Skip to main content

Posts

Showing posts matching the search for Attack

Attack Example - ClickJacking+Spoofing - UI Redress - Trusted User Interface

ClickJacking and Spoofing Attack Example - Trusted User Interface attack. It used to be that the most common operating system and browser being targeted for this kind of attack is Windows and IE. The underlying reason was that Windows has more users and Internet Explorer was basically File Explorer having a different user interface. Today, the attack surface is wider and much more complicated to notice. The screenshot posted here is a combination of a User Interface (UI) spoofing from a ClickJack.

Threats to Internet Safety

There are many Threats to Internet Safety for Filipinos and our government have long started passing laws that would enable us to counter the effects, prevent it from happening, and be made aware of its consequence. Let's start by understanding the official and legal definitions of these threats. Among them are: Cyberbullying, Online Scam, Online Libel, Identity Theft, and Photo & Video Voyeurism

Attack Example - Phishing - SMS Based - Smishing

What exactly is Phishing? It smells fishy, sounds like fishing, and it is exactly fishing. Knowing how social Filipinos are, almost everyone doesn't like being late in knowing who's an item in the office or who likes who, or what successful neighbors are doing to be successful. And so, we non-chalantly fish for information about it. That is exactly the core function of Phishing. It is to gather Personally Identifiable Information (PII) or information which can be used to identify individuals.

How To Detect Phishing - The Very Important Basic

You've probably already read us saying we prefer browsers over custom apps. And there's a really good reason for it. And today we'll dive into one those reason. Less than twelve hours of the time that this post is written, waves of articles online warned users that there is a widespread Phishing scam targeting Gmail users. The reality is that it's not only Gmail that is subject to this attack. All emails are. But for the time being, we'll use Gmail as a sample to illustrate a core problem. Yes, you may have guessed it already. People's mindset, misunderstanding technology and its wrong use.

One of the Many Reasons Why Encryption is Important

Many of us don't know the standards used in implementing the complex communication technologies that enables us today. Many of us do not know or even care about encryption or its use. We may not even know about the groups or companies that fight or go against governments to ensure that people have their right to privacy. Some will say that what you don't know can't hurt you but that is more often false. Just because you don't know gravity exists doesn't make gravity harmless. Just because you don't know fire burns mean you won't be burnt. Just because you don't know that effects of a hacking vulnerability doesn't mean you won't be hacked or be affected by it.

Internet Safety Myths

There are many myths surrounding Internet Safety and we'll be talking about them as a series of articles to dispel it. All in hopes to help bring in better internet usage habits for every Filipino. First an overview and later on, a separate article for each of the myths.

Selfies and Vanity - Social Engineering Data Collection - Prefetching Biometric Data

How many of you would like to know what your age is according to a computer? How many of you would like to know who your celebrity look-a-like is? Did you try one of those web app? How about the mobile app? Wow! you look like that actor?! Congratulations! Wait, we have ten other friends who look like that actor? What a boring world if thousands of you actually look-a-alike one famous actor! Seriously though, it is just sad how guillible people are. It didn't even actually try to properly score similarity factor. It is sad that people just gave some other people one of the most identifiable factor about them. And the most common excuse, it is just harmless fun. Fun, Vanity - among the many of our frailties that threat actors (hackers, scammers) can exploit or use against us. Yes, our search for fun and validation can be easily used against us. Biometric authentication is gaining ground in everyday use. The commonplace fingerprint authentication is ... well, commonplace. It's n...

Security Reminder: Uninstall Flash.

What exactly is Flash and why do I need to uninstall it? Flash has in the past years provided a lot of visual treat that wasn't entirely possible with other web tools or technology. For web developers back then using Flash also meant that they are at the top of their game. Unfortunately, as its use and adoption became very common, it also meant that it's a very good attack surface for malicious software or malware. Indeed it was and still is since it also became web page's video player of choice. It became so because it was a commonly installed plugin in most computers and the competing technologies weren't able to match its ubiquity or "common-ness."

Scam Alert - Credit Card - Methodology is Part of Social Engineering

Just the other day, we posted Attack Example - Phishing - SMS Based - Smishing and yesterday someone in Cagayan de Oro using facebook alerted people of a Scam Modus Operandi (M.O.) Do we think it's a scam? Yes it is.

200M Plus iOS Accounts in Possible Danger - Back Up Now

Last March 21, 2017 - Turkish Crime Family on twitter issued a warning that 200 Million iCloud accounts will be factory reset on April 7, 2017 . By 4:02am of March 22, it reported on twitter that the number of accounts has grown to 627M. They are currently improving their infrastructure to be able to effectively cause the maximum damage it can do. The amount of 75,000 USD was initially reported to be the price for them to back-off or cancel their attack but has since refuted those reports.

Vulnerability Alert - Smart TV - Spy On You

If you are one of those Smart TV owners, you may have heard already that someone can hack your TV and use it to spy on you. Haven't heard of it before?! Now you have and the only redeeming thing about the previous hack is that it required hackers physical access to your Smart TV. That poses an entirely different problem together.