<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Support Leeds, Yorkshire :: Ancar B Technologies &#187; spam</title>
	<atom:link href="http://www.ancarb.co.uk/blog/tag/spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ancarb.co.uk/blog</link>
	<description>IT Solutions company based in West Yorkshire with presence in London, Manchester and Leeds.</description>
	<lastBuildDate>Mon, 30 Jan 2012 11:56:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Best Practice for Implementing Web Security</title>
		<link>http://www.ancarb.co.uk/blog/2011/07/05/best-practice-for-implementing-web-security/</link>
		<comments>http://www.ancarb.co.uk/blog/2011/07/05/best-practice-for-implementing-web-security/#comments</comments>
		<pubDate>Tue, 05 Jul 2011 12:45:43 +0000</pubDate>
		<dc:creator>Richard.Payne</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[blocking]]></category>
		<category><![CDATA[content]]></category>
		<category><![CDATA[crimeware]]></category>
		<category><![CDATA[filtering]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[preventing malware]]></category>
		<category><![CDATA[protect]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[reputation scores]]></category>
		<category><![CDATA[secure]]></category>
		<category><![CDATA[security methods]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[threat of viruses]]></category>
		<category><![CDATA[url]]></category>
		<category><![CDATA[url filtering]]></category>
		<category><![CDATA[web policy]]></category>
		<category><![CDATA[web security]]></category>
		<category><![CDATA[web security methods]]></category>
		<category><![CDATA[web solutions]]></category>
		<category><![CDATA[web threats]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.ancarb.co.uk/blog/?p=485</guid>
		<description><![CDATA[In my last post Beware Legitimate Websites http://www.ancarb.co.uk/blog/2011/06/24/beware-legitimate-websites/ I discussed the threat of viruses some users are experiencing as a result of Web 2.0 and the ability it gives for various third parties to develop applications that can be infused &#8230; <a href="http://www.ancarb.co.uk/blog/2011/07/05/best-practice-for-implementing-web-security/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>In my last post <strong>Beware Legitimate Websites</strong> <a href="http://www.ancarb.co.uk/blog/2011/06/24/beware-legitimate-websites/">http://www.ancarb.co.uk/blog/2011/06/24/beware-legitimate-websites/</a> I discussed the <a title="Anti Virus Threat" href="http://www.ancarb.co.uk/business-solutions/anti-virus/">threat of viruses </a>some users are experiencing as a result of Web 2.0 and the ability it gives for various third parties to develop applications that can be infused with threats or mailiciously designed to target the unwary.</p>
<p><strong>So what can be done?</strong> Well introduce a company Web Policy of course!</p>
<p>Sounds onerous? It need not be if you follow the steps suggested below.</p>
<p><strong><span style="text-decoration: underline;">Step 1: Establish Who and What You Need to Protect</span></strong></p>
<p>It&#8217;s important to determine who you need to protect and what is of value.</p>
<p><strong>Who do you need to protect? (consider)</strong></p>
<ul>
<li>Employees</li>
<li>Visitors, customers and contractors (onsite access)</li>
<li>Branch and remote offices and mobile workers</li>
</ul>
<p><strong>What is of value?</strong></p>
<ul>
<li>Customer records</li>
<li>Employee records</li>
<li>Intellectual property</li>
<li>Financial information</li>
<li>Competitive information</li>
<li>IT systems, access information</li>
<li>Organisation/Company reputation</li>
</ul>
<p><strong><span style="text-decoration: underline;">Step 2: Understand Your Company&#8217;s Web Security and Productivity Requirements</span></strong></p>
<p>This centres on finding the right <strong><em>balance</em></strong> between making the network secure with methods that do not impinge on the productivity of staff.</p>
<p>It&#8217;s important to safeguard your company from Web threats and maintain a productive working environment. Once you understand your company&#8217;s Web security and productivity requirements, you can better evaluate the available Web solutions.</p>
<p><strong><span style="text-decoration: underline;">Step 3: Understand Web Security Methods</span></strong></p>
<p>Here we need to think about future needs and expectations as well as what is currently in place. Does your current solution contain both reactive and proactive methods. Let me explain.</p>
<ul>
<li><strong>Reactive Methods</strong> &#8211; Though they are useful in detecting<strong><em> known</em></strong> threats and enforcing policies, traditional security methods such as anti-virus scanning, URL (web address) filtering and reputation scores are reactive, and therefore less effective in protecting against <strong><em>new</em></strong> malware. These solutions block known viruses and worms by comparing content against signature databases, URL categories or reputation scores, <strong>all of which need to be updated each time a new attack is discovered.</strong></li>
</ul>
<p>&nbsp;</p>
<ul>
<li><strong>Proactive Methods &#8211; </strong><strong> </strong>Today&#8217;s sophisticated attacks require a solution that analyses content behaviour in <strong>real time</strong> and determines whether the content is malicious. Scanning all active content as users access it and blocking malicious content <strong>at the gateway</strong> is extremely important. Proactive control like Real-time Code Analysis<strong> </strong>detects mailicious intent of new emerging malware.</li>
</ul>
<p><strong><span style="text-decoration: underline;">Step 4: Evaluate Web Security and Productivity Solutions</span></strong></p>
<p>In reality, no organisation is immune ot security threats. When evaluating web security solutions, it is important understand the technologies used and how effective they are at preventing malware attacks. Below is a list of security methods employed in numerous companies/organisations.</p>
<ul>
<li><strong>URL Filtering</strong></li>
</ul>
<p>URL (Web Address) Filtering controls employee browsing habits and improves productivity and network performance. Although millions of URLs (Web Addresses) are scanned each day, URL filtering has become ineffective in detecting modern malware because the majority of infections occur through legititmate websites (see my previous blog). URL filtering was designed to be a <strong>productivity tool &#8211; not a security tool. </strong>As such, it doesn&#8217;t detect and block mailicious code stored in legitimate caching servers, search engines or Web 2.0 sites.</p>
<ul>
<li><strong>IP Reputation Lists</strong></li>
</ul>
<p>Reputation scores are assigned to domains using parameters such as the IP <strong>of the hosted site, the site owner, how long the domain is registered and whether the URL appears in mass SPAM emails</strong>. Reputation scores only apply for the name of the domain registrar -<strong> not for individual web pages</strong>, so malware infected pages can existing on legitimate websites that have high reputation scores.</p>
<ul>
<li><strong>Anti-Virus</strong></li>
</ul>
<p>Useful for blocking known attacks in the first line of defense, gateway anti-virus solutions look for signatures for known attacks, require days or longer to release a new signature and often miss attacks that use SSL, code obfuscation and other anti-forensic methods.</p>
<p>With dynamic cyber-attacks, malicious content is<strong> morphed during distribution,</strong> so no matching signature is available.</p>
<ul>
<li><strong>Real Time Proactive Technology</strong></li>
</ul>
<p>Therefore, it is important to scan all content <strong>as users access it</strong> and identify threats without the need for a historical signature database lookup. With Real Time Code Analysis, all inbound and outbound Web content is scanned, and analysed <strong>at the time of the request</strong> &#8211; before it is delivered to the user. Bydetermining code intent, known and undiscovered Crimeware, malware, Trojans, targeted attacks and other malicious web content are detected and blocked before they can penetrate company networks.</p>
<p><strong><span style="text-decoration: underline;">Step 5: Implement an Effective Internet Acceptable Use Policy (AUP)</span></strong></p>
<p>Establish through policies that address all Web, social networking and Web 2.0 tools currently in use or that might be used in the future. To be successful and Acceptable Usage Policy must be enforceable. This usually requires the installation of security software or hardware that monitors, blocks and reports inappropriate use of a company&#8217;s IT infrastructure.</p>
<p>That&#8217;s it for now. In my next blog I will outline the considerations and essential elements of an Acceptable Usage Policy.</p>
<p>Thanks</p>
<p>Richard</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ancarb.co.uk/blog/2011/07/05/best-practice-for-implementing-web-security/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>What is Backscatter? Can I stop it?</title>
		<link>http://www.ancarb.co.uk/blog/2010/05/12/what-is-backscatter-can-i-stop-it/</link>
		<comments>http://www.ancarb.co.uk/blog/2010/05/12/what-is-backscatter-can-i-stop-it/#comments</comments>
		<pubDate>Wed, 12 May 2010 10:17:23 +0000</pubDate>
		<dc:creator>SupportTeam</dc:creator>
				<category><![CDATA[Communications]]></category>
		<category><![CDATA[Hints & Tips]]></category>
		<category><![CDATA[backscatter]]></category>
		<category><![CDATA[crawler]]></category>
		<category><![CDATA[MTA]]></category>
		<category><![CDATA[NDR]]></category>
		<category><![CDATA[NDR spam]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spamming]]></category>
		<category><![CDATA[spiders]]></category>

		<guid isPermaLink="false">http://www.ancarb.co.uk/blog/?p=146</guid>
		<description><![CDATA[So, you log into your email Monday morning and there&#8217;s 500+ Non-Delivery Reports for emails you haven&#8217;t sent. What&#8217;s going on. Has your account been hacked? Unlikely. The more likely reason is that you&#8217;re a victim of Backscatter. What is &#8230; <a href="http://www.ancarb.co.uk/blog/2010/05/12/what-is-backscatter-can-i-stop-it/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>So, you log into your email Monday morning and there&#8217;s 500+ Non-Delivery  Reports for emails you haven&#8217;t sent. What&#8217;s going on. Has your account  been hacked? Unlikely. The more likely reason is that you&#8217;re a victim of  Backscatter.</p>
<p>What is it? In brief, backscatter is the influx of Non Delivery Reports (or NDR&#8217;s) into a victim&#8217;s Mail Server (or MTA).</p>
<h4>What is an NDR?</h4>
<p>Mail Transfer Agents support a service called Delivery Status Notification (DSN) which allows end users to be notified of  the status of an email, such as the successful or failed delivery of email messages.</p>
<p>A non-delivery report is a status message sent by the recipient or interim email server that informs the sender of a email message delivery failure. There are several issues that can trigger an NDR, the most common are when the recipient of the message does not exist or when the destination mailbox is full.</p>
<h4>Smarter Spamming?</h4>
<p>Email servers offer a simple measure against SPAM by only accepting emails that have a valid source domain.</p>
<p><em>i.e. The domain exists. </em></p>
<p>Spammers are aware of this and have a simple way of bypassing this check which is to mimic email addresses from a valid domain.</p>
<p>Spammers use several methods for harvesting email addresses from the web. One method is the use of &#8220;Web Spiders&#8221;. Spiders crawl the Internet and web sites for email addresses that can be added to a database to be both a recipient, and used as a valid email address for sending spam.</p>
<h4>From SPAM to Backscatter</h4>
<p>So now you&#8217;re in the database, you&#8217;re likely to be targeted for the receipt of SPAM, and unfortunately it&#8217;s likely that a Spammer is going to use your email address at some point to send a batch of SPAM emails.</p>
<p>Even though you&#8217;re not the true source of the emails, you are the legitimate owner of the &#8220;Senders&#8221; address. As such any Non-Delivery Report is going to be returned to you.</p>
<p>So depending on the frequency of abuse, or indeed the size of the attack, you could potentially about to receive thousands of Non-Delivery Reports thanks to a spammer.</p>
<h4>Can it be stopped?</h4>
<p>Unfortunately it is easy to mimic someones email address, however there are measures to firstly prevent you being the source of such a violation, and secondly reduce or prevent the influx of backscatter.</p>
<p>The &#8220;Sender Policy Framework&#8221; or SPF have introduced additional DNS Records (SPF Records) that allow you to specify who is allowed to send email from your domain (Mail Servers). This way, if an email is received by a mail server from a source other than defined in your SPF record, the connection will be dropped and the email will not be processed.</p>
<p><em><strong>Note:</strong> Googlemail, Hotmail and Microsoft are already implementing policies whereby if an SPF record does not exist, your email may be rejected.</em></p>
<p>Other options include disabling all catchall or wild-card mailboxes. When this feature is disabled the spammer has to match your exact email address and not your domain, so your mail server will not be accepting non-delivery reports for email addresses which do not exist on your mail server.</p>
<p>It is also recommended that you configure your mail server to reject during SMTP transmission rather than bounce email messages which cannot be delivered. Email servers such as Microsoft Exchange, Postfix, Sendmail and Qmail have patches to improve the behavior to create less backscatter.</p>
<h4>A better solution</h4>
<p>Using an external host to relay and filter your inbound email can prevent the receipt of SPAM and Backscatter, as well as reduce the loads generated by SPAM on your local mail servers.</p>
<p>Be low are a few more resources to give a little more information on the subject.</p>
<h4>The Backlash!</h4>
<p>The source of a Backscatter attack is no the SPAMMER, but it is the servers that are not configured to reject emails for invalid email addresses. These servers, although they&#8217;re the victim of an actual SPAM attack are now being listed on a UCE Blacklist (<a href="http://www.backscatterer.org/" target="_blank">http://www.backscatterer.org/</a>), which in turn gets your outbound email rejected due to your server being listed on a Black List.</p>
<p>As you can see, it is important to configure your email and DNS services correctly to ensure your neither the subject of a backscatter storm, nor listed unknowingly in a Blacklist.</p>
<h3>Other Resources</h3>
<p>Open SPF &#8211; <a href="http://www.openspf.org/" target="_blank">http://www.openspf.org/</a><br />
SPF Record Creator &#8211; <a href="http://old.openspf.org/wizard.html" target="_blank">http://old.openspf.org/wizard.html</a><br />
Microsoft Sender ID Framework -<a href="http://www.microsoft.com/mscorp/safety/content/technologies/senderid/wizard/" target="_blank"> http://www.microsoft.com/mscorp/safety/content/technologies/senderid/wizard/<br />
</a>Reducing Backscatter on Exchange &#8211; <a href="http://www.avianwaves.com/Blog/default.aspx?id=31" target="_blank">http://www.avianwaves.com/Blog/default.aspx?id=31</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ancarb.co.uk/blog/2010/05/12/what-is-backscatter-can-i-stop-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top Tips for cutting out SPAM</title>
		<link>http://www.ancarb.co.uk/blog/2010/04/27/top-tips-for-cutting-out-spam/</link>
		<comments>http://www.ancarb.co.uk/blog/2010/04/27/top-tips-for-cutting-out-spam/#comments</comments>
		<pubDate>Tue, 27 Apr 2010 10:40:44 +0000</pubDate>
		<dc:creator>SupportTeam</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spamming]]></category>
		<category><![CDATA[theft]]></category>
		<category><![CDATA[tip]]></category>

		<guid isPermaLink="false">http://www.ancarb.co.uk/blog/?p=129</guid>
		<description><![CDATA[SpamCop is currently having 92 million reported Spamming sources per month, and Ancar B Technologies Anti Spam solution is filtering over 3 million emails a month of which less than 15% is HAM. With such a volume of Spam email &#8230; <a href="http://www.ancarb.co.uk/blog/2010/04/27/top-tips-for-cutting-out-spam/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>SpamCop </strong>is currently having 92 million reported Spamming sources per month, and Ancar B Technologies Anti Spam solution is filtering over 3 million emails a month of which less than 15% is <strong>HAM</strong>. With such a volume of <strong>Spam </strong>email in your inbox, we&#8217;re wasting more and more time filtering though the junk in our mailboxes.</p>
<p>Free email services such as Hotmail and Googlemail offer a high level of filtering services as standard, but these are geared towards individual users.</p>
<p>For the rest of us, here are a few top tips to prevent help prevent the infestation of <strong>Spam </strong>in your inbox.</p>
<h4>Top Tops for Spam Reduction</h4>
<ul>
<li><strong>Disable the Automatic Download of Images</strong> &#8211; Applications such as Outlook do this as standard. Why? Firstly, it saves on bandwidth if you don&#8217;t really need the image. Secondly, and more importantly, spammers can track which users download the images which allows them to track legitimate email addresses and record them for futher spam attacks.</li>
<li><strong>Never follow links in SPAM</strong> &#8211; Again, URL tracking is in place which allows a Spammer to tack and target legitimate addresses.</li>
<li><strong>Avoid the use of a Catch All address</strong> &#8211; Put simply, you&#8217;re generating a honeypot for spammers as every possible conceivable email address will be valid and you will receive far more <strong>SPAM </strong>in your inbox.</li>
<li><strong>Use generic email addresses on the web</strong> &#8211; Never use a private email address on web sites. Web Crawlers are constntly trawling for email addresses to add to their database. So use info@ rather than your personal email to keep the SPAM out of your inbox.</li>
<li><strong>Sign up for a Googlemail Account</strong> &#8211; And use it just for signing up to sites/forums or any other site you need to enter an email address in order to access information. As mentioned previously, they have great <strong>SPAM</strong> filtering systems and it keeps your inbox clean. <a href="http://www.googlemail.com" target="_blank">Googlemail</a></li>
<li><strong>Read Privacy Policies</strong> &#8211; Following on from the last point, don&#8217;t just tick the box and sign up. Read a web sites privacy policy to ensure they&#8217;re not going to pass on your details. Additionally, watch out for &#8220;pre-checked&#8221; boxes signing you up to mailshots.</li>
<li><strong>Use an email client with a Junk Filter</strong> &#8211; Microsoft Outlook and Mozilla Thunderbird both have built in filtering engines to help keep your Spam email under control.</li>
<li><strong>Never use TO or CC on Mailshots</strong> &#8211; A mistake made by many people. Always BCC users on a Bulk Mailshot. This keeps the groups email addresses private and prevents mail loops and mail scatter.</li>
<li><strong>Disable Automatic Read Receipts</strong> &#8211; Your just letting Spammers know they can send you more mail.</li>
<li><strong>NEVER REPLY TO SPAM</strong> &#8211; Need we say more?</li>
<li><strong>Do not pass on Chain Messages</strong> &#8211; They may occasionally be funny, but read down the next one you receive. How many email addresses appear in the message. your just adding yourself to a long list of email addresses ready to be added to a database.</li>
<li><strong>Report Spam</strong> &#8211; <a href="http://www.spamcop.net" target="_blank">www.spamcop.net</a> &#8211; Report any <strong>Spam </strong>you receive to help yourself and others in the future.</li>
<li>Consider a Mail Filtering Service &#8211; Of course, Ancar B Technologies offers a <a href="http://www.ancarb.co.uk/solutions/30/Hosted_Email_Anti_Spam.html">mail filtering service</a>, but to be impartial, I can also recommend <a href="http://www.websense.com/content/home.aspx" target="_blank">Symantec&#8217;s Websense</a></li>
</ul>
<h4>Avoiding Phishing and ID Theft</h4>
<p><strong>Phishing </strong>is quickly becoming one of the biggest forms of <strong>Spam </strong>and is now considered the biggest global threat for <strong>Fraud</strong>. Here are a few simple tips for ensuring your protection.</p>
<ul>
<li><strong>Never Contribute to Charity Emails</strong> &#8211; If you want to donate, visit the Charities official web site.</li>
<li><strong>A Bank will NEVER ask you for your details</strong> &#8211; Under no circumstances will a bank ask you for your personal information on an email. You know who you bank with, if you want to log in to check anything, go to their site yourself.</li>
<li><strong>If it looks like spam, it probably is</strong> &#8211; Simply delete it.</li>
<li><strong>Never provide personal information</strong> &#8211; If an email asks you for personal information, delete it.</li>
</ul>
<p>These steps are only simple, and generally common sense prevails. But following these simple tips will reduce the <strong>Spam</strong> in your inbox and also provide protection against<strong> Identity Theft</strong> and <strong>Fraud </strong>from <strong>Phishing emails</strong>.</p>
<p>Happy Emailing!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ancarb.co.uk/blog/2010/04/27/top-tips-for-cutting-out-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

