Friday, April 11, 2014

Alert: More News About Heartbleed

Companies are beginning to issue statements on whether or not their web servers were compromised by the Heartbleed vulnerability. If you use any of the services below you need to visit them and change your password. You also need to change your password for any other site where you have used that same password.

Facebook, Instagram, IFFT, Pinterest, Twitter, USAA, Intuit – Turbo Tax, DropBox, Box, LastPass, Minecraft, NetFlix, OKCupid, Wunderlist, SoundCloud

Google: Search, Gmail, YouTube, Wallet, Play, Apps and App Engine. That Play is effected is a big deal. That means your Android phone and tablets are wide open. Google has yet to announce how they will handle issuing updates for all of the apps in the Google Play store.

Yahoo: Yahoo Search, Yahoo Mail, Yahoo Finance, Yahoo Sports, Yahoo Food, Yahoo Tech, Flickr and Tumblr

Amazon: Elastic Load Balancing, Amazon EC2, Amazon Linux AMI, Red Hat Enterprise Linux, Ubuntu, AWS OpsWorks, AWS Elastic Beanstalk and Amazon CloudFront,

More Bad News:

Because GoDaddy’s own servers were affected it means that the certificates they issued are also effected and must be rekeyed and reinstalled. Although we recently switched to providing our own SSL certificates to our clients through ENOM most of our clients are still using GoDaddy certificates. This means that we’ll be asking for a new set of security keys for each of your from GoDaddy and reapplying the certificates to your servers. Since your server isn’t directly affected this is merely a precautionary measure.

Some Good News: Here’s what isn’t affected.

Your servers. Microsoft software including all of their hosted products are safe. Bing is safe. eBay, Amazon (store), PayPal, Federal Government websites, Nordstrom, Wal-Mart, Target, Bank of America, Chase, Capital One, e*Trade, Citigroup, Fidelty, Schwab, Ameritrade, USBank, Wells Fargo and LinkedIN are all safe. EverNote and Apple are safe.

If you have any difficulty changing your passwords ask us for assistance. If you have any questions about Heartbleed ask us about that too.

-Amy

Labels:

Wednesday, April 09, 2014

Alert: HeartBleed

Heartbleed is the latest in an epidemic of attacks on the Linux foundation of the Internet. Most websites use Linux in one way or another but until recently the hacker community has left them alone. But a couple of months ago cPanel, the application that every website uses to publish itself, was hacked and now it’s OpenSSL. OpenSSL is the SSL certificate processing portion of websites. The hack allows your username and password and any other data that you enter into the website to be harvested in plain text defeating the whole purpose of an SSL protected website. The worst part about these recent hacks is that no one noticed them for the last two years.

You can find out if a website that you visit hasn’t been patched yet by entering its address into this tool http://filippo.io/Heartbleed/ I would recommend doing that for any website where you are entering in your username and password.

If you are curious about which websites were vulnerable, here are a few that still are as of last night: yahoo, flickr, eventbright, zoho, squidoo, petflow, fool, lastpass and slate. They are among tens of thousands.

So let’s say you use one or more of those common websites. You might feel that there’s nothing there in your personal information to worry about. There’s just your name, email address, home address, business address and perhaps some stored credit card information. The later is of course a concern but the larger concern is whether you used that same password any where else. That’s really what the bad guys are after. Because once they have a password of yours, they throw it at the websites that might yield money: credit card, banking, investments, tax returns, payroll, maybe they’ll order something from Amazon. That’s the real danger. So take the time to look and change those passwords.

If you need assistance, we’re here to help.

-Amy

p.s. My apologies for yesterdays post. It was not meant for you. I hit enter and sent it to the wrong group. That was for ThirdTier where we help other IT firms with technical issues and for the last 16 months we also help them build better businesses. It’s time to give back and help make this profession better as a whole.

Labels:

Wednesday, October 02, 2013

ALERT: Cryptolocker Virus

This is the worst virus I’ve ever come across. Cryptolocker encrypts not only the files on your computer but ALL of the files that you have access to on the network.

image

There is no good cure. The only real solution is to reload every infected machine completely. The only other solution is to pay the ransom. Yes the makers of cryptolocker hold the decryption key and await your payment.

How To Avoid Infection

According to my best sources you get infected by doing one of these things:

  • This infection was originally spread via email sent to company email addresses that pretend to be customer support related issues from Fedex, UPS, DHS, etc. These emails would contain an attachment that when opened would infect the computer.
  • Via exploit kits located on hacked web sites that exploit vulnerabilities on your computer to install the infection.
  • Through Trojans that pretend to be programs required to view online videos. These are typically encountered through Porn sites.

If you get this virus, all of your files will have to be restored from backup. This is not only time consuming but expensive. Please, please, please do not open any attachments. Only visit company work related websites and don’t click on anything that you don’t have too. Any questions at all about whether you should open or click please contact us and ask.

-Amy

Labels:

Friday, September 13, 2013

Alert: Office Update Issues

There are two problems occurring due to updates to Microsoft Office 2010 and 2013. They effect different types of installations.

1. If you purchased your computer from a retail outlet it probably shipped with a trial edition of Office 2010. This trial edition has long since expired but is still installed on your computer. You have another version or edition of Office installed. If those conditions are met then your Office icons will go Orange and the file associations that allow you to click on a Word document and have Word open (as an example) are reset to the expired trial edition. The solution is to reset the file associations and remove the expired trial software.

1a. If you purchased your computer from a retail outlet it may have included a click-to-run version of office. This installation type is used by some computer manufacturers to minimize what they have to install on the computer before they ship it. Instead of installing office they install what is essentially a shortcut to download office. If you have installed office this way then the same file association problem will occur as above. You are most likely to experience this problem at home.

2. If you purchased Office through volume license and one of a set of two updates gets installed but not both, then the Outlook folder pane will be hidden behind a big blank space. The solution for this problem is to install the second update. Unfortunately the second update is currently a manual download and isn’t being delivered via normal channels (the mistake that Microsoft made) so it is unlikely that anyone will get the second update. We have the file and are ready to install it but we can’t do it proactively because to do so would also break Outlook.

Microsoft is currently working on automated fixes for these two issues which I would expect to happen soon. In the meantime if you hit either of these call us. We have the manual fix available and can do it quickly for you.

-Amy

Labels: