Saturday, 29 March 2014

65. Typosquatting: How Spelling Errors Could Lead to Scams


It’s a common enough scenario, and familiar to most: When typing a URL in the Web browser’s address bar, you accidentally mistype the name. You may type ctibank.com instead of citibank.com, gacebook.com instead of facebook.com, or the ever popular gooogle.com instead of google.com.
 
The page at the wrong address is an example of typosquatting, where scammers register domains with names that are similar to legitimate sites. The owner of the site benefits from the fact that the user mistyped the name, whether by displaying ads and links, setting up fake storefronts, or tricking users with phishing pages.



At best, it’s just an annoyance. At its worst, it may be malicious. And it’s pretty prevalent. Experts have estimated nearly 80 percent of mistyped URLs wind up on typosquatting sites.


Not Always Bad, But Usually
Of course, some sites may legitimately have addresses that look similar to popular brands. Those are easy to figure out. If you land on goole.com, you will know it’s a site about an English town, and not a typosquatting one. Then there are the pages that seem harmless, such as the ones displaying advertisements or a parked page with a bunch of links. The typosquatting page window.com has links to Windows 7 and Windows 8, but if you don’t click on it and just close the window, no harm done.

While advertisements, offers to sell you the domain, or these parked pages constitute a majority of the typosquatting sites, there is a very real danger associated with these fake pages. Cybercriminals can grab these domains to create fake websites that look similar to the actual site so that users don’t realize right away they’ve landed in the wrong place. This is the perfect setup for a phishing scam, to trick users into entering their login credentials before redirecting them back to the real site. The users don’t realize what happened, and the criminals operating the site now have their information.

Fake sites Wikapedia.com and Twtter.com took the phishing scam another step further, by making the pages look like the real sites and displaying advertisements for contests offering iPads and MacBooks as prizes. Users were prompted to enter their credit card information and other sensitive information as part of the contest to claim their prizes.


Fraudulent Transactions
Scammers may set up an online store to convince visitors to browse and shop for products. If it was a typo domain appl.com, users may not realize they’d just bought junk and not a brand new Mac Book Pro. Or they may see a link for iTunes but wind up signing up for a service that sends prime-rate SMS messages to your cellphone.

Scammers may also be using the sites to drive some clicks to their advertising campaigns. Don’t click.

Criminals may setup sites hosting malware at these sites. This is a bit more unusual, since attackers aren’t going to be able to dispose of the domain and move onto a new one when the address invariably gets blacklisted for hosting malware. There aren’t that many variations of the domain name the attackers can use, so they tend to use other scams instead that will let them use the domain for a longer period of time.


How to Stay Safe
Companies take typosquatting seriously. Apple has in the past gone to the courts regarding appl.com, wwwApple.com, appl-e.com, and apples-stores.com for being too similar to its own domain name. Back in 2012, a United Kingdom watchdog organization fined wikapedia.com and Twtter.com $156,000 each for trying to trick users into thinking they were the real sites. A California judge ruled in favour of Facebook in May last year, awarding the social networking giant close to $2.8 million in damages and control of a little over a hundred domains with misspelled variants of its name.

When typing in the link to a website, pay close attention to what you type. Don’t just hit enter or click on “search” right away—read over what you typed to try to catch that typo at the last minute.

It’s also important to get in the habit of quickly checking the URL to make sure you landed on the page you intended. Sometimes the site may look like the real thing, and that last check can help you from making a big mistake.

Enable safe browsing mode in the Web browser. Internet Explorer, Firefox, and Chrome all have features where they block access to a page suspecting of hosting malware or otherwise malicious. If the site you fat-fingered is malicious, the browser will stop you.

Make sure your security software is up-to-date. If the typosquatting page hosts malware, the antivirus software will most likely detect the danger and block the file from being downloaded onto your computer.

Above all, never, ever, click on links in emails, text, chat messages, or social networking sites. You may not realize the links have a typo when you first look at it. If you type the URL instead of clicking, you will notice the typo, and thus avoid the scam.



(c) Zone Alarm Newsletter
 
---------------------------------
 

Monday, 10 March 2014

64. How to remove a CD from a closed drive.


Have you ever needed to open your optical drive when the power was off? Maybe the drive quit working but your favorite music CD, game DVD, or BD movie was stuck inside? Or you simply powered down your PC and left the CD in the drive.

This easy trick will get the drive bay open fast! It will work every time on a laptop PC but extra care is needed on a desktop or tower PC.

Difficulty: (Very) Easy

What You Need: A single, reasonably-heavy-duty paperclip

Time Required: Using a paperclip to open your stuck disc drive will probably take less than 5 minutes, start to finish

Here's How:

1. Unfold the paperclip until there is at least 1 to 2 inches (2 to 5 cm) that is perfectly straight.

2. Look closely at your disc drive. Directly under or above the drive bay door (the part that "ejects" the disc) there should be a very small pinhole. On a laptop the pinhole will be right on the face of the CD drive.

Tip: If you have one of those desktop optical drives where a large door flips down before the drive bay ejects, pull that down with your finger and then look for the pinhole.

3. Push the paperclip into the pinhole. On a laptop the CD drive will pop open immediately.

4. On a desktop or tower, directly behind the pinhole, is small gear that when rotated will manually open the drive.

Remove and reinsert the paperclip as often as needed to eject the drive bay enough to grab a hold of it.

5. Slowly pull on the drive bay until it's fully retracted. Take care not to continue to pull when you feel resistance.

6. Remove the disc from the drive.

Slowly push the drive bay back into the drive until closed.

---------------------------
 

Tuesday, 25 February 2014

63. Why You Should Take Your Passwords Seriously



I have touched on this subject in previous articles but make no apologies about repeating it. YOUR PASSWORDS ARE OFTEN YOUR ONLY SECURITY ON SENSITIVE SITES SUCH AS BANKS AND INVESTMENTS. Read the article and take note. Even after banging on about this aspect of security for a long time, my own “very secure” password was compromised on my email account a couple of months ago :-

Unfamiliar messages. Passwords that no longer work. These are just two of the many clues that cybercriminals have gotten a hold of your password and broken into your account.

With the password compromised, the first step is to regain control over the account by changing passwords and checking configuration settings to make sure nothing has changed. However, if the root problem (how the passwords were successfully stolen) is not fixed, then the accounts will just get compromised again and again. That’s why it’s important to take your passwords seriously and to make sure they are strong.

Passwords are immensely valuable, whether they are for email, e-commerce sites, or even “just” a social media platform. Criminals aren’t after your Spotify passwords because they want to see who your favorite artists are. They are banking on the high likelihood that the same password will unlock your email, retail Website, or even your work network. Considering the number of people who re-use their passwords across multiple sites, there is a good chance that someone’s Twitter password is the same as that person’s online banking account.


This is why it’s important to have a unique password for every account and service. If attackers do manage to steal one password, at least the damage is limited to just that site, instead of impacting multiple services. It’s also important to recognize how cybercriminals steal the passwords in the first place and avoid those scams from the start.


How Cybercriminals Steal Passwords
Cybercriminals employ several methods to steal passwords. They can use stealthy malware, tricky social engineering techniques, or just plain brute-force to guess the password. Whichever method they use, the goal is the same: gain access to as many user accounts as possible.


Malware:
All it takes to infect a computer with malware is one person opening a specially crafted attachment, or clicking on a booby-trapped link in a spam message. Cybercriminals send out spam messages promising special deals on luxury goods, offering exclusive details on current events, or the latest gossip on celebrities to trick people into clicking on links. Or they craft emails using basic social engineering tricks to convince users the emails are legitimate, such as pretending to apply for a job, sending delivery notification messages, or even using data mined from social media sites and pretending to be an acquaintance.

The malware likely installs a keylogger component on the computer, which captures every keystroke typed, whether it’s an email message or every single login credential for every single site the user visits. Once the keylogger is installed, the criminals can easily harvest every password ever entered. This is why it is important to keep the security software regularly updated and to scan the computer regularly for malware.


Phishing:
Phishing is a form of social engineering that is very effective. Attackers craft a message that appears to be from a legitimate brand, such as your bank, or well-known sites such as eBay and PayPal, or even a corporate site. When the user clicks on the link, they see a Website which looks like the real thing—maybe the logo on the page is the same. The user thinks it is a real site and enters their login credentials. All the information typed on the bogus site goes directly to the criminals, and the user often has no idea that the password, and now the account, has been compromised.

This is why it is important to be wary of messages in the inbox, to avoid clicking on links in email messages, and to scrutinize all sites to make sure the site is real. Checking the URL carefully is a good way to screen out bad sites, such as www.fcebook.com.


Password Cracking
Cybercriminals may just try to brute-force the password, operating on the assumption that the password is not so complicated. Many users still make the mistake of selecting simple passwords, such as ’123456′ or ‘password.’ If the password is a common word that can be found in the dictionary, or a simple sequence of numbers and letters, there are cracking tools that can figure out the actual password. This is why it is important to select unique passwords that are complex, such as having both lower case and upper case letters, symbols, and numbers. Passwords should also be long, to make it harder to crack.

Attackers will continue to employ various techniques to try to get their hands on user passwords. By employing better password hygiene, users can protect themselves from attack, and to minimize the damage even if the password does get compromised. Passwords aren’t perfect, but unless something better comes along, make sure your passwords are all unique, complex, and long.


Reproduced from the Zone Alarm Blog
 

Wednesday, 5 February 2014

62. More news on Windows 8


A few weeks ago I mentioned that the next version of Windows was expected to be called Windows 8.2 and would probably arrive in October – exactly a year after Windows 8.1 and two years after the original Windows 8. That all seems sensible and logical, but it now also seems to be wrong.

A new version of Windows is indeed on the way, but it’s due to arrive in April. And rather than being called Windows 8.2, it will apparently go by the exotic name of ‘Windows 8.1 Update 1’. From that name and the speed of its arrival, we can surmise that there won’t be a great deal that’s new or notable about it.

For something new (and hopefully notable), we have to wait until April 2015 and the release of what really should be the next version of Windows. Although Microsoft isn’t commenting publicly about it, there’s no doubt that some private commenting has been going on, and the rumours have a ring of truth.

The first rumour is that 2015’s version will be named ‘Windows 9’. The change of name obviously helps to emphasise that this version really is new, but there’s little doubt that Microsoft is keen to shed the name ‘Windows 8’ and its negative associations.

The second rumour is that the Start menu is coming back, and the third is that the new-fangled ‘Modern UI’ apps which currently fill your whole screen will be able to run in ordinary windows on the desktop, just like all the other programs we’ve been using for decades. In essence, then, the rumours hint that Windows 9 will herald a return to a more-familiar Windows.

More generally, they suggest that Microsoft is back-peddling furiously on its earlier plans for Windows. The whole point of Windows 8 was to expand Windows’ reach to encompass tablet computers and other touch-screen PCs, but the plan has misfired badly: most tablet users are choosing an Apple iPad or one of the many Google Android devices, while ordinary PC users have decided that Windows 8 is designed for tablets so it’s no use to them.

This perception of Windows 8 isn’t likely to change between now and April 2015 and that means three wasted years for Microsoft. In that time, Apple and Google have sewn up the market for tablets and smartphones between them, leaving Microsoft with just the dwindling PC market – the same market it had before, but now feeling rather ignored and let-down.

The one ray of hope on Microsoft’s horizon is that no-one is yet competing with Windows on ordinary PCs. Millions of PC users are drumming their fingers and waiting for a version of Windows they feel is designed for them. Windows 9 really has to be that version; the big question is whether Microsoft is willing and able to deliver it.


From PC Tips for Seniors www.pcforseniors.co.uk.



---------------------------- 
 

Wednesday, 29 January 2014

61. Print your document pages in the correct order


Most printers – especially home inkjets – print onto the side of the paper that faces upwards. So, if you’re printing a multi-page document, the first page emerges face up, then the second page lands on top of it, and so on. At the end, you have a pile of sheets with page 1 on the bottom and the last page on top, and then you have to deal them out from top to bottom to reverse their order. Wouldn’t it be helpful if they could be printed in the correct order – from last page to first page – to save this bother?

Well, in Microsoft Word they can. It just takes a quick change to one of Word’s options and your documents will always be printed this way:

* Word 2013/2010: click the File tab and choose Options. At the left of the window that opens, click Advanced. Scroll down to the ‘Print’ section and tick the box beside Print pages in reverse order, then click OK.

* Word 2007: click the circular Office button and then click Word Options. At the left of the window that opens, click Advanced. Scroll down to the ‘Print’ section and tick the box beside Print pages in reverse order, then click OK.

* Word 2003/2002: choose Tools > Options and select the Print tab in the window that opens. Tick the box beside Reverse print order and then click OK.
 

--------------------------------

Saturday, 18 January 2014

60. Windows 7, a long goodbye





It’s been with us for over four years now, but Windows 7 is just starting to bid us farewell. Microsoft announced in December 2013 that it’s no longer selling Windows 7 at retail. In other words, you can’t nip into a computer store and buy a boxed copy of Windows 7 to install.

The same announcement also included the news that Windows 7 would cease to be sold with new PCs after October 2014, but apparently that was a mistake. Microsoft is now saying that the date for this is ‘to be determined’.

Whatever the actual dates, the time has come for Windows 7 to bow out. However, like all Windows-related goodbyes, this one will take a long time. If you use Windows 7 and you can’t be tempted away from it by Windows 8, Microsoft is going to continue supporting it and supplying regular updates for it until 2020.

But perhaps that isn’t going to matter. Perhaps you could be tempted away from Windows 7 after all. You may not have been enticed by Windows 8, and you may have turned your nose up at the improvements brought by Windows 8.1, but the word is that Windows 8.2 is going to be a more attractive proposition. Two little snippets have just been leaked by Microsoft insiders:

?The new-style Windows 8 apps, which currently occupy your entire screen when you use them, will be able to run in ordinary windows on the desktop, just like all the other programs we’ve been using for donkey’s years.

?Having brought back the Start button in Windows 8.1, Microsoft will bring back the much-missed Start menu in Windows 8.2.

If these two rumours do turn out to be true, it will be hard to find any reason to stick with Windows 7. The implication is that Windows 8.2 could have everything we know and like about Windows 7, coupled with some clearer thinking about the newer elements of the system.
 


From PC Tips for Seniors www.pcforseniors.co.uk.
-----------------------------

Friday, 3 January 2014

59. A Great Application to use with your Kindle



Everywhere I go now there are people sitting on beaches or by the pool or at airports etc. reading their latest book on a Kindle. In a previous article I showed you how to transfer books from your PC to your Kindle using the built-in File Management software on your PC.

All of this is still valid but there is another much easier way to transfer books straight onto a Kindle, and maybe rename them or change the cover picture etc.

I speak here of Kindle books which you may have been given or have downloaded from the Internet, NOT those you purchase from Amazon as the latter are transferred to your Kindle on demand.

There are many types of ebooks out there on the Internet and they have different extensions to their file names. Files with extensions .mobi and .prc are already compatible with the Kindle whilst the other main category is the .epub extension which cannot be used directly.

Now if you search out and download a programme called Calibre, a genuinely free piece of software (although they welcome small contributions to help with their development) which will keep all of your books together, enable editing of their titles or cover pictures, and will also translate books with a .epub extension into a .mobi book allowing it to be read on the Kindle.

Full instructions come with the download of the software and it is simplicity itself to install and use. One of its beauties is that it recognizes when you have your Kindle plugged in to the PC and when you want to send a book to the Kindle you click on its title in Calibre then click on a button at the top which says “Send to Device” and the transfer is done for you.

I have several collections of books by my favourite authors and obviously the titles don’t necessarily follow on from one another. I rename my books so that they display in the correct order. For example, my books by Peter Robinson about Inspector Banks, the detective in Yorkshire, I rename them with the prefix “Banks 01.....”, “Banks 02......” etc.

These titles are then transferred to the Kindle along with the book allowing easy finding of a book in a particular series or genre.
 

------------------------------