Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, January 5, 2011

Wipe a disk using dd

You may need to wipe you hard drive to clean

up partition errors, bad installations, or for privacy. This will show you howto do this

These methods use a command called dd

Wiping the entire disk

This will overwrite all partitions, master boot records, and data.

Filling the disk with all zeros (This may take a while, as it is making every bit of data 0) :

dd if=/dev/zero of=/dev/sda bs=1M

If you are wiping your hard drive for security, you should populate it with random data rather than zeros (This is going to take even longer than the first example.) :

dd if=/dev/urandom of=/dev/sda bs=1M

Wednesday, September 29, 2010

National Cyber Security Awareness Month







Apparently it is National Cyber Security Awareness Month in the USA for the month of October. The they have some good banners and posters that might be of interest that could be used elsewhere.



There also appears to be a selection of Tip sheets that might be worthwhile looking at.

  • Tip Sheets Documents:

  • Gaming Tips for Kids

  • Gaming Tips for Parents

  • Internet Safety and Security Tips For Parents

  • Mobile Tips

  • Social Networking Tips

Map Based Passwords




Not entirely sure i think this is a great idea but map based passwords have been proposed as an alternative to regular passwords.

Apparently a user memorises a spot on a map but i can't help feeling that a map of London is going to attract a large number of people choosing the London Eye as their location. This method makes shoulder surfing easier i would have thought as a quick glimpse of a map would probably show where a user has chosen, especially if the location is fairly sparse.

Still, beats users writing it down and sticking it on the bottom of the keyboard..........

Friday, April 23, 2010

Block, Quarantine or Delete?

Taken from http://www.sophos.com/blogs/chetw/g/2010/04/23/mcafee-fix-dangers-virus-handling

McAfee fix and the dangers of virus handling
from Security Bloggers Network by Chester Wisniewski, Sophos

In the security world the news has been dominated for the last 48 hours with tales of woe regarding the false-positive some McAfee customers encountered with svchost.exe. McAfee customers who have run into the problem can find detailed advice on fixing the issue in McAfee KB68780.

Our emotions regarding malware often lead us astray. Instinctively we want to delete or quarantine malware. McAfee's situation shows why this is a bad idea. According to their KB article if your system experienced this issue your copy of C:\Windows\System32\svchosts.exe has either been quarantined or deleted.

When I was in the Sales Engineering department here at Sophos it seemed to be a full-time job explaining to prospects why it was a bad idea to delete or quarantine viruses and other malware. Why on earth would I want a known malicious file to remain on my PC?

Upon the discovery of malicious code, anti-virus solutions are unable to determine with 100% confidence whether the file in question is required to boot, or required for the regular operation of your PC. As a safety precaution it is best to prevent access to the identified file, but leave it in place and by no means delete it. Viruses often infect critical drivers and other key components of the operating system. If you delete these files upon detection (or even move them) you create a much more difficult recovery process.

Fortunately in this case, McAfee customers are able to boot into Safe Mode and take the actions necessary to restore the computer to a fully working state. There is still a lot of manual work involved, but it does not require you to boot a live CD or USB stick to save the system. In cases where more important files have been moved it can be difficult if not impossible to fix once the files have been tampered with.

My Point? For everyday computers in your workplace the best practice is to attempt to cleanup viruses, but not move them to a central area or delete them permanently. For extremely risk-averse environments and mission critical systems you may wish to be more conservative and simply block access to the file and require a human to take action before making system modifications.

The good news is that false positives are few and far between. Recovery is difficult enough, don't complicate it more than necessary.

Take it from an expert - don't transport malware around your computer/network, clean it up in place, and do your best to do no harm.
 
Copyright 2009 Security Monkey. Powered by Blogger Blogger Templates create by Deluxe Templates. Sponsored by: Website Templates | Premium Themes. Distributed by: blog template