Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Conficker Worm Removal and Defense!


What is the Conficker Worm?

Microsoft released an update in October to resolve a critical security hole in the Windows "Server" service. Since people aren't as diligent about patching as they should be, hackers created a new worm that spread like wildfire, leaving systems completely under their control. Security researchers have determined that the virus is expected to go "live" on April 1st, 2009, causing your computer to do bad things—but since the worm uses a P2P protocol it's nearly impossible to identify the source.

How Does It Spread?

The worm originally started spreading using a network attack against the file sharing services in Windows, but since it can automatically update itself, it adapted to spread through the autoplay feature on removable media like USB thumb drives, by adding a new option to open where you see "publisher not specified". This allows the worm to spread to systems already patched against the original vulnerability, so using anti-virus software is even more important, because once it's on your computer it can spread further.

Exerpt from LifeHacker

More Info:
Microsoft
Fsecure
Symantech

Removal Tool Download:
Downadup Removal Tool - Symantec approved download.

Open Source Freebie Portable Keepass Ultimate Password Security!


I have been looking for that perfect password database program for quite sometime now. So after I saw Keypass on just about every website and blog on the internet and getting excellent reviews! I decided to download the portable edition and give it a try. I was absolutley impressed its one of those must have programs in my list now! If you are saving your passwords in Firefox that is VERY unsafe! Firefox has an addon that imports all your passwords from Firefox to Keypass in a click of a mouse! A new KeePass plug-in called ClockWork's Firefox to KeePass Importer was since developed specifically for this purpose. All you need to do is install the Firefox to Keepass Converter plug-in and the KeePass XML Import plug-in. It's still a multi-step process, but it's better than the old alternative and the developer has detailed instructions.

Download the newest portable version here:

http://downloads.sourceforge.net/keepass/KeePass-2.06-Beta.zip

KeePass database stores all your passwords inside of it in an encrypted state, and uses one master password and/or a key-file to access that database. KeePass has fields for username, password, URL and notes associated with each login, and you can create login groups (like, Windows, web sites, Wifi networks) to organize your passwords. KeePass is highly secure; if you keep it running, it will lock its workspace after a certain amount of idle time and require you enter the master password again to access the database.

Check this post at Lifehacker for several helpfull posts on Keypass! It may seem a bit complicated at first but once you set it up and tune it to your preferences its an amazing tool!
All in all Keypass is the ultimate password database to store all your private information for worry free computing!

Security Threats for 2009!


Twenty years after the release of the Morris Worm, one of the first worms discovered on the Internet, the Web has proven to be the primary place where bad guys lurk, looking for poorly secured websites to plant malicious code. And, they find plenty.

According to the 2009 Security Threat Report [PDF] from Sophos, one new infected Web page is discovered every 4.5 seconds. With that in mind, we thought we'd take a look at the top security threats you should be looking out for in 2009.

SQL Injection Attacks

The Sophos research showed that over the past year the number of SQL injection attacks against innocent websites increased, a trend Sophos expects will continue next year.

Web insecurity, notably weakness against automated remote attacks such as SQL injections, will continue to be the primary way of distributing web-borne malware.

A recent report from the Internet Crime Complaint Center also points to an increase in SQL injection attacks in 2008, specifically relating to financial services and the online retail industry. Unfortunately, cyber criminals prey on the needs of Web users at any given time, and this time the economic crisis is their meal ticket.

The article is well worth reading if you're interested in how attackers compromise websites by SQL Injection or if you want ideas on how to reduce the likelihood of intruders gaining access to your private data.


Third Party Advertising Agencies and Scareware

In February 2008, Sophos confirmed a 'poisoned Web advertising campaign' on BBC competitor ITV's website that affected both Windows and Mac machines. While we've all seen Scareware, the pop ups designed to scare people into buying anti-virus software, this is the first time it has been seen for the Mac.

According to Sohpos, a Flash file was injected into traffic served up by ITV.com via third party advertising agencies. Designed to promote a program called Cleanator (Windows) or MacSweeper (Macs), the programs claimed to detect "compromising files" and encouraged users to purchase a full version of the package.

As websites often use third parties to serve up their advertising, Graham Cluley, senior technology consultant at Sophos suggests taking care when selecting agencies. "Website owners should ask the third party agencies they use what procedures they have implemented to positively vet the adverts that they deliver for malicious content or unsavory links.


Social Networking Sites

With social networking on the rise, the bad guys have found yet another playground on the Web. The Sophos report reveals 1800 Facebook users had their profiles defaced in August by an attack that installed a Trojan while displaying an animated graphic of a court jester.

Gated sites appeal to the bad guys because they form a "launching pad" for mass distributing malware attacks and spam, like the recent Koobface Trojan which attacked both MySpace and Facebook and transformed victim machines into zombie computers to form botnets.

Twitter too has become a tool for cyber criminals to distribute malware and marketing messages. In many cases, the bad guys steal members' usernames and passwords and bombard the victims' friends with marketing messages or direct them to third party websites. With Twitter especially, it is difficult to discern where links are going due to the 140 character limit and the use of services that shorten URLs.

On the flip side however, Chris Boyd of FaceTime Security Labs at this years RSA Conference explained that social networking sites are incredibly useful for security researchers. "The people that create these things have been on social networking sites since the beginning; they need to be on them a lot to understand them intimately enough to exploit them. But many times they leave a trail online that we can use to track them, to find out things like their names, ages and friends."


Apple Macs Becoming "Soft Targets"

While Mac malware is miniscule compared to Windows malware, Sophos recommends Mac users follow safe computing best practices and avoid complacency even though cyber criminals are more likely to stick to attacking Windows computers in the foreseeable future due to the higher financial incentive.

With so many Windows home users seemingly incapable of properly defending themselves against malware and spyware, it seems sensible to suggest that some of them should consider switching to the Apple Mac platform. This is not because Mac OS X is superior, but simply because there is significantly less malware currently being written for it.

Along with the scareware attack mentioned earlier, there have been other attempts to infect Mac computers in 2008: the OSX/Hovdy-A Trojan, the Troj/RKOSX-A Trojan, and the OSX/Jahlav-A Trojan.



Smartphones: A New Toy for Cyber Criminals

While most malware and spam is produced as a result of financial incentive, with smartphones, Sophos believes malware will more likely be written by those wanting to make headlines. As neither the iPhone or the G1 has yet been the target of a significant attack, someone will want to be the first and claim the title.

Apple iPhone

According to Sohpos, iPhone users are more vulnerable to phishing attacks than their desktop counterparts for three reasons:

  • They may be more willing to click on links because entering URLs on a touch screen is more difficult
  • The iPhone version of Safari doesn't display URLs embedded in emails before they are clicked on making it more difficult to tell whether a link leads to a phishing site
  • The iPhone browser doesn't display full URLs making it easier for the bad guys to trick users

Google Android

Hackers are only just getting a real look at the Android OS so there is not much to report however, one security flaw was revealed only days after the G1 went on sale. The flaw, discovered by Charles Miller, a principal security analyst at Independent Security Evaluators, was in the browser partition of the phone. According to the New York Times, the flaw enabled keystroke logging software to be installed, making it an easy trick to steal identity information and passwords.

Additionally, while many are impressed with Google's open attitude to applications, others are concerned about the ease in which malicious software could be distributed and caution when it comes to downloading third party apps is advised.

Sophos predicts as more people purchase smartphones, creating threats will become increasingly attractive to cyber criminals: Imagine a generic Mac OS X attack made for the iPhone that could also cripple the Mac computer.


Other Interesting Stats from the Sophos Report

  • There were five times as many malicious e-mail attachments at the end of 2008 than at the beginning of 2008
  • The United States hosts the most malware on the Web at 37 percent
  • Computers in the United States relay the most spam at 17.5 percent

Cyber criminals will always be ahead of security experts simply because most of what the anti-malware providers discover is generally published for the public; the bad guys aren't as open with what they do. But, being aware of trends, keeping security patches up to date, and installing firewalls will do much to thwart the majority of attacks.

News Via - Read Write Web


Surfing Anonymously Xerobank & OperaTor!


My top pick here has long been Xerobank (aka TorPark), a special version of the Firefox browser that comes pre-configured to make use of the Tor anonymizing network. Now having looked at Opera Tor [1], suggested by subscribers Rob Fuller and Allan Marillier, I'm not so sure.

As you might have guessed Opera Tor is a special version of the Opera 9.21 Browser configured to use Tor. It's got some good things going for it. It's portable, it's smaller than Xerobank, it loads faster, it connects faster to the Tor Network and seems to run a little zippier as well. The Opera browser used as a base is more than a match for Firefox, with many features (including BitTorrent) built into the basic browser; features that need to be added as extensions to Firefox.

On top of that you get the excellent free mail client that comes with Opera. And it has another feature not available in Xerobank: the excellent Privoxy proxy server that provides powerful ad filtering, security screening and more. So with all of these pluses am I making Opera Tor my top recommendation? I would, except for a strange message that appears on eSnips, one of the two Opera Tor official download sites.

The message says "This file has been flagged by our users as inappropriate and is under review." I have no idea what this means and my attempts to have eSnips clarify it have not been answered. What I can say is that Opera Tor has passed all the malware tests on my PC and is also rated 100% clean by Softpedia. A Google search also came up with a blank.
Draw your own conclusions, but Opera Tor is now the product I'm using on my personal USB flash drive. Freeware, all Windows versions 6.4MB.

News Via: http://windowssecrets.com/

Opera Tor:

http://letwist.net/operator

Xerobank:

http://xerobank.com/


Hamachi vpn and outpost firewall (Info for all firewalls)

Here is what I finally did to get Hamachi under control of my firewall. I use Outpost Free on some, and Outpost Pro on others, but the rules remain the same. In fact, the rules should apply to any firewall.

First, there are a number of IP addresses that need to have rules. The ones I found are:

63.208.197.* — Level 3 Communications (Hamachi?)
239.255.255.250 — IANA
82.165.226.212 — RIPE
82.165.243.45 — RIPE

Those are public ip’s, needing rules for both UDP or TCP. Here is how my rules go:

Hamachi Home TCP Rule:
Protocol: TCP
Direction: Outbound
RemoteHost: 63.208.197.*
AllowIt

Hamachi Home UDP Rule:
Protocol: UDP
RemoteHost: 63.208.197.*
AllowIt

Hamachi IANA/RIPE UDP Rule:
Protocol: UDP
RemoteHost: 239.255.255.250,82.165.226.212,82.165.243.45
AllowIt

These rules are for Hamachi.exe. I found I also needed a rule for Svchost.exe. Since I have other rules for Svchost.exe, I found that I had to include this specifically for Hamachi.

Svchost Hamachi Rule: (svchost.exe)
Protocol: UDP
RemoteHost: 5.0.0.1
RemotePort: 67
LocalPort: 68
AllowIt

That should wrap up the rules needed for any application threads (.exe’s). Next, I turn to System settings. In Outpost, I do not allow outgoing DHCP. My WAN is a static ip in front of an NAT router.
I use static ip’s in my local network. I had to either allow outgoing DHCP (free version) or make a global rule (Pro version). The custom rule is this:

Allow Hamachi DHCP:
Protocol: UDP
RemotePort: 67,68,546,547
AllowIt

That takes care of getting connected. Next there are the local side of things to consider.

First and foremost, with XP SP2 I am constantly annoyed by the “Acquiring network address” symptom. Hamachi was driving me nuts with the limited connectivity of that. One solution was to start Hamachi offline, disable my nic, then enable it. Bye Bye acquisition. However, I now fix it by starting Hamachi and going online. Then I navigate regedit to [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\YOUR # HERE], and find the device that has the value “DhcpIPAddress” that matches my Hamachi address. Then I edit the IPAddress from 0.0.0.0 to the Hamachi address, and edit SubnetMask from 0.0.0.0 to 255.0.0.0. That fixes that. Note that these are NOT the Dhcp values, but the ones normally used for static ip’s. I tried to make the Hamachi adapter static, but it fails to finish connecting. No worries though, as this method gets rid of that “Acquiring network address” annoyance.

Hamachi appears to use a 5.x.x.x scheme for it’s ip addressing, so for network connectivity amongst other peers, you must make some more exceptions. In Outpost, there are 2 ways. One is to enable Netbios, and enter your peers Hamachi addresses into the allowed list. I prefer the Outpost Pro method, which is to make a global trusted zone and put those Hamachi ip’s in that. Either way, if you are blocking netbios you will not be able to file share and the like.

Hamachi also requests to open a connection to 169.254.132.178, which is an IANA net block address, from 169.254.0.0 to 169.254.255.255. I put a rule in effect to allow netbios communication with this ip range, but found it works without it, so I dumped it. Time will tell what use it plays.

That about covers what I had to do to make Hamachi compliant with Outpost firewall.

Credit to the original poster Mr.woo at this site

http://forums.hamachi.cc/viewtopic.php?t=283&postdays=0&postorder=asc&highlight=outpost&start=15&sid=d40d51faa3b3b87cd170733dfb262b7e

A Guide to Producing a Secure Configuration Using Outpost Firewall:http://www.outpostfirewall.com/forum/showthread.php?s=&threadid=9858

Basics of firewall rules! (Very good)

If you’re like me, your experience with software firewalls has primarily been an application is trying to receive/send some form of communication… do you wish to allow it?… we say yes/no, choose whether it should remember our answer, and life continues until the next prompt.

Not that there is anything wrong with that experience, that was the norm for our beloved firewalls of old… until one day we realize that the product(s) we’ve stuck with (or flipped between) hasn’t been updated for months/years, or is a resource hog, etc… and found ourselves searching for, finding, and installing Comodo Personal Firewall (CPF).

We open up CPF for the first time, see an Application Monitor, and get all excited like we found our comfort zone once again. And for the most part, we are right, but here is where our education begins, as Application Control Rules don’t operate alone… they require Network Control Rules (within the Network Monitor) to set the stage for all communication flow. (I think I have read this referred to as Traffic Shaping.)

Now we can bring a quick end to our education by using the Add a trusted zone Wizard (within Tasks) which will help create some core rules to let some basic communication flow in/out of our PC… but where is the fun in that? And what would we have learned?

(if you are interested in the learning curve I went through, check out http://forums.comodo.com/index.php/topic,1102.0.html)

So let’s start the education!

Now before we jump into Network Control Rule creation, let’s get the Rules Terminology straight.

Network Control Rule’s Terminology

Rule ID - sets the order Rules are applied. A communication attempt starts at the top of the Network Control Rules (ID 0), and works it’s way down through the Rules (unless stopped/blocked) until it finds a Rule that allows the comminication (unless blocked before it hits that Rule).

Action/Permission - when a communication attempt occurs, do we want to Allow or Block it?

Protocol - “A convention or standard that controls or enables the connection, communication, and data transfer between two computing endpoints.” Or more simply put, the type of communication (i.e. IP, TCP, UDP, etc…) http://en.wikipedia.org/wiki/Protocol_%28computing%29

Port - TCP and UDP protocols typically use ports to map data to a particular process running on a computer. As an example, a server used for sending and receiving email may provide both an SMTP and a POP3 service; these will be handled by different server processes, and the port number will be used to determine which data is associated with which process. http://en.wikipedia.org/wiki/TCP_and_UDP_port

Direction: Communication requests can hit our PC whether we’ve asked for it or not

  • Inbound Rule - defines unrequested inbound communication (for the selected Protocol)… like hackers probing our ports, or a friend on our LAN trying to join the FPS/RTS game we are hosting.
  • Outbound Rule - defines requested inbound communication (for the selected Protocol)… like opening IE, “requesting” google to load, and receiving the inbound homepage

Source IP - who made the request for communication (IP address or Range/Zone)

Remote IP - who is responding to a request for communication, or is the expected responder (IP address or Range/Zone)

*** For more verbose terminology definitions for these and other things, please refer to Ewen’s Internet and Networking Terminology for Beginners ***

One of the most important observations on the definitions above (other than the heirarchy of the Rules set by the Rule ID) is that both InBound Rules and OutBound Rules both control information comming into our PC. InBound Rules deal with incoming information/communication we didn’t ask to happen (but may want to happen), while OutBound Rules deal with incoming information/communication we asked to happen.

Ok, assuming that my definitions are well in hand, let’s start putting some of them together; specifically showing how Source and Remote relate to Inbound Rules and OutBound Rules.

Source

  • InBound Rules use Source to define who is trying to send our PC information. Like another PC on our LAN, or a hacker sitting in his/her mom’s basement on some other continent. Smiley
  • OutBound Rules will always have a Source of our PC (whether we specifically set its IP address, its subnet / Zone, or use Any)… when we launch IE to browse Google, it is us on our PC making the request to open the webpage.

Remote

  • InBound Rules will always have a Remote of our PC (whether we specifically set its IP address, its subnet / Zone, or use Any)… whether its another PC on our LAN looking for Shares/Printers or to join a game hosted on our PC, or the hacker in his/her mom’s basement, ourt PC is the expected responder.
  • OutBound Rules use Remote to define who is the expected responder to our request for communication/information… the rule needs to know we are expecting google to respond to our request to load the google homepage.

On with some Rules!

Alright, I think we have enough to try creating our first Network Control Rules. So let’s think about what we want, then try using the building blocks of the Rules (our terminology definitions) we’ve looked at to create a rule for it.

Rule A
Where should we start? How about keeping that hacker, probing for ports, off our PC? Good plan! I like how you think. Smiley

I want to… Block attempts by an hacker (outside my network/PC) from reaching my PC, regardless of what protocol they try use.

Using the Rule building blocks: (after selecting to Add a new Rule)
Action: Block (we want to make a rule to stop the hacker) (I also suggest checking the “create an alert if this rule is fired” option so that attempts [good or bad] blocked by this rule are logged)
Protocol/Direction: IP In (The hackers communication attempt will be one we didn’t request to occur)
Source IP: Any (I know what your thinking… we said we wanted to stop communication from outside our network, and Any would also mean the LAN!! Good observation. We’ll need another rule to fix that by allowing the LAN communication before it hits this Block All catch rule… so let’s make that rule next [Rule B])
Remote IP: Any (remember, InBound Rules will always have a Remote of our PC [whether we specifically set its IP address, its subnet / Zone, or use Any])
IP Protocol: Any (regardless of what protocol they try and use. Did you notice when you selected Any from the dropdown list here all the protocol types Any covers?)

And there is our First Network Control Rule!

Rule B
So we discovered that Rule A was pretty agressive and even Blocked our LAN. But remember what we learned about Rule ID’s and the order Rules are applied? If we put a new Rule (Rule B) before Rule A that Allows other PC’s on our LAN to send communication requests, we should be Ok, right? Right. Wink

And what if you aren’t on a LAN? Then this rule means nothing to you.

Note: Now before we get started on this Rule, I want to mention something useful that we’ll want to make sure we have set. I don’t know about you, but I don’t want to have to type the IP addresses (or ranges) for the PC’s on my netweork when I’m defining Rules, so unless you have a [LAN] or [Home Network] Zone defined, please do that now by switching to the Tasks tab, and pressing the Add a New Zone button… give it a name and a start/end range. Good!

I want to… Allow all requests for communication from other PC’s on my LAN to my PC

Using the Rule building blocks: (now we could select to Add a new Rule and move it above Rule A, or you could right-click Rule AAdd RuleAdd Before [either way works])
Action: Allow (we want to make a rule to let the other LAN PC’s make requests to us)
Protocol/Direction: IP In (The LAN communication attempt will be one we didn’t request to occur, but we expect that)
Source IP: Zone: [LAN] (Any PC on our LAN can now send our PC information/requests)
Remote IP: Any (remember, InBound Rules will always have a Remote of our PC [whether we specifically set its IP address, its subnet / Zone, or use Any])
IP Protocol: Any (All request/communication types [similar to Rule A, except this time we are Allowing])

And there is our Second Network Control Rule!

Rule C
So far we have set the way we want CPF to handle incoming communication to our PC that wasn’t requested by us. So I guess our next rule should take care of incoming replies to requests we made for communication, like to support our IE/Firefox requests for webpages, or us trying to join a friend who is hosting a LAN game.

I want to… Allow responses to come back to my PC from anywhere (the Web or the LAN) that were requested from my PC.

Using the Rule building blocks: (just as with Rule B, we could select to Add a new Rule and move it above Rule A, or you could right-click Rule AAdd RuleAdd Before [either way works])
Action: Allow (we want to make a rule to let our PC receive a response to a request it made)
Protocol/Direction: IP Out (We are starting a request that will return a response)
Source IP: Any (remember, OutBound Rules will always have a Source of our PC [whether we specifically set its IP address, its subnet / Zone, or use Any])
Remote IP: Any (let the responder to our request come from anywhere, LAN or Web)
IP Protocol: Any (All request/communication types [similar to Rule B])

And there is our Third Network Control Rule!

Rule D
Now sometimes a response to our communication request is going to come in on a diferent port. Take Bittorrent for example, we request a file and the download starts on a predetermined/configured TCP/UDP port, i.e. 6881 by default. For each file we want to download simultaneously, we need a new TCP/UDP port, i.e. to download 4 we would need 4 ports… 6881, 6882, 6883, & 6884. Similar to opening the ports on our Firewalls/Routers (without the need for forwarding, as the communication is already comming into our PC).

I want to… Allow requests for incoming TCP/UDP communication (on ports 6881, 6882, 6883, & 6884) from any PC on the web to my PC

Using the Rule building blocks: (just as with Rule B, we could select to Add a new Rule and move it above Rule A, or you could right-click Rule AAdd RuleAdd Before [either way works])
Action: Allow (we want to make a rule to let requests be made)
Protocol/Direction: TCP/UDP In (Even though we asked to dowload a file [feels outbound], the response is coming back on a different port than our request; therefore, it is going to look like the remote PC is trying to request in inbound communication)
Source IP: Any (Let the request come from anywhere… somewhere on the web in this case)
Remote IP: Zone: [LAN] (remember, InBound Rules will always have a Remote of our PC [whether we specifically set its IP address, its subnet / Zone, or use Any])
Source Port: Any (we don’t care what port it left the remote PC on in this case)
Remote Port: A set of ports [6881,6882,6883,6884] (we only want to allow the remote PC to sent to the ports we configured Bittorrent to use)

And there is our Fourth Network Control Rule!

Hopefully this has been enough combinations to give you the basis for thinking of new Network Control Rules you may need to define.

Tracing Unexpected Internet Activity!

One of the most unnerving computer experiences is to notice sudden unexpected internet activity from your PC when you’re not using the internet at the time.

It can be brought to your attention several ways; for example the lights on your modem might start blinking furiously, your firewall may indicate internet activity or your download/upload monitor could show that a lot of information is being received or transmitted.

When this happens to me, the first thought that goes through my mind is that a malware program may be “phoning home” to some remote PC divulging all my personal information.

Now I know this is unlikely because my PC is well protected but I know enough about security to know that it’s possible. So whenever this happens I immediately investigate what’s happening. So should you; in the following paragraphs I’ll show you how.

When you are connected to the internet you are not connected at one point but at multiple points. These different points are called ports. Data can flow in and out each of these ports. It’s a bit like the way flies get into your house. They can get in (or out) the front door, the back door, the windows or the chimney. These openings in your house are just like the ports in your computer.

There can be up to 65000 ports on your computer but normally these are shut. When you start a program that connects to the internet such as your web browser, that program opens one or more ports to make the connection.

So when you computer shows signs of unexpected internet activity what you need to do is to track down what ports are open and then identify the programs that opened those ports.

There’s a whole class of utilities called port enumerators that will do this job for you. In fact, there are more than a dozen such programs currently available. Additionally, many firewalls and most anti-trojan programs have in-built port enumerators though these are often quite basic.

I’ve looked at most of these products and found two that are outstanding:

My favorite free port enumerator is called CurrPorts from Nirsoft. It works best with Window 2000 and later though Windows 98 users can still use the product with less information displayed.

CurrPorts, like all port enumerators, shows all the ports that are currently open on your PC. It also shows you the process that opened each port and the time the port was opened. Most importantly it flags in pink, any suspicious ports.

Now “suspicious” here just means worth checking. However this flagging makes the job of interpreting results much easier for less experienced users.

CurrPorts also allows you to track down the remote site a particular port is connected to. If it’s somewhere like North Korea, China or Romania you have a problem.

If you do have a problem CurrPorts allows you to immediately shut down that port. That reduces the potential damage but of course doesn’t solve the problem. To do that you need to find the malware program responsible.

How you do that is unfortunately, beyond the scope of this article. As a quick guide I suggest you download HijackThis from the link below and follow the instructions on the same page how to paste the output to the Tom Coyote web forums.
http://www.tomcoyote.org/hjt/

The folks on the forum should be able to help you permanently get rid of the problem and it won’t cost you a cent either.

CurrPorts is a great product but it has one weakness; it doesn’t tell you the amount of data flowing in and out the open ports on your computer.

This is a really important piece of information when you are trying to track down sudden unexplained internet activity. There may be dozens of open ports on your PC but what you want to know the ones that are currently being used to transmit or receive data.

I couldn’t find any free port enumerator that provides this information but there are two shareware products that do: Port Explorer from Diamond Computer and TCPView Pro from SysInternals.

Port Explorer is the standout pick. Port Explorer works with all versions of Windows and a home license is $29.95. Simply put, it’s the best port enumerator I’ve ever used. Port Explorer does pretty well everything that CurrPorts does and more. It combines ease of use with great power; a rare quality in technical utilities.

In this context its greatest ability is to show for each open port, the amount of information being transmitted and received. The display can even be sorted on this criterion so the ports moving the most data appear at the top. This makes
identification of the culprit program really easy.

Once the cause of the internet activity has been identified Port Explorer provides a whole raft of tools to help you identify the remote computer using the port. It even includes a packet sniffer so you can see what information is being transmitted.

Both Port Explorer and CurrPorts can provide you with the information you need to identify the cause of unexpected internet activity. I suggest you check out both and go with the program that best suits your needs. Whatever, every experienced user should have a port enumerator installed on their PC ready and waiting to track down those mystery internet connections. You may only occasionally require such a product but it’s a great comfort to have one on hand when you really need it.

CurrPorts: http://www.nirsoft.net/utils/cports.html
Port Explorer: http://www.diamondcs.com.au/portexplorer/

Guide to Securing Your PC!

In today’s climate what is the best approach to avoiding getting your PC infected with malware? Here are some simple steps you can take to ensure viruses, trojans, keyloggers and other nasties don’t take control of your PC

After spending years testing security products I’ve learned an important lesson.

Don’t get infected by malware.

In other words, put maximum effort into preventing infection rather than detecting and removing infection.

This statement may seem bland and unremarkable but there’s more to it than you think.

The traditional way of adding additional protection

For a long time I’ve advocated the best way of protecting your PC was by using multiple security layers based on anti-virus, anti-spyware, anti-trojans, HIPs and other security software.

It’s still a sound approach but I’ve come to believe that for most folks, the cost is too high and the additional protection afforded too little.

The cost here is not so much financial though that is an issue, but rather the serious impact adding many security layers can have on the performance of your PC.

There is also a cost in complexity. The more security programs you run the more chance they will either interfere with each other or with other programs.

Each additional layers you add increases your protection but by an incremental amount only. A good anti-virus program may offer 95% protection. Adding a good anti-spyware utility may increase this to 97%. The addition of an anti-trojan may take it to 98%.

This is because today’s security products overlap in function much more than they used to. A modern anti-virus program will detect a lot of spyware while a modern spyware program will detect some viruses, worms and trojans as well.

Although the protection achieved only goes up incrementally with each layer added, the processing load on your PC will rise more or less in proportion to the number of layers. So using adding an anti-spyware layer to your anti-virus layer will double the load on your PC. Adding in an anti-trojan as well may well triple it.

So folks, while layering is a good thing we are faced here with a law of diminishing returns.

But that’s not the only problem with the traditional layering approach to protection. If an aggressive malware program is allowed to run on your PC it may disable all your layers of protection rendering them useless.

I’ve seen it happen many times and it is a frightening sight to see all your security programs icons disappear from the system tray

Thankfully some security programs resist termination by hostile agents but the majority don’t. And even those that do resist may well prove vulnerable to new, more advanced termination methods yet to be developed by malware programmers.

My approach these days is simple: if you allow malware programs to run on your PC don’t expect your security programs to fully protect you. If you are lucky they will but with security, you shouldn’t rely on luck.

So how do you prevent infection?

The basics

  1. Ensure you keep Windows and MS Office completely up-to-date by applying the latest fixes from the Microsoft Update Service.
  2. Make sure your other software products are also fully updated, particularly popular products like Firefox, Opera, the Adobe Reader, Sun Java, Flash plug-ins and media players. The easiest way to do this is to use the free Secunia Software Inspector
  3. Be carefull where you surf. In particular stay away from sites offering commercial software serial numbers, keygens and other hacked material. Avoid accidentally wandering to hostile sites by installing McAfee Site Advisor, a free browser plug-in that appends site security ratings to search engine listings.
  4. Never click on email attachments from untrusted sources however tempting and attractive such attachments may seem. Similarly, never click on links in email from unknown correspondents.
  5. Never install programs unless you are fully confident they are clean. In particular, only download files from trusted sources and never install programs that friends give you on removable media unless you have verified that are clean by submitting them to free web based testing services such as Jotti and Virus Total.
  6. Install a robust firewall to ensure worms can’t secretly enter your PC via the internet. My current favorites are the free Comodo firewall and ZoneAlarm Pro but there are several other excellent choices including Jetico and Netveda to name but two.

These basic measures are surprisingly effective in keeping your PC free from infection. Indeed, I’ve known users who follow these rules and don’t use any additional security products yet have never had a malware infection.

However, sticking to these rules is not easy; it requires a level of discipline most users don’t have. Who hasn’t been tempted to open a funny PowerPoint email attachment or install a free game?

And it’s not only a question of discipline. These days you can get infected simply by innocently surfing to a hostile web site or opening a “loaded” MS Office document. You need more protection that the basic security rules can provide.

Protection is better than cure

The best way to increase your level of protection is to make sure that if a malware program sneaks its way on to your PC that it is never allowed to run on your PC in a normal Windows environment.

A normal Windows environment is a user account with full administrator rights. It’s probably what you are using right now as it is the default setup in all recent versions of Windows up to but excluding, Windows Vista.

There are three way you can keep malware well away from your normal Windows account.

  1. Use a Windows limited user account for your daily work
  2. Run all high risk programs with limited rights
  3. Run all high risk programs in a sandbox or virtual machine

Each method has its pros and cons so let’s look at them individually.

Option 1: Use a Windows limited user account for your daily work

Using a limited user account can be very effective in preventing malware infection as most malware products need full administrator rights to install themselves. In a limited account they just can’t get a foothold.

It’s easy to set up a limited user account. Just go the Control Panel, select User Accounts and create a new user account as a limited user. Then sign in to this account for your normal computer work rather than the account you a currently using

Setting up a limited account may be easy but using it can be a real pain. For example you won’t be able to install most programs. You won’t be able to update others. You won’t be able to access any part of the PC other than your own documents and the shared documents area. Heck, you won’t even be able to change the system date!

Some folks can work with these limitations or work-around them by swapping to a full privilege administrator account when they need to install programs or do other more advanced tasks. Others use the Windows “Run as” command and similar utilities to temporarily elevate their privileges when needed.

Most users though, find using a limited account to be simply too awkward and inconvenient. Sure. their computer is safe but that’s little comfort if their PC is only barely usable.

That said using a limited account is an excellent solution for advanced users prepared to tolerate the inconvenience or ordinary users with basic computer needs. If Granny never does anything but check her mail and browse to newspaper sites to read the headlines than setting her up with a limited account is a good way to go. Do expect phone calls though; one day even Granny is going to need to do something that requires administrator privileges.

Option 2: Run all high risk programs with limited rights

This is a more practical strategy. Run as a full administrator user but restrict the rights of all programs such as your browser and email client that can be sources of malware infection.

Getting this to work could be a complex business but thankfully there are some free utilities available that were written to perform this exact task.

The best known of these is DropMyRights. It allows users to easily create special versions of their browsers, email clients IM client, media player or other internet facing programs that run from a full administrator account but with the restricted rights of a Windows limited user.

It’s a simple and neat solution that provides good protection from infection yet doesn’t inconvenience the user in the same way as working from within a limited user account. I’ve written a practical guide to running programs using DropMyRights. You can find it here

The approach however has some weaknesses perhaps the worst of which is downloaded files. Yes you are safe from infection while using a browser but if you run any files you download then you can easily be infected if those files contain embedded malware.

There’s no easy way of getting around this either. However our next solution provides the perfect answer.

Option 3: Run all high risk programs in a sandbox or virtual machine

The strange name “sandbox” derives from the Java world where it refers to the highly contained and restricted environment in which Java programs (applets) are allowed to run. They are allowed to “play in the sandbox” but not go outside it. The important point is that while running in the sandbox, the programs have no access to your PC.

So it is with sandbox security programs. While browsing or engaging in any computer activity within the sandbox you are totally corralled off from your other parts of your PC. Any files you download are isolated to the sandbox. Similarly, any programs that are executed only do so within the sandbox and have no access to your normal files, the Windows operating system or indeed any other part of your PC.

That means that if you get infected by malware while using the sandbox your “real” computer is nor affected. Furthermore you can close the sandbox and all that’s within it is erased including any infections, leaving your real PC in a pristine state.

Sandboxing is a great security solution for preventing infection. There are also some excellent sandboxing programs around including my favorite, the donationware utility “SandBoxie.”

There are some downsides. Sandboxing creates a two-worlds view of your computer and this confuses some users. It is not necessarily always clear whether at a given moment you are working in the sandbox or not. Overcoming this potential confusion requires users to be attentive and disciplined. If they get it wrong and think they are surfing in the sandbox when they are not it’s possible to become infected.

This confusion is particularly evident with downloaded files. Files in the sandbox are not really permanently on your computer unless you deliberately move them from the sandbox to your real PC. If you shut the sandbox without moving them they will be lost forever.

This two-worlds view is simply too confusing for some users. With sandboxing, a confused user can be an unsafe user.

There are other problems too. Sandboxing is only available for PCs running Windows 2000 and later. Furthermore sandboxing can create problems on some PCs. Indeed I’ve known PCs to seize up totally with a sandbox installed. Luckily though, this is not common.

Virtual machines such as VMWare and Microsoft’s Virtual PC are similar to sandboxing but take the idea one step further by completely separating the virtual machine from the real PC at a conceptual level. Rather than have a sandbox as part of your real PC you have a virtual PC that is notionally fully distinct from your PC.

This difference aside these two virtualization models have a lot of similarities. Infections that are incurred in the virtual machine cannot affect the real PC. Similarly shutting down the virtual PC removes all trace of infection.

Unfortunately they also share the same user confusion: “Am I in my real PC or the virtual one?”

The greater separation provided by the virtual machine approach does offer more robust security model than sandboxing but it comes at a cost. Virtual machines consume a lot of memory and a have a fair degree of processing overhead compared to sandboxing. And moving between the real and virtual machines can be more awkward than with sandboxing. Like sandboxing virtualization can be troublesome on some PCs.

From a user’s perspective sandboxing is the more attractive option though IT professionals would probably prefer the greater flexibility and superior isolation offered by virtual machines. I’ve written a practical guide to surfing using a sandbox which you can find here.

Security wise both offer excellent protection from malware infection. The protection is so good that disciplined users don’t really need many other security products to protect them.

Indeed all you need is a good firewall and a good anti-virus program. Combine these with a good sandbox and you will have better security than other users who employ five or more different layers of active security software protection.

Even better your PC will run fast; a complete contrast to machines running multiple security products.

What about on-demand scanning?

OK I’ve come out heavily against running multiple active security products but what about passive security products like on-demand scanners?

An on-demand scan is one you manually initiate. It may be an anti-virus scanner, an anti-spyware scanner, a rootkit detector or a keylogger scanner.

I’m all for on-demand scans as, unlike using products that employ active monitoring, they don’t impose an on-going overhead on your computer. The only computer power they consume is while they are actually performing a scan.

Take for example a good anti-spyware scanner like the free version of AVG Antispyware or the excellent free Panda Anti-rootkit detector. They consume virtually no computer power unless you actually run the programs. And because they are not constantly running they are less inclined to cause any problems with other programs.

So by all means runs on-demand scans periodically: weekly, monthly whatever. They are a good backstop to your Anti-virus program.

Conclusion

When it comes to today’s aggressive malware programs, preventing malware from ever getting on your PC is a better strategy than trying to intercept it when it tries to run.

You can prevent malware getting on your PC by combining safe computing practices with other techniques such as reducing the privileges of high risk programs, sandboxing and the use of virtual machines.

Reducing the privileges of high risk programs is a simple workable solution for most users. Sandboxing and virtualization offer a more complete solution but are not entirely free of practical problems. For those who can work with these problems, sandboxing and other virtualization solutions offer the best way currently available to prevent malware installing itself on your PC.

With these elements in place the only active security software you really need are a good firewall and broad spectrum anti-virus program. That said you can, indeed should, supplement these with periodic on-demand scans of your PC with a good anti-spyware product and a good rootkit detector. These on-demand products won’t impose the on-going overhead you would incur with security software that uses active monitoring.

None of this comes without cost. Defensive computing requires time and discipline. Users not prepared to put in the effort are advised to stay with a layering strategy using multiple security products.

For me, the days of running five or more active security software products on my PCs are over. Your Grandmother was correct, an ounce of prevention is worth a pound of cure.

How to Improve Your Security When Using a Public Terminal!

Using a hotel computer, one in an internet cafe or airport is a risky business. Public terminals are fine for general browsing and even (with a few precautions) collecting your email but when it comes to logging in to your bank account or making an online purchase they really should be avoided.

We all know that but life doesn’t always allow us to follow the rules; sometimes we simply have to use a public terminal to conduct a confidential transaction

Well I’d dearly like to be able to tell you a way you can use a public terminal with complete safety. I can’t. What I can do is show you some ways you can do it with a high degree of security. OK it’s not 100% but it’s better than no security at all.

There are two main areas of risk when using a public terminal. First someone may be using a session logger to record the flow of data between the PC you are using and the websites you visit. Second there may be a keylogger fitted to the PC that allows someone to capture your keystrokes and sometimes your mouse clicks and screen session as well.

Risk 1: Session Logging

It’s dead easy for an ill-intentioned internet cafe operator to record your internet traffic. Indeed I once visited a cafe and noticed the clerk at the front desk was unabashedly scanning traffic from the shop’s computers using Ethereal. So believe me, it happens.

It’s important that you understand when you a visiting a normal website that most of the information that flows between the PC you are using and the website you are visiting is visible and readable. It’s there for anyone to see. “Anyone” includes your ISP or the clerk in the internet cafe.

If you are visiting a secure website (i.e. one whose address begins with https rather than http) your data stream is secure. That’s because your data is encrypted end to end i.e. PC to server. Yes, it can still be seen but all that can be seen is a lot of gobbledygook.

If you use Gmail or Yahoo! webmail this is good news as both of these have secure website connections. The last time I used Hotmail it wasn’t secure and many other webmail services aren’t secure either. It’s easy to tell: go to your webmail site and login. If the URL in the browser address bar starts with https it is secure. That means you can read your mail on any public terminal and no one can read your mail by intercepting the traffic between the PC you are using and the webmail service.

If your webmail service uses http rather than https then your email can be intercepted and read. If your email only includes things like a get-well message to Aunt Maud then there is no problem but if it contains your social security number, bank account and other personal details then you should start worrying.

Almost all online banking sites and e-commerce sites use https. That’s comforting as it means no one can read your confidential data flowing between the computer you are using and the remote server. Sure they can see the data flow but they can’t decrypt it.

Defensive counter-measures against session logging

There are however, a number of ways to convert even a standard http into a secure encrypted https connection. Using a virtual private network is one way but that’s an option more readily available to corporate users than individuals. A simpler solution is to use a secure anonymizing network like the free Tor system.

Although Tor was designed to allow you to surf anonymously it has an attractive side benefit: it creates a secure https connection between your PC and the first Tor server. It’s not secure beyond the first Tor server but interception is most unlikely once you get beyond the first server. The most likely location for someone to look at your web traffic is between the PC you are using and the first Tor server.

Setting up Tor is simple if you use a product like the free Firefox based XeroBank browser (formerly TorPark). Just start up XeroBank and the rest pretty well happens automatically. XeroBank is also portable so you can safely browse from a public terminal using a copy of XeroBank installed on your USB flash drive.

Surfing with XeroBank is noticeably slowed by the long chain of Tor servers through which your data passes. However a little extra time is a small price to pay for the additional security and anonymity. Besides if you really need speed you can switch back to normal non-secure browsing easily within XeroBank.

If you use XeroBank you can safely read your email even for non-secure webmail websites like HotMail. Whether the content of your webmail warrants the effort involved only you can decide.

I should note in parting that SSL (and thus https) is not immune to decryption. In particular so called “man in the middle attacks” have proven effective. However this kind of advanced attack is highly unlikely in an internet cafe.

Risk 2: Keyloggers

There is no 100% safe way to enter passwords from a public terminal. That’s a fact.

Modern keyloggers can capture not only keyboard strokes but mouse clicks and the Windows Clipboard. They can also take screen shots of what you are doing. Keeping your confidential information from the prying eyes of the best of these sinister products is extremely difficult, perhaps impossible.

So the golden rule is don’t ever enter confidential information into a hotel computer, an internet cafe PC or other public terminal.

That’s the rule but rules get broken. Sometimes we simply have to use a public terminal. I have and I bet most of my readers have too.

So what can you do to improve your security when entering passwords?

Quite a lot actually. Of the many different options available to improve your password security to me the most attractive is to enter your passwords using a password manager like RoboForm2Go running from your own USB flash drive. It’s an option I covered in my May 2007editorial column.

When run from a USB flash drive RoboForm2Go provides excellent security. In fact I’ve not yet found a keylogger that can capture the information it enters into login boxes and web forms from Portable Firefox. Don’t take that to mean RoboForm2Go is 100% safe. It’s not; no product is.

One particular area of weakness of RoboForm2Go is the master password you must enter to activate the password manager. If a keylogger captured that and also managed to copy the encrypted RoboForm master password file from your USB drive then you are in deep trouble as they would be able to access all your passwords.

So protecting that password is critical. Some special issues apply to protecting your RoboForm2Go password and they are addressed later in the article. Let’s first look at the question of protecting passwords in general.

Defensive counter-measures against keyloggers

(a) Use strong passwords

Make your passwords (or passphrases) long and semi-random. Passwords like “SncnGnls3Fp” are much better than something like “banana”. This is not only because long random passwords are more difficult to crack but also because they are more more difficult to unscramble from a keylogger log particularly when used in concert with some of the other techniques mentioned below.

Remembering long semi random passwords is difficult but there are lots of mnemonic systems that can help.

By way of example the password “SncnGnls3Fp” I mentioned above is actually “RoboForm2Go” transformed by a simple formula where the first letter is shifted one forward in the alphabet (R -> S) while the next letter is shifted one back (o -> n). The same alternating pattern continues for the rest of the characters.

There a lot of different techniques for creating and remembering strong passwords and phrases. You can find some in this Microsoft article. Also worth consulting is this Wikipedia article on password strength.


(c) Use password obfuscation

Obfuscation is just a fancy way of saying you can should disguise your password by entering it in more complex way than just typing it in from the keyboard.

Obfuscation works because keyloggers just record a long string of the characters you type. At some point the owner of the keylogger has to scan the string to identify passwords so you want to make this task as hard as possible.These days keyloggers make identifying passwords easier by labeling the name of the window where the keystrokes (and mouse click) were made. Even so, obfuscation can still be very effective

There are many ways of obfuscating input. Here are a few:

(i) Where you have two entry boxes on the screen such as a username and password, alternate entry between the two fields after each character is typed by using using your mouse to move between the entry fields

(ii) Rather than just entering the password from the keyboard cut and paste some of the characters that make up your password from another part of the screen. Ideally this should be from the same window as the one containing the password field but other windows will work fine too.

(iii) Drop and drag and drag some characters rather than enter them from the keyboard

(iv) Enter some character by holding down the Alt key and using the numeric keypad. For example the letter “a’ can be entered by ALT 123.

(v) Use an onscreen keyboard to enter some of the characters.

(vi) Enter the last half of your password first followed by the first half. Then drop and drag the second half to the front from inside the password box.

(vi) Insert some random characters

For simplicity lets say your password is abcdefg.

Rather than enter your password as a simple sequence of letters throw in some additional dummy random characters along these lines: aMNbOcZdPQReSfgTUV

Now go back and delete the dummy letters one at a time. Delete some characters using backspace, others using the mouse to highlight the letter(s) and the then hitting the Delete key or using the right click context menu and selecting “delete.”

Obfuscation works

By combining the dummy character trick with the various multiple entry techniques you can confuse pretty well any keylogger.

However don’t feel you have to use every single obfuscation trick I’ve mentioned; that’s overkill. Indeed you may not be able to use all these techniques as some sites and products limit what you can do do. For example RoboForm2GO disables cut and paste as well as drop and drag when you are entering the master password. It also won’t allow you to access (get focus in) any window other than the password box. However you can still enter and delete dummy characters as well as entering characters using the Alt (numeric keyboard) trick and combined with a long random password that’s good enough.

It’s enough because any hacker reading a log from a keylogger has to read, identify, analyze and re-assemble what’s recorded. That’s hard work. If you use long random passwords combined with even a few obfuscation techniques then almost certainly you’ve made the job too hard. Possible yes, but too hard, specially when there is easy picking available elsewhere.

But you can increase your security further. use an on-screen keyboard.

(d) Use an on-screen keyboard (OSK)

An on-screen keyboard (OSK) is, as its name implies, a screen version of a normal keyboard where you “type” characters by clicking with your mouse the appropriate key on the screen. Windows has an OSK built-in that can be accessed from Start / All Programs / Accessories / Accessibility / On Screen Keyboard or alternatively from Windows key + U.

Now many folks think that using an OSK to enter password data is more secure because a keylogger can’t capture the keystrokes. Unfortunately this is only partly true.

First some OSKs (including the Windows OSK) simply emulate actual keystrokes and these can be recorded by many keyloggers. Second anyone can see what you are entering with an OSK by simply taking a screen movie or even a rapid series of screen shots. Third by recording mouse click coordinates it may be possible to deduce the characters entered with an OSK. Finally it may be possible to capture the password from the OSK using a clipboard monitor when you copy the OSK entered password into a password form field.

That’s the bad news. The good news is there are some OSKs that don’t emulate keyboard input. Two of these are free, portable and specifically designed for secure entry. The first is Neo’s SafeKeys; the second is Monitor Only Keyboard (MOK)].

SafeKeys has some nifty features such as the ability to start up in a different screen position and with a different size every time you run it. This effectively defeats mouse click loggers. It also allows you to drag and drop the entered password into a web form thus bypassing clipboard loggers.

MOK has its own charms: it disables clipboard logging and has the option of a variable key layout. It doesn’t support drag and drop but the copy implementation results in equal security to SafeKeys.

So on balance, there is little between the products; each is a perfectly viable solution. Unfortunately both are still vulnerable to screen capture. However a screen capture program would have to take very frequent snaps or a continuous movie to successfully capture all your virtual keystrokes. That’s possible, though the host PC would take a big performance hit in the process.

But there is a simple way of getting around screen capture programs: enter part of your password with an OSK and the remainder with the real keyboard. Combine the keyboard entry with a little basic obfuscation and you have a pretty secure solution.

Protecting your RoboForm2Go Master Password

There are some special problems involved in protecting your RoboForm master password when using Roboform2Go from a USB flash drive connected to a public terminal.

Before I address these I want to state that I strongly recommend using RoboForm2Go for safely accessing password-protected websites. It’s one of the easiest and most valuable steps you can take to improve your mobile security.

With RoboForm2Go, all of your website passwords are safely encrypted on your USB flash drive, and it’s virtually impossible for anyone to decrypt the information from the stored files.

Impossible, that is, unless they have your master password. And there’s the catch.

To use RoboForm2Go you must at some point, enter your master password. If attackers use a keylogger to capture that password and also copy your RoboForm2Go password files from your USB drive, then they will have complete access to all your passwords. Hardly a pleasant thought.

So protecting your master password is absolutely critical.

In recognition of this problem, Siber Systems, the developer of RoboForm, has implemented some features that make it more difficult for keyloggers to capture your password.

First, they disable copying text from the master password window. Second, they disable drop and drag. Third, the password entry window contains no text, only graphics. Finally, and most importantly, they include in the password window a link to a special screen based keyboard (MOK) that allows you to enter your master password using mouse clicks.

Frankly, the first three of these measures are of limited benefit. They don’t stop most keyloggers and, unfortunately, limit the range of obfuscation measures you can use to disguise your master password. You can’t, for example, use the highly effective technique of dropping and dragging part of your entered password from the end of the password to the start. Nor can you cut and paste text from within the master password window or type dummy characters elsewhere in the window.

So these RoboForm security measures are really of limited value. So limited that I’ve been able to capture the RoboForm master password in every keylogger I’ve tried.

These particular measures may be limited in value but the MOK built into RoboForm2Go is much more useful. It’s quite a secure implementation, unlike the inbuilt Windows MOK.

In total contrast to keyboard entered passwords, I’m yet to find a single keylogger that can pick up passwords entered by the RoboForm MOK.

But there’s a small catch. While a keylogger may not be able to grab your password, a screen session recorder can. That’s because the RoboForm MOK indicates visually each time you click a “key” with your mouse. This makes your MOK password entries plainly visible on a screen movie.

It would have been much smarter for Siber Systems to have indicated a keyboard press with a sound from the PC speaker and have no screen indication at all. That way a screen session recorder would only show the movements of your mouse over the keyboard without showing what “key” you actually clicked.

That’s the bad news. The good news is that the hostile use of screen session recorders is rare compared to the use of keyboard keyloggers. In fact, very rare. That’s because taking a live screen movie consumes a lot of computer resources. So much that the computer would be really slowed down and the presence of the keylogger made obvious.

Periodic screen snapshots are, however, reasonably common in keylogging programs. That’s because they take far fewer resources than a video, yet still reveal a lot. Fortunately, they are most unlikely to capture enough of your MOK input to reveal your master password. Think about it. Even if the logging program took a screen shot every second it would be virtually impossible to get your entire password. But screen recorders take shots much less frequently than once a second - most operate in minutes rather than seconds.

So on balance using the RoboForm2Go MOK is the way to go. It’s not perfectly safe just very safe. It is however, way safer than using keyboard input to enter your master password.

But before you enter anything with a MOK do turn around and make sure nobody is watching over your shoulder. Shoulder surfers just love MOK password entry :>)