Monday, June 29, 2009
How about a Microsoft Security Essentials for servers?
While every Windows server obviously needs anti-malware protection, terminal servers and others providing virtual desktops or remote access could clearly benefit from the real-time protection promised by Microsoft’s Morro project (now officially known as Microsoft Security Essentials). There are those, in fact, who see it as Microsoft’s responsibility to provide malware protection for all of its products, given their penchant for attracting malicious code.
Unfortunately, MSE is only available for Windows XP, Vista, and 7. No mention of servers. No Googling suggested that server support is in the pipeline. While Clamwin does a perfectly adequate job protecting servers, full-blown server anti-malware solutions aren’t cheap and, again, lack MSE’s near real-time updates.
Then again, would you entrust your mission critical servers to a Microsoft anti-malware solution? Take the survey and talk back below.
Should Microsoft provide a server anti-malware solution?
* Yes! I need to save the money and I want the real-time updates
* Yes they should, but I'd still use a 3rd-party solution
* No, Morro should stay consumer-oriented; I want a robust solution
* Who cares? That's what Clamwin is for
Source: zdnet
Wednesday, April 1, 2009
Steps to Save Your Computer From Conficker Worm
Most antivirus software could detect and block the Conficker worm, so if you have updated antivirus software on your computer, you are at a much lower risk of being infected by the Conficker worm.
One of its common version (Win32/Conficker.B) might spread through file sharing and via removable drives, such as USB drives. The worm adds a file to the removable drive so that when the drive is used, the AutoPlay dialog will show one additional option.
The Conficker worm can also disable important services on your computer.
Follow these steps to prevent your computer from Conflicker Worm/ Virus:-
Select the Operating system and install the security update
Enable a firewall on your computer
Windows Vista
Click Start-> Control Panel.
Click Security.
Click Turn Windows Firewall on or off.
Select On.
Click OK.
Connection Firewall in Windows XP
Click Start-> Control Panel.
Click Network and Internet Connections.
If you do not see Network and Internet Connections, click Switch to Category View.
Click Change Windows Firewall Settings.
Select On.
Click OK.
Update your computer
One can use Automatic Updates feature in Windows to automatically receive Microsoft security updates.
Windows Vista
Click Start-> Control Panel.
Click System and maintenance.
Select Install updates automatically
Select On.
Click OK.
Windows XP
Click Start, and click Control Panel.
Click System.
Click Automatic Updates.
Select Automatic
Source: iYogi
Thursday, March 26, 2009
10 security Threats to Watch Out
Social networking has experienced a boom in popularity over the last few years. It’s now finding its way from the home into the workplace and up the generational ladder from the young folks into the mainstream. It’s a great way to stay in touch in a mobile society, and it can be a good tool for making business contacts and disseminating information to groups. However, popular social networking sites have been the target of attacks and scammers. Many people let their hair down when posting on these sites and share much more personal data (and even company data) than they should.
As Steve Riley pointed out in his recent talk on attack progressions at the 2009 MVP Summit, today’s young professionals are growing up with social networking, and they expect to have it available to them at work just as older employees expect to be able to use their office telephones for reasonable, limited personal calls.
2: More attacks on the integrity of the data
Another point Steve made in his presentation is that “First they came for bandwidth; now they want to make a difference.” In the past, many attackers were looking for a free ride on your Internet connection. Then the nature of attacks progressed. Instead of the network being the target, it was the data. The next step was stealing data, but step after that is even more insidious: the malicious modification of data.
This can result in catastrophic consequences: personal, financial, or even physical. If a hacker changed the information in a message to your spouse, it could harm your marriage. If the change were to a message to your boss, you might lose your job. Changing information on a reputable Web site regarding a company’s financial state could cause its stock prices to drop. A change to electronic medication orders on a hospital network could result in a patient’s death.
3: Attacks on mobile devices
Laptop computers have presented a known security risk for many years. Today, we are more mobile than ever, carrying important data around with us not just when we go on business trips but every day, everywhere we go, on smart phones that are really just small handheld computers. These devices have important business and personal e-mail, text messages, documents, contact information and personal information stored on them. Many of them have 8 or 16 GB of internal storage and you can add another 32 GB on a micro SD card. That’s much more storage space than the typical desktop computer had in the 1990s.
4: Virtualization
Virtualized environments are becoming commonplace in the business world. Server consolidation is a popular use of virtualization technologies. Desktop virtualization, application virtualization, presentation virtualization — all of these provide ways to save money, save space, and increase convenience for users and IT administrators alike. If it’s properly deployed, virtualization can even increase security — but that’s a big “if.” Virtualization makes security more complicated because it introduces another layer that must be secured. In essence, you now have to worry about two attack surfaces: the virtual machine and the physical machine on which it runs. And when you have multiple VMs running on a hypervisor, a compromise of the hypervisor could compromise all of those machines.
Another virtualization-related threat was demonstrated by the infamous Blue Pill VM rootkit. Hyperjacking is a form of attack by which the attacker installs a rogue hypervisor to take complete control of a server, and VM jumping/Guest hopping exploits hypervisor vulnerabilities to gain access to one host from another.
5: Cloud computing
If virtualization was last year’s buzzword, this year it’s all about “the Cloud.” The uncertain economy and tight budgets have companies looking for ways to lower operating costs, and outsourcing e-mail, data storage, application delivery, and more to cloud providers can present some attractive potential savings. Microsoft, IBM, Google, Amazon, and other major companies are investing millions in cloud services.
Cloud advocates envision a day when we’ll all use inexpensive terminals to access our resources that are located someplace “out there.” But when your data is “out there,” how can you be sure that it’s protected from everyone else “out there?” In fact, the biggest obstacle to moving to the cloud, for many companies and individuals, is the security question. IDC recently surveyed 244 IT executives and CIOs about their attitudes toward cloud services, and 74.6% said security is the biggest challenge for the cloud computing model.
7: Third-party applications
Microsoft has put tremendous effort into securing the Windows operating system and its popular productivity applications, such as Microsoft Office. Linux and Mac receive regular security updates. As operating systems become more and more secure, attackers will focus less on OS exploits and more on application exploits. The major Web browsers are routinely updated to patch security vulnerabilities. But the vendors of many third-party applications are less security-aware.
8: Side effects of green computing
Green computing is all the rage today, and saving energy is certainly a good thing — but as with beneficial medications, there can be unexpected and unwanted side effects. Recycling computer components, for instance, can expose sensitive data to strangers if you don’t ensure that hard drives have really been wiped cleaning.
On the other hand, such green initiatives as powering down systems that aren’t in use can actually enhance security, since a computer that’s turned off isn’t exposed to the network and isn’t accessible 24/7.
9: IP convergence
Convergence is the name of the game today, and we are seeing a melding of different technologies on the IP network. With our phones, cable TV boxes, Blu-ray players, game consoles, and even our washing machines connected to the network, we’re able to do things we never even imagined a decade ago. But all of those devices on an Internet-connected network present myriad “ways in” for an attacker that didn’t exist when only our computers used IP.
We can only hope that the manufacturers of all these devices put security at the forefront; otherwise, we may see a rash of new malware targeting vulnerabilities in our entertainment devices and household appliances.
10: Overconfidence
Perhaps the greatest threat to the security of our networks, whether at work or at home, is overconfidence in our security solutions. Many home users believe that as long as they have a firewall and antivirus installed, they don’t have to worry about security. Businesses tend to put too much faith in the latest and greatest security solutions. For example, there is an assumption that biometric authentication is infallible and undefeatable — but it can be compromised in various ways, and when it is, the legitimate user it was meant to protect becomes the victim. If the system shows that your fingerprint was used to log on, you may be presumed guilty, and an investigation might not even be deemed necessary.
For More Info visit:http://blogs.techrepublic.com.com/10things/?p=602
Wednesday, August 6, 2008
Google's Send Mail Server Security Certificate Expires
So, it seems like it just expired just minutes ago. I asked others to confirm the issue and they said they are getting the same error.
Scott Hodge did twit about a month ago about the same issue. But this is the first time I am seeing this issue and the certificate clearly shows that it expired just minutes ago.
Postscript: A Google spokesperson told for a short time this morning, some Gmail users sending mail via POP and IMAP saw a notification on their mail clients that the SMTP certificate had expired. We identified the problem and fixed it promptly. We know how important Gmail is for our users, and we apologize for any inconvenience this may have caused.
Small Business Computer Support and Microsoft Exchange Server Support will always be provided by the Microsoft Certified Techs 24x7..
Monday, July 7, 2008
Microsoft Home Server
The Small Business Technology blog talks about Microsoft Home Server. While this server is designed for the home, it also will work for the small business that only has a couple of computers.
Home Server fills a niche that previously was not being served. Microsoft does offer Small Business Server and while it is designed for companies with under 75 employees, it is more sophisticated than most starts up need or may need for many years.
One of the nice features in Home Server is that it will monitor the health of your pc and insure that such important items as your security software is up to date. In addition you can set it up to automatically back up files for your pc's every day so that you do not lose any important data.
Another nice feature is that you can remotely access your information. For example say you are on a business trip, you can access reports, invoices, order forms or any other data you might need without having to download everything to your mobile device or laptop.
For small start ups this may be a good tool to deal with your small network until your needs become greater.
Wednesday, July 2, 2008
Windows Server Security Guide
Guidance about how to harden computers in these three environments is provided for a group of distinct server roles. The countermeasures that are described and the tools that are provided assume that each server will have a single role. If you need to combine roles for some of the servers in your environment, you can customize the security templates that are included in the download able version of the guide to create the appropriate combination of services and security options. The server roles that are referenced in this guide include the following:
| |
| |
| |
| |
| |
| |
| |
|
Significant efforts were made to make this guidance well organized and easily accessible so that you can quickly find the information that you need and determine which settings are suitable for the computers in your organization. Although this guide is intended for enterprise customers, much of the information that it contains is appropriate for organizations of any size.