Security

Articles about Security on omid.dev — guides, topics, and notes from the field.

6 Common Myths and Misconceptions About Malware

Published: January 4, 2011 Reading time: 5 min

Over the past few decades, computer security has become an important concern among users. Security vendors have faced tremendous challenges dealing with complex security threats with IT experts placing more effort on educating people. Nevertheless, there are many computer security myths that exist today and surprisingly, many people still believe them. In this blog post, we’ll reveal a few of the most common malware myths and the misconceptions that can put you at risk. ...

Continue Reading

Malware Prevention guide for Windows

Published: January 3, 2011 Reading time: 3 min

To help secure your computer against malware: If your computer is already infected or you are in doubt, first look at the Malware Removal Guide. Build up your malware defenses Install antivirus and antispyware programs from a trusted source Never download anything in response to a warning from a program you didn’t install or don’t recognize that claims to protect your PC or offers to remove viruses. It is highly likely to do the opposite. Get reputable anti-malware programs from a vendor you trust. I recommend Avira. It’s highly recommended that you create another layer of protection beyond Avira. This second layer could be composed with Malwarebytes’ Anti-Malware, Hitman Pro or any other on-demand antimalware software. Use a safe browser with good extensions I recommend Google Chrome with uBlock and WOT. Update software regularly Cybercriminals are endlessly inventive in their efforts to exploit vulnerabilities in software, and many software companies work tirelessly to combat these threats. That is why you should: ...

Continue Reading

Malware Removal guide for Windows

Published: January 2, 2011 Reading time: 2 min

If after following this guide you failed disinfecting your computer, or you cannot follow this guide yourself, I will be available to help you. The most important thing in fighting malwares is: Do NOT Panic. Do NOT Hurry. Do NOT ignore any step in removal guide unless I tell you. This manual for removing malwares can be used for either minor or major malware infection. Download and Burn Avira Rescue System to a blank Disc, Boot your computer using that and let it scan and remove malwares detected. Restart your computer into safe-mode with networking. (How to use Safe Mode?) Clean temporary files using TFC. [Let it reboot your computer, come back to Safe Mode With Networking] Download HitmanPro to your desktop, run it in force breach mode and click next to scan your computer, let it remove the malwares it find, if it ask you for license active the 30 Days trial version. after removal, restart your computer. [Try it in Safe Mode With Networking] Download, install and update Malwarebytes Antimalware, let it scan your computer and remove everything it find [Try in Safe Mode With Networking]. Download and run avast! Browser Cleanup to cleanup and reset your browsers. Download and install HostsMan. after install run it, click on “update Hosts”, choose “MVPS Hosts” (and you may choose “Peter Lowe’s AdServers List” for blocking Ads) and in below options choose “Overwrite Current” hosts. this step would immunize your Hosts File and would prevent any internet traffic to malware sites/domains and also would fix Windows Hosts File if it has been HiJacked by malwares. Disable System Restore and then re-enable it again. If you have windows installation disc, insert it into drive, open Run command from start menu (In windows vista/7, open start menu and type ‘Run’ and then press enter) and type ‘sfc /scannow’. this will check windows for mission or corrupted files and will restore them from disc. sometimes during getting infection or malware removal some files might get corrupted or being deleted which this action will solve it. Make sure your windows and all installed programs are fully updated and there are no insecure program: Check for Update. also you may do some additional scans too, here is some of them: ...

Continue Reading

Your own email @facebook.com? Beware Facebook survey scam

Published: December 20, 2010 Reading time: 1 min

Thousands of Facebook users have been hit by a scam which claims to give them early access to a facebook.com email address. Messages, appearing in the news feed of users who have fallen for the scam, read: Just got my own email @facebook.com! Quickly get one before someone takes your name [LINK] However, clicking on the links leads you to a webpage which tricks you into giving a third party application permission to post to your Facebook wall. ...

Continue Reading

New hacked site notifications in search results

Published: December 20, 2010 Reading time: 2 min

Today we’ve added a new notification to our search results that helps people know when a site may have been hacked. We’ve provided notices for malware for years, which also involve a separate warning page. Now we’re expanding the search results notifications to help people avoid sites that may have been compromised and altered by a third party, typically for spam. When a user visits a site, we want her to be confident the information on that site comes from the original publisher. Here’s what the notification looks like: ...

Continue Reading

Don’t Lie to Me, Angelina!

Published: December 15, 2010 Reading time: 2 min

Earlier this year I received a Facebook invite in my Yahoo! Mail account from none other than Angelina Jolie herself. I kid you not. While it’s true that we live in the Digital Age where communicating with anyone is a mere tap of a finger away—whether it’s via email, IM, Facebook, Twitter, etc.—the chances that Ms. Jolie would randomly reach out to a regular Joe, such as myself, is still pretty darn improbable. So, the following questions raced through my mind: ...

Continue Reading

The top 50 passwords you should never use

Published: December 15, 2010 Reading time: 2 min

Are you one of the many people who is using a dangerously easy-to-guess password? Maybe now’s the time to fix that before it’s too late. Twitter, LinkedIn, World of Warcraft and Yahoo are amongst the popular websites which are advising users to change their passwords in light of the recent security breach at the Gawker Media family of sites. The issue is that many people (33% in our research) use the same password on every single website. That means that if your password gets stolen in one place (like Gawker’s Gizmodo or Lifehacker websites), it can be used to unlock access to other sites too. ...

Continue Reading

Plenty of Updates announced

Published: December 11, 2010 Reading time: 1 min

Avira TechBlog: Next Tuesday is going to be tough for administrators: The Redmond company announces 17 security bulletins which are supposed to fix 40 security vulnerabilities. Only two of the bulletins deal with “high”ly critical rated security holes within Windows and the Internet Explorer. The rest of the updates fixes the Windows operating systems, Microsoft’s Office, SharePoint and Exchange.

Continue Reading

QuickTime 7.6.9 update resolves 15 vulnerabilities

Published: December 11, 2010 Reading time: 2 min

This week Apple announced the availability of QuickTime 7.6.9 for OS X 10.5 and Windows platforms. This release fixes 13 vulnerabilities in QuickTime for OS X Leopard and 15 vulnerabilities on the Windows platform. Keep in mind that if you use iTunes it requires that you install QuickTime as well, so be sure to check for updates. Apple has provided a direct download link for IT folks at http://www.apple.com/quicktime/download/. All 13 vulnerabilities for OS X can cause unexpected application termination (what you and I call a crash, but you can’t say crash on a Mac) or arbitrary code execution (make QuickTime run programs… BAD). ...

Continue Reading

Dutch police website attacked after arrest of suspected hacker

Published: December 11, 2010 Reading time: 1 min

Just a day after Dutch police arrested a 16-year-old boy in connection with WikiLeaks-related denial-of-service attacks, websites belonging to the Netherlands computer crime cops and prosecutors have been struck with a similar assault. Dennis Janus, a spokesman for the National Police Service confirmed that both the police website, and that of the National Prosector’s Office had been offline for much of the day, with many theorizing that the likely reason is a distributed denial-of-service (DDoS) attack similar to that which was launched against MasterCard, PayPal and other firms. ...

Continue Reading