Thursday, 6 March 2014

HTTPS can leak your Personal details to Attackers

  


Explosive revelations of massive surveillance programs conducted by government agencies by the former contractor Edward Snowden triggered new debate about the security and privacy of each individual who is connected somehow to the Internet and after the Snowden’s disclosures they think that by adopting encrypted communications, i.e. SSL enabled websites, over the Internet, they’ll be secure.

People do care of their privacy and many have already changed some of their online habits, like by using HTTPS instead of HTTP while they are surfing the Internet. However, HTTPS may be secured to run an online store or the eCommerce Web site, but it fails as a privacy tool.
 
The US researchers have found a traffic analysis of ten widely used HTTPS-secured Web sites “exposing personal details, including medical conditions, financial and legal affairs and sexual orientation".
 
The UC Berkeley researchers Brad Miller, A. D. Joseph and J. D. Tygar and Intel Labs' researchers, Ling Huang, together in "I Know Why You Went to the Clinic: Risks and Realization of HTTPS Traffic Analysis’ (PDF), showed that HTTPS, which is a protocol to transfer encrypted data over the Web, may also be vulnerable to traffic analysis.
 
Due to similarities with the Bag-of-Words approach to document classification, the researchers refer their analysis as Bag-of-Gaussians (BoG).
 
"Our attack applies clustering techniques to identify patterns in traffic. We then use a Gaussian distribution to determine similarity to each cluster and map traffic samples into a fixed width representation compatible with a wide range of machine learning techniques,” say the researchers."
 
They also mentioned that, "all capable adversaries must have at least two abilities." i.e. The attacker must be able to visit the same web pages as the victim, allowing the attacker to identify patterns in encrypted traffic indicative of different web pages and "The adversary must also be able to observe victim traffic, allowing the adversary to match observed traffic with previously learned patterns" they said.

The Test analysis carried out in the study includes health care services, legal services, banking and finance, Netflix and YouTube as well. The traffic analysis attack covered 6,000 individual pages on the ten Web sites and identified individual pages in the same websites with 89% accuracy in associating users with the pages they viewed.

Snowden mentioned previously, "Encryption works. Properly implemented strong crypto systems are one of the few things that you can rely on. Unfortunately, endpoint security is so terrifically weak that NSA can frequently find ways around it" So, the technique allows Government agencies to target HTTPS traffic to mine metadata from ISP Snooping, Employee Monitoring, and which they could use for Surveillance and Censorship purpose.

Friday, 14 February 2014

Wirte your own simple Ruby Script :)

Hey Guys,

Today we are going to learn on how to  write a very simple and also usefull ruby script which one we can use it in our day to day life. As a information security expert as we should prise the following quote,

                           “If you are not updated, You will be outdated”

Everyday morning Information Security people will see some online blogs to update their knowledge. Its not only for Info Sec people its also applicable for all. So, we have written a very simple
ruby script which will open all your favorite sites in your browser with one shot. We hope it will make
your life some more easier. 

Ruby Script:
 
You can add any sites as per your wish in the blue color links, 
--------------------------------------------------------------------------------------------------------------------------------------------------------------------
system("firefox http://www.exploit-db.com/ http://www.osvdb.org/
http://www.sans.org/reading-room/ https://www.incidents.org/ https://isc.sans.edu/podcast.html
http://krebsonsecurity.com/ http://ddanchev.blogspot.in/ http://taosecurity.blogspot.in/
http://blog.uncommonsensesecurity.com/ http://roer.com/ https://www.schneier.com/")
--------------------------------------------------------------------------------------------------------------------------------------------------------------------

Step 1: 
Copy above script and paste it in text file:- (You can also customize the weblink as per your wish)


Step 2:

Save the same as filename.rb, here is an example, we saved our script as dailybread.rb in Desktop. 


Step 3:
 
So, Our script is available in Desktop.

 Let's start working on it :-p 

run it - #ruby dailybread.rb

 

Step 4: 

Hit enter with all your favorite sites which is added in the script and it will open in browser.
 
Its very simple but it may be help you a lot. Feel free to leave your comments.

Tuesday, 21 January 2014

Learn Ethical Hacking at BRISK Launching BISE V/2 Sunday, January 26, 2014 from 10:00 AM (IST) Chennai, India

Event Details

Dear Friends,

Brisk Info Sec proudly announce our next Brisk Information Security Expert Version 2 certification program.
Batch starts on 26/01/2014 (Sunday).
Who should attend this course:
  • Peoples interested in Hacking and Information Security
  • Software Engineers
  • Web application developers
  • Networking Persons
  • Information Security people
  • Auditors
  • Lawyers
  • Risk Assessment Managers
  • Testing Peoples
  • BE/B.Tech students
  • Bsc , Msc CS/IT
  • MCA
  • Diploma CSE / IT
  • Job Seekers
  • Business Peoples
Teaching Methods:
We know what people want. That is why we classified our course into two main categories and they are as follows,
  1. White Hat Hacking 
  2. Black Hat Hacking
This structured course is balanced at 750 slides with Numerous opportunities to watch instructor-led demos, whilst hacking our library of over 100 practical exercises, finishing with at the course is executed in the following style:
  • Brief theory delivered in lecture-style with examples.
  • Interactive demonstrations of key techniques.
  • Hands-on hacking.
  • Conducting International certificate online exam
  • Full hands on Windows OS and Kali Operating System. 

Course Details:
Duration         :     48 hours
Total Days      :    6 days (8hrs per day)
Tool kits         :    Text book + 5 DVD +Online Exam + Brisk Laptop Bag + Placement Assistance
Batches         :    Weekend batches (Saturday & Sunday)

Visit & register in our office on or before 25/01/2014 and get 25% of discount from our fees.
BISE V/2 Fees : Rs 20000/- only
Offer upto 25/01/2014 : 25%
BISE V/2 Fees after Discount : Rs 15000/- Only
Download Our Browcher

Venue:
Brisk Info Sec
No 150,Office No - 1,Ist Floor, Dharma Towers,
Nelsonmanikem road,Choolimedu, Chennai
PH - 9597978375
Email-contact@briskinfosec.com
Website-www.briskinfosec.com

'123456' giving tough competition to 'password' in Worst 25 Passwords of 2013


123456, password, 12345678, qwerty… or abc123, How many of you have your password one of these??? I think quite a many of you.

Even after countless warnings and advices given to the users by many security researchers, people are continuously using a weak strength of password chains.

After observing many cyber attacks in 2013, we have seen many incidents where an attacker can predict or brute-force your passwords very easily.

From 2012, the only change till now is that the string “password” has shifted to the second place in a list of the most commonly used passphrases and string “123456” has taken the first place recently, according to an annual "Worst Passwords" report released by SplashData, a password management software company.

They announced the annual list of 25 most common passwords i.e. Obviously the worst password that found on the Internet. The Most common lists of the passwords this year are "qwerty," "abc123," "111111," and "iloveyou", which are really easily guessable.

"Another interesting aspect of this year's list is that most short numerical passwords showed up even though websites are starting to enforce stronger password policies," says Morgan Slain, CEO of SplashData.  

Below are the worst passwords list of 2013 with Rank and showing the comparison of it from 2012:





If you are also using one of these passwords or other dictionary words, then you are advised to change it as soon as possible. We further advise you to use different passwords for different accounts, as if one of your account gets hacked, you’ll be totally ruined.

The above list of passwords was compiled from data dumps of stolen passwords posted online, and the firm says it was especially influenced by the millions of Adobe accounts that were compromised in the fall.

Fact & figure:
 Stricture Consulting Group attempted to decrypt the leaked Adobe passwords and released an estimate that almost 2 million of the more than 130 million users affected by the breach appeared to be using "123456" as a password.

Now when you talk about various security measures to protect your privacy and data, installing an Antivirus doesn’t mean that here your work gets over and you are safe enough. “God helps those who help themselves” likewise nobody can secure your privacy unless and until you yourself not willing to.
 
Here I have listed some useful tips to make your password strength secure and easier to remember:
  1. Use a combination of lowercase, uppercase, numbers, and special characters of 8 characters long or more like s9%w^8@t$i
  2. Use short passphrases with special characters separating to make it difficult for crackers and could be easily remembered like cry%like@me (cry like me)
  3. Avoid using the same combination of passwords for different websites
  4. If it is difficult for you to remember different passwords for different websites and accounts than try using Password manager applications like RoboForm, 1Password, LastPass.
STAY SECURE, STAY SAFE!

Friday, 17 January 2014

How to Give a Professional Look to your Desktop ?

Hi Guys !

Today we'll learn How to make your desktop attaractive and how to convert your dull windows xp & 7 into a professional Look ! Look at this picture its looking like super computer or US Army server ! and its Just normal windows 7 OS, Which is Modified desktop using RainMeter :)


Wokay, Lets Start !
1st of all you need to install Rainmeter on your desktop you can download rainmeter here
After downloading Rainmeter you need to download Skin of rainmeter.

Some Good RainMeter skins :
1-  Omnimo 5.0



Download here:

2- Jarvis (iRon Man Skin)

Jarvis is a Iron main inspired rainmeter skin, you can convert into hackers theme using new widgets and changing background image,Jarvis skin's centrel interface is damn cool.


Download here:

3- Electric Space:

 
Download here:

And many more:  Download here:

How to Install it ?

Go to your downloaded Skin right click on file and click on "install RainMeter skin"

 


 You Can add or remove widgets by right click on Desktop for example see the picture Given below!


Hope you enjoy this Post ! Please comment and share posts if you like :)