Showing posts with label Security Tips. Show all posts
Showing posts with label Security Tips. Show all posts

Tuesday, 18 March 2014

Use WhatsApp on Android? Your chats are not so secure

NEW DELHI: If you use WhatsApp on an Android phone, you should be careful about what you talk about or share on the instant messaging app. Using a few scripts and a rogue app, anyone can peer into your chat logs and see what you talk about with your friends. 

A Dutch security consultant has found that WhatsApp chat logs saved on the SD card of an Android phone can be read by other apps because of the way Android allows sharing of data between apps.

"The WhatsApp database is saved on the SD card which can be read by any Android application if the user allows it to access the SD card. And since majority of the people allows everything on their Android device, this is not much of a problem," Bas Bosschert wrote on his blog.

"What do we need to steal someone's WhatsApp database? First we need a place to store the database," Bosschert explained. "Next thing we need is an Android application which uploads the WhatsApp database to the website."

When an Android application is installed, whether from the Play store or through an APK file, which is an installer file for Android phones and can be downloaded from various sources, the app requests for permissions to use network and SD card etc.

To explain his hack, Bosschert set up a web server and then created an Android application that required several special permissions on a user's phone. But because Android OS allows applications to access various parts of the phone - this is why users can conveniently share almost everything through any app on Android phone - Bosschert's app had no difficulty gaining access to WhatsApp data.


Bosschert wrote that the code that allows his application to access WhatsApp data and then upload it to his web server can be added to a popular Android app by a rogue developer to fool users and steal WhatsApp chat logs.

The older versions of WhatsApp were so insecure that they didn't even encrypt their data stored on SD card. The data from older versions of whatsApp could be read by anyone once it was uploaded on the web server. Even the data from newer version of WhatsApp, which uses encryption, can be accessed with ease.

"The WhatsAppp database is a SQLite3 database which can be converted to Excel for easier access. Lately WhatsApp is using encryption to encrypt the database, so it can no longer be opened by SQLite. But we can simply decrypt this database using a simple python script. This script converts the crypted database to a plain SQLite3 database," wrote Bosschert. "We can conclude that every application can read the WhatsApp database and it is also possible to read the chats from the encrypted databases."

Bosschert joked, "Facebook didn't need to buy WhatsApp to read your chats."

The security issue apparently doesn't exist on iPhones or Windows Phone devices because on these smartphones, apps have limited access to storage and other phone hardware. The more flexible access to phone hardware allows Android apps to talk to each other and helps a user quickly share content between apps. This is very convenient compared to what is possible on iPhone or Windows Phone, where it is difficult to share content between apps. But it also exposes data to rogue apps.

Google says that it keeps an eye on apps inside its Play store and removes apps if they pose any security risks. But this doesn't negate the fact that theoretically it is possible for a rogue app to do more damage on Android because of the open nature of the OS compared to iOS, which uses silos. Google also advises people against installing apps that don't come through Play store. By default Android phones are set to not install apps downloaded outside the Play store.

Source : timesofindia.com

Sunday, 27 October 2013

Five safety tips for using a public computer


Public computers in libraries, Internet cafes, airports, and copy shops can be safe if you follow a few simple rules when you use them.
Read these tips to help keep your work, personal, or financial information private.
  • Don't save your logon information

    Always log out of websites by clicking "log out" on the site. It's not enough to simply close the browser window or type in another address.
    Many programs (especially social networking websites, web mail, and instant messenger programs) include automatic login features that will save your user name and password. Disable this option so no one can log in as you.
  • Don't leave the computer unattended with sensitive information on the screen

    If you have to leave the public computer, log out of all programs and close all windows that might display sensitive information.
  • Erase your tracks

    Internet Explorer offers InPrivate browsing that leaves no trace of specific web activity. For more information, see Internet Explorer 9 Features: InPrivate Browsing.
    Internet Explorer also keeps a record of your passwords and every page you visit, even after you've closed them and logged out.
    Disable the feature that stores passwords
    Before you go to the web, turn off the Internet Explorer feature that "remembers" your passwords.
    1. In Internet Explorer, click Tools  Gear icon, and then click Internet Options.
    2. Click the Content tab, and then click Settings, next to AutoComplete.
    3. Click to clear the check box for User names on passwords and forms.
    Delete your temporary Internet files and your history
    When you finish your use of a public computer, you can help protect your private information by deleting your temporary Internet files. For information on how to delete temporary Internet files see Delete webpage history.
  • Watch for over-the-shoulder snoops

    When you use a public computer, be on the look out for thieves who look over your shoulder or watch as you enter sensitive passwords to collect your information.
  • Don't enter sensitive information into a public computer

    These measures provide some protection against casual hackers who use a public computer after you have.
    But keep in mind that an industrious thief might have installed sophisticated software on the public computer that records every keystroke and then emails that information back to the thief.
    Then it doesn't matter if you haven't saved your information or if you've erased your tracks. They still have access to this information.
    If you really want to be safe, avoid typing your credit card number or any other financial or otherwise sensitive information into any public computer.
    source: Microsoft.com

Sunday, 4 August 2013

Disable USB port in a Windows by editing registry.

This articles describes how to disable USB port in a Windows PC by editing registry. Follow the steps given below to disable USB port from registry editor.

Warning: Modifying the registry is always risky, if anything goes wrong Windows OS needs to be reinstalled. So be very careful while modifying the registry.
  1. Clcik Start and then click Run
  2. Type regedit in Run window and click  OKRegistry editor window o pens.
  3. Expand HKEY_LOCAL_MACHINE key on the left pane under My Computer (by clicking on + sign on left side of HKEY_LOCAL_MACHINE)
  4. Expand SYSTEM key under HKEY_LOCAL_MACHINE.
  5. Expand CurrentControlSet key under SYSTEM.
  6. Expand Services key under CurrentControlSet. (as shown below)
  7. Select usbstor key under Services.
  8. Select Start value on the right pane
  9. Right click Start value, select Modify in right click menu
  10. Edit DWORD value dialog will pop-up. Modify the Start value data to 4. Click OKbutton to commit the changes done. After modifying the value, the registry editor's right pane looks as shown below.
  11. Close the registry editor. Now USB port is disabled.
Note: To enable USB port modify the Start value to 3.

Wednesday, 31 July 2013

Tips to Protect Your Email Account from Hackers


protect your email from hackers

In the world of technology, there is always the danger of a security breach. The most common of this instance is when a hacker is able to access your email account to your demise and it generally makes your vital files, documents and perhaps important project portfolios and other essential documents with respect to your work highly vulnerable to a third party. Who knows, the hacker just might be a competitor who wants to take a peek of your valuable exchange of business correspondence with your clients or to completely pirate your active clients away from you. There is a high chance however that it could be any hacker who is just waiting for their prey at any opportunity that they can find to victimize.
Because many professionals are using their emails for their officials business, an email account becomes your valuable property and perhaps an asset that allows you to keep in touch and connect with your clients. Because of this reason, protecting your email account at all costs should always be a priority. If you are one among these professionals who find it a priority in keeping your email safe and protected against hackers, here are some useful tips to keep your email correspondence and files safe.

Here’s how you can protect your email From hackers:-


1. Before you create an email account you will be prompted to provide your own password. Maintaining a strong password for your email account is your first line of defense against hackers. A strong password attribute is one in combination of letters, numbers, lower and upper cases which makes it difficult to hack.
2. Make your password more difficult by adding punctuation marks and other symbols when your email service provider allows them to form part of your password.
3. Do not be tempted to use your birthday, nickname, pet name, family name or anything closely related to you that can be easily thought of by anyone as your password. If you are unsure whether you are creating a good password, make use of free sites that offer a tool for generating strong passwords like the PC Tool by Semantics.
4. When creating accounts to different websites that use your email address for log in, be sure that you have secured for yourself a difficult password to break on each account but make sure to have your own password manager to easily remember all your different passwords.
5. Never use the same password as your email account when signing up on various online sites.
6. Be wary about cell phone spyware that could be monitoring your device each time you get access to your email using your mobile phone. They can run stealth which quietly monitors your email correspondence without you knowing it. You should constantly update your operating system, launch a malware scan periodically on your phone and always audit your program file to check for suspicious programs that are installed on your mobile device.
7. Creating an alternative email account will give you another contingency plan on how to access your hacked email account or prevent hackers from gaining access to it. In case someone else managed to hack your email, you have an opportunity to access it again through your secondary email and change the account password.
8. When providing for an answer to a security question, make sure to provide an answer that can’t be easily guessed.   Look for a more unexpected answer, more so a memorable event in your life, which can take a hacker an eternity to find out. A complicated answer to these questions as long as you can fully remember or memorize it can drive away a hacker.  Unless he has the leniency of time, he’ll definitely leave your account alone immediately to find other accounts who can be hacked easily.
9. It is not impossible to find yourself needing to access a public computer in order to access your email in case of emergency. Internet café is the most common place where you can have an easy access to a public computer. When you do so, make sure that you have the automatic log in box unchecked before you start accessing your email account.
10. Ensure that you have successfully logged out of your account before leaving the public computer otherwise you are simply giving just anyone an instant access to your email account to your misfortune. 
Source: http://www.techtricksworld.com/

Monday, 8 July 2013

TIPS FOR SAFE EMAIL


  •  Guard Yourself against Phishing.
  • Change your password on regular basis as per the password policy.
  • Do not share your password with anyone.
  • Always remember to sign out properly after using your mail account.
  • Do not save or remember your password anywhere.
  • Use Anti-Virus software & update it on regular basis.
  • Update the operating system and application patches.
  • Use automatic reply only when needed.
  • Never open / respond any mail / attachment from unknown sender.
  • Never subscribe your email ID on unsafe locations (over internet).
   

1. Guard yourself against Phishing

Common email scams employ email messages and even websites that look official, but are in fact attempts to steal your identity to commit fraud. This is the activity commonly known as ‘Phishing’.

Make sure that the address in your browser is genuine and does belong to the website you need to access. Don't ever copy URLs from e-mails. Type out the URL in a new window.

Never click on a link within an email requesting that you enter your username, password, etc. The link can also be malicious.

Do not open any 'fishy' emails. Delete immediately. Emails that have misspellings, poor graphics, or include a long cc list of other email addresses can be suspicious. 

Install a web reputation filter on your desktop that alerts users to phishing websites.

Make sure that you have unique username and passwords for each account/website you regularly visit. 

Never give out sensitive personal or account information to someone that asks via email unless you have verified the message's authenticity.

2. Change your password on regular basis as per the password policy. 

It is recommended to change passwords on a regular basis .

3. Do not share your password with anyone. 

Don't share your password. Do not be duped by malicious e-mails asking you for your password. This is a well-known, trick designed to fool you into sharing your password. As a rule, never share it with anyone.

4. Always remember to sign out properly after using your mail account. 

Always log out of your email when finished, whether you are using web mail or POP mail. It is also recommended to log out whenever you have to leave your computer unattended for a considerable period of time.

5. Do not save or remember your password anywhere.

Do not “save / remember” your password anywhere (say your browser, POP Client).

6. Use Anti-Virus software & update it on regular basis.

It is also highly recommended to install and maintain a anti-virus software on your computer to prevent infection from USB drives, CDs or DVDs and so on. Make sure it is updated regularly. Scan all attachments with a virus program before downloading/executing any, even if they come from someone you know.

Computers that are infected with spyware/key loggers record every word that users are typing, hence a daily scan is recommended.

7. Update the operating system and application patches

Users need to ensure that their desktop/laptop has the latest operating system and application patches. If the patch levels are not updated, updated anti-virus software will not be able to prevent an infection. Both anti-virus and operating system patches need to work together.

8. Use automatic reply only when needed.

It is savvy to turn off any automatic replies in your email client saying that an email has been read or received, because this confirms that the email address is a good one. Spammers will then target your email as a priority and flood your inbox with even more unnecessary and potentially harmful mails.

9. Never open / respond any mail / attachment from unknown sender.

If it happens that a few spam mails do manage to sneak through, make it a must to delete all them. Replying / Opening such emails / attachments typically only informs the sender that they have found an active email address to send more spam emails or They may contain what are known as "letterbombs" or "viruses," which can damage your PC.

10. Never subscribe your email ID on unsafe locations (over internet).

Never subscribe your email address on any unsafe / fake website, they may try to flood your inbox or spammers will try to send bulk spam mails (which may contain virus).

Source : https://mail.nic.in/docs/nic1.html & http://mysapost.blogspot.in/

Sunday, 21 April 2013

IE Privacy Keeper


Fast, simple and efficient browsing history cleaner for Internet Explorer and Mozilla Firefox. Allows you to selectively keep history items. Cleans up index.dat files without the need for a Windows restart.
Portable version: 
The TakeAlong version of IE Privacy Keeper is especially designed for cases when you cannot or don't wish to install IE Privacy Keeper using the setup program. For instance, when you are renting a computer in a cyber cafe or when you have restricted rights on your computer at work.
The TakeAlong version is a standalone executable that does not require installation or the presence of any auxiliary files. It will not write anything to the registry on the machine where it is executed. You can take it along on a diskette, CD or a USB Drive.
The TakeAlong version has the following differences from the full version:
  • Automatic cleanup (at windows startup/shutdown, etc.) is N/A
  • Cleanup notification options (tray icon, tray balloon, simple window, etc.) are N/A
  • The last cleanup log is not saved
  • The "IE Privacy Keeper" item in the IE Tools menu is N/A
  • The "Secure Delete" item in the Windows Explorer context menu is N/A
  • "Clean Up Now" shortcut keys combination is N/A
  • Hiding IE Privacy Keeper from the list of running processes is N/A
  • Locations of the standard folders (History, temp files) cannot be changed
Source: http://www.browsertools.net  Via : http://srfix.blogspot.in

Wednesday, 27 March 2013

Protect Your Password

Password protection is a priority.

Today advanced hardware makes it easy to crack passwords. In such a scenario, what should users do to prevent hackers? Geeta Padmanabhan has the lowdown

If you thought your clever password was something no one could hack, well, you are in denial. Consultancy firm Deloitte reports that 90 per cent of user-generated passwords are vulnerable to hacking. What, even my traditional (clever) combo of eight characters complicated by numbers, letters and symbols? Yes.

Last year, Zappos.com lost names, email-IDs, phone numbers and partial credit card numbers of 24 million customers. LinkedIn admitted its user passwords were “compromised”. Some 400,000 Yahoo email-ID passwords were hacked last July. In 2011, 77 million passwords were stolen from Sony’s PlayStation Network. GoDaddy's passwords were breached. FBI, NBC-sites, 112 Indian government sites found their “secure” passwords “exposed”. If it's any consolation, Taliban sites were successfully attacked too. Just check out what services like “iFramers” do to hacked websites.

RE-USING PASSWORDS

How did our passwords get so susceptible? Longer passwords infused with @, *, % symbols are difficult to remember, so we pick a small subset from them — and they get cracked. We slip-up by re-using passwords. Credit-checking firm Experian found that the average user has 26 password-protected online accounts but uses only five different passwords. Deloitte says 10,000 most common passwords access 98 per cent of all accounts. When you key in the same password for online banking and Warhammer, a security breach at the gaming site compromises the bank account password.
Even long passwords aren't safe, says Ashwini Rao, researcher at Carnegie Mellon University. Sentence-like/phrase-like passwords such as “abiggerbetterpassword” and “thecommunistfairy”, postal addresses, email IDs and URLs also make for less secure passwords now, she says.
Blame it on advances in password-cracking hardware. “It's called a brute-force attack,” says techie Mahesh, explaining its nuances. “Powerful computers/laptops try every possible permutation-combination to find the “right” one, no intelligence involved.” Creep! Our eight-character password, created from the 94-character keyboard is one of 6.1 quadrillion possible combinations. “A dedicated password-cracking machine employing virtualisation software and high-powered graphics-processing units can crack any eight-character password in 5.5 hours,” the Deloitte report said. Nefarious, says Mahesh. “A computer working alone may not be able to dig, say, military networks. So a zombie machine, could be yours, is roped in for the hack job. It's a small percentage of your CPU; you pay for unlimited time, so how will you know? Hey! “Wait,” he says. “There is also crowd hacking, where hackers share the power of thousands of machines to infiltrate the target. At no cost.”
Help! Twitter and Adobe re-set thousands of passwords after “embarrassing” goof-ups. Google alerts you on unusual mob-phone activity. It also wants you to insert Yubikey, a smart-chip embedded tiny key that goes into the USB drive, unlocks and automatically logs onto all your accounts without asking for a password. Yubikey works on Windows/Mac/Linux/iPad/Firefox/Chrome, and is waterproof, crush-safe, needs no battery or clients software/drivers. With a simple touch the YubiKey sends a one-time-password (OTP) as if typed. The unique passcode is verified by a YubiKey compliant app. Fine. “Things like YubiKey are definitely more secure as they support random passwords and provide two-factor authentication,” says Mahesh. “Corporates use them on a day-to-day basis because they are mandatory, but you will use it a lot less since it's optional.” You could lose it, you need to insert it, and always type in a master password to access websites. Too much!
“Multi-layer authentication” is possible. You log onto your credit card issuer’s site, type in your username/password, send another code/password to smartphone, and go online. Not terribly convenient! Password vaults or password safes (paid tools) offer you a central place to store all your passwords, encrypted and protected by — you guessed it — a password or token. These, presumably, are not easily cracked. Firefox can save user names and passwords for online services like banking.
Go for poor grammar and spelling, says Ashwini Rao. Hurray! Since “brute” searches for proper combo-words and grammar, you hoodwink it by staying outside the dictionary. She suggests phrases such as “Pineapplesi$nise”, “Exitingplan$isafoot”, that is, if you can memorise the deliberate mistakes. Try “eat cake at 8!” or “car_park_city?” (Idontnohowtospal.com). The high-tech crowd touts a biometric solution, but it has its hiccups. Smartphones ask you to connect nine dots — easy, many combos, visual/tactile (touch to remember). Connecting fewer dots generates more combinations.

FOLLOW GOOD PASSWORD PRACTICES

Never share your password. Avoid using non-secure networks at public places to send private information. Change password after using a non-secure network, change it frequently. Never store your password in a program. “I use Lastpass — a password manager and form-filler,” says Mahesh. “and a secure operating system like Linux. All codes are out in the open, so it is easier to review.” Mmmm... will you consider becoming a hacktivist? If you do, let me know.
Source : the Hindu

Wednesday, 17 October 2012

Enable / Disable USB storage devices in Windows XP


Enable / Disable USB storage devices in Windows XP using Group Policy


1. Click on Start button, then click on Run option , and Type GPEDIT.msc
2. Then Click on Administrative template under Computer Configuration
2. Click on Custom Policy setting , then Click on Restrict Drives
3. Double-click on Disable USB Removable Drives .
4. Select Enable for Restrict USB Removable drives , then click ok.
    And select Disable for Allow to USB Removable drives, then click ok


Enable/Disable USB storage devices using Registry 


1. Click on Start Button, then Click on Run Option then Type Regedit, then ok.
2. Click on the following Registry path

     HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UsbStor

3. Click on USBStor , then Click on Start in the Right Panel.

4. Type in the Value data Box, then click on Hexadecimal, then Click OK.

Re-Enable disable port

1. Type 3 in Value data Box , then click on Hexadecimal , then click ok

Friday, 22 June 2012

Tips To Protect and Secure Your Privacy On Twitter


Twitter is one of the most popular and addictive social networking sites today, apart from Facebook. Originally thought of as a micro blogging site, Twitter soon turned out to be a site where people started to share everything – from what they eat to what they think, their habits, their obsessions, their ups and their downs, what they are doing, what they intend to do and more. You can look at the timeline of any person and get to know many facts about him or her.

Is Protecting Your Tweets A Good Idea?

So how do you go about protecting your privacy on a site so seductive!? These tips that will help you stay secure and protect your privacy while using Twitter.

One of the methods to protect your privacy on Twitter is to protect your tweets. You can protect your tweets by visiting Settings. This way, people who are not following you cannot read your tweets. You also get to select who all can follow you. If you want to interact with limited people and with people whom you know, you can go ahead and protect your tweets.

But protecting your tweets is not a good idea as you may miss upon on followers. People, in general, do not like following people with protected tweets. Also, if you represent a service or business, you need to keep the tweets in public domain so that others can see how you treat others. In other words, keeping your tweets open means you have nothing to hide from others – and this attitude brings in more followers.

Protecting Your Privacy

Protecting your tweets is not a good idea, unless you wish to interact with limited people. If you want more followers and wish to have more people for interaction, it is recommended that you do not protect your tweets.

Then how do you protect your privacy? Here are some tips:

Be careful while tweeting. Do not share personal information such as phone numbers and email addresses on Twitter.
Though the geo tagging feature (see image above) is useful, use it only when you want your friends to know where you are when tweeting. Do not enable it for all tweets.
If you are linking Twitter to other social networking sites, know that Twitter can cross post to those social networking sites. Tweet in mind keeping the fact. If you do not want Twitter to cross post, revoke access to Twitter from other social networking sites.
When uploading pictures, make sure they do not contain any kind of personal information. People can use these pictures to trackback your location and other details.
Understand that other people can always retweet your tweets. Do not tweet anything that others can manipulate for their own needs.
Under Settings, you may also to unceheck Let other find me by my email address.
Make sure that the Always use HTTPS box is checked.
If you want, you can also Block any user. To do so, visit his Profile page and click on the Block item from the drop-down menu of his Person icon.

The bottom line is that there are no specific rules to stay safe on Twitter. You have to stay secure on your own – by staying careful when tweeting.

Go here, if you’d like to know what to do if you are Locked out of Twitter or if your account is compromised.

Wednesday, 23 May 2012

How to Hide the HDD Partitions?


This trick is for all those people who wants to hide tons of data into their box. So here it is, if you have very important data in your hard drive placed in some partition which you do not want anybody to see then this trick is only for you!!!
1. Just click on start>run type gpedit.msc
2. Now navigate through user configuration> administrative templates > windows components> windows explorer
3. Double click on “Hide these specified drives in My Computer” modify it accordingly.
4. Then just below you will find another option “Prevent access to drives from My Computer”, double click on this option and modify it accordingly.
5. To make it visible again select "disable" by double clicking on the “Hide these specified drives in My Computer” option.

WARNING:Don't try to experiment with other options in gpedit.msc if you don't know, what exactly your doing. Just have some patience and follow my tutorials regularly, i am going to tell you everything that is configurable in windows [and those also which you thought before, "Seems not possible to change ;-)" ].

Friday, 27 April 2012

7 Tips for Basic e-mail Security

Simple to implement, these tips can be a good start to making sure your e-mail communication becomes more secure.



1. Understand that no e-mail communication is 100% secure. We can do our best to make the percentage close to that, but sometimes - if the information is extremely important - you should consider ditching the e-mail option and deliver it in person (if possible). Avoid sending credit card or social security numbers via e-mail. It's also a good idea not to send user names and passwords for accounts you don't want to see compromised.

2. The more your e-mail is present in the confines of the cyberworld, the more spam you'll be likely to receive. Unfortunately, even if you're careful with disclosing your e-mail, chances are people will include you in mass mailings and you eventually your e-mail will be out there. To counteract this, you should definitely set up filters and rules. They will not catch every unwanted e-mail, but they will reduce their number. This is not just a matter of annoyance - basic users and novices are more susceptible to spam and scams. So why give the bad guys the possibility of trying out their angle?

3. Tied to the previous advice is this one: choose plain text over full HTML or XHTML rendition to reduce the risk of being targeted by a phishing attack.

4. Don't open attachments unless you know who it's coming from and you trust them.

5. Use encryption. Check with your ISP to see if they encrypt the authentication process. Encrypt your email message if possible. Are you familiar with the concept of steganography? You can hide messages in images, articles, shopping lists... Ideally, you can use both - first encrypt the message, then use a steganography software to embed it in a recent photograph. There are simple tools out there.

6. Don't access your e-mail from an unsecured network or potentially compromised computers. Yes, that particularly includes access from an Internet cafe. There be keyloggers.

7. Teach everybody who wants to know about it, especially your children (AND especially if you're using the same computer).

Courtesy : www.net-security.org

Saturday, 10 March 2012

How Employers Disable USB Ports & How Employees Enable them again



Desktop computer equipped with a CD writer or a DVD burner is a rare sight is most companies. But a much larger security threat is posed by the open USB ports where mischievous office workers can just plugin the Flash Pen Drive, External Hard Disk or their iPod music player and transfer corporate data or even copy licensed software to their memory sticks in seconds.


Also, USB keys are not just a popular way to sneak data out from companies, unhappy employees may use USB ports for delivering trojans or spyware into the company networks.



Now some smart admins disable usb drive by changing the BIOS settings and then lock the BIOS using passwords. Some not so-smart admins fix tapes over the USB ports to prevent employees from inserting any USB device into their computer. 



However, both these approaches can prove to be counter-productives as your staff can no longer use USB keyboards, wireless mouse, digital cameras, camcorders, scanners, printers or even USB microphones to their computers.



So a more reasonable option for sysadmins is to disable write access to USB port so that data files cannot be written to the mass storage device. The USB thumb drive will be read-only.



Open the Windows Registry and open the following key
HKEY_LOCAL_MACHINE\System\CurrentControlSet\ Control\StorageDevicePolicies



Now add a new DWORD called WriteProtect and put the value as 0 to disable write privileges to the USB port. To reverse the step, either delete the WriteProtect REG_DWORD or toggle the value to 1 which will enable the port.



Remember that the above trick works only with Windows XP SP2.



If you like to go a step further and disable users from connecting USB storage devices to their computers, here's the trick:


Open registry and navigate to the following registry key:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet \Services\UsbStor

Now in the right pane, double-click Start and type 4 in the Value data box (Hexadecimal) and quite the registry editor. To enable the USB storage devices, change the Start value back to 3.

No matter how good the protection tricks are, determined people always find workarounds. Here are some of the tricks that may render the above methods unusable:

» Employee may boot computer using a LiveCD like Knoppix or Ubuntu so the USB drives are again available to him for writing.

» They could open the computer chasis, take the battery out to reset the BIOS settings.

» Some may even invest in a PS2 to USB port converter.

» If he manages to get admin access for a temporary period (like installing software), he may undo the registry edits.

The cat-mouse game will never end. USB drives will remain a headache for the sysadmins for some time. However, Windows Vista will make life much simpler for IT administrators. There's a new Policy in Vista that allows USB keyboards or mouse to be used but not any USB devices. 


Source : http://labnol.blogspot.in/