text

FOSSASIA - THE PERFECT TECHNOLOGY BLOG... We are Fossasia Technologies, we are trying to provide you all the latest information about Information Technology, Best Search Engine Optimisation (SEO) Technique. We are doing research on the daily basis to provide you all the best technique for SEO so that you can use them on your projects to get high ranks on the SERP(Search Engine Result Page). These techniques are the best techniques through which you can get organic traffic from all the search engines on your website. We are Fossasia Technologies providing latest news about IT Field.
Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Friday, 21 August 2015

How hackers hijack the net's phone books

How hackers hijack the net's phone books


The net's DNS system acts like a switchboard to route your data correctly

Online services that charge to kick people out of games or bombard websites with data have been put out of action by PayPal and security researchers.
The payment firm and the experts worked together to identify the accounts used by so-called "booter" services,

They are thought to carry out hundreds of thousands of attacks each year and charge up to $300 (£200) a month.

Research suggests the action cut the number of active booter services by about 90%.

The booting services use many different ways to batter sites with data but have joined with many other cyber criminals recently in abusing art of the net's net infrastructure - the Domain Name System (DNS).

This acts like a phone book and translates the website names people use into the numeric equivalents that computers are happy with.

So when you type bbc.co.uk, DNS translates that into 212.58.244.18 so your browser can find the page.

"DNS underlies everything you do on the internet," said Neil Cook, chief technology officer at security firm Cloudmark. It is used billions of times a day to make sure you reach the site you are looking for. 

Its very usefulness has made it a tempting target for criminally-minded hackers, said Mr Cook, especially because few firms see it as a potential attack vector.

"Most people just see it as plumbing," he said. "They don't see it as a security hole."

A 'rogue' operator was using DNS as a way to cut the cost of using the web overseas

But it is, he said. An attacker that can subvert the DNS system has total control over the data emerging from a company, internet service provider (ISP), home or phone. 

Cloudmark was alerted to its potential for trouble by one of it customer, a mobile operator that noticed a massive jump in the amount of data being sent to its DNS servers. 

This was odd because the typical DNS query does not involve much data - a simple query and response. There was no good reason why, suddenly, far more data was being sent to those computers. 

Closer inspection revealed the culprit. "It was a rogue operator," said Mr Cook. "It had installed software on user's handsets so it did not have to pay roaming charges." 

The rogue was outside the UK and was funnelling customers data via DNS so it did not have to travel over the main mobile network and be paid for.
At its fastest, DNS can move data around at about 200 kilobits per second - much slower than most mobile networks. But, said Mr Cook, the fact that users paid nothing to browse the web overseas offset the inconvenience.

Back channel

Tom Neaves from security firm Trustwave said that might be plenty fast enough if an attacker wants to move a small amount of data - such as a password.

"A lot of people underestimate its potential as an attack tool because it was never meant to be used to transfer a lot of data," he said.

Mr Neaves has proved just how useful it can be for attackers by creating software that exploits DNS to slowly steal data. For criminal hackers intent on industrial espionage that slow rate is fine - especially when you consider that, on average, it takes companies more than 200 days to spot an intruder insider their network.



Trustwave has seen DNS exploited in other ways too, he said. It can be used as a command and control channel for a malicious program attackers have got running on a machine inside a network. Or as a way for attackers to communicate across networks in different companies.

And it does not end there, said senior analyst Darren Anstee from network monitoring experts Arbor. 

"There are a lot of ways to exploit DNS to do bad things," he said. 

Most often Arbor had seen it used to carry out Distributed Denial of Service attacks that sought to knock a site offline by overwhelming it with data. Using well-known techniques, said Mr Anstee, DNS servers could be tricked into sending data to a particular site. If enough DNS servers are enrolled into the attack the amount of data turning up at a target site can be overwhelming.
Arbor had seen attacks that funnelled more than 100 gigabits of data a second at a target. That's so much that it can have a knock-on effect on other systems on the same network. 

"The attack tools exist and the capability is built into various botnets and crimeware services," he said. Online there are so-called "booter" services that abuse DNS in a bid to knock people off game servers.

Attack evolution

Attackers had targeted home routers in a bid to subvert their DNS settings so they can get a look at the traffic and scoop up login names and passwords as they travel, he said.

Criminal hackers have hijacked home routers to divert traffic and steal data

Public-spirited efforts such as the Open Resolver Project have helped to patch many vulnerable home routers and stop them being abused for either DDoS attacks or to steal data. 

The OSR has enjoyed a lot of success and has managed to get about seven million devices fixed.

Unfortunately there are still about 20 million vulnerable devices accessible online, said Bruce van Nice, a director at DNS specialist Nominum. 

"That's a pretty good base of stuff that can be used for attacks," he said.
Defending against DNS-based attacks is hard because many of the defensive techniques used to counter other attacks do not work well when applied to DNS. This is because DNS only works well if data can travel quickly to and from servers. Inspecting each packet to see if it is properly formed and is not being used to steal data would slow the whole system down. Users would complain as web browsing slowed to a crawl.

There are techniques that can clean up traffic and mitigate DDoS attacks but defenders need to be aware that novel ways to abuse DNS are being produced all the time. 

Adversaries are not idle and are refining their techniques, said Mr van Nice.
"We see activity every single day and we see evolution in those attacks so someone is improving their capabilities.
"They do not do that without good reason."
 Source : bbc

We Are Fossasia Stay Connected With Us On Twitter . . . ! ! !

Sunday, 12 July 2015

Adobe to patch second Hacking Team Flash zero-day bug

Adobe to patch second Hacking Team Flash zero-day bug




Adobe next week will patch a second zero-day vulnerability found in the leaked documents from the Hacking Team, a controversial Italian company that sells surveillance software and exploits to governments, Adobe said late Friday.

The flaw will be patched this coming week; Adobe did not set a release date for the fix.

"Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system," Adobe noted in an advisory.

The vulnerability was the second uncovered in the gigabytes of documents leaked after attackers compromised the Hacking Team's network and pilfered emails, financial information and contracts from the firm's systems.

The company sells surveillance software to governments and corporations, and markets zero-day vulnerabilities that its clients can use to silently infect targets with the firm's software. According to the leaked information, Hacking Team deals with, or has dealt with, several repressive regimes, including Egypt, Russia, Saudi Arabia and Sudan, as well as with government agencies or arms of the military in the U.S., Germany, South Korea and Switzerland.

Adobe credited FireEye's Dhanesh Kizhakkinan with reporting the latest Flash flaw to the company. Kizhakkinan, a senior research scientist with the security vendor, posted some broad technical information about his findings on a FireEye blog Friday.

"The PoC is well-written, like the previous PoC by the same author," wrote Kizhakkinan, referring to the "proof of concept" attack code he unearthed in the Hacking Team's documentation.

Adobe patched the first Flash zero-day vulnerability on Wednesday, two days after researchers sifting through the massive cache had found that bug as well as others. Between Monday and Wednesday, cyber criminals rushed to add the Flash exploit code to their attack toolkits.

The same will likely happen with this newest Flash flaw, putting pressure on Adobe to quickly issue a patch. According to Adobe, the now-current editions for Windows, OS X and Linux are all vulnerable to the discovered exploit.
Source : computerworld


We Are Fossasia Stay Connected With Us On Twitter . . . ! ! !

Tuesday, 2 June 2015

Android Mobile Devices are in Danger of Hacking

Android Mobile Devices are in Danger of Hacking

According to a new study from the University of Cambridge, countless Android system operated devices are vulnerable to hacking because of the rest performed at the factories. More than 600 million devices are at risk.

The study conducted by Laurent Simon and Ross Anderson reviewed second hand Android devices which run its 2.3 to 4.3 systems. They discovered that even after resetting, the devices preserved some of the information previously stored on them, such as texts, images and data from apps

“After the reboot, the phone successfully re-synchronized contacts, emails, and so on,” states the report.
“We recovered Google tokens in all devices with flawed Factory Reset, and the master token 80 percent of the time. Tokens for other apps such as Facebook can be recovered similarly. We stress that we have never attempted to use those tokens to access anyone’s account.”

[Read the full research report here.]

Source : jewishbusinessnews

Wednesday, 27 May 2015

Threat intelligence, WiFi hacking and NSA playset

hacking
Security experts delivered a host of presentations at ITWeb Security Summit 2015 yesterday.

Commercial-grade threat intelligence, which the average firm buys to use inside the organisation, is useless, said Pete Shoard, head of cloud service product development at UK-based SecureData.

"The long and the short of it is that intelligence is a poor indicator that does not tell you anything" about what's going on in the company, said Shoard, delivering his presentation on threat intelligence-gathering at ITWeb Security Summit 2015, in Midrand, yesterday.

Shoard is responsible for the design and implementation of threat detection and defence mechanisms, and oversees the development of detection methodologies, reporting measures and response procedures. He specialises in harnessing the power of frontline technical data solutions, like SIEM, and big data platforms to deliver actionable threat intelligence.

Traditional indicators of compromise (IOCs) are fairly simple, he said, explaining most security vendors will provide a company with a list of bad domain names, malicious files, e-mail addresses (phishing senders) and IP addresses (known to be linked to threat activity).

"Those four types of indicators of compromise are very common on the market. What do they mean without investigation and research? When you find only one of those indicators of compromise on your estate, what does that mean to your organisation?

 "One would argue that means nothing to you. It just means something bad has happened on your estate – either post the event you've detected it, but you don't really know what's going on; or it has blocked it and you don't know what was coming or who's trying to get at you."

Shoard explained one way of creating more data about an attack is by adding relationships between the four indicators. "I can start to build a picture of what that hacker is trying to do to me."

The next step, he said, is to add internal intelligence to these linkages, which allows for risk-scoring of particular entities that have been targeted within an organisation. This is followed by adding external context, and then adding metadata to the indicator, he explained.

"This gives me more IOCs, helps me to understand who the targets are within my organisation; to a certain extent it gives me attribution, but definitely gives me intent. It tells me who this attack is designed for and what it's after," he said.

"I can take that intelligence and turn it into something actionable. I can prioritise my vulnerability management and prioritise how I use intelligence coming into my organisation, to make my organisation more secure by [giving direction to] that intelligence."


Speaking about the ubiquitous hacking medium of WiFi, Dominic White, CTO of information security company SensePost, said the company's Mana toolkit had been updated to include a range of improvements.

The new version of Mana, which incorporates SensePost's post-launch research, was available as of yesterday. The research involved rogue access points – wireless access points that mimic real ones in an attempt to get users to connect to it.

The range of tools in Mana is wide-ranging, but the toolkit simplifies attacks. The kit can be run on a Linux device or in a virtual machine, needing only a suitably capable wireless interface card, he said.
A single command launches a series of tools, starting by investigating wireless clients and networks in the area. Clients are forcibly disconnected if already associated with a network, and then encouraged to reconnect to a fake access point controlled by the toolkit.

Credentials are captured and decrypted. A man-in-the-middle attack gives clients the appearance of an Internet connection, and traffic is then captured and analysed, said White.

The toolkit can also create a fake WiFi hotspot service to dupe users into connecting, and new capabilities can push network profiles or digital certificates to a target device, allowing easier attacks against encrypted traffic.


According to Michael Ossmann, founder of Great Scott Gadgets, the NSA playset was inspired by the NSA ANT catalogue – a 50-page classified document listing technology available to the US National Security Agency (NSA) to aid in cyber surveillance.

He said the NSA playset is a set of security tools used by nation states to attack computer systems. "By sharing and building these tools, we are democratising technology, making it available to everyone."
The more of these kinds of security hardware built by the information security community, the more they will find ways of stopping these kinds of attacks, Ossmann pointed out.

"If we don't understand what the vulnerabilities are, we are never going to make systems hardware less vulnerable to nation states attacks. The more we build these things, the closer we are to building the next-generation technologies that take these playsets into account." The reason for the NSA playset is to raise awareness within the security field, understand the threats and find countermeasures, he added.
An example of the NSA playset, he revealed, is the SLOTSCREAMER, which is configured to access memory and IO; it is cross-platform and transparent to the operating system – with no zero-day needed. "The open hardware and software framework that we will release will expand the user's NSA playset with the ability to tinker with DMA attacks to read memory, bypass software and hardware security measures, and to directly attack other hardware devices in the system."

Another example is the KeySweeper device, which works like a typical USB wall charger. It "sniffs" and logs keystrokes made on nearby wireless keyboards. A device sends these decrypted, logged keystrokes to a hacker remotely.
Enjoyed this story? Subscribe us  Fossasia .

Source : itweb

Why Hacking Is Taking Place Even Aboard Flights

Why Hacking Is Taking Place Even Aboard Flights

NEW YORK (MainStreet) — Hacking is becoming more commonplace, and your data is not safer 30,000 miles up on in the air.

While surfing, shopping or sending emails aboard a flight is becoming more popular and is convenient as more airlines are adding Wi-Fi, your connection is just as insecure as hanging out in your local coffee shop.
Here are some common tips to avoid being hacked at the airport or during your flight.

If you are going to connect to a free wireless network, check to see if it is a secure, trusted hotspot operated by a known organization such a JetBlue, said Sergio Galindo, a general manager of GFI Software, a Durham, N.C. developer of IT solutions for small and medium-sized businesses.

Remain skeptical of suspicious-looking network names such as “Free Wi-Fi” or “AmAir2,” he said. Avoid logging into sensitive sites or engaging in mobile banking while on a free Wi-Fi network.
If you have to log-in through a website, make sure the site is secure and looks legitimate such as the fact that that everything is spelled correctly in the URL.

Paying for wireless connectivity does not mean it's secure. Other so-called “secure” Wi-Fi networks can still pose risks because they are difficult to manage. At some airports or airlines, those networks may not be managed at all, Galindo said.

“IT admins at airports often don’t have the time or resources to constantly monitor for intruders or interlopers,” he said. “It’s important to stay vigilant and follow data security best practices at all times.”

Since airline Wi-Fi networks are similar to public Wi-Fi networks because they are designed with the lowest possible interference against getting users connected, the amount of security on these networks will be “nearly non-existent,” said Mark Parker, a senior product manager at iSheriff, a Redwood Shores, Calif. cloud security provider.

“Users should assume that they are on a network that could potentially be shared by everyone else on the plane,” he said. “This means that there is nothing between your device and the device of that shady looking character over in seat 22D.”

Mobile Devices Can Be Hacked Too
It’s not only your laptop that hackers can worm their way into. Don’t forget about your smartphone and tablet. If you want to avoid the possibility of hacking altogether, turn off the Bluetooth and Wi-Fi on your mobile device and only use the LTE/4G/3G data connection from mobile device, said Jason Hart, a vice president at Gemalto, a Belcamp, Md. digital security company.

“It is easy for hackers to spoof Wi-Fi networks and fool your mobile device into connecting to it,” he said. “They do this by setting up spoof networks using commonly used Wi-Fi network names and your mobile device will automatically connect to a Wi-Fi network if it recognizes the name.”
 When you are using your laptop, only turn on Wi-Fi when you are connecting to a known Wi-Fi network and always turn on the Virtual Private Network (VPN) connection which routes your online activities through a private and secure network even when using Wi-Fi.
Make sure you disable all sharing services like iCloud on a laptop or mobile device. This is crucial, because not doing this means “you’re opening yourself up to more data and content that can be stolen,” Hart said.
Use two-factor authentication on everything that requires a password, including social media, because that’s “just good security hygiene,” he said.

Breaching most networks or systems is something that can be done easily, said Dave Bennett, CTO of IONU, a data security company based in Longmont, Colo. While having more access to Wi-Fi sounds like a good thing for consumers, in reality it is just opening more people up to additional data loss because public networks are “hideously unsecure,” he said.

“They can easily be snooped [allowing] them to get access to your data,” Bennett said. “It is common for trains, airplanes, airports and hotels to provide wireless access, and these are ripe for being compromised and becoming a common means of data leakage and loss.”

Instead of assuming that you won’t get hacked because you have software installed on your laptop, a better strategy is to “always assume that the network is compromised because it almost always is,” he said.
Travelers on a plane are even more vulnerable, because they are more likely to be have their Wi-Fi turned on for hours and do not suspect any intrusion attempts.

Since airlines appear to be switching to having fliers use their personal computers and wireless devices to deliver in-flight entertainment, this only opens up another connection which can be compromised and give hackers access to people’s data.

If your data is properly protected and backed-up, you are less vulnerable to data loss.
“Most people don’t protect their data or take some easy precautions before traveling,” he said. “They are just tempting fate.”

Even someone on your flight could be attempting to hack into your data, Bennett said.
 “Frankly, there are so many different ways in which you can attack someone’s computer if you know they are sitting a few seats away,” he said.

Commercially available products can allow a moderately computer savvy person to act as a “man in the middle” of a wireless network, Bennett said. Some of these devices are battery operated and small enough to be carried on board easily and allow the person to monitor, “snoop” and modify traffic flowing through the device such as such as e-mail, instant messages and browser sessions.

“Even someone who's security conscious can be easily burned by something like the Pineapple device,” he said. “Once a hacker on the plane finds a way onto your computer, they can implant malware such as Poison Ivy, with which they can take control of your computer, log your keystrokes to learn all of your passwords and provide a backdoor into your computer and access to your data.”

Travelers should take the same precautions you would with every other public network you use, “you’ll just be doing it in a much less comfortable seat at 35,000 feet,” said Parker.

Limit the amount of personal information you have on your portable devices, said Steve Weisman, a Boston lawyer and a lecturer of law, taxation and financial planning at Bentley University in Waltham, Mass. Use the cloud and opt for dual factor authentication which seeks two forms of identification such as a password and an SMS notification to access it.
“What you don't have can't be stolen,” he said. “Remember, even paranoids have enemies.”

Source : - mainstreet

Monday, 11 May 2015

top 10 infamous hackers and viruses

Urban Outlaws author Peter Jay Black gives a rundown of the most devious hackers and nastiest viruses he knows, and warns how to protect yourself against them

hacking

When you read about the “perfect crime” in a newspaper or a book, well, it can’t be. How could it? If it was a perfect crime, no one would ever find out! So, writing a list that includes the top hackers in the world doesn’t necessarily mean they were the best. The best hackers are the ones you never hear about. The best hackers are the people who remain anonymous. My list includes the ones that got caught, but they were still very impressive. Who knows, perhaps even the best hackers all get caught eventually.
Like many words in the English language, “hacker” has shifted in meaning over the years. The modern interpretation is “a person who uses computers to gain unauthorised access to data.” And although there are various arguments and stories about the origin of the term, its source is most likely from the Massachusetts Institute of Technology, during the early 60s.

There are different types of hackers too:

A White Hat is someone who doesn’t hack with criminal intent. These are the guys who work with companies, testing their security and reporting any weaknesses.

A Grey Hat, on the other hand, is someone who uses his or her hacking skills for both legal and illegal activities. They hack into secure systems without permission (the illegal bit) but they never steal money or data. They just do it to prove they can!

A Black Hat is someone who hacks into systems with deliberate criminal intent. This can be to steal money or information from companies or individuals.

Moving on to viruses, these are a completely different matter. Viruses come in all shapes and sizes. Some can just be a nuisance – like shutting down your computer, closing windows, things like that – while others can be very harmful - like stealing your personal information.

Steven Hawking has an interesting idea about computer viruses: “I think computer viruses should count as life. I think it says something about human nature that the only form of life we have created so far is purely destructive. We’ve created life in our own image.”

So, without further ado, I present a list of the top 10 infamous hackers and viruses. Remember, all of the hackers are black hat and all the viruses are very nasty!

1. The Creeper virus was first spotted on the internet’s pedecessor, Arpanet. It was a self-replicating program written in the early 70s. Once on the infected system, it would taunt people with the message, “I’m the creeper, catch me if you can!”

2. The Brain is considered to be the first MS-DOS virus in the world. It first appeared in January 1986 and caused disruption by replacing the boot sector of floppy discs. This virus – unlike many others – was quite obvious as it renamed the discs.

3. The Melissa A virus came in an email with a message that read “Here’s the document you asked me for…do not show it to anyone.” Then, once opened, the virus spread using the first 50 people in the address book. Its creator was sentenced to 10 years in prison, but received a shorter sentence for aiding authorities in capturing another virus creator.

4. Kevin Mitnick hacked various big companies such as Motorola and Nokia and caused a lot of problems. At one time, he was considered the most wanted computer criminal in United States history. But he changed later from a Black Hat to a White Hat and now Kevin helps companies with their online security.

5. Adrian Lamo hacked into many famous networks, such as Microsoft and The New York Times. In 2010, he reported a US soldier for leaking sensitive documents to WikiLeaks.

6. Vladimir Levin led a hacking group that carried out what’s thought to be the first online bank robbery! He transferred $3.7m from Citibank in over eighteen separate attacks. He was later caught and arrested at a London airport, then convicted and jailed.

7. In January 2007 the Storm Worm virus spread through computers using an email with a the subject line “230 Dead as Storm Batters Europe!” This was then used to entice readers into opening the email. When they did, their computer was infected with malware and a Trojan. Over three days the Storm Worm was thought to be accountable for 8% of malware globally!

8. In the early 1990s Kevin Poulsen hacked a radio competition phone line to make sure he was the 102nd caller and win a Porsche 944! The FBI pursued Poulsen for 18 months before he was caught and sent to prison. After leaving prison, Kevin became a journalist.

9. The Chernobyl virus rears its head each year on the anniversary of the Chernobyl disaster. This one is particularly nasty – it replaces critical computer files and even the main BIOS – which is essential for starting your computer! According to reports, it’s caused an estimated $1bn of damages.

10. Robert Tappan Morris invented the first known worm which appeared in 1988. It attacked thousands of computers at Cornell University causing many millions of dollars worth of damages.

So, now you know all about the nasty hackers and viruses out there how can you protect yourself from them? Unfortunately, you can’t. Well, not completely. What you can do to help protect yourself is add firewalls, install anti-virus programs and malware alerts, to let you know and help protect you from any potential threats.

The main thing to remember is to be careful!

Every time you go on to the internet, make sure you don’t share your personal data with a website unless you 100% trust them. Don’t click links on emails when you don’t know who they came from. Above all else, never share your address, real name or bank details with anyone you don’t know. It’s amazing what tricks bad people will try to catch you out!

And, like the best hackers in the world, remain forever invisible!


Source : - theguardian

Wednesday, 6 May 2015

How Dorkable Is Your Business?

hacking


It’s no surprise that businesses often make basic mistakes when it comes to cyber security. Whether it’s using “password” as a password, not having a firewall set up, forgetting to run security updates on the operating system, giving employees too much access to critical data -- the list goes on and on.
But there’s another mistake companies often make, simply because they don’t even know it’s a threat at all: exposing sensitive information to Google “dorking.”
Google dorking, or Google hacking, is one way malicious hackers can gain access to valuable information about a company. It involves using advanced commands in Google to find specific data sets that companies, as well as government agencies, have unwittingly made accessible by storing them on public-facing web servers.
These files aren’t easily found by the average person, however, anyone who knows how to perform a specialized web search can retrieve them in a matter of minutes. The type of information exposed to this type of search can include user logins and passwords, email lists, employer identification numbers (EIN), bank accounts, software settings, etc.
Exposing this information is dangerous, because it can pave the way for phishing email attacks, network breaches, financial fraud and much more. In fact, many sophisticated phishing campaigns rely on this type of open-source intelligence to create customized, highly convincing emails for targeted employees and executives. The threat is so severe the Department of Homeland Security issued an alert last year to law enforcement and public safety agencies, warning them about the potential risk of data breaches specifically due to Google dorking.
So, how does a company become vulnerable to this threat?
It essentially boils down to having sensitive files stored on a public web server, but that can happen in a few different ways.
First, a company could be storing this data on its own web architecture to make it easy to access or share these files within the company, as well as with its clients or vendors. However, the reverse is also true -- a company’s clients or vendors could upload its information to share or access more easily. There’s also the risk that executives or employees will store company files on third party sites with weak security. Lastly, federal, state and local government agencies routinely collect corporate data like tax IDs, which are often stored online in spreadsheet files.
Because a company’s private data is often housed by multiple parties, it’s impossible to eliminate this risk entirely. However, businesses can take a number of steps to significantly lower the damage potential.

1. Remove all sensitive information.

Every business should start by asking itself two key questions: which information is too valuable or risky to disclose to the public, and does any of that data really have to be stored through its website (i.e., on a public web server)?
Examples may include personnel files, customer profiles, financial records, etc. Sensitive files like this should never be stored through the website unless it’s absolutely essential for business operations. It's far safer to store them separately on a private, encrypted server.

2. Protect data that can’t be moved.

If a company has to keep sensitive data on its website, there are two ways it can protect it: encrypt it (require a login and passcode to access the data) and make sure the site is configured with robots.txt files to block web crawlers like Googlebot from indexing the data in public searches.
This, however, is a less secure solution than the one mentioned in No. 1, so think carefully about the risks versus benefits before going ahead.

3. Check the company’s online footprint.

Do a routine check to see if the company has critical data exposed on the web.
Here’s a simple way to do this: (a) Go to Google.com, (b) type in “site:COMPANY.COM filetype:xls”; (c) see if this pulls up any sensitive information; and (d) repeat the same command for DOC, PDF, PPT and other file types the company in question may use.

4. Remediate exposed data.

If private corporate information is found to be accessible on the web, use Google’s Webmaster tools to remove it from the cache.
However, if third parties are responsible for the accidental disclosure, notify them immediately and request the information be pulled from the Internet, servers and Google’s cache.
Source : - entrepreneur

The world’s most wanted hackers

The world’s most wanted hackers

Computer hacking is today a widespread, worldwide phenomenon, involving everyone from ‘script kiddies’ and activists to cyber-crime gangs and nation states. We Live Security looks at some of the world’s most wanted hackers who remain on the run, despite the wanted posters and big bounty signs.
Evgeniy Bogachev 
Evgeniy Bogachev is currently right at the top of the FBI’s top most wanted hackers and there’s good reason why – the Russian is widely-believed to be the writer, developer and mastermind behind the Game over Zeus botnet which, when working in tandem with the CryptoLocker ransomware, infected some 500,000 PCs worldwide.
Zeus looked to steal bank account numbers, passwords and other personal details, while it was also used to distribute CryptoLocker – the ransomware used to take over computers, encrypts files and demand a ransom in exchange for their decryption and safe return.
These two combined made for a powerful force – it’s believed that Bogachev was able to steal around $100 million prior to law enforcement disrupting the infrastructure behind Zeus and CryptoLocker.
Bogachev, known as “lucky12345” or “slavik” online, had other team members helping to conduct spam and phishing emails as the initial hook for victims. He was first indicted by a federal grand jury in Nebraska in August 2012 under charges of conspiracy to participate in racketeering activity, bank fraud, conspiracy to violate the Computer Fraud and Abuse Act, conspiracy to violate the Identity Theft and Assumption Deterrence Act, and aggravated identity theft. Just last year, he was finally indicted under his real name.
United States is offering a $3 million reward for information leading to the arrest or conviction of Bogachev, as reported by We Live Security here.
People’s Liberation Army Unit 61398 (China)
Last May, a grand jury in the Western District of Pennsylvania indicted what is believed to be five members of the People’s Liberation Army (PLA) Unit 61398, widely believed to be China’s prolific cyber-army.
The group was charged with 31 criminal counts, including; conspiring to commit computer fraud; accessing a computer without authorization for the purpose of commercial advantage and private financial gain; damaging computers through the transmission of code and commands; aggravated identity theft; economic espionage; and theft of trade secrets.
It is alleged that, between 2006 and 2014, Wang Dong, Sun Kailiang, Wen Xinyu, Huang Zhenyu and Gu Chunhui – all allegedly officers in the PLA Unit 61398 – were involved in a hacking conspiracy to compromise the computer networks of six American companies during times when the firms were engaged in negotiations, joint ventures or legal action with, or against, state-owned enterprises in China.
It is alleged that the Chinese hackers used their illegal access to steal proprietary information including, email exchanges between company employees and, more crucially, trade secrets relating to technical specifications for nuclear plant designs.
All five are charged with one count of conspiracy to commit computer fraud, eight counts of unlawfully trying to access information for commercial advantage, 14 counts of trying to secretly damage protected computers, six counts of identity theft, one count of economic espionage, and one count of trade secret theft. The US companies involved include Westinghouse, SolarWorld, the US Steel Corp, Allegheny Technologies, Alcoa and the US Steelworkers’ Union.
If captured, each of the five faces a maximum sentence of 217 years in prison.
Alexsay Belan
Alexsey Belan, a Russian national, is wanted for his alleged role in the hacking of three US-based companies between January 2012 and April 2013.
He is understood to have hacked into the computer networks of three major e-commerce companies in Nevada and California, stealing their user databases and sending them onto his own server. He also allegedly stole user data and the encrypted passwords of accounts, before selling the databases (presumably on the dark web).
Two separate federal arrest warrants for Belan have been issued dating back to September 2012, and they see the Russian charged with obtaining information by computer from a protected computer; possession of fifteen or more unauthorized access devices; and aggravated identity theft. The second warrant, issued in the following June, came after Belan was charged with two counts of fraud in connection with a computer and two counts of aggravated identity theft.
The FBI is offering a reward of up to $100,000 for information leading to the arrest of Belan, who is also considered an international flight risk.
Ercan Findikoglu
Ercan FindikoÄŸlu is suspected of stealing $60 million in card fraud and faces a possible 247 years in jail.
At one stage number two on the FBI’s most wanted list, FindikoÄŸlu, 33, stands accused of participating in numerous cyber criminal operations, most notably the hacking of the EnStage and ElectraCard payment card processors in India.
He and his team allegedly managed to alter the prepaid debit cards and remove the withdrawal limits.  These cards were then distributed to his cyber-criminal gang around the globe along with stolen pin to orchestrate a coordinated withdrawing spree.  The withdrawals were so successful that the group was believed to have stolen $45 million through around 140 ATMs in New York alone.
FindikoÄŸlu, first charged by the FBI in 2008, had previously run similar payment scams against cards from a bank in the UAE.
Yet despite being arrested by German police on an international warrant at Frankfurt airport in December 2013, he is yet to be extradited to the US. While a lower German court initially ruled that the police could extradite, Findikoglu appealed to the German supreme federal court, which overturned the decision. It said that there was no guarantee Findikoglu would not receive a disproportionate sentence if extradited to the US.
Andrey Nabilevich Taame
Syrian national Andrey Nabilevich Taame allegedly played a role in “Operation Ghost Click”, a malware scheme which infected more than four million computers in over 100 countries between 2007 and 2011.
The malware, ‘DNS Charger’, enabled hackers to modify browser settings on Windows to redirect traffic to advertising sites with malicious ads. The virus was first detected on NASA’s computer network.
Taame’s accomplices were arrested in November 2011 but Taame, who was born in Syria, remains on the run.
Farhan Ul Arshad
Farhan Ul Arshad is wanted for his alleged involvement in an international telecommunications scheme which defrauded individuals, companies and governments across the world, for almost four years and for millions of dollars.
Between November of 2008 and April of 2012, Arshad is believed to have compromised computer systems and conducted the scheme which ultimately defrauded victims of amounts in excess of $50 million. The international scheme involved members of a criminal organization that extended into Pakistan, the Philippines, Saudi Arabia, Switzerland, Spain, Singapore, Italy, and Malaysia, among other nations.
In June 2012, a federal arrest warrant was issued for Arshad , a Pakistan national working as a telecoms manager, in a United States District Court after he was indicted for conspiracy to commit wire fraud; conspiracy to gain unauthorized access to computers; wire fraud; and unauthorized access to computers.
FBI is offering reward of up to $50,000 for information leading to his arrest. Arshad was last known to be in Malaysia.
Source : - welivesecurity

Thursday, 30 April 2015

Travel Tip: What You Need to Know About Hotel Credit Card Hacking

travel money tips
Credit ­card fraud is no joke, and one of the riskiest places for credit card hacking is in hotels.
The most recent security breach was at Mandarin Oriental hotels, where hackers collected guests’ private credit­ card information. They targeted all of Mandarin’s properties in the U.S., and that may have started as far back as the end of last year.
A couple of years ago, there was a major attack on a management company with franchises like Hilton, Marriott, and Westin. Credit and debit ­card numbers were stolen from guests who used their cards in the hotel restaurants and bars.
Unfortunately, hotels tend to be big bullseyes for credit ­card fraud because of the high turnover, large number of transactions, and often outdated computer software.
Your best defense in this case is a good offense. Use a more secure card with an embedded microchip for travel. Keep a close eye on your statements, and focus specifically on small charges that wouldn’t necessarily be flagged by your credit­ card company as fraudulent transactions.

Source : - petergreenberg

10 biggest worries of global businesses

In a world of globalized business, companies have the opportunity to increase their scale. But they also face increased degrees of risks on many fronts. These days, the top concern of executives doing business around the world is the potential damage to brand and reputation, according to a new survey from risk management company Aon Risk Solutions. This is the first time that particular worry rose to the top since Aon began running this biennial survey in 2007.
Interviews with 1,418 companies around the world found the following 10 issues to be the most worrisome for global executives this year:
  1. Damage to reputation/brand
  2. Economic slowdown/slow recovery
  3. Regulatory/legislative changes
  4. Increasing competition
  5. Failure to attract/retain top talent
  6. Failure to innovate/meet customer needs
  7. Business interruption
  8. Third-party liability
  9. Cyber-risk (computer crime/hacking/viruses/malicious code)
  10. Property damage
The second item shows that companies still aren't comfortable with the pace of global economic improvement. However, such concerns finally moved from first place to second.
As worries about the world economy have abated, even if only a bit, longstanding concerns about such factors as reputation damage, competition, attracting and retaining talent, and business interruption "are taking on new dimensions and complexities," according to the Aon report.
"What's key is understanding the components of that risk [and] the connection with other risk," Rory Moloney, chief executive officer of Aon Global Risk Consulting, told CBS MoneyWatch. Executives should understand "risk in its [divisional] silo and also its exposure across the enterprise."
In the case of business interruption, companies now have to manage and protect global supply chains, in which an intricate set of suppliers and delivery routes brings together all the components for a product. A natural disaster, war, labor strike or other issue in one part of the world can disrupt the movement of goods with a chain of economic implications in multiple countries and among many different companies.
This is the first year that concerns over computer crime, hacking and malware have landed in the top 10, which is an interesting occurrence given how reputational damage is perceived as a byproduct of a digital attack and major cyberbreaches have been regular news for years.
As Sony (SNE), Home Depot (HD), Target (TGT) and plenty other big companies have learned, inadequate preparation for a cyber attack can result in ugly press and apparent reputational damage.
However, risk management can involve allowing something to happen because the costs to prevent the problem are greater than the perceived costs of the results. For example, many companies don't fix cybersecurity issues because the quantifiable financial downside is relatively tiny. According to the Ponemon Institute, Sony's reputation took a beating a few years ago after a major breach of its networks and the loss of large amounts of personal customer information. But in less than six months, things were back to normal.
Still, as the latest Aon survey found, the topic of cybersecurity has risen to the top 10 list of executive concerns.
Source : - cbsnews

Sunday, 26 April 2015

Will cyber attacks switch off the lights?

couple of months ago I lost my mobile phone. I duly called AT&T, my telephone company, to order a replacement — and received a nasty shock.

“So you are living in Shanghai,” an assistant announced, quoting an entirely unfamiliar Chinese address. Baffled, I explained that I didn’t live anywhere near the Bund; my residence was in Manhattan, New York.

cyber attack


“No, you live in Shanghai,” the voice firmly replied. When I protested vociferously, the AT&T official pronounced the three words that we have all come to dread: “You’ve been hacked.” Somebody, somehow, had managed to break into the AT&T systems and switch my cellphone billing address from New York to Shanghai. Presumably, they were Chinese.

Thankfully, I don’t seem to have suffered any financial loss from this breach: my account details were corrected and, as far I can tell (though it may be tempting fate to say so), nobody in China is walking around with a free iPhone in my name. But, like millions of others who have suffered similar attacks, I was left feeling violated and uneasy. And not just in relation to my phone.
These days we all rely so much on the internet that it’s difficult to imagine life without it; digital communications are intrinsic to almost every aspect of our daily existence. The terrible paradox of 21st-century living is that just as we are all becoming ever more dependent on those digital links, so the web is facing a dramatic increase in cyber attacks, either from criminals, mischief-makers or malevolent players such as terrorists. And in general we only discover just how vulnerable we are when something goes unexpectedly wrong — be it with mobile phones, bank accounts or anything else.

Electricity is one issue that has recently caught my attention. The modern western economy is highly dependent on the electricity grid, and whenever the grid has gone down in America — say, after Hurricane Sandy in 2012, or during the infamously widespread 2003 outage in America’s northeast — this has resulted in profound disruption.

So far — thankfully — no one has succeeded in creating any such major disruption by hacking into the electricity grid. In that sense, the situation seems a little better than in banking, where institutions including JPMorgan and Citigroup have suffered a series of cyber breaches.
Any sense of calm among power companies is illusory, however. Last week I attended a seminar with some cyber security experts and executives from the energy sector, where I was told that the power companies are now under constant, accelerating attack, either from troublemakers or (more often) state-sponsored players (think China and Iran). Nobody will say publicly how big or serious these attacks are but an investigation by USA Today earlier this year found that between 2011 and 2014 there were 362 reports of physical and cyber attacks on electric utility companies, according to the Department of Energy. Indeed, in 2013 alone some 161 cyber attacks on the energy sector were reported to the Department of Homeland Security, more than five times the level of two years before.

The power companies are fighting back and investing more in cyber surveillance. They are also creating what are known as “air gaps” between the networks (systems that ensure the grid can split apart quickly in the event of a breach, to stop contagion). Different parts of the federal government have quietly started holding joint briefing meetings about this.
And the good(ish) news, I was told, is that the public and private sectors are co-operating relatively well in this area, at least in comparison to other sectors such as banking. One reason for this, apparently, is that events such as Hurricane Sandy have created a template for joint public-sector/private-sector planning.



But numerous challenges remain. One problem is that electric power equipment tends — ironically — to be made in places such as China, which creates obvious risks. Another issue is that the components used in power stations tend to be so customised that they are difficult to replace in a hurry if damage occurs. Companies today do not keep an inventory of spare parts.
The other big issue is that nobody entirely knows whose responsibility it is to protect against these attacks. If terrorists conduct a physical attack inside America, it is generally assumed that the state — not private mercenaries — should fight back. But is it the government’s role to build inventories of a power company’s spare parts? Should the state be training cyber-surveillance officers? Or should companies do this themselves — and hope that shareholders will not punish them for investing in projects that do not produce returns?

There is unlikely to be any clear answer until — or unless — a really big attack on a banking network, phone system or electricity grid proves successful. Which is an alarming thought. But in the meantime, I am checking my utility accounts, bank accounts and phone bills a little more regularly. And I now plan to collect a stash of candles, batteries and tinned food. If the lights do go out, I want to be ready; or at least a little savvier than I have so often been with my mobile phone.

Source: - ft

Saturday, 25 April 2015

Infosec bods can now sniff out the NSA's Quantum Insert hacks

Sneaky state-sponsored snoopery can be picked up by counting HTTP packets


hacking

Security researchers have developed a method for detecting NSA Quantum Insert-style hacks.
Fox-IT has published free open-source tools to detect duplicate sequence numbers of HTTP packets, with different data sizes, that are the hallmarks of Quantum Insert.

The utilities developed by Fox-IT are capable of exposing fiddling with HTTP packets but are no by no means perfect and might themselves be circumvented, as a blog post by Fox-IT explains.
Quantum Insert, a favoured signals intelligence hacking technique exposed by documents leaked by Edward Snowden, is an "HTML redirection" attack that works by injecting malicious content into a specific TCP session. A session is selected for injection based on various factors or selectors, such as a persistent tracking cookie that identifies a person of interest.

When an interesting target is observed while eavesdropping on network traffic, another device – the shooter – is prompted to send a spoofed TCP packet. In order to craft and spoof this packet into the existing session, information about this session must already have been obtained. For the attack to work, the packet injected by the shooter has to arrive at the target before the "real" response of the webserver. If this is done successfully, a cyberspy or hacker can impersonate a webserver before flinging malicious traffic in the direction of targets, as explained in a video put together by Fox-IT. All this takes advantage of inherent weaknesses in TCP.

Anyone capable of monitoring a network and sending spoofed packets can perform Quantum-like attacks, although in practice it's easier for nation states to pull off this sort of subterfuge.
It's not only the NSA and the UK's GCHQ getting up to these shenanigans. China recently pulled off this type of attack, as research by CitizenLab on China’s Great Cannon illustrated.

"Detection is possible by looking for duplicate TCP packets but with different payloads, and other anomalies in TCP streams," explained Lennart Haagsma, a network security analyst at Fox-IT, adding that various counter-measures aside from its new detection tools are already available.

"The usage of HTTPS in combination with HSTS can reduce the effectiveness of QI [Quantum Insert]. Also using a content delivery network (CDN) that offers low latency can make it very difficult for the QI packet to win the race with the real server," he said.

The Snowden leaks include a slide from the Communications Security Establishment Canada describing how to detect Quantum Insert attacks, a useful pointer highlighted by Fox-IT that helped the Netherlands-based firm on its way towards developing Quantum Insert-sniffing tools.

Source : - theregister

Wednesday, 22 April 2015

Hackers using startling new ways to steal your passwords

hacking of password

You are dining outside in a restaurant and you receive an email. You remove your phone and without even thinking twice, you key in the PIN required to unlock your phone. Nobody can see what password you have typed, as your back is facing the wall. Hence, you are not worried that someone could intercept your passcode. However, sadly, there is.
Hackers can speculate PINs by interpreting video of people tapping on their smartphone screens even when the display itself is not visible, according to the presentation shown by the researchers at Syracuse University.
Software used to interpret such video relies on “spatio-temporal dynamics” to measure the distance from the fingers to the phone’s screen, and then guess exact which characters the fingers tap on a keypad. “It’s like lip reading,” says Vir Phoha, an engineering and computer science professor at Syracuse and co-author of a paper on the technology. “Based on hand movement and the known geometry of the phone, we can see which keys are pressed.”
No instances have been reported of hackers stealing PINs in such a way has been reported, however, it’s only a matter of time as anticipated by technologists. Phoha and three others Syracuse researchers wrote in their paper that “We believe that it is very likely to be adopted by adversaries who seek to stealthily steal sensitive private information.” This research was published by the Association for Computing Machinery last year. The technology is very easy simple for anybody who knows programming, and millions of targets are available due to the flaring use of smartphones.
In addition to this, the increased use of phones for doing banking transactions and managing other financial accounts makes PINs a profitable deal for hackers. The same video-analysis technology can be used to interpret PINs perforated into ATMs, smart locks on the front doors of homes, garage door openers and other gizmos that require similar codes.
Publishing such unauthorized technology through articles can surely tip hackers to think of new methods of cheating people. However, since technical journals have published such research articles, Security experts and some of their criminal enemies already are aware about it. So that’s when Yahoo Finance decided it’s the right time to notify consumers of this new form of hacking. National security and law enforcement agencies could also use it to keep record of bad guys; DARPA, the Pentagon’s technology skunk works, for instance, partly funded the Syracuse research.
50 volunteers were involved in the Syracuse experiments that had them keying PINs into HTC One smartphones, in a variety of different settings and postures. Researchers shot four different videos for each volunteer. Two off-the-shelf devices were used to make these recordings: a Google Nexus 5 smartphone camera and a Sony camcorder. All the videos were recorded from 12 to 15 feet away from either the side or back of the phone. None of the video recordings captured the phone screen or definitely showed what users were typing.
With a combination of image analysis and motion tracking algorithms, software filled in the gaps, which were remarkably effective at “guessing” the PINs users typed in. The software figured out the correct password between 40% and 62% of the time on the first guess, which depended on the quality of the video and the zoom ratio. Nearly 82% accuracy was produced after 5 guess that involved using of highest-quality video and 94% accuracy after 10 guesses. Use of more than one video for each phone raises the odds of success even further.
“We can do it in about 30 minutes once we capture the video,” says Phoha. “We have almost 100% accuracy.” This graph lays out the results of computer guesswork for video shot using the Nexus smartphone and the Sony camcorder at zoom levels of 2x, 4x and 6x:
The hackers could shoot the said video with the phone users not noticing them, especially in busy surroundings such as a bar, restaurant, bus, train, airport or shopping mall. Robbers have long seized people’s credit card numbers or ATM PINs by “shoulder snooping” during a transaction, or even looking on from a distance with binoculars or a camera with a zoom lens. In a way, hacking via video—which can be done secretly on a smartphone while the perpetrator appears to be safely tapping on the screen—is nothing more than a new twist to an old theme.
Source:- techworm