IT EXPLORIDA

Something To know

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Friday, 4 July 2014

HijackRat Threatens Mobile Banking

HijackRat is a new malware which infects Android supported devices. The aim of this bank trojan is to steal information from victimized devices and use it for bank frauds. The trojan is capable of performing the following tasks:

  • Stealing data

  • Stealing bank credentials

  • Spoofing


The earlier versions of such malware were capable of achieving only one of the above goals. HijackRat, on the other hand, can accomplish all of these tasks.

Features of HijackRat

If an Android smartphone or tablet has been infected by HikackRat, the malware will carry out the following activities.

  • Stealing and automatically sending text messages

  • Disabling any antivirus software or mobile security app which may be installed on the infected Android device

  • Malicious applications will start updating automatically

  • Stealing contacts

  • Replacing legitimate banking apps installed on the compromised device with fake utilities.


Currently, the bank trojan has been victimizing several banks in Korea. It can easily be used by cybercriminals to target financial institutes in Europe as well.

Possible Preventive Measures

The most obvious measures which can prevent HijackRat’s infection is the installation of an anti-malware program. However, Google claims that no such protection is required. Firstly, mobile devices can still fall prey to the malware despite antivirus protection. Secondly, Google says that every new app is checked before it can find its way into Play Store. However, despite these claims, a number of malicious software is still lurking around in Google’s app store. This makes Android users worried.

Solution

A device which has been compromised due to HijackRat can be fixed by taking away its administrative rights. In fact, users should always be cautions before giving permission to apps before downloading them. Permission to have access to contacts and your SMS means this information can be stolen. Therefore, every Android user must be cautious.

Microsoft Improves Encryption for Better Protection

The United States has been notorious for spying around, threatening the privacy of internet users all over the world. Google and Yahoo came up with a solution to offer the maximum amount of privacy for their services. This was accomplished by means of improved encryption. Now Microsoft follows in the footsteps of Google and Yahoo by doing the same. Encryption has been enhanced for Web Outlook as well as OneDrive cloud storage.

How does it Work

There is a large amount of information and data which is not safe to be transferred across the internet. However, data encryption provides protection to a large extent. When you send your information or data through an email or by filling out a form, the information is coded. It de-coded only at the receiving end. Microsoft has used different encryption techniques in order to ensure the maximum amount of protections for individuals around the globe who use Outlook or OneDrive. So, whether you are sending an email through Outlook or saving important files in OnceDrive cloud storage, your information and data will remain safe from prying eyes.

The Advantages

As data encryption keeps your information hidden in the form of a code, no third parties can have access to it. These third parties may be prying government agencies or cybercriminals who want to steal your sensitive information for the purpose of identity theft. Therefore, through improved encryption, Microsoft offers better protection to its users who would now feel more comfortable using these services.

Banking Trojan Cridex Appears in a New Form

There is now a new variant of the notorious Cridex banking trojan. Formerly known as Cridex, Feodo or Bugat, the new version of the malicious trojan is now referred to as Geodo. It is accompanied by a worm. Both work together to spread the infection to other systems. It infects Windows based devices and steals information for bank crimes.

Features of the New Cridex

The new Cridex, or Geodo, has come out with an enhanced feature which is important to achieve the goal which cybercriminals want. This feature allows the malware to spread itself on its own. The malware and its accompanying worm work together to send mails automatically from the compromised Windows systems to others. This malware can also be transformed from removable drives, such as USB flash drives. In addition, downloading a file from a malicious website can also download the malware to your Windows system. In this way, this banking trojan can easily infect more and more systems and get access to the banking information of various individuals.

Prevention

As new versions of malware keep coming up, most anti-virus programs fail to offer the necessary protection unless the anti-virus is update on regular basis. The best way to take preventive measures is by avoiding to connect removable drives to your system. Such drives travel around from one system to another and there is a high chance that they contain malicious applications.

In addition, avoid visiting untrustworthy websites and do not download any file from such websites at all costs.

Saturday, 28 June 2014

Breaking : Ptcl.com.pk HACKED BY SULTAN and MAKMAN

One of the Top telecom company PTCL(http://ptcl.com.pk) in Pakistan Hacked by Pakistani Hacker just because of Revising the packages by decreasing the downloading volume for consumers this is 3rd time downgrading the Packages in a last few months.

 

Tuesday, 24 June 2014

Google’s BoringSSL – A Safer Alternative to OpenSSL

Google’s BoringSSL is going to replace OpenSSL encryption protocol for tighter security and greater ease of use. Currently, OpenSSL is used by a number of social networking websites, search engines, websites of banks and other organizations for a secure transfer of data. However, the latest Heartbleed bug made OpenSSL vulnerable to cyber attacks. Therefore, Google came up with a safer encryption protocol which is known as the BoringSSL.

Heartbleed bug is a serious threat to the security offered by websites for data transfer. Attackers can target the servers of banks and other important organizations. Parts of the memory of the victimized server can then be read by the attackers. In this way, important information is revealed to them which can be used for bigger crimes, such as identity theft. No wonder, Heartbleed bug has left sensitive organizations feeling terrorized. Google’s BoringSSL has, therefore, come to the rescue.

At present, Google is using OpenSSL for Chrome as well as Android. The open source encryption protocol has been modified differently for different Google products. However, now the company is going to change over to its new encryption protocol for all products.

Just a few weeks after the breakout of Heartbleed bug, another encryption protocol had also been developed by OpenBSD Foundation. It is known as LibreSSL and is more secure than OpenSSL. Apart from Google’s own project, it will also be making contributions to OpenBSD. This will help bring improvements to OpenSSL which is still preferred by many independent developers and is currently being used by many existing websites.

Hong Kong’s Polling Website Sustains an Enormous DDoS Attack

Cyber criminals are wreaking havoc in the world of internet. Their power is growing every day, causing bigger problems to companies and government organizations. Recently, the largest ever DDoS attack to be experienced in the history of the World Wide Web has been incurred on Hong Kong’s Democracy website. It is being difficult to get rid of the malice owing to its extremity.

DDoS is short for Distributed Denial of Service. In this type of attack, a network of computers around the world is used. The owners of the compromised users are unaware about the fact that their machines are being manipulated to be used for cybercrime.

The DDoS attack made on Hong Kong’s Democracy voting website has been made using the largest network of comprised computers ever. It has affected the results of the mock online elections. The attack was made right on the first day when the polling began. A huge traffic is being diverted towards the website by the cybercriminals who are behind this attack. To be specific, there is a load of 300 gigabits per second on the website. One such big DDoS attack was made last year on the website of an NGO called Spamhaus.

CloudFare is a company based in San Francisco which is maintaining this voting website for Hong Kong. Mathew Prince, the CEO of CloudFare has reported the DDoS to be one of the biggest as well as the most persistent of such attacks. His Twitter status says he is busy fighting against the huge attack.

FBI and NYPD Join Forces to Take Down Hackers

Law enforcement agencies in the United States have set out to fight against cybercrime in the most effective way possible. Two of the most powerful US agencies, The FBI and NYPD, have combined their forces for this purpose. Both the organizations will use their power and authority to take down hackers in the US as well as other parts around the region.

Hackers pose a serious problem to the security of individuals as well as bigger organizations and even whole countries. Hacking leads to serious issues ranging from stealing of sensitive information and identity theft to bigger instances of terrorism around the world. Important government websites of the United States as well as the defense sector is constantly victimized by cyber attacks at a rate of 110,000 attacks in one hour. Therefore, the FBI and NYPD have set out to track illegal activities on the internet and take down hackers.

Apart from NYPD, the agents of the Federal Bureau of Investigation will also seek the help of the Metropolitan Transportation Authority to track activities related to cyber crime. In addition, a New York based team of forty-five members has been established in different parts of the country. The goal of the team is to deal with the issue of the ever growing cybercrimes. This involves keeping an eye on online activities of different individuals in the region.

Currently, no statement has been released by the FBI about further details of the project. It is also no known whether the internet monitoring will be confined to the US or to other parts of the world as well.

Monday, 2 June 2014

Info: .HTACCESS AND ROBOTS.TXT How Valuable these two files are?

Tiny little files have huge contribution towards your website existence. The more tiny they are in size the more powerful features they have.

But one should now play with these files without experience; especially when it comes to RegEx. these files can expose your server to the security threats, can restrict the Search engine Bots. even can impact the accessibility of website to the surfers.

When ever you make a change to these files. Test it again and again at different times and clearing your browser cache. Do NOT trust other people experience shared on the net.

Think Smart, Be Professional.
Awesome Inc. theme. Powered by Blogger.