• HEXUS
  • HEXUS.tv
  • channel
  • gaming
  • lifestyle
  • trust
  • community
  • ESReality
  • HEXUS.community discussion forums

    Welcome to the HEXUS.community discussion forums forums.

    You are currently viewing our boards as a guest which gives you limited access to view most discussions and other features. By joining our free community you will have access to post topics, respond to polls and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

    Go Back   HEXUS.community discussion forums > HEXUS.channels > HEXUS.lifestyle > Lifestyle News

    Lifestyle News All the latest news from the world of the digital home and more.

    View Poll Results: What was your understanding of the term, 'political engineering'?
    Only as a computer-security term. I'm not a computer guru. 0 0%
    Only as a computer-security term. I am a computer guru. 3 18.75%
    Only as a political-science term. I'm not a computer guru. 1 6.25%
    Only as a political-science term. I am a computer guru. 3 18.75%
    I knew it referred to both. I'm not a computer guru. 0 0%
    I knew it referred to both. I am a computer guru. 1 6.25%
    Never heard the term B4. I am not a computer guru 1 6.25%
    Never heard the term B4. I am a computer guru 4 25.00%
    Why are people ALWAYS picking on Microsoft? 2 12.50%
    DON'T bother me! I've got malware to finish! 1 6.25%
    Voters: 16. You may not vote on this poll

    Reply
     
    LinkBack Thread Tools
    Old 01-02-2006, 08:15 PM   #1 (permalink)
    HEXUS.lifestyle
     
    Join Date: Apr 2005
    Posts: 2,519
    Thanks: 13
    Thanked 2 Times in 2 Posts
    Prudish Microsoft response to Kama Sutra worm

    Microsoft recently joined the chorus of voices warning to protect yourself before Friday against an email-borne worm that could bring down your PC completely but it is doing so in such prudish terms that few will understand what it's saying.

    Making doubly sure that it won't cause anyone any offence - even if its prudery could result in a whole bunch of totally non-working PCs - the [Microsoft] Security Advisory sums up the whole issue with the Kama Sutra worm by saying,

    "The mass mailing malware tries to entice users through social engineering efforts into opening an attached file in an e-mail message".
    Don't understand? No, us neither - and that's whole point.

    Check out this HEXUS.headline

    Then, if you would, please participation in our poll - so we can try to get an idea of the proportion of people (of differing levels of computer experience) that will or won't have understood the meaning of the term 'social engineering' in the context it was used by Microsoft.

    Here, are two contrasting definitions, courtesy of Wikipedia:

    Social engineering (political science)
    Social engineering in political science refers to efforts to systematically manage popular attitudes and social behavior on a large scale, whether by governments or private groups.

    The term has a negative connotation, and is sometimes used as an accusation against any who propose to use law, tax policy, or other kinds of state influence to accomplish social goals. For instance, political conservatives in the United States have accused their opponents of 'social engineering' through their promotion of political correctness, on the basis that political correctness is an attempt to change social attitudes by defining 'acceptable' and 'unacceptable' language.

    Social engineering (computer security)
    Social engineering (computer security), is the practice of obtaining confidential information by manipulation of legitimate users. A social engineer will commonly use the telephone or Internet to trick people into revealing sensitive information or getting them to do something that is against typical policies. By this method, social engineers exploit the natural tendency of a person to trust his or her word, rather than exploiting computer security holes. It is generally agreed upon that “users are the weak link” in security and this principle is what makes social engineering possible.

    A contemporary example of a social engineering attack is the use of e-mail attachments that contain malicious payloads (that, for instance, use the victim's machine to send massive quantities of spam). After earlier malicious e-mails led software vendors to disable automatic execution of attachments, users now have to explicitly activate attachments for this to occur. Many users, however, will blindly click on any attachments they receive, thus allowing the attack to work.

    Last edited by Bob Crabtree; 02-02-2006 at 11:41 AM..
    Bob Crabtree is offline   Reply With Quote
    Old 01-02-2006, 08:44 PM   #2 (permalink)
    HEXUS.lifestyle
     
    Join Date: Apr 2005
    Posts: 2,519
    Thanks: 13
    Thanked 2 Times in 2 Posts
    In case anyone does want to protect their PC against, viruses, worms, trojans and other sorts of malware, and doesn't have a lot of readies to throw at the problem before Friday (though the same nasty is supposed to strike every third day of the month), below are some of the free apps you can use - and with confidence, in my experience.

    My current favourite anti-virus freebie is Grisoft's AVG Free.

    Set it to update daily and to run directly afterwards.

    Trojans are well dealt with by
    Lavasoft's Ad-Aware SE Personal Edition 1.06.

    and

    Safer-networking's SpyBot Search & Destroy.

    In my view you are better to have both of the last two installed and to run each of them at least once a week.

    In addition, you should use Microsoft's own freebies (get them via Windows Update) and, if you are technically knowledgeable, also get Merijn's HiJack This but use it with EXTREME care.

    To help you do that - but remember, any changes you make are down to you - there's a very useful auto-diagnostic tool here into which you can paste the log file that HiJack This produces.

    Other folks' suggestions are most welcome.

    Last edited by Bob Crabtree; 01-02-2006 at 09:14 PM..
    Bob Crabtree is offline   Reply With Quote
    Old 02-02-2006, 06:37 AM   #3 (permalink)
    Does he need a reason?
     
    Funkstar's Avatar
     
    Join Date: Aug 2005
    Location: Aberdeen
    Posts: 16,129
    Thanks: 329
    Thanked 632 Times in 531 Posts
    Funkstar's system
    i don't see what is so confusing about that sentance. Although it does sound like a standard response. This could be used to describe dozens of 'famous' worms over the last few years.

    Funkstar is offline   Reply With Quote
    Old 02-02-2006, 08:12 AM   #4 (permalink)
    Own The Competition
     
    PD HEXUS's Avatar
     
    Join Date: May 2004
    Location: England
    Posts: 921
    Thanks: 43
    Thanked 1 Time in 1 Post
    and here's a little something from Symantec which could prove helpful: W32.Blackmal@mm Removal Tool

    cheers,

    PD

    HEXUS.swankyDynamicSignature - Give it a click!

    AMD Athlon™ 64 FX-60 dual-core - ABIT AT8 32X (ATi CrossFire™ Xpress 3200 + ULI1575) - 2GiB CORSAIR XMS PRO (TWINX2048-3500LLPRO) - ATi Radeon® X1950 XTX 512MB GDDR4 - 1 x 74GB WD Raptor® WD740GD; 3 x 34GB WD Raptor® WD360ADFD; 1 x 200GB Seagate Barracuda 7200.9 - CORSAIR HX620W PSU - Lian Li PC-S80B - Dell Ultrasharp 2407WFP
    PD HEXUS is offline   Reply With Quote
    Old 02-02-2006, 11:02 AM   #5 (permalink)
    HEXUS.lifestyle
     
    Join Date: Apr 2005
    Posts: 2,519
    Thanks: 13
    Thanked 2 Times in 2 Posts
    Nice one Paul - I forgot all about that.

    But, people, do make sure you've got your antis in place - and keep them up-to-date and run them regularly; better not to get any nasties in the first place than to remove them after they've done their work.
    Bob Crabtree is offline   Reply With Quote
    Old 02-02-2006, 11:36 AM   #6 (permalink)
    HEXUS.lifestyle
     
    Join Date: Apr 2005
    Posts: 2,519
    Thanks: 13
    Thanked 2 Times in 2 Posts
    Originally Posted by Funkstar
    i don't see what is so confusing about that sentance. Although it does sound like a standard response. This could be used to describe dozens of 'famous' worms over the last few years.
    Ah, I understand your thinking - cos they've used geekish gibberish in the past, it's okay to use it now.

    Well, the absolute bottom line - in my view - is that Microsoft has a duty to communicate in such a way that ordinary mortals can understand what it's trying to tell them, especially if that's something that requires them to take some appropriate action.

    By mentioning NOTHING specific about the possible subject lines and contents of the body of the email, MS has done people no favours at all - and the only reasons I can think it has copped out are either prudishness somewhere in the decision-making hierachy or the fact that the people who write such stuff are so cut off from the real world that they don't realise they are using gibberish.

    It could, of course, be a combination of both.

    It's also my belief that were you to take a straw poll of normal computer users - ordinary people who don't live and die computers - a large majority, if they even knew what social engineering meant, would think of it in the context of political science, rather than computer security.

    But, perhaps, better that I test that theory by adding a poll to this thread [now done].

    Here, though, are two contrasting definitions, courtesy of Wikipedia:

    Social engineering (political science)
    Social engineering in political science refers to efforts to systematically manage popular attitudes and social behavior on a large scale, whether by governments or private groups.

    The term has a negative connotation, and is sometimes used as an accusation against any who propose to use law, tax policy, or other kinds of state influence to accomplish social goals. For instance, political conservatives in the United States have accused their opponents of 'social engineering' through their promotion of political correctness, on the basis that political correctness is an attempt to change social attitudes by defining 'acceptable' and 'unacceptable' language.

    Social engineering (computer security)
    Social engineering (computer security), is the practice of obtaining confidential information by manipulation of legitimate users. A social engineer will commonly use the telephone or Internet to trick people into revealing sensitive information or getting them to do something that is against typical policies. By this method, social engineers exploit the natural tendency of a person to trust his or her word, rather than exploiting computer security holes. It is generally agreed upon that “users are the weak link” in security and this principle is what makes social engineering possible.

    A contemporary example of a social engineering attack is the use of e-mail attachments that contain malicious payloads (that, for instance, use the victim's machine to send massive quantities of spam). After earlier malicious e-mails led software vendors to disable automatic execution of attachments, users now have to explicitly activate attachments for this to occur. Many users, however, will blindly click on any attachments they receive, thus allowing the attack to work.

    Last edited by Bob Crabtree; 02-02-2006 at 12:25 PM..
    Bob Crabtree is offline   Reply With Quote
    Old 02-02-2006, 11:37 AM   #7 (permalink)
    Seething Cauldron of Hatred
     
    Join Date: Aug 2005
    Posts: 7,939
    Thanks: 106
    Thanked 370 Times in 283 Posts
    or, just not open attachments on strange sounding emails?

    Which is easyer? Resisting the temptation to get some free porn which why would someone you don't know like that email you? Or having to deal with the consiquences of an infection..... Hmmm.......

    throw new ArgumentException (String, String, Exception)
    TheAnimus is offline   Reply With Quote
    Old 02-02-2006, 08:49 PM   #8 (permalink)
    is unemployed
     
    alsenior's Avatar
     
    Join Date: Nov 2005
    Location: Grimsby
    Posts: 2,329
    Thanks: 75
    Thanked 89 Times in 83 Posts
    alsenior's system
    Originally Posted by TheAnimus
    or, just not open attachments on strange sounding emails?

    Which is easyer? Resisting the temptation to get some free porn which why would someone you don't know like that email you? Or having to deal with the consiquences of an infection..... Hmmm.......
    sounds alot like real life
    alsenior is offline   Reply With Quote
    Old 06-02-2006, 03:09 PM   #9 (permalink)
    Registered+
     
    Join Date: Jul 2005
    Location: London, UK
    Posts: 19
    Thanks: 0
    Thanked 0 Times in 0 Posts
    beware of the grammar

    i don't see the missing "not" in that last paragraph that the author makes such a song and dance about. am i going mad?

    what it looks like the author was expecting to see was a standard "Customers who are not using the most recent and updated antivirus software are at risk...", but of course what it actually says is that "Customers who are using the most recent and updated antivirus software could be at a reduced risk of infection...", which is fine... meh. life goes on...
    ayembee is offline   Reply With Quote
    Old 06-02-2006, 03:46 PM   #10 (permalink)
    HEXUS.lifestyle
     
    Join Date: Apr 2005
    Posts: 2,519
    Thanks: 13
    Thanked 2 Times in 2 Posts
    Originally Posted by ayembee
    i don't see the missing "not" in that last paragraph that the author makes such a song and dance about. am i going mad?

    what it looks like the author was expecting to see was a standard "Customers who are not using the most recent and updated antivirus software are at risk...", but of course what it actually says is that "Customers who are using the most recent and updated antivirus software could be at a reduced risk of infection...", which is fine... meh. life goes on...
    No, you're not going mad (at least, judging from the above post, anyway).

    You are quite right in your observation and I was quite wrong in mine.

    That being so, I was going to change that section to correct my error.

    Then I read the original again and realised that what I was actually highlighting wasn't an error in what was written but a densely written sentence the meaning of which wasn't clear on the first or subsequent read-throughs by myself - someone whose daily life is spent juggling with words.

    Or am I just clutching at straws here?

    Debate, please.

    Bob
    Bob Crabtree is offline   Reply With Quote
    Old 06-02-2006, 04:53 PM   #11 (permalink)
    Registered+
     
    Join Date: Jul 2005
    Location: London, UK
    Posts: 19
    Thanks: 0
    Thanked 0 Times in 0 Posts
    oh, i certainly agree it's badly written, and worth a mild chastisement on those grounds alone, i just didn't think it was technically wrong... maybe one for the Plain English campaign
    ayembee is offline   Reply With Quote
    Reply

    Breadcrumb
    Go Back   HEXUS.community discussion forums > HEXUS.channels > HEXUS.lifestyle > Lifestyle News


    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Trackbacks are On
    Pingbacks are On
    Refbacks are On


    Similar Threads
    Thread Thread Starter Forum Replies Last Post
    Why response times of LCDs are misleading Carvahlo Graphics cards and Monitors 9 23-09-2004 07:35 PM
    New RPC hotfix from Microsoft Paul Adams Operating systems & applications 12 14-09-2003 07:44 AM



    All times are GMT. The time now is 09:26 AM.

    Any representations/statements made on the HEXUS.community discussion forums are the representations/statements of the author i.e. the person/organisation making them. If any such representations/statements are disputed they are a matter between the parties concerned.
    HEXUS Limited accepts no responsibility for any misrepresentations, inaccurate or false statements made by any person/organisation other than HEXUS Limited employees.
    For more information please read HEXUS Limited's terms, conditions and privacy policy.

    Hosted Exchange

    Powered by vBulletin® Version 3.8.4
    Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
    Content Relevant URLs by vBSEO 3.3.2
    © Copyright 2009 HEXUS® Limited. All rights reserved. Unauthorised reproduction strictly prohibited.