segunda-feira, 28 de outubro de 2013

Última hora: Resultados Parciais das Jornadas Conjuntas!

Até ao momento, eis os resultados parciais "oficiaiszitos" das Jornadas Conjuntas Parlamentares PSD/CDS-PP (mas que podiam ser do PS, PCP ou do Bloco, ou de outra liga qualquer):


Clube Desportivo Portugalito 0 - Porta dos Credores FC 2 (Resultado ao intervalo!);

Séculos de Existência AD (Agremiação Desportiva) 0 - Sistemas Partidários Unidos 5;

OE 2014 AR (Associação Recreativa) 7 - PIB B 0 (Equipa da segunda liga!);

Economia Sport 0 - Justiça Social FC 0 (Jogo interrompido por causa do mau tempo!);

Deport Irrevogável 0 - Vice-Primeiro-Ministro 4 (Foram registadas altercações entre os adeptos das duas equipas durante o desafio, ninguém foi identificado!);

Troika FC 5 - FMI 4 (Ou Troika FC 4 - FMI 5; ou ainda Troika FC 7,508 - FMI 7,324; talvez até Troika FC 4,239 - FMI 5,358; ninguém pode informar este resultado com certeza devido a flutuações na transmissão do encontro!)

PAF Sport (Programa de Assistência Financeira) 10 - Soberania AD 0;

Envelope Financeiro FC 5 - Agenda Partidária Portuguesa 0;

Patrões IQSADC (Imorais que se aproveitam da crise) 18 - Desempregados SA (Sem alternativa) 0;

Classe Média FC 0 - Protegidos S&A (Sistema e Associados) 6;



Estamos perto do FIM DA LIGA e ainda não se perfilam candidatos convincentes ao título!
Há fortes suspeitas de resultados combinados!
Confirmação de resultados e próximas jornadas, dentro de momentos...


Zeca









quarta-feira, 7 de agosto de 2013

Delato à ZON de uma fraude!

Aqui fica a cópia do correio electrónico que enviei à citada empresa:

Bom dia!

Venho por este meio apresentar a minha reclamação formal no que concerne ao facto de me enviarem a V/ fatura com o que eu considero “marketing agressivo” na primeira página, que pode ser considerado como fraude, facto pelo qual, envio esta comunicação para o V. endereço electrónico “fraude@zon.pt que solicita o envio de qualquer informação que o cliente possua, que diga respeito ao tema.

Compreendo que a liga inglesa seja motivo de aderência a um canal que além de gerar conflitos de interesse (é posse de um dos pseudo-concorrentes ao título da nossa Liga) possui parca ou nula conveniência na restante programação, mas enviar uma fatura, que por si só, é já uma correspondência indesejada, com a foto de um rapaz novo envergando a camisola desse pseudo-concorrente, com as quinas de campeão no braço é, no mínimo, publicidade enganosa! Ou o V/ departamento de Marketing está deveras desatualizado, ou conta simplesmente com a ignorância do comum membro da sociedade portuguesa (estarão V. Exas. a passar um atestado de burrice aos portugueses?).

Mesmo, creio eu, um adepto do clube proprietário do referido canal, que compreenda infimamente de desporto, vislumbrará que tirando 4 ou 5 estádios em Portugal, o apelo da Liga Zon Sagres, estará no consumível alcoólico que lhe dá nome (questão esta, igualmente muito discutível!) e que o “muito mais” apenas emprestará um sonífero potente a quem sofre de insónias!

Felizmente, graças à sapiência de familiares e dos meus progenitores, não sou adepto do clube proprietário do referido canal, mas desenganem-se V. Exas. se acreditam que a minha indignação é fruto de cultura desportiva minada por fanatismo de cor ou exacerbação emocional de ganhador, trata-se tão-somente, de um direito de consumidor que paga atempadamente as suas faturas, no que concerne ao facto de ser “brindado”, no ato final de consumo, reitero, com publicidade enganosa, vulgo fraude. Não bastará já, a restante oferta televisiva com formatos de manipulação e de direcionamento de pensamentos de massa?

Acreditem que para os milhões (???) de adeptos do clube proprietário do referido canal, que sejam V. assinantes e que ainda possuam neurónios funcionais, a prioridade estará em conseguir pagar as restantes faturas, para além da Vossa, que recebem ao fim do mês, e viver na ilusão de conseguirem esticar o dinheiro até essa data, não precisam de mais ilusões!

Peço então, encarecidamente, que não sejam mais uma instituição que pratica a publicidade enganosa, que almeja o lucro fácil, que deseja formatar pensamentos e que se queira equiparar ao clube proprietário do referido canal, vulgo fraude.

Na eventualidade de acharem, por motivos comerciais, que a aposta é pelo menos digna, ficam aqui alguns conselhos de marketing menos agressivo e mais realista que podem utilizar e aos quais não oporei nenhuma objeção:

“Benfica TV, adira já! O sonho comanda a vida!”

“Benfica TV, adira a um canal que lhe confere alegrias extremas duas vezes por década!”

“Benfica TV, adira a um canal em consonância com a economia do país, estagnado!”

"Benfica TV, já que a informação a que tem acesso diariamente é regulada e manipulada, pelo menos aqui, vai de encontro à sua opinião!”

“Benfica TV, esqueça a crise e chore as derrotas do seu clube. Aqui a tristeza não é condicionada!”

“Benfica TV, possua em sua casa, em horário nobre, algo que rivaliza com os telejornais em matéria de deceção!”

“Benfica TV, se já sofre há três anos, porque não pelo menos mais um?”

“Benfica TV, o ano passado foi quase, este ano, não enganaremos ninguém!”

“Benfica TV, pela Liga Inglesa vale a pena!”

“Benfica TV, pode ser triste, mas pelo menos descansa da crise!”


Agradeço, desde já, toda a atenção dispensada e aguardo mais criatividade na V. próxima fatura!
MCpts.,


Zeca


sábado, 3 de agosto de 2013

My latest cover letter to a job application!

Hi, my name is, well... read the form! 
But I'm usually known by Charlie. 

Throughout a varied career and versatile features, I’ve acquired skills of adaptability that allowed me to adjust myself to unexpected situations and changes in methods, tools and contacts.
I welcome new ideas positively, and in that sense, I'm convinced I will bring more value to your business. I'm sure my personal style, dynamic, autonomous, responsible and outrageously creative, meets the job requirements.

(The two above paragraphs are from my original cover letter! Well, almost.)

I'm always in a good mood, except in the long period of times I'm not. My friends say I must have some kind of extra human battery cells and that I'm always fully charged. My record on "speaking without ending" is 48 hours, including two lunches and two dinners (I’ve skipped breakfast twice!) I truly enjoy communicating and making people laugh, although most of my jokes are entirely incomprehensive to normal human beings because of the high level of intelligence needed to understand them, and, unfortunately, my dearest friends are slow thinkers... 

I'm proactive and a team worker and I love to travel and meet other cultures and ladies. 

My career has been based in office jobs (with a lot of outdoor activities) and part-time jobs in witch (with a broom!) I’ve tried to sell important consumption items to people who were not in any need of the kind of important consumption items I was selling! I also love to write and allow myself to travel to the darkest places in my brain, searching for that degree of insanity that permits me to be one step (maybe one and a half!) beyond the common stupid-fuck.

I’ve know realized that I’ve written the word “fuck”. Normally it’s a word we shouldn’t say but as I’m writing if you don’t appreciate it, you can substitute it for a noisy sharp ‘beep’ and it will pass undetected. 

I’m a very polite person. 

I also mingle along greatly in any kind of event of any kind of organization or even in lower social classes’ gatherings, such as VIPs parties. I don’t remind myself of having any issues with anyone I’ve ever worked with, I’ve always get along fine with everybody, although some professionals I’ve met in my life can´t say the same. I always fulfilled the professional objectives given to me and passed them exceptionally, which sometimes led me to do my boss’s work…

I’m a experienced person in what concerns to living (I’m 39 years old) and I have no idea what so ever of what life’s all about, so I clearly think I’m eligible for the post!

Anything else you'd like to know, don't hesitate, and give me a call!

Yours truly,

Charlie (aka Zeca).


terça-feira, 30 de julho de 2013

Phishing - Solution Approaches!

"There are essentially two major ways to defend against social engineering scams, in order to protect your company and its employees. One is training your users, and the other is technical security controls. We believe you have to implement a combination of both user training and technical controls to be successful. Relying on just one approach or the other will probably not decrease your risk to an acceptable level.

Nearly 60% of employees receive phishing emails every day, so clearly technical controls are failing to stop many of these messages as they pass through the system. Often, the technical controls are working, but spearphishers continue to change their tactics to cope with the ever-improving technologies. Therefore, the user can be both the weakest point and the strongest resource in the defense of corporate networks. With the proper user training, you can turn the weak link into a protector of your organization.

Security Awareness Training
Security awareness training helps you educate your employees to stop risky activities such as clicking on a link in a questionable email, opening an attachment they are not expecting, or submitting something on a bogus forum.
Here are 15 good defenses to teach your company’s employees:

1.     Don’t trust links in an email.
2.     Never give out personal information upon email request.
3.     Look carefully at the web address; it could be a close approximation of the real URL.
4.     Type the real website address into a web browser.
5.     Don’t call company phone numbers listed in emails or instant messages; check a reliable source such as a phone book or credit card statement.
6.     Don’t open unexpected attachments or instant message download links.
7.     Be suspicious if emails says “do X or something bad will happen”.
8.     Be suspicious of any email with urgent requests for personal financial information.
9.     If the email sounds too good to be true, it probably is.
10.  Always ensure that you’re using a secure website when submitting credit card or other sensitive information via your web browser; look for the https:// and/or the security lock icon.
11.   Regularly log into your online accounts and check your bank, credit and debit card statements to ensure that all transactions are legitimate.
12.   Use a reputable anti-virus program.
13.   Enable two-factor authentication whenever possible. This combines something the user knows (such as a password or PIN) with something the user has (such as a smart card or token) or even something the user is (such as a biometric characteristic like a fingerprint).
14.   Keep your operating system updated, ensure that your browser is up to date and security patches are applied.
15.   Always report “phishing” or “spoofed” e-mails to your IT department.

Through this kind of security awareness training, you turn each one of your employees into security sensors in your organization. So, there are actually people who can now spot a phishing campaign and can alert security so that they can react. This type of threat might have otherwise have flown under the radar of security.

Technical Security Controls
Of course, training needs to be coupled with technical security controls. These technical controls will prevent or block many of the threats so that they never reach your users. We’ll take a look at some of the different types of controls and how they work.
Vulnerability management is your number one defense against attackers. It identifies existing vulnerabilities in software programs, browsers and plug-ins and helps shield your organization from potential damage, as well as mitigate vulnerabilities through patching, changing configurations or making application updates to remove vulnerable code. Programs like Microsoft Office and Adobe Reader are the typical applications that get exploited through phishing, so it is important to stay on top of any vulnerabilities associated with these programs. You also need to make sure your vulnerability management program is maintained and monitored over time. The keys to vulnerability management are to get visibility on client-side vulnerabilities, focus on solutions that highlight vulnerabilities exploited by malware kits, as well as validate and prioritize vulnerabilities to identify high-risk issues that must be fixed immediately.
Patch management is used to fix vulnerabilities based on input from vulnerability management. Some fixes are implemented through patching and some are through changing configurations. Software updates and security updates need to be done in a timely manner to keep up with patching vulnerabilities.

Malicious URL and attachment blocking can be done with web filters and SPAM filters. Microsoft Outlook has incorporated a good filter that will put emails into the junk folder if they contain a suspicious link – for example, a link that doesn’t have a domain name but only an IP address. Outlook will automatically put that email into the junk folder or it won’t let you click on the link until you confirm that it’s okay. (Of course, you need to train employees that these emails have been placed in the junk folder for a reason!) There are also web filters that you install at the Internet gateway of your company that will block malicious URLs.
Intrusion Prevention System (IPS) is another form of defense. If, for some reason, a user does click on a suspicious link, and a website is serving up a browser exploit, an IPS can detect that and block web-based exploitation.
Data Loss Prevention (DLP) / Egress filtering is a system designed to detect a potential data breach and prevent it by monitoring, detecting and blocking sensitive data while in use, traveling over the network or in storage. Let’s assume that your network has been compromised and that somebody’s inside the organization to actually complete the action. They haven’t reached their goal until they’ve actually downloaded the sensitive information, so, DLP and egress filtering is all about stopping that sensitive data from getting out of the network.

Disabling Java may be a drastic approach to security but Java has been a huge attack vector for compromising systems via malicious links in phishing emails. If you are using critical applications running on browser-based Java, or if your users need Java to get their jobs done, you may want to configure the browser to prompt and ask for permission before launching Java and educate your users to only allow Java on websites they trust."

By, Rapid7


Social Engineering Attacks Beyond Phishing Emails!

"Social engineering can also be used to launch other types of attacks as well. Some are web-based, others are more low-tech, but they are still quite effective because they take advantage of human nature.
Drive-by attacks exploit vulnerabilities in web browsers or plug-ins. Often they use a popular topic, such as celebrity gossip, and optimize a malicious website to rank highly in search engines for that news. When the user finds the site and clicks on it, their machine gets compromised. This is an untargeted attack, but when it compromises employees, it can still put company data at risk.
USB drives can be used by attackers to gain access into a network. The same file format exploit or executable exploit that is put into an email by an attacker can also put on a USB thumb drive or a CD ROM. A tactic would be to give the file an enticing name, such as “management salaries” or “layoff list” and then perhaps attach the USB drive to a couple of keys and drop it in the parking lot outside the company that the attackers want to intrude. Then, if an employee walks by and sees it, they would naturally pick this up. People want to be good citizens, return the key and the USB drive. To find the owner’s identity, they may plug the USB drive into their computer. When they see the enticing content, they double click on it, infecting their machine and opening up the corporate network to attackers.

Physical or in-person attacks rely on someone walking into a building, under a false pretense such as a package delivery, to get access to the building. They can also use a “tailgating” strategy to follow an authorized person into an off-limits area. Once they have physical access, they can plug a little device into the network to compromise it by phoning home to an attacker’s server.
Phone calls are another way that an attacker may trick users into handing over their credentials. They may use a ruse such as: “I’m Bob from the IT department; I’m seeing on our systems that your computer has been a little slow lately. Do you have time to sort that out right now?” They then walk you through a few steps, maybe they’ll send you to a malicious website, or maybe they will ask you to give them your credentials. Since the user believes it’s a helpful person from the IT department, many fall for this scam.
QR codes, the square 2D barcodes, are being used in marketing campaigns and could also be used as an attack vector as well. When scanned with a smartphone, the QR code sends the user to a website which could be malicious.

Social media including Facebook, LinkedIn, Twitter and other social media sites, can be used to send posts, updates, tweets or direct messages with URLs. When the link is clicked on, again victims are sent to malicious sites and their computers are compromised. With Facebook, user’s accounts can be attacked and then configured to send messages to their friends, which may entice people to click on something they normally wouldn’t.
Typical Steps of a Phishing Attack
In most phishing attacks, the user opens an email, and then clicks on a link in that email. This results in the user’s browser getting exploited. Maybe there is also a form on the web page that captures the users credentials as they are typed in. Alternately, the user could open an email attachment and their machine gets compromised that way."

By, Rapid7


Breaches Often Start With Phishing!

"Most of today’s data breaches start with a phishing email, giving company-confidential data to malicious outsiders. This is a real problem that companies need to address.
Phishing attacks are the most frequently used form of social engineering. They work because they take advantage of cognitive biases, or how people make decisions. These techniques prey on human emotion by appealing to greed, curiosity, anxiety or trust.

Phishing means that attackers are fishing for your private information. Attackers attempt to acquire information such as usernames, passwords, and credit card details by masquerading as a trustworthy entity in an electronic communication. Many times this is done to steal a victim’s login credentials and other confidential information. Phishing continues to grow and become more widespread with attacks up 37% year over year, and 1 in every 300 emails on the web containing elements pointing to phishing.
Phishing attacks can result in compromised client systems. Here are some different consequences of phishing that can impact your network:

Browser exploitation - Browsers and their plug-ins contain vulnerabilities that can be exploited simply by visiting a malicious website. An attacker can send an email with a link, which brings the user to a malicious website (which is often designed to look like a legitimate site.) Just by visiting that site the user’s browser and machine would be compromised and the attacker would have full access to the user’s computer. In addition, a completely legitimate website can be attacked to become malicious. So a user could be browsing a legitimate website that’s been attacked on the back end and injected with malicious code, which then exploits their browser.
File format exploitation – Opening a malicious email attachment is another way to trick users. Attachments are typically PDFs or Office files because those applications are widely distributed and widely used across platforms, and the chance that the recipient can read that kind of file is higher. Once the malicious attachment is opened it exploits vulnerabilities in a given application.
Executable exploitation – This exploit uses another form of email attachment, an executable file (ending in .exe) that runs when the user clicks on it. It is programmed to operate without needing a vulnerability in the program. Although .exe files are quite often blocked by email security features, there are other types of executables. For example, JAR (Java Archive) files end in .jar, rather than .exe, but they can still execute a malicious file when you double click on them." 
By, Rapid7


quinta-feira, 25 de julho de 2013

Mobile Device Management

“Simplified IT administration.

IT is already overburdened with provisioning, maintenance and support responsibilities. BYOD* shouldn’t increase user productivity at the cost of IT’s. Simplified IT administration is critical, and this is where you will see the most variation when evaluating MDM solutions.

There are several ways that MDM solutions can simplify administration. Over-the-air (OTA) administration and management allows the IT organization to maintain mobile devices anytime, anywhere, so users don’t have to visit the help desk. Initial setup and configuration can also be done over the air. You should also be able to automatically assign devices to existing groups from your user directory and apply the respective policies when they are registered via a self-service portal.

Centralized monitoring and control of all registered devices is a hallmark of MDM, but the ease of use and granularity of functions differ from one solution to another. Look for an MDM solution that allows you to manage all supported smartphones and tablets from one console, regardless of the operating system, service provider, network or location of the device.

If you are also using BlackBerrys, it makes sense to bring them into your MDM solution so you have the full inventory overview in one place. You should be able to track and report on all registered devices, and drill down to individual configuration settings, serial numbers, model numbers, hardware details and installed applications. A dashboard view can quickly show registered devices and whether or not they’re compliant with policies. Auditing allows you to easily track changes to devices and compliance status.

Graphical reports should provide the most important data at a glance. For example, charts should show the percentage of compliant vs. noncompliant devices, managed vs. non-managed devices, corporate-owned vs. employee-owned devices, etc., rather than require you to navigate through numerous menus to find the information.

Finally, the administrative interface should be action-oriented and easy to use. Consider how many clicks are required to perform basic functions like decommissioning a device, viewing device OS distribution, and defining the OS versions supported in the app. One or two clicks maximum should be all it takes to complete these tasks.”

By, Shopos Mobile Control.

  

*Bring your own device (BYOD) (also called bring your own technology (BYOT), bring your own phone (BYOP), and bring your own PC (BYOPC)) means the policy of permitting employees to bring personally owned mobile devices (laptops, tablets, and smart phones) to their workplace, and use those devices to access privileged company information and applications.