Thursday, July 13, 2017

There is no such thing as “too small to hack"

Does this bother you?
average website is attacked 22 times per day

No?
How about this one?
Thirty-nine percent of the hacked sites were infected with shell programs, and 73% contained backdoors. 






More Here:
https://blog.sitelock.com/wp-content/uploads/2017/07/SiteLock-Security-by-Obscurity-Infographic-Q2-2017.pdf

Monday, July 10, 2017

MQTT - The scary part of IoT


Lundgren struck oil – nearly literally in one case where he spotted an oil pipeline server in the Middle East that was exposed online – after finding an open port on a server last year that led to his ultimate, massive discovery of tens of thousands of open MQTT servers – including airplane coordinates, prison door controls, connected cars, electricity meters, medical devices, mobile phones, and home automation systems. He was able to read in plain text the data sent back and forth between those IoT devices and their servers.

"We could see prison doors open and close," says Lundgren

More Here:
http://www.darkreading.com/cloud/iot-devices-plagued-by-lesser-known-security-hole-/d/d-id/1329320?_mc=sm_dr&hootPostID=bdb8ca978ba09a55263919a9ca41d7f6

SpyDealer - Not a movie name , It is an Android Malware



From the Article:

SpyDealer has many capabilities, including:
  • Exfiltrate private data from more than 40 popular apps including: WeChat, Facebook, WhatsApp, Skype, Line, Viber, QQ, Tango, Telegram, Sina Weibo, Tencent Weibo, Android Native Browser, Firefox Browser, Oupeng Brower, QQ Mail, NetEase Mail, Taobao, and Baidu Net Disk
  • Abuses the Android Accessibility Service feature to steal sensitive messages from popular communication and social apps such as WeChat, Skype, Viber, QQ
  • Takes advantage of the commercial rooting app “Baidu Easy Root” to gain root privilege and maintain persistence on the compromised device
  • Harvests an exhaustive list of personal information including phone number, IMEI, IMSI, SMS, MMS, contacts, accounts, phone call history, location, and connected Wi-Fi information
  • Automatically answer incoming phone calls from a specific number
  • Remote control of the device via UDP, TCP and SMS channels
  • Spy on the compromised user by:
    • Recording the phone call and the surrounding audio & video.
    • Taking photos via both the front and rear camera
    • Monitoring the compromised device’s location
    • Taking screenshots

Friday, July 7, 2017

What happens if you don't patch your computers - Wannacry, NotPetya and everything else

The company that was on the spotlight for the pet, don't pet, notpetya (whatever )was Backdoored 3 Times, Servers Left Without Updates Since 2013

Now, before we start laughing , are we sure that the systems in our organization are up-to-date on patches ?


Check Here:
https://www.bleepingcomputer.com/news/security/m-e-doc-software-was-backdoored-3-times-servers-left-without-updates-since-2013/

Tuesday, June 27, 2017

Thursday, May 25, 2017

82% of Databases Left Unencrypted in Public Cloud - Anyone surprised?



The team analyzed more than one million cloud resources, processing 12 petabytes of network traffic, and dug for flaws in public cloud infrastructure. They found 4.8 million records, including protected health information (PHI) and personally identifiable information (PII), were exposed because best practices like encryption and access control aren't enforced

More info here:
http://www.darkreading.com/cloud/82--of-databases-left-unencrypted-in-public-cloud/d/d-id/1328966?_mc=sm_dr&hootPostID=af059d8271f774c137025b583778c95d