Showing posts with label Commandments. Show all posts
Showing posts with label Commandments. Show all posts

Wednesday, 18 January 2017

Scary new way to have your GMail password and account stolen.

This is an incredibly easy way for the evil doers to steal your GMail ID and password. This one could even catch out security people like me! 😱

So what happens is you receive an e-mail from somebody you know, who also had a GMail (note the emphasis on had). 

This e-mail will have a subject line of a previous e-mail conversation that you have had with that person and also, what appears to be an, attachment that had been attached in an earlier e-mail in that conversation. So far this e-mail is looking EXTREMELY legitimate.

That attachment, is actually an image in the e-mail with a link embedded in it and if you click on it, it will take you to, what appears to be, the GMail log-in screen, as follows:
Being asked to log-in like this would certainly trigger an alert in my mind that something was up. I would immediately check to see where this password page has come from, so I would look up at the address bar of the browser. This is what you would see:

So that looks OK doesn't it? https:// (nice and secure site) accounts.google.com (legitimate address) and the e-mail came from somebody I know, from an e-mail conversation I have had with them, that had an attachment, which was here again in this new e-mail. All very believable! So let me enter my GMail ID and password and ... you've now given the hackers your credentials.

Within minutes, they will have taken over your GMail account and will be sending this nasty surprise e-mail to your friends, family and colleagues.

So how do I know it's not a legitimate GMail login screen? Let's take another look at that address bar:

That first part of the address (highlighted) looks a bit odd, don't you think? It is very odd. It actually has a verrrrrrrrry long string of text, which stretches off beyond the end of what you can see in the address bar that executes a script, which brings up that log-in page.

Also, if you know your secure websites, you know that where there is proper https:// there is also a green padlock symbol like this:

That gives a high degree of confidence that the site is legitimate and properly secure.

Here's the best possible protection

I've said this numerous times. I tell everyone I know, that they must set this up to protect their accounts. 

It is known by many names - Two factor authentication or Two step verification or Login approvals.

I've a whole commandment dedicated to it, so please have a read and please implement it.

This protection, won't prevent you falling for the scam outlined above. What it will do is prevent the bad guys from accessing your account, even though they have your GMail ID and Password, they won't have your smart phone and as such won't be able to sign in as you.

Please implement Two factor authentication on all your on-line accounts. It really gives you the best possible protection.

h/t to the folks over on WordFence for the details on this.

Thursday, 27 October 2016

There is a lot of variations in evil e-mail the last couple of days.

I yearn for the days when evil e-mail was so easily identified "becuse it wuz ritten in, gud, inglish wit grate spellhng an pun.tation". ðŸ˜ƒ

In the last couple of days, the evil doers have been varying their scam e-mails fairly wildly and it's bound to catch out some people.

I'll run through three sneaky methods that have been attempted on others over the last 48 hours.

Friday, 23 September 2016

Here is a worrying aspect of the Yahoo breach.

Everyone has heard about the personal information related to 500 million Yahoo accounts being stolen from Yahoo in 2014. There's lots of helpful tips out there (and some here too), but some people may not realise that they have a Yahoo account.

Yahoo provides e-mail services to some big internet service providers (ISPs), over in the US AT&T, Rogers and Frontier.com. Over on this side of the Atlantic Sky and BT are large ISPs operating in Ireland and the UK. Their e-mail services are powered by Yahoo.

Snail mail delivers USB keys ... WTF?


I find I'm writing a second article about Evil USBs within a week. At least these ones don't destroy your equipment, but they might infect you with nasty software that does things that you really wouldn't want it doing.

In this case, in Victoria, Australia, Evil Doers were dropping USB drives into people's mailboxes. The report from Victoria Police stated:
Upon inserting the USB drives into their computers victims have experienced fraudulent media streaming service offers, as well as other serious issues.
The USB drives are believed to be extremely harmful and members of the public are urged to avoid plugging them into their computers or other devices.

Friday, 16 September 2016

A desktop/laptop killing device is on sale for €50.

As I'd mentioned in the detail section of a previous blog post there was a prototype USB memory stick that is designed to fry the electronics on a laptop or desktop, the instant it gets plugged into it.

Well it's now something you can buy for as little as €50. The worrying thing is, as of today (16th September 2016) they are out of stock!

What purpose does this device serve? 

According to their website "The USB Kill 2.0 is a testing device created to test USB ports against power surge attacks. The USB Kill 2.0 tests your device's resistance against this attack." Unfortunately in testing your device, this stick literally kills it!

Monday, 12 September 2016

Protect your on-line accounts, but not with text messages.

As I outlined here, if you are using an on-line account for e-mail, social media, etc. then one of the strongest means of protecting yourself from the evil doers is to use, what is called, two factor authentication. If you are not doing this now, you really should be as it improves your protection massively.

This is where you can set your on-line account to not only request your user ID and password (something you know) but also using your phone (something you have) by way of an app or sending you a text message with a code that you enter on the site to confirm you are you

If you have this set-up to authenticate by a SMS Text message, then a bad guy who has access to your LinkedIn details from the 2012 hack should not be able to access your e-mail account using the password that they have recovered from there, because as soon as they try to access your e-mail account, you will be sent a text message. So you're safe ... right?

Thursday, 14 July 2016

Evil doers just being evil ... news at 11!

The good folk over at Cisco's Talos Threat Intelligence Organisation have been looking at a new piece of "apparent" Ransomware called Ranscam.

The reason I use "apparent" is because it doesn't hold any of your data to ransom, quite simply because it's deleted it already! That doesn't stop it trying to get you to pay them good money, and even if you did pay up, you'll get nothing in return.

As we covered in Commandment IV of our Ten Commandments, if you have a good backup set up, then you need not concern yourself with whether Ransomware has or has not locked away your data. You simply wipe your equipment of the nasty malware and restore your data.

Ranscam isn't too widely spread at the moment and Talos reckon it was cobbled together rather quickly to try to cash in on this Ransomware market.

You can read the Talos report here:

If you want to get your staff to learn what steps they can take to reduce the risk of your business being affected by Ransomware, then check out the Security Awareness Training that is available from L2 Cyber Security.

Thursday, 7 July 2016

The Ten Commandments of Cyber Security


Click on the links for a summary and detail of each commandment.
  1. Thou shalt keep all of thy software and apps up-to-date with automatic updates.
  2. Thou shalt have Anti-virus software installed, updated and active.
  3. Thou shalt have a firewall in place on thine Desktop/Laptop as well as thine internet connection.
  4. Thou shalt always back up thy data and regularly check its integrity.
  5. Thou shalt cast aside messages from strangers and not open attachments/click links they may send you. (Corollary: Thou shalt never open an unexpected file/link from thine family, friends or colleagues)
  6. Thou shalt encrypt all data stored on thine mobile devices.
  7. Thou shalt use two factor authentication on any account that provides the facility.
  8. Thou shalt never reveal thine password for any account to anyone.
  9. Thou shalt never insert nor allow to be inserted, a USB memory stick that thy has never had complete control of since it was removed from its packaging.
  10. Thou shalt only use the official stores for apps.

X. Thou shalt only use the official stores for apps.

This is the final instalment in this series, which I have outlined here.

Summary:

This commandment is more targeted at the mobile device side of technology, but app stores are spreading into the desktop/laptop areas by way of Windows Store for Windows 8.1 and Windows 10.

From a mobile device perspective, you should only use the official app store for that platform. Most smartphones come with a setting that tells them to only allow apps to be downloaded and installed from the official sources (or not to be installed from untrusted sources).

Tuesday, 5 July 2016

IX. Thou shalt never insert nor allow to be inserted, a USB memory stick that thy hath never had complete control of since it was removed from its packaging.

This is the penultimate instalment in the series, which I have outlined here.

Summary:

This is an easy commandment to follow, but there might be temptation to breach it for convenience. 

If you find a USB memory stick on the street or in a car park, bring it to a waste electrical goods recycling centre and dispose of it there. I was going to say place it in a bin, but that would not be good for the environment.

If anybody comes to you and wants you to plug in a USB memory stick into your desktop or laptop, just don’t! No matter what promises they make as to the security and cleanliness of their systems, you simply cannot trust the device.

Thursday, 30 June 2016

VIII. Thou shalt never reveal thine password for any account to anyone.

This is the eight instalment in the series, which I have outlined here.

Summary:

This is one that should be an absolute no-brainer. Your password is your key to your data and applications. It should be absolutely sacrosanct and known only to yourself and NOBODY else. Nobody else has a need for it, except the evil doers and you wouldn’t give it to them willingly, would you? It couldn’t be simpler than this.

Tuesday, 28 June 2016

VII. Thou shalt use two factor authentication on any account that provides the facility.

This is the next instalment in the series, which I have outlined here.

Summary:

What is two factor authentication? Put simply it is a way of gaining access to an application by using two means of verifying the identity of the person requesting access. Typically the means of verification are (a) something you know – e.g.- a Password (b) something you have – e.g.- a Mobile phone (c) something you are – e.g.- a Fingerprint.

It is probably one of the best ways of protecting an on-line account from evil doers, who scour the web, stealing passwords by the millions from the likes of LinkedIn and MySpace.

Thursday, 23 June 2016

VI. Thou shalt encrypt all data stored on thine mobile devices.

This is the sixth instalment in the series, which I have outlined here.

Summary:

Your data is valuable to you. Even something as simple as the phone numbers in your phone’s contact app. It’s also valuable to the evil doers. They would dearly love access to your phone with all of the valuable e-mail, SMS, call logs, WhatsApp messages. Everything on your phone will be of some use to these criminals, because it is real data, with valid names, e-mail addresses, phone numbers, etc. and they can sell this online to anybody who wants it, such as your competitors. Wouldn’t they like to know that you’ve been making lots of calls to one of their customers recently.

Tuesday, 21 June 2016

V. Thou shalt cast aside messages from strangers and not open attachments/click links they may send you.

We are half way through this series, which I have outlined here.

Summary:

I’m going to start this summary with some scary figures. 93% of phishing e-mails in Quarter 1 2016 have carried a Ransomware payload (source - PhishMe Q1 2016 Malware review). 30% of people that receive phishing e-mails open them and 12% of those that do, then open attachments or click on links (source - Verizon 2016 Data Breach Investigations Report).

Putting this into real figures – if you have 50 staff and they each receive phishing e-mail, 46 of them will have received Ransomware, 14 of them will look at the ransomware e-mail and 2 of them will open an attachment or click the link which will bring Ransomware into your business and cause mayhem. Even if you have followed Commandment IV to the letter.

Friday, 17 June 2016

IV. Thou shalt always back up thy data and regularly check its integrity.

This is the next instalment in the series, which I have outlined here.

Summary:

In conjunction with the first, second and third commandments … are you seeing a pattern here? By following each of these simple commandments, you are providing additional layers of defence against the evil doers. This is what security experts refer to as Defence-in-Depth. The more precautions you take, the more difficult it makes life for the bad guys, so they move on to easier targets than you.

Friday, 10 June 2016

III. Thou shalt have a firewall in place on thine Desktop/Laptop as well as thine internet connection.

This is the third instalment in the series, which I have outlined here.

Summary:

In conjunction with the first and second commandments, having a Firewall in place on your desktop or laptop improves your security posture as it adds another layer of protection in the fight against the evil doers. It is by no means a perfect solution on its own, as a poorly configured firewall would offer as much protection as a string vest in -30c/-22f weather conditions.

Tuesday, 7 June 2016

II - Thou shalt have Anti-virus software installed, updated and active.

This is the next instalment in the series, which I have outlined here.

Summary:

In conjunction with the first commandment, having Anti-Virus software installed, updated and active on your desktop, laptop or mobile device dramatically improves your security posture. This adds another layer of protection in the fight against the bad guys. 

Thursday, 2 June 2016

I - Thou shalt keep all of thy software and apps up-to-date with automatic updates.


This is the first in the series, which I have outlined here.


Summary

This is the first commandment for a reason. It is probably the number 1 step to reducing your risk of being compromised by hackers or malware. The reason for this is because hackers discover vulnerabilities in applications that are widely used (web browsers, e-mail clients, office productivity suites, etc.) and exploit these vulnerabilities to compromise your system (desktop, laptop, servers or mobile devices). 

Tuesday, 31 May 2016

Ten Commandments of Cyber Security.

Over the coming weeks, I will post a series of short articles in support of each of what I am calling the Ten Commandments of Cyber Security. These are simple steps for improving your cyber security posture, which should reduce your risk of being compromised.

These commandments are listed below, but I would like your opinions on this subject too. Do you have a commandment to add or any thoughts on any of those listed? Please let me know and I will do a follow up after I have completed my run through.

 Ten Commandments of Cyber Security.



  1. Thou shalt keep all of thy software and apps up-to-date with automatic updates.
  2. Thou shalt have Anti-virus software installed, updated and active.
  3. Thou shalt have a firewall in place on thine Desktop/Laptop as well as thine internet connection.
  4. Thou shalt always back up thy data and regularly check its integrity.
  5. Thou shalt cast aside messages from strangers and not open attachments/click links they may send you. (Corollary: Thou shalt never open an unexpected file/link from thine family, friends or colleagues)
  6. Thou shalt encrypt all data stored on thine mobile devices.
  7. Thou shalt use two factor authentication on any account that provides the facility.
  8. Thou shalt never reveal thine password for any account to anyone.
  9. Thou shalt never insert nor allow to be inserted, a USB memory stick that thy has never had complete control of since it was removed from its packaging.
  10. Thou shalt only use the official stores for apps.