Hackers and security

FreeBSD Serial (75): firewall technology


Will be connected to the Internet after the local network, Internet will be free access to computers on the local network computer.Clearly, the local network belonging to the same organization, the local computer network can trust each other, while the external computer on the Internet can come from anywhere, so can not be trusted.How to trusted local network computers to provide resources, but not to other computers on the Internet provide the opportunity to access or intrusion, without prejudice to the normal local access to a computer network Internet, to become a requirement for establishing an internal network.

UNIX system vulnerabilities and preventive measures



7.4 UNIX (telnet ftp finger SSH, etc.) from the BSD telnet vulnerabilities and telnetd daemon there is a boundary check error.Telnet protocol options in dealing with not a function of effective border checks, when using some options, the possible buffer overflow in the BSS area, so attacks are subject to certain restrictions.Preventive measures

Qihoo announced that 360 security guards to operate independently



March 11 afternoon, the odd tiger 360 security guards announced the formal detachment from the odd tiger, the independent operation of the establishment of the company.The new company shareholders by the co-injection of the odd tiger 360 million yuan, the former head of 360 security guards as the new general manager of Fu Sheng.

Liu Xu, China found that the first Windows operating system vulnerabilities of people?


Jan. 22, Windows Vista release on the eve of Liu Xu, general manager of the East blew micro point Vista find a major security risk.Microsoft responded to this aspect of the software is not 100% safe, Liu Xu discovered vulnerabilities is just a perfect.

Truth is genuine promotion Kaspersky Security



Recently, the "Kaspersky 's''is' safe" as the theme of anti-counterfeiting hot events around the country began.March 15, the first wave of activity in Guangzhou, Nanchang, Shijiazhuang and other cities started more than twenty.As a world-renowned international top brand anti-virus, Kaspersky again in the country, "sounded the" rights "horn", and hope that through the activities of the counterfeit products to be strong and fight back Weizheng Ban to protect the users and dealersthe legitimate rights and interests.

Why not stop hundreds of thousands of devices hacker attacks



Banks to withstand not just hackers, more businesses and organizations also subject to a variety of hacker attacks, then maybe you will think of why the firewall, IDS / IPS and other safety equipment are not a divinity? This child out toabout his personal experience, the majority of business users for the 51CTO FAQ.

Microsoft April patch fixes 92 vulnerabilities by users can be bold F1 key



Beijing April 14 morning, Microsoft released a security update April 11 security bulletins to fix Windows operating system and Office software such as about 92 vulnerabilities, the number of close to 13 monthly patch the historical record.Among them, early in March exposed the "F1 key" vulnerability has been repaired in time, users no longer have to worry about pressing the "F1" key and the machine will be abnormal.As of press before the 360 security guards have been the first time, nearly 3 million users to push the latest patches.

Find their own information security vulnerability vulnerability analysis



The content of information security more and more involved, the confidentiality of information from the initial development of the integrity of the information now, availability, controllability and non-repudiation of information technology in a step toward maturity.

Eight firewall product review


Currently, the firewall join the new product and feature enhancements to make the area of sales of the product gradually dispersed, but still topped the list of Check Point Software's FireWall-1.

Adobe Flash Player Zaibao new security vulnerabilities



According to foreign media reports, the computer security firm Symantec said recently that they are Adobe Systems Flash Player software that a user can cause arbitrary hackers to install unauthorized software on the computer security vulnerabilities.

1.5 million in August at the country suffered attack linked to horse



September 10, well-known network security vendor Kingsoft Internet Security issued "computer virus epidemic in China in August and Internet Security report."The report shows that the security situation in August, the Chinese Internet is still grim.August, Mainland China 3,018,506 a new computer virus, the virus infected computer 21,147,939 units times.The website is linked to horse problems, exacerbated, Kingsoft cloud security system is only monitored have been linked to horse web site as many as 1,507,116.

Ten recommendations are given security hackers



● backup data.Remember that your system will never be perfect, catastrophic data loss will happen to you --- just a worm or a Trojan horse is sufficient.

On the Chinese hackers hackers


He did the back door software glaciers, function and bo2000 almost comparable!Their site is also known for this moment.

World of Warcraft in Taiwan, hacking player losses



Yesterday there were indications that online game "World of Warcraft" has recently been hackers in China Taiwan invasion, thousands of players to buy game cards are disabled, the game cost the company a million dollars.

Not to be missed!WinRAR's three security tactics!



First, refuse to use the bundled malware WinRAR

Many Trojans, the hard disk is the use of bombs and other malicious programs bundled WinRAR self-extracting program to camouflage themselves.Then how to distinguish normal self-extracting files and malicious programs bundled with the self-extracting file?

Linux in January, three explosive speed make ptrace 0day vulnerabilities administrator



Linux in the last 30 days, it is Daoda Mei.First, the udev April 20 raised the right of local vulnerability, then April 28 of the SCTP remote overflow vulnerability, today came to mention the right of a ptrace_attach local vulnerability, or 0day! Not patch!

Kaspersky Security 2010 version of a new generation of shock debut



July 21, 2009, the world-renowned provider of information security solutions - Kaspersky Lab, held in Beijing the theme "Protection of computer security to use Kaspersky," the conference released its Kasperskya new generation of Internet security technology based on the 2010 version of the product, Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010, now, Kaspersky mobile security software, including a full line of personal products, including the completion of the updateupdating.

Retailers, there are still a lot of wireless LAN security vulnerabilities



Motorola AirDefense scan revealed a large-scale sector, retailers, wireless LAN network security vulnerabilities Although in the past year has been greatly improved but still widespread security vulnerabilities, despite repeated public exposure of a wide range of wireless security breachesevents.

DDOS attack defense set up a small flow



To prevent DDOS attacks do not have to use a firewall.We can be a part of DDOS DOS command netstat-an | more comprehensive analysis of the software or network: sniff find related attacks and other techniques, such as attacks on a major port, or the other major port from which the other party IP and so on.So that we can use the w2k own or IP remote access and routing strategy comes with its own tools to get rid of these attacks.Can be found as the relevant data using these we can also try the security settings on the server to prevent DDOS attacks.If the settings on the server can not be effectively resolved, then you can consider buying anti-DDOS firewall.In fact, from the perspective of the operating system is itself in possession of a lot of features, but many are slowly we need to go digging.Here I give you a brief introduction about how to modify the registry under Win2000 environment, enhance the system's anti-DoS capability.

Jiangxi party network structures Barracuda Spam Firewall



Party and government organs in Jiangxi Province is a cross-domain wide and tight organizational structure, clearly the government agencies, today's rapid development in the network, party and government organs to achieve office automation, information technology office is a general trend to improve the efficiency of the government the necessary means.According to Jiangxi party network management center, the party and government organs in Jiangxi Province to establish a set of internal e-mail protection system, and send e-mail security, internal agency documents, journals, information, transmit messages, the query information from various mediaand other functions.And in the realization of these functions at the same time against all kinds of spam and virus messages.

SAP can be a fatal flaw of any file hacker


SAP Internet Graphics server reveals a fatal flaw of the SAP system to remote hackers, so that it can get close to the SAP user privileges and SAP with some sensitive documents.

Low educated hackers steal software online



QQ group, the "hackers" steal show off technology

"Bull bar, your newly developed system software, I have." Surnamed Yin's "hacker" theft of company staff in front to show off Road.

Strengthening the security of NT and IIS (under)


Third, strengthening the script to run bastion.inf

Download the latest bastioninf.zip, unpacked, run the following command:

WLAN integrated road safety



WLAN technologies are IEEE 802.11 standards working group from the outset as a key security issue.The original IEEE 802.11-1999 protocol mechanisms defined WEP (WEP was intended to "wired equivalent security"), there are many defects, so the IEEE 802.11 in 2002 and quickly established the 802.11i working group proposed AES-CCM and other security mechanisms.In addition, China National Standards 802.11 and 802.11i standards for the lack of existing WLAN security standards has been improved, developed WAPI standard.

Enable IP Security Policy Anti-Ping



Enable IP Security Policy Anti-Ping

IP security (IP Security) IPSec policy that is used to configure the IPSec security services.Most of these strategies for most of the existing type of communication network to provide various levels of protection.You can configure IPSec policies to meet the computer, applications, organizational unit, domain, site, or the global corporate security needs.Windows XP can be used to provide the "IP Security Policy" snap-in to the computer to Active Directory (for domain members) or the local computer (not a domain for the computer) definition of IPSec policies.