have a fair bit of information about my colleague and was reporting that Microsoft had flagged his PC as being infected with a known virus. At this point my colleague was suspicious and started to ask a few questions to which the bogus Microsoft teccy tried to answer with various cover up tactics. Asking my colleague to run a few commands on his PC etc.... This was when my colleague insisted that the bogus Microsoft person sent a letter to him stating exactly what was being asked so he could show it to the technical team at work (us). To this the Microsoft teccy replied an email would be quicker but my colleague insisted on a letter. I am sure a letter which will never arrive and if indeed it did, it certainly woulnn't be from Microsoft. click here for a story from 2010. Further Reading