Showing posts with label Vulnerability. Show all posts
Showing posts with label Vulnerability. Show all posts

Monday, 19 December 2016

Do you own a Netgear router? If so, you may have a serious vulnerability.

Netgear Routers Vulnerable


If you have one of the following Netgear router models, you could be exposed to a serious vulnerability:
  • R6250
  • R6400
  • R6700
  • R7000
  • R7100LG
  • R7300
  • R7900
  • R8000
There is a simple test that you can carry out to determine if you have a vulnerable router. From a device connected to the router, open the following link in a browser:
     http://www.routerlogin.net/cgi-bin/;echo$IFS'Vulnerable!'
If you see a simple webpage that says Vulnerable!, then you have an affected router.

The risk with this vulnerability is that hackers can scan the internet looking for these routers and if they detect one, they can take it over quite simply and use it for nefarious purposes.

Netgear have made some patches available, but not for every model at the moment. These patches require technical skills to install safely, so please contact your IT support provider. Don't expect your teenager to be able to do this, unless they have already had experience of flashing router firmware successfully before. Making a mistake when doing this, could render the router unusable.

While you await for the router to be patched, you can protect yourself by opening the following link in a browser:
Once you have done that try the previous link above to see if it still says Vulnerable! 

If you reboot/restart the router after this, you will need to open that last link above again.

If you have any questions or concerns, please contact us on info@L2CyberSecurity.com or call us on 087-436-2675.

Wednesday, 26 October 2016

If you have Adobe Flash Player installed, read this now.


I really HATE Adobe Flash player. ðŸ˜¡ It is the internet equivalent of Typhoid Mary. If you don't need it, uninstall it. If you do need it, use Chrome as your browser. Why the rant?

Adobe has released a Critical update to Flash Player because of a vulnerability with it that has already been exploited in targeted attacks against Windows.
https://helpx.adobe.com/…/produ…/flash-player/apsb16-36.html


If you use Chrome or Microsoft's Edge or Internet Explorer 11, then the Flash player built in to these will get updated automatically. So concern yourself not.

However if you use Internet Explorer 10 or less (check Help->About) or other browsers and have Flash Player installed, then go to the following link and be sure to UNCHECK the "Optional Offers" and Click "Install Now" and follow the directions to upgrade your Flash Player.
https://get.adobe.com/flashplayer/

The sooner Flash goes away, the happier I will be. ðŸ˜‰

In the meantime ... Let's be careful out there.

Thursday, 29 September 2016

Using the Internet Safely. Training from L2 Cyber Security Solutions.

Human Error
Did you know that evil software gets past commercial anti-virus and e-mail filtering products on a worryingly regular basis.

Firewalls and Anti-virus packages lure people into a false sense of security. While they do provide protection up to a point, if somebody opens an e-mail attachment that contains new Malware, these protections are effectively useless.

Cyber incidents, most notably Ransomware attacks have seen massive increases recently. 93% of phishing e-mails in Quarter 1 2016 have carried a Ransomware payload (source - PhishMe Q1 2016 Malware review). 30% of people that receive phishing e-mails open them and 12% of those that do, then open attachments or click on links (source - Verizon 2016 Data Breach Investigations Report).

These statistics highlight the fact that a significant weak link in any organisation, where it comes to using the internet and e-mail, are THE STAFF, but it's not their fault.

The best protection to cover this gap are staff that are aware of what the threats are and how they manifest themselves. Once they are armed with the knowledge of what to look out for, they will be much less likely to cause a security breach.

The training that L2 Cyber Security Solutions delivers is comprehensive, yet simple for all to follow.

Using the Internet Safely

Course Outline

Lecture / Workshop


Duration:

1 day


Audience:

People who have access to and utilise the internet and e-mail, whether for personal or business purposes, as part of their day. 


Prerequisites:

A basic understanding of internet browsing and e-mail usage is a prerequisite.


Programme Aim:

This training will give the attendees an understanding of the risks and threats associated with using the internet and e-mail.


Learning Outcome:

The participants will know how they can take some simple steps to avoid being adversely affected by the various risks presented to them. They will also learn how to create unique and strong passwords.


Course Content:

  1. Malware (incl. Ransomware)
  2. Spam
  3. Social Engineering
  4. Phishing and Spear-Phishing (incl. CEO Fraud)
  5. Safe Web Browsing
  6. Good Security Practices
  7. Mobile Security
  8. Creating a unique and strong password

Call us on 087-436-2675 or e-mail info@L2CyberSecurity.com to discuss your requirements and get a quotation.

Tuesday, 16 August 2016

A Nightmare on Quadrooter Street.

When I was a teenager, watching slasher flicks like A Nightmare on Elm Street (the original 1984 version) and Halloween, in order to look like a "tough guy" I developed a sort of movie watching buffer whereby when any startling occurrence happened (e.g. the scary guy leaps out of the shadows), I would simply sit there all cool-like while all around me leaped out of their seats. I would mentally take a moment to let the occurrence happen and then internally say "Yep! That thing that happens in every scary movie happened" and just continue watching. I just don't react to the situation the instant it happens.

Nowadays I continue this type of trick when I read scary stories. For example, last weeks blog post about the Garda Síochána hack. After all the initial "Mob hack the Garda" hyperbole, it would appear, after a few days, that it was a simple Ransomware incident.

And so it is with the recent story from Check Point Software Technologies Ltd about their sexily named Quadrooter. A set of four vulnerabilities what they discovered in the Qualcomm chips that are in use in up to 900 million Android devices worldwide.