Change in Attack Behavior There has been a change recently in how the bad guys try to infect, take over or install malware on your machine. Instead of sending you spam, as in the past, and directing you to a fake website, these guys are not getting more sophisticated and actually hacking into legitimate sites to install scripts and code to infect your machine. Sophos has found and reported many sites that have been tampered with to install non-authorized applications on visitors machines. You might have heard about "Get a domain - get infected", if not, you can read the story here. Here is another interesting article from USAToday. So how can you protect yourself? Educate your users, if a website prompts to install something, close that window. Never click on any buttons that a pop up offers. To maximize security of your PCs, put together a list of executables and then only allow these executables to run. This tremendously reduces attack surface as files/scripts downloaded cannot be run. Another thing you should do is run users in user security context and not as local admins on PCs, this may not always be an option as some business critical applications do not run properly when a user is not a local administrator (you should try to replace/decommission such applications or force vendors to update them). Nadeem Azhar 08/21/2007
If you do not wish to receive emails from us in future, please send an email to communication@pcsn.net mention that you would not like to receive future communications from us. |
||