Tuesday, 30 December 2014

SECURITY CONCEPTS :- EBOOK FOR FREE

This is a free book about computer, network, technical, physical, information and cryptographic security. You can download it as a pdf file.
Description:-
I wrote this paper to try and examine the typical problems in computer security and related areas, and attempt to extract from them principles for defending systems. To this end I attempt to synthesize various fields of knowledge, including computer security, network security, cryptology, and intelligence. I also attempt to extract the principles and implicit assumptions behind cryptography and the protection of classified information, as obtained through reverse-engineering (that is, informed speculation based on existing regulations and stuff I read in books), where they are relevant to technological security.
         Table of Contents
  1. Metadata
  2. Security Properties
  3. Security Models
  4. Security Concepts
  5. Economics of Security
  6. Adversary Modeling
  7. Threat Modeling
  8. Physical Security
  9. Hardware Security
  10. Distributed Systems
  11. Identification and Authentication
  12. Authorization – Access Control
  13. Secure System Administration
  14. Logging
  15. Reporting
  16. Abuse Detection
  17. Abuse Response
  18. Forensics
  19. Privacy
  20. Intrusion Response
  21. Network Security
  22. Email Security
  23. Web Security
  24. Software Security
  25. Human Factors and Usability
  26. Attack PatternsTrust and Personnel Security
  27. Cryptography
  28. Randomness and Unpredictability
  29. Cryptanalysis
  30. Lateral Thinking
  31. Information and Intelligence
  32. Conflict and Combat
  33. Security Principles
  34. Common Arguments
  35. Editorials, Predictions, Polemics, and Personal Opinions
Book Details :-
Author(s): Theodore Parker
Format(s): PDF, HTML
File size: 1.83 MB
Number of pages: 246
Download Link-:   Security_Concepts

New ‘Fakedebuggerd’ vulnerability in Android 4.x OS lets hackers root access


New ‘Fakedebuggerd’ vulnerability in all versions of Android OS upto lollipop, lets hackers root access Security Researchers at Chinese antivirus company 360 have found out a new vulnerability in the Google’s Android operating system which is named as ‘Fakedebuggerd.’ This new vulnerability allows potential hackers to gain root access to install files and escalate privileges on the smartphones and tablets running on Android OS and run malicious codes at will.

As per the 360 researchers, the Fakedebuggerd vulnerability enables a potential attacker to access an
area that can be accessed only with system or root permissions. The vulnerability uses two known
Android 4.x Privilege Escalation (PE) exploits, ‘FramaRoot’ and ‘TowelRoot’, to run code under root
privileges and to install a root toolkit on the device. This allows the potential hacker to hide the code both from the Android user as well as the security solutions running on the devices. As such the hacker may inject any malicious App without users notice.



Fakedebuggerd targets Android 4.x devices

The vulnerability is of high risk as it gives serious privilege escalation to the handlers of malware and this is the first time the researchers have found out any Privilege Escalation vulnerabilities in Android 4.x. As said above, uses two exploits, TowelRoot’ and ‘FramaRoot’ together which means it has a higher rate of infection as well as higher chances of hiding itself from the AV engines aboard the users device. The Towelroot exploit is based on the futex() syscall vulnerability (CVE20143153).


This Linux vulnerability was discovered five months ago by Comex and affects almost all Android devices prior to Android 5.0 lollipop. The other exploit, Framaroot, is basically a rooting tool and based on several exploits for most Samsung, LG, Huawei, Asus and ZTE devices and more. The exploits which form the Framaroot are named after heroes of the popular JRR Tolkein triolgoy “The Lord of the Rings,” like Gandalf, Boromir, Pippin, Legolas, Sam, Frodo, Aragorn and Gimli. Almost all Android smartphones which are made by the above companies are able to execute Framaroot quite easily which makes Fakedebggerd very powerful vector.



Modus Operandi Once the Fakedebuggerd vulnerability is exploited and the root toolkit is deployed on the infected device, malicious code to collects sensitive data like unique identifiers, device versions and network connectivity data. Additionally it will install unnecessary Apps like Flashlight and Calender without the users permission.
The Fakedbuggerd is quite aggressive in its intent and uses extreme measures to keep them installed.
As of now no security solution or antivirus can detect this malware, therefore precaution is the best remedy against getting infected through this vulnerability. Stay away from thirdparty and unverified APKs and use the official Google Play Apps for download. 
Even if you have to download a APK, stick with trusted and wellreviewed app developers. Beware fake advertisements (malvertisements) and phishing links on all forms of communication –SMS, email and social networks.



Even if these Apps are removed by user using root privileges, the Fakedbuggerd reinstalls them automatically using the PE exploit. And as said above due the malware’s perfect hiding technique, simply deleting the suspicious apps wont work in this case. The Fakedbuggerd malware is a serious threat because of its ability to access root privileges and run malware laden codes on infected devices. In today’s world of convergence when the critical and confidential enterprise data and mobile phones are interconnected, Fakebuggerd can cause havoc unseen before. 

The Gameover Trojan ‘Zeus’ program is back



Cyber criminals are trying to create a new botnet based on what is likely a modification of Gameover Zeus, a sophisticated Trojan program whose command-and-control infrastructure was taken over by law enforcement agencies at the beginning of decemeber.


The Gameover Zeus malware is designed to steal log-in credentials, as well as personal and Financial information from users when they access banking and other popular websites.
According to the U.S. Federal Bureau of Investigation, which took part in the Gameover botnet takedown, the Trojan program infected more than a million computers globally and led to losses of over US$100 million.


Disrupting the original botnet required special techniques and the assistance of security vendors, because unlike most Trojan programs, which use a limited number of servers and domain names for command and control, Gameover had a peer-to-peer architecture that didn’t o4er a single point of failure and allowed infected computers to update each other.


The malware also had a backup mechanism that relied on a domain name generation algorithm (DGA) to ensure that computers can receive commands even when they got disconnected from the peer-to-peer network. Through this mechanism the malware generated random-looking domain names at certain time intervals and tried to access
them. Attackers were able to predict which domain names the bots will generate on a certain day, and could register one of those domains in advance to issue commands.


On Thursday, more than a month after the takedown, researchers from Malcovery Security spotted several email spam campaigns distributing a Trojan program that appears to be heavily based on the Gameover Zeus binary. The modification no longer relies on a peer-to-peer infrastructure and uses a DGA as the primary command-and-control mechanism.


“Malcovery analysts confirmed with the FBI and Dell SecureWorks that the original GameOver Zeus is still ‘locked down’,” the Malcovery researchers said Thursday in a blog post. “This new DGA list is not related to the original GameOver Zeus but bears a striking resemblance to the DGA utilized by that Trojan.”


In addition to the DGA similarity, the list of URLs and strings used by the new Trojan program to decide what sites to target matches the one used by the old Gameover botnet.
“This discovery indicates that the criminals responsible for GameOver’s distribution do not intend to give up on this botnet even after su4ering one of the most expansive botnet takeovers/takedowns in history,” the Malcovery researchers said.

Monday, 29 December 2014

HOW TO STOP PENDRIVES FROM GETTING UNWANTED VIRUS

Today, A big problem for windows user is to secure their data from viruses. Especially, in Pendrives, no one wants to keep their important data in pendrives because pendrives are portable devices and during sharing data it may get infected by virus like Shortcut virus, Autorun.inf , and new folder virus etc.
Some people recover their data by simply using Command prompt but some people think there is only option left and it is to format the flash drive.
well! if your pendrive is infected by any of these virus you can simply follow these step to get your hidden data back.
  • Open CMD (command prompt)
  • Open Flash drive in cmd ( if your drive is ‘G’ than enter ‘G:’ after c:\user\ press [ENTER] )
  • Now type following line and press enter:
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlStorageDevicePolicies] “WriteProtect”=dword:00000001
That’s it your USB is now sheltered
To TURN DEFENCE OFF
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlStorageDevicePolicies]
attrib -s -h /s /d
Now open your flash drive in windows you will see all your files . but wait ! is it enough ? No way! your flash drive is still not fully secure . Above command just shows all your files that are hidden by viruses. If you desire to protect your USB from getting unwanted files i.e. virus, worm, spy, Trojan etc than follow these steps. What I’m gonna tell you is that how to setup your registry to end a computer from saving files to your USB (It’ll block all of them) If you have windows 7 or windows 8 then you can immobilize the writing option to USB drives. This trick is very helpful if you have virus in your computer and desire to copy files from a USB Drive but don’t desire to transfer virus to the USB. Follow the given steps to disable the USB writing option:
Open notepad and copy and paste the following:
Windows Registry Editor Version 5.00
Now keep the file with the extension “.reg”.
Click on the file you presently saved. In the pop-up window chose YES and then OK.

Open notepad and copy and paste the following:
Windows Registry Editor Version 5.00
“WriteProtect”=dword:00000000
Now put aside the file with the extension “.reg”.
Click on the file you presently saved. In the pop-up window click YES and then OK.
That’s it your defense is now disabled.                                 

Sunday, 28 December 2014

Check who use your PC in your Absence . .

       CHECK WHO USE YOUR PC IN YOUR ABSENCE

Rejected Nuts - These days generally some people log in to our pc and check photos and other data or any other useful information without our permission, and we always don't want anybody to access our pc without our permission which most of the people like to do. if you want to know the details than when was your pc accessed then I am here to show you how can you check that who logged on to your pc.
Into Windows, there is one in-built too will records all events in your computer called“Event Viewer”. This application records all your computer activities from login tolog off etc.The Event Viewer can be accessed in all Windows Operating system includingWindows XP, Vista, Windows 7 and Windows 8.Here, I”ll show you how to find the login events in Windows 8. To open the EventViewer, type the eventvwr.msc in Run Command (Open run command Press Win +R Keys ) and press enter or go to Command prompt and type eventvwr.msc and press enter.Now the Event Viewer utility will open, and many logs will be shown to you. To get login events of you computer click Windows logs -> System in the left panel.

The System log will show all the logs from kernel, Wireless network service start.
There you can also find out the login event “Winlogon”. Just click the login event
to display the properties of that event in the panel below.
In the properties, you can get the much needed information such as Login time,
user account, event ID.

Note :
If you have found that someone has accessed your computer, change your user
password immediately with complex one and scan your computer with Best
Antivirus applications and Anti-malware security applications, remove threats if
you found.

Beware: Fake 'The Interview' App Affects Android Users


"The Interview", the controversial North Korean-baiting film which appeared to be the root cause of the cyber mishap occurred at Sony Pictures Entertainment that threatened terror attack at theaters showing the movie, now threatens to expose users of Android phones to a malware attack.

Since its release, everyone is talking about "The Interview" — the Seth Rogen and James Franco-starring comedy centered around a TV host and his producer assassinating North Korean dictator Kim Jong Un. Because cybercriminals are known to take advantage of major events where there is a high level of public interest, The Interview became their target.

In a joint investigation, Security researchers of McAfee and Technische Universität Darmstadt and the Center for Advanced Security Research Darmstadt (CASED) has discovered an Android app claiming to download 'The Interview' comedy on their smartphone devices actually infects users’ devices with banking trojan in order to steal their financial information.

The Banking Trojan is appeared to be hosted on Amazon Web Services and is delivered via a torrent file. Researchers have identified that the malware campaign is targeting Android users in South Korea and is active from the last few days. The campaign is attempting to exploit the popularity of The Interview movie that triggered tension over its release on Christmas.

The malware trojan, detected by the researchers at McAfee as Android/Badaccents, targets customers of some Korean banks as well as an international bank, Citi Bank. According to researchers, the Trojan is selective about its victims and avoids infection of devices sold in North Korea.
"One aspect which will probably raise eyebrows, is that the malware code includes a routine to check the device’s manufacturing information," Graham Cluley wrote on his blog. "If it is set to either 삼지연 (Samjiyon) or 아리랑 (Arirang), smartphone manufacturers whose Android devices are sold in North Korea, the malware will not infect, and instead display a message that an attempt to connect to the server failed."
The researchers' findings cited by Cluley revealed that at least 20,000 devices have been infected and that the information exfiltrated from the devices is uploaded to a Chinese mail server.

Security researchers at McAfee has notified Amazon Web Security about the malware hosting issue so that the Amazon-hosted files can be removed and prevent further infections. However, other online storage services could be used by cyber criminals for carrying out the campaign.

Usually cybercriminals use third party Android app to distribute trojan malware in order to infect smartphone users, but this is the first time when cyber crooks have chosen torrent websites to deliver the Trojan, probably because "The Interview" is already at the top of search results in Korea and most of the countries.

What Happens When Malware Infects Your Computer And Creates Thousands Of Fake Clicks On Ads


Online ad fraud costs advertisers more than $7 million every month, as they pay for digital ads that were never actually seen by humans.
Much of this online ad fraud is created by botnets: armies of PCs infected with malware that generates thousands of fake clicks on ads. The botnet controllers tend to be unethical web publishers that want to ramp up the prices of advertising on their sites by inflating the amount of clicks on their sites.
Ad fraud has a number of drastic consequences. For users, it can significantly slow down their machine. For advertisers, it means they have to pay more to actually generate meaningful results from their online advertising. And for ethical publishers and advertising technology companies, it diminishes trust in the digital advertising industry, which could lead to less spending.
But while the consequences for all those involved are dire, it can be difficult to really understand how ad fraud works in practice.
That’s why fraud detection company Forensiq has created a video to highlight just how quickly a computer infected with malware can start racking up thousands of false ad impressions.