Government and media websites shut down as cyber-attack fears plague region on 63rd anniversary of Korean war


Several government and media websites in South and North Korea were shut for several hours on the 63rd anniversary of Korean war, and Seoul said its sites were hacked and alerted people to take security measures against cyber-attacks.
It was not immediately clear whether the shutdown of North Korean websites, including those belonging to Air Koryo and the Rodong Sinmun newspaper, was triggered by hacking. Rodong Sinmun, Uriminzokkiri and Naenara websites were operational a few hours later.
South Korean national intelligence service officials were investigating the cause of the shutdown of the North Korean websites. Pyongyang did not make any immediate comment.
Seoul said it was also investigating attacks on the websites of the presidential Blue House and the prime minister's office as well as some media servers.
The attacks in South Korea did not appear to be as serious as a cyber-attack in March, which shut down tens of thousands of computers and servers at broadcasters and banks. There were no initial reports that banks had been hit or that sensitive military or other key infrastructure had been compromised.
It was not immediately clear who was responsible, and the neighbours have long traded accusations over cyber-attacks.
Several Twitter users who purported to be part of a global hackers' collective claimed they attacked North Korean websites. Shin Hong-soon, an official at South Korea's science ministry in charge of online security, said the government was not able to confirm whether these hackers were linked to the attack on South Korean websites.
Officials in Seoul blamed Pyongyang for the attacks in March and said an initial investigation pointed to a North Korean military-run spy agency as the culprit.
In recent weeks the North has pushed for talks with Washington amid soaring tensions on the Korean peninsula, culminating in Pyongyang making threats over UN sanctions and US-South Korean military drills.
Investigators detected similarities between the cyber-attack in March and previous hacking attributed to the North Korean spy agency, including the recycling of 30 of 76 malware programs used in the attack, South Korea's internet security agency said.
The cyber-attack on 20 March struck 48,000 computers and servers, hampering banks for two to five days. Officials said no bank records or personal data were compromised. Staff at the TV broadcasters KBS, MBC and YTN were unable to log on to news systems for several days, although coverage continued. No government, military or infrastructure targets had been affected.
South Korea's national intelligence service said the North was behind a denial of service attack in 2009 that affected dozens of websites, including that of the presidential office. Seoul also believes Pyongyang was responsible for attacks on servers of Nonghyup bank in 2011 and Joongang Ilbo, a national daily newspaper, in 2012.
Pyongyang blamed its neighbour and the US for cyber-attacks in March that temporarily disabled internet access and websites in North Korea.
Experts believe North Korea trains large teams of "cyber-warriors", and say the South and its allies should be braced for attacks on infrastructure and military systems. If the inter-Korean conflict were to move into cyberspace, South Korea's deeply wired society would be more widely affected than North Korea's, which largely remains offline.
taken from;http://www.guardian.co.uk/world/2013/jun/25/north-korea-south-websites-hacking-cyber-attack

Phishing Attack


Phishing is a type of Internet fraud, the criminal counterfeit copy of a popular Internet service (no email service, internet banking website and social networking sites) to create and make them attractive to users.
                           According to reports around the world last year, averaging 1.02 million phishing attacks every day. The report stated, '2012-13 102 100 phishing attacks worldwide internet users every day have to face. Every day, 19,000 in Russia, 12,000 in the U.S., 10,000 in India, 6,000 in Germany, 3,000 in France and 3,000 phishing attacks in the UK. "
               The report said that in 2011-12 the figure was just 52,000. Of this, 12,000 phishing attacks in Russia, 5 thousand in the U.S., four thousand in India, 3 in Germany thousand, two thousand one thousand attacks in France and in the UK

About Tech support phone scams


Cyber criminals don't just send fraudulent email messages and set up fake websites. They might also call you on the telephone and claim to be from Microsoft. They might offer to help solve your computer problems or sell you a software license. Once they have access to your computer, they can do the following:

  • Trick you into installing malicious software that could capture sensitive data, such as online banking user names and passwords. They might also then charge you to remove this software.
  • Take control of your computer remotely and adjust settings to leave your computer vulnerable.
  • Request credit card information so they can bill you for phony services.
  • Direct you to fraudulent websites and ask you to enter credit card and other personal or financial information there.

Neither Microsoft nor our partners make unsolicited phone calls (also known as cold calls) to charge you for computer security or software fixes.

What you Need to Know
Cybercriminals often use publicly available phone directories so they might know your name and other personal information when they call you. They might even guess what operating system you're using.
Once they've gained your trust, they might ask for your user name and password or ask you to go to a website to install software that will let them access your computer to fix it. Once you do this, your computer and your personal information is vulnerable.

Do not trust unsolicited calls. Do not provide any personal information.

Here are some of the organizations that cybercriminals claim to be from:
  1. Windows Helpdesk
  2. Windows Service Center
  3. Microsoft Tech Support
  4. Microsoft Support
  5. Windows Technical Department Support Group
  6. Microsoft Research and Development Team (Microsoft R & D Team)
How to Protect Yourself from such phone call:-
If someone claiming to be from Microsoft tech support calls you:
  • Do not purchase any software or services.
  • Ask if there is a fee or subscription associated with the "service." If there is, hang up.
  • Never give control of your computer to a third party unless you can confirm that it is a legitimate representative of a computer support team with whom you are already a customer.
  • Take the caller's information down and immediately report it to your local authorities.
  • Never provide your credit card or financial information to someone claiming to be from Microsoft tech support.
What to do if you already gave information to scam tech support team:- 

If you think that you might have downloaded malware from a phone tech support scam website or allowed a cybercriminal to access your computer, take these steps:

  • Change your computer's password, change the password on your main email account, and change the password for any financial accounts, especially your bank and credit card.
  • Scan your computer with the Microsoft Safety Scanner to find out if you have malware installed on your computer.
  • Install Microsoft Security Essentials. (Microsoft Security Essentials is a free program. If someone calls you to install this product and then charge you for it, this is also a scam.)
Taken from http://www.microsoft.com/security/online-privacy/avoid-phone-scams.aspx

India's share of the worldwide Internet phishing attacks in April 2013


India's share of the worldwide Internet phishing attacks has risen to around 8 per cent. The number of Internet users in the country of 137 million. Phishing attacks in India in April 2152. In April, as phishing attacks worldwide Internet network in India at 8 per cent of them were. According to EMC Storage Solutions IT firm, phishing attacks, India's position in the U.S., UK and South Africa to the fourth position.

NYSE listed by EMC's RSA security division may report fraud that in April of 2013, total 26 902 cases of phishing. Such phishing attacks compared to March grew by 10 percent. 46 per cent of all phishing attacks on the U.S. and the way he is ranked first in the list. In Britain, 11 percent and 9 percent of the total phishing attacks in South Africa.
Taken from http://hindi.business-standard.com/storypage.php?autono=73660

Cyber Crime



Every time one jumps on to surf the wonderful World Wide Web they are susceptible to a cyber crime! Understanding the top five computer crimes is valuable information for the novice and even expert internet surfer reports(Cyber Crime)
1 Child Pornography(Cyber Crime)
 Sad but true, child pornography makes this list. Child pornography is among the fastest growing criminal segments on the Internet. Child pornography is publishing and transmitting obscene material of children in electronic form. In recent years child pornography has increased due to the easy access of the internet, & easily available videos on the internet. (Cyber Crime)Child pornography is a crime in India. Information Technology Act, 2000 & Indian Penal Code, 1860 provides protection from child pornography. (Cyber Crime)Child is the person who is below the age of 18 years reports indianchild.c0m(Cyber Crime), according to sources it is estimated that over 20,000 images of child pornography are posted online weekly.(Cyber Crime)
2 Software Piracy(Cyber Crime)
Software Piracy is amongst the most common cyber crime which can be defined as "copying and using commercial software purchased by someone else". (Cyber Crime)Software piracy is illegal and a big loss for the company producing the software as each pirated piece of software takes away from company profits. However it is legal to make backup copies after you purchase software but if you give one to a friend it is considered a crime.(Cyber Crime) (Selling a copy is also illegal)(Cyber Crime)
3 Malware(Cyber Crime)
Malicious Software (Malware) tops the list of computer crimes as it enables cyber crime on a massive scale. Malware(Cyber Crime) can be of different types like Trojans, viruses, worms and any other software that attaches to a computer without individuals being aware of its presence. Unlike the traditional malware(Cyber Crime) and viruses there are new category malwares(Cyber Crime) that infect your pc and you may not even realize it. Most of them are invisible and hard-to-spot malware (Cyber Crime)can also be extremely hard to remove.(Cyber Crime)
4.Identity Theft(Cyber Crime)
Identity theft while not always computer related is often committed through the use of computers.(Cyber Crime) Millions have been a victim of identity theft across the globe.(Cyber Crime) Identity theft is committed with an intention to acquire your personal information, without your knowledge and uses it in an offendable way to commit fraud.(Cyber Crime)
5 Cyberstalking(Cyber Crime)
Cyberstalking(Cyber Crime) can be defined as using the internet to harass. In most cases victims have very little information about the harassers, however don't start counting out that old flame yet!(Cyber Crime)
(Cyber Crime)taken from:-http://www.siliconindia.com/news/enterpriseit/5-Most-Dngerous-Computer-Crimes-nid-114463-cid-7.html(Cyber Crime)(Cyber Crime)

Computer Virus Infection indicators:


We want to install latest antivirus in our PC and after installation we think our computer became safe and secure but we have to know our computer is infected or not,for this there is no need of huge technical skill simply monitor your PC and find out is behave of your PC match  with following behave.

Virus Infection indicators:


  1. Your computer always stops responding when you try to use Microsoft Office products.
  2. You cannot start Windows Task Manager.
  3. Antivirus software indicates a virus is present.
  4. You received an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear or a sudden degradation in system performance occurs.
  5. There is a double extension on an attachment that you recently opened, such as .jpg.vbs or .gif.exe.
  6. An antivirus program is disabled for no reason and it cannot be restarted.
  7. An antivirus program cannot be installed on the computer or it will not run.
  8. Strange dialog boxes or message boxes appear on screen.
  9. Someone tells you that they have recently received e-mail messages from you containing attached files (especially with .exe, .bat, .scr , .vbs extensions), which you did not send.
  10. New icons appear on the Desktop that you did not place there, or are not associated with any recently installed programs.
  11. Strange sounds or music plays from the speakers unexpectedly.
  12. A program disappears from the computer, and it was not intentionally uninstalled.
  13. A virus infection could also cause the following symptoms, but these symptoms could also be the result of ordinary Windows functions, or problems within Windows that is not caused by a virus.
  14. Windows will not start at all, even though you have not made any system changes, or you have not installed or removed any programs.
  15. Windows will not start because certain critical system files are missing, and then you receive an error message that lists those files.
  16. There is a lot of modem activity. If you have an external modem, you may notice the lights blinking extensively when the modem is not being used. You may be unknowingly supplying pirated software.
  17. The computer starts as expected sometimes, but at other times it stops responding before the desktop icons and taskbar appear.
  18. The computer runs very slowly and it takes a long time to start.
  19. Out-of-memory error messages appear, even though your computer has plenty of RAM.
  20. New programs do not install properly.
  21. Windows spontaneously restarts unexpectedly.
  22. Programs that used to run now stop responding frequently. If you try to remove and reinstall the software, the issue continues to occur.

Wireless network security


Wireless-network security isn't a single issue. Businesses need to recognize that they are fighting attacks on several fronts. Many wireless-network threats are unique to the technology, including:
Threats:
Roaming Attackers: Attackers don't have to be physically located on a business's premises in order to access data on its wireless network. Criminals use network scanners, such as NetStumbler, with a laptop or other portable device to sniff out wireless networks from a moving vehicle — an activity called "wardriving." Performing the same task while walking down a street or through a business site is called "warwalking."
Rogue Access Points: A rouge access point is one that exists without the permission or knowledge of the wireless network's owner. Employees often install rogue access points to create hidden wireless networks that circumvent the installed security measures. Such stealth networks, while fundamentally innocuous, can create an unprotected gateway that serves as an open door to intruders.
The Evil Twin: Sometimes referred to as WiPhishing, an evil twin is a rogue access point that hides under a nearby network's name. The Evil Twin waits for an unsuspecting user to sign into the wrong access point and then steals the individual's network data or attacks the computer.
Network Resource Theft: Cheapskates like to get free Internet access from nearby wireless networks. Even if these individuals intend no direct harm, they still hijack network bandwidth to surf the Web and perform other online activities, draining network performance. More nefarious freeloaders will exploit the connection to send email from a company's domain or to download pirated content — exposing the host business to legal action.
Protection Methods
With wireless providing so many opportunities for attackers to enter and harm networks and business systems, it's no surprise that a wide array of security tools and techniques have arrived to help businesses secure their networks. Here are the top protection methods:
Firewalls: A strong network firewall can effectively block intruders trying to enter a business's network via a wireless device.
Security Standards: The first wireless-network security standard — WEP (Wired Equivalent Privacy) — was highly insecure and easily compromised. Newer specifications, such as WPA (Wifi Protected Access), WPA2 and IEEE 802.11i are much stronger security tools. Businesses with wireless networks should take full advantage of a least one of these technologies.
Encryption and Authentication: WPA, WPA2 and IEEE 802.11i supply built-in advanced encryption and authentication technologies. WPA2 and 802.11i both support AES (Advanced Encryption Standard), the specification used by many U.S. government agencies.
Vulnerability Scanning: Many attackers use network scanners that actively send messages to probe nearby access points for information, such as SSID (service set identifier) and MAC (machine access code) names and numbers. Businesses can use this same approach to uncover attacker-exploitable weaknesses in their wireless network, such as unsecured access points.
Lower the Power: Some wireless routers and access points allow users to lower the transmitter's power, reducing the device's coverage range. This is a useful way of limiting access to on-site users. Careful antenna positioning and placement can also help keep signals from "bleeding" into off-site locations.
Education: All employees should be trained in the proper use of wireless devices and instructed to report any unusual or suspicious activities they detect.
taken from:-http://www.itsecurity.com/features/essential-guide-wireless-security-071708/

Cyber Crime Police Stations in India

1. Mumbai

Assistant Commissioner of Police
Cyber Crime Investigation Cell
Office of Commissioner of Police office,
Annex -3 Building, 1st floor,
Near Crawford Market, Mumbai-01.

+91-22-22630829
+91-22-22641261

Web site: http://www.cybercellmumbai.com
E-mail id: officer@cybercellmumbai.com
----------------------------------------------------------------------------
2. Chennai

Assistant Commissioner of Police
Cyber Crime Cell
Commissioner office Campus
Egmore, Chennai- 600008

+91-40-5549 8211
E-mail id: s.balu@nic.in

For Rest of Tamil Nadu,
Address: Cyber Crime Cell, CB, CID, Chennai

E-mail id: cbcyber@tn.nic.in
----------------------------------------------------------------------------
3. Bangalore

Cyber Crime Police Station
C.O.D Headquarters,
Carlton House,
# 1, Palace Road,
Bangalore – 560 001

+91-80-2220 1026
+91-80-2294 3050
+91-80-2238 7611 (FAX)

Web site: http://www.cyberpolicebangalore.nic.in/
Email-id: ccps@blr.vsnl.net.in, ccps@kar.nic.in
----------------------------------------------------------------------------
4. Hyderabad

Cyber Crime Police Station
Crime Investigation Department,
3rd Floor, D.G.P. Pffice, Lakdikapool,
Hyderabad – 500004

+91-40-2324 0663
+91-40-2785 2274
+91-40-2329 7474 (Fax)



Web site: http://www.cidap.gov.in/cybercrimes.aspx
E-mail id: cidap@cidap.gov.in, info@cidap.gov.in
----------------------------------------------------------------------------
5. Delhi

CBI Cyber Crime Cell:
Superintendent of Police,
Cyber Crime Investigation Cell
Central Bureau of Investigation,
5th Floor, Block No.3, CGO Complex,
Lodhi Road, New Delhi – 3

+91-11-4362203
+91-11-4392424

Web site: http://cbi.nic.in/
E-Mail: cbiccic@bol.net.in
----------------------------------------------------------------------------
6. Thane

3rd Floor, Police Commissioner Office
Near Court Naka, Thane West,
Thane 400601.

+91-22-25424444

Web site: www.thanepolice.org
E-Mail: police@thanepolice.org

7. Pune
Assistant Commissioner of Police
Cyber Crime Investigation Cell
Police Commissioner Office of Pune
2, Sadhu Vaswani Road, Camp,
Pune 411001

+91-20-2612 7277
+91-20-2616 5396
+91-20-2612 8105 (Fax)

Web site: http://punepolice.com/crime branch.html
E-Mail: punepolice@vsnl.com
----------------------------------------------------------------------------
8. Gujarat
DIG, CID, Crime and Railways
Fifth Floor
Police Bhavan
Sector 18, Gandhinagar 382 018

+91-79-2325 4384
+91-79-2325 3917 (FAX)

Flame virus warning

Microsoft issues Flame virus warning
Microsoft warned that a bug in Windows allowed PCs across the Middle East to become infected with the Flame virus and released a software fix to fight the espionage tool that surfaced last week.
Security experts said they were both surprised and impressed by the approach that the attackers had used, which was to disguise Flame as a legitimate program built by Microsoft. Kaspersky Lab, one of the researchers who helped to discover the Flame virus.
The creators of the virus obtained that certificate by manipulating a component of the Windows operating system known as terminal services licensing, or TS licensing, that is designed to authorize business customers to use advanced features of Windows. 
A bug in TS licensing allowed the hackers to use it to create fake certificates that identified Flame as being from Microsoft, Mike Reavey, a senior director with Microsoft's Security Response Center, said in a blog post. 
He feared that other hackers might be able to copy the technique to launch more widespread attacks with other types of viruses, Reavey said. 
"We continue to investigate this issue and will take any appropriate actions to help protect customers," Reavey said in the blog post. 
News of the Flame virus, which surfaced a week ago, generated headlines around the world as researchers said that technical evidence suggests it was built on behalf of the same nation or nations that commissioned the Stuxnet worm that attacked Iran's nuclear program in 2010. Researchers are still gathering information about the virus. 
Microsoft's warning is available at blogs.technet.com/b/msrc/

Change passwords on LinkedIn Now


If you have a LinkedIn account, now's a good time to change your password. Up to 6.5 million user accounts and encrypted passwords have reportedly been leaked and posted to a Russian hacker site.
LinkedIn hasn't confirmed the passwords have been stolen, but did confirm on its Twitter account they're looking into it. The leak comes off the news that LinkedIn's mobile apps transmit personal data, including meeting notes and calendar info in plain text. Regardless of whether the leak is confirmed or not, it's a good time to change your password. To do so, go straight to the LinkedIn Change Password page (you'll need to be logged in), enter a new, secure password, and click Change Password.
   LinkedIn has confirmed that some of the compromised passwords are LinkedIn accounts. If your password was compromised your account password has already been made invalid and you'll receive an email with instructions for how to reset your password (you can also double-check here: LeakedIn). If you use the same password and email address for other websites as you did with LinkedIn make sure you change those as well.