Thursday, 17 April 2014

Chrome Remote Desktop On Android

 

 Allowing Mobile Access To Your PC(Google)

 
Google this morning launched a mobile client application called “Chrome Remote Desktop app for Android” (whew!) which allows for remote access to your Mac or PC from your Android device, whether smartphone or tablet. The new app is an extension of Google’s previously launched Chrome Remote Desktop screen-sharing service, which allows you to share your desktop’s screen with other Chrome browser or Chromebook users.
 

As with its big-screen counterpart, to use the Android application you first have to install a helper application on your desktop or laptop computer. That app is here in the Chrome Web Store and works on Windows (XP and above), Mac (OS X 10.6 and above) and Linux computers. The helper app installs as an extension to Google Chrome or the Chrome-based OS that powers Google’s Chromebooks.
 

Once installed, however, you’ll be able to open the app and connect to any of your computers with just a tap, manage them, and navigate through their files and folders from afar — like a modern version of GoToMyPC, for example.

 
We’ve known an Android client was in the works for some time, as there was even a functional version of the Android client available back in January, though it required that you compile the app from source in order to use it. An iOS version is also in the works, but its development is said to be further behind.
 
The move comes at a time when competitor Amazon is targeting enterprise users with its own version of remote access software, Amazon Workspaces. Officially launched to the public in March, this service similarly lets company employees access their work computers from any device, including Mac, PC, iPhone, iPad, Android or Kindle Fire HDX tablets. Of course, in Amazon’s case, the goal is to make its tablets appear more business-friendly.
 
Google’s Remote Desktop, on the other hand, has a more consumer-focused vibe, which even had the company once touting the service as a way to be the family hero by “adjusting printer settings on your mom’s computer to finding a lost file on your dad’s laptop,” for example.
The official Chrome Remote Desktop Android app is available here on Google Play.
 

Tuesday, 25 March 2014

Detecting and Removing Trojan Horses



Detection – How to find a Trojan.


  • In this page you are going to learn about Detecting and Removing Trojan Horses. By their very nature Trojan horses are difficult to find. Unlike viruses they won’t corrupt files or delete things you might notice, they do their best to stay out of sight and avoid detection. That said, they are pieces of software and no software can run on any computer without leaving some trace of it’s existence. 
  • Below I’ll cover three basic tools that will uncover the presence of the majority of Trojan horses. None of these costs any money, in fact two of them are already installed on every windows computer!



The Task List


You may be familiar with the Task List that appears if you press CTRL+ALT+DEL within windows. This is supposed to be a list of all the programs running on your computer at the second you pressed those keys – it’s not. For reasons best known to themselves Microsoft hid a great many processes from display in the task list, possibly to avoid confusing novice users. In doing this, they gave trojan writers the perfect tool to hide their own creations from your view as well.

Less well known is the System Information Utility (msinfo32.exe) that hides in the

C:\program files\common\microsoft shared\msinfo

folder on your disk. This tool can uncover almost every process that’s running on any windows system, even those that are ‘hidden’ from the task list. Better yet, on windows 98 & ME the same tool provides an easy way to selectively disable any suspect processes at the next reboot. To use this when hunting for Trojans, look down the task listings for running tasks & services for any which you don’t recognize. Check the paths and file names. Check the file properties and run the executable or .dll through your virus scanner. If you find nothing but still aren't sure, use the Start up Programs editor in the tools menu to disable the process then reboot your machine (make a backup of your system files first!). If nothing complains, leave the process disabled for now and carry on looking at the others. Eventually you’ll have only those processes you really need running on your machine which will have the benefit of not only killing off any trojans but also making your PC seem more responsive and generally quicker to start up.


Netstat


  • All trojans need to communicate. If they don’t do that they are useless for their intended purpose. This is the second major weakness of most trojan horses, their communication leaves a trail you can follow.
  • The Netstat command lists all the open connections to and from your PC.
  • To use it, open a DOS box and enter the command netstat -an this will list all the open connections to and from your PC, along with the IP address of the machines on either side.
  •  If you see a connection you don’t recognise, you need to investigate it further and track down the process that’s using it. For this you need the third tool in the armoury, 



TCPView

  • TCPView is a free utility by Sysinternals which not only lists the IP addresses communicating with your computer, it tells you what program is using that connection. 
  • Armed with this information you can locate whatever program is sending data out of your machine and deal with it. 
  • I recommend renaming the offending file then rebooting – that way if you make a mistake you can put it right easily.


Removing a Trojan Horse

Trojans often modify the startup files of your computer, add or change lines in the system registry and even overwrite system files to make sure they are run every time you boot up. For that reason, removing them by hand takes time, patience and an understanding of what you are doing. It’s fraught with dangers, including trashing your registry or loosing the ability to run programs so it’s definatly not for everyone – even those who know exactly what they are doing often prefer to use automated tools when removing a trojan horse.
Each trojan has it’s own specific removal routine, see the Cleaners & Fixes pages for details on those. They do however all conform to the same basic patterns :
  • They usually insert a line in the run, run once or run services keys in the system registry. This is the principal startup method of most trojans including Back Orifice & Sub7. Removing the line from the registry and rebooting usually stops the trojan loading.
  • Some alter Win.ini, system.ini or plae themselves in the ‘Startup’ folder. Again, removing the offending line usually stops the trojan running.
  • Some alter or replace system files. These need careful handling and are best left to experts or automated tools.
  • One in particular can modify a certain setting in the registry, causing it to be executed before ANY program you run. removing this line stops you running ANYTHING! Again, this is best left to experts or automated tools to deal with.
The steps involved in removing a trojan are simple :
  1. Identify the trojan horse file on your hard disk.
  2. Find out how it is being started and take the necessary action to prevent it being restarted after a reboot.
  3. Reboot your machine and delete the trojan horse.
  4. See the Recovering from a System Compromise pages for more in-depth help on what else you may need to do.

Friday, 7 March 2014

"Girl killed herself" Facebook scam - be aware before you Share!

You know the saying about buses - you don't see one for ages, then three come along at once.
Facebook scams and hoaxes are a bit like that, except for the "you don't see one for ages" part.
But, judging by the most popular articles on Naked Security over the past couple of weeks, large-scale hoaxes and scams do sometimes come in threes.
A perfecta of long-running Facebook falsehoods has topped the charts recently.
Firstly, it was Talking Angela, the chat bot cat that was accused of all sorts ofdubious behavior - including behavior that isn't programmed into the software, couldn't have happened, yet was widely and regularly reported by people claiming "I saw it with my own eyes."
Secondly, it was the annual "Facebook will close from 29-31 February" hoax, circulated presumably as a joke but apparently taken seriously by some.
Now, it's the venerable "Girl killed herself video" bait-and-switch scam, already in its fifth year, that is making a reappearance.
→ Hoaxes and scams aren't the same, but they are similar in how they end up being shared over and over again. Generally, hoaxes are bogus warnings that spread because people forward them on the assumption that it's better to be safe than sorry. Scams are bogus links that spread because people forward them in return for some illusory benefit, such as access to an intriguing-sounding video.
We've written about the "Girl killed herself" video before, right back to 2010.
There are numerous variations on the theme, but the premise is often that a teenager committed suicide in shame after being caught out, perhaps by her own father, in some sort of inappropriate online activity.
There's a video, and you're invited to watch.
Here's how this sort of scam plays out, based on one of the versions circulating right now:
1. One of your friends Shares a link along the lines of "Girl killed herself live on cam."
2. It comes from a friend, so you click the link and arrive at a page that doesn't overtly claim to be affiliated with Facebook, but nevertheless uses visual clues to make it look more official than it is.
3. You're invited to Like the publisher's Facebook page, a request that seems routine and harmless enough:

4. If you take a look, the publisher's page was recently created and might best be described as uninspired and uninspiring, but it seems harmless enough, perhaps leading you into a false sense of safety. (Banality is a surprisingly good cover for scammers, when you think about it.)

5. You can skip past the Like popup, but before you watch the video, you are forced to Share it:
 6. And once you have shared it, you need to answer some questions as a sort of CAPTCHA - one of those tests to prove you're a person, in this case a person who's old enough to watch adult videos:
→ CAPTCHA stands for Completely Automated Procedure for Telling Computers and Humans Apart. CAPTCHAs are challenges that are meant to be reasonably easy for humans to work out, but tricky for computers to process accurately. Examples include reading fuzzy characters against a distracting background, or answering arithmetical questions written out longhand using words, not symbols.
Except that the questions to prove you are illegible are, in fact, pay-per-click surveys or special offer pages that clock up revenue for the scammers every time someone fills them in:

Saturday, 3 August 2013

5 Physical security tips for protecting your Devices





As we read earlier this week, the chances that one or more of your digital devices may get stolen are uncomfortably high. So what would happen if your mobile device falls into the wrong hands? Here are a few tips that will help minimize the damage if it happens to you.

1. Password-protect your computing devices.


While it sounds obvious, if anyone steals your device they will have to defeat your password to get at your data and accounts, which will significantly slow attackers. Although it is not impossible to defeat password protection on a digital device, it adds a useful layer of protection, buying you time to locate and recover the device.

2. Always backup your files.


Why? Even if you can’t recover a stolen device that does not mean you have to lose all your information and software. Regular backups are the ultimate defense against theft of your files. There are plenty of options for backup these days including online backup. (Here’s an example of an online backup service.)

My colleague David Harley has written about backup here on the blog and here is a link to Aryeh Goretsky’s white paper on the subject (.pdf). Taking the time to setup backup really pays off if a device is stolen, helping reduce the pain involved in re-creating the sensitive content.

3. Use tracking software to help get your stolen device back.


Why? Getting your stolen device back is not impossible, particularly if the device itself can tell you where it is and you can communicate with it using a sort of “remote control” via SMS or other methods. You may even be able to communicate with the person who has it. (Here’s an example of how one piece of anti-theft software for PCs.)

4. Don’t tempt thieves with unattended mobile devices, particularly in public places.


Why? Leaving your computer or mobile device unattended in a car, airport or restaurant is akin to asking for it to be stolen. In a recent survey we found that 1 in 5 stolen devices were taken from a car, 12% from an airport, train, bus, or other public transportation, and 11% from a restaurant or coffee shop. (Here’s an example of anti-theft software for Android devices.)

5. Encrypt sensitive data.


Why? Storing sensitive data in encrypted files prevents anyone exploiting your data if your computer is stolen. Note: File encryption is available free on recent version of both the Microsoft Windows and apple Mac OS X operating systems. This step is a lot easier than it used to be, so the pain level is low these days (unlike in years past).
Bonus tip. 

Think about removing sensitive data from your device.


Why? Your computer may interact with sensitive data but it does not need to store all of it right there in one place. Consider using encrypted removable media for sensitive data and carrying that separate from the computer. Maybe leave sensitive work files on the company network and access remotely over a secure connection. This way, if “bad things” happen, you’ll have much lower likelihood that the bad actors got off with critical information.