Skip to main content

Posts

Threats & vulnerabilities considered for risk assessment

Hello Friends, Today I want to share the Threats & vulnerabilities we considered for implementing risk assessment. The list comprehends also threats & vulnerabilities from ISO 22301 in order to have the larger effect possible on improving confidentiality, integrity and availability of the assets. THREATS Access to the network by unauthorized persons Breach of contractual relations Breach of legislation Compromising confidential information Concealing user identity Damage caused by a third party Damages resulting from penetration testing Destruction of records Disaster (human caused) Disaster (natural) Disclosure of information Disclosure of passwords Eavesdropping Embezzlement Errors in maintenance Failure of communication links Falsification of records Fire Flood Fraud Industrial espionage Information leakage Interruption of business processes Loss of electricity Loss of support services Malfunction of equipment Malicious code Misuse of informa...

CIA Triad for- Base of Information security

The essential security principles of confidentiality, integrity, and availability are often  referred to as the  CIA Triad. All security controls must address these principles. These three  security principles serve as common threads throughout the CISSP CBK. Each domain  addresses these principles in unique ways, so it is important to understand them both in  general terms and within each specific domain: Confidentiality is the principle that objects are not disclosed to unauthorized subjects. Integrity is the principle that objects retain their veracity and are intentionally modified by  authorized subjects only. Availability is the principle that authorized subjects are granted timely access to objects  with sufficient bandwidth to perform the desired interaction. Different security mechanisms address these three principles in different ways and offer varying  degrees of support or application of these principl...

Hackers develop ATM -malware : No Card.. !! No PIN...!!

Security issues associated with Windows XP-driven ATMs - following the operating system going end-of-life earlier in the year - it appears that criminals have moved in for the kill, developing malware specifically designed to exploit cash machines that still run the embedded operating system. According to Kaspersky Lab, which has been working with Interpol on the issue, the malware - Tyupkin - allows criminals to gain cardless access to ATM funds using six digit access codes.Vicente Diaz, Kaspersky's principal security researcher said that the fraud shows that criminals are improving their tactics and appear to be able to gain enough access to ATMs to install program code.Kaspersky claims that the Tyupkin malware does not infect ATMs, but must be installed via physical access to the device. The criminals are then are able to check the amount of notes in each of the ATM's cartridges and select from which cartridge to draw up to 40 notes at a time.Diaz says that, based on ...

Hacked Apple Devices

Today in the morning, a number of  Australian  users of Apple devices ( Connected  to iCloud) found their devices locked. Really this is a shock-full news. Customers find their Apple products like phones, tablets, and even laptops and  desktops  showing a message originating in Apple’s find my device service that states “Device hacked by Oleg Pliss” and  the user send US$100 to unlock  the device . According to the reports, the attack was initiated in the early hours of the morning across Australian, one user named ‘deskokat’ reporting that being woken up at 4:30AM with the associated ‘hacked by Oleg Pliss’ message and sounds being played out of their iPad. “I thought it was the morning alarm. I just signed in with my code, and all seems ok. I then signed in to my powerbook — but as a guest user — VERY grateful I did,” deskokat wrote. “Message to say I’d been hacked there too, wouldn’t let me sign out without...

My article for May'14 in Cyber Safar :- પાસવર્ડ ક્રેકિંગ & સિક્યોરીટી

પાસવર્ડ સિક્યોરીટી વિષે આમ તો આપણે  ઘણું જાણતા હોઈએ છીએ પરંતુ તેમ છતાં હોવી જોઈએ એટલી જરૂરી સિક્યોરીટી રહેતી નથી અને વારંવાર પાસવર્ડ ચોરી અને હેકિંગ ની ઘટનાઓ બનતી રહે છે.  સિગારેટ કે ગુટકાના પેકેટ પર જેમ મોટા મોટા અક્ષરે ચેતવણી આપી હોવા છતાં તેને અવગણવામાં આવે છે તેમ પાસવર્ડ સિક્યોરીટી માટે પણ જેતે વેબસાઈટ કે સર્વિસ પ્રોવાઈડર  દ્વારા અપાતી સૂચનાઓ ને અવગણવામાં આવે છે. આપણે આ અંક માં આપણે જાણીશું કે અલગ અલગ એપ્લીકેશન ની પાસવર્ડ સ્ટ્રેટેજી કઈ સેટ થાય છે અને આ પાસવર્ડ ને ક્રેક કરવો શક્ય છે કે નહિ. પાસવર્ડ ક્રેકિંગ :- કમ્પ્યુટર સિક્યોરીટી ના શબ્દકોશ પ્રમાણે કમ્પ્યુટર સીસ્ટમ માં સ્ટોર થયેલ એન્ક્રિપ્ટેડ (સામાન્ય યુઝર ના વાચી શકે તેવા) ને રીકવર કરવાની પ્રોસેસ ને પાસવર્ડ ક્રેકિંગ કહેવાય છે. પાસવર્ડ ક્રેકિંગ નો મુખ્ય હેતુ ભૂલી ગયેલા પાસવર્ડ ને ફરીથી રીકવર કરવા માટે હોય છે. પરંતુ ઘણી વાર તેનો દુરુપયોગ થઇ શકે છે.હેકર્સ આવી રીતે કોઈ પણ કમ્પ્યુટરમાં કે એપ્લીકેશન માં ઘુસી ને ડેટા ચોરી શકે છે. આપણા  આ આર્ટીકલ માં અપને જાણીશું કે પાસવર્ડ કઈ રીતે ક્રેક થઇ શકે અને આ ક્રેકિંગ...

Steganography : Technique to send secret Data

Steganography is the art and science of hiding information by embedding messages within other, seemingly harmless images or other types of media.  The word steganography is of Greek origin and means "concealed writing". The first recorded use of the term was in 1499 by Johannes Trithemius in his Steganographia, a treatise on cryptography and steganography disguised as a book on magic. Generally, messages will appear to be something else: images, articles, shopping lists, or some other covertext and, classically, the hidden message may be in invisible ink between th e visible lines of a private letter. Technical Steganography Technical steganography offers a broad variety of methods. It is nearly impossible to divide up all these methods. & Its uses scientific methods to hide a message, such as the use of invisible ink or microdots and other size-reduction methods. Some methods of technical steganography are: Invisible Ink One of the metho...

Disaster Recovery :- Save your information assets now...!!!

Disaster Recovery is the process an organization uses to recover access to their software, data, and/or hardware that are needed to resume the performance of normal, critical business functions after the event of either a natural disaster or a disaster caused by humans.  While Disaster Recovery plans, or DRPs, often focus on bridging the gap where data, software, or hardware have been damaged or lost, one cannot forget the vital element of manpower that composes much of any organization.  A building fire might predominantly affect vital data storage; whereas an epidemic illness is more likely to have an affect on staffing. Both types of disaster need to be considered when creating a DR Plan. Thus, organizations should include in their DRPs contingencies for how they will cope with the sudden and/or unexpected loss of key personnel as well as how to recover their data. Disaster Recovery Plans are generally part of a larger, more extensive practice known as Busin...