Tips and Tricks :
Security Software and their Configuration :
Common sense : Not only Installing Security Protection software like Firewall,
Anti-Virus, Anti-Spyware, Anti-Spamware, Anti-Popup, etc software are
enough, you have to Configure it equally as well. This type of
software needs to be trained up for your computer usage environment.
According to your use and habit. You have to take care of your
computer, like your pet, or like your car. Otherwise it will
stop functioning properly, and ultimately even fail or fail to protect
you. Which is very common. Staying free of bad stuff, requires
your effort. If you are not doing anything to protect yourself,
then your computer hardware, or software, or someone else, or some outsider,
or some (bad) hacker, or some malware (harmful software), or some poorly
designed code, or some bad code Will cause you trouble. Just like your
body, to stay in a healthy state/shape, requires your effort,
otherwise, you will become out of shape.
Tips & Tricks : You must install Security Protection
Software/Solution (SPS), like Firewall,
Anti-Virus, Anti-Spyware, Anti-Popup, etc software. Many SPS comes in a
suite or bundle edition or version. Usually they contain multiple SPS
features. If you install it early, when you've purchased computer,
or when you've installed the operating system (Microsoft Windows, Apple MacOS,
Linux, Unix, etc), then you will have less chance of getting infected.
Those who installs later, you should know that, many SPS or SPS suit fails
to catch or clean the system properly if it's already infected, because,
harmful computer codes (malware) that are intended to do harm, are also getting
advanced (to hide from SPS detection) day by day as well. Second most important
thing is to configure your SPS, and train it, according to your need or usage
habit. At least install one of the trustworthy and freely available SPS
software.
Don't Be Afraid : To configure SPS or SPS suit edition requires direct or related
knowledge, experience or training (related to computer software, their location,
network traffic and port usage, etc). But if you don't have it, don't get
afraid of that or ignore it. Choose a SPS, which requires less knowledge,
and easy to setup. Check various website that are displaying comparison
and review of the type of software that you are looking for.
Tips & Tricks : When you are starting a non-SPS software, your SPS
software will/should ask for your permission, if you want to allow that
non-SPS software to run, or not, SPS software will/should also ask if you want
it to allow to communicate to server computer on Internet, or not.
When such window or popup messages comes up, then look at the warning or prompt
window carefully, find out which software is trying to run/execute, and
try to find, from what folder location. Then take a decision.
If it is a software that you trust, or you have installed to full-fill your need,
or your computer manufacturer company have installed it, then you may allow
it, otherwise, do not allow it to connect to internet server.
Must do : Even if you make a mistake, you can always go back to
a configuring tab or a configuring button or a page inside your SPS software,
where you will be able to change the decision that you have made, about that
non-SPS program/software. Don't wait to do this step later, try to find that
configuring list, or page of software list, inside the SPS software/program,
Now. This will help you on changing and/or correcting the permission
mistakes.
Situation : Many SPS (Security Protection Software/Solution) software,
also provides more information on computer network traffic type, direction of
traffic/data flow, port number, IP address, domain or node name, etc.
For example, If you are starting the Mozilla Firefox web browser software
(like Microsoft Internet Explorer), your SPS software may ask you, that,
A software named "Firefox" or firefox.exe, from the location
"C:\Program Files\Mozilla\Firefox", is trying to take TCP outbound
internet traffic connection to the (for example) google.com or IP address
74.125.19.9O on port 80. Do you want to allow it ? Yes or
No ?
Tips & Tricks : When a software is trying to get information from the
servers located on the internet, for example, here, google.com or its
IP address, then SPS displays "Outbound", or similar words. If
someone, or some software, is trying to connect to your computer, from the
internet, then it will display/say "Inbound", or similar meaning
words. You should not allow that (Inbound traffic), unless you are using
P2P (Peer to Peer) type of software, or a Server type of software. TCP
is a type of network traffic, a protocol, a communication language for
computers to talk to one another, that is to, transmit/receive data and send/receive
instructions, over the TCP compatible local or/and intranet or/and internet
network connection, network devices, etc. Usually, web-page-servers,
like google.com or similar, delivers this type of traffic in-between
their web-page-server computer(s) and your computer's web client software,
which is in this case, is "Firefox". Web page servers also uses very
specific well known TCP port, port 80 & 443, usually. Another type
of server is FTP file servers, they use TCP traffic on port 21 & 20,
usually. For example, if Firefox is trying to start a TCP outbound
connection to a website on port 6000, then you should not allow it,
unless you are very much sure of, that website does uses that specific port
for delivering the web pages that you are trying to access/view. Some
web page servers use proxy server or non-standard port, for people to reach
their website pages, for example, through port 8080. Many P2P
client software may use UDP type of traffic also. P2P client software
also uses multiple ports to connect to multiple computers that are located on
Internet side. And it can also use inbound traffic as well, which is not
safe. Unless you can bind/restrict the traffic, to be used only by
the/that P2P software alone, Not By Anything Else. You need good firewall
for that. You must also use, very very good and up-to-date anti-virus
software, if you are downloading files through P2P software. Since they
are known for containing & spreading virus(es), malwares, rootkits, etc.
Must do : When you see/find a popup window from your
SPS software/application, then please do not
Skip it, do not Ignore it. The warning message is to notify you of some
out-of-normal situation or activity, and most likely will require your
prompt response or action. Read the warning message, and take an action
which will keep your computer and yourself, out of any infection or infection
chances, or any other type of risk or loss. Please do not take risk.
Delete the file or software that causes this warning. Goto another website,
or look for a different source to obtain a fresh file/software/image/video, which does not results in such/that type of warning. You may also inform and question
your supplier, why the item was creating warning ?
Tips & Tricks : Email checking client software (like, Outlook Express,
Thunderbird) uses port 110, 25, 143, 465, 587, 993 and/or
995, usually. Many ISP (Internet Service Provider) blocks the usage of
port 25, unless you request them specifically to open/allow it to be
used, or alternately uses port 26 or other port. Find info on your email
account service provider, which ports are allowed. Then allow only those
ports and websites to be used, by your email client program only. Email
Spammers send emails to various many addresses. Do Not allow external
content / image/pictures, or any script, to be executed or run or to access any
unknown site from your email client program, and do not give your email address
to a website where it will be displayed publicly. If you do that, then
spammers will know, which email address is reaching that content and
thus grow their email harvesting database. Even just by viewing an
external picture or a graphics file embedded inside your email, inside your
email client software, can expose your email address to that spammer !
Unless the image/graphics or multi-media file was embedded or included internally
inside/within the email itself. If the email is from a trustworthy entity
/ person, only then view its images / media files, or else, keep them non-viewable,
or non-playable or in disabled state. When a friend/relative,
or co-worker sends you email with attached files, or when you are downloading
some files from a website, Don't open it Directly, to view it, first
Save the attachment/download file onto some folder (like, Desktop, My Documents,
etc), then Scan with your Anti-Virus software by right clicking on that folder
(without going inside the folder) and select Scan with Anti-virus or Scan for Threats,
etc or by selecting a similar meaning options, whichever is installed/available
in that computer. After the scan process has finished without finding any
malwares, then you can double click on the file to open. If you do not
follow this previous step, you are taking big risks to get infected.
Keep in mind, not everyone is without infection or without harmful intention.
If no-one is infected (or working with & on viruses) then how virus(es), malwares,
etc are surviving, spreading ? causing havoc ? Don't hurry to get
infected.
Situation : Virus or Malware detection database files are usually updated
after few days of when a New virus or malware was introduced (or comes out) and
when such related acitivities or affects were reported back to the database creator
company, so during that period a new virus or malware can do lot of harmful
activities. And on another side, bad/harmful hackers can make even such
webpage(s), which, just by viewing or visiting it, your computer may
get infected with virus or malware, or a backdoor accessing internet connection
is made from bad hacker/group operated, or controlled, or compromised internet server
computer(s), into your computer, home or office network or computer(s),
to do harmful activities toward your computer or to you or to your family or
group. If any one of the computer inside your home or office is already
infected or compromised, then it becomes even more easier to infect or
compromise the other computers. The bad/hamful hackers or groups are doing
such activities, each for a different purpose or reason, every moment and
daily. Some of them are after your Money only, and some of them do such
activities just for Fun only, and some of them do it to show their might or
power, and some doing it for their own agenda or demand or to protest.
Tips & Tricks : Set your Anti-Virus or Anti-Malware software to Scan and
Clean automatically, ALL files. If cleaning fails, then that file should
be rightaway deleted, without even asking the computer's user. Stopping harmful
hackers completely is just not possible, but it is possible to make the
situation very harder for them, by using good firewall(s), which can
detect and control even (software) component level network connections, and
can disconnect your software from internet, when it's required internet
activity is over.
Tips & Tricks : Not all but some web browser/client
software have features to disable codes that can harm your computer, like
JavaScript, AJAX, VBScript, ActiveX-script, ActiveX, JavaApplet, pop-up, etc.
You should install different types of web browser and prefer to use that one,
which gives you the option for safer web surfing. And again, installing
is not enough, you have to configure it further, based on your
need. Some safer JavaScripts, AJAX codes can be allowed. Similarly,
'ActiveX', 'JavaApplets' can be allowed for a very trustworthy and known website,
only.
...
Last updated, partially on Mar 6th, 2011.