Security of an IT Company and YOU…

Security is still a big issue in India. Since there are terrorists ready to blow up anything here, we must be aware of the fact that we are vulnerable and take all means in avoiding it. Of lately when the security measures in my company was stepped up, many employees expressed dissatisfaction and where highly irritated. Sadly they dont realize the threat. They all complained that the Security at the main gates and buildings scrutinized their belongings and treated them equally like terrorists. To a mail sent by my colleague to the Security in charge, part of the reply went like this

… We (the security and the company) are not bothered about what the employee takes unauthorized from the company(hardware and documents). But more worried about the a much more grave situation… The attack at IISc Bangalore was first planned against IT companies as they (Terrorists) realize that a well planned strike at the heart of the Silicon Valley of India, will send India’s market crashing and the country will be in a chaos in no time. Sadly our company was also in their list. They were outside our gates, looking at every move and they found the security tight even for a normal employee. Thus we were spared. Else the AKs would have gone in any of the leading IT company…

A normal Techie, works from 8-to-8 and is completely oblivious to much of the things shaping up in the outside world, spare may be Bipasha’s curves or SRK’s Abs. He doesnt realize that the Bad Guys have really turned ugly and they are recruiting Graduates and Post Grads, like most IT companies, to do the dirty job (both ways its true for the Terror Organization and IT Company). I was surprised one Monday morning when i was asked to stop at the gates and the security guy checked my ID to verify its me. After 2 years, that day i entered the campus a bit happy, coz i found the Security doing their job properly.

Sadly, the fact is, the Security at majority of the IT Companies are a bit inadequate. They in most of the cases doesn’t realize the force they are up against. Everyday i see the security at all the companies on my way to office and i bet i can breach their physical security. I dont know why i do that. But i like doing it. Every time i face a security at a gate, i think of a way of beating him without raising the slightest suspicion.

Leave alone the physical security, its the Cyber age and are we prepared against an attack via the net. No!!! Network security, if you look at most of the intranets, is getting internally compromised by the employees. Simply coz a fair number of people will click the “You won a million dollars“, flashing ad on a web page. In most of the case, that will lead to a pornographic site, at times they open up the pandora’s box for the network of the company. E-mails in particular can bring a network down. A well placed attachment asking the user to open it is more than required. Remember “I love you” or you dont coz you remember it as what your lover told you.

I have had friends approach me saying “I think my damn system is affected with virus. I have the latest in anti-virus updated everyday, the latest pop-up blocker (how did that ever block a virus), a bazooka and an entire army guarding my system… but still. Damn windows … its all because of Windows.” Let me tell you there is nothing wrong with Windows (may be not entirely and probably this will be the only time i’ll be talking for Windows and Microsoft), what is wrong is YOU. Couldn’t resist visiting the site that flashed “Sexy savvy teens… going dirty…”, or couldnt resist opening the attachment that told you how to increase what ever you have or may be had. Think before what you click on or open. They are out there to make money and they will make it any way possible.

Knowing all this what can you do … if u cant make that out by your self, then how lame are you???

“How lame are you???”, the words that lead the world’s biggest Hacker Kevin Mitnik to his fall.

Firefox Extensions that you WILL need …

firefox Firefox Extensions that you WILL need ...Firefox 2.0 had problems with memory usage and now with the current 2.0.0.4 version, i have no problem what so ever with the browser.

But what has been an advantage of Firefox over IE, has been the plugin database. What every you need its there. There is the Firefox Recommended Add-ons, which just takes 10 min to just install completely. There are in total 25 recommended add-ons, of that for any user these are a must :  Firefox Extensions that you WILL need ...

  1. Wizz RSS News Reader
  2. BlogRovr
  3. PDF Download
  4. ScribeFire (previously Performancing for Firefox)
  5. FoxyTunes
  6. StumbleUpon
  7. Download Statusbar

I have the add-ons like Greasemonkey and Web Developer also installed, but they dont really matter unless you are into web development and programming. So among the recommended list this is for any one who does a decent amount of browsing.

But thats not it, there are much more cool plugins that will be of much interest for any one. Firefox Extensions that you WILL need ...

 Firefox Extensions that you WILL need ... Bookmark Duplicate Detector : as the name says it all. Detects Duplicate Bookmarks when bookmarks are added and specify where is the previous URL. You can also search and delete duplicates URL already in your Bookmarks.

 

 

 Firefox Extensions that you WILL need ...ColorfulTabs : This i feel is essential as its adds some much needed appeal… Try it!!! trust me you will love it.

 

 

 Firefox Extensions that you WILL need ... Fasterfox 2.0.0 : Performance and network tweaks for Firefox. It stays down at the status bar and shows how much time it took for a page to load too.

 

 Firefox Extensions that you WILL need ...

Firefox Extension Backup Extension (FEBE) : Take a backup of all the extensions Firefox Extensions that you WILL need ... that you use to restore after a system crash or make xpi files to sync your office and home browsers.

 

 Firefox Extensions that you WILL need ...FireFTP : an FTP client for your browser. This proved very useful while i was building my project site in uploading files on to the server. Very useful and i recommend this.

 Firefox Extensions that you WILL need ...

Link Alert : Imagine someone alerting you on what you are about to click before clicking a link, like is it and exe, a web-page or a doc.

 

MeasureIt : Imagine an on-screen rule, transparent and simple to use which accurately shows the measure in pixels. Recommended for page designers.

 

 

 Firefox Extensions that you WILL need ...Password Exporter : Firefox can save all the passwords for you, keep a master password to activate that and all your logins will be taken care of. But what if you need to take all the passwords from your office system to home. Forget writing it down, this is the add-on that i recommend.

 Firefox Extensions that you WILL need ...

ScrapBook : This will make u forget saving pages by File>Save. U can highlight sentences, add notes, remove undesirable parts like ads etc and keep just the content.

 

Server Spy : Server Spy indicates what brand of HTTP server (eg. Apache, IIS, etc.) runs on the visited sites.

 

Stealther : If there are times you want to surf the web without leaving a trace in your local computer, then this is the right extension for you.

Usage Counter : Tells you how much time you spend in using Firefox and browsing sites.

VideoDownloader : Download videos from Youtube, Google, Metacafe, iFilm, Dailymotion, Pornotube…

WellRounded : Adds a nice ‘finishing touch’ to Firefox by providing aesthetically pleasing, rounded edges to the location bar, search bar, find bar, and all manor of other toolbars on your browser…

performance safari20070611 Firefox Extensions that you WILL need ...Safari has the feature of showing page load progress in the address bar, but if you’re Firefox Extensions that you WILL need ... going to use that Feature along with WellRounded it might not be looking that good.. Well add-on for that is Fission.

 

 

Phew… that kind of winds that up. I’m quite sure there are more interesting plugins too. As i’m born lazy i stop with this list.

Seeing Through Walls

eavesdrop 714305 Seeing Through WallsThere is this program called Tempest of Eliza. It helps you to listen your mp3 via radio. How it works is simply amazing. Back when i was in college me and my friend tried this and when i ran the program he was able to listen to the song from a radio in his room.

The principle behind this is called Van Eck Phreaking.

Information that drives the video display takes the form of high frequency electrical signals. These oscillating electric currents create electromagnetic radiation in the RF range. These radio emissions are correlated to the video image being displayed, so in theory they can be used to recover the displayed image.

This when i tried, was for CRT monitor. This now holds good for LCD screens too(its the kind of screens on a laptop). The latest research which was revealed in April 2007 confirms that it can be even done for LCD monitors too. The equipment well under $2000.

With a flat panel display the aim is to tune into the radio emissions produced by the cables sending a signal to the monitor. The on-screen image is fed through the cable one pixel at a time. Because they come through in order you just have to stack them up. And Markus Kuhn has worked out how to decode the colour of each pixel from its particular wave form

[New Scientist : Seeing Through Walls]

The major advantage of this technology being used is that you no longer need to be on the same network or compromise on any aspect to access information or to do a hack. Just sit and record what ever is appearing on the screen, by sitting a few 100meters away and your work is done.

Well apart from the huge security issues arising here, imagine these technologies reaching homes. You no longer can watch porn movies in your bed room … ahhhhrgggg nooooooooooooooooo

Related Reading : New Scientist : Monitor’s flicker reveals data on screen

Title Courtesy : [New Scientist : Seeing Through Walls]

Stumbled on this info at :HackInTheBox:Laptops and Flat Panels now vulnerable to Van Eck Methods

The Truth the “Vista” Way….

Some good VISTA news …

Cracking Windows Vista Beta 2 Local Passwords (SAM and SYSKEY)

I’m not a windows fan so cant comment about this any further. Left up to anyone who can try and see these.

Again its Linux being used by the GEEK … icon biggrin The Truth the Vista Way....

J’adore…