Cyber Security Tip & Tricks
Showing posts with label website. Show all posts
Showing posts with label website. Show all posts

Thursday, November 17, 2011

Choose Smart Password for your online accounts and protect from hacking

Password is the first line of defense against cyber criminals. If you are using the same password on different websites allows hijackers to access your important accounts details like email, and bank details, if they manage to steal your password from a less secure website.   You're likely to have dozens of accounts across the web, and you can't guarantee the security of all of those accounts. Many smaller companies don't have security technology capable of guarding your data from cyber criminals. When you use the same password across the web, a cyber criminal can gain access to a less secure account and then use that password to compromise your important accounts.



To create a smart password try the following steps:

  • Use unique passwords for your accounts, especially important accounts like email and online banking. Re-using passwords is risky. If someone figures out your password for one service, that person could potentially gain access to your private email, address, and even your money. 

  • Using numbers, symbols and mixed-case letters in your password increases the difficulty of guessing or cracking your password. For example, there are more than 6 quadrillion possible variations for an eight-character password with numbers, symbols, and mixed-case letters - 30,000 times more variations than an eight-character password with only lowercase letters.  Do NOT use personal information such as birth dates, anniversaries, special events, etc. because if the hacker is a so-called friend of acquaintance, your password yells free information. Additionally the longer the pass word the more secure, 8 characters in length is acceptable but 14 is recommended.

  • Choose a combination of letters, numbers, or symbols to create a unique password that's unrelated to your personal information. Or, select a random word or phrase, and insert letters and numbers into the beginning, middle, and end to make it extra difficult to guess (such as "sPo0kyh@ll0w3En"). Using simple words or phrases like "password" or "letmein," keyboard patterns such as "qwerty" or "qazwsx," or sequential patterns such as "abcd1234" make your password easier to guess or crack.

  •  Make sure to regularly update your recovery email address so that you can receive emails in case you need to reset your password. You can also add a phone number to receive password reset codes via text message. Additionally, many websites (including Gmail) will ask you to choose a question to verify your identity if you ever forget your password. If you're able to create your own question, try to come up with a question that has an answer only you would know. The answer shouldn't be something that someone can guess by scanning information you've posted online in social networking profiles, blogs, and other places. If you're asked to choose a question from a list of options, such as the city where you were born, be aware that these questions are likely to be less secure. Try to find a way to make your answer unique — you can do this by using some of the tips above — so that even if someone guesses the answer, they won't know how to enter it properly.

  • Don't leave notes with your passwords to various sites on your computer or desk. People who walk by can easily steal this information and use it to compromise your account. If you decide to save your passwords in a file on your computer, create a unique name for the file so people don't know what's inside. Avoid giving the file an obvious name, such as "my passwords." If you have a difficult time remembering multiple passwords, a trusted password manager may be a good solution. Spend a few minutes checking out the reviews and reputations of these services.

Source: Google.com


Tuesday, September 18, 2007

The net is an insecure place - US CERT Reminder

If you use Gmail, eBay, MySpace, or any one of dozens of other web-based services, the United States Computer Emergency Readiness Team wants you to know you're vulnerable to a simple attack that could give an attacker complete control over your account.

US CERT warned that Google, eBay, MySpace, Yahoo, and Microsoft were vulnerable, but that list is nowhere near exhaustive. It said the world's biggest websites have yet to fix the gaping security bug, which can bite even careful users who only log in using the secure sockets layer protocol, which is denoted by an HTTPS in the beginning of browser address window. Just about any banking website, online social network or other electronic forum that transmits certain types of security cookies is also susceptible.

The vulnerability stems from websites' use of authentication cookies, which work much the way an ink-based hand stamp does at your favorite night club. Like the stamp, the cookie acts as assurance to sensitive web servers that the user has already been vetted by security and is authorized to tread beyond the velvet rope.

The thing is just about every website transmits these digital hand stamps in the clear, which leaves them wide open to snoops monitoring public Wi-Fi traffic or some other type of network. Once attackers have the cookie, they gain complete access to the victim's account, and depending on the way many cookies are crafted, those privileges may continue in perpetuity - even if the victim changes the account password.

Indeed, awareness of this man-in-the-middle vulnerability is by no means new. For more than a decade people have known that authentication cookies could be manipulated, but somehow it took the folks at Errata Security to make a presentation at Black Hat to remind the world that the risks continue.

If you're waiting for a fix, we recommend you pack a very large lunch. And beyond that, where possible you might switch to Google, which has already gone a long way to closing the hole.

As the only web-based email service we know of that offers a start-to-finish SSL session, the service is among the most resilient to cookie hijacking. Unfortunately, Gmail doesn't enable persistent SSL by default, and has done little to educate its users about its benefits.

The company also offers SSL for its calendar, search history, documents and reader services, and a Google spokesman said security engineers "are actively working to expand capacity to enable HTTPS encryption for all users."

In the meantime, a Firefox extension called CustomizeGoogle provides a simple way to ensure that all sessions with the above-mentioned Google services are automatically protected by SSL.

Tuesday, July 24, 2007

iPhone Hacked Successfully - Security Firm Says

iPhone Hacked Successfully - Security Firm Says

A vulnarabilty has found in the Apple Inc.'s iPhone handset that can help an attacker to gain access to the private data stored on it. This flaw has found by a team of security expert of Independent Security Evaluators (ISE). Hackers could gain access to the iPhone through a wireless access point or through a website controlled by the attacker. This was the first major security incident reported.

Numerous hackers have been working to gain access to the iPhone in order to activate certain features or to allow it to be used on cellular networks. However, this is the first major exploitation of an iPhone security flaw.

The expolit is delivered via a malicious web page opened in the Safari browser on the iPhone, ISE said on its Website. There are several methods that an attacker utilize to get a victim to open such a webpage.

1. An attacker controlled wireless access point:

The iPhone connects to wireless Internet access networks, such as Wi-Fi, an attacker could create a network with the same name and encryption method as one the handset already uses. The attacker could then substitute a Web page with exploit code to gain access to the phone.

2. A misconfigured forum website:

A link planted on an unedited or unmoderated online forum, an attacker could cause the exploit to run in any iPhone browser that viewed the thread.

3. A link delivered via e-mail or SMS:

A link sent by SMS or e-mail to use make use of the flaw and gain access to the handset.

The ISE said that when the iPhone's Safari browser opens a malicious Web page, malicious code can be run on the phone via the flaw, allowing the attacker to read the iPhone's SMS log, address book, call history, and voicemail information, which are also then sent to the attacker. It could send the user's mail passwords to the attacker, send text messages that sign the user up for pay services, or record audio that could be relayed to the attacker.

Source: nytimes

iPhone Hacked Successfully - Security Firm Says

iPhone Hacked Successfully - Security Firm Says

A vulnarabilty has found in the Apple Inc.'s iPhone handset that can help an attacker to gain access to the private data stored on it. This flaw has found by a team of security expert of Independent Security Evaluators (ISE). Hackers could gain access to the iPhone through a wireless access point or through a website controlled by the attacker. This was the first major security incident reported.

Numerous hackers have been working to gain access to the iPhone in order to activate certain features or to allow it to be used on cellular networks other than AT&T Inc.'s. However, this is the first major exploitation of an iPhone security flaw.

The expolit is delivered via a malicious web page opened in the Safari browser on the iPhone, ISE said on its Website. There are several methods that an attacker utilize to get a victim to open such a webpage.

1. An attacker controlled wireless access point:

The iPhone connects to wireless Internet access networks, such as Wi-Fi, an attacker could create a network with the same name and encryption method as one the handset already uses. The attacker could then substitute a Web page with exploit code to gain access to the phone.

2. A misconfigured forum website:

A link planted on an unedited or unmoderated online forum, an attacker could cause the exploit to run in any iPhone browser that viewed the thread.

3. A link delivered via e-mail or SMS:

A link sent by SMS or e-mail to use make use of the flaw and gain access to the handset.

The ISE said that when the iPhone's Safari browser opens a malicious Web page, malicious code can be run on the phone via the flaw, allowing the attacker to read the iPhone's SMS log, address book, call history, and voicemail information, which are also then sent to the attacker. It could send the user's mail passwords to the attacker, send text messages that sign the user up for pay services, or record audio that could be relayed to the attacker.

Source: nytimes

Friday, July 13, 2007

Fake website in the name of AKG Centre

The State Police Hi-Tech Cell have come across a website viz. www.akgcentre.org.in - registered neither by the CPM nor with its knowledge.

The Thiruvananthapuram City Police have registered a case and the efforts are on to find out the culprit behind which the portal was registered with the assistance of Hi-Tech Cell.

Source: Newindpress

Wednesday, June 27, 2007

CM's website hacking: State Police to sent ‘Letter of Rogatory’

The State police are planning to sent a ‘Letter of Rogatory’, a formal request by a Court to the Interpol, to get certain details pertaining to the Chief Minister's website hacking case.

Though the State police had earlier sent a request to the Interpol Wing attached to the CBI seeking the details through their counterparts in the US, Russia and China, they refused to had over the requests for want of a ‘Letter of rogatory’.

They have however preserved the electronic evidence including log files required by the State Police to crack the case.

The State Police are concerned that this would delay the investigation. The State Police would prepare the draft ‘letter of rogatory’ and send it to the Interpol wing of CBI who will forward it to the External Affairs Ministry.

The letters would be later produced before the Chief Judicial Magistrate and letter would be forwarded through the court.

It may be recalled that the Vigilance and Anti-Corruption Bureau had initiated a ‘letter of rogatory’ for collecting certain details from a French company involved in the Brahmapuram power plant corruption case.

Chief Minister's website ‘www.keralacm.gov.in’ was hacked and inserted objectionable contents. The police had found that the site was hacked from Internet Protocol addressed located in the US, Russia and China following the help of Interpol was sought.
Source: newindpress

Monday, June 18, 2007

Thumbstrips - View or Search Your Web Browser History in a Picture Timeline

Thumbstrips is a wonderful Firefox extension that helps you view recently visited web pages in a visual manner - it's a more user friendly and powerful approach than the native Firefox History view (Ctrl+H).

Thumbstrips, like an automatic screen capture program, takes screenshots of the websites that you are visiting and also records other details like how long you stayed on that web page and the number of times you viewed that page in your current session.
Thumbstrips Extension[Firefox Only]
Source: Digital Inspiration

Sunday, June 10, 2007

Hacking of CM's Website - Kerala Police sought INTERPOL help

The Kerala Police have sought the assistance of the International Police Organisation (INTERPOL) to track those who behind the hacking of the official Website of Kerala Chief Minister www.keralacm.gov.in.

Hackers had inserted links to objectionable contents in the CM’s Website. New topics were created in the Discussion Forum and links to certain websites with objectionable contents are inserted.

The Website was hacked by unidentified persons four times recently. The Hi-Tech Crime Enquiry Cell of Kerala Police with the help of C-DAC Cyber Forensic Division Experts traced the IP (Internet Protocol) Addresses. These addresses are located in the US, Russia and China. Meanwhile, the official Website run by C-DIT has been pulled out from the World Wide Web for an overhaul.

Source: Newindpress

Monday, June 4, 2007

വിഎസിന്‍റെ സൈറ്റ് ഹാക്ക് ചെയ്തു



തിരുവനന്തപുരം: മുഖ്യമന്ത്രി വി എസ്‌ അച്യുതാനന്ദന്‍റെ ഔദ്യോഗിക വെബ്സൈറ്റ്‌ നാലുതവണ ഹാക്ക്‌ ചെയ്യപ്പെട്ടതായി വെളിപ്പെട്ടു.സൈബര്‍ ക്രൈം സെല്‍ ഇതേകുറിച്ച്‌ നടത്തിയ അന്വേഷണം എങ്ങും എത്തിയിട്ടില്ല.മുഖ്യമന്ത്രിയുടെ സൈറ്റിന്‍റെ പരിപാലന ചുമതല സിഡിറ്റിനാണ്‌.

കൃത്രിമ പാസ്‌വേഡ്‌ ഉപയോഗിച്ച്‌ വെബ്സൈറ്റിലെ വിവരങ്ങള്‍ മാറ്റുകയും പുതിയവ തിരുകി കയറ്റുകയും ചെയ്തിരുന്നു. സൈബര്‍ ക്രൈംസെല്‍ മേധാവി ഐ ജി ലോക്നാഥ്‌ ബെഹ്‌റയുടെ നേതൃത്വത്തില്‍ അന്വേഷണം പുരോഗമിക്കുന്നുണ്ട്‌.

മൂന്നാര്‍ ദൗത്യസംഘത്തില്‍പെട്ട ഐ ജി ഋഷിരാജ്സിങ്ങിനെ കൊന്നുകളയുമെന്ന ഭീഷണിയും മുഖ്യമന്ത്രിയുടെ വെബ്സൈറ്റില്‍ പ്രത്യക്ഷപ്പെട്ടിരുന്നു. വധഭീഷണി അയച്ച മേല്‍വിലാസത്തെ കുറിച്ച്‌ അന്വേഷണം പുരോഗമിക്കുന്നു. എന്നാല്‍ അന്വേഷണത്തിന്‍റെ കൂടുതല്‍ വിവരങ്ങള്‍ പറത്തുവിട്ടിട്ടില്ല.
Source: MSN India

AddThis Social Bookmark Button

Recent Comments