Zero-Day Attack

~~Recently, there’s been news that Microsoft has found out that there have been zero-day attacks focused on a vulnerability on Microsoft Word 2010. It was originally spotted in Word 2010, but it also affects other versions, like Word 2003, 2007, 2013, 2013RT, Office for Mac, and Web apps. This happens when an attacker uses a malicious RTF file (or email in Outlook) configured to open with Microsoft Word as the email viewer. Because Word is set to be the default email viewer in Office 2007 through 2013, these are the most likely vulnerable to this threat. Microsoft has not released a path addressing this issue yet, but it has plans to do so by April 8th, which happens to coincide with the last day that they will be supporting Windows XP and Office 2003. Until then, there is a fix-it in their knowledge base, which they recommend people use until the patch is released. What the fix says is to disable opening RTF files with Word. Wikipedia defines the term Zero-day attack as an “attack or threat…that exploits a previously unknown vulnerability in a computer application, one that developers have had no time to address and patch.” In this case, Microsoft found out that this vulnerability was being exploited when it was reported by Office users, which means that Microsoft had no idea of this vulnerability until it was brought to their attention by users who had been already hacked. This exploit allows the hacker to have the same rights as the current user, meaning that if the user is logged in as an administrator, they hacker will have administrator’s rights as well. The attacker can then do as he/she pleases, delete data, uninstall programs, and even create other user accounts, without you knowing until it’s too late. Although there is no patch for this exploit yet, it is important to keep up with news regarding computer security and to apply any fixes regarding this vulnerability and to keep checking updates for all your computer software. If you don’t want to be vulnerable to such attacks, please contact us right away. TRA consulting is an IT Consulting company that supports Long Beach, OC, and the Greater LA Area. We can help you keep your computer and network safe from intrusion. With our many years of experience in computer repair and pc security, you can be sure that your personal data is secure and that your computer will run optimally. TRA consulting not only focuses on Home Personal security, but also in SOHO (Small Office/Home Office) security. Our goal is to provide full IT support to growing small businesses who are too small to have a full time IT staff, yet big enough that they need one. We have many highly satisfied customers in the Long Beach, Orange County, Southbay, and Los Angeles area. Contact us today, and let us take care of all of your computer security needs. Our prices are reasonable and our services are top notch.

Security, Security, Security

~~When was the last time that someone said “I hope my network gets attacked by a hacker today”? Unless you have a honeypot, no one is looking forward for that to happen. Unfortunately, there are many people and businesses who not only are not equipped to prevent an intrusion in their systems, but worse yet, they also have no way to detect if their network’s been breached or if their systems have been hacked until it is too late. Taking initiative in your pc and network security is an underrated method to prevent not only loss and compromise of your data, but also saves you the time and headache to try to get yourself back to where you were before. At TRA consulting, our philosophy is to get your network and systems secured so that you don’t have to experience this situation. If you’ve unfortunately have been a victim of hacking, we can help you get peace of mind by securing your network, computers, and data. TRA Consulting has been servicing the Long Beach area, Southbay, Orange County, and the Greater Los Angeles area for years, and we won’t rest until you can fall asleep at night knowing that your data is safe and secure Cyber-threats come in different shapes and sizes. For example, the stealing of sensitive data from Target servers, in which millions of customer’s credit card information was compromised, was the biggest cyber hacking event in recent memory. The reason why this hit home for a lot of people was because, well, everyone shops at Target. Hearing that hackers made out with millions of people’s sensitive credit card information from the place you did your X-mas shopping, makes you feel vulnerable as when you first found out that that a Russian hacker got your PayPal password and they used it to send themselves $400 worth of clothing.  Yes, that happened to me. Thankfully Paypal refunded me the money this hacker took from my account within a few days. However, dealing with credit card companies and banks regarding money stolen from your credit card and bank account is a much bigger headache. In an age where online banking is ubiquitous, taking care of your sensitive financial information is of the utmost importance. The target breach taught us that there is some things that are out of our control, but at the same time showed us that sometimes its human lack of foresight that puts data in jeopardy. Taking initiative in securing your personal computer can reap many benefits in the long run. Hindsight may be 20/20, but foresight, especially regarding your computer security, can be a big money saver. Contact us today, and let us take care of your home/office security. Our years of experience and competitive prices makes us one of the best IT consulting companies based in the Long Beach area. We also serve the Orange County, Southbay, and Greater Los Angeles Area. Our years of computer experience can help you fix almost an problem you have at a reasonable price. Contact us today. v

Time For An Upgrade

~~As April 8th draws near, there are still many people and companies still using Window XP on their PC’s. If for some reason, you are not aware, Microsoft is going to pull the plug on Windows XP support, meaning that starting on April 9th there won’t be any new windows updates for it. There are two main reasons why you need to upgrade to Windows 7 or Windows 8 by April 8th. Hackers have been aware of this date since Microsoft announced it. They know how popular XP is still around the country and around the globe, especially in developing countries like China, India, and Taiwan. After April 8th, hackers may use vulnerabilities that they have found in Windows XP, but have not yet been disclosed, to attack the computers that have not upgraded. Another reason for concern is that there will be new vulnerabilities found in windows XP that Microsoft won’t be patching. Even patches that Microsoft releases for Windows 7 and 8/8.1 can make Windows XP more vulnerable. Hackers can use those patches to figure out what vulnerability they are addressing, and then use that knowledge to try to exploit a similar vulnerability in windows XP, if it exists. This means that the longer you have the 12 year old OS in your computer, the more vulnerable you become and the more likely you are to become a victim of one of the many forms of cybercrime. If you don’t want to be vulnerable to such attacks, please contact us right away. TRA consulting is an IT Consulting company that supports Long Beach, OC, and the Greater LA Area. We can help you upgrade your PC’s to a new operation system at a very reasonable price. Recently there was an article that stated Microsoft has been helping the government shift away from Windows XP to Windows 7, and that only 10% of their computers are still running XP. They hope to get the last remaining computers upgrades in the next few months. However, banks are having a more difficult time moving their computers towards windows 7, especially their ATM’s. Just earlier this month, there was a figure on a CNN money article that up to 95% of bank ATM’s are still running windows XP and it doesn’t look like they will be able to make the April deadline. However, banks like JP Morgan have bought a one year extension of service and plan to move all of their ATM’s to Windows 7 as early as July. What about the average person, or Small Office? Well, TRA Consulting is here for you. We are an IT Consulting and Computer repair company in Long Beach, and we also service the Greater LA Area, Orange County and the Southbay. Not only can we help you migrate away from Windows XP, but also help you with the overall security of your system and network. Like the saying goes, an ounce of prevention is worth a pound of cure. And at TRA Consulting, we specialize in getting you that ounce of prevention at the best price possible.

Rethinking Security

~~There have been a number of news stories in recent months that highlight a pattern of computer and internet security issues that has slowly emerged as more and more companies rely on internet connections and networks to complete transactions and store customer data. Most of these problems were reported as a single flaw in one layer of security, but the more investigators probed the security breaches and their causes, the more they found that the problems existed in several layers of the security systems that were in place. Though there have been several stories of data being leaked, today we will focus on Target’s breach in network security. By now, most people have heard of, or been a victim of, the Target point-of-sale breach which happened last November and December over the course of a month and a half in 2013. This breach harvested credit card information from Target’s point-of-sale card swipe machines at their brick and mortar stores and sent that information to hackers. Hackers did this by infecting their POS systems with malware. Though Target had anti-malware data leak prevention software installed on their systems, for some reason, the program did not catch the malware, thereby allowing it to infect Targets credit card machines. But there were more layers of security that were compromised that made it easier for the hackers to get into Target’s system. Investigators believe that the breach was first made through a third-party contractor – possibly maintenance staff – who had remote access to Target’s computer systems. These contractors probably had their own security issues that Target did not check into properly, and thus this third party contractor was more vulnerable to hacking, thus making Target more susceptible. There was no two-factor authentication system in place to make sure it was the third party company logging in and not imposters. Another layer of security that was compromised was the lack of proper segregation in Target’s networks. The third-party contractor, that investigators believe was the point of entry into Target’s systems by hackers, had access to heating and cooling systems, but that also gave the hackers access to the systems handling credit card payments. To make matters worse, Target was warned of these flaws in its security, and the warnings did not get to the right personnel who could have corrected the matter. The failure of communication resulted in a failure of another layer of their security. It’s easy to see in hind-sight how the different layers of security failed to work together to prevent the infamous breach of Target’s credit card systems. Proper lines of communication and chain of command within the IT branch of Target in addition to proper vetting and over-sight given to third-party contractors, separating the less sensitive networks from the more sensitive credit card point-of-sale networks, and keeping malware up to date and working seamlessly with the other layers of security would have helped to prevent hackers from obtaining sensitive credit card information. TRA Consulting, Inc., in Long Beach can help your business avoid problems like Target’s by working with you to find security solutions for all your computer networks and systems. We can consult with you to help your business expand its layers of security and to make sure they are all working together seamlessly.

Microsoft’s New Office Online

~~Microsoft recently rebranded and re-launched its online version of Microsoft Office, Office Online. Since 2010, the online version of Office was called Microsoft Office Web Apps, but this name created quite a lot of confusion for users who wondered whether this was a downloadable program or an app from an app store. Actually, it is neither one of those things. Instead, Office Online, as Office Web Apps is now called uses cloud computing and cloud storage to power the online version of its Word, Excel, PowerPoint and OneNote. The online versions of these programs do have fewer features and options when compared with the complete Microsoft Office software package that you install onto your computer. But these lighter versions offered by Office Online offer some capabilities and perks not available through the full Microsoft Office program. While many businesses may find it the most worthwhile to stick with the full and complete version of Microsoft Office for their workers’ computer stations, many small and medium-sized businesses, like the ones served by TRA Consulting, Inc. in Long Beach, might benefit from offering Office Online to their employees instead of the full Office version. One reason is that workers can access their documents from any computer anywhere, making documents easier to complete and access, especially when a deadline is looming. Another reason businesses might find this computing solution attractive for their offices is the cost. Microsoft has been touting a subscription-based method of payment in the last couple of years, citing that this mode is much cheaper than buying the full, downloadable versions of Microsoft Office. By paying for the online subscription, businesses can reduce software costs and save workers time and productivity by making documents and spread sheets available online and accessible twenty four hours a day, seven days a week. Another attractive feature of the newly updated Office Online is real-time co-editing. Microsoft added this feature last November. This would allow workers to collaborate on documents from any computer in any location. In addition to real time co-editing, they also added other enhancements, including the ability to switch more easily between different apps such as from Word to Excel and back, and they also added a library of ready-to-use templates. These apps are linked to SharePoint which is Microsoft’s collaboration platform where there is a central hub for accessing, storing and sharing documents created in Office Online. Microsoft has been trying to up its game in the cloud computing arena to compete with Google’s suite of online products for individuals as well as its subscription service for business users. Part of the reason for the rebranding was to alleviate confusion and to make Office Online easier to find and access.  Whether you want to buy the traditional desktop-installed version of Microsoft Office, subscribe to Office Online, or use another program entirely, let TRA Consulting, Inc. help you find a cost-effective and convenient word processing and document-creation software or cloud-supported solution for your small or medium-sized business.

California’s Drought and How Computers and the Internet are Helping Us Find Solutions

~~We here at TRA Consulting, Inc. in Long Beach have been hearing, reading, and seeing quite a number of news stories about California’s latest water crisis. Experts say this has been the worst drought in more than 100 years and that it looks like it will be continuing for the foreseeable future. But there are a number of resources available these days that we did not have the last time drought reared its ugly head. Chief among them is our ability to use new technologies to help us solve the problems associated with this drought. The last time there was a major drought in the late 1980s and early 1990s, we did not have the some of the tools that we can use now. There are a number of agencies and businesses working on this problem. One company called Leak Defense is developing a device for detecting water leaks in the home that will be similar to a smoke detector. The device can be installed by home owners and will use the home’s Wi-Fi system to alert home owners to potential water leak issues such as a running toilet. The device will be easy to install and require no special knowledge of plumbing. It will attach to the outside of an intake pipe and detect the flow of water. It is sensitive enough to pick up a dripping kitchen faucet, yet calibrated to ignore legitimate water usage like someone taking a shower. Every little bit of water saved from leaky faucets and toilets from homes and businesses across the state really adds up. Another new development is the increasing use of smart water meters in homes, apartment buildings and businesses. These smart water meters can collect quite a lot about specific water usages and times and that information can more easily be reported to researchers who can develop more new technologies to help us conserve water in more effectively. Moreover, that information can be brought to the market where start-up companies can develop new products, like the water leak detector mentioned above, and bring those products to market. Some public utility agencies are using text messaging to spread the word about water conservation to its customers. One Oakland-based agency tried out a pilot program that issued water usage report cards to some of its customers. Through the use of the information they were able to gather using smart water meters and a program developed by the company WaterSmart Software, they were able to show users how and where in their homes water could be conserved and urged them to take action. Reports show that many did take action to conserve more water after being encouraged to do so. The pilot program reported a five percent reduction in water consumption with promising results that it might grow if the program were expanded to more utility users for a longer period of time. The new technologies of software as a service (SaaS), behavioral economics, and big data that have been developed since the last time we had a drought could help us to go a long way towards solving our water shortage issues.

Cloud computing: What is it and how can it help you and your business?

~~Something we hear a lot about lately is “the cloud.” But what is it exactly and why has it become important in both the business and private sectors?  The term is so popular these days that it has become somewhat a cliché. And within that cliché, it has become harder and harder to define this nebulous term that everyone seems to keep flinging around. Some even go as far as defining the cloud as anything outside your firewall. But cloud computing is really more a great way for your business to add computing capacity and capabilities without investing in costly infrastructure and the time it takes to get these physical, site-based systems up and running including training personnel in its use, software licensing. Cloud computing involves subscription or pay-per-use services that can increase your company’s computing capabilities by using the internet. These services usually involve renting out space on a server or remote computer and retrieving the information stored in that space or using that remote system’s computing powers for your business needs. These services include, but are not limited to, applications like word processing and accounting, secure data storage, and spam filtering to name a few. These services are offered through a wide variety of companies, large and small. It can be difficult to know which service, subscription or application is right for you. TRA Consulting, a computer solutions firm based in Long Beach, can help you decide which cloud computing options might work best for your small or medium-sized business and then help you implement those services. But first, let’s discuss the kinds of subscriptions and services that are available to you through cloud computing. Desktop management services are one of the aspects of cloud computing that has been around the longest. This allows updates, software downloads and computer maintenance on your business’ computers to be done from a remote location. Another aspect of cloud computing is software as a service or SaaS. This allows users to access a program or application through the internet which sometimes makes it cheaper than hosting the application on your own local servers and avoiding costly software licensing. SaaS is commonly used for Human Resources apps and ERP (Enterprise Resource Planning, a popular business management software). Online data storage is another aspect of cloud computing, these services are helping to augment datacenters through the use of virtual commodity servers. There are some web services that are also important parts of cloud computing. These web services offer APIs (application programming interface) that allow you to do payroll processing, postal services, credit card processing and mapping all through cloud computing. While the term cloud computing is still a mystery to most and can mean a number of different things to different people, there are many great ways that cloud computing can help you and your business thrive. Contact TRA Consulting, Inc. today to find out how we can help you expand your businesses computing power without much extra cost.

The Hacking Epidemic at the Sochi 2014 Winter Olympics

~~The Sochi 2014 Winter Olympics in Russia are in the final stretch. In just a few days, athletes from around the world will be completing their competitions, attending the closing ceremonies, and heading home. But in the meantime, smart phones, computers and tablets in Sochi have been under near constant attack from hackers since before the games began. As NBC Nightly News reported on February 4th, when athletes, support teams, volunteers, reporters, and spectators began arriving in Sochi, Russia in preparation for the games, they found their electronic devices were quickly threatened.  Most people turn on their cell phones when they get off the airplane upon arriving in a new place. When they get to their hotel, they usually fire-up their laptops or tablets. It seems like a very natural thing to do these days, especially when you want to let loved ones and colleagues know you have arrived safely and catch up on any correspondence you might have missed. But as several news stories have warned, hackers are taking advantage of the huge influx of unwitting Olympic visitors to Sochi to gain as much personal information or other sensitive data from the devices that came into the country with their owners. Phones may be tapped wirelessly and hackers can listen into your conversations, and in many cases smart phones automatically downloaded malware that left it open to other types of cyber attacks. The information gleaned by hackers about visitors then might be used by that hacker for theft, or sold to other criminal enterprises for the purposes of identity theft, or even completely hijack a visitors’ computer, tablet or phone to carry out criminal activities. News sources reporting on the wide-spread hacking in Sochi are reporting that travelers are advised to have no expectation of privacy when they arrive in Sochi. These sources also recommended that travelers remove all sensitive data from smart phones, tablets and computers before leaving home, avoid the public wifi, not use their devices at all, or just leave them at home. Another option might be to buy a new disposable phone once you arrive at your destination for use only in that location. Whether you traveled to Sochi to enjoy the Winter Olympics, or you are an armchair warrior watching from home, it’s smart to think ahead about computer security here at home and for when you travel. As the example from the Sochi Winter Olympics illustrates, traveling has taken on a new dimension in terms of computer safety and security. At TRA Consulting, let us handle the headache for you. We can advise you on the best way to keep your devices safe for your next business trip or vacation. If you have recently returned from travels, we can help with virus removal and protect your computer, tablet, or phone from future threats. We are serving the Long Beach and Greater Los Angeles areas with computer solutions, training, consulting, and virus removal for individuals, small, and medium-sized businesses    

Cyber Attacks on Businesses During the 2014 Sochi Winter Olympics

~~The 2014 Winter Olympics in Sochi Russia are winding down and in a few days, athletes and spectators will be attending the closing ceremonies and hoping flights headed home. Many news outlets have warned since before the games started that individuals traveling to Sochi were at great risk for hacking to their computers, tablets, and mobile devices and that information privacy in Russia would be difficult to come by. But other news sources are also warning that businesses are also vulnerable to cyber criminals during the 2014 Sochi Winter Olympics. And the bad news is that you don’t even have to travel outside of your country of origin to be targeted by hackers that are taking advantage of the excitement around the Winter Olympics. Many computer experts are warning businesses to be vigilant against attacks from the start of the Winter Olympics opening ceremony at the Fisht Olympic Stadium, to the closing ceremonies that will take place on Sunday February 23, 2014. There will be a lot of interest in the games throughout the two and a half weeks they are held and that offers cyber criminals a perfect window of opportunity to target users with phishing attacks by masking emails designed to steal information. These emails are often disguised as updates on the games, sports commentary or other insights about the Winter Games. Hackers will then capitalize on this interest in the Winter Games by using those emails to inject malware, viruses and tracking software, sometimes right onto company servers. Other attacks on computer systems may not have criminal intent, but may be just as difficult to deal with. These would come in the form of cyber attacks from what’s now known as hacktivists. These are activists for social justice issues that use the internet, computers, and hacking to send a message about the social cause they are promoting, but hacktivists can also carry out acts of terrorism in their attempts to express their dissent. And just like the cyber criminals mentioned above, these hacker/activists are attracted to events that garner a lot of public attention because they believe they can get their message out to a wider audience. At TRA Consulting, a busy IT solutions firm serving the Long Beach, Orange County and the Greater Los Angeles area, we can help you protect your business from phishing scams and other hacking activities by making sure your system is secure from top-to-bottom. We offer computing solutions for server and network security, set-up of email filters and firewalls that will help you and your employees save valuable time by ensuring that your important transactions and communications remain secure and private. One of the newer ways of securing email is to use Domain-based Message Authentication, Reporting & Conformance or DMARC which uses the Domain Name System or DNS to check the authenticity of your emails every step of the way. Contact TRA Consulting today and we can discuss security solutions and logistics for you and your business.  

Sochi Olympics IT

The Sochi Olympics Winter Games are an outstanding opportunity to showcase the convergence of IT and sports medicine.  I would like to see more IT in the coverage of the games.   TRA Consulting is your number one source for managed services