19 December 2011

CISSP Training - New Curricula - Target 18 Feb 2012 Exam @ New Delhi

CISSP Training - New Curricula - Target 18 Feb 2012 Exam @ Delhi.

Online fraud 3rd most prevalent economic crime in India

With the increasing use of social media and personal devices in the workplace, cyber crime is now the third most prevalent economic crime in India. This rise, attributed largely to insiders, may have a correlation to the tendency of professionals here to flout a company’s IT policies more often compared to those in other countries.

According to the Global Economic Crime Survey, 2011, conducted by accounting firm PricewaterhouseCoopers earlier this month, cyber crime came third in the list of common economic crimes in the country, following asset misappropriation and corruption. About a quarter of the respondents stated that they had been victims of such crimes in the past 12 months and half opined that such threats were on the rise.

Statistics indicate that senior managements in Indian companies do not place enough emphasis on managing cyber threats and frauds. Although the CIO is usually responsible for IT security risks, the CEO and the board should understand and probe into the risk of cyber crime.
Employees, on the other hand, believe companies need to be more flexible in IT policies and give them more space in terms of usage of social media and devices. Cisco found that while not many employees find policies to be unfair, a large majority across countries feel their IT policies needs some improvement and updating.

Besides working professionals, college students awaiting to to start their careers also hoped for liberal IT policies from prospective employers. Cisco, which surveyed 1,400 college students, found 60% of them in India expected flexible and open-minded IT regulations that allowed them to stay connected to their work and and personal lives at the same time. A mere 17% said that they would abide by the policies issued by employers.


Click here to read more ......

Solutions : www.xcyss.in

17 December 2011

Yashwant Sinha gets hate mail, tells police

Senior BJP leader and former finance minister Yashwant Sinha has become the latest victim of harassment on cyberspace as it has turned out that he has been receiving hate mail from the last two months.

Police sources said Mr Sinha, who represents the Hazari Bagh constituency in Lok Sabha, has been receiving hate mail filled with communal references and personal abuses from one Ravinder Singh. The investigators have not been able to verify the antecedents of Singh so far but a case was registered at the economic offences wing of Delhi police under Information Technology Act on Thursday.


A complaint sent to Delhi police commissioner B.K. Gupta by Mr Sinha states that he has been receiving hate mails from Singh for two months and had even written to him to desist from the act. “Ravinder Singh has been sending me hate emails for some time now. My email address is widely known and taking advantage of that, this person has of late been sending me abusive mails,” Mr Sinha told the police.


“I once replied to him and requested him not to send me further emails. However, my request has fallen on deaf ears and he continues to send me mails,” Mr Sinha stated. Sources said two mails sent by Singh to Mr Sinha on November 7 and November 30 are full of abuses, targeting Mr Sinha on the basis of his association with Bharatiya Janata Party and on the basis of his religion. “The recent mails contain some references which are communal in nature following which Mr Sinha thought it was necessary that legal action be taken against the accused,” a crime branch source said.
Last month, senior BJP leader Arun Jaitley had approached the crime branch with a complaint against an unidentified person who had been spreading defamatory information on the social networking site Twitter against him through his fake profile.

Click here to read more ......

Solutions : www.xcyss.in

Cyber criminals will target small business, the cloud, mobile and social networks in 2012

Cyber crooks will target small businesses, social media attacks will be more common, and mobile security threats will reach an all-time high in 2012.

So says The Cyber Security and Information Assurance Division of Kroll Inc., which released its annual security forecast, highlighting key areas of risk and trends that will impact how organizations and governments combat and respond to cyber threats.

The events of 2011 suggest that the cyber security landscape will find public and private organizations are still on unsteady footing. Traditional pain points for organizations including mobile technologies, incident response and regulatory requirements will intensify as new and developing challenges surface in 2012.

  • Mobile technology security threats will be at an all-time high. Mobile technologies are changing so rapidly that in some organizations the demand and pressure to deploy new technologies (e.g., tablet computers) will outstrip the organization’s existing capabilities to secure them. This unfortunate dynamic is no secret to thieves who are ready and waiting with highly targeted malware and attacks employing mobile applications. Similarly, the perennial problem of lost and stolen devices will expand to include these new technologies and old ones that previously flew under the radar of cyber security planning.
  • Social media will increase in popularity as a conduit for social engineering attacks. Social media adoption among businesses is skyrocketing and so is the threat of attack.
  • Small businesses (SMBs) will enter the crosshairs of cyber attacks. “Hacktivism” may make headlines, but the fact of the matter is that data thieves are simply looking for the path of least resistance. Of late, that path has been leading directly to SMBs that house large amounts of valuable data but lack the data security budgets of their big business peers.
  • As cloud services gain in popularity, related breach incidents will flourish. Companies are smartly embracing the cloud for the associated cost savings and ease of use. Unfortunately, current surveys and reports indicate that companies are underestimating the importance of security due diligence when it comes to vetting these providers.
  • Business and government cooperation will be mission-critical for economic and infrastructure health. Cyber crime has the capacity to cripple almost every aspect of commerce from the largest corporation to the individual consumer.
Click here to read more ......

Solutions : www.xcyss.in

SOPA bill

The House of Representatives is expected to vote on the Stop Online Piracy Act (SOPA), a bill sponsored by Rep. Elton Gallegly. This bill drastically expands the power of the federal government and enables it to censor the Internet.

Companies that do understand, such as Google, Ebay, Microsoft, reddit, Tumblr, Twitter and Wikipedia, have come out against this bill as it threatens California technology companies and cripples the Internet.

While piracy is a legitimate concern, this bill allows the federal government to shut down any site that has one single link to any copyrighted material, meaning if your son posts a video on Youtube that includes a copyrighted song, the government can shut down all of Youtube or Facebook or Google or any other Internet company.

This is not hyperbole, this is literally the end of the Internet as we know it, a draconian and unprecedented expansion of government power that China would be proud of.

Click here to read more ......

Solutions : www.xcyss.in

16 December 2011

DHS issued - Blueprint for a Secure Cyber Future



The Blueprint for a Secure Cyber Future builds on the Department of Homeland Security Quadrennial Homeland Security Review Report’s strategic framework by providing a clear path to create a safe, secure, and resilient cyber environment for the homeland security enterprise.
......

The Blueprint lists four goals for protecting critical information infrastructure:
• Reduce Exposure to Cyber Risk
• Ensure Priority Response and Recovery
• Maintain Shared Situational Awareness
• Increase Resilience
.......

The Blueprint also lists four goals for strengthening the cyber ecosystem:
• Empower Individuals and Organizations to Operate Securely
• Make and Use More Trustworthy Cyber Protocols, Products, Services, Configurations and
Architectures
• Build Collaborative Communities
• Establish Transparent Processes
.......




Click here to read more ....

 Solutions : www.xcyss.in

How the RQ-170, US drone was hijacked

The Christian Science Monitor is reporting that the RQ-170 was hijacked by the Iranians using a well know exploit that sure seems to me to be a lot like an old and well known cyber attack known as "the man-in-the-middle" attack. 
Using intelligence gleaned from previously downed and less sophisticated drones, an Iranian engineer, identified that the global positioning system (GPS) is the weak link in the drone's security posture.
The "electronic ambush" begins by jamming the drone's communications forcing the plane into autopilot whereby it loses its "brain".  From there, the Iranians were able to "spoof" and interject landing coordinates to get the plane to land where they wanted it to land.

........

Click here to read more ......

 Solutions : www.xcyss.in

FBI says hackers hit key services in three US cities

At a recent cybersecurity conference, Michael Welch, deputy assistant director of the FBI's cyber division, said hackers had accessed crucial water and power services.
....
"We just had a circumstance where we had three cities, one of them a major city within the US, where you had several hackers that had made their way into Scada systems within the city," Mr Welch told delegates at the Flemings Cyber Security conference.


.....
Click here to read more ...... Solutions : www.xcyss.in

The Kremlin's Ham-handed Effort to Squelch Online Dissent

.....
In total, 14 sites were victims of DDoS attacks, including those of the radio station Ekho Moskvy, the newspaper Kommersant, and Golos, the country's only independent election watchdog. Those Web sites were attacked as early as 6:40 on Sunday morning, according to Alexei Venediktov, Ekho Moskvy's editor-in-chief, and remained offline for the entire day. According to information-security experts at Yandex, Russia's largest search portal, more than 200,000 computers were turned into "slaves" for the DDoS attack, in which a targeted site receives so many requests for access that it simply shuts down. It is a simple, cheap, and effective way to disrupt a Web site, at least temporarily.
.......

Click here to read more ...... 

 Solutions : www.xcyss.in

Anatomy of a Nitro Cyber Attack by Symantec

Latest report by Symantec.
.....
"The Nitro Attacks whitepaper, published by Symantec Security Response, was a snapshot of a hacking group’s activity spanning July 2011 to September 2011.  The same group is still active, still targeting chemical companies, and still using the same social engineering modus operandi,"
.....
They are sending targets a password-protected archive, through email, which contains a malicious executable. The executable is a variant of Poison IVY and the email topic is some form of upgrade to popular software, or a security update. The most recent email brazenly claims to be from Symantec and offers protection from 'poison Ivy Trojan'," the authors explain.
......
"The attachment itself is called “the_nitro_attackspdf.7z”. The attachment archive contains a file called “the_nitro_attackspdf                            .exe”. (The large gap between the “pdf” and “.exe” is a basic attempt to fool a user into assuming that the document is a PDF, when it is really a self-extracting archive.)," the article states.




Click here to read more ...... 

 Solutions : www.xcyss.in

Man held for hacking email account of rival firm

VADODARA: The cyber crime cell of city crime branch cracked a hacking case and arrested one person on Tuesday. The case involves two city-based outsourcing firms Office Beacon andZodiac Infotech that are competitors.

Tejas Mehta has been arrested for hacking the official email account of Office Beacon for professional gains. Mehta, who works withDesign 4U, sister concern of Zodiac Infotech, had earlier worked for Office Beacon.

Police said Mehta hacked into the email account of Office Beacon (OB)to get an order.

Mehta used to work for OB and had resigned from there in 2010 to join Design 4U. In December 2010, OB got information from its New York-based client that they have got an email from ID awalker@design4u.com. The mail had landed in OB's client's id soon after OB had sent it quotations for a deal. The quotations sent by awalker email id were less than OB's quotations. When OB official Chandrakant Thakkar checked their official id he realized that it had been hacked. OB officials then checked their company servers and dug out the IP address from where the second mail was sent.

It came to light that the email was sent from Zodiac Infotech. Investigations revealed that Mehta had hacked OB's email id from Zodiac Infotech and was using it to keep track of OB's deals and offers.

Click here to read more ......

Solutions : www.xcyss.in

UTV alleges trademark misuse

NEW DELHI: UTV has written a letter to the social-networking site, Facebook, asking it to remove a page that was using its name for duping aspiring actors. Further, Delhi high court has granted temporary stay in the misuse of trademark of UTV Software Communications. The order came while hearing a civil suit filed by the production house on December 12 against a fake casting agency running under the name of 'UTV Entertainment Media Private Ltd' in Noida.

"UTV lodged a complaint with Facebook after it found a page with the name of 'UTV Entertainment Media Pvt Ltd'. Facebook was informed that the logo appearing on the page was deceptively similar to UTV's logo. The page was then removed," said a source.


Click here to read more ......

Solutions : www.xcyss.in

15 December 2011

Mumbai: Man, son held in friendship club case

A father-son duo has been arrested by the Cyber Crime Police of the city crime branch in the friendship club fraud case.

Investigations revealed that Babu Latif Shaikh and his son Ejaz had provided mobile numbers to the operators of the club and were also handling monetary operations of the club.

Explaining the modus-operandi, the police said the gang published an advertisement in newspapers on the name of Aaliya Friendship Club. On payment of Rs10,200 membership fee, the club promised to connect their members to “smart, good-looking and high-profile women”.

When one of the victims contacted the club in October this year, he was told to deposit money in a bank account. When the club failed to meet their promise, the victim realised that he had been cheated and lodged a police complaint. Investigations revealed that it was a full-fledged racket in the garb of friendship club.

Click here to read more ......

Solutions : www.xcyss.in

14 December 2011

Student in obscene MMS web

The cyber crime department of the City Central Crime police station on Tuesday arrested a B.Tech student who circulated an obscene MMS of his ex-girl friend and also posted the photos online on a false Facebook profile created in her name. Police said the accused, 19-year old G. Krishna, a B.Tech (bioinformatics) student of Satyabhama Deemed University in Chennai, confessed that he sent the obscene MMS and made the Facebook postings after the victim, a medical student, stopped talking to him and he felt dejected.

He also took print-outs of the photos and dropped them off at the house of her relatives.

Police said that the two were schoolmates at Abhyasa in Toopran.

After they left school, Krishna got a common friend to contact her. He spoke to her on the phone and they met a couple of times during which time he took the photos. When she cut off all relations with him, he bore her a grudge. Krishna printed the photographs and dropped them at her relative's house. The girl's father warned him and his parents, who said they would control him. But Krishna went on to create the false profile and posted the photos online and sent the MMS to their common friends. Krishna is charged with defamation and under section 66 A of the IT Act.


Click here to read more ......

Solutions : www.xcyss.in

10 December 2011

'Gmail' storage upgrade phishing mail steals user logins and passwords

Anew phishing mail from ‘Gmail’ has popped up on the Internet asking users to upgrade their account storage because their quota has been exhausted. A closer look will show that it’s actually a phishing e-mail and not a genuine one. We received this e-mail last night, and a quick glance at our Gmail storage did show that data storage was quite close to its limit. Also, the e-mail first arrived in our inbox and not in the spam folder. Here’s a closer look at what happened next.

Billgates@microsoft.com has run out of space!..on Gmail!?

Billgates@microsoft.com has run out of space!..on Gmail!?

Titled ‘Google Account Storage Quota Exhausted on ******@gmail.com’, the e-mail may look genuine to most users, initially. The mail is sent by no_reply@qmail.com and at first, it’s difficult to actually notice the difference in the alphabets because the name shows Accounts Support with the actual e-mail in brackets, like any other standard mail you’ll get in your Gmail inbox. Here’s a screenshot of what’s written in the email:

Might fool some unsuspecting users

Might fool some unsuspecting users

For an unsuspecting user, this mail does look creepily close to a genuine mail by Gmail, but if you’ll hover over that link and look at the bottom left you’ll get to see the REAL URL, which is servicessc.----.acconutx.net (Obviously, we’re not putting up the entire URL!) It takes you to a page that looks quite identical to Google (the minute giveaway being the slightly warped Gmail icon) that asks you to choose your ‘Free’ storage option and enter your password. Thereafter, the site simply mentions that your account has been successfully updated.

Phishing complete!

Phishing complete!

Hopefully, these emails will end up in the spam folder. Unfortunately, the first victims might have already fallen prey to this scam. If you’re one of those who have already clicked on the link and entered your password, we’d suggest you immediately change your password, because in all certainty your password has been compromised.

Click here to read more ......

Solutions : www.xcyss.in

09 December 2011

Virtual Attack, Real Threat

Cyber warfare is emerging as the new dimension of war
New Delhi: Foreign entities penetrated into the servers at the National Informatics Centre (NIC) servers to launch attacks on other countries including Chinese servers, read a leading newspaper headline, few days back. The servers at NIC hold crucial information of the official websites and emails of the Indian government. The websites of PMO, embassies, law enforcement and intelligence agencies are continuously probed to extract sensitive information related to the national security. Information on our government servers are constantly under threat. These are far more sophisticated attacks than some mischievous hacker groups.
On 19 October 2011, Symantec has released a report on a new threat called Duqu. A server in Mumbai was shut after the initial reports of Symantec Corporation revealed that they had found out that it was compromised.

It was used as a command and control server to manage other machines and was communicating with the computers that were infected with the Duqu malware. This mysterious computer virus, according to the report, is similar to the Stuxnet which created havoc in Iran’s nuclear power plant and disrupted its production temporarily. The Advanced Persistent Threats (APT) like Stuxnet and Duqu has the potential to target a critical infrastructure and according to the reports, India is one of the highly infected countries to these advanced threats.

Click here to read more ......

Solutions : www.xcyss.in

Congress website hacked, Sonia Gandhi's profile defaced

NEW DELHI: Hackers broke into the officialwebsite of India's ruling Congress party Friday and defaced the profile page of party presidentSonia Gandhi with a pornographic message.

The attack coincided with Gandhi's 65th birthday and came just days after the Indian government pledged a crackdown on "unacceptable" internet content, that included faked naked pictures of the Congress leader.

The pornographic text included a reference to a Pakistan-based email address, but did not otherwise identify the hackers.

Earlier this week, Communications Minister Kapil Sibal pledged a crackdown on "unacceptable" online content, saying Internet giants such as Google, Yahoo! and Facebook had ignored India's demands to screen images and data before they are uploaded.

He highlighted examples of faked pictures of naked politicians, including Sonia Gandhi, and other images and social network pages that he said could inflame religious tensions.

Official Indian websites have been repeatedly hacked in the past. Last year, a group who identified themselves as the " Pakistan Cyber Army" hacked the website of the country's top police agency.

Click here to read more ......

Solutions : www.xcyss.in

5-6 pc of spam e-mails originate from India

According to international reports, the total email traffic worldwide categorised as spam is about 75-80 per cent in 2011

The government on Friday said about 5-6 per cent of the global spam or junk e-mails in 2011 originated from India.

"According to international reports, the total email traffic worldwide categorised as spam is about 75-80 per cent, in the year 2011. The share of spam e-mails originating from India is about 5-6 per cent of the total worldwide spam email traffic," Minister of State for Communications and IT Sachin Pilot said in a written reply to the Lok Sabha.

He added that though the Indian government has not conducted any study regarding the misuse of internet, various organisations across the globe have published reports on internet security covering aspects like spam e-mails.

Junk mails from malware-infected computers, selling counterfeit or illicit goods, generally contain malicious links to another false website. Due to the nature of IT and cyber space offering anonymity and not restricted by geographical boundaries, the problem of spam mails could be minimised but cannot be eliminated completely.

The Indian Computer Emergency Response Team (CERT-In), in coordination with the industry and service providers, is working towards disablement of "spam bots" located in India.

Compromised computer systems known as "spam bots" are largely responsible for generating majority of spam mail traffic. Section 66A of the Act provides for punishment for sending spam or unsolicited e-mail messages from communication services.


Click here to read more ......

Solutions : www.xcyss.in

08 December 2011

Cyberwar is more ugly than we thought

........


The ongoing uncertainty about who's to blame for Stuxnet and mistaken assumptions from the investigation and reports theorizing Russian hackers had attacked an Illinois water utility last month– show that we may be technologically ready to integrate solidly damaging digital attacks with attacks using bombs or bullets.
More clearly they show that we don't know what to expect from cyberwar, even after years of being involved in at least two– one in which the U.S. has failed to stop the high-volume data thieves working for China's military, the other mixing murder, malware, bombings and sabotage in Iran.
The only thing obvious so far is that even when U.S. cyberwar capabilities vastly outmatch those of the opponent (Iran), victory is far from guaranteed.
The ongoing tussle with Iran shows we're even uncertain that full-out cyberwar would give any country the leverage to make an enemy change its behavior, or its stance on an important issue.
The ongoing scandal with Chinese data thieves and the mix-up with the Illinois water utility makes it clear the U.S. isn't even sure of its ability to keep its digital infrastructure from being invaded, or even know for sure when it has been.
It's not hard to believe we're on the cusp of a new era of cyberwar; it is hard to be confident that will be an improvement in either the destructiveness of real war or that the U.S. will be as strong in cyberspace as it is in the real world.


Click here to read more .... 

Solutions : www.xcyss.in