Thursday, 8 May 2014
Protecting Tech-savvy kids
Posted by
Unknown
at
09:58
Wednesday, 4 December 2013
Gauging employees’ moods using their search trends
- Whether the user is actively performing work related searches (most of their queries should be work related)
- Whether they are doing anything suspicious
- If they have particular personal or personality problems which might require the company’s assistance
So what exactly is search engine query monitoring?
Why is it useful?
Great, tell me how to do it!
What search engines are supported?
Search over HTTPS? Will search engine monitoring work in this case?
What value does this give me?
1) TV Series or Movie Downloads – people attempting to search for TV series or movies to download which could lead to legal liability when pirated material is downloaded via the company’s connection
2) Adult and Pornography Searches – people attempting to search for Adult content via search engines despite you blocking Adult websites
3) High Risk Searches – searches for explosives, weapons, suicide or other possible problematic situations
4) Your own custom search term report – GFI WebMonitor allows you to easily create your own reports for specific terms, and in any language you want
Interested yet? Try GFI WebMonitor for 30 days and monitor what your users are searching for. You might be surprised!
Posted by
Unknown
at
11:25
Malware as a Service
So what exactly is Malware-as-a-Service (MaaS) and why it is used?
Malware as a service is essentially an online service which is used by people who have written a specific piece of malware and want this to get distributed quickly. Essentially what the MaaS does is take the headache out of distributing the malware. Let’s say you’ve written your own malware program which you want to distribute. You could do a few things to help push its distribution1. Infect pirated software with your malware and upload it to common piracy websites
2. Create a website which invites visitors to download something fake which in reality is your malware
3. Make the virus self-replicating and distribute it via some kind of software vulnerability
4. Infect your friends USB sticks with the malware and rename it to something which they are likely to open
As you can see all of the above either require a significant amount of effort or are not really effective. The MaaS also known as exploit kits effectively allow you to distribute your malware at a very cost-effective price. If your malware is going to give you financial benefits, then a MaaS service to distribute the malware widely will be very handy, and very cheap. Quoted prices from certain exploit kits start from as low as $50 for using the kit for a day, to $1500 for a year’s service making it very cheap considering its effectiveness.
But how does the infection happen?
There are a number of steps which happen to infect a user. Let’s say that you don’t want to go through the above processes to distribute the malware and you’ve decided to use an exploit kit. After paying for the service, the following will happenStep 1: Your malware is loaded onto a distribution server ready to get deployed to new victims
Step 2: The MaaS authors discover web servers of legitimate software which have problems or vulnerabilities in their setups. These vulnerabilities allow the MaaS authors to inject a piece of hidden HTML code which will be used to perform certain malicious actions
Step 3: A normal user visits the legitimate (but compromised) website. The hidden code analyses the user and detects what browser and other software they have installed on their computer. If the user has software which has not been unpatched then the next step is executed
Step 4: Based on the analysis in step 3 the user is redirected to another website which will use a targeted exploit to infect the user with the malware. As an example, if a user has a version of Java which hasn’t been updated, they will be redirected to an Java exploit
Step 5: The exploit is executed which deploys the malware using the unpatched vulnerability
The effectiveness of the distribution is due to a number of reasons
1. The sheer amount of compromised websites (millions) which exist on the internet right now and which will keep getting compromised in the future allowing for a huge audience to be exposed to the malware
3. The delivery of an exploit targeted to the specific user’s unpatched software – they will attach the user with an exploit which they know will work
4. The fact that the exploit does not need any kind of additional user interaction such as a click or a download. Just visiting the website will result in an infection (what is termed as a drive-by download)
5. The lucrative business of MaaS which allows the authors to keep expanding the sites they use, the exploits they use, the AV avoidance techniques
6. Using spamming, SEO poisoning, or other techniques to push users towards the compromised sites
How effective are these kits? And how many of them are there?
Very effective. Different security vendors quote different numbers for each kit, but all of them agree on one common conclusion. These malicious websites used by these kits make up the absolute majority of threats in the wild today. The majority of infections which happen today are coming from these exploit kits. Old viruses and distribution methods have become insignificant when compared to these new malicious URLs. There are tens of exploits kits out there, the Blackhole Exploit kit used to be one of the most effective (though the author Paunch has reportedly been arrested and the kit is no longer being updated), Neutrino, Glazunov and many more. As the business gets more lucrative the MaaS authors start to get competitive between themselves, making improvements in all aspects of the kit from usability, price, infection and obfuscation techniques.Ouch! … How do I protect myself and my employees?
Posted by
Unknown
at
11:11
Thursday, 19 September 2013
Cloud storage? What's the price of free space?
1) Employees using cloud storage to intentionally or unintentionally leak confidential information – this is a risk which can cripple any business. Anything from leaking product development plans by mistake, leaking customer data or client lists to competitors for monetary gain, or leaking financial data or documents – there is a very high risk of losing confidential information to cloud storage
2) Downloading malicious software via cloud storage – whenever a user accesses files from cloud storage accounts, especially from accounts which they don’t own, they are creating a serious security risk. This is especially so, if the cloud storage accounts are being used to store cracked software, which are typically booby-trapped with trojans and other malware. The risk to your company’s security is not to be ignored
3) Draining your bandwidth – isn’t it comfortable to upload the contents of your SD card to cloud storage whilst you are at the office? With larger and larger file sizes for photos, uploads to Cloud storage can easily hog the upload stream of a company. And although typically the upload stream is not used much by most companies, a hogged upload stream typically causes slowdowns in the downloads too. Any download requires a healthy non-hogged upload stream, so if the upload is being hogged, downloads are being affected for EVERYONE! Large file downloads from cloud storage are also likely to hog bandwidth.
Your employees should be educated first and foremost on the risks associated with cloud storage. This however, is usually not enough. Web monitoring software can quickly help you identify how cloud storage is being used and / or abused. It can help your track and report on how much bandwidth is being used by cloud storage, and who are the users who are accessing these services. You can then determine whether you want to allow this or not, but isn’t it better to be informed?
Posted by
Unknown
at
09:11
Monday, 9 September 2013
Who's about to go crazy this March Madness?
The NCAA Men’s Division 1 Basketball Championship, AKA “March Madness”, is a major distraction in U.S. workplaces every year. The tournament kicks off March 19, with the busiest tournament days occurring on Thursday, March 21 and Friday, March 22 during standard business hours (beginning at 9am ET).
It’s only natural that employees’ level of interest is high when there is so much focus on the tournament in such a short span of time. Employees who are following the tournament closely are highly likely to turn to the Internet to stay up-to-date on the latest news and scores. With so many websites available to follow the tournament, it is very common for employees to watch live streams of games, listen to audio commentaries, view game highlights on ESPN and others, search for the latest results and stories, and participate in other related activities while at work – all of which are likely to cause a significant disturbance in three ways:
Bandwidth bottlenecks
With multiple users streaming content simultaneously, the available bandwidth is easily taken up. This can have a severe impact on other applications which are dependent on the Internet, such as VoIP, CRM, email and other cloud and Internet-enabled applications. Typical streaming content consumes 10Mb of data per minute. Multiply that by a significant number of employees and you can see why a bandwidth spike creating a bottleneck is inevitable.Productivity loss
With games held during regular business hours, many users will be following results as they happen. This major distraction could severely impact productivity over the course of the tournament.Security problems
Hackers have always used high interest stories and trending topics as lures to infect users’ machines. March Madness is no different, and it is almost certain that cybercriminals will use the tournament to trick unsuspecting users into falling for fake websites, SEO poisoning, phishing and other malicious scams.To manage these problems, companies need to be prepared to enforce Internet usage and web filtering best practices, including:
- Informing and educating employees about the effects associated with March Madness and giving them browsing tips that will help to address these challenges – e.g. advising users to avoid streaming live games, to be cautious of which websites they visit and to avoid clicking on links that come from an unfamiliar source.
- Implementing web security software that:
- Automatically blocks malicious websites and ensures any websites visited are free of malware. A point to note is that an anti-virus engine alone is not enough to stop all threats – a dedicated web security engine is now also a must.
- Allows you to define bandwidth quotas, such as limiting downloads from streaming media websites to 100Mb a day, and limiting visits to news, media and sports sites to 30 minutes per day.
- Blocks websites which could pose legal liabilities, such as gambling websites.
- Setting up action-based alerts to anticipate problems before they develop and take the necessary action to immediately remediate issues as they rise.
If you’re interested in a good web filtering solution, take a look at GFI WebMonitor.
You can download a free trial for 30 days. It’s worth a try!
Posted by
Unknown
at
13:07
Porn in the UK parliament - also in your office?
Porn in Parliament – Also in Your Office?
Why does this happen?
It’s difficult to pass judgement on this issue. My view is that when someone is in their office, bored or tired after a long day, and having ‘exhausted’ their energy on Facebook, they might think that a quick peek at a ‘naughty’ website will not harm anyone? It’s also fair to say that most users probably already know that a web filtering solution is in place, and that their internet activity is monitored, so most of these are more likely than not deliberate attempts to access blocked online material. A user might come across an adult website while researching other topics, but the sheer number of attempts detailed in the statistics simply does not add up to this conclusion. When a specific website is visited, then it indicates intent to do so; however that’s up to the reader to judge.What should you be thinking about?
Even though employees in the Houses of Parliament probably had a good idea that their online activity was monitored, it didn’t prevent them from attempting to access adult material. Moving away from the topic of porn and MPs in the UK, and looking at matters closer to home, how can you prevent something similar from happening?What can you do to make sure that your staff spend their time more efficiently and productively? Here are a few tips:
1) First things first, if you don’t have a web filtering and monitoring system in place, then you really should implement one – unless you want to start wondering what each employee in doing online
2) You need a web filtering solution which will allow you to drill-down exactly into what a specific user is doing, as given by example in this short video: Monitoring Internet activity at the office.
3) Your web filtering should proactively advise and alert you when a user attempts to visit ‘naughty’ websites, or other illicit webpages, so that your HR department can decide whether or not to remind them of the company’s best practices on Internet usage.
4) You should invest some time and resources discovering how much time users are spending on websites which are unrelated to their official duties.
GFI WebMonitor® is an affordable solution that allows you to address all of the above. Besides the ability to block categories of undesirable websites, it is very easy to use the Activity dashboards and reports to identify employees whose time could be better spent working for you, than searching the web for themselves. Real-time configurable alerts allow you to send emails to the appropriate people when their online behaviour merits it. Search engine query monitoring, for example, will clearly show what a user’s intentions were and the appropriate department can take the necessary actions, including education, to ensure there are no repeat offenders. GFI WebMonitor offers companies many other benefits such as added web browsing security and mitigation of bandwidth issues.
Posted by
Unknown
at
13:04
Sunday, 7 April 2013
Android MODs and Kernel's - my experience
Anyway, after taking a huge number of different backups, I went for my first MOD. Slimbean. I must admit that after the richness (although bloated) experience of TouchWiz, Slimbean was a shock. It was so raw, and so lean that it felt overwhelmingly empty. TouchWiz maybe bloated, but there are definitely quite a lot of built features which are hard to replace. Stuff such as the large amount of gestures, features like SmartStay have their own value. Even, the blank background and the feel of a mostly Vanilla Android was a bit of a shock, and it takes getting used to.
After I mostly setup CM 10.1, I was fairly happy - but I ran into another issue. Android OS was eating up way more battery that I was expecting. I spent quite a few days troubleshooting what could have been causing this problem. I installed a heck of a lot of battery monitoring apps, including BetterBatteryStats and tried to understand all the partial wakelocks which were happening. I turned off syncing, location, widgets and whatever else usually causes potential battery issues. Eventually from many threads I read on XDA forums and many other places, it looked like I had run into some kind of kernel issue. Once again, I saw somewhere that flashing a kernel could be the solution to my problems. Once again, I started a search for a good kernel. Siyah looked to be quite a safe bet and I was soon flashing Siyah.
As soon as I flashed Siyah, the Android OS issue was immediately gone. And the battery life is awesome. I use the phone heavily, with multiple calls, music, playing games and various other activities, radio and Wifi on, and I still get a full day with quite some battery to spare.
Eventually, I've tweaked CM to be a very pleasant experience despite the lack of TouchWiz features. At this point, I don't miss them anymore and I've gotten used to the lean experience and moreover I quite like it. Also, CM gives me access to the latest Android versions much earlier than the Stock Samsung Android does. Here is a screenshot of my various homescreens.
So, if you are looking to take the plunge, from TouchWiz to something else, prepare yourself. Overall, it's a great experience.
Just wanted to share my thoughts my Android modding experience.
Posted by
Unknown
at
19:27
Tuesday, 5 March 2013
What the hack?
1. Facebook and Apple®
2. The New York Times (and other cyber attacks)
3. Twitter Accounts
4. Leaked user data
Posted by
Unknown
at
19:58
The Harlem Shake and the effects on your organization
Bandwidth quotas – A GFI® success story
Posted by
Unknown
at
19:56
Monday, 4 March 2013
The geek that I am ...
Posted by
Unknown
at
10:02
Guess who's back?
Posted by
Unknown
at
09:50
Tuesday, 24 November 2009
Debugging SmartPart User Controls
Ok, so you are faced with this situation
1. You are using SmartPart because its easier for your .NET developers to write UserControls, rather than WebParts (thank god for SharePoint 2010 where developing webparts will be easier at last).
2. Using SharePoint functions such as using SPContext and local debugging (i.e. using a normal web application for testing rather than SharePoint) present a headache, since the context is not available when you are debugging locally.
3. You need the best of both worlds, i.e. easy and quick debugging, but using SmartPart and user controls.
1. Create post build events which copy your User Control dll to the SharePoint folder, and your user controls to the UserControls folder
e.g. copy c:\develpment\xxx.dll c:\inetpub\wwwroot\80\wss\...

2. On the Web Application project properties, rather than using the Visual Studio web server for debugging, use the IIS webserver and specify the web application where your user controls are getting deployed.

3. Press F5 and voila, your dlls, and User Controls files are copied to SharePoint, and SharePoint is loaded and attached to the debugger.
This will now allow you to step into your User Control's code whilst having all SharePoint functions still available! :)
Posted by
Unknown
at
17:05
Monday, 5 October 2009
Reading Settings from the Web.Config file from an Event Handler
The SharePoint web.config is in my opinion the best place to put in any configuration settings. To read the config settings from an Event Handler isn't so straight forward but the following code does it nicely:
The SPItemEventProperties comes from the EventHandler.
<add key="Username" value="svc-sharepoint"/>
public static string ReadKeyValueSetting(SPItemEventProperties properties, string keyName)
{
EventLog evita = new EventLog();
evita.Source = ("ReadFromConfig");
string webApplicationName = "";
using (SPSite siteCollection = new SPSite(properties.SiteId))
{
if (string.IsNullOrEmpty(siteCollection.WebApplication.Name))
throw new ApplicationException("Web application name is empty!");
else webApplicationName = siteCollection.WebApplication.Name;
}
System.Configuration.Configuration config = WebConfigurationManager.OpenWebConfiguration("/", webApplicationName);
if (config == null)
throw new ApplicationException("Web Configuration is null");
AppSettingsSection appSettings = config.AppSettings;
if (appSettings == null)
throw new ApplicationException("Web.config appSettings section cannot be found!");
if (appSettings.Settings[keyName] == null string.IsNullOrEmpty(appSettings.Settings[keyName].Value))
{
evita.WriteEntry("KeyName doesn't exist!", EventLogEntryType.Warning);
throw new ApplicationException("Key value cannot be read from appSettings. Make sure this key and its value exist!");
}
return appSettings.Settings[keyName].Value;
}
Posted by
Unknown
at
15:48
Monday, 28 September 2009
Using HTML to create visual graphics in SharePoint
ok, so you want to create some basic KPIs without installing / buying any webparts. You can do that, using a combination of Calculcated Columns and the Custom Editor Web Part.
Posted by
Unknown
at
14:29
Thursday, 28 May 2009
Programing Search Queries
A good article by a MOSS MVP on the programming MOSS Search
http://blog.mastykarz.nl/sharepoint-people-search-lessons-learned-programmatically-running-search-queries/
Posted by
Unknown
at
11:09
Tuesday, 12 May 2009
WSS 3 - No search results returned
Well I've been banging my head against this error for quite a while and finally managed to resolve it.
Hopefully this will help somebody else out there.
Posted by
Unknown
at
13:25
Wednesday, 29 April 2009
Exporting / Importing Profile Properties from your Shared Services Provider
If you ever had to customise Profile Properties in the Shared Services Provider, you'll know what a royal PITA it is to migrate the properties from one SSP to another (especially in a Staging environment). Typically, you would either backup and restore the SSP, or recreate the Profile properties from scratch. With the latter you would have the problem of possibly not recreating the properties identically to the latest version.
Posted by
Unknown
at
09:25
Labels: export import profile properties shared services provider
Thursday, 23 April 2009
My Profile Search Link Setting
When user's click on My Profile, the details entered are displayed with a link to a Search Center whic refines that link.
Posted by
Unknown
at
13:18
Wednesday, 22 April 2009
Customising Refine Your Search
The Refine Your Search is quite a nice feature of the People Search, through as always we'd love to be able to control the properties to Refine by.
Posted by
Unknown
at
08:51
Monday, 30 March 2009
People Search Interesting Customizing Information
The following blog lists some good information about SharePoint People Search, and some problems / limitations which you will probably encounter when extending the Out of the Box People Search functions:
Posted by
Unknown
at
10:43
Labels: sharepoint 2007 people search
