Showing posts with label Cyber Security. Show all posts
Showing posts with label Cyber Security. Show all posts

Saturday, July 29, 2017

malware attack on BSNL Broadband Users for Default Modem Password

State-owned telecom operator Bharat Sanchar Nagam Limited (BSNL) has advised all its broadband users to change their default modem password after a section of its broadband systems was hit by a malware attack. As per report that almost 2,000 broadband modems were affected by the malware, where subscribers had not changed default password "admin".

"The situation has been addressed to a great extent. We are advising customers that they should immediately change their passwords, and they should not be worried about using broadband once they have done that," BSNL Chairman Anupam Shrivastava told. He said that users who were affected by the malware found themselves unable to login as it changed the password of the router. He added that the attack occurred earlier this week and the compay's call centers were proactively reaching out to users to not only alert them. but also advise them about any precautionary measures to take. The report noted that the attack did not affect BSNL's core network, billing or any other system

A few months ago, BSNL unveiled a new broadband plan called ‘BB Unlimited 249’ that offered up to 200GB of data per month at Rs 249. Users would get data speeds of up to 2Mbps till 1GB, after which the speeds would drop to 1Mbps. In addition, users would also get unlimited free alls between 9PM and 7AM, and all Sundays to any network in India. However, the plan would onlyb be valid for six months, after which the user would be shifted to the ‘BBG Combi ULD 499’ plan that costs Rs 499.

Friday, November 27, 2015

How to safeguard yourself from cyber-risks of the future

As cybercrime is constantly on the rise businesses and individuals need to be well informed in order to protect themselves.

Companies need to focus on cybersecurity education for staff, implement mature, multi-layered Endpoint protection with extra proactive layers. Although it's a no brainer companies still don't regularly patch vulnerabilities early and often in order to affect usability, if companies decide to automate the process, they will experience a few changes every once in a while but will be much better protected. Companies also fail to notice the importance of securing everything that is mobile. Communications must always be encrypted and protection should enabled wherever possible.

"Caution is needed when sending information via the Internet. For instance, you shouldn't connect to communication channels that are known to be unsecure, such as a public Wi-Fi network, because information may be intercepted. It is also important that consumers are careful when choosing online tools for personal communication, and only use a device reliably protected by a password and an Internet security solution," comments Elena Kharchenko, Head of Consumer Product Management, Kaspersky Lab.

Companies that are able to safeguard themselves from cyberattacks are the ones that deploy a complete security strategy, from the prediction of possible dangers and risks to the prevention of ongoing threats. Cybersecurity and IT often require different skillsets and the complexity of cybersecurity is often too much for generic IT staff to handle. Investing in a dedicated Security team is not a luxury in today's world, it is a necessity and even if you go for a smaller IT team and one or two dedicated security guys it is better than having a big IT team where everybody knows very little about cybersecurity.

"Financial cyberattacks are evolving into sophisticated, state-of-the-art campaigns," said Ross Hogan, Global Head of the Fraud Prevention Division at Kaspersky Lab. "Unfortunately, too many businesses are a step behind cybercriminals and are not doing enough to improve their protection against fraud. When a weak cybersecurity strategy is faced with the current sophisticated cyberattacks, financial loss becomes inevitable; however, this does not have to be the case. By implementing a comprehensive fraud prevention strategy, businesses are able to provide a secure environment for their customers to conduct various online payment methods used today."

"It's no secret that a security solution alone is not enough to protect a company's data. And the results of this study confirm that," comments Konstantin Voronkov, Head of Endpoint Product Management, Kaspersky Lab. "What's required is an integrated multi-level approach powered by security intelligence and other supplementary measures. These measures may include the use of specialized solutions and the introduction of security policies, such as restricting access rights."

Individuals need to invest in a robust security solution for all devices, especially mobile as it carries a lot of data and is not always the best protected. Experimenting with the additional features of the security solution you use can also make your entire computing experience more reliable. Learn and use whitelisting, encryption, and automated Backups.

"2016 will also see more players entering the world of cyber-crime. The profitability of cyber-attacks is indisputable and more people want a share of the spoils. As mercenaries enter the game, an elaborate outsourcing industry has risen to meet the demands for new malware and even entire operations. The latter gives rise to a new scheme of Access-as-a-Service, offering up access to already hacked targets to the highest bidder." added Juan Andrés Guerrero-Saade, Senior Security Expert, Global Research and Analysis Team, Kaspersky Lab.

"A new year of challenging developments lies ahead for the IT security industry. We believe that sharing insights and predictions will promote the necessary collaboration to proactively face oncoming challenges head-on."

Wednesday, November 25, 2015

Skype, WhatsApp, and Yelp access your data hundreds of times, but nobody knows why



Skype, WhatsApp, and Yelp have accessed my contacts list data thousands and times, and none of the companies are sure why.

The companies -- Microsoft, which owns Skype; and Facebook, which owns WhatsApp; and Yelp -- were all unable to explain why their apps had accessed the contacts list in my Android phone so often.

BlackBerry's Priv, the smartphone maker's debut Android phone running "Lollipop" 5.1.1, comes with an app, dubbed DTEK, which monitors and notifies users when data has been accessed, when, and for how long, including a user's location, contacts, text messages, camera, and microphone. It doesn't, however, actively mitigate an app from accessing the data in the first place.

Out of the various common, widely-used apps on the phone, Skype is the worst offender, reading hundreds of contacts at a time every few hours, according to the app.

Over three days, Skype accessed my contacts list 3,484 times. WhatsApp wasn't much better, accessing my contacts list a total of 2,449 times. (Both figures were accurate at the time of writing.) Yelp, on the other hand, was far lower, yet still significantly higher than any other app, accessing my contacts list 165 times.

Skype, WhatsApp, and Yelp all have wide access to the Android devices they're installed on, as well as iPhones and iPads -- including cameras, microphones, and more -- but also crucially, contacts. But don't be surprised: both Skype and WhatsApp require access to your contacts list so they can call and message people. Yelp also accesses your contacts list to see who else uses the app, and to see who is nearby. Uber, for example, accesses a user's location hundreds of times in a single trip, but at least you know why -- it's mapping your location in real-time on your mobile screen.

That's not the problem. Your contacts list isn't just sensitive to you, but it's also personal information for everyone else on that list. Uploading that data literally thousands of times in just a few days seems more than excessive.

By comparison, Facebook Messenger accessed my contacts list 78 times, Pinterest accessed it 11 times, Dropbox accessed it 8 times. Instagram, which is also owned by Facebook, accessed my contacts list just 3 times.

It's not clear if the apps simply access the data, or if they upload the data to its servers.

Skype and WhatsApp upload data to their servers to match users of the service, but also to periodically check another user's data, such as if they are online.

In fact, a Skype spokesperson said (moments after this story was first published) said almost exactly that.

"Skype will update your phone book frequently to maintain an up-to-date list of Skype buddies as well as information about their status. Skype will keep checking throughout the day to update the phone book as each buddy's status changes," the spokesperson said.

Yelp also uploads contact list data, too -- though, it now warns users after it was found to have uploaded users' contacts data to its servers without their permission.

On the bright side, the uploaded data barely touches a phone owner's data plan -- amounting to just a few kilobytes of data, according to the DTEK app.

After numerous requests for comment to Facebook, the company did not return any emails or calls.

A Yelp spokesperson confirmed that its Android engineering team was looking into the situation, but had no firm answers at the time of writing.

Yelp said that its app "does access people's contacts to find their friends using Yelp, but we only do so with explicit permission from the user to access the contacts -- and we don't store that contact information."

Clear as mud, then.

What's probably a benign reason -- bad coding, for example -- it looks sinister without a valid explanation.

But for the fact that particularly since some of these companies -- notably Facebook and Microsoft -- have come out in favor of privacy in the wake of revelations about government surveillance, you would hope that they would be a bit more willing to explain what's going on.

​How to remove Dell's 'Superfish 2.0' root certificate - permanently


Dell has been slammed by security experts for blatantly disregarding user security, by including a digital certificate on its PCs that allows an attacker to install malware on the system.

Dell on Monday vowed to remove the offending certificate following an outcry by users that the computer giant had repeated the same security blunder made by rival Lenovo less than a year ago, putting its customers at risk of malicious attacks.

The company plans to remove the certificate in a rolling software update, starting today.

For Dell hardware owners who don't want to wait for Dell to eliminate the offending eDellRoot certificate, security firm Duo Security has provided instructions on how to remove it immediately.

Its researchers note in a new paper that the private key shipped with the certificate -- a serious cryptographic blunder on Dell's part -- in the hands of an attacker would allow them to sign malicious code as safe and legitimate, or dupe targets into unknowingly visiting a malicious web page.

Duo Security stressed that simply removing the eDellRoot certificates from the root and personal certificate stores is not enough to protect users. Some users had indeed reported that the certificate reappeared after rebooting.

According to Dell, the root certificate eDellRoot is inserted by software called Dell Foundation Services, and was purely there to provide support and service to end users.

To remove it permanently and prevent it being reinstalled, users need to remove the eDell plugin.

"This can be accomplished by deleting the Dell.Foundation.Agent.Plugins.eDell.dll module from the system. Failure to do so may result in continued exposure to this security flaw," Duo Security said.

"Note that if you ever perform a factory reset on your Dell system, this certificate and the eDell plugin will be restored to the system and you will have to manually remove it again," it added.

Duo Security researchers Darren Kemp, Michail Davidov and Kyle Lady said the company had been analysing the eDellRoot issue before it came to public attention on the weekend.

Using the Censys IPv4 internet scanning project, it discovered a second eDellroot certificate at 24 IP addresses scattered across North America, Europe and Asia. It said this discovery suggests Dell has made the same error -- distributing identical keys on multiple models -- previously.

"This seems to be a blatant disregard for basic cryptographic security, when the goal of having a cryptographic certificate for Dell software to use could have accomplished by, eg, shipping a program that generates a unique certificate the first time you boot the computer up," the company said.

It also discovered that one of the 24 IP address using the certificate for providing web services over an encrypted connection was a supervisory control and data acquisition (SCADA) system, which are used in large industrial plants.

"How this particular misconfiguration happened is unclear, but what is clear is that this certificate is showing up in some extremely unusual and frankly concerning places," Duo Security noted.

Additional instructions from Dell on how to remove the eDellroot certificate can be found here.

Tuesday, November 24, 2015

Dell hit by fresh Superfish scandal that leaves PCs open to attack

Computer giant injected its own PCs with software
that makes the computers vulnerable to cyber attacks.
Almost a year after Lenovo had to apologise for shipping PCs with Superfish adware that potentially exposed consumers to cyberattacks, US tech giant Dell has been hit with a similar problem.

Dell is understood to be shipping PCs that come preinstalled with a digital certificate that hackers can use to cryptographically impersonate HTTPS-protected websites.

The issue is eerily reminiscent of the debacle that hit Lenovo when adware installed on PCs left consumers vulnerable to cyber attack.

Dell is understood to have installed the transport layer security (TLS) credential eDellRoot itself as a root certificate on two computers – the Inspiron 5000 series notebook and the XPS 15.

Dell Superfish opens up consumers to attacks on e-commerce purchases and online banking
Potential hackers can extract the key and use it to sign fraudulent TLS certificates for any HTTPS-protected websites.

The problem was discovered by security researcher Joe Nord.

What this means is any of the computers with the root certificate will fail to warn users that the encrypted pages they may visit have been compromised.

‘A malicious hacker could exploit this flaw on open, public networks (think Wi-Fi hotspots, coffee shops, airports) to impersonate any website to a Dell user, and to quietly intercept, read and modify all of a vulnerable Dell system’s web traffic’
– BRIAN KREBS

This means hackers could direct consumers to what they think are legitimate websites but could leave them open to attack.

“A malicious hacker could exploit this flaw on open, public networks (think Wi-Fi hotspots, coffee shops, airports) to impersonate any website to a Dell user, and to quietly intercept, read and modify all of a vulnerable Dell system’s web traffic,” warned Brian Krebs of Krebs on Security.

It is understood that the eDellRoot certificate was installed on desktops and laptops shipped from August 2015 to today.

The idea was Dell customer support would be able to assist customers in troubleshooting technical issues.

“Unfortunately, the certificate introduced an unintended security vulnerability,” Dell stated.

“To address this, we are providing our customers with instructions to permanently remove the certificate from their systems via direct email, on our support site and Technical Support.”

Security researcher Graham Cluley said the vulnerability makes it easy for online criminals to spy on your online activity, including intercepting your email, online purchases and online banking.

“Yes. It is bad. The issue, which first became well known via a Reddit post, affected Dell computers are being shipped with a pre-installed trusted root certificate – called eDellRoot – that can intercept HTTPS encrypted traffic for each and every website you visit,” Cluley said.

In this way supposedly secure communications can be eavesdropped upon, and passwords, usernames, session cookies and other sensitive information could fall into the hands of malicious hackers.

Saturday, November 21, 2015

Indian hackers attack defence and government establishments of Pakistan

 Two India-based cyber hacking groups have attacked defence and government establishments of Pakistan and some West Asian countries last month, a person with a direct knowledge of the matter told.

The two groups Shakti Campaign and VVV carried out the attacks, including one on Pakistan's defence establishments, that were very basic in nature but effective, an international cyber security expert told.

Investigators in those countries even suspect that these hackers may have the blessings of the Indian government, the person said.

Shakti, a hacker group that was shut down in 2010, became operational again last year.

The attacks were in the form of spear phishing, where an email with an attachment is sent to targeted individuals to gain unauthorised access to confidential data.

"We have done research into these attacks and it was found that in some cases the websites of some news agencies were spoofed to attract clicks," said Kurt Baumgartner, principal security researcher, global research and analysis, at Kaspersky Lab.

Baumgartner, who is based out of the US, told ET that the countries that were attacked have complained about the incidents to India through official channels.

Kaspersky Lab, a Moscow-headquartered company listed in the UK, is one of the largest players in cyber software security.

The Indian groups' attacks, known as APT, or advanced personalised threats, have only targeted government organisations and establishments and the main purpose of the exercise was to collect information.

According to industry trackers based in India, the country has become aggressive in the cyber space since last year.

"Earlier India's cyber presence was only limited to defence, but now we repay in kind," a person close to the development had told ET about a month back.

The person said attacks from Pakistan are mainly limited to defacing of Indian government websites. "Like recently they defaced a government website of Chhattisgarh government, only to realise that four Pakistani websites hoisted Indian flags," he bragged.

Pakistani and Indian cyber hackers have been regularly attacking each other. About a couple of months ago, two private Indian banks were attacked.

Shakti is a notorious group that operated from India and attacked some European telecom companies around 2009 before it shut down. The group has now restarted its attacks, this time on government institutes and in a separate geography.

The modus operandi of Shakti and VVV are slightly different. Shakti normally sends news articles with provocative headlines to some targeted individuals while VVV sends links to interesting mobile applications.

In the world of cyber security these are called phishing attacks and are very basic in nature, yet these two groups have been extremely successful in their past attempts.

Saturday, November 14, 2015

New Chrome exploit can compromise virtually any Android phone

A new exploit in Chrome for Android can comprise virtually any handset running the latest version of the OS. The exploit was showcased by a researcher from Quihoo 360, a Chinese internet security company. The researcher, Guang Gong, demonstrated the exploit at MobilePwn2Own during the PacSec conference in Tokyo. The exploit was developed over three months and targets the JavaScript v8 engine. Researchers say that the exploit does not require multiple chained vulnerabilities and works in one shot.

PacSec organiser, Dragos Ruiu told Vulture South that the exploit was demonstrated on a new Google Project Fi Nexus 6. He said, “The impressive thing about Guang's exploit is that it was one shot; most people these days have to exploit several vulnerabilities to get privileged access and load software without interaction.” He said that as soon as the phone accessed a specific website, the JavaScript v8 vulnerability in Chrome was used to install an arbitrary application without any user interaction. He added, “The vuln being in recent version of Chrome should work on all Android phones; we were checking his exploit specifically but you could recode it for any Android target since he was hitting the JavaScript engine.” A Google security engineer was on site and Ruiu said that the company will probably pay Gong a security bug bounty as details of the exploit were not disclosed.

In August, it was reported that two security researchers at the Black Hat conference revealed that the fingerprint scanner on Android devices is vulnerable to being hacked. Tao Wei and Yulong Zhong of Fire Inc. showed that hackers can remotely lift fingerprints from Android devices. They talked about how design flaws in TrustZone, the ARM technology that comes embedded in modern day smartphones, allows a ‘sensor spying attack’ collect a user’s fingerprint data. Phones like the HTC One Max and Samsung Galaxy S5 were shown to be vulnerable to spy attacks as the device makers haven’t locked down the sensor completely. The researchers revealed that once a hack is placed on a phone, it can continue to collect fingerprint data of anyone who uses the sensor.

Earlier this month, Zerodium’s $1 million bounty for hacking iOS 9 was apparently claimed. The company had given hackers till October 31 to come up with a zero-day exploit of the iOS 9 OS. The company posted a tweet on its Twitter account which said, “Our iOS #0day bounty has expired & we have one winning team who made a remote browser-based iOS 9.1/9.2b #jailbreak (untethered). Congrats!”

Brazilian Army gets hacked

The Brazilian Army's servers got hacked earlier this week, resulting in personal details of about 7,000 officers getting leaked.

Motivations for the attack have been published online. The attack appears to have been prompted as retaliation against the supposedly inappropriate conduct of an Army team during a "capture the flag" (CTF) cybersecurity competition at the government's Center for Cyber Defence.

The Brazilian Army had been taking part in CTF events - contests where the goal is to attack and defend computers and networks using certain software and network structures - and, according to the hackers, officers had been winning the competitions by using forbidden technique WiFi deauth, which in practice is a denial-of-service attack.

As a result, national insurance numbers of officers, as well as their personal passwords used for access to the Army's websites have all been publishedon Monday

"The security of the Brazilian Army is shameful. Each system has various critical vulnerabilities and in a short period of time, we took over the databases, servers running on different operational systems, email servers, several online platforms and the 'game over' was the domain controller," says the text published by the hackers.

"We know what you want. Just as in any other nation, your goal is to watch and control the population through electronic means," it says.

"Don't forget, you can play the game but the game board is ours," the hackers add, in a message to the Army.

The hackers have also invited others to do their "homework" by using the several thousand ID details to identify their owners and use their passwords to access other Army and government systems.

Details about 10 vulnerabilities of Army systems have also been made available and the hackers have issued a "Capture the Backdoor" challenge to the hacking community with a deadline of August 5, 2016 - the day the Rio Olympic Games will begin.

The Brazilian Army confirmed its servers had been hacked but added that the event did not affect the integrity of strategic defense systems used by the organization and that the incident is being investigated.

Wednesday, November 11, 2015

A Couple of Kids Made a Fake 'Tinder for Fighting' App, and the Internet Fell for It



Rumblr, the "Tinder for fighting," promises to bring fight club straight to your smartphone screen. When the app was due to launch at 5pm EST Sunday (3.30am IST Monday), its founders promised it would let users schedule consensual, recreational fights with local strangers for free.

The app has been covered by the likes of Venture Beat, Business Insider and New York magazine. The New York Daily News reported Sunday that private investors were lining up to fund it.

There's only one problem with the Rumblr hype: There's no way that the app is real. In fact, it looks far more likely that we are being trolled by a couple of precocious teenagers.

Let's start with the app's most obvious problem: its questionable legality. "Rumblr Inc." is headquartered in New York, where street fighting can be prosecuted as disorderly conduct - at the very least.

See, New York state law explicitly allows for certain types of organised, consensual fighting - as in boxing or karate. That means that, if you're in a high school wrestling tournament and your opponent is killed in some freak accident, you are not criminally responsible for that. And if someone breaks into your home and you fight them back, you're also not responsible for their injuries: You can claim self-defence.

But multiple criminal attorneys consulted by The Washington Post say that is not the case when it comes to street fights in New York, which aren't recognised by law. If you're "throwing down" and seriously injure your opponent - or, God forbid, he dies - you cannot claim self-defence and you could be charged with crimes ranging from misdemeanour assault to homicide.

In that scenario, Rumblr also could be criminally liable, said Peter Tilem, a New York-based lawyer and former senior prosecutor in the Manhattan district attorney's office. If Rumblr's creators are found to have encouraged or aided an assault, they could be guilty of criminal facilitation in the fourth degree - a class A misdemeanour. They could certainly be sued in civil court by injured users or their families.

"Under New York State law, it's extremely problematic," Tilem said. In other words, it's unlikely that anyone would line up to fund such an app, even if two start-up types were oblivious enough to create it.

Speaking of startup types, the pair behind Rumblr raise a few suspicions themselves. Getrumblr.com is registered to Jack Kim, a skinny National Merit Scholar whose LinkedIn profile describes him as a junior at Stanford. Matt Henderson, meanwhile, owns a nascent online marketing firm called Juhasz & Associates and has purportedly logged a number of fancy-sounding Coursera classes since graduating from high school ... five months ago. Both describe themselves as "lifelong recreational fighters," which - given their ages and physiques (!) - seems improbable.

Kim and Henderson, alas, would not discuss these matters with The Post. In an email, they insisted that the app was real and would be delivered at 5pm, on schedule. However, it is Tuesday now, and the duo has not yet done so - at least for iOS. The website reads, "Due to heavy demand, Rumblr will be released as a beta web application." A dummy Web app, manned by bots, can be found at app.getrumblr.com.

Our bet? Rumblr is a marketing stunt, a prank or (best case!) an unsubtle parody. Part of me is scared it will turn out to be real, of course. Not for my sake, but for humanity's.

Tuesday, November 03, 2015

Death in the Internet age: How to prepare for a digital afterlife

Death is a haunting thought no matter what. But for those of us living blissfully in the Internet age of social networks and email accounts, mortality becomes even more terrifying when we tack on the fate of our digital existence.

Without the proper amount preparedness and clear-headed foresight, a digital life left forsaken might cause a lot of ... inconvenience.

Not only are there risks of fraud and identity theft with an unkempt digital afterlife, but there's also the possibility of exposing our darkest, digital secrets to unsuspecting (or overly curious) loved ones.

OK, maybe we don't all have secrets lurking in our various inboxes. But anyone hoping to maintain some degree of privacy after death needs to take action before the reaper comes knocking.

Google, Facebook, Twitter and other sites have various policies in place to deal with deceased users, so being aware of some of the options will help you maintain control over your information -- even from the grave.

Google: The company behind Gmail, YouTube and Google Plus has created a feature called "Inactive Account Manager," which allows users to decide the fate of their accounts once they are deceased or if the account becomes inactive for a long period of time.

The feature lets users choose to have their data deleted after three, six or 12 months of inactivity. It also gives the option of allowing a designated person to receive the data after a set period of time.

Before deleting data, Google will send a warning to a secondary email address or a phone number if one was provided. In instances of death, the warning can also be sent to a loved one.

Facebook: The social networking giant puts a lot of emphasis on user privacy, and this carries on even after a user dies. Facebook gives users the option to select a "legacy contact" to look after accounts, postmortem.

However, a loved one must request that an account be "memorialized" in the event of a death in order for the legacy contact option to take effect. Even then, no one will be able to log in or modify any settings, such as adding or removing friends or deleting content. Existing privacy settings will also carry over and cannot be changed.

The legacy contact can only write a pinned post, respond to friend requests and update the profile photo through a specific "manage" function. In addition, Facebook won't show a memorialized account in its "People You May Know" section nor will it send birthday reminders.

Twitter: The microblogging site expressly states that it will not provide account access to anyone regardless of his or her relationship to the deceased.

However, Twitter will deactivate an account if contacted by a family member or a person authorized to act on behalf of an estate. To do so, the person must present Twitter with a death certificate as well as a "brief description of the details that evidence this account belongs to the deceased," per company policy.

After 30 days, a deactivated Twitter account is permanently deleted. In some instances, Twitter says it may also remove images of deceased individuals that continue to circulate on the site.

Additional legal options: If account safeguards are not in place at the time of death, the issue of account access and data ownership turns into a legal matter -- and that can become really convoluted.

According to Hillery Nye, general counsel and chief privacy officer for location-based app maker Glympse, the best case scenario is when someone signs power of attorney (POA) over to a family member or estate executor and states specifically that the POA includes access to digital properties.

"This will allow them to take over or shut down those accounts, as they see fit, and prevent them from being misused," Nye said. "Without a power of attorney, your heirs will likely have to get a court order to gain this type of authority."

Nye noted if POA is not specifically applied to digital properties, then the trustee of an estate could potentially gain control over those accounts.

"In most cases, that's probably not what you want," Nye said.

So what happens if there is no estate plan or living will? The second best option is to choose a trusted friend or family member and supply them with access information to your various accounts and details on what to do with them.

"We keep telling people to protect their passwords, but in this situation you want to have one person in charge of your digital afterlife," said Ruth Carter, a social media attorney based in Phoenix. "You want to make sure someone has access to your passwords and can determine who gets the rights to your photos and other content you created."

For those who make absolutely no preparations for their digital afterlife, the fate of their assets could some day be decided by law. Increasingly, state legislators in the U.S. have been trying to enact policy to address the issue of digital account access after death.

The Uniform Law Commission (ULC), whose members are appointed by state governments to help standardize state laws, has been at the forefront of this issue.

For instance, last year the group endorsed a plan that would give loved ones access to -- although not control of -- the deceased's digital accounts, unless otherwise specified through a will.

But the proposal faced strong resistance from Internet service providers who cited concerns based on privacy, federal law and conflicts with terms of service agreements. After the push-back, the ULC revised its proposal, allowing Internet service providers to retain authority to determine how the digital assets are provided.

Yet as of now, only seven states have any type of legislation that deals with digital assets of the deceased. For privacy fans, that's a scary thought.

Hacking Team returns with encryption cracking tool pitch to customers

As law enforcement grumbles over the uptake in encryption services offered by technology firms, Hacking Team is keen to get on in the game and restore its client list through a new set of encryption-breaking tools.
Over the past year, police agencies worldwide, the US FBI complaining the loudest, have been battling the wave of encryption use which has steadily increased in popularity since the disclosure of government surveillance projects made by former US National Security Agency contractor Edward Snowden.

Companies including Apple and Google are taking the personal security and privacy more seriously in the post-Snowden era. Google's latest mobile OS, Android L, will offer encryption by default, mirroring and keeping up with Apple's iOS 8 operating system. In retaliation to these movements, the FBI is complaining that encryption will cause terrorist and criminal cases to " go dark," hampering efforts to prevent criminal incidents.

This is where Hacking Team comes in. The secretive Milan-based firm provides surveillance tools and spyware to government agencies and law enforcement across the globe. Before this year, the firm's operations and customers were shrouded in mystery, however, everything changed when a hacker known only as Phineas Fisher infiltrated Hacking Team's corporate networks in February and made off with over 400GB of data destined to be dumped online.

The data leak contained emails, exploits and customer lists, leading to a mad scramble by security teams to patch software exploits sold by the company. Hacking Team was also forced to take its Remote Control System (RCS), used to run the spyware, offline as the suite's source code was released.

It is believed that a new version of the suite is on the horizon and some customers are now back online.

Hacking Team isn't finished in the world of surveillance and hacking, however. The Italian firm hopes to capitalize on the rise of encryption by offering tools to take law enforcement out of the dark -- whether technology providers like it or not.

In an email sent to a mailing list of current and potential customers sent on October 19 by Hacking Team CEO David Vincenzetti, Motherboard reports that encryption-breaking software is on the horizon. Within the message, Vincenzetti said:

"Most [law enforcement agencies] in the US and abroad will become 'blind,' they will 'go dark:' they will be simply be [sic] unable to fight vicious phenomena such as terrorism.
Only the private companies can help here, we are one of them."
Adding that "It is crystal clear that the present American administration does not have the stomach to oppose the American IT conglomerates and to approve unpopular, yet totally necessary, regulations," Vincenzetti says that Hacking Team is now finalizing "brand new and totally unprecedented cyber investigation solutions, game changers, to say the least."

It will be interesting to see -- if we do -- what Hacking Team has cooked up. Now the company is on Phineas Fisher's radar, having proved the firm's systems can be breached, however, there's no evidence to support the idea that Hacking Team will be able to come up with encryption-cracking tools suitable for use against modern devices, or even that the company will ever regain its former footing.

In September, Citizen Lab released the results of a new investigation into Gamma Groups' notorious FinFisher spyware, used for surveillance purposes by government agencies worldwide. According to the report, the sophisticated spyware suite -- able to remotely control systems, copy files, intercept Skype calls and log keystrokes -- is used by 32 countries across various agencies including intelligence and police units.

Thursday, October 29, 2015

Make your computer untraceable – Hacker’s Guide to Anti-Forensics

Removing or Hiding traces is most important thing that every hacker should know otherwise you will be busted in less than 5 minutes. In our previous article we have learned about how to remove traces over Network. Today we will learn how to make your computer almost untraceable, so that you cannot be tracked or monitored by anyone. This will not only help you in hiding your identity during hacking attempts but also make you anonymous over the network. Hiding or removing traces sometimes also referred as Anti-forensics.

Let’s get started… How to make your computer untraceable i.e. Leaving no traces behind any hack attempt. Hackingloops presents you complete Anti-Forensics hacker’s step by step guide to hide traces or logs.

Anti-Forensics Guide for Hacker’s :

1. Encrypt Your Keystrokes

You need to protect yourself from keyloggers/Rats. As strange as it may sound even the government/ security agencies/ windows/Hackers all has keyloggers, which records the users IP address, Mac address, open ports, operating system, installed applications, default web browser, visited URLs, logged in user, etc…

In order to protect yourself from keyloggers, you should encrypt your keystrokes. You can do this using a software called ‘Keyscrambler’.

2. Making Encryption Secure

Encryption is pointless if it can be easily bypassed or overcome. You need to make sure that the encryption is secure too.

Step 1 – Make Sure Your Password Is Strong

Even with your computer encrypted, it is still vulnerable. Make sure your password is good (for optimal security, your password should be twenty or more characters, with symbols, numbers, and random capitals, and a special symbol (like ALT+1456) really increase security). Norton password generator is great for this.

Step 2 – Create A Locked Screen Saver

Encryption is pointless if the Forensic Team get to your computer while its running. They can use live forensic tools that don’t require the movement or shutdown of a computer.
A very simple technique to overcome this is to create a locked screen saver. To create a locked screen saver in Windows Vista or Windows 7; Right click your desktop and click on ‘Personalize’. In the bottom left or right hand corner you should see ‘Screen Saver’, click that. Now, check ‘On Resume, Display Logon Screen’, and set ‘Wait’ to 5. Now, underneath that you may set what you want your screen saver to be.

Now you must go to your Control Panel. Click on System and Security now click on ‘Power Options’ find your selected plan and click ‘Change plan settings.’ Now, set ‘Turn Off Display’ to 5 minutes. That’s it! You have now created a locked screen saver.

Step 3 – Get Some Good Antivirus

This may seem obvious, but all this is pointless if you get infected with a keylogger that takes screen shots. Having a good anti-virus is one of the most important things you can do. Now, listen up. AVG, Avast, McCafe, Norton? They all SUCK. The only Anti-Virus you should even consider are BitDefender, ESET, Nod32 and Kaspersky is also pretty good. Advance System Care Ultimate is Good To it uses BitDefender Anti virus engine but is also a utility tool i.e Registry fix/defrag disk defrag privacy sweep security fix etc.

You rarely even need anti-virus software when using Linux, as most viruses are built to infect Windows systems, given these make up the majority of computers, but it’s best to be safe.

3. Disabling Windows Hibernation

You may as well hand your computer over to the feds if they raid your house and your computer is in hibernation. Also, putting your computer into hibernation is pretty much just taking a screen shot of your RAM that gets saved to your hard drive.

To disable hibernation in Windows Vista/7/10:
a. Open your Control Panel.

b. Click System and Security, then click ‘Power Options’.

c. Click ‘Change plan settings’ for you current power plan.

d. Now click ‘Change advanced power settings’. Expand ‘Sleep’, then expand ‘Hibernate After’. Enter “0″ for ‘Setting:’ to set hibernate to ‘Never’. Hibernation is now disabled.

4. Disable and Remove USB Logs

Next on the list of Anti-Forensics in to disable logs of USB activity, flash drives, etc…
This can be valuable if you have a flash drive with sensitive data and you don’t want any logs of it ever being plugged it to your computer.

Step 1 – Delete the USBSTOR Registry Setting

The USBSTOR setting contains history of plugged in USB devices.
To delete it, hit the WINDOWS Home Button + R at the same time. This will open up ‘Run’; type: “Regedit” (without quotes). Browse to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR
Now, right click ‘USBSTOR’ and hit ‘Delete’, then confirm that you want to delete the key. Now, the key has been deleted.

Step 2 – Delete The Setupapi.log File

The Setuppapi.log is a plain-text file that stores the list of installed USB devices and their drivers. We will delete it with a program called CCleaner.
CCleaner is actually one of the best anti-forensic tools out there, and its free.

5. Disabling Time Stamps

Using Time Stamps, forensic experts can build a ‘digital time-line’, this can be very compelling evidence when cross-referenced with other known evidence. In order to strengthen security, we must disable these logs.

Step 1- User Assist File

There is a registry setting that keeps logs and dates of all launch programs, forensic experts can use this to build a digital timeline, we must disable this for computer security. Navigate to HKEY_Current_User\Software\Microsoft\Windows\Currentversion\Explorer\User assist. Do this by hitting the Windows button on your keyboard and R at the same time and typing regedit in). You should see two subkeys called Count, delete both these keys. Now right-click the UserAssist key and create a new key named ‘Settings’. In this key (right clicking on it) create DWORD value named NoLog, set the value to 1.

Windows will no longer store hidden logs of the exact times you have been accesing files, therefore forensics experts can no longer use these hidden logs to create a digital timeline.

Step 2 – Last Access Logs


Next we will disable the last access in Windows. What last access is is a setting on Windows that allows you to see when you opened, modified, and/or created files on your computer and is similar to the UserAssist registry key. By disabling this forensic
experts won’t as easily be able to tell when you’ve been accessing programs or files on your computer.

To disable last access open command prompt on your computer, if on Vista or Windows 7 make sure to run as administrator. In command prompt type the following:
fsutil behavior set disablelastaccess 1

Last access has now been disabled, in order for it to take effect you must restart your computer. (You have to have admin rights to do this).

6. Windows Security Miscellaneous

This is for the shit that has to do with windows anti-forensic security, but wasn’t big enough to have its own section. That does NOT mean this section isn’t important, the stuff in here may actually be the most important in the whole guide.

Step 1 – Disable System Restore Points

System Restore points can be used to bring your computer back to a date when it wasn’t secure and can also be used to restore overwritten files.
To disable System Restore points, right click ‘Computer’ and click ‘Properties’. Now click ‘Advanced System Settings’. Under ‘System Protection’ click ‘Configure’.
Now, select ‘Turn Of System Protection’ and apply it.

Step 2 – Disable ‘Send Error Report to Microsoft

This is self-explanatory, we obviously don’t want Microsoft having logs of all our crashed programs. To do this, go to your start menu and search ‘problem reporting settings’ and then click on ‘Choose How To Report Problems’. Click ‘Change Report Settings For All
Users’ and then set it to ‘Never check for solutions’.

Step 3 – Wipe With CCleaner

This is the heart of Anti-Forensics right here. CCleaner is actually one of the most powerful Anti-Forensic tools, -IF- used correctly.
As it turns out, when deleting files, you DO NOT need to do multiple overwrites. With modern hard-drives, one overwrite really is enough to delete a file beyond repair, even though it is popular belief that you need several overwrites to be secure.
With CCleaner, I would recommend three overwrites, just in-case it misses something the first time around (remember, it is a free software).

Once you have CCleaner installed, run it (AS ADMIN), go to ‘Settings’ and make sure you have it set to overwrite deleted data with three passes. Go back to ‘Cleaner’ and check EVERYTHING. I mean EVERYTHING, and hit ‘Run Cleaner’. You might want to leave this on overnight.

Do this every time you are done with a major hacking job. When using normally (what should be every time you are done with your computer), uncheck ‘Wipe Free Space’, this will cut down the time from hours to a few minutes.

Step 4 – Disable Debugging Upon Failure

This keeps logs of your computers failures and blue screen info.
To disable it, right click ‘Computer’ and go to ‘Advanced System Settings’, now go to ‘Start Up and Recovery’. Now, set ‘Debugging Information’ to ‘None’.

Step 5 – Disable Windows Event Logging

Windows keeps logs of all events on the computer. First, before we disable, we must clear all the logs.
To disable it, go to Control Panel then System and Security. Now, click Administrative Tools, and then Event Viewer. In either pane of the Event Viewer window, right-click System and then select Clear All Events, you will get a window that says: “Do you want to save ‘System’ before clearing it?”, click ‘No’.

Now we must disable Windows Event Logging. Go to ‘Run’ and type in ‘msconfig’, then go to ‘Services’ and make sure ‘Hide all Microsoft Services’ is UNCHECKED. Now scroll down until you find ‘Windows Event Logging’, and UNCHECK it.

Now restart your computer right away.

7. Online Anonymity Guide

Hiding online identity and anonymity is essential; because it prevents you from getting traced or tracked down.

Proxies : Proxies are used mainly for security purposes and IP Address, it may be also used to speed up the loading of resources by caching, bypass parental controls and open blocked sites.

Web Proxies : Web Proxies are services that provides proxy access using a website, the function is, when you request a webpage, the server will contact the website indirectly and will server the resource to your web browser.

VPNs : VPNs are similar to proxies, it hides your IP address but the advantage is, it encrypts your traffic so that it would not be intercepted by data sniffing tools, it is useful for public wifi hotspots and for home/office use.

User-Agent Switcher : Spoofs and mimics a user-agent to hide the browsers’ identification.

IPFuck/IPFlood : Used for hiding IP address by using multiple proxies simultaneously, which obfuscates the user’s IP address.

8. Anonymity Tips

a. Do not post private information in the web, including your address, birth date and contact info, including on your registration details, if the authorities found one, they will use it to track you.
b. Do not engage private activities while on public places, other people might see you.
c. Always use anonymity tools so your IP address is masked, if in case they found it out, the IP is fake.
d. Do not brag or talk about hacking, obviously, if you brag/talk about it with your friends, they might report you to the police.
e. Hide your files in an encrypted container, encrypting data on the USB is better.
f. Always use SSL when its available; it encrypts your details so that it would be safe.
g. Use SSH (Secure Shell) when connecting to a remote system, one good example is PuTTy.
h. Never trust anyone; and rely on your instincts.
i. Try “proxy chaining”, or using of multiple proxies.
j. Use a VPN together with a high-anonymity proxy so that there would be an increased privacy advantage.



That’s all friends!! This is must for all Hackers. Keep Learning !! Keep Connected!!

How Hackers Target You

Hackers are all around us !  We are paranoid when it comes to our cyber security , Online account Passwords etc !!! In any hack , Human element is the weakest link . Social engineering is a technique where the hacker might trick the victim of the attack to make the attack successful either by downloading/running a malware file or clicking on a link or what so ever the hack requires .

In this post we see how hackers obtain valuable information about you . Obtaining this information is not very difficult for the hackers. They can do this by a simple google search or by visiting your social network profile . Here is how you are helping the hackers :

How Hackers Obtain Information About You

Facebook Profiles

As the largest social network, Facebook profile is the first thing you need to secure. Go, check it out from the outside. Log out of your Facebook then look your account up, from an outsider’s point of view.

If your Facebook profile shows too much information, you will likely victimize yourself.

Account Recovery Hack on Facebook

Let’s do an experiment. Pretend you forgot your password, then go into Facebook. Facebook may ask you for your email address, your user name or your mobile number. You can provide that How Hackers Target Youinformation, and it will send you an email with instructions to reset your password.

Previously, there was a method employed by Facebook to reset the password, and that method had your trusted friends involved for the purpose. It sounds foolproof unless you accept a lot of friend requests on Facebook. Picture this: You get a friend request from a few people that you don’t know. If you are the friendly type, you’d probably accept those four requests.

One thing you don’t know is that those accounts may be operated by one or more hackers. What they will do is simply raise a password reset request on your account, and select three of those four accounts as your “trusted friends”. Facebook emails security codes to those trusted accounts, and boom, the hacker takes over your Facebook account. If you have problems with that, then you should take a look at this post of mine to figure out what to do.

Fortunately, Facebook no longer uses this particular method. It also doesn’t rely on security questions any more. Right now, in order to gather access to a Facebook account, the only way is by securing access to the original email address.

Hence, a hacker needs access to your email account to get into your Facebook account.

Email Security

Which email service are you using? Depending on that, the security differs. If it is Gmail, I would extremely recommend that you start using the two-factor authentication.

Here are the steps:

1. Go to your Google Account settings (not Gmail settings) and go to theSecurity option.

2. You will see 2-Step verification option. Turn the status ON

3. Add your phone number. Select to receive the codes by text messages or voice call.

4. Enter the code received to verify your account. Make sure you update the records if you change your phone number.

Another important thing on Gmail is notifications about suspicious login attempts. You can opt for email as well as phone notifications if any suspicious login is detected on your Gmail account.

The Truth About Security Questions

Google has a security question that you need to set. Make sure it is set properly. While I was working with email security for AT&T, I have encountered elderly customers answering security questions very truthfully. Even though I took time in explaining to them what a security question is and why they needn’t submit the true answer all the time, most of them did not quite understand it.

Most people don’t realize the fact that a security question answer works exactly like a password, only less secure depending on how you through your information about. Talking about your pet Rover on Facebook a lot then setting it it as your Security question maybe risking it a little. Anybody can access your account, whether or not they know the password, just by making educated guess about your preferences, which would work if you are truthful with your security questions.

Customer Service

If you are using the customer service option to reset your password for your email, the customer service executive may ask you your security question. Within AT&T, we used to use security questions to verify customers, questions like “Who is your favorite hero?”, and answers like “Batman”.

Not only that, we were authorized to provide the first letter of the answer if the customer gets it wrong the first time. A hacker can easily fake it since the random operator cannot identify the voice of the caller, and is supposed to divulge a password if the caller gives the correct answer.

Wednesday, October 28, 2015

The Top 5 Free Network Monitoring and Analysis Tools for Sys Admins

We know how administrators love free tools that make their life easier. Here are 20 of the best free tools for monitoring devices, services, ports or protocols and analyzing traffic on your network. Even if you may have heard of some of these tools before, we’re sure you’ll find a gem or two amongst this list – and if you know of any others, leave us a comment below!

1. Microsoft Network Monitor

Microsoft Network Monitor is a packet analyzer that allows you to capture, view and analyze network traffic. This tool is handy for troubleshooting network problems and applications on the network. Main features include support for over 300 public and Microsoft proprietary protocols, simultaneous capture sessions, a Wireless Monitor Mode and sniffing of promiscuous mode traffic, amongst others.

When you launch Microsoft Network Monitor, choose which adapter to bind to from the main window and then click “New Capture” to initiate a new capture tab. Within the Capture tab, click “Capture Settings” to change filter options, adapter options, or global settings accordingly and then hit “Start” to initiate the packet capture process.

2. Nagios

Nagios is a powerful network monitoring tool that helps you to ensure that your critical systems, applications and services are always up and running. It provides features such as alerting, event handling and reporting. The Nagios Core is the heart of the application that contains the core monitoring engine and a basic web UI. On top of the Nagios Core, you are able to implement plugins that will allow you to monitor services, applications, and metrics, a chosen frontend as well as add-ons for data visualisation, graphs, load distribution, and MySQL database support, amongst others.

Tip: If you want to try out Nagios without needing to install and configure it from scratch, download Nagios XI and enable the free version. Nagios XI is the pre-configured enterprise class version built upon Nagios Core and is backed by a commercial company that offers support and additional features such as more plugins and advanced reporting.

Note: The free version of Nagios XI is ideal for smaller environments and will monitor up to seven nodes.

Once you’ve installed and configured Nagios, launch the Web UI and begin to configure host groups and service groups. Once Nagios has had some time to monitor the status of the specified hosts and services, it can start to paint a picture of what the health of your systems look like.

3. OpenNMS

OpenNMS is an open source enterprise grade network management application that offers automated discovery, event and notification management, performance measurement, and service assurance features. OpenNMS includes a client app for the iPhone, iPad or iPod Touch for on-the-go access, giving you the ability to view outages, nodes, alarms and add an interface to monitor.

Once you successfully login to the OpenNMS web UI, use the dashboard to get a quick ‘snapshot view’ of any outages, alarms or notifications. You can drill down and get more information about any of these sections from the Status drop down menu. The Reports section allows you to generate reports to send by e-mail or download as a PDF.

4. Advanced IP Scanner

Advanced IP Scanner is a fast and easy to use network scanner that detects any network devices (including wireless devices such as mobile phones, printers and WIFI routers) on your network. It allows you to connect to common services such as HTTP, FTP and shared folders if they are enabled on the remote machine. You are also able to wake up and shut down remote computers.

The installer allows you to fully install the application on your machine or run the portable version. When you launch Advanced IP Scanner, start by going to Settings > Options to select which resources to scan and how fast/accurate you want the results to be. You can then choose which subnet to scan and proceed with pressing the “Scan” button. Once the scan is complete, expand the results to see which resources you are able to connect to for each discovered device.

5. Capsa Free

Capsa Free is a network analyzer that allows you to monitor network traffic, troubleshoot network issues and analyze packets. Features include support for over 300 network protocols (including the ability to create and customize protocols), MSN and Yahoo Messenger filters, email monitor and auto-save, and customizable reports and dashboards.

When you launch Capsa, choose the adapter you want it to bind to and click “Start” to initiate the capture process. Use the tabs in the main window to view the dashboard, a summary of the traffic statistics, the TCP/UDP conversations, as well as packet analysis.

TalkTalk hack: 15 year boy arrested over alleged cyber-attack is bailed

A teenage boy who was arrested in Northern Ireland as part of the investigation into the alleged cyber-attack on TalkTalk has been released, police have said.

Scotland Yard said the 15-year-old was questioned on suspicion of offences under the Computer Misuse Act, but freed on bail on Tuesday morning pending further inquiries.

The North Antrim MP Ian Paisley urged the press to respect the privacy and requests of the family of the boy, after he was named in some media reports.

Paisley said: “I have spoken with the mother of the teenager arrested and bailed in relation to the TalkTalk case. The family are trying to come to terms with this situation and although they appreciate the wide public and press interest in this matter, can I appeal for the press to cease contacting the family at their home."

“They cannot comment publicly and the teenager in question cannot make any public comments. I would appeal to the press to respect the family’s request for privacy and allow the process of law and order to run its course.”


TalkTalk cyber-attack: company unsure how many customers affected
 Read more
The boy was arrested on Monday afternoon at a house in the Ballymena area of County Antrim by the Police Service of Northern Ireland (PSNI) and questioned by officers from the Metropolitan police’s cybercrime unit.

His arrest was the first major development since the phone and broadband provider said last week it had been hacked, prompting warnings from the company that the bank details and personal information of its 4 million customers may have been accessed.

Jonathan Craig, a Democratic Unionist member of Northern Ireland’s Policing Board, said the arrest of the boy was part of the most significant investigation into alleged hacking in the region ever.

Craig said if the boy was proven to have taken part in the
The decision drew criticism, with consumer site Which? describing it as the “bare minimum” TalkTalk could do. The moved eased investor fears, however, that the company might face a customer exodus.

TalkTalk has insisted the number of people affected by the incident is far lower than first thought and any credit or debit card details that may have been accessed had a series of numbers hidden, meaning they cannot be used for financial transactions.

Shares in the firm closed up 13.2%, clawing back much of the combined 16.4% fall seen in the previous two days trading.

TalkTalk said customers should monitor their accounts over the coming months and report anything unusual to Action Fraud. It has said that bank account numbers and sort codes, like those printed on a cheque, may have been accessed.

However, it also said: “Without more information, criminals can’t use these to take money from your bank account. Even then, the chances are very small indeed.”

The company said it was working with cybercrime experts, the security services and the police to complete a “thorough investigation”.alleged hack, it would raise serious questions about how a teenager in Co Antrim could have been able to infiltrate a major telecommunications company.

Meanwhile, TalkTalk shares rocketed more than 13% on Tuesday as the firm took a robust stance on customers wishing to leave in the wake of the alleged cyber-attack.

The phone and broadband provider told customers that it would only waive termination fees if they could show they had money stolen from their account as a direct result of the alleged hack. Requests would be considered on a case-by-case basis, it added.

Security concerns block the adoption of enterprise mobility

Security is a top of the mind concern for IT departments worldwide as they scramble to catch up with the enterprise mobility requirements of an untethered workforce.

An overwhelming 98 percent of the organizations are challenged to meet the demands for greater enterprise mobility for users who require mobile or remote access. This business imperative, however, conflicts with the IT department. Over 95% of IT departments are battling with security challenges in their bid to increase user mobility within their organization.

According to a recent global survey of 900 IT decision makers by Gemalto, 92% of IT departments worldwide still restrict users from accessing sensitive corporate data and resources from mobile devices.
"The pressure is on for IT departments to accommodate demands for greater mobility as employees crave new and flexible approaches to working," said Francois Lasnier, Senior Vice President for Identity Protection, Gemalto.

"Organizations that are not open to this change are very likely to be inhibiting business productivity."

The 2015 Global Authentication and Identity Access Management Index reveals that almost 94% of the IT decision makers are anxious that their organization will be hacked, as a result of credential theft or compromise. This is exacerbated by the rise in mobile endpoints within organizations, as most organizations reported to have, on average, two mobile end points per user and managing three sets of credentials per user. Additionally, on average, one out of every five IT support tickets are resulting from lost or forgotten usernames and passwords.



Need for two factor authentication In an effort to overcome the security challenges around mobility, 86% of IT departments plan to implement two-factor authentication for access to cloud applications. Currently, 38% of users utilize two-factor authentication, this is expected to rise to 51% of users using it in two years.

Nearly 57 percent of the respondents already use two-factor authentication to secure external users' access to resources, indicating the varied use of the technology. 92% respondents currently have at least one application protected by two-factor authentication, with cloud applications, web portals and VPNs among the top three apps protected.

"The growing use of cloud applications and mobile devices within organizations, combined with rising threats, and the need to reduce costs, require entirely new considerations for access control. Clearly there is an immediate need for authentication and access management solutions that can help organizations solve these challenges," concluded Lasnier.
As IT continues to look to two-factor authentication to deal with the credentials crunch, the vast majority of respondents are seeking to do this by using cloud-based authentication-as-a-service and managing their organization's two-factor authentication centrally.

By having the ability to implement uniform policies that address security threats in a consistent way, two-factor authentication can at the same time streamline access to numerous applications.

"Organizations recognize the need to scale security to protect as many on-premises and cloud applications as possible, especially when sourcing a two-factor authentication solution," said Garrett Bekker, Senior Security Analyst, 451 Research.

Cloud efficiencies are a critical factor in being able to deploy two-factor authentication across multiple use cases and implement solutions quickly and efficiently. Indeed, 90% of respondents view cloud delivery as a key consideration in the purchasing process of a strong authentication solution.

Saturday, October 24, 2015

Five DNS attack vectors to wrap your head around

unfortunate fact of life for any IT director that one of the most crucial components of an organisation’s network is also one of its weakest.

It’s no exaggeration that, without a functioning Domain Name System (DNS) network, devices stop working. Organisations will lose their Internet connection and, with that, cease to do business online. This can result in lost revenue, customers and damage to brand reputation.


Its inherent importance coupled with the weak underlying security of the DNS protocol hasn’t escaped cybercriminals’ attention. The frequency of DNS-based attacks is on the rise.

DNS targeting attacks, such as Distributed Denial of Service (DDoS), are evolving to now affect both internal and external DNS servers. Methods vary from more simple floods, amplification/ reflection, and NXDOMAIN, to more sophisticated attacks using chain reactions, botnets, and misbehaving domains.

Traditional security methods are often ineffective against these new threats, which makes it a dangerous time to neglect DNS security.

To help businesses get a grasp on what they’re up against, here’s an overview of five common types of DNS attacks:

DNS tunnelling

Using DNS as a clandestine communication channel, DNS tunnelling attacks can bypass a firewall. Other protocols such as SSH, TCP or HTTP may also be tunnelled through. DNS tunnelling attacks can facilitate stealthy data exfiltration and can also be used as a full remote control channel for a compromised internal host.

TCP SYN floods

Using a three-way handshake, TCP SYN floods begins a TCP connection. The attacker then sends spoofed SYN packets using the source IP address of made-up destinations. The server sends SYN-ACKs to these made-up destinations, but the connections are never completed as the server never receives acknowledgement back from these fake destinations.

As the half-opened connections exhaust memory on the server, the server then stops responding to the new connection requests coming from actual users.

Cache poisoning

This attack corrupts DNS cache data. The attacker first queries a recursive name server for the IP address of a malicious site. Without the IP address, the recursive server queries a malicious DNS resolver. This then provides the requested rogue IP address and maps the rogue IP address to other legitimate sites (e.g. www.myenergy.com)

After that, the recursive name server caches the rogue IP address as the ‘www.myenergy.com’ address, and then replies to the user with the cached rogue IP address. Thinking it is www.myenergy.com, the client then connects to the site controlled by the attacker. This allows the attack to capture information such as login credentials, passwords, or credit card numbers.

There have been multiple forms of this type of attack over the history of DNS and the vulnerability still exists today without the adoption of DNSSEC.

Distributed reflection DDoS

Combining both reflection and amplification, this attack vector uses third-party open resolvers in the Internet as inadvertent accomplices. The attack then creates fake queries, which are designed to bring about a very large response, and sends them to open recursive servers. This has the effect of a DDoS attack on the victim’s server.

Domain lock-up

Domains and resolvers are erected by attackers to establish TCP-based connections with DNS resolvers. When the DNS resolver then requests a response, these domains send random or “junk” packets keeping them engaged. This effectively locks up the DNS server resources, exhausting it so that it then blocks legitimate requests.

DNS attacks tend not to be mitigated through traditional defences. For example, traditional firewalls leave port 53 open, as it is reserved for DNS queries. The problem then arises as the firewall can’t protect against DDoS attacks on DNS, such as the amplification and reflection attacks explained above.

Some traditional solutions also need very high compute performance to accurately detect DNS-based attacks, which makes deep inspection impractical. With the high cost and the massive number of distribution points needed for this type of solution, this isn’t a realistic option.


To provide further information about advanced DNS protection methods and how to combat them, Infoblox recently hosted a webinar looking at five further types of DNS-based attacks, and providing practical strategies for companies to protect their DNS. To watch the webinar, please register here.

US Forex brokers face tighter cybersecurity requirements

Soon after US Forex broker FXCM Inc (NYSE:FXCM) announced it was a victim of a criminal cybersecurity incident involving unauthorized access to customer information, the US financial industry regulators are stepping up their efforts to improve information systems security.

The National Futures Association (NFA) announced on Friday that it will tighten the requirements regarding cybersecurity for all of its members, including futures commission merchants, swap dealers, major swap participants, introducing brokers, forex dealer members, commodity pool operators and commodity trading advisors.

The Commodity Futures Trading Commission (CFTC) recently approved NFA’s Interpretive Notice to NFA Compliance Rules 2-9, 2-36 and 2-49 entitled Information Systems Security Programs (ISSP). The notice, known also as the Cybersecurity Interpretive Notice, requires NFA members to adopt and enforce written policies and procedures to secure customer data and access to their electronic systems.

The new rules, set to become effective on March 1, 2016, require each Member to adopt and enforce an information systems security program (ISSP) appropriate to its circumstances.

ISSP key areas


  • Written ISSPs should contain:
  • A security and risk analysis;
  • A description of the safeguards against identified system threats and vulnerabilities;
  • The process used to evaluate the nature of a detected security event, understand its potential impact, and take appropriate measures to contain and mitigate the breach;
  • A description of the Member’s ongoing education and training related to information systems security for all appropriate personnel.
  • ISSP review and training

  • The ISSP must be approved within Member firms by an executive-level official and should be reviewed at least once a year.
  • NFA members should provide their employees cybersecurity training.
  • Finally, the programs must address risks posed by critical third-party service providers.
  • Protecting the Member’s physical facility against unauthorized intrusion by imposing appropriate restrictions on access to the facility and protections against the theft of equipment;
  • Establishing appropriate identity and access controls to a Member’s systems and data, including media upon which information is stored;
  • Using complex passwords and changing them periodically;
  • Using and maintaining up-to-date firewall, and anti-virus and anti-malware software to protect against threats posed by hackers;
  • Using supported and trusted software or, alternatively, implementing appropriate controls regarding the use of unsupported software;
  • Preventing the use of unauthorized software through the use of application whitelists;
  • Using automatic software updating functionality or, alternatively, manually monitoring the availability of software updates, installing updates, and spot-checking to ensure that updates are applied when necessary;
  • Using supported and current operating systems or, alternatively, implementing appropriate controls regarding the use of unsupported operating systems;
  • Regularly backing up systems and data as part of a sustainable disaster recovery and business continuity plan;
  • Deploying encryption software to protect the data on equipment in the event of theft or loss of the equipment;
  • Using network segmentation and network access controls;
  • Using secure software development practices if the Member develops its own software;
  • Using web-filtering technology to block access to inappropriate or malicious websites;
  • Encrypting data in motion, (e.g. encrypting email attachments containing customer information or other sensitive information), to reduce the risk of unauthorized interception; and
  • Ensuring that mobile devices are subject to similar applicable safeguards.

Will you trust your selfie to make your online payments?


The online payments industry has seen quite a boost in the past few years. Apps like Paytm, PayUMoney and Oxigen Wallet made it simpler for smartphone users to store their Debit/Credit card information for quicker checkouts, but soon these apps might face some stiff competition from industry players entering the Biometrics Payment space. Most Apple users have already experienced authenticating payments for iTunes and other purchases using Touch-ID.

Google too has activated touch-payments on its new Play Store for Android users. But now, your finger will not be the only body part enjoying this priveledge. In a move to hop on to the tech bandwagon, Mastercard is also strengthning its plans to introduce a pilot programme, which will allow users to authenticate their payments by clicking a Selfie. The pilot programme will roll out on Mastercard's identity check app and users will be asked to verify payments by aligning their face to a circle (the way you align your cards for Uber)  and blinking to take a Selfie.

Online market place, Alibaba had also announced its plans for a facial recognition payment platform in association with Ant Financial, but unfortunately, owing to strict regulations in China, it hasn't seen the light of day till now.

Smartphone giants, Samsung & LG have also expressed interest in the Biometrics payment space and if rumours are to be believed, future flagships like the Samsung Galaxy S7 & LG G5 may come with a new Iris scanner. With the iris security protocol, users can scan their eyes (Mission Impossible style) and create their biometric identity, which can later be used to make online payments. According to a recent report by Tractica, by 2021, 34% of all smartphones shipped wordwide will sport atleast a fingerprint sensor.

So yes, lots is happening in the biometrics payment space, but is all that's happening good for end users? Afterall, biometrics is no joke and such technology is highly vulnerable to hack attacks.

Last year, German hacking group, Chaos Computer Club (CCC) managed to pick up fingerprints of the German Defense Minister, Ursula von der Leyen, using just a standard photo camera and fingerprint identification technology - VeriFinger. CCC managed to click pictures of the minister's thumb during a press conference and created an identical copy of the print which could easily fool present finger-print recognition software.

Ethical Hacker and CEO of Lucideus Tech, Saket Modi says, "When you replace conventional passwords it is always better to go for biometrics as it's more secure." But, he also says that there is a loophole.

"The moment there is a software that authenticates a pre-existing image, (in this case a fingerprint or a selfie) there are multiple flaws that are possible. These flaws in the software can be played around with by hackers," claims Modi. He goes on to add that one should not assume that biometrics is 100% secure and that it is possible to run forensics on a smartphone's hard disk to recover any kind of biometric information.

That said, the future of biometric payments, atleast in India, seems a little bleak. "Passwords are not going anywhere anytime soon. People still understand the conventional ways. India has a large population, not very educated about digital platforms and will still prefer convential payment methods," predicts Modi.

So will you trust your 'Self'ie to clear your payments? Tell us your thoughts about biometric payment methods in our comments section below.

How to Use an Android device as Second Monitor for your PC or MAC

How to Use an Android device as Second Monitor for your PC or MAC!! 💠 The method is quite simple and easy and you just need to follow...