Google Search

Showing posts with label Sophos. Show all posts
Showing posts with label Sophos. Show all posts

Saturday, September 28, 2013

Sophos RED scoops "Protector Award" at this year's AusCERT conference

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

We try to avoid being too marketroidistic here on Naked Security.

After all, we're aware that you can work out which company's products we'd recommend just by looking at the URL of this article.

But when our technical colleagues get outside recognition for the excellence of the products they create, we can't help but mention it.

(Especially when said techies are stuck at the coalface, knee deep in code, while one of their colleagues gets to collect their award at a Gala Dinner event in a subtropical holiday resort.)

So we're proud to say that at this evening's 2013 Information Security awards at the AusCERT conference in Australia, Sophos scooped the Protector Award with Sophos RED.

RED, you ask, from a company with a blue logo?

Yes! RED stands for Remote Ethernet Device, and it's a brilliantly simple way of connecting up your branch office or remote workers:

The Sophos Remote Ethernet Device protects branch offices and provides secure remote access. Simply plug the device into your Internet router and centrally manage it from the Sophos UTM appliance at headquarters. Branch office traffic is forwarded to the Sophos UTM appliance for complete security.

The neat thing about the RED is that it can't be misconfigured when it arrives at the remote office.

You enter the unique device ID printed on your RED into your Sophos Network Security Gateway (or UTM for short) back at HQ, and a new configuration file is automatically created and stored with the Sophos provisioning service.

When the non-techie at the remote office plugs in the unit and turns it on for the first time, the RED and the cloud automatically do the rest.

You end up with an encrypted Virtual Private Network (VPN) connection that is equivalent to having your remote workers plugged into your wired network at head office.

Delivering a product of this sort that Just Works isn't a job for the faint hearted programmer.

The challenge of words like zero in computer science is that they are unambiguously absolute.

So when you promise a "zero configuration" experience, you really have to mean it: you can't have a single pop-up dialog, tick box, or [OK] button.

? Even a washing machine typically needs some user-side configuration, no matter that it's just twiddling a dial and pressing a switch.

So, congratulations to our techie brothers and sisters for making "zero" mean zero!

By the way, if you're wondering why you might want to consider a full-blown VPN instead of just relying on remote workers to connect to key services over HTTPS, take a look at some of the comments on our recent Wireless Security Myths video.

HTTPS secures individual transactions, but it doesn't secure the DNS lookups of your remote users, and it doesn't shield the times or destinations of their connections.

That might not sound like a lot, but an attacker who controls your DNS can entirely own your network, and an attacker who knows the pattern of your communications can apply traffic analysis and learn more about your business than you might like.

Much worse, rather obviously, is that HTTPS works with co-operating secure websites only; it protects nothing else that leaves or enters your computer.

So...which company's product would I recommend for remote office connectivity?

Let me just say, "You can work it out just by looking at the URL of this article."

Follow @duckblog


View the original article here

Tuesday, May 28, 2013

Sophos CEO suffers from a watery end for #ComicRelief

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Dunking. Image from ShutterstockRed Nose Day is a UK-wide fundraising event organised by the Comic Relief charity every two years which culminates in a night of comedy and moving documentary films on BBC One Television.

In the past we have put members of our senior management team into a gunge tank, staged boxing matches on bouncy castles and had a spacehopper race around the Sophos car park.

But this year, we decided to become a bunch of dunkards.

A large tank of water was brought into our offices, and a high tech mechanism devised which involved throwing tennis balls at a switch. If the tennis ball hit with enough ferocity, the Sophos worker would be plunged into the water - to the delight of their baying co-workers who had sponsored their preferred victims.

It was no surprise to find that Sophos CEO Kris Hagerman was high on most people's list for a dunking, and he came prepared with sunglasses, Hawaiian shorts and flipflops. This was definitely a man who knew where his towel was.

Comic Relief is a great charity to support - so make sure to visit the Red Nose Day website to find out how you can help raise funds.

So far the "Sophos Dunkards" team has raised approximately £7000 for charity. Thanks to all who helped!

PS. If you want to see more, check out our Sophos Dunkards photo album on Facebook.

http://twitter.com/gcluley

View the original article here

Sunday, January 13, 2013

Sophos staff win Movember contest while raising money for prostate cancer research

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Peter Gale from Team MophosFor the unfamiliar, Movember (The month formerly known as November) is a moustache-growing charity event, held each November, that raises funds and awareness for men's health.

The Mo Bros and Mo Sistas of Sophos Vancouver formed a team this year, Team Mophos, on the international Movember website to see how much money we could collectively raise as an office.

How'd we do? Well, 25 individuals participated from the Vancouver office alone, raising more than $6000 Canadian for charity (It's not too late! Click Team Mophos above to contribute).

In major cities, Movember also coordinates some celebrations and contests at the end of the month and Vancouver was no exception.

Onur Komili from Team Mophos

There are all kinds of different contests and awards for the best and most creative mustachioed faces.

Peter Gale, Product Development Manager, and Onur Komili, Sr. Web Threat Researcher in SophosLabs, decided to enter the best costume contest as the legendary 1990's wrestling team The Legion of Doom.

Considerable effort was put into the outfits and makeup to create just the right amount of menace, respect and of course an opportunity to show off the stache.

Team Mophos Legion of Doom

I am proud to announce they were selected by the Mo Bros and Mo Sistas at the Vancouver Gala Parté as best Team Mo Bro, and Onur won the award for Man of Movember.

Congratulations, guys. Aside from the fun we all had we were able to raise a tidy sum of money for a good cause.

Follow @chetwisniewski

View the original article here

Tuesday, December 25, 2012

Sophos awarded VB100 in Windows Server 2003 R2 comparative anti-virus test

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

VB100 awarded to Sophos in October 2013 comparative testThe latest edition of Virus Bulletin magazine includes a comparative test of 36 different anti-virus products, exploring their ability to reliably detect malware on the Windows Server 2003 R2 platform.

Just as with the tests that Virus Bulletin conducts on other operating system platforms, the VB100 title is only awarded if a product is capable of detecting all in-the-wild viruses in both on-demand and on-access modes without suffering from any false positives.

Sophos performed well in the tests, outperforming a number of competing firms, and was awarded the VB100 title by detecting 100% of the viruses in Virus Bulletin's "in-the-wild" collection and not having any false alarms.

Virus Bulletin's Technical Consultant & Test Team Director John Hawes praised Sophos's stability, and highlighted our consecutive awards:

“Sophos put in a very strong performance in our latest comparative, easily earning VB100 certification and achieving good scores in all our measures. Stability was particularly impressive, with no problems encountered at all even in heavy stress tests - this earns Sophos our highest possible rating of ‘Solid’ for a second consecutive test, one of only two products to achieve this feat.”

More information about this latest test can be found in the October 2012 edition of Virus Bulletin magazine, that has just been published.

Don't forget that you can see Sophos's long track record in independent comparative tests on Sophos's reviews page.


View the original article here

Saturday, November 17, 2012

New updated Virus Removal Tool from Sophos now available

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

cute robot 170As promised, Sophos has just released an updated version of its free Sophos Virus Removal Tool (Version 2.2).

This Windows tool, which is designed to work alongside your existing anti-virus installation, removes viruses, spyware, rootkits and fake anti-virus.

At the launch of the first version of the software earlier this year in April, Naked Security readers kindly provided feedback for the tool's developers:

The top three issues readers highlighted were:

Speed up scanning timeImprove malware clean-upIncorporate auto-update capabilities

The good news is that this release addresses all these points. It also boasts improved scan status information, including a progress bar for scanning and for cleanup; and the option to run the tool in safe mode as well as run on computers using proxy settings.

Sophos Virus Removal Tool is completely free and requires no registration.

Visit sophos.com to learn more. Or click here to download immediately.

(Oh, and for you Mac users out there, you can download the wonderfully free Sophos Anti-Virus for Mac home edition.)

http://twitter.com/caroletheriault

http://twitter.com/nakedsecurity

Tags: anti-malware, Anti-virus, disinfect, disinfection, Fake antivirus, free, Malware, remove viruses, rootkits, Sophos Virus Removal Tool, SVRT, Virus, viruses


View the original article here

Wednesday, October 24, 2012

Shh/Updater-B false positive by Sophos anti-virus products

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Latest information:

Knowledge base article: http://www.sophos.com/en-us/support/knowledgebase/118311.aspx

We will continue to update the knowledge base article above with the latest advice for self-service. Please consider following our support team @SophosSupport on Twitter for updates.

Updated article below:

Some Sophos customers have reported detections today of Shh/Updater-B.

Many of these reports involve detections of Sophos's own code, but there are a number of third-party applications which are also being identified.

Sophos would like to reassure users that these are false positives and are not a malware outbreak, and apologises for any inconvenience.

False positive

If you have Live Protection enabled, you should stop seeing these detections as the files are now marked "clean" in the cloud. (Details of how to enable Live Protection can be found in this knowledgebase article).

If you do not have Live Protection enabled you will stop seeing the new detections once javab-jd.ide has been downloaded by your endpoint computers (released at Wed, 19 Sep 2012 21:32 +0000 UTC).

There is no cleanup for this detection, and you will see it quarantined unless you have your on-access policy set to move or delete detections if cleanup is not possible.

Please double check your SAV policy under cleanup; You want to ensure your secondary option (when cleanup is not available or does not work) to be set to ‘deny access’ and not delete or move. Once the detections have stopped, you can acknowledge the alerts in the Console, this way you can see who is still reporting it, and confirm it is trending down.

You should also check that any third-party applications that may have been erroneously detected as Shh/Updater-B are restored.

Further information:

Knowledge base article: http://www.sophos.com/en-us/support/knowledgebase/118311.aspx

The knowledge base article will be updated as appropriate. Please consider following our support team @SophosSupport on Twitter for updates, and if you have a support question use our online product support forum.

http://twitter.com/SophosSupport

http://twitter.com/NakedSecurity


View the original article here

Tuesday, September 18, 2012

Sophos Techknow - All about Java

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Welcome to another episode of Techknow, the podcast in which Sophos experts debate, explore and explain the often baffling world of computer security.

In this episode, entitled All about Java, Paul Ducklin and Chester Wisniewski dig into the what, the how, and most importantly the why, of the popular programming language that dominated security headlines in August 2012 for all the wrong reasons.

Java brings with it some significant risks, yet for many people, it's "just there on my computer." And the reason it's there is, "It's always been there. And you need it for lots of websites, don't you?"

Even in the business world, many organisations never quite seem to have got around to asking where, or even if, Java is needed on corporate assets such as laptops and servers.

In this quarter-hour podcast, Duck and Chet tell you All about Java (did you know it was originally named after a tree?), and help you to make an informed decision in balancing its risks and rewards.

Listen now:

(31 August 2012, duration 16'19", size 11MBytes)

Listen later:

Download Techknow podcast

Follow @duckblog
-

Tags: drive-by, drive-by download, Exploit, Java, JavaScript, Linux, Malware, oak, Oracle, osx, solaris, Sun, techknow, vulnerability


View the original article here

Friday, September 14, 2012

Sophos sucks? Being insulted by malware authors can be the best reward

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Sometimes things can get a little personal between those who write malware, and those whose job it is to protect against it.

Loser sign, blowing raspberries. Image from Shutterstock

Researchers, such as those who work at SophosLabs, may devote significant effort into probing a specific attack, kit or family of malware. Typically the knowledge they acquire is used in writing generic detections such that customers are protected from that threat.

And detection is the last thing the attacker wants. After all, detection means no profit.

So ensues the cat-and-mouse game between the attacker and the researchers, where polymorphism is the attacker's weapon of choice (used in order to evade detection).

Perhaps the most rewarding thing about working for a security company is to think about our efforts thwarting attacks. Sometimes, we see evidence of this in the attacker's behaviour - they may completely switch tactics, effectively accepting defeat in their battle against our protection.

Occasionally we annoy them to such an extent that they vent their anger within the malware itself!

For example, our generic detection on the landing page for a popular exploit kit annoyed the authors to such an extent that, earlier in the year, they temporarily renamed the filename of their landing page.

How charming.

Similar expressions of annoyance have been seen on some scareware (fake anti-virus) landing pages. Search engine optimisation (SEO) is being used to redirect users to these pages, where they are tricked into installing scareware.

The landing page mimics a system scan, using simple JavaScript to fake the file scanning progress. Historically, the filenames used have been embedded within the script as a simple array.

Then, presumably frustrated by our Mal/FakeAvJs-A detection, the attackers split the array up, using "interesting" variable names:

Sometimes, reversed :)

Sometimes, they like to hide the message a little :)

This week I noticed that they have now started to obfuscate that part of the script, using a common, commercial obfuscation tool:

Sigh. Mal/FakeAvJs-A remains.

Messages like this from attackers are encouraging. We should take them as a compliment. It is nice to know that we're having an impact disrupting their criminal business.

Follow @SophosLabs

Man making 'loser' sign, blowing raspberry image from Shutterstock.


View the original article here

Tuesday, August 14, 2012

Sophos Techknow - Understanding SSL

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Welcome to another episode of Techknow, the podcast in which Sophos experts debate, explore and explain the often baffling world of computer security.

In this episode, entitled Understanding SSL, Paul Ducklin and Chester Wisniewski look into the ecosystem of SSL (Secure Sockets Layer) and TLS (Transaction Layer Security).

SSL is often taken for granted.

To many of us, it's not much more than "the S in HTTPS", or "the padlock in the browser."

But how does it work? Are SSL and TLS the same? Who verifies SSL certificates? How do we know we can trust them? What happens if we realise we can't? What technological glitches do we need to know about?

Duck and Chet discuss all this, and more, in this quarter-hour podcast.

Listen now:

(03 August 2012, duration 16'10", size 11MBytes)

Listen later:

Download Techknow podcast

Follow @duckblog
-

Tags: CA, Certificate Authority, collision, DigiNotar, hash, MD5, Podcast, random, randomness, SSL, techknow, TLS


View the original article here

Tuesday, May 22, 2012

Free Sophos Anti-Virus app for your Android

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

A recent survey of 900 Naked Security readers found that 39% of you used a smartphone running Android.

To help you better safeguard your Android phone and tablet, Sophos just published Sophos Mobile Security for Android [BETA] in Google Play.

Sophos would love it if you could take a look and provide some feedback on it. Send your thoughts by email to the Sophos mobile security team.

So, what does this app actually do?

protects Android smartphones and tablets from malicious apps and other riskslocates a lost or stolen devicelocks a stolen devicescans the apps on your device and cross-check them with the latest security expertise from Sophos Labs.

Here are a few screenshots of the app in action.

Android screenshots

Android Mobile Security and EICAR test file

And even the recent fake anti-virus nasty, which attempts to send expensive SMS messages to premium-rate services is detected by Sophos Mobile Security BETA.

So, check it out, and email Sophos at mailto:SophosMobileSecurityBeta@sophos.com?Subject=Feedback%20Sophos%20Mobile%20Security%20for%20Android%20BETA and tell them what needs improving.

UPDATE: Some people have reported that Sophos Mobile Security cannot be uninstalled using the standard Application Manager.

To uninstall, users should open Loss and Theft module in Sophos Mobile Security and choose Deactivate the administration capability. On that screen there is a hint: "If you want to uninstall Sophos Mobile Security, you need to deactivate its device admin capability".

Once the administration capability is deactivated, Sophos Mobile Security can be uninstalled using the usual procedure for any other app.

(Background information: Activating administrative permissions for the application on your device is required for Loss and Theft functionality. The same device administration permissions need to be *de-activated* first through Sophos Mobile Security before uninstalling.

This is standard Android behaviour. Sophos has not changed the way programs should be uninstalled.)

http://twitter.com/caroletheriault

Android image courtesy of Shutterstock.


View the original article here

Monday, May 7, 2012

Facebook teams up with Sophos and other security vendors

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Facebook and SophosFacebook and security. Is it a marriage that has any legs?

The social networking giant today announced its partnership with a number of security vendors, including Sophos.

A Facebook blogger writes:

Nothing is more important to us than the safety of the people who use Facebook, and the security of their data...That’s why we’re thrilled to announce the Antivirus Marketplace and welcome Microsoft, McAfee, TrendMicro, Sophos, and Symantec to the Facebook Security family.

Facebook and Sophos

No matter how in love we are with Facebook, many of us would have kicked it to the curb if the bad outweighed the good, and some baddies started to dent Facebook's armour.

So Facebook came up with a great way to tackle the problem of widespread threats: jump between the sheets with the experts in the security industry.

Now Facebook and security aren't easy bedfellows. Facebook constantly needs to offer new bells and whistles to stay fresh and competitive. Its natural aim is increased sharing and connectivity.

Security specialists like Sophos offer protection, and they often do that by closing doors to anything potentially harmful. The security industry is essentially made up of internet sentinels keeping watch all the time and jumping out to protect their charges when something nasty rears up.

But they do say opposites attract...

So when Facebook came knocking, Sophos opened its doors wide. And smiled. Teamed up, they are much better able to catch and annihilate scams before they impact huge numbers of users.

This is how it works: Sophos's threat labs constantly collect and sort mountains of data on malicious and scammy links. Sharing this info with Facebook means that the social platform can get a heads up on scams before they become a problem for large numbers of users.

So, if Facebook gets wind of something dodgy spreading on its platform, they consult our vast database. And if it's found to be potentially malicious, they will alert the user.

But users also have a role to play if they want Facebook to remain the most popular hang out in town.

Think about it this way: even the sexiest of cars provide many safety features like brakes, airbags and seatbelts, but if we fail to take advantage of them and drive like dingbats, they're useless.

To better safeguard your account, make sure you choose a strong unique password for your Facebook account, and don't tell it to ANYONE. Look over the privacy settings regularly and carefully choose your configuration. Take care when downloading applications. Only befriend people you know. Report suspicious activity to Facebook.

And the Naked Security team will continue to do its part, alerting its community -- via its Facebook page and its award-winning security news site -- to bad stuff that sneaks up on Facebook.

Ultimately, both Facebook and Sophos want users safe and happy. And this partnership might mean that we are in a better place to achieve that aim, but only if we all do our part.

As an added bonus, Sophos is giving away its Sophos Anti-Virus for Mac: Home Edition – no strings attached. In fact, there are a number of free security tools you can check out.

So, here's to a fruitful relationship between Sophos and Facebook.

Follow @CaroleTheriault

View the original article here

Thursday, April 19, 2012

Free Virus Removal Tool for download from Sophos

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Filed Under: Featured, Malware

Sophos free Virus Removal ToolYou know that feeling when you're pretty sure your Windows machine *might* be infected, but your anti-virus finds nothing?

Or worse, your anti-virus does detect malware, but the instructions to disinfect and rid your system of the malware are so complicated that you want to pull out your hair?

Well, Sophos has just released its Virus Removal Tool. Designed to be child's play to use, it detects and, more importantly, disinfects all those nasty viruses, spyware, rootkits and even fake anti-virus with its flagship industrial-strength anti-virus.

Best of all it is free, and for Naked Security readers, there are no details to enter before you can download and use it.

Actually, really best of all, there is no need to remove existing anti-virus that is already installed.

virus-removal-tool-screenshot

For the past year or so, the Virus Removal Tool has been used by some of Sophos's biggest customers to disinfect complicated malware that sneaked onto a poorly protected computer, but this is the first time Sophos has released this tool to the public at large.

Sophos has also provided a free support forum called Sophos FreeTalk where you can ask any questions about this and other free Sophos products.

The majority of our readers are pretty security conscious, and we know from experience that many of you are probably the IT guy or gal called upon to help family and friends sort out their computers when things go awry. Sophos hopes that this tool will make your lives a little bit easier.

Sophos's free Virus Removal Tool

Lastly, Sophos would love to hear your thoughts on its Virus Removal Tool. It sees this as a tool worth investing in, but the company wants to make sure it gets your thoughts first so it can prioritise any improvements accordingly.

Follow @caroletheriault


View the original article here

Monday, October 24, 2011

The state of cyber security - Join Sophos and the NCSA in Washington DC

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Computer seeking medical helpI would like to invite all of our readers to an event October 27th, The State of Cyber Security, in Washington DC hosted by the National Cyber Security Alliance and Sophos.

I am proud to be speaking at the event along with Michael Kaiser, executive director of the National Cyber Security Alliance and Rob Strayer, director of the National Security Preparedness Group from the Bipartisan Policy Center.

At the event we will host a cocktail reception followed by a panel presenting the latest information on what threats we are facing and how the public and private sectors can work together to make the online world a safer place.

For those of you in the United States you may have heard that October is National Cyber Security Awareness Month (NCSAM).

NCSAM logo

The goal of NCSAM is to educate the public about the risks they face online and provide practical advice on how to stay safe online all year round.

The NCSA provide a website with videos, tips and information for consumers and small businesses called StaySafeOnline.org to help further this goal.

One of the primary themes this year is a campaign called "Stop, Think, Connect", which has helpful videos on topics from how to be a safe surfer, to how to be a safe gamer online.

Stop, Think, Connect logo

We hope you can join us next Thursday and help to get the word out to our friends, neighbors and co-workers about being safe online.

If you aren't able to attend you can follow the event on Twitter by searching for #NCSAM11.

Follow @chetwisniewski

View the original article here