Tuesday, July 28, 2015

Multimedia Hack Affecting 95 Percent of Android Phones

IF You Use an Android phone;  Beware, Your Android smartphones Can BE hacked by Just A malformed text message.


Security Researchers Have found That 95% of  Android  Devices Running version 2.2 to 5.1 of operating System, Which Includes Lollipop and KitKat, are Vulnerable to Security A bug, affecting more Than 950 Million Android smartphones and Tablets.

Almost all Android smart devices available today are open to attack that could allow hackers to access the vulnerable device without the owners being aware of it, according to Joshua Drake, vice president of platform research and exploitation at security firm Zimperium.

The vulnerability resides in Actually A Core Android component called " Stagefright , "A Multimedia playback Library Used by Android to Process, Record and Play Multimedia Files such as PDFs.

A Text Message Received ... Your Is your phone hacked



Drake has developed and published a scary exploit that uses a specially crafted text message using the multimedia message (MMS) format.

How it Works


All A hacker Needs Is The phone Number of The Victim's Android device. The hacker Could Then sends message The Malicious That Will surreptitiously execute Malicious code on The Vulnerable device with No end user action, No Indication, nothing Required.







Sunday, July 26, 2015

 Meet 360 Total Security
(Your Unified Solution  For PC Security and Utility)


For Real Time Protection and Timely Updates

How to Make your Chrome and Firefox browse faster 



The Better Solution Is   OneTab . Available for Chrome and  Firefox browsers.




To Install  One Tab Into Google Chrome in under 5 seconds, Click OneTab

Friday, June 26, 2015


How to Build an Adaptive Security Culture



By Bruce Cowper, SecTor
If you do not ADAPT, you do not Survive. It's A Principle That Runs throughout Nature and Business - and IT's Just as True in cybersecurity. Security teams Need to BE as adaptable in Their Technological environments as animals are in Their Natural Ones. Often, though, security practitioners are rigid, slow moving and unresponsive.
Things Have to change. It's Time for an Adaptive Approach to Security. This Is True especially now. Since The early 2000s, cybersecurity Threats Have been accelerating.
In 2000, US-CERT logged twenty-One Thousand Seven Hundred Fifty-Six cyberattacks. The Biggest Causes of such incidents AT The Time; Denial of Service attacks, BIND Domain name System software vulnerabilities and The LoveLetter worm. The First botnet HAD only surfaced A year Before, and Windows XP Would not Ship Until A year Later. Social Media did not EXIST.   

Today's Threats Have Expanded in Number. In 2009, PwC Recognized 3.4 Million Cyber ​​incidents. Last year, That Number hit 42.8 Million, Representing A 66 percent CAGR over five years.  
They Also Have deepened in complexity and Type. Cybercrime Is A Commercial Operation. Zeus malware Is Being repurposed to Attack Specific Vertical Markets. Exploit Kits are available off The shelf, and Even mainstream websites Can BE Made Malicious  
Cyberattackers always Look for Advantage The next, Which typically involves exploiting new Technologies. BECAUSE Systematic Innovation Is in The Technology Sector, They Have Plenty of feedstock.
You do not Fight A multi-headed, Fast-Moving Enemy by freezing. You Adopt A Culture of adaptability, Able to bend and Flow, and counter new Kinds of Attack as They emerge. As Bruce Lee famously put SO: "Become like water."
This culture of adaptive security breaks down into three parts, which map broadly to the three phases of a cyber-incident: before, during and post-attack.

Not so Rigid Risk Management

The First and preventative Part of this Strategy focuses on risk Management. Many risk Management teams take A Rigid and overly structured Approach.
One common mistake Is to Focus on Security Features product. Relying on A Security Appliance to cover All of your Bases May SEEM like an Easy win, But May you find That The Security Capabilities of those Solutions do not Match The Needs of your Organization.
These Needs are Changing as The Technology Changes. Ten years ago, departmental managers Would not Have HAD recourse to Cloud-based Applications such as analytics and CRM. Now They May well Spend Their Own Budget on those Services.
These dissolve Technologies The Traditional perimeter-based Security Model, Creating new Threat vectors. Risk Management and Security Infrastructure Design must BE Fluid Enough to Absorb Them, Which MEANS That cybersecurity teams must BE Willing to Their Perceptions Mold Around Them.

Make No Assumptions

The Second Part of an Adaptive Security Strategy Looks AT How The Organization ACTS When an Attack Is Underway. The First rule Is to Admit your Own vulnerability? Assume you Will BE AT breached Some Point. Acknowledge That Even The Best risk Management Will not make you invincible.
Avoid Making assumptions That Will blind you to Potential Threats During, Agents this Phase. Your cybersecurity Team May Have A tailored Response to Specific Threats, assuming That They are The Most Likely. If you ignore those Threats That you Never Thought Would occur, you May BE Caught unawares and end up taking longer to resolve an attack.
Blindness Can MANIFEST Itself in Other Ways, TOO, particularly When looking AT How you Respond to an Attack Across Different Components of your Technology architecture. Many Systems Directly Affect MANY others. If your Active Directory System Is Compromised, for Example, That May Touch Other Systems such as Human Resource Applications, Access Control Layer Or Collaboration software. Your Response Team must BE Able to Explore These Systems as Quickly as an ATTACKER does.
That Can Challenging BE, BECAUSE companies Tend to Create Organizational Silos Around These Systems That Can STOP Response teams Thinking laterally about Them. Sometimes, Different teams Can Even BE Dedicated to Specific parts of The Technology Infrastructure, Which Can Restrict Cross-System visibility.

Update Your Response and Test

FINALLY, There's The Post-Attack Phase. This Is Where your Team Gets to plug The hole That an ATTACKER exploited. This Is Where an Adaptive Security Strategy Comes Into ITS Own. Running A Post-Incident Review Is One Part of this Process. Security teams can then secure the hole that was exploited and also look for similar vulnerabilities elsewhere in the infrastructure.
The other part of the process is updating the risk management process and the response "playbook" with information gleaned from the attack, so that your company's security is hardened and the response team better equipped to cope next time.
IT's Also Important for Organizations to Test themselves once Fixes Have been Applied, to prove That They Have Adapted. A "War Games" Approach Can BE Useful here, with hired attackers specifically Setting out to Gain Access Via The SAMe Attack vector.
Doing All of These Things Will help companies Close The Circle by Positive Feeding information back Into The Security Process. This Is Where an Adaptive Security architecture Comes Into ITS Own.

Building Security into Organizational Culture

These pointers Will help you Build more Operational and Tactical adaptability Into your cybersecurity Operation. These are Great for Short-to-Mid term Challenges, But There are Longer-term, more Strategic lessons Learned here to BE, TOO. Security Threats Will Just morph as dramatically as Technology does. How Can you ADAPT to These Changes;
Explore The EXTENT Security to Which Is Built Into your Organizational Culture, Rather Than Being merely bolted on. Includes appointing this Security Staff AT A Strategic, Managerial Level and secure driving processes (such as secure software Development and Procurement secure) throughout The Company. Engaging Employees Properly and systematically with user Security awareness Training That Actually Works Is Also A Crucial Part of The Equation. After All, companies are not Just Collections of processes? They're Also Built from People.    
All The Technologies That underpin those processes, and Which are Used by those People, are Going to change Even more dramatically in The next FEW years Than They did The last FEW. Mobility, Cloud computing, The Internet of Things and The Digital Supply Chain are Going to Evolve and Work Together, in Unison. It's All Speeding up, Which MEANS That your cybersecurity Practice Will Need Bruce Lee-like skills. Are you Ready to Become like Water;
Bruce Cowper   Is A Founding Member of The Security Education Conference Toronto (SECTOR), Which Runs Oct. twenty to twenty-one, 2015.


Source




Why Is Fighting Cybercrime So Hard?

It's tough to target the few hundred super hackers that experts believe are behind the majority of cyber attacks.




A few hundred expert hackers offering "crime as a service" are behind a large percentage of all the cybercrime acts committed. That's the conclusion of a group of international law enforcement experts from organizations including the FBI and the UK's National Crime Agency.
Talking at the recent InfoSec Europe security conference in London, FBI agent Michael Driscoll said that there is evidence that just 100 to 200 people around the world are enabling organized crime gangs to mount technical attacks by selling them malware, botnets, distributed denial of service ( DDoS) capabilities and other hacking services.
Despite the small number of people behind many of the attacks, the effects of their actions are devastating, Driscoll said.
"The average loss on the Internet is $ 3,000, and bank losses average $ 1,800. That may not seem like a lot, but we get about 22,000 complains a month and we think that is about 10 percent of the total," he said. "There is constant hacking and online fraud; the volume is huge."
Catching organized crime gang members, and the cybercriminal masterminds who offer services to them, is hard - or in many cases impossible, said Alan Woodward, a professor at the Surrey Centre of Cyber ​​Security. That's because they operate in concert from all over the world.
"Some people think that the financial threats stem from Russia, IP threats come from China and so on, but it is not as simple as that," he explained. "These organized criminal gangs in particular are international and distributed. There might be one member in the Ukraine, one in the UK and so on."

Reach out to Law Enforcement

The good news for anyone whose company faces the threat of attack by cybercriminals - and that means just about any company - is that law enforcement agencies can help you. But before they can be of help, it's essential that you make contact with them.
"One thing that's sure is that you can not be secure on the Internet, so my advice is to make sure you are talking to law enforcement now. Do not wait until you get hit and it is too late," said the FBI's Michael Driscoll.
"You need to engage with the FBI, or with CERT, or with the National Crime Agency," he said. "They push information about criminal activity to companies, so you need to make sure that you are getting that. And you need to be sending information about odd activity that you spot back to law enforcement."
Woodward said that doing so can be crucial to the fight against cybercriminals. "Threat intelligence is very important; do not underestimate it. You need to share intelligence, use what you learn from others, and have a plan for when you get hit."

Hack Attribution

What makes "solving" cybercrimes particularly difficult is that attribution is hard. You may know that your organization has been hacked, but law enforcement agencies may have no idea where the attack came from - let alone who is responsible.
"We are getting better at fingerprinting attacks but it is very easy to put in false flag trails so attribution is difficult," said Woodward.
(The widely publicized Sony Attack in November 2014 HAS been attributed to The North Korean Government, But this only Possible Attribution WAS BECAUSE of information Provided by Local Rather Than Intelligence Agents by A Forensic Analysis of The hack.)  
This is in sharp contrast to traditional criminal landscapes, pointed out Andy Archibald, deputy director of the National Crime Agency's National Cybercrime Unit. He said most cities play host to people involved in illegal activity such as drug dealing, firearms sales, immigration scams and even the provision of hitman services. Law enforcement officers monitor and limit these activities using covert policing to build up a picture of who is involved in each crime field.

How to Fight Cybercrime, at a High Level

Because it is so hard to pin down those involved in cybercrime, the unanimous opinion of the law enforcement experts was that the best way to fight it is to disrupt their activities as much as possible.
How can this be done? Archibald suggested going after so-called bullet proof hosting services - many of which are based in China, other parts of Asia and Russia and its surrounding countries.
Bullet proof hosting services can be used by organized crime gangs to:
  • offer downloads of exploit kits and other malware
  • serve as botnet command and control centers
  • provide drop storage for stolen financial details captured by banking Trojans and other malware
  • host forums where stolen credit card information and exploit ideas are exchanged
He also suggested cracking down on money launderers who help organized crime gangs clean the proceeds of their crimes, and even going after anti-virus testing services. These can be used to help malware authors test if their software is susceptible to detection by common anti-virus software used in the enterprise, he said.
Disrupting cybercriminals may well be the most practical way to tackle their illegal activities, but at best it can only limit the number of their attacks, and resulting data breaches, rather than solving the problem completely.
That means that having clear plans in place to mitigate the damage of a data breach when - not if - your company gets hit is vital, Woodward stressed. "The number of businesses that go bust after an attack is growing every day, so knowing how to respond is absolutely key."


Wednesday, June 17, 2015

How to use two-step verification with your Microsoft account



Microsoft has offered two-step verification (2FA) process since early 2013. Also known as two-factor authentication or two-step authentication, the process strengthens your account security by requiring you to enter your password (step 1), then a security code (Step 2). The Security code Can BE Sent to you by E-mail, SMS, phone Call Or you Can Use an authenticator app on your Mobile device.
Enabling Two-Step verification on your Microsoft account Will Enable IT Across All Microsoft Services Currently That Support Two-Step verification, like Windows, Outlook.com , Office, and SkyDrive . Here's How to get Started:  

Enable two-step verification

microsoft-account-setup-two-step.jpg
On The 1st Step:  Go to this Account Settings page , and Look for an email Both Address and phone Number under The section titled "Security info Helps Keep your account secure." If either piece of information Is Missing, click on The Add Security info Link and Follow The prompts.   
The SMS functionality of 2FA relies on your phone Number Being Connected to your account, do not Skip SO IT. Otherwise you'll Need Access to your email account to Receive your Secondary log-in code.
On The 2nd Step:  Click on The "Set up Two-Step verification" Link.
On The 3rd Step:  Follow The Setup Process Until you REACH The end, Then click "Done." You May Asked to Provide BE A verification code, Sent to either your phone Via SMS Or to your email Alternate Address, Before you complete The Can Two-Step Setup. Once IT's complete, you shouldnt Receive an email Confirmation from Microsoft Sent to your email Alternate Address.

Pair an authenticator app with your Microsoft account

verification-app.jpg
You Can get Security Codes by email, phone Call Or SMS, But an Even EASIER passing Is to Use an authenticator app on your Mobile device. Authenticator Apps, like Google Authenticator, Run Locally on your device and Work Even IF your device does not Have an Internet Connection. The Use an authenticator app, you First Have to pair IT with your Microsoft account.
On The 1st Step:  Download The authenticator app of your Choice to your device. Android , iOS , and BlackBerry users Can Use Google Authenticator, While Windows Phone users Can Use Microsoft Authenticator   
On The 2nd Step:  Go back to your Microsoft account Security info page , and you shouldnt See A prompt to Setup an Mobile app. If not, click on "Set up Identity verification app" Link under The Identity verification Apps section.  
Step on The 3rd:  Launch your Preferred authenticator app, Then Scan The bar code on The Screen.
Step on The 4th:  The When Security code appears in The authenticator app, ENTER IT in The Box, Then click on The Pair Button.

Using two-step verification

Once you've enabled Two-Step verification on your Microsoft account, logging in to your Microsoft Services Will Require your account password and A Security code. Fill out The Required information (usually we The Four last digits of your phone Number, Or A Portion of your email Address) to Trigger The Security code Being Sent to your device. Otherwise, Launch Whatever app you Used to set up verification Codes (Google Authenticator, for Example) and Then ENTER The code in The Field text.
Lastly, Some Apps and Devices do not Support Security Codes. In those instances, you Can Go to The Security info page and Create an app password  to log in.