Showing posts with label INTERNET. Show all posts
Showing posts with label INTERNET. Show all posts

Monday, 30 November 2020

Phishing email and fraudulent website

  Don't believe in such email as below; Don't just see the name of the sender, check the sender's email address:


If you fall for it and click the link will take you to:


IT LOOKS LIKE THE OFFICIAL CYPRUS POST OFFICE

Take a look the the URL  https: // cyprus- inc -cy. com/ user/ d8b6d

and DON'T FALL FOR IT

Sunday, 27 September 2020

Ransomware Attacks are not problem for us

 


If there is one characteristic that defines cybercrime today, it is the capacity to evolve and adapt to new environments and the ability to find ways of evading the cybersecurity measures taken by victims. 

Ransomware is no exception. One of the main features of ransomware as a threat, in addition to kidnapping data, is that it is constantly reinventing itself to persist over time and ineffectiveness.

This type of malicious software has evolved greatly since it began, and today there is a wide variety of families in existence, giving rise to new, more sophisticated strains.

Did you know that?

  • 65% of ransomware infections are delivered via phishing 
  • A ransomware attack will take place every 11 seconds by 2021 
  • 85% of ransomware attacks target Windows systems. 
  • The average cost of a ransomware attack in 2019 was $133,000 
  • 50% of IT professionals don’t believe that their organization is ready to defend against a ransomware attack.  
  • Hackers attack  every 39 seconds or an average of 2,244 times a day 
  • Between January 1st and June 30th, 2020, ID Ransomware received 100,001 submissions relating to attacks that targeted companies and public sector organizations. 
  • 90 % of IT pros had clients that suffered ransomware attacks in the past year 
  • Ransomware costs will reach $20 billion by 2021 
  • 51% of businesses have been impacted by ransomware in the last year
  • 0 affected Scicane customers
Don't be a victim - Contact us for further information @ info@scicane.com (no obligation)

Friday, 8 May 2020

Adobe FLASH RIP


Adobe posted on the 25th of July 2017 the forthcoming death of Flash player.


Adobe has long played a leadership role in advancing interactivity and creative content – from video, to games and more – on the web. Where we’ve seen a need to push content and interactivity forward, we’ve innovated to meet those needs. Where a format didn’t exist, we invented one – such as with Flash and Shockwave. And over time, as the web evolved, these new formats were adopted by the community, in some cases formed the basis for open standards, and became an essential part of the web.

But as open standards like HTML5, WebGL and WebAssembly have matured over the past several years, most now provide many of the capabilities and functionalities that plugins pioneered and have become a viable alternative for content on the web. Over time, we’ve seen helper apps evolve to become plugins, and more recently, have seen many of these plugin capabilities get incorporated into open web standards. Today, most browser vendors are integrating capabilities once provided by plugins directly into browsers and deprecating plugins.

Given this progress, and the collaboration of several technology giants – including Apple, Facebook, Google, Microsoft and Mozilla – Adobe has planned to 'switch off' Flash. Specifically, they will stop updating and distributing the Flash Player at the end of 2020. They encourage content creators to migrate any existing Flash content to these new open formats.

Firefox and Chrome keep notifying users when visiting flash enabled sites that they will stop working at the very same date. Thus get prepared, any site you depend on, is using Flash, you will not be able to open or run (if you are the owner/hoster) by the end of this year.

Thursday, 2 April 2020

Zoom: It appears to have more problems than it solves

Zoom admits meetings don't use end-to-end encryption

Video conferencing app Zoom does not use end-to-end encryption, according to reports, despite specifically stating that it does on its website.


Though Zoom offers users the option to “enable an end-to-end (E2E) encrypted meeting,” and provides a green padlock that claims “Zoom is using an end to end encrypted connection,” the company this week admitted that offers no such thing.

A spokesperson for the company told The Intercept that, despite its claims, it was "currently not possible" to enable end-to-end encryption for its video meetings.

Instead, the spokesperson revealed, the service uses Transport Layer Security (TLS) which encrypts data between user's meetings and Zoom's servers. End-to-end refers to data encrypted between calls, blocking out third parties - which includes the service provider. As a result, the company can see and use the data for things like targeted ads. 

"When we use the phrase ‘End to End’ in our other literature, it is in reference to the connection being encrypted from Zoom end point to Zoom end point,” the spokesperson added.

Part of Zoom's appeal to organisations is its simplicity and the fact it can be used for free, albeit without any premium features, which lets businesses try it out before forking out any money. "Video conferencing is a fantastic necessity in times like these but it is vitally important to understand the security and privacy concerns that go in parallel with this increasingly popular form of communication," said Jake Moore, a cyber security specialist for ESET. "For social and light business meetings they are fine as long as users realise what data is being shared by Zoom to third parties. I certainly wouldn't recommend using free software for sensitive or private meetings."

Unpatched Zoom App Bug Lets Hackers Steal Your Windows Password

According to the latest finding by cybersecurity expert @_g0dmode, which was also confirmed by researcher Matthew Hickey and Mohamed A. Baset, the Zoom client for Windows is vulnerable to the 'UNC path injection' vulnerability that could let remote attackers steal login credentials for victims' Windows systems.


The attack involves the SMBRelay technique wherein Windows automatically exposes a user's login username and NTLM password hashes to a remote SMB server when attempting to connect and download a file hosted on it.

The attack is possible only because Zoom for Windows supports remote UNC paths, which converts such potentially insecure URLs into hyperlinks for recipients in a personal or group chat.


To steal the login credential of user running zoom for Windows, all an attacker needs to do is sent a crafted URL (i.e. \\x.x.x.x\abc_file) to the victim over its chat interface, as shown, and wait for the victim to click it once.

To be noted, the captured passwords are not plaintext, but a weak one can easily be cracked in seconds using password cracking tools like HashCat or John the Ripper.

In a shared environment, like office space, stolen login details can be reused immediately to compromise other users or IT resources and launch further attacks.

Besides stealing Windows credentials, the flaw can also be exploited to launch any program already present on a targeted computer or downloaded as part of the attacker's social engineering campaign.


Zoom has already been notified of this bug, but since the flaw has not yet been patched, users are advised to either use an alternative video conferencing software or Zoom in your web browser instead of the dedicated client app.

Source(s) & more info: Hacker News, ITPro

Sunday, 29 March 2020

UPDATED: Zoom beams iOS user data to Facebook for targeted ads

According to ITPro, Zoom has updated the code in its platform to remove the in-app ‘Login with Facebook’ feature on iOS platforms after it emerged the Facebook SDK was unnecessarily collecting user device information.

The conferencing app, which has exploded in popularity, doesn’t explicitly say it sends data to Facebook in its privacy policy

The video conferencing platform Zoom is sending iOS users’ analytics data to Facebook without explicit consent, even if users don’t have an account with the social networking giant.

The popularity of the online communications software has exploded in the last few weeks as more and more workers and individuals adjust to remote working and life in self-isolation, and search for ways to stay in touch.

Zoom is transferring some user data to Facebook through one of the social media platform’s software development kits (SDKs), however, according to an analysis by Motherboard. Zoom users may not be aware this is happening, however. 

The conferencing app connects to Facebook’s Graph application programming interface (API) after downloading and opening the app. This API is the main route through which developers can send and receive data to and from Facebook. 


According to the analysis, Zoom notifies Facebook when an iOS user opens the app, and then provides details on the user’s device, including the model, as well as their time zone, and city they’re connecting from. 

More info and resources: Motherboard, ITPro

Sunday, 27 October 2019

UK businesses are to blocked from using .eu domains?



Deadline of 1 January 2020 scrapped following Commons Brexit vote


Plans to stop UK businesses from owning .eu website domains have been put on hold following this week's Brexit deal vote.

Domain registry manager EURid had previously stated that UK businesses would no longer be able to register for the .eu domain name from the 1 November 2019, should the UK leave without a deal on the 31 October.

It also said that businesses would have until 1 January 2020 to prove they had operations within the EU, and therefore qualify for the .eu domain, otherwise, they would have their domains withdrawn.

Given that the UK government has secured a majority for the second reading of its deal, and that talks suggest the EU will grant an extension to the negotiation period, this has diminished the likelihood of a no-deal scenario on the 31 October.

As a result, EURid has said that its "entire plan" has now been put on hold.

Source and more info: ITPro

Thursday, 15 March 2018

Frequently Asked Questions about the incoming GDPR

When is the GDPR coming into effect?
 The GDPR was approved and adopted by the EU Parliament in April 2016. The regulation will take effect after a two-year transition period and, unlike a Directive it does not require any enabling legislation to be passed by government; meaning it will be in force May 2018. 

In light of a uncertain 'Brexit' -  I represent a data controller in the UK and want to know if I should still continue with GDPR planning and preparation?
  If you process data about individuals in the context of selling goods or services to citizens in other EU countries then you will need to comply with the GDPR, irrespective as to whether or not you the UK retains the GDPR post-Brexit. If your activities are limited to the UK, then the position (after the initial exit period) is much less clear. The UK Government has indicated it will implement an equivalent or alternative legal mechanisms. Our expectation is that any such legislation will largely follow the GDPR, given the support previously provided to the GDPR by the ICO and UK Government as an effective privacy standard, together with the fact that the GDPR provides a clear baseline against which UK business can seek continued access to the EU digital market. (Ref: http://www.lexology.com/library/detail.aspx?g=07a6d19f-19ae-4648-9f69-44ea289726a0)

Who does the GDPR affect?

 The GDPR not only applies to organisations located within the EU but it will also apply to organisations located outside of the EU if they offer goods or services to, or monitor the behaviour of, EU data subjects. It applies to all companies processing and holding the personal data of data subjects residing in the European Union, regardless of the company’s location.

What are the penalties for non-compliance?

 Organizations can be fined up to 4% of annual global turnover for breaching GDPR or €20 Million. This is the maximum fine that can be imposed for the most serious infringements e.g.not having sufficient customer consent to process data or violating the core of Privacy by Design concepts. There is a tiered approach to fines e.g. a company can be fined 2% for not having their records in order (article 28), not notifying the supervising authority and data subject about a breach or not conducting impact assessment. It is important to note that these rules apply to both controllers and processors -- meaning 'clouds' will not be exempt from GDPR enforcement.

What constitutes personal data?
 Any information related to a natural person or ‘Data Subject’, that can be used to directly or indirectly identify the person. It can be anything from a name, a photo, an email address, bank details, posts on social networking websites, medical information, or a computer IP address.

What is the difference between a data processor and a data controller?

 A controller is the entity that determines the purposes, conditions and means of the processing of personal data, while the processor is an entity which processes personal data on behalf of the controller.

Do data processors need 'explicit' or 'unambiguous' data subject consent - and what is the difference?

 The conditions for consent have been strengthened, as companies will no longer be able to utilise long illegible terms and conditions full of legalese, as the request for consent must be given in an intelligible and easily accessible form, with the purpose for data processing attached to that consent - meaning it must be unambiguous. Consent must be clear and distinguishable from other matters and provided in an intelligible and easily accessible form, using clear and plain language. It must be as easy to withdraw consent as it is to give it.​  Explicit consent is required only for processing sensitive personal data - in this context, nothing short of “opt in” will suffice. However, for non-sensitive data, “unambiguous” consent will suffice.

What about Data Subjects under the age of 16?
 Parental consent will be required to process the personal data of children under the age of 16 for online services; member states may legislate for a lower age of consent but this will not be below the age of 13.

What is the difference between a regulation and a directive?

 A regulation is a binding legislative act. It must be applied in its entirety across the EU, while a directive is a legislative act that sets out a goal that all EU countries must achieve. However, it is up to the individual countries to decide how. It is important to note that the GDPR is a regulation, in contrast the the previous legislation, which is a directive.

Does my business need to appoint a Data Protection Officer (DPO)?

 DPOs mustbe appointed in the case of: (a) public authorities, (b) organizations that engage in large scale systematic monitoring, or (c) organizations that engage in large scale processing of sensitive personal data (Art. 37).  If your organization doesn’t fall into one of these categories, then you do not need to appoint a DPO.

How does the GDPR affect policy surrounding data breaches?

 Proposed regulations surrounding data breaches primarily relate to the notification policies of companies that have been breached. Data breaches which may pose a risk to individuals must be notified to the DPA within 72 hours and to affected individuals without undue delay.

Will the GDPR set up a one-stop-shop for data privacy regulation?The discussions surrounding the one-stop-shop principle are among the most highly debated and are still unclear as the standing positions are highly varied. The Commission text has a fairly simple and concise ruling in favor of the principle, the Parliament also promotes a lead DPA and adds more involvement from other concerned DPAs, the Council’s view waters down the ability of the lead DPA even further. A more in depth analysis of the one-stop-shop policy debate can be found here.




Source: https://www.eugdpr.org/gdpr-faqs.html

Wednesday, 30 August 2017

How the NSA identified Bitcoin 'creator'

The ‘creator’ of Bitcoin, Satoshi Nakamoto, is the world’s most elusive billionaire. Very few people outside of the Department of Homeland Security know Satoshi’s real name. In fact, DHS will not publicly confirm that even THEY know the billionaire’s identity. Satoshi has taken great care to keep his identity secret employing the latest encryption and obfuscation methods in his communications. Despite these efforts (according to my source at the DHS) Satoshi Nakamoto gave investigators the only tool they needed to find him — his own words.
  Using stylometry one is able to compare texts to determine authorship of a particular work. Throughout the years Satoshi wrote thousands of posts and emails and most of which are publicly available. The NSA was able to the use the ‘writer invariant’ method of stylometry to compare Satoshi’s ‘known’ writings with trillions of writing samples from people across the globe. By taking Satoshi’s texts and finding the 50 most common words, the NSA was able to break down his text into 5,000 word chunks and analyse each to find the frequency of those 50 words. This would result in a unique 50-number identifier for each chunk. The NSA then placed each of these numbers into a 50-dimensional space and flatten them into a plane using principal components analysis. The result is a ‘fingerprint’ for anything written by Satoshi that could easily be compared to any other writing.

But why? Why go to so much trouble to identify Satoshi? The source says that the Obama administration was concerned that Satoshi was an agent of Russia or China — that Bitcoin might be weaponized against us in the future. Knowing the source would help the administration understand their motives. As far as I can tell Satoshi hasn’t violated any laws and I have no idea if the NSA determined he was an agent of Russia or China or just a Japanese crypto hacker.
 The moral of the story? You can’t hide on the internet any more. Your sentence structure and word use is MORE unique than your own fingerprint. If an organization, like the NSA, wants to find you they will.

For more information and source: Medium
Author of complete article: Alexander Muse

Saturday, 12 August 2017

Πως να προστατευτείτε από απάτες "ψαρέματος" (phishing) με απλές μεθόδους


Είναι πλέον δύσκολο να μην αντιλαμβανόμαστε την αυξανόμενη συχνότητα των επιθέσεων phishing μέσω ηλεκτρονικών μηνυμάτων. Μέσα σ' αυτή τη χρονιά, οι συχνότερες επιθέσεις έγιναν σε χρήστες Google Cloud Docs. Τα λογισμικά καταπολέμησης κακόβουλων επιθέσεων γίνονται ολοένα και πιο 'εξυπνα' ή καλύτερα πιο αποτελεσματικά έτσι οι προσπάθειες καταδολίευσης και απάτης επικεντρώνονται πλέον από τους hackers στην 'ολίσθηση' στο λάθος των χρηστών.

Ακόμη και να νομίζετε ότι δεν σας αφορά αυτό το άρθρο, αξίζει να το διαβάσετε. Μπορεί να μη πληρώνετε μέσω διαδικτύου, μπορεί να 'νομίζετε' ότι δεν έχετε ευαίσθητες πληροφορίες στην 'διαδικτυακή σας παρουσία'. Όμως ΕΧΕΤΕ. Από τη στιγμή που χρησιμοποιείτε το διαδίκτυο
ΕΙΣΤΕ ΕΥΑΛΩΤΟΙ!

Τι είναι το phishing;

Οι επιθέσεις phishing όπως αντιλαμβάνεται κανείς, είναι προσεγγίσεις που μοιάζουν νάναι νόμιμες και λογικές, προερχόμενες από ηλεκτρονικά μηνύματα ή/και (σε συνδυασμό) με ιστοσελίδες με πρωταρχικό στόχο την ανάκτηση πρόσβασης στο ηλεκτρονικό ταχυδρομείο του χρήστη ή έμμεσα/αμεσα στους τραπεζιτικούς λογαριασμούς του. Είναι με πανουργία και αποτελεσματικότητα προετοιμασμένες επειδή φαίνεται να προέρχονται από οργανισμούς ή εταιρείες με τις οποίες συνεργάζεστε. Σας οδηγούν σε σελίδες πανομοιότυπες με αυτές που έχετε εμπιστευτικά δεδομένα. Πέφτει στην παγίδα ο χρήστης και βάζει τους κωδικούς του νομιζόμενος ότι εισέρχεται είτε στην ασφαλή πύλη του ηλεκτρονικού ταχυδρομείου του ή στη σελίδα της τράπεζας του που του ζητά να επαναβεβαιώσει τους κωδικούς του. Ο σκοπός του ψαρέματος είναι πάντα ο ίδιος, να αποκτήσει πρόσβαση σε ευαίσθητες περιοχές του χρήστη. Οι hackers τότε αντιγράφουν τον τρόπο γραφής του χρήστη, τιμολόγια που συνήθως πληρώνει και κλέβει την (ηλεκτρονική) ταυτότητα του.

Απλοί τρόποι να μην είστε το επόμενο θύμα phishing

Πάντα να σκέφτεστε διπλά πριν κάνετε κλικ σε σύνδεσμο (link) που σας δίνεται είτε μέσω ηλεκτρονικού ταχυδρομείου (email), SMS, messenger κλπ. Αναρωτηθείτε αν ο αποστολέας θα σας έστελνε μήνυμα τέτοιου περιεχομένου. Θα σας ζητούσε κάτι τέτοιο; Για παράδειγμα οι τράπεζες συνεχώς σας θυμίζουν ότι δεν σας ζητούν τους κωδικούς σας είτε από ηλεκτρ. μήνυμα ή άλλη ιστοσελίδα. Αποφεύγετε επίσης να κάνετε κλικ σε συνδέσμους τύπου shortURLs (π.χ https://goo.gl/Z6gYE5, http://alturl.com/i3tew αυτά είναι ασφαλή), δεν ξέρετε που σας οδηγούν. Με τον ίδιο τρόπο να αποφεύγετε να στέλνετε μηνύματα με τέτοιους συνδέσμους. Δεν είναι παράνομο ή κακό αλλά όταν οι παραλήπτες σας γνωρίζουν ότι δεν χρησιμοποιείτε τέτοιους συνδέσμους, ΔΕΝ θα ανοίξουν ένα τέτοιο σύνδεσμο αν φανεί ότι αποστέλνεται απο σας.

Συνδέσμοι, URLs, Domains

Επίσης οι σύνδεσμοι δεν σημαίνει ότι σας οδηγούν σ' αυτό που φαίνεται στο κείμενο. Π.χ www.bankofcyprus.com ενώ νομίζετε ότι σας οδηγεί στην Τράπεζα Κύπρου, σας παίρνει στην Google! Κοιτάζετε το σύνδεσμο που γράφει στην κάτω μεριά του προγράμματος email που χρησιμοποιείτε (status bar). Εκεί φαίνεται πραγματικά η ιστοσελίδα που θα ανοίξετε. Οι hackers φυσικά δεν θα σας στείλουν σε 'αθώες' σελίδες όπως η Google Search Engine.
Κοιτάζετε πάντα στο address bar του browser σας και βεβαιώνετε ότι είστε στη σελίδα που θέλετε να είστε. Απομνημονεύετε τους σημαντικούς διαδικτυακούς χώρους ενθυμούμενοι το domain τους. Για παράδειγμα, η www.hellenic-bank.com ΔΕΝ ΕΙΝΑΙ η Ελληνική τράπεζα (Κύπρου) της οποίας η σελίδα φυσικά είναι www.hellenicbank.com (χωρίς την '-').
Προσοχή στην λεπτομέρεια!
 Οι phishers είναι έξυπνοι, ρισκάρουν, είναι θρασείς. Βελτιώνουν τις τεχνικές τους και σκαρφίζονται καινούργιες μεθόδους προσέγγισης του θύματος. Παίζουν ιδιαίτερα με αναγραμματισμούς των ονομάτων. Οι ιστοσελίδες http://helenicbank.com/ ή  http://hellenikbank.com/ φυσικά ΔΕΝ σας οδηγούν στην Ελληνική τράπεζα. Ο ένας συνδεσμος είναι με ένα 'l' αντί με δύο ενώ ο άλλος είναι γραμμένος με 'k' αντί με 'c'.

Ηλεκτρονικά μηνύματα, Emails

Προσέχετε τα ηλεκτρονικά μηνύματα από που προέρχονται. ΜΗΝ βλεπετε ΜΟΝΟ το όνομα. Για παράδειγμα ένα μήνυμα από τον "Christos Andreades <234ss44ff gmail.com="">" είναι προφανές ότι δεν είναι από τον Χρίστο τον οποίο ίσως ξέρετε!
Με τον ίδιο τρόπο μπορεί να γνωρίζετε κάποιο Χρίστο με email christos@mydomain.com αλλά λαμβάνετε μήνυμα από το email christos@my-domain.com. Υπάρχουν πολλαπλά τέτοια κρούσματα.

Πολλοί χρήστες του διαδικτύου χρησιμοποιούν δωρεάν υπηρεσίες email όπως της Google (gmail), Microsoft (outlook.com, hotmail.com), Yahoo (yahoo.com) κλπ. Πολλοί επίσης τα χρησιμοποιούν και για επαγγελματική χρήση (κακώς!)
Εδώ οι hackers πάλι αναγραμματίζουν το username. Γνωρίζετε πχ κάποιον με email nikoshalikakakis@gmail.com. Σας στέλνουν email με αποστολέα nikoshallikakakis@gmail.com. Ένα 'l' περισσότερο! όμως ΔΕΝ είναι από τον γνωστό/συνεργάτη/πελάτη σας!

Ένα τελευταίο στα email που πρέπει να προσέχετε είναι ποιος είναι ο αποστολέας και ποιο email είναι δηλωμένο για 'reply to'. Είναι μια από τις ιδιότητες των email. Μπορώ για παράδειγμα να στέλνω email με το όνομα μου και το email μου αλλά θέλω οι απαντήσεις (replies) να πηγαίνουν στο 'κεντρικό' email της εταιρείας μου:
Christos Doe
reply to: MyCompany
Αυτή την ιδιότητα κάνουν πολλοί hackers χρήση γιατί υπάρχει (εύκολα) η δυνατότητα να στείλουν email κάνοντας χρήση ένα πραγματικό email που γνωρίζετε αλλά για σκοπούς επικοινωνίας μαζί του και όχι με τον γνωστό σας, βάζουν στο reply to το email του hacker!

Εταιρειες με καλή δομή στις email πλατφορμες τους κάνουν χρήση του λεγόμενου SPF Record το οποίο μπορεί να απαγορεύει στους διάφορους mailservers να αποδέχονται email των εταιρειών αυτών αν δεν προέρχονται από τους δικούς τους mailservers.

Λογισμικά προστασίας

Η χρήση λογισμικών προστασίας (antivirus, antimalware, firewalls κλπ) ΔΕΝ ΕΙΝΑΙ παντα αρκετή! Πρέπει να προσέχετε διπλά, σαν να μην έχετε προστασία! Οι επιθέσεις απάτης μπορούν να έρθουν είτε από email, instant messaging (messenger, whatsup etc) ακόμη και από SMS! Σκεφτείτε διπλά πριν δώσετε ευαίσθητα στοιχεία σας μέσω κάποιου μέσου που αναφέρουμε ποιο πάνω.

Τιμολόγια, πληρωμές

Ελέγχετε όταν κάνετε πληρωμές τιμολογίων. Τα τιμολόγια πολλές φορές αναγράφουν αριθμούς λογαριασμών τραπεζών που πρέπει να γίνει η πληρωμή. Συγκρίνετε τους αριθμούς αυτούς με τους αριθμούς που έχετε κάνει χρήση σε προηγούμενη πληρωμή. Αν ακόμη συναλλάσεστε συχνά με αυτή την εταιρεία και κάνετε πληρωμές μέσω online banking, φυλάξετε τις εταιρείες αυτές στους beneficiaries που σας δίνει δυνατότητα (συνήθως) η τράπεζα σας να φυλάξετε.
Αν παίρνετε εντολές πελατών σας για πληρωμές, επιβεβαιώνετε μαζί τους με δεύτερο τρόπο (πχ SMS verification) ότι σας έστειλε να κάνετε αυτή την πληρωμή.

Επιπλέον προστασία

Τέλως ακόμη μια καλή μέθοδος προστασίας είναι και το multi-factor ή two-step authentication. Πολλοί από σας που κάνετε διαδικτυακές πληρωμές, ήδη το χρησιμοποιήτε με το λεγόμενο 'dongle' που σας υποχρεώνει η τράπεζα να έχετε για τις πληρωμές σας. Πολλές υπηρεσίες Cloud όπως η Google, Microsoft κλπ το παρέχουν και το συστήνουν.

Τελειώνοντας...

Προσέχετε στο διαδίκτυο, έχει καταντήσει να είναι πιο επικίνδυνο από το να περπατάς στο δρόμο....

Μπορείτε να επικοινωνήσετε μαζί μας για περισσότερες πληροφορίες και συμβουλές στο email μας, info(at)scicane.com

Το παρόν άρθρο όπως και τα υπόλοιπα στην ιστοσελίδα αυτή αποτελούν πνευματική ιδιοκτησία της SCICANE LTD και απαγορεύεται η χρήση/αντιγραφή/επαναδημοσίευση μέρους ή όλου του άρθρου χωρίς την έγγραφή αποδοχή της εταιρείας

Περισσότερες πληροφορίες για μας στο About Us


Solar panel grids next victim of attack?

Image result for solar panel pictureHackers could exploit a recently discovered flaw in solar panels to overload energy grids and create power cuts, according to new research.

Recently discovered 17 vulnerabilities in solar power inverters - hardware used to convert the energy gathered into electricity for the main grid. The inverters, many of which are internet-connected, could be targeted by hackers, allowing them to remotely control the flow of power, according to the research.

Westerhof a Dutch researcher, first discovered the vulnerabilities when working on an undergraduate dissertation, and explained his further research at a security conference in the Netherlands on Monday. The full details of the hack have not been released in an effort to prevent malicious attacks.

 A UK government report published yesterday proposed huge fines for companies managing essential infrastructure, if their cyber security is found lacking. Under the Network and Information Systems directive (NIS), failure to implement adequate cyber security measures to thwart hacking attempts would result in fines of up to £17 million, or 4% of a company's global turnover.

Further info & source: ITPro

Wednesday, 9 August 2017

Tech support scammers have a new method for phishing attacks on Windows 10

 On Tuesday, Microsoft's Malware Protection Center announced that it had learned about new strategies to target those using Windows 10, via links that lead to fraudulent tech support sites.

The new techniques, which introduce a different layer to the mix, embed links in phish-like emails—and represent a step up from the previous methods used by scammers, potentially leading to a wider pool of victims. 
Previously, these types of scams involving tech support were done in a cold-call fashion. Now, however, a series of malicious ads will automatically redirect victims to a fake tech support page, in which Windows 10 users are presented with a display of fake Blue Screen of Death (BSOD) or other bogus Windows secthe new techniques, which introduce a different layer to the mix, embed links in phish-like emails—and represent a step up from the previous methods used by scammers, potentially leading to a wider pool of victims. Previously, these types of scams involving tech support were done in a cold-call fashion. Now, however, a series of malicious ads will automatically redirect victims to a fake tech support page, in which Windows 10 users are presented with a display of fake Blue Screen of Death (BSOD) or other bogus Windows security alerts

Sending mass emails that pretend to come from popular sites like LinkedIn or Amazon has been a mainstay of online scammers, who include links to fake bank or email login sites. But now, this tactic is being redirected to tech support sites in order to phish credentials.

More information and source: Techrepublic

Sunday, 6 August 2017

TESTING SMTP AUTH USING TELNET


https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcRmXnlag7HE1K23AFH4LbYwdYVnQ3LTajT3s12cfGP63v-tneC-



Test if SMTP authentication is working.


Sometimes you need to test SMTP Authentication is working on your server, and you may not have Outlook or another email client handy to test the connection.

You can verify SMTP authentication is working by using telnet and accessing the SMTP server directly. Below is a quick tutorial on how to test your server with Atmail for SMTP authentication details.
RESOLUTION
  1. First, make sure SMTP authentication is enabled via the Atmail Webadmin > Services > SMTP Settings > SMTP Authentication = On
  2. Next, create or verify an existing username and password on the system
  3. Build the Base64 username/password
    SMTP AUTH LOGIN will encapsulate the username and password as a Base64 string. This is used to prevent sending the username/password plaintext via the network connection. Using Perl, you can issue the following command to encode the username and password as a base64 string, which can be sent to the SMTP server. Note the @ symbol is escaped to pass the string via Perl.
    # perl -MMIME::Base64 -e 'print encode_base64("myusername\@domain.com")'
    bXl1c2VybmFtZUBkb21haW4uY29t
    # perl -MMIME::Base64 -e 'print encode_base64("weakpass")'
    d2Vha3Bhc3M=
  4. Access the local system. Commands we issue are highlighted in bold.
    # telnet localhost 25
    Trying 127.0.0.1...
    Connected to localhost.localdomain (127.0.0.1).
    Escape character is '^]'.
    220 mydomain.com Welcome to the @Mail SMTP Server ( Exim )
    ehlo test.com
    250-mydomain.com localhost [127.0.0.1]
    250-SIZE 52428800
    250-PIPELINING
    250-AUTH LOGIN
    250-STARTTLS
    250 HELP>
    The above command will verfiy AUTH LOGIN is enabled on the server. Next, send the following command to start the SMTP Authentication process.
    AUTH LOGIN
    334 VXNlcm5hbWU6 ( Server returns username as a base64 string )
    bXl1c2VybmFtZUBkb21haW4uY29t
    334 UGFzc3dvcmQ6 ( Server returns password as a base64 string )
    d2Vha3Bhc3M=
    235 Authentication succeeded
  5. Congratulations, SMTP authentication is now enabled and confirmed working on your server. Note you must send the Base64 string of the username and password as two commands.

Thursday, 29 June 2017

Petya ransomware



The Petya ransomware attack that crippled computers in 64 countries worldwide was spread by accounting software, according to Microsoft, highlighting the dangers posed by compromised third-party apps.
The outbreak started in Ukraine, where more than 12,500 machines were infected, and there is now evidence this new Petya malware variant was initially spread via an updater for the tax accounting software MEDoc.

 A large number of organizations were infected, many in Ukraine, including Danish transport company Maersk, Russian oil firm Rosneft, the Kiev metro system, National Bank of Ukraine, the law firm DLA Piper, US pharmaceutical company Merck and many others.

petya-ransom-note.png

How to protect yourself

Once the ransomware infects a machine, it then attempts to spread itself to other PCs on the network. To propagate itself, it will try to steal credentials to gain local admin privileges, attempt to use file-shares to transfer the malicious file between PCs, and then remotely execute the file. The ransomware encrypts entire hard drives and demands a Bitcoin payment of $300 to release them.
The malware can also spread itself using the EternalBlue exploit for an SMB vulnerability, which was used by WannaCry to spread between machines. The vulnerability was patched by Microsoft in March this year.
Microsoft recommends applying this security update, but for those who aren't able to, it suggests firms "disable SMBv1 with the steps documented at Microsoft Knowledge Base Article 2696547" and "consider adding a rule on your router or firewall to block incoming SMB traffic on port 445".
Another workaround for blocking infection by Petya is to create an extensionless, read-only file called perfc in the C:\Windows folder, using the steps outlined here.
Microsoft also provides a detailed a breakdown of commands and network activity that indicate a Petya infection.


Other reports say that the provider of the email address shown to receive the ransom closed it down, deactivated it so there's no way to pay or ask decryption of your data from the attacker.

While steps were taken to be able to block the attack in your pc, so far there's no 'kill switch' to stop the virus from spreading.

Ofcourse the known story still comes up: "keep you windows machine" updated with security updates and also have a good antivirus solution to protect yourself like the one we offer.

Source: Techrepublic

Tuesday, 16 May 2017

“WannaCry” Ransomware

a ransomware attack has emerged that is worthy of tears. WannaCry ransomware has hit the scene, spreading like wildfire across 150 countries and infecting more than 250,000 machines, which includes a massive takedown of 16 UK NHS medical centers in just one day. Other major countries impacted include Spain, Russia, Ukraine, India, China, Italy, and Egypt.
Now, how is this massive attack possible? The ransomware attack exploits the Server Message Block (SMB) critical vulnerability–also known as the Equation Group’s ETERNALBLUE exploit, part of the FuzzBunch toolkit released by Shadow Brokers a couple of weeks ago. Basically, the attacker can use just one exploit to gain remote access into a system. Once access is gained, the cybercriminal then encrypts data with a file extension “.WCRY.” Not to mention, the decypter tool used can hit users in multiple countries at once, and translate its ransom note to the appropriate language for that country. The ransom is said to demand $300 to decrypt the files.
The good news is, consumers don’t have to worry about this attack affecting their personal data, as it leverages a flaw within the way organizations’ networks allow devices to talk to each other.
However, this attack does act as a reminder for consumers to prepare for personal ransomware attacks. In order to stay prepared and keep your personal data secure, follow these tips:
-Be careful what you click on. This malware was distributed by phishing emails. You should only click on emails that you are sure came from a trusted source. Click here to learn more about phishing emails. 
-Back up your files. Always make sure your files are backed up. That way, if they become compromised in a ransomware attack, you can wipe your disk drive clean and restore the data from the backup.
-Update your devices. There are a few lessons to take away from WannaCry, but making sure your operating system is up-to-date needs to be near the top of the list. The reason is simple: nearly every software update contains security improvements that help secure your computer and removes the means for ransomware variants to infect a device.
–Schedule automatic updates. It’s always a good practice to set your home systems to apply critical Windows Security Updates automatically. That way, whenever there is a vulnerability, you receive the patch immediately.
–Apply any Windows security patches that Microsoft has sent you. If you are using an older version of Microsoft’s operating systems, such as Windows XP or Windows 8, click here to download emergency security patches from Microsoft. 
–Keep security solutions up-to-date. 
source: McAfee

Friday, 5 May 2017

Tips to keep your online accounts secure

If you didn't know, the first Thursday in May of each year has been officially declared World Password Day—a day to promote good security hygiene and password habits. In 2017, that day has fallen on May 4.

Here's a simple four-step approach to better passwords:

1. Create strong passwords

Strong passwords, according to the World Password Day website, have at least eight characters, with a mix of uppercase letters, lowercase letter, numbers, and symbols. They also avoid the use of personal information, such as birthdays or middle names.

2. Use a different password for each account

Using a different password for each online account is important because, if you share passwords across accounts, one compromised password can be used to log into another account. This is especially important regarding online banking and financial accounts.

3. Get a password manager

Password managers, like LastPass or 1Password for example, can help you store multiple passwords, often in an encrypted manner, for easy access. Typically, they will require one master password with additional layer of authentication to access the stored passwords.

4. Turn on multi-factor authentication

Multi-factor authentication adds an additional layer of security on top of your standard password. For example, an app may require you answer a security question, input a unique code, or use a fingerprint scanner on top of using your password. Check the security settings of your favorite apps and passwords to see if multi-factor authentication is available.

Source: TechRepublic

Monday, 1 May 2017

Companies still fail security basics, as ransomware rises

Most breaches take advantage of simple passwords

Companies are still failing to take basic steps to secure their businesses, a new report has found.

Verizon's annual Data Breach Investigations Report, published today, revealed that of the almost 2,000 breaches and security incidents that were analysed, a whopping 81% used easily-guessed or stolen passwords.

Furthermore, over 65% of malware infections were delivered via email attachments - a technique that has been around for decades. Pretexting - a form of social engineering used to obtain privileged information - is also on the rise.

With so many enterprises falling victim to age-old tactics, why are businesses still failing to take basic security measures like strong password hygiene and regular data backups?

"It's a very good question, and it's one we ask ourselves on a recurring basis," Verizon's director of international security solutions, Ali Neil, told IT Pro, "because this is not the only year that we find that the human vector is probably the most susceptible, and theoretically the easiest one by which to combat things."

"You don't have to pay a fortune for a SIEM solution or an intrusion detection solution, you actually have to enforce some basic standards," he added. "Our message is that training is the simplest thing you can do with people."

Not everyone agrees, however. Bromium's EMEA CTO, Fraser Kyne, said that companies need to spend less time focusing on employee training, not more.

"What most interested me in this year's report was that phishing attacks are actually becoming even more prevalent," he said. "One in 14 users are being duped into clicking on a bad link or attachment; but even worse, a quarter of those people go on to do it again. There is a phrase that I think is very apt here - "You can't patch stupidity'.

"Organisations therefore need to shift the onus away from controlling user behaviour if they are to get a handle on the situation. The best way of mitigating phishing attacks is to have a safety net in place, allowing end users to click with freedom, without having to worry too much about stumbling upon a bad link or malicious attachment."

The report included further interesting findings, such as the fact that organised crime gangs were behind more than half of all breaches, almost 70% of all threats to healthcare come from within the organisation, and around 50% of attacks on educational institutions were perpetrated by state-affiliated hackers.

Unsurprisingly, ransomware has also gone up by 50% compared to last year's report. Across the numerous reports put out by the security industry, a consistent rise in ransomware activity is one of the universal constants.

Source: ITPRO

Thursday, 20 April 2017

Refine Web Searches with Google



Refine web searches

You can use symbols or words in your search to make your search results more precise.

Google Search usually ignores punctuation that isn’t part of a search operator.Don’t put spaces between the symbol or word and your search term. A search forsite:nytimes.com will work, but site: nytimes.com won’t.

Common search techniques

Search social media

Put @ in front of a word to search social media. For example: @twitter.

Search for a price

Put $ in front of a number. For example: camera $400.

Search hashtags

Put # in front of a word. For example:#throwbackthursday

Exclude words from your search

Put - in front of a word you want to leave out. For example, jaguar speed -car

Search for an exact match

Put a word or phrase inside quotes. For example,"tallest building".

Search for wildcards or unknown words

Put a * in your word or phrase where you want to leave a placeholder. For example, "largest * in the world".

Search within a range of numbers

Put .. between two numbers. For example,camera $50..$100.

Combine searches

Put "OR" between each search query. For example,  marathon OR race.

Search for a specific site

Put "site:" in front of a site or domain. For example, site:youtube.com or site:.gov.

Search for related sites

Put "related:" in front of a web address you already know. For example, related:time.com.

Get details about a site

Put "info:" in front of the site address.

See Google’s cached version of a site

Put "cache:" in front of the site address.


Thursday, 9 March 2017

Microsoft cuts size of Windows 10 updates by 65%

Microsoft has managed to reduce the size of its Windows 10 updates by 65% thanks to the use of differential download packages in its Unified Update Platform (UUP) technology, which only update the system with the changes rather than re-installing the entire platform.

This will be the case even for the big updates, rather than just the smaller bug fix ones, which will come as a great relief to Windows 10 users who find themselves wasting hours downloading and installing hefty operating system updates.

The innovation will come as part of the Windows 10 Creators Update, Microsoft said. "It’s also important to note that Windows Insiders may not get a differential download packages even if we ship them," Bill Karagounis, director of program management for Microsoft's Windows Insider Program and OS Fundamentals division, said.

"A baseline build has to be set for differential download packages and if that baseline build is newer than the build Windows Insiders are updating from (in the case where they are not on the latest flight) – they will receive a larger download."

Microsoft will let users decide when to update their Windows 10 devices, rather than automatically updating smartphones, tablets and desktops without notice.

Michael Fortin, the CVP of the Windows and devices group core quality and John Cable, the director of program management for Windows servicing and delivery, made the announcement in a blog post, saying the company was responding to customer feedback with the Creator's Update.

for more information read ITPro

Tuesday, 18 October 2016

Barracuda's blacklist - keep out

Barracuda Spam Firewall is a popular spam filtering software. One of the ways it figures out whether an email is Spam or not is through the use of its "Intent Engine". The "Intent Engine" is a human run and maintained blacklist which is turned "On" by default with each new Barracuda installation.
To get blacklisted inside the "Intent Engine" you must first have had a complaint submitted to Barracuda by one of its customers. By default Barracuda assumes all mail is good mail, until that initial complaint is filed. Once a complaint is filed, a person will look at your email for three attributes to determine if it belongs on the blacklist.
  1. "To:" line cannot be obfuscated. Anyone who uses blind carbon copy line (BCC line) to load up a list of recipients would fail this test.
  2. The email must let the recipient know how they got on the email list inside the body of the message.
  3. There must be a one-click unsubscribe link.
If the email fails in any of these areas, then the person analyzing the email will add URLs that are linked to in the email to the blacklist which means that future emails sent by that sender could be blocked. Once your URL gets on the blacklist, any Barracuda customer who has the "Intent Engine" turned on will likely not receive your messages.

We encourage our customers to add a quick one-line explanation to the body of their messages that explain how and where permission was gained from the customer to be on your list. This line can be in the header or the footer of the message. Not only would this help with deliverability, but it would also help make transparent your relationship with the end recipient which is always a good thing.

source: Campaigner
read more: Barracuda Lookup

Barracuda's blacklist - keep out

Barracuda Spam Firewall is a popular spam filtering software. One of the ways it figures out whether an email is Spam or not is through the use of its "Intent Engine". The "Intent Engine" is a human run and maintained blacklist which is turned "On" by default with each new Barracuda installation.
To get blacklisted inside the "Intent Engine" you must first have had a complaint submitted to Barracuda by one of its customers. By default Barracuda assumes all mail is good mail, until that initial complaint is filed. Once a complaint is filed, a person will look at your email for three attributes to determine if it belongs on the blacklist.
  1. "To:" line cannot be obfuscated. Anyone who uses blind carbon copy line (BCC line) to load up a list of recipients would fail this test.
  2. The email must let the recipient know how they got on the email list inside the body of the message.
  3. There must be a one-click unsubscribe link.
If the email fails in any of these areas, then the person analyzing the email will add URLs that are linked to in the email to the blacklist which means that future emails sent by that sender could be blocked. Once your URL gets on the blacklist, any Barracuda customer who has the "Intent Engine" turned on will likely not receive your messages.

We encourage our customers to add a quick one-line explanation to the body of their messages that explain how and where permission was gained from the customer to be on your list. This line can be in the header or the footer of the message. Not only would this help with deliverability, but it would also help make transparent your relationship with the end recipient which is always a good thing.

source: Campaigner
read more: Barracuda Lookup