Category Archives: Antivirus Vendors

Antivirus Vendors

The 3 most common questions about Clickjacking

This procedure is called Clickjacking and it is one of the most used techniques by hackers trying to gain access over your accounts or obtain private data.

How does clickjacking work?

It all starts with a user receiving an e-mail that mimics perfectly the messages usually sent by a company he is a client of. This e-mail would have to include a fake link for the user to reset the password used on the real company website when he would actually be providing the hackers access to his account. Knowing both the e-mail address and the associated password, they can now extract all the personal information they need and take over the specific account.

Practically, once the customer clicks on the button in the e-mail, he will end up on the hacker’s website. There, the latter will attempt to make an http/https call to the real company’s API’s/forms to reset the user’s password/e-mail address and take over his account.

When does clickjacking this work?

In order for clickjacking to work, the user had to be previously logged in the account that he owns on the real company website. Also, if no CSRF protection is activated on the company’s end and official website/API accepts calls from other domains with no filtering, chances are that the operation becomes successful.

Clickjacking can also work locally (on your machine) when you manually create an iFrame and inject the company’s forms. This however doesn’t impact the end user/ customer because it only takes place on the hacker’s computer.

How can I be sure that I am not a victim of clickjacking?

We recommend all companies to implement the 2 following methods to keep safe from this kind of attacks:

  1. Do not accept requests from other websites (domains). If possible, use the x-frame-options header and set it to SAMEORIGIN so that other domains cannot access the methods/ API on your company’s end (this header should not be accessible / usable in all browsers).
  2. Implement CSRF token validation making sure that for each form display page there is an uniquely assigned CSRF token to the customer. The CSRF token can only be obtained by logging in as the real customer.

The post The 3 most common questions about Clickjacking appeared first on Avira Blog.

How to boost security on your Facebook account with two-step verification

two-step-verification-facebook

No doubt you’ve heard about two-step verification used on various social networks.

Having this option enabled lets you increase security on your account and helps prevent unauthorized and potentially malicious access.

In the case of Facebook, the process is simple, and all you need is your cell phone handy to confirm access from a new device. In Facebook, a new device is one that you haven’t used previously to connect to the platform.

This way, what you have to do is approve logins to prevent others from accessing your account.

Here we explain step-by-step how to enable login approvals.

How to boost security on your Facebook account with two-step verification

In your Facebook account, go to Settings.

facebook-settings

Go into Account Settings and select Security. There you will see “Login Approvals”.

facebook-login

From there click “Require a security code to access my account from unknown browsers”.

facebook-login-approvals

facebook-security-code

When you enter the code that they send to your phone, you will have to enter your Facebook account password.

facebook-password

Now you have enabled login approvals.

facebook-complete

Facebook also gives you the option to print security codes in case at some time you don’t have your phone handy. It’s easy, right?

The post How to boost security on your Facebook account with two-step verification appeared first on MediaCenter Panda Security.

Avira HR Team @Top Employers Job Fair

Software engineering: from everyday challenges to real world solutions

The second day of event, our colleague Radu Calin (Web Backend Software Engineer) gave a presentation about Distributed computing during the workshop we organized. We were happy to learn that this session raised unexpected interest among the candidates attending the fair: more than 120 people had registered for what we designed as a workshop with 40 participants.

Radu talked about how we managed to build a product that makes life easier for millions of users worldwide, all the while solving some of the most difficult problems of the cloud era. He went more in-depth, showing the attendees how the Avira team managed to create a scalable distributed system with pure fun and passionate engineering. Towards the end, he did not forget to give some details about what makes “life at Avira” so special and the audience was really impressed.

All in all, the event was a great success for our HR team:  2 days, over 500 applicants, almost 1400 flyers taken home by the candidates, 1 workshop with 58 participants, and over 5000 participants to attend the fair in search of their next Top Employers.

If you missed the event but you also want to” join the battle”, you can also check the current job opportunities and apply directly on our career page. A virtual job fair is also organized to follow up with Top Employers attendees, check it out here.

The post Avira HR Team @Top Employers Job Fair appeared first on Avira Blog.