Tuesday, December 15, 2009

WARNING: Acrobat Reader Exploit…TURN OFF JAVASCRIPT NOW!

Malicious hackers are exploiting a zero-day (unpatched) vulnerability in Adobe’s ever-present PDF Reader/Acrobat software to hijack data from compromised computers.

According to an advisory from Adobe, the critical vulnerability exists in Adobe Reader and Acrobat 9.2 and earlier versions.  It is being exploited in the wild.

The company has activated its security response process but declined to offer any more details until an investigation is complete.

Unfortunately, the company did not provide any mitigation guidance for customers.

The folks at ShadowServer describe the situation as “very bad.”

We did not discover this vulnerability but have received multiple reports of this issue and have examined multiple different copies of malicious PDFs that exploit this issue. This is legit and is very bad.

Here’s what we know so far:

We can tell you that this exploit is in the wild and is actively being used by attackers and has been in the wild since at least December 11, 2009. However, the number of attacks are limited and most likely targeted in nature. Expect the exploit to become more wide spread in the next few weeks and unfortunately potentially become fully public within the same timeframe. We are fully aware of all the details related to the exploit but do not plan to publish them for a few reasons:

  1. There currently is no patch or update available that completely protects against this exploit.
  2. There is little to no detection of these malicious PDF files from most of the major Antivirus vendors.

With that said we can tell you that this vulnerability is actually in a JavaScript function within Adobe Acrobat [Reader] itself. Furthermore the vulnerable JavaScript is obfuscated inside a zlib stream making universal detection and intrusion detection signatures much more difficult.

In the interim, Adobe PDF Reader/Acrobat users are urged to immediately disable JavaScript:

Click: Edit -> Preferences -> JavaScript and uncheck Enable Acrobat JavaScript

Or, better yet, use an alternative PDF Reader software program.

Monday, December 14, 2009

How to Setup and Configure OpenDNS

I’ve written about using OpenDNS in past post (and other blogs), but I’ve never really sat down and given step by steps on how and why to configure this free service.

First I’ll start with the “why”…WARNING…A little “GEEK” info coming at you:

When you type an address like www.yahoo.com in your browser address bar, the computer doesn’t know where yahoo.com points to and it will therefore ask the DNS server.

The job of a DNS server is to translate this human-readable web address (like www.yahoo.com) into a computer-readable number also known as an IP address (209.131.36.158). Once your computer knows the IP location of a web domain name, it opens the website in your browser.

DNS is such an integral part of our Internet life working behind the scenes every time we connect to a website. In most situations, our Internet Service Provider specifies the DNS Server address that we key into the browser network settings or the router.

Unfortunately, this can prove to be the weakest link in protecting our families.

The honest bottom line is that there's no way to absolutely, positively block porn, or anything else for that matter. You can make it more difficult, and maybe that's enough, but for every approach we might consider taking there will be ways to circumvent it.

So with that out of the way, let's block some porn...

You Are The ISP

The approach is actually quite simple: when a computer connects to your network at boot time, it asks your router for an IP address. Along with that IP address the router also provides the IP addresses that should be used for DNS lookups (the lookups that translate human readable "google.com" into what your computer really uses to connect: 74.125.19.104.).

OpenDNS

  1. You’ll need to go to www.opendns.com 
  2. Write Down “Your IP:” in upper right, and click “Create Account”.image
  3. Select your DNS Source (normally the Router option).image
  4. Choose your Router Brand…if you don’t see your router brand, select the “general router instructions” link. image
  5. Follow the instructions for configuring your router.
  6. After you Finish the configuration settings, you’ll be directed to your “Dashboard”.  You’ll be promoted to enter your IP address (remember the number you wrote down on step 1?). If you have a dynamic IP (one that rotates every couple of days), then use the “client-side software” and follow the configuration wizard.

The Dashboard is you MAIN interface with OpenDNS.  From here you can customize which filters you want to use, custom error messages and look at the websites that are being blocked as well as the most popular site requested.

image

You can use the pre-built settings (High, Moderate, Low, Minimal or Custom).  I personally use custom so I can block all social networking, but I can put in an exception for Facebook.com

image

(Note: fbcdn.net is part of www.facebook.com)

With these settings any computer/device that connects to the internet through this router would use OpenDNS's service.

So what happens if your IP address changes?

This is a very common scenario for consumer internet connections, and is called "dynamic IP addressing". One day your internet connection might be on one IP address, and another day it might change. This is totally normal, and is controlled by your ISP.

You can update your IP address with OpenDNS manually, of course. However, OpenDNS does make available a small program which will automatically update OpenDNS's record of your IP address when it changes. You only need to install it on one machine - yours. Once OpenDNS understands that the internet IP address has changed for your account, its features are applied to all computers accessing sites through that connection.

With a little “tweaking” you can even add your own error messages. image

I like my kids to know that they’re being monitored…just like the corporate world, when users know someone’s monitoring, web traffic to inappropriate sites drops dramatically. ;-)

One final caveat: what we've been talking about is web access. OpenDNS doesn't filter incoming email, so any porn spam you might be getting will continue, but the links to those site should be blocked. You'll need to investigate spam filtering solutions for that, and those are likely not things you'll be able to implement without impacting the computers involved.

I’m OUT!

-SuperDale

Monday, December 7, 2009

Facebook Users…Still giving out too much personal info.

I came across an article about how bad ID theft on Facebook is getting….yeah…..it’s worse.  Please read this article and WATCH the video!  Then educate your family and friends.

"According to Sophos, Facebook users are getting sloppier with their personal info, not better. Revisiting a 2007 survey in which a plastic frog got 87 hits out of 200 friend requests, this time a rubber duck and a cat got 87 out of 200 friend requests, plus a bonus 8 friends who decided to trust them anyway. The research also suggests that older Facebook users are sloppier than the young, being keener to build their list of friends. (The older users had more than 4x the friends each, on average, than the young.)"

http://www.sophos.com/blogs/duck/g/2009/12/06/facebook-id-probe-2009/

-SuperDale

Friday, December 4, 2009

Great Googly-Moogly

So Google just released “Public-DNS” (it’s still in beta). Configuring your DNS to point to Google should give you faster access. If you know DNS and you think about what Google does…their DNS cache/database is got to be huge…which should make things faster/more secure.

http://code.google.com/speed/public-dns/

Give it a try!

I’m OUT!

-SuperDale

Thursday, September 24, 2009

Twitter WARNING!

OK folks…I knew it was coming…PLEASE for the safety of your identity and your family safety…review this article about the latest scam.

http://www.f-secure.com/weblog/archives/00001773.html

-Dale

Tuesday, May 26, 2009

50 Top Text Acronyms you should be aware of...

Here's a link to some acronyms that kids are using today...WARNING..some of these are descriptive!

http://www.myfoxatlanta.com/dpp/news/fox_5_links/Top_50_Text_Acronyms_Parents_Should_Know_052009

-SuperDale

Friday, May 15, 2009

Holy Swap-File, Batman!

One method of increasing your system performance and increasing your security, is to…(are you a ready for this one!)…delete the Swap-File (also known as the PageFile).  Now I’m not saying to permanently remove the swap-file, that would be VERY bad…but rather remove it as the computer shuts down and recreate it as the computer reboots… WHY? you ask.. couple of reasons.

  1. Sensitive information may have been temporarily stored in the virtual memory pagefile. For this security reason and others, it may be a good idea to enable this setting to clear the virtual memory pagefile occasionally or when you suspect this. When this setting is enabled it will clear the virtual memory pagefile, and the hibernation file only on a portable computer, when you restart or shutdown the computer.
  2. If you leave the file in place…over time it get “fragmented”, which makes the system work harder to find the files it needs…by deleting it, and restarting the computer, a NEW and IMPROVED swap file is created, which is not fragmented.

So how do you do this?….It’s a little “Geeky”, but here you go:

WARNING: THIS METHOD ONLY WORKS ON VISTA ENTERPRISE, BUSINESS, AND ULTIMATE…for Vista Home and Preium, look towards the bottom of this article for section 2.

Section 1)

Open the Local Group Policy Editor.
2. In the left pane, click on Computer Configuration, Windows Settings, Security Settings, Local Policies, and Security Options. (See screenshot below)

image
3. In the right pane, right click on Shutdown: Clear virtual memory pagefile and click on Properties.
4. To Enable Clear Paging File at Shutdown -
A) Select (dot) Enabled and click on OK. (See screenshot below step 5A)
B) Go to step 6.
5. To Disable Clear Paging File at Shutdown -
A) Select (dot) Disabled and click on OK.
image
6. Close Local Group Policy Editor window. Your done.
7. If you enabled this setting, then restart or shutdown the computer to clear the Virtual Memory Paging File.

 

Section 2)

1. To Disable Clear Paging File at Shutdown -
A) Click on the download link below to download the
Disable_Clear_Page_File.reg file.
B) Go to step 3.
2. To Enable Clear Paging File at Shutdown -

A) Click on the download button below to download the
Enable_Clear_Page_File.reg file.


3. Click on Save, and save the .reg file to the Desktop.
4. Right click the .reg (On Desktop) file and click on Merge.
5. Click on the Run button for Security Warning pop-up.
6. Click on Continue (UAC), Yes, and then OK when prompted.
7. When done, you can delete the .reg file (On Desktop).
8. If you enabled this setting, then restart or shutdown the computer to clear the Virtual Memory Paging File.

-SuperDale (http://myfamilysafety.blogspot.com)

(Note: I’m not responsible for any issues that these files may or may not cause…there’s my disclaimer)