Friday, November 14, 2008

Social Engineering: 8 Common Tactics

Most articles I’ve read on the topic of social engineering begin with some sort of definition like “the art and science of getting people to comply to your wishes”, “an outside hacker’s use of psychological tricks on legitimate users of a computer system, in order to obtain information he needs to gain access to the system”, or “getting needed information (for example, a password) from a person rather than breaking into a system”. In reality, social engineering can be any and all of these things, depending upon where you sit. The one thing that everyone seems to agree upon is that social engineering is generally a hacker’s clever manipulation of the natural human tendency to trust. The hacker’s goal is to obtain information that will allow him/her to gain unauthorized access to a valued system and the information that resides on that system.

Security is all about trust. Trust in protection and authenticity. Generally agreed upon as the weakest link in the security chain, the natural human willingness to accept someone at his or her word leaves many of us vulnerable to attack. Many experienced security experts emphasize this fact. No matter how many articles are published about network holes, patches, and firewalls, we can only reduce the threat so much... and then it’s up to Maggie in accounting or her friend, Will, dialing in from a remote site, to keep the corporate network secured.

I was searching for some information related to social engineering in the net. I found some good interesting social engineering tactics at networkworld.com (A very good site, normally I refer to update myself).Thought of sharing with you guys...

Click on the below link to get an idea of the most prevalent social engineering tricks used by phone, e-mail and Web.

http://www.networkworld.com/news/2008/110608-social-engineering-eight-common.html

Tuesday, November 11, 2008

Three Plead Guilty in $2 Million Citibank ATM Caper

Three New Yorkers accused of using hacked Citibank ATM card numbers and PINs to steal $2 million from customer accounts in four months have pleaded guilty to federal conspiracy and access device fraud charges.
The defendants -- Ivan Biltse, Angelina Kitaeva and Yuriy Rakushchynets, aka Yuriy Ryabinin -- are among 10 suspects charged earlier this year in connection with a breach of a server that processes ATM transactions from 7-Eleven convenience stores. Those ATMs are branded Citibank, but they're owned by Houston-based Cardtronics.

For more information visit:-

Wednesday, November 5, 2008

Social Engineering - Palin Tricked Into Chat With Canadian Comic Posing as Sarkozy!

Republican vice presidential candidate Sarah Palin was tricked by two Canadian comedians into thinking she was having a telephone conversation with French President Nicolas Sarkozy.
The conversation, posted on the Internet, ranges from American politics to the perils of hunting with Vice President Dick Cheney, who accidentally shot and injured a hunting companion in 2006.
Comedian Marc-Antoine Audette, masquerading as Sarkozy, suggested he and Palin go hunting together, perhaps by helicopter. Palin said she would be ``a careful shot.''
The McCain campaign confirmed the telephone call. ``C'est la vie,'' said Palin spokeswoman Tracey Schmitt.
Palin was ``mildly amused to learn that she had joined the ranks of heads of state, including President Sarkozy, and other celebrities in being targeted by these pranksters,'' said Schmitt.
Audette asked Palin if Joe the Plumber was her husband, and she replied that, no, her husband was a ``normal American who works hard and doesn't want the government to take his money,'' according to the audio.

Courtesy: Bloomberg

http://www.bloomberg.com/apps/news?pid=20601087&sid=aWvdSt1G3ztU

Wednesday, October 29, 2008

Web-Harvest - Open Source Web Data Extraction tool

Web-Harvest is Open Source Web Data Extraction tool written in Java. It offers a way to collect desired Web pages and extract useful data from them. In order to do that, it leverages well established techniques and technologies for text/xml manipulation such as XSLT, XQuery and Regular Expressions. Web-Harvest mainly focuses on HTML/XML based web sites which still make vast majority of the Web content. On the other hand, it could be easily supplemented by custom Java libraries in order to augment its extraction capabilities.
Source:
http://web-harvest.sourceforge.net

Sunday, October 26, 2008

Information Security Policy for Small Business.

Information security policy, while being one of the most important steps in helping to secure an information system, is also one of the most frequently overlooked and misunderstood in small businesses. Performing the steps necessary to create strong, effective, and more importantly, enforceable policy are usually perceived to be beyond the resources of most small businesses.

Yet with the pervasiveness of small business, these information systems can become unwitting tools for attackers and provide a stepping stone for larger attacks on enterprise networks.

By understanding the pertinent issues in creating and maintaining effective policy, small businesses can create workable rules by first understanding the psychology of their workers, the Information landscape in which they operate, and the
value of the information being protected.
Intresting.....??? Okay... then move on... click on the below link for more:-

Friday, October 24, 2008

MS ships emergency patch for Windows worm hole!

Microsoft has released an out-of-band patch to fix an extremely critical worm hole that exposes Windows users to remote code execution attacks.

The emergency update comes just one week after the regularly scheduled Patch Tuesday and follows the discovery of a targeted zero-day attack, Microsoft said in an advisory. The vulnerability is rated “critical” on Windows 2000, Windows XP and Windows Server 2003.

On Windows Vista and Windows Server 2008, the flaw carries an “important” rating.

For more information about this patch visit:-

http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx


Study: Most Data Breaches Preventable!


Seventy-five percent of all data breaches result in compromised data within a matter of days. Despite this, the study also reveals that 63 percent of companies don't learn about data breaches until months after their data has been compromised. Even after breaches are discovered, the study finds that nearly half of them take weeks to fix.

The Verizon Business Risk Team reviewed more than 500 corporate data breaches between 2004 and 2007 and found that 87 percent could have been prevented -- if only the companies had the proper security measures in place at the time of the breach. After four years of forensic research involving more than 230 million records, the "2008 Data Breach Investigations Report" found that 73 percent of breaches resulted from external sources, while 18 percent were caused by insiders. Thirty-nine percent implicated business partners -- a number that increased five-fold over the time period of the study -- while 30 percent involved multiple parties.

The first-of-its-kind study looked at data breaches in a wide variety of industries, including retail, food and beverage, technology, and financial services. According to the findings:

* Most breaches resulted from a combination of events rather than from a single action. Specifically, 62 percent were attributed to a significant error; 59 percent resulted from hacking and intrusions; 31 percent incorporated malicious code; 22 percent exploited a weakness; and 15 percent were due to physical threats.

* Of those breaches caused by hacking, 39 percent were aimed at the application or software layer. Fewer than 25 percent of attacks took advantage of a known or unknown vulnerability. Significantly, 90 percent of known vulnerabilities exploited had patches available for at least six months prior to the breach.

* Nine of 10 breaches involved some type of "unknown" -- unknown systems, data, network connections, and/or account user privileges. Also, 75 percent of breaches were discovered by a third party rather than the affected organization.

* Seventy-five percent of all data breaches result in compromised data within a matter of days. Despite this, the study also reveals that 63 percent of companies don't learn about data breaches until months after their data has been compromised. Even after breaches are discovered, the study finds that nearly half of them take weeks to fix.

The study urges businesses to be proactive and provides key recommendations to help them protect themselves:

* Align process with policy -- In 59 percent of data breaches, organizations had established security policies and procedures, but they had not been enacted through actual processes. Create solid data protection policies and then follow through.

* Achieve "essential" then worry about "excellent"- Identify a set of essential controls and ensure they are implemented across the organization without exception before moving on to more advanced controls.

* Create a data retention plan -- Sixty-six percent of breaches involved data that the victim did not know was on the system. Identify and quantify the types of data retained during business activities and then work to categorize it based on risk and liability.

* Control data with transaction zones -- Investigators concluded that network segmentation can help prevent, or at least partially mitigate, an attack.

* Monitor event logs -- Evidence of events leading up to 82 percent of data breaches was available to the organization prior to actual compromise. Processes that ensure the timely, efficient, and effective monitoring of and response to network events are critical to protecting data.

* Create an incident response plan If a breach occurs, be ready to act. An effective incident response plan will ensure a breach can be stopped before data is compromised.

* Increase awareness and testing -- Educate employees about the risks of data compromise, their role in preventing it, and how to respond.