Webroot Unveils Webroot(R) Internet Security Complete, the First Consumer Offering to Protect You, Not Just Your PC

Webroot Unveils Webroot(R) Internet Security Complete, the First Consumer Offering to Protect You, Not Just Your PC
Webroot, the first Internet security service company, today announced the availability of Webroot Internet Security Complete, the company’s newest consumer offering. Webroot Internet Security Complete introduces the most comprehensive protection for today’s Internet user, integrating Webroot’s enterprise-class cloud protection with technologies that secure what consumers care about the most …

Read more on CNW Group via Yahoo! Finance

Kaspersky Internet Security Review Part 1


Welcome to the big daddy of internet security…KIS 2010. This review is broken into multiple parts that will be uploaded every few days until i’m finished with it.

BlueCoat ProxyClient

As I warned, I attended a BlueCoat seminar on Wednesday and I’m getting a few days worth of blog posts from that.

In March of 2009, I blogged that I was testing the BlueCoat ProxyClient.   The ProxyClient provides URL filtering via WebPulse and also attempts to provide acceleration to VPN users and users on slower network sites.   Each feature can be enabled or disabled automatically depending on location.  Last year I had ProxyClient deployed to the IT department for quite a while until it was time to test some HTTP SaaS solutions.  At that point I uninstalled ProxyClient from all computers.   I didn’t return it after I completed my HTTP bakeoff.   I only renewed with BlueCoat for one year and didn’t want to roll out something and then switch it only a year out.

Looking at this months desktop virus reports, its pretty clear that a large number of the infections occur while systems are remote.   Outside the facility they currently only have SEP11 as protection.   For a long while I felt that if I was going to offer protection, URL filtering wasn’t good enough.   I needed antivirus.   But from what I wrote about yesterday with WebPulse, I am now thinking this is a significant step up security wise.   Also it doesn’t have the SaaS risk. 

To be sure some of our users might revolt if we put one more security product on “their” desktop.   But I a strong case can be made for deploying ProxyClient.   If you own BlueCoat and you pay for BlueCoat WebFilter, then the ProxyClient is no charge.  At most companies, users are increasingly mobile.   Unless you’ve got some other strong protections (such as only allowing browsing through an always tunnel vpn connection, and also removing local admin rights) I’d take a strong look at adding this protection.

PC Tools Internet Security 2009 (version 6) review part 1


Should you buy PC Tools Internet Security 2009? Find out now!!!

SANS – Internet Storm Center – CME-24 (Blackworm) Analysis: The destruction does not appear to spread across Windows network shares

SANS – Internet Storm Center – CME-24 (Blackworm) Analysis: The destruction does not appear to spread across Windows network shares

CME-24 Analysis: The destruction does not appear to spread across Windows network shares (NEW)

I wanted to share some of the results of some long hours spent looking at this malware.  When the infection occurs, it immediately places copies of itself  locally on each share and on each share/mapped drive that it finds.  Based on this behavior, my initial thoughts were that the destructive payload would be carried out via shares and/or mapped drives as well.

I now have changed my initial thoughts on how the destruction would occur.  Here are some of my notes from my testing of this concept.  Here is the MD5 from the file I was using:

1c66904ecb846da5b1fb2072f9ea6e0e *New WinZip File.exe

The first test I did led me to believe that the destruction would be carried out via the shares and mapped drives.  In my intial test, I had two infected systems (one XP and one W2K) with drives mapped to each other.  I infected each box, changed the system time to Feb 2 at 11:50pm, launched ethereal, filemon and ran the the first shot using RegShot.  After an hour, I stopped the captures and launched my second shot of the hard drive with RegShot.  All my data files were now over written, zip files were corrupted, etc.  Everything was happening as I thought it would.  All my mapped drives had corrupted files. The security logs from each box showed accesses from the other.

For the rest of this in depth analysis, go here: SANS – Internet Storm Center – Cooperative Cyber Threat Monitor And Alert System.


February 2, 2006 –


Posted by
antivirusguy |
Antivirus News

Blackberry security

All the security settings in the world don’t matter if they aren’t turned on.

According to the Washington Examiner, the social security numbers names and addresses of nearly 700 Prince William County Virginia residents was potentially disclosed when a county issued Blackberry was stolen.  The Blackberry stolen from a vehicle parked in a county employee’s driveway overnight.  

Like most news we’ll probably never hear the rest of this.   It sounds IT negligence to deploy a Blackberry without a PIN timeout requirement and encryption enabled.  There wasn’t an existing policy about PII on the Blackberry.   And of course we have to think about physical security.   Its easy to have a false sense of security about the things we leave in our cars.

Kaspersky Internet Security 2009 Prevention Review


Can KIS 2009 protect your computer from all the malware out on the internet? Find out!

SANS Internet Storm Center – “Malicious” Websites

SANS Internet Storm Center – “Malicious” Websites

 

“Malicious” Websites

Published: 2007-11-10,
Last Updated: 2007-11-10 21:26:57 UTC
by Koon Yaw Tan (Version: 1)

Previously, we often warn people from visiting unknown/suspicious websites as they could contain malicious content. But nowadays, even visiting known websites, you could be affected. It was reported that the India Times website contains hundreds of malicious files that could infected those visit the website.
http://www.theregister.co.uk/2007/11/10/india_times_under_attack/
Legitimate websites containing malicious content is not something new as it has already happened a couple of times. Web administrators must be prudent to ensure their websites are properly secure. Hackers are now clever enough not to deface your websites to alert you but rather plant malicious content on them and wait for victims. Periodically running a vulnerability scan on your web systems is necessary to avoid known holes. Let us know if you have other good tips for the web admin.

SANS Internet Storm Center; Cooperative Network Security Community – Internet Security – isc


November 11, 2007 –


Posted by
antivirusguy |
Security News

McAfee Internet Security 2009 Prevention Review and Test


Will McAfee Internet Security protect your PC from threats. Find out as I try to load 10 pieces of malware on a computer with mcafee internet security 2009

Tynt

I installed Tynt Insight on here tonight.   Tynt is javascript on the webpage that tracks when cut and paste is used on the page.  More importantly it adds attribution.   Generally when I’m copying a couple sentences to quote in a blog post I have to grab the URL separately.   This makes it a one step process, so attribution is more likely.  

So if I have written:

Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi.

When that is copied and pasted it will look like

Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi.

 I saw it in use on Wired and really wanted it, so I tracked down what they were using and then did some more searching.   I see some people think its really obnoxious.   I think it just helps people attribute properly, and isn’t in your face otherwise.

There are WordPress plugins to add Tynt so I dont even have to edit the theme.  So far easy as pie.  

 If you think Tynt is creepy there is a opt out available at their site.

Next Page »