Computer Security

Posted By: John H.

Computer Security - 06/28/02 06:15 AM

Since I work on PCs for a living, and pay close attention to security/upgrades/patches, I thought it a good idea to post a few things here on the subject. Anybody coming to this forum is on the internet/WWW, and so is subject to a certain degree of risk, just by reason of being online. This info might be old hat to some, but a learning experience for others, depending on 'computer literacy' level....

There's a good article now at the Consumer Reports site that talks about the importance of firewall and antivirus software being installed on computers:

http://www.consumerreports.org/static/0206com0.html

For those who don't have firewall or antivirus software installed -- money's not an excuse any more! Both can be downloaded for free.

• Firewall software:

ZoneAlarm personal edition is free for personal use, and is probably the easiest one to use --
http://download.com.com/3000-2092-10039884.html?part=zonealarm&subj=dlpage&tag=button

Kerio (formerly Tiny) Personal Firewall is also free for personal use --
http://www.kerio.com/us/kpf_home.html

Once you have a firewall installed, you can check to see that it's doing its job properly at several sites around the Web, that'll scan your computer from their location, to see if you're vulnerable. Some of these are:

Steve Gibson's ShieldsUp! -- https://grc.com/x/ne.dll?bh0bkyd2

Sygate Online Services (SOS) -- http://scan.sygatetech.com/

Symantec (Norton) Security Check -- http://security1.norton.com/ssc/home.asp

Running these scans before-firewall and after-firewall, or with firewall disabled, then firewall enabled, can be a real eye-opener.

• Antivirus software:

AVG 6.0 Free Edition --
http://www.grisoft.com/html/us_downl.htm#FREE

I've put AVG on right many people's machines, and it works well. Can't beat the price, either (unless they paid you to use it...)


These subjects really are getting serious. If a hacker is able to get into your machine, he/she can download any data you may have stored on your computer, including user names and passwords to online banking or stock trading sites; credit card numbers and expiration dates; bank account numbers; etc. That's all they need to perform an identity theft, and start charging goods and services to your good name. Once that happens, it can be really hard to get out from under it in some cases.

Also, if a hacker is able to get into your machine, he/she may be able to use it as a 'zombie'; one machine among hundreds or thousands of remote control computers that the hacker uses to attack other destinations on the web, such as government web sites. I sure don't want my machine being used by some stranger to do things like that, and you sure don't either.

Where viruses are concerned: it's important to have antivirus software installed, but equally important to keep it up to date with current definitions. If those definitions are out of date, then the A/V program doesn't know how to recognize the latest threats; and something like 200 new viruses come out each and every month. Just about every time I find a virus on a computer, that computer's antivirus definitions are found to be way out of date. Keeping them current can greatly lower the odds of catching a 'bug'. It's a good practice to check online for antivirus definition updates at least once a week; twice a week is better.

• On another subject: if you run Microsoft Windows, it's important to go to the Microsoft Windows Update site on a regular basis, and download any Critical Updates they have for your particular brand of Windows.

Go to http://windowsupdate.microsoft.com

and click on the Product Updates link. (Note: the site only works with MS Internet Explorer.) The site will scan your computer, then present a list of available updates. The Critical Updates will be at the top of the list; these are just what they say, "critical". As in, "do it right away"!

If you'd like to get on Microsoft's Security Notification Service (which comes by e-mail, and is free), you can do so at

http://www.microsoft.com/technet/security/bulletin/notify.asp

Words to the wise! An ounce of prevention, and all that. Security's getting tougher out there on that Net. It's up to us to secure our own machines.

[ June 28, 2002, 12:41 AM: Message edited by: John ]
Posted By: Ikan

Re: Computer Security - 06/28/02 01:23 PM

I suggest everyone take John seriously on this: my PC got infected last night at 4:30 AM....I awoke checked my e-mail, saw a letter warning about a 4th of July virus, scanned it, "no virus" opened it and WHAM! ...it was a virus.
I'm sitting on the floor with my trusty Mac laptop (they never get hit) until the Chinese techies figure this one out (John: it's called Backdoor.optix virus...no cure yet.)
Posted By: John H.

Re: Computer Security - 06/28/02 05:09 PM

Ikan,

That one's not too bad, fortunately, where damage is concerned. Actually it's a Trojan, designed to 'phone home' to Hacker Daddy like a homing beacon, so he can 'see' you, and come see what your machine has to offer. That's where a firewall product like ZoneAlarm comes in handy; it'll monitor outgoing traffic (as well as incoming), and pop up a warning on anything it doesn't recognize that's trying to connect in the outward direction....such as a Trojan.

But this makes me wonder how current your A/V definitions are! Most variants of the Optix family were discovered between August and December of last year. Current definitions should have caught that bug, easy. (oops) Or could this be some brand-new variant.
Posted By: zyph

Re: Computer Security - 06/29/02 01:24 AM

Ikan, the person who runs the following site is considered one of the top people in the world in dealing with trojan viruses. I suggest you ask him if he knows what to do. Don't be put off by the site. He's really very good. I know him personally.
http://www.anti-trojan.cc/
Hope he can help.
Posted By: Ikan

Re: Computer Security - 06/29/02 02:10 AM

Thanks, you two! Yes it was a brand new variant that has my Chinese egg-heads stumped with the crooked smile they are famous for...with actually means "Gee! This is a clever one! Nice challenge.."
I apparantly had the latest update within 12 hours, but this was a Thursday special.I have BlackIce anfd NAV, but this was new on them both.
Will look at that sight, zyph, when I get my PC back. (Happy Sabbath)
Posted By: John H.

Re: Computer Security - 06/29/02 03:14 AM

Good luck with that, then.

There's always fdisk/format. [Wink]
© 2024 Maritime 2nd Advent Christian Believers OnLine Forums Consisting Mainly of Both Members & Friends of the SDA (Seventh-day Adventist) Church