Showing posts with label Awareness. Show all posts
Showing posts with label Awareness. Show all posts

Monday, May 28, 2012

Upcoming Security and Hacking Conferences


Below is the consolidated list of upcoming popular security and hackers conferences. Those who are interested in attending or speaking in any one of these conferences can refer the link provided in the respective conference titles. 
   
Conferences
Location
Date
Moscow, Russia
May 30-May 31 2012
Honolulu, HI
Jun 18-Jun 21 2012
Athens, Greece
Jul 10-Jul 13 2012
Lasvegas, NV
Jul 25-Jul 26 2012
Las vegas, USA
Jul 26-Jul 29 2012
Trivandrum, India
Aug 3-Aug 4 2012
New Delhi, India
Aug 24-Aug 25 2012
Baltimore, USA
Aug 25-Aug 30 2012
New Delhi, India
Sep 26-Sep 29 2012
Melbourne, Australia
Oct 17-Oct 18 2012
Melbourne, Australia
Oct 20-Oct 21 2012
Helsinki, Finland
Oct 25-Oct 26 2012
Miami, USA
Oct 25-Oct 31 2012
Brussels, Belgium
Nov 20-Nov 21 2012
Las vegas, USA
Dec 1-Dec 6 2012
Pune, India
Dec 1-Dec 2 2012
Norway
Dec 3-Dec 4 2012

Happy Learning :-)  !!!!

Sunday, May 20, 2012

System Hacking by exploiting vulnerability of Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier.




Oracle Java SE versions mentioned above is prone to a remote code-execution vulnerability in Java Runtime Environment. 

The vulnerability can be exploited over multiple protocols. This issue affects the 'Scripting' sub-component. 

This vulnerability affects the following supported versions: JDK and JRE 7, 6 Update 27 and earlier.

Here is the CVE update : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3544


Demonstration

I have prepared a demo to show How this vulnerability can be exploited to hack a system.


OR

Visit direct link http://www.youtube.com/watch?v=FDiEZZ8xA3U is video is not clearly visible above. 

Disclaimer  : This video is made for public awareness purpose and author is not responsible for any misuse of this video. 


Prevention : 

Update the latest version of the components. 



Friday, June 4, 2010

Alert: New Social Engineering Attack




I am reproducing a mail which I received from a information security group. This is a new social engineering attack and these types of social engineering attacks can be minimize by social awareness campaign only. I am contributing my cents through my blog.

It all started when I received a call from someone claiming that he was from my mobile service provider and he asked me to shut down my phone for 2 hours for 3G update to take place. As I was rushing for a meeting, I did not question and shutdown my cell phone. After 45 minutes I felt very suspicious since the caller did not even introduce his name. I quickly turned on my cell phone and I received several calls from my family members. I called my parents and I was shocked that they sounded very worried asking me whether I am safe. My parents told me that they had received a call from someone claiming that they had me with them and asking for money to let me free. The call was so real and my parents even heard 'my voice' crying out loud asking for help. My parent was at the bank waiting for next call to proceed for money transfer. I told my parents that I am safe and asked them to lodge a police report. Right after that I received another call from the guy asking me to shut down my cell phone for another 1 hour which I refused to do and hung up. They keep calling my cell phone until the battery had run down. I myself lodged a police report and I was informed by the officer that there were many such scams reported. MOST of the cases reported that the victim had already transferred the money! And it is impossible to get back the money.

Be careful as this kind of scam might happen to any of us!!! Those guys are so professional and very convincing during calls. 


Be Safe and Stay Alert!

Wednesday, March 17, 2010

Hackers need your help first to succeed





Many of you may surprise to hear this but in most cyber security incidents it has been found that they succeeded because victims have helped them first. Today I am going to explain how a user may help cyber criminals.

Awareness: Social Engineering attacks are one example where attacker successfully executes attacks and      victim couldn’t prevent it because of lack of awareness of latest attack trends and their countermeasures.   Today knowledge should not limit to using a system; we all need to update our self with the latest security trends and must be aware how to use a system securely. 
Ignorance:  It is being said that “Real knowledge is to know the extent of one's ignorance” and attackers work on same principle to come inside your trusted boundary. Let me explain with one example, it is advisable that user should change their passwords after certain period of time. How many of us are following this? Similarly there are few set of guidelines that one should follow while using this sophisticated system.
Rely: It’s a human nature that we usually rely on someone very easily who care for us or who think about us and most of the times we judge people in day to day interactions but in an Internet platform these classic judgments methodology are one of the soft and useful weapon of cyber criminals. Phishing attack is one example which is executed by using two common human behaviors- Rely and Ignorance. Don't rely too much on labels, for too often they are trap.  

Finally, I would like to say that Awareness is not expensive so do not try Ignorance and must Rely on acquisition of knowledge.