Senin, 17 Desember 2012

Password Legacy.


Bruce Wayne, the millionaire rich become poor overnight and lost all his money, all this happened because fingerprinted successfully stolen and used to conduct derivatives transactions on the stock exchange Gotham. At least from the story above we can see the importance of authentication and dangerous if it falls into the wrong hands. Authentication is a way to identify a person in the absence of face-to-face and the very rapid development of the world's demand efficiency and one of the tools to achieve efficiency is the internet and technology. Where wherever you are, with the help of the internet and technology supporting you will always be connected with the services that you use the service. Such as banking services either ATM or mobile banking, telephone (VoIP), email, Facebook or other services. One of the methods most often used for authentication is a username and password, because this method is among the most inexpensive, easy and most extensive coverage and does not require a program or a special tool. Indeed, there are more sophisticated methods such as TFA (Two Factor Authentication) that uses an additional token / calculator password to increase security especially important and critical transactions. However, because of the special equipment is needed cause TFA application fee be higher than conventional passwords so far with password authentication is the most popular method used.


Brute Force and Captcha


At the beginning of the application credentials where service users only need to enter the Username and Password, this method is successfully used to identify the users of the service. But in line with the development of the internet and the high added value of a service account, there is a lot of effort to get another person's account incorrectly. One of the methods most commonly used are Brute Force. Brute Force is an attempt to guess the password of the account in a way tried out all possible passwords massive and repetitive. In theory, as well as any password you use when in Brute Force, sooner or later one day MUST be successful in getting. The key is on the complexity of the password (a combination of letters, numbers, and long kharakter password) and how the resources are used. Therefore, the service providers to rack my brain to deal with a brute force attack is because it is the absence of face-to-face, anyone who knows a legitimate credentials (username and password) will be directly received and considered the owner of the account in question. One method used is to limit the maximum number of password trial, where if there is a mistake in entering a password or PIN in a certain amount then the chance to try out would be limited. If you do not believe please enter the wrong PIN more than 3 times on your ATM card, that card will undoubtedly be on the block and not be able to trade before re-verification. To improve the protection of your account, security practitioners to rack my brain to find a method of how to distinguish between bots (automated programs password stealer) with humans. Currently, a very popular method is the Captcha. CAPTCHA actually stands for Completely Automated Public Turing test to tell Computers and Humans Apart is basically a method to identify and distinguish human to human. The most commonly used method is the display letters or numbers on the stack in such a way that it can be read by the human eye but can be hard on the read or scanned by a program / bot. And because it proved to be quite effective, Captcha is now the standard of protection either at the first open an account or service at the time of authentication. Captcha addition, some owners use the services of additional methods such as "Sign-in seal" (Yahoo) and Google began to start applying TFA Google account by verifying sending one time password via SMS to the mobile number that you specify "every time" you access Google account from a new device. Most likely the goal is to prevent illegal access to your account if the password is successfully stolen, because the accessor must not access from your device but from the device / computer different.


In addition to the threat of brute force, the owner of the account is also haunted by trojan attack which if successfully implanted on the victim's computer will be able to record keystroke. So anything that is typed by the computer which will be known by a trojan program and usually this information will be sent secretly to the trojan makers. Another method that is often used by criminals in an attempt to get credentials is using fake websites (phishing) that looks very similar to the original site, and if the victim deceived into thinking he was in the original site and enter the credentials, the credential information will fall into the hands of criminals. Seeing the possibilities above, would the author do not necessarily recommend you to fast internet access and no significant transactions over the internet. At this time it is very difficult and inefficient if not using the internet for help with daily activities. We can not get away from email, Facebook, Twitter, bank accounts, Skype, Instagram or ATM, and all this requires credentials. The most important thing is how to build and protect your credentials as well as in case the worst happens we want.


KeePass Password Safe

One of the most common problems faced by owners of credentials is the large number of different accounts he has. If every account he would have to remember different credentials, what often happens is a silly thing, like a song sung by the cemetery, but in this case it is forgotten not forgotten his verse, but forgot the password. Where the account holder is protected by himself and can not access the account because forgot the password. Moreover, a lot of advice from security analysts who advise the owner of the account change their password on a regular basis, the more confused again .... Which account password yah? Therefore, many owners choose a password shortcut by using the same password for all accounts. This could be catastrophic for the same password will be used to access all your accounts. The author never had a complaint from Facebook users whose accounts have been successful in stealing the people and to restore his account need to access your account reset code in his Yahoo account. But because he used the same password for your Yahoo mails, he did not have access to it and eventually forced to create a new Facebook account.


The virtual world has many problems, but the virtual world also provides a solution to the problem. One solution that is effective and safe way to deal with this problem is a Password Manager program. The program is pretty widely available, both commercial version and a free version. Writers on this occasion will introduce a free open source program but it is reliable and safe to manage a collection of your credentials.
KeePass Password Safe is a password management program that works to keep all your credentials securely so you do not need to remember all the passwords and only need to remember one master password. To increase security, in addition to using a master password to access your KeePass password database is also equipped with AES encryption, Rijdael and Twofish so that even if the data file passwords fall into the hands of others, it would be very difficult for the inventor to open the file. In addition to the security features of a powerful and convenience to not have to remember passwords, KeePass can also provide additional protection because you do not have to type in your Username and Password but only need to do the [Copy] and [Paste] from KeePass. KeePass program can be downloaded from http://keepass.info/download.html and although the official version is only available for Windows users, available ports to use the same KeePass database on Iphone / Ipad, Android, Blackberry, Windows 7 and Palm.

Source : http://www.vaksin.com/, September 3, 2012.

Sabtu, 15 Desember 2012

Online malware Kaleidoscope 2012.


Despite the tendency to spread malware in 2012 has spread to new platforms such as OS and Android are experiencing an increase in the addition of the highest malware and beat OS Windows (although the total number of malware on Windows OS is still the most) and the advent of malware attacks targeting Facebook users as the number of users is more than 1 billion. Although Facebook help you find your old friends, but once familiar with Facebook ("friend" later) you do not forget there are two "friends" of old is no less powerful than Facebook, the first is your mailbox in 2012 is estimated at 3.3 billion mailboxes and no less great is the number of internet sites that Google Index reached more than 40 billion pages. (See figure 1)

Figure 1, the size of the Internet from the number of pages in Google's index

If in the world economic arena, the strength of America is still the number one in the world followed by China, Japan and Germany. And of the total number of China's Internet users, ranking first defeat America. However, the incidence of malware that infects websites position slightly shifted where America still ranks first with an infection rate of 42.03%, followed by Germany at position 2 with an infection rate of 7.3%, and China ranked third with 5.84% infection rate . But the 4-position is occupied by the Japanese economy turns taken by the Russians with an infection rate of 5.79% indicates that although the Russian economy ranks only 11 (UN version) but it seems criminal to site problems this country has more capabilities and be able to pass economic ranking . Interestingly, these sites are infected with malware Japan ranks was only 19. If the cause is due to see the language does not seem to matter as well as China and Korea who have a language with kanji still ranks high. Is it because of the implementation of security on sites in Japan are better than other countries, it is becoming an interesting phenomenon to study. (See figure 2)

http://vaksin.com/2012/1212/online%20malware/online%20malware%202012_html_m20341acb.gif
Figure 2, the percentage of infected websites malicious code based on national origin.


If the internet site security management in Japan deserves thumbs up and follow, and what about Indonesia? For that we need to compare with other countries in Southeast Asia. (See table 2)
Table 2, the number of web pages infected with malware and Internet users in Southeast Asia, data www.internetworldstats.com


Anomalies in the number of sites infected with malicious code as happened in Russia and Japan in the world seems to occur also in Asean. Indonesia, which has the largest Internet user turned out as many as 55 million sites in Indonesia are plagued by malware penduduki only ranked 38th in the world with a percentage of 11.93% of the total infection infections or malware in Asean ranks third in Asean. Ranked first in Asean is not occupied by Filipinos but by Vietnam that records the number of sites infected with 5884 or 34.54% of the total infections in ASEAN and peaked at number 23 in the world ranking 3rd followed by Thailand which ranked 26th with a percentage of the world's infected sites by 30 , 05% as ASEAN or the number of infections by 5118 website. While the Philippines has a population of Internet users number 2 in Asean after Indonesia was only ranks 6 below Indonesia, Singapore and Malaysia with a total of only 410 sites infected sites or 2.41% of the total infected site in Asean or 63 world ranking. Singapore and Malaysia respectively ranks 4 and 5 with a percentage of 11.67% rank infection and 9.14% or the 39 and 44 world ranking. To get an idea of ​​nasty malware that infects pages in Asean and pie charts, please refer to Figure 3 below:

Figure 3, Figure cakes percentage of malicious code that infects site in Asean


Any site that terinfeks and what type of infection?
If you are curious about what kind of malware that infect these sites and any site that in infection. According to observations Vaksincom generally malware that infects the umumnyadi domination by Trojan, Backdoor, Script, PHP Framer and malware. But there is a dangerous malware that infects html file and found to infect many sites in Indonesia, none other than the Ramnit.
The agency / firm malware infected very broad scope, from private companies, educational institutions (high school, university), large enterprises (conglomerates), government to mining companies that have the funds and resources mumpunipun not escape this malware infection. See figure 4 and 5.

Figure 4, one of the departments of the infected sites were detected Ramnit G Data Total Protection with Web technologies Protection
 

Figure 5, the world's departments Ramnit infected and trying to inject "svchost.exe" to the victim computer using VBScript.

Source : http://vaksin.com/, Desember 4, 2012.

Selasa, 11 Desember 2012

How to Detect Fake Follower on Twitter ?

 

The phenomenon of fake followers on Twitter is not a secret anymore. That said, there are even services "purchase" for those concerned follower.Well, for Twitter users who want to know how many followers they were "real", not active, or false, now the company has been providing media analysis Socialbakers named Fakefollowers services that can help.How to use it easily. Twitter account owner Fakefollowers simply visit the site and type in your account name, then click on the "check". Before that, the user can choose whether you want to follow on Twitter Socialbakers account or not by checking the box at the bottom.Having given permission to the user account Fakefollowers to follow, follower stats will be displayed. Here it can be seen how much of a false or empty, inactive, or "good" (actually an active Twitter user).According to Socialbakers, if a user has a false follower of 20 percent or less, then the user account that can be said to be trusted and nothing to worry about.


Users who have numbers between 20-50 percent false follower suggested that "be careful". But that percentage may increase as a result of the number of followers that a lot.If this figure is penetrating 70 percent, most likely the account has become a victim of cybercrime.How to identify a follower Socialbakers fake? There are several criteria, among others:
  1. Comparison between accounts that followed (Following) and follow (follower) of less than 50:1
  2. Posted to tweet contained the words spam smelling like about diet or a lot of money by working from home
  3. Post tweet repeated more than three times
  4. More than 90 percent of posting a tweet retweet
  5. More than 90 percent of the tweets include a link and the account has a comparative account connexion followed (Following) and follow (follower) of 7:1 or more
  6. Account in question never posted tweet
Users can use the services Fakefollowers 10 times in one day. Twitter user accounts identified his followers could belong to anyone. This means that users can know things like how many fake followers to follow your favorite celebrity or business rivals.


Socialbakers own Twitter account has 23,000 followers. Only 4 percent of them are fake or inactive accounts. Want to try it? Visit FakeFollowers features on the site SocialBaker. 
Author : Oik Yusuf
Editor: Surya Hidayat Wicaksono
Source : http://tekno.kompas.com/, Tuesday, December 11, 2012, 7:45 pm