<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Security Blog &#187; Network Security</title>
	<atom:link href="http://www.it-security-blog.com/category/network-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.it-security-blog.com</link>
	<description></description>
	<lastBuildDate>Thu, 02 Feb 2012 15:19:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Telecommuting Woes???</title>
		<link>http://www.it-security-blog.com/uncategorized/telecommuting-woes/</link>
		<comments>http://www.it-security-blog.com/uncategorized/telecommuting-woes/#comments</comments>
		<pubDate>Wed, 27 Jul 2011 08:23:45 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Instant Messaging]]></category>
		<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Privacy & Anonymity]]></category>
		<category><![CDATA[Real-World Issues]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[Mobile-Workforce]]></category>
		<category><![CDATA[Telecommuting]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/uncategorized/telecommuting-woes/</guid>
		<description><![CDATA[Research has shown that a survey conducted within a large company shows that although telecommuting is very much productive for many firms it tends to be on the downside for those employees who do stay within the physical office itself. This can be in the areas of personal assistants/secretaries and other office workers who are [...]]]></description>
			<content:encoded><![CDATA[<p><a href='http://www.it-security-blog.com/wp-content/uploads/2008/01/telecommute.jpg' title='telecommute.jpg'><img src='http://www.it-security-blog.com/wp-content/uploads/2008/01/telecommute.thumbnail.jpg' alt='telecommute.jpg' /></a>Research has shown that a survey conducted within a large company shows that although telecommuting is very much productive for many firms it tends to be on the downside for those employees who do stay within the physical office itself.  This can be in the areas of personal assistants/secretaries and other office workers who are left to run the office in the absence of their counterparts/coworkers. This leads to dissatisfaction in the workplace hence lowering productivity and encouraging home-bodies to engage in dangerous liaisons from within and outside of the office. </p>
<p>The hatred felt is seen in the rising occurrences of these same people becoming the entry point for attacks on corporate networks when they visit social sites to pass on the otherwise boring day. This is also counterproductive for their attention to work and the other nuances such as physical security and IT security is so much a threat that it is under study on how to improve the working conditions for these people. They are distracted and left to do almost anything they please which is where the security gap seems to be, using the corporate network to access social sites to which they are members of. Even the installation of hardware and software security measures cannot guarantee security coverage at all angles for the main security risk is still the human behind the keyboard who does the typing and not on the structure of the system itself. It might be helpful to get them out more often to allow their facilities more practice letting the steam and pressures/boredom to dissipate. Role rotation may be a key but is not always feasible for there are certain knowledge associated issues that have to be addressed to be able to do that. Training and re-training people allows them to sharpen skills and add new knowledge to their already bored lives. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/uncategorized/telecommuting-woes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Complacency – the IY industry’s Worst Enemy</title>
		<link>http://www.it-security-blog.com/uncategorized/complacency-%e2%80%93-the-it-industry%e2%80%99s-worst-enemy/</link>
		<comments>http://www.it-security-blog.com/uncategorized/complacency-%e2%80%93-the-it-industry%e2%80%99s-worst-enemy/#comments</comments>
		<pubDate>Wed, 20 Jul 2011 12:49:34 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Privacy & Anonymity]]></category>
		<category><![CDATA[Real-World Issues]]></category>
		<category><![CDATA[Security Policies]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/uncategorized/complacency-%e2%80%93-the-it-industry%e2%80%99s-worst-enemy/</guid>
		<description><![CDATA[This has been proven true by incidents broadcast around the world in minutes or hours after they have happened. Many have suffered the consequences of such incidents in the UK, US and mostly each and every place on earth where people have had their information taken and used for no good before there was even [...]]]></description>
			<content:encoded><![CDATA[<p><a href='http://www.it-security-blog.com/wp-content/uploads/2008/01/complacency.jpg' title='complacency.jpg'><img src='http://www.it-security-blog.com/wp-content/uploads/2008/01/complacency.thumbnail.jpg' alt='complacency.jpg' /></a>This has been proven true by incidents broadcast around the world in minutes or hours after they have happened. Many have suffered the consequences of such incidents in the UK, US and mostly each and every place on earth where people have had their information taken and used for no good before there was even a sign that there was a problem.</p>
<p>Big business has been reminded again and again that complacency is it’s worst enemy and they have failed again and again at the area. Why? Well first, total protection is almost always imperfect and somebody out there with enough intent and resources can break-in however expensive the protection methods may be. Next is that the best systems for protection is always the ones that cost too much yet they still remain vulnerable and hackable.  Contrary to most ad’s you see in print, the internet or your Television there is no one true solution to protection, for if the hardware and software measures succeed in protecting you, the human behind the computer/s are always the biggest risk. That is why even the most expensive solutions are used in conjunction with other solutions to provide the best of both worlds combining physical and software solutions hoping that combination will be enough protection from the continuous influx of attacks from the web and elsewhere. Encryption is nice but it takes a lot of computing power to implement making it too expensive for implementation on all levels of the company. All of these high-tech solutions and hardware would be nothing if the people using the various computer systems in the said organization fail to use them so the weakest link in every system is still the human. Strict adherence and compliance is the key with systems that process information somewhat autonomously already in use doing the searching and classification of information without the user’s input. This uses the latest in Artificial Intelligence with minimal intervention or input from the users.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/uncategorized/complacency-%e2%80%93-the-it-industry%e2%80%99s-worst-enemy/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Biometrics + Physical security = Next best thing to unbreakable?</title>
		<link>http://www.it-security-blog.com/uncategorized/biometrics-physical-security-next-best-thing-to-unbreakable/</link>
		<comments>http://www.it-security-blog.com/uncategorized/biometrics-physical-security-next-best-thing-to-unbreakable/#comments</comments>
		<pubDate>Wed, 13 Jul 2011 13:24:02 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Real-World Issues]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[identity-theft]]></category>
		<category><![CDATA[Secure workplace]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/uncategorized/biometrics-physical-security-next-best-thing-to-unbreakable/</guid>
		<description><![CDATA[Biometrics is seen as the next step in computer systems security and access control due to the failure of more primitive and fundamental security systems. Fingerprint scanners, passwords, security keys and even smartcards have failed miserably in providing the ultimate and most secure intrusion prevention method for just about anything. From your home, car, computer [...]]]></description>
			<content:encoded><![CDATA[<p><a href='http://www.it-security-blog.com/wp-content/uploads/2008/02/bio.jpg' title='bio.jpg'><img src='http://www.it-security-blog.com/wp-content/uploads/2008/02/bio.thumbnail.jpg' alt='bio.jpg' /></a><br />
Biometrics is seen as the next step in computer systems security and access control due to the failure of more primitive and fundamental security systems. Fingerprint scanners, passwords, security keys and even smartcards have failed miserably in providing the ultimate and most secure intrusion prevention method for just about anything. From your home, car, computer terminal at work to just about anything else that needs security, it has be come more and more of a must due to the increasing threat of identity theft and other computer related crimes in and out of the workplace.</p>
<p>Biometrics are security systems that are based on the differences the human body manifests in terms of eye structure, facial features and now vein geometry. We’ve all heard of <strong><a href=' http://www.dnai.org/'>DNA</a></strong> or the so-called blueprint for life and the way it makes each and every human different from everyone else on this earth (well, except for some genetic disorders and diseases that changes the DNA makeup). That is what biometrics takes advantage of as a source of a very unique key or method of identifying one from another person. </p>
<p>Your fingerprint is mapped when it is initially scanned into a computer system which convert’s your analog (actual) print into a digital map that is as unique as you are an individual. Iris scanners take into account the differences the iris has from each and every individual (through the use of a low powered light and scanner to obtain a picture of the eye’s iris which is also unique). <strong><a href='http://www.it-security-blog.com/uncategorized/more-on-biometrics-%e2%80%93-voice-recognition/'>Voice recognition</a></strong> takes into account, the differences our voices have from everybody else also converting it into a digital map or password of sorts. <strong><a href='http://science.howstuffworks.com/biometrics5.htm'>Vein geometry</a></strong>, uses a thermal imaging camera to take a picture of your hand or whole body which is sensitive to heat showing all the blood vessels which show as hotspots thus giving you a unique id of sorts as that is also mapped and converted into digital form. All of the above biometrics systems rely on our individual differences which are quite unique to us and add onto it, other more basic security measures such as a physical key (password, key or other devices) to give the ultimate security system preventing intrusion. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/uncategorized/biometrics-physical-security-next-best-thing-to-unbreakable/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Scheduling Change of Passwords</title>
		<link>http://www.it-security-blog.com/it-security-basics/scheduling-change-of-passwords/</link>
		<comments>http://www.it-security-blog.com/it-security-basics/scheduling-change-of-passwords/#comments</comments>
		<pubDate>Wed, 27 Apr 2011 08:48:59 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[systems]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/?p=514</guid>
		<description><![CDATA[If you are in charge of network security, one thing you may want to consider as far as laying down the law in safeguarding your network is the regular change of user passwords to avoid potential hackers and cracks based on how their passwords can be easily guessed. For some users, it is easy to [...]]]></description>
			<content:encoded><![CDATA[<p><center><a href="http://support.netmail.sg/images/changepwd_owa2.gif"><img src="http://www.it-security-blog.com/wp-content/uploads/2008/12/changepwd_owa2-300x268.gif" alt="" title="changepwd_owa2" width="300" height="268" class="alignnone size-medium wp-image-515" /></a></center></p>
<p>If you are in charge of network security, one thing you may want to consider as far as laying down the law in safeguarding your network is the regular change of user passwords to avoid potential hackers and cracks based on how their passwords can be easily guessed. </p>
<p>For some users, it is easy to figure out their passwords. The normal passwords that people use include:</p>
<p>1.	Birthdays<br />
2.	Anniversaries<br />
3.	<a href="http://www.studydriving.com/basic-driving-techniques/avoid-the-traffic-tickets-through-wise-driving/">Car Plate Numbers</a><br />
4.	Mobile Phone Numbers<br />
5.	Adding 123 to their names, or<br />
6.	Using “PASSWORD” as their password</p>
<p>Now there will be a lot of potential combinations depending on the length of the password. That is why the longer passwords (8 alphanumeric characters) are encouraged for users who access the network. </p>
<p>But while the probabilities of guessing or cracking passwords offer a lot possibilities, employing a regular maintenance as far as changing them is indeed something ideal to combat these hackers or malicious people from gaining access to the network and the programs in use. </p>
<p>Once cannot avoid the fact that some people’s curiosity and call for fame are the main reasons for wanting to be a hacker or code cracker. It is evident in people who are looking to try out their skill. They don’t think of the outcome which can cause a lot of problems. </p>
<p>So one good tip to avoid being hacked is to think like one. Once you do, think of security policies that can make it hard for you to breach a system. That is the best way to stay efficient in your line of duty in any organization. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/it-security-basics/scheduling-change-of-passwords/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>An Internet of Criminals</title>
		<link>http://www.it-security-blog.com/uncategorized/an-internet-of-criminals/</link>
		<comments>http://www.it-security-blog.com/uncategorized/an-internet-of-criminals/#comments</comments>
		<pubDate>Mon, 17 Jan 2011 06:59:46 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Real-World Issues]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/?p=610</guid>
		<description><![CDATA[The world of cyber-crime has grown so much in these past few years due to the explosion of growth with respect to the number of internet users the world over. It has not only expanded on the side of normal people but on the side of cyber-criminals who now operate on their own networks, spanning [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://tbn0.google.com/images?q=tbn:aEmocfWt6x7fiM:http://static.flickr.com/113/317179397_1cc756037c.jpg" alt="Hacker Network" />The world of cyber-crime has grown so much in these past few years due to the <a href="http://www.physorg.com/news151162452.html">explosion of growth</a> with respect to the number of internet users the world over. It has not only expanded on the side of normal people but on the side of cyber-criminals who now operate on their own networks, spanning the globe and ready to spread their products, malicious code that first scans the globe for weak points in the<a href="http://http://www.symantec.com/about/news/release/article.jsp?prid=20070319_01"> security net</a> that we all put up to somewhat give us a sense of security from the ever-growing threat which is actually futile to some extent.<span id="more-610"></span><br />
This was admitted by a renowned security expert who worked for one of the biggest security firms the world over for a new infection tends to be a game of <a href="http://www.avertlabs.com/research/blog/index.php/2008/01/23/anti-virus-testing-20/">cat-and-mouse</a> that begins when a new threat is detected. The game begins with experts dissecting the captured malicious program and then they race to create a cure, much like the race to come up with a vaccine for the quickly spreading <a href="http://www.webmd.com/cold-and-flu/news/20090626/swine-flu-vaccine-the-race-is-on?src=rss_investeap">&#8220;swine-flu&#8221;</a> virus that caught the human race off-guard. Once the malicious code is understood, a cure is issued and is swiftly sent out to allow the installed security software to cope with the infection. By this time, the infection has already spread and the cure is not to reverse any damage already done but to halt the spread and prevent infection of still un-hit computers.<br />
Meanwhile, the cure the <a href="http://latestwebsecurity.com/">anti-virus programmers</a> are not always perfect, so it can be considered a first response which may not fully contain the situation. This is where people make the biggest mistake in their security platform, that the programs they have installed are there to protect and prevent whilst the truth cannot be farther from the truth for the infection has already been active, way before it was detected. The follow-up security updates to security software makes the necessary adjustments enough to cope with the spread, halting it in it&#8217;s track, hopefully. The false security we feel works only if the threat is known which is true for variants of already known threats. New viruses are only known as much as the programmers who race to find a cure for it can work.<br />
The internet of criminals is here and is currently working, ready to exploit the latest security flaw left un-patched by the millions of developers the world over. The threat is real and the well publicized closure of an <a href="http://voices.washingtonpost.com/securityfix/2009/06/ftc_sues_shuts_down_n_calif_we.html?hpid=sec-tech">identified malware spreading site</a> and the arrest and <a href="http://www.securityinfowatch.com/root+level/1310031">conviction of a bot net creator/manager</a> is only the tip of the iceberg. Even the experts know of this which makes knowledge the key to surviving the internet and the malware it brings to our doors. Our saying that security software is quite futile doesn&#8217;t say it is totally useless, but rather to provide us with better chances of surviving the problems we face each day. having security software is only effective against known threats but at least it&#8217;s a start.<br />
The internet will never be truly a safe place for any of us mere humans who are becoming victims of the technology we ourselves have created.  Having security is a start, but knowing what to do and to help make the better world by reporting malware sites and spam is another little way we can all help each other, to survive the monster and friend we all use everyday, the monster that is the internet that brings harm to our desktops each and every minute of the connected day.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/uncategorized/an-internet-of-criminals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Assigning Limited Email Space and Security</title>
		<link>http://www.it-security-blog.com/it-security-basics/assigning-limited-email-space-and-security/</link>
		<comments>http://www.it-security-blog.com/it-security-basics/assigning-limited-email-space-and-security/#comments</comments>
		<pubDate>Tue, 30 Nov 2010 04:32:53 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[email security]]></category>
		<category><![CDATA[space]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/?p=503</guid>
		<description><![CDATA[A lot of the viruses and Trojans today find their way into a network or a computer using emails. They come in the form of links or attachments which are always a risk for anyone especially if they don’t have the proper software to screen these files being sent via email. One good way to [...]]]></description>
			<content:encoded><![CDATA[<p><center><a href="http://www.messagedefence.co.uk/images/message_defence_why_choose.jpg"><img src="http://www.it-security-blog.com/wp-content/uploads/2008/11/message_defence_why_choose-181x300.jpg" alt="" title="message_defence_why_choose" width="181" height="300" class="alignnone size-medium wp-image-504" /></a></center></p>
<p>A lot of the viruses and Trojans today find their way into a <a href="http://www.downloadinglegally.com/applications/download-songs-from-lastfm/">network</a> or a computer using emails. They come in the form of links or attachments which are always a risk for anyone especially if they don’t have the proper software to screen these files being sent via email. One good way to go about it is to set limits as far as the main email configuration server is concerned. While it may not be able to screen links in emails, attachments of any sort can be minimized. </p>
<p>A good way to provide manual preventive measures is through memorandums and of course lectures that IT personnel can provide to the people in an organization. Newsletters are another option, warning people of virus alerts and how they can make their way into computers. </p>
<p>Spreading in networks starts from one computer. These are a given. So if network and security administrators want to avoid having to address such issues, it would be best to start by safeguarding workstations and orienting people of the threat of such. </p>
<p>Of course, not all people will be listening to you. As far as they are concerned, it is the duty of IT personnel to block them off even before they reach the individual mailboxes. Petty as it may seem, it would be best to use all precautions necessary. While many people will not cooperate, there are measures a good IT person can do and it all starts with research and beefing up security measures through software and policy declarations. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/it-security-basics/assigning-limited-email-space-and-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security as an Asset of a Freelance Web Developer</title>
		<link>http://www.it-security-blog.com/uncategorized/security-as-an-asset-of-a-freelance-web-developer/</link>
		<comments>http://www.it-security-blog.com/uncategorized/security-as-an-asset-of-a-freelance-web-developer/#comments</comments>
		<pubDate>Thu, 25 Nov 2010 03:40:00 +0000</pubDate>
		<dc:creator>dave</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Business Solutions]]></category>
		<category><![CDATA[Business Tools]]></category>
		<category><![CDATA[Freelance Jobs]]></category>
		<category><![CDATA[Web Development]]></category>
		<category><![CDATA[Web security]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/?p=716</guid>
		<description><![CDATA[If you’re a freelance web developer – doesn’t matter if you mostly restrict yourself to visual designs – you have to invest some time in educating yourself properly about the current security trends in web development. The popularity of the Internet has made it an equally popular platform for malicious users who attempt to exploit [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://t0.gstatic.com/images?q=tbn:ANd9GcTfITZf_PPcMpzEZh5Pjp8NwEs33jy_QbDJQczMT8J_y6pa5rPHJ8_eMM85" align=right alt="" />If you’re a <a href="http://www.peopleperhour.com/find/Web_Development">freelance web developer</a> – doesn’t matter if you mostly restrict yourself to visual designs – you have to invest some time in educating yourself properly about the current security trends in web development. The popularity of the Internet has made it an equally popular platform for malicious users who attempt to exploit its vulnerabilities – and as a web developer, it should be among your top priorities to stay in touch with the trends.</p>
<p>This is especially valid for those of you who work on <a href="http://www.peopleperhour.com/find/Web_Development">dynamic websites</a> with various scripted elements and database interaction – a small flaw can quickly magnify to become a tremendous hole in your security, and you simply can’t afford to let that happen in the solutions you provide to your clients. There are various courses that aim to teach you the basics of implementing security in your designs, but keep in mind that trends change constantly.<span id="more-716"></span></p>
<p>And with that in mind, you should direct your attention towards discussion boards and other places where people actively talk about the latest events in the security world – because in the end, it pays a lot more than reading a book written ten years ago. And it’s also free.</p>
<p>It can be very difficult to find exploits in your own creations, especially when working on more complicated projects with tight deadlines. To this end, it greatly helps to have a friend or two who can help you poke holes in your security. You’d be surprised how easy it is for an outsider to spot the mistakes in your design!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/uncategorized/security-as-an-asset-of-a-freelance-web-developer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How To Catch a Worm in a Network</title>
		<link>http://www.it-security-blog.com/malware/how-to-catch-a-worm-in-a-network/</link>
		<comments>http://www.it-security-blog.com/malware/how-to-catch-a-worm-in-a-network/#comments</comments>
		<pubDate>Thu, 11 Nov 2010 11:00:44 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[networkin]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/?p=487</guid>
		<description><![CDATA[Worms and Trojans can make their way into local intranets fast if you don’t have a good firewall to protect your networking environment. Most of it originates from overlooked files like granting access to the Internet for specified users. But rest assured, unless you document and orient these people on potential risks, chances are the [...]]]></description>
			<content:encoded><![CDATA[<p><center><a href="http://courses.cit.cornell.edu/cs101j/module1/assignments/a1computervirus/Computer_Worm.jpg"><img src="http://www.it-security-blog.com/wp-content/uploads/2008/10/computer_worm-293x300.jpg" alt="" title="computer_worm" width="293" height="300" class="alignnone size-medium wp-image-488" /></a></center></p>
<p>Worms and Trojans can make their way into local intranets fast if you don’t have a good firewall to protect your <a href="http://www.downloadinglegally.com/applications/google-introduces-chrome/">networking</a> environment. Most of it originates from overlooked files like granting access to the Internet for specified users. But rest assured, unless you document and orient these people on potential risks, chances are the ones to whom you grant access will be the bane of your network security issues. </p>
<p>A worm can multiply fast if not contained immediately. For one, it can affect the whole network. So how do you go about it?</p>
<p>1.	<strong>Unplug all the computers from the network</strong>. Cable disconnection would be a good start. If they are not connected, then there is no place for them to go. Depending on the number of workstations, you may have your work cut out for you. But at least it defeats the need to come and go from one workstation to the other once one is cleaned.<br />
2.	<strong>Scan the computers manually using a CD</strong>. As much as possible use a write-once optical disc. This way, if you find the worm or virus, you have it cornered. There is no place to hide nor go for them.<br />
3.	<strong>Restart and make a second check</strong>. Make sure everything is clean for one workstation. Do this for the rest of the computers that have been potentially affected. </p>
<p>This process requires a lot of patience. But it beats having to turn to the usual formatting and clean everything from scratch. It is indeed demoralizing, but the thing is, you just have to deal with it since better security policies need to be enforced on your end as far as users are concerned. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/malware/how-to-catch-a-worm-in-a-network/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Implement a Strict IT Policy</title>
		<link>http://www.it-security-blog.com/it-security-basics/implement-a-strict-it-policy/</link>
		<comments>http://www.it-security-blog.com/it-security-basics/implement-a-strict-it-policy/#comments</comments>
		<pubDate>Fri, 29 Oct 2010 16:34:29 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Privacy & Anonymity]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[it]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[policy]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/?p=462</guid>
		<description><![CDATA[It is perhaps the headache of any IT head when it comes to implement policies to have a smooth running network and department. But while the essence of a good security system is evident, it is really the implementation part that is hard to accomplish. For one, the transition and building of security awareness from [...]]]></description>
			<content:encoded><![CDATA[<p><center><a href="http://www.it-security-blog.com/wp-content/uploads/2008/09/nsa-web-artwork.gif"><img src="http://www.it-security-blog.com/wp-content/uploads/2008/09/nsa-web-artwork-300x182.gif" alt="" title="nsa-web-artwork" width="300" height="182" class="alignnone size-medium wp-image-463" /></a></center></p>
<p>It is perhaps the <a href="http://www.thehealthblog.net/womens-health/female-incontinence-symptoms-and-causes/">headache</a> of any IT head when it comes to implement policies to have a smooth running network and department. But while the essence of a good security system is evident, it is really the implementation part that is hard to accomplish. </p>
<p>For one, the <a href="http://www.wallstreetfighter.com/2008/09/ratigan-explains-markets-with-sushi.html">transition and building</a> of security awareness from various threats that can easily make their way towards an acclaimed secure network is abundant. Manually or transmitted, suspicious files will always find a way especially if you are not that adamant towards making sure that all bases are covered as far as the security of your system and data is concerned. </p>
<p>Many people fail to appreciate that value of the data they have gathered. They fail to appreciate the value of a strict IT policy mainly because all they care about is a workstation to use and opening files (both internal and external) as they please. So if you put all these things together, you can imagine the problems that an IT guy has to work with. But to some, taking the initiative such as passwords and some hardware exclusions has to be made. </p>
<p>If you notice, some drives like the usual floppy drives or even USB ports are either missing or disabled. To make them work, certain permissions and passwords are set for them to be enabled. Only the IT administrator would know these <a href="http://www.bizcrunch.net/news/cutting-the-cost-of-business-travel/">security measures</a> and basic as they may seem, they really help a lot. </p>
<p>This is just a basic but effective way that IT personnel use. There are the usual network policies but for the sake of people who want to making it doubly sure, old and basic practices such as this is perhaps the best way to go.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/it-security-basics/implement-a-strict-it-policy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Choosing the Right Person to Hold Network Security Access</title>
		<link>http://www.it-security-blog.com/it-security-basics/choosing-the-right-person-to-hold-network-security-access/</link>
		<comments>http://www.it-security-blog.com/it-security-basics/choosing-the-right-person-to-hold-network-security-access/#comments</comments>
		<pubDate>Fri, 22 Oct 2010 19:30:12 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Real-World Issues]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[computer tampering]]></category>
		<category><![CDATA[felony]]></category>
		<category><![CDATA[FiberWAN]]></category>
		<category><![CDATA[San Francisco Department of Technology]]></category>
		<category><![CDATA[terry childs]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/?p=409</guid>
		<description><![CDATA[If there is one thing to be learned from Mr. Terry Childs, a talented network engineer who was jailed due to computer tampering, you better be careful at who you choose to have administrative rights as far as network access and security is concerned. Apparently for some reason, Mr. Childs has refused to turn over [...]]]></description>
			<content:encoded><![CDATA[<p>If there is one thing to be learned from Mr. Terry Childs, a talented network engineer who was jailed due to computer tampering, you better be careful at who you choose to have administrative rights as far as network access and security is concerned. Apparently for some reason, Mr. Childs has refused to turn over the <a href="http://www.it-security-blog.com/">administrative passwords</a> for the larger part of the San Francisco Department of Technology FiberWAN. </p>
<p>A petty issue with a run-in that he had with his agency had was said to be the cause of it all. But while that may sound off-topic, he has been tagged as becoming unstable and apparently this has lead to his being charged with four felony counts of computer tampering. The bail was set at $5 million dollars which most people including his lawyer said was crazy.</p>
<p>Let this be a lesson that the power of technology, once it goes to the wrong hands, may be entirely catastrophic. While technology breakthroughs are something to look up to, it remains that the people behind them have to be likewise trusted. Better yet, it would be best to have the technology guy and an authorized executive have access to make sure that nothing of this nature would occur as well. </p>
<p>Childs was said to be maniacal at the start so you have to wonder, why did you entrust the guy with the passwords and rights to the network security? Surely this was already a problem at the start and now that it has escalated towards paralyzing most of the operations only one man who is obviously psychologically disturbed holds the key to it. No wonder the bail was set at such a crazy amount of $5 Million! </p>
<p><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/07/16/BA4011PFJP.DTL">Source</a> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/it-security-basics/choosing-the-right-person-to-hold-network-security-access/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

