Affichage des articles dont le libellé est Infosec. Afficher tous les articles
Affichage des articles dont le libellé est Infosec. Afficher tous les articles

Identify the Gaps in Your Security Strategies

Every day we hear stories about Businesses lose critical data; regardless of billions of dollars invested in cyber security, we have failed to provide full proof security. We’ve secured our organizations by building layers of walls around networks, applications, storage, identity and devices.



Data security company Vera has identified some shocking gaps in security policies to help enterprises better understand and diagnose their data security loopholes.

Behavioral Gap

According to breach study by Ponemon, it has been noticed that human negligence is responsible for 25% of data breaches globally.

Most of the time employees avoid using internal systems and software tools for their routine task. That is the biggest behavioral gap an organization can have. Employee bypasses the secure File Transfer Protocol (FTP) servers by simply copy and pasting data into insecure files and then sends it from their personalized email accounts. This is the major gap where transmission of sensitive data remains undetected by the enterprise security layers.

Visibility Gap

The data is lost when companies are unable to trace that where, when and for what the information is being used. The big question is that what is being done with your information by third party vendors? Most of the employees receive files unintentionally. If data is regulated, businesses bear responsibility for it, even when you cannot see it.

Control Gap

The ability to lock down access to the lost documents is gone when data in slipped away or passed the security layers of the organization. There isn’t any undo button for lost files to revoke the access controls to access the information. It’s the root cause of many cloud collaboration and storage fear that need to be addressed sooner before it’s too late.

Response Time Gap

We lose data because of the time delay it takes to identify and respond to the incident and new technologies that are sharing enterprise data. Many employees do their task regardless of its security impact and then information security is left way behind. Enterprises require security that operates at the speed of business, with the flexibility to be adapted by each and every employee and stakeholders.

Mobile Security

The phones and tablets your employees and partners use to access information is the main concern for enterprise security. The security gap is created when employee, customers and partners start using mobile devices for personal use as well. The third party application can easily breach the security layer of the organization’s system and can cause information leak. This gap can easily overcome by conducting awareness sessions for each and every stakeholder that is dealing with the company’s information.

Businesses today simply cannot fill security gaps by following old strategies to secure information. It’s time to look at protecting the data throughout its entire life cycle from its propagation from employee to outside the organization, application and devices then further where that information is being used as well. That’s the only way we can overcome these gaps and protect the information at its best.


~ samedi 13 août 2016 0 commentaires

Secured! Think Again About That Printer in the Corner

In many organizations the printers are used too often and in some it is collecting dust, apparently, it’s the best target that can be used as an attacking surface. There are countless companies who don’t bother about updating the firmware of their printers, leaving their documents open to attackers. The inventories like printers and others are not even discussed in annual security audits and are assumed to be useless in security aspects.



As printers are seemingly harmless, that’s the exact reason it poses a serious threat. Sometimes, the best attack vector for an attacker is the one to which no one bothers to think about. However, a recent IDC survey found that 35 percent of all security breaches in offices were traced back to an unsecured printer or multi-function device, costing companies $133,800 each year.

Why Companies Should Consider Printer as a Security Threat?

As printers are the essential inventories to business from small organizations to huge corporate level organizations and are ignored when it comes to vulnerability management and assessment. Enterprise security tools are only to protect computers and network; they often do not block or monitor access from the printers. That makes the printer a trouble-free approach to the attacker.

Chris Vickery, a white hat hacker and Security Researcher at MacKeeper said: “Getting control of a printer within an organization can provide a foothold for further attacks and a position to ‘pivot’ out of into networks”.

There are some serious effects if the printer gets compromised and used by attacker, like attackers can capture every document sent to the printer. It could be serious business intelligence comprise that no organization can tolerate.

Preventing Data Loss from Printers

It’s too easy to suggest one ultimate security tip to prevent such threat that includes the replacement of outdated printers with newer models that have some latest security features. Furthermore, Data encryption should be introduced to all latest printers to prevent data exposure if compromised. Although it has been adopted by Xerox in March 2016, other companies should also consider this feature to introduce with their products.

In the end, as IT administrators are responsible to configure printer and other multipurpose device in an organization, they should be aware of the threats associated with those devices so some serious countermeasures can be taken prior to the transmission of data.


~ mercredi 10 août 2016 0 commentaires

The most commonly used passwords on the internet - Research

The social networking site LinkedIn was the talking point of Infosec community this week because of the data breach of its 117 Million users. The site was initially hacked four years ago, but the results of hack are showing now. The data of its users is up for sales on dark web according to various sources.



This isn't the first time a major internet giant have fallen victim of data breach, which affected its millions of users all over the world. Last year Ashley Madison an online dating website was hacked which have led to the resignation of its CEO and destroyed the marriages of many people.
However, the question is how hackers are able to breach these highly secured websites and gain passwords of millions of users. Yes, mainly it's because of the lack of cyber security steps taken by those organizations, but the users are equally responsible for becoming a victim of these hacking attacks. 

EHacking researchers have seen that most of the passwords that are hacked previously are commonly used around the globe and most people doesn't care if their password isn't secure. The passwords leaked from the latest LinkedIn hack are similar to the hacks of past years. 

We have gathered the list of most commonly used passwords on the internet right now. List also includes the passwords leaked after the LinkedIn hack.  

RankPasswordFrequency
1123456753,305
2linkedin172,523
3password144,458
412345678994,314
51234567863,769
611111157,210
7123456749,652
8sunshine39,118
9qwerty37,538
1065432133,854
1100000032,490
12password130,981
13abc12330,398
14charlie28,049
15linked25,334
16maggie23,892
17michael23,075
1866666622,888
19princess22,122
2012312321,826
21iloveyou20,251
22123456789019,575
23Linkedin119,441
24daniel19,184
25bailey18,805
26welcome18,504
27buster18,395
28Passw0rd18,208
29baseball17,858
30shadow17,781
3112121217,134
32hannah17,040
33monkey16,958
34thomas16,789
35summer16,652
36george16,620
37harley16,275
3822222216,165
39jessica16,088
40ginger16,040
41michelle16,024
42abcdef15,938
43sophie15,884
44jordan15,839
45freedom15,793
4655555515,664
47tigger15,658
48joshua15,628
49pepper15,610

How to create a strong password

Creating a strong password needs the combination of alphabets, numbers, signs. Here are some examples: 

3Hghfwg-09;l or gTHncdsY93]ND 


~ jeudi 19 mai 2016 0 commentaires

Twitter adopts anti-abuse measures to tackle violent threats and abuse



 Twitter has announced some alterations in product and policy in order to tackle violent threats and abuse on its platform.

In a blogpost, Twitter has affirmed to adopt anti-abuse measures. It involves the implementation of new technology that enables to identify and limit the reach of abusive tweets. It also includes renewed violent threat policy that allows Twitter to lockdown the accounts belonging to suspects of cyberbullying.



Shreyas Doshi, Twitter director of product management, admits in a blog post that the company's previous policy was "unduly narrow" and allowed for certain kinds of threatening behavior to go unchecked. Twitter is giving authority to its enforcement team, to lock abusive accounts for a specified period of time. This interlude is designed to force abusers to delete tweets that violate the abuse terms. However, it also allows Twitter to require a user's phone number to reinstate their account.


Twitter is also trying an advanced feature that will enable the enforcement team to identify abusive tweets and "limit their reach" on the platform. The tool will use "signals and context" that indicate abuse and the similarity between a tweet and other content that was previously deemed abusive.

Particularly, to cut abusive trolls off at the moment of tweeting, rather than after targeted abuse has hit home and caused the intended distress. This is a significant step for a company that has been optimistic in pronouncing the ‘tweets must flow’ in the past.

 In February CEO Dick Costolo admitted that Twitter sucked "at dealing with abuse and trolls on the platform." 

The twitter’s ultimate goal is to s to ensure that it is a safe place for the widest possible range of perspectives and they will continue to evaluate and update their approach in this critical arena.

“While dedicating more resources toward better responding to abuse reports is necessary and even critical, an equally important priority for us is identifying and limiting the incentives that enable and even encourage some users to engage in abuse,” according to Doshi.


~ mardi 21 avril 2015 0 commentaires

BT introduces "Ethical Hacking for Vehicles"

The British phone today announced the launch of “BT Assure Ethical Hacking for Vehicles”. This new service has been developed to prevent connected vehicles from cyber-attacks.

Connected vehicles including cars, trucks, buses, and other sort of commercial vehicle rely on various connectivity options such as WiFi, 3G or 4G data links, Bluetooth and other wireless technologies. These services provide a wide range of new on-board features.



These technologies have also provided hackers the gateway to gain access and control of the essential features and functions of vehicles. It also provides information on drivers’ habits for commercial purposes without the drivers’ consent and even remotely hijacking a vehicle.

BT has a strong global team of ethical hackers and security experts who wants to extenuate attacks before they take place even before cars turn out the production line.

Hubertus von Roenne, BT vice-president stated that citing one case where an electric car acquired malware after it was plugged in at a rigged charging station. It means that manufacturers are facing a whole new level of risk.

He further declared that the company's expanding its team to the automotive industry now because the automotive threat landscape continues to develop.

Earlier this year, sister-site CBS News' 60 Minutes showed how even the toughest military machines can be cracked open in minutes.

"It raises questions of safety, it raises questions of privacy, because no longer do you need a crowbar in order to break into a car, now you can do it with an iPad," Sen. Ed Markey (D-MA) said in response to the report.

But the government agency that invented the Internet has a brilliant videogame inventor on its side working to make the web safe for all users, starting with the military.


~ lundi 20 avril 2015 0 commentaires

Fidelis Cybersecurity Solutions provides Products to Combat Security Threats

Marlin Equity Partners has signed an agreement with General Dynamics to acquire Fidelis Cybersecurity Solutions, a company which recently discovered the new remote access Trojan AlienSpy.

Marlin Equity firm announced on Tuesday that Fidelis will become the foundation of a new cybersecurity company called Fidelis Cybersecurity.



Fidelis Cybersecurity Solutions, a part of General Dynamics Mission Systems, offers a comprehensive portfolio of products, services, and expertise to help customers withstand the sophisticated threats and to prevent data and intellectual property theft.


Recently, Fidelis released a threat advisory which includes details of a new remote access Trojan (RAT) which is known as AlienSpy. According to the firm, the RAT is being used in international phishing campaigns which target both businesses and consumers. AlienSpy reveals a number of sophisticated functions due to which Fidelis suspects that the malicious code is the result of collaborative efforts as it comprises multiplatform support and new evasion techniques.

Fidelis offers a product, Fidelis XPS™ which provides an advanced threat defense. The world’s largest organizations view it as highly effective in detecting and preventing not only initial malware infections, but also the subsequent spread of malware within organizations and the theft of information.

 Fidelis complements this solution with an elite incident response team which is on the frontline helping customers investigate breaches and stop zero days, and a threat research team conducting original research and incorporating real-time insights into Fidelis XPS.

Peter Chung, a principal at Marlin, has stated:
"Marlin is very excited to partner with Fidelis' world class management team to expand and grow the company's industry-leading solutions. As global cybersecurity threats continue to become more prevalent, Fidelis' technology is uniquely positioned to help customers defend themselves against advanced malware attacks and internal and external data theft."

Marlin Equity Partners is a global investment firm with over $3 billion of capital under management, and since it’s founding has acquired over 85 companies.


~ mardi 14 avril 2015 0 commentaires

An Interview with the Founder of Bulb Security, Georgia Weidman

Georgia Weidman is one of the few women in the Infosec industry who made a name for herself. She is an experienced penetration tester, security researcher and trainer. She is also the founder of Bulb Security which is highly rated security firm for security assessments and training.

Georgia was awarded a DARPA Cyber Fast Track grant to build the Smartphone Pentest Framework (SPF). She is also the founder of Shevirah Inc. a provider of testing tools for assessing and managing the risk of mobile devices in the enterprise and testing the effectiveness of enterprise mobility management solutions. Shevirah allows security teams to integrate mobility into their risk management and penetration testing program. Georgia is invited as a speaker on many international security conferences To name a few she has spoken at the Blackhat Briefings, Brucon, Hack in the Box, Derbycon, and many Bsides events.

Georgia’s work has been featured in print articles including CNN, Ars Technica, PC World, and MIT Technology Review. She’s also discussed security on television on programs such as Fox News Live and 16×9 on Global TV Canada.


Georgia completed her bachelor’s degree at the age of 18. After that she perused her education in Computer Science from James Madison University with emphases in information security and secure software engineering.
Georgia success story doesn’t end there. Her book was published recently under the tile Penetration Testing: A Hands-on Introduction to Hacking. Here is an exclusive interview that she gave to Ehacking. We have asked some

EH: Hi Georgia, as we see in your short biography you have achieved tremendous success as an Infosec professional which is a rare thing.  World want to know what brings you to this Industry? 

GW: Well both my parents are technical, so it was kind of a given that I would pursue some sort of technical career. I went to an early college program that was all female. While there were fewer students in the STEM fields, I thought that was because they were harder fields of study than other subjects. It wasn’t actually until graduate school that it even occurred to me that women in computer science are rare. I’ve never let that hold me back though. I discovered cyber security in the collegiate cyber defense competition (CCDC) a competition in the United States for college students to get a taste of the life of security professionals managing a network actively under attack. I really enjoyed the competition, even though naturally it was more stressful to keep a network alive and well when a lot of security professionals kept trying to break into it. I immediately knew I had found my calling and decided to pursue a career in information security.

EH: You are pretty much becoming a role model with your accomplishments for the young girls. What message do you want to give them?

GW: Never let anyone tell you don’t belong in information security. Unfortunately, there are a lot of people who get jealous of anyone else’s success and try to tear other people down. Anyone who is in a minority in the industry gets more than their fair share of abuse. Don’t let it get you down. If people are mean to you, it means you are doing something right, making mean people jealous of your successes. It’s easier said than done to not let things like that get to you, but it’s important that people with a passion for information security pursue a career in this field.



EH: Give us an insight about your book? What was the motive behind it and what do you want to accomplish through it?

GW: I wanted to provide a hands-on book for beginners, people just starting in information security, to help them learn. When I was first starting out I had a lot of trouble getting the experience I needed to move forward. Lots of tutorials would assume understanding of Linux or programming or even previous information security experience that I didn’t have. And a lot of times when I would ask for help I’d get something along the lines of “Get off N00b!” which was very frustrating. I teach introductory technical information security courses, but naturally not everyone will be able to attend those. With the book hopefully I will be able to reach more people who are interested in learning these skills. Readers will have to do the work to learn the skills, setting up the environment and working through the exercises, but it makes the information available for beginners everywhere to learn.

EH: You have an M.S degree in Computer Science. Do you think that it is important for the people to succeed in this Industry to have an educational background in Computer Science?

GW: I went to college early at the age  of 14. So when I graduated I was only 18 and not sure what I wanted to do yet. I went to get a Master’s degree just to avoid moving back home with parents after college. Luckily in the course of my studies I joined the cyber defense club at my school and discovered my passion for information security. I know many security professionals who do not have a  college degree or studied another subject. Hard work and gaining skills in information security will get you far in this industry. That said, it is much easier to get your first information security job if you have a computer science educational background. Many schools even offer an information security concentration.

EH: We have seen that some hacking groups are pretty much in news in recent times like Syrian Electronic Army and Anonymous. What is the motivation behind those attacks?

GW: Why do people do bad things? That’s a question for the psychologist or philosopher. Hacking attacks are motivated by the same things as other types of attack. There are monetary rewards associated with attacks whether from some entity paying you for the attack or the “spoils” of the attack like credit card information. There is also the thrill and prestige that comes from said attack, although the individual anonymity is a drawback. I think the primary motivation for these latest attacks are to generate fear. Or maybe it is just a warning to us to take security seriously.

EH: The companies are investing millions on their Cyber security programs but still we see time to time that even the most powerful companies fall victims to cyber attacks. As a founder of a Bulb security do you think the world will ever have a full proof Cyber Security program which was impossible to breach?

GW: I don’t think it’s possible to have a running network without at least some vulnerability. Consider your home. You probably have door locks, maybe an alarm system, maybe bars on the windows if you live in a very high crime area. But would you consider your house impossible for a thief to break into? What if the thief knows how to pick locks? What if the thief poses as a delivery person or police officer to trick you into gaining access? We can and should minimize risk as much as possible, but we must never assume that we are not vulnerable to any attacks. This will give us a false sense of security and we will not do the things we need to insure we are as secure as possible.


EH: According to a research the Cyber Security industry will grow three times in the next 4 years. This is the hottest Industry right now for the Investors. How do you see the future of this Industry? What challenges this Industry is facing and what steps can be taken to eliminate those challenges?

GW: The biggest challenge I see is the way our networks and assets are changing. In a traditional network where everything is hosted locally, physically in our data center, on someone’s desk, etc. The only way they can communicate is over the network, with all traffic passing through our perimeter to the Internet. With the rise of mobile, the cloud, etc. this is changing drastically. Traditional methods of vulnerability assessment, incident response, etc. are not sufficient to deal with these changes. In particular, my work centers around moving vulnerability assessment and penetration testing capabilities forward to cover the unique issues around mobile devices such as the mobile modem, near field communication, and the effectiveness of security controls around mobile such as enterprise mobility management solutions and data containers.

EH: What is your opinion about Edward Snowden?


GW: When Edward Snowden exposed our government’s spying practices, most people were not at all surprised by the news. This is really sad because privacy is one of those freedoms we should be protecting instead of giving away. Most of our privacy laws are built on an expectation of privacy. Do you have any expectation of privacy, now?

EH: Women in information security, is it still myth or they can make it?

GW: Of course they can make it, and anyone who says otherwise is the people who shouldn’t be making it in information security. Anyone who says otherwise needs to climb back under the rock they came from.

EH: At the end, what would you recommend/suggest to someone new in information security filed?

GW: My book of course. And there’s some great free training available at Cybrary.it including a course from me that does some of the exercises from my book (and some additional exercises and topics) in video form.
Something along the line of do lots of different types of trainings to figure out what you like and what you are good at. Network/intern with people in those areas so your talents become known.
interesting questions related to the current scenario, the future of Infosec and the role of women in this industry.

Georgia Weidman has achieved tremendous success in pretty short time. She was gifted because of her family background but it was in college when she realized her potential in a Cyber security competition. 
 
The biggest reason behind her success is the passion, Georgia is a perfect role model for the young generation specially for those who think this industry is for men only.

~ 0 commentaires

France Accused for Mass Surveillance Plans

Privacy advocates have criticized French tech companies for introducing a bill that they argue will put the entire French population "under surveillance."

According to the organization Human Rights Watch (HRW), the bill could open the back door to a surveillance society. Among the dangers identified by the NGO are the proposed new powers of the Prime Minister, who would be able to authorize surveillance operations covering a much broader range of objectives than those permitted under international law, the lack of judicial supervision and the lack of transparency.



New technologies including microphones, trackers and spy cameras will be used by the agent to carry out spying activities. They would also be able to intercept conversations typed on a keyboard in real time.
All these interceptions would be authorized by the Prime Minister, without the prior approval of a judge, and would be authorized after the fact by a new administrative authority, the National Commission for the Control of Intelligence Techniques (CNCTR).


The companies protested that installing "black boxes" on their networks as required by the law will "destroy a major segment of the economy," and if passed it will force them to "move our infrastructure, investments, and employees where our customers will want to work with us."

International human rights law views the protection of national security and public safety as justifying surveillance. HRW have warned that the French laws are extending towards laying the foundations of a surveillance state.

HRW claims that wide-ranging authorities would be granted to French prime minister to run surveillance ops practically unconstrained by the "rather toothless" new Commission.

Surveillance actions which may involve hacking and malware could be renovated frequently without judicial scrutiny or notification to the target. Data acquired through surveillance may be retained for five years and in some situations even for a longer period.


~ dimanche 12 avril 2015 0 commentaires

India VS Pakistan Cyber war - The battle of Nonsense Cyber Armies

Countries nowadays don't want to start wars on their border because it creates win-lose situation, loads of destruction, human life and infrastructure are in danger and there are many other disadvantages are there. The bitter truth is that human can't live without having a war, so we (human) have chosen a new ground to commence war. The ground is commonly known as cyber world, or the world based on electron and the switch.

Whether it is USA VS China, India VS Pakistan & North Korea VS USA, all the countries are developing their cyber forces to attack on the enemy, recently China has admitted that they have the cyber force but other countries are yet to admit.

The Scenario of Cyber warefare

India VS Pakistan, they have many things in common, including the hate; both countries are in development phase, but they used to attack on each other technological infrastructure to give the maximum damage. The war might not be going at the state level, but their individuals are involved in cyber warfare, these individuals might be university students, graduates or the one looking for a job.


The war might not be at the state level because the state should not be interested to deface a website of a real estate agent (here we mean a common website having lots of vulnerabilities). So who are they? They, Pakistan Cyber Army (PCA), Indian Cyber Army (ICA) and others (there are plenty of groups). What their motives are? Why they are doing this?

An Analysis of this Nonsense War

Next time if you hear that PCA or ICA has hacked 10K websites, you should not give a ****. They are nobodies, they don't have a mission, vision, values or even a team; they do this to have fun and these defacement are nothing but a show off, they used to promote one of their forum and to make common people fool so that they join them, praise them and beg them to teach hacking.

Their definition of hacking is to use Google dork to get a vulnerable website, perform SQL-injection by using automatic tools like Havij and SQLmap, get in and replace a home page with an image that's it. They don't care about the happenings and development of Infosec industry because they are a bunch of fools and they know nothing.

Final Note: A suggestion

If you are interested in cyber security and infosec then you should not indulge yourself in defacement because the result won't lead you to your destination and you will soon find yourself in the middle of nowhere. My suggestion for both people across the border is to learn the technology and implement it for the betterment of the society and involve yourself in construction instead of destruction. Learn hacking but make sure that defacement is not hacking.

Now what do you say? Use the comment box.

~ dimanche 29 mars 2015 0 commentaires

'AntiDetect' tool only way to Cashout from a Stolen Credit Cards

All the Banks around the world are now moving towards the embedded chip technology in their credit and debit cards to avoid any fraudulent activities from thieves and hackers. All the banks in U.S and Europe are already switch to this technology now hackers are using tools like AntiDetect and FraudFox to cashout from stolen cards. These tools doesn't only fools the e-commerce sites that they are not criminals but also hides their digital fingerprints because of it those sites have no track of them.



All the browsers has their own digital fingerprints which was initially designed for banks to prevent fraud. The users fingerprint detects all the information of users browser from his operating system to the plug-ins installed in his browser plus his time-zone. Banks can leverage fingerprinting to flag transactions that occur from a browser the bank has never seen associated with a customer’s account.


E-commerce sites and merchant accounts (payment service providers) use this technology to block any transaction if  it is previously linked with unauthorized sales or fraudulent activities. Earlier this year the story came from various media outlets that how FraudFox, is helping the hackers to cheat the browsers fingerprints and remain anonymous. But FraudFox just a new entry in an established market which is lead by AntiDetect which is helping thieves to cashout from stolen Credit cards from online merchants.

AntiDetect tool is in this market for a long time now and also the market leader. The latest version of this tool is 6.0.0.1 which not only enables the criminals to fool browsers like Mozila, IE, Chrome, Safari etc but also enables them to easily change the components of their system to avoid fingerprinting.

Using AntiDetect is not only easy but its highly successful among the underground hacker forums because it will keep changing your Version of browser, Adobe version, plug-ins installed in your browser,Language, Operating system type and your timezone. This will make it impossible for the online merchant to stop you shopping from e-commerce site or cashing out from the stolen credit card.

I think it’s safe to say we can expect to see more complex anti-fingerprinting tools come on the cyber-criminal market as fewer banks in the United States issue chipless cards. There is also no question that card-not-present fraud will spike as more banks in the US issue chipped cards; this same increase in card-not-present fraud has occurred in virtually every country that made the chip card transition, including Australia, Canada, France and the United Kingdom. The only question is: Are online merchants ready for the coming e-commerce fraud wave?

~ mardi 17 mars 2015 0 commentaires

FREAK: Another bug that Threaten the World

FREAK is the latest encryption bug discovered by a team of security researchers. This bug will put the users secure web connection at risk and also exposes the users sensitive information. Previously it was thought that this bug was only limited to the Apple and Google browsers but the latest revelations suggest that flaw leaves communication between affected users and websites open to interception on almost every platform..




Microsoft, Google, Apple and all other companies are working on their patches to overcome this bug named as FREAK.  But it is still days away. The Question is How the user can protect himself in the mean time? The Answer of this Question is simple. User should avoid those platforms that are more Vulnerable to this bug. The next thing you should do is to avoid those websites that are Vulnerable to this bug named FREAK.

What is FREAK and How can you tackle this bug?

The FREAK flaw affects SSL/TLS, the protocol that creates a secure connection between you and a website. The secure connection is created when you connect with HTTPS and have a padlock in your browser address bar. That “lock” means that your personal data is encrypted when it’s sent to the website.

This Freak flaw has affected some major browsers like:
  • Internet Explorer - Windows
  • Safari                    - Mac OS / iOS
  • Chrome                - Mac OS / Android
  • Opera                   - Mac OS / LINUX
  • Stock Browser     - Blackberry / Android
The only browser which the security team believes is not Vulnerable to all operating systems including Android and iOS mobile devices and tablets is Mozila Firefox.  All users should install Mozila in their devices to tackle this FREAK bug until their Operating systems came up with patches which will take probably few days.

Sites that are Vulnerable to FREAK

The list of sites that are vulnerable to this bug is endless. Even sites that are on HTTPS are not secure from this bug. The list of sites include retail to government and lots of things in between. Some of the highest-traffic domains that are affected include Business Insider, American Express, Groupon, Bloomberg, NPR, Kohls, and MIT. A number of very high-profile government sites were also affected, including the NSA, the FBI, and the White House’s sites, as well as the site (USA-Jobs) that all applicants for any federal job must use.

Recommended Steps 

Update with all patches when available 

Microsoft, Apple, and Google will all be releasing patches within the next few days, so it’s critical to update your system when those patches are available.

Use Firefox to browse securely 

Until patches are available for the above affected browsers, you may want to use Firefox on iOS, Android, and Mac OS to securely browse the web and connect to your online accounts.

Replace vulnerable passwords 

Though it’s unlikely that you were attacked, as devices and websites are patched it may be a good time to change the passwords to any accounts accessed on any of your devices shown to be vulnerable. You can also use the LastPass Security Challenge to review the strength of your passwords. Our Auto-Password Change feature will also help you replace passwords automatically. It’s important to use a different, strong password on every website, so that a password stolen from one website can’t be used to login to any of your other accounts.


~ lundi 9 mars 2015 0 commentaires

The Theory of Every Hacking Attack

Nobody can hack you without your permission”

Sometimes it is very hard to transfer your feelings and thoughts into words, especially if you are trying to say something about someone’s privacy and security. It is not an easy job to handle a situation when your friend, client or loved one got hacked, but you have to manage it; you have to take some steps to reduce the loss as much as you can. Why we always think about the techniques to be implemented after getting hacked, why not do something that prevents hacking attacks? Why not find the problem that ended as hacking attack?

Every hacking Attack

The answer of all of these questions is hidden within yourself, you at the very first sight are responsible to manage and secure your assets (privacy, passwords and etc). Nobody can hack you without your permission does not mean that hacker needs your written approval prior hacking attack. But in true sense it means that, you intentionally or unintentionally give opportunity to a hacker to exploit your security. So you are the one who is responsible and answerable for your own security and privacy, Government, your ISP and even your vendor have limited resources while managing your security. But you got all the resources.

Let's consider an example, I witness that many organizations are reluctant to upgrade their systems and processes that prevents the hacking attack; most of the time they care about saving or they simply don't care the security of their data. And the result is breached, data stolen; now tell me who is responsible? Is it the network administrator who gave several proposal to upgrade the system but you did not release the fund. So who is responsible?

The theory of every hacking attack is: “Nobody can hack you without your permission” or “Your security is directly proportional to your willingness to stay secure

It’s time to take some serious steps to strengthen your security and you should care about it because it’s all about your data. Being related with Infosec industry, you should also spread the information, knowledge and awareness so that a common user can take some steps to stay secure.

It's our job to spread the theory of every hacking attack.

~ mercredi 4 mars 2015 0 commentaires

Security Researchers from India, Egypt,U.S and U.K benefited most from Facebook Bug Bounty Program

The social networking giant has paid around $1.3M in 2014 as part of its bug bounty program. Even though the numbers are down from the year 2013 when the company paid around $1.5M in rewards to different security researchers. The average reward of bounties in year 2014 according to the Facebook is $1,788.



The concept of the program was to encourage the white hat hackers to find the vulnerabilities in the social networking site so the company can fix it before some blackhat takes advantage of that vulnerability. The total number of countries who are reporting the bugs on social networking giant is 123. Top 5 countries by volume whose researchers came forward and report the vulnerabilities on the social networking site include India, Egypt, U.S, U.K and Philippines.



 India

With around total number of 196 bugs Indian security researchers tops the list just like in 2013. Indian researchers collected the average prize money of around $1,343.  

Egypt

Surprisingly the second country by Volume of bugs reported to the Facebook is Egypt. Egypt security researchers reported around 81 bugs which is a far lesser number when you compare them with the Indian researchers. The average prize money that Egyptian security researchers collected is around $ 1,220. 

 U.S

The third on the list is United States who researchers earned around the average of $2,470 from the 61 bugs that they reported. 

U.K

The security researchers from U.K also took full advantage of this bug bounty program by Facebook and reported 28 Bugs and earned the most averaged money from all countries $2,768. It is clear that Facebook bounty program benefited the most to U.K security researchers who collected the biggest sums of prize money.

Philippines 

The fifth on the top 5 list is Philippines from where around 27 bugs are reported and the average award that Philippines security researchers collected is $1,093. 

Facebook thinks they are going towards the right direction with this security strategy. Already around 100 new bugs are reported and fixed by the social networking sites this year.  Another positive point is this that the researchers are now finding bigger and better bugs that before. Which keeps making Facebook more secure than ever.

~ mardi 3 mars 2015 0 commentaires

Most Influential Women in Infosec Around The Globe

Infosec (Information security) is a field dominated by the men around the world. A rough idea is only 10 to 15 percent Female infosec are active in the world right now. Here we screened out some of the Top females from the field of Information security and rank them according to their skills in the world of Infosec.


Jennifer Leggio




At the top of our list is Jennifer Leggio, she is from Austin,Texas. She is the worlds most known Infosec women right now. She worked with ZDNET and Forbes tech contributor. She is a hockey lover. 

Runa A. Sandvik




The second on the list is Runa A. Sandvik a well known Computer and Network security analyst. She completed her education from Norwegian University of Science and Technology. Right now she is the technical advisor at Freedom of Press Foundation, Forbes and TrueCrypr Audit project.She lives in Washington DC, from where she share all the security and privacy researches with her twitter followers.

 Erin Jacobs (SecBarbie)    


SecBarbie got the third spot in the most influential women in Infosec in the world right now. 'SecBarbie' is basically the social media name, and the name by which 'Erin Jacobs' is known in the world of Infosec. She is the partner at Urbane Security and lives in Chicago, USA. After founding the Urban Security Erin Jacobs Spend most of the past 10 years concentrating on the operations of mid-sized global businesses and their unique security and technology needs.

Katie Moussouris


Katie Moussouris is an Ex-Hacker and its pretty unique thing how she entered the Infosec industry.  Right now she is the Chief Policy Officer at HackerOne. Prior to her assosiation with Hackerone.com she worked at Microsoft and Symantec, where her work encompassed industry-leading initiatives, such as Microsoft's bounty programs, BlueHat conference content chair, security researcher outreach, Vulnerability Disclosure Policies and MSVR (Microsoft Vulnerability Research). She also founded Symantec Vulnerability Research (SVR). She now serves as a subject matter expert for the U.S. She is one of the well known women in the infosec industry who now works as a security researcher to make internet safer for the world.

Elinor Mills


Another influential women in the infosec industry is Elinor Mills. She lives in San Francisco Vice President of Content and Media Strategy for Bateman Group. She was previously associated with the CNET with work on Internet Security and Privacy she made her name in the industry. Because of her outstanding work in the field of Information Security she gained the no.5 spot in our list.

Aloria 


Aloria is the Tumblr security engineer got the 6th spot. She is from Brooklyn and she provides her followers all the tips of how to be secure on the internet. She is ambitious and talented. We wont be surprised if she claimed in the ranking in the coming years. 

Jennifer Minella


Another well known women in the world of Infosec Jennifer Minella grabbed the 7th spot in our list. Perhaps one of the most beautiful Infosec in the world right now Jennifer Minella is the former Ballroom Dance. Now she is the VP of of Engineering & consulting CISO at Carolina Advanced Digital. She completed her education from North Carolina State University in computer and network security. She also write on Enterprise network security on Searchsecurity.com

Georgia Weidman


Georgia Weidman is from Austin,Texas and the founder of Bulb Security. Prior to this she worked as an Security analyst in the companies like IBM, Gemini Security Solution, Neohapsis. She completed her education in Computer and network security from James Madison University. She provides security trainings, services and solution on Bulb Security. She is one of the well known name in the industry right now.

Cheri Sigmon 


Cheri Sigmon is one of the top infosec in the industry right now. Cheri's profile speaks for herself. She is the Senior Cyber security Manager at A Federal Agency. She is also the member of The National Association of Professional Women, NAPW. Cheri completed her education from Webster University. She also looks after the Cyber security of various departments of U.S Government. 


 


~ jeudi 22 janvier 2015 0 commentaires