Tuesday, March 15, 2011

Fix Windows 7 Firewall Failure Error

Problem :

My first experience with Windows 7 64 bits...After adjusting Windows 7 Firewall to it's highest security level, the Gibson Research firewall leak test demonstrated that Windows 7 firewall failed to prevent breeching. I downloaded Zone Alarms free firewall and that was successful in plugging the leak, however, it seems that Zone Alarm was not compatible with 64bit OS and my computer was freezing upon startup! I am also running Microsoft Security Essentials which does not seem to contain any independent firewall settings. I have uninstalled Zone Alarm and now remain with only a leaky Windows 7 firewall. Any advise???


Solution :


Windows 7 also has a test application, Action Center. If there is any leak, it will be detected and the notification will pop up. If not, we usually consider that the system is safe and we need not modify anything. At this stage, I suggest you restore the Windows Firewall settings to default and check whether everything is fine. Meanwhile, regarding the report from the third party application, please contact the manufacturer for further assistance about the reported leak.

Wednesday, October 13, 2010

Fortinet goes virtual

Fortinet is introducing virtual versions of four of its physical appliances that are designed to protect traffic as it moves between virtual machines.

FortiGate, FortiManager, FortiAnalyzer and FortiMail appliances will be compatible with VMware virtual environments, the company says, extending security as well as management and reporting to the traffic traveling among VMs.

FortiGate is the company's unified threat management (UTM) appliance that performs a range of security functions including firewall, VPN and intrusion detection. FortiGate software will be deployable on VMware VMs. It will be licensed for two, four and eight virtual CPUs.

One feature of FortiGate physical appliances is virtual domains, the ability to create separate firewall and administrative domains within one appliance. Virtual domains are supported within virtual FortiGate instances, the company says.

FortiManager is the management platform for Fortinet appliances, FortiAnalyzer is the analysis and reporting tool, and FortiMail is the e-mail security scanner.

In each case the functionality will be the same as for the appliances. Because instances of the products run on VMs within physical machines, they can filter and report on traffic among the guests on the host machines, Fortinet says.

Other vendors offer security software for deployment on VMs including Catbird, Reflex Systems, Check Point, Altor, Stonesoft, Vyatta and others. Cisco is expected to announce virtual security platforms soon.

FortiGate Virtual Appliance starts at $9,995 for a two CPU version, $14,995 for the four CPU version and $29,995 for the eight CPU verstion. FortiManager Virtual Appliance, with a license of 5,000 devices/120,000 FortiClient agents, costs $22,495. FortiAnalyzer Virtual Appliance will become available in Q4, and FortiMail Virtual Appliance is due in Q1 2011. Pricing for them has not been set.

Read more about data center in Network World's Data Center section.

Source : Network World

Saturday, September 18, 2010

ZoneAlarm announces its Vista-compatible firewall

Checkpoint has released an updated ZoneAlarm 7.1 that's designed to work with Windows Vista's architecture. This is the first true two-way firewall for the Windows Vista environment. Windows Vista includes the Windows Firewall, however, it blocks only inbound traffic, allowing all "except where excepted" outbound traffic. This may seem like a fine distinction, but it can be huge. If you acquire a remote-access Trojan on your Windows Vista machine, Microsoft may not flag the outbound traffic.

Checkpoint explained its delay in releasing this product in an e-mail. "Rather than rush to market with a patchwork solution when only a small fraction of our users were actually using Vista," the company said, "we decided to invest in the long-term." This includes building the product on Microsoft's Windows Filtering Platform API, rather than continuing to use the soon-to-be outdated TDI API. Not only does this provide ZoneAlarm with more stability under Windows Vista, but it means Checkpoint won't have to rewrite its code when TDI does expire.

ZoneAlarm continues to provide a free version in addition to its paid versions. Its Internet security suite continues to use best-of-breed third-party products such as the Kaspersky antivirus engine and MailFrontier antispam filters.

Source: news.cnet.com

Wednesday, August 25, 2010

Tips to Protect Yourself If You Are Online Gamer

Gamers could have a greater risk of being exposed to online threats. Here are some tips to help keep you safe.


Online Gaming

Online gamers are as likely as anybody else to encounter scams and malware attacks. In fact, because gamers often spend a considerable amount of time online, they may even be more likely than most users to be exposed to an attack. Further, the camaraderie that exists in close-knit gaming communities makes it all the more likely that people will be tempted to click on a link sent by another competitor – especially as they may be thinking more about the action at hand than potential risks. In a recent newsletter, Australian security company PC Tools explained how attacks can work:

  • Seed pirated copies of popular games with malware. Most recently, cybercrooks abused public interest in StarCraft II, targeting gamers downloading from a BitTorrent site. Several .exe files were malicious, and contained the ability to inject code, log keystrokes, and capture passwords.

  • Attempt to gain access to a gamer’s personal information (usernames, passwords, even credit card information) by pretending to share a common interest. Take advantage of known vulnerabilities in software or operating systems to spread various forms of malware (viruses, worms, trojans, and the like). Once one computer has been infiltrated, an entire network could be next.

PC Tools also provided some hints on how to keep safe while gaming:

  • Don’t get zapped: Get both signature-based and behavior-based anti-malware protection. Signature-based antivirus software proactively screens incoming and outgoing emails, Internet downloads, zip files and hard drives. Behavioral-based protection provides efficient and proactive protection against Internet threats such as viruses, keyloggers, rootkits and trojans, as well as new and unknown threats.

  • Turn on your shield: A firewall will prevent unauthorized users from gaining access to your computer through the Internet or a network and will also make sure that unauthorized programs don’t take up your bandwidth while you play.

  • Play smart: Don’t supply other players with your personal details or click on any links they offer you, limit the amount of personal information you supply the game’s administrator server, and don’t share your game password or your account credentials with other gamers –- fellow gamers and hackers can cheat!

  • Do your homework before you play: Research the game’s hacking history on the Internet before you subscribe to an online game to identify the security risk.

If you’re a parent of kids who are into online games, there is an additional point you need to consider. It’s not unusual for kids to look for ways to avoid paying for games, and that can put their computers at risk – they may end up downloading compromised files or end up visiting malicious, malware-serving websites. I’ve seen computers belonging to young family members that have been infected with a smorgasbord of malware (yes, Ben and Izaac, I am talking about you!), from password-stealing Trojans to malware that causes pop-up ads for gambling and porno websites. Now, if a kid is doing this from their own computer then, depending on your moral standpoint, you may or may not consider it too much of an issue. If, however, a kid is causing the family computer – one that’s used for online banking and other financial transactions – to be compromised, it can be a real problem (example). Installing an antivirus program and keeping it updated will certainly help, but it’s still not a sure-fire solution as there is always a risk that it may not detect a new strain of malware.

The best advice is not to share a computer with your kids but, of course, this is not an option for everybody. If you do need to share a computer with your kids, here are a few hints that may help keep you – and your money! – safe:

Set rules. Tell your kids that they are not allowed to download cracked/pirated software and explain why.

  • Password-protect your antivirus program so it cannot be disabled.

  • Educate yourself. Learn the risks and learn to recognize warning signs (for example, if your 13 year old has installed WinRAR, you’ll probably want to ask why!).

  • Block it completely. If you’d prefer to simply block your kids from playing online games, you can do so using the excellent and no-cost OpenDNS or other parental control software. Additionally, you can use User Accounts to prevent your kids installing software without your permission (Why use a standard user account instead of an administrator account?)

  • Talk to them. Make sure that you understand what your kids use the computer for and make sure that they understand the risks associated with certain types of activity.

Has your computer ever been compromised as a result of online gaming? Or do you have a security tip to share? Leave a comment and let us know!

Source: sync-blog.com

Tuesday, June 15, 2010

Group Releases Guidelines for Future AV Software Tests

A coalition of security companies and researchers have agreed on guidelines for how security software products should be tested, which may help put an end to long-running disputes about different testing methodologies.

Two sets of guidelines covering principles for testing security software for performance and testing entire security suites were adopted by the Anti-Malware Testing Standards Organization (AMTSO) at its latest meeting in Helsinki.

The guidelines are part of a series of documents on AMTSO's Web site aimed at introducing a set of standards broadly agreed through the industry as appropriate for ranking the effectiveness of security software.

Security companies have bickered over tests run by organizations such as AV-Test.org and Virus Bulletin and others, which regularly test and rank security software.

Among the contentious issues are the age of the malicious software samples used to test antivirus programs. Companies that failed to detect certain kinds of malware have argued in the past that the samples weren't threats any more and that they had removed the signatures from their databases.

Other companies have countered that their failed test wasn't accurate since other technologies in their software would have stopped the particular threat. Some antivirus testing programs perform static testing, where an antivirus engine is run against a set of samples.

But many security companies have incorporated other complex ways to detect malware. One such method, known as behavioral detection, checks to see how malware behaves on a computer.

The new guidelines are voluntary, but many testing organizations have agreed to go along with them, such as Virus Bulletin, AV-Comparatives, West Coast Labs and ICSA Labs, said David Harley, an AMTSO board member and director of malware intelligence for ESET. AV-Test.org will also use the guidelines, according to Andreas Marx, who founded the company.

"We're just trying to get people to think harder their methodologies so that they actually make sense," Harley said. "It doesn't mean you can't do things different ways, it just means you have to try and conform to a rationality."

Virus Bulletin has contributed to the guidelines covering performance testing, said John Hawes, technical consultant and test team director.

"We've already started implementing some of the ideas developed while discussing and designing this document, with some major expansions to the performance data we report in our comparatives in recent months and more improvements on the way," Hawes said. "We're also hard at work developing a new style of test which will allow us to measure the full range of features in many of today's security solutions."

AMTSO has reached agreement with many security companies, but the nonprofit organization is still viewed with some suspicion by other consumer organizations outside of the security industry that do security software testing, Harley said.

AMTSO's membership comprises mostly vendors, but the organization will work to communicate that the standards that have been developed are sound and can be trusted to provide more accurate test results, Harley said. "That's something we are going to have to work on," Harley said.

Source: pcworld.com

Wednesday, May 5, 2010

Fake Anti-Virus Software

While Trojans and bots are the most prevalent forms of malware circulating the web, cyber criminals’ use of rogue anti-virus software is steadily increasing.

So claims Sunbelt Software, which released its list of the top 10 malware threats in April. The rankings were largely unchanged from March apart from the entry of a loader for a rogue security product named SecurityTool.

The FraudTool.Win32.SecurityTool (v) threat took the final place in the top 10, removing Virtumonde from the list.

A recent report from Google claimed that fake anti-virus software now accounts for 15 per cent of all malware on the web.

“Trojans and bots are very prevalent. We also have an indication that rogue security products continue to spread," said Sunbelt Software research centre manager Tom Kelchner.

"In recent months many security researchers at antivirus companies have been noticing a slow but steady increase in rogue activity. It's becoming a very significant source of income for the bad guys,” he added in a statement.

Trojan.Win32.Generic!BT was ranked as the most prevalent form of malware threat by Sunbelt, with a 33.74 share, far ahead of Exploit.PDF-JS.Gen in second place on 3.41 per cent.

Source: itpro.co.uk

Monday, April 12, 2010

5 Tips for protecting Windows 7 with Anti-Virus Program

An anti-virus program or software is a critical part of any Microsoft operating system that interacts with other systems, especially if it is connected to the Internet and works with browser, email, or instant messenger traffic. It looks like everyone has his or her favorite anti-virus solution and it is different from everyone else’s. For personal desktop systems, however, there are some rules of thumb that seem to be fairly universal among security experts:

Don’t run two anti-virus programs- Running two anti-virus applications at the same time is just asking for trouble. Whether it is because their real-time scanners fight over access and between the two of them can slow your PC to a crawl, or because one might misidentify virus signature files maintained by the other as actual virus infections, many problems can crop up that make using two desktop anti-virus programs effectively incompatible with each other.
Scan the entire Windows 7 PC- A real-time scanner is not enough. You should also make sure you perform full-system scans frequently, and automate the process with a scheduled nightly scan if possible. Real-time scanners only finds an incoming virus before it infects your PC if it happens to pass through a point of access that the scanner can effectively protect, and even then sometimes something might get through before there is a virus signature available for your Anti-Virus program.
Get Anti-Virus with a real-time scanner- You require an on-access, real-time scanner to ensure that some of the most common infection vectors for viruses and worms are checked live, to prevent an infection from spreading when your system first encounters the virus or worm. Real-time scanning can be a real burden on system performance, and there may be times when you would want to disable it to increase your performance, but you need to be very careful about that. Surfing the Web and checking email are not the times to turn off your anti-virus real-time scanner for extra performance.

Install your Anti-Virus program before connecting to the Internet- Any Microsoft Windows system should have anti-virus program installed before connecting to the Internet. We have seen malware insinuate itself onto a computer in less time than it took to download anti-virus software to use on the system. If you have not seen that, and you use that as evidence you do not need to worry about anti-virus until after you have opened a browser and visited to a Website where you can download Anti-virus software.

Don't trust default Anti-Virus program- Norton and McAfee, once among the most trusted anti-virus programs for Windows users. Now a days, most home desktop security experts recommend that any system that comes with any default anti-virus program get something else installed instead, as quickly as possible.
Other factors can play a vital role in protecting against virus infection, of course. A good firewall good user practices when browsing the Web, checking email, or downloading files and even Microsoft Windows 7 User Account Control can help sometimes.