Best Tips to Protect your Web Sites from Hackers and Malicious contents

Hack

The Web is scarier than most people realize, according to research published recently by Google.These Web-based attacks become much more common in recent years as firewalls and better security practices by Microsoft have made it harder for worms and viruses to directly attack computers. Nowadays about 1.3 percent of all Google search queries list malicious results somewhere on the first few pages.

Criminals are getting better at this kind of work. They have built very successful automated tools that poke and prod Web sites, looking for programming errors and then exploit these flaws to install the drive-by download software. Often this code opens an invisible iFrame page on the victim’s browser that redirects it to a malicious Web server. That server then tries to install code on the victim’s PC. “The bad guys are getting exceptionally good at automating those attacks,”

[ad#add-top-in]

Following are some tips to get rid of this hackers or hijackers activity.

Keep you password and username safe change it frequently only with strong password check your password with Microsoft

Keep your PC clean from viruses and spy-wares because there are chances to hijack your PC contents and login cookies etc. Scan your PC for viruses now with NOD32 Online Antivirus Scanner

Keep all folders and files permissions proper in your web hosting accounts/server. Never give full permission for the folders and files, that means read write and execute permission. If you are hosting sites in Linux platform never give 777 permission (read write and execute permission) to all members even for net users of file and folders. The preferred maximum permission is 755. This means write permission for root user and only read and execute permission for others.

There are many techniques used to hack/hijack the website

Cross Site Scripting (XSS)

SQL injection flaws

Site reconnaissance

Session hijacking

Application denial of service

Cookie/session tampering

To withstand from this you need “professionally well designed websites” and also powerful web sitefirewall at server end.

You need to choose good web hosting platform or company which provides good firewalls and Security. If you are going for Linux platform better to choose Grsecurity enabled kernel Servers; especially for shared hosting.

But not the least the best way to find the flow in website is by checking the web site stats all the day. By this you can find the links/URL which are not related to your website so that you can delete it before it spreads through search engines.

If some one reports your site having virus then its 99% sure your site home pages are having masked IFrames at the beginning or last lines of the page, which actually downloads virus file form some other server/site. You can fix it your self by editing your home page and removing the contents which looks like as shown bellow.

Iframe

These are some of the tips which really helps to protect yourself from Hackers and Malicious contents

Tips to Protect your PC from Malicious Sites Using McAfee Siteadvisor Plug-In

McafeeMcAfee SiteAdvisor, a plug-in for Internet Explorer and Firefox browsers, tests, analyzes and rates websites in detail for unsafe or annoying practices such as dangerous downloads, spamming, misuse of personal information and browser hijacking. This helps you sidestep possible identity theft or fraud traps. When searching with Google, Yahoo! or MSN, SiteAdvisor’s easy-to-understand safety ratings too

[ad#add-top-in]
1) Browser tool bar

As you browse Site, a small button on your browser toolbar changes color based on SiteAdvisor’s safety results.
Red (Danger) Mc Red

McAfee tests revealed some serious issues that you’ll want to carefully consider before using this site at all. (Example: The site sent lots of spam e-mail or bundled adware with a download).

Yellow (Caution) MC Yellow

McAfee tests revealed some issues you should know about. (Example: a site tried to change browser defaults, or sent a lot of non-spam e-mail)

Green (Safe) mc green

McAfee Tested the site and didn’t find any significant problems. (Secure sites.)

Gray (Not submitted site) Mc Gary

The site has not been tested, or is in the process of being tested also you have option to submit the site to test also.

You have a menu options on SiteAdvisor’s toolbar which let you customize SiteAdvisor or see a site’s detailed test results too.

2) Search Page

When you search with Google, Yahoo! or MSN, SiteAdvisor’s safety ratings appear next to search results. Ratings—Red indicates dagger that means this site reported virus downloads and also linked to malicious sites which already rated Red in Macfee database.

Search-res

You can also get more information about the site by keeping the mouse pointer on the alert symbol; it will show a popup in search window it self, which gives summary of the sites status.

Search Pop

3) Detailed Test Results

Also a detailed test results for every site are available by clicking on the more info link; in that you can see the external sites which are linked to this site as shown bellow.
Linked

So it will be very hand if you installed McAfee SiteAdviso in your PC while surfing the giant www network.

Download it here….

Install KDE 4 on Windows

KDE-win

The preferred way of installing KDE apps under windows is the KDE-Installer. Windows 2000, XP, 2003 and Vista are supported.

The installer is a small piece of software which pulls the required packages from the remote repository and installs them on your Windows machine. It also automatically downloads any packages which are required to satisfy any dependencies which makes it very user friendly. Detailed installation instructions as follows…

* Installer Download it here..
* Download and save the latest version to a directory, e.g. C:\KDE4
* Run the installer, download what you need [see Download needed packages below].
* Add a KDEDIRS environment variable [Start >> Control Panel >> System >> Advanced >> Environment Variables, click [New] User variable and create Variable name KDEDIRS with Variable value the directory where you installed KDE4, e.g. C:\KDE4].
* Add your lib directory and your bin directory to your Windows %PATH%. (Start >> Control Panel >> System >> Advanced >> Environment Variables, double-click the Path System Variable and add “%KDEDIRS%\lib;%KDEDIRS%\bin” to your path separated by semicolon.]
* If you don’t have Visual Studio 2005 installed, download and install the “Microsoft Visual C++ 2005 SP1 Redistributable Package (x86)” [1]
* Try running a Qt application in the bin directory, such as linguist.exe
* If that works, try running a KDE application such as kwrite.exe.

The download for me took a long time since the installer had to pull in over 400 MB of packages. But once all the necessary packages finished downloading, the installer then proceeded to install all the packages in the specified location.
[ad#add-top-in]
There are a number of applications already such as the KDE games, KWrite, Konqueror, Dolphin file manager and so on and all of them worked on my machine. I have to concede that other than the KDE games which played quite well, most other software is at the least, still buggy. Konqueror and KWrite guzzles up memory like there is no tomorrow. The Konsole (KDE terminal) has yet to be ported to Windows and so you cannot access the terminal from within Konqueror. Dolphin complains that it cannot find the home directory each time I open it in Windows. KWrite is a lot slow in opening up and so on.

Update:1 [02/15/2009]

Simple steps to uninstall Windows KDE from Windows XP or Vista……

New Updated version KDE 4.0.5 Released

KDE-4

The fifth maintenance version of KDE4 released, the KDE Community announced. KDE 4.0.5 brings you performance improvements, bug fixes and many updated software and translations for most of its components. KDE 4.0 is already translated into 49 languages and more are coming soon.

KDE 4.0.5 comes with several bugfixes and performance improvements. Most of them are recorded in the changelog. KDE continues to release updates for the 4.0 desktop on a monthly basis. KDE 4.1, which will bring large improvements to the KDE desktop and application will be released in July this year. A first Beta is already available for testing.
[ad#add-top-in]
KDE 4.0.5 stabilises the desktop further, users of previous KDE 4.0 versions are encouraged to update. Improvements revolve around lots of bugfixes and translation updates. Corrections have been made in such a way that results in only a minimal risk of regressions.

Installing KDE 4.0.5 Packages

Next Generation Notebooks with AMD Turion X2 Ultra Dual-Core

AMD

AMD announced its next-generation notebook platform, delivering the ultimate HD visual performance and increased energy efficiency. The platform features new AMD Turion X2 Ultra Dual-Core Mobile Processors with ATI Radeon HD 3000 Series Graphics for superior 3D performance and HD image quality, with industry-leading wireless for greater throughput and range. These new notebook designs come from leading OEMs including Acer, Asus, Clevo, Fujitsu, Fujitsu Siemens Computers, HP, MSI, NEC and Toshiba.

This next-generation AMD notebook platform also serves as the foundation for new AMD Business Class, AMD GAME and AMD LIVE notebook solutions.

The next-generation AMD notebook platform also incorporates the latest in wireless connectivity technologies like 802.11 draft n and 3G from leading Better by Design technology partners including Atheros, Broadcom, and Ralink. These technologies provide superior range, faster data transfer and allow users to stay connected on the go.

The next-generation AMD notebook platform also incorporates innovative power management technologies, including AMD Enhanced PowerNow!™ Technology and ATI PowerXpress™ Technology to maximize the efficient use of power for extended battery life.

AMD Turion X2 Ultra Dual-Core Mobile Processor and ATI Radeon HD graphics, are now available from OEM customers.

whach the video….

Intel with 4 new desktop chipsets & AMD with 3 new Quad Core AMD Opteron 1300 Series processors

[ad#add-top-in]
AMD today introduced three new Quad-Core AMD Opteron 1300 Series processors for one socket servers and workstations.

AMD

Global tier one OEMs including HP and Dell plan to incorporate the new processors into upcoming platforms, and global supercomputer leader Cray is now shipping Quad-Core AMD Opteron 1300 Series processor-based Cray XT4 systems and upgrading some of the world’s fastest supercomputers to incorporate Quad-Core AMD Opteron 1300 Series processors.

In the same time Intel has four new desktop chipsets to show off from this year’s Computex trade show in Taiwan. The G45 and the G43 focus on HD video playback by way of a new Intel Graphics Media Accelerator X4500HD integrated graphics chip. The P45 brings support for faster memory and is the first mainstream Intel-made chipset with two graphics card slots. A scaled-down P43 chipset rounds out the new 4 Series. All of the chipsets use Intel’s familiar LGA 775 processor interface, which means support for Intel’s Core 2 Duo and Core 2 Quad desktop CPUs. Intel has also added a 1,333MHz front side bus to each chipset, as well as support for DDR3 RAM, as well as DDR2 or DDR3 RAM at speeds up to 1,333MHz.

The new Quad-Core AMD Opteron Models 1352 (2.1GHz), 1354 (2.2GHz), and 1356 (2.3GHz) processors are designed to empower small to mid-market customers to meet growing IT and budgetary demands and increase business productivity. With the enhanced computing capabilities of AMD’s native quad-core architecture in the same socket and thermal requirements as previous AMD Opteron 1000 Series processors, Quad-Core AMD Opteron 1300 Series processors provide small and mid-size customers an energy-efficient yet powerful computing platform that can maximize IT resources and grow with their business demands.

Google had security issue with its GrandCentral.com telecom service and Google.com : Fixed

Google

Google has fixed security issue related to its Central telecom service and its Google.com Web site..

Google fixed a cross site scripting exposure on the log-in page for Grand Central, a service that allows people to have numerous phone numbers ring on one phone and have a unified voice mail.

A cross-site script is a vulnerability found increasingly in Web applications in which malicious code can be injected into Web pages that could be used to attack or compromise visitors to the site.

“This issue was reported on Monday morning, and google closed it shortly after being notified”.

The vulnerability was posted to a security e-mail list called Full Disclosure and was not reported to Google in advance, meaning Google had to race to fix the issue before someone could write an exploit for it.

[ad#add-top-in]

In a separate security issue, Google fixed a weakness that allowed people to create a spoof site that looks like it goes to the Google.com domain but actually redirects a Web surfer to a different site. Such redirect links are usually distributed via e-mail and often send people to a site with malicious code that can be used to attack or compromise the visitor’s computer.

Google, meanwhile, was working to fix a redirect vulnerability related to the site of its DoubleClick online advertising unit.

Adobe launched Acrobat 9 and online community Acrobat.com

Adob

Adobe Systems Inc. launched a new version of its document sharing software Acrobat 9 on Monday also online community Acrobat.com too.

The hosted services in Acrobat.com include:

– Adobe Buzzword®, a Web-based word processor that can be used to easily co-author and share documents for comment and review, creating high-quality print results;

– Adobe ConnectNow, a personal Web conferencing service that includes desktop sharing, video and voice conferencing and integrated chat;

– Centralized online file sharing with access controls, online PDF conversion for up to five documents, and support for high quality, Web-embeddable documents;

– Developer APIs for real-time collaboration, file sharing and conversion.

In addition, Acrobat.com gives Acrobat 9 users access to a “personal workspace in the clouds” that is available from virtually anywhere for working with others online. Acrobat 9 users can work with Acrobat.com as a central location for sharing forms and collecting forms data, conducting shared reviews, and co-navigating a PDF document with colleagues.
[ad#add-top-in]
Acrobat.com also works with Adobe Reader® 9 software, giving Adobe Reader 9 users easy access to Acrobat.com so they can share files, convert up to five documents to PDF online and participate in electronic forms and shared reviews initiated by Acrobat 9 users.

Acrobat.com is available immediately in English as public beta for free sign up.

Use new Adobe Acrobat 9 to:

– Share your ideas

Use Acrobat 9 to create polished PDF files, present multiple documents in a PDF Portfolio, and even add multimedia. And all in a single file.

– Control your work

Use Acrobat 9 to apply passwords, set permissions, and permanently remove sensitive information — so you can feel confident your work is safe.

– Work better with everyone

With Acrobat 9, your entire team can view and respond as comments are being made — streamlining your reviews and approvals.

– Simplify form creation

With just a few clicks, you can create a form that virtually anyone can fill out and save electronically.

Acrobat 9 Pro Extended, Acrobat 9 Pro and Acrobat 9 Standard for Microsoft Windows®, and Acrobat 9 Pro for Mac OS X, are expected to be available by July 2008 in English, French, German, and Japanese language versions.

Yahoo announced BrowserPlus while Google de-branded Gears!!

Yahoo

Yahoo announced software called BrowserPlus that has a similar philosophy. Expand what’s possible to make Web applications a better alternative to programs running natively on a personal computer. Right now, it’s available only in a “sneak peek” on some Yahoo-operated Web sites.

But a year after the Google launched its Gears project, Google appears to be trying to make it easier for competitors to embrace Gears. At its Google I/O conference here Wednesday, Google de-branded Gears today, taking its name off the project and announcing some new Web browser support in the works.

“BrowserPlus is a technology designed to extend the Web, so that developers can build more exciting Web applications and so end users can get more done inside their Web browsers,” Yahoo said on a BrowserPlus frequently-asked-questions page.

Different Web sites can use BrowserPlus to support things like drag and drop from the desktop, easier file uploads, more efficient and secure acquisition of feeds and information, and native desktop notifications.

BrowserPlus works on Mac OS X 10.4 and 10.5 machines and on Windows XP and Vista machines. Supported browsers are Internet Explorer 7 or later, Apple Safari 3 or later, and Firefox 2 or later.

New Google Earth API and Browser plug-in unveiled

Google API

Google has unveiled the New Google Earth API and browser plug-in, allowing web developers to embed Google Earth inside any web page with a few lines of code, while the JavaScript API can be used to to enable Earth-based web applications.

Users are interested in seeing the world’s information in a geographic context, which has lead to the rise of the Geoweb, a collection of user-generated content associated with a given location. The Google Maps API, with over 150,000 developer sites, and the Google Earth client, with over 400 million downloads, are both successful tools to help users visualize this Geoweb of content.
[ad#add-top-in]
View the thousands of existing 3D buildings, or add their own 3D models and also switch to Google Sky mode for high-res imagery of stars, planets, and galaxies. As the latest member of their Maps API family, the Google Earth API allows web developers to turn their web pages into 3D map applications. They can now use the Earth as their canvas, leveraging the same technologies used in the desktop Google Earth client.