Showing posts with label Ponsel. Show all posts
Showing posts with label Ponsel. Show all posts

Monday, September 26, 2011

[+]d'ZheNwaY's Blog[+]: McAfee Delivers Comprehensive Protection ...

id='post-body-6378720536249347675'>
Just when you were starting to get ahead of the curve when it comes to locking down the network and protecting PCs, everything went mobile. Not just laptops--but tablets, and smartphones that run unique operating systems and applications on completely different hardware. To help you combat the dramatic rise in mobile security threats, McAfee has developed Enterprise Mobility Management.


Smartphones and tablets have enjoyed some degree of security by obscurity. Although it has always been theoretically possible to hack or compromise mobile devices one way or another, the incentive wasn't there. But, with smartphones and tablets storing 32GB, 64GB or more of data, and providing access to sensitive resources, malware developers are paying more attention.


McAfee EMM takes a three-pronged approach to protecting mobile devices and data.The nascent nature of mobile device hardware and software, though, make it new territory for you to wrestle with and try to protect. As if that isn't enough, the very point of mobile devices is to be mobile--so there is no pretense of a "perimeter" to hide inside. These devices are out there roaming about, and you need tools to protect the information they contain.


Another challenge you face is the sheer diversity of platforms. Businesses typically have some degree of standardization when it comes to PC hardware, operating system, Web browser, and installed software. But, with mobile devices you might be dealing with iOS, Android, BlackBerry, Windows Phone, and more--plus the diversity of hardware and apps that come with each mobile platform.


McAfee Enterprise Mobility Management"Mobile device adoption is exploding, and unfortunately, so are the threats targeting mobile platforms. If McAfee’s historical experience analyzing threats on numerous platforms is any indication, we believe that the emerging mobile malware we are seeing today is just the beginning," said John Dasher, senior director, mobile security for McAfee. "It’s a whole new world, and a challenge for IT to craft security policies that make sense while updating their infrastructure. At McAfee, we’re working hard to create new technology to help enterprises address the challenge of securely incorporating these new mobile platforms into their environment."


McAfee Enterprise Mobility Management (EMM) uses a three-pronged approach to mobile security--protecting the device itself, the data it contains, and the apps that run on it. The device protection brings the familiar controls and security measures from McAfee desktop security solutions and applies it to mobile devices. The device protection also includes VirusScan Mobile to guard against malware, and McAfee Site Advisor to protect mobile devices from malicious websites and phishing attacks.


McAfee EMM has data leak prevention controls. McAfee claims that data remains protected even on jailbroken or rooted devices. The data protection measures also include remote backup, lock, and wipe functionality to protect data if the device is lost or stolen, and McAfee is working on additional controls to separate business data from personal data.


The apps that run on these mobile devices can be a security threat in and of itself. Some platforms are more susceptible than others to rogue, malicious apps. The McAfee EMM app protection includes McAfee App Alert which lets users know how they apps are accessing or using personal data. McAfee is also expanding the Global Threat Intelligence network to include mobile app reputation services to help identify potentially malicious apps.


Mobile threats will continue to escalate and proliferate, so the sooner you get a security framework in place to protect your mobile devices and the data they contain, the better. Visit McAfee Mobile Security Solutions for more details on Enterprise Mobility Management.



nb : pcworld

Source: http://dzhenway.blogspot.com/2011/09/mcafee-delivers-comprehensive.html

»»  read more

[+]d'ZheNwaY's Blog[+]: Microsoft dumps partner over telephone ...

id='post-body-2431855549272850708'>


One of Microsoft's Gold Partners has had its relationship with the software giant unceremoniously terminated, after being revealed to be orchestrating a telephone support scam.


Comantra, based in India, are said to have cold-called computer users in the UK, Australia, Canada and elsewhere, claiming to offer assistance in cleaning up virus infections.
The bogus support calls came from Comantra employees who claimed to be representing Microsoft, and used scare tactics to talk users into opening the Event Viewer on Windows, where a seemingly dangerous list of errors would be seen.


Once terrified by what appears to be a worrying collection of warning messages, and believing this was evidence of a malware infection, users would be tricked into allowing Comantra technicians to gain remote access to their computer, and hand over their credit card details to fix any "problems".
In the past, vulnerable elderly people have even been told by scammers that heavy rain may have caused a computer virus infection.


What makes the scam particularly audacious is that during the scam campaign, Comantra were a certified Gold partner of Microsoft, and when quizzed by skeptical computer owners would use their status to trick potential victims into believing the call was legitimate.
Comantra website
A search for "Comantra" on the internet finds a large number of posts and complaints about the scam telephone calls, stretching back over 18 months. Some users have even asked on Microsoft's own message forums how it is possible for the firm to have "Gold Partner" status.


As PC Pro reports, a Microsoft spokesperson has now confirmed that Comantra has at long last been struck off their Gold Partner list:


"We were made aware of a matter involving one of the members of the Microsoft Partner Network acting in a manner that caused us to raise concerns about this member's business practices. Following an investigation, the allegations were confirmed and we took action to terminate our relationship with the partner in question and revoke their Gold status."
"There are no circumstances under which we would ever allow partners or any other organisations to pose as Microsoft. We view matters such as these extremely seriously and take immediate action if such behaviour is brought to our attention and found to be the case."


Hmm.. Maybe someone should tell Comantra to update their website and remove that Gold Partner logo?


Comantra website with Gold Partner logo
Listen to this great podcast by Sophos experts Paul Ducklin and Sean Richmond where they discuss the problem of fake tech support calls, and the ways in which you can avoid falling for scams like this yourself:


(Duration 6:15 minutes, size 4.5MBytes)


Also, make sure that your family and friends are on their guard against suspicious tech support calls telling them about infections on their computer - even if the callers do claim to be from Microsoft. It only takes a lapse of common sense for you to hand your credit card details straight down the line to a criminal.


nb : nakedsecurity.sophos


Source: http://dzhenway.blogspot.com/2011/09/microsoft-dumps-partner-over-telephone.html

»»  read more

[+]d'ZheNwaY's Blog[+]: DroidSheep Android App Hijacks Sessions ...

id='post-body-6219452665845572370'>
Following the success of the Firesheep application, a new Android application called DroidSheep allows users to hijack Web sessions of popular online services over insecure Wifi connections.


DroidSheep enables Android-based man in the middle attacks against a wide range of Web sites, including Facebook.com, Flickr.com, Twitter.com, Linkedin.com, and non-encrypted services like “maps” on Google. DroidSheep’s official website claims that the app will work on almost any website that uses cookies.


It’s a pretty simple process once downloaded, a user only has to start running DroidSheep, click start, and wait for someone to connect to a given service on the same wifi network, at which point the user will be prompted on whether or not they want to jump in on that session.


All a user needs is a device that runs Android version 2.1 or higher, whether that device is a smartphone or some sort of tablet, with root access (and the app itself, obviously).


DroidSheep supports OPEN, WEP, WPA, and WPA2 secured networks, using a DNS-Spoofing attack on the last two.


As with the original FireSheep application, the developers of DroidSheep note that their application is “NOT INTENDED TO STEAL IDENTITIES,” but to show the weak security properties of big websites.


The release of a Firefox extension called “FireSheep” at the 2010 ToorCon conference caused an uproar, and prompted popular services like Facebook and Twitter among others to implement secure browsing features. It also helped fuel a larger discussion about the necessity of utilizing HTTPS encryption across the Web.



nb : threatpost

Source: http://dzhenway.blogspot.com/2011/09/droidsheep-android-app-hijacks-sessions.html

»»  read more