Showing posts with label Security Tips. Show all posts
Showing posts with label Security Tips. Show all posts
How to identify phishing scams (Phishing Hack)
What is Phishing?In the field of computer security, phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.
What does a phishing scam look like?
Phishing e-mail messages take a number of forms. They might appear to come from your bank or financial institution, a company you regularly do business with, such as Microsoft, or from your social networking site.
Securing Your Network From Hackers With HoneyPots?
First thing any hacker would do to compromise any network is gathering information passively and seeking vulnerable services as well as ports. And this is where Honeypots play a role of fake vulnerability in network.
Honeypots are fake theoretically, but not practically. They are real vulnerabilities in Network intentionally kept open & designed to gather information about the possible attack / attacker.
How Honeypots Work?
This fake vulnerability attracts any hacker towards it & he would try to compromise it. The Honeypot will itself stores the data regarding how hacker is trying to break it, what tools he might be using, his intentions, keystrokes and many such things.
This information is useful to network security administrator in many ways. Generally the attack is not done in one shot. Hackers try some initial attacks. And based on its results he hacks into major network flaws after some days.
So Honeypots help security people to secure the networks from the information they have gathered from initial attack. They are called as honey pots only because they are made available in network of vulnerabilities like Honey Comb.
Are Honeypots Vulnerable itself?
Sure they are. There are lot of smart ass hackers – who if anyhow come to know that they are dealing with Honeypots, They can totally screw things up.
Because, they are actually dealing with the system file in the network. So they are already inside it without any breakdown. If they can compromise this fake vulnerability Honeypot i.e. that they can surely break in to the system in less time.
Vulnerability is a vulnerable after all & Honeypots too. But there are very rare chances for attacker to identify it & needs great experience. So, planting Honeypot into any network architecture would be a more secure scenario for any host or network.
Honeypots are fake theoretically, but not practically. They are real vulnerabilities in Network intentionally kept open & designed to gather information about the possible attack / attacker.
How Honeypots Work?
This fake vulnerability attracts any hacker towards it & he would try to compromise it. The Honeypot will itself stores the data regarding how hacker is trying to break it, what tools he might be using, his intentions, keystrokes and many such things.
This information is useful to network security administrator in many ways. Generally the attack is not done in one shot. Hackers try some initial attacks. And based on its results he hacks into major network flaws after some days.
So Honeypots help security people to secure the networks from the information they have gathered from initial attack. They are called as honey pots only because they are made available in network of vulnerabilities like Honey Comb.
Are Honeypots Vulnerable itself?
Sure they are. There are lot of smart ass hackers – who if anyhow come to know that they are dealing with Honeypots, They can totally screw things up.
Because, they are actually dealing with the system file in the network. So they are already inside it without any breakdown. If they can compromise this fake vulnerability Honeypot i.e. that they can surely break in to the system in less time.
Vulnerability is a vulnerable after all & Honeypots too. But there are very rare chances for attacker to identify it & needs great experience. So, planting Honeypot into any network architecture would be a more secure scenario for any host or network.
How to Stay Secure Online
In light of recent events, security has been a serious priority for all of us. Although there is no 100% full-proof plan, there are ways to greatly improve your online security and plan for the worst. Here are our recommendations.
The Bad News: Nobody's Safe
- No matter how safe you think you might be, something bad can always happen.
- The only way to ensure your private information always remains private and in your control is if it never leaves your own head.
The internet and reality aren't much different, in that sense. There is plenty of, if not more, risk in the real world than there is on the web, but we're just more accustomed to dealing with it. The online world is still very young and so we're learning to protect ourselves as we go along. Nonetheless, like with anything, there is no surefire protection. The web is imperfect. We are imperfect. Ultimately, no site is un-hackable. A person or group with enough knowledge and determination can bring nearly any site down. That said, we can certainly try our best to protect ourselves and be prepared for worst-case scenarios.
Create Strong, Resilient Passwords
There are several ways to keep remarkably strong passwords, but every strategy has a point of weakness and a level of inconvenience that you're going to have to accept. We're going to go over a method that we feel is all-around the best way to go, but include a few variations along the way so you can decide what suits you best.
Create Strong, Secure Passwords that Even You Don't Know
When it comes to our own, individual online security we put a lot of trust in our password managers. Password managers keep track of your passwords on multiple sites so you never need to remember your password when it's time to log in. This way you can memorize your one master password and never have to worry about remembering any of the others. This is enormously convenient, but what's more important is the added security benefits. A good password manager can help generate incomprehensible passwords, store them in its database, and decode them locally, only one your machine, when it needs to enter them into the web site. You can use a password manager to generate a unique, complex password for every site you visit. Each site will have a different password, you'll have no idea what any of them are, and all you'll have to do is remember the one master password you set for it.
While there are a number of good password managers out there, like KeePass and 1Password, our favorite is LastPass. LastPass offers incredibly wide support for several operating systems, web browsers, and mobile phones. It's also completely free, remarkably secure, and comes with many features to help you stay as protected as possible. Since you're likely not without a few passwords at this point in your life online, LastPass can help you audit and update your passwords to make them more secure.
But what about creating a secure master password?
While all the passwords LastPass (or your other password manager) will generate will be about as strong as they can be, you want to have a strong master password as well. While your password manager can generate one for you, often times it's going to be too hard to remember and too inconvenient to type (especially on a mobile phone). If you don't mind the extra work for the extra security, your best bet is to have the most secure password you can have. If you want something you're sure you won't forget, Mozilla offers an easy way to create a strong password you'll be able to remember:
- Change that number (in this case, "two") to its numerical equivalent: A bird in the hand is worth 2 in the bush If you're not in the mood for a cute strong password public service announcement, the concept goes something like this:
- Pick a phrase you can remember with a number in it, like "A bird in the hand is worth two in the bush."
- Condense the phrase by only using the first letter of each word: Abithiw2itb
- Add some special characters you can remember: #Abithiw2itb!
Doing this gives you all the characteristics of a good, strong password: lowercase and capital letters, at least one number, special characters, and a combination of those things that basically makes no sense when you look at it and turns out to be longer than eight total characters.
While we recommend generating complex passwords with your password manager, you can use this same technique to create unique passwords for individual sites. You can take the password and add a suffix specific to each web site. Sticking with out example, let's say you wanted to use this password for Lifehacker. Just add :L1feh@cker, :Lh, or whatever you'll be able to remember to the end of the password: #Abithiw2itb!:Lh. This way you can type your complex password as you normally would and just append your abbreviation for the site you're logging into. This method is a little easier, but it's not impossible for someone to figure out. Ideally you'll want to let your password manager handle your password generation for you, but if that's just not for you then this method is a reasonable alternative.
If at any point you're not sure about your password's security, head on over to How Secure Is My Password? to get an approximation of how long it would take to crack using an average desktop computer. would take about seven billion years, which seems pretty good. If you're satisfied with the password you've derived, you've got your new master password. If you're not, keep trying and checking.
Keep Your Other Information Protected
Your passwords are not the only kind of important information you don't want floating around the internet, and chances are you have a few gadgets you wouldn't want to fall into the wrong hands. Fortunately there are quite a few ways you can
Protecting Your Credit Cards
If you shop online, your credit card number has been entered into at least one web site. While this is unavoidable, and just about as safe as using your credit card out in the real world, the fact still remains that your number could be intercepted and used to make unauthorized purchases. One easy way around that problem is using temporary credit card numbers. While not every bank offers this service, if yours does you might want to take advantage of it. If you're making a purchase online—especially at a site you don't trust—you just generate a unique credit card number that will expire after its first use. This is also extremely helpful if you sign up for a trial and want to prevent automatic re-billing.
Keeping Your Mobile Technology Secure
There really isn't any assurance your technology won't get stolen someday. As previously mentioned, it happened to me in less than a minute. Fortunately there are a number of tools to keep your laptops and mobile phones secure from tampering, or at least initiate a remote data wipe in the event of a breach.
One of our favorite tools is Prey, which is a free tool (for up to three devices) that can help you track and (potentially) recover your stolen laptop or Android smartphone. If you're looking for a solution for your iOS device, Apple now offers find my iPhone for free. If you're not using an iPhone 4, it is still possible to enable the free Find My iPhone, but it'll take a little bit of extra work. Once you get it up and running, you'll be able to remotely locate your iPhone, send it a message, and wipe your personal data. To get started, you can download Find My iPhone in the iTunes App Store. Despite the name, it'll work with any iOS device (but GPS and 3G service certainly help).
That just about wraps it up for guide to online security. With so many options out there, it's hard to cover the entire spectrum. If you feel we've missed something or have some good tips, please share them in the comments. Thanks for reading, and stay safe!
How to Remove a Keylogger
Keylogger is a dangerous software that executes almost invisibly as a low level system process. It is usually started up in an invisibility mode when your computer is booted - so there is no way the user can detect it. This program logs all the key strokes that you type on the keyboard and then transmits the logged information to the intruder who infected the computer with the keylogger program.
Keyloggers are extremely dangerous and can be used to steal personal information such as your social security number, credit card number, and passwords to just about everything. This may lead to identity theft or theft in general. Keyloggers are especially dangerous to anyone who uses online banking or online cash sites such as PayPal for a large amount of money.
When you suspect that you are infected with a keylogger, do NOT type any personal information. Even if you are typing in a normal word document, the keylogger still keeps track of everything you type.
If you desperately need to login to your Email or somewhere secure and password protected, there is one way to get around the keylogger.
Click on Start -> Go to All Programs -> Click on Accessories -> Select Accessibility ->Click on On-Screen Keyboard
Executing the above steps opens a keyboard on your screen so that you can click whatever letter you would like to type. Since a keylogger does not track where and what you click, this helps you to get around it in times of urgency. Typing with the on-screen keylogger is a great hassle. The only alternative is to eradicate the keylogger program completely from the computer.
Before you can eradicate the keylogger program and make the compute safe, you will need to detect it. Detecting a keylogger is not simple. It can be installed in over a 100 places on your computer, usually located in one of the system files. However, there is a much easier way to detect if a keylogger is running or not. Right click on your desktop’s task bar and click on Task Manager. Alternatively you can press Ctrl + Alt + Del simultaneously to open the Task Manager. Task Manager displays a list of all the applications currently executing on the computer. Click the tab that says Processes. This gives you information about all the programs, hidden and visible that your computer is currently running.
Unless you know a lot about system processes and application processes, you will have difficulty figuring out what you are looking at. The name of each process is under Image Name. The keylogger will show up on the list of processes as well as many other programs and background processes. However, you may not be able to distinguish between the different processes.
You will need to know which process to end before you can stop the keylogger. There are many sites available on the Internet that provides a vast amount of information on each and every process that you may encounter. One of these sites is Liutilities. This site provides some background information on each process as well as specifying the author and which program it is part of. One of the best features of this site includes a recommendation about what to do with that process. Most of the time, the process you look up will be harmful and simply part of the operating system or another program you are running.
Another fantastic site for information on processes is Neuber. As with Liutilities, Neuber gives you background information on that process. A special feature they have is user created comments. Anyone can rate a process in terms of its security a leave a comment about how to deal with the process. Generally, these comments are very accurate. Neuber also provides a 'security rating' for each process based on the average rating by users.
However, some find it hard and long drawn out to research each process individually. Thankfully, there is a program called Security Task Manager that is free to download. It will display information about each of the processes that are currently running, as well as specifying if they are dangerous or not. You will immediately be notified should anything harmful come up. Produced by Neuber, the program also shows the security rating and a random comment made by a user for each process. This program does have its disadvantages though. Processes that the program has never encountered before are not given a security rating or a comment. It is therefore advised that you research these processes individually.
Once you have found the harmful process in the Task Manager, click the process and then click the 'End Process' button towards the bottom right. The process you have selected should be terminated immediately.
Once this is complete, you should be safe until you reboot your computer. If you do not delete the keylogger, upon rebooting your computer, the keylogger will start up again.
Once you have stopped the keylogger, run anti-virus and spyware checks on your entire computer. Some free virus scan utilities that are recommended are A2, Dr. Web and AVG. However, highly advanced keyloggers such as TypeAgent, KGB, and SpyOutside can often slip through these scans and remain undetected.
If the antivirus scans fail to show any result, you will need to manually detect and delete the keylogger. Keyloggers are usually located in the system files, so do not delete anything that you aren't 100% sure is the keylogger. Doing so may lead to errors in other areas of the computer. Go to 411-spyware and search for the type of keylogger that has infected your system. If it is listed, there should be instructions about how to manually remove the keylogger.
A great way to check if the keylogger has been completely removed from the system is to reboot. Remember the name of the keylogger's process and reboot the computer. If the process is not there when the computer has rebooted, you are safe.
Ethical Hackers vs. Malicious hackers
It is important to know the difference between an ethical hacker & a malicious hacker ( also know as crackers)
Ethical hacker as we already know is a person who hacks system to find vulnerabilities and secure them.On the other hand, a malicious hacker or a cracker hacks system to take control over it.There are mainly two reasons because of which a person could hack a system -
For fun - Yes , a malicious hackers will hack a system and then boast about it in front of friends.
For Some benefit- Benefits ranging from financial to personal. A malicious hacker could hack into a credit card transcation processing server to get a list of credit card numbers & use them in a financial fraud.
Please keep in mind, malicious hackers are criminals & hacking someone’s system without his/her consent is a legal offense punishable under law.
In modern parlance , the hacker ethic is either:
The belief that information-sharing is a powerful positive good, and that it is an ethical duty of hackers to share their expertise by writing free software and facilitating access to information and computing resources wherever possible; and/or
The belief that system cracking for fun and exploration is ethically acceptable as long as the hacker commits no theft, vandalism, or breach of confidentiality.
Both of these normative ethical principles are widely,but by no means universally,accepted among hackers.The first and arguably the second,emerged from the MIT Artificial intelligence Laboratory during the ’60s and ’70s.
Secure your web page against SQL injection
There is a number of things you can do… I will show you a few here…
Alternative one
Lets say this is your code:
Lets say this is your code:
Code
<?php
$result = mysql_query(‘SELECT text FROM pages WHERE id=’ . $_GET['id']);
echo($result);
echo($result);
?>
This means that you are selecting the page content which is ‘text’ from ‘pages’ in the SQL database, and you are sorting out the right page content with $_GET['id'] and $_GET['id'] is the thing in the url… Example;
Code
http://google.com/index.php?id=123
This code is easily injectable… But if you do this:
Code
<?php
$result = mysql_query(‘SELECT text FROM pages WHERE id=’ . mysql_real_escape_string($_GET['id']));
echo($result);
echo($result);
?>
You are 100% secure
Alternative two
This one is not as good as the first one… But still works
Again we say this is your php code:
Code
<?php
$result = mysql_query(‘SELECT text FROM pages WHERE id=’ . $_GET['id']);
echo($result);
echo($result);
?>
Again this is very simple to inject… But if you check $_GET['id'] for “illegal” characters! Like this:
Code
<?php
$pos = strrpos(strtolower($_GET['id']), “union”);
if ($pos === false){}else
{
die;
}
if ($pos === false){}else
{
die;
}
$pos = strrpos(strtolower($_GET['id']), “select”);
if ($pos === false){}else
{
die;
}
if ($pos === false){}else
{
die;
}
$pos = strrpos(strtolower($_GET['id']), “information_”);
if ($pos === false){}else
{
die;
}
if ($pos === false){}else
{
die;
}
$result = mysql_query(‘SELECT text FROM pages WHERE id=’ . $_GET['id']);
echo($result);
echo($result);
?>
Why is Security Needed?
A dictionary meaning for security is “Freedom from Danger, risk ,etc”. Security is important Concept weather it be Physical or virtual.you hire security services like Security guards & Securiy Solutions like fencing ,alarm systems,locks etc. to protect you physical assets (money,property, gold). Just like this , you have some virtual assets like your password ,websites,domain names,servers etc.When your physical assets are not safe a robber can easily get hold of them.Similarly, when your virtual assets are not secure , a hacker can easily take control over them and do what he desires to do.When your physical assets are damaged,local Police department is available to help you but the case is not same for virtual or online security.If your email account password is hacked by someone, you most likely are not going to get much help from a cyber crime team, no matter how important mails you had in your inbox.This makes knowledge about online security even more important since no one else is going to help you & you have to defend your castle of Virtual assets all by yourself.
The use of e-commerce i.e commerce done via the internet has made online security more important.Now a days people or companies have sensitive data on there servers loosing which can damage there Business.
Now we have the answer to the question of why online security is important.
FIND SENDER’S IP ADDRESS IN YAHOO EASILY
In this tutorial i shall be writing about the trick to get the IP Address of sender in Yahoo Mail. This is useful if someone is spamming your inbox with junk mail or any other reason you may have to find the location of the email sender.
Guide to tracking of emails to find sender’s IP address using email headers.
After you find out the IP address of the sender you just have to use a location lookup service to find the exact location (country, city, etc) of the sender. You should also read: How to Track the location of an IP address.
Note: You won’t be able to find the real IP address if the sender uses an Anonymous proxy server.
Here is a step by step guide to get the IP address of an email sender in Yahoo! Mail:
1. Log into your Yahoo! mail with your username and password.
2. Click on Inbox or any folder where you have stored your mail.
3. Open the mail
4. At the bottom right region of the email, you’ll see there is a drop-down option “Full Headers”. If you can’t find it press Ctrl+F and search for “header”.
5. Click on it and look for Received: from followed by the IP address between square brackets [ ].
6. That should most likely be the IP address of the sender. If there are many instances of Received: from with the IP address, select the IP address in the last pattern. If there are no instances of Received: from with the IP address, select the first IP address in X-Originating-IP.
Now, you can find the exact location of the sender by using GeoBytes IP Locator or IP2Location.




