Skip to main content

Posts

Finally...!!! Microsoft introduces its new browser -Edge

Microsoft    is now ready with the new generation of lightweight, faster browsers like Google’s Chrome with a new name and branding for its Project Spartan browser project. The new Edge browser will be part of the new Office 10 suite of products and was unveiled today at the Microsoft Build developer conference in San Francisco. Microsoft Edge will be the only browser running on Microsoft Windows 10 mobile, but users can download the Edge browser or Internet Explorer 11 for laptops, larger tablets, or desktop machines as well. It’s still fuzzy if Edge will be available on other mobile platforms such as Google’s Android or Windows mobiles. The world has gone more completely mobile and browsing habits have changed. We now expect the web browser to handle phone calls, run web extensions, and applications. As our expectations changed, Internet Explorer did not and that's why we are running towards Chrome . In a blog post from March, when Microsof...

Cyber Bullying : Be careful... Once its said, the web is fed...!!

Hello Friends,  Today I bring a very serious topic of Cyber-bullying which is major concern in the society and corporate as well.  What is bullying ? Bullying means any unwanted, aggressive behaviour among school/college aged children or teen that involves a real or perceived power imbalance. The behaviour is repeated, or has the potential to be repeated, over time. Both kids who are bullied and who bully others may have  serious, lasting problems .  What is Cyberbullying? Cyberbullying is bullying  using electronic technology. Electronic technology includes devices and equipment such as cell phones, computers, and tablets as well as communication tools including social media sites, text messages, chat, and websites. Examples of cyberbullying : to send mean(vulgar) text messages or emails to spread rumours  by email or posted on social networking sites,  sending embarrassing picture...

ISO/IEC 27001 - Information security management

Hello Friends, Today we gonna talk about information security standards. I am sure you all are aware about ISO standards.So for IT there is 27k series including all IT requirements. The ISO 27000 family of standards helps organizations keep information assets secure. Using this family of standards will help your organization manage the security of assets such as financial information, intellectual property, employee details or information entrusted to you by third parties. ISO/IEC 27001 is the best-known standard in the family providing requirements for an information security management system (ISMS). What is an ISMS? An ISMS is a systematic approach to managing sensitive company information so that it remains secure. It includes people, processes and IT systems by applying a risk management process. It can help small, medium and large businesses in any sector keep information assets secure. Benefits of ISO 27001 By achieving certification to ISO 27001 your orga...

Is really Proxy free for use?

Hello Friends,  Last week Govt. of India have banned few websites for downloading, music and other content. Now may be you or our script kidding (so called hackers) will believe that they will use some free proxy sites to visit or use all those blocked website.  Are you one of them who is using free proxy from the open internet..? Many people use free proxy servers to access sites/content not available in their countries, or in order to “anonymously” browse the internet. When searching for a suitable proxy, you have surely noticed the relatively large number of free proxies. You try one, and although it’s a little slow, it works. You can now watch The Interview on YouTube even if it is blocked. Did you ever think about why it’s free? A proxy works as a traffic relay point. When using a proxy, all your traffic goes through that particular proxy server. This means, that someone, somewhere has to pay for a server and for a good internet connection, so that hundreds, t...

Threats & vulnerabilities considered for risk assessment

Hello Friends, Today I want to share the Threats & vulnerabilities we considered for implementing risk assessment. The list comprehends also threats & vulnerabilities from ISO 22301 in order to have the larger effect possible on improving confidentiality, integrity and availability of the assets. THREATS Access to the network by unauthorized persons Breach of contractual relations Breach of legislation Compromising confidential information Concealing user identity Damage caused by a third party Damages resulting from penetration testing Destruction of records Disaster (human caused) Disaster (natural) Disclosure of information Disclosure of passwords Eavesdropping Embezzlement Errors in maintenance Failure of communication links Falsification of records Fire Flood Fraud Industrial espionage Information leakage Interruption of business processes Loss of electricity Loss of support services Malfunction of equipment Malicious code Misuse of informa...

CIA Triad for- Base of Information security

The essential security principles of confidentiality, integrity, and availability are often  referred to as the  CIA Triad. All security controls must address these principles. These three  security principles serve as common threads throughout the CISSP CBK. Each domain  addresses these principles in unique ways, so it is important to understand them both in  general terms and within each specific domain: Confidentiality is the principle that objects are not disclosed to unauthorized subjects. Integrity is the principle that objects retain their veracity and are intentionally modified by  authorized subjects only. Availability is the principle that authorized subjects are granted timely access to objects  with sufficient bandwidth to perform the desired interaction. Different security mechanisms address these three principles in different ways and offer varying  degrees of support or application of these principl...

Hackers develop ATM -malware : No Card.. !! No PIN...!!

Security issues associated with Windows XP-driven ATMs - following the operating system going end-of-life earlier in the year - it appears that criminals have moved in for the kill, developing malware specifically designed to exploit cash machines that still run the embedded operating system. According to Kaspersky Lab, which has been working with Interpol on the issue, the malware - Tyupkin - allows criminals to gain cardless access to ATM funds using six digit access codes.Vicente Diaz, Kaspersky's principal security researcher said that the fraud shows that criminals are improving their tactics and appear to be able to gain enough access to ATMs to install program code.Kaspersky claims that the Tyupkin malware does not infect ATMs, but must be installed via physical access to the device. The criminals are then are able to check the amount of notes in each of the ATM's cartridges and select from which cartridge to draw up to 40 notes at a time.Diaz says that, based on ...