Wednesday, May 17, 2017

Zomato Hacked

Just got the news that Zomato has been hacked and 17 millions users records have been sold on dark trace. The database includes emails and password hashes of registered Zomato users.
In 2015 also the company was hacked by a white hat Indian Hacker named Anand. Zomato assured no payment information has been stolen.

Tuesday, May 16, 2017

WannaCry - Ransomware

Hi,
The morning on 12th May was not good. It started with the news of a ransomware attack that impacted 74 countries by that time. The biggest and largest victim was UK NHS where the computers of several hospitals were targeted with WannaCry Ransomware. The files on the computers were encrypted by the malware and users were asked to pay $300 in bitcoin to restore their documents.
The services of these hospitals were impacted severely and Doctors were using pen and papers for critical tasks. A&E was closed for non-critical patients.
Within three days wannacry spread like fire in the jungle and by the time this blog is being written there are already 150 countries which have been impacted by this nasty malware.
In China 30,000 organizations were affected on Mainland China.
More than 4,300 educational institutes were infected.
In France auto manufacture Renault were not able to open its plant in Douai.
In Japan  over 2,000 computers were affected. Nissan Motor, Hitachi were also impacted.
In India 120 computers were impacted in Gujrat Govt. GSWAN. Computers in Kerla and Andhra Pradesh were also impacted  by the malware. Police department in Mumbai was also impacted by the malware.
The national power company a hospital and one private business were impacted in Taiwan.

Sunday, June 7, 2015

CryptoWall 3.0


Threat –

CryptoWall 3.0

          Is a malware spyware/ransom ware that can steal the victim’s information and ask for the payment from users to release it. It uses Tor ( hidden Internet) to execute its online payment process.

 

How it spreads

Spam/Phishing Emails

It comes as an attachment in an spam or phishing mail (generally in zip file) and once user opens the zip file. It prompts the user to download the PDF file pretending to be harmless “Resume” etc.

  

Protection

Spam filtering 
Internet Firewall 
User awareness 
 

NjRat Malware


Threat –

NjRAT – A remote access Trojan complied in .Net 4.0 capable of  taking complete control of an infected device. The malware is capable of logging keystrokes, downloading and executing files, providing remote desktop access, stealing application credentials, and accessing the infected computer’s webcam and microphone.

 

How it spreads

1.       Spam/Phishing Emails offer users to install video game (need for speed etc.), video games cracks, application key generator and Antivirus etc.

2.       By visiting a compromised website which again asks to download antivirus etc.



Protection  

Internet Firewall
Spam filtering
End Point Protection
User awareness  

 
 

DYRE MALWARE



Threat –

DYRE MALWARE

·         A Trojan with Man in the middle (MITM) attack capabilities and coveted VNC Session,  designed to steal login credentials by grabbing the whole HTTPS POST packet, which contains the login credentials sent to a server  during the authentication process, and forwarding it to its own server.

·         It can then compromise the victim’s Bank /others account and can block the user to access his own account.

·         It has VNC capability as well to perform DoS or DDoS attack through the victim machine once the system is affected with the malware.

·         It works through a configuration file  and currently there are 90 target Banks  (mainly from Romania, United Kingdom, Ireland, USA, and UAE)  in that configuration file  


How it spreads

Spam/Phishing Emails

It comes as an attachment in an spam or phishing mail and once user invokes it, the Trojan executes itself and gets installed on  victim’s computer.

 

How to Protection

Spam Filtering
End Point Protection  
            User awareness  
                  1.       User not to fall prey to unsolicited mails.
                  2.       User  not to open email attachments if sender is unknown or unfamiliar.

Sunday, April 26, 2015

Password Security

 Passwords
Weak passwords are one of the biggest reasons of security breaches all around the world. Whenever someone starts talking about security, he/she definitely will talk about passwords' security. There is a standard list of precautions of Dos and Don’ts.  
Normally you can find this list on any of the security awareness mailer or on Internet and it  goes as follows
1-      Do not create weak passwords.
2-      Imagine strong passwords and the characteristics of strong password are
3.       Create long password 8-9 characters
4.      Your password must consists alphanumeric values and special character.
5.       Use pass-phrase and make it complex for example “TimeforTea” now you can make it “T1mef0rt3a” or  “T1mef@rT3a”
6-      Do not share your password with your friends and colleagues
7-      Do not write your password on postit and stick to monitors and on your desk.
8-      Do not use one password for all the accounts. Try to be creative, categorize the accounts as per confidentiality & criticality and create different password for different type of accounts.
9-      Avoid using public computers to login to your banking accounts.
10-      Try to adopt Two factor authentication wherever possible ; Two factors authentication is a double layer security where you are required to get authenticated with more one than one ways.. for example what you know and what you have. Bio-metric authentication adds "Who you are" component in the authentication.
11-      Beware of the websites that asks your personal details. Do not disclose passwords online.
12-      Beware of the phishing accounts – Phishing is a method, used by attackers to incite users so they can click on the fake links given in the genuine looking email. The sender pretends to be a genuine source like your bank etc. Once you click on the fake link or enter your credentials, the hackers steal your information and misuse it.
13-   Beware of shoulder surfing. Always check your surroundings before you enter the credentials.
Hell Bent to crack
There are lots of free tools easily available on Internet to hack others’ password. Some of the most common are Brutus, RainbowCrack, Wfuzz, Cain and Abel and John the Ripper etc. Due to the high speed internet with more and more bandwidth, it takes quite less time to crack the complex passwords. The Problem is that dictionary words and their combinations are easy to guess. As a matter of fact there are lots of such lists available on internet which you can simple use to crack the password. There are cognitive tools which require some human inputs about the target so they can produce the list of probable password the target can think of...these tools can prove lethal if someone really knows a lot about the target and has the intention to crack his/her secret passwords.
“Single Sign On”
Nowadays, big companies introduce “Single Sign On”, an access management appraoch, where a user logs in once and gains access to all systems without being prompted to log in again at each of them. There are apparent benefits and disadvantages of this approach.  It is easy to remember one strong password than multiple easy passwords. It is convenient and increases the security since it would be difficult and time taking for an attacker to crack the strong password. On the other hand, it is a single point of failure, once a single password compromised, it can create havoc.
Fusion is the way
People are adopting the new fusion approach while creating the password that is mixing two languages. If you know English and Hindi, you can use “Hinglish” to create passwords and that would be really difficult for dictionary attacks to crack.  For instance you can create a password such as “MeraDoggy@049”.  
Do not create so much complex password that you cannot remember and even the strongest password, if kept and stored insecurely serves no purpose.  

Thursday, April 23, 2015

All about CISSP


Hi Folks,

Recently I acquired CISSP (Certififed Information System Security Professional) Certificate and the exam was really a tough one. Once I cleared the exam, I started getting calls from my friends and colleagues who would ask me the tips of passing the exam like what they should study and what should be the correct approach to nail the one of the toughest exam in security domain.

So I thought of summarizing it here so it will be easy for me to just send the link of this blog to my friends and it may prove beneficial for other aspirants as well.

The facts about CISSP exam are all available on internet like the CISSP Certification is governed by International Information Systems Security Certification Consortium, also known as (ISC)². This Certificate has been approved by United States DoD (Department of Defense). There are around 100 thousands CISSP around the world as of now. CISSP contains 10 domains which are as follows

1.Access control
2.Telecommunications and network security
3.Information security governance and risk management
4.Software development security
5.Cryptography
6.Security architecture and design
7.Operations security
8.Business continuity and disaster recovery planning
9.Legal, regulations, investigations and compliance
10.Physical (environmental) security

This is an online exam and can be booked via Pearson VUE. The fee is $599 for one attempt. The exam contains 250 questions which are mostly cognitive and you get 6 hours for the exam.

Once you pass the exam, you need to get endorsement from one of the existing CISSP holder to become Certified. You have the option of becoming Associate ISC2 in case you do not possess the minimum requirement of work experience to get the endorsement.

Now comes the tricky part - The preparation. There are lots of good writers and trainer for CISSP but I studied Shon Harris, She had a wonderful ability to describe the lengthy and boring subjects with so much ease and fun.

I studied the CISSP book written by Shon Harris "CISSP All-in-One" and I attempted the questions given in the book and other 500 questions in the questions bank but this is not enough. One needs to go into details and refer other books like "CISSP Practice: 2250 Questions, Answers, and Explanations" and online information wherever required.

What I have found is that CISSP exam is not only about the knowledge but it is a mind game as well. The questions asked in exam are so unique in their formation, that you will hardly come across to any question you have seen previously but still if you are clear on the Security fundamentals and have a clear understandings of the CISSP domains, you can still figure out the answers. Below are the important points to note down -

  1. You need to prepare for the exam in a planned way. You need to devote some time daily for study. You just cannot do it in two full days.
  2. You just cannot rely on one book or one question bank. Shon Harris is good but look for other sources also.
  3. You need to attempt all the questions given in the book and in questions banks. You need to be well versed in how to eliminate the wrong answers. Check some videos on YouTube.
  4. You need to hold your nerve while taking exam. You may feel you are not going to pass it, but still give your best, and keep patience till the end.
  5. Do not give up and leave the test in the middle, Attempt all the questions.
  6. Do not waste time on difficult questions. First answers the questions you find easy and then come back again to answer the difficult ones.
  7. Do not change the answer again and again. Most of the time, what you think first time could be the correct answer. Just do not be panic and answer with patience
  8. Believe me 6 hours are not a very lengthy time for CISSP. You need 6 hours that's why they have provided.
  9. Finally keep you cool and believe in yourself. If you could not do it you wouldn't have attempted it.

I hope this will help you.



Sunday, April 19, 2015

Defense in Depth


With the evolution of technologies our dependency on digital devices has increased manifold. And we are exposed to cyber-attacks more than ever. Lately, some of giant organizations like Sony and Amazon have become the victims of cyber-attacks and that have sent ripples to the others similar or smaller and less protected establishments to ponder over how immune they are for such attacks or what defense mechanism they have to defend if such attacks happen to their organizations. As they say Cyber Attack is not the question of yes or no it is the question of ‘When’, we need to be as ready as expecting the attack today itself. Security is never much but the terms; ROI (Return on Investment) and cost benefit analysis are also relevant. Most of organizations adopt multilayered security approach, Security at the perimeter-Firewalls, DMZ (De militarized Zone), IPS (Intrusion Prevention System), IDS (Intrusion Detection System) Honey pots, WAFs (Web Application Firewall) and Host based Protection System as Antivirus, Anti-spy ware, threat protection etc. Considering this as not enough, many organizations place SOC (Security Operations Centre) and NOC (Network Operations Center) to have a robust mechanism in order to defend the cyber-attacks. SIEM (Security Incident and Event Management) helps to captures logs in real time, generate alerts and does the correlations also to identify the abnormal or suspicious activities on the network. SIEM solutions like HP Arcsight, MacAfee ESM, and Alien Vault USM also help in auditing breaches such as misuse of the privilege user IDs and unauthorized changes etc. organizations are also introducing End User IT Analytic Solutions like Nexthink & SysTrack that monitor the end user activities in real time and generate alerts and reports to helpdesk to respond to any security incident quickly and efficiently.  ISO27001 and ISO27035 articulate the need of a robust Security Incident Management to actually make use of these automated security tools. Unless the organizations have a strong Incident Management in place, they will find themselves off-guard when they have to do a face to face with DoS/DDoS (Denial of Service/Distributed Denial of Service) attack for example.

The basic components of a Security Incident Management are Preparation, Detection & Analysis, Containment Eradication & Recovery, and Post Incident Activity 

 

This is a continuous cycle and each subset of the cycle is as important as the entire cycle. Organizations need to have a clear and well defined Incident Management Policy & guidelines with clarity on the roles and responsibility of all the teams/individuals involved in the cause. Post Mortem to actually find out lessons learnt is very important as they say “There is a principle that says, never waste a good crisis."

However as the defense security is not complete without strong Incident Management Program, the same is true about Information Security Awareness. Security Awareness has lately become the major part of any security defense program. Given the rise of Social engineering techniques such as phishing, spear phishing, email spoofing and APTs Security Awareness has become the talk of the town. With the help of Social engineering attackers can penetrate even the strongest perimeter security and break into the most reliable and secured network. Many companies are investing on security awareness program besides other traditional security protection measures.  Security Awareness can thwart most of the security incidents and can keep a check on insider attacks. Organizations need to have a thorough Information Security Awareness Program in place to educate the employees about the security threats and best practices.

 

 

 

Wednesday, July 24, 2013

Attack methods Part I

 

 

ATTACK METHODS ( Hacking Terminology)

 

Information security is as important as the information itself. In the complex world of web and interconnected networks, security is a major concern and only the proactive approach to secure our information can reduce/mitigate the risk posed by the advanced threats and attacks.

As the technology is growing so are the ways to attack the system/networks.. some popular attack methods to the systems/information are as below :

 

Virus :

Virus a piece of code or program which is pushed in our system by attacker without our knowledge and gets executed . Virus has the capability to replicate itself.The virus  can spread in the system in no time and can spread even across the network bypassing the security. Virus can be less or more harmful depends on the code. Its kind of malware which is attached to the files or programs and as the user runs the programs the virus infects the system.

 

Worms:

Worm is also a kind of virus but the only difference between virus and worms is that virus needs human action to run as they are attached to the files and programs but worms can run on its own and spread. They can travel independently from machine to machine, across the networks and cause severe damage to the applications/systems.

 

Trojan Horse :

Trojan horse could be a software or executable file which apparently looks useful and once we execute, it will install some malicious code in the system and send out the information across the network. It can open some ports in the system without the knowledge and wishes of the victim and open a backdoor for the attacker to gain unauthorised access compromising the information.

 

E-mail Spam:

Email spam is the situation where the target mailbox is filled by usually unsolicited mails resulting exceeding the mail quota and preventing the user to use the email services. it can be un intentional if any of the users sends a mail copying groups that contains hundreds of recipients. the situation aggravates when unaware recipients start replying to the mail creating flood or chain of mails consuming the bandwidth and introducing Denial of Service.

 Botnets:

A set of compromised computers which are called zombie computers although their owners are unaware of this, running software usually installed through worms, Trojan horse or backdoors. The 'Bot' has been taken from Robot and 'Net' has been derived from network. According to a report from Russian-based Kaspersky Labs, botnets -- not spam, viruses, or worms -- currently pose the biggest threat to the Internet.

 

Phishing:

The act of sending the fraud mails to users  falsely claiming from a legitimate source and then direct them to some fake website persuading the users to enter their confidential information like password, credit card details and bank account details. The purpose of phishing is to steal the valuable information of the users by befooling them. Phishers use a number of different social engineering and e-mail spoofing ploys to try to trick their victims.

 

War Dialing :

War Dialing is a situation where the attacker penetrates the system through dialing to the modem connected to the network. War dialer usually a freeware program, automatically dials a defined range of numbers to target the victim.

 

Brute Force Attack:

Brute force is also called exhaustive search, is a method where the attacker tries multiple combinations to crack the password or Data Encryption Standard keys using brute force) in an attempt to gain unauthorized access.  The approach is less intelligent but has good success though it is very time consuming.

 

Data Alternation attack:

Alternation attacks occur when someone makes unsolicited or unauthorized modifications to code or data, attacking its integrity. These attacks can occur in different forms and have a variety of consequences. An organization might have a Software Development Life Cycle, but the binary code can be altered. A person with access can recompile an existing program to add another library or DLL. The primary defense against an alteration attack is a cryptographic hash. If we can record the state of a program or data before it is altered and securely store the hash, you can periodically recheck the program or data and compare it with the stored hash. SHA 2 is recommended for the hash algorithm.

 

 Denial of Service attack:

Denial of Service attack happens when the attacker prevents the legitimate user accessing information or services. This is done either by targeting your computer or the computer or network/website you are accessing. The attacker can prevent the users to use email or website or banking accounts. The attacker can use several methods to do this, for example, ping flood to exhaust the bandwidth or spam flood exceeding your mail quota resulting in DoS or phlashing where the damage is done to the extent of replacement of hardware.

Brute force attack, Banana attack, Pulsing zombie and bandwidth saturating attacking are example of application level DoS attack.

 

 Distributed Denial of Service attack:

Distributed Denial of Services attack happens when attacker used multiple computers to flood the victim network or computer in order to prevent him accessing information or services.

to be continued....  

 

 

 

Friday, July 19, 2013

How to Configure Wireless Broadband Router Securely?




How to Configure Wireless Broadband Router Securely?




















User name and Password
Change the default user name and password because they are often easily guessed. Some manufacturers might not allow you to change the username, but at least the password should be changed.

Encryption (WEP/WPA/WPA2)
Whenever possible, WEP should be avoided. Instead, use WPA2/AES or WPA/AES if it is supported on the device.

Authentication Type (Open Authentication or Shared Key Authentication)
The shared key mechanism should never be used. Instead, a stronger mutual authentication as defined in the 802.11i standard should be considered.

Wireless Network Name / SSID
The default SSID should be changed. The new SSID should not be named to refer the network products being used, reflect your name or other personal information, otherwise the information could aid an attacker in collecting reconnaissance information about you and your wireless network.

Broadcast Network Name / SSID
Users may consider disabling SSID broadcasting or increasing the “Beacon Interval” to the maximum. Suppress SSID broadcasting could not prevent sophisticated attackers to steal SSID by sniffing the management frames between the communication of access points and clients, however it could able to stop casual wireless clients from discovering the wireless network or attempting to access.

MAC Address Filtering
Enabling MAC address filtering is recommended as another layer of protection.
Dynamic Host Configuration Protocol (DHCP)
Disabling the DHCP feature, if possible, is recommended, as DHCP makes it easier for malicious attackers to access a wireless network

When you want to use public wireless services

                          

    TIPS ON INTERNET SURFING VIA PUBLIC  WIRELESS SERVICES


            





Once you have a wireless device such as a notebook computer or a hand-held device connected to public wireless hotspots, you are exposing yourself to potential attacks from remote attackers. Nonetheless, the following security tips may prevent you from falling into the traps laid by attackers:


1. Don’t leave your wireless device unattended
2. Protect Your Device With Passwords: Enable your device’s power-on login, system login authentication, and password-protected screen saver.
3. Disable Wireless Connection When It Is Not In Use: Wi-Fi, infrared, and Bluetooth devices are constantly announcing their presence if they are enabled.

That means they are waving hands to attackers, even though you may be unaware of it.
4. Keep Your Wireless Network Interface Card Drivers Up-to-date: A network interface card driver is just a piece of software. It is not immune to software bugs. Keeping the drivers up-to-date assures that wireless devices have the latest protection and support from product vendors.
5. Protect your device with anti-virus software using the latest virus definitions: This can minimise the risk of infection by computer viruses or spyware.
6. Encrypt Sensitive / Personal Data on the Device: Even when an unauthorised user gains access to your device, encryption will keep your data away from an opportunistic thief.

7. Turn off Resource Sharing Protocols for Your Wireless Interface Card: When you share files and folders, your shared resources may attract attackers attempting to manipulate them.
8. Remove Your Preferred Network List When Using Public Wireless Service: Some operating systems offer a feature for you to build your own list of preferred wireless networks. Once you have this list defined, your system will keep searching for a preferred network and try to connect to the preferred network automatically. By capturing this information sent out from your system, an attacker could set up a fake wireless access point, which meets the settings of a wireless network on your Preferred Network List. In doing so, your device would automatically connect to the attacker’s fake wireless network.
9. Turn off Ad-Hoc Mode Networking: “Ad-hoc” mode networking enables your wireless device to communicate with other computers or devices through a wireless connection directly with minimal security against unauthorised incoming connections. This should be disabled to prevent attackers from easily gaining access to information and resources on your device.

10. Do Not Enable Both Wireless and Wired Network Interface Cards at the Same Time: When a device is connected to a wired LAN with the wireless network interface card still enabled, there is a possibility that attackers can sneak into the wired LAN through an open wireless network if network bridging is enabled.
11. Check the Authenticity of a Captive Portal: Captive portal web pages are commonly used in public hotspots as a means of user authentication and for deterrent protection. When connecting to a public hotspot, the user will be redirected to a captive portal page. However, attackers could also set up fake captive portals to harvest personal information. Therefore, when using public hotspots, it is important to check the authenticity of a captive portal by verifying the server certificate from the website.
12. Don’t Send Sensitive / Personal Information When Using Public Wireless Networks: Public wireless networks are generally considered to be insecure. You should not transmit sensitive or personal information over a public hotspot without proper security controls.
13. Encrypt Your Wireless Traffic Using a Virtual Private Network (VPN): If transmission of sensitive or personal information over a public wireless network is unavoidable, a VPN solution can help ensure the confidentiality of communications using cryptographic technologies.
14. Disable Split Tunnelling When Using VPN: It is possible to connect to the Internet or other insecure networks while at the same time holding a VPN connection to a private network using split tunnelling, but this may pose a risk to the connecting private network.