Cyber Security Tip & Tricks
Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Wednesday, May 21, 2014

Using strong passwords and secure your online credentials

Recently eBay has announced to their users that they should change their passwords immediately due to a cyber attack that compromised a database containing encrypted passwords. A press release sent out by the company stresses that only non-financial data was affected. eBay found no evidence of any unauthorized access to their financial or credit card information.  It is reported that PayPal, the popular payment processor network, has not been affected. Therefore it is strongly recommended all readers to look into their accounts and make changes in their passwords to be on the safe side.
To secure you online accounts you can use password managers and also use two-factor authentication facilities providing by Google, Facebook, Twitter, Dropbox and dozens of other sites.  If you're not up to using two-factor authentication or a password manager at least use a strong password that may protect your online accounts a great extend. 

Strong Passwords


Strong password can be created by mix up with numbers, lowercase letters, capital letters and special characters. Choose longer password and it is the better and not easy to decrypt. You are requested to never use the same password twice. If you are using the same password across the board and if a hacker does track down your password then they can easily have access to all of your accounts. Never use passwords like your kids name, birthday, anniversary, "1234567", or the ever popular, "password" it will be easily to hack your password. 

Password Managers

Password Managers are the best for keeping your passwords secure, while also keeping them organized. Some of the password managers offer a secure password generator so you don't have to do any thinking on the matter. Password mangers are great choices and offer values far beyond writing all of your passwords down in a "safe place".  Some of the popular password manager are list below.


Two-factor Authentication

Two factor authentication adds an extra layer of security to your Google accounts as well as other services like Facebook, Twitter and Dropbox. Account.  It may drastically reducing the chances of having the personal information in your account stolen. To break into an account with 2-Step Verification, bad guys would not only have to know your username and password, they'd also have to get a hold of your phone. Two-factor authentication adds an extra layer of security to your accounts, requiring you to enter a code provided either in an app (like Google Authenticator) or as a text message. The ensures that only you can get into the account, even if someone has your password. Read more on two-factor verification


Press Release of e-bay
SAN JOSE, Calif.--(BUSINESS WIRE)--eBay Inc. (Nasdaq: EBAY) said beginning later today it will be asking eBay users to change their passwords because of a cyberattack that compromised a database containing encrypted passwords and other non-financial data. After conducting extensive tests on its networks, the company said it has no evidence of the compromise resulting in unauthorized activity for eBay users, and no evidence of any unauthorized access to financial or credit card information, which is stored separately in encrypted formats. However, changing passwords is a best practice and will help enhance security for eBay users.
Information security and customer data protection are of paramount importance to eBay Inc., and eBay regrets any inconvenience or concern that this password reset may cause our customers. We know our customers trust us with their information, and we take seriously our commitment to maintaining a safe, secure and trusted global marketplace.
Cyberattackers compromised a small number of employee log-in credentials, allowing unauthorized access to eBay's corporate network, the company said. Working with law enforcement and leading security experts, the company is aggressively investigating the matter and applying the best forensics tools and practices to protect customers.
The database, which was compromised between late February and early March, included eBay customers' name, encrypted password, email address, physical address, phone number and date of birth. However, the database did not contain financial information or other confidential personal information. The company said that the compromised employee log-in credentials were first detected about two weeks ago. Extensive forensics subsequently identified the compromised eBay database, resulting in the company's announcement today.
The company said it has seen no indication of increased fraudulent account activity on eBay. The company also said it has no evidence of unauthorized access or compromises to personal or financial information for PayPal users. PayPal data is stored separately on a secure network, and all PayPal financial information is encrypted.
Beginning later today, eBay users will be notified via email, site communications and other marketing channels to change their password. In addition to asking users to change their eBay password, the company said it also is encouraging any eBay user who utilized the same password on other sites to change those passwords, too. The same password should never be used across multiple sites or accounts. Source: BusinessWire


Thursday, November 17, 2011

Choose Smart Password for your online accounts and protect from hacking

Password is the first line of defense against cyber criminals. If you are using the same password on different websites allows hijackers to access your important accounts details like email, and bank details, if they manage to steal your password from a less secure website.   You're likely to have dozens of accounts across the web, and you can't guarantee the security of all of those accounts. Many smaller companies don't have security technology capable of guarding your data from cyber criminals. When you use the same password across the web, a cyber criminal can gain access to a less secure account and then use that password to compromise your important accounts.



To create a smart password try the following steps:

  • Use unique passwords for your accounts, especially important accounts like email and online banking. Re-using passwords is risky. If someone figures out your password for one service, that person could potentially gain access to your private email, address, and even your money. 

  • Using numbers, symbols and mixed-case letters in your password increases the difficulty of guessing or cracking your password. For example, there are more than 6 quadrillion possible variations for an eight-character password with numbers, symbols, and mixed-case letters - 30,000 times more variations than an eight-character password with only lowercase letters.  Do NOT use personal information such as birth dates, anniversaries, special events, etc. because if the hacker is a so-called friend of acquaintance, your password yells free information. Additionally the longer the pass word the more secure, 8 characters in length is acceptable but 14 is recommended.

  • Choose a combination of letters, numbers, or symbols to create a unique password that's unrelated to your personal information. Or, select a random word or phrase, and insert letters and numbers into the beginning, middle, and end to make it extra difficult to guess (such as "sPo0kyh@ll0w3En"). Using simple words or phrases like "password" or "letmein," keyboard patterns such as "qwerty" or "qazwsx," or sequential patterns such as "abcd1234" make your password easier to guess or crack.

  •  Make sure to regularly update your recovery email address so that you can receive emails in case you need to reset your password. You can also add a phone number to receive password reset codes via text message. Additionally, many websites (including Gmail) will ask you to choose a question to verify your identity if you ever forget your password. If you're able to create your own question, try to come up with a question that has an answer only you would know. The answer shouldn't be something that someone can guess by scanning information you've posted online in social networking profiles, blogs, and other places. If you're asked to choose a question from a list of options, such as the city where you were born, be aware that these questions are likely to be less secure. Try to find a way to make your answer unique — you can do this by using some of the tips above — so that even if someone guesses the answer, they won't know how to enter it properly.

  • Don't leave notes with your passwords to various sites on your computer or desk. People who walk by can easily steal this information and use it to compromise your account. If you decide to save your passwords in a file on your computer, create a unique name for the file so people don't know what's inside. Avoid giving the file an obvious name, such as "my passwords." If you have a difficult time remembering multiple passwords, a trusted password manager may be a good solution. Spend a few minutes checking out the reviews and reputations of these services.

Source: Google.com


Tuesday, February 12, 2008

How to Protect your online accounts

Due to vulnerabilities in Operating System and other application software users' online accounts can become compromised through phishing schemes, viruses, and spyware. Users can secure their own account and their online identity quickly and easily by following the online safe practices. Some of the safe practice I regularly follows are listed below. You may look into these steps and take a decision today itself to safe guard from Online frauds.

1. Don't share: Keep your username, password and personal information secret. You are requested to change your password regularly. Password must be alphanumeric with special character and greater than 8 character in length.

2. Don't click: Never click on any link you suspect to be malicious, even if sent by someone you trust. Scan your computer regularly for viruses, spyware and adware. Updates your Operating System and other application software regularly.

3. Don't click: Never click on links in emails that claim to be from mail provider (gmail.com, yahoo.com), bank authorities (hdfcbank.com, icicibank.com), auction sites (ebay.com, amzone.com) or social networking sites (orkut.com, myspace.com). Scan your computer regularly for viruses, spyware, and adware.

4. Don't spread: Never enter your account login and password on sites other than the original site. Never check remember me when you're using a shared computer.

5. Don't Share Personal Data: Avoid posting sensitive personal data, such as email addresses, phone number or pictures, in public places.

6. Don't forget to click the Logout link of the page when you're done using an online account.

7. Don't script: Never paste a URL or script into your browser while logged into a account especially social networking site viz. orkut.com, mysapce.com no matter what it claims to do.

Friday, September 7, 2007

Pentagon Computer Hacked Into By Chinese

The Chinese military hacked into a Pentagon computer network in June
in the most successful cyber attack on the US defense department, say
American ­officials.

The Pentagon acknowledged shutting down part of a computer system
serving the office of Robert Gates, defense secretary, but declined to
say who it believed was behind the attack.

Current and former officials have told the Financial Times an internal
investigation has revealed that the incursion came from the People’s
Liberation Army.

One senior US official said the Pentagon had pinpointed the exact
origins of the attack. Another person familiar with the event said
there was a “very high level of confidence...trending towards total
certainty” that the PLA was responsible. The defense ministry in
Beijing declined to comment on Monday.

Tuesday, September 4, 2007

2007 Hacker Reverse Engineering Challenge

Similar to the Hacker Challenge in 2006, it is being run by a U.S. company performing security testing and security metric research. The purpose of this challenge is to evaluate the effectiveness of software protections. The results of this effort will be used to improve protection measures.

There will be three distinct, yet related, phases to this contest. The first phase will be a hacker challenge, for which anyone can register to participate. The second stage of the contest will be a market (based on the Phase 1 challenge). Participation in this second phase will be by invitation only, based on performance in the first phase. The third phase of the contest will be a more challenging hacker challenge; this phase may or may not be invitation-only. There are opportunities to earn money in all three phases of the contest.

All file downloads and uploads necessary for the contest will be possible after the participant has logged in. The market will also be visible, at the appropriate time, after logging in.

All payments are in U.S. dollars, and will be made anonymously via PayPal with prizes up to $50,000USD for the three phases.

You can read more here.

http://www.hackerchallenge.org/

Monday, September 3, 2007

E-mail accounts of embassies and Government offices across the world, including India hacked due to lack of Cyber Security

A hacker, Dan Egerstad from Sweden, who published passwords of 100 e-mail accounts of embassies and Government offices across the world, including India, on his website http://derangedsecurity.com. The hacker said he took only a few minutes to figure out the account details.

This shows that there is lack of basic cyber security. Due to the lack of security anyone with moderate skills in security could have figured this out and done it. A cyber security expert said that a POP (Post Office Protocol) server that had not been updated for security could have been exploited by the hacker to get usernames and passwords.

The Indian Express said in their website that they were sent a test mail to the Indian Ambassador in China on her official email ID and, using the password posted online, to check the authenticity and was able to access it. These email IDs contained important official details including phone numbers, commercial documents, official correspondence and personal mails.

Within hours of the story appearing in the Indian Express, the DRDO mail server was shut down and all embassy e-mail accounts were taken offline by the Ministry of External Affairs (MEA). However, it will take cyber forensic experts several days to get an idea of how much confidential material was illegally accessed.

DRDO confirmed that the hacked account belonged to a Defense Scientific Information and Documentation Centre (DESIDOC) official, but it was rarely used. The Ministry of Defense (MoD), however, said it was conducting a detailed investigation into the incident.

Tuesday, August 28, 2007

hackers @ microsoft - Microsoft's Official Blog

"Hackers @ Microsoft" - that's the name of a new Microsoft blog officially launched on blogs.msdn.com which also hosts thousands of other blogs written by Microsoft Employees.

The focus of this blog is likely to be a little different from most other blogs you'll see on blogs.msdn.com. Microsoft employs some of the best hackers in the world and actively recruits them and develops them. They work on all kinds of projects, whether it be in development, research, testing, management and of course security.

This blog is *especially* provided "AS IS" with no warranties, and confers no rights. Opinions are not of Microsoft. he new Microsoft Hackers blog is located at blogs.msdn.com/hackers.

Monday, July 30, 2007

Cyber Crime – Hacking - Software Engineer arrested from Chennai

Cyber Crime – Hacking - Software Engineer arrested from Chennai

One M.S. Ramasamy, a 37 year old Software Engineer from Avadi, had arrested on 27.07.07 by the Chennai Cyber Crime Police on charges of hacking and stealing confidential and proprietary information from the server of a US IT Company. He was a former employee of that IT Company. Police framed charges under Section 66 of the IT Act, 2000 which dealing with Hacking and Section 408 of the IPC which dealing with Criminal Breach of Trust by Clerk or Servant.

In its press release Chennai Police said that Mr. Ramasamy had reportedly hacked into the company’s headquarter computer system when he was working as an Engineer in Caterpillar India Private Limited during January and February this year.

The accused accessed the company’s server located at Peoria in Illinois, US, by using another employee’s User ID and password and downloaded confidential information. A closed circuit camera recorded the activities of the sever room. By analyzing the server log and the visuals from the camera Police tracked the accused. Police arrested the hacker from an IT Company at Hosur, where he was employed. The Police confiscated the hard disk and pen drive containing the files.

Source: Hindu

Tuesday, July 24, 2007

iPhone Hacked Successfully - Security Firm Says

iPhone Hacked Successfully - Security Firm Says

A vulnarabilty has found in the Apple Inc.'s iPhone handset that can help an attacker to gain access to the private data stored on it. This flaw has found by a team of security expert of Independent Security Evaluators (ISE). Hackers could gain access to the iPhone through a wireless access point or through a website controlled by the attacker. This was the first major security incident reported.

Numerous hackers have been working to gain access to the iPhone in order to activate certain features or to allow it to be used on cellular networks. However, this is the first major exploitation of an iPhone security flaw.

The expolit is delivered via a malicious web page opened in the Safari browser on the iPhone, ISE said on its Website. There are several methods that an attacker utilize to get a victim to open such a webpage.

1. An attacker controlled wireless access point:

The iPhone connects to wireless Internet access networks, such as Wi-Fi, an attacker could create a network with the same name and encryption method as one the handset already uses. The attacker could then substitute a Web page with exploit code to gain access to the phone.

2. A misconfigured forum website:

A link planted on an unedited or unmoderated online forum, an attacker could cause the exploit to run in any iPhone browser that viewed the thread.

3. A link delivered via e-mail or SMS:

A link sent by SMS or e-mail to use make use of the flaw and gain access to the handset.

The ISE said that when the iPhone's Safari browser opens a malicious Web page, malicious code can be run on the phone via the flaw, allowing the attacker to read the iPhone's SMS log, address book, call history, and voicemail information, which are also then sent to the attacker. It could send the user's mail passwords to the attacker, send text messages that sign the user up for pay services, or record audio that could be relayed to the attacker.

Source: nytimes

iPhone Hacked Successfully - Security Firm Says

iPhone Hacked Successfully - Security Firm Says

A vulnarabilty has found in the Apple Inc.'s iPhone handset that can help an attacker to gain access to the private data stored on it. This flaw has found by a team of security expert of Independent Security Evaluators (ISE). Hackers could gain access to the iPhone through a wireless access point or through a website controlled by the attacker. This was the first major security incident reported.

Numerous hackers have been working to gain access to the iPhone in order to activate certain features or to allow it to be used on cellular networks other than AT&T Inc.'s. However, this is the first major exploitation of an iPhone security flaw.

The expolit is delivered via a malicious web page opened in the Safari browser on the iPhone, ISE said on its Website. There are several methods that an attacker utilize to get a victim to open such a webpage.

1. An attacker controlled wireless access point:

The iPhone connects to wireless Internet access networks, such as Wi-Fi, an attacker could create a network with the same name and encryption method as one the handset already uses. The attacker could then substitute a Web page with exploit code to gain access to the phone.

2. A misconfigured forum website:

A link planted on an unedited or unmoderated online forum, an attacker could cause the exploit to run in any iPhone browser that viewed the thread.

3. A link delivered via e-mail or SMS:

A link sent by SMS or e-mail to use make use of the flaw and gain access to the handset.

The ISE said that when the iPhone's Safari browser opens a malicious Web page, malicious code can be run on the phone via the flaw, allowing the attacker to read the iPhone's SMS log, address book, call history, and voicemail information, which are also then sent to the attacker. It could send the user's mail passwords to the attacker, send text messages that sign the user up for pay services, or record audio that could be relayed to the attacker.

Source: nytimes

Wednesday, June 27, 2007

CM's website hacking: State Police to sent ‘Letter of Rogatory’

The State police are planning to sent a ‘Letter of Rogatory’, a formal request by a Court to the Interpol, to get certain details pertaining to the Chief Minister's website hacking case.

Though the State police had earlier sent a request to the Interpol Wing attached to the CBI seeking the details through their counterparts in the US, Russia and China, they refused to had over the requests for want of a ‘Letter of rogatory’.

They have however preserved the electronic evidence including log files required by the State Police to crack the case.

The State Police are concerned that this would delay the investigation. The State Police would prepare the draft ‘letter of rogatory’ and send it to the Interpol wing of CBI who will forward it to the External Affairs Ministry.

The letters would be later produced before the Chief Judicial Magistrate and letter would be forwarded through the court.

It may be recalled that the Vigilance and Anti-Corruption Bureau had initiated a ‘letter of rogatory’ for collecting certain details from a French company involved in the Brahmapuram power plant corruption case.

Chief Minister's website ‘www.keralacm.gov.in’ was hacked and inserted objectionable contents. The police had found that the site was hacked from Internet Protocol addressed located in the US, Russia and China following the help of Interpol was sought.
Source: newindpress

Monday, June 18, 2007

Netstat - Hackers Tool



A video about netstat is in the Youtube. Those who do not play with it could see the possibilities it offers to us. Anyway check it out and tell me your opinion.



Network Statistics - Netstat is a command-line tool that displays network connections (both incoming and outgoing), routing tables, and a number of network interface statistics. It is available on Unix, Linux, and Windows XP, Windows NT-based operating systems.


Thursday, June 14, 2007

Michigan Man Fined for Using Coffee Shop's Wi-Fi Network


A Michigan man has been fined $400 and given 40 hours of community service for accessing an open wireless Internet connection outside a coffee shop. Under a little known state law against computer hackers, Sam Peterson II, of Cedar Springs, Mich., faced a felony charge after cops found him on March 27 sitting in front of the Re-Union street Café in Sparta, Mich., surfing the Web from his brand-new laptop. Last week, Peterson chose to pay the fine instead as part of a jail-diversion program.

Someone from a nearby barbershop had called cops after seeing Peterson’s car pull up every day and sit in front of the coffee shop without anybody getting out.

“I just curiously asked him, ‘Where are you getting the Internet connection?’, you know,” Sparta Police Chief Andrew Milanowski said. “And he said, ‘From the café.’”

Milanowski ruled out Peterson as a possible stalker of the attractive local hairdresser, but still felt that a law might have been broken.

“We came back and we looked up the laws and we figured if we found one and thought, ‘Well, let’s run it by the prosecutor’s office and see what they want to do,’” Milanowski said.

A few weeks later Peterson said he received a letter from the Kent County prosecutor’s office saying that he faced a felony charge of fraudulent access to computer networks and that a request had been made for an arrest warrant.

Source: FoxNews



Skype is great!

Sunday, June 10, 2007

Hacking of CM's Website - Kerala Police sought INTERPOL help

The Kerala Police have sought the assistance of the International Police Organisation (INTERPOL) to track those who behind the hacking of the official Website of Kerala Chief Minister www.keralacm.gov.in.

Hackers had inserted links to objectionable contents in the CM’s Website. New topics were created in the Discussion Forum and links to certain websites with objectionable contents are inserted.

The Website was hacked by unidentified persons four times recently. The Hi-Tech Crime Enquiry Cell of Kerala Police with the help of C-DAC Cyber Forensic Division Experts traced the IP (Internet Protocol) Addresses. These addresses are located in the US, Russia and China. Meanwhile, the official Website run by C-DIT has been pulled out from the World Wide Web for an overhaul.

Source: Newindpress

Monday, June 4, 2007

വിഎസിന്‍റെ സൈറ്റ് ഹാക്ക് ചെയ്തു



തിരുവനന്തപുരം: മുഖ്യമന്ത്രി വി എസ്‌ അച്യുതാനന്ദന്‍റെ ഔദ്യോഗിക വെബ്സൈറ്റ്‌ നാലുതവണ ഹാക്ക്‌ ചെയ്യപ്പെട്ടതായി വെളിപ്പെട്ടു.സൈബര്‍ ക്രൈം സെല്‍ ഇതേകുറിച്ച്‌ നടത്തിയ അന്വേഷണം എങ്ങും എത്തിയിട്ടില്ല.മുഖ്യമന്ത്രിയുടെ സൈറ്റിന്‍റെ പരിപാലന ചുമതല സിഡിറ്റിനാണ്‌.

കൃത്രിമ പാസ്‌വേഡ്‌ ഉപയോഗിച്ച്‌ വെബ്സൈറ്റിലെ വിവരങ്ങള്‍ മാറ്റുകയും പുതിയവ തിരുകി കയറ്റുകയും ചെയ്തിരുന്നു. സൈബര്‍ ക്രൈംസെല്‍ മേധാവി ഐ ജി ലോക്നാഥ്‌ ബെഹ്‌റയുടെ നേതൃത്വത്തില്‍ അന്വേഷണം പുരോഗമിക്കുന്നുണ്ട്‌.

മൂന്നാര്‍ ദൗത്യസംഘത്തില്‍പെട്ട ഐ ജി ഋഷിരാജ്സിങ്ങിനെ കൊന്നുകളയുമെന്ന ഭീഷണിയും മുഖ്യമന്ത്രിയുടെ വെബ്സൈറ്റില്‍ പ്രത്യക്ഷപ്പെട്ടിരുന്നു. വധഭീഷണി അയച്ച മേല്‍വിലാസത്തെ കുറിച്ച്‌ അന്വേഷണം പുരോഗമിക്കുന്നു. എന്നാല്‍ അന്വേഷണത്തിന്‍റെ കൂടുതല്‍ വിവരങ്ങള്‍ പറത്തുവിട്ടിട്ടില്ല.
Source: MSN India

AddThis Social Bookmark Button

Recent Comments