Official blog of Data64

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, 16 September 2015

SALAMI THEFT

The salami theft is considered as a technique which is regarded as one of an automatic form of the crime.
This covers a part of a financial crime involving secret execution of an unauthorized program that causes the unnoticed debiting of a small amount of assets or money from a large number of sources or accounts .
It gained the Popularity from the fact that the small slices of profits are to be taken without noticeably reducing the whole amount.
The Person, who was really responsible for slicing, then sneaks away with all the stolen pieces. From another angle, the person deceptively acquires the whole slices, formed by aggregating those tiny slices of the source ; Of course, it is to be  considered the potential danger of the salami attacks, we must consider an example of salami slicing, well known as penny shaving or penny slicing that is as mentioned.

For example



If we consider a banking system, the DD (Demand Deposit)  system of programs for checking accounts could be changed or can be modified  (using the unauthorized  method or the illegal methods ) to randomly reduce each of a few  thousand  accounts by 1 rupee or 2 rupees by transferring the money to  the  persons favored account, where it can be withdrawn through authorized methods. i.e is to make the black money white.
 No controls and checking mechanism  are violated because the money is not removed from the system of accounts. Instead, very small amounts of funds are merely rearranged, which the affected persons rarely notice. Many such variations are possible.

Prevention Tips

• Contrast programs and files that may contain checksums with backup versions to determine the veracity loss.
• Write-protect the diskettes, more than ever when testing an untrusted computer program.
• Prevent booting a hard disk drive system from a diskette.
• While transferring files from one computer to the  another, use diskettes that does not have an executable files that strength  to be infected.

Detection of Salami Attacks

 There are several technical methods that are available:-
- A very specialized detection checksum can be built into the suspect program to determine the salami attacks
 -A snapshot storage space dump listing could be obtained at times in alleged program
-The identifiable amounts are being taken, which can be traced;
- Iterative binary search for matching halves of all accounts is another costly way to segregate an felonious account
However, a clever man can change the amounts debited and credited. So now comes a question can he be detected???????
Yes, Person performing this attack usually withdraws the money from the accounts in which it accumulates; so records will show an imbalance between the deposit and withdrawal transaction isn’t it. However, all accounts and transactions would have to be balanced over a significant period of time to detect these discrepancies.

Monday, 14 September 2015

TOR BROWSER

Tor Browser has been designed to help
you preserve your privacy online. Tor Browser is a tool set that can help you anonymizing web browsing and publishing, instant messaging, and other applications that use the TCP protocol. This can be helpful for private use and business use. It means that confidential information can be kept from prying eyes. ISPs, key loggers and other types of malware are not able to track your activities easily.
The interface allows you to toggle it on and off based upon when you need anonymity online. Tor Browser also lets you choose from various proxy tunnels based on a world map that displays exactly where each one is located. 
Overall, Tor Browser is a simple, well organized and effective tool for users who are concerned about security or invasions of privacy whilst they are online. The browser interface is a standard, user friendly affair and the application is relatively lightweight.
TOR Browser can be downloaded from the link given below:
https://www.torproject.org/download/download-easy.html.en

Steps to download TOR Browser

A pop up will appear after it got downloaded (Internet Connection Is Mandatory).
Configure Tor Browser according to your needs.
Configure the Tor with your Browser if it does not get configured automatically(if it is configured it will show you a screen as shown below).

SOME INSTRUCTION FOR USING TOR SUCCESSFULLY

Use the Tor Browser
Tor does not provide safety to all of the Internet traffic when you run it. Tor only protects your applications that are properly configured to send their Internet traffic through Tor. It is configured to protect your privacy and anonymity on the web as long as you are browsing with the Tor Browser.
Don't torrent over Tor
Torrent file-sharing applications ignore proxy settings and make direct connections even when they are told to use Tor. Even if your torrent application connects only through Tor, you will often send out your real IP address in the tracker GET request, because that's how torrents work. 
Don't enable or install browser plugins(Can harm your anonymity)
The Tor Browser will block browser plugins such as Flash, RealPlayer, QuickTime, and others: they can be manipulated into revealing your IP address. Similarly, we do not recommend installing additional add-ons or plugins into the Tor Browser, as these may bypass Tor or otherwise harm your anonymity and privacy.
Use HTTPS versions of websites
Tor will encrypt your traffic encryption, the Tor Browser include Https to force the use of HTTPS encryption with major websites that support it. However, you should still watch the browser URL bar to ensure that websites you provide sensitive information to display a blue and green button
Don't open documents downloaded through Tor while online
The Tor Browser will warn you before automatically opening documents that are handled by external applications. DO NOT IGNORE THIS WARNING. You should be very careful when downloading documents via Tor (especially DOC and PDF files) as these documents can contain Internet resources that will be downloaded outside of Tor by the application that opens them. This will reveal your non-Tor IP address. If you must work with DOC and/or PDF files, we strongly recommend using a disconnected computer
Use bridges 
Tor tries to prevent attackers from learning what destination websites you connect to. However, by default, it does not prevent somebody watching your Internet traffic from learning that you're using Tor. If this matters to you, you can reduce this risk by configuring Tor to use Tor Bridge. Ultimately the best protection is a social approach

Thursday, 3 September 2015

The Problem of ATM Skimmers

The method used by criminals to capture data from the magnetic stripe on the back of the ATM card. The devices used are smaller than a deck of cards and are often fastened in a close proximity to or over the top of the ATM’s factory installed card reader. The ATM skimming is a worldwide problem today.
In 2008, more than $1 billion was stolen in ATM-related crimes. Sure, some thieves take the old-fashioned route and crack them right open, but there's a much quieter, high-tech form of theft targeting ATMs. It's called skimming.

ATM skimming is like identity theft for debit cards

Thieves use hidden electronics to steal the personal information stored on your card and record your PIN number to access all that hard-earned cash in your account. That's why skimming takes two separate components to work.
The first part is the skimmer itself, a card reader placed over the ATM's real card slot. When you slide your card into the ATM, you're unwittingly sliding it through the counterfeit reader, which scans and stores all the information on the magnetic strip of ATM skimmer machine.
This is not the end of stealing actually because to get all the necessary and the most important information about the particular person’s ATM card the thieves need to steal the PIN number of the particular person’s ATM card.
And to get the PIN number here comes the concept of camera hidden on or near the ATM machine; tiny spy cameras are positioned to get a clear view of the keypad and records all the ATM’s PIN action.
So the users should always be aware of the objects mounted on the ATM or near the ATM machine. A pinhole or off-color piece of plastic could give away the camera's hiding place. Cameras could even be hidden in brochure racks or pamphlet box etc.
Some ATM skimmers employ fake keypads also which is placed and in lieu of cameras to capture PIN numbers.
Just like the card skimmers fit over the ATM's true card slot, skimming keypads are designed to mimic the keypad's design and fit over it like a glove. If you notice that the keypad on your ATM seems to protrude oddly from the surface around it, or if you spy an odd color change between the pad and the rest of the ATM, it could be a fake.

The Pictorial Representation of the use of ATM Skimming machine

 




Unfortunately, there are even more ways for thieves to access your bank account via an ATM and some of them don't even require skimming. Some times when we do card payment in time of any shopping purpose or anything then the person in the billing counter may steal all your ATM card information by sliding your ATM card in another mimic Card sliding slot which may be with the billing person but completely hidden to the authorized person of the ATM card. This case only can take place if the person who is doing card payment is completely unaware of the stealing.

Concluding Note

Be aware and be safe. In the trend of technology the thieves also apply their knowledge of technology to steal the money from you. Maximum persons now a days keep their money in their own personal ATM account instead of keeping them at their home. But the thieves can any time steal your money by stealing the necessary credentials whenever you go to take out the money from your ATM account through the ATM machine. So be aware of your identity getting theft.

ZeusBot | Trojan Horse Malware

Trojan horse in Canakkale, Turkey
Zeus or Zbot is a Trojan horse malware package that runs on the versions of Microsoft Windows. While it is capable of carrying out many malicious and criminal tasks. It is often used to steal banking information of a man-in-browser keystroke logging and from grabbing. It is also used to install the CryptoLocker Ransomware.

It is a malware toolkit that allows a cyber-criminals to build his own Trojan Horse. A Trojan Horse is computer program that appears to be legitimate but actually hides an attack. Zeus is basically sold in the black market and it facilitates the non-programmers to purchase the technology they need to carry out in the cyber crimes. According to a 2010 report from SecureWorks, the basic Zeus package starts at about $3,000. Additional modules, which can cost as much as $10,000, are available for specific tasks. 

Useful Terminology
  • Malware, short for malicious software, is any software used to disrupt computer operation, gather sensitive information, or gain access to private computer systems.
  • A Trojan horse, or Trojan, in computing is any malicious computer program which misrepresents itself as useful, routine, or interesting in order to persuade a victim to install it.
  • Man-in-the-Browser (MITB, MitB, MIB, MiB), a form of Internet threat related to Man-in-the-Middle (MITM), is a proxy Trojan horse that infects a web browser by taking advantage of vulnerabilities in browser security to modify web pages, modify transaction content or insert additional transactions, all in a completely covert fashion invisible to both the user and host web application. 
  • Keystroke logging, often referred to as keylogging or keyboard capturing, is the action of recording (or logging) the keys struck on a keyboard, typically in a covert manner so that the person using the keyboard is unaware that their actions are being monitored.
  • Form grabbing is a form of malware that works by retrieving authorization and log-in credentials from a web data form before it is passed over the Internet to a secure server. 
  • Ransomware is a type of malware that restricts access to a computer system that it infects in some way, and demands that the user pay a ransom to the operators of the malware to remove the restriction.
  • Cryptolocker is a ransomware Trojan which targeted computers running Microsoft Windows. 
Zeus is mainly spread through phishing. It was first introduced in July 2007 when it was used to steal information from the United States Department of Transportation. It became more wide spread in march,2009.

In June 2009 security company Prevx discovered that Zeus had compromised over 74,000 FTP accounts on websites of such companies as the Bank of America, NASA, Monster.com, ABC, Oracle, Play.com, Cisco, Amazon, and BusinessWeek.

Zeus gained notoriety in 2006 as being the tool of choice for criminals stealing online banking credentials. The malware can be customized to gather credentials from banks in specific geographic areas and can be distributed in many different ways, including email attachments and malicious Web links. Once infected, a PC can be recruited to become part of a botnet.

Because a Trojan built with a Zeus toolkit is so adaptable, variations of Zeus Trojans are often missed by anti-virus software applications. According to a report by security vendor Trusteer, 77% of the PCs infected with Zeus Trojans have up-to-date anti-virus software.

Hence, we can say that Zeus which is also known as Zbot is a Trojan horse is a money stealing machine that steals all the banking informations.
Concluding Note:

Keeping your computer safe from Zeus is not a monumental task. By following a few simple rules about Internet safety and coupling those rules with a robust security solution, you can rest assured that your computer is safe from the vast majority of Trojans and other malware that's out there.

Trojan horses are so named because they need your permission to run on your computer, either when you run the program yourself, or if you open a document or image that then runs the program. With this in mind, the first and best defence against Trojans is to never open an email attachment or run a program when you aren't 100 percent certain of the source, which includes all files downloaded from peer-to-peer programs or websites. But this is rarely possible in today's interconnected world, so awareness among the people is very important.

Copyright © Data64 ThinkPod | Powered by Blogger

Design by Anders Noren | Blogger Theme by NewBloggerThemes.com