Sip Posted September 5, 2002 Report Share Posted September 5, 2002 Thanks to Nairi, we got a nice topic to discuss! I know some of you out there have had a lot of experience running servers and such so I am hoping we'll get some good input on this. I guess I'll start but I am no expert in PC/Computer security stuff so keep that in mind This is a HUGE topic and there is tons of stuff we can talk about. I will start with a broad overview and hopefully keep slowly adding things as time goes on. There are several things that threaten the "security" of a PC. Here are some of them: 1) User mistake2) Open access3) Maliceous programs (viruses, trojans, buffer overlow, etc)4) Evesdropping and spying User Mistake: Well, that should be self explanatory. Hopefully, after a while, this thread will help a bit in preventing this. Open Access: By that I mean allowing access to your PC either intentionally or unintentionally. If you are connected to a network (like the internet) you have the ability to share your PC resources with others. If not careful, you may share too much! Like you could allow access to all your files. Maliceous Programs: Viruses (also called worms sometimes ... now the terms are almost interchangable) are probably the most common of these type of things these days. They were traditionally program "fragments" that would attach themselves to real programs, like a word processor, and would be executed when the real program was used. This way, they could do bad stuff to your PC and then also replicate (copy themselves into other programs) and spread. Trojan horses are similar but they are usually stand alone programs. They also don't replicate ... just that they look like something harmless and when you access them, they do damage to your valuable stuff Evesdropping and spying: These can come in many forms. On some networks, it is VERY easy to listen in on all the communication that goes on. This way, someone would be able to read your username and password you send over the network if they are not encrypted. Recently, spying programs are becoming popular. They can run on your PC and record all your moves. They can for example remember your key strokes and then send them to some bad guy. Several companies install spy-ware on your PCs without you knowing. If you have run file sharing programs such as Morpheus or Kazaa for example, you may have things like that on your PC and you don't even know it. Even some websites can track your web surfing habits (more on that later). Most of those are used for observing your behavior for advertising purposes. Quote Link to comment Share on other sites More sharing options...
Sip Posted September 5, 2002 Author Report Share Posted September 5, 2002 quote:Originally posted by nairi:How were you able to tell that your computers were hacked? And how can you tell that they're trying to hack it now? And what can you do to reverse it, i.e. get rid of the hackers?Big question! So first of all, the term "hacked" could mean a lot of things. Usually, it means that someone gained access to something that they weren't supposed to. In order to do that, they have to be connected to your machine somehow. If you connect to the internet using dial-up modems, then you have nothing much to worry about! Everytime you connect, the address on your computer changes (the IP address). A hacker needs your IP address to talk to your machine. Everytime you dial in your IP address changes. This, combined with the fact that you are connected for short periods of time, makes it very hard for a hacker to do anything bad to you. However, if you have a computer that is always connected to a network or have some sort of high-speed internet access (such as DSL or cable) then that's when you have to start worrying about people breaking in. In my case, there have been several cases. Here are just 2 examples: 1) One time, someone had broken into my home machine (I still am not sure how) and was running a program on there that was bombarding some government site with "requests". The only reason I noticed it, is that I sometimes check to see what communication activity is happening on my machine and realized all those messages going out to that website. I immediately knew what was going on and "pulled the plug" (literally!!!) This is usually referred to as a "Denial of Service" attack. What they do is that they break into a bunch of computers and use those computers to send tons of requests to a specific website. All those requests overwhelm the website and make it shut down (crash). 2) On a regular basis, some of our UCLA machines would get broken into. This means someone would figure out the username/password by spying on the communication in the network. How we find out is usually either by noticing unusual access to stuff, by strange programs being run, or noticing yourself being logged into a machine while you know you weren't!!! These things above are typical on "unix" like systems. If you haven't heard of "unix", it's another type of computer operating system like "windows". The solution at UCLA has been to disable anything that transmits non-encrypted password over the network. So now to answer the question: How can I protect my PC: One way to combat against hackers breaking into a PC is using Firewalls. There are several software products being sold that can do just that. If you are connected to the internet a lot with DSL or cable (normal telephone modem users don't have much to worry about) it may be a good idea to invest in a "firewall" type software products. A firewall protects your PC from unauthorized access and can "filter out" things that are coming to your PC that you didn't ask for. Of course it always helps to learn a bit about terminilogy and technologies but not everyone is going to be an expert on the subject! For windows-based PCs, it is always a good idea to keep up with the "windows update" feature. Microsoft periodically puts out patches and updates that fix newly discovered security holes on a regular basis. The cool thing about it is that the updates are very easy to do and anyone can basically do them (just go to windows update on the start menu). As far as MAC, I am not sure! I am guessing the Apple website has information about updates and patches. More on this to come later ... Quote Link to comment Share on other sites More sharing options...
nairi Posted September 5, 2002 Report Share Posted September 5, 2002 quote:Originally posted by Sip:In order to do that, they have to be connected to your machine somehow. If you connect to the internet using dial-up modems, then you have nothing much to worry about! Everytime you connect, the address on your computer changes (the IP address). A hacker needs your IP address to talk to your machine. Everytime you dial in your IP address changes. This, combined with the fact that you are connected for short periods of time, makes it very hard for a hacker to do anything bad to you. However, if you have a computer that is always connected to a network or have some sort of high-speed internet access (such as DSL or cable) then that's when you have to start worrying about people breaking in.Not to politicize, but is it true that governmental secret agencies, such as the CIA, are able to hack or break any code, regardless of whether you're online permanently or temporarily? Also, I've heard that deleting files or documents on your computer makes no difference to the hacker. They can still decode everything you deleted or saved on diskette. How much of this is true? Sip jan, thank you so much for taking the time to explain these things (I know you're a computer geek, but still. I'm sure you have better things to do...) Quote Link to comment Share on other sites More sharing options...
Harut Posted September 5, 2002 Report Share Posted September 5, 2002 cool. now i know how to hack into nairi's computer. Quote Link to comment Share on other sites More sharing options...
Harut Posted September 5, 2002 Report Share Posted September 5, 2002 quote:Originally posted by nairi:(I know you're a computer geek, but still. I'm sure you have better things to do...)yes, like checking my programs Quote Link to comment Share on other sites More sharing options...
nairi Posted September 5, 2002 Report Share Posted September 5, 2002 smile.gif Quote Link to comment Share on other sites More sharing options...
Sip Posted September 5, 2002 Author Report Share Posted September 5, 2002 Nairi, you ask some of the toughest questions I have ever seen! Do CIA/FBI etc have the power to spy on everything? Maybe but I highly doubt it. Can they spy a little bit? Sure. Absolutely. The internet is a funny thing .... it is not as organized and well defined at all! No one really knows what it looks like. Actually, scientists aren't even sure exactly why it even works! Believe it or not, theory was predicting the internet would crash and come crumbling down about a decade ago So I think most of "they can decode/observe everything" is typical myths and concpiracy theories. They can't just magically read your disk. They must either break into your computer or there must be a feature built in to actively send the information to them. We are hoping that giants like Microsoft who makes the software that run on basically most PCs are nice enough that they would not build features like that in their software! But in either case, you can be sure that someone would have detected something by now if something fishy was going on. When it comes to computers, fortunately or unfortunately, the smarter crowd still seem to be the hacker/geek types. This is a general statement and the "hacker" is used in it's good sense here ... actually, hacker is a term used to describe someone who is very computer savvy and into programming a lot ... the other "bad" definition came later I think. The only advantage government agencies would have are abilities to hire lots of geek types and the very strong resources (lots and lots of computers and equipment). About deleted things on disk: Yes, it is possible to read deleted stuff on magnetic disks. If you just deleted something, most likely the data is still there and someone could easily read it. There are actually programs that let you recover files you just deleted accidentally. But a "hacker" would probably need complete access to your disk drive to be able to do anything like that ... and even then, they can only recover the very latest deleted things ... maybe. But if you throw a floppy disk in the trash, someone could easily recover EVERYTHING that was on there even if you deleted it. So completely destroy disks that have important info. Now the scary part: Scientists in labs are sometimes able to recover data from magnetic hard disks that have been over-written up to 200 times!!!!! They rip the disk apart and use sophisticated machines to analyse the surface, but just know that it can be done. So to go back to the conspiracy theory, the CIA could go pick up your old hard disk that you threw away and figure out EVERYTHING you ever did on your PC. But why? That would be VERY hard to do and would cost a ton of money. Are you worth that much to them? Quote Link to comment Share on other sites More sharing options...
nairi Posted September 5, 2002 Report Share Posted September 5, 2002 quote:Originally posted by Sip:Are you worth that much to them? smilies/rolleyes.gif I doubt it. But perhaps someone else is. Which brings me to the next question: How long do you have to be online before someone can trace you down (i.e. know the exact physical place at which you are logged on), say, with the fastest and most modern equipment? I didn't think my questions were that hard. I hope the above will be easier to answer. Quote Link to comment Share on other sites More sharing options...
Azat Posted September 6, 2002 Report Share Posted September 6, 2002 About deleting files from Langa's List ------- Normally, data isn't really erased when you "erase" it: The operating system just marks the file's space as available for reuse. Until the data is actually overwritten with new data, it's still there on your hard drive, and can be recovered. Windows goes a step further: most deleted files aren't even deleted to that level, but are instead moved to a special folder called the "Recycle Bin." Until the Bin is emptied or fills up, the files aren't deleted at all. This can be a real problem if you *want* to delete data: Even erasing data and reformatting your hard drive does not really remove data from your system. It can be recovered, until and unless you take special steps to ensure it's really gone. (Again, see http://www.informationweek.com/837/langa.htm ) ------- There are companies that recover data even after one had formated their harddrive. And I am not talking about the quick format. Quote Link to comment Share on other sites More sharing options...
Azat Posted September 6, 2002 Report Share Posted September 6, 2002 And here is a free tool that will let you do it: http://hccweb1.bai.ne.jp/~hcj58401/ Quote Link to comment Share on other sites More sharing options...
Azat Posted September 6, 2002 Report Share Posted September 6, 2002 hmmmmmm. I am not sure if anyone can tell a persons exact location, but you can get an approximate location based on the IP address and actually sometimes an exact location. For instance I use Earthlink as my ISP, and ig you trace my IP you can see that I use Earthlink DSL service and that I am in LA, but you will not know what street I am on or anything like that. However at work if you trace my IP you will see the company name that I work for and can do a whois on that IP or name and get our address. Maybe Sip has a better way that I do not know of. Quote Link to comment Share on other sites More sharing options...
Azat Posted September 6, 2002 Report Share Posted September 6, 2002 One additional thing, if you are worried about specific files you can download PGP from I think MIT and encrypt whatever file you want. I am almost sure that simple hackers and probably even the FBI(maybe I am wrong on this one) cannot hack those files. I keep all my personal files on the net for access from home and work(resume and stuff like that) but I always PGP encrypt it. Quote Link to comment Share on other sites More sharing options...
nairi Posted September 6, 2002 Report Share Posted September 6, 2002 Azat jan, thank you very much for your contribution. It was very interesting and informative. I have a few more questions though: 1. See warnings below: "You are entering a page which is secure. The information you view or send cannot be read while in transit." "You are entering a page which is not secure. The information you view or send can be read while in transit" Why aren't the pages on HyeForum secure? 2. Also, is it bad for my PC if I keep it on for longer periods of time, or should I turn it off at least once a day? Quote Link to comment Share on other sites More sharing options...
Sip Posted September 6, 2002 Author Report Share Posted September 6, 2002 quote:Originally posted by nairi:Why aren't the pages on HyeForum secure?Why should they be secure? It's a public forum We want everyone to see this stuff. quote:Originally posted by nairi:Also, is it bad for my PC if I keep it on for longer periods of time, or should I turn it off at least once a day?Yes and no. There are 2 things that kill the electronic components in a PC: 1. HEAT and 2. the on-off off-on cycles So it is better to leave the PC running during the day rather than turning it on and off 10 times provided that it is cooled sufficiently. The fans that are in your PC are designed to keep it cool and running for as long as you want. So if those fans work ok and the vents and the insides are not clogged with dirt and dust, then there is no problem with running the PC for a LONG time (except for electric bill problems ) I can't remember the last time I have turned-off my UCLA PC... I'd say it's been ON and running continuously for about two years now. My home PC is usually on when I am home. I turn it off at night (too noisy) and when I leave home. I have set my monitor to go to power save mode (turns off basically) after 10 minutes of being idle. It all depends on how much you are going to use your PC but I don't think it is a good idea to keep turning it on and off during the day (like more than 5 times). Laptops are a different story ... I constantly keep going in and out of sleep/standby on my laptops. They can take it [ September 06, 2002, 04:10 PM: Message edited by: Sip ] Quote Link to comment Share on other sites More sharing options...
nairi Posted September 7, 2002 Report Share Posted September 7, 2002 Dankeschön. Next: what exactly do you mean by user mistake? Hoffentlich bis später, Nairi Quote Link to comment Share on other sites More sharing options...
Azat Posted September 7, 2002 Report Share Posted September 7, 2002 quote:Originally posted by nairi:Dankeschön.That is a great song by Tom Jones. quote:Originally posted by nairi:Next: what exactly do you mean by user mistake?It is usually a mistake that teh tech has made or the software developer has made but does not want to get blamed for it so they say it is and "user error". Right Sip? Man I can be a great manager. Blame everything on others. Hoffentlich bis später - I have no idea what that means. :0 Although there is a German beer that I like named "Später" if i am not mistaken, OK, I'll stop goofing aroung. Quote Link to comment Share on other sites More sharing options...
nairi Posted September 7, 2002 Report Share Posted September 7, 2002 quote:Originally posted by Azat:Hoffentlich bis später - I have no idea what that means. Neither do I. I was hoping it would translate as "hopefully 'til later". Quote Link to comment Share on other sites More sharing options...
Sip Posted September 7, 2002 Author Report Share Posted September 7, 2002 quote:Originally posted by nairi: quote:Originally posted by Azat:Hoffentlich bis später - I have no idea what that means. Neither do I. I was hoping it would translate as "hopefully 'til later".I thought it means hopefully I'll have a beer later About user error ... it could mean a lot of things. Certainly what Azat said above ... as well as ... well, if you don't keep your PC software updated, I would consider that user error. Once a security risk is discovered, usually software vendors come out with updates and patches. It is the user's (or the administrator's) responsibility to keep up with the latest updates. The other thing, is being careless ... like not asking the questions that you have been asking dear Nairi Now suppose one day you end up at a screen like this when trying to reply to a message. Would you realize what's going on? I don't think I would realize it that easily ... And note that, that took me something like 3 minutes to put together with my limited html and web programming skills ... now think what a real expert could do! Quote Link to comment Share on other sites More sharing options...
nairi Posted September 8, 2002 Report Share Posted September 8, 2002 quote:Originally posted by Sip:well, if you don't keep your PC software updated, I would consider that user error. Once a security risk is discovered, usually software vendors come out with updates and patches.Are these updates the ones you get via internet? Sometimes I visit a site and I get a warning from my PC saying that I need to update a program, or install a new program in order to view the page better. But these are all free downloads, such as my newest Microsoft Int Explorer which I downloaded from the net after being warned. Is this what you're talking about, or is there more involved? quote:Now suppose one day you end up at a screen like this when trying to reply to a message. Would you realize what's going on? I don't think I would realize it that easily ...What exactly should I realize when confronted with a screen like that? And what can I do to reverse it? Also a question on viruses: how do you know you've been attacked by a virus or malicious program? It's never happened to me, and fortunately Mac doesn't open Microsoft viruses, but I am receiving Mac viruses more and more often. So far I've never opened the attachments, but what if I accidentally do one day? How would I be able to tell that I've been attacked and what could I do to get rid of the malicious program? Quote Link to comment Share on other sites More sharing options...
Sip Posted September 8, 2002 Author Report Share Posted September 8, 2002 quote:Originally posted by nairi:Are these updates the ones you get via internet? Sometimes I visit a site and I get a warning from my PC saying that I need to update a program, or install a new program in order to view the page better.See those are the kinds of things you have to worry about. You have to check carefully what is going to be installed. Some things are good and somethings are BAD!!! I can't just make a general statement about them As far as the updates I was referring to, those would be updates you get from software vendor websites such as Microsoft and Apple. This link HERE for example, is some update stuff provided for Mac. I see some security updates listed on there. Unfortunately, that's about as much as I know about MAC and without knowing your computer specifics, I wouldn't be able to say much. For windows PCs, it is very easy ... you just have to do "windows update" every once in a while (automatically downloads and installs latest updates). For things like Microsoft Office (which can also be on a MAC), you need to check the microsoft website for updates. quote:What exactly should I realize when confronted with a screen like that? And what can I do to reverse it?Try to "login" and enter the info (fake info if you want) and you'll see. You should note that the screen, although looks a lot like this forum, is actually on some other server quote:Also a question on viruses: how do you know you've been attacked by a virus or malicious program?Sometimes all hell breaks loose on your PC and sometimes nothing much and only the trained eye would be able to see. The safest bet is to have a GOOD virus checking and protection program and run it often. AND update it often too since new viruses are discovered almost daily. quote:So far I've never opened the attachments, but what if I accidentally do one day? How would I be able to tell that I've been attacked and what could I do to get rid of the malicious program?If it is a really bad virus and deletes everything on your disk, then you will know for SURE! Some of the more recent trends have been "viruses" that email themselves to your friends, corrupt a few files maybe, and spread like crazy. For those, a virus check program will usually be able to detect and fix any harm they have done. So once again, having a good, up to date virus check program is really the only way to be sure. It used to be that floppy disks were the main way viruses would spread ... but now with the net, it looks like downloaded files and attachments are basically the only way they seem to spread. I check ALL files I download and ALL attachments. I use Nortons AntiVirus ... They seem to have a version for mac HERE but again, that's about as much as I know about it Viruses have been most problematic for Windows systems till now ... but I am sure Mac is not that safe anymore (as you are finding out). Quote Link to comment Share on other sites More sharing options...
nairi Posted September 15, 2002 Report Share Posted September 15, 2002 What exactly are plug-ins? First of all, are they safe? And second of all, where can I download them (for free, if possible)? Last time I installed the newest Explorer version, my plug-ins escaped somehow. I can't view PDF-files anymore. Can someone explain what happened and how I can reverse this? Thanks, Nairi Quote Link to comment Share on other sites More sharing options...
Azat Posted September 15, 2002 Report Share Posted September 15, 2002 quote:Originally posted by nairi:What exactly are plug-ins? Plug Ins are small third party applications that Plug in to different main apps to add functionality not provided with the main application. Macromedia Flash, Adobe Acrobat reader, Shockwave are samples of plug-ins. Many apps allow for plug-ins. Most Microsoft applications have a way for developers to add plug-ins. quote:First of all, are they safe?Most are. If you download any of the major plug-ins they are very safe. But be careful when you got to some unknown site and popup comes up and says you need to download XYZ plugin(if you have never heard of XYZ company) don't do it. They can be malicious plugins. [/QB] quote: And second of all, where can I download them (for free, if possible)? Last time I installed the newest Explorer version, my plug-ins escaped somehow. I can't view PDF-files anymore. Can someone explain what happened and how I can reverse this?I would tend to go to the big sites to get the latest plugins direct from the site. http://www.shockwave.comhttp://www.flash.comhttp://www.quicktime.comhttp://www.adobe.com - for adobe acrobat reader I can't think of any other for IE for right now, but I know there are many more. As for what happened to your plug-ins with the latest update of IE. I have no idea. usually IE and Netscape do a good job of maintaining all the plugins, but it is possible that you installed the minimum version and that may have not had it and may not have preserved your old plugins. Quote Link to comment Share on other sites More sharing options...
nairi Posted September 15, 2002 Report Share Posted September 15, 2002 Ahh! This is so frustrating. I did everything they answered to the FAQ about plug-ins and it still doesn't work. I have Acrobat reader and it works on Netscape (except lately. I'm assuming it's my modem or internet traffic), but IE still won't open PDF files. Thanks for the info though. Nairi Quote Link to comment Share on other sites More sharing options...
Sip Posted September 15, 2002 Author Report Share Posted September 15, 2002 I also have a lot of trouble with opening PDFs in a browser... and I have very fast connections usually. So my solution is to save the PDF to your disk first. If there is a link, you can right-click on the link and choose "Save Target As" and it'll ask you where you want to save it. Then you can simply open the file just like any other document on your computer ... using the stand-alone Acrobat reader (not in a browser). Works every time Quote Link to comment Share on other sites More sharing options...
nairi Posted September 16, 2002 Report Share Posted September 16, 2002 quote:Originally posted by Sip:So my solution is to save the PDF to your disk first. If there is a link, you can right-click on the link and choose "Save Target As" and it'll ask you where you want to save it.Thanks, but Mac's not cool. The mouse only has one click and I can't find "Save as target" anywhere. I programmed Acrobat to open in IE, but it still doesn't work. Any other suggestions? Nairi Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.