<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Avira - TechBlog</title>
	<atom:link href="http://techblog.avira.com/feed/en/" rel="self" type="application/rss+xml" />
	<link>http://techblog.avira.com</link>
	<description></description>
	<lastBuildDate>Thu, 23 May 2013 13:47:15 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>How to enable two-factor authentication for Twitter</title>
		<link>http://techblog.avira.com/2013/05/23/how-to-enable-two-factor-authentication-for-twitter/en/</link>
		<comments>http://techblog.avira.com/2013/05/23/how-to-enable-two-factor-authentication-for-twitter/en/#comments</comments>
		<pubDate>Thu, 23 May 2013 13:41:14 +0000</pubDate>
		<dc:creator>Sorin Mustaca</dc:creator>
				<category><![CDATA[Improve your security]]></category>
		<category><![CDATA[Security News]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[two factor authentication]]></category>
		<category><![CDATA[two-factor]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=5110</guid>
		<description><![CDATA[Not a week passes without seeing in the press that some Twitter account have been hacked (as in used without authorization). Twitter tried to create more awareness about creating secure passwords and educating the users to not fall for the &#8230; <a href="http://techblog.avira.com/2013/05/23/how-to-enable-two-factor-authentication-for-twitter/en/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Not a week passes without seeing in the press that some Twitter account have been hacked (as in used without authorization).</p>
<p>Twitter tried to create more awareness about creating secure passwords and educating the users to not fall for the classical social engineering techniques. But, with over 200 million users, it is close to impossible to educate everybody.</p>
<p>This is why Twitter started a few weeks ago to rollout two-factor authentication.</p>
<p>Unfortunately, at the moment of writing this article, this feature is not yet available in Germany, so I can&#8217;t test it myself.</p>
<p>However, here are the easy steps to enable <a href="https://blog.twitter.com/2013/getting-started-login-verification" target="_blank">two-factor authentication for Twitter</a>:</p>
<p>- Visit your <a href="https://twitter.com/account/settings">account settings</a> page.</p>
<p>- Select “Require a verification code when I sign in.”</p>
<p><a href="http://techblog.avira.com/wp-content/uploads/2013/05/twitter-sec-settings.png"><img alt="twitter-sec-settings" src="http://techblog.avira.com/wp-content/uploads/2013/05/twitter-sec-settings-300x114.png" width="300" height="114" /></a></p>
<p>If your country is not supported, you will not be able to enable that checkbox.<br />
- Click on the link to “add a phone” and follow the prompts that allows you to select your carrier.</p>
<p><a href="http://techblog.avira.com/wp-content/uploads/2013/05/twitter-2factor-sms.png"><img alt="twitter-2factor-sms" src="http://techblog.avira.com/wp-content/uploads/2013/05/twitter-2factor-sms-300x243.png" width="300" height="243" /></a></p>
<p>&nbsp;</p>
<p>For Germany, all major carriers are listed, but unfortunately none of them is supported.</p>
<p><a href="http://techblog.avira.com/wp-content/uploads/2013/05/twitter-auth.png"><img alt="twitter-auth" src="http://techblog.avira.com/wp-content/uploads/2013/05/twitter-auth-300x170.png" width="300" height="170" /></a><br />
- After you enroll in login verification, you’ll be asked to enter the six-digit code that was sent to your phone via SMS each time you sign in to twitter.com.</p>
<p>Here is a <a href="http://youtu.be/IsdvJI0AK5M" target="_blank">film</a> which explains visually how to enable it.</p>
<p>What is not clear yet is if there is a possibility to mark a computer as trusted so that you don&#8217;t have to enter the authentication code every time you login on the same computer. Currently, it seems that it is wanted to enter the authentication code for each login even on the same computer.</p>
<p><a href="https://support.twitter.com/articles/76036-keeping-your-account-secure">Here</a> are some other tips from Twitter about how to protect your account better. Do note that all these tips can be applied to other accounts as well, not only to Twitter.</p>
<p>Check here the entire <a href="http://techblog.avira.com/2013/02/17/improve-your-security-11-enable-two-factor-authentication/en/" target="_blank">series for enabling two-factor authentication</a>.</p>
<p>If you want to improve your overall security, check our <a href="http://techblog.avira.com/2011/11/12/improve-your-security-series/en/" target="_blank">Improve Your Security</a> series.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Sorin Mustaca</p>
<p><a href="http://www.sorinmustaca.com" target="_blank">IT Security Expert</a></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2013/05/23/how-to-enable-two-factor-authentication-for-twitter/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Emails containing fake invoices from Zalando and Deutsche Bahn distribute malware</title>
		<link>http://techblog.avira.com/2013/05/16/emails-containing-fake-invoices-from-zalando-and-deutsche-bahn-distribute-malware/en/</link>
		<comments>http://techblog.avira.com/2013/05/16/emails-containing-fake-invoices-from-zalando-and-deutsche-bahn-distribute-malware/en/#comments</comments>
		<pubDate>Thu, 16 May 2013 08:43:48 +0000</pubDate>
		<dc:creator>Sorin Mustaca</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[db.de]]></category>
		<category><![CDATA[deutsche bahn]]></category>
		<category><![CDATA[invoice]]></category>
		<category><![CDATA[mahnung]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[zalando]]></category>
		<category><![CDATA[zalando.de]]></category>
		<category><![CDATA[zip]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=5098</guid>
		<description><![CDATA[We wrote before about the smart methods of fooling users to do things (execute files) which they would not normally do. Two weeks ago we&#8217;ve seen a mass mailing in the German language containing malicious payload pretending to be invoices &#8230; <a href="http://techblog.avira.com/2013/05/16/emails-containing-fake-invoices-from-zalando-and-deutsche-bahn-distribute-malware/en/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>We <a href="http://techblog.avira.com/2013/04/30/emails-containing-fake-invoices-from-apple-and-plus-de-distribute-malware/en/" target="_blank">wrote before</a> about the smart methods of fooling users to do things (execute files) which they would not normally do. Two weeks ago we&#8217;ve seen a mass mailing in the German language containing malicious payload pretending to be invoices from Apple and Plus.de.</p>
<p>Cybercriminals are sending again personalized emails in the German language pretending to come from the well-known website Zalando.de (shoes and women accessories) and from the Deutsche Bahn (German Railways).</p>
<p><a href="http://techblog.avira.com/wp-content/uploads/2013/05/zalando.png"><img class="alignnone size-medium wp-image-5099" alt="zalando" src="http://techblog.avira.com/wp-content/uploads/2013/05/zalando-300x202.png" width="300" height="202" /></a>   <a href="http://techblog.avira.com/wp-content/uploads/2013/05/Bahn-Malware.png"><img class="alignnone size-medium wp-image-5104" alt="Bahn Malware" src="http://techblog.avira.com/wp-content/uploads/2013/05/Bahn-Malware-206x300.png" width="206" height="300" /></a></p>
<p>Same as before, the text is addressed to the recipient of the email directly and it threatens him so that the user opens the ZIP archive and executes the malicious file.</p>
<p>All payloads are detected by Avira software as TR/Jorik.Androm.pqr and HIDDENEXT/Worm.Gen.</p>
<p>&nbsp;</p>
<p style="text-align: right;">Sorin Mustaca</p>
<p style="text-align: right;"><a href="http://www.sorinmustaca.com" target="_blank">IT Security Expert</a></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2013/05/16/emails-containing-fake-invoices-from-zalando-and-deutsche-bahn-distribute-malware/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Avira Server Security is Windows Server 2012 certified</title>
		<link>http://techblog.avira.com/2013/05/16/avira-server-security-is-windows-server-2012-certified/en/</link>
		<comments>http://techblog.avira.com/2013/05/16/avira-server-security-is-windows-server-2012-certified/en/#comments</comments>
		<pubDate>Thu, 16 May 2013 07:31:07 +0000</pubDate>
		<dc:creator>Sorin Mustaca</dc:creator>
				<category><![CDATA[Avira Software]]></category>
		<category><![CDATA[Awards]]></category>
		<category><![CDATA[certified]]></category>
		<category><![CDATA[server security]]></category>
		<category><![CDATA[win8]]></category>
		<category><![CDATA[windows server 2012]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=5101</guid>
		<description><![CDATA[Following the certification of Avira Free Antivirus and Avira Premium Security, we are happy to announce you that the Avira Server Security obtained the certification for Windows Server 2012. &#160; You can download and test the product from here. &#160; Sorin &#8230; <a href="http://techblog.avira.com/2013/05/16/avira-server-security-is-windows-server-2012-certified/en/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Following the certification of <a href="http://techblog.avira.com/2013/04/03/avira-free-antivirus-is-windows-8-certified/en/" target="_blank">Avira Free Antivirus</a> and <a href="http://techblog.avira.com/2013/05/07/avira-premium-antivirus-is-windows-8-certified/en/" target="_blank">Avira Premium Security</a>, we are happy to announce you that the <a href="http://www.avira.com/en/for-business-avira-server-security" target="_blank">Avira Server Security</a> obtained the certification for Windows Server 2012.</p>
<p><a href="http://techblog.avira.com/wp-content/uploads/2013/05/EN_WS12_Cert_Blu286_2_rgb.png"><img class="alignnone size-medium wp-image-5102" alt="EN_WS12_Cert_Blu286_2_rgb" src="http://techblog.avira.com/wp-content/uploads/2013/05/EN_WS12_Cert_Blu286_2_rgb-256x300.png" width="256" height="300" /></a></p>
<p>&nbsp;</p>
<p>You can download and test the product from <a href="http://www.avira.com/en/download/product/avira-server-security" target="_blank">here</a>.</p>
<p>&nbsp;</p>
<p style="text-align: right;">Sorin Mustaca</p>
<p style="text-align: right;">Product Manager</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2013/05/16/avira-server-security-is-windows-server-2012-certified/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Be aware of fake Facebook extensions</title>
		<link>http://techblog.avira.com/2013/05/14/be-aware-of-fake-facebook-extensions/en/</link>
		<comments>http://techblog.avira.com/2013/05/14/be-aware-of-fake-facebook-extensions/en/#comments</comments>
		<pubDate>Tue, 14 May 2013 08:30:21 +0000</pubDate>
		<dc:creator>Sorin Mustaca</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[extensions]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[hijacking]]></category>
		<category><![CDATA[logged in]]></category>
		<category><![CDATA[login]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=5080</guid>
		<description><![CDATA[We have received from our partners in the AV industry reports about malicious browser extensions trying to hijack Facebook profiles. According to Microsoft, this threat was first discovered in Brazil but because of the social engineering techniques it uses, it &#8230; <a href="http://techblog.avira.com/2013/05/14/be-aware-of-fake-facebook-extensions/en/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>We have received from our partners in the AV industry reports about malicious browser extensions trying to hijack Facebook profiles. According to <a href="http://blogs.technet.com/b/mmpc/archive/2013/05/10/browser-extension-hijacks-facebook-profiles.aspx" target="_blank">Microsoft</a>, this threat was first discovered in Brazil but because of the social engineering techniques it uses, it spread fast in other countries and languages as well.</p>
<p>All Avira products detect it as TR/Febipos.B.2.</p>
<p>The malware is a malicious browser extension specifically targeting Chrome and Mozilla Firefox.</p>
<p>This trojan monitors a user to see if they are currently logged-in to Facebook. Once logged in, the malware can do all kind of actions on behalf of the user:</p>
<ul>
<li>like a page</li>
<li>share posts</li>
<li>invite friends</li>
<li>chat with friends</li>
<li>comment on a post</li>
</ul>
<p><span style="font-size: medium;"><span style="line-height: 24px;">You can find more information about this trojan on <a href="http://blogs.technet.com/b/mmpc/archive/2013/05/10/browser-extension-hijacks-facebook-profiles.aspx" target="_blank">this page</a> (Microsoft).</span></span></p>
<p>This trojan is another proof that staying logged on social media websites is not always a good idea. Browsers store the user name and password for you, but you should not enable to remain logged in. So, please don&#8217;t enable &#8220;Keep me logged in&#8221;. It would only cost you one click more to login after the browser saved the login details.</p>
<p><a href="http://techblog.avira.com/wp-content/uploads/2013/05/facebook-logout.png"><img class="alignnone size-medium wp-image-5081" alt="facebook-logout" src="http://techblog.avira.com/wp-content/uploads/2013/05/facebook-logout-300x20.png" width="300" height="20" /></a></p>
<p>Also pay attention to what extension you are installing in your browser. Always make sure that the extension comes from a known publisher and that it has a good reputation.</p>
<p>&nbsp;</p>
<p style="text-align: right;">Sorin Mustaca</p>
<p style="text-align: right;"><a href="http://www.sorinmustaca.com" target="_blank">IT Security Expert</a></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2013/05/14/be-aware-of-fake-facebook-extensions/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A new ransomware trojan variant with children pornography</title>
		<link>http://techblog.avira.com/2013/05/13/a-new-ransomware-trojan-variant-with-children-pornography/en/</link>
		<comments>http://techblog.avira.com/2013/05/13/a-new-ransomware-trojan-variant-with-children-pornography/en/#comments</comments>
		<pubDate>Mon, 13 May 2013 13:33:58 +0000</pubDate>
		<dc:creator>Sorin Mustaca</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[BKA]]></category>
		<category><![CDATA[BKA TRojaner]]></category>
		<category><![CDATA[children pornography]]></category>
		<category><![CDATA[Ransomware]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=5068</guid>
		<description><![CDATA[We wrote about the ransomware trojan (aka BKA Trojan) and its new methods of blackmailing people to pay: claim in the name of an official institution that the user did something illegal, like storing children pornography pictures on his computer. The new &#8230; <a href="http://techblog.avira.com/2013/05/13/a-new-ransomware-trojan-variant-with-children-pornography/en/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>We wrote <a href="http://techblog.avira.com/2013/01/31/the-bkaransom-trojan-comes-now-with-child-pornography/en/" target="_blank">about the ransomware trojan</a> (aka <a href="http://www.bka.de/EN/Home/homepage__node.html?__nnn=true" target="_blank">BKA</a> Trojan) and its new methods of blackmailing people to pay: claim in the name of an official institution that the user did something illegal, like storing children pornography pictures on his computer.</p>
<p>The new variant of the BKA trojan attempts to blackmail the owners of infected computers with four pornographic pictures of children (last <a href="http://techblog.avira.com/2013/01/31/the-bkaransom-trojan-comes-now-with-child-pornography/en/" target="_blank">version</a> had only one picture). It pretends to come from the press office of the <a href="http://www.bka.de/EN/Home/homepage__node.html?__nnn=true" target="_blank">BKA</a>.</p>
<p><img class="alignnone size-medium wp-image-5070" style="font-size: 12px; line-height: 18px;" alt="Revoyem_DE_2013-05" src="http://techblog.avira.com/wp-content/uploads/2013/05/Revoyem_DE_2013-05-97x300.png" width="97" height="300" />                            <img class="alignnone size-medium wp-image-5069" style="font-size: 12px; line-height: 18px;" alt="Revoyem_DE_2013-04" src="http://techblog.avira.com/wp-content/uploads/2013/05/Revoyem_DE_2013-04-145x300.png" width="145" height="300" /></p>
<p>But, if the last version only was mentioning that the user is in possession of pornographic materials with children, the difference this time is that the trojan actually copies pictures on user&#8217;s computer. To be even more credible, the trojan has names and birth dates of the children in the pictures (to prove that they are minors).</p>
<p>Same as the other variants known, the malware locks the user’s computer and asks 100€ (135 USD) to be paid via UKash or paysafe. Failing to do this has the consequence that all data on the computer will be destroyed and the user (identified with IP address and user agent string of the browser) will be condemned and punished. The cybercriminals are constantly trying new texts in order to look as convincing as possible.</p>
<p>The malware is distributed via drive by downloads as an executable file with temporary names.</p>
<p>Various media reported that this new version has also a better support for the webcam, so if the computer&#8217;s webcam is supported, the user can see himself in the small picture in the screen. Unfortunately, our VLAB could not test this scenario at this time. This social engineering technique creates an acute sense of emergency because it transfers the message that the <a href="http://www.bka.de/EN/Home/homepage__node.html?__nnn=true" target="_blank">BKA</a> is &#8220;watching&#8221; the user.</p>
<p>&nbsp;</p>
<p>Starting with the engine version 8.2.10.246 all Avira products detect the malicious files of the trojan with a generic detection as TR/Crypt.ULPM.Gen. Also the pictures that are dropped on user&#8217;s computer will be deleted. Please note that the full repair functionality is only available in the Windows products and not in the Rescue System and the command line scanner.</p>
<p>We strongly advise the user to never pay the ransom. Use the <a href="http://www.avira.com/en/download/product/avira-antivir-rescue-system" target="_blank">Rescue CD</a> to clean up the malware from your computer or <a href="http://market.avira.com/en/experts-search?utm_source=techblog&amp;utm_medium=article1305&amp;utm_campaign=techblog_post" target="_blank">ask an expert</a> to help you.</p>
<p style="text-align: right;">Sorin Mustaca</p>
<p style="text-align: right;"><a href="http://www.sorinmustaca.com" target="_blank">IT Security Expert</a></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2013/05/13/a-new-ransomware-trojan-variant-with-children-pornography/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to protect your social media account</title>
		<link>http://techblog.avira.com/2013/05/10/how-to-protect-your-social-media-account/en/</link>
		<comments>http://techblog.avira.com/2013/05/10/how-to-protect-your-social-media-account/en/#comments</comments>
		<pubDate>Fri, 10 May 2013 10:18:44 +0000</pubDate>
		<dc:creator>Sorin Mustaca</dc:creator>
				<category><![CDATA[Improve your security]]></category>
		<category><![CDATA[Security News]]></category>
		<category><![CDATA[Improve your Security]]></category>
		<category><![CDATA[Password]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[tips]]></category>
		<category><![CDATA[two factor authentication]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=5061</guid>
		<description><![CDATA[You&#8217;ve heard in the press that many celebrities and companies got their social media accounts hacked. Twitter even issued an official warning to all press agencies to protect their accounts better. Here are useful tips how to easily protect your &#8230; <a href="http://techblog.avira.com/2013/05/10/how-to-protect-your-social-media-account/en/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>You&#8217;ve heard in the press that many celebrities and companies got their social media accounts hacked. <a href="http://www.bbc.co.uk/news/technology-22351987" target="_blank">Twitter even issued an official warning </a>to all press agencies to protect their accounts better.</p>
<p>Here are useful tips how to easily protect your account:</p>
<p>&nbsp;</p>
<p>1. Protect your social media account with a strong password.</p>
<p><a href="http://techblog.avira.com/2012/06/08/improve-your-security-9-create-good-passwords/en/" target="_blank">Here are some good tips how to create a good password</a>.</p>
<p>&nbsp;</p>
<p>2. Enable two-factor authentication whenever possible.</p>
<p>The two-factor authentication assumes that the user is who he is (authentication via user/password) and in the same time that he has something that only he can have (phone, code, biometric data, etc.)</p>
<p><a href="http://techblog.avira.com/2013/02/17/improve-your-security-11-enable-two-factor-authentication/en/" target="_blank">Here is how you can do this</a> for the most common social media portals and not only.</p>
<p>&nbsp;</p>
<p>3. Password protect your mobile device.</p>
<p>Many users access their social media accounts from mobile devices. But, mobile devices, due to their nature are being taken everywhere and sometimes get lost or stolen.</p>
<p>Make sure you password protect your mobile device and even encrypt it if it is possible.</p>
<p><a href="http://techblog.avira.com/2011/12/22/improve-your-security-7-password-protect-your-smartphone/en/" target="_blank">Here are some tips how to do this</a>.</p>
<p>&nbsp;</p>
<p>4. Don&#8217;t use the same account for all activity you make.</p>
<p>Try to create a computer account for each user and if you work with sensitive data, even for each activity. Don&#8217;t forget that browsers and not only save confidential infos in cookies and databases. These infos are specific for each user. By creating an account for each user, you make sure that these data doesn&#8217;t reach the wrong user.</p>
<p><a href="http://techblog.avira.com/2011/05/19/improve-your-security-5-use-dedicated-accounts-for-each-user/en/" target="_blank">Here are some tips how to do this</a>.</p>
<p>&nbsp;</p>
<p>5. Keep your computer clean.</p>
<p>Make sure that your computer is not infected with a keylogger when you work with social media. A keylogger will copy all your input and send it to cybercriminals.</p>
<p>Always Use an <a href="http://www.avira.com/en/for-home" target="_blank">antivirus software</a>.</p>
<p>&nbsp;</p>
<p>6. Protect your computer so that only authorized users can access it.</p>
<p>Even if the computer is not infected, there might be others who have access to it. All websites allow the users to save their login information so that they can access the site faster next time. This has as consequence that if someone opens the browser and types the address of the social media website, they will land in your account.</p>
<p><a href="http://techblog.avira.com/2011/02/08/improve-your-security-2-securing-your-notebook/en/" target="_blank">Here are tips how to protect your computer easily.</a></p>
<p>&nbsp;</p>
<p>7. Change your password often</p>
<p>No matter how secure your password is, it is necessary to change it regularly. Many portals get hacked and attackers might get their hands on your password, even if it is a good one.</p>
<p>&nbsp;</p>
<p>8. Don&#8217;t use the same password on multiple accounts.</p>
<p>If one account gets hacked, then it is a matter of time until the attackers obtain, based on your email address, your other accounts.</p>
<p>&nbsp;</p>
<p>9. Use a different email address and user name for each social media account.</p>
<p>By doing this you make sure that an attacker has a hard time to obtain your other social media accounts.</p>
<p>&nbsp;</p>
<p>10. Restrict user permissions</p>
<p>On Facebook for example, you can have normal users and administrators for a page.</p>
<p>By allowing too many administrators, you have many attack targets. Also, it is harder to control and protect so many accounts.</p>
<p>&nbsp;</p>
<p style="text-align: right;">Sorin Mustaca</p>
<p style="text-align: right;"><a href="http://www.sorinmustaca.com" target="_blank">IT Security Expert</a></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2013/05/10/how-to-protect-your-social-media-account/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Avira Premium Antivirus is Windows 8 certified</title>
		<link>http://techblog.avira.com/2013/05/07/avira-premium-antivirus-is-windows-8-certified/en/</link>
		<comments>http://techblog.avira.com/2013/05/07/avira-premium-antivirus-is-windows-8-certified/en/#comments</comments>
		<pubDate>Tue, 07 May 2013 11:32:18 +0000</pubDate>
		<dc:creator>Sorin Mustaca</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[premium]]></category>
		<category><![CDATA[win8]]></category>
		<category><![CDATA[windows 8 certified]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=5037</guid>
		<description><![CDATA[As previously announced, we continue to improve the compatibility with Windows 8 of our products. After the Free Antivirus certification, we are happy to inform you that Avira Antivirus Premium is the next Avira product which is Windows 8 certified. &#160; The certification of &#8230; <a href="http://techblog.avira.com/2013/05/07/avira-premium-antivirus-is-windows-8-certified/en/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>As previously <a href="http://techblog.avira.com/2012/12/11/a-further-step-into-achieving-windows-8-compatibility/en/" target="_blank">announced</a>, we continue to improve the compatibility with Windows 8 of our products.</p>
<p><a href="http://techblog.avira.com/wp-content/uploads/2013/04/Win8_Blu286_M_rgb.png"><img alt="Win8_Blu286_M_rgb" src="http://techblog.avira.com/wp-content/uploads/2013/04/Win8_Blu286_M_rgb-300x100.png" width="300" height="100" /></a></p>
<p>After the <a href="http://techblog.avira.com/2013/04/03/avira-free-antivirus-is-windows-8-certified/en/" target="_blank">Free Antivirus certification</a>, we are happy to inform you that <a href=" http://www.avira.com/en/for-home-avira-antivirus-premium" target="_blank">Avira Antivirus Premium</a> is the next Avira product which is Windows 8 certified.</p>
<p><a href="http://techblog.avira.com/wp-content/uploads/2013/05/premium-win8.png"><img class="alignnone size-medium wp-image-5038" alt="premium-win8" src="http://techblog.avira.com/wp-content/uploads/2013/05/premium-win8-300x229.png" width="300" height="229" /></a></p>
<p>&nbsp;</p>
<p>The certification of the other products will follow in the next weeks.</p>
<p>But don’t worry, all other products for <a href="http://www.avira.com/en/for-home" target="_blank">Home</a> and <a href="http://www.avira.com/en/for-business" target="_blank">Business</a> work on Windows 8 very well, they are just not yet certified by Microsoft.</p>
<p style="text-align: right;">
<p style="text-align: right;">Sorin Mustaca</p>
<p style="text-align: right;">Product Manager</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2013/05/07/avira-premium-antivirus-is-windows-8-certified/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Planned cyberattack attack against the USA infrastructure (Updated)</title>
		<link>http://techblog.avira.com/2013/05/06/planned-cyberattack-attack-against-the-usa-infrastructure/en/</link>
		<comments>http://techblog.avira.com/2013/05/06/planned-cyberattack-attack-against-the-usa-infrastructure/en/#comments</comments>
		<pubDate>Mon, 06 May 2013 21:52:50 +0000</pubDate>
		<dc:creator>Sorin Mustaca</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[anonymous]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[N4m3le55 Cr3w]]></category>
		<category><![CDATA[opisrael]]></category>
		<category><![CDATA[opusa]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=5028</guid>
		<description><![CDATA[After the #OpIsrael against Israel cyberspace, anonymous hackers called themselves &#8220;N4m3le55 Cr3w&#8221; announced that they have scheduled another cyber attack on USA based websites and servers on 07/05/2013. In the above mentioned text it is also explain what the reason for the attack is: &#8220;war crimes &#8230; <a href="http://techblog.avira.com/2013/05/06/planned-cyberattack-attack-against-the-usa-infrastructure/en/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>After the <a href="http://crypt0nymous.tumblr.com/post/47270432228/list-of-confirmed-affected-websites-during-opisrael" target="_blank">#OpIsrael against Israel</a> cyberspace, anonymous hackers called themselves &#8220;N4m3le55 Cr3w&#8221; announced that they have <a href="http://pastebin.com/TyvAK20F" target="_blank">scheduled</a> another cyber attack on USA based websites and servers on 07/05/2013. In the <a href="http://pastebin.com/TyvAK20F" target="_blank">above mentioned text</a> it is also explain what the reason for the attack is: &#8220;<i>war crimes in Iraq, Afghanistan and Pakistan</i>&#8220;.</p>
<p><a href="http://techblog.avira.com/wp-content/uploads/2013/05/announcement.png"><img class="alignnone size-medium wp-image-5030" alt="announcement" src="http://techblog.avira.com/wp-content/uploads/2013/05/announcement-300x193.png" width="300" height="193" /></a></p>
<p>Also noteworthy is that the activists also explain which means they will use to attack the USA infrastructure:</p>
<blockquote><p>We will now wipe you off the cyber map. Do not take this as a warning. You can not stop the internet hate machine from doxes, DNS attacks, defaces, redirects, ddos attacks, database leaks, and admin take overs.<b><i><br />
</i></b></p></blockquote>
<p>I also find extremely interesting their advice to the American people:</p>
<blockquote><p>And to the American people we suggest switching your bank accounts from a big bank to a local union.</p></blockquote>
<p>Can it be that these guys don&#8217;t understand that we live in an interconnected world and that if they bring down the headquarter of a big bank, then the entire system collapses?</p>
<p>The author of the article has also written which tools they will be using to attack the USA cyber infrastructure.</p>
<p><a href="http://techblog.avira.com/wp-content/uploads/2013/05/tools.png"><img class="alignnone size-medium wp-image-5031" alt="tools" src="http://techblog.avira.com/wp-content/uploads/2013/05/tools-170x300.png" width="170" height="300" /></a></p>
<p>&nbsp;</p>
<p>The group <a href="http://pastebin.com/LXHKjsfg" target="_blank">has posted also a list of targets</a> which will be hit by this attack. In the list are a lot of .gov and .mil websites and also well-known names of financial institutions.</p>
<p>No matter what this group will do or try to do, we do not think that the impact on the infrastructure will be so massive as they say. Maybe some websites will be defaced, the entire network segment in USA will be slowed down for a while, but it is very unlikely that someone will be actually harmed.</p>
<p>Nevertheless, we advise all readers to be aware of the fact that there will probably be a lot of opportunist criminals that will raise phishing websites which probably will respond faster than the original websites.</p>
<p>&nbsp;</p>
<p>Update 17:40 CET+1:</p>
<p>Top 10 websites mentioned <a href="http://pastebin.com/LXHKjsfg" target="_blank">here</a> are alive and running smoothly. Can it be that the cyber-criminals are waiting for the start of the USA business day? Or is it that they are just not successful?</p>
<p>&nbsp;</p>
<p style="text-align: right;">Sorin Mustaca</p>
<p style="text-align: right;"><a href="http://www.sorinmustaca.com" target="_blank">IT Security Expert</a></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2013/05/06/planned-cyberattack-attack-against-the-usa-infrastructure/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New movies, same old malware tricks</title>
		<link>http://techblog.avira.com/2013/05/06/new-movies-same-old-malware-tricks/en/</link>
		<comments>http://techblog.avira.com/2013/05/06/new-movies-same-old-malware-tricks/en/#comments</comments>
		<pubDate>Mon, 06 May 2013 12:24:08 +0000</pubDate>
		<dc:creator>Sorin Mustaca</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[codecs]]></category>
		<category><![CDATA[fake]]></category>
		<category><![CDATA[into darkness]]></category>
		<category><![CDATA[iron man 3]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[players]]></category>
		<category><![CDATA[programs]]></category>
		<category><![CDATA[start treck]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=5017</guid>
		<description><![CDATA[&#160; You probably don&#8217;t live on this planet if you haven&#8217;t seen at least the trailers from these two movies. And, from curiosity, there is only one step to social engineering for the masses. Iron Man 3 and Star Trek &#8230; <a href="http://techblog.avira.com/2013/05/06/new-movies-same-old-malware-tricks/en/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>&nbsp;</p>
<p>You probably don&#8217;t live on this planet if you haven&#8217;t seen at least the trailers from these two movies. And, from curiosity, there is only one step to social engineering for the masses.</p>
<p><a href="http://www.imdb.com/title/tt1300854/" target="_blank">Iron Man 3</a> and<a href="http://www.imdb.com/title/tt1408101/" target="_blank"> Star Trek &#8211; Into Darkness</a> are the titles that make the news these days.</p>
<p><a href="http://techblog.avira.com/wp-content/uploads/2013/05/ironman3.png"><img class="alignnone  wp-image-5018" alt="ironman3" src="http://techblog.avira.com/wp-content/uploads/2013/05/ironman3-248x300.png" width="149" height="180" />    <a href="http://techblog.avira.com/wp-content/uploads/2013/05/startrek.png"><img class="alignnone  wp-image-5019" alt="startrek" src="http://techblog.avira.com/wp-content/uploads/2013/05/startrek-258x300.png" width="155" height="180" /></a></a></p>
<p>It didn&#8217;t take long until various criminal groups started to exploit the news and published so called &#8220;online&#8221; versions of the movies. This means nothing else that online streaming.</p>
<p>We leave aside the legal implications which streaming a movie for free has, as it is not the topic of this article.</p>
<p>If you run a search on Google for &#8220;watch iron man 3 online&#8221;, you find about 380 mil (yes, million) results. Many of these pages will drive you to a website that most of the time offers the movie  some but only through some special codecs or versions of known codecs.</p>
<p><a href="http://techblog.avira.com/wp-content/uploads/2013/05/flash1.png"><img class="alignnone size-medium wp-image-5021" alt="flash" src="http://techblog.avira.com/wp-content/uploads/2013/05/flash1-300x189.png" width="300" height="189" /></a></p>
<p>&nbsp;</p>
<p><a href="http://techblog.avira.com/wp-content/uploads/2013/05/player.png"><img class="alignnone size-medium wp-image-5022" alt="player" src="http://techblog.avira.com/wp-content/uploads/2013/05/player-167x300.png" width="167" height="300" /><a href="http://techblog.avira.com/wp-content/uploads/2013/05/codec.png"><img class="alignnone size-medium wp-image-5025" alt="codec" src="http://techblog.avira.com/wp-content/uploads/2013/05/codec-300x179.png" width="300" height="179" /></a></a></p>
<p>There is nothing for free. Even if you don&#8217;t pay money, you pay by other means.</p>
<p>Once you download and install these programs, codecs, updates or whatever the pages require, you open the virtual door of your computer to malware. The so called player will download various malware on your computer thus transforming it in a bot.</p>
<p>We advise all users to not fall for these cheap tricks.</p>
<p>&nbsp;</p>
<p style="text-align: right;">Sorin Mustaca</p>
<p style="text-align: right;"><a href="http://www.sorinmustaca.com" target="_blank">IT Security Expert</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2013/05/06/new-movies-same-old-malware-tricks/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Emails containing fake invoices from Apple and Plus.de distribute malware</title>
		<link>http://techblog.avira.com/2013/04/30/emails-containing-fake-invoices-from-apple-and-plus-de-distribute-malware/en/</link>
		<comments>http://techblog.avira.com/2013/04/30/emails-containing-fake-invoices-from-apple-and-plus-de-distribute-malware/en/#comments</comments>
		<pubDate>Tue, 30 Apr 2013 09:13:45 +0000</pubDate>
		<dc:creator>Sorin Mustaca</dc:creator>
				<category><![CDATA[Spam/Phishing Analysis]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[mahnung]]></category>
		<category><![CDATA[plus.de]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[vertrag]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=5009</guid>
		<description><![CDATA[The German users should be aware of a massive spam campaign with emails pretending to come from Apple and Plus.de (discounter) containing a invoice of a good they bought from their shop. The so called invoice is in a ZIP &#8230; <a href="http://techblog.avira.com/2013/04/30/emails-containing-fake-invoices-from-apple-and-plus-de-distribute-malware/en/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>The German users should be aware of a massive spam campaign with emails pretending to come from Apple and Plus.de (discounter) containing a invoice of a good they bought from their shop.</p>
<p><a href="http://techblog.avira.com/wp-content/uploads/2013/04/mahnung1.png"><img class="alignnone size-large wp-image-5011" alt="mahnung" src="http://techblog.avira.com/wp-content/uploads/2013/04/mahnung1-1024x285.png" width="640" height="178" /></a></p>
<p><a href="http://techblog.avira.com/wp-content/uploads/2013/04/plus_de-mahnung.png"><img class="alignnone size-large wp-image-5012" alt="plus_de-mahnung" src="http://techblog.avira.com/wp-content/uploads/2013/04/plus_de-mahnung-1024x244.png" width="640" height="152" /></a></p>
<p>The so called invoice is in a ZIP archive containing a &#8230; SCR file. SCR is the classical extension for screen saver programs in Windows. The file in the archive is called &#8220;Rechnung.scr&#8221; and it is currently detected by our products as TR/Rogue.957311 and TR/Kazy.169263.1.</p>
<p>So, what is that makes this spam campaign so special?</p>
<p>There are a couple of items which are not seen usually in such spam campaigns:</p>
<p>- They address the recipient using the full name.</p>
<p>- The archive attached is called &#8220;&lt;First Name&gt; &lt;Last name&gt; Dritte Mahnung store.apple.com/de &lt;registration number&gt;.zip&#8221; or &#8220;Kaufvertrag &lt;First Name&gt; &lt;Last name&gt; Plus.zip&#8221;</p>
<p>- Makes use of social engineering which addresses the German speaking countries directly. &#8220;Dritte Mahnung&#8221; is in German and it means the third demand to pay letter. Usually, after the third demand the companies send the unpaid invoices to a lawyer. This is public knowledge in the German speaking countries.</p>
<p>&nbsp;</p>
<p>We can only make some wild guesses from where did the cyber criminals get the email addresses with full name. It can be that they got them from the companies that got hacked previously (Linkedin, Last.fm, Evernote, etc.)</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p style="text-align: right;">Sorin Mustaca</p>
<p style="text-align: right;"><a href="http://techblog.avira.com" target="_blank">IT Security Expert</a></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2013/04/30/emails-containing-fake-invoices-from-apple-and-plus-de-distribute-malware/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
