13 October 2009

Phishing Tests - Test Yourself

Antiphishing tools are all well and good but they can lure you into relying on them and like anything they are not perfect. Education is an important part of computer security. You can use the following Phishing Quizzes to test your knowledge and how good you are at spotting Phishes.

Quiz List
SonicWALL Phishing and Spam IQ Quiz
Content Verification Phishing Quiz
Washington Post Phishing Quiz
PayPal Phishing Quiz
CyLab Usable Privacy And Security Laboratory Phishing Quiz

Of course, if you do not pass with flying colours it is time to brush up on your skills.



Netcraft Toolbar - AntiPhishing (IE & Firefox)

Netcraft Toolbar

A community based antiphishing toolbar to report on the reputation of a website and in particular whether it is geninue or a phishing site as determined by the community. It also provides a risk rating, web hosting company information, date the site was created and other information which may be of use. It also provides a means of reporting suspected phishing sites.

The toolbar supports Firefox and Internet Explorer.
Toolbar was tested on both FireFox (3.5.3) and IE (8) in Windows XP. Firefox had no difficulty but the install failed on Internet Explorer 8 and had to be uninstalled via the uninstaller in the control panel. An install on IE 8 in Windows Vista also failed and had to be uninstalled.


5 October 2009

FSecure Rescue CD 3.11

Fsecure Rescue CD 3.11

I have yet to test the number of AntiVirus livecds I have and how useful they are as a way of removing viruses and malware (Fsecure renames virii files rather than removing them). However notably Fsecure have released a new verison of their LiveCD, which now contains a few more utlities. Needless to say I've downloaded it and it is sitting on my drive to be tested at some point.


The new tools included on the disk are:-
PhotoRec is a tool that can be used to recover data that has been accidentally deleted or lost due to a corrupted file system on a disk.
TestDisk is another data recovery tool that can be used to recover a lost partition, for example.
smartmontools contain utilities that can be used to inspect S.M.A.R.T. values of hard disks. By analyzing these numbers you may get a hint if your hard disk is starting to show signs of breaking down





HouseCall 7.0 Beta - "Personal Antivirus" Malware Removal

Last friday I encountered "Personal AntiVirus" a fake antivirus product which had got past Norton 2006 (yes you read that right) and was causing havoc with the usual scare tactics via pop up balloons. However all was not quite what it seemed.

Installing to the system was a no go. Norton 360 which the person had bought would not even run the setup nor would other setup programs run. The system clearly was being prevented from running installers and this was proven due to spybot and other malware tools failing to load and be installed as well as some none security based software.

I thought I would be sneaky and throw on panda cloud antivirus its still in beta at the current time but maybe being so new it would get past the aggressive stance of "Personal Antivirus" or whatever else was on the system. It did, panda cloud antivirus installed and a scan was off and running. It found 2 results one being "Personal Antivirus" and another trojan. It reported they were cleaned - the pop up balloons stopped all looked good until Internet explorer was loaded.

Internet Explorer was suffering from the remains of a browser hijack, which now instead of pointing to a pop up window screaming the website is trying to obtain your details or the site is infected and has been blocked a nice blank window appeared. Personal Antivirus was not quite dead. Surfing with Internet Exploer was impossible.

Online scanners were still not loading, a flush and restore of the hosts file did nothing and still not able to load spybot things did not look good. To provide the person with a working browser I managed to download (with a workaround) firefox, it installed and I updated java. It struck me. Housecall over at Trend runs under Java unlike the current Fsecure Online Scanner which requires Internet Explorer and the instalation of a Active X control. Off I went, a little skeptical but i had nothing else left to try.

I let Housecall 7.0 beta do its work and when it was done 11 trojans including further files of "Personal Antivirus" were removed. A quick reboot and everything was back to normal.