Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


October 26, 2008

Top Ten Net-Surfing Risks at Work

When the threat comes from within...
RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Sometimes, the biggest threat to your network security can come from within, either intentionally or unintentionally. In fact, many breaches comes from someone on the inside doing something unintentionally that "invites" some external exploit in. Here is a list of the top ten list of dangerous activities to be doing on the Internet at work. Share these with your employees and let them know that their Internet excursions could bring risk to the company: 1. Opening forwarded emails with jokes, videos, pictures, etc. These are emerging as the biggest new threat to internal network security. Many people do not realize that these emails are merely attachments and often have been forwarded hundred or thousands of times, often originating overseas. Crackers and identity thieves are starting to use these innocuous looking emails as payloads for their malicious code because people will gladly click on them even though they have been trained to not click on attachments from unknown parties. Do not click on these emails nor should you forward them to any others. You quite possibly can be helping to infect your friends and family with spyware or worse. 2. Peer to Peer (file sharing) programs (BitTorrent, EDonkey, Limewire, etc) In addition to tying up your companies bandwidth, you could expose your bank to lawsuits for copyrighted material on your work computer. The penalty for possessing copyrighted materials is up to $125,000 per incident (read this as per FILE!). Also these programs often share out your hard drive without your knowledge so other downloaders can get what you have, opening up your computer and network to attack. Finally, many of have been reported to have numerous security flaws and holes allowing remote attack. 3. Music or Movie Download sites Similar to the comments above, the materials on these sites are often copyrighted and posted without the owners consent. Additionally these sites are often rife with spyware and pop-up adds. 4. Free Software or Game sites Same comments as above. Unless it’s the manufacturer's site (like Microsoft) or a legitimate reseller (like Newegg), don’t go there to download software. Claims of a FREE Antivirus or Anti-spyware program are often spyware themselves. Do not load any programs off the web without the consent of your network administrator. 5. Online Gaming Sites Gambling sites present as special problem for employers and employees alike since it is usually against federal law to use such sites. Some sites have been raided and they have traced bets back to individual bettors. Also such sites are often run from overseas by less than scrupulous individuals. 6. Webpage profile sites such as Myspace and Facebook You have probably heard the news stories about pedophiles and other criminals that prey on children (and adults) on these sites. Identity thieves have now figured out that they can use such profiles to “case” individuals for “social engineering” attacks. They submit random requests to become your “friend’ or be added to your site and then collect personal data. They are a gold mine for such criminals, often containing birthdays, family member or friend names, addresses or other personal information. System administrators, company execs, or people in valuable or high profile positions are particularly sought out. 7. Personals sites such as Match.com, e-harmony.com Using online personal sites has become the new way to date in the 21st century. While there are some benefits to these sites (allowing busy professionals or particularly shy people meet mates), there are also dangers. Again, having your personal information available for review by anonymous browsers can be a lure for identity thieves who often attempt to develop a rapport or friendship with their marks by appearing to know their social circle. Also, posters to such sites often misrepresent themselves in minor or even major ways. A recent study of one of the major dating sites found that over 30% of the applicants were already married. 8. Chat programs While it can be fun to chat or IM with people all around the world, keep in mind that using such programs at work can be a security risk as well as a productivity drain. These programs often have flaws that allow for files to be downloaded off your computer and some of them even allow remote control of your computer. 9. Freemail sites such as hotmail, yahoo mail or gmail. Many people use these free services as their primary or secondary email source. However, they should never be used for work purposes or especially not sensitive company business. The email is unsecured as it passes over the Internet, opening up your correspondence to eavesdroppers. Also, these sites are notoriously insecure and cracking into someone’s hotmail or gmail is a trivial task for any neophyte hacker. Because almost all of the sites allow for password resetting by email, hackers can request a password reset and then intercept the response or just guess your challenge questions which are often easy to discern via public information searches. Freemail sites are not held to the same security standard as your IT systems so you should not use them from work computers. 10. Streaming Audio or Video. Watching CNN or ESPN via the Net can be a great way to get news right away or catch that game while you work. And while watching major, reputable sites is a not a danger other than being a productivity and bandwidth drain, some of the lesser sites (such as youtube.com) can have copyrighted and/or obscene materials on them without warning. Remember you can be held liable for anything downloaded or watched on your computer so think before you click.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
CES 2009: Ballmer Announces Windows 7, Windows Live, Live Search Milestones

During his first-ever Consumer Electronics Show (CES) 2009 keynote address last night in Las Vegas, Microsoft CEO Steve Ballmer announced the pending public availability of a feature-complete Windows 7, the final version of Windows Live Essentials, and ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

Where is Microsoft NetMeeting in Windows XP?

...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events Security Summit

Virtualization Forum: Optimizing Storage, Networks, Desktops, and Security

Cloud Computing Forum: Integrating Software, Server and Storage as a Service into Your Enterprise IT Delivery Model

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2009 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing