<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Blogjer - Technology at a glance &#187; security</title>
	<atom:link href="http://www.blogjer.com/category/internet/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.blogjer.com</link>
	<description>Tips &#38; Tricks To Get Online Visibility</description>
	<lastBuildDate>Sat, 10 Dec 2011 03:52:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Fortinet November Threat Landscape Report Highlights Reduced Spam Levels after Bredolab Takedown</title>
		<link>http://www.blogjer.com/2010/12/07/fortinet-november-threat-landscape-report-highlights-reduced-spam-levels-after-bredolab-takedown/</link>
		<comments>http://www.blogjer.com/2010/12/07/fortinet-november-threat-landscape-report-highlights-reduced-spam-levels-after-bredolab-takedown/#comments</comments>
		<pubDate>Tue, 07 Dec 2010 05:16:51 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[fortinet]]></category>

		<guid isPermaLink="false">http://www.blogjer.com/?p=12124</guid>
		<description><![CDATA[Fortinet November Threat Landscape Report highlights a 12 percent reduction in global spam after Dutch authorities dismantled a large Bredolab network by taking more than 140 servers offline. Koobface, a botnet well known for spamming popular social media sites, was taken offline on November 14 when UK ISP provider Coreix took three MotherShip servers offline. [...]]]></description>
			<content:encoded><![CDATA[<p>Fortinet November Threat Landscape Report highlights a 12 percent reduction in global spam after Dutch authorities dismantled a large Bredolab network by taking more than 140 servers offline.</p>
<p>Koobface, a botnet well known for spamming popular social media sites, was taken offline on November 14 when UK ISP provider Coreix took three MotherShip servers offline.</p>
<p>FortiGuard labs disclosed zero-day vulnerabilities in Adobe Shockwave, Adobe Flash, Microsoft Office PowerPoint, and Apple QuickTime.</p>
<p>More info available on the press release below</p>
<p><em><span style="text-decoration: underline;">Press Release</span></em></p>
<h1><strong><span style="font-family: 'Times New Roman'; font-size: medium;"><em>Fortinet November Threat Landscape Report Highlights Reduced Spam Levels after Bredolab Takedown</em></span></strong></h1>
<p><em><span style="font-family: 'Times New Roman'; font-size: medium;"> </span></em></p>
<p><em><span style="font-family: 'Times New Roman'; font-size: small;">Koobface Servers Taken Down on November 14 Reconfigured to New Control Servers Five Days Later</span></em></p>
<p><em><strong><span style="font-family: 'Times New Roman'; font-size: small;">MALAYSIA, 6 December, 2010 </span></strong>- <span style="color: black;">Fortinet </span>– a leading network security provider and the worldwide leader of unified threat management (UTM) solutions – today announced its November 2010 Threat Landscape report, which highlights a 12 percent reduction in global spam after Dutch authorities dismantled a large Bredolab network by taking more than 140 servers offline.</em></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em> </em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em>“Bredolab was often used to load spam engines, which are typically used to sell fraudulent pharmaceuticals,” said Derek Manky project manager, cyber security and threat research at Fortinet. “The scale of this Bredolab botnet had a huge impact on spam levels, dropping as much as 26 percent one week after it was dismantled.”</em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em> </em></span></p>
<p><strong><span style="text-decoration: underline;"><span style="font-family: 'Times New Roman'; font-size: small;"><em>Koobface Takedown</em></span></span></strong></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em>Koobface, a botnet well known for spamming popular social media sites, was taken offline on November 14 when UK ISP provider Coreix took three MotherShip servers offline. Koobface used intermediary servers (proxies) to communicate with these MotherShip servers through HTTP port 80.</em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em> </em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em>“We confirmed that on November 14, when the primary servers were taken offline, the intermediary servers failed to proxy content, which effectively crippled the botnet,” Manky continued. “Unfortunately, we saw communication restored five days later on November 19th. This is likely due to the fact that Koobface contains an FTP harvesting module.”</em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em> </em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em>Operators may use stolen FTP credentials to hijack Web servers for intermediary/proxy use. By reconfiguring their intermediary servers to new MotherShip servers, the operators seemingly regained control of their botnet.</em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em> </em></span></p>
<p><strong><span style="text-decoration: underline;"><span style="font-family: 'Times New Roman'; font-size: small;"><em>Adobe, Microsoft, Apple Zero-Day Vulnerabilities</em></span></span></strong></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em>In November, FortiGuard labs also disclosed zero-day vulnerabilities in Adobe Shockwave (FGA-2010-54), Adobe Flash (FGA-2010-56), Microsoft Office PowerPoint (FGA-2010-58), and Apple QuickTime (FGA-2010-61). In addition to the four zero days, 146 additional new vulnerabilities were covered by FortiGuard IPS; 40 percent of which were actively exploited in the wild. As of this writing, a zero-day vulnerability is still being exploited in the wild for Microsoft Internet Explorer (FGA-2010-55). All five vulnerabilities were critical, and had the potential to allow attackers to execute arbitrary code from a remote location.</em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em> </em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em>New and old vulnerabilities will continue to be exploited, so it’s important to keep all application patches up to date. Additionally, a valid intrusion prevention system (IPS) can help mitigate attacks against both known vulnerabilities and zero-days. With the use of communication through common protocols, application control is becoming more important to identify malicious activity on the application level.</em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em> </em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em>FortiGuard Labs compiled threat statistics and trends for November based on data collected from FortiGate network security appliances and intelligence systems in production worldwide. Customers who use Fortinet’s FortiGuard Services should be protected against this vulnerability with the appropriate configuration parameters in place.</em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em> </em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em>FortiGuard Services offer broad security solutions including antivirus, intrusion prevention, Web content filtering and anti-spam capabilities. These services help protect against threats on both application and network layers. FortiGuard Services are updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and zero-day protection from new and emerging threats. For customers with a subscription to FortiGuard, these updates are delivered to all FortiGate, FortiMail and FortiClient products.</em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em> </em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em>The full November Threat Landscape report, which includes the top threat rankings in several categories, is available now. Ongoing research can be found in the FortiGuard Center or via FortiGuard Labs’ RSS feed. Additional discussion on security technologies and threat analysis can be found at the Fortinet Security Blog.</em></span></p>
                  <div id="lass"><table style="width: 547px; height: 58px;" id="tkod" border="1" cellpadding="3" cellspacing="0"><tbody id="in_f"><tr id="x52g"><td id="t-61" width="100%">If you like this post then please consider subscribing to my <a title="full feed RSS" target="_blank" href="http://feeds.feedburner.com/NotJustABlog/" id="lir7">full feed RSS</a>.&nbsp; <br id="n8k0">You can also <a title="subscribe by Email" target="_blank" href="http://www.feedburner.com/fb/a/emailverifySubmit?feedId=896848" id="yn:q">subscribe by Email</a> and have new posts sent directly to your inbox.<br id="ejzb"><span id="og23" style="font-weight: bold;">&nbsp;<br id="s4-r"></span><span id="og23"><br />
This post originally came from Zaki's <a id="rf:t" href="www.blogjer.com">Blogjer.com</a></span></td></tr></tbody></table></div><span id="t7vz" style="font-weight: bold;"></span><br id="bvf9"><span id="rg-m" style="font-weight: bold;"></span><br id="pzdj" style="font-weight: bold;"><br id="q1m7">      <p>---<br />Related Articles at Blogjer - Technology at a glance:<ul><li><a href="http://www.blogjer.com/2010/11/03/october-threat-landscape-report-highlights-increased-zeusmoney-mule-risk/" rel="bookmark" title="Permanent Link: October Threat Landscape Report Highlights Increased Zeus/Money Mule Risk">October Threat Landscape Report Highlights Increased Zeus/Money Mule Risk</a></li><li><a href="http://www.blogjer.com/2009/01/13/mcafee-monthly-spam-report-educating-people-about-spam/" rel="bookmark" title="Permanent Link: McAfee monthly spam report &#8211; educating people about spam">McAfee monthly spam report &#8211; educating people about spam</a></li><li><a href="http://www.blogjer.com/2010/08/04/fortinet-july-threat-landscape-report-shows-sasfis-botnet-variants-multiplying/" rel="bookmark" title="Permanent Link: Fortinet July Threat Landscape Report Shows Sasfis Botnet Variants Multiplying">Fortinet July Threat Landscape Report Shows Sasfis Botnet Variants Multiplying</a></li><li><a href="http://www.blogjer.com/2010/09/03/fortinet-august-threat-landscape-report-shows-return-of-ransomware-and-rise-of-%e2%80%98do-it-yourself%e2%80%99-botnets/" rel="bookmark" title="Permanent Link: Fortinet August Threat Landscape Report Shows Return of Ransomware and Rise of ‘Do-it-Yourself’ Botnets">Fortinet August Threat Landscape Report Shows Return of Ransomware and Rise of ‘Do-it-Yourself’ Botnets</a></li><li><a href="http://www.blogjer.com/2007/12/02/getting-rid-of-spoof-and-spam-email/" rel="bookmark" title="Permanent Link: Getting rid of spoof and spam email">Getting rid of spoof and spam email</a></li></ul></p><br />]]></content:encoded>
			<wfw:commentRss>http://www.blogjer.com/2010/12/07/fortinet-november-threat-landscape-report-highlights-reduced-spam-levels-after-bredolab-takedown/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fortinet Introduces World’s Fastest Unified Threat Management Security and Switching Blades</title>
		<link>http://www.blogjer.com/2010/12/01/fortinet-introduces-world%e2%80%99s-fastest-unified-threat-management-security-and-switching-blades/</link>
		<comments>http://www.blogjer.com/2010/12/01/fortinet-introduces-world%e2%80%99s-fastest-unified-threat-management-security-and-switching-blades/#comments</comments>
		<pubDate>Wed, 01 Dec 2010 12:12:39 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[FortiGate-5000]]></category>
		<category><![CDATA[fortinet]]></category>

		<guid isPermaLink="false">http://www.blogjer.com/?p=12057</guid>
		<description><![CDATA[Fortinet has introduced world’s fastest unified threat management mecurity and switching blades with following key highlights. The latest FortiGate-5000 series appliance family delivers essential network defenses for dynamic, multi-tenant large enterprise and service provider networks, including security-as-a-service and infrastructure-as-a-service environments. The new FortiGate-5001B is a high performance security blade that integrates a wide range of [...]]]></description>
			<content:encoded><![CDATA[<p>Fortinet has introduced world’s fastest unified threat management mecurity and switching blades with following key highlights.</p>
<ul>
<li>The latest FortiGate-5000 series appliance family delivers essential network defenses for dynamic, multi-tenant large enterprise and service provider networks, including security-as-a-service and infrastructure-as-a-service environments.</li>
<li>The new FortiGate-5001B is a high performance security blade that integrates a wide range of critical security services and native 10-Gigabit Ethernet (GbE) support for FortiGate-5000 chassis-based platforms which delivers up to blazing 40 Gbps of firewall throughput and up to 17Gbps of virtual private network (VPN) throughput.</li>
<li>FortiSwitch-5003B switching blade delivers 10-GbE switching to the backplane fabric of the FortiGate-5000 series chassis and operates with exceptionally low latency to maximize multi-threat security performance required by increasingly bandwidth-hungry data centers.</li>
</ul>
<p>Press Release</p>
<h1><em><strong><span style="font-size: medium;">Fortinet Introduces World’s Fastest Unified Threat Management Security and Switching Blades</span></strong></em></h1>
<p><em><span style="font-size: small;"> </span></em></p>
<p><em>New Blades Coupled with FortiGate Chassis Will Provide up to 500 Gbps Firewall Throughput Performance</em></p>
<p><em><strong><span style="font-size: small;"> </span></strong></em></p>
<p><em><strong><span style="font-size: small;">MALAYSIA</span></strong><strong>, December 1, 2010 </strong>– Fortinet &#8211; a leading network security provider and the worldwide leader of unified threat management (UTM) solutions – today announced the newest flagship model in the FortiGate-5000 series appliance family along with a new high-performance switching option. These products combine to deliver essential network defenses for dynamic, multi-tenant large enterprise and service provider networks, including security-as-a-service and infrastructure-as-a-service environments.</em></p>
<p><em><span style="font-size: small;"> </span></em></p>
<p><em><span style="font-size: small;">The new FortiGate-5001B is a high-performance security blade that integrates a wide range of critical security services and native 10-Gigabit Ethernet (GbE) support for FortiGate-5000 chassis-based platforms. Delivering up to a blazing 40 Gbps of firewall throughput and up to 17 Gbps of virtual private network (VPN) throughput, the FortiGate-5001B integrates essential security functions in a compact Advanced Telecom Computing Architecture (ATCA)-compliant blade form factor. This includes enterprise firewall, virtual private network, application control, intrusion prevention, anti-virus/anti-malware, anti-spam and Web filtering. To optimize the performance of these security services, the FortiGate-5001B security blade integrates the latest Intel 4-core CPU and two Fortinet FortiASIC NP4 network processor chips. This is Fortinet’s fourth generation of ATCA-compliant solutions, having shipped the first generation of its ATCA chassis-based FortiGate-5001SX and FortiSwitch-5003 in 2004. Fortinet brought its second generation of ATCA-compliant appliances in 2006 with the FortiGate-5005FA2 and FortiController-5208 and the third generation in 2008 with the FortiGate-5001A and FortiSwitch-5003A. Adding onto Fortinet’s pioneering innovation in the telecom industry is the FortiGate’s achievement of NEBS Level 3 compliance – a requirement for operation of carrier-class equipment in the central offices of major telecommunications companies. </span></em></p>
<p><em><span style="font-size: small;"> </span></em></p>
<p><em><span style="font-size: small;">Delivering 10-GbE switching to the backplane fabric of the FortiGate-5000 series chassis, the new FortiSwitch-5003B switching blade operates with exceptionally low latency to maximize multi-threat security performance required by increasingly bandwidth-hungry data centers.  Fortinet’s new products, designed for very large enterprises, carriers and managed service providers, provide consolidated security services and simplified network infrastructures that deliver substantially increased performance, dramatically improved multi-threat protection and significantly lower operating costs. </span></em></p>
<p><em><span style="font-size: small;"> </span></em></p>
<p><em><span style="font-size: small;">When coupling the FortiGate-5001B with the FortiGate<span style="color: #1f497d;">-</span>5140 chassis, telecommunications and managed security service providers will have up to 500 Gbps firewall throughput performance, making the chassis the fastest blade system firewall in the industry. By combining a FortiGate-5000 series chassis with the new FortiGate-5001B security blade and optional FortiSwitch-5003B switching blade, customers have access to a modular, multi-threat security solution with carrier-grade reliability and scalability required by 10-GigE network environments.  As a highly modular platform, the FortiGate-5000 series is designed to be the cornerstone of high-performance security infrastructures.  Ideal for high-speed multi-threat security gateways, managed security services, and complex security zoning applications, the FortiGate-5000 series, equipped with the new FortiGate-5001B and FortiSwitch-5003B blades, can be integrated with Fortinet&#8217;s centralized management and reporting solutions to provide broad control of large-scale deployments.</span></em></p>
<p><em><span style="font-size: small;"> </span></em></p>
<p><em><span style="font-size: small;">The FortiGate-5000 Series also offers the following benefits: </span></em></p>
<p><em><span style="font-size: small;">• Redundant, hot swappable power supplies and fans to minimize single-points of failure.</span></em></p>
<p><em><span style="font-size: small;">• Use of active/active and active/passive high availability modes for uninterrupted service.</span></em></p>
<p><em><span style="font-size: small;">• Integration with Fortinet’s FortiManager centralized management and FortiAnalyzer centralized reporting appliances to simplify security management, reporting and analysis while reducing operating expenses.</span></em></p>
<p><em><span style="font-size: small;">• Availability of FortiGuard™ Subscription Services to deliver automated, real-time and up-to-date protection against security threats and exploits.</span></em></p>
<p><em><span style="font-size: small;">• Deployment flexibility that includes network segmentation by customer, business unit or any other logical partition to maximize control through the use of virtual domains.  The platform is also ideal for virtualized environments.</span></em></p>
<p><em><span style="font-size: small;">• Complements or upgrades existing security infrastructure by enabling only the services needed in integrated, all-in-one security blades.</span></em></p>
<p><em><span style="font-size: small;">• Design the exact mix of multi-threat security, load-balancing, and high-speed networking required to support organizational security requirements.</span></em></p>
<p><span style="font-size: small;"> </span></p>
<p><span style="font-size: small;">“You can’t take a ‘cookie-cutter’ approach to network security, especially in large-scale, business-critical environments supporting hundreds of thousands or millions of end customers and clients,” said Michael Xie, founder, CTO and vice president of engineering at Fortinet.  “That’s why we continue to innovate with agile and modular approaches to network defense because each customer environment has a unique threat profile and corresponding security and performance requirements.  In recognition of this, we are once again pushing the envelope of high-performance network security with the introduction of the FortiGate-5001B and FortiSwitch-5003B blades.” </span></p>
<p><span style="font-size: small;"> </span></p>
<p><strong><span style="font-size: small;">Availability</span></strong></p>
<p><span style="font-size: small;">The FortiGate-5001B and FortiSwitch-5003B will be available this quarter.</span></p>
                  <div id="lass"><table style="width: 547px; height: 58px;" id="tkod" border="1" cellpadding="3" cellspacing="0"><tbody id="in_f"><tr id="x52g"><td id="t-61" width="100%">If you like this post then please consider subscribing to my <a title="full feed RSS" target="_blank" href="http://feeds.feedburner.com/NotJustABlog/" id="lir7">full feed RSS</a>.&nbsp; <br id="n8k0">You can also <a title="subscribe by Email" target="_blank" href="http://www.feedburner.com/fb/a/emailverifySubmit?feedId=896848" id="yn:q">subscribe by Email</a> and have new posts sent directly to your inbox.<br id="ejzb"><span id="og23" style="font-weight: bold;">&nbsp;<br id="s4-r"></span><span id="og23"><br />
This post originally came from Zaki's <a id="rf:t" href="www.blogjer.com">Blogjer.com</a></span></td></tr></tbody></table></div><span id="t7vz" style="font-weight: bold;"></span><br id="bvf9"><span id="rg-m" style="font-weight: bold;"></span><br id="pzdj" style="font-weight: bold;"><br id="q1m7">      <p>---<br />Related Articles at Blogjer - Technology at a glance:<ul><li><a href="http://www.blogjer.com/2010/11/08/fortinet-leverages-spirent-solutions-to-validate-best-in-class-performance-of-fortigate-3040b/" rel="bookmark" title="Permanent Link: Fortinet Leverages Spirent Solutions To Validate Best-In-Class Performance Of FortiGate-3040B">Fortinet Leverages Spirent Solutions To Validate Best-In-Class Performance Of FortiGate-3040B</a></li><li><a href="http://www.blogjer.com/2010/10/20/fortinet-advocates-healthcare-organizations-to-consider-their-data-security-strategy-in-today%e2%80%99s-dangerous-cyberspace/" rel="bookmark" title="Permanent Link: Fortinet Advocates Healthcare Organizations to Consider Their Data Security Strategy in Today’s Dangerous Cyberspace">Fortinet Advocates Healthcare Organizations to Consider Their Data Security Strategy in Today’s Dangerous Cyberspace</a></li><li><a href="http://www.blogjer.com/2010/12/07/fortinet-november-threat-landscape-report-highlights-reduced-spam-levels-after-bredolab-takedown/" rel="bookmark" title="Permanent Link: Fortinet November Threat Landscape Report Highlights Reduced Spam Levels after Bredolab Takedown">Fortinet November Threat Landscape Report Highlights Reduced Spam Levels after Bredolab Takedown</a></li><li><a href="http://www.blogjer.com/2010/09/03/fortinet-august-threat-landscape-report-shows-return-of-ransomware-and-rise-of-%e2%80%98do-it-yourself%e2%80%99-botnets/" rel="bookmark" title="Permanent Link: Fortinet August Threat Landscape Report Shows Return of Ransomware and Rise of ‘Do-it-Yourself’ Botnets">Fortinet August Threat Landscape Report Shows Return of Ransomware and Rise of ‘Do-it-Yourself’ Botnets</a></li><li><a href="http://www.blogjer.com/2010/11/19/fortinet-introduces-new-messaging-security-appliance-for-high-performance-corporate-email-routing/" rel="bookmark" title="Permanent Link: Fortinet Introduces New Messaging Security Appliance for High-Performance Corporate Email Routing">Fortinet Introduces New Messaging Security Appliance for High-Performance Corporate Email Routing</a></li></ul></p><br />]]></content:encoded>
			<wfw:commentRss>http://www.blogjer.com/2010/12/01/fortinet-introduces-world%e2%80%99s-fastest-unified-threat-management-security-and-switching-blades/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fortinet Introduces New Messaging Security Appliance for High-Performance Corporate Email Routing</title>
		<link>http://www.blogjer.com/2010/11/19/fortinet-introduces-new-messaging-security-appliance-for-high-performance-corporate-email-routing/</link>
		<comments>http://www.blogjer.com/2010/11/19/fortinet-introduces-new-messaging-security-appliance-for-high-performance-corporate-email-routing/#comments</comments>
		<pubDate>Fri, 19 Nov 2010 15:03:51 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[FortiMail-3000C]]></category>
		<category><![CDATA[fortinet]]></category>

		<guid isPermaLink="false">http://www.blogjer.com/?p=11886</guid>
		<description><![CDATA[Fortinet yesterday announced the highly versatile FortiMail-3000C messaging security appliance, which delivers secure email processing breakthroughs designed to satisfy the most demanding corporate messaging environments – supporting up to 50,000 users with a single system. The FortiMail-3000C which features a 20-percent performance improvement over its predecessors, is ideally suited for large enterprises and application service [...]]]></description>
			<content:encoded><![CDATA[<p>Fortinet yesterday announced the highly versatile FortiMail-3000C messaging security appliance, which delivers secure email processing breakthroughs designed to satisfy the most demanding corporate messaging environments – supporting up to 50,000 users with a single system.</p>
<ul>
<li>The FortiMail-3000C which features a 20-percent performance improvement over its predecessors, is ideally suited for large enterprises and application service and software-as-a-service (SaaS) providers.</li>
<li>The FortiMail-3000C features important server mode enhancements made possible by the new FortiMail 4.0 MR2 operating software, which enables the appliance to function as full-featured SMTP mail server supporting secure POP3, IMAP and Web mail clients.</li>
</ul>
<p>More on that available on the press release below.</p>
<p>Press Release</p>
<div id="_mcePaste"><strong><em>Fortinet Introduces New Messaging Security Appliance for High-Performance Corporate Email Routing</em></strong></div>
<div><strong><em><br />
</em></strong></div>
<div id="_mcePaste"><em>Top-of-the-Line FortiMail-3000C E-Mail Security Solution Delivers Intelligent Message Protection, Secure Content Delivery and Data Loss Prevention for Enterprises and Service Providers</em></div>
<div><em><br />
</em></div>
<div id="_mcePaste"><em>MALAYSIA, 18 November, 2010 – Fortinet &#8211; a leading network security provider and the worldwide leader of unified threat management (UTM) solutions – today announced the highly versatile FortiMail-3000C messaging security appliance, which delivers secure email processing breakthroughs designed to satisfy the most demanding corporate messaging environments – supporting up to 50,000 users with a single system.  Featuring a 20-percent performance improvement over its predecessors, the FortiMail-3000C is ideally suited for large enterprises and application service and software-as-a-service (SaaS) providers, especially those subject to PCI/DSS or HIPAA regulations in retail, payment, financial and healthcare industries.</em></div>
<div><em><br />
</em></div>
<div id="_mcePaste"><em>The FortiMail-3000C features important server mode enhancements made possible by the new FortiMail 4.0 MR2 operating software, which enables the appliance to function as a full-featured SMTP mail server supporting secure POP3, IMAP and Web mail clients.  This capability is ideal for companies that want to replace aging mail servers, combine email functions into a single device and for offering secure email services to remote offices.</em></div>
<div><em><br />
</em></div>
<div id="_mcePaste"><em>To help ensure the secure delivery of confidential or regulated content to customers, partners or employees, the FortiMail-3000C offers Identity-Based Encryption (IBE) that enables encrypted messages to be sent without the need for any user provisioning or additional hardware. FortiMail IBE is unique in providing “push” or “pull” delivery options.  This allows encrypted emails to be delivered directly to users and/or stored on the FortiMail appliance for retrieval, making the system extremely easy to deploy and use.  In addition, the system features customizable and predefined dictionaries that detect the accidental or intentional loss of confidential or regulated data.  This enables administrators to block messages containing data matching a range of patterns including credit card, social security, insurance and bank routing numbers.  Alternatively, policies can be created to require the encryption of messages containing this data to help organizations achieve HIPAA and PCI/DSS compliance.</em></div>
<div><em><br />
</em></div>
<div id="_mcePaste"><em>Using the same form factor and antispam, antivirus and anti-spyware protection afforded by other FortiMail devices, the FortiMail-3000C features an extra CPU, 16 gigabytes of RAM and a fiber interface, all of which are designed to deliver high performance.  The system is designed to route up to 1.2 million emails per hour and 1.1 million emails per hour with FortiGuard Antispam and Antivirus. The FortiMail-3000C supports up to a total of six terabytes of RAID 1/5/10/50 storage capacity with hot-swap hard drives.</em></div>
<div id="_mcePaste"><em>In addition to the new FortiMail-3000C platform, Fortinet is also announcing the upcoming availability of FortiMail 4.0 MR2 operating system. The enhancements to FortiMail 4.0 MR2 include improvements to productivity and security.</em></div>
<div><em><br />
</em></div>
<div id="_mcePaste"><em>Security enhancements include increased access control and expanded dictionary-based policy enforcement:</em></div>
<div id="_mcePaste"><em>•     Address Groups – Create access control rules for groups of user email or IP addresses.</em></div>
<div id="_mcePaste"><em>•     Dictionary Triggered Archive – Allows dictionary contents to be used to trigger email archiving in addition to sender/recipient and keyword values.</em></div>
<div><em><br />
</em></div>
<div id="_mcePaste"><em>There are several improvements to the Server mode functionality designed to boost productivity, including:</em></div>
<div id="_mcePaste"><em>•     Calendar Function – Provides a calendar for scheduling events and sending invites via the webmail interface.</em></div>
<div id="_mcePaste"><em>•     Address Book – Supports extended search information, user group creation and LDAP server synchronization.</em></div>
<div><em><br />
</em></div>
<div id="_mcePaste"><em>“In these budget-tightening times, total-cost-of-ownership is a crucial selection criteria for messaging security solutions,” said Michael Xie, founder, CTO and vice president of engineering at Fortinet.  “We’ve paid close attention to this market dynamic which is why we don’t use expensive and complex per-seat licensing models.  And, unlike competing offerings that frequently cobble together third-party antivirus or other protection schemes, we offer customers real-time updates directly from our FortiGuard threat prevention services.”</em></div>
<div id="_mcePaste"><em><br />
</em></div>
<div><em>Availability</em></div>
<div id="_mcePaste"><em>The FortiMail-3000C appliance is available now. FortiMail 4.0 MR2 will be available in Q1 2011.</em></div>
                  <div id="lass"><table style="width: 547px; height: 58px;" id="tkod" border="1" cellpadding="3" cellspacing="0"><tbody id="in_f"><tr id="x52g"><td id="t-61" width="100%">If you like this post then please consider subscribing to my <a title="full feed RSS" target="_blank" href="http://feeds.feedburner.com/NotJustABlog/" id="lir7">full feed RSS</a>.&nbsp; <br id="n8k0">You can also <a title="subscribe by Email" target="_blank" href="http://www.feedburner.com/fb/a/emailverifySubmit?feedId=896848" id="yn:q">subscribe by Email</a> and have new posts sent directly to your inbox.<br id="ejzb"><span id="og23" style="font-weight: bold;">&nbsp;<br id="s4-r"></span><span id="og23"><br />
This post originally came from Zaki's <a id="rf:t" href="www.blogjer.com">Blogjer.com</a></span></td></tr></tbody></table></div><span id="t7vz" style="font-weight: bold;"></span><br id="bvf9"><span id="rg-m" style="font-weight: bold;"></span><br id="pzdj" style="font-weight: bold;"><br id="q1m7">      <p>---<br />Related Articles at Blogjer - Technology at a glance:<ul><li><a href="http://www.blogjer.com/2010/11/08/fortinet-leverages-spirent-solutions-to-validate-best-in-class-performance-of-fortigate-3040b/" rel="bookmark" title="Permanent Link: Fortinet Leverages Spirent Solutions To Validate Best-In-Class Performance Of FortiGate-3040B">Fortinet Leverages Spirent Solutions To Validate Best-In-Class Performance Of FortiGate-3040B</a></li><li><a href="http://www.blogjer.com/2010/12/01/fortinet-introduces-world%e2%80%99s-fastest-unified-threat-management-security-and-switching-blades/" rel="bookmark" title="Permanent Link: Fortinet Introduces World’s Fastest Unified Threat Management Security and Switching Blades">Fortinet Introduces World’s Fastest Unified Threat Management Security and Switching Blades</a></li><li><a href="http://www.blogjer.com/2010/08/23/fortinet-expands-web-application-firewall-family-with-new-appliances-for-enterprises-application-service-and-cloud-based-service-providers/" rel="bookmark" title="Permanent Link: Fortinet Expands Web Application Firewall Family with New Appliances for Enterprises, Application Service and Cloud-based Service Providers">Fortinet Expands Web Application Firewall Family with New Appliances for Enterprises, Application Service and Cloud-based Service Providers</a></li><li><a href="http://www.blogjer.com/2010/10/20/fortinet-advocates-healthcare-organizations-to-consider-their-data-security-strategy-in-today%e2%80%99s-dangerous-cyberspace/" rel="bookmark" title="Permanent Link: Fortinet Advocates Healthcare Organizations to Consider Their Data Security Strategy in Today’s Dangerous Cyberspace">Fortinet Advocates Healthcare Organizations to Consider Their Data Security Strategy in Today’s Dangerous Cyberspace</a></li><li><a href="http://www.blogjer.com/2008/11/26/paypal-introduces-security-key-texted-to-your-mobile-sms/" rel="bookmark" title="Permanent Link: Paypal introduces security key texted to your mobile (SMS)">Paypal introduces security key texted to your mobile (SMS)</a></li></ul></p><br />]]></content:encoded>
			<wfw:commentRss>http://www.blogjer.com/2010/11/19/fortinet-introduces-new-messaging-security-appliance-for-high-performance-corporate-email-routing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fortinet Leverages Spirent Solutions To Validate Best-In-Class Performance Of FortiGate-3040B</title>
		<link>http://www.blogjer.com/2010/11/08/fortinet-leverages-spirent-solutions-to-validate-best-in-class-performance-of-fortigate-3040b/</link>
		<comments>http://www.blogjer.com/2010/11/08/fortinet-leverages-spirent-solutions-to-validate-best-in-class-performance-of-fortigate-3040b/#comments</comments>
		<pubDate>Mon, 08 Nov 2010 14:23:44 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[fortinet]]></category>

		<guid isPermaLink="false">http://www.blogjer.com/?p=11837</guid>
		<description><![CDATA[Fortinet today announced the results of performance tests conducted on the FortiGate-3040B, the newest Fortinet multi-threat security appliance purpose-built for large enterprise and data center environments. Some key highlights are: · Spirent Communications plc. announced the results of performance tests conducted on the FortiGate-3040B, the newest Fortinet multi-threat security appliance purpose-built for large enterprise and [...]]]></description>
			<content:encoded><![CDATA[<p>Fortinet today announced the results of performance tests conducted on the FortiGate-3040B, the newest Fortinet multi-threat security appliance purpose-built for large enterprise and data center environments. Some key highlights are: </p>
<p>·         Spirent Communications plc. announced the results of performance tests conducted on the FortiGate-3040B, the newest Fortinet multi-threat security appliance purpose-built for large enterprise and data center environments.</p>
<p>·         Testing with Spirent solutions showed that the FortiGate-3040B delivers a steady 40Gbps of performance in both UDP and TCP traffic through four 10 Gbps Ethernet ports and supports full line-rate application traffic with zero packet loss.</p>
<p>·         The appliance also achieves latency as low as 3.94 microseconds under 100 percent load. Other test results unveils that the ForitGate-3040B supports up to 5,600,000 concurrent sessions and 160,000 transactions per second.</p>
<p>Press Release</p>
<p>Fortinet Leverages Spirent Solutions To Validate Best-In-Class Performance Of FortiGate-3040B</p>
<p> Spirent TestCenter Used for Performance Evaluation of New High-End Security Appliance; FortiGate-3040B Delivers Extremely Low Latency with 40 Gbps Firewall Throughput </p>
<p>MALAYSIA, 8 November, 2010 &#8211; Fortinet &#8211; a leading network security provider and the worldwide leader of unified threat management (UTM) solutions, and Spirent Communications plc., the leading provider of testing solutions for networks, devices and services, today announced the results of performance tests conducted on the FortiGate-3040B, the newest Fortinet multi-threat security appliance purpose-built for large enterprise and data center environments. Testing with Spirent solutions showed that the FortiGate-3040B delivers a steady 40Gbps of performance in both UDP and TCP traffic through four 10 Gbps Ethernet ports and supports full line-rate application traffic with zero packet loss. The appliance also achieves latency as low as 3.94 microseconds under 100 percent load. Other test results unveil that the FortiGate-3040B supports up to 5,600,000 concurrent sessions and 160,000 transactions per second.</p>
<p>FortiGate-3040B comes standard with eight 10-Gigabit Ethernet ports, all in a single, compact 2-RU appliance form factor.  The appliance also includes both of Fortinet’s innovative FortiASIC processors &#8212; content processor (CP4) and network processor (NP4). </p>
<p>The UDP traffic throughput test was performed with Spirent TestCenter, which was used as a UDP traffic injector through a total of four 10 Gbps Ethernet ports. The test was conducted with a mix of packets, including 66, 594 and 1518 byte packets, and showed performance of 130 million packets per second. The amount of latency introduced by the FortiGate-3040B was minimal, with an average of 7.14 microseconds and getting as low as 3.94 µs at 64 bytes and zero packet loss. </p>
<p>The TCP traffic throughput test was performed with the Spirent Avalanche, used as a HTTP application traffic generator through a total of four 10 Gbps Ethernet ports. The test was conducted under the following parameters: three-way TCP handshakes; TCP Window Size at 64kB; and 10 HTTP transactions in 1 TCP connection. It showed application data performance of 37,65 Gbps throughput, which is equivalent to 40 Gbps of  line-rate Ethernet.</p>
<p>“The Spirent TestCenter platform has become the standard for testing high-end security products in complex networks,” said Jeff Schmitz, vice president, Networks &#038; Applications at Spirent Communications. “Large enterprise and data center environments must protect their most critical assets while, at the same time, keeping up with the increased bandwidth requirements of their network. The test of FortiGate-3040B validates the robustness, performance, and stability Fortinet’s customers can expect from this high-end network security system.”</p>
<p>The Spirent test results highlight the best-in-class firewall price-performance of the FortiGate-3040B. This 10-GbE network security appliance provides the highest 10-GbE port density in<br />
its class and includes the latest FortiASIC network processors (NP4), which work inline with the flow of traffic and accelerate firewall and VPN functions.</p>
<p>“For several years now, we’ve been able to prove to our customers that our high-end UTM appliances can compare with point solutions in terms of performance and robustness. The addition of the FortiGate-3040B to our network security product line is no exception,” said Michael Xie, founder, CTO and vice president of engineering for Fortinet. “By leveraging Spirent’s test methodology and services, we enhance our customers’ confidence in our new products. With this test in particular, we are able to objectively demonstrate the outstanding performance and quality of the FortiGate-3040B, which delivers an unmatched mix of performance, flexibility, and security for its price class.”</p>
<p>Fortinet’s FortiGate-3040B appliance is the latest to join the FortiGate-3000 series product family, and integrates high-performance firewall capabilities with advanced unified threat management protection in a single system to help protect organizations’ vital assets. It adds to the FortiGate-3950B series, which was introduced earlier this year and delivers up to 120 Gbps of low-latency firewall inspection performance to help secure the most demanding enterprise environments, including high-speed data centers and network perimeters.</p>
<p>Fortinet’s FortiGate-3040B provides high bandwidth connectivity to the security gateway and delivers up to 17 Gigabits-per-second of virtual private network (VPN) performance.  The appliance provides exceptional deployment versatility by providing the industry’s greatest port-density in its price class. A total of 20 ports are included on the system comprised of modular SFP+, SFP and traditional RJ-45 ports.</p>
<p>Like other enterprise-class multi-threat security appliances from Fortinet, the FortiGate-3040B is equipped with the FortiOS 4.0 MR2 operating system to effectively neutralize a wide range of security threats facing networks today.  </p>
                  <div id="lass"><table style="width: 547px; height: 58px;" id="tkod" border="1" cellpadding="3" cellspacing="0"><tbody id="in_f"><tr id="x52g"><td id="t-61" width="100%">If you like this post then please consider subscribing to my <a title="full feed RSS" target="_blank" href="http://feeds.feedburner.com/NotJustABlog/" id="lir7">full feed RSS</a>.&nbsp; <br id="n8k0">You can also <a title="subscribe by Email" target="_blank" href="http://www.feedburner.com/fb/a/emailverifySubmit?feedId=896848" id="yn:q">subscribe by Email</a> and have new posts sent directly to your inbox.<br id="ejzb"><span id="og23" style="font-weight: bold;">&nbsp;<br id="s4-r"></span><span id="og23"><br />
This post originally came from Zaki's <a id="rf:t" href="www.blogjer.com">Blogjer.com</a></span></td></tr></tbody></table></div><span id="t7vz" style="font-weight: bold;"></span><br id="bvf9"><span id="rg-m" style="font-weight: bold;"></span><br id="pzdj" style="font-weight: bold;"><br id="q1m7">      <p>---<br />Related Articles at Blogjer - Technology at a glance:<ul><li><a href="http://www.blogjer.com/2010/12/01/fortinet-introduces-world%e2%80%99s-fastest-unified-threat-management-security-and-switching-blades/" rel="bookmark" title="Permanent Link: Fortinet Introduces World’s Fastest Unified Threat Management Security and Switching Blades">Fortinet Introduces World’s Fastest Unified Threat Management Security and Switching Blades</a></li><li><a href="http://www.blogjer.com/2010/09/03/fortinet-august-threat-landscape-report-shows-return-of-ransomware-and-rise-of-%e2%80%98do-it-yourself%e2%80%99-botnets/" rel="bookmark" title="Permanent Link: Fortinet August Threat Landscape Report Shows Return of Ransomware and Rise of ‘Do-it-Yourself’ Botnets">Fortinet August Threat Landscape Report Shows Return of Ransomware and Rise of ‘Do-it-Yourself’ Botnets</a></li><li><a href="http://www.blogjer.com/2010/12/07/fortinet-november-threat-landscape-report-highlights-reduced-spam-levels-after-bredolab-takedown/" rel="bookmark" title="Permanent Link: Fortinet November Threat Landscape Report Highlights Reduced Spam Levels after Bredolab Takedown">Fortinet November Threat Landscape Report Highlights Reduced Spam Levels after Bredolab Takedown</a></li><li><a href="http://www.blogjer.com/2010/08/04/fortinet-july-threat-landscape-report-shows-sasfis-botnet-variants-multiplying/" rel="bookmark" title="Permanent Link: Fortinet July Threat Landscape Report Shows Sasfis Botnet Variants Multiplying">Fortinet July Threat Landscape Report Shows Sasfis Botnet Variants Multiplying</a></li><li><a href="http://www.blogjer.com/2010/08/23/fortinet-expands-web-application-firewall-family-with-new-appliances-for-enterprises-application-service-and-cloud-based-service-providers/" rel="bookmark" title="Permanent Link: Fortinet Expands Web Application Firewall Family with New Appliances for Enterprises, Application Service and Cloud-based Service Providers">Fortinet Expands Web Application Firewall Family with New Appliances for Enterprises, Application Service and Cloud-based Service Providers</a></li></ul></p><br />]]></content:encoded>
			<wfw:commentRss>http://www.blogjer.com/2010/11/08/fortinet-leverages-spirent-solutions-to-validate-best-in-class-performance-of-fortigate-3040b/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>October Threat Landscape Report Highlights Increased Zeus/Money Mule Risk</title>
		<link>http://www.blogjer.com/2010/11/03/october-threat-landscape-report-highlights-increased-zeusmoney-mule-risk/</link>
		<comments>http://www.blogjer.com/2010/11/03/october-threat-landscape-report-highlights-increased-zeusmoney-mule-risk/#comments</comments>
		<pubDate>Wed, 03 Nov 2010 13:46:27 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[fortinet]]></category>

		<guid isPermaLink="false">http://www.blogjer.com/?p=11815</guid>
		<description><![CDATA[October Fortinet Threat Landscape Report highlights few key points on the increased of Zeus/Money Mule risks as follows Fortinet today announced its October 2010 Threat Landscape Report which warns of increased Zeus activity and the related risks money mules take when signing up for questionable job opportunities. Money mules have been aggressively recruited this year to [...]]]></description>
			<content:encoded><![CDATA[<p>October Fortinet Threat Landscape Report highlights few key points on the increased of Zeus/Money Mule risks as follows</p>
<ol>
<li>Fortinet today announced its October 2010 Threat Landscape Report which warns of increased Zeus activity and the related risks money mules take when signing up for questionable job opportunities.</li>
<li>Money mules have been aggressively recruited this year to help cyber criminals launder money.</li>
<li>Fortinet’s Money Mule warning signs and key guidelines on how to prevent someone from inadvertently becoming a money mule.</li>
</ol>
<p>Further reading could be found on the press release</p>
<h1><strong><span style="font-family: 'Times New Roman'; font-size: medium;"><em>Fortinet October Threat Landscape Report Highlights Increased Zeus/Money Mule Risks</em></span></strong></h1>
<p><span style="font-family: 'Times New Roman'; font-size: medium;"><em> </em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em>Report Offers Money Mule Recruitment Warning Signs </em></span></p>
<p><strong><span style="font-family: 'Times New Roman'; font-size: small;"><em>MALAYSIA, 29 October, 2010 </em></span></strong><em>- <span style="color: black;">Fortinet –</span> a leading network security provider and the worldwide leader of unified threat management (UTM) solutions – today announced its October 2010 Threat Landscape report, which warns of increased Zeus activity and the related risks money mules take when signing up for questionable job opportunities.</em></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em> </em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em>“As outlined in our ‘<a href="http://blog.fortinet.com/fret-the-threat-2010-predictions-realized/" target="_blank">2010 Threat Predictions Realized</a>’ report, money mules have been aggressively recruited this year to help cyber criminals launder money,” said Derek Manky, project manager, cyber security and threat research, Fortinet. “A recent example of this is the worldwide prosecutions of a Zeus criminal operation, which included 37 charges brought against alleged money mules.”</em></span></p>
<p><strong><span style="font-family: 'Times New Roman'; font-size: small;"><em> </em></span></strong></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em>Recent Zeus stories illustrate how prevalent money mules have become and how they are being used to filter, disguise and spread money transfers. Mules today are typically recruited into criminal organizations through legitimate-looking advertisements. A suspect ad may suggest a client is looking for a “payment processing agent,” “money transfer agent,” or something as general and vague as an “administrative representative.” These recruitment ads can be found anywhere from print and online job sites to direct points of contact. While many mules likely enter into the business relationship knowing the full criminal implications of what they’re doing, there are a surprising number that do not.</em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em> </em></span></p>
<p><strong><span style="font-family: 'Times New Roman'; font-size: small;"><em>Preying on the Desperation of Job Seekers</em></span></strong></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em>One of the most recent money mule recruitment emails FortiGuard flagged this month began the subject line with, &#8220;Re: CV.” The body of the email offered the recipient an &#8220;administrative representative&#8221; position for a proposed salary of </em></span><span style="color: black;"><em>€</em></span><em>5,000 per month plus commission. One of the listed job duties was to &#8220;administer day-to-day financial responsibilities for clients,&#8221; as well as prepare weekly financial reports.</em></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em> </em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em>“The majority of opportunities we’re seeing today offer prospects roughly 10 percent commission for any transfers they make,” Manky continued. “With a few simple clicks, a $10,000 transfer could net the mule roughly $1,000.” </em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em> </em></span></p>
<p><strong><span style="font-family: 'Times New Roman'; font-size: small;"><em>Money Mule Warning Signs</em></span></strong></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em>The following guidelines can be used to help prevent someone from inadvertently becoming a money mule:</em></span></p>
<p><span style="font-family: Symbol; font-size: small;"><em>·<span style="font-family: 'Times New Roman'; font-size: xx-small;"> </span></em></span><em>If the job offer sounds too good to be true, then it probably is. Be wary of any job opportunities that promise great rewards for little or no work or work experience.</em></p>
<p><span style="font-family: Symbol; font-size: small;"><em>·<span style="font-family: 'Times New Roman'; font-size: xx-small;"> </span></em></span><em>If the job description is vague, unclear and/or doesn’t stipulate who you would be reporting to in the new position, then do deeper research into the company to get those questions answered.</em></p>
<p><span style="font-family: Symbol; font-size: small;"><em>·<span style="font-family: 'Times New Roman'; font-size: xx-small;"> </span></em></span><em>Be especially scrupulous with regards to money transfer job offers that are coming from overseas, as they can be very difficult to research and verify. If the company in question doesn’t have verifiable contact information (phone, email contact and address) on their web site, think twice about working with them.</em></p>
<p><span style="font-family: Symbol; font-size: small;"><em>·<span style="font-family: 'Times New Roman'; font-size: xx-small;"> </span></em></span><em>Be cognizant of any company that asks for a personal bank account number as the means through which money is expected to flow. Recruiters will typically mandate that their mules use anonymous money transferring services for outbound funds; as with any scam, be cautious of a request such as this.</em></p>
<p><span style="font-family: Symbol; font-size: small;"><em>·<span style="font-family: 'Times New Roman'; font-size: xx-small;"> </span></em></span><em>Security services such as antispam and web content filtering can also help to minimize money mule recruitment attempts, as they could help flag the recruitment emails, or potentially warn or block specific illegitimate job recruitment domains.</em></p>
<p><span style="font-family: Symbol; font-size: small;"><em>·<span style="font-family: 'Times New Roman'; font-size: xx-small;"> </span></em></span><em>Anyone suspecting they may have been a victim of this type of crime should contact their bank immediately.</em></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em> </em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em>FortiGuard Labs compiled threat statistics and trends for October based on data collected from FortiGate network security appliances and intelligence systems in production worldwide. Customers who use Fortinet’s <a href="http://www.fortinet.com/products/fortiguard_services/" target="_blank">FortiGuard Services</a> should already be protected against the threats outlined in this report.</em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em> </em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><a href="http://www.fortinet.com/products/fortiguard.html" target="_blank"><em>FortiGuard Services</em></a><em> offer broad security solutions including antivirus, intrusion prevention, Web content filtering and anti-spam capabilities. These services help protect against threats on both application and network layers. FortiGuard Services are updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and zero-day protection from new and emerging threats. For customers with a subscription to FortiGuard, these updates are delivered to all FortiGate, FortiMail and FortiClient products.</em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em> </em></span></p>
<p><span style="font-family: 'Times New Roman'; font-size: small;"><em>The full October <a href="http://www.fortiguard.com/report/roundup_october_2010.html" target="_blank">Threat Landscape report</a>, which includes the top threat rankings in several categories, is available now. Ongoing research can be found in the <a href="http://www.fortiguard.com/" target="_blank">FortiGuard Center</a> or via <a href="http://www.fortiguard.com/" target="_blank">FortiGuard Labs</a>’ <a href="http://www.fortiguard.com/rss/fg.xml" target="_blank">RSS feed</a>. Additional discussion on security technologies and threat analysis can be found at the <a href="http://blog.fortinet.com/" target="_blank">Fortinet Security Blog</a>.</em></span></p>
                  <div id="lass"><table style="width: 547px; height: 58px;" id="tkod" border="1" cellpadding="3" cellspacing="0"><tbody id="in_f"><tr id="x52g"><td id="t-61" width="100%">If you like this post then please consider subscribing to my <a title="full feed RSS" target="_blank" href="http://feeds.feedburner.com/NotJustABlog/" id="lir7">full feed RSS</a>.&nbsp; <br id="n8k0">You can also <a title="subscribe by Email" target="_blank" href="http://www.feedburner.com/fb/a/emailverifySubmit?feedId=896848" id="yn:q">subscribe by Email</a> and have new posts sent directly to your inbox.<br id="ejzb"><span id="og23" style="font-weight: bold;">&nbsp;<br id="s4-r"></span><span id="og23"><br />
This post originally came from Zaki's <a id="rf:t" href="www.blogjer.com">Blogjer.com</a></span></td></tr></tbody></table></div><span id="t7vz" style="font-weight: bold;"></span><br id="bvf9"><span id="rg-m" style="font-weight: bold;"></span><br id="pzdj" style="font-weight: bold;"><br id="q1m7">      <p>---<br />Related Articles at Blogjer - Technology at a glance:<ul><li><a href="http://www.blogjer.com/2010/12/07/fortinet-november-threat-landscape-report-highlights-reduced-spam-levels-after-bredolab-takedown/" rel="bookmark" title="Permanent Link: Fortinet November Threat Landscape Report Highlights Reduced Spam Levels after Bredolab Takedown">Fortinet November Threat Landscape Report Highlights Reduced Spam Levels after Bredolab Takedown</a></li><li><a href="http://www.blogjer.com/2010/09/03/fortinet-august-threat-landscape-report-shows-return-of-ransomware-and-rise-of-%e2%80%98do-it-yourself%e2%80%99-botnets/" rel="bookmark" title="Permanent Link: Fortinet August Threat Landscape Report Shows Return of Ransomware and Rise of ‘Do-it-Yourself’ Botnets">Fortinet August Threat Landscape Report Shows Return of Ransomware and Rise of ‘Do-it-Yourself’ Botnets</a></li><li><a href="http://www.blogjer.com/2009/01/13/mcafee-monthly-spam-report-educating-people-about-spam/" rel="bookmark" title="Permanent Link: McAfee monthly spam report &#8211; educating people about spam">McAfee monthly spam report &#8211; educating people about spam</a></li><li><a href="http://www.blogjer.com/2010/08/04/fortinet-july-threat-landscape-report-shows-sasfis-botnet-variants-multiplying/" rel="bookmark" title="Permanent Link: Fortinet July Threat Landscape Report Shows Sasfis Botnet Variants Multiplying">Fortinet July Threat Landscape Report Shows Sasfis Botnet Variants Multiplying</a></li><li><a href="http://www.blogjer.com/2010/10/20/maxis-to-offer-samsung-galaxy-tab-on-29-october/" rel="bookmark" title="Permanent Link: Maxis To Offer Samsung Galaxy Tab On 29 October">Maxis To Offer Samsung Galaxy Tab On 29 October</a></li></ul></p><br />]]></content:encoded>
			<wfw:commentRss>http://www.blogjer.com/2010/11/03/october-threat-landscape-report-highlights-increased-zeusmoney-mule-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Five Easy Steps To iPhone Security</title>
		<link>http://www.blogjer.com/2010/09/28/five-easy-steps-to-iphone-security/</link>
		<comments>http://www.blogjer.com/2010/09/28/five-easy-steps-to-iphone-security/#comments</comments>
		<pubDate>Tue, 28 Sep 2010 00:53:54 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[fortine iphone security tips]]></category>
		<category><![CDATA[fortinet]]></category>
		<category><![CDATA[IOS]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[iphone security]]></category>
		<category><![CDATA[iphone security tips]]></category>
		<category><![CDATA[securing iphone]]></category>

		<guid isPermaLink="false">http://www.blogjer.com/?p=11406</guid>
		<description><![CDATA[With iPhone 4 frenzy continue to last until the next couple of weeks here in Malaysia as well as other countries, do not taking  lightly about the possible threat that could harm your iPhone and it&#8217;s user. If the iPhone is meant for your kids, it&#8217;s a good idea to start thinking of securing your [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.blogjer.com/wp-content/uploads/2010/09/secure_iphone4.jpg" rel="thumbnail"><img class="alignnone size-full wp-image-11408" title="secure_iphone4" src="http://www.blogjer.com/wp-content/uploads/2010/09/secure_iphone4.jpg" alt="secure iphone4 Five Easy Steps To iPhone Security" width="267" height="400" /></a></p>
<p>With iPhone 4 frenzy continue to last until the next couple of weeks here in Malaysia as well as other countries, do not taking  lightly about the possible threat that could harm your iPhone and it&#8217;s user. If the iPhone is meant for your kids, it&#8217;s a good idea to start thinking of securing your loves one from anything that could possibly hurt them. Fortinet FortiGuard Labs has released short but useful article that will be a basis to get started with. Read on.</p>
<p><strong>Five Easy Steps to iPhone Security!</strong></p>
<p><em>Apple’s latest shiny new iPhone 4 gadgets may have taken the world by storm but in the same vein, such mobile devices are now becoming a key target for cybercriminals and mobile spyware.</em></p>
<p><em>Why? Well, your trusty iPhone contains your closely guarded personal information, including photographs, contact database, possibly your credit card details, banking information, email exchanges, personal address, etc. It also connects you to tens if not hundreds of Internet applications that make your life easier. So now, imagine all this information falling into unscrupulous hands, a psychotic stalker, or becoming public information overnight!<br />
</em></p>
<p><em>This is exactly what a mobile spyware can do once it has entrenched itself in your iPhone. This insidious, crafty malware can secretly tap your phone calls, record and transfer SMS/MMS/e-mail messages, locate you geographically, listen to your surroundings, take pictures, downloads contacts, log activity&#8230; or steal your online banking credentials like the infamous Eeki worm did.</em></p>
<p><em>So, even if it has not been affected yet, do not underestimate the potential vulnerability of your iPhone. Taking care of your iPhone security is very much like taking care of your child.<br />
Education plays an important role!</em></p>
<p><em>Follow these essential security tips to protect your iPhone and its data:</em></p>
<p><strong><em>1. Would you let your child answer a stranger?</em></strong></p>
<p><em>No. So, do not open unknown SMS or MMS on your iPhone.</em></p>
<p><strong><em>2. Just before buying your child a new game, wouldn&#8217;t you check if it&#8217;s suitable for his/her age or if other parents consider it as an interesting game?</em></strong></p>
<p><em>You probably try to. The same applies to your phone: gather as much information as possible before downloading an unknown application (search for comments and reviews from other users,<br />
scan for online against viruses etc).</em></p>
<p><strong><em>3. Do you inoculate your child against polio?</em></strong></p>
<p><em>Then, you might consider installing an anti-virus on your mobile phone, or at least check anti-virus reports regularly.</em></p>
<p><strong><em>4. Imagine a highly dangerous virus was circulating in your child’s school. Wouldn’t you keep him/her away, until any risks have disappeared?</em></strong></p>
<p><em>Similarly, do not connect your iPhone to an infected computer and run anti-virus software on your PC or laptop to make sure it is malware-free before connecting your iPhone for synchronization.</em></p>
<p><strong><em>5. When your child is harmed, wouldn’t you report it to some official authority (school,police, medical doctor)?</em></strong></p>
<p><em>Do the same with your phone. Do not fear to report suspicious activities to your operator, your bank, consumer groups, anti-virus companies or in worse cases to the nearby police station. The<br />
more we are aware, the more we can all fight against criminality.</em></p>
                  <div id="lass"><table style="width: 547px; height: 58px;" id="tkod" border="1" cellpadding="3" cellspacing="0"><tbody id="in_f"><tr id="x52g"><td id="t-61" width="100%">If you like this post then please consider subscribing to my <a title="full feed RSS" target="_blank" href="http://feeds.feedburner.com/NotJustABlog/" id="lir7">full feed RSS</a>.&nbsp; <br id="n8k0">You can also <a title="subscribe by Email" target="_blank" href="http://www.feedburner.com/fb/a/emailverifySubmit?feedId=896848" id="yn:q">subscribe by Email</a> and have new posts sent directly to your inbox.<br id="ejzb"><span id="og23" style="font-weight: bold;">&nbsp;<br id="s4-r"></span><span id="og23"><br />
This post originally came from Zaki's <a id="rf:t" href="www.blogjer.com">Blogjer.com</a></span></td></tr></tbody></table></div><span id="t7vz" style="font-weight: bold;"></span><br id="bvf9"><span id="rg-m" style="font-weight: bold;"></span><br id="pzdj" style="font-weight: bold;"><br id="q1m7">      <p>---<br />Related Articles at Blogjer - Technology at a glance:<ul><li><a href="http://www.blogjer.com/2008/07/02/paypal-security-challange/" rel="bookmark" title="Permanent Link: paypal security challange">paypal security challange</a></li><li><a href="http://www.blogjer.com/2008/07/06/how-to-prevent-sending-email-from-ms-outlook-without-subject-in-place/" rel="bookmark" title="Permanent Link: how to prevent sending email from MS outlook without subject in place">how to prevent sending email from MS outlook without subject in place</a></li><li><a href="http://www.blogjer.com/2008/11/26/paypal-introduces-security-key-texted-to-your-mobile-sms/" rel="bookmark" title="Permanent Link: Paypal introduces security key texted to your mobile (SMS)">Paypal introduces security key texted to your mobile (SMS)</a></li><li><a href="http://www.blogjer.com/2008/06/10/even-security-blog-does-have-spams/" rel="bookmark" title="Permanent Link: even security blog does have spams..">even security blog does have spams..</a></li><li><a href="http://www.blogjer.com/2010/03/15/apple-to-support-multitasking-in-iphone-os-40/" rel="bookmark" title="Permanent Link: Apple To Support Multitasking in iPhone OS 4.0?">Apple To Support Multitasking in iPhone OS 4.0?</a></li></ul></p><br />]]></content:encoded>
			<wfw:commentRss>http://www.blogjer.com/2010/09/28/five-easy-steps-to-iphone-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fortinet Expands Web Application Firewall Family with New Appliances for Enterprises, Application Service and Cloud-based Service Providers</title>
		<link>http://www.blogjer.com/2010/08/23/fortinet-expands-web-application-firewall-family-with-new-appliances-for-enterprises-application-service-and-cloud-based-service-providers/</link>
		<comments>http://www.blogjer.com/2010/08/23/fortinet-expands-web-application-firewall-family-with-new-appliances-for-enterprises-application-service-and-cloud-based-service-providers/#comments</comments>
		<pubDate>Mon, 23 Aug 2010 06:27:38 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[fortinet]]></category>
		<category><![CDATA[Web Application Firewall]]></category>

		<guid isPermaLink="false">http://www.blogjer.com/?p=10965</guid>
		<description><![CDATA[Fortinet on early this month has announced the expansion of the web application firewall family with new appliances designed for enterprises, application service and cloud-based service providers, among the key highlights are: Fortinet announced two new appliances for its FortiWeb family of web application firewalls – the FortiWeb-1000C, designed for mid-to-large enterprises, and FortiWeb-3000C, the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.blogjer.com/wp-content/uploads/2010/08/fortinet.gif" rel="thumbnail"><img class="alignnone size-full wp-image-10427" title="fortinet" src="http://www.blogjer.com/wp-content/uploads/2010/08/fortinet.gif" alt="fortinet Fortinet Expands Web Application Firewall Family with New Appliances for Enterprises, Application Service and Cloud based Service Providers" width="432" height="62" /></a></p>
<p>Fortinet on early this month has announced the expansion of the web application firewall family with new appliances designed for enterprises, application service and cloud-based service providers, among the key highlights are:</p>
<ul>
<li>Fortinet announced two new appliances for its FortiWeb family of web application firewalls – the FortiWeb-1000C, designed for mid-to-large enterprises, and FortiWeb-3000C, the flagship system for high-end enterprises, application service and cloud-based service providers.</li>
<li>Each appliance is equipped with the new FortiWeb 4.0 MR1 firmware that is designed to provide maximum protection for web applications containing sensitive data subject to Payment Card Industry (PCI) guidelines.</li>
<li>The FortiWeb-1000C and 3000C appliances are integrated web application and XML firewalls that protect against attacks targeted at web applications and web services infrastructure.</li>
</ul>
<p>Press Release</p>
<h1><em><strong>Fortinet Expands Web Application Firewall Family with New Appliances for Enterprises, Application Service and Cloud-based Service Providers </strong></em></h1>
<p><em> </em></p>
<p><em>FortiWeb-1000C and FortiWeb-3000C Leverage Major New Firmware to Provide Greater </em></p>
<p><em>Deployment Flexibility and Significant Security Enhancements </em></p>
<p><em><strong> </strong></em></p>
<p><em><strong>MALAYSIA, 10 August 2010 </strong>– Fortinet, a leading network security provider and a worldwide leader of unified threat management (UTM) solutions – today announced two new appliances for its FortiWeb family of web application firewalls – the FortiWeb-1000C, designed for mid-to-large enterprises, and FortiWeb-3000C, the flagship system for high-end enterprises, application service and cloud-based service providers.  Each appliance is equipped with the new FortiWeb 4.0 MR1 firmware that is designed to provide maximum protection for web applications containing sensitive data subject to Payment Card Industry (PCI) guidelines.  The new web application firewalls will also blunt potentially crippling attacks such as SQL injection and cross-site scripting, and help prevent security breaches from exposing highly sensitive data loss such as credit card numbers and personally identifiable information.</em></p>
<p><em>With the addition of the FortiWeb-1000C and FortiWeb-3000C, Fortinet now offers four web application firewall appliances to provide retail and payment, financial services and healthcare customers with a full range of deployment options.  In the case of retail and payment customers, the new FortiWeb products greatly minimize the complexity of complying with PCI Data Security Standard (DSS) section 6.5 and 6.6 as well as California Senate Bill 1386 that address the rampant problems of identity theft and financial fraud.  The FortiWeb-1000C and FortiWeb-3000C also provide robust patient data protection as part of HIPAA compliance for healthcare organizations.</em></p>
<p><em>“The need to protect web applications that contain sensitive credit, financial or personal information from increasingly sophisticated attacks and data loss has never been greater,” said Paula Musich, senior analyst, Current Analysis. “The simple fact of the matter is that organizations are deploying web applications and regulated Internet-facing data more broadly than ever.  For hackers and cyber-criminals, that’s like painting a giant bulls-eye on those applications, which gather credit card data and personally identifiable information with minimal protection in place. That’s why putting in place sophisticated web protection and threat management solutions with powerful policy enforcement capabilities should be a standard practice for any organization doing business on the web.”</em></p>
<p><em>The FortiWeb-1000C and 3000C appliances are integrated web application and XML firewalls that protect against attacks targeted at web applications and web services infrastructure. Because they provide detailed visibility into an organization’s threat landscape, the FortiWeb application firewalls eliminate the need to manage separate web and threat management tools and consoles. Not only does this streamline security efforts and reduce infrastructure complexity, it drastically reduces the time required to protect regulated data and achieve regulatory compliance.</em></p>
<p><em>To preserve optimal web application performance, the FortiWeb application firewalls leverage an intelligent, application-aware load-balancing engine to distribute traffic and route content across multiple web servers. This load balancing increases application performance, improves resource utilization and application stability while reducing service response times.</em></p>
<p><em><strong>What’s New in FortiWeb Application Firewalls</strong></em></p>
<p><em>The release of FortiWeb 4.0 MR1 provides a series of major enhancements to the new FortiWeb-1000C and FortiWeb-3000C application firewalls, including:</em></p>
<p><em>•           <strong>Policy wizard and pre-defined policies</strong> – allows for one click deployments and eases the process of rules creation greatly</em></p>
<p><em>•           <strong>Advanced alert tool</strong> – makes it easy to sift through hundreds of alerts, identify repetitive attackers using various aggregation fields and quickly understand the nature of attacks.</em></p>
<p><em>•           <strong>Enhanced Protocol Constraints</strong> – enforces policies that ensure any access to the web application is done in accordance with the HTTP RFC standard.</em></p>
<p><em>•           <strong>Extended signatures and DLP</strong> – allows customers to create their own granular signatures and data loss prevention patterns from a FortiWeb graphical user interface for any type of event, in addition to the pre-defined application signatures and data loss prevention rules.</em></p>
<p><em>“Customer demand for more powerful web application infrastructure security is soaring due to a combination of evolving attacks, security breaches, regulatory compliance and web defacement incidents,” said Michael Xie, founder, CTO and vice president of engineering at Fortinet.  “At the same time, more content is being delivered via the web, and both cloud providers and large enterprises need robust security solutions that can protect web application infrastructures without affecting application performance. The addition of the FortiWeb-1000C and FortiWeb-3000C appliances to the FortiWeb product family directly addresses this demand. These new platforms can play a pivotal role in helping preserve the security and uninterrupted operation of our customers’ web application infrastructures.”</em></p>
<p><em><strong> </strong></em></p>
<p><em><strong>Availability</strong></em></p>
<p><em>The FortiWeb-1000C and FortiWeb-3000C are available now.</em></p>
                  <div id="lass"><table style="width: 547px; height: 58px;" id="tkod" border="1" cellpadding="3" cellspacing="0"><tbody id="in_f"><tr id="x52g"><td id="t-61" width="100%">If you like this post then please consider subscribing to my <a title="full feed RSS" target="_blank" href="http://feeds.feedburner.com/NotJustABlog/" id="lir7">full feed RSS</a>.&nbsp; <br id="n8k0">You can also <a title="subscribe by Email" target="_blank" href="http://www.feedburner.com/fb/a/emailverifySubmit?feedId=896848" id="yn:q">subscribe by Email</a> and have new posts sent directly to your inbox.<br id="ejzb"><span id="og23" style="font-weight: bold;">&nbsp;<br id="s4-r"></span><span id="og23"><br />
This post originally came from Zaki's <a id="rf:t" href="www.blogjer.com">Blogjer.com</a></span></td></tr></tbody></table></div><span id="t7vz" style="font-weight: bold;"></span><br id="bvf9"><span id="rg-m" style="font-weight: bold;"></span><br id="pzdj" style="font-weight: bold;"><br id="q1m7">      <p>---<br />Related Articles at Blogjer - Technology at a glance:<ul><li><a href="http://www.blogjer.com/2010/12/01/fortinet-introduces-world%e2%80%99s-fastest-unified-threat-management-security-and-switching-blades/" rel="bookmark" title="Permanent Link: Fortinet Introduces World’s Fastest Unified Threat Management Security and Switching Blades">Fortinet Introduces World’s Fastest Unified Threat Management Security and Switching Blades</a></li><li><a href="http://www.blogjer.com/2010/11/08/fortinet-leverages-spirent-solutions-to-validate-best-in-class-performance-of-fortigate-3040b/" rel="bookmark" title="Permanent Link: Fortinet Leverages Spirent Solutions To Validate Best-In-Class Performance Of FortiGate-3040B">Fortinet Leverages Spirent Solutions To Validate Best-In-Class Performance Of FortiGate-3040B</a></li><li><a href="http://www.blogjer.com/2010/11/19/fortinet-introduces-new-messaging-security-appliance-for-high-performance-corporate-email-routing/" rel="bookmark" title="Permanent Link: Fortinet Introduces New Messaging Security Appliance for High-Performance Corporate Email Routing">Fortinet Introduces New Messaging Security Appliance for High-Performance Corporate Email Routing</a></li><li><a href="http://www.blogjer.com/2010/12/07/fortinet-november-threat-landscape-report-highlights-reduced-spam-levels-after-bredolab-takedown/" rel="bookmark" title="Permanent Link: Fortinet November Threat Landscape Report Highlights Reduced Spam Levels after Bredolab Takedown">Fortinet November Threat Landscape Report Highlights Reduced Spam Levels after Bredolab Takedown</a></li><li><a href="http://www.blogjer.com/2010/09/03/fortinet-august-threat-landscape-report-shows-return-of-ransomware-and-rise-of-%e2%80%98do-it-yourself%e2%80%99-botnets/" rel="bookmark" title="Permanent Link: Fortinet August Threat Landscape Report Shows Return of Ransomware and Rise of ‘Do-it-Yourself’ Botnets">Fortinet August Threat Landscape Report Shows Return of Ransomware and Rise of ‘Do-it-Yourself’ Botnets</a></li></ul></p><br />]]></content:encoded>
			<wfw:commentRss>http://www.blogjer.com/2010/08/23/fortinet-expands-web-application-firewall-family-with-new-appliances-for-enterprises-application-service-and-cloud-based-service-providers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fortinet July Threat Landscape Report Shows Sasfis Botnet Variants Multiplying</title>
		<link>http://www.blogjer.com/2010/08/04/fortinet-july-threat-landscape-report-shows-sasfis-botnet-variants-multiplying/</link>
		<comments>http://www.blogjer.com/2010/08/04/fortinet-july-threat-landscape-report-shows-sasfis-botnet-variants-multiplying/#comments</comments>
		<pubDate>Wed, 04 Aug 2010 11:30:07 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[fortinet]]></category>

		<guid isPermaLink="false">http://www.blogjer.com/?p=10424</guid>
		<description><![CDATA[Fortinet has just released July 2010 Threat Landscape report  which showed that 8  Sasfis botnet variants have landed in the company’s top 10 malware listing this period. Among the key highlight in the report are as follow. For complete report, please find the press release at the bottom of this post. Eight Sasfis botnet variants [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.blogjer.com/wp-content/uploads/2010/08/fortinet.gif" rel="thumbnail"><img class="alignnone size-full wp-image-10427" title="fortinet" src="http://www.blogjer.com/wp-content/uploads/2010/08/fortinet.gif" alt="fortinet Fortinet July Threat Landscape Report Shows Sasfis Botnet Variants Multiplying" width="432" height="62" /></a></p>
<p>Fortinet has just released July 2010 Threat Landscape report  which showed that 8  Sasfis botnet variants have landed in the  company’s top 10 malware listing this period. Among the key highlight in the report are as follow. For complete report, please find the press release at the bottom of this post.</p>
<ul>
<li>Eight Sasfis botnet variants have landed in Fortinet’s top 10 malware listing this period.</li>
<li>Earlier this year, the Sasfis botnet was dedicated to downloading and executing software (primarily fake antivirus) on infected systems. This period, Sasfis was observed downloading updated spamming modules</li>
<li>This month’s Stuxnet attack, reiterates the importance of quickly patching security holes as fixes become available and having a broad intrusion prevention system (IPS) in place.</li>
</ul>
<p>Press Release</p>
<h1><strong><span style="font-family: Times New Roman; font-size: medium;">Fortinet July  Threat Landscape Report Shows Sasfis Botnet Variants Multiplying and Focusing on Spam Delivery</span></strong></h1>
<p><em><span style="font-family: Times New Roman; font-size: small;">Stuxnet Attack Still Under Investigation While Awaiting Microsoft Patch </span></em></p>
<p><strong><span style="font-family: Times New Roman; color: black; font-size: small;">MALAYSIA, 4  August, 2010</span></strong><span style="color: black;"> – Fortinet </span>– a leading network security provider and a worldwide leader of unified  threat management (UTM) solutions<span style="color: black;"> </span>– today announced its July 2010 Threat Landscape report, which showed that  eight Sasfis botnet variants have landed in the company’s top 10 malware listing this period. This is an increasingly common occurrence, as  developers continue to roll out updated copies of their creations. Earlier this  year, the Sasfis botnet was dedicated to downloading and executing software  (primarily fake antivirus) on infected systems. This period, Sasfis was observed downloading updated spamming modules. Typical Sasfis spam examples  include fake UPS invoices and Facebook photo links.</p>
<p>Spam bots continue to diversify, sending a variety of spam themes on a  frequent basis,” said Derek Manky, project manager, cyber security and threat research, Fortinet. “This month we observed various socially engineered emails that came with HTML attachments. These attachments further  contained obfuscated javascript which would redirect users to malicious sites. The diversity of these spam campaigns and their targets shows how botnets  continue to evolve to serve the needs of their underground customers.”</p>
<p><strong><span style="font-family: Times New Roman; font-size: small;">Stuxnet Attack</span></strong></p>
<p>This month’s Stuxnet attack (read our FAQ <a href="http://blog.fortinet.com/stuxnet-a-comprehensive-faq/" target="_blank">here</a>), reiterates the importance of quickly patching security holes as fixes become  available and having a broad intrusion prevention system (IPS) in place. Even with  proper patch management, all it takes is one zero-day vulnerability to be  exploited (even in low volume) to potentially cause a significant impact. While  the Stuxnet attack is still under investigation, the fact that a trojan  associated with the exploit was seemingly developed to target industrial control  systems underscores this point. This is also a good example of how little  interaction is required by the end user to become infected. The Stuxnet exploit  attacked a Windows Shell vulnerability (<a href="http://blogs.technet.com/b/mmpc/archive/2010/07/16/the-stuxnet-sting.aspx" target="_blank">CVE-2010-2568</a>). To launch its attack, a user simply opened a folder.</p>
<p>“We saw a similar attack method with PDF files through JBIG2 image streams  and Windows shell extensions back in <a href="http://blog.fortinet.com/?s=CVE-2009-0658" target="_blank">February  2009 (CVE-2009-0658)</a>,where simply browsing a folder could trigger an infection,” Manky continued. “Fortinet detects the vulnerability associated with the Stuxnet attack  as &#8216;MS.Windows.Shell.LNK.Code.Execution,&#8217; and generically detects the  exploited ‘.LNK’ payload with antivirus as &#8216;W32/ShellLink.a!exploit.CVE20102568&#8242;. As of writing, there are  workarounds but no official patch has been released from Microsoft.”</p>
<p><strong><span style="font-family: Times New Roman; font-size: small;">Windows</span></strong><strong> Help Center</strong><strong> Vulnerability Exploited</strong></p>
<p>On June 5, vulnerability within the Windows Help and Support Center that could allow remote code execution was publicly disclosed. Like  Stuxnet, this is yet another example of a zero-day vulnerability successfully  attacked before a patch is made available. We witnessed attacks on the  vulnerability as early as June 11<sup>th</sup> before Microsoft issued a patch for <a href="http://www.microsoft.com/technet/security/advisory/2219475.mspx" target="_blank">CVE-2010-1855</a><span style="font-size: x-small;"> </span>on July 13<sup>th</sup>. The attacks that occurred through Websites were made  more potent because they were launched through the HCP protocol handler,  which is used by all browsers. In many cases Websites that serve exploits will  try to fingerprint browsers and launch attack code tailored to those browsers.</p>
<p>FortiGuard Labs  compiled threat statistics and trends for July based on data collected  from FortiGate network security appliances and intelligence systems in  production worldwide. Customers who use Fortinet’s FortiGuard Subscription Services should already be protected against the threats outlined in this report.</p>
<p>To read the full July Threat Landscape report which includes the top threat rankings in each category, please visit: <a href="http://www.fortiguard.com/report/roundup_july_2010.html" target="_blank">http://www.fortiguard.com/report/roundup_july_2010.html</a>.<span style="font-size: x-small;"> </span>For ongoing  threat research, bookmark the FortiGuard Center or add it to your RSS feed. Additional discussion on security  technologies and threat analysis can be found at the Fortinet Security Blog at <a href="http://blog.fortinet.com/" target="_blank">http://blog.fortinet.com</a>.  To learn more about FortiGuard Subscription Services, visit <a href="http://www.fortinet.com/products/fortiguard.html" target="_blank">http://www.fortinet.com/products/fortiguard.html</a>.</p>
<p>FortiGuard Subscription  Services offer broad security solutions including antivirus, intrusion prevention, Web content filtering and anti-spam capabilities.  These services help protect against threats on both application and network  layers. FortiGuard Services are updated by FortiGuard Labs, which enables  Fortinet to deliver a combination of multi-layered security intelligence and  zero-day protection from new and emerging threats. For customers with a  subscription to FortiGuard, these updates are delivered to all FortiGate, FortiMail and FortiClient products.</p>
                  <div id="lass"><table style="width: 547px; height: 58px;" id="tkod" border="1" cellpadding="3" cellspacing="0"><tbody id="in_f"><tr id="x52g"><td id="t-61" width="100%">If you like this post then please consider subscribing to my <a title="full feed RSS" target="_blank" href="http://feeds.feedburner.com/NotJustABlog/" id="lir7">full feed RSS</a>.&nbsp; <br id="n8k0">You can also <a title="subscribe by Email" target="_blank" href="http://www.feedburner.com/fb/a/emailverifySubmit?feedId=896848" id="yn:q">subscribe by Email</a> and have new posts sent directly to your inbox.<br id="ejzb"><span id="og23" style="font-weight: bold;">&nbsp;<br id="s4-r"></span><span id="og23"><br />
This post originally came from Zaki's <a id="rf:t" href="www.blogjer.com">Blogjer.com</a></span></td></tr></tbody></table></div><span id="t7vz" style="font-weight: bold;"></span><br id="bvf9"><span id="rg-m" style="font-weight: bold;"></span><br id="pzdj" style="font-weight: bold;"><br id="q1m7">      <p>---<br />Related Articles at Blogjer - Technology at a glance:<ul><li><a href="http://www.blogjer.com/2010/09/03/fortinet-august-threat-landscape-report-shows-return-of-ransomware-and-rise-of-%e2%80%98do-it-yourself%e2%80%99-botnets/" rel="bookmark" title="Permanent Link: Fortinet August Threat Landscape Report Shows Return of Ransomware and Rise of ‘Do-it-Yourself’ Botnets">Fortinet August Threat Landscape Report Shows Return of Ransomware and Rise of ‘Do-it-Yourself’ Botnets</a></li><li><a href="http://www.blogjer.com/2010/12/07/fortinet-november-threat-landscape-report-highlights-reduced-spam-levels-after-bredolab-takedown/" rel="bookmark" title="Permanent Link: Fortinet November Threat Landscape Report Highlights Reduced Spam Levels after Bredolab Takedown">Fortinet November Threat Landscape Report Highlights Reduced Spam Levels after Bredolab Takedown</a></li><li><a href="http://www.blogjer.com/2010/11/03/october-threat-landscape-report-highlights-increased-zeusmoney-mule-risk/" rel="bookmark" title="Permanent Link: October Threat Landscape Report Highlights Increased Zeus/Money Mule Risk">October Threat Landscape Report Highlights Increased Zeus/Money Mule Risk</a></li><li><a href="http://www.blogjer.com/2010/08/23/fortinet-expands-web-application-firewall-family-with-new-appliances-for-enterprises-application-service-and-cloud-based-service-providers/" rel="bookmark" title="Permanent Link: Fortinet Expands Web Application Firewall Family with New Appliances for Enterprises, Application Service and Cloud-based Service Providers">Fortinet Expands Web Application Firewall Family with New Appliances for Enterprises, Application Service and Cloud-based Service Providers</a></li><li><a href="http://www.blogjer.com/2010/11/08/fortinet-leverages-spirent-solutions-to-validate-best-in-class-performance-of-fortigate-3040b/" rel="bookmark" title="Permanent Link: Fortinet Leverages Spirent Solutions To Validate Best-In-Class Performance Of FortiGate-3040B">Fortinet Leverages Spirent Solutions To Validate Best-In-Class Performance Of FortiGate-3040B</a></li></ul></p><br />]]></content:encoded>
			<wfw:commentRss>http://www.blogjer.com/2010/08/04/fortinet-july-threat-landscape-report-shows-sasfis-botnet-variants-multiplying/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake Antivirus Threatening Windows 7 Computers</title>
		<link>http://www.blogjer.com/2010/03/23/fake-antivirus-threatening-windows-7-computers/</link>
		<comments>http://www.blogjer.com/2010/03/23/fake-antivirus-threatening-windows-7-computers/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 13:14:31 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[fake antivirus]]></category>
		<category><![CDATA[sophos]]></category>
		<category><![CDATA[windows 7 threat]]></category>

		<guid isPermaLink="false">http://www.blogjer.com/?p=8805</guid>
		<description><![CDATA[The &#8216;honeymoon&#8217; period for Windows 7 is almost over with the rising number of virus/malware that targeting that OS. The latest is, Sophos has just issued warning about malware that targeting Windows 7 computers to download fake antivirus software. The malware will try to fool you with pop up dialog box stating that your computer [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-8811" title="bfakeale1jpg" src="http://www.blogjer.com/wp-content/uploads/2010/03/bfakeale1jpg.jpeg" alt=" Fake Antivirus Threatening Windows 7 Computers" width="434" height="326" /></p>
<p>The &#8216;honeymoon&#8217; period for Windows 7 is almost over with the rising number of virus/malware that targeting that OS. The latest is, Sophos has just <a href="http://www.sophos.com/blogs/sophoslabs/?p=9178">issued warning</a> about malware that targeting Windows 7 computers to download fake antivirus software.</p>
<p>The malware will try to fool you with pop up dialog box stating that your computer has many serious threats. Clicking on the &#8216;Remove all Threats immediately&#8217; message will pop out another dialog box asking you to download the file called win_protection_update.exe. If you proceed, the malware that downloaded together with the exe file will asking for money to ‘disinfect’ the computer.</p>
<p>This unwanted incident can be simply avoided by ignoring such messages and avoiding visiting high risk websites such as porn, torrent and etc.</p>
<p><a href="http://www.infosecurity-us.com/view/8254/sophos-identifies-fake-antivirus-software-targeting-windows-7/">via</a></p>
                  <div id="lass"><table style="width: 547px; height: 58px;" id="tkod" border="1" cellpadding="3" cellspacing="0"><tbody id="in_f"><tr id="x52g"><td id="t-61" width="100%">If you like this post then please consider subscribing to my <a title="full feed RSS" target="_blank" href="http://feeds.feedburner.com/NotJustABlog/" id="lir7">full feed RSS</a>.&nbsp; <br id="n8k0">You can also <a title="subscribe by Email" target="_blank" href="http://www.feedburner.com/fb/a/emailverifySubmit?feedId=896848" id="yn:q">subscribe by Email</a> and have new posts sent directly to your inbox.<br id="ejzb"><span id="og23" style="font-weight: bold;">&nbsp;<br id="s4-r"></span><span id="og23"><br />
This post originally came from Zaki's <a id="rf:t" href="www.blogjer.com">Blogjer.com</a></span></td></tr></tbody></table></div><span id="t7vz" style="font-weight: bold;"></span><br id="bvf9"><span id="rg-m" style="font-weight: bold;"></span><br id="pzdj" style="font-weight: bold;"><br id="q1m7">      <p>---<br />Related Articles at Blogjer - Technology at a glance:<ul><li><a href="http://www.blogjer.com/2009/08/06/looking-for-antivirus-program-in-bahasa-melayu-try-avg-antivirus/" rel="bookmark" title="Permanent Link: Looking for antivirus program in Bahasa Melayu: Try AVG Antivirus">Looking for antivirus program in Bahasa Melayu: Try AVG Antivirus</a></li><li><a href="http://www.blogjer.com/2009/02/13/how-to-sync-files-shared-folder-using-windows-live-sync/" rel="bookmark" title="Permanent Link: How to sync files, shared folder using Windows Live Sync">How to sync files, shared folder using Windows Live Sync</a></li><li><a href="http://www.blogjer.com/2009/11/19/synctoy-synchronizes-folders-and-files-between-locations/" rel="bookmark" title="Permanent Link: SyncToy Synchronizes Folders and Files Between Locations">SyncToy Synchronizes Folders and Files Between Locations</a></li><li><a href="http://www.blogjer.com/2009/03/30/manage-shared-computers-with-windows-steadystate/" rel="bookmark" title="Permanent Link: Manage shared computers with Windows SteadyState">Manage shared computers with Windows SteadyState</a></li><li><a href="http://www.blogjer.com/2010/08/04/fortinet-july-threat-landscape-report-shows-sasfis-botnet-variants-multiplying/" rel="bookmark" title="Permanent Link: Fortinet July Threat Landscape Report Shows Sasfis Botnet Variants Multiplying">Fortinet July Threat Landscape Report Shows Sasfis Botnet Variants Multiplying</a></li></ul></p><br />]]></content:encoded>
			<wfw:commentRss>http://www.blogjer.com/2010/03/23/fake-antivirus-threatening-windows-7-computers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Fixes for IE7, Visio, Microsoft Exchange &amp; SQL Server</title>
		<link>http://www.blogjer.com/2009/02/14/security-fixes-for-ie7-visio-microsoft-exchange-sql-server/</link>
		<comments>http://www.blogjer.com/2009/02/14/security-fixes-for-ie7-visio-microsoft-exchange-sql-server/#comments</comments>
		<pubDate>Sat, 14 Feb 2009 07:05:32 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft patch]]></category>

		<guid isPermaLink="false">http://www.blogjer.com/?p=2796</guid>
		<description><![CDATA[February Microsoft patch released on 10th December, fixes critical flaw on the following applications. If your automatic update turned off, make sure you check for update and install this patch immediately. Internet Explorer 7 &#8211; Fix flaw that allow a malicious Web site to install malware on a vulnerable PC. Visio &#8211; Fix flaw where [...]]]></description>
			<content:encoded><![CDATA[<p>February Microsoft patch released on 10th December, fixes critical flaw on the following applications. If your automatic update turned off, make sure you check for update and install this patch immediately.</p>
<ul>
<li> <strong><span id="lw_1234445800_0" class="yshortcuts">Internet Explorer 7</span></strong> &#8211; Fix flaw that allow a malicious Web site to install malware on a vulnerable PC.<a href="http://us.rd.yahoo.com/dailynews/pcworld/tc_pcworld/storytext/musthavesecurityfixesforie7microsoftservers/30917111/SIG=1222as9j2/*http://www.microsoft.com/technet/security/Bulletin/MS09-002.mspx"></a></li>
</ul>
<ul>
<li><strong>Visio</strong> &#8211; Fix flaw where attacker can run any command if you open a hacked Visio file.</li>
</ul>
<ul>
<li> <span id="lw_1234445800_2" class="yshortcuts"><strong>Microsoft Exchange</strong> &#8211; </span>Fix flaw where Microsoft Exchange could be taken over by a specially crafted TNEF message sent to it by an attacker.</li>
</ul>
<ul>
<li><strong>SQL server</strong> &#8211; Fixing flaw for possibly another attack after successful SQL injection attack.</li>
</ul>
<p>The patches run on one of my notebook for IE7 and SQL server flaw.</p>
<p><img class="alignnone size-full wp-image-2878" title="hotfix" src="http://www.blogjer.com/wp-content/uploads/2009/02/hotfix.png" alt="hotfix Security Fixes for IE7, Visio, Microsoft Exchange & SQL Server" width="371" height="202" /></p>
                  <div id="lass"><table style="width: 547px; height: 58px;" id="tkod" border="1" cellpadding="3" cellspacing="0"><tbody id="in_f"><tr id="x52g"><td id="t-61" width="100%">If you like this post then please consider subscribing to my <a title="full feed RSS" target="_blank" href="http://feeds.feedburner.com/NotJustABlog/" id="lir7">full feed RSS</a>.&nbsp; <br id="n8k0">You can also <a title="subscribe by Email" target="_blank" href="http://www.feedburner.com/fb/a/emailverifySubmit?feedId=896848" id="yn:q">subscribe by Email</a> and have new posts sent directly to your inbox.<br id="ejzb"><span id="og23" style="font-weight: bold;">&nbsp;<br id="s4-r"></span><span id="og23"><br />
This post originally came from Zaki's <a id="rf:t" href="www.blogjer.com">Blogjer.com</a></span></td></tr></tbody></table></div><span id="t7vz" style="font-weight: bold;"></span><br id="bvf9"><span id="rg-m" style="font-weight: bold;"></span><br id="pzdj" style="font-weight: bold;"><br id="q1m7">      <p>---<br />Related Articles at Blogjer - Technology at a glance:<ul><li><a href="http://www.blogjer.com/2009/01/13/technet-msdn-technology-summit-15-jan-2009/" rel="bookmark" title="Permanent Link: TechNet MSDN Technology Summit &#8211; 15 Jan 2009">TechNet MSDN Technology Summit &#8211; 15 Jan 2009</a></li><li><a href="http://www.blogjer.com/2008/06/10/even-security-blog-does-have-spams/" rel="bookmark" title="Permanent Link: even security blog does have spams..">even security blog does have spams..</a></li><li><a href="http://www.blogjer.com/2008/07/02/paypal-security-challange/" rel="bookmark" title="Permanent Link: paypal security challange">paypal security challange</a></li><li><a href="http://www.blogjer.com/2010/03/07/microsoft-to-end-support-windows-vista-without-service-pack-and-windows-xp-sp2/" rel="bookmark" title="Permanent Link: Microsoft To End Support Windows Vista Without Service Pack and Windows XP SP2">Microsoft To End Support Windows Vista Without Service Pack and Windows XP SP2</a></li><li><a href="http://www.blogjer.com/2009/02/11/wordpress-271-out-now/" rel="bookmark" title="Permanent Link: WordPress 2.7.1 out now">WordPress 2.7.1 out now</a></li></ul></p><br />]]></content:encoded>
			<wfw:commentRss>http://www.blogjer.com/2009/02/14/security-fixes-for-ie7-visio-microsoft-exchange-sql-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Paypal introduces security key texted to your mobile (SMS)</title>
		<link>http://www.blogjer.com/2008/11/26/paypal-introduces-security-key-texted-to-your-mobile-sms/</link>
		<comments>http://www.blogjer.com/2008/11/26/paypal-introduces-security-key-texted-to-your-mobile-sms/#comments</comments>
		<pubDate>Wed, 26 Nov 2008 22:21:13 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[e-banking]]></category>
		<category><![CDATA[paypal]]></category>
		<category><![CDATA[paypal security key]]></category>
		<category><![CDATA[securite]]></category>

		<guid isPermaLink="false">http://www.blogjer.com/?p=736</guid>
		<description><![CDATA[Paypal has taken a security measure to the next level, maybe on par with financial institution&#8217;s internet banking with a new security feature. Familiar with Maybank&#8216;s TAC (transaction authorization code)?? If you&#8217;re a Maybank&#8217;s internet banking user, sure you&#8217;ll be. So, this one has almost similar concept with that. The new feature is the extension [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.blogjer.com/wp-content/uploads/2008/11/paypal_logo.png" rel="thumbnail"><img class="alignnone size-medium wp-image-751" title="paypal_logo" src="http://www.blogjer.com/wp-content/uploads/2008/11/paypal_logo.png" alt="paypal logo Paypal introduces security key texted to your mobile (SMS)" width="111" height="39" /></a></p>
<p>Paypal has taken a security measure to the next level, maybe on par with financial institution&#8217;s internet banking with a new security feature.</p>
<p>Familiar with <a href="http://www.maybank2u.com.my/" target="_blank">Maybank</a>&#8216;s <a href=" http://www.maybank2u.com.my/consumer/online_banking/about_tac.shtml" target="_blank">TAC</a> (transaction authorization code)?? If you&#8217;re a Maybank&#8217;s internet banking user, sure you&#8217;ll be. So, this one has almost similar concept with that.</p>
<p>The new feature is the extension of the <a href="https://www.thepaypalblog.com/2007/10/the-paypal-secu/" target="_blank">Paypal Security Key token</a> introduced earlier. Besides the key being generated from the token, there is another option where the key is now sent to your registered mobile phone.</p>
<p>But wait, this security feature is at present not available in most countries including Malaysia. The lucky ones are United States, Australia, Austria, Canada and Germany. Paypal account holders from these countries can register via <a href="https://www.paypal.com/securitykey" target="_blank">registration page</a>.</p>
<p>No second security layer to us just yet, so make sure you <a href="http://www.blogjer.com/2008/07/11/secure-your-paypal-before-its-too-late/" target="_blank">secured your account</a> sufficiently.</p>
<p><a href="https://www.thepaypalblog.com/2008/11/the-paypal-security-key-goes-mobile/" target="_blank">via<br />
</a></p>
                  <div id="lass"><table style="width: 547px; height: 58px;" id="tkod" border="1" cellpadding="3" cellspacing="0"><tbody id="in_f"><tr id="x52g"><td id="t-61" width="100%">If you like this post then please consider subscribing to my <a title="full feed RSS" target="_blank" href="http://feeds.feedburner.com/NotJustABlog/" id="lir7">full feed RSS</a>.&nbsp; <br id="n8k0">You can also <a title="subscribe by Email" target="_blank" href="http://www.feedburner.com/fb/a/emailverifySubmit?feedId=896848" id="yn:q">subscribe by Email</a> and have new posts sent directly to your inbox.<br id="ejzb"><span id="og23" style="font-weight: bold;">&nbsp;<br id="s4-r"></span><span id="og23"><br />
This post originally came from Zaki's <a id="rf:t" href="www.blogjer.com">Blogjer.com</a></span></td></tr></tbody></table></div><span id="t7vz" style="font-weight: bold;"></span><br id="bvf9"><span id="rg-m" style="font-weight: bold;"></span><br id="pzdj" style="font-weight: bold;"><br id="q1m7">      <p>---<br />Related Articles at Blogjer - Technology at a glance:<ul><li><a href="http://www.blogjer.com/2008/07/02/paypal-security-challange/" rel="bookmark" title="Permanent Link: paypal security challange">paypal security challange</a></li><li><a href="http://www.blogjer.com/2009/12/19/paypal-release-app-for-blackberry/" rel="bookmark" title="Permanent Link: Paypal Releases App for Blackberry">Paypal Releases App for Blackberry</a></li><li><a href="http://www.blogjer.com/2008/07/11/secure-your-paypal-before-its-too-late/" rel="bookmark" title="Permanent Link: secure your paypal before it&#8217;s too late">secure your paypal before it&#8217;s too late</a></li><li><a href="http://www.blogjer.com/2007/12/02/getting-rid-of-spoof-and-spam-email/" rel="bookmark" title="Permanent Link: Getting rid of spoof and spam email">Getting rid of spoof and spam email</a></li><li><a href="http://www.blogjer.com/2009/08/07/withdraw-paypal-using-maybank-debit-card/" rel="bookmark" title="Permanent Link: Withdraw Paypal Using Maybank Debit Card">Withdraw Paypal Using Maybank Debit Card</a></li></ul></p><br />]]></content:encoded>
			<wfw:commentRss>http://www.blogjer.com/2008/11/26/paypal-introduces-security-key-texted-to-your-mobile-sms/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>secure your paypal before it&#8217;s too late</title>
		<link>http://www.blogjer.com/2008/07/11/secure-your-paypal-before-its-too-late/</link>
		<comments>http://www.blogjer.com/2008/07/11/secure-your-paypal-before-its-too-late/#comments</comments>
		<pubDate>Fri, 11 Jul 2008 15:59:57 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[e-commerce]]></category>
		<category><![CDATA[ecommerce]]></category>
		<category><![CDATA[paypal]]></category>
		<category><![CDATA[paypal hack]]></category>

		<guid isPermaLink="false">http://www.blogjer.com/?p=393</guid>
		<description><![CDATA[Last week, I blog about the appearance of Paypal Security Challenge (captcha) screen, which shows up on the screen, once I logged in into my Paypal account. I never came across it  before. It&#8217;s odd.. The same screen won&#8217;t appear again, even though I purposely key in wrong password multiple times using different system. What [...]]]></description>
			<content:encoded><![CDATA[<p>Last week, I blog about the appearance of <strong><a href="http://www.blogjer.com/2008/07/02/paypal-security-challange/" target="_blank">Paypal Security Challenge</a></strong> (captcha) screen, which shows up on the screen, once I logged in into my Paypal account. I never came across it  before. It&#8217;s odd.. The same screen won&#8217;t appear again, even though I purposely key in wrong password multiple times using different system. What I&#8217;m wondering is, if this screen appears whenever there are repetitive invalid attempts by unauthorized user/bot to access my account,  as pointed out by <a href="http://blog.eches.net/" target="_blank">Eches</a>. Sounds creepy huh?</p>
<p>Back to the CAPTCHA, it is not a new stuff in Paypal. According to the source in <a href="http://en.wikipedia.org/wiki/PayPal" target="_blank">Wiki</a>, Paypal has been using it (and some say invent it) since 90s to block an attempt by automated system to access Paypal. However, I&#8217;ve no answer on  what kind of form or situation triggering this CAPTCHA</p>
<p>A quick check on my RSS feed spot 2 webmasters on <a href="http://www.ghacks.net/2008/07/02/unauthorized-payment-done-with-my-paypal-account/" target="_blank">Ghacks</a> and <a href="http://www.saifulsham.com/index.php/archives/2008/06/13/elakkan-paypal-anda-dirompak/" target="_blank">Saifulsham</a>(his brother) who has their Paypal account fund been stolen or used for unauthorized transaction. Fraud can happen to anyone, even without you notice it or provide early signal.  Even after all security measure being taken, to ensure the safety of the account, this kind of thing can still happen when hackers become more creative than ever.</p>
<p>1 commentator in Ghack point me out to Youtube, where there are a lots of how-to-hack-paypal videos. I watch couple of them, including the one on top of the search result. It shows how to update certain paramenter on salespages&#8217;s source code to buy stuff on net with 1 cent.  I never tried it (and not gonna tried it), so I&#8217;m not sure if it works now. But it give basic impression that fully automated peyment system using Paypal is not that secure, without the involvement of human check.</p>
<p>There are couple of points that I learn from these 2 posts. I bet you know it, but not yet implement it. First and foremost is, don&#8217;t ever use your Paypal account (your email) for any registration, regardless with any kind of services. You might also consider to limit the usage of your Paypal email account even for email purpose. Use or create a new email account</p>
<p>Use debit card instead of credit card for your Paypal account. I&#8217;m sure many will disagree with this, but please give it some thought. Here is why. In case your account hacked, the damage is minimum to the extent of fund only in your account. You&#8217;re not risking losing more money since debit card amount is limited and most of the time, it only has amount whenever you want using it</p>
<p>Be careful when selling your Paypal fund for cash in forum. Your identity is in risk even though you&#8217;re registered using different email address. This is especially true if your password is not strong enough, which consist of common personal info such as your name, your nickname, what you like, your website etc. All these infos are crucial for intruder,  in process of guessing your password using automated system, thus gain a control. But you shouldn&#8217;t put much worry on this, if your password is strong enough.</p>
<p>Other than that, you might want to consider login into your e-commerce account (such as Paypal) from only your system. Avoid using public computer by any means if possible. You might not aware that public computer could have been installed with <a href="http://en.wikipedia.org/wiki/Keystroke_logging" target="_blank">keylogger</a>.  It&#8217;s not hard to find free keylogger nowadays. There are tonnes of <a href="http://www.google.com/search?q=free+keylogger&amp;ie=utf-8&amp;oe=utf-8&amp;aq=t&amp;rls=org.mozilla:en-US:official&amp;client=firefox-a" target="_blank">free keylogger</a> available on the net</p>
<p>OK now, it&#8217;s turn to listen to Paypal advice (taken from their website)</p>
<blockquote>
<p class="subheadingClickthrough">Website Security</p>
<ul>
<li><span class="emphasis">Type in the PayPal URL: </span>To safely and securely access the PayPal website or your PayPal account, open a new web browser (e.g., Internet Explorer or Netscape) and type in the following: https://www.paypal.com/</li>
</ul>
<p class="subheadingClickthrough">Password Safety</p>
<ul>
<li><span class="emphasis">Never share your PayPal password:</span> PayPal representatives will never ask you for your password. If you believe someone has learned your password, please change it immediately and <a href="https://www.paypal.com/row/cgi-bin/webscr?cmd=_contact">contact us</a>.</li>
<li><span class="emphasis">Create a secure password:</span> Choose a password that uses a combination of letters, numbers, and symbols. For example, $coo!place2l!ve or 2Barry5Bonds#1. Avoid choosing obvious words or dates such as a nickname or your birth date.</li>
<li><span class="emphasis">Keep your PayPal password unique:</span> Don&#8217;t use the same password for PayPal and other online services such as AOL, eBay, MSN, or Yahoo. Using the same password for multiple websites increases the likelihood that someone could learn your password and gain access to your account.</li>
</ul>
<p class="subheadingClickthrough">Email Security</p>
<ul>
<li><span class="emphasis">Look for a PayPal Greeting:</span> PayPal will never send an email with the greeting &#8220;Dear PayPal User&#8221; or &#8220;Dear PayPal Member.&#8221; <span class="emphasis">Real PayPal emails will address you by your first and last name</span> or the business name associated with your PayPal account. If you believe you have received a fraudulent email, please forward the entire email—including the header information—to <a href="mailto:spoof@paypal.com">spoof@paypal.com</a>. We investigate every spoof reported. Please note that the automatic response you get from us may not address you by name.</li>
<li><span class="emphasis">Don&#8217;t share personal information via email:</span> We will never ask you to enter your password or financial information in an email or send such information in an email. You should only share information about your account once you have logged in to www.paypal.com/row.</li>
<li><span class="emphasis">Don&#8217;t download attachments:</span> PayPal will never send you an attachment or software update to install on your computer.</li>
</ul>
<p class="subheadingClickthrough">Use Your Account Wisely</p>
<ul>
<li><span class="emphasis">Don&#8217;t share your account:</span> Don&#8217;t use your PayPal account to collect or transfer money for someone else. These types of activity are often conducted as forms of money laundering or mail fraud and may result in significant criminal penalties. If someone contacts you and asks you to transfer money on their behalf, you should deny the request and <a href="https://www.paypal.com/row/cgi-bin/webscr?cmd=_contact">contact us</a> immediately.</li>
<li><span class="emphasis">Increase your security:</span> Become a Verified PayPal member.</li>
</ul>
<li><span class="emphasis">Look for legitimate sites:</span> Examine all privacy and security seals before doing business with a particular website and make sure they are legitimate.</li>
</blockquote>
                  <div id="lass"><table style="width: 547px; height: 58px;" id="tkod" border="1" cellpadding="3" cellspacing="0"><tbody id="in_f"><tr id="x52g"><td id="t-61" width="100%">If you like this post then please consider subscribing to my <a title="full feed RSS" target="_blank" href="http://feeds.feedburner.com/NotJustABlog/" id="lir7">full feed RSS</a>.&nbsp; <br id="n8k0">You can also <a title="subscribe by Email" target="_blank" href="http://www.feedburner.com/fb/a/emailverifySubmit?feedId=896848" id="yn:q">subscribe by Email</a> and have new posts sent directly to your inbox.<br id="ejzb"><span id="og23" style="font-weight: bold;">&nbsp;<br id="s4-r"></span><span id="og23"><br />
This post originally came from Zaki's <a id="rf:t" href="www.blogjer.com">Blogjer.com</a></span></td></tr></tbody></table></div><span id="t7vz" style="font-weight: bold;"></span><br id="bvf9"><span id="rg-m" style="font-weight: bold;"></span><br id="pzdj" style="font-weight: bold;"><br id="q1m7">      <p>---<br />Related Articles at Blogjer - Technology at a glance:<ul><li><a href="http://www.blogjer.com/2008/11/26/paypal-introduces-security-key-texted-to-your-mobile-sms/" rel="bookmark" title="Permanent Link: Paypal introduces security key texted to your mobile (SMS)">Paypal introduces security key texted to your mobile (SMS)</a></li><li><a href="http://www.blogjer.com/2008/07/02/paypal-security-challange/" rel="bookmark" title="Permanent Link: paypal security challange">paypal security challange</a></li><li><a href="http://www.blogjer.com/2009/12/19/paypal-release-app-for-blackberry/" rel="bookmark" title="Permanent Link: Paypal Releases App for Blackberry">Paypal Releases App for Blackberry</a></li><li><a href="http://www.blogjer.com/2009/08/07/withdraw-paypal-using-maybank-debit-card/" rel="bookmark" title="Permanent Link: Withdraw Paypal Using Maybank Debit Card">Withdraw Paypal Using Maybank Debit Card</a></li><li><a href="http://www.blogjer.com/2008/01/04/donate-to-wikipedia/" rel="bookmark" title="Permanent Link: Donate to wikipedia">Donate to wikipedia</a></li></ul></p><br />]]></content:encoded>
			<wfw:commentRss>http://www.blogjer.com/2008/07/11/secure-your-paypal-before-its-too-late/feed/</wfw:commentRss>
		<slash:comments>15</slash:comments>
		</item>
		<item>
		<title>even security blog does have spams..</title>
		<link>http://www.blogjer.com/2008/06/10/even-security-blog-does-have-spams/</link>
		<comments>http://www.blogjer.com/2008/06/10/even-security-blog-does-have-spams/#comments</comments>
		<pubDate>Tue, 10 Jun 2008 07:10:19 +0000</pubDate>
		<dc:creator>Admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[michael howard]]></category>
		<category><![CDATA[microsot]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.blogjer.com/?p=348</guid>
		<description><![CDATA[Micheal Howard is a security expert in MS and he has quite good articles for those working on MS platform or environment. It looks odd however, if security blogs such as one belonged to Michael Howard, was spammed by such as illegal trackback, which appears to undermine the security level of the blog itself. While [...]]]></description>
			<content:encoded><![CDATA[<p>Micheal Howard is a security expert in MS and he has quite good <a href="http://msdn.microsoft.com/en-us/magazine/cc301009.aspx" target="_blank">articles</a> for those working on MS platform or environment. It looks odd however, if security blogs such as one belonged to <a href="http://en.wikipedia.org/wiki/Michael_Howard_(Microsoft)" target="_blank">Michael Howard</a>, was spammed by such as illegal trackback, which appears to undermine the security level of the blog itself.</p>
<p>While he is busy with his security tips and speech around the world, doing paper work, writing new books, spammer (human or bot who never sleeps) has taken advantage by leaving spam trackback which appears to get loosen off from Microsost security/filter itself. This is nothing new and such behaviour can easily be avoided by even new bloggers.</p>
<p>If you use WordPress, maybe you should try <a href="http://sw-guide.de/wordpress/plugins/simple-trackback-validation/" target="_blank">Simple Track Back</a> plugin to overcome this problem. It works well on my tiny blog. Or if you use your own MS blog platform (if it exists) or other blogging platform, why not request your engineers to create the same.</p>
<p>It does not only enhance the blog credibility, but also shows that your blog is as secured as your system.</p>
<p>My attempt to browse the illegal trackback was unsuccessful, since our Smart Filter blocks this URL as &#8221;Spammer URL&#8217; . It looks like this system is clever than yours in handling spam.</p>
<p><img style="border: 0pt none;" src="http://www.blogjer.com/images/security_blog_spam.png" alt="security blog spam even security blog does have spams.." width="558" height="515" title="even security blog does have spams.." /></p>
<p>note: this serves as an entertainment only, don&#8217;t take it seriously okey! I do know that spam is different from security.</p>
                  <div id="lass"><table style="width: 547px; height: 58px;" id="tkod" border="1" cellpadding="3" cellspacing="0"><tbody id="in_f"><tr id="x52g"><td id="t-61" width="100%">If you like this post then please consider subscribing to my <a title="full feed RSS" target="_blank" href="http://feeds.feedburner.com/NotJustABlog/" id="lir7">full feed RSS</a>.&nbsp; <br id="n8k0">You can also <a title="subscribe by Email" target="_blank" href="http://www.feedburner.com/fb/a/emailverifySubmit?feedId=896848" id="yn:q">subscribe by Email</a> and have new posts sent directly to your inbox.<br id="ejzb"><span id="og23" style="font-weight: bold;">&nbsp;<br id="s4-r"></span><span id="og23"><br />
This post originally came from Zaki's <a id="rf:t" href="www.blogjer.com">Blogjer.com</a></span></td></tr></tbody></table></div><span id="t7vz" style="font-weight: bold;"></span><br id="bvf9"><span id="rg-m" style="font-weight: bold;"></span><br id="pzdj" style="font-weight: bold;"><br id="q1m7">      <p>---<br />Related Articles at Blogjer - Technology at a glance:<ul><li><a href="http://www.blogjer.com/2008/10/16/silence-is-golden-for-spams/" rel="bookmark" title="Permanent Link: Silence is golden for spams?">Silence is golden for spams?</a></li><li><a href="http://www.blogjer.com/2008/12/05/drupal-better-than-wordpress/" rel="bookmark" title="Permanent Link: Drupal better than WordPress??">Drupal better than WordPress??</a></li><li><a href="http://www.blogjer.com/2008/11/10/identifying-spams-no-longer-a-big-deal/" rel="bookmark" title="Permanent Link: Identifying spams no longer a big deal">Identifying spams no longer a big deal</a></li><li><a href="http://www.blogjer.com/2008/07/02/paypal-security-challange/" rel="bookmark" title="Permanent Link: paypal security challange">paypal security challange</a></li><li><a href="http://www.blogjer.com/2008/01/04/spammer-also-taking-a-break/" rel="bookmark" title="Permanent Link: spammer also taking a break">spammer also taking a break</a></li></ul></p><br />]]></content:encoded>
			<wfw:commentRss>http://www.blogjer.com/2008/06/10/even-security-blog-does-have-spams/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

