see latest Virus Alerts
Computer Security News USA
  Volume 52   Issue 03   June 11, 2009

 Resource Hotline:  
 View the entire Resource Hotline list here.

This site needs a sponsor!  If you can help, please contact us.
  This site is   PowWeb: The perfect Hosting Solution™    
 Since  March 8, 2005    
 

Computer Security News for Security and Defense Professionals, for home users . . .  and for you!

Technology for Computer Security, Information for Home and Professional computer users.  Extensive coverage of hardware and software security issues and solutions.

Computer Security News is here to help you find and stay current with all things "computer security".  Here, you can find links to articles and resources to help you stay informed and protected from all aspects of many computer security issues.  Each week we will bring you the latest information about cyber crime, virus or worm outbreaks, software patches, and more. Our technology section will give you links to interesting and informative articles regarding cutting-edge technology. 

Weekly updates will be available via email newsletter.  To subscribe to the newsletter, see the "Subscribe to our newsletter" block, below.

Thanks to everybody contributing comments and suggestions with ideas to improve the site.  We remain committed to providing the most useful news and information sources for all manner of security resources.  Volunteers, please write!!

 
What you can find here:
Information.  Whether you are trying to learn how to secure a "home" PC or network, or a corporate enterprise network, or physical premises, you can find information here to help.  The purpose of this site is to provide information to help make your world a more secure place, with a focus on technology.
 
 
What you will NOT find here:
You will not find any ad banners, pop-ups, pop-unders or "float-overs" here.  There are no links to sites that are selling "scam" products, and no links to sites that are giving us any "kickback" of any kind.  Because it is time-consuming to maintain these pages; to gather, filter and present you this information, eventually we will be offering products and services for a fee.  But the information presented here will always be free.



 
 
Special Recognition:
If you are interested in the area of network intrusion detection, visit the MIT Lincoln Lab site and read their Intrusion Detection Evaluation report.  Despite this information being a bit old technologically speaking (it is from 1998, 1999), there is a great deal of interesting and useful information there.

If you are interested in, or in the process of, obtaining security certifications (and/or others), then check out the products that ExamForce offers.  These materials are designed with your success in mind.  ExamForce has long been recognized as a leader in exam preparation materials, and offers wide topic coverage.




 
 
Interesting Site of the Month:
June 2009
Our pick for Interesting Site of the Month is the "Microsoft Security Central" site.  This site offers many useful downloads and tips for the average home Windows PC user, including guidance to help prevent online fraud, spyware and/or viruses, security newsletters, and more.

Visit our Computer Security News Archive to see previous "Security Site of the Month" awards.

Other sites of interest include . . .
  CERT - Home Computer Security
  CERT - Home Network Security
  Computer Security FAQ(s)
  NIST - Computer Security Division
  Unix Tools




 
 
Interested in Windows Vista?
June 2007
Visit the Windows Vista A to Z pages at Computerworld



 
 
Security Advisories:

Oracle Critical Patch Updates and Security Alerts

Linksys WRT54G Wireless-G Broadband Router

Cisco Security Advisories





 
 
Is your Windows Computer secure?
Physical access remains the worst threat
Recently, a friend asked for help with a computer that was password protected.  The machine was set up with Windows XP Professional for an employee no longer with the organization.  Not wanting to reformat the drive because of important documents they wished to recover, I was asked how to access the machine.  This was new territory for me, but it took only a few minutes to find a solution.  Among a long list of sites with potential solutions, I found these two:
 Instructions on Password Recovery
 OPHCRACK (the time-memory-trade-off-cracker)
It took all of 15 minutes to get into the Administrator account of the machine in question.  The point is, keep your computer physically safe from those who may try to gain unauthorized access.  And if security is important, use a BIOS password as well as a logon password.  If the computer is not your personal property, make sure that the appropriate personnel have the necessary information to access it should you be unavailable to do so, as well as current backups of any/all files that contain data that is the property of, or important to, the owner.




 
 
National Cyber Security Alliance (NCSA)
Stay Safe Online offers Good Advice
If you have not visited Stay Safe Online, you should.  This site offers good advice and up-to-date information regarding computer related and information related security.  The Department of Homeland Security and The United States Computer Emergency Readiness Team (US-CERT) created the National Cyber Alert System to help you protect your computer.  Of the many excellent pages at their site, you will want to add the Department of Homeland Security's Cyber Security Tips to your "Favorites".



 
 
Antivirus software:  USE IT!
 
 Antivirus for Linux

  http://www.bitdefender.com/site/linux/
  http://www.centralcommand.com/
  http://www.clamav.net/
  http://www.f-prot.com/products/
  http://www.grisoft.com/doc/5/lng/us/tpl/tpl01

 Antivirus for Windows
  http://www.my-etrust.com/microsoft/
  http://www.avast.com/eng/avast_4_home.html
  http://www.bitdefender.com/site/windows/
  http://www.clamwin.com/
  http://www.f-prot.com/products/
  http://usa.kaspersky-labs.com/products/anti-virus.php
  http://safety.live.com/site/en-us/default.htm
  http://www.windowsonecare.com/





 
 
Microsoft Security:
   Microsoft works toward safer computing

 Resources
  Microsoft OneCare
  Microsoft Live Safety Center
  Microsoft Anti-Malware Engineering Team
  Microsoft Security at Home
  Microsoft techNet Security Center
  Microsoft Security Home page
  Microsoft Security Developer Center
  Microsoft Security Learning Center

 Product Updates
  Microsoft Windows Update
  Microsoft Office Update

 Related
  Windows Security site at windowsecurity.com
  Microsoft Security FAQ at securityadmin.info
  Security Products and Services from Shavlik



Latest Headlines & Security Articles:

 Beladen Loads Hacked Web Sites With Badness 

 Bills would kill DHS satellite surveillance office 

 ATM malware spreading around the world 

 FTC sues, shuts down California Web Hosting Firm 
 FTC persuades court to shutter rogue ISP 

 IRS halts development of Customer Account Data Engine 

 Hackers claim $10,000 prize for breaking into StrongWebmail 

 New Weapon Against Drive-by Downloads Emerges 

 Obama's Cybersecurity Dream Could Come True 

 A Gordian knot awaits future Cybersecurity Chief 

 Security strengthened for .org domain 

 Google SERPs Redirections Turn to Bots 
 JSRedir-R script biggest malware threat on the web 
 Top 10 Malware Sites 


 PC-pwning infection hits 30,000 legit websites 
 Mass Injection Compromises More than Twenty-Thousand Web Sites 

 FBI e-mail clobbered after virus 

 Financial districts a wireless hacker's paradise 

 Anti-U.S. Hackers Infiltrate Army Servers 

 Racism, Hate, Militancy sites proliferating via social networking 
 Web 2.0 and Cyberterrorism 

 Obama: Cyber Security is a National Security Priority 
 Obama action plan calls for cybersecurity coordinator 
 Obama's cybersecurity plan prompts praise and some questions 

 Hackers exploit unpatched Windows bug 

 The Scrap Value of a Hacked PC 

 Gumblar Google-poisoning attack morphs 

 Cybersecurity Review Finds U.S. Networks 'Not Secure' 

 Scientists Demonstrate All-fiber Quantum Logic 

 Twitter gets targeted again by worm-like phishing attack 

 DHS wants budget to back cybersecurity efforts 

 Facebook Among Top Phished Web Sites 

 Massive ID fraud and cheque scam busted in NYC 

 Viral web infection siphons ad dollars from Google 

 Aetna warns 65,000 about Web site data breach 

 IRS Created Dumpster-Diver Swimming Holes 


 Researchers: Cyber spies break into govt computers 

 Researchers poke holes in super duper SSL 

 Mozilla patches Firefox's critical Pwn2Own bug 

 Conficker: Doomsday, or the World's Longest Rickroll? 
 Conficker's capabilities worry researchers 
 Leaked memo says Conficker pwns Parliament 
 How Much Is Conficker Really Impacting Enterprises? 

 Security analyst spots three flaws in Google Docs 
 Google plays down security concerns over Docs 

 Worm breeds botnet from home routers, modems 

 Hacked File-Upload Accounts Prized by E-Jihadis 

 Most electronic voting isn't secure, CIA expert says 

 Facebook glitch hands off control of corporate Pages 

 Telos wins Air Force security work 

 Mac OS X Top Target in Browser Beatdown 
 Apple Mac users warned of web-based malware threats 

 Microsoft: IE8 bugs squashed 
 Hack contest sponsor confirms IE8 bug in final code 
 A grim day for browser security at hacker contest 

 Web Fraud 2.0: Data Search Tools for ID Thieves 

 Symantec Data Leak Remains Under Investigation 

 Creation of White House cybersecurity office still uncertain 

 Rogue Antivirus Distribution Network Dismantled 
 Antivirus2009 Holds Victim's Documents for Ransom 

 'Cybercrime exceeds drug trade' myth exploded 

 Users spurn latest Adobe PDF patches, says researcher 


 Why Web Site Security Matters to Us All 

 Unpatched PDF bug poses growing threat 

 One in 20 corporate PCs infested by bots 

 White House to wrap up cyber review in April 

 Firefox went ton up in bugs in 2008 

 Twitter Security Hole Left Accounts Open to Hijack 
 Twitter accounts hijacked in new attack 

 Billions in stimulus money seen for technology 

 Cloud computing: myth or reality? 

 NYPD faces ID theft risk after data stolen 

 Phishers automate attacks using 'Google hacking' 

 Recovery.gov linked to other stimulus tracking sites 

 Second rogue Facebook app bewilders users 

 Scientists Closer To Making Invisibility Cloak A Reality 


 Passport RFIDs cloned wholesale by $250 eBay auction spree 

 OpenOffice Installs Insecure Java Version 

 IT groups lobby against "Buy American" provisions 

 Microsoft changes Windows 7 UAC after new exploit code surfaces 

 A New Internet Attack: Parking Tickets 

 Report: Most Spam Sites Tied to Just 10 Registrars 

 Three hospital worm infection dubbed 'substantive failure' 

 Online Job Scams Are on the Rise, FBI Warns 

 SRA warns of possible data breach 

 Mozilla patches critical Firefox flaws 

 Open Source Research Platform: Wireless At WARP Speed 

 IBM Targets Adobe Flash Vulnerabilities with New Tool 

 MySpace Removes Thousands of Sex Offenders from Web Site 

 New OS X research warns of stealthier Mac attacks 


 China's anti-censor software pimps user data 

 New York adds security requirement to software contracts 

 Payment Processor Breach May Be Largest Ever 
 Payment processor warns of network breach 

 DHS nominee stresses cybersecurity, border technology 

 Microsoft Windows Does Not Disable AutoRun Properly 
 Worm now infects 1 in every 16 PCs 
 Superworm seizes 9m PCs, 'stunned' researchers say 
 Tricky Windows Worm Wallops Millions 
 Downadup worm infects more than 3.5 million 
 This computer worm turns 

 Three years undercover with the identity thieves 

 Airline ticket receipt scam spreads malware 

 FBI goes global on threats 

 Apple's First 2009 Patch Batch Fixes 7 QuickTime Flaws 

 DNS requires a layered approach 


 Rep. Jackson Lee proposes cybersecurity bill 

 DARPA sets first phase contracts for National Cyber Range 

 LinkedIn pages that promise prurient pics link to malware 

 Pro-Palestine vandals deface Army, NATO sites 

 Hacktivist tool targets Hamas 

 Web designers admit to trashing client's Web site 


FEATURE:  Cybercrime is a growing threat
   Cisco: Cybercriminals more savvy than ever in 2008 
   Cybercrime leaves cybercops in the virtual dust 
   Top cops urge greater focus on cybersecurity 
   Trend Micro hit by massive Web hack 
   Tories issue cyber-crime warning 
   How cyber crime went professional 
   Meet A-Z: The computer hacker behind a cybercrime wave 


 One Weak Link to Rule Them All 
 Group attacks flaw in browser crypto security 
 An easy fix ignored 

 Security vendors ready fix for 'Curse of Silence' SMS attack 

 TCIO Council panel details functions 

 New Linux kernel released 

 Business groups sue over Homeland Security E-Verify program 

 Chinese spy scare sours Australia's plans for nationwide broadband 

 Commission to fund research on China's cyberwarfare capabilities 

 11 in China sentenced for software piracy 

 Zune music players crashing en masse 

 CastleCops shuts up shop 

 Amazon warns customers of infected digital photo frames 

 FEMA unveils DisasterAssistance.gov 

 Accused Scareware mongers held in contempt of court 

 Chinese schools & search-sites host malicious code 

 US cybersecurity defences fail to thwart mock cyberattack 

 Software pinpoints wireless handset locations 

 Nanocar inventor takes top science award 


 Microsoft Wages War Against Fake Security Software 

 PC Got a Virus? Consider Getting Help Offline 

 Verizon wins $31M judgment in cybersquatting case 

 NIST conducts risk analysis of e-voting 

 Digital picture frame viruses back for Christmas 

 Google, Apple, Microsoft sued over file preview 

 Oil software exec pleads guilty to hacking charges 

 Spectrum group calls for $15B broadband investment 

 Feds consider searches of terrorism blogs 

 Beware Holiday e-Greeting Cards, Digital Hitchhikers 

 Massive layoff is a security issue 

 A battle plan for cyberdefense 


 Microsoft Issues Emergency Security Patch For IE 
 Microsoft sees 'huge increase' in IE attacks 
 Microsoft: Emergency Patch for IE Flaw Coming Wednesday 
 Microsoft offers workaround for IE7 flaw 

 Justice IG finds IT security vulnerabilities 

 EDS to assess security of DISA systems 

 American Express web bug exposes card holders 

 The Crash Of 2008: A Mathematician's View 

 Auditor: IRS doesn't check cyberaudit logs 

 Thousands of Feds no longer contribute to TSP 

 Mumbai Attacks Show India's Technology Shortcomings 

 Google Ads Lead to Phony Apps 

 NOAA models tsunami warning system 

 Boeing protests GOES-R award to Lockheed 


 Microsoft: Big Security Hole in All IE Versions 

 Google releases Browser Security Handbook 

 'Facebook for Kids' slammed by security researchers 

 DHS system doesn't guarantee privacy 

 Spam levels climb as criminals replace crippled botnets 

 Google's answer to Web app security: Native Client 

 Robots Designed To Save Lives Of Construction Workers 

 GAO: US-VISIT program has problems 

 Electronic votes mysteriously vanish in Ohio election 

 Microsoft Issues Advice on Internet Explorer Zero-Day Attacks 

 Court Freezes Assets of Alleged 'Scareware' Purveyors 

 Face-recognition tool nabs ID theft suspect 

 Daft list names Firefox, Adobe and VMWare as top threats 

 Software Locates People And Objects 

 New trojan in mass DNS hijack 


 Ministers hit by two new security fiascos 

 Fraudsters get into the Cloud 

 Trojan Horse steals 500,000 bank, credit card log-ons 
 Undetectable data-stealing trojan nabs 500,000 virtual wallets 
 Virtual Heist Nets 500,000+ Bank, Credit Accounts 

 Buzz of the Week: Vote early, Vote Often 
 E-voting fears run high as election day looms 
 Rigged e-Voting machine snacks on Homer Simpson 

 Spammers Target Google Blogspot and Apple MobileMe 

 Web Security Firm warns of Obfuscated Code 

 Crooks can make $5M a year shilling fake security software 

 Java Update Promises to Remove Older Versions 

 McAfee suspects fingered for $3.8m fraud 

 Copyright infringement and the CISSP, Part 1 
 Copyright infringement and the CISSP, Part 2 

 Microsoft warns of another update to Windows Update 

 Inspector general knocks HIPAA security oversight 

 IBM's Latest Answer to Online Banking Security 

 Nigeria antifraud agency to unplug Internet at homes 

 Android phone users get update for flaw 

 Immature tech likely to get lucky in credit crunch 

 Army OKs network security tool 

 Are design issues to blame for vote 'flipping' in touch-screen machines? 

 Agencies miss HSPD-12 target 


This is not related to computer security, but we thought
many of our readers would enjoy this interesting story . . .
   University researchers developing cancer-fighting beer 


 Security hole in Google Android G1 Phone 

 How DNS cache poisoning works 

 Google reports itself for aiding and abetting malware 

 New federal ID cards easily cloned, study says 

 Data-Stealing Trojan Exploiting Just-Patched Windows Flaw 
 Trojan attacks Microsoft's emergency patch vulnerability 
 (see "Critical Microsoft Windows Update", below)

 Hybrid Memory Solves Key Problem For Quantum Computing 

 New law brings 911 services into Internet Age 

 Cyberoam:  Spammers hijack legitimate e-mail 

 DHS rule could make IT items harder to import 

 Feds raid Miley Cyrus hack suspect 

 Hackers Steal Money From French President Sarkozy's Bank Account 

 Click fraud at 16 percent as scammers resort to botnets 

 Ohio elections website hacked as vote scuffle gets ugly 

 FBI, FTC Take Down Scammers & Spammers 

 High-tech bank robbers phone it in 


Critical Microsoft Windows Update:  23 OCT.08

 Microsoft to Issue Emergency Security Update Today 

 Attack code for critical Microsoft bug surfaces 

 Microsoft releases emergency Windows patch 

 Microsoft's urgent security update: What it means 

 Microsoft Security Bulletin MS08-067 – Critical 

 NOTE that there have been several reports indicating that
 Windows Automatic Update Service does not find this critical
 update. We urge you to visit the Windows Update site manually
 to verify that the update is installed on your computer.


 Use Gmail, Go to Jail? 

 McAfee antes up against cybercrime 

 Student gets jail for crashing university servers 

 Google patches Chrome 'carpet bomb' bug 

 Secure Flight to take off next year 

 Ohio searches for state-site attacker 

 Battelle develops new technology for port security 

 A team effort against ID theft 

 Locals leave SSNs unprotected 

 Air Force seeks input on defending cyberspace 

 U.S. government bolsters efforts to fight ID theft, report says 


 'Experimental' security fix is Malware, Microsoft says 

 H-1B process plagued by fraud, Grassley says 

 Phishers, Virus Writers Exploit Global Financial Crisis 

 World Bank servers breached repeatedly 
 World Bank denies hackers pwned key systems 

 Lawmaker's son indicted for Palin e-mail hack 

 Visitor driver's license applicants must show U.S. approval 

 Turbo-charged wireless hacks threaten networks 

 Spammers Favor Obama Over McCain 7 to 1 

 Data mining for terrorists is an exercise in futility 

 Organized crime tampers with European card swipe devices 

 NSA spied on US aid workers, officers, and journalists in Baghdad 

 Clickjacking Attack Lets Web Sites See, Hear You 

 Apple Releases Mega Patch Security Update 

 U.S. Brain Trust: Beware of trawling-for-terrorist apps 

 Exploit code loose for six-month-old Windows bug 

 Spam Volumes Plummet After Atrivo Shutdown 


 Researcher finds evidence of massive site compromise 
 Hackers exploit Neosploit to booby trap BBC, US postal service 

 Administrator admits stealing Navy computers 

 TCP flaws allow deadly DoS attacks 
 Vendors rush to fix bug that could crash Internet systems 

 Beware of hotel Internet connections 

 Spam Swine break Next-Gen CAPTCHAs 

 The IT worker's Wall Street meltdown worry list 

 Air Force seeks cyber engineering assistance 

 Blaming the Good Samaritan 

 Frustrated researcher details iPhone security bugs 

 Second bill tackles laptop border searches 

 Laptop stolen from McCain campaign in Missouri 

 Nasty web bug descends on world's most popular sites 

 DHS: President’s Cyber Initiative paying off 

 Hackers penetrate South Korean missile manufacturer 

 Stealthy malware expands rootkit repertoire 

 Report claims surveillance of Chinese messaging 
 Chinese Skype spies on users, researcher says 

 Blocking Traffic by Country on Production Networks 

 FAQ: Clickjacking -- should you be worried? 

 Bastard Gator child dies sudden death 


 Cisco releases bundle of router security patches 

 Unlocking the national cybersecurity initiative 

 Net sleuths spot poker site cheat code 

 Fake Facebook 'Add Friends' E-Mail Adds Malware 

 U.S., China lead world in botnet attacks 

 Mozilla patches 11 bugs in Firefox 

 Sarah Palin E-Mail Hacker Tied To Tennessee Democrat 
 Grand jury fails to level charges in Palin hack case 
 Net proxy may pinpoint Palin email hackers 

 Positive Security: Worth The Work? 

 'Malware-friendly' Intercage back among the living 
 Internet Shuns U.S. Based ISP Amid Fraud, Abuse Allegations 

 Buzz of the Week: Security on the mind 

 Securing the world against terrorists, scammers, and thugs 

 Two-thirds of firms hit by cybercrime 

 Microsoft to drop support for Office 2003 SP2 

 Miracle airship tech sustained by DARPA pork trickle 

 Senate Panel Approves Cyber-security Bills 

 Fake Popup Warnings Fool Internet Users Even After Repeated Mistakes 

 Anatomy of a malware scam 

 Second hacker in TJX case pleads guilty 


 Covert operation floats network-sniffing balloon 

 Facebook Tries To Exterminate Worm 

 Editorial:   Encouraging mediocrity 

 Online Crime Gang Stole Millions 
 Russian Hacker Gang Steals with Impunity, says Researcher 

 Microsoft Plans 12 Security Fixes For Aug. 12 'Patch Tuesday' 

 Beckstrom on cybersecurity 

 Kaminsky: Many ways to attack with DNS 

 Fake-CNN spam mutates as attacks continue 

 Protect your crypto key from the cold 

 Al-Qaida said to lose key WMD operative 

 Homeland Security Authorizes Laptop Searches At U.S. Borders 
 DHS can search, seize electronics from travelers 

 DOJ fingers global ring in alleged data thefts 

 New Tool to Automate Cookie Stealing from Gmail, Others 

 Massachusetts Transit Authority sues to silence undergrads 
 Massachusetts transit agency sues to stop hacker talk 

 New exploit poisons patched DNS servers, claims researcher 

 Wireless Awareness: Don't Be A Sheep 

 Google Gadgets an Open Door for Attack 

 IT security oversight may have enabled data breach 

 Missing laptop found, but security questions remain 

 Lawsuits can be an expensive IT threat 

 Researchers Warn of Social Networking Scams 

 Researcher: Intel fixed two critical flaws in its chips 

 SQL attacks inject government sites in US, UK 

 Unblinking Eye 


 WabiSabiLabi Co-Founder Arrested 

 China spying 'biggest US threat' 

 Spy charges for US computer duo 

 Apple Releases Godzilla-Sized Security Patch 

 U.S. girds for battle with computer 'botnets' 

 Many Retailers Easy to Hack, Study Finds 

 Did NSA Put a Secret Backdoor in New Encryption Standard? 

 DoubleClick Serves Up Vast Malware Blitz 
NOTE:  If you have a good HOSTS file, you're not at risk.

 Most Malware Made in China 

 Is the Chinese government infecting us with malware? 

 Chinese Fraudsters Fake Drug Watchdog Web Site 

Developers, here's a multi-platform tool that can
help you create better quality & more secure code.



Visit our Computer Security News Archive for links to previously listed articles and resources.


Security Events and Training

 AVS 52nd International Symposium & Exhibition 
(biomaterials, energy, nanoelectronics, more)

 Next Generation Networks 
(NGN covers security issues and much more)

 Network Security Conference 
(this is a "must" for IT professionals)

 Understanding and Applying Machine Vision 
(automation, robotics, security-applicable)


Newsletters, Subscriptions and Whitepapers

 Securing Wireless LANs with PEAP and Passwords 

 Subscribe to free (and not free) electronic journals 

 Subscribe to Site Updates at stevethornburg.com 

 For IT Professionals:   "Information Security" 

 Wi-Fi HotSpot Security Guide  from it-goodinfo.com

 
Many more . . . (coming soon)
 Security Resources
Hardware
  Targus Security Accessories 
  Microsoft Fingerprint Reader 
  High Voltage Security Briefcase 
  Security Cameras and Equipment 
  Security Cameras and Equipment 
  Data Backup, Disaster Recovery 

  more Hardware Security info 
Software for Windows
  Microsoft Security Home 
  Microsoft AntiSpyware 
  Microsoft Windows Update 
  Microsoft Office Update 
  Computer Security and Software Resources 
  Windows™ XP Security Guide  from Microsoft

  more Software Security info 

Online Resources
There are a number of useful resources available at the following internet sites...
  Check your online bandwidth - download and upload speed measurement 
  Check visibility of your computer's internal IP address 
  Choose from a rated list of free pop-up blockers 


Certifications

  Certification Hub: Study Test Questions with Answers 
  Check Point Certified Security Administrator 
  Cisco Certified Security Professional 
  ExamForce Security Certification Exam Preparation products 
  Microsoft Learning Security Resources 
  SANS Computer Security Training, Certification and Research 


 
 Focus on Security
Network Honeypots are Affordable Intrusion Detection and Prevention Systems
Network "honeypots" provide an affordable effective method to detect and/or prevent intruders from penetrating your network.  Put simply, a honeypot, or honeynet, is a system attached to your network that allows easy access to attackers.  However, because there is nothing of any tangible value there, you are not jeopardizing your "real" networked assets.  Regardless of whether an attack is being done manually, via automated netbots, worm code, or some combination of methods, the honeypot gives the attacker a sweet taste of success - sort of.  What the attacker sees as success is actually a trap, allowing you to examine their methods and gather evidence against them.  It is beyond the scope of this site to present a detailed report about honeypots, but below are links to pages that have already done that work, with details of how to install and configure a network honeypot. You can find free software and all the details you need to get up and running with a powerful intrusion prevention system.  And in case you are wondering, the degree of protection offered by a honeypot goes way beyond the protection offered by a mere firewall - the best of which are still penetrable under attack by a skilled cracker.

  •   Basic description of a Honeypot

  •   Honeypots have been around for a while (article, November 2003)

  •   Many believe that Prevention is Better than Cure


  •     Honeypot software  such as Honeywall, Sebek, Snort and more.
        Honeyd  is a virtual honeypot.
        Setup instructions  for a Honeyd virtual honeypot.
        networkintrusion.uk.co  offers information and resources.
        Intrusion detection and prevention learning guide   ← Excellent resource!
        Layered Approach to Security in the Network Perimeter   (a PDF document from Juniper Networks)
        Honeypots Revealed  from SecurityDocs.com
        Strategies & Issues  Honeypots - Sticking It to Hackers
        Symantec  Enterprise Security article
        Catch malicious network activity  with a Honeyd virtual Honeypot
        Honeypots  The sweet spot in network security
        Ways of Building Honeypots  from Clarkson University
        Honeypots work  but Raise Legal Questions.
        Honeypot FAQ  (be sure to have a pop-up blocker, and don't look at the banners!)

    Related:  Firewalls
    For those of you who are serious about security, check out Endian Firewall.  Endian Firewall is a linux security distribution that turns a computer into a full-featured security appliance.  Remember, a byte of prevention is worth 9.0949470177283729 terabytes of cure (1 terabyte = 1,099,511,627,776 bytes).


     
     Robotics News
    As technology continues to move forward, we will see an ever stronger presence of robotics in security applications.  To some degree, this trend is clearly visible in the military.  We already have numerous robotic assistants in the field, used to help locate and neutralize roadside bombs, for example.  To a lesser degree we have a small deployment of robotic weapons, even though numerous systems are available.  As time moves forward we will see more and more robotic systems, both defensive and offensive, in the military arena.  But before that time, we will see a multitude of robotic assistants available for home and commercial use.  In the interest of robotics awareness, I will post links here to various articles regarding all aspects of robotics, especially if applicable to security.  From time to time, I will post links to articles regarding weapons development.  Over time, I believe we will see a rapid convergence of robotics and weapons systems, thus helping make the world a safer place.  In practical application, terrorists and would-be terrorists will likely be among the first targets of these highly efficient and lethal systems.

    The DARPA Grand Challenge
    The DARPA Grand Challenge is a competition for robotic vehicles that is sponsored by the Defense Advanced Research Projects Agency (DARPA).  There is a great deal of research, and a great deal of learning, as a result of these annual events.
      CMU's Tartan Racing Wins Urban Challenge
      DARPA Urban Challenge winners
      DARPA Grand Challenge

    Robotics in Security
      Two robotics firms merge for security Apps 
      Self-replicating Robots demonstrated at Cornell 
    General Robotics News
      MSU developing robotic arm capable of doing breast exams 
      Robots to Replace Child Camel Jockeys 


     Military, Weapons and More . . .
      Air Force tunes nonlethal directed-energy weapons 
      Idaho National Laboratory receives second round of funding for cyber threat reduction program 

     
     Subscribe to our newsletter, send us your comments or suggestions...
    Subscribe to our Newsletter

     Subscribe to our newsletter here:  Subscribe 
    Cancel Subscription

     Cancel an existing subscription here:  Cancel 

     Send us your comments, complaints, suggestions or enthusiastic praise:  Comments and Suggestions 



     Check your system security  here 
     (sorry, temporarily disabled)


     Home   Basic Security   eMail Security   Entertainment   Imagery   Music   Site Map   Subscriptions   Technology   XP Users 

     (above links take you to areas at  stevethornburg.com)