Affichage des articles dont le libellé est Random. Afficher tous les articles
Affichage des articles dont le libellé est Random. Afficher tous les articles

The Ultimate Guide to Security Threats

Internet security expert McAfee is helping everyday web users to get up to speed with the threats they face online with a new tool.

The firm has launched The Ultimate Guide To Security Threats in a bid to raise awareness of the common dangers that lurk within the realms of the world wide web.

The guide, embedded below, offers an at-a-glance resource for users to bookmark and understand viruses, spam, spoofing, phishing, Trojan horses, botnets, worms, spyware and DDos attacks.

It also looks at a timeline of high profile recent hacks, demonstrating the scale and severity of the security risk – as well as the increasing sophistication and ambition displayed by cyber criminals.

Brought to you by McAfee - Intel Security

~ lundi 16 mai 2016 0 commentaires

Your Prime account isn’t enough: the security you need for Amazon Web Services

There is almost nothing Amazon can’t do for you. It can instantly deliver a book to your tablet, ship you everything from a whisk to a wheelbarrow overnight, and not only stream TV shows and movies, but produce them. It was no surprise then that when Amazon got into the web services game they did so in a major way, offering scalable and cost-effective cloud computing that quickly sky-rocketed in popularity, earning the number one position in cloud computing and showing no signs of relinquishing the crown. However, as good as Amazon Web Services (AWS) are, they are by no means a complete computing solution. At least when it comes to security.

What AWS can do for you

Amazon Web Services is free to join, and as it is a cloud computing model, you only pay for what you use. AWS offers everything from website hosting solutions, data management, storage solutions, digital media services, software development kits all the way to business applications. Essentially, with everything AWS offers, it eliminates the need for on-premise IT infrastructure.
Businesses ranging from small and medium-sized businesses to major enterprises are moving their IT infrastructure to AWS in order to spend less time managing infrastructure and more time focusing on things like product development, sales and customer service. Fashion retailer Nordstrom, for example, has shifted its websites, mobile apps and other internal IT tools to AWS, while cereal brand Kellogg’s has replaced its on-premise relational database for data analysis with a faster, more powerful and more cost-effective setup on AWS.
But what about security?

What AWS can’t do for you?

With so many businesses and major corporations relying on AWS to that extent, of course Amazon offers built-in security for their cloud computing services, securing the infrastructure. This includes having highly secure data centers, ensuring client privacy and segregation, having network and security monitoring systems, and offering security features such as firewalls, encrypted data storage, and a dedicated connection option.
While these security features are valuable, they may not provide all of the protection required by your business. The built-in AWS firewall does not manage either inbound or outbound traffic as well as a more traditional firewall, and the policies that can be set in the AWS firewall simply aren’t as complex or as rigorous as needed for many businesses.
Further, while AWS pulls some of the security load, your business is by default expected to do its part as well. AWS secures the infrastructure, and your business is expected to secure everything you run on or put into the AWS infrastructure. This includes things like server side encryption and network traffic protection. Another thing to consider is that while AWS infrastructure security is, of course, good, it isn’t fool-proof. In the past AWS computing services have been exploited in order to launch large-scale DDoS attacks. Additional security is never going to be a bad thing.
But since you’ve probably either moved to cloud computing or are considering a move to cloud computing because it can make your IT so much simpler, it stands to reason that there are easy ways to achieve excellent AWS security.
Eventually, it’s a Jungle out there (shutterstock)

Why yes, Amazon has a Marketplace for that
AWS Marketplace is an online store chock full of software and services that can be instantly purchased and put into use in the cloud. This includes developer tools, ecommerce solutions and other business necessities, and it also includes leading security solutions that can provide your cloud computing environment with tight, enterprise-level security.
Some of the premier security solutions designed specifically for AWS include products such as Incapsula’s Web Application Firewall and DDoS protection. The Web Application Firewall, or WAF, picks up where AWS’s firewall leaves off, setting strict rules for how visitors are allowed to interact with your website and other online services, thereby defending your AWS-hosted applications from any hacking attempts as well as bots and malware.
DDoS protection protects your business from not just the outages that can be caused by DDoS attacks, but the intrusion attempts, damage to hardware and software, and theft of data and intellectual property that so often go along with DDoS attacks.
Helping Amazon round out their offerings
Amazon generally doesn’t need any help taking over the world with its various ventures, but security is the one area where Amazon Web Services could use a little assistance, and investing in this additional security is absolutely necessary for the protection of your business. If your business is already in the cloud, or you’re thinking of moving to it, keep those few Amazon shortcomings in mind.


~ mardi 22 septembre 2015 0 commentaires

Most Famous Hackers of all Time

The hacking now a days became a very cool career in the eyes of the young generation. With the biggest companies like Sony, JP Morgan, Yahoo, CNN. NewYork Times, Ebay all hacked in the past even with their millions of dollars investment on securing their Websites. The Hackers in the peoples eyes are the most coolest persons on the planet.

There are two type of Hackers, first are Black Hat and the second are White Hat hackers. The Black Hat hackers are known for the utilization of the skills for the bad purposes, also dubbed as Cyber Criminals. While the White Hat hackers are known for the utilization of skills for good purposes.These hackers test the companies to test the integrity of their systems. They are also known as Ethical Hackers

Here were look at some of the most talented and famous hackers that the world has ever seen. We ranked them according to their skills and talent.

1. Jonathan James






Jonathan James came into light when he became the first juvenile to be sent to jail for Cyber Crimes. Jonathan was born on 12 dec 1983 and died at the age of only 24 in 2008. Jonathan was first arrested at the young age of 15. When he was sentenced for his crime his age was only 16. He committed many serious cyber crimes in year 1999 but his most famous one is on Defense Threat Reduction Agency, when he installed a backdoor in the agency's server.

Defense Threat Reduction Agency comes under the U.S defense department it analyzes the threats that the country could face from inside and outside. Jonathan seen very confidential documents through the backdoor he installed in the server of  Defense Threat Reduction Agency.
James other major cyber crime include the NASA hack, He hacked in the NASA systems and stole the software worth around $1.7 Million. That forces NASA to shut down its operations and systems ultimately raking up a $41000 cost. James is the pioneer of Hacking in the U.S he was naturally gifted and god knows if he had chosen the right path maybe he could end up like some great geniuses world has ever seen.

2. Adrian Lamo



Adrian is known for his security breaches of well known organizations like Microsoft and New York Times. He was born on 20 Feb 1981. Because of his tactics of using internet connections of Libraries, coffee shops and other restaurants he is dubbed as the "Homeless Hacker".

Lamo's intrusions consisted mainly of penetration testing, in which he found flaws in security, exploited them and then informed companies of their shortcomings. Citigroup, Bank of America, Yahoo are among the high profile organizations that suffered the hit of Adrian attacks.

When Adrian Lamo hacked the New York Times server things get serious because he viewed the personal information on contributors. Because of this he was fined $65000 approximately and sentenced 6 months of home containment. He also spend the 2 years from sentence on payroll. Whatever you say about this guy he is definitely one of the most talented Hackers alive today. 

3. Gary McKinnon




Gary McKinnon is an Scottish national born in 10 Feb 1966. In 2002 Gary McKinnon was accused of the biggest military hack of all time. An message appear on the screens of the US Army computers that says 'your security system is a crap' and it further read 'I am Solo. I will continue to disrupt at the highest levels'. The authorities later find out that this is the work of an Scottish system administrator name Gary McKinnon.

 Gary McKinnon is accused of hacking into US systems and NASA computers while using his cyber criminal name 'Solo'. He was performing the cyber crimes from his girlfriends aunt's network from her home. These activities took place from 2001 to 2002. He was questioned by various countries authorities after his attacks and his computer was detained.  Since then he is appearing in courts to defend himself till 2012.

4. George Hotz



George Hotz is an American who was born in 2nd Oct 1989. He was known for unlocking the iPhone's so the other carriers can be used in them around the world. He is the one who developed the jailbreak tool and bootroom exploits on Apple's iOS. But when he jailbreak the Sony PlayStation 3 he gained everyone's attention, that resulted in company suing him. In a stated retaliation to Sony’s gap of the unstated rules of jail breaking – never prosecute – the hacker group Anonymous attacked Sony in what would be the dubbed as the most costly security break of all time to date. Hotz deny any connection with this attack.

5. Michael Calce



Michael Calce also known as Mafia boy has taken down some biggest commercial sites such as Fifa.com, Yahoo, Amazon,Dell, eBay,CNN. All these sites had been taken down in year 2000. At that time Yahoo was still the world largest search engine and because of his attack the site is shut down for around an hour. Calce a.k.a Mafia Boy took down these sites to establish the dominance of his Cyber group (TNT) and also for his own accomplishment. Calce was arrested for his attacks and sentenced 8 months in open custody and a year on probation. Calce was also had a restricted use of internet according to the courts orders. He is one of the most dangerous hackers that the world had seen in the last decade.


~ mardi 13 janvier 2015 0 commentaires

10 Biggest Hacking Attacks of 2014

It is very difficult to decide whether it was the biggest hacking attack or the worst hacking attack that created a sense of insecurity in the mind of common users, 2014 is about to end (well happy new year and holidays) and the echo of the hacking attack carried out in this year, will be listened in the next year or may be in many years after.

2014 was the year of cyber criminals and hackers, their unstoppable hacking attack has shocked the world's population; from corporate sectors to the famous celebrities; everyone seems to be their target. While writing this article, I am still thinking to rearrange the list of hacking attacks because every attack was a disaster and it is not an easy job to give them a rank.

  1. Heartbleed Bug

Heartbleed was not an actual hacking attack but heartbleed is a bug/vulnerability in the popular OpenSSL software that led many hackers to exploit the servers. Heatbleed was the serious security threat even six months after of its discovery. One the POC of heartbleed is that the hackers exploited it to steal4.5 Million patient records; Community Health Systems, the renowned hospital operator in U.S was the victim of this hacking attack.
  1. Shellshock

ShellShock vulnerability was bigger than HeartBleed Bug. It was affecting Linux and Mac OS X, Shellshock was targeting the kind of machine that runs most of the servers around the globe. Hackers created their botnet that exploited the shellshock vulnerability, some of the famous target was:
  • Akamai
  • United States Department of Defense
  • NAS (network attached storage system)
  1. Neiman Marcus Hack

More than 1.1 million customers were affected in the hack of high-end retailer Neiman Marcus. The sophisticated, self-concealing malware was "clandestinely" installed on the department store operator's system. The software then actively tried to collect or "scrape" payment card data from July 16 to Oct. 30, the company explained.
  1. Ebay

In May, eBay revealed that hackers had managed to steal personal records of 233 million users. The hack took place between February and March, with usernames, passwords, phone numbers and physical addresses compromised. The notorious Syrian Electronic Army had claimed the responsibility of this attack but Ebay or any other authentic source did not confirm it.

  1. South Korea Credit card hack

South Korea credit card hack was the nightmare for the infosec security professionals. Credit card details from almost half of all South Koreans have been stolen and sold to marketing firms. The data was stolen by a computer contractor working for a company called the Korea Credit Bureau that produces credit scores. 20 million South Koreans or 40% of the country's population was the victim of this attack.

  1. Home Depot

The payment system of one of the largest home improvement retailer was hacked, the corporation said that the hacking attack was bigger than the one that struck Target Corp. last year. In addition to the 56 million credit-card accounts that were compromised, Home Depot said around 53 million customer email addresses were stolen as well.

  1. JPMorgan credit card hack


The JPMorgan Chase & Co breach is being called the worst known compromise in history, affecting approximately 76 million households and 7 million small businesses. Contact information, including name, address, phone number and e-mail address, as well as internal JPMorgan Chase information about the users, was compromised.

  1. iCloud Hacks - Celebrities Photos

This is one of the famous hacking attack where hackers have posted the nude pictures of celebrities on the Internet. The privacy of many celebrities were invaded when a hacker obtained personal photographs from various digital devices, and began spreading them across the Internet, all the photographs were stolen from iCloud. Apple said it was a targeted attack and none of the cases they have investigated has resulted from any breach in any of Apple's systems including iCloud(R) or Find my iPhone.

  1. Sony hacks

On November 24, 2014, personally identifiable information about Sony Pictures Entertainment (SPE) employees and their dependents, e-mails between employees, information about executive salaries at the company, copies of unreleased Sony films, and other information, was obtained and released by a hacker group going under the moniker "Guardians of Peace" or "GOP".


  1. Regin

On November, Symantec has discovery piece of software called Regin, which it had found lurking on computers and stealing data in Ireland, Russia, Saudi Arabia and several other countries. Regin may have been created by Western state to spy on governments, it can steal password, take snapshot and even recover the deleted files. Researcher claimed that Regin is more advanced than Stuxnet, which was developed by US and Israel government hackers in 2010 to target the Iranian nuclear programme. The European Union and a Belgian telecommunications company were also the target of Regin.

Cybercrime and hacking attack have reached new heights. At the end of 2014, we should start working to create security awareness in order to prevent the hacking attacks in future. We need more advance protection system and the training to think smarter than hackers; yes we can do this because this is the only option that we have.


~ lundi 29 décembre 2014 0 commentaires

Internet Security can Sacrifice with Typo squatting

It a common thing that people make mistakes while typing an internet address on their web browser. This can happen even with the good typists that they miss or type the wrong character. Most of us would just correct their mistake immediately without realizing that the mistake made any difference. However, very few of us are aware that even such a small mistake can cause harm to our internet security. It usually happens when you mistype the name of a popular website because cyber criminals and hackers are looking for new opportunities to make easy money.




You will realize your typing mistake when a malicious website will open in your browser instead of the website you want. Once you have landed on a malicious website, it will trick you to download malicious software. You may also get trapped to share your personal or financial information. Thus, it helps cyber criminals to take advantage of your typing mistake by setting up fake websites.

Definition of Typo squatting

Typo squatting is the fraudulent web practice of the cyber criminals and hackers. This web practice is illegal and is also known as URL squatting or domain. Many countries including the US have a law against this form of cyber squatting. Basically, cyber squatting is to use or register the name of an existing website and take profit from the trademark belonging to someone else.

The third parties behind this form of fraudulent web practice are typically known as cyber squatters. They register versions with wrong spellings of a popular web address that coincide with the common typing mistakes made by the internet users. Therefore, if you make a typing mistake similar to any of those versions, then your browser will direct you to the malicious site. It may compromise your internet security. It has happened with popular web addresses with the misspelled words including Wikipedia as wikapedia, Twitter as twtter, Google as goole, Craiglist as craigilist, Apple as pple and more.

Aim of Typo squatters

The main aim of typo squatters is to compete for web traffic with the popular websites and earn easy money through their advertisements. The targeted companies become the real victims without your internet security at risk. They may trick you into downloading some type of malware or spyware or get hold of your personal information in return for fake appealing deals. Even with no intention of visiting unethical sites, they can direct you to dating or adult sites.  

Avoid Risks of Typo squatting

Primarily, you should be careful when typing a web address in your web browser. Every person in your family should know this because an infected computer can compromise the internet security of the whole family. If you are not sure of the correct spelling of a website, then use a trusted search engine, such as Google or Yahoo, instead of directly typing in your browser. Protect your computer and system from viruses, phishing attempts, malware and spyware by getting a comprehensive suite for internet security.


Article is written by Gloria and she recommends internent security 2013 test for your laptop and computers.



Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ mercredi 31 juillet 2013 0 commentaires

Buy And Download Legal Music At Iomoio.Com

With the increasing demand of download sites, a number of illegal sites have come up. Let me introduce you to a decent mp3 download site, www.iomoio.comThis is one of the best online music store where you can download your music at the best term and price. You can download mp3 songs by following these steps. The first step towards having memorable online experiences is through creating a user account by signing up at the website. Once you have signed up, the website offers two complimentary music tracks. Their charges are as low as 50 cents; this is cheap as compared to other such service providers.



Apart from the cheap mp3 downloads the website also gives discounts and bonuses when you buy music from them. The is an additional bonus of 16 dollars when you buy music worth 32 dollars or more. There is also one hundred percent discount offered on music purchased worth ninety-six dollars or more. The iomoi.com interface takes into account usability and it the interface is easy to use and navigate. They offer good services by giving a 60 seconds preview of the music, so that you can listen to it before buying the mp3 songs.

Iomio.com is one of the very few sites that offer free ringtones for any song purchased. The interface also boasts predictive search, which is on the spot most of the times though some tracks may be delivered incorrectly. Another key point that sets iomio.com at the top is its very rich database of songs with about 1.5 million tracks in its index. To facilitate navigation, the music is divided into a number of categories. Moreover, for recoverability, the downloaded track is saved as a back up in your account, and it can be re-downloaded.

All the payments are done via a secure network, and all major credit and debit cards are accepted. The music track can be downloaded at a rate of 196kbps. I recommend iomio.com to those interested in buying all the best selling albums and legal music.


Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ mardi 9 avril 2013 0 commentaires

Get The Best Dedicated Server Hosting With Serverclub.com


Are you looking for a server hosting company? Then look no further. Serverclub.comCompany is there for you by offering dedicated server hostingservices at the best terms and prices. Server club is there to reduce on errors many people make by designing a website and forget an important and critical service, Hosting. No user wants a slow loading site; people love interactive websites that give quick responses.




At present, every business is run via the internet. Businesses are very busy creating brand and a global market through social media and other platforms over the internet. They want to grab a wider market and this has led to the increasing demands and plans for hosting. There are a number of companies that have come up to offer hosting services. However, if someone is looking for affordable hostingservices, you should consider Server club because of their unlimited hostingservices and quality software and hardware support 24/7. Linux dedicated servers can make the back bone of a highly traffic online business.

A dedicated web server gives a better loading speed with better security. A site that has high speed depends largely on how the best hosting is done. Therefore, if a business has a website with frequent visitors then you should go for shared hosting. I recommend Server club because of their user support services. They have engineers who help a client perform the initial free software installation and server set up at any time. They also include free reboot panels for servers, which are designed for viewing statistics, bandwidth usage, invoice payments and system support ticketing.

Server Club Company is located at Evoswith data center in Amsterdam. They are of the most advanced hosting providers with experienced professionals. If you are ready to move to a new level in your online business, by having a high performing site or blog, consider Server club today.



Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ lundi 8 avril 2013 0 commentaires

Download Of All Your Mobile Apps Free With General Play


In this era and age of technological advancement in the mobile industry, people are using their phones to access the internet, play games, listen to music and watch videos, which is why General-play.com an app service provider has sifted a huge stack of apps to find the best one for every phone. The site also allows a Smartphone user to download free android apps with much ease. www.general-play.comis platform independent and incorporates the all options for iPhone, iPad, iPod, Android and applications for windows phone windows devices.



The latest advancements in the mobile technology have seen the smartphone industry booming and people everywhere love this portable devices because they are more convenient as compared to laptops. A smart phone has an all-in one feature and is built on a mobile operating system, which utilize mobile appsand general-play offers. An individual can search for apps and play games of his or her choice, and all are available in this website. As compared to other sites, their user-friendly interface and easy navigation is ideal, and one is assured to get what he or she wants for each device, regardless of whether it is an iOs, Android or Blackberry device.


It is now four years since this website was launched and has now acquired a niche in the mobile world. I would recommend General-play.com to any person, who loves to enjoy the latest games and apps through his/her mobile phone. This is also because general-play.com has developed to be one of the most known search engine especially, for content specified for mobile devices. Its advanced search engine helps one to search through various search contents and app markets at one time. Therefore, if you want free mobile apps and games or if you want to be kept informed on trends in the app or mobile market, then this is the right and most convenient place to be.


Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ 0 commentaires

Get Free Website Services Today With Ucoz.Com

In this digital age and era, one of the most effective avenues of disseminating information, is through websites. To have a global presence, create your own website today with www.ucoz.com and enjoy the advantages of having a virtual presence. The need of having a website takes the advantage of people worldwide, who have access to the internet. Therefore, create your website in minutes with just few clicks via ucoz's free site builder, which has a unique user-friendly interface.

For your information, no coding is required in building a website, which is interactive and incorporates all the multimedia elements like images, videos and flash images. Design your website in minutes, by first creating your own login account, then choose a design from the Html and flash templates that suit your taste. The designs are colorful and there are hundreds of layouts to choose from. Customize your template with ease taking into account the web design principles. Flexibility is ensured and you can Change and edit anything with the easy drag and drop tools.

With 7 years' experience in web design, Ucoz offers you an opportunity of having a website that fits both the individual and business needs. Ucoz enjoys an average of one million active websites and one hundred million website views per day. With the data backup features of their website, recover-ability is ensured. Ucoz also offers free webhosting and unlimited space hosting with a free built in content management system. Their web hosting service supports ads and some ads and banners are more likely to appear on your website or on the control pane.

Unlike other website creation service providers, Ucoz allows you to use your own domain name as your website address and if you do not have your own domain name, you can get a free domain name containing ucoz.com. Consider creating your own tailor-made website that will meet your needs with ucoz.com.





Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ samedi 6 avril 2013 0 commentaires

How To Use Cloud Computing

The Cloud is meant to be user friendly and not at all complex, but some people are still confused about the Cloud. In the near future many are saying The Cloud may become one of the largest websites on today's market. And, coincidentally, The Cloud is very user friendly.





Who Should Use The Cloud?

Anyone and everyone can take advantage of The Cloud. Individual persons and businesses, large, small, corporations, you name it and The Cloud is for everyone who uses a computer who wants better security, at cost effective prices.

Benefits Gained for the Cloud Software

Anything that you set on your cloud is downloaded off site. If you must send your portable devices for repair or it crashes, you can access all your valuable information off your cloud, stored off site. The Cloud can be used on your desktop or laptop, but at this time it is not too user friendly, in this respect, unless it turns into a browser and many feel that The Cloud is heading in that direction. The Cloud is at this time used for tablets and iPhones. When you set all of your valuable information on your Cloud it is security protected and you never have to worry about someone else gaining your information. You can use your iPhone, laptop, desktop and Droid to access your Cloud and always have your information under one umbrella.

You no longer will have to secure and protect each piece of information as The Cloud does this automatically for you. You can add information when you need. When you are on The Cloud, it will automatically update information for you. Your pass word can be given to anyone you wish to have it. You and they can access this information from anywhere on any device.

The Cloud is very inexpensive and cost effective, because gone are the days of purchasing high cost software. If you are a small mom and pop business owner, and use a computer you will now have all of the unlimited use of tools to help you in your business. Big corporations are jumping on The Cloud, and you will have all of the same advantage of using the tools they use that helps their business prosper. There are an unlimited number of tools available for you to grab a hold of and use.

The Cloud is like the center of a big wheel, sitting protected under an umbrella, that is ready to grab up any number of spokes in that wheel to use until you decide you have no need for it, and you just put the spoke back. The monthly charges are so low that there should be no reason for every person to not grab a Cloud and sit there.

How Does Someone Set Up Their Cloud?

The first thing to do is to select a hosting service, such as Amazon Web Services, and set up a virtual computer. Amazon was the first to offer Cloud computing to the public, about 2006. According to Amazon, within this virtual computer you will have to set up your security, firewall and settings to login, your hard drive and so forth. Then being done, you will access the prompts when given by the hosting platform. There may be other tools that you will want to grab up and install. According to Amazon, your login capabilities are set in place to access your own Cloud.

This How To Guide for Cloud Computing is from www.trainace.com, a leading computer training company out of Maryland who offers nationwide IT Certification.


Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ lundi 1 avril 2013 0 commentaires

Web Vulnerability Scanner

Website security breaches are now a common problem, hackers are targeting thousands of website daily to achieve their malicious purpose. Website security is a common concern for both web-master and the user of this website, after the security breaches the web-master and user both suffers. It is actually a big issue to handle the security breaches, nobody want their website to be hacked. So everybody want to protect their website and the user also want the protection of their important information which store in the database of website, but question is how?


The answer is,

“You can protect your website by implementing secure code, security policies and by fixing the vulnerabilities”

Automatic web vulnerability scanner tools are very useful to find the vulnerability on a website, but which software is useful in what condition ? This is the question and I want you to give the answer.

Best Web Vulnerability Scanner


I have previously created list of best 6 vulnerability scanner tools, but so many people have asked about their favorite tool which actually was not there. So I am introducing a new section of ehacking here to get user input and maintain the list of best information security tools. At the start of this section we are going to create the list of web vulnerability scanner tool.



How Can I Give my Input ?

Well, the easiest way to give your input is by commenting at the end of this blog post, we are actually asking the same question of our social media channels too but it is highly recommended that you give your input by commenting here.

The list would be contain top 10 scanners from both the house of open source community and commercial edition, so kindly make your comment in the pattern like:

Vega vulnerability scanner
Netsparker web security scanner
Nikto
.
.
.
.
and so on

If you are on Facebook (I am sure you have your profile there) than you can participate on poll and make sure to invite your friends so that we will be able to create the best list ever.


I am looking forward to get your input.



Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ mardi 26 mars 2013 0 commentaires

Mitigating Inherent Security Risks Of Software Of Unknown Pedigree (SOUP)

Assuming that third-party suppliers are taking sufficient security precautions is a risky assumption. In actuality, the majority of externally developed software applications fail to comply with existing enterprise security policies upon first submission. As many as eight out of ten initial submissions will fail initial compliance audits. As SOUP is increasingly utilized among today’s enterprises, precautions such as vendor application security testing are an integral part of effective security.




Software developers build upon previous work and open-source code

Many of today’s developers make use of previously developed work that can be defined as SOUP. It’s more efficient to combine open-source, commercial software and previous code, adding new code and creative work to create the features and functionality needed to speed up development time and lower costs.
But when you’re using externally developed applications, especially a combination of software from multiple vendors, it’s difficult to know exactly what’s in the code. It’s important to be aware of the rules and licenses surrounding permitted use and alteration of third-party software, as well as have a thorough understanding of what’s in the code base.

Enterprises used to rely heavily on provenance

The main problem with SOUP—and one of the primary reasons some companies have been hesitant to utilize it--is that it can introduce security vulnerabilities. The Office of the Director of National Intelligence released a report in 2011, Securely Taking on New Executable Software of Uncertain Provenance (STONESOUP), outlining necessary steps for successfully incorporating SOUP while minimizing increasing inherent security risks across an existing software infrastructure.

Most software vulnerabilities originate in a program’s source or object code. But without using vendor application security testing, enterprises rely primarily on provenance to determine the validity and security reliability of third-party applications:
  • Software that comes from a trusted company.
  • Software developed using established and proven processes.
  • Software developed by vendors with which the enterprise has a solid relationship.
While provenance provides a basis for determining which programs to consider, it fails to provide an adequate assessment of the true security of an application. Third-party developers, even if they conduct thorough application testing before releasing a product to customers, can miss inherent vulnerabilities as well as those that wouldn’t pass an enterprise’s strict security protocols. Using vendor application security testing is necessary to reduce the potential vulnerabilities introduced by SOUP and ensure that third-party applications meet at least the minimum security rules set forth by your enterprise.

Cross-site scripting and other vulnerabilities reduced through adequate security measures

About two-thirds of government applications have cross-site scripting (XSS) vulnerabilities, one of the major security risks with both third-party and internally developed applications today. Cross-site scripting allows hackers to insert malicious code through a web page, making it possible to obtain login credentials, financial information and other otherwise secured data—and once the initial data is obtained, sophisticated cybercriminals can use a single piece of information to gain access to vast amounts of an individual’s or enterprise’s proprietary data.

While XSS is just one example of the security risks associated with SOUP, XSS and other vulnerabilities can be reduced using vendor application security testing. Even if your company doesn’t have a full understanding of the source code used in third-party applications, vendor application security testing can analyze these applications against your enterprise’s existing security rules and protocols.

Eliminating the use of SOUP altogether is one way to avoid introducing inherent security risks and vulnerabilities that could be disastrous for an enterprise. But companies who want to continue to capitalize on reduced development costs and faster time-to-market by using SOUP see an increase in compliance of third-party applications when vendor security application testing is used as a standard.

About the Author

Fergal Glynn is the Director of Product Marketing at Veracode, http://www.veracode.com/security/web-security, an award-winning application security company specializing in spoofing attack guide from Veracode and other security breaches with effective risk assessment tools

Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ lundi 25 mars 2013 0 commentaires

Security Awareness Training: Why Every Business Needs It

The need for security awareness training is more important than ever. Every company that plans to stay competitive must make this type of training mandatory for every employee. The reason for a stringent and complete training program and the need for every employee to be aware of security is the surprising direction from which security threats may come. The security threat that companies face comes as much from within as it does from outside corporate spying.


Definition of the Direction of Threats

The threat from outside is usually better understood by company management than the threat from within. The internal threat is not just from unhappy employees. The employee who is unaware and untrained is the biggest threat. Employees who have not undergone security awareness training hurt the company by visiting Internet sites that have active malware. They often respond to emails that are phishing attacks and often keep their login and password information stored in an unprotected manner. Some uninformed employees may never think of the damage they do when discussing company projects in social gatherings, both on company time and outside the confines of the company facilities.

Why the Level of Training Intensity Must Be High

The only way to ensure that employees are not damaging the company, inadvertently or knowingly, is to set up company mandatory security training awareness programs. Every existing employee must be required to take this training when the program is started. New employees should be required to undergo security awareness training before starting their new job. This training should also require successful completion of a test to ensure a working knowledge of this vital topic has been received and understood. Update training should be required on a recurring basis as well.

Training should be much more than an hour or two of classroom training. The company needs its own website that is dedicated to the security awareness of the company. Each employee should receive random hints and reminders by email, and posters on security should be posted in prominent places throughout the company facilities.
In this manner every company can have an increased level of confidence that each employee is knowledgeable of company policies, procedures on the matter of security for any information relating to the personnel, and products or projects of the company. This type of security awareness training is the only way that employees will know, understand and put to use best practices expected by company management.

Getting Started with Security Awareness Training

At the beginning, if the company does not have personnel trained in the curriculum for this training, it may be desirable for select employees to attend outside training in order to learn what is needed. By having the company's own personnel return to oversee this type of training sets the tone about the seriousness of this type of training.


Peter Wendt is a writer from Austin, TX, that has researched a lot on the topic of malware and computer security, and highly recommends this security awareness training program for businesses and employees. 



Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ lundi 18 mars 2013 0 commentaires

The 6-Strikes Rule is Coming: Will it Impact You?

The commonly called "six-strikes rule" has been batted around since 2011. The fairly new Center for Copyright Information is the driving force behind this initiative which they refer to as the "Copyright Alert System." When internet service providers detect the unauthorized access to copyrighted content, they send warnings to subscribers. Repeat offenders may experience temporarily reduced internet speed, temporary downgrade in service tier or a compulsory online education program. Subscribers penalized with the online education program would be redirected to the page. Though it's not explicitly stated, it is implied that no other internet access would be allowed until the online program is completed.


The CCI provides this video to explain the system:




So, while you're safely looking at funny pet pictures on a website, downloading funny pet videos might be another story altogether. For that matter, someone hacking into your wireless (if it's encrypted) or borrowing your wireless might get you flagged.

Content owners are driving this system, by lurking in places they suspect are illegally sharing their content. They then notify an ISP who alerts the subscriber. When infringement stops, so do alerts. Subscribers should not be continually reminded of past red flags, only current ones. Thus far, it appears that ISPs won't cancel subscriptions due to alerts, but they might slow or downgrade your service.

Challenging Charges

For subscribers who feel they've been wrongly targeted, they can challenge the alerts (or so it says in the video). What the video neglects to mention is that challenges aren't free or simple. The initial alerts, educational in nature are not reviewable. Alerts that contribute to mitigation (slowing or other impairment of your connection) can be challenged.

According to the CCI, challenges must be submitted within 14 calendar days "from your ISP’s system." We're not sure, however what that means exactly. Hopefully when an alert is presented, so too will be the means to challenge it. The review is independent and run by the American Arbitration Association. It also will cost you $35. Oh, and there's a list of accepted reasons for requesting a review, so you'd better not have a unique or original reasoning.

Don't Risk It

Any mitigation measures are suspended once you've filed everything. There's currently no indication of a standard time frame for the review process. If your challenge is deemed successful you'll get back your $35 and previous alerts will "no longer be associated" with your account. Though, we're not sure if that means your record is expunged. If you're denied, you forfeit the $35 fee and are subjected to mitigation measures by your ISP.

If you're not already worried about how much of your personal information is on the web, it seems like this is one more way to risk your private and personal information. The CCI asserts that although content owners can report IP addresses to ISPs, Personal information about consumers won't be shared by ISPs. You may not change the way you access the web, but you should double check that you've secured your wireless network.

Do you think this program will change the way people access content? We'd love to hear your thoughts in the comments.


Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ jeudi 7 mars 2013 0 commentaires

IT Disaster Recovery Top Trends

The natural calamities do often cause losses in many ways including ruining the infrastructure of any business organization and huge data loss. Hence you could see disasters like snowstorms, earthquakes and hurricanes destroying the corporate facilities and data centers to a great extent. Therefore businesses today feel the need of having a tangible disaster recovery plan to deal with any such situation.


 

The disaster recovery is influenced by a number of trends, which companies plan, implement and check their recovery strategies. The IT and security teams are supposed to enhance the trends found in disaster recovery, which can help the companies to carry out steps instead of making their efforts complicated. Let’s check out the top trends found in IT disaster recovery as discussed under:

Cloud services

Since the use of cloud technology is improving every passing day leading to its access to different companies, hence IT companies and security providers consider it as an important resource to chalk out a competent recovery strategy. The cloud configuration simply helps the corporate users to carry out software upgrades all over the multiple tenant systems without any disruptions since the storage is virtualized. As per the Forrester Research reports, a number of companies call cloud strategy as a vital trend as it has the potentials of shaking up the legacy systems. It can be embarked as a feasible option to different companies in disaster recovery trends.

Virtualization

Lately, server virtualization is among the emerging trends found in technology sector, which has made companies to consider it as an important element of a good disaster recovery strategy. It has the capacity to expedite the disaster recovery strategy implementation along with recovering the business data during any disaster in quick time. Also, virtualization has the potentials of making disaster recovery like an IT function instead of corporate audit type function. Lastly, the easy portability of virtual machines has helped companies and business organizations to use this technology as a crucial piece during their recovery efforts.

Mobile devices over the workplace

The use of Mobile devices at workplaces is another popular trend, which means that these devices could play an important role in recovering procedures from any kind of disaster. The mobile devices are easier to carry anywhere and thus could help the IT team and security providers in the disaster recovery. However, the very same devices simply make the DR process a bit complicated. Here you need a proper mobile device management system along with a number of tools like BlackBerry Enterprise Server. All of these things together make the process complex for the disaster recovery management. Yet experts feel that with enhanced and planned methods, you could embark with more easy solutions.

Social media

Unlike the mobile devices, social media is an important platform, which companies have to remain in touch before and after any disaster. There are instances when employees remained in touch during the disaster time due to snowstorms using platforms like Facebook and Twitter or even through the emails. If businesses rely over the directory services or exchange based internal email systems then during disasters, social media could be called as the most viable alternative for all. As per the Forrester, social networking platforms could be called as a vital player for the disaster recovery programs.

Final word

There is always a threat to data centers of research and commercial organizations for natural calamities and manmade disasters. Hence it is important for such groups to embark with a competent disaster recovery strategy. While chalking out the same, the above four trends found in this domain could help you in devising some of the best disaster recovery program for your business or research organization.

About The Author: Margaret is a writer/blogger. She loves writing travelling and reading books. She contributes in Hotline America Reviews




Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ mardi 18 décembre 2012 0 commentaires