By Syed Akbar
Facts About Flame Virus
1. Flame virus uses keyloggers and screenshot to transmit data to the hacker.
2. It could create cyber catastrophe if it hits a large nation like India.
3. It is the king of espionage and steals all the data from computer
including the songs played, words exchanged in chat, and the pixs
stored in hard disk.
4. The virus can steal crucial nuclear, space, scientific and
government information within no time and passes it on to the hacker.
5. International Telecommunications Union issues the “most serious
warning” to all nations
6. Most complex, sophisticated and complete data spy tool, 20 times
more powerful than the existing one
7. The virus is master-controlled by 80 remotely accessed computers
maintained by the virus creators
=========
A major computer virus is now threatening the cyber
security and crucial installations of several nations. Called the
Flame Virus, it could spy everything one does on a computer, sitting
within the confines of office or home, including the film songs one
listens to, the crucial data stored on the hard disk and the chat
between friends.
The virus is also capable of stealing vital information from
governments and scientific institutions, throwing up a major cyber
security challenge. It is the most complex of all computer viruses
created so far and thus quite difficult to decode and fight back. The
virus has been hailed as the king of espionage with capabilities to
secretly record conversations.
Flame virus has affected hundreds of computers within a day of its
discovery, in the Arab world, with the prime target being Iran.
Incidentally, Iran was the target of similar attack two years ago,
when its nuclear system was hacked.
According to cyber security expert, MH Noble, the Flame virus uses
keyloggers and screenshots, which means everything done on a computer
is transmitted to the hacker.
If the virus hits India, it could result in a major cyber catastrophe.
India is fast joining exclusive clubs of nations in nuclear
technology, information and communication technology and space
technology and remote sensing. However, Flame virus is not of
immediate concern for Indian Intelligence, nuclear and scientific
bodies as the security system is foolproof.
Cyber security experts allege that Flame virus could be the handiwork of some
software security solutions company, which want to market its new
anti-virus product. The prime target seems to be developing countries,
where internet security is often
compromised. There are however, no reports of the flame virus infection so
far in India. Luckily, India has escaped similar major attacks in the past.
It is the third cyber attack weapon targeting systems in the Middle
East to be exposed in recent years. Iran has alleged that the West and
Israel are orchestrating a secret war of sabotage using yber warfare
and targeted assassinations of its
scientists as part of the dispute over its nuclear programme.
Stuxnet attacked Iran's nuclear programme in 2010, while a related
programme, Duqu, named after the Star Wars villain, stole data.
Showing posts with label Internet Security. Show all posts
Showing posts with label Internet Security. Show all posts
Wednesday, 30 May 2012
Monday, 16 April 2012
Beware of phising: How to detect internet fraudsters?
By Syed Akbar
"Dear customer, there was a major crash in our computer system. We have lost some of the vital data. Could you click on the link below to send us the details of your credit card like its number, expiry date, credit limit and password so that we could update our data after restoration".
"Congratulations! You have won $ 100,000 in a draw of lots of email addresses collected at random from the web. To claim the money, do fill up the following personal details and send us at the email link given below" .
"Dear account-holder, we suspect that an unauthorised transaction has been carried out on your savings bank account. To make sure that your bank account is not manipulated, please click the link below and confirm your personal identity."
If you receive these types of messages to your email address or in a pop-up window while you are surfing the internet, just ignore them. Do not reply to such messages or give personal details, because you are being phished by clever cyber cheats.
Instances of phishing or "password harvesting" have been on the rise in Hyderabad with the city, thanks to its
numerous software firms, attracting the attention of computer hackers and cyber cheats from around the world.
A couple of days ago, M Ramesh, an executive in an advertising firm, received a Yahoo message from his "banker" saying that they need the "existing" password of his credit card as the bank's main server has been hacked."I was about to fill up the details when my colleague suggested that I cross-check with the banker on telephone or in person. When I rang up the call centre of the bank, I realised that the message was fake. I believed the message because it resembled other messages that I receive from my banker regularly," Ramesh points out.
What actually the cyber cheats or "phishers" do with the data they receive from unsuspecting net-users? There have been thousands of instances of creation of fake credit cards and siphoning of money through ATMs using the password provided by the unsuspecting cardholder. Moreover, personal details will quite often help phishers to do on-line business transactions to purchase valuables.
Phishers generally target customers of banks and financial institutions that have a large turnout. In the last couple of months, customers of nearly all major banks in Hyderabad have been targeted by phishers. Besides banking customers, those who use amazon.com, AOL, BestBuy, eBay, MSN, PayPal and Yahoo have also been the target. According to anti-phishers, as many as 10,000 phishing mails are sent to users in Hyderabad.The Crimes Investigation Department of the State police lists "phising" as one of the cyber crimes attacking penal action."The number of phishing attacks, and the associated costs, has increased 10 fold as compared to last year and is on a continuous rise," says MH Nobel of Zoom Technologies.
=====
How to identify phishing messages
=====
1. There will be no personal greetings in the message. Your name will be missing because the sender does not know who you are.
2. Notice whether there is an IP address in the link. If you click on this, it will take you to the fake bank/institution instead of the genuine one.
3. It is better if you do not use the net to provide personal details, particularly passwords or your mother's maiden name, as not all phishing attacks require a fake website. This can be done even through a genuine website. If the website is not fake, cyber cheats give a telephone No. (supposedly of a bank) and when the unsuspecting person dials the telephone number, he or she is asked to dial the card number and then the password. Both the card number and the password are recorded through voice over IP.
4. In case of suspicion, call the banker or make a personal visit to verify the authenticity of the email message.
5. Install anti-phishing software in your computer to detect phishing attempts.
6. Lodge a police complaint, if necessary.
7. Check whether the URL starts with https:// or http://. If you're using IE, look for the lock symbol in the right of the status bar and double-click it to check the validity of the digital certificate.
8. Check your bank accounts regularly to ensure that listed transactions are really carried out by you.
"Dear customer, there was a major crash in our computer system. We have lost some of the vital data. Could you click on the link below to send us the details of your credit card like its number, expiry date, credit limit and password so that we could update our data after restoration".
"Congratulations! You have won $ 100,000 in a draw of lots of email addresses collected at random from the web. To claim the money, do fill up the following personal details and send us at the email link given below" .
"Dear account-holder, we suspect that an unauthorised transaction has been carried out on your savings bank account. To make sure that your bank account is not manipulated, please click the link below and confirm your personal identity."
If you receive these types of messages to your email address or in a pop-up window while you are surfing the internet, just ignore them. Do not reply to such messages or give personal details, because you are being phished by clever cyber cheats.
Instances of phishing or "password harvesting" have been on the rise in Hyderabad with the city, thanks to its
numerous software firms, attracting the attention of computer hackers and cyber cheats from around the world.
A couple of days ago, M Ramesh, an executive in an advertising firm, received a Yahoo message from his "banker" saying that they need the "existing" password of his credit card as the bank's main server has been hacked."I was about to fill up the details when my colleague suggested that I cross-check with the banker on telephone or in person. When I rang up the call centre of the bank, I realised that the message was fake. I believed the message because it resembled other messages that I receive from my banker regularly," Ramesh points out.
What actually the cyber cheats or "phishers" do with the data they receive from unsuspecting net-users? There have been thousands of instances of creation of fake credit cards and siphoning of money through ATMs using the password provided by the unsuspecting cardholder. Moreover, personal details will quite often help phishers to do on-line business transactions to purchase valuables.
Phishers generally target customers of banks and financial institutions that have a large turnout. In the last couple of months, customers of nearly all major banks in Hyderabad have been targeted by phishers. Besides banking customers, those who use amazon.com, AOL, BestBuy, eBay, MSN, PayPal and Yahoo have also been the target. According to anti-phishers, as many as 10,000 phishing mails are sent to users in Hyderabad.The Crimes Investigation Department of the State police lists "phising" as one of the cyber crimes attacking penal action."The number of phishing attacks, and the associated costs, has increased 10 fold as compared to last year and is on a continuous rise," says MH Nobel of Zoom Technologies.
=====
How to identify phishing messages
=====
1. There will be no personal greetings in the message. Your name will be missing because the sender does not know who you are.
2. Notice whether there is an IP address in the link. If you click on this, it will take you to the fake bank/institution instead of the genuine one.
3. It is better if you do not use the net to provide personal details, particularly passwords or your mother's maiden name, as not all phishing attacks require a fake website. This can be done even through a genuine website. If the website is not fake, cyber cheats give a telephone No. (supposedly of a bank) and when the unsuspecting person dials the telephone number, he or she is asked to dial the card number and then the password. Both the card number and the password are recorded through voice over IP.
4. In case of suspicion, call the banker or make a personal visit to verify the authenticity of the email message.
5. Install anti-phishing software in your computer to detect phishing attempts.
6. Lodge a police complaint, if necessary.
7. Check whether the URL starts with https:// or http://. If you're using IE, look for the lock symbol in the right of the status bar and double-click it to check the validity of the digital certificate.
8. Check your bank accounts regularly to ensure that listed transactions are really carried out by you.
Wednesday, 16 March 2011
Mobile spoofing fast catching up in Hyderabad city
2011
By Syed Akbar
Strange it may sound, but one can create mistrust between two persons by sending hate sms to one of them through the other's mobile, without actually touching his or her mobile phone. All one has to do is to login to a certain website, register and start sending sms to any person in India faking someone else's mobile number.
Mobile spoofing or sending sms to persons using a third person's mobile number, is fast catching up among youngsters in the city, causing concern to security agencies. Mobile spoofing is a new security breach to hit the country, after internet protocol (IP) or caller ID faking. Though mobile or sms spoofing has been there for quite some time, it is of late catching up with students and youths.
Ethical hackers warn that many youngsters think they are playing a prank, but this innocent prank may turn out to be a major security risk for the country, if some anti-social elements get involved in mobile spoofing.
According to cyber crime experts, the person receiving the fake sms will not know that the message is spoofed or fake. There's no technical way of finding out from where the sms has originated. The websites facilitating mobile spoofing exploit certain security vulnerabilities to obtain access to sms-internet tunnel by creating a malicious code or Trojan.
Even the mobile service provider does not know that the network is being misused. The software allows one to send sms from any sender ID to any mobile and one can fake the sender ID to any phone number.
Says additional SP (cyber crimes) U Rammohan, faking sms can pose security risk if some terrorist or anti-social groups are involved in it. “We can trace the sender of fake smses through the IP address, but it is quite a challenging task. If the proxy IP address is used to send sms, it becomes difficult, though not impossible, to reach the sender,” he points out.
Mobile spoofing websites offer both free and paid sms spoofing service. Sites offeringfree service limit the number of fake sms between 10 and 30. But those charging a fee provide unlimited sms facility. The mobile spoofing websites quite popular among youngsters playing prank with their friends include xxsidxx.co.cc, fakemsg.com,fakemytext.com, www.sneaksms.com and sms.fake.com.
Ethical hackers blame it on mobile companies for the continuation of the menace. Cell phone companies need to set up advanced authentication mechanism. SMS servers are victims of huge vulnerability exploits since they are not properly secured and widely exposed, observes networking security engineer MM Ganga Raju.
“The only way of detecting and blocking spoofed messages is to screen incoming mobile originated messages to verify that the sender is a valid subscriber and that the message is coming from a valid and correct location,” he adds.
There's also a dedicated software "sms spoof" which is freely available in the internet.Once it is downloaded in the mobile phone, one can send sms using a third person's number.
"You can send sms from the website to a woman using her husband's number informing her to hand over money to a person he deputes. Since the woman gets sms from her husband's mobile number, chances are she may hand over money or jewellery to an impostor, if she fails to cross-check the message with her husband," says ethical hacker MV Rama Rao.
By Syed Akbar
Strange it may sound, but one can create mistrust between two persons by sending hate sms to one of them through the other's mobile, without actually touching his or her mobile phone. All one has to do is to login to a certain website, register and start sending sms to any person in India faking someone else's mobile number.
Mobile spoofing or sending sms to persons using a third person's mobile number, is fast catching up among youngsters in the city, causing concern to security agencies. Mobile spoofing is a new security breach to hit the country, after internet protocol (IP) or caller ID faking. Though mobile or sms spoofing has been there for quite some time, it is of late catching up with students and youths.
Ethical hackers warn that many youngsters think they are playing a prank, but this innocent prank may turn out to be a major security risk for the country, if some anti-social elements get involved in mobile spoofing.
According to cyber crime experts, the person receiving the fake sms will not know that the message is spoofed or fake. There's no technical way of finding out from where the sms has originated. The websites facilitating mobile spoofing exploit certain security vulnerabilities to obtain access to sms-internet tunnel by creating a malicious code or Trojan.
Even the mobile service provider does not know that the network is being misused. The software allows one to send sms from any sender ID to any mobile and one can fake the sender ID to any phone number.
Says additional SP (cyber crimes) U Rammohan, faking sms can pose security risk if some terrorist or anti-social groups are involved in it. “We can trace the sender of fake smses through the IP address, but it is quite a challenging task. If the proxy IP address is used to send sms, it becomes difficult, though not impossible, to reach the sender,” he points out.
Mobile spoofing websites offer both free and paid sms spoofing service. Sites offeringfree service limit the number of fake sms between 10 and 30. But those charging a fee provide unlimited sms facility. The mobile spoofing websites quite popular among youngsters playing prank with their friends include xxsidxx.co.cc, fakemsg.com,fakemytext.com, www.sneaksms.com and sms.fake.com.
Ethical hackers blame it on mobile companies for the continuation of the menace. Cell phone companies need to set up advanced authentication mechanism. SMS servers are victims of huge vulnerability exploits since they are not properly secured and widely exposed, observes networking security engineer MM Ganga Raju.
“The only way of detecting and blocking spoofed messages is to screen incoming mobile originated messages to verify that the sender is a valid subscriber and that the message is coming from a valid and correct location,” he adds.
There's also a dedicated software "sms spoof" which is freely available in the internet.Once it is downloaded in the mobile phone, one can send sms using a third person's number.
"You can send sms from the website to a woman using her husband's number informing her to hand over money to a person he deputes. Since the woman gets sms from her husband's mobile number, chances are she may hand over money or jewellery to an impostor, if she fails to cross-check the message with her husband," says ethical hacker MV Rama Rao.
Monday, 31 July 2006
Beware of phishing: Tips to keep away internet scams

July 31, 2006
By Syed Akbar
Hyderabad: "Dear customer, there was a major crash in our computer system. We have lost some of the vital data. Could you click on the link below to send us the details of your credit card like its number, expiry date, credit limit and
password so that we could update our data after restoration".
"Congratulations! You have won $ 100,000 in a draw of lots of email addresses
collected at random from the web. To claim the money, do fill up the following personal details and send us at the email link given below". "Dear account-holder, we suspect that an unauthorised transaction has been carried out on your savings bank account. To make sure that your bank account is not manipulated, please click the link below and confirm your personal identity."
If you receive these types of messages to your email address or in a pop-up window
while you are surfing the internet, just ignore them. Do not reply to such messages or give personal details, because you are being phished by clever cyber cheats.
Instances of phishing or "password harvesting" have been on the rise in Hyderabad
with the city, thanks to its numerous software firms, attracting the attention of computer hackers and cyber cheats from around the world.
A couple of days ago, M Ramesh, an executive in an advertising firm, received a
Yahoo message from his "banker" saying that they need the "existing" password of his credit card as the bank's main server has been hacked.
"I was about to fill up the details when my colleague suggested that I cross-check
with the banker on telephone or in person. When I rang up the call centre of the bank, I realised that the message was fake. I believed the message because it resembled other messages that I receive from my banker regularly," Ramesh
points out.
What actually the cyber cheats or "phishers" do with the data they receive from
unsuspecting net-users? There have been thousands of instances of creation of fake credit cards and siphoning of money through ATMs using the password provided by the unsuspecting cardholder. Moreover, personal details will quite often help phishers to do on-line business transactions to purchase valuables.
Phishers generally target customers of banks and financial institutions that have a
large turnout. In the last couple of months, customers of nearly all major banks in Hyderabad have been targeted by phishers. Besides banking customers, those who use amazon.com, AOL, BestBuy, eBay, MSN, PayPal and Yahoo have also been the target. According to anti-phishers, as many as 10,000 phishing mails are sent to users in Hyderabad.
The Crimes Investigation Department of the State police lists "phising" as one of
the cyber crimes attacking penal action. "The number of phishing attacks, and the associated costs, has increased 10 fold as compared to last year and is on a continuous rise," says MH Nobel of Zoom Technologies.
=====
How to identify phishing messages
=====
1. There will be no personal greetings in the message. Your name will be missing
because the sender does not
know who you are.
2. Notice whether there is an IP address in the link. If you click on this, it will
take you to the fake bank/institution
instead of the genuine one.
3. It is better if you do not use the net to provide personal details, particularly
passwords or your mother's maiden
name, as not all phishing attacks require a fake website. This can be done even
through a genuine website. If the
website is not fake, cyber cheats give a telephone No. (supposedly of a bank) and
when the unsuspecting person
dials the telephone number, he or she is asked to dial the card number and then the
password. Both the card
number and the password are recorded through voice over IP.
4. In case of suspicion, call the banker or make a personal visit to verify the
authenticity of the email message.
5. Install anti-phishing software in your computer to detect phishing attempts.
6. Lodge a police complaint, if necessary.
7. Check whether the URL starts with https:// or http://. If you're using IE, look
for the lock symbol in the right of
the status bar and double-click it to check the validity of the digital certificate.
8. Check your bank accounts regularly to ensure that listed transactions are really
carried out by you.
Tuesday, 25 July 2006
Da Vinci Code: It's Internet Virus On The Prowl

July 25, 2006
By Syed Akbar
Hyderabad: It’s been confirmed — The Da Vinci Code is bad for you. The virus, that is. A computer bug bearing the controversial film’s name has affected dozens of mobile phones and laptops in the city.
The virus, which spreads via wireless Bluetooth technology, causes a message to pop
up on Bluetooth devices: ‘Receive message via Bluetooth from Da Vinci Code?’ Once a
curious mobile phone user accepts the message, the virus enters the system and
destroys the phone’s data.
A picture depicting an eye and a cross appears on the desktop and phone’s gallery.
Mridul Sharma (32), an operations manager at an event management firm, received the
virus during a corporate presentation a few days ago. “The Da Vinci Code name
actually excited me. I assumed the file was either an MMS clipping or a still and
accepted it.
My entire system collapsed and data was deleted. I had just bought my Nokia N91
handset worth Rs 31,000 and had to pay Rs 1,500 to format my mobile hard disk and
reload the software,” said Sharma.
"I received the virus on my laptop and phone. Apparently my Bluetooth device was
active. The technician who repaired my phone told me this was a common virus, which
had simply been renamed The Da Vinci Code to attract the users,” said 35-year-old
Sanjay Menon.
Abhishek Datta, a software expert, said, “Once a phone is affected, formatting is
the only option. You cannot retrieve your data.”
Seems that "Da Vinci Code" really a good naming for mobile viruses for now as this
movie quite prestigious in "Cinema Heat"!
Will we have "Mutant-X", "Mission Impossible 3" etc as mobile phone viruses in the
future? Let see how creative are those nasty creator then!
Safeguards
1. An anti-virus with REAL TIME PROTECTION will provide you with tight security.
2. Turn your bluetooth detection mode in "Hidden" or "Invisible" mode or just switch
it off if it's not necessary.
3. Never try to install an unknown file and proceed to the installation step.
4. Backup your data from time to time just in case...
5. Please beware of any MMS that come with *.SIS file attachment. Delete it if it's
quite suspicious.
That's so simple to keep your phone infected by this similar mobile phone virus.
Subscribe to:
Posts (Atom)
Mother's Care
Minnu The Cat & Her Kittens Brownie, Goldie & Blackie
Someone with Nature
Syed Akbar in an island in river Godavari with Papikonda hills in the background
Recognition by World Vegetable Centre
Under the shade of Baobab tree
At Agha Khan Akademi in Kenya
Gateway to the Southern Hemisphere
Convention on Biodiversity
Syed Akbar at the 11th Conference of Parties to the United Nations Convention on Biological Diversity
