Showing posts with label email. Show all posts
Showing posts with label email. Show all posts

Saturday, April 5, 2014

If you really want to keep your Windows XP


These tips are in no particular order. Note that some tips may require also following other tips that might come after or before them.
  • Always log on as a Limited User unless you absolutely must update some software.
    Lack of administrator rights blocked over 90% of the Windows OS* malware in 2013.
  • Keep all your software and applications up to date. Make a list of programs that need regular updates and check for updates at least monthly.
  • Don’t use Internet Explorer; install the latest versions of Opera, Chrome, or Firefox.
  • Install and use the NoScript and Ghostery plugins for Firefox.
  • Uninstall JAVA. At least, disable it in all browsers.
  • Uninstall or restrict use of Adobe products. A recommended alternate PDF reader is Sumatra (I have not used it). Use the built-in readers in Chrome or Firefox instead of a plugin. 
  • If downloading an Office document, preview it in a viewer instead of the full program. Disable any macros.
  • Uninstall Microsoft Security Essentials and use a 3rd party antivirus such as the free options from Avast, AVG and others.
  • Upgrade to Microsoft Office 2007 or newer. Better still, move to a non-Microsoft suite.
  • Upgrade to Internet Explorer 8 (the highest level that works with XP).
  • Don’t access the internet (including email) from your XP computer. Don’t install unknown software downloaded from the internet by other computers.
  • If you must browse the web, restrict the ability of malware to get to you:
    • Ensure you are behind a router – the first-line firewall – and that Windows firewall is active.
    • Configure your email reader to display only text – no pictures or links.
    • Use Firefox with NoScript. Learn the controls in NoScript and don’t casually allow everything.
    • Browse only to sites you are familiar with.
  • If you must use email on XP, restrict the ability of malware to get to you:
    • Use webmail. In particular, gMail online is practically immune to transmitting malware to your system.
    • Use a mail client other than Outlook or Outlook Express.
    • Configure your mail client to display messages as “text only.”
    • Do not open email attachments or follow links until you have independently verified with the sender they are benign. Read our article on evaluating an email.
  • Shut your computer off when not using it.
    You may discover you have very little need for XP. Plus, older computers are less efficient and you’ll save on your energy bill. 
* Logging on as a Limited User will block most malware that attacks flaws in and installs to the Windows operating system. This does not include malware that attacks flaws in individual programs such as JAVA, email, Microsoft Office, or .pdf documents.

Additional References
Some of these references are documents and must be downloaded and viewed in their program. Yes, they're safe for XP.
PC Club of Charlotte’s original presentation
http://pc3.org/smfpc3/index.php/topic,266.0.html and
http://zaitech.com/articles/misc/download_documents/TheEndOfXP.docm

Security researcher Steve Gibson’s comments:
https://www.grc.com/sn/sn-447-notes.pdf (first page) and
http://twit.tv/show/security-now/447.

                 
Creative Commons License. This work by Bill Barnes is licensed under a Creative Commons BY-NC-SA 3.0 US License. Permissions beyond the scope of this license may be available at http://zaitech.com/satellite/contacts.htm.
(c) 2014 Bill Barnes - Disclaimer - Home Page - Blogs Home




Thursday, August 2, 2012

No phishing


Did that email really come from my bank, or is it just a good imitation? Phishing is a message that purports to come from one source, but actually comes from a bad guy; usually trying to steal your valuable personal information.

Last month we discussed ways to recognize whether an email was probably legitimate. Here is an example of a good email I received from one of my financial institutions.
First of all, notice that I have disabled automatically showing pictures in email I receive (green circle). The critical content of the message is completely contained in text. Pictures can hide links or silently allow the sender to track that you actually opened the email and might be susceptible to more like this. Sloppy phishers may also use pictures wholesale to copy the look of the legitimate mailer rather than recreating the text from scratch.

Secondly, there are only two places (red circles) where they give you the specifics to contact them: one is a phone number and the other an email address. Neither of these contact points asks directly for your personal information.

As a reminder of good practices, the central part of the message advises you to type their website into your browser - no links to hide a bad connection - and log on to your account.

A few other financial institutions use similar good practices to send you critical information. Others - credit cards are notoriously bad - wrap their status updates around a myriad of pictures and links. Some of these links may not even go back to the sender, but to advertisers or other third parties. That type of email may be acceptable for a newsletter, but don't ever log in to your account from a link in a congested email.

Read more
Windows Secrets
article on "Whether Windows is safe for banking"


And then, there's a bad email from a financial company:
 

 Creative Commons License. This work by Bill Barnes is licensed under a Creative Commons BY-NC-SA 3.0 US License. Permissions beyond the scope of this license may be available at http://zaitech.com/satellite/contacts.htm.
(c) 2012 Bill Barnes - Disclaimer - Home Page - Blogs Home

Saturday, July 7, 2012

Should I open this email?

Should I open this email?

A client asks:
I received an email from someone I don’t recognize. The email had an attachment (document) he wanted me to evaluate. Do I dare open the attachment?  Is there any way I can do so and guarantee it is not a virus? 

Basically, no. You can’t guarantee it’s benign.

In this sort of circumstance, either as sender or recipient, I try to validate the legitimacy of the contact. In the text of the email I identify myself and the attachment by filename and size. Sometimes I will make non-email contact to alert the recipient or verify the sender. Unless you or the data on your system are particularly high value, it’s unlikely a random attack would take the effort to pass these tests.

If you can’t make this “out of band” contact and still want to open the message or its attachment, there are some unilateral assessments you should make first. Start with the anti-spam / anti-phishing / anti-virus triggers you apply to every subject line, message, and attachment.
In the preview, before you open the email:
•    Are you expecting this?
•    Do the From and To addresses look reasonable. For example, do names look random or made up, are there multiple similar addressees at the same domain, or is your exact address missing from the list? If it makes reference to an account, especially a financial account, and is not directly and exclusively addressed to you; it’s probably a phishing attack.
•    Is the subject line meaningful and relevant?
•    If it refers to an “issue with your account;” does it identify the account or describe the problem?
•    Does the content apply to you? (Immediately trash a notice from BigBank if you don’t do business with them.)
•    Do the grammar, writing style, and content ring true to the request? If it comes from someone you know, do the style and content match what they usually send?
•    Are there excessive links and do they connect to what you expect? Hover your mouse over the link and look at the entire URL. Work back from the first “/” after “http://.” A link of “http://BigBank.com.BadGuys.ru/...” will actually take you to BadGuys’ site. While you’re looking at the links, pay attention to the top level domain (TLD). That is the letters left of the “/” until you hit a period – classically “.com” or “.org.” The “.ru” in the example above refers to Russia; along with China, a common starting point for malware. This is a minor indicator as bad guys can buy a .com and good things can come from unexpected countries such as bit.ly (a useful URL-shrinking service), where the “.ly” stands for Libya. (http://en.wikipedia.org/wiki/List_of_Internet_top-level_domains#Country_code_top-level_domains)
•    Are the attachment’s name and file type what they appear to be? It’s an old trick to name the attachment “CuteKitty.jpg” and then pad the name out with many spaces before giving the actual functional name of “…virus.exe” which falls off the edge of the page.
•    Is it delivered primarily as pictures? Your previewer should be set not to download pictures automatically, but only on your request. Downloading the pictures can deliver malware and return significant tracking information about you. If you can’t comprehend the gist of the message from the text it doesn’t deserve further analysis.
•    Look at the source of the message. In Microsoft Office (retail) Outlook, right-click on the message and choose View Source. This is very geeky and includes a lot of garbage; but, with experience, you may be able to spot something suspicious. Backtracking the internet headers is even more obscure, but can reveal that the sender is not who he appears to be.
•    Did it pass your up-to-date virus and spam checker? Antivirus programs often remove the malware attachments and deliver a message that contains very little text. There’s usually a good reason for it to be labeled spam.
•    Right-click the attachment and save it to a temporary folder on your computer or sacrificial thumb drive. Run an on-demand virus check on it.
•    Be sure all your viewing software is up-to-date. There is often a “check for updates” option under the Help or Tools menu or you can go to the publisher’s website. Especially visit adobe.com, java.com, and microsoft.com at least monthly to check for updates for Adobe Reader, Flash Player (hopefully, you’ve never installed Shockwave Player), Java, and Windows.
•    Open the attachment in less common programs. For example, use foxit (www.foxitsoftware.com) for .PDFs rather than Adobe Reader or send office documents to Google Documents (docs.google.com).
•    Open the attachment on a Linux or Apple computer as malware is often (but not necessarily) Windows-specific. You can get a CD to boot your PC directly into Linux. Everything runs in memory and when you reboot there’s no record (and hopefully, no residual evil) from what you just did.
•    If this were a legitimate email and you trashed it without opening would it really cause any problems?

Surf - and email - safe!

Read more:
An example of a "good" email from your bank. 


 Creative Commons License. This work by Bill Barnes is licensed under a Creative Commons BY-NC-SA 3.0 US License. Permissions beyond the scope of this license may be available at http://zaitech.com/satellite/contacts.htm.
(c) 2011 Bill Barnes - Disclaimer - Home Page - Blogs Home

Pages