Showing posts with label Tech. Show all posts
Showing posts with label Tech. Show all posts

Sunday, October 11, 2015

Avoid being Hacked!

5+ Tips to keep Bank Accounts Safe from Hackers


   Today its the world of Internet. It's an integral part of our daily life. We use it for several reasons like communication, searching for information, ticketing, social engineering and also for making payments. A Mumbai-based businessman was cheated of Rs 41 lakh after criminals hacked into his email account earlier this month. Like this we get several news around the globe that hackers stole the money from bank accounts, misused the credit cards and etc...,

There are several people on the internet called "Hackers" who are out to get your money by preying on your unsuspecting instincts. These Hackers use various methods to steal our money online. Here are the 5 common methods they used to hack the system and do fraudulent actions.

Hackers | Avoid being Hacked
Hacker

1. Email Spoofing : Everyone use email for work or personal use. This makes it one of the easiest methods to contact someone and lure him with fake schemes.The most common fraud emails include those about winning lotteries or a wealthy prince looking to invest money through you. Emails like these from people you don't know should be red flagged. These emails with attachments that can install spyware or viruses when you open the attachment. Banks never send emails to share your account number, password, credit card number and etc..,
Email Spoofing | Avoid being Hacked
Email Spoofing

Counter Measures :
 # The simple way to be safe against email fraud is to neither download attachments nor send details to unknown senders.
 # Do not share or register your email in public domains.
 # Delete or mark the emails as Spam received from unknown sender.
 # Install an Antivirus Software and be updated with latest virus definition.


2. Phishing Website : Phishing is the attempt to acquire sensitive information such as usernames, passwords, and credit card details and sometimes indirectly money, often for malicious reasons by masquerading as a trustworthy entity in an electronic communication. Most of the time it is the bank websites that get duplicated. They look exactly like the original and will ask you to input your LoginID and Password to proceed. If you provide these details, the creator of phishing website will use them to access your account. The easiest way to detect a fake bank website is to see the browser address bar. Check for "https:" in the website address bar. This means that the site uses a secure certificate and mostly all bank websites use this. In terms of Mobile Apps, check for the developer name which is usually written below the app name in the app store. Only download banking apps from the official app stores.

Phishing Website - Bank of America | Avoid being Hacked
Phishing Website

Counter Measures :
 # Check for "https:" in the website address bar.
 # View Security Certificate of website. In Mozilla Firefox, before the address bar we can see the name in green colour which indicates as secure website. We click that to view the security certificate of website.
 # Enable "Two-Factor Authentication" for banking transaction.
 # Update the Internet Browser to the latest.
 # Always download Mobile Apps from app store in smartphones.
 # Install an Antivirus Software and be updated with latest virus definition.


3. Keylogger : A keylogger is software installed on a computer that records each and every keystroke you do on the keyboard. A hacker can find your login details just by accessing the entire log of your key presses. Public internet cafes are an easy target to install these key loggers to get crucial information from unsuspecting users. There is essentially no way to detect if a keylogger is running in the background or not. Keylogger is not only a software, there are several hardware keyloggers available very cheap in the market which are installed in the computers.




Keylogger - Software | Avoid being Hacked
Keylogger - Software
Keylogger - Hardware | Avoid being Hacked
Keylogger - Hardware

 













 Counter Measures :
 # Use virtual keyboards and most of the bank websites have this.
 # Regularly update the Operating System to the latest version,
 # Use onscreen keyboard. In Windows -> Run -> osk
 # Install an Antivirus Software and be updated with latest virus definition.



4. Fake Ads : Any advertising or promotion that misrepresents the nature, characteristics, qualities or geographic origin of goods, services or commercial activities. If you see a product available at a price which is way below the regular asking price, it is bound to be some sort of scam. You can get discounts online, but when something is listed as 80% or 90% off the retail price, it's a red flag. Keep in mind that these products could also be stolen or imported products being sold. When you try to buy any product online, you are bound to share your bank account number, credit card details which are indirectly stolen by the hackers.



Fake Ads | Avoid being Hacked
Fake Ads
 Counter Measures :
 # Use Ad Blockers. Install adblocker addons to the browser.
 # Try to purchase online in reputed e-commerce portal.
 # Install an Antivirus Software and be updated with latest virus definition.



5 . Phone Scams : Every year, thousands of people lose money to telephone scams from a small amount to their life savings. Scammers will say anything to cheat people out of money.They use some special phrases like "You've been specially selected" | "You've won big money in a foreign lottery" | "We'll just put the shipping and handling charges on your credit card". No one from your bank will ever call and ask to share your account number, password, credit card number and etc..,  There are many advertisements sent by banks to avoid this issue. Any call claiming to be from the bank and asking for bank details is a red flag. Smartphones are the biggest challenges today. Do not open the text message received from unknown sender. It may encrypted and causes damage.



Phone Scam | Avoid being Hacked
Phone  Scams
Counter Measures :
 # Do not share your Phone/Mobile number in public domain.
 # Activate "Do not Disturb" facility to your number from service provider.
 # Always download Apps from app store in smartphones.
 # Install an Mobile Antivirus Software and be updated with latest virus definition.

Thanks for reading the blog. Kindly transfer the knowledge & Share it!

Friday, September 25, 2015

Firefox's Hello

Firefox Hello | A Browser comes with its own Instant Messaging

Hello | Firefox browser comes with its own instant messaging
Firefox Hello

   In the latest update of Firefox 41, it is now the first browser to have built-in instant messaging.

Firefox's Hello, developed and built directly into a browser which will let us to send and receive instant messages when we are in a video call in Firefox for Windows, Mac and Linux.

Hello is WebRTC (Web Real Time Communication) powered which enable us todo video chating. This can all be done without the need for setting up an account or giving up any of our personal information. Hello icon in the menu bar or customization panel, simply click the ‘Start a conversation’ button to create your first conversation. Now when you start a conversation, a window opens showing a self-view until the person you have invited clicks on the link and joins you. While you’re waiting for them to join, you can navigate away from this call window to a website. Hello will then notify you when another party joins the room. The Hello icon will turn blue and you’ll get an audio alert.

Firefox Hello | Chat Window
Firefox Hello Chat Window


Every conversation uses a unique URL for two people to communicate more easily over video or audio. You can create multiple conversations (Groups) and name them for different occasions, making it easier to go back to the people you speak to regularly without having to create a new link each time. We can label the conversation as ‘Team’ for weekly check-in with a co-worker and another ‘Family’ for our regular family catch-up. All the conversation are saved and can be retrieved whenever required.

To contact someone directly, you just need to make sure both parties have Firefox Accounts. If your contacts have a Firefox Account and are online, then you can call these contacts directly from Firefox. We can easily import contacts to your Hello address book from Google Account. Just select ‘Import Contacts’ from the address book and then sign into your Google account to give permission.

Firefox Hello as a comprehensive tool for communicating over the Web, will be testing new features like screen sharing and online collaboration so people can be more productive and get the most out of their video calls in the near future.

Friday, August 7, 2015

Yahoo's Tool fixes one of the Biggest Problems with Email

Yahoo fixes the Biggest Email Problem

Yahoo Email Problem
Marissa Mayer - CEO Yahoo!


      Starting next week, Yahoo Mail is getting a beefed-up search feature that's better at helping its 255 million users dig through your email for the stuff you want, reports the New York Times.
It's super common for e-mail users, like me, to use their e-mail as a total online life archive. Photos, documents, coupons, whatever else I need, I just do a Gmail search and dig through messages dating back to 2007 until I find what I was looking for.

The new Yahoo Mail search is designed with that in mind. If you search for "Photos from Disneyland," its algorithm will apparently go to work and just display an impromptu photo gallery culled from your messages.

It can also help you narrow a search, so that if you're looking for your American Airlines boarding pass, it won't also show you every marketing e-mail you've ever gotten from them. Another potential use is for finding coupons from a store while you're at that store, sifting through your unopened promo email.

Google, the world's No.1 Internet search company, has tried to tackle this problem from a different direction. The company takes a more proactive approach with tools like the Inbox app and Google Now, which automatically surface information inside of emails that it thinks are relevant based on contex such as geographic location and time of day. But Google's actual email search function works mostly the same as it has for the last almost-decade.

For Yahoo CEO Marissa Mayer, a former Google executive who for years oversaw the design of Google's search engine, the focus on email search is a natural move. Mayer recently amended Yahoo's search partnership with Microsoft, giving Yahoo new freedom to develop search offerings.

The technology that Yahoo is employing here will also go into other products like Fantasy Sports and the new Livetext app, per that report. It can also be used for smarter, more personal search.

It's an important move for Yahoo, which has spent most of the last decade allowing Google to leapfrog it in terms of search innovation. Now let's see how the new email search tool works in real life.

Courtesy : BusinessInsider

Thursday, August 6, 2015

7+ Steps to Browse any Banned Websites

How to Browse any Blocked Websites?




#1. Use a proxy to browse the site in anonymity. There are tons of "free proxy servers". When you are using proxy servers please ensure you are not using it to access your banking or sharing any personal data since the data can be intercepted by the third party. But it's an easy way to access blocked sites. You can configure your browser to use proxy server using a special port or directly access proxy server and use the url bar provided in their site to type the address you want to visit. Here is a list of few free proxy servers:
   a. Hidemyass   -   https://www.hidemyass.com/proxy
   b. Kproxy         -  http://www.kproxy.com/
   c. Proxify         -  https://proxify.com/

#2. Use a paid VPN service. They typically provide you servers from many different country - pick one which won't block the sites you want to visit. VPN service usage can be tracked down so use it wisely. And "ibvpn" is cheap and speed is good too.

#3. Use TOR free service to roam the internet without any sort of censorship.

#4. For ease of use install Firefox add-on or Chrome extension. Here are few to help you with: Browsec, Zenmate, Hola(No Linux support) and Frigate.

#5. Use a smart DNS service. Here is a list of services: https://7labs.heypub.com/tips-tricks/best-smart-dns-providers.html

#6. Visit translate.google.com and type in the URL to access your site. Will work for few type of sites only.

#7. The best trick and the most free/simple one if you are slightly technical inclined. Ping the domain and get the IP address then put a host entry in /etc/hosts if you are in Linux/Mac, if using windows the etc/hosts can be found under c:\windows\system32. The entry should be in the form of "ipaddress yourcustomdomainname.com" yourcustomdomainname.com can be any name which isn't blocked.  After you access the primary url and when you navigate to a new link again it might say the site is blocked but just again change the name of the primary domain in URL to your hosts entry domain name and it would work.


Permission Denied Website


#8. If your isp is really stupid you can directly use ip instead of domain name to avoid the restriction without using any of the above mentioned method.

@ Please don't take this learning for accessing Porn sites.

Author : Navin Sylvester

Monday, July 27, 2015

Golroted

Beware, virus targeting email, banking data on the prowl......



Cyber security sleuths have alerted Indian internet users about the destructive phishing attacks by a virus which could compromise personal email and banking-related data.
The virus, identified as 'Golroted', belongs to the deadly 'Trojan' category of computer viruses which is characterised by its smart capability of masking its original content and looking like genuine.
"It has been reported that variants of a new malware family, dubbed as Golroted, having spyware functionalities are spreading. These malware typically spread through spear phishing mails having attachments as zipped archives or Microsoft Office document exploits or via removable drives," the Computer Emergency Response Team of India (CERT-In) said in a latest advisory to domestic internet users.
The CERT-In is the nodal agency to combat hacking, phishing and to fortify security-related defences of the Indian internet domain.
The agency said once the virus infects a system successfully, it is capable of stealing Personal Identifiable Information (PII) from the affected machine that includes computer name, local date or time, Internet Protocol address, installed security software, among other private and sensitive system details.
The virus is notorious for undertaking specific attacks with regard to banking and financial transactions, ultimately leading to loss of funds kept in the bank account.
"Golroted is reported as targeting banking sites, online payment sites, email accounts, social networking sites among others. The stolen information is ex-filtrated to a pre-configured File Transfer Protocol server/web panels or to email addresses as attachments," it said.
The agency said at least two aliases or pseudo-identities of the said virus have been detected till now.
"The spyware is capable to log key strokes, capture screen shots, scrap web browsers for saved passwords, browsing history etc," it said.
The agency has suggested some counter-measures in this regard.
Do not allow administrative access to systems, with the exception of special administrative accounts for administrators, do not download or open attachment in emails received from untrusted sources or unexpectedly received from trusted users, do not visit untrusted websites and enable firewall at gateway or desktop level.
The agency also said that vulnerable systems, whom the virus could target, should install and scan anti-malware engines and keep them up-to-date.
Do not follow unsolicited web links or attachments in email messages, limit or eliminate the use of shared or group accounts, turn off file sharing if not needed and disable "save credentials" feature in browsers, are some of the counter-combat measures suggested by the agency.

Courtesy : TOI