Cyber Security Tip & Tricks
Showing posts with label network security. Show all posts
Showing posts with label network security. Show all posts

Saturday, December 27, 2008

Take precaution against Cyber Theft - During this Holidays


  1. Be wary of holiday gift cards and holiday coupon offers sent via e-mail—these often have malicious links within the offer which lead to downloads of info-stealing Trojans or the hackers try to scam you out of your bank account information.
  2. When visiting your favorite online retailer to purchase gifts, be sure to type the actual Web site address of the retailer into your browser. Do not follow links provided by e-mail offers or pop up ads. Many times these are fraudulent sites made to look like the legitimate retail sites.
  3. When making online purchases, always use a credit card that limits your fraud liability. Avoid using debit cards to do online purchases when possible so as to limit your personal exposure to any possible fraudulent transactions.
  4. When making online purchases, always look at your Web browser for the https (as opposed to http) protocol that proceeds a Web address. The “s” let’s you know that the Web site is providing a layer of security for transmitting your personal information over the Internet.
  5. Be wary of unsolicited e-mails, even from senders that you know, that include links or attachments. Before clicking on links or attachments, ALWAYS verify that the correspondent sent you the e-mail and enclosed link or attachment.
  6. Be wary of e-mails notifying you that your banking certificate or token is out of date and to download a new certificate or token. Before taking any action, verify with your financial institution by calling them on a number that is not provided in the email.
  7. Avoid using simple (weak) or default passwords for any online site.


U.S. government vulnerable to Internet predators

U.S. government vulnerable to Internet predators

Most Internet users have some awareness of the problem of threats to the entire system from criminals, terrorists and potentially hostile nations, since they encounter it in the form of spyware, viruses and other online nuisances.

However, the most disturbing "cyber" threats are largely invisible to the general public, because they involve attacks on specialized networks used by the armed forces, healthcare professionals, air traffic controllers, financial institutions, public utilities and heavy industry.

Each of these vital components of modern society now relies on Internet Protocol communications to run efficiently, and in most cases the new technology was assimilated without a careful assessment of its vulnerability to attack by outsiders.

Friday, December 26, 2008

The Duhs of Security

The Duhs of Security

This security awareness video was developed by the Commonwealth of Virginia to promote simple changes in behavior that will strengthen security.

* Dont allow tailgating
* Guard your password and change it often
* Safe sensitve information to secure backed-up network storage areas
* Lock the computer when unattended
* Pick up sensitive printouts immediately
* Dont have sensitive conversations where you can be overheard.
* Be wary of suspicious emails
* Keep electronic media secure and safe from theft or damage.

Tuesday, October 16, 2007

Single password for online accounts are more risk

Those who use the same password for online accounts viz. email, e-banking, shopping accounts, are more at risk from online fraud or identity theft. The popularity of social networking sites such as Orkut, Facebook, etc are making life easier for online criminals.

A new survey by computer security firm McAfee, has revealed that as many as 16 percent of people used the same password for online accounts, while a whopping 41 per cent never changed their passwords.

Most users post personal details commonly used as passwords on their pages, such as their educational history, names of pets and favorite football team, wife name, children name, favorite hero,etc are common sources for a password.

According to a report by the Daily Telegraph, online banking fraud rose by 44 per cent last year to 33.5 million pounds in the UK, while Internet shopping fraud amounted to 155 million pounds. (ANI)

In India, online crimes are increasing tremendously because of the popularity of social networking sites and poor awareness of security measures.

Wednesday, October 10, 2007

Microsoft released its security updates for October 2007

Microsoft has released its critical and important updates. These updates involve applications including Kodak Image Viewer, Outlook Express and Windows Mail, Internet Explorer, and a vulnerability in Microsoft Word. All of these could allow remote code execution and elevation of privileges.


Security updates are available from Microsoft Update, Windows Update, and Office Update. Security updates are also available at the Microsoft Download Center.

For more details on these updates, here's the link to Microsoft's Security Bulletin.

Thursday, September 20, 2007

Netstat - Know your network connection

netstat (network statistics) is a command-line tool that displays network connections (both incoming and outgoing), routing tables, and a number of network interface statistics. It is available on Unix, Unix-like, and Windows NT-based operating systems.

If you are worried that some programs on your PC are secretly making connections to websites in the background, here's a quick tip that uses a simple DOS command to detect and prevent such suspicious activity:

1. Open Windows Run Command from the Start Menu

2. Type CMD command in the Run box and press OK.

3. Type "netstat -b 10 > netact.txt" in the command window and press ENTER. After some times say 2 minutes, press Ctrl+C.

4. Type "netact.txt" on the command line to open the log file in notepad (or your default text editor)

The file netact.txt will have a log of all process that made a connection to the Internet in the last two minutes. It will also show which process connected to which website in this time. And not just the web browsers (like iexplore.exe , firefox.exe or opera.exe), the log will also show your IM clients, download managers, email programs or any software that requires a net connection.

Scroll though the netact.txt file and look for any process names or website addresses that you are not aware of. If you track one, go to the task manager (or Process Explorer) to find the location of the executable on your computer and eliminate it.

Monday, September 3, 2007

E-mail accounts of embassies and Government offices across the world, including India hacked due to lack of Cyber Security

A hacker, Dan Egerstad from Sweden, who published passwords of 100 e-mail accounts of embassies and Government offices across the world, including India, on his website http://derangedsecurity.com. The hacker said he took only a few minutes to figure out the account details.

This shows that there is lack of basic cyber security. Due to the lack of security anyone with moderate skills in security could have figured this out and done it. A cyber security expert said that a POP (Post Office Protocol) server that had not been updated for security could have been exploited by the hacker to get usernames and passwords.

The Indian Express said in their website that they were sent a test mail to the Indian Ambassador in China on her official email ID and, using the password posted online, to check the authenticity and was able to access it. These email IDs contained important official details including phone numbers, commercial documents, official correspondence and personal mails.

Within hours of the story appearing in the Indian Express, the DRDO mail server was shut down and all embassy e-mail accounts were taken offline by the Ministry of External Affairs (MEA). However, it will take cyber forensic experts several days to get an idea of how much confidential material was illegally accessed.

DRDO confirmed that the hacked account belonged to a Defense Scientific Information and Documentation Centre (DESIDOC) official, but it was rarely used. The Ministry of Defense (MoD), however, said it was conducting a detailed investigation into the incident.

Tuesday, August 28, 2007

hackers @ microsoft - Microsoft's Official Blog

"Hackers @ Microsoft" - that's the name of a new Microsoft blog officially launched on blogs.msdn.com which also hosts thousands of other blogs written by Microsoft Employees.

The focus of this blog is likely to be a little different from most other blogs you'll see on blogs.msdn.com. Microsoft employs some of the best hackers in the world and actively recruits them and develops them. They work on all kinds of projects, whether it be in development, research, testing, management and of course security.

This blog is *especially* provided "AS IS" with no warranties, and confers no rights. Opinions are not of Microsoft. he new Microsoft Hackers blog is located at blogs.msdn.com/hackers.

Tuesday, July 24, 2007

iPhone Hacked Successfully - Security Firm Says

iPhone Hacked Successfully - Security Firm Says

A vulnarabilty has found in the Apple Inc.'s iPhone handset that can help an attacker to gain access to the private data stored on it. This flaw has found by a team of security expert of Independent Security Evaluators (ISE). Hackers could gain access to the iPhone through a wireless access point or through a website controlled by the attacker. This was the first major security incident reported.

Numerous hackers have been working to gain access to the iPhone in order to activate certain features or to allow it to be used on cellular networks. However, this is the first major exploitation of an iPhone security flaw.

The expolit is delivered via a malicious web page opened in the Safari browser on the iPhone, ISE said on its Website. There are several methods that an attacker utilize to get a victim to open such a webpage.

1. An attacker controlled wireless access point:

The iPhone connects to wireless Internet access networks, such as Wi-Fi, an attacker could create a network with the same name and encryption method as one the handset already uses. The attacker could then substitute a Web page with exploit code to gain access to the phone.

2. A misconfigured forum website:

A link planted on an unedited or unmoderated online forum, an attacker could cause the exploit to run in any iPhone browser that viewed the thread.

3. A link delivered via e-mail or SMS:

A link sent by SMS or e-mail to use make use of the flaw and gain access to the handset.

The ISE said that when the iPhone's Safari browser opens a malicious Web page, malicious code can be run on the phone via the flaw, allowing the attacker to read the iPhone's SMS log, address book, call history, and voicemail information, which are also then sent to the attacker. It could send the user's mail passwords to the attacker, send text messages that sign the user up for pay services, or record audio that could be relayed to the attacker.

Source: nytimes

Tuesday, June 12, 2007

10 Free Ways to Track All Your Passwords

With the proliferation of web services — there’s a new one out each day, it seems — it feels like we’re always creating new accounts, each with a different username and password.

The easy options — using the same password each time or writing them down on paper or in a spreadsheet — aren’t exactly the most secure. In fact, security experts strongly warn against these options as they leave you vulnerable to online theft.

So what’s a web surfer to do? If you’ve got more than a dozen services, you’re not going to remember all of them. It’s time to look into a password manager — and if you’re a cheapskate like me, you want a free one.

Let’s agree, from here on in, to stop using our dog’s name and birth date for our single password. Here are 10 free options for doing that:

Firefoxx or IE: Both popular browsers offer fairly secure ways of storing your username or passwords for different sites, once you enter them the first time. This is very handy, and can save a ton of time. Unfortunately, under certain conditions, the password could be lost, requiring you to enter the password again. And if you’ve been relying on the browser to remember the password, you’re out of luck. Also, this solution is only for online passwords, not for network or desktop passwords.
KeePass: One of the most popular password managers out there, KeePass is great because it’s open-source, free and cross-platform — available for Windows, Linux, OS X, and even mobile devices. It keeps all your passwords, online and off, in a secure database, so you only have to remember one master password. Be sure that master password is safe!
Clipperz: Unlike most password managers, this solution is online — so you can access it anywhere. And it stores more than passwords — credit card numbers, account numbers, anything really. Storing passwords and other confidential information online can make someplace nervous, but Clipperz uses an encryption method that means not even Clipperz knows what it’s storing. This is a good solution if you need access to your passwords from multiple computers, rather than just one or two.
OSX Keychain: If you use a Mac, you’re most likely familiar with Keychain, which comes with OSX. Basically, it’s a password manager that uses your OSX admin password as the master password.
KeyWallet: Windows only, this little utility sits in your system tray, and you just pull it up when you need to enter a password. As a utility, it is browswer-independent, which is ideal for some.
Password Manager Plus: The Billeo Free Password Manager Plus toolbar works with both Firefox and Internet Explorer, and allows you to store not only passwords but credit card numbers and online account information, and can autofill your information as you shop online or paying bills, for example.
Password Hasher: This Firefox extension generates strong passwords for you by scrambling your master password with the site’s name. The passwords generated by this extension are better than any you could come up with yourself.
PasswordSafe: This free online service works on any modern web browser, for any OS, and a desktop version is available for Windows or Mac. Basically, it uses an encrypted safe to store your passwords, along with other information including software keys, website logins, pin numbers, email logins and more.
Password generator: This is a little bookmarklet that combines your master password with the site’s name to create a stronger password, and one that is different for each site. Very handy and simple.
Algorithm: The best solution may not even be a technology solution — remembering strong passwords could be as simple as coming up with a way to change a base password using the name of the online service you’re logging into. For example, if you come up with a base password of “xlg519″ (based on your partner’s initials and your cat’s birthday), you can add the first two and last two letters of a service’s name (”amon” for Amazon) and you’ve got your password!

Some notes on passwords:





Never give out your master password if you use a password manager. Be sure you never forget it.
Don’t write passwords on a little piece of paper and stick it in your drawer. If it gets stolen, you only have yourself to blame.
Password managers may not be safe on a shared computer — it is probably best to only install them on a computer that only you use.
Using common information for your password is not secure — such as your birthday, initials, kids’ birthdays, names, etc. And no, “password” is not a safe password.
Using the same password for everything is a bad idea, because once that password is discovered, a thief has access to all your accounts.
Source: Lifehack.org

Sunday, June 10, 2007

Hacking of CM's Website - Kerala Police sought INTERPOL help

The Kerala Police have sought the assistance of the International Police Organisation (INTERPOL) to track those who behind the hacking of the official Website of Kerala Chief Minister www.keralacm.gov.in.

Hackers had inserted links to objectionable contents in the CM’s Website. New topics were created in the Discussion Forum and links to certain websites with objectionable contents are inserted.

The Website was hacked by unidentified persons four times recently. The Hi-Tech Crime Enquiry Cell of Kerala Police with the help of C-DAC Cyber Forensic Division Experts traced the IP (Internet Protocol) Addresses. These addresses are located in the US, Russia and China. Meanwhile, the official Website run by C-DIT has been pulled out from the World Wide Web for an overhaul.

Source: Newindpress

Recent Comments