Oracle of ONE1

Obscure words of unity

Firefox Keywords and Domain Guessing

I use Firefox regularly and am quite happy with its feature set and extensibility. There are a few options that I change to enhance my experience and security. These are:

  1. Domain guessing
  2. Internet keywords
  3. Keyworded bookmarks

I turn off Domain guessing and Internet keywords; and instead use Keyworded bookmarks extensively. Accessing two of these settings requires entering about:config in the address bar. This provides direct access to Firefox’s configuration settings but is not recommended for novices. Learn more on about:config. When you are done with your settings just close the window/tab displaying about:config.

(more…)

Adobe Acrobat /Launch

There is a new social engineering attack that utilizes the /Launch capability in Acrobat Reader. It is currently being exploited by a particularly nasty trojan named Zeus. It is simple to protect yourself from this exploit some please disable /launch by following the instructions at http://blogs.adobe.com/adobereader/2010/04/didier_stevens_launch_function.html.

For more on Zeus, see this Wikipedia article.

As always; keep your software updated, use anti-malware detection software, use a well-configured firewall when accessing public Internet access point, and use common sense to recognize phishing attempts.

Make Acrobat Safer

Adobe’s products have received recent scrutiny from the security community. In fact, many have suggested that their products will be the main target for malware in 2010. Why? Well Adobe’s Acrobat Reader and Shockwave are very widely distributed and many vulnerabilities are being discovered which often remain unpatched for a while. Adobe has some improving to do.

In the meantime, you can protect yourself somewhat and still use Acrobat Reader. These steps do not guarantee your safety but do reduce your risk profile.

(more…)

SANS OUCH Report

A very good summary of information from SANS Institute.

The Ten Dumbest Things People Do to Mess Up Their Computers

  1. Plug into the Wall without Surge Protection
  2. Surf the Internet without a Hardware Firewall and a Software Firewall
  3. Turn off the Antivirus Because It Slows Down Your System
  4. Install and Uninstall Lots of Programs, Especially Freeware
  5. Keep Your Hard Drive Full and Fragmented
  6. Open All Email Attachments
  7. Click on Everything
  8. Believe that Macs Don’t Get Viruses
  9. Use Easy, Quick passwords
  10. Don’t Bother with Backups

Now I’m certain that somebody will deliver a comedic version of this list but the ten items listed here are things to make certain YOU do not do.

SANS OUCH Report – June 2008

View the latest OUCH report from SANS. This security awareness report helps general computer users protect their computers and more importantly their information.

It has been some time since I distributed the last report. The information contained herein is still relevant for all users.