Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

Friday, May 5, 2023

Here's something you never want to see: intruder alert, intruder alert. So catch it before it's too late!

Great news coming out of IES today. We are now taking preorders for the IES HoneyPot. Now you can setup a "sting" operation 24/7 on your network, often alerting you - and us - of an issue before it becomes a real problem.

What is a honeypot you ask? "It's a sacrificial computer system that’s intended to attract cyberattacks, like a decoy. It mimics a target for hackers, and uses their intrusion attempts to gain information about cyber criminals and the way they are operating or to distract them from other targets".

Despite the compact size of our honeypot device, it looks like a real computer system to hackers - with applications and data, fooling cyber criminals into thinking it's a legitimate target. For example, a honeypot could mimic a company's customer billing system, a frequent target of attack for criminals who want to find credit card numbers. Once the hackers are in, they can be tracked, and their behavior assessed for clues on how to make the real network more secure.

It is important to note that a honeypot isn't set up to address a specific problem, like a firewall or anti-virus software. Nor is it meant to replace these network necessities. Instead, it's an information tool that can help you understand existing threats to your business and spot the emergence of new threats. With the intelligence obtained from a honeypot, security efforts can be prioritized and focused.

WE ARE GIVING THESE DEVICES AWAY for a limited time to any of our clients that are interested. We just ask that you cover the annual subscription fee of $365...yes, just $1 per day. Contact us today (781-816-9437 or contactus@iesadvisors.com) to learn more about our devices and see how they can help add a layer of security to your network. Since the devices are plug and play, we can ship it right to your location. Simply plug it into power & Ethernet so IES can do the rest!



Friday, February 20, 2015

Lenovo in hot water after shipping laptops with malware pre-installed.

Computer maker Lenovo has been shipping laptops pre-packaged with malware that makes you more vulnerable to hackers - all for the sake of serving you advertisements.

Made by a company called Superfish, the software is essentially an Internet browser add-on that injects ads onto websites you visit.

Besides taking up space in your Lenovo computer, the add-on is also dangerous because it undermines basic computer security protocols.

That’s because it tampers with a widely used system of official website certificates. That makes it hard for your computer to recognize a fake bank website, for instance.

Customers started spotting this on their Lenovo computers in mid 2014.

After facing a fierce backlash by customers and computer security experts this week, Lenovo acknowledged that "user feedback was not positive." As of January, Lenovo has stopped pre-loading the software on new computers, a company spokesman said. Lenovo also promised it "will not pre-load this software in the future" and said it disabled the feature on its servers, which essentially kills the program on everyone’s computer.

Source: Yahoo Tech

Wednesday, August 7, 2013

Do you save passwords in Google Chrome? Maybe you should reconsider...

You might want to think twice before you let someone borrow your computer.

The most obvious risk of allowing someone else access to your desktop is that they can impersonate you, using any app where you’re already signed in. They could send prank messages using your default email client, or profess your undying love for Justin Bieber using your logged-in Twitter account.

That’s annoying, but far from fatal.

But the situation becomes considerably worse if you use Google Chrome to save and sync passwords for easy logins at your favorite websites. An intruder who has unrestricted access to your computer for even a minute can view and copy all of your saved passwords just by visiting an easy-to-remember settings page: chrome://settings/passwords.

That link opens the local copy of your saved password cache, which is synchronized to every machine where you sign in with your Google account.

And the funny thing is, anyone who visits that page can see the plaintext version of every saved password just by clicking a button.

The saved password list shows the web address, username, and password for each saved set of credentials. Initially, the saved password is displayed as a row of asterisks. But if you click the masked password, you see a “Show” button that you can click to immediately display the saved password.

A malicious or spiteful intruder who can lure you away from your computer briefly can see your saved passwords, then close the settings page. And you have no idea that your credentials have been compromised.

Source: ZD Net