Wednesday, 2 May 2012
Want someone else’s Hotmail account
A few days ago, Whitec0de reported on a newly found vulnerability in Hotmail’s passwords. It enabled a hacker to take complete control of a user’s Hotmail account – not merely accessing the user’s mail, but preventing access for the legitimate account holder. It effectively stole the user’s entire Hotmail email database – and all the confidential and sensitive data it contains.
The methodology leaked out – it wasn’t difficult. “All hell broke loose,” said Whitec0de, “when a member from a very popular hacking forum offered his service that he can hacked ‘any’ email accounts within a minute.” The going rate was as low as $20 per account.
Yet again a great example why we need more than static passwords. When are we going to learn?????
Monday, 9 April 2012
Your Facebook credentials at risk
Thursday, 19 January 2012
The never-ending saga of passwords. When is enough enough?
For hackers, it was simply the Christmas gift that kept on giving. Having hacked the Texan-based database over the festive break, those responsible saw a seemingly never-ending run of headlines dominate the national agenda. For the UK, the game-changer was when The Guardian revealed that 221 British defence staff had been exposed as part of the hack. There were red faces all around. For whilst it is believed that staff would have different passwords to access more sensitive Whitehall information, it once again showed how easily static passwords can be snaffled, exposed and someone’s identity potentially stolen.
Yet passwords aren’t a new security ‘phenomenon.’ Indeed they’ve been around since the advent of the PC. The problem is that people don’t take them seriously enough. With headlines dominated by cyber crime, companies have invested in protecting their firewall. Put simply they’ve locked their houses, but left the windows open. It doesn’t matter how sophisticated your antivirus is, if a hacker has passwords then they can assume an authorised identity to wreak untold damage.
You might be reading this, thinking really are passwords all that important? Well, let me ask you a few questions. How do you secure users access to corporate information? How do you secure your IT systems? How do you check who is authorised to access what information? How do remote workers access the network? Yes, you guessed it – passwords. The reason that passwords are such a vulnerability is because human nature dictates that not only will the password not be selected at random but have a personal connection to the user (something that any hacker can deduce within seconds), but that for ‘ease’ they will use the same password and log-in for every application. Once you have one password, the entire corporate network opens up before you. And who is going to stop you? As far as the system is concerned you’ve been authenticated.
The advent of tablet PCs and smartphones is only exacerbating the situation. Most users store email and company sensitive information on mobile devices without giving it a second’s thought. Access to this data allows them to work on the move and keep pace with their colleagues during the working day. But what many people don’t realise is that most smartphones will automatically log you on to free Wi-Fi. Brilliant, who doesn’t love free Wi-Fi? You might think it’s easy and convenient, but for hackers free Wi-Fi spots make accessing sensitive information like taking candy from a baby. They can set up a rogue spot and within seconds of you logging on have not only users corporate passwords, but also passwords for their mobile banking and Face Book account, amongst others.
In a world where hackers are scoring big-wins, companies cannot afford to secure access to their systems with static passwords. And neither can they afford to be exposed by third parties they work with that have less than robust security policies in place. At the time of the hack Stratfor defended itself and stated that the passwords had been encrypted but clearly this posed no obstacle for the hackers responsible. The only way to protect against such attacks is to implement one-time passwords and strong user authentication.
In the past many companies have dismissed two-factor authentication as too expensive to implement and manage or that it interferes with the user experience. Yet, that is no longer the case. The barriers of cost, complexity and management have been removed and now companies of any size can use it. For the price of a cup of coffee, businesses can now secure unlimited users, via multiple channels, whether that is through the cloud, smartphone apps or key fobs.
Stratfor once again demonstrates that despite all the hype of cyber security, passwords are a real threat to businesses around the world. How many more incidents must we read about before businesses move away from static passwords and start to better protect themselves and their customers against hackers?
Tuesday, 22 November 2011
Smartphones in the enterprise: A false sense of security
Security has been about evolution. First came the PC, big and clunky it taught us about the importance of keeping the good guys in and the bad guys out. Then came the era of laptops and, well, losing them which showed – at the expense of some very red faces - the importance of ensuring secure remote access. And now comes the new generation; the smartphone. Surely by now we’ve learnt our lessons from the past and are well prepared for the next iteration of security challenges that the move to mobility will bring with it?Well, not quite. In many ways, it feels like Groundhog Day, with the same mistakes being played out. The 2011 Get Safe Online campaign kicked off with a warning aimed at educating consumers about the security scams out there targeting their smartphone. But with more and more smartphones being deployed in the corporate environment, arguably it is businesses that have the most to lose.
Smartphones have become the bedrock of any remote access strategy. Easy to use and intuitive they enable staff to access email, download and work on attachments as well as access corporate weband cloud-based applications such as Salesforcewhilst on the move. But it is this very ease of use that lulls people into a false sense of security. Would you like it to remember your password for next time? Yes please. Would you like to enable automatic log on? Yes please. All these quirks designed to make our lives easier, only hasten the speed with which a hacker - or even someone that has found your lost device - can get into sensitive files or the corporate network and do damage.
For example, most mobile devices from tablet PCs to smartphones are set up to automatically search for and log onto the nearest WiFi hotspot. And who says no to free WiFi? But with some cheap equipment from a high street electrical store a hacker can set up a ‘fake’ WiFi spot and snaffle all the passwords they need to break into the corporate network using someone else’s identity in a matter of seconds. And as the lines between personal and professional use of smartphones start to blur, it is becoming even harder to mitigate the risks.
Most IT departments and security chiefs know that if their company rolls out iPhones, staff will download applications from the App Store. Until last week they were probably quite relaxed about this as Apple has a ‘quality control’ process in place before apps can be sold and downloaded. But the discovery of a rogue app has shown that Apple’s processes are foolproof. What looked like a harmless appwas actually designed to unleash chaos. And what of Android? Predicted by Ovum to gobble up a 25 per cent share of the enterprise market in next five years. Yet its Market Place has no rules or any way of governing what applications are uploaded onto its Market Place and made available to an unsuspecting public.
Right now, companies can’t validate if people accessing the network are who they say they are. Instead they rely on static passwords to authenticate the person rather than one time use passwords which are unique and can’t be stolen. Traditional approaches to passwords are the weakest link in any security policy; companies shouldn’t continue to make the same mistake in the mobile world.
Monday, 31 October 2011
Spy Smartphone Software Tracks 'Every Move'
http://news.sky.com/home/technology/article/16099260
Tax rebates stolen by Revenue and Customs hackers – from today’s Sunday Times
Fraudsters have found a way to hack into government tax records and divert refunds meant for others into their own bank accounts.
An investigation by The Sunday Times has revealed that criminals are secretly examining HM Revenue & Customs’ records looking for anyone who has paid too much tax. They then change the details of the bank accounts into which the repayments are to be made.
Alternatively, the hackers file fictitious tax returns showing large overpayments directly into the HMRC computer in the names of genuine taxpayers, then ask for refunds.
Victims become aware of the scam only when they are officially contacted by HMRC and told an overpayment is being transferred into their account.
HMRC is now facing questions over its security procedures and how the hackers are able to infiltrate its records. Experts claim it has failed to react as promptly as the banks to the risk of online fraud.
Roger Symes, 53, a ship broker from Surbiton, in south-west London, received a letter last month from HMRC advising him of a refund. He said: “They gave details of a bank account into which they were paying the money, but it wasn’t my bank account.
“My accountant said he had the same problem with 18 other clients.” The refunds applied for were between £100 and £4,000.
The hackers are accessing the tax files using the sign-on and passcodes assigned to accountants who file clients’ tax returns online. How they are obtaining these security details is unclear. It is not known whether it is via computer attacks on individual accountancy firms or by breaching HMRC’s own systems.
One hacker who spoke to The Sunday Times this year said he had accessed HMRC’s systems and had been able to obtain details of agent sign-ons and passcodes. A security expert said the claim was credible but HMRC denied its systems had been compromised.
Once a hacker has an agent sign-in, he can read the tax records of all the accountant’s clients, amend them and change the bank account details. Accountants who have spoken to this newspaper said hackers have been accessing taxpayer records for at least two years.
Claire Savage, a chartered accountant in Milton Keynes, Buckinghamshire, spotted irregularities in one of her clients’ files in June last year.
She said: “I called him up to ask about his new bank account, which turned out not to be his at all. When I realised that security had been breached I went through all of my clients’ files. A fair chunk of them — around 10 — were affected, and repayments of up to £3,000 had been requested in each case.” None of Savage’s clients lost money to the fraudsters.
Ralph Hayden, a chartered accountant at GW Cox & Co in Frinton-on-Sea, Essex, said 41 of his clients had been affected by a similar scam, which was first noticed in November 2009.
He said: “HMRC said that it must be our systems that had been breached but we called in computer experts who confirmed that it definitely wasn’t.
“In most cases, a tax return had not yet been filed, so a false return was submitted. In others, their returns had been edited, so that a repayment was now due. HMRC were not advising their frontline staff in case it was an inside job.”
On hmrconline.com, a blog about the HMRC, one taxpayer reveals that his accountant was also targeted. The posting states: “We recently returned from holiday to the news that 91 of our accountant’s client accounts had been hacked at the HMRC government gateway website.
“Hackers had accessed information on 91 individuals or organisations and had entered false end-of-year accounts in order to claim self-assessment refunds.
“We then received a letter from HMRC to advise us that the refunds were on their way to what we knew were false accounts. They actually paid out. HMRC now apparently know what they have done but to add insult to injury they have now started to send demands for repayment to the people [whose] accounts had been hacked.”
Unlike HMRC, the big banks ask customers conducting transactions online to provide additional passcodes for each financial transaction. These are generated by inserting a bank card into a hand-held reader provided by the bank.
Jason Hart, managing director of Cryptocard, a computer security company, said: “If you just had a static passcode, then once it’s compromised, you’re going to be a massive target for the fraudsters. It’s an invisible threat because they can get into your system at any time and you don’t even realise.”
Sunday, 30 October 2011
Spy Smartphone Software Tracks 'Every Move'
11:14am UK, Sunday October 30, 2011
Sam Kiley, security editor
As marketing pitches you don't get much lower: "Track every text, every call and every move your spouse makes…"
Yes, software manufacturers have harnessed the green-eyed monster.
"A cell phone plays a role in almost every affair," said one producer of mobile phone spyware.
Another spelled it out: "When you begin to notice signs of a cheating spouse, the best way to catch that cheat is to spy on his or her cell phone using spy software.
"Such software is required because the cell phone has become the modern day keeper of secrets and its uses are as versatile and diverse as their makes and models."
But it is not just for jealous partners.
There is no way that a victim would know his phone had been comprehensively hacked.
Software designed to completely mine every secret on a smartphone can track its users, record their calls, copy their emails, read their text messages and bug the rooms the phones are sitting in.
Jason Hart, a cyber security expert with Cryptocard, explained how easy it is to turn a mobile phone into a pocket spy.
It starts with a little 'social engineering'.
By hacking the phone of someone the victim might trust, and learning something about them from reading their Tweets and Facebook page, the attacker will send a personalised email from a known account.
The user opens an email and a document, a picture, letter or pdf file.
A programme can be embedded in the attached document which takes the hacked user's phone off to a secret website site which covertly downloads spying software onto the smartphone.
Shortened weblinks are also a risk.
"Using Facebook and Twitter (and) getting an individual to click on a shortened link would actually take them to a website and automatically install malware," said Mr Hart.
"There is no way that a victim would know his phone had been comprehensively hacked."

Spyware 'can covertly operate all of a smartphone's functions from afar'
Attacks on smartphones shot up by 46% last year, and this year the percentage is likely to be in the thousands.
We loaded the commercial software onto my phone and very quickly Mr Hart was watching my emails come through.
The vendors of the software promised that he would be able to intercept and listen to my calls - we could not get that to work. But, as a bug, my phone was close to perfect.
The software meant Mr Hart could dial into my phone and it would secretly answer - broadcasting any conversation I was having near the handset back to him.
"Once a criminal or spy has got hold of software like this and loaded it onto your phone, there is very little indeed that you will be able to do either to detect or, or defend yourself. This is a total compromise," Mr Hart said.
Spyware can covertly operate all of a smartphone's functions from afar, turning it on and off, and stealing its secret contents.
Almost 500,000 new smartphones will be sold this year around the world.
Malware developers are running ahead of the industry's ability to develop tools which, in any case, would inevitably restrict how useful smartphones can be to a customer.
But, as losses to intellectual property theft are estimated to cost the UK £17bn a year, it is clear companies will be demanding an air gap between smartphones used for business - and smartphones used for everything else.
So, for the skiving worker, the truant teenager and the faithless spouse, there can only be a few words of advice - that phone isn't smart, it's a sneak.
Monday, 17 October 2011
Password Risks - Smart Phones at risk
An estimated 480 million smartphones will be sold this year. They are indeed wonders of technology.
Henry Harrison, from UK cyber security experts Detica, said: "This is a fully fledged computer that's sitting in your pocket." It can, and probably will, betray you as a result.
The flaw in the smartphone is that it is too useful and too user friendly - for users who trade convenience for security.
They collect our emails, store our bank details, we tweet and use Facebook on them. They are our bank vault, our confidante, our guide.
But as Cryptocard's Jason Hart demonstrated - they are our new Achilles heel.
Mr Hart purchased a cheap item of equipment from a high street electrical store and downloaded free software from the internet - all he needed to set up an "evil twin" Wi-Fi connection.
Criminals use these to harvest passwords and other sensitive data from smartphones or computers - often giving their Wi-Fi hotspots fake names familiar to punters at cafes and in airports.
Full story: http://news.sky.com/home/technology/article/16090250
Monday, 10 October 2011
Facebook Passwords
Social media users are increasing their chances of identify fraud, by providing clues to their online passwords.
A study by me commissioned by life assistance company CPPGroup Plc (CPP) has revealed that one third (32%) of Facebook profiles contain at least two pieces of personal information such as their mother’s maiden name, date of birth, hobbies or children’s names. This information is often also used as a password or as an answer to a security question when users look to reset their online account log-in details.
In the study, details including the name of the user’s first school (64%), employer (46%), dates of birth (25%), children’s names (25%) and favourite football team (17%) were found to be visible on many people’s Facebook profiles.
As the most active social media users, those aged 18 to 24 with a Facebook account are the most likely to publicise their personal information – and often to complete strangers. This age group has on average more than 250 friends but 81%[i] say they do not trust all of their Facebook ‘friends’. Half (50%) have accepted a friend request from a total stranger and 9% would accept an invitation from someone they did not know if they were good looking or popular.
But it’s not just the 18 to 24 year olds who are making themselves vulnerable - users of all ages are putting themselves at risk. One third (33%) of all those with a Facebook account admit to accepting an invitation from people they had never met before, with 38%[ii] confessing they don’t know everyone they are friends with on the site.
Over half (52%) of the Facebook account holders questioned had received friendship requests from strangers. And despite recent media controversy around privacy and security on the site, one in twenty (6%) users allow anyone and everyone to see their entire profile.
Danny Harrison, CPP’s Identity fraud specialist is calling on individuals to not use personal information for online passwords or security questions.
“It isn’t a good idea to use personal information for passwords online. Sharing is the whole point of Facebook and other social media sites, so users are naturally going to promote their personal information online. The problem is this information could be used by fraudsters to reset passwords and access people’s online accounts. To compound the problem, there are tools available online that can capture keywords from a website, including a Facebook profile, and others which will trial variations of the identified keywords until a password match is found.
For this reason, we are advising people to not use personal information as a means to verify their online identity and facilitate access to their online accounts.”
Personal information most commonly used as passwords[iii]:
1. Interests
2. Hobby
3. Favourite football team
4. Favourite football player
5. Children’s names
6. First school
7. Pet’s name
8. Dates of Birth
9. The user’s name
10. Maiden name
For further details please refer to my white paper.
Friday, 7 October 2011
Sky News Live Web Chat
Join Our Chat On Smartphone Security
Wifi can make smartphones potentially vulnerable to hackers
11:18am UK, Monday October 17, 2011
The growing number of iPhones, BlackBerrys and other smartphones provide an opportunity for cyber criminals to steal your data.
More than four million people in the UK have been the victims of identity fraud, with wifi access meaning secret passwords stored on your devices are vulnerable.
Ethical hacker Jason Hart answers your questions on how to keep your smartphone safe.
Monday, 27 June 2011
Just how easy is it to hack into your life?

Last week I was asked by Neil Tweedie to demonstrate how easy it is for someone to hack into your life. After three questions about his family i tap away on my keyboard. Two minutes later - just two minutes - an email arrives in Neil's work inbox.
“I didn’t need all three answers, just the one,” explains the cyber security adviser. “Now I have control of your email and with it knowledge of your financial transactions, interests and friends. I can access your online accounts and use your credit card details to go shopping.”
Hacking is back in the news. This week Ryan Cleary was arrested at his home in Essex and charged with disrupting the website of Britain’s Serious Organised Crime Agency (Soca).
Agencies in the United States are also understood to be investigating whether he was involved in similar attacks on the United States Senate, the Central Intelligence Agency and Sony by an international hacking ring called LulzSec (short for Laugh Out Loud Security). Cleary is 19 and, according to his mother, a recluse, leaving his bedroom only rarely. But for hackers, the world, the cyber world, is their oyster. They can pay you a visit, harvest your most sensitive information, and disappear without trace.
For the full story please refer to: http://www.telegraph.co.uk/finance/newsbysector/mediatechnologyandtelecoms/digital-media/8597757/Just-how-easy-is-it-to-hack-into-your-life.html
Tuesday, 22 March 2011
E-bay phones blog post
Due to rapid technological advances, smartphones have much more memory and capability to save personal data, increasing the risk of identity fraud to users. This threat will only increase further if people continue to store data, including credentials like usernames and passwords, on their mobile phones.
Over half of the 35 used mobile phones and 50 SIM cards analysed contained personal information on them - 247 individual pieces of data in total. The information recovered included personal and at times, highly sensitive information which, fallen into the wrong hands, could put the previous owner at direct risk of identity fraud.
One thing that was clear from the investigation was that perhaps unsurprisingly - due to their increasingly central role in users’ day to day lives - smartphones hold much more personal information on them about their former owner compared to older mobile phone models. An analysis of one smartphone alone uncovered usernames, passwords, credit card information, videos, company information, photos, email addresses and notes - certainly enough information to start a social engineering attack. For a start, a fraudster would quite easily be able to take ownership and control of the previous owner’s email account, login to online shopping sites they had visited and purchase items fraudulently.
The worrying combination is this: most mobile phones do not allow a user to totally remove all personal content or user data, and the ability to recover deleted data from a mobile is a very simple process that can be undertaken with limited technical knowledge. For the purposes of this experiment, I used SIM card readers and software that can be easily accessed in the public domain.
These results highlight a clear requirement for heightened awareness amongst consumers about the need for digital security on their phones. An effective way for this threat to be reduced is by the use of Two Factor Authentication, meaning the user generates a onetime password on demand. The sooner a commodity based authentication service is available the sooner we are going to minimise the risk.
But until such an authentication is commonplace, what can consumers do to protect themselves from passing on their personal data in their old phones or SIMs? In the first instance, never keep an old SIM card – remove it and destroy it. Also, regardless of whether they intend to sell on their mobile phone, users need to be careful not to store vast amounts of personal information on their devices. The less data that’s on a mobile device in the first place, the easier it will be to wipe and protect the user. Other keys steps to help consumers protect themselves include:
• Restore all factory settings - This is the first step to take to conduct a top level clearance of data on the handset
• Delete any back-ups - Even if data stored on a smartphone, PDA or laptop is securely removed from the mobile device, that’s not to say it won’t exist on a back up elsewhere
• Log out and delete – It’s vital to log out of social network sites accessed on the phone as well as wireless connections, company networks and applications. Once logged out, delete passwords and any wireless connections.
• Various passwords - The use of the same ID/password combination on multiple systems, and storage of them on mobile phones should be avoided. If it is necessary to store these details on a phone, it’s best to try and use a picture reminder of the password.
Remember, if a phone is being sold on to a retailer, it should be wiped and the SIM card destroyed.
If you want more information on how to protect yourself or see how these experiments worked, please visit CPP’s blog
Monday, 11 October 2010
My Recent Wardrive

Following my report on my Wardrives around Bristol, Cardiff, London, Birmingham and Manchester I came to an interesting – and frightening – conclusion. And there were two points to this conclusion: firstly people rely on WEP or its derivatives far too much, and secondly the great misconception that people have about hotspots being secure.
To my first point then...WEP encryption is not the security measure people think it is. Most do not know that cracking the encryption can be ridiculously easy; all you need is a gadget, some free software, wi-fi and a little patience. From there it’s just a matter of capturing users’ data – their username, password and details of the website they’re accessing.
And regarding the second point – with users’ assuming they’ll be secure when using a hotspot I’m afraid they could have a nasty surprise one day. A lot of hotspots have said encryption above and as well as cracking that encryption, there are other ways to ‘snoop’ on what people are doing – again enabling the criminal to capture their usernames and passwords.
Also, do you notice that I keep mentioning that in each case above it’s the hotspot user who is the one losing their identities? While the proliferation of free wi-fi, hotspots and criminals will not be letting up any time soon, there is one thing people can do to protect themselves – and the applications they access: and that is to have better password protection. For the user it could be a longer, stronger password and for businesses who want to protect their digital assets, it could be equipping your employees with two-factor authentication.
Sunday, 1 August 2010
My response to a recent article in the Telegraph

Man who published details of 100m Facebook users 'learning how to break passwords'
http://www.telegraph.co.uk/technology/facebook/7917373/Facebook-security-fears-after-private-details-of-100m-users-leaked-to-web.html
With regards to the Facebook security fears after 'private details of 100m users leaked to web'.
I wanted to very definite responded to this……nothing makes a password truly secure!
Static passwords are fundamentally insecure and signify the biggest security threat facing organisations today. Readily available software such as invisible keyloggers allows hackers to capture every name and password of any user on a network.
Invisible keyloggers have the capability to override the latest security software in order to steal user names and passwords, no matter how long or complex the user makes them. Hackers can and do use this software to extract and manipulate information from user’s e-mail addresses, social media accounts and even IT networks protected by a secure encryption protocol.
Passwords are the softest security target and until people and organisations start adopting strong authentication in the form of for instance two-factor authentication this problem won’t go away
Worrying only a small per cent of businesses use 2FA.
Business of all Sizes have to starting getting there heads of of the clouds and replace static Passwords with Two Factor Authentication
Friday, 18 June 2010
Tutorial 1 - Hacking The Email Password of a Pop Account

Tutorial 1 - Hacking The Email Password of a Pop Account
I'm going to get straight into the first, and simplest attack you can carry out with Cain: Acquiring someone's email pop account password.
1. You need to be on the wireless network of the computer you are targeting.
2. You need to have Cain's configuration set up as in Tutorial 1.
3. The target must not be using ssl-pop (this is very unusual so you should be fine).
The following is a step by step guide to capturing the pop password (a lot of the early steps will be used for further tutorials):
Open Cain and go to the 'Sniffer' tab along the top row. Make sure you also turn on the sniffer, using the icon in the top left which looks like a little network card.
Right click in the empty grid below and select 'Scan Mac Addresses'. Choose 'All hosts in my subnet'.
A list of IPs, MAC addresses, computer names and (empty) user names will appear. If you know the computer name you want to target, great. If you need the user name however, simply right click on the computer you are interested in and select 'Resolve Host Name'.
Now you are ready to begin ARP poisoning your target. There are many explanations of poisoning but I will not go into it in detail here as it will detract from the tutorial. Essentially, you are telling the server that you are the target's computer, while telling the target that you are the server. In this way all traffic from the target is passed through you before reaching the server...and vice versa.
Click on the APR tab along the bottom left row of icons.
Make sure your mouse cursor clicks in the top one of the two empty grids. Then click on the blue plus arrow on the top row of icons.
You will be presented with a list of IPs, MACs and names in the left grid. Select the one which corresponds to your server, usually called 'Home' or the name of your internet provider's router. It should stand out.
Then in the right hand grid, select the computer you want to target. Click OK.
To begin ARP poisoning your target, click on the radiation type symbol in the top left, next to the sniffer symbol - which you will have turned on a while back.
You should now see traffic begin to accumulate in the grid underneath - if there isn't any then either your target is on a sneaky break and turned off their computer, or perhaps you have not selected the correct device as in Tutorial 1.
All that now remains is to wait until your target either checks their email through Outlook (or similar like thunderbird etc) or sends an email.
Now click on the tab called 'Passwords' on the bottom row. You will probably see lots of http entries popping up - don't worry about these for now.
Watch the 'pop3' and 'smtp' entries (you don't have to sit and watch constantly, you might get a bit bored!).
Sooner or later an entry will appear in one or both of those fields. It will contain the username and password of the pop email account.
This method has been tried and tested on many occasions as part of our network security probes. It's worked every time, and usually very fast, as people like to check their emails often.
As with any of these posts, if you are having trouble, leave a comment here and I will reply to you as soon as possible.
Thursday, 17 June 2010
An insight into work of the hacker.
In a desire to reduce risk and meet compliance and audit requirements, companies invest in security technologies including firewalls, anti-virus and anti-spy/spam. The smart ones also implement security policies and controls in an effort to protect their network, assets, and business. Unfortunately all this can be defeated instantly because hackers too are harnessing new methodologies, technologies and resources. Hackers will try the easy route first, looking for the weakest links in your network, such as an out of date OS, an un-patched web server, or default configurations. But the easiest by far is getting your password.
While usernames are used in conjunction with passwords, they cannot realistically protect your data or business. Companies assign usernames systematically, often using standard first name/last name formats, making it a breeze for a hacker to find or guess a username. All that is left to protect your system is a vulnerable password and as such entry is ‘authorised’ there will be no sign of forced entry, and little chance of an alarm being raised; the biggest and most invisible threat facing us all. So, how exactly do hackers go about getting passwords?
The methods range from the ridiculously simple to highly technical. Guessing the password is ridiculously simple. A recent study of 32 million passwords showed just how ‘guessable’ passwords can be. ‘123456’ was in first position with ‘Password’ at fourth and nearly 50% of users, used names, slang words, dictionary words, or trivial passwords using consecutive digits, adjacent keyboard keys etc. A quick web search will present a hacker with a handy list.
Hackers rely on continued use of the password because it is so weak. Phishing and phasing attacks use “dummy” web sites to trick users into providing passwords and personal details. Social networks are now firmly established as a great resource for hackers who see them as the best Social Engineering Hacking tool.
A more technical approach may involve the use of traditional keyloggers, and sniffing programs, and all are available free on the internet. Typing ‘Password Hacking’ into Youtube will return over six-thousand videos demonstrating the password hack and so even the novice is off to work. With passwords so discredited, there are three key things to consider in response.
1. Password best practices state:
• They should contain at least eight characters
• They should contain a mix of four different types of characters - upper case letters, lower case letters, numbers, and special characters. If there is only one letter or special character, it should not be either the first or last character in the password.
• It should not be a name, a slang word, or a dictionary word. Neither should it include part of your name or e-mail address.
• Passwords should be changed every 30 – 90 days
2. Check your infrastructure for unnecessary or out of date bug-riddled network devices, services, or applications? Conduct a regular network audit.
3. Educate users on password security, social engineering threats and some of the latest trends. They are users not security specialists. Do they know all of the above? Do they know not to use the same password across their social and business applications? You have a duty of care.
Good password practice will help, but two-factor authentication takes it to a new, much more secure level. Providing users with a PIN and a token which generates a one-time password, valid for a single use, will deprive hackers of their quiet and invisible entry into your network. Through a combination of implementing best practice, keeping your network infrastructure robust, and employees educated, the hacker risk can be mitigated and your confidentiality and integrity maintained.
Thursday, 18 February 2010
Cloud Security
There is however a but; many Cloud-based services available today, can often lack the appropriate level and type of security protection required to prevent hackers accessing sensitive data stored, accessed, and transported through the Cloud. Even organisations that have shown a reluctance to take up Cloud computing may actually be using services based in the Cloud without realising it. For example, applications such as Salesforce and Google apps are Cloud-based, as are social networking services, including Twitter and LinkedIn.
Industry experts express concern that businesses joining the Cloud computing bandwagon to benefit from its impressive repertoire of benefits, may not be making an appropriate and necessary review of its impact on existing security policies. As one who focuses on security and was once and ethical hacker, I am concerned that moves to a virtual world, using Cloud-based technologies could end up being a disaster, unless businesses act fast. My concern centres on the number of vendors and providers who frankly are only paying lip service to security and are more caught up in the hype than the reality. Every service or platform I look at is still only secured by a traditional password, and that is just not sufficient to keep hackers at bay, and to guarantee confidentiality or integrity; consider the recent attacks on Twitter…
Because Cloud computing represents a revolution in IT management, it is a paradigm shift and this makes it even more critical that businesses review their security policies again. With more than 223 million records containing sensitive material compromised since 2005, according to Data Breach DB, a clearing house for data breach information, and the more recent attacks on Twitter in July 2009, businesses must make Cloud security a new priority.
The easiest way to conduct fraud online is through stealing a valid user name and password using tools like key loggers or old fashioned social engineering. You wouldn’t even know it had happened. Organisations need to review security policies and ensure that they are adequately protected. On average it takes less then a minute to gain someone’s username and password. There are many technology tools available today, as well as complementary services to boost security. We need to remember that business is about people, processes and technology and it is essential that all users are aware of the dangers and how to mitigate them. I strongly recommend that businesses take some simple and immediate steps to counter the threat of identity theft and hacking, and go through a process to ensure its data, its business, and its future is as secure in the Cloud as it should be in the Enterprise.
My recommendations for improving cloud security
1. Teach all end users safe internet skills
2. Perform a detailed vulnerability assessment
3. Ensure anti-virus protection is current and kept up to date on all devices
4. Use a firewall to protect every point in the organisation
5. Use VPN technology for secure connections and encryption for all information on portable devices
6. Deploy strong authentication for remote users, requiring a strong password, PIN, and separate token
Thursday, 21 January 2010
Maximising Margins in Security and Convergence
Sandown Park Race Course, 23rd February
York Race Course, 25th February
Friday, 1 January 2010
Wecolme to my Master Class Series.
In this edition I Sees if an SSL VPN is Really Secure?
Looking at the increasing buzz around federated ID
Looking at identities at risk.
