There are two types of Web application attacks: automated and manual.
Automated attacks can be used to exploit a Web application using automated
Web application attack tools such as wget, curl, blackwidow and teleport pro.
Using these automated tools, crawling and attacks can be done shortly.
This type of attack can be avoided by setting “honey traps” using HTTP Module
(used in pre/post-processing of requests). The attacker can be put into an infinite
loop using defence trick once it is trapped.
To launch manual attacks, hackers must conduct information gathering such as
address identification, port scanning, social engineering and vulnerability scanning
to find out vulnerabilities that can be exploited.
Resources:
http://www.cybersecurity.my/data/content_files/13/87.pdf?.diff=1176417313
Tuesday, 4 October 2011
Monday, 3 October 2011
SECURING APPLICATIONS FROM HACKER

MOST companies today use the Web to do business with customers, employees,
suppliers and others. This is because it is easier to maintain a Web-based
application than a Windows-based one. But how can we be sure that a Webbased application is secured? Or that data is being shared only by the authorised
users?
The Gartner Group estimates that 75 per cent of cyber attacks today are at the
application level. And about 97 per cent of over 300 Web sites audited are
vulnerable to Web application attacks. The US Federal Bureau of Investigation
also reveals that 95 per cent of the companies are hacked from Web applications,
and only five per cent of them are aware of the attacks
(http://conference.hackinthebox.org/hitbsecconf2005kl/materials/TT-ShreerajShah-Webhacking-Kungfu.pdf).
From the figures, we can deduce that most company Web sites are prone to cyber
attacks, and some of these companies are not aware that their Web applications
have vulnerabilities that can be exploited by hackers.
According to statistics published by the National ICT Security and Emergency
Response Centre, there have been significant increases in Web defacement
incidents. In the first quarter of this year, there were 256 Web defacements
involving both public and private Web sites, compared to the previous quarter
which recorded 42 of such incidents.
To have a secure Web application, developers of the application must know each
attribute such as query string, form, cookie, script, etc, because they are
vulnerable. These attributes can be exploited by an attacker and expose sensitive
company information if they are not used securely.
Thursday, 29 September 2011
Third Poll Analysis
Last week, we posted a poll question for our visitors to titled : "Which one of these scams have you heard before?"
From the result, 1 person chooses "Phisher Scams". Another person also chooses "Nigerian Scams". 3 person chooses "Lottery Scams". This has shown that most of our visitors were scammed because of greed in money. Users should be more careful when playing lottery online. We should be cautious of those lottery scams website.
From the result, 1 person chooses "Phisher Scams". Another person also chooses "Nigerian Scams". 3 person chooses "Lottery Scams". This has shown that most of our visitors were scammed because of greed in money. Users should be more careful when playing lottery online. We should be cautious of those lottery scams website.Wednesday, 28 September 2011
Top ten tips on avoiding cyber scams
People since time immemorial have fallen for scams of various kinds. Chalk it up to wishful thinking, dreaming, greed, what have you, but eventually, everyone finds themselves gullible. If that weren’t the case, life would lose some of its luster. We love to play act; we love to be fooled; and, we love to fool others as long as it’s all in good fun. Unfortunately, there are malicious people–cyber criminals and scam artists–who love to take advantage of those traits for their own gain and our (usually financial) loss.
Here are the top ten tips, courtesy of OnGuardOnline.gov for avoiding online scams:- Don’t send money to someone you don’t know.
- Don’t respond to messaes that ask for your personal or financial information.
- Don’t play a foreign lottery.
- Keep in mind that wiring money is like sending cash: once it’s gone, you can’t get it back.
- Don’t agree to deposit a check from someone you don’t know and then wire money back.
- Read your bills and monthly statements regularly - on paper and online.
- In the wake of a natural disaster or another crisis, give to established charities rather than one that seems to have sprung up overnight.
Resource:
http://onguardonline.gov/
http://www.bbb.org/us/article/top-ten-cyber-monday-tips-for-staying-safe-when-shopping-online-23416
Sunday, 25 September 2011
How do scammer target you
There are many forms of scam all around us;
In our everyday life, watch out for :
1. Unsolicited offers that are promoted through email, SMS (short message service) or MMS (multimedia message service). These offers often come from unknown contacts that have never been in contact with you before.
2. Offers of unlikely promises, like the certainty of winning lotteries, wealth, or lose weight.
3. Emails using a lot of capital letters, bad grammars, or unusual subject headings.
4. Work-at-home schemes offering easy ways to earn a big amount of money.
5. Incredible health cures that claim to cure difficult-to-cure conditions and illnesses
6. E-mails from "legitimate" companies asking for account details (usually providing a phising link)
7. Lottery, prizes, and other wins, asking you to send money or personal details to claim your winnings
8. Modem jacking -- make sure websites, especially adult sites don not download internet diallers, which will cost us money in our phone bills.
Source :
http://www.scamwatch.gov.au/content/index.phtml/itemId/693900
In our everyday life, watch out for :
1. Unsolicited offers that are promoted through email, SMS (short message service) or MMS (multimedia message service). These offers often come from unknown contacts that have never been in contact with you before.
2. Offers of unlikely promises, like the certainty of winning lotteries, wealth, or lose weight.
3. Emails using a lot of capital letters, bad grammars, or unusual subject headings.
4. Work-at-home schemes offering easy ways to earn a big amount of money.
5. Incredible health cures that claim to cure difficult-to-cure conditions and illnesses
6. E-mails from "legitimate" companies asking for account details (usually providing a phising link)
7. Lottery, prizes, and other wins, asking you to send money or personal details to claim your winnings
8. Modem jacking -- make sure websites, especially adult sites don not download internet diallers, which will cost us money in our phone bills.
Source :
http://www.scamwatch.gov.au/content/index.phtml/itemId/693900
Labels:
cyber scam,
internet fraud,
tips
Thursday, 22 September 2011
Podcast #3 : Poll Analysis 2 (Bahasa Malaysia)
Salam sejahtera semua nama saya Thanaraj dari blog e-cyber-aware. Minggu lepas kami telah menyediakan sebuah soalan untuk para pengikut kami, menyatakan bahawa macam mana anda hendak memastikan bahawa anda tidak menjatuhi dalam sebuah perangkap semasa anda membeli barang dari laman sesawang.
Hello all! my name is Thanaraj from the blog e-cyber aware. Last week we have prepared a question to the followers of our eCyber-aware blog, asking The way to ensure that you are not falling in a trap when you buy the merchandises online. From the results obtained we knew that our followers choose an answer of "inquire about refund and warranties on all items".Which rank number 1 by fulfilling 50% percentage of the chart. This shows that the followers fear the quality of the goods in terms of mendaoat damaged goods.
The second option, the followers of our blog is the want to, "Ensure that the website is safe when you send your credit card number electronically, and this option has satisfied 33% percent of the chart.
Next, The third option of our blog followers to be careful when replying to this Super deals show that the followers of our blog is very alert to scams scammers will trick trickswebsite.
The final choice is "investigating other sites related to the number of companies satisfied 0% percentage of the chart by them.
Daripada keputusan yang diperolehi kami dapat tahu bahawa ramai memilih! iaitu daripada 50% daripada pengikut kami memilih jawapan tentang "bayaran balaik dan jaminan ke atas semua barang. Ini menunjukkan bahawa para pengikut kita takut akan kualiti barang iaitu dari segi mendaoat barang yang rosak atau pecah.
Pilihan kedua, para pengikut blog kita pula ialah ingin, "Memastikan bahawa laman web itu selamat apabila anda menghantar nombor kad kredit anda secara electronik dan pilihan ini telah memuaskan 33% peratus sahaja.
Seterusnya, pilihan ketiga para pengikut blog kita berhati hati apabila membalas kepada tawaran istimewah ini menunjukan bahawa para pengikut blog kita amat awas akan trik trik penipuan penipu laman sesawang.
Pilihan akhir merupakan "menyiasat laman web lain yang berkaitan dengan jumlah syarikat yang dipuaskan oleh mereka.Jawapan ini telah memuaskan 0%.
Hello all! my name is Thanaraj from the blog e-cyber aware. Last week we have prepared a question to the followers of our eCyber-aware blog, asking The way to ensure that you are not falling in a trap when you buy the merchandises online. From the results obtained we knew that our followers choose an answer of "inquire about refund and warranties on all items".Which rank number 1 by fulfilling 50% percentage of the chart. This shows that the followers fear the quality of the goods in terms of mendaoat damaged goods.
The second option, the followers of our blog is the want to, "Ensure that the website is safe when you send your credit card number electronically, and this option has satisfied 33% percent of the chart.
Next, The third option of our blog followers to be careful when replying to this Super deals show that the followers of our blog is very alert to scams scammers will trick trickswebsite.
The final choice is "investigating other sites related to the number of companies satisfied 0% percentage of the chart by them.
Wednesday, 21 September 2011
Podcast #2 : Phishing - Technique Used In Cyber Scam (Bahasa Malaysia)
Hello everyone, today i will be discussing one of the technique that is used by scammer to scam internet user which is phishing. Phishing is the act of sending an e-mail to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft. The e-mail directs the user to visit a Website where they are asked to update personal information, such as passwords and credit card, social security, and bank account numbers, that the legitimate organization already has. The Web site, however, is bogus and set up only to steal the user's information.
Phishing, also referred to as brand spoofing or carding, is a variation on "fishing," the idea being that bait is thrown out with the hopes that while most will ignore the bait, some will be tempted into biting.
Phishing, also referred to as brand spoofing or carding, is a variation on "fishing," the idea being that bait is thrown out with the hopes that while most will ignore the bait, some will be tempted into biting.
Hello rakan-rakan sekalian, hari ini saya akan berbincang tentang perlakuan "phishing" iaitu satu teknik yang digunakan oleh penipu siber untuk mendapatkan maklumat pengguna internet. "Phishing" berlaku melalui tindakan menghantar e-mel kepada pengguna secara palsu yang mendakwa untuk menjadi perusahaan yang sah yang ditubuhkan dalam usaha untuk penipuan pengguna ke dalam menyerahkan maklumat peribadi yang akan digunakan untuk kecurian identiti. E-mel yang mengarahkan pengguna untuk melawat laman web di mana mereka diminta untuk mengemaskini maklumat peribadi, seperti kata laluan dan kad kredit, keselamatan sosial, dan nombor akaun bank, bahawa organisasi yang sah sudah mempunyainya. Laman web, bagaimanapun, adalah palsu dan hanya untuk mencuri maklumat pengguna.
"Phishing", juga dirujuk sebagai menipu jenama atau "carding", adalah perubahan daripada perkataan "memancing," idea yang berkaitan tentangnya ialah umpan yang tercampak keluar dengan harapan bahawa manakala kebanyakan akan mengabaikan umpan, ada yang akan tergoda ke dalam gigitan.
Subscribe to:
Posts (Atom)
