Pages

Saturday, December 17, 2016

Who doesn't like to b a creator of something new..
Who doesn't want play God and feel devine
Well here is chance to play your own role as God while working on your computer.
Check out the God mode in MS Windows.  This feature has been available with all versions of MS Windows 7 onwards.. We will how it's done in Windows 10.. Follow the link given below
https://fossbytes.com/how-to-enable-godmode-windows/

Saturday, November 12, 2016

There have been frustrating times for coder and students and general Linux users while taking down notes ot just jotting  down their thought that they wish they had something simpler yet powerful notepad like tool.. Well there are a list of apps which augment features of notepad and features like Evernote..
Check these out
http://www.makeuseof.com/tag/top-notepad-apps-linux-can-sync/

Saturday, November 5, 2016

The emphasis on ensuring safety of your digital assets,  data included cannot go overboard ever.  This is one such field that would always remain Achilles heal for management and sore point of discussion in boardroom meetings whenever financial allocations are being carried out.. Check this out.. A primer

http://www.bizlibrary.com/article/cybersecurity-training-team-sport/

Saturday, October 29, 2016

  *Though a dated,  old article but give lots of basic information about different image formats that comes with tips on what format to be used and when..
This is a detailed summary of all popular image formats with comparisons also..  Handy reference
 Happy hunting

Ref http://blog.hubspot.com/insiders/different-types-of-image-files


(All copyrights of respective owners) 

Wednesday, August 10, 2016

Is Human factor weakest link in security?

Human factor: Weakest Link!
  • It has been always been a strong point of debate  whenever it is discussed for implementation of Cyber Security..  Who is the Weakest Link? Identification has never been difficult for Security team and they  have be univocally supported by both, Executives and /management…THE USER.
  • The User.. is known by many other names
    • Client
    • End user
    • field agents
    • office staff
    • non developers
  • Since ages the human link is taken as “Weakest Link” in security be it Physical or now “Cyber”.
  • However This fact has been overlooked more often that not that very same “HUMAN” factor is major contributor in implementing the ROBUST SECUTIY ARCHITECTURE.
  • Awareness : What Lets one down is the “Lack Of Awareness Training”..The basics are forgotten..what is the main factor to plug this?.. Create Awareness… How? Training is the best way of creating awareness.
    • It can be integral part of appraisals process.
    • Divide into various levels of training
      • Beginners ..for freshers and new recruits
      • Middle level…for those having completed some time in the company and those who are due for appraisal
      • Advanced and Refresher courses… At the time of change of any major policy or revision as well as on introduction of new equipment
  • Thus we can say its always the Onus on the Security Professionals as well as the Management
  • A detailed study carried out by eforensics magazine highlights such issues https://eforensicsmag.com/human_factor/

Saturday, April 25, 2015

Cost of data loss: How realistic we are about finances of data breaches?

  1. The data breach and subsequent loss of records for transactions and confidential details of customers are always a matter of concern for any company. However it becomes very difficult to put exact or near exact cost per record loss due to the breach.
  2. Verizone has tried to breach this barrier and to put cost per record and it comes out to be..... Dollars 0.58 . Amazingly low. Another research firm puts this between 188 to 210 dollars per record.
  3. Check out the details https://m.facebook.com/l.php?u=https%3A%2F%2Ffortune.com%2F2015%2F04%2F24%2Fdata-breach-cost-estimate-dispute&h=jAQHhn8X8

Monday, April 6, 2015

Facebook Thugging... new era of cyber threats

Ever heard of a term Cyber Bullying. Normally its associated with children being threatened by criminals, paedophiles etc online in chat rooms etc.
However a case of intimidating a facebook user by displaying a gun pointed towards camera with menacing smile has lead to arrest of a lady for "Facebook Thugging".
As per the details available, the lady posted a pic of herself pointing gun towards the camera that was followed by a comment something to the effect that "That's what you will get if you come lookin for me".
Though she took off the pic later on admitting that she thought it was intimidating, police arrested her on the charges of threatening on facebook.
Therefore be careful what you post and how I is going to be visualised by others.
Don't be impulsive. Think before you act.
http://www.techworm.net/2015/04/woman-arrested-for-facebook-thugging.html

Saturday, February 28, 2015

Digital Forensics Application Software EnCase

The Digital forensics or more precise computer forensics fascinated me a lot ever since I ssaw a demo on stenography. Later on while handling the same and using various forensic software suites further made me interested in exploring the various facets of Digital forensics.

However once i started pursuing my MS, it left little time to do something else.

Recent chance meeting, though long overdue, with a good friend who had switched his job made me think again about rekindling this area once again.

Today when I thought of starting once again, first thing about digital forensics struck me was , to know more about EnCase.

Came across this primer and advanced link. I thought of sharing with you all.

Digital Forensics Today Blog: A Treasure Trove of EnCase Version 7 Resources to Help You Make the Transition

Friday, February 20, 2015

Lenovo Compromises Laptops Security.

China has done it again.
One of world's three largest Laptop and PC manufacturer faltered as it inadvertently installed an adware Superfish.
 This adware or the software that automatically displays advertisements, maliciously hijacks the encrypted connection and throws open them for hackers to launch MITM(man in the middle) attacks and also eavesdrop on your communications via infected laptop.
This was reported by CEO of security research firm Errata Securities.
As per the report even uninstalling Superfish doesn't mitigate the threat. The Software has already authorised itself to take over secure connections and throws them open, declaring them safe and trusted, even when they are not. This leaves the laptop vulnerable to NSA type snooping attacks.
In recent past similar reports of Xiomi collecting user data and sending them to servers In China.
 More details can be explored.on the link given below.
Happy Hunting.
http://goo.gl/9SHXJl

Thursday, February 19, 2015

TV is Watching Your Actions

Till now everyone was watching their favourite movies, soap operas and adventure, sports program on big LED TVs . Now , however the TV are becoming smart and they are “keeping an Eye” on your activities.Read the article for complete details

Beware! Samsung Smart TV Is Listening To Everything You Say!

Sunday, February 15, 2015

Hexinator....a good hex editing software

Every time you have a situation where in you require to go through the binaries and raw files, go through hex data to determine what's happening behind the scene or attempt reverserngineering , you look for a good hex editor and at times any additionalinformation provided by the hex editor is welcome.
Thus get hold of New Hexeditor.
Details at https://hexinator.com/

Sunday, January 11, 2015

CyanogenMod: A New Version of Android

What is CyanogenMod?
  • Its another Operating System from the Stables of  OPEN SOURCE communities
  • Its a based on Android Platform.
  •  It  supports  
    • native theming support,
    • FLAC audio codec support,
    • a large Access Point Name list,
    • an OpenVPN client,
    • Privacy Guard – a per-application permission management app,
    • support for tethering over common interfaces,
    • CPU overclocking and other performance enhancements,
    • soft buttons and other "tablet tweaks", 
    • Wi-Fi, Bluetooth and GPS, etc.
  • It also boasts of increased performance and reliability compared with official firmware releases.
  • Its development cycle grew with new releases of Android right from Gingerbread, honeycomb, Ice Cream Sandwitch, jelly bean and now Kitkat.
  • No longer releasing Stale modes of OS. only rolling models .
  • The first nightly release of CyanogenMod 12, based on Android 5.0 Lollipop, began rolling out for a selected number of devices on 6 January 2015.
Source wiki

ATM Vulnerabilties Enable Cash Withdrawal Without Debit

  1. One would have come across the reports in news papers, how the ATM was targeted and cash looted by robbers or hoe they skimmed off your account off some cash when you didn't bother about the guy standing behind you inside the ATM observing you entering the PIN (Shoulder Surfing).
  2. There were instances of a key logging device pasted over the Keypad that would transmit all ATM PINs entered to the hacker.
  3. Can you beat this  " Withdraw the Cash Legitimately without getting it debited FROM OUR ACCOUNT"
  4. Yes.
  5. The modus Operandi is very simple. After You have entered the PIN and amount required to be withdrawn, you just block the cash dispensing opening. The machine will take it as fault in delivery mechanism and reverse the debited amount. However your cash would have been dispensed by then.
  6. This kind of fraud has been reported in Bangalore by a security firm against bank employees, though no arrest has been made in tis connection so far.

Tuesday, December 23, 2014

Sony Hack and aftermath, Begining an era of Cyber War !!!!!!

  • The Sony servers were hacked allegedly by North Korea hackers at the behest of their leaders in order to protest for the : The Interview” a movie by Sony Picture , putting their supreme leader in bad frame.
  • This lead to compromise of various servers of Sony Pictures, loss of many unreleased pictures and otherwise sensitive information and data, besides receive of threatening emails by Sony Pictures employees as alleged by them
  • This forced Sony Pictures to subsequently postpone the release of the movies
  • Also came into the picture the statements form US presidents and counter statement from North Korea, escalating in retaliatory cyber attacks on each other.
  • Is this start of A full fledged Cyber war?
  • Maybe Yes or maybe its just a case of Cyber Vandalism as said by Mr Obama.
  • Lets say goodbye to 2014 and welcome 2015 with New, Unknown challenges of Cyber Space

 

Monday, December 22, 2014

Cyber Threats:The Year That Was 2014

  1. The year of 2014 was a hectic and busy year for CISOs and CIOs. There were many revelation by ex- Employees about their agencies gathering information or spying on even friendly nations in the name National Security.
  2. Wikileaks, Snowden, PRISM etc scared the hell out of common Internet users as well as Governments across the world. Everyone felt naked. There was an aura of Disbelief that swept across EU and other friendly nations of US when it was revealed that their data transmissions were intercepted by NSA to "Quell " any suspected Terrorist strikes.
  3. Similarly revelation of many long standing Bugs and vulnerabilities by various independent researchers introduced the cyberworld of Heartbleed, Shellshock,etc . It's possible that these vulnerabilities had been exploited by them for years.
  4. Lastly not to mention was the case of iOS being targeted big time by WireLurker.
  5. Are we going to see the resurgence of old bugs or there are going to be some new evils that will emerge in 2015!!!!!!!!!!!!!!!!!!

Thursday, December 18, 2014

ICANN Hacked ....Again

   image source: www.darknet.org.uk
  • The Internet Corporation for Assigned Names and Numbers (ICANN) is responsible for the coordination of maintenance and methodology of several databases of unique identifiers related to the namespaces of the Internet, and ensuring the network's stable and secure operation.(Wikipedia definition).
  • It address the issue of domain name ownership resolution for generic top-level domains (gTLDs).
  • As per the information available, ICANN has been subject to a spear-phishing attacks since November 2014.
  • The attack has caused the loss of email credentials, names and addresses of personal  user details stored in Centralised Zone Data System. 
  • Besides this the ICANN blog, ICANN wiki and WHOIS information portal has also been compromised.
  • Since its creation, ICANN has been the subject of criticism and controversy.
  • This is not the first such attack targeted towards ICANN. In June 2008,  a Turkish gp "NetDevilz" hijacked the ICANN site and redirected it to site giving out message as  "You think that you control the domains but you don’t! Everybody knows wrong. We control the domains including ICANN! Don’t you believe us?"
  • Here is the first hand information given by ICANN on its site   https://www.icann.org/news/announcement-2-2014-12-16-en

Thursday, December 4, 2014

Sony picture hacking linked to allegedly to unreleased film on North Korean supreme leader


The recent hacking attack on Sony Pictures that resulted in loss both in terms of finances as well as the leaking of digital prints of unreleased motion pictures.
It has been observed by FBI that potential threat exists for  Business in US particularly from the similar malware attack that would wipe out data when infected .
Besides leaked movies, Sony Pictures also lost information related to emails and casting details of yet to be produced motion pictures

The movie, The Interview, slated for a Dec 25 release, featured a plot to assassinate Kim Jong Un, the supreme leader of the DPRK, leading to speculation that hackers from North Korea may have been responsible for the incident.
 

Wednesday, October 29, 2014

Digital wallet ......a boon for e shoppers and online merchants.



Digital wallet: A step towards reduced financial fraud risk?

 

 

Updated Oct 29th, 2014..http://www.cysectips.blogspot.in

We started trading as homo-sapiens, using surplus items to barter for things we require. It then graduated to introducing a form of currency with fixed values predefined to be paid in lieu of an item being purchased.

Slowly but surely the present day currency started formulating. It moved from metal currency to paper currency to plastic currency, as and when the technology changed and demands and desires of th Man increased.

Now with #online frauds and #cybercrimes threatening banks and individuals alike, involving skimming money out if accounts by stealing credit card details and online banking credentials, the use of #DigitalWallet has provided an alternate and relatively secure medium to transact online.

The #DigitalWallet requires one to setup an account with one of the #DigiWallet service providers/apps, register with them and keep topping up periodically as per your shopping requirement.

 

Advantages:

·         No physical carrying of plastic card.

·         Minimal exposure risk due to non filling of card or account details like credit or debit card.

·         Transactions can be carried out via apps or internet or sms in case of limited connectivity..

·         One can keep track on spending by setting up limits.

·         Can track the expenditure and items purchased list.

·         Being a new service, a lot of discounts are on offer.

·         Only login-id required to make transaction. Thus very easy and user friendly.

Limitations:

·         Limited number of merchants as on date provide this facility.

·         limits to national boundaries. International purchases not yet possible.

·         If your phone is lost then very high risk of fraud and you are not covered under money back if a transaction is made.

Available options In India:

·         Paytm....lots of online offers.

·         Ruplee..for payment at restaurants.

·         Oxi-wallet...can pay bills, recharge mobiles, dth etc

 


https://www.evernote.com/shard/s376/sh/fb94f679-c838-4d62-bba0-7185028bcb41/1eba5ac184e6a99f7c99e7f5fac08c8d

Saturday, September 27, 2014

Russia wants Twitter and Facebook to store the data in local servers

  • It has always been a bone of contention between the social networking sites Facebook and Twitter, who are having their servers in US, for installing local servers by many countries like China, Russia and India,
  • In their efforts only China have  been successful, forcing US based social networking sites  to have local data servers for sifting of all online activities of their citizen.
"Back in July, Vladimir Putin signed a law requiring all web services handling Russians’ personal data to store that information in local data centers. It was always obvious that this would be a problem for the likes of Google, Facebook and Twitter, which do not use Russian data centers – and so, it has come to pass." Source: http://www.gigaom.com
  • This may be seen as an aftermath of Russian interference in Ukraine. However in general it is being viewed as attack on freedom of speech
  • Read full article at http://goo.gl/UqDArl

Saturday, August 16, 2014

You are Being Tracked and Yes ! YOU have agreed to it!!!!!!!


  1. Recent years have seen uncovering of many secret projects, government sponsored, wherein unsuspected users of Internet have been subject to monitoring of their activities without even being aware of. 
  2. Neither the permission nor willingness or permission of all those subjected to monitoring were sought. they were also not informed of it.PRISM, Snowden, Wikileaks etc may not be a strange name now.
  3. However Are You aware that at times "YOU ARE APPROVING THE TRACKING OF YOUR MOVEMENT "
  4. Yes you read it correctly, but HOW.
    • Here's How! When you log into your account through mobile/smart phone, you are asked to accept "track My Location". By using this the Google Maps keep on putting blips for every movement and keep track of it.
    • Secondly Track my location is also utilised by most of the users to locate nearest available Store, Cinema houses, Bus Stations, Restaurants etc. This way you get the information of your locality. BUT you have also given away your location.
    • Check this web sit out for proof of it!
http://junkee.com/google-maps-has-been-tracking-your-every-move-and-theres-a-website-to-prove-it/39639

Proud Blogger

Powered By Blogger