The Internet is at war. Please read this if you run a DNS server.

A Dutch ISP that acts as a spam haven is DDOSing Spamhaus, and they’re using DNS to do it. The attack is using spoofed DNS queries to create, basically, a smurf-like attack. And the sheer volume of traffic is likely to affect the Internet as a whole.

That might explain why my recruiters were complaining that it was taking forever to look up job postings today. (Yes, I can publicly admit that I’m talking to recruiters. That’s another story.)

But basically, if you run a DNS server, you need to check your configuration to keep lowlives from using your DNS as a weapon. Here is a useful page for those of you running BIND, the one of the most popular DNS servers.

This was the most common type of attack in 2012; it looks like some people are trying to up the ante in 2013. We can make it stop, but every sysadmin running a DNS server is going to have to pitch in to help.

No, it doesn’t take a “serious hacker” to crack wi-fi through WPS

John C Dvorak is raving in PC Magazine about Netgear wireless routers and range extenders and how easy WPS makes it to set them up–and providing some very seriously flawed security advice along the way.

“Note that WPS is crackable by serious hackers using brute-force attack, but any SOHO user not dealing with government secrets should be fine.”
Read more

How to check to see if a FedEx or UPS e-mail message is real

“Did you order anything lately?” my wife asked me.

“Not that I can think of,” I said.

“We got this e-mail about a FedEx package that they couldn’t deliver on the 17th,” she said. “It has a ‘print receipt’ button.”

Don’t click on that button.

Read more

And the most security-riddled program of 2012 was….

Secunia released its annual vulnerability review, a study of the 50 most vulnerable pieces of software in 2012. It was a fairly tight-three way race at the top, and the distance between #3 and #4 was huge.

I was actually surprised at who the top three were. They weren’t the three usual suspects. But in the case of the top two, they did, to their credit, roll out fixes within 30 days of disclosure.

So now that I’m killing you with suspense….
Read more

Some computer maintenance for the upcoming family get-togethers

If you’re like me and do some computer maintenance for families during holiday weekends, the time to plan Easter computer maintenance is now.

Here’s some stuff I recommend doing to keep your non-computer-enthusiast relatives’ systems running smoothly. Be sure to bring your own laptop along, just in case. If a computer is too broken to get online or to get online safely, nothing beats a working system for downloading the stuff you need to fix it. Read more

Bitdefender 60-second virus scan: a review

I mentioned Bitdefender 60-second virus scan the other day, but didn’t give it a proper review. It’s time I remedy that.

It’s a small 160K stub that downloads a few more megabytes worth of stuff after you run it. Unlike most other free antivirus apps, this one is intended to be secondary–a marketing tool to show you what your primary antivirus isn’t catching that Bitdefender would, I suppose. But I think it’s useful as a second line of defense, and recommend using it as such.

Read more

The men (boys) who spy on women through webcams

Ars Technica made a bit of a splash this week with this provocative headline. This is real.

The article gives the usual advice, like not opening e-mail from strangers, not clicking attachments from strangers, and not visiting dodgy websites. That’s all good advice, as is staying off torrent and other file sharing sites, but even all that is not enough.
Read more

Here’s a nice Linux tool: checkrestart

Tom Gatermann told me about a nice tool for Debian (and presumably Ubuntu) called checkrestart. Sometimes, even though you did an apt-get update and apt-get upgrade to bring your system up to date, you can still be running the out-of-date version of something. That’s the problem checkrestart helps you solve.

Read more

How to pick a decent password

Although I write about passwords about 8 times a week, it seems, it occurs to me that I haven’t–at least not recently, that I can find–written about how to make up a halfway decent password.

So, here’s how to make a decent–I won’t say great–password.

Read more

Java’s been updated again. For the fifth time this year.

Seriously, Java and Flash and Acrobat have been updated so many times this year, you could almost make a drinking game out of it. Java is on update number five for the year, and it’s only the first week of March.

Of course, if you uninstalled Java, you don’t have to worry about 0-day vulnerabilities or the patches that come afterward to prevent them. If you installed Secunia PST, you don’t have to worry about the updates; they come down automatically. The ideal thing is to do both.