Wednesday, October 24, 2012

Can you trust your Anti-Virus??

My belief has always been that the Anti-Virus makers are always a couple of steps behind and will always remain playing 'catch up'. The common users on Microsoft Windows platform are living under false assurances that once you have a patched up anti-virus, you are safe!! The saying in the Anti-Virus industry goes - Always run antivirus software and make sure the virus definitions are current.

Thats far from the truth and will show this briefly.

First, those using pirated copies of Windows OS and Windows MS-Office application suite - just know 'YOU ARE SITTING DUCKS' - and do not for a moment think that nothing is gonna happen!! Its just the 'ostrich-head-in-the-sand' attitude - until when the 'knock-out' punch arrives (though praying you do not face it!!) - in case you are using these pirated versions on the Internet for all you financial and personal (FB? Linkdin? Twitter? E-Mails? Banking?? Bill Pay? Online Purchase? etc..). DO GO AHEAD AND SPEND SOME $$$ ON GENUINE SOFTWARE - its worth the trouble! Or change over to the safe and secure Linux systems - Linux Mint or Ubuntu recommended - Go ahead and use it!! Assuring you, the Linux OS is now so user friendly that its setting it up can be done by a Primary class student!!

Coming to the main story - Every Software company keeps making 'security updates' to ensure any vulnerabilities that become known are patched up!! To patch up - you need to have genuine software (in Microsoft platform, you buy the software using precious $$$, in Linux - you download the OS and applications for free)

In the month of October 12, Microsoft released a major security patch to take care of some critica vulnerabilities. This can be assessed from the Microsoft Security Bulletin Site for Oct 12.

Among the Microsoft security alerts, the one that is very critical view the 'mango people' or aam-admi are effected is MS12-064. Visit the site to read more. The screen shot below shows it :-

To ensure you are protected from this exploit, you NEED to patch your MS-Office application suite. Other option - dump your pirated copy and start using the great office suite 'LibreOffice' available for free for Windows Platform from this site.

The reason for my this message is, lately I have been receiving targeted mails on my GMail accounts with attachments that seems too good to not open and see! Importantly, the mail subjects seems to a 'Targetted' attacks as they relate to some areas of my interest!!! Meaning, someone out there is sending mails knowing very well what type of documents/forwards (doc, PPT, XLS - MS-Office formats) one is interested in. And this comes from mail ids of known/trusted people (obviously their accounts has been hacked!!) Check out some of the 'interesting' mails I received last week. There has been some interesting PPTs and XLS files also falling into the same categories.

View my own interest and knowledge in security, and view using Linux + LibreOffice exclusively, I believe I am at very low risk - though I take necessary precautions of system scans nearly every other day! (when did you do your last system scan?? Did you leave it to your AV Software??)  Yess, I am a bit paranoid about my IT Security!!

The point I want to make, I had both the above document scanned using a number of reputed Anti-Virus software on fully patched up systems (facility available for free at Jotti Malware Scan site). The results were astounding and summarised as follows briefly:-
(A) The documents are using the latest Microsoft Vulnerabilities - namely the vulnerabilities that are being addressed in Microsoft Oct 12 bulletins - hoping that users are maybe using un-patched MS-Office (and they are right on target!!)
(B) More seriously - most of the so called reputed Anti-Virus Software failed to detect these malware. (Check out the 'Found Nothing' Remarks. This right away busts the myth that using a patched up anti-virus will protect the users.  I REST MY CASE 


Screen shots of the virus-scan on the documents received by mail attached below showing that many reputed Anti-virus software failed to detect that the documents contained malware!!   




Options for you:-
(A) Let go the assurances that if you have an updated Anti-Virus, you are safe!!
(B) Buy original software and ensure it is regularly patched/updated
(C) Move over to Linux (Linux Mint or Ubuntu or others) + LibreOffice in case you want rock solid performance and safe/secure software that remains patched automatically without you spending large $$$$$

BE SAFE in your Cyber Space!!!

No comments:

Post a Comment