ZoneAlarm is an easy-to-use firewall that blocks hackers and other unknown threats.
- Intrusion Blocking systematically identifies hackers and blocks access attempts.
- Stealth Mode automatically makes your computer invisible to anyone on the Internet.
- Automatic Program Configuration provides safety and simplicity by automatically configuring programs. Automatically decides whether to allow or deny Internet access to individual programs.
- Expert Controls give savvy users precise control over security settings.
This free version is for non-commercial use only.
ZoneAlarm
So lately you suffered a computer crash and a headache of course due to a virus intrusion or a spyware. So people ask me what are the ways to avoid that. Here are some of the basic steps that everyone should follow to prevent such an intrusion.
1) Install a reputed antivirus software.
2) Upgrade your Internet Explorer to version 7
3) Use Firfox browser for increased security.
4) Regularly install windows update and keep it on.
5) Run liveupdate on your antivirus and put it on automatic update mode.
Read the complete article here: TechJunkies
(Sam is a Certified Ethical Hacker who blogs at TechJunkies)
Security experts have discovered vulnerabilities in OpenOffice.org that could allow attackers to remotely execute code on Linux, Windows or Apple Mac-based computers. OpenOffice version 2.0.4 and earlier versions are vulnerable to maliciously crafted TIFF files, which can be delivered in an e-mail attachment, published on a Web site or shared using peer-to-peer software. The next version of OpenOffice (version 2.3) arrived on September 17 and is not affected by the flaw. The vulnerability was discovered by researchers at iDefense, who claim that the OpenOffice TIFF parsing code is flawed.
"When parsing the TIFF directory entries for certain tags, the parser uses untrusted values from the file to calculate the amount of memory to allocate. By providing specially crafted values, an integer overflow occurs in this calculation. This results in the allocation of a buffer of insufficient size, which in turn leads to a heap overflow," the iDefense team reported last Friday. TrustDefender co-founder Andreas Baumhof said: "This vulnerability allows someone to execute malicious code on your computer. It's an OpenOffice bug so it doesn't matter what type of operating system you run; it allows you to run malicious software with the same rights as the user who runs OpenOffice." "At this stage, it's only confirmed on Linux," Baumhof said. "But typically it would affect all operating systems. The only difference with Linux and Windows is that home users typically run Windows as the administrator."
Full Story
Thumb drives are a convenient and cool way to carry around your data, and with drive sizes in the gigabytes, you can store a ton of photos, files, music, and video in a very tiny space. Unfortunately, due to their small sizes, they are targets for information thieves. Think about it - all that personal data - your resume, email, password-files, and pictures of your girlfriend can be picked up and copied and returned before you even noticed it was missing. You want to have this data handy, but handy for you and not for that scumbag down the hall with the sticky fingers.
Like you, the US Military wanted portable but secure storage, and the guys at IronKey stepped up. They've developed the perfect solution that's one-part thumb-drive, and two parts Mission: Impossible. Their thumb drives hold up to 4 Gigabytes of data, but includes a hardware encryption chip that scrambles the data so as to be completely unreadable without a password.
Passwords can be hacked, but not the IronKey. It's built to withstand attacks both virtual and physical. 10 incorrect password attempts, and the encryption chip self-destructs, making the contents of the flash drive totally unreadable. The contents of the drive are filled with epoxy, so if a hacker tries to physically access the chips, he'd more likely damage them instead. Even if he did get access to the memory chips, they'd be worthless without the encryption chip. Electron-shielded, even a scanning electron microscope can't get inside.
Applications built right onto the IronKey help keep your personal data safe. For example, the password manager keeps your passwords safe. How? Your passwords are securely stored in a hidden hardware-encrypted area inside the device (and not in the drive's file system), being first locally encrypted with 256-bit AES, using randomly generated keys encrypted with a SHA-256 hash of your device password. All of this data is then doubly encrypted with 128-bit AES hardware encryption. Hack that.
A secure copy of Firefox included with your IronKey encrypts your browsing session through a VPN tunnel to IronKey's Secure Sessions Service. It works by tunneling your entire web browsing communications through the Tor-based Secure Sessions proxy on your IronKey. The Secure Sessions tunnel connects over an encrypted connection to their network routing servers, which in turn route your traffic between a number of servers, and then eventually out to your destination website. This approach protects your identity and your confidentiality, encrypting and anonymizing your Web surfing on almost any network or VPN (virtual private network).
These drives have already seen duty in Afghanistan, keeping US Military secrets safe from unsavory people. They're certainly good enough even for your most sensitive data.
All this goodness is demoed here. Go check it out!
* Fast 30MBPS Read, 20MBPS Write
* Drive contents encrypted with AES CBC-Mode Encryption
* Onboard IronKey Password-manager keeps all your internet passwords safe
* Secure version of Firefox included that encrypts all your web-surfing traffic
* Encased in a potted metal case, not plastic, making it one of the strongest USB keys around
* Exceeds MIL-STD-810F military waterproofing standards
* The encryption chip self-destructs if an invasive attack is detected
* If your Ironkey is lost, you can restore from a secure backup to a new Ironkey in minutes
* Dual channel SLC NAND Flash for high-quality and read/write speeds
* Windows XP and Windows Vista only, but Mac and Linux drivers are in development
A 'highly critical' vulnerability has been found in the Opera web browser which could be exploited to remotely compromise a user's system. The flaw is caused when Opera uses already freed memory to parse BitTorrent headers, and can lead to an invalid object pointer being de-referenced.
This can be exploited to execute arbitrary code if the user is tricked into clicking on a specially-crafted BitTorrent file and then removes it from the download pane by right-clicking. The vulnerability is reported in version 9.21 of Opera on Windows, but security monitoring website Secunia, which rated the flaw 'highly critical', said that other versions may also be affected. The problem can be fixed by upgrading to Opera 9.22.
But what i suggest is, do not use Opera for torrents. You can use uTorrent, BitComet etc... There are many freeware/Open Source torrent clients available.
Red Hat last week continued its appliance assault via a partnership with Symantec.
The companies have crafted a pair of software bundles meant to give Linux customers easier access to high-end security features. Customers can pick from pre-tested packages that included Red Hat Enterprise Linux or the Red Hat Application Stack with Symantec Critical System Protection. As you might expect, the packages are aimed at small- to mid-sized business that could use some help securing their data centers with relative ease.
Symantec's Critical System Protection handles a wide variety of tasks, including protection against zero day exploits and buffer overflow and memory-based attacks. It also automates some security policy procedures.
Since Critical System Protection covers both server and application protection, the companies will sell their new bundles as Secure Server Host and Secure Server Host for Applications. The server bundle, which will run on two-socket systems, covers intrusion protection and detection, while the application bundle, also aimed at two-socket x86 gear, focuses on security policy and compliance.
Read More...