Thursday, October 10, 2013

What To Do If You're "Infected"

How do you know your computer is infected?

Unfortunately, there is no particular way to identify that your computer has been infected with malicious code. Some infections may completely destroy files and shut down your computer, while others may only subtly affect your computer's normal operations. Be aware of any unusual or unexpected behaviors. If you are running anti-virus software, it may alert you that it has found malicious code on your computer. The anti-virus software may be able to clean the malicious code automatically, but if it can't, you will need to take additional steps.

What can you do if you are infected?

Minimize the damage .  If you are at work, contact Information Resources immediately by calling (913) 588-7995. The sooner they can investigate and clean your computer, the less damage to your computer and other computers on the network. If you are on your home computer or a laptop, disconnect your computer from the internet. By removing the internet connection, you prevent an attacker or virus from being able to access your computer and perform tasks such as locating personal data, manipulating or deleting files, or using your computer to attack other computers.

Remove the malicious code.  If you have anti-virus software installed on your computer, update the virus definitions (if possible), and perform a manual scan of your entire system. If you do not have anti-virus software, you can purchase it at a local computer store (see Understanding Anti-Virus Software for more information). If the software can't locate and remove the infection, you may need to reinstall your operating system, usually with a system restore disk that is often supplied with a new computer. Note that reinstalling or restoring the operating system typically erases all of your files and any additional software that you have installed on your computer. After reinstalling the operating system and any other software, install all of the appropriate patches to fix known vulnerabilities (see Understanding Patches for more information).

How can you reduce the risk of another infection?

Dealing with the presence of malicious code on your computer can be a frustrating experience that can cost you time, money, and data. The following recommendations will build your defense against future infections:
  • use and maintain anti-virus software - Anti-virus software recognizes and protects your computer against most known viruses. However, attackers are continually writing new viruses, so it is important to keep your anti-virus software current.
  • change your passwords - Your original passwords may have been compromised during the infection, so you should change them. This includes passwords for web sites that may have been cached in your browser. Make the passwords difficult for attackers to guess (see Choosing and Protecting Passwords for more information).
  • keep software up to date - Install software patches so that attackers can't take advantage of known problems or vulnerabilities. Many operating systems offer automatic updates. If this option is available, you should enable it.
  • install or enable a firewall - Firewalls may be able to prevent some types of infection by blocking malicious traffic before it can enter your computer (see Understanding Firewalls for more information). Some operating systems actually include a firewall, but you need to make sure it is enabled.
  • use anti-spyware tools - Spyware is a common source of viruses, but you can minimize the number of infections by using a legitimate program that identifies and removes spyware (see Recognizing and Avoiding Spyware for more information).
  • follow good security practices - Take appropriate precautions when using email and web browsers so that you reduce the risk that your actions will trigger an infection.
As a precaution, maintain backups of your files on CDs or DVDs so that you have saved copies if you do get infected again.

Additional information:
  • Recovering from a Trojan Horse or Virus
  • Before You Connect a New Computer to the Internet
  • Securing Your Web Browser

This information was adapted from an original production by US-CERT and republished for non-commercial use as outlined in their Privacy & Use policy.

Tuesday, October 8, 2013

Protect Your Personal Information

Here's another set of tips from our friends at StopThinkConnect.org on how to protect your personal information:

  • Secure your accounts: Ask for protection beyond passwords. Many account providers now offer additional ways for you verify who you are before you conduct business on that site.
  • Make passwords long and strong: Combine capital and lowercase letters with numbers and symbols to create a more secure password.
  • Unique account, unique password: Separate passwords for every account helps to thwart cybercriminals.
  • Write it down and keep it safe: Everyone can forget a password. Keep a list that’s stored in a safe, secure place away from your computer.
  • Own your online presence: When available, set the privacy and security settings on websites to your comfort level for information sharing. It’s ok to limit how and with whom you share information.

  • Friday, October 4, 2013

    Major Adobe Data Breach

    On October 3, 2013, Adobe announced that it had been a victim of a cyber attack that resulted in a data breach. This breach resulted in attacker(s) gaining access to the detailed information belonging to 38 million customers.  The information includes:
     
    • Customer names
    • Encrypted credit or debit card numbers
    • Expiration dates
    • Other information relating to orders

    Adobe also acknowledged that the attacker(s) have gained access to the source code for Adobe Acrobat, ColdFusion, and ColdFusion Builder.

    Adobe will be emailing all customers who have been affected by this breach and informing them to change their passwords, as well as providing additional guidance to help safeguard against potential misuse of the compromised data if their credit or debit card numbers were part of the breach.
     
    Please note that it's likely that attackers will attempt to take advantage of this breach by sending fake emails that appear to come from Adobe.  If you receive an email related to this breach, do NOT click any links or reply with any information. 

    Our recommendations for anyone who may be affected by this breach are as follows:
    1. Check to see if you are affected by entering your email address at http://adobe.cynic.al/.
    2. Change passwords for all Adobe accounts.
    3. Change passwords for any other accounts that may use the same password as your account on Adobe.com.  (Remember:  it's not a good idea to use the same password on multiple websites!)
    4. Monitor financial accounts that are used for purchasing Adobe products for fraudulent activity.
    For more information, see Adobe's website at http://blogs.adobe.com/conversations/2013/10/important-customer-security-announcement.html.

    Recognizing Fake Antivirus Software

    What is fake antivirus?

    Fake antivirus is malicious software (malware) designed to steal information from unsuspecting users by mimicking legitimate security software. The malware makes numerous system modifications making it extremely difficult to terminate unauthorized activities and remove the program. It also causes realistic, interactive security warnings to be displayed to the computer user.

    How can my computer become infected with fake antivirus?

    Criminals distribute this type of malware using search engines, emails, social networking sites, internet advertisements and other malware. They leverage advanced social engineering methodologies and popular technologies to maximize number of infected computers.

    How will I know if I am infected?

    The presence of pop-ups displaying unusual security warnings and asking for credit card or personal information is the most obvious method of identifying a fake antivirus infection.

    What can I do to protect myself?

    There are lots of things you can do to protect yourself from these antivirus scams:
    • Become familiar with how your antivirus works and make sure it is always up to date.
    • Be cautious when visiting web links or opening attachments from unknown senders.
    • See Using Caution with Email Attachments for more information.
    • Keep software patched and updated.
    • See Understanding Patches for more information on the importance of software patching.
    • To purchase or renew software subscriptions, visit the vendor sites directly.
    • Monitor your credit cards for unauthorized activity.
    This information was adapted from an original production by US-CERT and republished for non-commercial use as outlined in their Privacy & Use policy.

    Thursday, October 3, 2013

    Keep a Clean Machine

    Here are some simple tips from our friends at StopThinkConnect.org on how to keep your computer secure:
       
    • Keep security software current: Having the latest security software, web browser, and operating system are the best defenses against viruses, malware, and other online threats.
    • Automate software updates: Many software programs will automatically connect and update to defend against known risks. Turn on automatic updates if that’s an available option.
    • Protect all devices that connect to the Internet: Along with computers, smart phones, gaming systems, and other web-enabled devices also need protection from viruses and malware.
    • Plug & scan: “USBs” and other external devices can be infected by viruses and malware. Use your security software to scan them.
    Want more tips on how to stay safe and secure online?  Visit the Stop.Think.Connect page at http://stopthinkconnect.org/tips-and-advice/.

    Wednesday, October 2, 2013

    Passphrases, Not Passwords

     
    Did you know that the average person's password is fairly easy to guess?  Most people use their name or something personal about them in their passwords, so hackers use dictionaries of common English names, numbers and words to hack passwords.  In fact, you can see the list of the top 10,000 passwords here.  (Hopefully you're isn't on the list!)  But perhaps what's even more startling is that current software has been successfully used to crack passwords that are 55 characters long!

    But you don't need to be one of those average people...  Instead, think about replacing your out of date passwords with strong passphrases.  What's that?  What's a passphrase and how do I pick one?  We're glad you asked. 

    These 5 tips will help you out:
    1. Choose a phrase that's at least five words long. You might start with your favorite book, song, movie or a quote. Longer passwords are harder to guess than shorter ones, so you could use the entire phrase as your password.  We still recommend doing Step 2.  If the application won't allow such long passwords, then you could use the first letters of each word as your password. For example, the first letters of the book title "The Cat in the Hat" are: tcith. This step protects you from a dictionary attack, in which someone tries to crack your phrase using known words (and proper names).
    2. Alter some of it. The hardest to guess passwords\passphrases are "complex", which means they use a mix of numbers, symbols and upper and lower case letters.  Take your passphrase from Step 1 and replace some lowercase letters with capital letters, numbers or symbols. For example: Tc!tH capitalizes the first and last letter and replaces the "i" with an exclamation point. (You could replace an "a" with the "@" symbol too.) Make it simple; don't write your system down.
    3. Customize the password for each use. Add a character or three to the core password to ensure that every pass phrase is at least seven characters long and includes a number. Generate an extra letter and number based on the name of the program you're accessing. For example: g6Tc!tH could be a password for a Google Gmail account, adding an "o" for the last letter of Google, and a 6, for the number of letters in Google.
    4. Write down your hint. Now you can write down a mnemonic device that will jog your memory without being obvious to anyone else. Hide this piece of paper or keep it in your wallet. For example, you could write down "basic: cat" to recall the Dr. Seuss title.
    5. Establish different levels of passwords. Use different core phrases to develop passwords for online banking, for accounts that use your credit card and for those that don't involve financial information.
    6. Change your passwords often.  If you can't change your password every 90 days, use daylight-saving time as the reminder to change your passwords.  If you don't change them and someone is able to get them, this will stop them from using your accounts for a long period of time.
    Want to test how long it would take a hacker to crack your password?  You can test a password over at HowSecureIsMyPassword.net.  But don't put in your actual passwords!!!

    Tuesday, October 1, 2013

    Happy National Computer Security Awareness Month!

    NCSAM It's finally here! National Computer Security Awareness Month starts today and the entire KUMC campus is celebrating throughout the month of October with both online and face-to-face opportunities to learn more about how to keep you, your family, and your data safe and secure. Each day on this blog, we'll focus on a different risk or threat such as phishing, iPad and mobile device security, social media privacy, or keeping track of all those passwords.  It will be a learning experience, but it will be a fun one....we promise!

    During the week of October 28th, we hope you'll bring your lunch and join us for all four of the following Lunch 'n Learn sessions from 12 to 1 p.m. 
    (You can sign up now using the links below):

    Monday, October 28th:  Got (Too Many) Passwords?
    Description:  Passwords, passwords, passwords for your bank site, your personal and work email, Facebook, and on and on. How do you keep track of all of them? Bring your lunch and learn about a FREE and secure way to manage your passwords, including how to make sure they're always available when you need them.

    Tuesday, October 29th:  Defend Yourself: Top 10 FREE Security Tools
    Description:  A new computer taken out of the box and connected to the Internet is easily taken over by a hacker within minutes. If you've got a computer, you need to arm yourself with the right tools to fight this constant battle. Bring your lunch and learn about the FREE security tools that are a must-have for any PC owner.

    Thursday, October 31st:  R U My Friend? Privacy and Social Media
    Description: Social media sites like Facebook and Instragram are great for keeping track of friends and sharing your everyday life with those you love. But there's also a dark side to sharing your information on these types of sites. Bring your lunch and find out how companies and criminals use the information and photos that you share on these sites and what YOU can do to protect yourself on social media.

    Friday, November 1st:   Mobile Revolution: Mobile Device and Cloud Security
    Description: Smartphones, iPads, tablets and other mobile devices are literally changing the way we work and play. But do you know how to protect your shiny new device from hackers? And just what does it mean to store your data "in the cloud"? Bring your lunch and your questions as we discuss security issues related to mobile devices and storing data in the cloud.


     
    The more you participate, the more chances you have to win one of the great prizes* to be raffled off on November 1st!  And, even if you can' t make one of the sessions, you can still enter the raffle by participating in the online treasure hunt starting October 28th.
     *Prizes to be announced later this month.

    We hope you'll join us in the celebration!

    UPDATE 10/24/13:  Prizes for this year have been announced and they look great.  Click here to find out details on what prizes are available and how you can enter to win. 

    UPDATE 10/28/13: The online security scavenger hunt is now open.  Even if you can't find time to attend the Lunch 'n Learn sessions, completing the hunt will give you an entry into the prize drawing on Friday.  Good luck!