india-to-have-national-cyber-security
“We are working on a cyber security policy. We need more work to curb cyber crimes,” SiliconIndia News quoted Minister for Communications and Information Technology Kapil Sibal as saying. –
“We are working on a cyber security policy. We need more work to curb cyber crimes,” SiliconIndia News quoted Minister for Communications and Information Technology Kapil Sibal as saying. –
An Interesting article in NBC News technology security section: A security firm found it could bypass Google’s two-step login verification process, reset a user’s master password and gain full control of the account “simply by capturing a user’s application-specific password.”
Application-specific passwords are passwords generated by Google that you can opt to use instead of your master password. They are long and awkward, and the whole point of them is that they aren’t really something you’d ever remember or even store anywhere. The trouble was, users were led to think they could only be used once, but Duo Security said, in a report, that they could in fact be used anywhere — and without a second point of authentication. The trick for the hacker was to obtain the application-specific password, and that’s really hard.
To read more click here:
An interesting article form Dark reading in there advanced-threats sections on Cyberespionage: The Obama administration is turning up the heat on nation-state cyberespionage attackers: A new policy aimed at protecting the U.S. government and businesses from theft of their intellectual property goes further than previous administrations in addressing the worst-kept secret that cyberspies are stealing U.S. IP.
Direct diplomatic pressure, greater law enforcement engagement, promotion of better security practices by potential victims, tougher legislation, and more aggressive public awareness campaigns are some of the main approaches of the strategy announced yesterday by administration officials.
To read more Click Here:
An interesting article on Naked Security: It was 2011, and if you were a Gmail user you might have found things had begun to turn ugly.
Spam messages, spear-phishing attacks, and bogus “I’m stranded in a foreign country” scams, began to appear in some users’ inboxes, defeating Google’s anti-spam systems.
To read more about this click here:
An article on phishing in google doc’s from Naked security: Earlier this week it was being widely reported that Oxford University had taken the drastic step of completely blocking Google Docs, after it had seen a dramatic increase in the number of phishing attacks exploiting the service, targeting staff and students.
What wasn’t so widely reported was that the University’s block was short-lived. As Robin Stevens of Oxford University Computing Services explained in a blog post – docs.google.com was only blocked for 2.5 hours:
To read more about this click here:
Interesting article in NBC NEWS technology section: A new report says that the Chinese military is secretly obtaining sensitive data from U.S. companies. A key technique is “spearphishing,” an approach that tricks a targeted individual to reveal information that can be used to infiltrate the company or government agency that person works for.
Security companies have been warning about spearfishing for the last two to three years, and its use is increasing. But now that it has become top news, thanks to a report from U.S. computer-security firm Mandiant Corp. explaining how Chinese operatives tricked workers at Coca-Cola and other major American firms, what is at the top of many people’s minds is this: How do you know if you’re being spearphished?
For more information on this article click here:
The ratio of websites running on CMS’s can be assumed to be more than the custom designed sites built from scratch. Quite understandably, there are more number of users using WordPress than any other CMS, hence it becomes crucial to have enhanced security measures for your site. Due to a large volume of users using WordPress as a platform, an increasing number of hackers and fraudsters try to compromise the security of such sites. In majority of the instances sites running on WordPress are compromised due to outdated files and/or plug-ins. Such outdated versions of the associated scripts act as an easy meal for fraudsters.
So what measures should an individual adopt to keep a WordPress installation safe and secure from being compromised ?
Primarily, it is crucial to have a latest version of WordPress. In-addition, there are couple of useful WordPress plug-ins that can help you safeguard your website hosted on an affordable web hosting server.
BulletProof Security
Average Rating : 4.5 || Total Downloads : 143,241
This plugin in particular has been considered to be one of the reliable security plug-ins for WordPress. It helps in protecting a WordPress based site against XSS, RFI, CRLF, CSRF, Base64, Code Injection and SQL Injection hacking attempts. Moreover, it offers a single click .htaccess WordPress security protection.
The files that are protected with this plugin are wp-config.php, bb-config.php, php.ini, php5.ini, install.php and readme.html with .htaccess security protection. Moreover, it holds the capability to check DB errors off, file and folder permissions check.
6Scan Security
Average Rating : 4 || Total Downloads : 3,844
The plugin is claimed to offer protection against the SQL Injection, Cross-Site Scripting (XSS), Directory traversals, Remote file inclusion, including the one’s listed in OWASP Top Ten security vulnerabilities.
It has been developed in a way that there is no adverse effect on the site’s performance.
Ultimate Security Checker
Average Rating : 4 || Total Downloads : 35,851
This too similar to couple of other plugins seems to be quite appreciated by users. It a common scenario where a hacker manages to get access to the WordPress installations and delete the data it contains. The Ultimate Security Checker is capable of identifying security issues on your site. It scans the installation for known vulnerabilities and grades it accordingly. It suggests the vulnerabilities which you may either fix on your own or do it automatically.
Better WP Security
Average Rating : 4 || Total Downloads : 41,417
The plugin ensures that multiple security holes are patched without the need to bother about conflicting features. It comes with a built-in feature that bans troublesome bots, switches off the ability to login for a given time period, bans the users trying to login too many times with incorrect information and more importantly it enforces strong passwords for all accounts.
WP Plugin Security Check
Average Rating : 5 || Total Downloads : 4,168
It may at-times happen that due to an outdated security plugin a hacker manages to breach in, this plugin searches for plugins for bad practices and possible security holes limiting the risk of a compromised website.
Secure WordPress
Average Rating : 4 || Total Downloads : 611,889
This plugin removes the error information on login pages, adds index.html to plugin directories, hides the WordPress version (except from the admin area) hides the plugin-update information for non-admins, it blocks any bad queries that pose harm to your WordPress installation.
WP DB Backup
Average Rating : 4 || Total Downloads : 1,238,595
We all are aware about the importance of website backup, this plugin allow users backup the core WordPress database tables with minimum clicks. Looking at the number of downloads one can imagine its popularity amongst webmasters.
Read more on the EUKHOST.com Blog Site.
US-Cert has just distributed a notification about the release of Chrome 16.0.912.77 for Linux, Mac, Windows, and Chrome Frame to address multiple vulnerabilities.
The vulnerabilities may allow an attacker to execute arbitrary code or
cause a denial-of-service condition.
Security fixes and rewards:
Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.
The bugs 106484, 107182, 108461, and 109556 were detected using AddressSanitizer.
* Bug 107182 was fixed in 16.0.912.75 but accidentally excluded from the release notes.
More information can be retrieved from the Google Chrome Release blog entry and update to Chrome 16.0.912.77.
This is no surprise, scammers have taken big news events such as Michael Jackson and Mel Gibson’s death as well as the Haiti and Japan earthquakes to name a few topics to either profit or spread malware. This article by Ted Samson of InfoWorld explains the latest victim to this trend… Steve Jobs of Apple.
By Ted Samson | InfoWorld
Follow @tsamson_IW
“As much of the world mourns the passing of Steve Jobs — one of the technology industry’s greatest visionaries — the bottom feeders of the cyber crime world are greedily exploiting the tragedy through scams promising unwitting users a chance to win a free iPad.
Sophos has reported in its Naked Security blog on one such scam already circulating via Facebook that reads as follows: “In memory of Steve, a company is giving out 50 ipads tonight. R.I.P. Steve Jobs,” followed by a tailored bit.ly link ending with “restinpeace-steve-jobs.” Clicking the link takes users to one of countless malicious Web pages.”
Read more at InfoWorld.com
A Hacker group known as “The Lulz Boat” hacked the PBS website on Sunday and posted a false story claiming the rapper Tupac Shakur who has been dead for 15 years is actually alive and living in New Zealand.
Officials at PBS Television confirmed hackers broke into the organization’s website and posted the false story about the deceased rapper and removed it off their website Monday morning.
The Lulz Boat hacking group stated they were “less than impressed” after watching the network’s program “WikiSecrets” and “decided to sail our Lulz Boat over the PBS servers for further… perusing.”
Many Wikileaks supporters found the programming to be an unfair depiction of the organization and Bradley Manning. Manning is a military intelligence analyst, who is suspected of leaking thousands of classified documents that ended up on the WikiLeaks website. The disclosure of these document have been deemed one of the largest leaks of classified material in U.S. history.
In conjunction to the false story, the hackers also posted login information of PBS journalist, contractors, internal PBS websites and a number of internal communications such as letters and emails to a public website.
Anne Bentley, PBS’ vice-president of corporate communications, said in an email “all affected parties were being notified of the issue.”
These types of compromises occur too often due to technology, configuration or policy weaknesses at some of our major organizations. Last week it was the New York Times site, this week it is PBS, who is next… your organization?
