Showing posts with label Security Tutorials. Show all posts
Showing posts with label Security Tutorials. Show all posts

Monday, April 21, 2014

WARNING! Your Flash Player may be out of date.

Adobe Flash Malware driven by infected "Router" The Moon Malware

Few days ago, I started to receive a pop-message "WARNING! Your Flash Player may be out of date". Please update to Continue., when I was trying to access websites like Facebook, YouTube, Google, etc.

If you're receiving a similar message then continue to read but make sure you don't click on anything nor try to update the flash player from the pop-window. You may check your current version of the "Adobe Flash Player" by visiting "Adobe" official website. If you're using Google Chrome browser, it already includes Adobe Flash Player built-in. Google Chrome will automatically update when new versions of Flash Player are available.

You will also notice that the same message is poping-up on all the devices which are connected to the same router (mobile phones, laptops etc.).



Now even the dumbest person should know it is not coming from computer but from the network which means your router is infected. It's commonly happening with Linksys, Asus and few other manufacturers.

How to fix this?

  • Reset your router (by holding down the reset button under the router for 6 seconds). Note after restart all your ISP settings will be lost.
  • Configure your router again with the ISP settings (username and password also required).
  • Clear your browsers cache and pop-up message will not appear again.
Refer here for some basic tips on hardening your router to avoid such things happening again.

Thursday, November 8, 2012

How to crack/reset your Windows account?

Have you lost or forgotten your Windows password?

It's one of the security best practice to enable password on your Windows user account to ensure you have adequate protection from malicious access to your personal files. 

It is a common practice to forget your computer password if you're not using it for a while or perhaps just returned from holidays. Unfortunately, currently Windows operating systems doesn't have an option to reset your password like we commonly see in web applications such as Facebook, Hotmail etc.

In the majority of the cases, I have seen users have to format and reinstall the Windows to access their computer again but unfortunately they have to sacrifice  loss of their personal data if they haven't backed-up.

So what to do? How to crack/reset the password of the Windows operating system?

I recently come across this nice password resetter tool "Password Resetter", which cracks windows password in minutes without affecting your personal data.

As stated on their website that it can recover 99,9% of passwords from nearly any Windows installation in a matter of seconds! You do not need to remember old passwords in order to crack your Windows password.

Password Resetter recovers the lost Windows administrator or user password from any Windows Operation System. It supports Windows Vista, XP, NT, 2000 and the newest Windows 7.

How to use Password Resetter?

1) Download a copy of Password Resetter.

2) Burn the image on CD/DVD. The package comes with the detailed tutorial.

3) Once the bootable CD/DVD is ready, boot the system with this CD/DVD. Select the user account and then click on reset button.



Another cool feature?

It supports USB, which means you can crack/reset your Windows password with USB drives in case you do not have CD/DVD.  

This is not a freeware, you will need to purchase this software for around $35 for personal use.

Monday, March 26, 2012

How to develop effective Information Security Awareness Program?

Security Awareness Training Topics

Security Awareness is a key challenge in Implementing information security. Many organizations find it difficult to provide the right information security awareness to its staff and thus have less support from its staff in implementing the information security measures.

It is important to tailor the security awareness program to cover the potential threats and risks of the organization.

The first item in the security awareness should be about the password security. The password security awareness should cover topics such as:
  • What is the password policy of the organization

  • How to build secure but easy to passwords in compliance with the password policy

  • Possible tools for password storage and how to use them securely

  • Now writing down of passwords in excel or paper or sickies

  • How the Password sharing is dangerous to the staff in specific and the organization in general
Keeping the work place clean or Clean Desk Policy. This should include topics like:
  • Importance of having a clean workplace from a security perspective

  • Potential confidentiality issues when the critical documents are in the eyes of those who are not supposed to have access

  • Importance of shredding of documents when they are no more required

  • Keeping the printer and fax trays empty all the time
Information Handling and Classification

Classification guidelines and information on how to handle the information should be part of this discussion. this should cover topics such as:
  • Classification labels and when and how to use them

  • Precautions to take when sending or receiving such information
Physical Security

Visitor Control is another area, which can be part of information security awareness. Checkout this cartoon on Physical & Information Security Awareness, it can be part of the security awareness materials.

Key things include (1) questioning the visitors without a badge or who looks suspicious (2) accompanying the visitors to confidential areas such as datacentre (3) about piggybacking etc…

Another Physical Security control is about the protection of laptops and other mobile computing devices. It is often the laptops, smart phones, or removable devices which are getting lost. Protection of these devices are critical in information security. Many times we have heard about data leakage through lost or stolen devices

Another key area to include is Incident Reporting and Management. This should cover the types of incidents to be reported, whom to be reported, means of reporting etc…

Phishing & Social Engineering is another key topic which can be included. This will help the staff not to become a victim of such attacks by malicious internal or external entities. Cover the possibility of email and phone channels for social engineering.

Social Networking and its threats are another set of topic which can be covered within the security awareness session. Topics like what to post in the social media and what not, who represents the company in social media and things like that.
Bring Your Own Device or BYOD and use of the personal device usage within the organization. What are the restriction related to BYOD including the removable media

Acceptable use of the IT environment such as Internet and Email, Desktop systems etc…

Desktop security including the use of antivirus, locking or logging of the system when not in use.

Importance of data backups. Corporate process on backups. Is it allowed to backup only to the file servers? Or can the user backup to a USB or CD.

Critical Success Factors of an Information Security Awareness session
  • Engaging with the staff interactively

  • Quoting real life examples. It would be helpful to include News items on related contents

  • Having good humour included in the topics

  • References to the corporate security policies is a key item to be included in the related topics

  • Choose the right topics for the right group of audience. Social engineering, desktop security etc might be a topic for all groups.

    Your board members or senior management may not want to undergo one hour awareness sessions and thus, the topics should be carefully opted when designing the materials for them

  • Have a test or a quiz at the end of the session. It will give an opportunity to understand the effectiveness of the awareness sessions
The above list gives a number of topics useful for a typical information security awareness session.

Friday, February 24, 2012

Intrusion Detection for Embedded Control Systems

Digital Bond's SCADA Security Scientific Symposium (S4)

S4 did include one paper from academia, IDS for Embedded Control Systems presented by Jason Reeves of Dartmouth College and the TCIPG effort. Jason and a TCIPG team had previously developed a research product called Autoscopy and have recently enhanced it in Autoscopy Jr.

The primary purpose of Autoscopy Jr. is to detect rootkits on embedded control systems while limiting the overhead to less than 5%. The primary method is to monitor the sequence of executed instructions in a learning phase and then detect behavior that is indicative of rootkits. Jason refers to it as something akin to function level whitelisting.


It’s a detailed technical talk worth watching if you are interested in the future of IDS in PLC’s, RTU’s and other field devices. The performance testing showed it was under the 5% threshold and there were ways to improve the performance further by identifying the most resource intensive Kprobes.

The effectiveness is an open question. The team did test this against 15 rootkits that attempted control flow hijacking, but there was not a set of real world embedded system rootkits to test against.

Refer here to watch the presentation video.

Monday, February 20, 2012

Learn the process of documentation writing to implement ISO 27001

ISO 27001 Video Tutorials

One of the biggest obstacles for companies starting to implement ISO 27001 is writing various documents required by this information security standard.

Information Security & Business Continuity Academy has launched ISO 27001 Video Tutorials, a new product that facilitates the process of documentation writing.

According to ISO Survey of Certifications published by the International Organization for Standardization (ISO), ISO 27001 is within the 5 most popular management standards, and is also one of the standards with the highest growth in the number of certified companies – about 20% annually.

However, the fact that a large percentage of companies that have started to implement this standard never finish the job is less known. The reason for failure is very often insufficient time or lack of knowledge for writing the documentation – ISO 27001 has very specific requirements about how the documentation should look like.

At the moment 13 video tutorials are available, and each month 2 new tutorials will be published. A total of 50 video tutorials are planned, which will cover all the steps in ISO 27001 implementation – from setting up the project all through successful certification.

Dejan Kosutic, the author of the video tutorials said:
"I've worked with quite many companies as a consultant, and most of those companies struggle with the same thing – how to fill in the documentation. I believe these video tutorials will increase the success rate of ISO 27001 projects by at least 25%, and increase the speed of implementation by 50%".

Thursday, January 5, 2012

How Developers Can Secure their Code?

5 Application Security Tips

Over the last 30 years, many organizations have done an amazing job of automating their business, resulting in productivity gains, efficiencies and innovations.

Unfortunately, the threat landscape has changed dramatically during this time. A lot of that application code, written without security in mind decades ago, is still the heart-and-soul of many enterprises. That code was designed for a world where computers could not be accessed remotely.

Since then, it has been wrapped, integrated, connected, ported, and most importantly, exposed. That application code is not strong enough to withstand today's threat.

OWASP has a number of free and open-source resources that developers can use right now to help secure their code.

5 Tips for Developers

Start with the OWASP Top Ten
- This awareness document will help you understand, identify, and fix the most critical application security risks quickly.

Get hands-on with WebGoat - WebGoat is a deliberately flawed application that is riddled with holes to give people the opportunity for hands-on learning. It is open-sourced to help developers and security testers get experience with real vulnerabilities.

Leverage the OWASP Cheat Sheets - This is a fantastic series from leading experts globally. Let me know what you think of the Cross-Site Scripting Prevention Cheat Sheet, one of OWASP's most popular pages.

Verify Your Applications - There is no substitute for getting real facts about the security of your application portfolio. OWASP Application Security Verification Standard helps developers get started scanning, testing and code reviewing with tools like OWASP Zap and CSRFTester.

Get Training - Perhaps the hardest thing about application security is that there are so many different ways that software can fail, particularly when it's targeted by a motivated attacker. The key is training to get started with securing applications quickly.

If instructor-led training isn't possible, eLearning solutions are available to allow developers to learn on-demand and get hands-on, practical experience with vulnerabilities, security controls and real code. Training is a remarkably effective way to reduce vulnerabilities.

Before you trust your business to application software, make certain that the people who are writing your code know how to defend your business and its assets. It's time to learn.

Friday, December 16, 2011

What does it really take to exploit a printer?

Printer Hack: Researchers Can Set Media’s Pants on Fire

In the past couple of weeks, there has been quite a bit of press and blogging about a security vulnerability in HP printers that was discovered by researchers in the Intrusion Detection Lab at Columbia University.

In a nutshell, the researchers found a way to replace the operating firmware on an HP printer with firmware of their own design that can do bad things, and they also found a way to do it to a printer that is on a private network behind a firewall.

MSNBC ran an “exclusive” story about it calling it a “devastating attack” to which “millions of printers” could be subjected. Its lede suggested that hackers could cause the printer to catch fire, or be used for identity theft, or be used to take control of entire networks.

In practice, this isn’t an easy vulnerability to exploit on a large scale.

Let me explain:

First, you need to target a printer that supports PJL and its largely undocumented remote firmware update (RFU) function. Many printers support PJL, but RFU is less commonly supported. Many printers don’t have any mechanism for remote updates, and many others use something other than PJL’s RFU function for remote updates.

Once you've found a printer that supports PJL and its RFU function, you'll need to make sure that it will apply a firmware update without checking its authenticity. I can’t speak for other manufacturers, but my employer’s products have been using digital signature verification for firmware updates for at least the seven plus years that I have worked for them.

Next, you need to be able to create new firmware to do your bidding. To do that, you need to know what is the manufacturer and model of your target. The researchers demonstrated exploitation of a victim’s printer that was on a private, firewalled network, but didn’t mention how they determined which make and model of printer would be used by a particular victim. They would need to know that in order to send the correct firmware image to the victim.

And then there is the matter of reverse-engineering printer firmware. It is certainly possible, but not very practical when you consider that there are thousands of different printer models to contend with.

The researchers say that “rewriting the printer’s firmware takes only about 30 seconds”, but they are referring to the time it takes for the printer to update its flash memory and not how long it takes for someone to reverse-engineer a printer to do something malevolently useful.

Next, you need to get the victim to print a document that contains the firmware update code, and of course they need to print it on the printer that you targeted. I don’t know if it is possible to embed an RFU in a printable document in such a way that isn’t obvious when the document is viewed, as most people do before they print something. Perhaps they will disclose that detail at the Chaos conference.

Now, finally, you own the victim’s printer.

Saturday, May 7, 2011

Free On-Line CEH Course

Logical Security is providing 25 hours of free CEH on-line training

The video modules are outlined below and can be found here.

Hope you find them useful!

1. Ethical Hacking and Penetration Testing
2. Footprinting and Reconnaissance
3. TCP/IP Basics and Scanning
4. Enumeration and Verification
5. Hacking and Defending Wireless/Modems
6. Hacking and Defending Web Servers
7. Hacking and Defending Web Applications
8. Sniffers and Session Hijacking
9. Hacking and Defending Windows Systems
10. Hacking and Defending Unix Systems
11. Rootkits, Backdoors, Trojans and Tunnels
12. Denial of Service and Botnets
13. Automated Penetration Testing Tools
14. Intrusion Detection Systems
15. Firewalls
16. Honeypots and Honeynets
17. Ethics and Legal Issues

All videos can be viewed at
www.logicalsecurity.com/resources/resources_videos.html

Thursday, March 31, 2011

SC Magazine’s recent study of less-shouted-about THREATS

Risks and Rewards of Archiving!

Cloud and social media security are much discussed areas of focus within our profession but what about some of the less shouted-about threats? I thought you might be interested in SC Magazine’s recent study of some of these, which will be discussed in greater detail in 3 of their upcoming webcasts; found at http://www.scwebcasts.tv and http://www.scstudio.tv respectively.

Below is a little more info on the 3 topics to help you assess their relevance to your organisation:

STAMP OUT COSTLY SECURITY DEFECTS IN SOFTWARE DEVELOPMENT
Going live at 2pm GMT, 30th March


The Coverity Scan found an alarming 50,000 defects in just 300 open-source software products. This webcast will give you an instant understanding of the secure coding practices that you should adhere to to eliminate these increasingly costly security vulnerabilities.

Speakers: Robert Seacord, Secure Coding Director, CERT - Software Engineering Institute, Michael White, Technical Director, Coverity

You can secure your free place at: http://www.scwebcasts.tv

ARE RISKY APPLICATIONS UNDERMINING YOUR BUSINESS SECURITY?
Going live at 3pm GMT, 12th April

With 75% of new attacks (CERT) targeting applications and with the lines blurring between personal and business devices, this webcast will shed vital light on the real security repercussions of risky apps in the workplace and what you can do to secure them.

Speakers: Tim Mathias, Director of Security, Thomson Reuters Chris Wysopal, Co-founder & CTO, Veracode

You can secure your free place at: http://www.scwebcasts.tv

THE RISKS AND REWARDS OF ARCHIVING

This webvideo is live now on SC’s site at http://www.scstudio.tv

83% of the 200 IT professionals that SC spoke to (representing both SMEs and larger enterprises) reckoned the cost of email downtime to their business to be over $500,000. This interesting SC Studio show which you can watch right now at http://www.scstudio.tv , offers some interesting pointers on one of the most effective ways to reduce this risk/cost – archiving.

Speakers: Brian Shorten, Risk and Security Manager, Cancer Research UK Giovanni Alberici, Archiving & Continuity Specialist, Symantec.cloud

I hope the shows are relevant to your organisation. As always, do feel free to get in touch with any thoughts on these topics or ideas for future ones.

For the webcasts, if you can’t make the live date of the webcasts you can of course watch them live in the archive at your leisure at http://www.scwebcasts.tv. The studio show you can watch whenever you like at http://www.scstudio.tv .

Saturday, February 5, 2011

What is network Scanning?

Examine your Network With Nmap

Network scanning is an important part of network security that any system administrator must be comfortable with. Network scanning usally consists of a port scanner and vulnerability scanner.

Port scanner is a software that was designed to probe a server or host for open ports. This is
often used by administrators to verify security policies of their networks and can be used by an attacker to identify running services on a host with the view to compromise it. A port scan sends client requests to a server port addresses on a host for finding an active port. The design and operation of the Internet is based on TCP/IP. A port can have some behavior like below:
  • Open or Accepted: The host sent a reply indicating that a service is listening on the port.
  • Closed or Denied or Not Listening: The host sent a reply indicating that connections will be denied to the port.
  • Filtered, Dropped or Blocked: There was no reply from the host.
Port scanning has several types such as: TCP scanning, SYN scanning, UDP scanning, ACK scanning, Window scanning, FIN scanning, X-mas, Protocol scan, Proxy scan, Idle scan, CatSCAN, ICMP scan.

TCP scanning

The simplest port scanners use the operating system’s network functions and is generally the next option to go to when SYN is not a feasible option.

SYN scanning

SYN scan is another form of TCP scanning. Rather than use the operating system’s network functions, the port scanner generates raw IP packets itself, and monitors for responses. This scan type is also known as halfopen scanning, because it never actually opens a full TCP connection.

UDP scanning

UDP is a connectionless protocol so there is no equivalent to a TCP SYN packet. If a UDP packet is sent to a port that is not open, the system will respond with an ICMP port unreachable message. If a port is blocked by a firewall, this method will falsely report that the port is open. If the port unreachable message is blocked, all ports will appear open.

ACK scanning

This kind of scan does not exactly determine whether the port is open or closed, but whether the port is filtered or unfiltered. This kind of scan can be good when attempting to probe for the existence of a firewall and its rule sets.

FIN scanning

Usually, firewalls are blocking packets in the form of SYN packets. FIN packets are able to pass by firewalls with no modification to its purpose. Closed ports reply to a FIN packet with the appropriate RST packet, whereas open ports ignore the packet on hand.

Nmap support large number of this scanning. A vulnerability scanner is a computer program designed to assess computers, computer systems, networks or applications for weaknesses. It is important that the network administrator is familiar with these methods.

There are many types of software for scanning networks, some of this software is free and some are not, at Sectools you can find list of this software. The significant point about Nmap (Network Mapper) is Free and Open Source. Nmap is a security scanner originally written by Gordon Lyon (also known by his pseudonym Fyodor Vaskovich) for discover hosts and services on a computer network. Nmap runs on Linux, Microsoft Windows, Solaris, HP-UX and BSD variants (including Mac OS X), and also on AmigaOS and SGI IRIX.

Nmap includes the following features:
  • Host Discovery
  • Port Scanning
  • Version Detection
  • OS Detection
  • Scriptable interaction with the target
Nmap Works in two modes, in command line mode and GUI mode. Graphic version of Nmap is known as Zenmap. Official GUI for Nmap versions 2.2 to 4.22 are known as NmapFE, originally written by Zach Smith. For Nmap 4.50, NmapFE was replaced with Zenmap, a new graphical user interface based on UMIT, developed by Adriano Monteiro Marques. Working with Zenmap is easy and have a good environment for work.

Tuesday, January 18, 2011

Open WiFi and Firesheep

Hijack Facebook Using Firesheep

What’s new about Firesheep isn’t the exploit – HTTP session hijacking has been well known for years – it’s that Firesheep is a simple Firefox plug-in that is available to anyone and requires no technical expertise to utilize. In other words it allows anyone with Firefox and Firesheep to be a hacker. No experience required.

What’s the problem with unsecured WiFi?

If you connect to the internet at unsecured WiFi hotspots, like say your favorite coffee shop or book store, then you have always been at risk of the vulnerability exploited by Firesheep. So what exactly is this vulnerability?

This exploit is commonly referred to as HTTP session hijacking or side-jacking and, it’s been known and used by bad guys for a very long time. Up until now it required some modicum of expertise on the part of the hacker to accomplish a side-jacking attack. The attacker had to use a packet sniffer to capture all those packets flying around, decode the packets to find session cookies in the clear and then create spoofed session cookie responses to join your session. For experienced hackers this wasn’t terribly challenging since they usually had software that would automate the process.

Firesheep was developed for the express purpose of exposing the HTTP session hijacking problem to everybody on the internet, ostensibly to force sites like Facebook to quit making it so easy. This Firefox plugin is named for the notorious Blackhat Wall of Sheep where clueless, unsuspecting users’ unprotected private information is intercepted and displayed very publicly. If you are foolish enough to attend the Blackhat conference in Las Vegas without seriously locking down your communications you will end up on the Wall of Sheep where you will be mocked and worse by other participants.

Firesheep automates side-jacking attacks in a very simple way by building it all right in to your Firefox browser. Facebook advised checking their new Account Security Page, which gives you a history of sign-ins by IP address thereby letting you know if there are two IPs currently signed-in from the same access point.

Anti-Firesheep tools like Fireshepherd were released. Written by Gunnar Atli Sigurdsson, an electrical engineering student at the University of Iceland, Fireshepherd periodically jams the local wireless network with a string of junk characters intended to crash Firesheep when the snooping program reads them.

How can websites keep you secure over unsecured WiFi?

The vulnerability that is exploited by side-jacking has been well understood for years, so too has the solution / mitigation. Consequently your bank has been using this more secure mechanism for most of those years.

On Internet banking websites, an HTTP over SSL (HTTPS) connection is established before you send your credentials to the your bank’s web site. But note that after your credentials are validated, the secure HTTPS connection is maintained for the entire session. In other words once you establish that secure encrypted channel with your bank, everything for the entire session is protected. I know what you’re thinking now:

Why doesn’t Facebook, Twitter and Flickr do their sessions like this? Clearly they have the SSL capability because they use it for the logging in part of the session. It turns out that Eric Butler, the developer of Firesheep, was motivated by exactly these questions. Quoting from the announcement on his blog:

This is a widely known problem that has been talked about to death, yet very popular websites continue to fail at protecting their users. The only effective fix for this problem is full end-to-end encryption, known on the web as HTTPS or SSL.

There are several reasons that websites don’t use strictly HTTPS sessions. First, they want their sites to be accessible to the largest possible audience, including users of older mobile devices that may not support HTTPS connections. Second, there is a lot more overhead involved on both ends when everything is encrypted. Those are the main reasons, but I don’t mean to imply that they good reasons. The first reason may have been valid five years ago, but smart phones and other portable devices have come a long way in that time. The second reason may have been valid before broadband internet connections were ubiquitous, but certainly no one in a WiFi hotspot is connecting via a modem at 28K. Besides, it would be easy to keep the legacy mode connection for those few users who actually have old smart phones or dial-up connections. As always, the real reason is financial.

They would have to develop and roll out changes to not only the web servers but to all of those slick little apps that everybody is using. Remember the problems that Microsoft encountered when making Hotmail use fulltime HTTPS that were mentioned earlier.

What can you do to be secure over unsecured WiFi?

So while popular websites like Facebook are trying figure out how they can fix this problem with the smallest amount of effort, what can you and I do if we want to mess around on Facebook while enjoying a latte at our favorite coffee shop? There are several approaches you can take but the goal is to create a secure connection between your web browser and the insecure website. The best way to do this is to connect to a secure Virtual Private Network (VPN) and once that secure connection is established, surf wherever you like since the last hop on the journey to and from your web browser will be secure. This is great if you have access to a VPN like most road warriors use to connect to the office. Problem with that is that most businesses take a dim view of using VPN bandwidth and company resources to play around on Facebook.

You could install a VPN at home, but that is not an exercise for the fainthearted. There are some subscription based VPN services such as Hide My Ass (HMA http://hidemyass.com/ vpn/) that will provide a VPN to anyone for a fee. It’s not terribly expensive (1 month for around $12 US or a year for around $80 US) and is certainly easier than setting up your own VPN and way cheaper than getting fired for misusing the company VPN.

Finally there are browser add-ons that attempt to force HTTPS connections to sites that don’t offer them, like say Facebook, Twitter or Flickr. Unfortunately there are many websites where these just won’t work. Furthermore most of these add-ons are implemented as intrusive toolbars and egregious ad-ware.

Saturday, November 13, 2010

Android on the iPhone?

Install Android 2.2 on the iPhone 2G and 3G over WiFi

Hackers have come up with a way of rescuing Apple fanboys who have elderly versions of the iPhone.

For a while now Jobs' Mob has been forcing its long suffering customers to upgrade their 2G and 3G phones to the broken iPhone 4 by saddling them with an upgrade which made their gizmos slower. Now Redmond Pie has come up with a method of replacing iOS on iPhone 2G and 3G models with Android 2.2 Froyo without using any tools on a host computer.

The outfit had shown off an Android installation before. This involved running iPhoDroid on a host computer connected to a jailbroken iPhone 2G or 3G. This new process uses Bootlace 2.1 to install Android directly via WiFi. It works on iPhone 2Gs with iOS 3.1.2 and 3.1.3 and iPhone 3Gs with 3.1.2, 3.1.3, 4.0, 4.0.1, 4.0.2 and 4.1.

Refer here to read more details.

Saturday, October 2, 2010

Maltego 3 - Quick and Effective Information Gathering Tool

Maltego is a one-stop resource for carrying out foot-printing and passive analysis

Maltego is a premier information gathering tool that allows you to visualize and understand common trust relationships between entities of your choosing.

Currently Maltego 3 is available for Windows and Linux. There is also an upcoming version for Apple users that has yet to be released.

Information gathering is a vital part of any penetration test or security audit, and it’s a process that demands patience, concentration and the right tool to be done correctly. In our case Maltego 3 is the tool for the job.
  • Maltego can be used for the information gathering phase of all security related work. It will save you time and will allow you to work more accurately and smarter.

  • Maltego aids you in your thinking process by visually demonstrating interconnected links between searched items.

  • Maltego provide you with a much more powerful search, giving you smarter results.

  • If access to "hidden" information determines your success, Maltego can help you discover it.



Please refer here for detailed explanation, here for its documentation and here to download.

Sunday, September 5, 2010

Best Practices for Protecting ATMs and POS Terminals

10 Tips to Thwart Skimming

The keys to thwarting card skimming can be summed up in four ways - layered security, monitoring, system audits and education. Here are 10 best practices to follow in securing ATMs and point-of-sale devices at financial institutions and retail locations.

1. Deter Self-Service Terminal Skimming

Pay-at-the pump skimming incidents are on the rise, prompting some convenience stores and gas stations to change the locks on the enclosures that house self-service pumps. The Pantry, a convenience store chain in the south, has opted to use an anti-tampering security tape. The Pantry spokesman Scott Yates says the tape seals the area on a fuel pump where criminals install skimming devices to steal card information. If the tape is tampered with, the word "Void" appears on the tape. The tape is monitored by employees periodically each day. The Pantry operates more than 1,600 convenience stores in 11 states.

2. Respond Quickly to ATM Skimming

ATM skimming has taken off anew, and security experts say any institution has to be ready for the crime. First, banking institutions should have an incident response plan in place to react quickly to ATM skimming attacks when they are detected. Plans should include everything from whom should be contacted to immediate actions that need to be taken by the institution. If a device is found, all employees should know what to do. Educate branch employees and third-party vendors, as well as ATM service providers. Make sure they are monitoring the outside of the ATMs for residue or devices.

3. Use Layered Security Approach

Businesses should install a series of security layers, ranging from not storing card data to tokenizing the data using an outsourced service provider. If data needs to be stored, all data should be encrypted, while in transit and at rest. Strong network segmentation and comprehensive configuration change controls also should be implemented. A whitelist approach to data access control, as well as a whitelist approach to data transfer routines and destinations, are among other measures Litan recommends.

4. Increase Physical Security

To insert a skimming device, it is often necessary to remove a point-of-sale terminal from its location, or swap the existing terminal for another compromised terminal. Consider installing cable locks on POS terminals. Some have slots, so a cable lock can be attached to the terminal. This can then be threaded through the cable connecting the terminal to the cash register and then secured to prevent both the terminal and the cable from being compromised.

5. Ensure PCI Compliance

Make sure all POS terminals comply with the Payment Card Industry Council's Derived Unique Key Per Transaction (DUKPT) standard. Securely install terminals with unique hardware as a deterrent, and visibly inspect them, along with the registers, every day. Ensure all POS terminals are PCI compliant. Also, when any work is done on the devices, make sure it is done by an authorized service provider.

6. Audit PIN Entry Devices

PEDs need to be checked on a regular basis, recording them and cross-checking the serial numbers. Retailers are recommended to follow PED Security Guidelines and review the condition and placement of internal closed circuit TV systems to cover all areas.

7. Use CCTV to Monitor

Use applicable lighting to support payment environments and CCTV monitoring capabilities as required. Ensure ATMs and self-service pumps are well illuminated and meet minimum physical requirements, as defined by the appropriate regulatory mandates. Cameras should be situated such that they record the area around the point of sale PED device, without actually being capable of recording any PIN number entered. Save the CCTV images for 90 days.

8. Inspect All Locations

Frequently check the ATM fascia as well as the ATM's surroundings -- or those of external POS terminals -- ensuring nothing has been added or moved. Monitor the locations where ATMs and terminals are, especially if skimming attacks have been reported in the area. Have branch staff check these devices during off-hours as well as over weekends and holidays - all prime times for criminals to install skimmers.

9. Set Common Standards

Include visual standards for all ATMs and POS terminals, and maintain the standards at all branches or locations. Take a photograph of each machine, inside and outside. Show employees what the devices should look like, so when an ATM or POS terminal is quickly examined, employees readily recognize anything suspicious.

10. Educate Employees

Security-awareness training for all store and branch employees is a recommended place to start. Have a set of procedures for them to follow. Retailers should train staff to periodically check POS equipment, for instance, ensuring POS-device IDs still match, and no equipment has been swapped or changed.

Monday, June 21, 2010

Windows HCP Flaw - No Patch available yet

If you are running Windows XP or Windows Server 2003, you must update your registry — or someone could run software or commands on your computer as if they were you.

Anyone running Windows XP or Windows Server 2003 needs to update their registry ASAP.

A critical bug in the Help and Support center was made public recently and Microsoft has neither a fix nor an estimate as to when a fix might be available. Worse still, sample code to exploit the bug is readily available, along with a detailed explanation of the flaw, making it especially easy for bad guys to exploit the vulnerability.

The problem has to do with the way HCP:// links are processed. Normal website links, of course, use HTTP, HCP links are used by the Help and Support Center (helpctr.exe).

Microsoft's
Security Advisory (2219475) warns "This vulnerability could allow remote code execution if a user views a specially crafted Web page using a Web browser ... "

If the bug is exploited, a bad guy can run software or commands on your computer, as if they were you. The last phrase is important but hasn't been stressed in the articles I've seen on the subject.

Refer
here for more details on how to fix this vulnerability until patch is available from Microsoft.

Monday, June 7, 2010

7 Tips for Social Media Safety

Law Enforcement - and Potential Employers - are Watching What You Say and Do Online

Think twice the next time a contact tries to "friend" you on Facebook or "follows" you on Twitter. It may turn out to be an undercover fed looking to scrutinize your employment history or examine your personal references.

U.S. law enforcement agents are following people into popular social-networking sites, going undercover with false online profiles to communicate with suspects, gather private information and view photos and videos that are restricted to a user's network. Their main intention is to trail and catch criminals, tax evaders and other wrongdoers, as well as gather evidence to support their cases.

Information on social media sites has been used against employees in ways ranging from performance evaluation to legal risk. For example, when an employee files for disability compensation and during the same period posts pictures of physical activity."There are real concerns in terms of how social media can affect your employment status and potential job opportunities by what you do on a daily basis on these sites.

Tips for Job Seeker's Safety

From a job seeker's perspective, one needs to be consistent in one's activities and information posted about employment history, business references and recommendations provided. The slightest conflict in their profiles can make them a potential target for fraud and ruin their online reputation.

Use Good Judgment: Consider how your comments would be perceived before you actually post them, and put logic above emotion at all times. Before you hit 'post,' realize that this will be a permanent reflection of your identity, and it may never be erased. Assume that anything you put on a social networking site will be seen by third parties, and "ask yourself whether you would want that seen.

Know Your Contact: The key is: know your contacts. Do not accept friend requests from suspicious people. Use proper introductions when adding users as friends or connections. Once you connect with somebody, they will have access to your information, and -- depending on who they are -- you might not want them to have that level of access. A good practice is to go through your contact list frequently to ensure you have a tight and trusted network of people.

Do Not Tag Photos: Don't allow individuals to tag your photo, as unflattering pictures could end up costing you or your friends their jobs. A big risk in your friend putting that picture up of you from college doing silly things, and then tagging the picture -- It might also get picked up on a search engine. So, if a recruiter does a search, it could come up. There are settings in social media sites to prevent friends from being able to tag you.

Change Your Passwords: often and do not use the same password for social networking sites that you use for your email accounts and online banking.

Know Your Privacy Settings: Many sites such as Facebook provide users with a great deal of control over who can access their information. Those settings can be confusing, says Navetta, but there are websites like these that explain how to lock down Facebook's privacy settings, including BusinessInsider.com. Note also that Facebook is creating simplified privacy settings for future use.

Be Consistent: Using the same photo, consistent profile language, message and links on all social media sites reduces the chances of identity theft and generates trustworthiness and recognition among employers when conducting background checks. Job seekers also need to think twice before clicking on any links in social media sites, as these links can show up on their online history and result in turning off recruiting and hiring managers.

Avoid Controversial Statements: If you think that somebody could take offense with respect to a political view or offensive language or comments, don't make them on a social media site that can be viewed by others, says Navetta. "Remember: if there is nothing offensive on your site, there is nothing for potential employers to get judgmental about."

Thursday, June 3, 2010

Test Yourself - How aware are you about your risks of ID-Theft?

Privacy Awareness Week

Easy online test looks at 11 situations in you might be subject to ID theft. For each situation, you get a choice of statements. Decide which statement best decribes you and click the box beside it.

At the end, you will receive a score and assessment of your answers for each situation.

Refer
here to begin the test and also find some more information in the "book" at the bottom right of each screen, with some tips for you to use.

Thursday, May 28, 2009

An easier way to fully patch a rebuilt system

Create a do-it-yourself Windows update CD

Many people asked for a way to slipstream XP Service Pack 3 into their installation media or for an easier way to fully patch a rebuilt system.
The most obvious method is to build your own SP3 slipstream media. The Lifehacker site offers a good how-to page that describes the process step by step. An alternative is to create a patch CD. There are several options for doing this, one of which is presented on the PatchMate site.

The Windows Updates
Downloader site and AutoPatcher — a resources provide alternative approaches to the same end. Any of these sites will help you do what Microsoft is failing to do: give us a way to update our Windows installation media so we can legally and easily reinstall our operating systems on the same hardware when the machines become sluggish or need a refresh.

Friday, December 5, 2008

Enjoy Free Solaris 10 OS Training from SUN

Sun Open Learning Center offering free OS training

In this economic climate, it is as important as ever to keep your skills up-to-date. Now you can enhance your Solaris 10 OS skills with free training at the new Sun Open Learning Center.

The Sun Open Learning Center allows you to:

* Get free access to our most popular Solaris 10 OS training
* Engage in live conversations with Solaris instructors and experts in Second Life virtual world
* Obtain highly desired system administration skills for the Solaris 10 OS

Excellent initiative from SUN. I don't use Solaris much in my daily work life but all the administrators out there should take advantage of this cool offer.

Saturday, October 4, 2008

Computer Forensic Live CD

Helix 3

Helix is a ubuntu based linux distro that aims to help your work on Computer Forensic , Incident Response and Electronic Discovery. It almost has everything you need for your live forensic. By using Helix live cd , you can still boot into customized linux environment, that includes customized linux kernels, excellent hardware detection and many applications dedicated to Incident Response and Forensics.


Helix has been modified very carefully to NOT touch the host computer in any way and it is forensically sound. Helix wil not auto mount swap space, or auto mount any attached devices. Helix also has a special live side for Incident Response and Forensics.

Helix focuses on Incident Response & Forensics tools. It is meant to be used by individuals who have a sound understanding of Incident Response and Forensic techniques.

Refer here to download HELEX3.