Cyber Security Tips N Tricks describes various tips and tricks about cyber security, safe surfing, ethical hacking, network security, Internet, news related to software, hacking, security breaches, vulnerabilities, phishing, google, yahoo, CERT, US CERT, security agencies, etc.
Thursday, February 27, 2025
Understanding Identity Theft and Advanced Techniques for Identity Theft Protection
Saturday, June 22, 2013
Facebook Security Breach 6M Users details exposed
We have already notified our regulators in the US, Canada and Europe, and we are in the process of notifying affected users via email. We appreciate the security researcher's report to our White Hat program, and have paid out a bug bounty to thank him for his efforts."
Facebook did not specify time period for which the user details were exposed but said the bug was reported only 'recently'. It has alerted its six million users whose personal details were exposed besides sending out an apology via email.
Here is the full text of the apology email:
Dear....,
Your privacy is incredibly important to everyone who works at Facebook, and we're dedicated to protecting your information. While many of us focus our full-time jobs on preventing or fixing issues before they affect anyone, we recently fell short of our goal and a technical bug caused your telephone number or email address to be accessible by another person.
The bug was limited in scope and likely only allowed someone you already know outside of Facebook to see your email address or telephone number. That said, we let you down and we are taking this error very seriously.
Describing what caused the bug can get pretty technical, but we want to explain how it happened. When people upload their contact lists or address books to Facebook, we try to match that data with the contact information of other people on Facebook in order to generate friend recommendations. Because of the bug, the email addresses and phone numbers used to make friend recommendations and reduce the number of invitations we send were inadvertently stored in their account on Facebook, along with their uploaded contacts. As a result, if a person went to download an archive of their Facebook account through our Download Your Information (DYI) tool, which included their uploaded contacts, they may have been provided with additional email addresses or telephone numbers.
Here is your contact Information (inadvertently accessible by at most 1 Facebook user):
[Phone number]
[Email address 1]
[Email address 2]
We estimate that 1 Facebook user saw this additional contact info displayed next to your name in their downloaded copy of their account information. No other info about you was shown and it's likely that anyone who saw this is not a stranger to you, even if you're not friends on Facebook.
We recognize that mistakenly sharing contact info is unacceptable, even if you are acquainted with people who saw these details, and we've taken measures to prevent this from happening again. For more information on the bug, please read our blog post.
All of us at Facebook take this issue very personally. We appreciate your ongoing use of Facebook, and are working every day to deliver the level of service you expect and deserve.
Thank you,
The Facebook Team
Friday, May 3, 2013
Securing Your Facebook Account
Facebook has emerged as the world’s most popular and largest social networking site with more than one billion users. Facebook has successfully marked its presence among teens as well as young and older adults. It’s a way to connect with your family or friends, a means of interaction with strangers.
Limit your connections
Most key privacy settings are accessible by clicking the arrow in the upper right-hand corner of your profile screen (next to your name and the Home button). From here, select Privacy Settings in the drop-down menu. Click on Edit Settings next to the How You Connect option to begin your profile lockdown. This section contains five privacy settings.Facebook offers many features to its users for a safe and secure online experience. Facebook has recently announced and added the full HTTPS support for the site to keep you protected from security threats like viruses, malware and hackers. But, if you are using HTTPS support, encrypted pages take longer to load and your account will be slower. The best part of Facebook, however, is that you can customize your account’s settings and privacy to suit your needs.
Profile -> Settings
Go to: settings -> privacy
Here you can customize visibility of your basic details such as profile information, status updates, friends, your wall, photos or videos you are tagged in etc. In short, you can adjust your privacy on all of the above elements.
Profile -> Settings
Go to: settings -> general accounts setting
In this section, you can customize your contact details such as your phone number, user name, password and e-mail address. You also can hide your contact details from strangers.
Profile -> Settings
Go to: settings -> timeline and tagging settings
In this section, you can adjust your settings for tagging of photos, who can see your timeline and who can add items to your timeline.
Profile -> Settings
Go to: settings -> blocking
Facebook also offers a unique “block” feature. You can use this feature to block those who are sending you weird messages, posting spam links or are annoying you in any way.
Other security measures
- Do not click on suspicious links.
- Use a unique password for accessing your Facebook account and never disclose it to anyone else.
- Avoid logging into your Facebook account on untrusted networks.
- Just because a link is on Facebook doesn’t mean it is safe avoid clicking on Facebook ads.
- Avoid using third party applications like online data transfer, information exchange, games etc.
- Never forget to logout.
- Share your posts, updates, pictures within your friend circle rather than making it public.
How-To Video: Securing Facebook
Monday, July 19, 2010
Beware about Scareware Software Live Supports
Now a days fake anti-virus software (scareware )distributors are offering 'Online Support' to convince their victims to steal their valuable data including credit card information. This was discovered by Mr. Nicolas Brulez of Kaspersky that the scareware distributors are now offering actual live support. Users installing fake anti-virus software Security Master AV and clicking on the 'Online Support' button are directed to a chat window in which they can put questions directly to the scareware 'vendor'. As a special offer, the 'support team' offers a one-day trial version of the full product, which reliably removes the imaginary malware identified by the 'demo' version from the user's system. Debora Brown, Kendra Grace and David Lee appear to have all the time in the world online to convince victims in fluent English that their software is genuine and to get them to install the bogus full product. Alternatively, victims can call them up, or send an email. It is suspected that the extra-helpful scareware distributor is located in Russia or the Ukraine. The FBI recently charged three men accused of extracting around $100 million from internet users in more than 60 countries.
Sunday, December 28, 2008
90 Percent of emails received Worldwide are SPAM
90 Percent of emails received Worldwide are SPAM
A recent survey has found that 90 percent of the emails sent to a person’s inbox are usually spam. 90pct of emails received worldwide are spamThe survey report suggests that more and more hackers are devising new ways to send in spam emails, reports the China Daily.
It further states that virus-infected computers are woven into “botnets” used to attack more machines, and to send sales pitches to e-mail addresses in low-cost quests to bilk readers out of cash.
“Every year we see threats evolve as criminals discover new ways to exploit people, networks and the Internet,” Cisco chief security researcher Patrick Peterson, who was involved in drafting the report, said.
According to the Cisco Annual Security Report, junk e-mail make up for nearly 200 billion messages daily, approximately 90 percent of email worldwide.
As per the survey, the US is the biggest source of spam, accounting for 17.2 percent messages.
Turkey and Russia ranked second and third, accounting for 9.2 percent and 8 percent spam respectively, according to Cisco.
This year, botnets were used to inject an array of legitimate websites with an IFrames malicious code that reroutes visitors to websites that download computer viruses into their machines.
“The botnet is, in many cases, ground-zero for online criminal threats,” Peterson said.
“Using malware to infect someone's computers is an incredibly common mechanism and harnessing them all together is a way they do their click fraud, spam emails, and data stealing,” he added.
Online criminals are turning botnets on web-based e-mail accounts. Hackers are "reputation hijacking" by using botnets to figure out weak passwords protecting web-based e-mail accounts, according to Peterson.
Weak passwords consist of family names, birthdays, home addresses or other terms considered relatively easy to deduce.
Once access is gained to legitimate e-mail accounts, a plethora of spam messages are sent in the owners' names.
Source: ANI
Sunday, February 17, 2008
Why you probably aren’t practicing good password security
Strong passwords are difficult to remember.
Juggling a multitude of passwords is a pain.
Updating passwords compounds the memorization problem.
Due to vulnerabilities in Operating System and other application software users' online accounts can become compromised through phishing schemes, viruses, and spyware.
I suggest the following good security practice for you:
Strong passwords that are hard to guess.
Different passwords at each site.
Periodically changing existing passwords.
Tuesday, February 12, 2008
How to Protect your online accounts
1. Don't share: Keep your username, password and personal information secret. You are requested to change your password regularly. Password must be alphanumeric with special character and greater than 8 character in length.
2. Don't click: Never click on any link you suspect to be malicious, even if sent by someone you trust. Scan your computer regularly for viruses, spyware and adware. Updates your Operating System and other application software regularly.
3. Don't click: Never click on links in emails that claim to be from mail provider (gmail.com, yahoo.com), bank authorities (hdfcbank.com, icicibank.com), auction sites (ebay.com, amzone.com) or social networking sites (orkut.com, myspace.com). Scan your computer regularly for viruses, spyware, and adware.
4. Don't spread: Never enter your account login and password on sites other than the original site. Never check remember me when you're using a shared computer.
5. Don't Share Personal Data: Avoid posting sensitive personal data, such as email addresses, phone number or pictures, in public places.
6. Don't forget to click the Logout link of the page when you're done using an online account.
7. Don't script: Never paste a URL or script into your browser while logged into a account especially social networking site viz. orkut.com, mysapce.com no matter what it claims to do.

