L2 Cyber Security Blog

Musings and thoughts about current Cyber Security stories. Also some useful advice for all of my followers.

Tuesday, 31 May 2016

Ten Commandments of Cyber Security.

Over the coming weeks, I will post a series of short articles in support of each of what I am calling the Ten Commandments of Cyber Security. These are simple steps for improving your cyber security posture, which should reduce your risk of being compromised.

These commandments are listed below, but I would like your opinions on this subject too. Do you have a commandment to add or any thoughts on any of those listed? Please let me know and I will do a follow up after I have completed my run through.

 Ten Commandments of Cyber Security.



  1. Thou shalt keep all of thy software and apps up-to-date with automatic updates.
  2. Thou shalt have Anti-virus software installed, updated and active.
  3. Thou shalt have a firewall in place on thine Desktop/Laptop as well as thine internet connection.
  4. Thou shalt always back up thy data and regularly check its integrity.
  5. Thou shalt cast aside messages from strangers and not open attachments/click links they may send you. (Corollary: Thou shalt never open an unexpected file/link from thine family, friends or colleagues)
  6. Thou shalt encrypt all data stored on thine mobile devices.
  7. Thou shalt use two factor authentication on any account that provides the facility.
  8. Thou shalt never reveal thine password for any account to anyone.
  9. Thou shalt never insert nor allow to be inserted, a USB memory stick that thy has never had complete control of since it was removed from its packaging.
  10. Thou shalt only use the official stores for apps.
Posted by Unknown at 09:57:00 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Labels: Best Practice, Commandments, Defence in Depth, Security

Wednesday, 18 May 2016

Phishing by a spreadsheet?

So you receive an unexpected e-mail from a stranger, with the subject of "Important Notice" and it contains an attachment. If you've received L2 Cyber Security Solutions Staff Security Awareness Training, then you consign it to junk/spam and move on with your life.

However, if you do open the file, you get what looks like a spreadsheet, but it needs you to log in to Microsoft Excel (for some reason).

The attachment was not a spreadsheet, but was in fact a web page type file (officially a HTML document) and it contains hidden computer code that will transmit any login details you give it to the evildoers who created this. 

Of course you have turned on two factor authentication for your e-mail ... right? That means that even if you did enter your e-mail address and password into this sneaky phishing attack, you will be safe from your e-mail account being compromised because the criminals will need your phone to allow them access to your account. However now would be a good time to change your password anyway (just in case they get your phone). 

If you fell for this and have not turned on two factor authentication on your e-mail account, then please go and change your password immediately. If you have used that password on other accounts (like Facebook, LinkedIn, PayPal, etc.), please go and change them all immediately too - and for the love of dogs, please turn on two factor authentication in whichever services provide it! It really will make you more secure.

Fortunately the website to where the details are transmitted has been blocked, but this just shows how creative the bad guys are. You can't let your guard down for a moment.

And lets be careful out there!

Posted by Unknown at 09:36:00 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Labels: Excel, Phishing, Security, Spreadsheet

Monday, 16 May 2016

Sneaky Facebook phishing attack.

I became aware of this really sneaky attempt by hackers to steal people's Facebook ID and password recently. It's quite clever and I must admit that I could quite easily have fallen victim to it, had I not read the article.

I've put a link to the full article at the bottom of this post, but essentially what happens is:

  • If you click on a compromised link, a very legitimate looking "Facebook Page Verification" form will appear asking for your e-mail/phone, password and a  security question.

























  • If you fill it in, it will say that the first attempt is incorrect.
  • If you fill it in again, it will then come back to say it has been accepted and is awaiting approval, which might take 24 hours.


The failure at the first attempt is a clever ruse to fool people that might input a false ID and password initially (in case the form is illegitimate) before proceeding with their correct credentials when they perceive the site to be legitimate (as it rejected their false details).
  
Whatever you have typed in will be taken and used/abused by the evildoers.

The only way to protect yourself from being compromised is to turn on "Login Approvals" in your Facebook security settings. This will mean if somebody (including you) try to log in to your Facebook account from a different device/location, they will need to use your phone to get a code to prove you are who you told Facebook you are.

If you have already filled in your details on this page, change your Facebook password immediately and turn on the Login Approvals. If your e-mail account associated with Facebook has the same password, then change that one too and if possible turn on it's Two-Factor Authentication (i.e. to use your phone to secure that account as well).

And lets be careful out there!

http://news.netcraft.com/archives/2016/04/22/hook-like-and-sinker-facebook-serves-up-its-own-phish.html
Posted by Unknown at 14:35:00 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Labels: Facebook, Phishing, Security
Newer Posts Home
Subscribe to: Posts (Atom)

About Me

Unknown
View my complete profile

Sticky Post

The Ten Commandments of Cyber Security

Blog Archive

  • ►  2017 (1)
    • ►  January (1)
  • ▼  2016 (38)
    • ►  December (6)
    • ►  October (4)
    • ►  September (6)
    • ►  August (4)
    • ►  July (5)
    • ►  June (10)
    • ▼  May (3)
      • Ten Commandments of Cyber Security.
      • Phishing by a spreadsheet?
      • Sneaky Facebook phishing attack.

Subscribe To

Posts
Atom
Posts
All Comments
Atom
All Comments
© L2 Cyber Security Solutions 2016. Simple theme. Powered by Blogger.