ESET KENYA

ESET KENYA
THE BEST SECURITY FOR THE SMART COMPANIES

Monday, 20 January 2014

Cash crash ahead?



Death’ of Windows XP could leave 95% of world’s ATMs vulnerable


As many as 95% of ATM machines around the world could be vulnerable from April onwards, when Microsoft cuts off regular security patches for Windows XP on April 8. Most ATM machinesworldwide still run the ageing operating system – and some banks may continue ‘indefinitely’.
There is a reports that ATM software company KAL estimates that just 15% of ATMs will upgrade to Windows 7 by April. “That leaves thousands of machines running out-of-date software,” the site said.
A report by Bloomberg Businessweek says that 420,000 ATMs in the U.S. still run Windows XP, according to Robert Johnston, marketing director at NCR, the largest supplier of ATMs in America, and now face a ‘deadline’ to upgrade. After April 8, the machines will be at risk of non-compliance with industry standards, and at increased risk of attacks against the OS.
Speaking to The Verge, NCR said that most ATMs still run the full version of Windows XP, with support ending in April, while a minority run Windows XP Embedded, which will be supported until 2016.
Many banks face costly hardware upgrades to replace ageing machines which cannot support Windows 7 – JP Morgan says 3,000 of its 19,000 ATMs will require “enhancements” to support Windows 7, according to Bloomberg.
The Verge reports that JP Morgan is to buy a custom support contract from Microsoft to extend the life of ATMs running Windows XP.
“The ATM world is not really ready, and that’s not unusual” says Aravinda Korala, chief executive officer of ATM software provider KAL, according to a report by the Daily Mail, which describes XP-powered machines as ‘vulnerable’. “ATMs move more slowly than PCs.”
In a presentation in December, Mr Korala suggested that some banks intended to continue to use XP-powered machines ‘indefinitely’.
Earlier this month, Microsoft affirmed that XP would no longer be “a supported operating system”, but that it would provide assistance to users in the form of antimalware signatures for some months after the April deadline for patches, as reported by We Live Security here. “To help organizations complete their migrations, Microsoft will continue to provide updates to our antimalware signatures and engine for Windows XP users through July 14, 2015.”
Despite Microsoft setting April 8, 2014 as the “end of support” date for Windows XP, around a third of PCs worldwide still run the operating system, according to research firm Net Applications.
“We will continue to help our customers complete their migrations as Windows XP end of life approaches,” Microsoft said via its blog post. The company made it clear, though, that Windows XP was a less safe option than newer versions of its OS. “Our research shows that the effectiveness of antimalware solutions on out-of-support operating systems is limited. Running a well-protected solution starts with using modern software and hardware designed to help protect against today’s threat landscape.”
Windows XP users already face a higher risk of malware infection, as reported by We Live Security here. Per 1,000 PCs scanned, 9.1 XP machines had been infected – as compared to 1.6 for Windows 8, according to a report by Neowin.
“Microsoft Windows XP was released almost 12 years ago, which is an eternity in technology terms. While we are proud of Windows XP’s success in serving the needs of so many people for more than a decade, inevitably there is a tipping point where dated software and hardware can no longer defend against modern day threats and increasingly sophisticated cybercriminals,” Microsoft wrote in a statement last year.

Sunday, 19 January 2014

The JKIA Blast was the Work of Terrorists

Police now confirm that terrorists did indeed attempt to blow up a cafe at the JKIA Unit 1 Departures. NTV has established that terrorists had visited the airport twice in the last two weeks before returning on the fateful Thursday to carry out their mission that luckily did not go as planned.
The impeccable sources also confirm that the same terrorists are the ones who abandoned their vehicle at Shauri Moyo.
january 16th
22:42
Three people walked to the cafe two sit on a seat next to the door while the other one drops something inside a  dust bin
22:43
Suspect abruptly leaves the cafe
22:45
Explosion goes off in a bin










Runaway Kenyan in Saudi Arabia lives in distress with no papers





A 19-year-old Kenyan housemaid Lavin Oloo is leading a pathetic life in Jeddah, without any travel documents or money for sustenance.
Lavin, who had run away from her sponsor alleging that he had failed to fulfill the terms of contract, could not avail of the amnesty since all her documents including passport are in the sponsor’s possession. The sponsor refused to return her passport arguing that he had spent a lot in recruiting her.
Lavin told Arab News that she ran away from her sponsor because he did not pay her monthly salary of SR800. She worked with his family for three months during which time she was also forced to work for his relatives without payment. She left her job hoping that the Kenyan Embassy in Riyadh would help her return home.
Stating that she has spent one year and 11 months in the Kingdom, Lavin said she did not have any travel documents or money and the sponsor has refused to get her final exit visa.
She tried to find employment elsewhere when she couldn’t return home. However, most people refused to hire her as the amnesty period ended on Nov. 3, 2013, and labor laws prohibited hiring of expats who had run away from their sponsors.
In July last year, Lavin met some Kenyan officials from the embassy in Riyadh who had been sent to Jeddah to help Kenyan expats wanting to leave the Kingdom. But, they failed to do anything because she had no travel documents.
“The Kenyan Embassy told me that I would have to visit them in Riyadh to get help. But I have no travel documents to go there. I went to the deportation center of the Passport Department but they too couldn’t help me get deported to my country,” she said.
Lavin does not know whether her sponsor has her Iqama. “When I came to Saudi Arabia, my sponsor promised that he would take care of Iqama procedures. But, I think he has not done anything yet,” she said.
Arab News tried to get in touch with Ali Mohamed Mambo, second secretary at the Kenyan Embassy in Riyadh, to get information on the issue, but they don't respond anyway

Monday, 13 January 2014

FIFA World Player of the Year

Cristiano Ronaldo has been crowned the FIFA World Player of the Year for the second time, breaking the stranglehold of his great adversary Lionel Messi.
The Real Madrid superstar saw off competition from Barcelona’s Messi and Bayern Munich’s Franck Ribery to claim the coveted Ballon d’Or.
An emotional Ronaldo walked onto the stage to collect his award with his son Cristiano and couldn't hold back the tears as he was presented with the trophy.
 

Kidero, Shebesh to face charges after talks fail

Governor Evans Kidero during his confrontation with Nairobi women representative Rachel Shebesh at City Hall in September 06, 2013. PHOTO | FILEGovernor Evans Kidero during his confrontation with Nairobi women representative Rachel Shebesh at City Hall in September 06, 2013. 



 
Justice Isaac Lenaola on Monday allowed Director of Public Prosecution Keriako Tobiko to proceed with charges against Nairobi Governor Evans Kidero and Women Representative Rachel Shebesh.
This was after the two politicians failed to agree on a out of court settlement.
Lawyer Cecil Miller, representing Ms Shebesh, told the Judge that they had waited in vain for Mr Kidero to meet the terms for reconciliation.
He said Ms Shebesh is ready to face the charges.
Governor Kidero will be charged with assault charges after allegedly slapping Ms Shebesh during a scuffle at City hall in September last year.
Ms Shebesh will be charged with creating public disturbance.
Governor Kidero and Ms Shebesh were involved in a scuffle at City Hall in the full glare of the media.
The incident happened when Ms Shebesh, accompanied by aggrieved Nairobi City County workers who are demanding better pay, went to Dr Kidero’s office.
The governor had just returned from a meeting with visiting Nigerian President Goodluck Jonathan when he came face to face with Ms Shebesh, some members of the County Assembly and the workers.
The situation turned chaotic and it was then that Dr Kidero allegedly slapped Ms Shebesh before telling her off.
After the incident, both the governor and the Women Representative separately recorded statements with the police.

GANGSTERS KILL FIVE PETROL STATION WORKERS BY HACKING THEM TO DEATH IN NAIVASHA, KENYA!

Armed gangsters on Monday morning hacked to death five workers at Total petrol station in Naivasha and stole more than Sh1 million from the office.

The gangsters struck at around 3am, killing the workers - two of whom were women - before breaking into the main office and stealing the money.

Joseph Gichoya, the owner of the petrol station, said he was alerted at around 4:30am and drove to the scene where he found his workers dead.

The number of gangsters who carried out the attack is yet to be established.

Detectives have already collected evidence from the scene. The glass door to the main office had been smashed and the safe forced open.

The dead were identified as three male petrol station attendants and two female employees who had earlier been working at the restaurant.

Sunday, 12 January 2014

ESET in 10


Why wait for hours for delivery while you can get it in less than 10 minutes
order eset antivirus and get it in 10 minutes within Nairobi .Why wait for that long call us on
Tel: (020) 2349490
: (254) 020-3750848
Cell:0721 319897 / 0736 319897 Nairobi
or visit our office on
eNkei Centre 2nd Flr Suite#205, Above KCB Ngara

Android! 12 tips to toughen up your new device for the real world

 This holiday season was a boom time for Android devices – with activations of Android smartphones and tablets on Christmas day hitting new heights, and narrowing the gap against rival Apple, according to analyst Flurry.
If you’re one of the lucky ones who unwrapped a Google Nexus tablet or one of Samsung’s army of different-sized Androids, congratulations – but there are a few sensible steps to take before taking that device into the ‘real world’, especially if you intend to use it for work.
There have been many scare stories about Android this year, often relating to malware targeting the OS – some rather overstated, but many, sadly close to the truth.
ESET’s Annual Threat Trends Predictions report for 2014 found that detections of Android malware have increased 63% from 2012 to 2013 – with new strains of malware posing serious threats, such as Trojans targeting  online banking apps. Previous generations of phone malware often merely ran up bills using premium SMS numbers, or assaulted users with unwanted adverts.
If you’re a user ‘switching sides’ from an Apple iDevice, you might be alarmed – and it’s easy to feel at risk when you’re getting used to a new system. But it’s not quite as bad as it seems.
Thankfully, Android itself now offers some great built-in protection against theft and malware – including a great anti-theft system quietly rolled out by Google to many Android users.
Downloading free AV software such as ESET’s Mobile Security and Antivirus is a great way to ensure your device – and your data – are safe, but our tips should help even novices get the most out of their new Androids, and ensure that even if the worst happens, and a cellphone is stolen, the data on it will remain safe.
Once it’s started up, lock it down
Various Android devices from different manufacturers offer their own different security systems built in, but the really bulletproof ones are Google’s, and common to all up-to-date Android devices – the most basic one is getting a screen lock in place, and it’s common to every model. Do this before you take your device anywhere. Head to Settings > Security > Screen Lock. On new devices, you’ll usually get a choice of pattern, PIN, or password. A pattern’s less secure than a PIN, and a password is your best choice. If you’re using your tablet or smartphone for business, be extra careful. Talk to your IT department, and read our guide to encrypting data on Android here.
While you’re at it, double-lock the important stuff
If someone does crack your code (sometimes possible simply by turning a handset sideways and looking for greasy finger marks – which is why choosing a pattern code can be risky), you can add another line of defense by locking individual apps – a very sensible step, and the reason that the excellent, free App Lock is, its makers claim, the most-downloaded app on Google’s Play Store. App lock lets you create a PIN which locks important apps – your email, Dropbox, or anything else which could hand data to cybercriminals. Better still, App Lock is pretty good at defending itself – it has mechanisms to ensure it can’t be uninstalled unless you have the PIN.

If you share ANY devices, be careful with Google Now
Google’s Now service can be accessed on Android via either a swipe up from the bottom of the screen, or via a Google Search box on screen, depending on which make of Android you choose – offering “predictive search” – ie guessing information you might need, based on your habits. Used carefully, it’s great – offering reminders of flights you have to catch (culled from Gmail), and traffic conditions on your commute (based on GPS data harvested by the handset). But while the ‘predictive’ search experience adds a lot to Android, it can also give a lot away. Any device signed in to the same Google account – ie a tablet you share at home – will ‘know’ whatever information you opt to share with Now, including potential privacy minefields such as your web search history. Thankfully, you can tailor how it works for you from Now, or from Google’s dashboard page – do so carefully.
Taking your phone to work? Talk to IT first
The trend for workers “bringing their own devices” to work is increasing year-on-year – but your boss, and your IT department will thank you if you ask first. Around 30-40% of devices in workplaces fly “under the radar”, according to former vice-president of security body ISACA Rolf von Roessing, who warned that workplaces faced a “tidal wave” of threats unless users were educated about risks, as reported by We Live Security here. If you’re taking your own phone to work, ask your IT department for advice – and remember that even an email ‘Sent’ box can contain information invaluable to a criminal looking to penetrate a company network. Your boss will thank you if you’re open about using your own smartphone in the workplace – or even for working from home. Our in-depth guide to bringing devices to work – and not bringing disasters with them – can be found here.
Lost it already? Don’t panic!
Despite frequent malware attacks – and an official app store that is still home to thousands of malicious and spammy apps – Google offers a pretty decent selection of security features built in – including a location tracker, which can help find a lost device, even if it’s just down the back of the sofa. Visit  Google’s Android Device Manager page to activate it, while logged into your Google account, and you’ll be able to force a device on silent mode to ring, remote-lock a device, and view its location on a map. If you own several Androids, you’ll be able to see them all. More advanced protection is offered by AV programs such as ESET’s Mobile Security and Antivirus, but Google’s own, rolled out quietly to any users of Android 2.2 and above last autumn, is a good first stop.
Keeping sensitive info on your smartphone? Don’t store it on a removable SD card
If you are keeping sensitive information on your phone – you really shouldn’t, if at all possible – don’t keep it on a removable SD card. This makes it easier for attackers to access data. If, for instance, your photos include an image of your credit card or passport, don’t store them in external memory.  Ensure anything you want to keep safe is stored in your device’s internal memory, and protect this using a strong password. Google’s Android Device Manager page offers useful options to wipe data remotely if a phone is stolen – and AV apps such as ESET’s Mobile Security and Antivirus  offer more options for users who have lost a handset, including playing sounds and remotely locking devices (with built-in password protection so criminals can’t disable the anti-theft functions.
 Encrypting your phone WILL slow it down – but keep your data safe
Encrypting your device – so that all data on board is PIN-protected – isn’t for everyone – it will slow your device down, which can be painful if you’ve just unwrapped a top-of-the-range smartphone. But if you are carrying work information on it, it’s a good way to ensure sensitive data is safe, even if the device falls into the wrong hands.  Thankfully, it’s easy to encrypt your device in Android’s own settings menu – Settings/Security/Encryption – in an option available since  Android Gingerbread 2.3.4. Choose Encrypt Device and Encrypt External SD Card, then wait while the device crunches your data (this takes a while). After that point, your data is PIN-protected. This will slow your device, though. A more detailed We Live Security guide to encryption – on mobile and PC – can be found here, with explanations of when and why you might want to encrypt data.
 Google’s Play store isn’t perfect – but it’s FAR safer than most ‘unofficial’ stores
For ‘defectors’ moving from iOS to Android, the fact that malicious and spammy apps sneak into Google’s official Play store may be a shock – unlike Apple’s App Store, there is not an approval process, so ‘bad’ apps can sneak onto Play. Play, though, remains a far safer place to shop than unofficial stores – or bogus ‘review’ sites offering free apps.  Google removes ‘bad’ apps once users complain – but some lurk around for quite a while. Watch out for close-but-not-quite clones of popular apps and games – a classic trick – and in general, think like you are shopping on eBay (ie does the developer sound legitimate? What do the reviews say?). Most apps on Play, though, ARE safe – if you follow our detailed guide to being a happy app-y shopper here. But the most crucial oogle Play, Amazon’s App Store and GetJar, you will be much safer – although “bad” apps can still sneak into those.
Don’t feel you HAVE to root your Android
For many tech-savvy phone users, the chance to ‘root’ an Android device – gain root access to the phone’s OS, which allows users to, among other things, uninstall all the unwanted apps with which Samsung and other phone makers routinely bloat their devices. There are dozens of tutorials on how to root devices online, and many Android forums make it seem like a “first step” for users, allowing Android fans to run apps which require root access, such as firewalls – normally blocked by the OS. But rooting a phone opens users up to new risks – and cuts off many of the protections built into Android itself. It will also severely annoy your employer, if the handset happens to be a work one. Malicious apps with root access can cause far more damage than normal ones – and the unofficial app markets where apps for rooted devices are traded are filled with malware, sometimes disguised as popular apps. “Free” versions of the predictive text app Swiftkey appeared on pirate sites – infecting users foolish enough to download with a keylogger which took note of every keystroke in Swiftkey, with the goal of stealing data.
Read the “permissions” screen EVERY time you install an app
Most computer users are pretty impatient while shopping – and used to skipping straight past huge legal documents without reading a word – but while Android’s App Permissions page looks boring, it’s THE single most important defense built into the system.  “Bad” apps will request access to and control over huge amounts of your Android’s functions – such as reading all network communications, or sending SMS messages – if an app has a huge list of Permissions, it’s an “alarm bells” moment. Why WOULD a screensaver need to send SMS? Our detailed guide to safe Android app shopping can be found here.
Don’t EVER install a banking app from a link
Governments around the world have warned of the risk to consumers from ‘fake’ banking apps – either delivered on their own, or as part of an attack against a PC, where the malware attempts to fool users into downloading the fake app by delivering messages through bogus bank sites. An increasing number of PC Trojans target Android devices with fake banking apps – with several families of banking malware  such as Qadars, reported by We Live Security here attempting to fool users into installing malicious apps via their PC’s browser – aiming to bypass two-factor authentication systems used by banking sites. Banking Trojan Hesperbot, discovered by ESET and reported here uses a malicious webpage to instruct users to enter their cellphone number and make, and attempts to install a malicious app that bypasses security systems. Your bank will NEVER distribute apps in this way – instead, download your bank’s app from Google’s Play, and ensure yours is up to date. . “ESET products like ESET Smart Security and ESET Mobile Security protect against this malware,” says Robert Lipovsky, ESET malware researcher who leads the team analyzing this threat.
Paying for something with your phone? Be VERY careful
Up-to-date Androids such as Samsung’s Galaxy S4 and HTC’s One ship with an NFC (Near Field Communication) chip – a new technology designed to transmit data over short distances, and used in some countries, such as Chile, as a tap-to-pay system in stores. But point-of-sale terminals have become an increasing target for cybercriminals – as witness these We Live Security reports - and ESET researchers warn that NFC payment systems could become a target for cybercriminals this year. In this year’s Annual Threat Trends Predictions 2014 report, ESET researchers wrote, “Any technology used for bank transfers is a potential target of computer attacks. As this means of payment becomes more popularly used, malicious code may appear to steal information relating to these transactions.” Be cautious about any means of storing money on your phone – such as Bitcoin wallets – or paying direct via NFC.
Author martin kamau
 

Friday, 10 January 2014

Tech Support Scams: Second Byte at the Cherry

Is there really anything new to be said about tech support scams? Unfortunately, the FTC tells us there is. Not only because people are still falling prey to this type of fraud, but because the scammers are still finding new approaches to harvesting their victims’ credit card details. Some quite interesting, sophisticated technical tricks are used to persuade you that:
  1. you have a problem with your computer
  2. that the scammer knows or could possibly know anything about your computer
  3. that the scammer needs you to give him access to your computer so that he can prove to you that the problem is real and to enable him to ‘fix’ it for you.
But sometimes a more generic social engineering approach also turns up, and one of these has been flagged by the Federal Trade Commission (FTC). In brief, Nicole Vincent Fleming tells us that support scammers are calling back and offering a refund.
As it happens, I’ve seen a couple of reports in the past year or two that have suggested a somewhat similar variation, but too few to determine exactly what form the scam was taking. And in fact, it’s not uncommon for 419 scammers to kick off with an offer to reimburse people who are – wait for it – victims of 419 scams. In that instance, the scammer doesn’t usually admit to being a 419 scammer, but poses as a representative of a government agency (for instance).
The FTC article, however, suggests that at least some of these calls are from scammers revisiting previous victims and offering a refund if they considered the service unsatisfactory, which isn’t something I’ve seen reported previously. Sometimes, though, it seems that the refund is offered on account of the ‘service’ going out of business, and that resembles previous reports I’ve seen, though looking at them in the light of the FTC article, I don’t think that the callers operating this particular variation of the scam are necessarily the same scammers who may have called previously. At least one of our correspondents was puzzled and alerted by the fact that the caller offering a refund didn’t represent the same company with whom he thought he had a contract.
The article gives more information on how the scam works and advice on what to do if you fell for it (complain to the FTC, reverse credit card charges and so on).
I suspect, though, that the real step-change here is that the scammers have once more crossed a line. Earlier in the evolution of the scam, we found that some scammers who admitted that they were not being altogether honest with their victims nevertheless justified their actions by claiming they were providing a useful service. And from time to time, we see comments along the lines of “this isn’t really a scam, more like aggressive marketing”. (I don’t agree, by the way: selling a service by lying to the customer is fraud, in my book.)
Later, we saw scammers who reacted aggressively when they thought they weren’t going to get the payment they anticipated: if they’d already been allowed access to the victim’s machine, they would try to trash the system. While trashing someone’s system for non-payment doesn’t often stand up as a defence in court – remember Dr. Popp and the AIDS Trojan? –motivation in the case where the criminal thinks he’s supplied some kind of service is kind of understandable, if morally, ethically and legally indefensible.
What the FTC is describing, though, seems to me to be a clear case of fraud: asking for credit card details on the grounds that you’re going to give them money and then taking money instead seem unequivocally criminal to me. I don’t see how any scammer can seriously convince himself that this is somehow offering a legitimate service. Of course, this doesn’t mean I think that the scammers weren’t previously aware that what they were doing is wrong: only that it’s harder for scammers to justify their actions to themselves.
If you’re interested in finding out more about this kind of scam, I’ve been maintaining a page on the AVIEN blog for some time with links to resources pertaining to support scams and related issues, papers, articles, and blogs (to which this and the FTC article will shortly be added): PC ‘TECH SUPPORT’ COLD-CALL SCAM RESOURCES. Of course, there are an awful lot of articles on the topic here on WeLiveSecurity. We’ve also posted several papers on the topic:

Thursday, 9 January 2014

Companies have “heads in sand” about security threat as employees sneak mobile devices to work, report

Employers are failing to face up to the threats posed by employees who use their own mobile devices at work – 40% of companies do not consider the ‘bring your own device’ (BYOD) trend even to be on their agenda, according to a survey of IT and communication industry workers.
Just one quarter of those surveyed said that their employer had embraced the idea – but IT experts have warned that employees will bring in devices “under the radar” unless employers make policy clear.
Managing Director of Qubic,  cloud communication specialist, which conducted the survey via ChannelWeb.co.uk, Chris Papa says: “This is coming whether they like it or not and sooner or later they are going to have to deal with it. Employees are using their own devices and bringing them into work regardless of their employers’ views.”
“Undecided employers will have to climb down off the fence and either prohibit BYOD for work completely, blocking access to their systems and their clients’ data, or apply sufficient controls to protect their own and their clients’ data.”
Earlier this year, Rolf von Roessing, head of security trade body ISACA said that in many workplaces, security teams were facing a “tidal wave” of challenges caused by mobile devices.
“For effective protection, security professionals need access to mobile operating systems, but this is not always possible and consequently 30% to 40% of devices are under the radar,” said von Roessing.
Over the past year, ESET’s detections of Android malware have risen 60%, as revealed in the annual Threat Trends Prediction report. ESET labs have also noted an increase in Android malware built using PC-like techniques.
“Next year will also see an escalating increase in serious threats targeting Android phones and tablets – ESET detections of such malware increased more than 60% between 2012 and 2013. This trend is predicted to continue in 2014,” the report warns.
Chris Papa says: “The employer and employee must have a clear understanding of what is expected of them. Of paramount importance is ensuring that the benefits BYOD has to offer, do not compromise the security of the workplace.”
ESET Senior Security Researcher Stephen Cobb said, in a detailed blog post cataloguing some of the risks of BYOD,“The phenomenon of organizations allowing or encouraging their employees to use their own computing devices for work–known as Bring Your Own Device, or BYOD–is now widespread in many countries, bringing with it some serious risks to company networks and data.”
A We Live Security guide to the risks of BYOD – and how to avoid being the guy who, as the old IT joke has it “brings his own disaster,”