<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Walker News &#187; Security</title>
	<atom:link href="http://www.walkernews.net/category/software/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.walkernews.net</link>
	<description>A capsule of walker's experience in life...</description>
	<lastBuildDate>Sun, 29 Jan 2012 16:29:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>YouTube Videos Show How Clickjacking Works</title>
		<link>http://www.walkernews.net/2011/05/28/youtube-videos-show-how-clickjacking-works/</link>
		<comments>http://www.walkernews.net/2011/05/28/youtube-videos-show-how-clickjacking-works/#comments</comments>
		<pubDate>Sat, 28 May 2011 14:22:00 +0000</pubDate>
		<dc:creator>Walker</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Youtube]]></category>

		<guid isPermaLink="false">http://www.walkernews.net/?p=8015</guid>
		<description><![CDATA[For those who wonder what clickjacking is, watch these YouTube videos that demo the attack.]]></description>
			<content:encoded><![CDATA[There is an article on Wikipedia describes what <a href="http://en.wikipedia.org/wiki/Clickjacking" target="_blank">clickjacking</a>  is. In simple words, this attack works by hiding an iframe on top of the visible web objects that prompt user to click on it.<br />
<span id="more-8015"></span><br />
To figure that out, these two YouTube videos might help you understand clickjacking better and how to avoid such attacks against your precious online accounts (e.g. Facebook, Gmail, etc).<br />
<br />Symantec demos the Facebook clickjacking attack:<br />
<object width="500" height="314"><param name="movie" value="http://www.youtube.com/v/jgAO8WU2lp0?fs=1&amp;hl=en_US&amp;rel=0"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/jgAO8WU2lp0?fs=1&amp;hl=en_US&amp;rel=0" type="application/x-shockwave-flash" width="500" height="314" allowscriptaccess="always" allowfullscreen="true"></embed></object><br />
<br />Another YouTube video demos how an Internet game using clickjacking to spy on user&#8217;s webcam:<br />
<object width="500" height="405"><param name="movie" value="http://www.youtube.com/v/gxyLbpldmuU?fs=1&amp;hl=en_US&amp;rel=0"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/gxyLbpldmuU?fs=1&amp;hl=en_US&amp;rel=0" type="application/x-shockwave-flash" width="500" height="405" allowscriptaccess="always" allowfullscreen="true"></embed></object><br />
<ul class="related_post"><li><a href="http://www.walkernews.net/2010/09/12/where-does-youtube-and-facebook-cache-flash-or-mp4-videos-in-windows-7/" title="Where Does YouTube And Facebook Cache Flash Or MP4 Videos In Windows 7?">Where Does YouTube And Facebook Cache Flash Or MP4 Videos In Windows 7?</a></li><li><a href="http://www.walkernews.net/2010/05/31/youtube-tip-uses-feather-beta-for-faster-video-page-loading/" title="YouTube Tip: Uses Feather Beta For Faster Video Page Loading">YouTube Tip: Uses Feather Beta For Faster Video Page Loading</a></li><li><a href="http://www.walkernews.net/2010/04/08/the-official-list-of-youtube-top-videos/" title="The Official List Of YouTube Top Videos">The Official List Of YouTube Top Videos</a></li><li><a href="http://www.walkernews.net/2009/04/26/how-to-embed-swf-or-flv-file-in-microsoft-excel-2007/" title="How To Embed SWF or FLV File In Microsoft Excel 2007?">How To Embed SWF or FLV File In Microsoft Excel 2007?</a></li><li><a href="http://www.walkernews.net/2009/04/08/reveal-the-name-of-song-or-music-that-used-in-youtube-video/" title="Reveal The Name Of Song or Music That Used In YouTube Video">Reveal The Name Of Song or Music That Used In YouTube Video</a></li><li><a href="http://www.walkernews.net/2009/03/12/new-youtube-player-interface-to-view-hd-video-clip/" title="New YouTube Player Interface To View HD Video Clip">New YouTube Player Interface To View HD Video Clip</a></li><li><a href="http://www.walkernews.net/2008/12/11/how-to-create-high-quality-and-high-definition-video-for-youtube/" title="How To Create High Quality And High Definition Video For YouTube?">How To Create High Quality And High Definition Video For YouTube?</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.walkernews.net/2011/05/28/youtube-videos-show-how-clickjacking-works/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Can SysKey Prevents TRK Resets Windows 7 Administrator Password To Blank?</title>
		<link>http://www.walkernews.net/2010/01/21/syskey-prevent-trk-reset-windows-7-administrator-password/</link>
		<comments>http://www.walkernews.net/2010/01/21/syskey-prevent-trk-reset-windows-7-administrator-password/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 16:57:11 +0000</pubDate>
		<dc:creator>Walker</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[TRK]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://www.walkernews.net/?p=3732</guid>
		<description><![CDATA[Do you think Syskey or Windows System Key Protection can secure Windows 7 Administrator account password from being reset to blank or empty by Windows password rescue tool like TRK?]]></description>
			<content:encoded><![CDATA[While I appreciate a rescue tool to reset Windows 7 administrator password in case I forgot the passkey after coming back from a long holiday, I hate to know someone using it to break into my Windows 7 machine and put my valuable data at risk. So, I rather hope there is no way to reset the forgotten password and let the data remain unrecoverable.<br />
<span id="more-3732"></span><br />
You probably know that how easy it is to use such tool, like Trinity Rescue Kit (TRK), to reset Windows account password of a vanilla installation. So, I am eagerly looking for best Windows security practice to prevent TRK or similar tool from breaking into Windows 7.<br />
<br />The BitLocker Drive Encryption could be one of the most promising Windows security features to prevent TRK crack the Windows 7 Administrator account. No one can sure it is bulletproof at now and forever. Besides, enabling BitLocker Drive Encryption might introduce significant performance issue on certain system or certain application.<br />
<br />For my aging Dell Latitude D410, it is going slower than expected after turning on the BitLocker. However, I cannot afford to leave data exposed when the mobile computer goes to the wrong hand. So, I turn to try Windows System Key Protection (Syskey) introduced since Windows NT (and should have been enhanced over the time).<br />
<br /><img src="http://www.walkernews.net/wp-content/uploads/2010/01/Windows-7-Syskey.jpg" alt="Secure Windows 7 account password by turning on the Windows System Key Protection or Syskey feature." title="Secure Windows 7 account password by turning on the Windows System Key Protection or Syskey feature." width="500" height="223" /><br />
<br />1) At an elevated privilege Windows Command Prompt, type <code>syskey</code> and press ENTER. <span class="subhead2">Warning:</span> Once the Syskey is enabled, this encryption cannot be disabled.<br />
<br />2) Click Update button to bring up Startup Key dialog box, select &#8220;Password Startup&#8221;, give it a &#8220;complicated&#8221; password, and click OK.<br />
<br />3) Click OK button again to enable the good old Syskey in the hope it could really secure the SAM file (Windows Account Database).<br />
<br />Next, I tried to boot up TRK from USB flash drive. Surprisingly, the winpass shell scripts that execute the chntpw program stills capable to reset the Windows administrator account password to blank in no time! I guess that chntpw simply remove the encrypted password of the specified Windows account. <br />
<br />After rebooting from Trinity Rescue Kit, Windows 7 boots up and then Syskey prompts for the passkey as I expected, before the system proceeds to the GINA (Graphical Interface for Network Authentication).<br />
<br /><img src="http://www.walkernews.net/wp-content/uploads/2010/01/Windows-7-Syskey-prompt.jpg" alt="Windows 7 prompt for Syskey password before presenting the normal GINA or Graphical Interface for Network Authentication screen." title="Windows 7 prompt for Syskey password before presenting the normal GINA or Graphical Interface for Network Authentication screen." width="351" height="175" /><br />
<br />After entering the &#8220;complicated&#8221; password I set for the Syskey, Windows 7 continues loading and then present the Desktop without asking me for the Windows account password.<br />
<br /><span class="subhead">Verdict</span><br />
<br />Enabling Syskey could NOT prevent TRK from resetting Windows account password to blank / empty. <br />
<br />However, you still have to provide a correct Syskey password in order to gain access to Windows 7 Desktop. Unless the bad guy can also crack the Syskey protection, Windows 7 reboots after a number of wrong passkey entered for the Syskey prompt. Again, no one sure the Syskey cannot be crack at now and forever.<br />
<br />To make it harder for bad guy, use Encrypting File System (EFS) to encrypt sensitive data files!<br />
<br />Optionally, turn on BIOS password so that your semi-hacker colleague couldn&#8217;t break into your Windows 7 as easy as he wish :-)<br />
<ul class="related_post"><li><a href="http://www.walkernews.net/2011/02/21/genuine-windows-7-sp1-iso-file-and-sha1-checksum-available-on-official-site/" title="Genuine Windows 7 SP1 ISO File And SHA1 Checksum Available On Official Site">Genuine Windows 7 SP1 ISO File And SHA1 Checksum Available On Official Site</a></li><li><a href="http://www.walkernews.net/2010/09/30/direct-download-adobe-flash-player-standalone-offline-installer-for-ie-and-firefox/" title="Direct Download Adobe Flash Player Standalone Offline Installer For IE and Firefox">Direct Download Adobe Flash Player Standalone Offline Installer For IE and Firefox</a></li><li><a href="http://www.walkernews.net/2010/08/30/how-to-display-sound-or-speaker-icon-in-windows-7-notification-area/" title="How To Display Sound Or Speaker Icon In Windows 7 Notification Area?">How To Display Sound Or Speaker Icon In Windows 7 Notification Area?</a></li><li><a href="http://www.walkernews.net/2010/08/16/windows-7-tip-add-playlists-to-windows-media-player-jump-list/" title="Windows 7 Tip: Add Playlists To Windows Media Player Jump List">Windows 7 Tip: Add Playlists To Windows Media Player Jump List</a></li><li><a href="http://www.walkernews.net/2010/08/15/where-does-windows-media-player-keeps-playlists-on-windows-7/" title="Where Does Windows Media Player Keeps Playlists On Windows 7?">Where Does Windows Media Player Keeps Playlists On Windows 7?</a></li><li><a href="http://www.walkernews.net/2010/03/19/one-click-to-add-elevated-command-prompt-shortcut-in-right-click-menu/" title="One-click To Add Elevated Command Prompt Shortcut In Right-click Menu">One-click To Add Elevated Command Prompt Shortcut In Right-click Menu</a></li><li><a href="http://www.walkernews.net/2010/03/19/windows-registry-command-line-tool-the-reg-escape-character/" title="Windows Registry Command Line Tool: The Reg Escape Character">Windows Registry Command Line Tool: The Reg Escape Character</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.walkernews.net/2010/01/21/syskey-prevent-trk-reset-windows-7-administrator-password/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How To Prevent TRK Crack Windows 7 Administrator Account?</title>
		<link>http://www.walkernews.net/2010/01/13/how-to-prevent-trk-crack-windows-7-administrator-account/</link>
		<comments>http://www.walkernews.net/2010/01/13/how-to-prevent-trk-crack-windows-7-administrator-account/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 18:45:07 +0000</pubDate>
		<dc:creator>Walker</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Howto]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://www.walkernews.net/?p=3689</guid>
		<description><![CDATA[Understand how could TRK crack the Windows 7 administrator account without the owner knowing the Windows system has been cracked?]]></description>
			<content:encoded><![CDATA[While the Trinity Rescue Kit (TRK) is a useful tool for computer that cannot boot up normally, this customized Linux distribution can also be one of the most dangerous tools when it is on the hand of black hat hackers. As the Chinese idiom said: &#8220;water can take boat as well as sinking the boat (水能载舟亦能覆舟)&#8221;.<br />
<span id="more-3689"></span><br />
To enlighten you how could this useful toolkit turns bad and how could you prevent the bad guys from breaking into the Microsoft latest Windows 7 system, I share what I have tested just now, <span class="subhead2">for education purpose only</span>.<br />
<br /><span class="subhead2">Remember</span>, everything in Linux is case-sensitive, so as TRK:<br />
<br />1) Boots up the Windows 7 computer from TRK bootable CD/DVD-ROM or USB flash drive.<br />
<br />2) Run <code>winpass -u Administrator</code> or replace the &#8220;Administrator&#8221; with any other Windows user account of administrators group (for example, <code>winpass -u Walker</code>).<br />
<br />3) Select the discovered Windows installation from the list and then choose Option 1 to reset the said Windows account password to blank / empty.<br />
<br />4) If the password cleared successfully, you should notice that TRK automatically create a backup copy of SAM file as SAM.trk. Take note of the Windows OS hard disk drive device file in TRK (in my screenshot, it is hda2).<br />
<br /><img src="http://www.walkernews.net/wp-content/uploads/2010/01/TRK-Reset-Windows-Password.jpg" alt="How could TRK crack Windows 7 administrator account password?" title="How could TRK crack Windows 7 administrator account password?" width="500" height="220" /><br />
<br />5) Reboot into Windows 7. You should be able to login automatically with the user account specified to winpass shell script executed in step 2.<br />
<br />6) Reboot into Trinity Rescue Kit. Type <code>mountallfs -g</code> to mount Windows 7 NTFS file system in read-write mode:<br />
<br /><img src="http://www.walkernews.net/wp-content/uploads/2010/01/TRK-Mount-NTFS-In-Read-Write-Mode.jpg" alt="The TRK mount Windows 7 NTFS file system into read and write mode." title="The TRK mount Windows 7 NTFS file system into read and write mode." width="500" height="120" /><br />
<br />7) With reference to the SAM file path in step 4, change directory to that folder. Execute <code>mv SAM.trk SAM</code> to replace the SAM file with backup copy (the original SAM file before you reset the said account password to blank / empty). By doing so, TRK effectively revert the Windows account password from empty / blank to the original state.<br />
<br /><img src="http://www.walkernews.net/wp-content/uploads/2010/01/Replace-Windows-7-SAM-File-With-Backup-Copy.jpg" alt="Use TRK to replace the Windows 7 SAM file with the backup copy in order to revert the blank password back to original state." title="Use TRK to replace the Windows 7 SAM file with the backup copy in order to revert the blank password back to original state." width="500" height="28" /><br />
<br />As you can imagine now, how dangerous it is if your vanilla Windows 7 machine is left in the public area and everyone could easily access to it.<br />
<br />The bad guy who uses TRK could easily gain access to Windows 7 with a blank password, do whatever things to leave a backdoor and left it back to you appear intact. I would say you won&#8217;t easily notice they have done this as you can still login with a darn complicated password that you think it is impossible for one to break it in few ten years. In actual fact, however, they can gain access in no time as they do not crack the complicated password but simply reset and revert it back.<br />
<br /><span class="subhead">So, how to prevent TRK cracks Windows 7 admin password?</span><br />
<br />1) Use the BitLocker Drive Encryption to secure both the operating system and data drives. While I do not read much about this Windows 7 BitLocker, but I am somewhat convinced of its encryption capabilities to safeguard Windows 7 from true unauthorized system access.<br />
<br /><img src="http://www.walkernews.net/wp-content/uploads/2010/01/Use-Bitlocker-Drive-Encryption-To-Prevent-TRK-Crack.jpg" alt="Turn on BitLocker Drive Encryption to prevent bad guys from hacking the vulnerable, vanilla Windows 7 machine." title="Turn on BitLocker Drive Encryption to prevent bad guys from hacking the vulnerable, vanilla Windows 7 machine." width="500" height="139" /><br />
<blockquote>
BitLocker is not available in all Windows 7 editions. BitLocker Drive Encryption is only available in a computer running Windows 7 Enterprise, Windows 7 Ultimate, or Windows Server 2008 R2.
</blockquote>
<br />2) Configure BIOS to prompt password for booting up Windows 7. This is not a good idea too as out there are many toolkit used for resetting BIOS password.<br />
<br />3) Keep an eye on the Windows system Security log in Windows Event Viewer, to spot whoever login to your Windows account without your consent.<br />
<ul class="related_post"><li><a href="http://www.walkernews.net/2011/06/06/how-to-unlock-windows-account-at-command-prompt/" title="How To Unlock Windows Account At Command Prompt?">How To Unlock Windows Account At Command Prompt?</a></li><li><a href="http://www.walkernews.net/2011/06/04/how-to-create-batch-file-with-endless-for-loop-on-windows-7/" title="How To Create Batch File With Endless For Loop On Windows 7?">How To Create Batch File With Endless For Loop On Windows 7?</a></li><li><a href="http://www.walkernews.net/2011/05/01/how-to-disable-windows-7-user-account-control-feature/" title="How To Disable Windows 7 User Account Control Feature?">How To Disable Windows 7 User Account Control Feature?</a></li><li><a href="http://www.walkernews.net/2011/04/15/how-to-print-windows-version-on-desktop/" title="How To Print Windows Version On Desktop?">How To Print Windows Version On Desktop?</a></li><li><a href="http://www.walkernews.net/2011/04/13/how-to-turn-on-windows-7-black-theme-instantly/" title="How To Turn On Windows 7 Black Theme Instantly?">How To Turn On Windows 7 Black Theme Instantly?</a></li><li><a href="http://www.walkernews.net/2011/04/05/how-to-turn-off-citrix-application-sound-on-windows-7/" title="How To Turn Off Citrix Application Sound On Windows 7?">How To Turn Off Citrix Application Sound On Windows 7?</a></li><li><a href="http://www.walkernews.net/2011/03/26/how-to-make-internet-explorer-opens-citrix-ica-file-automatically/" title="How To Make Internet Explorer Opens Citrix ICA File Automatically?">How To Make Internet Explorer Opens Citrix ICA File Automatically?</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.walkernews.net/2010/01/13/how-to-prevent-trk-crack-windows-7-administrator-account/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How To Get SHA-1 Checksum Of File In Windows?</title>
		<link>http://www.walkernews.net/2009/12/27/how-to-get-sha-1-checksum-of-file-in-windows/</link>
		<comments>http://www.walkernews.net/2009/12/27/how-to-get-sha-1-checksum-of-file-in-windows/#comments</comments>
		<pubDate>Sun, 27 Dec 2009 12:39:55 +0000</pubDate>
		<dc:creator>Walker</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Howto]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://www.walkernews.net/?p=3611</guid>
		<description><![CDATA[What program can be used to compute or check SHA-1 checksum of a file in Windows?]]></description>
			<content:encoded><![CDATA[What is that SHA-1 checksum and how to compute or check the SHA-1 checksum in Windows 7?<br />
<span id="more-3611"></span><br />
You will come across SHA-1 checksum as you download the DVD image file of Microsoft Windows SDK for Windows 7 and .NET Framework 3.5 SP1.<br />
<br /><img src="http://www.walkernews.net/wp-content/uploads/2009/12/What-Is-SHA-1-checksum.jpg" alt="What is SHA-1 checksum? How to compute or check SHA-1 checksum of a file?" title="What is SHA-1 checksum? How to compute or check SHA-1 checksum of a file?" width="461" height="210" /><br />
<br />Similar to MD5 checksum, SHA-1 is just another cryptographic hash values or message digest of data. While MD5 hashing algorithm creates a 128-bit hash value, SHA-1 hashing algorithm creates a 160-bit hash value.<br />
<br />In order to ensure a piece of data (e.g. string, file, program, etc) received by recipient is genuine or has not been tampered, the publisher will and should use a hashing algorithm (e.g. MD5, SHA-1, etc) to calculate the data checksum and pass it to recipient for verification.<br />
<br />Upon receive the data completely, recipient uses the same hashing algorithm to compute the data checksum and verify it against the one sent by publisher. Should the hash value or message digest match, then the data is said to be genuine or remains intact. <br />
<br />So, after download the Windows SDK ISO image, you should check and verify the SHA-1 checksum to confirm the image file has not been corrupted (caused by incomplete download, etc).<br />
<br />Although Microsoft Windows doesn&#8217;t bundle any file checksum program, cannot even find one in the latest Windows 7, there are many 3-party freeware. For example both <span class="subhead2">HashCheck and digestIT 2004</span> are capable to calculate MD5 and SHA-1 checksum of files. The HashCheck can even compute CRC-32 and MD4 checksum, if you&#8217;re interested in these hash values too.<br />
<br />There is also one offer from Microsoft Download Center. However, the <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=B3C93558-31B7-47E2-A663-7365C1686C08&#038;displaylang=en" target="_blank" rel="nofollow">Microsoft File Checksum Integrity Verifier</a> is stated as an unsupported command line file checksum utility. Well, no big deal &#8211; although it works but I bet you will not want to keep using this boring command line program after trying HashCheck that integrate file checksum functions to Windows Explorer.<br />
<ul class="related_post"><li><a href="http://www.walkernews.net/2009/03/13/how-to-get-a-free-copy-of-windows-7-beta-product-key/" title="How To Get A Free Copy Of Windows 7 Beta Product Key">How To Get A Free Copy Of Windows 7 Beta Product Key</a></li><li><a href="http://www.walkernews.net/2011/07/17/how-to-receive-earthquake-alert-on-facebook-or-rss-feed-reader/" title="How To Receive Earthquake Alert On Facebook Or RSS Feed Reader?">How To Receive Earthquake Alert On Facebook Or RSS Feed Reader?</a></li><li><a href="http://www.walkernews.net/2011/06/06/how-to-unlock-windows-account-at-command-prompt/" title="How To Unlock Windows Account At Command Prompt?">How To Unlock Windows Account At Command Prompt?</a></li><li><a href="http://www.walkernews.net/2011/06/06/using-regular-expression-to-insert-nofollow-attribute-to-hyperlink/" title="Using Regular Expression To Insert nofollow Attribute To Hyperlink">Using Regular Expression To Insert nofollow Attribute To Hyperlink</a></li><li><a href="http://www.walkernews.net/2011/06/04/how-to-create-batch-file-with-endless-for-loop-on-windows-7/" title="How To Create Batch File With Endless For Loop On Windows 7?">How To Create Batch File With Endless For Loop On Windows 7?</a></li><li><a href="http://www.walkernews.net/2011/05/01/how-to-disable-windows-7-user-account-control-feature/" title="How To Disable Windows 7 User Account Control Feature?">How To Disable Windows 7 User Account Control Feature?</a></li><li><a href="http://www.walkernews.net/2011/04/15/how-to-print-windows-version-on-desktop/" title="How To Print Windows Version On Desktop?">How To Print Windows Version On Desktop?</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.walkernews.net/2009/12/27/how-to-get-sha-1-checksum-of-file-in-windows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Disable Adobe Reader JavaScript Function Or Take The Risk!</title>
		<link>http://www.walkernews.net/2009/12/16/disable-adobe-reader-javascript-function-or-take-the-risk/</link>
		<comments>http://www.walkernews.net/2009/12/16/disable-adobe-reader-javascript-function-or-take-the-risk/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 15:54:53 +0000</pubDate>
		<dc:creator>Walker</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Adobe Reader]]></category>

		<guid isPermaLink="false">http://www.walkernews.net/?p=3515</guid>
		<description><![CDATA[There is a security flaw in Adobe Reader which could be exploited by hackers who target the loophole in the PDF reader's JavaScript function.]]></description>
			<content:encoded><![CDATA[Do you believe that hackers could put your valuable data at risk as you open a manipulated PDF file with Adobe Reader?<br />
<span id="more-3515"></span><br />
Yes, it is true. With reference to <a href="http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214" target="_blank">an alert from Shadowserver Foundation</a><sup>1</sup>, Adobe Reader with JavaScript function enabled (by default) is subject to exploit by hackers who target the security flaws. If you open a crafted PDF file with Adobe Reader that allows JavaScript execution, your valuable personal data will be at risk of being stolen. <br />
<br />Until Adobe publishes a latest Adobe Acrobat Reader or patch to fix this JavaScript vulnerability, you should disable the Adobe JavaScript feature in no time:<br />
<ul>
<li>Click Edit menu followed by Preferences. Alternatively, press CTRL+K keyboard shortcut to bring up Adobe Reader Preferences dialog box.</li>
<li>Locate and click the JavaScript on the left pane and deselect the check-boxes to disable Adobe JavaScript from putting you data at risk.</li>
</ul>
<br /><img src="http://www.walkernews.net/wp-content/uploads/2009/12/Disable-Adobe-Reader-JavaScript.jpg" alt="How to disable Adobe Reader JavaScript function?" title="How to disable Adobe Reader JavaScript function?" width="500" height="308" /><br />
<br />For your info, the latest Adobe Reader 9.2 and earlier versions are all subject to this JavaScript security flaw, and the attack using this flaw is not easily detected by Antivirus and/or Internet security suite.<br />
<br /><sup>1</sup><small>The Shadowserver Foundation is an all volunteer watchdog group of security professionals that gather, track, and report on malware, botnet activity, and electronic fraud.</small><br />
<ul class="related_post"><li><a href="http://www.walkernews.net/2009/11/20/how-to-restore-the-missing-adobe-reader-menu-bar/" title="How To Restore The Missing Adobe Reader Menu Bar?">How To Restore The Missing Adobe Reader Menu Bar?</a></li><li><a href="http://www.walkernews.net/2008/06/29/how-to-download-adobe-reader-full-setup-file-for-different-os/" title="How To Download Adobe Reader Full Setup File For Different OS">How To Download Adobe Reader Full Setup File For Different OS</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.walkernews.net/2009/12/16/disable-adobe-reader-javascript-function-or-take-the-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How To Secure Gmail Connection By Encrypting Session With HTTPS?</title>
		<link>http://www.walkernews.net/2009/12/06/how-to-secure-gmail-connection-by-encrypting-session-with-https/</link>
		<comments>http://www.walkernews.net/2009/12/06/how-to-secure-gmail-connection-by-encrypting-session-with-https/#comments</comments>
		<pubDate>Sun, 06 Dec 2009 05:03:30 +0000</pubDate>
		<dc:creator>Walker</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Gmail]]></category>
		<category><![CDATA[Howto]]></category>

		<guid isPermaLink="false">http://www.walkernews.net/?p=3401</guid>
		<description><![CDATA[If you particular about Gmail security, make sure to force Gmail always applies https protocol to secure connection.]]></description>
			<content:encoded><![CDATA[Unless your Gmail account is only receiving newsletters or keeping emails that are not really personal and important, you should pay attention to Gmail security related announcements and features.<br />
<span id="more-3401"></span><br />
There is an option in Settings page, allows user to enforce Gmail applying HTTP or HTTPS browser connection:<br />
<br /><img src="http://www.walkernews.net/wp-content/uploads/2009/12/Secure-Gmail-Session.jpg" alt="The options used to secure Gmail connection." title="The options used to secure Gmail connection." width="500" height="287" /><br />
<br />By default, Gmail only apply HTTPS protocol during account login session (in fact that is Google Account authentication page which is later redirected to Gmail Inbox). The subsequent connection between you (the browser) and Gmail server is on the insecure HTTP protocol.<br />
<br /><span class="subhead">Two methods to always secure Gmail session</span><br />
<br />You can choose either one of these two methods to completely secure Gmail connection, from the moment you log in until log out:<br />
<br /><span class="subhead2">Always use HTTPS</span><br />
<br />As shown in the screenshot (above), click <span class="subhead2">Settings</span> link (top-right corner) and access to General tab of Settings page. Locate the &#8220;Browser Connection&#8221; section, select &#8220;Always use HTTPS&#8221; and then (remember) to click the &#8220;Save Changes&#8221; button (at bottom of page).<br />
<br />The <a href="http://mail.google.com/support/bin/answer.py?hl=en&#038;ctx=mail&#038;answer=74765" target="_blank">drawbacks of using this method</a> are as follow:<br />
<ul>
<li>For those who use Gmail Notifier, make sure the <a href="http://www.google.com/mail/help/downloads/notifier_https.zip" rel="nofollow" target="_blank">Gmail Notifier patch</a> is installed. Otherwise, Gmail Notifier will work unexpectedly when &#8220;Always use https&#8221; option is enabled.</li>
<li>Both Google Toolbar and Gmail for mobile application might encounter unexpected errors</li>
</ul>
<br /><span class="subhead2">Explicitly tells web browser to access Gmail over HTTPS protocol</span><br />
<br />Regardless what web browser you&#8217;re using, so long as the browser supports HTTPS protocol, you can manually type this following URL in address bar and press ENTER key to forcibly access Gmail over HTTPS protocol, from the time of log in until log out:<br />
<pre
<span style="color:#F00;font-weight:bold;">https://</span>mail.google.com
</pre>
<br />The <span class="subhead2">advantage</span> of using this manual method is that you can decide when to use HTTPS. If you can&#8217;t access to Google Account over HTTPS, you could simply access Google web services over the insecure HTTP protocol (if you willing to bear the risk).<br />
<ul class="related_post"><li><a href="http://www.walkernews.net/2010/10/20/how-to-make-gmail-displays-external-images-embedded-in-message/" title="How To Make Gmail Displays External Images Embedded In Message?">How To Make Gmail Displays External Images Embedded In Message?</a></li><li><a href="http://www.walkernews.net/2010/08/26/how-to-organize-gmail-emails-with-personal-folder/" title="How To Organize Gmail Emails With Personal Folder?">How To Organize Gmail Emails With Personal Folder?</a></li><li><a href="http://www.walkernews.net/2009/12/15/how-to-turn-off-gtalk-or-chat-feature-in-gmail/" title="How To Turn Off GTalk Or Chat Feature In Gmail?">How To Turn Off GTalk Or Chat Feature In Gmail?</a></li><li><a href="http://www.walkernews.net/2009/12/13/how-to-insert-image-inline-in-gmail-messages/" title="How To Insert Image Inline In Gmail Messages?">How To Insert Image Inline In Gmail Messages?</a></li><li><a href="http://www.walkernews.net/2009/12/11/how-to-know-that-i-have-activated-gmail-labs-features/" title="How To Know That I Have Activated Gmail Labs Features?">How To Know That I Have Activated Gmail Labs Features?</a></li><li><a href="http://www.walkernews.net/2009/12/05/how-to-activate-and-try-gmail-labs-product-in-gmail/" title="How To Activate And Try Gmail Labs Product In Gmail?">How To Activate And Try Gmail Labs Product In Gmail?</a></li><li><a href="http://www.walkernews.net/2009/04/26/better-way-to-enable-gmail-https-for-reading-email-securely/" title="Better Way To Enable Gmail Https For Reading Email Securely">Better Way To Enable Gmail Https For Reading Email Securely</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.walkernews.net/2009/12/06/how-to-secure-gmail-connection-by-encrypting-session-with-https/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How To Configure Kaspersky IS 2010 Firewall Rule?</title>
		<link>http://www.walkernews.net/2009/11/30/how-to-configure-kaspersky-is-2010-firewall-rule/</link>
		<comments>http://www.walkernews.net/2009/11/30/how-to-configure-kaspersky-is-2010-firewall-rule/#comments</comments>
		<pubDate>Sun, 29 Nov 2009 20:06:55 +0000</pubDate>
		<dc:creator>Walker</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Howto]]></category>
		<category><![CDATA[Kaspersky]]></category>

		<guid isPermaLink="false">http://www.walkernews.net/?p=3351</guid>
		<description><![CDATA[The new firewall maintenance interface is Kaspersky IS 2010 is quite confusing to me and maybe to you as well.]]></description>
			<content:encoded><![CDATA[Kaspersky explicitly claims that only version 9.0.0.736 (Critical Fix 2) and higher are compatible with Windows 7. That might not be true, however, especially to those who experiences Windows 7 hang problem when copying some files with Easy Asian characters.<br />
<span id="more-3351"></span><br />
In addition, I don&#8217;t think that everyone happy with its new Firewall rule maintenance interface. To me, it is confusing and not user-friendly.<br />
<br /><span class="subhead">Kaspersky IS 2010 Firewall &#8220;problem&#8221; and solution</span><br />
<br />These following guides are made with reference to version 9.0.0.736, the latest Kaspersky IS that said compatible with Windows 7, at this time of writing.<br />
<br />1) Trusted applications are automatically allowed to all network activities. In some occasions, I hardly able to stop a new program from sending information to Internet right after installation have done, because the program signed with digital signature and thus classified as trusted program.<br />
<br /><span class="subhead2">To prevent this from happening</span>, I&#8217;ve to disable the network card from Windows during installation. After installation completes, define a new Firewall filtering rule that block all network access to supersede default rules set by Kaspersky.<br />
<br /><span class="subhead2">To add user-defined filtering rule to a program</span>: In Firewall filtering rules, select target program in the list and click &#8220;Add&#8221; link (at bottom) to proceed with Network Rules dialog box (as shown).<br />
<br /><img src="http://www.walkernews.net/wp-content/uploads/2009/11/kaspersky-IS-2010-Firewall-Rule.jpg" alt="Add your own firewall filtering rule to supersede default firewall rule defined by Kaspersky IS 2010" title="Add your own firewall filtering rule to supersede default firewall rule defined by Kaspersky IS 2010" width="500" height="437" /><br />
<br /><img style="float:right;margin:0px 0px 0px 5px;" src="http://www.walkernews.net/wp-content/uploads/2009/11/kasperksy-2010-firewall.jpg" alt="Delete old and unwanted firewall filtering rule from Kaspersky IS 2010" title="Delete old and unwanted firewall filtering rule from Kaspersky IS 2010" width="250" height="205" />2) Are you mad looking for a way to delete application from the Firewall filtering rules?<br />
<br />You cannot manually delete an application appears in Firewall filtering rules setup page. You can, however, delete the application from <span class="subhead2">Application Activity Control</span> &#8211; right click a program from the list and select &#8220;Delete from the list&#8221;:<br />
<ul>
<li>Click the Kaspersky icon in Notification Area (System Tray). Alternatively, go to Start button > All programs > Kaspersky Internet Security 2010 to launch the security program.</li>
<li>In the main program user interface, click &#8220;My Security Zone&#8221; follow by &#8220;Application activity&#8221; link:<br />
<img src="http://www.walkernews.net/wp-content/uploads/2009/11/Housekeep-kasperksy-2010-firewall-rule.jpg" alt="Delete or housekeep unwanted firewall rules from Kaspersky IS 2010" title="Delete or housekeep unwanted firewall rules from Kaspersky IS 2010" width="450" height="195" /></li>
<li>Select &#8220;All&#8221; from the Category drop-drop list box, locate the unwanted program and right click to select &#8220;Delete from list&#8221; option. That&#8217;s the way to delete or housekeep unwanted firewall rules in Kaspersky IS 2010!</li>
</ul>
<br />3) Kaspersky IS 2010 will automatically delete programs from firewall filtering rules, if the programs remain inactive for a number of days that defined by user. Right click Kaspersky icon in Notification Area, select Settings, click Application Control on the left panel, and tick the check box labelled as &#8220;Delete rules for applications remaining inactive for more than xx days&#8221;.<br />
<br />Not happy with the new Kaspersky IS? Well, you have choice to live with it or drop it and pick up alternative Internet security software to safeguard your lovely Windows 7.<br />
<ul class="related_post"><li><a href="http://www.walkernews.net/2011/08/02/kaspersky-causes-cisco-anyconnect-vpn-client-unable-to-establish-connection/" title="Kaspersky Causes Cisco AnyConnect VPN Client Unable To Establish Connection">Kaspersky Causes Cisco AnyConnect VPN Client Unable To Establish Connection</a></li><li><a href="http://www.walkernews.net/2010/11/26/how-to-fix-kaspersky-high-cpu-usage-problem/" title="How To Fix Kaspersky High CPU Usage Problem?">How To Fix Kaspersky High CPU Usage Problem?</a></li><li><a href="http://www.walkernews.net/2009/03/27/how-to-remove-or-uninstall-avg-free-antivirus/" title="How To Remove Or Uninstall AVG Free Antivirus?">How To Remove Or Uninstall AVG Free Antivirus?</a></li><li><a href="http://www.walkernews.net/2012/01/30/activate-facebook-timeline/" title="Activate Facebook Timeline">Activate Facebook Timeline</a></li><li><a href="http://www.walkernews.net/2012/01/16/how-to-check-db2-table-size/" title="How To Check DB2 Table Size?">How To Check DB2 Table Size?</a></li><li><a href="http://www.walkernews.net/2012/01/16/how-to-hard-reset-android-tablets/" title="How To Hard Reset Android Tablets?">How To Hard Reset Android Tablets?</a></li><li><a href="http://www.walkernews.net/2012/01/15/how-to-configure-android-3-2-1-proxy-setting/" title="How To Configure Android 3.2.1 Proxy Setting?">How To Configure Android 3.2.1 Proxy Setting?</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.walkernews.net/2009/11/30/how-to-configure-kaspersky-is-2010-firewall-rule/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

