29 February 2012

Government, business, military are internet security threats


Usually the bĂȘte noire of the annual RSA conference is the criminal hacking community, but security guru Bruce Schneier asserts that government, business, and the military may well pose a bigger threat to security professionals.

"The current risks to internet freedom, openness, and innovation don't come from the bad guys – they are political and technical".
Attempts at ill-conceived legislation are a major concern. Outsiders trying to legislate something they have no understanding of (a "series of tubes", anyone?) has led to some very troubling moves on behalf of government on internet security. Sometimes these laws are brought forward for the best of intentions – however misguided – but all too often they are merely the result of lobbying.

The temporary suspension of SOPA/PIPA was a case in point, he said. The laws were not a good idea, but didn’t fail for that reason – and no politician wants to be seen as soft on crime he pointed out. The success of the campaign had nothing to do with Wikipedia going dark and everything to do with Google and others using their own lobbying bodies against it.

Law enforcement was another example of government interference that Schneier highlighted..........

Click here to read more .... 

Solutions : www.xcyss.in

28 February 2012

Scammers "Phishing" For Credit Card Security Numbers


Scammers are trolling the waters for your credit card information, using a new "phishing" scam that's targeting the trust of credit card users.
The scammer poses as a representative asking if there have been any purchases or changes to your account.
If you say no then asks you to repeat the credit card number and the three number security number. Chances are they already have your information, but need the three digit code to make a purchase.

Click here to read more .... 

Solutions : www.xcyss.in

Government to set up agency to scan tweets, emails and updates


The government is setting up an internet scanning agency which will seek to monitor all web traffic passing through internet service providers in the country. The scanning agency to be called National Cyber Coordination Centre (NCCC), will issue 'actionable alerts' to government departments in cases of perceived security threats. 

The move comes as the government has been unable to prevent many terror attacks, in the absence of a credible internet scanning system. All government departments will now talk to the Internet Service Providers such as Bharti Airtel, RCOM, BSNL,MTNL and Tata Communications through NCCC for real time information and data on threats. 


All tweets, messages, emails, status updates and even email drafts will now pass through the new scanning centre. The centre may probe further into any email or social media account if it finds a perceived threat. 
Click here to read more .... 

Solutions : www.xcyss.in

27 February 2012

Many parents unaware of cyberbullying


Many U.S. parents are clueless about cyberbullying when it comes to their own child, a survey indicates. 

Parents might not know about bullying incidents because their children conduct social networking activities in a number of different locations, using a wide variety of devices, and across a broad range of media platforms. 

Although many parents said they think their children will tell them about cyberbullying, but they don’t,  because they are usually: 

– Embarrassed about the situation.

– They’re afraid of backlash from the bully or others.

– They fear losing access to their computer.

– They’re worried they did something wrong.

Click here to read more ....

Solutions : www.xcyss.in

Student jailed for "extensive" Facebook hack

A British student Glenn Mangham, 26, a software development student, who hacked into Facebook's internal network risking "disastrous" consequences for the website, was jailed for eight months on Friday in what prosecutors described as the most serious case of its kind they had seen. This was the most extensive and flagrant incidence of social media hacking to be brought before British courts.



Mangham said he had previously helped search engine Yahoo Inc improve its security and wanted to do the same for Facebook. However, prosecutors rejected his explanation.

Click here to read more .... 

Solutions : www.xcyss.in

WikiLeaks publishes security think tank emails


* Stratfor has been likened to a shadow CIA
* Company defiant, says it will not be cowed
* "Anonymous" hacker group helped obtain data
* Stratfor says some emails may be forged, altered
The anti-secrecy group WikiLeaks began publishing on Monday more than five million emails from a U.S.-based global security analysis company that has been likened to a shadow CIA.
The emails, snatched by hackers, could unmask sensitive sources and throw light on the murky world of intelligence-gathering by the company known as Stratfor, which counts Fortune 500 companies among its subscribers.

Click here to read more .... 

Solutions : www.xcyss.in

22 February 2012

Satellite phone encryption cracked by German researchers

German researchers Benedikt Driessen and Ralf Hund of Ruhr University in the paper titled Don't Trust Satellite Phones claim they have found weaknesses in two commonly-used satellite encryption protocols that could render them vulnerable to eavesdropping in real time. They also describe how they reverse engineered the GMR-1 and GMR-2 encryption algorithms or stream ciphers used to secure voice traffic on a range of commercial satellite networks.

The pair attacked different digital signal processor (DSP) firmware updates for two handsets, Thuraya’s GMR-1-based SO-2510, and Inmarsat’s GMR-2 IsatPhonePro, extracting the encryption keys used to secure communications in half an hour using a $2,000 setup.
...
This theoretical attack is mainly for commercial users who don’t employ extra security and ETSI, the standards body that looks after GMR-1 and 2.

Read the research paper's abstract from here: 


Solutions : www.xcyss.in

17 February 2012

Cyber ​​Security is like chess

KPN's announcement that a server containing personal data of customers and businesses is hacked is just one example of the continuous threat from cyberspace. Over the past year, there are several examples to show where the security of prominent business and government was broken, where there is often data was stolen.
  • The boundaries of the corporate network fade, for example by the use of multiple devices (PCs, laptops, tablets and mobile phones) are not all by the company itself are provided and managed (Research IDC and BT Benelux: 'mobility biggest concern for Dutch CIOs' ) - but still connected to the corporate network via the cellular or Wi-Fi network.
  • The movement toward cloud-based services. Not only is 'the cloud' in principle accessible anywhere, introducing cloud-based solutions, often centralizing data result.
  • IT departments have no time, budget or manpower to protect all systems. Often also lacks awareness of the risks and thus support at board level.
  • Data, including e-mail is often not encrypted. 
  • It contains all the software code errors, and this will never change. 
You can compare it to chess, it is important to think ahead and to each time the opponent makes a move, to block it. This can be done with so-called 'ethical hackers', who think and act as hackers, and also make use of the latest resources available to hackers. However, they do not go beyond reporting the problems they discover - and so strive to be one step ahead of cyber crime. But even a master chess player loses the occasional party.
Click here to read more ....

Solutions : www.xcyss.in

DDoS Attackers Start Targeting IPv6 Networks


Cybercriminals have started launching distributed denial-of-service (DDoS) attacks against networks that transmit data over IPv6 (Internet Protocol version 6), according to a reportpublished recently by DDoS mitigation vendor Arbor Networks.
Even though 2011 was the first year when IPv6 DDoS attacks were recorded, such incidents remain rare because they are not economically relevant for Internet criminals.
Some companies have projected increases of more than 100 percent for their IPv6 traffic volumes over the next 12 months, but the changes will be insignificant compared to the overall traffic volume.
The majority of organizations remain reluctant to switch to the new IP protocol version because their existent network security and traffic analysis equipment is not fully compatible with it.
Many infrastructure solutions currently do not offer the same features and functionality for IPv6 as they do for IPv4. This lack of feature parity means that security teams do not have the same visibility and mitigation capabilities when trying to identify and block IPv6-based attacks against targets.
Solutions : www.xcyss.in

Identity theft, phishing top tax scams in U.S.


Identity theft and phishing top the federal U.S. tax service's list of "dirty dozen" scams, which tend to peak this time of year as millions of Americans gear up to file their tax returns.
While the "dirty dozen" schemes are common year round, many occur most frequently during tax filing season.
Identity theft occurs when thieves use a taxpayer's identity and personal information to file a tax return and claim a fraudulent refund.
Phishing is usually carried out through an unsolicited email or a fake website to lure potential victims and prompt them to provide personal and financial information..........

Click here to read more .... 

Solutions : www.xcyss.in

Five arrested on cyberbullying charges

Two men, a woman and one juvenile were arrested Thursday on cyberbullying charges by Port 
Barre Police. 

The arrests are the result of an investigation initiated more than a month ago, when Terry Mudge
 filed a complaint with the police department stating that her 15-year-old son, Spencer, had been
physically attacked at Port Barre High School and verbally threatened through Facebook.

The threats began shortly after Spencer had posted a comment on Facebook regarding 
15-year-old Eric Myers, who died Dec. 29 of an accidental self-inflicted gunshot wound.
Click here to read more .... 

Solutions : www.xcyss.in

15 February 2012

Man Jailed For Grooming Teen


An illegal immigrant has been jailed for three years for grooming a Harpenden 13 year old.
Ismail Kiggundu, 29, of Commonside East, Mitcham, encouraged the teenager to send him naked photographs of herself and persuaded her to travel from her home to his room in Surrey to have sex. 
He met her through an over 18s dating site called Tagged, where he told her he was 19. 
Even though he knew she was under-age he continued the relationship and encouraged her to bunk off school to see him. 

Click here to read more ....

Solutions : www.xcyss.in

Angry with heavy homework, Chinese student hacks govt website

In his bid to highlight his frustration due to excessive homework, a Chinese teenager hacked a government education website. 

The hacker left messages on the webpage, complaining that his school gave students homework that was "suffocating" during the winter vacation. Experts have identified the hacker as an eight-grade boy from a middle school in the district.


Click here to read more .... 

Solutions : www.xcyss.in

B’desh group hacks BSF site to ‘avenge border killings’


A group of Bangladeshi hackers have breached thousands of Indian websites, including that of the Border Security Force (BSF) and the Trinamool Congress. The attack came within hours of a Bangladeshi newspaper reporting that some Indian hackers had destroyed at least five of their government sites. 
    Simultaneously, Pakistan hackers gained access to about 2,000 Indian sites, claiming their object was “to hit Indian cyber fence and to defend Bangladeshi hackers in this ongoing cyber war”. Another hacker consortium hacked into more than 700 Indian websites. 


Click here to read more .... 

Solutions : www.xcyss.in

13 February 2012

Hacker group attacks five Bangladesh official government websites

Hacking has always been the top most problem over internet and this time hackers, claiming to be Indians have attacked five official ministries websites of Bangladesh as well as that of a trade organisation. Websites were of the ministries of communications, youth and sports, primary and mass education, education and posts and telecommunications.


The sites went black and displayed the message: "Hacked by Love the Risk, Amal Landhe, Lnx Root, Silent Killer."

In between two eyes resembling Indian flags, the hackers wrote: "We have an EYE on you."

While, the name of the hacker group named "Indian Cyber Army" was also displayed over the website. 

Click here to read more .... 

Solutions : www.xcyss.in

CIA website hacked

Hacker group Anonymous Friday night took down the website of the Central Intelligence Agency (CIA).

"CIA TANGO DOWN: https://www.cia.gov/ #Anonymous," the hacker group wrote on Twitter.

Anonymous did not make public any details about the hacking, but the group's hackers normally use distributed denial of service (DDoS) attacks to knock their targets offline.
Click here to read more .... 

Solutions : www.xcyss.in

Microsoft's India store hacked, usernames & passwords stolen

Hackers, allegedly belonging to a Chinese group called Evil Shadow Team, struck at www.microsoftstore.co.in on Sunday night, stealing login ids and passwords of people who had used the website for shopping Microsoftproducts.

While it is troublesome that hackers were able to breach security at a website owned by one of the biggest IT companies in the world, it is more alarming that user details - login ids and passwords - were reportedly stored in plain text file, without any encryption......

Click here to read more ....

Solutions : www.xcyss.in

10 February 2012

Man arrested in online sexting sting


A Bayonne man who was near the end of the hiring process to become a substitute teacher for Rutherford High School was arrested Wednesday by the Passaic County Sheriff's Department on charges of attempted sexual assault of a minor.
24-year-old Richard D'Amato Jr. was arrested as part of an online sting in which he is alleged to have sent explicit messages to an officer who posed as a 12-year-old girl.

Click here to read more .... 

Solutions : www.xcyss.in

Spammers dangle the V-Day bait


Anita Aggarwal, 21, found an alluring offer on her FB account: a perfect gift for her fiancé. Excited about the gift, she filled in the application sharing all her information including her personal id. Soon Anita realised that her email id had been hacked.


With Valentine’s Day just a few days away, it is not surprising if you have already started receiving mails and enticing messages on your Facebook pages which include big discounts on jewellery, food and even slimming products. However, these are tricks with a target — to infect computers, and steal personal details.


Spam companies have also come across Facebook page-based attacks centring around Valentine’s Day. Users are asked to post a Valentine’s theme in their Facebook profile from where they are redirected to another website which asks users to download the theme which is a fake website. On installing the theme, cyber criminals can access your personal information and data on your personal PC’s and Computers.

Click here to read more .... 

Solutions : www.xcyss.in