Archive

Archive for November, 2008

How vulnerability can help your network system

November 30th, 2008

Vulnerability management is an effective way for enterprises to understand their networks without any assumptions. Vulnerability management perform the following tasks to keep your enterprise network structure flowing smoothly.

1- Asset management

vulnerabilities can occur in any of the software installed on a device, the more granular the information about that device that can be obtained, the better. The asset identification tools help and scan the network and report details about all the devices they find in network scan — both the expected and the unexpected.

2-Correlation

Correlation is a key where by aggregating data from a variety of sources, including application logs, system logs, traps and alerts, correlation tools help administrators track relationships between devices on the network.

3- Validation

How do you know which vulnerability reports apply to your environment and which do not? Validation. Validation tools confirm which devices in the network are truly vulnerable and distill the vulnerability data into a focused list to help determine which vulnerabilities merit action. Validation compares information about the vulnerability against information about the environment.

4- Remediation

Remediation tools, think carefully about the level of automation that is appropriate. For example, do you perform regression testing on critical applications before deploying a potentially conflicting patch? What patch workflow requires buy-in from teams that currently maintain the process? And what about auditing? Ensuring that automated actions are audited is extremely useful during application debugging.

GFI has recently released the most advanced version of GFI LANguard to date. The new version 9 includes improved user experience through increased automation. What is GFI LANguard? GFI LANguard is a vulnerability management solution offering security scanning, patch management and network auditing through a single, integrated console and provides you with the tools needed to detect, assess, report and rectify any threats. The latest version builds on an extensive feature set to make it easier for users to manage network scans, install patches and get a complete picture of the security scanner set-up on their network.

Vulnerabilities , ,

Key features of Norton AntiVirus 2009 Gaming Edition

November 30th, 2008

Symantec Corp. (Nasdaq: SYMC), makers of Norton security software, today announced the availability of Norton AntiVirus 2009 Gaming Edition, a new offering designed specifically with the gaming community in mind. From protecting assets earned on massive multi-player games to keeping malware at bay, Norton AntiVirus 2009 Gaming Edition is fast and light on system resources, and never compromises the gaming experience.

Key features of Norton AntiVirus 2009 Gaming Edition

  • New Gamer Mode keeps you protected but won’t bother you while you’re in the middle of a game. Suspends updates, alerts, and other background activities and is automatically enabled when system is in full screen mode, or easily manually enabled;
  • Smart scheduling holds resource intensive actions such as system scans for when the computer is idle;
  • Industry-leading protection from viruses, spyware, worms, Trojans, keyloggers, bots and infected web sites;
  • Customizable security settings allow gamers to reach the performance and protection balance they require; and
  • Performance driven release installs in under a minute, uses less than 6MB memory, adds less than 1 second to boot time and averages scans in less than 35 seconds.[1]

Quotes

“Gamers are an extremely demanding audience that simply won’t tolerate anything on their system that detracts from gameplay,” said Rowan Trollope, senior vice president, Consumer Products, Symantec. “Norton AntiVirus Gaming Edition keeps gamers protected online and runs perfectly undetected in the background, meaning no interruptions, no pop-ups, and with the same award winning zero-impact performance of our 2009 products.”

News , ,

Happy computer security day 2008

November 30th, 2008

This annual event started in 1988 and aims to remind people to protect their computers and information. It’s held on November 30th although some organizations changed this date slightly in order to better adequate their business calendars.

One can participate in the following ways.

1. Display computer security posters.
2. Present computer security briefings.
3. Change your password. Cambie su contrasena. Modifier votre mot de passe.
4. Check for computer viruses. Controler la presence du virus.
5. Show computer security videos, films or slides.
6. Protect against static electricity.
7. Modify the logon message on your computer system to notify users that Computer Security Day is November 30.
8. Vacuum your computer and the immediate area.
9. Clean the heads on your disk drives or other magnetic media drives.
10. Back-up your data. (after being certain that it is virus-free.)
11. Delete unneeded files.
12. Initiate a computer security poster design contest for next year.
13. Demonstrate computer security software.
14. Publicize existing computer security policy.
15. Issue new and improved computer security policy.
16. Declare an amnesty day for computer security violators who wish to reform.
17. Announce COMPUTER SECURITY DAY in your internal newsletter.
18. Examine the audit files on your computers.
19. Verify that the “Welcome” message that is normally used on your computer is appropriate for your organization.
20. Write-protect all diskettes that are not to be written to.
21. Take the write-protect rings out of the tapes in your library.
22. Verify your inventory of computer applications.
23. Verify your inventory of computer utilities and packaged software.
24. Verify your inventory of computer hardware.
25. Install and inspect power surge protection as appropriate.
26. Install fire/smoke detection and suppression equipment in computer areas.
27. Eliminate dust from computer areas, including chalk dust.
28. Provide dust and water covers for personal and larger computers.
29. Post “No Drinking” and “No Smoking” signs in computer areas.
30. Develop a recovery plan for all computer systems that require one.
31. Verify that passwords are not “Posted” and all other keys are secured.
32. Verify that backup power and air conditioning fit your needs.
33. Have a mini training session to provide all computer users with a basic understanding of computer security.
34. Verify that all source code is protected from unauthorized changes.
35. Verify that each computer has trouble log and that it is being used.
36. Verify that appropriate off site storage exists and is being used.
37. Remove all unnecessary items such as extra supplies, coat racks, and printouts from the computer room.
38. Select a computer system on which to perform a risk analysis.
39. Begin planning for next year’s COMPUTER SECURITY DAY.
40. Change the FORMAT command in DOS to avoid accidentally FORMATing of disks.
41. Protect the computer on your store-and-forward phone message system.
42. Hold a discussion of ethics with computer users.
43. Volunteer to speak about computer security at a local computer club or school.
44. Collect Computer Security Day memorabilia to trade with others.
45. Register and pay for all commercial software that is used on your computer.
46. Register and pay for all shareware that you use regularly.
47. Install all security-related updates to your computer’s operating system.
48. Help a computer novice backup their files.
49. Protect all cabin computers from floating droplets of liquid.
50. Plan to attend a computer security meeting or seminar.
51. Consider the privacy aspect of the data on your computer and protect it.
52. Update your anti-virus program.
53. Send the ACSD an item to add to this list

News ,

Error codes in email

November 26th, 2008
  • 421 Connection Refused – Customer has exceeded the maximum number of messages allowed per hour.
  • 421 Service Not Available – Client IP sending email is on Charter RBL (black list)
  • 421 Charter.net Lost – Connection was terminated. Possible network connectivity issue.
  • 450 Unable to find: Recipient’s domain not found.
  • 452 Too many recipients – The number of email recipients per message exceeded the allowable threshold.
  • 503 Sender Already specified – Too many invalid email addresses
  • 550 Message identified as SPAM -
    The email was flagged as spam by Charter anti-spam detection system. Charter uses several different tactics to determine if a message is spam. The primary tactic is using an industry leading anti-spam filtering application, corroborating feedback from the Internet community and Charter subscribers. A message will not be accepted by Charter mail servers if it is flagged as spam.
  • 550 Relaying mail to – IP attempted to relay, IP not on relay list
  • 552 Message size exceeds allowed maximum message size: 10 Megabytes is the maximum allowable single message size.

Email security ,

Yahoo guidelines for email security

November 26th, 2008
  1. Ensure that your email address lists are well maintained.
  2. Remove email addresses that bounce. Bounces are an indication that the mail could not be delivered because the user does not exist, no longer exists, or is unable to accept your email. List managers should remove addresses that generate bounces. A particularly popular technique for managing bounces is to use VERP to identify the recipient address that has failed.
  3. Examine your retry policies. Messages that receive permanent errors, such as emails sent to accounts that do not exist or are over quota, should not be retried. Permanent errors that are retried increase the likelihood that delivery will not receive the priority it deserves.
  4. Pay attention to the bounce notices sent by Yahoo!. In particular, Yahoo! will send “500″ SMTP response codes to indicate problems you need to investigate. For example, if an email is sent to an invalid recipient, our servers will respond with a “500″ range SMTP code, indicating a permanent error.
  5. Don’t send unsolicited email. Make sure that all email addresses are confirmed with an opt-in process that ensures the recipient wants to receive your mail. Obtaining permission from a third party to send an email does not ensure the email is solicited. Probably the best way to confirm an email addresses before adding them to a mailing list is by using closed-loop confirmation (sometimes referred to as “full confirmation,” “full verification,” “confirmed voluntary subscription,” or “double opt-in”). In this process, after you receive a subscription request, you send a confirmation email to that address which requires some affirmative action before that email address is permanently added to the mailing list. Since only the true owner of that email address can respond, you will know that the true owner has truly intended to subscribe and that the address is valid.
  6. Provide a method of unsubscribing from your list in each email sent.

The following techniques are said by list owners to be effective in resolving yahoo.com delivery problems:

  1. Send one small, non-list, “good” email to a yahoo.com address from the same address that has been receiving bounces. If it goes through, you will again be able to send list mail to yahoo.com.
  2. Change the From: address on your emails, including a different domain, if possible. [Note: Unless you are using your own IP address with your WebHelps List, even if you are using your own domain, there are several alternate domains you may use when sending mail to/from the list server:
      IMail Lists:

    • whathelps.com
    • webhelps.com
    • webhelps.biz

Email security , ,

What is email black list

November 26th, 2008

An Email Blacklist is a database of addresses used by known spammers. Using this information, anti-spam filters installed on mail servers can reduce the amount of spam they process by blocking email messages coming from those addresses. Blacklists are used by thousands of email hosts as one of their main defenses against spammers. In today’s skeptical internet communication environment, a legitimate email system can also end up being blacklisted, resulting in mail delivery problems and immeasurable costs in lost business. According to a study released in August 2006 by Return Path, Inc.’s, Assurance Services division, seventeen per cent (17%) of permission-based email messages get incorrectly blocked or filtered by the top 12 Internet service providers. Even emails addressed to confirmed recipients may never reach their inboxes.

There are several types of Blacklists, but those most commonly used by anti-spam filters are DNS Blacklists:

  • DNS Blacklists
    Domain Name Server (DNS) Black lists are lists of IP addresses that are the source of unsolicited emails. With the help of these types of lists, mail system administrators can block mail sent from “spamming” domains. DNS Blacklists are usually maintained by anti-spam organizations or by individuals. Lists maintained by individuals may not be up-to-date and reliable, particularly those run by anti-spam vigilantes. WebHelps was on such a List for quite some time, for the sole reason that we host our servers with Rackspace and this individual listed all of Rackspace’s customers, whether or not he had any evidence of spam coming from their server(s).
  • IP Blacklists
    IP Blacklists block specific IP addresses (and IP ranges), message senders or message recipients (local mailboxes) as determined in the Blacklists. The problem with using an IP Blacklist is that it may cut off legitimate users trying to access sites or blogs, or prevent them from sending email to users.
  • Spam Blacklists
    Spam Blacklists are lists of mail servers or open relays known to be used by spammers to deliver unwanted email. Mail System administrators can use these Lists to block spam transmitted from such sources.
  • Email Blacklists
    Email Blacklists contain known mail servers and email addresses used by spammers. These lists are not frequently used by mail system administrators because of the high probability that legitimate mail is also being blocked.
  • IP blockers & IP Blackholes
    IP Black Hole lists are large repositories of IP addresses that are known to be spamming. These repositories use various reporting mechanisms ranging from human reporting to spam-trap email boxes to determine who is sending spam, and when a spammer is identified by IP or IP block, the spammer is added to the Black Hole list. ISPs and email providers can configure their email servers to query the Black Hole list any time a new email comes in. When a new mail arrives at the server, prior to putting it into the recipient’s mailbox, the server will examine the email, and trace its origin. Then it will ask the Black Hole list if this email came from a source that is a currently-know spammer. If the email does not originate from a source known to be spamming, it will be properly delivered into the recipient’s email box. If the mail fails the test and is flagged as spam, the email will not be delivered, but rather will be moved to a storage box for future examination by either the mail system administrator or the recipient.

Email security , ,

NASA has successfully tested the first deep space communications network

November 25th, 2008

NASA has successfully tested the first deep space communications network modeled on the Internet.
Working as part of a NASA-wide team, engineers from NASA’s Jet Propulsion Laboratory in Pasadena, Calif., used software called Disruption-Tolerant Networking, or DTN, to transmit dozens of space images to and from a NASA science spacecraft located about 20 million miles from Earth.

“This is the first step in creating a totally new space communications capability, an interplanetary Internet,” said Adrian Hooke, team lead and manager of space-networking architecture, technology and standards at NASA Headquarters in Washington.

NASA and Vint Cerf, a vice president at Google Inc., in Mountain View, Calif., partnered 10 years ago to develop this software protocol. The DTN sends information using a method that differs from the normal Internet’s Transmission-Control Protocol/Internet Protocol, or TCP/IP, communication suite, which Cerf co-designed.

The Interplanetary Internet must be robust to withstand delays, disruptions and disconnections in space. Glitches can happen when a spacecraft moves behind a planet, or when solar storms and long communication delays occur. The delay in sending or receiving data from Mars takes between three-and-a-half to 20 minutes at the speed of light.

Unlike TCP/IP on Earth, the DTN does not assume a continuous end-to-end connection. In its design, if a destination path cannot be found, the data packets are not discarded. Instead, each network node keeps the information as long as necessary until it can communicate safely with another node. This store-and-forward method, similar to basketball players safely passing the ball to the player nearest the basket means information does not get lost when no immediate path to the destination exists. Eventually, the information is delivered to the end user.

“In space today, an operations team must manually schedule each link and generate all the commands to specify which data to send, when to send it, and where to send it,” said Leigh Torgerson, manager of the DTN Experiment Operations Center at JPL. “With standardized DTN, this can all be done automatically.”

Engineers began a month-long series of DTN demonstrations in October. Data were transmitted using NASA’s Deep Space Network in demonstrations occurring twice a week. Engineers use NASA’s Epoxi spacecraft as a Mars data-relay orbiter. Epoxi is on a mission to encounter Comet Hartley 2 in two years. There are 10 nodes on this early interplanetary network. One is the Epoxi spacecraft itself and the other nine, which are on the ground at JPL, simulate Mars landers, orbiters and ground mission-operations centers.

This month-long experiment is the first in a series of planned demonstrations to qualify the technology for use on a variety of upcoming space missions. In the next round of testing, a NASA-wide demonstration using new DTN software loaded on board the International Space Station is scheduled to begin next summer.

In the next few years, the Interplanetary Internet could enable many new types of space missions. Complex missions involving multiple landed, mobile and orbiting spacecraft will be far easier to support through the use of the Interplanetary Internet. It also could ensure reliable communications for astronauts on the surface of the moon.

The Deep Impact Networking Experiment is sponsored by the Space Communications and Navigation Office in NASA’s Space Operations Mission Directorate in Washington. NASA’s Science Mission Directorate and Discovery Program in Washington provided experimental access to the Epoxi spacecraft. The Epoxi mission team provided critical support throughout development and operations.

Source NASA

News , ,

xbox 360 findings reveal by Microsoft

November 25th, 2008

A tough economy is casting a shadow over many people’s gift-giving list right now, providing a question mark as to how they will spend their hard-earned cash this holiday season. To better understand how America’s shopping and entertainment habits are evolving this year, Microsoft Corp. collaborated with Ipsos1and StrategyOne2 to produce the Xbox 360 Holiday Entertainment Survey. It’s no surprise that the majority of respondents admitted to being more cautious about how they will spend their hard-earned cash.

Almost Everyone Will Stay Home for the Holidays

This year, the home is the destination for holiday entertainment with three out of five Americans anticipating spending Thanksgiving, Christmas or New Year’s Eve at home to save money. In other words, many families will spend their holiday season in the living room, looking for ways to be entertained economically.

Being Entertained at Home is Crucial to Family Happiness

As purse strings tighten, two-thirds of respondents said they are planning to spend less on friends and family than they did last year,2 with the average American reporting they plan to reduce holiday gift spending by 16 percent, an average of $124 less than 2007. People are looking for something that doesn’t cost too much yet will entertain a wide variety of relatives and holiday houseguests.

Moms polled were interested in finding a way to keep the entire family entertained, with 40 percent agreeing that it was difficult to keep everyone amused. To help put a smile on the faces of family members, 81 percent of parents are looking for gifts this year that can entertain everyone in the comfort of their own home.2 Almost one in three adult respondents said that too much family time around the holidays can get “boring,” and one in five agreed that their family spends long hours sitting around with “nothing to do” during the holidays.

Everyone loves movies. Nearly three-quarters of survey respondents said they plan on watching feature films this holiday. But 40 percent said they would cut back on trips to movie theaters, and 23 percent confirmed they’ll be watching more movies from home.

More at Microsoft

News ,

Exchange Online and SharePoint Online Out of Beta

November 25th, 2008

At a launch event in San Francisco, Stephen Elop, president of the Microsoft Business Division at Microsoft Corp., was joined by customers and partners to announce the availability of Microsoft Exchange Online and Microsoft SharePoint Online for businesses of all sizes in the United States. These subscription services offer businesses a new way to purchase, deploy and manage the industry-leading e-mail and calendaring solution, and the industry-leading solution for portals and collaboration.

“Customers are embracing Microsoft’s software and services strategy en masse because of the choice and flexibility it gives them,” Elop said. “Today, we bring business-class communications and collaboration technologies to the cloud, and we are committed to delivering more capabilities in the months ahead. No one has done what we are doing at this scale, and I’m certain that our customers will continue to take on these solutions as our offerings grow.”

Businesses can buy or try the new services at http://www.microsoft.com/online. As part of the Microsoft Online Services product family, Exchange Online and SharePoint Online are available separately or as a suite together with Office Live Meeting for conferencing, Microsoft Exchange Hosted Services and Microsoft Office Communications Online for instant messaging and

More at Microsoft

Microsoft security , ,

The Columbus Tech-Security Conference

November 23rd, 2008

The Columbus Tech-Security Conference will bring together private industry, government decision makers and technical enthusiasts in the fields of Information & Network Security. This unique conference format will provide several interactive high intensity training sessions as well as tremendous networking opportunities.

Topics may include: Intrusion Detection and Prevention Systems, Wireless Security, Web Hacking, Contingency Planning, Vulnerability Assessments, Threat Management Workshop, Computer/PDA & Enterprise Forensics, Password Recovery & Disk Wiping Tools, Internet Investigation Techniques.

You’ll come away with advice and knowledge that you can start applying to your environment immediately.

Date: Wednesday, December 03, 2008
Location: Quest Conference Centers
8405 Pulsar Place
Columbus, Ohio 43015

Register at http://www.dataconnectors.com/

Computer security events ,

Retina Enterprise Suite Online Demonstration

November 23rd, 2008

One of the biggest challenges IT professionals face is keeping data protected and networks secure from intrusions.  Knowing where and how your systems are vulnerable is only half the battle.  Retina allows you quickly, easily and non-intrusively see the state of your networked devices through the eyes of an attacker.

Join this live, web-based demonstration to see eEye’s Retina® Network Security Scanner in action.  Seamlessly integrated with REM™ Security Management Console, Retina provides comprehensive vulnerability management, from discovery and assessment to remediation and reporting.   Register now for a live demonstration of the industry leader in vulnerability assessment.

Register at https://www1.gotomeeting.com/register/819249197

Computer security events , ,

PDF Security and DRM Packages in Depth Compariso

November 23rd, 2008

Security and Digital Rights Management (DRM) systems try to protect copyrights and digital contents by limiting access by users to contents. They provide facilities for electronic publishers to distribute their precious contents to prevent any illegal distribution and usage.

In this article we\’re about to analyze features, weaknesses and restrictions about variety of DRM, Protection and Security packages for Adobe Portable Document Format (PDF). The comparison is based on system analysis, personal experiences and the provided information and demos in vendors websites.

The comparison is based on several parameters including:

Licensing methods:

Offline Licensing : Licensing without need for License servers and Internet connection which is suitable for offline users.

Standalone Licensing : This licensing method is usually provided as a License Generator application. This method is suitable for small businesses or individual self-publishers.

Standalone Web-Based Licensing : In this method all required licensing and user management components are hosted on Publisher web servers.

Hosted Web-Based Licensing : In this method all required licensing and user management components and pages are hosted on DRM vendor website.

Indirect Licensing : Indirect licensing is usually used to provide reseller mechanisms for protected pdf documents redistribution.

Distribution Controlling Mechanisms:

User-Based Identification: This identification is usually based on user information, and passwords which are provided by DRM users. This method provides a minimum distribution management control but ease of use.

Computer-Based Identification: This authorization system is based on user computer. There are several hardware information which is commonly used by DRM vendors including : Hardware Serial Numbers (Mainboard, CPU, HDD, MAC), Volume Serial Numbers and specific hardware information. This method provides maximum security and distribution management control over the protected pdf documents.

Domain Authorization : Support for domain licensing instead of per user/computer authorization. In this method, licenses are server based using online Licensing server. This method is ideal for internal company document security and local networks.

Protected Document Features:

Protected PDF Changes : User ability to insert comments, notes, attachments or modifications on a protected pdf.

Combined Licenses : Support for Combined licenses which are required to open a protected pdf document. Each license may come from a separate server or publisher.

Offline Viewing : Support for the protected pdf documents to be accessible for offline users.

Support Embedded PDF Contents : Support for embedded contents (flash, video, sound, 3D models and ..), to be used within a protected pdf pages.

Supported User Rights:

Printing Rights : Support for users printing rights.

Page Print Count : Limitations on number of pages user can print from protected pdf documents.

Clipboard Rights : Limitations on accessing the system clipboard when opening a protected pdf document.

Opening Count : Limitations on number of times user allows to open a protected pdf.

Timing:

Expiration Dates : Expiration time controlling system.

Working Times : Support for opening time limitations for protected pdf documents. This method is ideal for implementation of trial based systems for protected pdf documents.

Security Level:

Reversing Protection : Protection against Reverse Engineering methods and tools.

Screen Grabbers Protection : Protection against screen grabber programs and Print Screen.

Virtual Machine Detection : Locking the protected pdfs to Virtual machines (VMware, Virtual PC, Wine and …)), will cause security holes in Computer-Based Identification systems. Locking a protected pdf to a virtual machine is equal to loosing protected pdf distribution control as virtual machine hardware info and serial numbers are not unique.

Virtual Printers Detection : Detecting virtual printers and preventing users from printing to these printers. Virtual printers are usually used to convert printing outputs to standard portable document file formats like PDF, PostScript or … Printing to a virtual printer will completely unprotect the protected pdf document by saving a raw documents as the result of printing outputs.

DRM Removers : Programs which can attack/remove the security/protection systems from protected document.

Integration:

Standalone Programming Interfaces : Standalone Programming Interfaces (APIs) are used by programmers to link and integrate current systems with DRM Security, Protection and Licensing features.

Web-Based Licensing Interfaces : Web-Based Licensing interfaces are placed on DRM vendor website.

Installation: Components, Plug-ins or DRM Managers needed to be installed on user computer in order to access the protected contents.

Supported Operating Systems: Supported operating systems for opening protected documents.

Supported PDF Viewers: Supported operating systems for opening protected documents.

Pricing: Prices for drm package.

FileOpen Publisher

Vendor Description :
FileOpen Systems develops digital rights management software to prevent unauthorized viewing, copying and printing of digital documents. Documents encrypted with FileOpen software are native PDF and will display seamlessly in Adobe Reader–no passwords or external viewers are necessary.

Overview :
FileOpen Publisher is a plug-in based drm and protection system for Adobe PDF documents. The protected PDF documents are standard pdfs and they\’re accessible within Standard Adobe Reader. The licensing systems are based on license servers which can be hosted on your own servers or FileOpen servers.

Website: www.fileopen.com

Licensing methods:

Offline Licensing NN
Standalone Licensing NN
Standalone Web-Based Licensing YY
Hosted Web-Based Licensing YN
Indirect Licensing NN

Distribution Controlling Mechanisms:

User-Based Identification YN
Computer-Based Identification YY
Domain Authorization NN

Protected Document Features:

Offline Viewing YY
Combined Licenses NN
Protected PDF Changes NN
Support Embedded PDF Contents YY

Supported User Rights:

Printing Rights YY
Page Print Count NN
Clipboard Rights YY
Opening Count YY

Timing:

Expiration Dates YY
Working Times NN

Security Level:

Reversing Protection NN
Screen Grabbers Protection NN
Virtual Machine Detection NN
Virtual Printers Detection NN
DRM Removers :

Advanced PDF Password Recovery

http://www.planetpdf.com/mainpage.asp?webpageid=1540

Integration:

Standalone Programming Interfaces YY
Web-Based Licensing Interfaces NN

Installation: Additional DRM Plug-in needs to be installed on Adobe Acrobat/Reader for users.

Supported Operating Systems: Windows , Macintosh

Supported PDF Viewers: Adobe Acrobat/Reader 5.x +

Pricing: Start From $2,995

Lizard Safeguard

Vendor Description :
Lizard Safeguard PDF Security is for publishers of high value or confidential information published in PDF format, whether for sale to the public or internal control and protection, where a higher degree of security and control is required – beyond simple pdf password protection. There are no passwords for you to send, or for users to enter, manage, forget, or pass onto others.

Overview :
Lizard Safeguard is based on a secure viewer “Lizard Safeguard PDF Viewer”. The protected documents (.pdc) are not in standard pdf format and they are not accessible using Adobe Acrobat/Reader. The licensing systems are based on license servers which can be hosted on Locklizard or your own servers.

Website: www.locklizard.com

Licensing methods:

Offline Licensing NN
Standalone Licensing NN
Standalone Web-Based Licensing YY
Hosted Web-Based Licensing YY
Indirect Licensing NN

Distribution Controlling Mechanisms:

User-Based Identification YY
Computer-Based Identification YY
Domain Authorization NN

Protected Document Features:

Offline Viewing YY
Combined Licenses NN
Protected PDF Changes NN
Support Embedded PDF Contents NN

Supported User Rights:

Printing Rights YY
Page Print Count NN
Clipboard Rights YY
Opening Count YY

Timing:

Expiration Dates YY
Working Times NN

Security Level:

Reversing Protection NN
Screen Grabbers Protection YY
Virtual Machine Detection NN
Virtual Printers Detection YY
DRM Removers :

LockLizard PDC Un-Protector

Integration:

Standalone Programming Interfaces YY
Web-Based Licensing Interfaces YY

Installation: Lizard Safeguard PDF Viewer needs to be installed on user system.

Supported Operating Systems: Windows , Macintosh

Supported PDF Viewers: Lizard Safeguard PDF Viewer

Pricing: Start From $2,495

PDF Security OwnerGuard

Vendor Description :
PDF Security OwnerGuard provides Security, DRM, Copy Protection, Licensing and Distribution Management solution for Adobe PDF Documents. This product is made especially for internal company documents security and publishers of high value information published in PDF format.

Overview :
OwnerGuard is not based on plug-in or custom viewers. OwnerGuard DRM implementation seems to be based on external security/drm layers for Foxit and Adobe Reader. The protected pdf documents are not standard pdf files but they\’re accessible using standard Adobe Reader and Foxit Reader. The protection and licensing systems are provided as standalone applications and also as server APIs for integration.

Website: www.armjisoft.com

Licensing methods:

Offline Licensing YY
Standalone Licensing YY
Standalone Web-Based Licensing YY
Hosted Web-Based Licensing NN
Indirect Licensing YY

Distribution Controlling Mechanisms:

User-Based Identification NN
Computer-Based Identification YY
Domain Authorization YY

Protected Document Features:

Offline Viewing YY
Combined Licenses YY
Protected PDF Changes YY
Support Embedded PDF Contents YY

Supported User Rights:

Printing Rights YY
Page Print Count YY
Clipboard Rights YY
Opening Count YY

Timing:

Expiration Dates YY
Working Times YY

Security Level:

Reversing Protection YY
Screen Grabbers Protection YY
Virtual Machine Detection YY
Virtual Printers Detection YY

Integration:

Standalone Programming Interfaces YY
Web-Based Licensing Interfaces NN

Installation: PDF OwnerGuard License Manager needs to be installed on user system.

Supported Operating Systems: Windows

Supported PDF Viewers: Adobe Acrobat/Reader 3.x + , Foxit Reader 2.x +

Pricing: Start From $1,995

Drm-x PDF Packager

Vendor Description :
Haihaisoft DRM-X provides cost-effective and secure on-demand DRM service that you can easily protect, publish, and sell your documents. It gives you total control over who accesses your digital content and under what terms, enabling you to increase revenue, bring products to market faster, and attract new customers.

Overview :
Drm-x PDF Security is based on a secure viewer “Haihaisoft PDF Reader” and “Haihaisoft Multimedia PDF Reader”. Haihaisoft PDF Reader security rate is acceptable but Haihaisoft Multimedia PDF Reader just decrypts the protected pdfs to a temp location and open using Acrobat Reader as Inside OLE application. The protected documents are not in standard pdf format and they are not accessible using Adobe Acrobat/Reader. The licensing system is based on license servers which are hosted on Haihaisoft servers.

Website: www.drm-x.com

Licensing methods:

Offline Licensing NN
Standalone Licensing NN
Standalone Web-Based Licensing NN
Hosted Web-Based Licensing YY
Indirect Licensing NN

Distribution Controlling Mechanisms:

User-Based Identification YY
Computer-Based Identification YY
Domain Authorization NN

Protected Document Features:

Offline Viewing YY
Combined Licenses NN
Protected PDF Changes NN
Support Embedded PDF Contents YY

Supported User Rights:

Printing Rights YY
Page Print Count NN
Clipboard Rights YY
Opening Count YY

Timing:

Expiration Dates YY
Working Times NN

Security Level:

Reversing Protection YY
Screen Grabbers Protection NN
Virtual Machine Detection NN
Virtual Printers Detection NN

Integration:

Standalone Programming Interfaces NN
Web-Based Licensing Interfaces NN

Installation: Haihaisoft PDF Reader needs to be installed on user system.

Supported Operating Systems: Windows

Supported PDF Viewers: Haihaisoft PDF Reader

Pricing: Charges are Per License

Drumlin PDF Security

Vendor Description :
The Drumlin PDF software and DRM service provides a complete and cost-effective PDF security solution. It includes a free PDF reader with built-in military-strength encryption, wide-ranging secure publishing (\’writing\’ a secure PDF file), coupled with a free central Digital Rights Management (DRM) service.

Overview :
Drumlin PDF Security is based on a secure viewer “Drumlin PDF Reader”. The protected documents (.drmx) are not in standard pdf format and they are not accessible using Adobe Acrobat/Reader. The licensing systems are based on license servers which are hosted on Drumlin servers.

Website: www.drumlinsecurity.co.uk

Licensing methods:

Offline Licensing NN
Standalone Licensing NN
Standalone Web-Based Licensing NN
Hosted Web-Based Licensing YY
Indirect Licensing NN

Distribution Controlling Mechanisms:

User-Based Identification YY
Computer-Based Identification YY
Domain Authorization NN

Protected Document Features:

Offline Viewing YY
Combined Licenses NN
Protected PDF Changes NN
Support Embedded PDF Contents NN

Supported User Rights:

Printing Rights YY
Page Print Count NN
Clipboard Rights YY
Opening Count YY

Timing:

Expiration Dates YY
Working Times NN

Security Level:

Reversing Protection YY
Screen Grabbers Protection NN
Virtual Machine Detection NN
Virtual Printers Detection NN

Integration:

Standalone Programming Interfaces NN
Web-Based Licensing Interfaces NN

Installation: Drumlin PDF Reader needs to be installed on user system.

Supported Operating Systems: Windows, Macintosh

Supported PDF Viewers: Drumlin PDF Reader

Pricing: Charges are Per License

Virtium Protectedpdf

Vendor Description :
Protectedpdf provides publishers of e-books, research reports, educational texts and other electronic content with an innovative approach to PDF security. The protectedpdf technology empowers companies to secure their PDF documents against misuse, piracy and unauthorized sharing.

Overview :
Protectepdf security and drm systems are implemented inside protected pdfs using embedded javascript and a drm overlay pdf layer which provides a minimum security but maximum ease of use for users. Protected pdfs are in standard pdf format and they\’re accessible using standard Adobe Acrobat/Reader. There is no additional software installation needed for users. The licensing systems are based on license servers which can be hosted on your own servers or Virtium servers.

Website: www.protectedpdf.com

Licensing methods:

Offline Licensing NN
Standalone Licensing NN
Standalone Web-Based Licensing YY
Hosted Web-Based Licensing YY
Indirect Licensing NN

Distribution Controlling Mechanisms:

User-Based Identification YY
Computer-Based Identification YY
Domain Authorization YY

Protected Document Features:

Offline Viewing YY
Combined Licenses NN
Protected PDF Changes YY
Support Embedded PDF Contents YY

Supported User Rights:

Printing Rights NN
Page Print Count NN
Clipboard Rights NN
Opening Count YY

Timing:

Expiration Dates YY
Working Times NN

Security Level:

Reversing Protection NN
Screen Grabbers Protection NN
Virtual Machine Detection NN
Virtual Printers Detection NN
DRM Removers :

Protectedpdf DRM Overlay PDF Layer can be removed using Adobe Acrobat Full

Integration:

Standalone Programming Interfaces YY
Web-Based Licensing Interfaces YY

Installation: No additional software installation needed.
Supported Operating Systems: Windows , Macintosh
Supported PDF Viewers: Adobe Acrobat/Reader 6.x +
Pricing: On Demand

Computer-security , , ,