November 26, 2011

Facebook Help Center Community Forum overrun with spam

Spammers have attacked the Facebook Help Center Community Forum over the Thanksgiving holiday weekend in the US. Most of the spam consists of links for live streaming American sporting events.

MCTS Certification, MCITP Certification

Microsoft MCTS Certification, MCITP Certification and over 2000+
Exams with Life Time Access Membership at http://www.actualkey.com


The Facebook Help Center’s page for asking questions about various help topics has been overrun with spam. All 22 sections of the Community Forum, as well as each of their subsections, have been attacked by spammers.

There are multiple Facebook accounts being used in the attack: some are asking questions and others are answering them. It’s not yet clear if these are bogus accounts created for just this purpose or if the perpetrators have compromised already-existing Facebook accounts.

The spammers are trying to lure users with the usual nonsense: most are links for streaming live sports matches (boxing, football, hockey, and so on), but the usual weight loss offers are also present. Some of them are just text, but most include a link to a third-party website.

Almost all of the links lead to a webpage asking you for your e-mail address, although some just take you to a bogus website with ads. It doesn’t appear any of these webpages contain malware, but spammers can always change where the links redirect you to. Do not click on any of these links.

It’s possible the spammers are taking advantage of the Thanksgiving holiday weekend in the US. I’m not sure whether more users check out the Community Help Topics during this time, but it’s very likely Facebook has fewer staff working to get rid of threats like this one.

This attack has rendered the self-help support community effectively useless. Legitimate questions are being pushed down towards the bottom; on most of the sections, the first page only contains spam. I have contacted Facebook with this issue and will update you if I hear back.

Update: “Protecting the people who use Facebook from spam and malicious content is a top priority for us, and we are always working to improve our systems to isolate and remove material that violates our terms,” a Facebook spokesperson said in a statement. “Recently, our Help Center Community Forum experienced an increase in spam claiming to offer streaming video of American sporting events. We are taking steps to address the issue and encourage people to protect themselves by never clicking on strange or suspicious links.”

November 25, 2011

CompTIA Hardware Support Multimedia Certification Courses - The Inside Track

CompTIA A+ computer training covers four specialised areas - you'll have to qualify in two of these areas to reach the level of competent in A+. This is why, many training establishments limit their course to 2 of the 4 sectors. We think this is selling you short - yes you'll have qualified, but knowledge of every section will prepare you more fully for when you're in industry, where you'll need a more comprehensive understanding. So that's why you should train in everything.

Comptia A+ Training, Comptia A+ certification

Best comptia A+ Training, Comptia A+ Certification at Certkingdom.com



A+ computer training courses cover diagnostics and fault finding - via hands on and remote access, as well as building computers and repairing them and working in antistatic conditions. If you're considering being the kind of individual who is a member of a large organisation - in network support, add Network+ to your CompTIA A+, or consider the Microsoft networking route (MCSA - MCSE) to give you a better comprehension of how networks work.

The perhaps intimidating chore of finding your first job can be eased by some companies, via a Job Placement Assistance programme. But don't place too much emphasis on it - it's quite easy for their marketing department to overstate it's need. Ultimately, the still growing need for IT personnel in the United Kingdom is what will make you attractive to employers.

You would ideally have help and assistance with preparing a CV and getting interviews though; also we would encourage all students to get their CV updated right at the beginning of their training - don't procrastinate and leave it for when you're ready to start work. A good number of junior support roles are offered to people who are in the process of training and haven't even passed a single exam yet. This will at the very least get you on your way. If it's important to you to find work near your home, then you'll probably find that a local IT focused recruitment consultancy might work much better for you than a national service, for they are much more inclined to have insider knowledge of what's available near you.

A slight frustration for a number of course providers is how hard men and women are focused on studying to pass exams, but how little effort that student will then put into getting the role they've studied for. Get out there and hustle - you might find it's fun.

A knowledgeable and specialised advisor (as opposed to a salesman) will talk through your current situation. There is no other way of working out your starting level of study. With some real-world experience or qualifications, you may find that your starting point is very different to someone completely new. If this is going to be your first effort at an IT exam then you should consider whether to start out with some basic Microsoft package and Windows skills first.

Quite often, students have issues with a single training area which is often not even considered: The way the training is divided into chunks and physically delivered to you. Drop-shipping your training elements one stage at a time, as you pass each exam is the usual method of releasing your program. Of course, this sounds sensible, but you must understand the following: How would they react if you didn't complete each and every module at the proposed pace? Often the staged order won't fit you as well as another different route may.

To avoid any potential future issues, many trainees now want to make sure that every element of their training is sent immediately, and not in a piecemeal fashion. That means it's down to you how fast or slow and in what order you'd like to work.

November 23, 2011

How LAN problems can impact on your firewalls

Last week seems to have been a firewall issue week for me. I worked on incidents in two large networks where problems on the LAN managed to bring down firewalls at the edge of the network. Firewalls have come a long way since the original stateless varieties, which were little more than a collection of access control lists. These were superseded by stateful firewalls which kept track of the state of network connections. Modern firewalls are now application aware, you can do things like block access to certain applications or prevent users from using applications like Bittorrent.

MCTS Certification, MCITP Certification

Best Avaya Certification Training and Avaya Exams Training and more Cisco exams log in to examkingdom.com



However, these firewalls don't come without their problems. They require lots of computing power to analyze and filter applications as they pass through. On some networks it can be a challenge getting the right balance of application awareness and traffic throughput. The more features you enable, the more stressed your firewall becomes. A lot of firewalls are priced on throughput: the greater the throughput, the greater the price. As a result of this, I see some networks with firewalls that are just about coping due to the costs involved of upgrading to the next model.

One incident I worked on last week was with an Internet service provider (ISP). A couple of their corporate firewalls, which linked their staff networks to the Internet, were resetting themselves. They suspected a resource issue on the firewalls and installed extra memory, but this seemed to make the problem worse. We discovered the source of the problem by looking at the network traffic going from the network core to the firewalls.

We found that large volumes of syslog traffic was being routed to an external IP address. This was unusual as syslog is normally used for managing local networks. We looked at the external IP addresses and saw that they were from an IP range that was once owned by the ISP. They sold it off and updated routing tables. However, nobody checked if any remaining systems were exporting data to this old subnet. Once routing tables were updated the syslog traffic was now sent out via their firewall. This caused an overload and the firewalls reset themselves.

It's an interesting problem caused by the lack of IPV4 address space. A block of addresses is very valuable. For example, earlier this year Microsoft paid $7.5 million to purchase a block of 666,624 IPv4 addresses. If you are looking to change IP addressing on your network, make sure you have monitoring in place so that you can identify what is using the IP addresses and for what reason.

The second incident I looked at involved a large university in Scotland. The connection rate limit on their main firewalls was peaking. This resulted in complaints from network users that connections were dropping or that downloading and uploading was slow.

Networks within educational campuses are typically more open than they would be in a corporate environment. This means that even things like what's on the TV schedules can affect network performance. Applications like Bittorrent can generate large numbers of connections as it downloads small pieces of data from lots of other clients on the Bittorrent network. In the case of this university network, users on their WiFi networks were tunnelling Bittorrent over TCP port 80. This resulted in large amounts of traffic and connections. The firewall rules were updated to only allow 80 parallel connections per IP address and the firewalls stabilized.

I do like the way application aware firewalls are evolving, more awareness of traffic coupled with clever management interfaces. However, no matter what firewall you choose you should be able to see what is going in and out of your network perimeter. Try and do this independently of the firewall, no point in trying to switch on logging or extra diagnostics if it's already stressed out. Knowing what is going in and out of your network can also help prevent network breaches.
Bookmark and Share