Cyber Security

As we know we are leaving in cyber world where technology and internet provide lot of benefits with huge dangers aspect.cyber world serves equally to both hackers and crackers.
It also provide lot of way of security hence we need to take precautions to protect(secure) yourself online.


 What are some warnings to remember or some security tips to use?

    Don't trust candy from strangers - Finding something on the internet does not guarantee that it is true.or secure or it will full fill all security criteria 

Anyone can publish information online without checking it is secure(security) or not , so before accepting a statement as fact or taking action, verify that the source is reliable.or secure 
It is also easy for attackers to "spoof" email addresses, so verify that an email is legitimate before opening an unexpected email attachment or responding to a request for personal information 
If it sounds too good to be true, it probably is - You have probably seen many emails promising fantastic rewards or monetary gifts. However, regardless of what the email claims, there are not any wealthy strangers desperate to send you money. Beware of grand promises—they are most likely spam, hoaxes, or phishing schemes . Also be wary of pop-up windows and advertisements for free downloadable software—they may be disguising spyware.    
Don't advertise that you are away from home - Some email accounts, especially within an organization, offer a feature (called an autoresponder)
that allows you to create an "away" message if you are going to be away from your email for an extended period of time. The message is automatically
sent to anyone who emails you while the autoresponder is enabled. While this is a helpful feature for letting your contacts know that you will not be
able to respond right away, be careful how you phrase your message. You do not want to let potential attackers know that you are not home, or, worse, give specific details about your location and itinerary. Safer options include phrases such as "I will not have access to email between [date] and [date].
" If possible, also restrict the recipients of the message to people within your organization or in your address book. If your away message replies to spam, it only confirms that your email account is active. This may increase the amount of spam you receive  Lock up your valuables - If an attacker is able to access or breaches your cesurity, your personal data, he or she may be able to compromise or steal the information.
Take steps to secure this information by following good security practices
 Some of the most basic precautions or security include locking your computer when you step away; using firewalls, anti-virus software, and strong passwords security ; installing appropriate software security updates; and taking precautions or security when browsing or using email.
 Have a backup plan - Since your information could be lost or compromised (due to an equipment malfunction, an error, or an attack),
 make regular backups of your information so that you still have clean, complete copies
Backups also help you identify what has been changed or lost.

Cyber war: Google, China in fresh spat over email hacking

BEIJING/SAN FRANCISCO: Suspected Chinese hackers tried to steal the passwords of hundreds of Google email account holders, including those of senior US government officials, Chinese activists and journalists , the internet company said.[sintuhack]

The claim by the world's largest web search engine sparked an angry response from Beijing, which said blaming China was "unacceptable," pointing to further tensions in an already strained relationship with Google.[sintuhack]

The perpetrators appeared to originate from Jinan, the capital of China's eastern Shandong province, Google said. Jinan is home to one of six technical reconnaissance bureaus belonging to the People's Liberation Army and a technical college US investigators last year linked to a previous attack on Google.
[sintuhack]

Washington said it was investigating Google's claims while the FBI said it was working with Google following the attacks — the latest computerbased invasions directed at multinational companies.
[sintuhack]

Andrew Davies of the Australian Strategic Policy Institute , an independent security and defence think tank, said governments needed to pay more attention to hacking no matter where it originated from. "I think there has been a certain lack of appreciation of the looming threat around the world," Davies said.

The hackers recently tried to crack and monitor email accounts by stealing passwords, but Google detected and "disrupted " their campaign, the company said on its official blog. Google said it had notified the victims.

[sintuhack][sintuhack][sintuhack][sintuhack][sintuhack][sintuhack]

NOTE-- THE ABOVE CONTENT TAKEN FROM GOOGLE NEWS http://timesofindia.indiatimes.com/world/china/Cyber-war-Google-China-in-fresh-spat-over-email-hacking/articleshow/8705176.cms

Cyber law or It act of India

Cyber laws are meant to set the definite pattern, some rules and guidelines that defined certain business activities going on through internet legal and certain illegal and hence punishable .Today sintuhack will explian some fact about cyber case (sintuhack). The IT Act 2000, the cyber law of India , gives the legal framework so that information is not denied legal effect, validity or enforceability, solely on the ground that it is in the form of electronic records.

One cannot regard government as complete failure in shielding numerous e-commerce activities on the firm basis of which this industry has got to its skies, but then the law cannot be regarded as free from ambiguities.(sintuhack)


The IT Act 2000 attempts to change outdated laws and provides ways to deal with cyber crimes. Let’s have an overview of the law where it takes a firm stand and has got successful in the reason for which it was framed.(sintuhack)

1. The E-commerce industry carries out its business via transactions and communications done through electronic records . It thus becomes essential that such transactions be made legal . Keeping this point in the consideration, the IT Act 2000 empowers the government departments to accept filing, creating and retention of official documents in the digital format. The Act also puts forward the proposal for setting up the legal framework essential for the authentication and origin of electronic records / communications through digital signature.(sintuhack)

2. The Act legalizes the e-mail and gives it the status of being valid form of carrying out communication in India . This implies that e-mails can be duly produced and approved in a court of law , thus can be a regarded as substantial document to carry out legal proceedings.(sintuhack)

3. The act also talks about digital signatures and digital records . These have been also awarded the status of being legal and valid means that can form strong basis for launching litigation in a court of law. It invites the corporate companies in the business of being Certifying Authorities for issuing secure Digital Signatures Certificates.

4. The Act now allows Government to issue notification on the web thus heralding e-governance.(sintuhack)

5. It eases the task of companies of the filing any form, application or document by laying down the guidelines to be submitted at any appropriate office, authority, body or agency owned or controlled by the government. This will help in saving costs, time and manpower for the corporates.(sintuhack)

6. The act also provides statutory remedy to the coporates in case the crime against the accused for breaking into their computer systems or network and damaging and copying the data is proven. The remedy provided by the Act is in the form of monetary damages, not exceeding Rs. 1 crore($200,000).(sintuhack)

7. Also the law sets up the Territorial Jurisdiction of the Adjudicating Officers for cyber crimes and the Cyber Regulations Appellate Tribunal.(sintuhack)

8. The law has also laid guidelines for providing Internet Services on a license on a non-exclusive basis.(sintuhack)

The IT Law 2000, though appears to be self sufficient, it takes mixed stand when it comes to many practical situations. It looses its certainty at many places like:(sintuhack)

1. The law misses out completely the issue of Intellectual Property Rights, and makes no provisions whatsoever for copyrighting, trade marking or patenting of electronic information and data. The law even doesn’t talk of the rights and liabilities of domain name holders , the first step of entering into the e-commerce.(sintuhack)
2. The law even stays silent over the regulation of electronic payments gateway and segregates the negotiable instruments from the applicability of the IT Act , which may have major effect on the growth of e-commerce in India . It leads to make the banking and financial sectors irresolute in their stands .(sintuhack)(sintuhack)
3. The act empowers the Deputy Superintendent of Police to look up into the investigations and filling of charge sheet when any case related to cyber law is called. This approach is likely to result in misuse in the context of Corporate India as companies have public offices which would come within the ambit of "public place" under the Act. As a result, companies will not be able to escape potential harassment at the hands of the DSP.(sintuhack)
4. Internet is a borderless medium ; it spreads to every corner of the world where life is possible and hence is the cyber criminal. Then how come is it possible to feel relaxed and secured once this law is enforced in the nation??(sintuhack)

The Act initially was supposed to apply to crimes committed all over the world, but nobody knows how can this be achieved in practice , how to enforce it all over the world at the same time???(sintuhack)

* The IT Act is silent on filming anyone’s personal actions in public and then distributing it electronically. It holds ISPs (Internet Service Providers) responsible for third party data and information, unless contravention is committed without their knowledge or unless the ISP has undertaken due diligence to prevent the contravention .(sintuhack)
* For example, many Delhi based newspapers advertise the massage parlors; and in few cases even show the ‘therapeutic masseurs’ hidden behind the mask, who actually are prostitutes. Delhi Police has been successful in busting out a few such rackets but then it is not sure of the action it can take…should it arrest the owners and editors of newspapers or wait for some new clauses in the Act to be added up?? Even the much hyped case of the arrest of Bajaj, the CEO of Bazee.com, was a consequence of this particular ambiguity of the law. One cannot expect an ISP to monitor what information their subscribers are sending out, all 24 hours a day.(sintuhack)

Cyber law is a generic term, which denotes all aspects, issues and the legal consequences on the Internet, the World Wide Web and cyber space. India is the 12th nation in the world that has cyber legislation apart from countries like the US, Singapore, France, Malaysia and Japan .(sintuhack)

But can the cyber laws of the country be regarded as sufficient and secure enough to provide a strong platform to the country’s e-commerce industry for which they were meant?? India has failed to keep in pace with the world in this respect, and the consequence is not far enough from our sight; most of the big customers of India ’s outsourcing company have started to re-think of carrying out their business in India .Bajaj’s case has given the strongest blow in this respect and have broken India ’s share in outsourcing market as a leader.(sintuhack)

If India doesn’t want to loose its position and wishes to stay as the world’s leader forever in outsourcing market, it needs to take fast but intelligent steps to cover the glaring loopholes of the Act, or else the day is not far when the scenario of India ruling the world’s outsourcing market will stay alive in the dreams only as it will be overtaken by its competitors.sintuhack,sintuhack,sintuhack,sintuhack,sintuhack,sintuhack,sintuhack,sintuhack

Online Survey Company Is Fraud Or Not-how to know

Today, when there is hot dispute is already going on between the star news and online paid survey company Speak Asia after publishing the negative news about Speak Asia and their business behavior. sintuhack strongly feel that sintuhack should post an article to help you find the possible online fraud survey companies which are asking for money any how.


1. Whois Lookup:
A/c to sintuhack try to who is look up for the domain of official website of paid survey company you can easily find the following details.sintuhack also suggest you to know
Who is the owner of website domain?
From since long the website is active, means since how long the company is in survey business?
What is the registered official address? Where the company office is actually located.
All these info helps a lot to decide weather the company you are researching about is just another online scam or not.


2. SEO Research:
Seo research on the paid survey website can easily tell you the fact about how the website is popular in the world. You can look for number of backlinks, Google page rank and alexa rank for this. From alexa traffic analysis you can also find the location of main traffic toward the website so you can know where the website is doing more business in the world.


3. Online Complains and Scam Discussion boards:
One thing more a/c to sintuhack use google to know page rank of that website.
If you search in Google with the words like complain, fraud, scam along with the company name, you can easily find the various blogs or websites where people might have discussed about their issues or complaints with the company. Although every good company will also have some issues with clients but too much of them can really alarm you about possible online scam.


4. Make money online blogs and forums.
Here sintuhack talking about the blogs and forums where people are generally from the similar niche and discuss about how to make money online. It would be great source to find the exact information about such paid scams. If you are new to online money making niche and much not aware of the scams you can also post comments (here also) and threads in forum in similar niche to get reviews of experts in the same niche.


5. Think smartly, wisely and independently.
And last sintuhack guide you to use internet smartly wisely and independently
Think smartly to detect online scams
Its my own experience that people always get trapped in scams because they are always in search of quick rich formula and hence they generally do not think for the most important questions. So think like you want to investigate about the company and not want to invest in it, this way you can find most answers easily.

Pharming -- a new Way for Internet fraud


Hackers appear to have an increasing interest in reaping financial reward from their actions and creations. If, until now, phishing -- using e-mails to lure users into entering data into spoofed online banking Web sites -- was one of the most widespread fraud techniques, 'pharming' now poses an even greater threat.
Basically, pharming involves interfering with the name resolution process on the Internet. When a user enters an address  this needs to be converted into a numeric IP address as 21.15.63.87. This is known as name resolution, and the task is performed by DNS (Domain Name System) servers. These servers store tables with the IP address of each domain name. On a smaller scale, in each computer connected to the Internet there is a file that stores a table with the names of servers and IP addresses so that it is not necessary to access the DNS servers for certain server names.
Pharming consists in the name resolution system modification, so that when a user thinks he or she is accessing to bank's Web page, he or she is actually accessing the IP of a spoofed site.
Phishing owed its success to social engineering techniques, but since not all users take the phishing bait, its success was limited. Also, each phishing attack was aimed at one specific type of banking service, further reducing the chances of success. Pharming on the other hand, can affect a far greater number of online banking users.
In addition, pharming isn't just a one-off attack, as is the case with phishing e-mails, but remains present on the computer waiting for the user to access the banking services.
The solution against this new kind of fraud lies, as ever, in anti-virus security solutions. Pharming attacks depend on an application in the compromised system (this could be an exe file, a script, etc). But before this application can run, obviously it needs to reach the operating system. Code can enter the system through numerous channels; in fact, in as many ways as information can enter the system: via e-mail (the most frequent), Internet downloads, copied directly from CD or floppy, etc. In each of these information entry points, the anti-virus has to detect the file with the malicious code and eliminate it, provided it is registered as a dangerous application in the anti- virus signature file.
Unfortunately, the propagation speed of malware today is head-spinning, and there are more malicious creators offering their source code to the rest of the hacker community to create new variants and propagate even more attacks. The virus laboratories don't have enough time to prepare the malware detection and elimination routines for new malicious code before they start spreading to PCs. Despite the efforts and improvements from virus labs, it is physically impossible for them to prepare an adequate solution in time against some of these threats that can spread in just a few minutes.
The solution against these kinds of threats should not, therefore, depend, at least not in the front line of protection, on a reactive solution based on viral identifier files but rather systems that detect the actions that theses threats carry out. In this way, every time there is an attempted attack on the computer's DNS system (as in the case of pharming applications), the attack is recognized and blocked along with the program carrying out the attack.
However, there is an added danger with pharming, which lies in anonymous proxy servers. Many users want to hide their identity (their IP address) when using the Internet and use online proxy servers so that the connection is made under the server IP and not the client IP. In a worst case scenario, one of these proxy servers could have its name resolution system poisoned so that users trying to access their bank Web site, could actually be viewing a spoofed site, even though their local name resolution system is operating perfectly.
In any event, the threat that pharming poses is a serious one, although one that is easily resolved. Only with systems that can detect and block changes in IP address resolution systems in computers can we hope to prevent the avalanche of malicious code that will soon be upon us

Pharming Security

PHARMING-- BY request of one my reader,i am trying to explain what is Pharming.Due to short of time i cant explain all about pharming.
Pharming is the exploitation of a vulnerability in the DNS server software that allows a hacker to acquire the domain name for a site, and to redirect that website's traffic to another web site. DNS servers are the machines responsible for resolving internet names into their real addresses - the "signposts" of the internet.


If the web site receiving the traffic is a fake web site, such as a copy of a bank's website, it can be used to "phish" or steal a computer user's passwords, PIN or account number. Note that this is only possible when the original site was not SSL protected, or when the user is ignoring warnings about invalid server certificates.


For example, in January 2005, the domain name for a large New York ISP, Panix, was hijacked to a site in Australia. In 2004 a German teenager hijacked the eBay.de domain name.


Secure e-mail provider Hushmail was also caught by this attack on 24th of April 2005 when the attacker rang up the domain registrar and gained enough information to redirect users to a defaced webpage.

Computer Hackers and Predators


How computer hackers and predators are threat for your computer security?

People with bad mind, not the computers, create computer threats. Computer predators victimize unaware people for their gain.  A predator having access to the Internet is exponentially bigger threat to your PC than the others. Computer hackers and predators are unauthorized users who break into others computer systems to steal, change or destroy valuable information, often by installing dangerous and harmful malware without your knowledge. The use of clever tactics and detailed technical knowledge help them to access the information you really don’t want to let them know.
What computer hackers and predators do to find you?
Everyone who uses a computer with a Internet connection is susceptible by the threats of computer hackers and predators. These online demons mainly use spam emails or instant messages, phishing scams, and bogus Web sites (fake or duplicate webpage which almost look like the original) to deliver dangerous and harmful malware to the computer and disable your computer security. They will also try to access your computer and thus your private information directly if you had not taken protection by configuring your firewall. They can also peruse your personal Web page or monitor your chat room conversations. Generally by using a fake identity, predators can fool you and make you into revealing sensitive personal and financial information.
Be aware: computer hackers and predators can do the following things to you.
With the help of malware transmitted by the hacker, he can get your personal as well as financial information without your knowledge. Then he can use this information for his benefit and it will harm you in the aspect of loss of money as well as private information and data. In either case, they may:
•    Know your usernames and passwords and will change it or use it according to him.
•    Using your info they can open credit card and bank accounts in your name
•    Steal your money and Ruin your credit
•    additional credit cards  or Request new account Personal Identification Numbers (PINs) o
•    Make purchases form offline stores.
•    Add themselves or an alias that they control as an authorized user so it’s easier to use your credit
•    Obtain cash advances from your credit card
•     Abuse your Social Security number
•    Sell your information to such person who will use it for illegal purposes
Especially predators can pose a serious physical threat. Be extremely cautious when agreeing to meet an online “friend” or acquaintance in person.
Ways to know that are you in the net or not?
Regularly check the accuracy of your personal accounts, credit cards bills and other documents. Are there any unexplained transactions?
Questionable or unauthorized changes?
 If so, the dangerous and harmful malware is already installed by predators or hackers in your computer.
What can I do about computer hackers and predators?
Read as much as possible about the articles on computer security threats on this blog and increase our knowledge about this. Although Hackers and predators pose equally serious and but very different threats you will wiser enough to avoid their tricks.
To protect your computer from hackers and predators:
•    Regularly check the accuracy of your personal accounts and deal with any discrepancies instantly.
•    Use extreme caution when entering any chat rooms or posting on personal Web pages
•    Put a limit on the personal information you post on a personal Web pages
•    Carefully monitor requests  on social networking sites by online “friends” or acquaintances for predatory behavior
•    Keep personal and financial information out of any type of online conversations
Take these steps to protect your computer from hackers right away:
•    Switch to 2 way firewall.
•    Update your operating system on regular basis.
•    Increase your browser security settings.
•    Only download software from trusted sites you trust.
•    First carefully evaluate free software then use and do same in the case of file-sharing applications before downloading them.
•    Practice safe email protocol.
•    Don't respond messages from unknown senders, even don’t open it.
•    Immediately delete messages you suspect to be spam.
•    Make sure that you have the best internet security products installed on your computer.
•    Always use antivirus protection
•    Also Get antispyware software protection
An unprotected computer is a like a free gift for computer hackers and predators. To protect your computer from hackers and predators also use a spam filter or gateway to scan inbound email or IM messages. While free anti-spyware and antivirus downloads are widely available, they just can’t keep up with the continuous onslaught of new malware strains due to their limited functionality. Previously undetected forms of malware can often do the most damage, so it’s necessary to have up-to-the-minute updated and guaranteed protection.

How to Avoid Phishing Scams

The number and sophistication of phishing scams sent out to consumers is continuing to increase dramatically. While online banking and e-commerce is very safe, as a general rule you should be careful about giving out your personal financial information over the Internet. The Anti-Phishing Working Group has compiled a list of recommendations below that you can use to avoid becoming a victim of these scams.

* Be suspicious of any email with urgent requests for personal financial information
o unless the email is digitally signed, you can't be sure it wasn't forged or 'spoofed'
o phishers typically include upsetting or exciting (but false) statements in their emails to get people to react immediately
o they typically ask for information such as usernames, passwords, credit card numbers, social security numbers, date of birth, etc.
o phisher emails are typically NOT personalized, but they can be. Valid messages from your bank or e-commerce company generally are personalized, but always call to check if you are unsure
* Don't use the links in an email, instant message, or chat to get to any web page if you suspect the message might not be authentic or you don't know the sender or user's handle
o instead, call the company on the telephone, or log onto the website directly by typing in the Web adress in your browser
* Avoid filling out forms in email messages that ask for personal financial information
o you should only communicate information such as credit card numbers or account information via a secure website or the telephone
* Always ensure that you're using a secure website when submitting credit card or other sensitive information via your Web browser
o Phishers are now able to 'spoof,' or forge BOTH the "https://" that you normally see when you're on a secure Web server AND a legitimate-looking address. You may even see both in the link of a scam email. Again, make it a habit to enter the address of any banking, shopping, auction, or financial transaction website yourself and not depend on displayed links.
o Phishers may also forge the yellow lock you would normally see near the bottom of your screen on a secure site. The lock has usually been considered as another indicator that you are on a 'safe' site. The lock, when double-clicked, displays the security certificate for the site. If you get any warnings displayed that the address of the site you have displayed does NOT match the certificate, do not continue.
* Remember not all scam sites will try to show the "https://" and/or the security lock. Get in the habit of looking at the address line, too. Were you directed to PayPal? Does the address line display something different like "http://www.gotyouscammed.com/paypal/login.htm?" Be aware of where you are going.
* Consider installing a Web browser tool bar to help protect you from known fraudulent websites. These toolbars match where you are going with lists of known phisher Web sites and will alert you.
o The newer version of Internet Explorer version 7 includes this tool bar as does FireFox version 2
o EarthLink ScamBlocker is part of a browser toolbar that is free to all Internet users - download at http://www.earthlink.net/earthlinktoolbar
* Regularly log into your online accounts
o don't leave it for as long as a month before you check each account
* Regularly check your bank, credit and debit card satements to ensure that all transactions are legitimate
o if anything is suspicious or you don't recognize the transaction, contact your bank and all card issuers
* Ensure that your browser is up to date and security patches applied
* Always report "phishing" or “spoofed” e-mails to the following groups:
o use the form on this page or forward the email to reportphishing@antiphishing.org
o forward the email to the Federal Trade Commission at spam@uce.gov
o forward the email to the "abuse" email address at the company that is being spoofed (e.g. "spoof@ebay.com")
o when forwarding spoofed messages, always include the entire original email with its original header information intact
o notify The Internet Crime Complaint Center of the FBI by filing a complaint on their website: www.ic3.gov/

Bug disables 150,000 Gmail accounts

NEW DELHI, INDIA: Gmail, with its huge storage capacity, is considered a store house of personal information for many, where many valuable informations are securely kept. But think twice before relying too much on keeping all your informations there alone.
Because, Google's email service has been affected with a bug and almost 150,000 Gmail account holders have reportedly lost their e-mail, attachments and Google Chat logs lost.
Google said it is investigating a glitch in the service of Gmail, which has caused the huge data lose for many users.
The bug reset the affected accounts and showed a welcome message to some users. Google said in a statement that the bug had affected less than 0.08 per cent of all Gmail users. Yes, percentage wise it is a small amount, but 150,000 not a small number too!
It said that their engineers are trying to solve the glitch and as soon as possible the accounts will be restored soon.
“Affected users will be temporarily unable to sign in while we repair their accounts. For those Gmail users reporting missing messages, our engineers are working to restore them as soon as possible,” Google said in a statement.

Firefox spoofing flaw reported

Mozilla’s Firefox web browser is vulnerable to spoofing attacks, according to an Israeli security researcher. Aviv Raff reported on his blog on Wednesday that Mozilla Firefox v2.0.0.11 allows information presented in a basic authentication dialogue box to be spoofed, opening up the possibility of users being redirected to a malicious website. Earlier versions of the browser may also be affected.

According to Raff, when a web server returns a 401 status code, it causes Firefox to display an authentication dialogue box. The 401 status code is returned by the web server when it recognises that the HTTP data stream sent by a browser or bot is correct, but access to the URL requires further user authentication.

The authentication dialogue box displays the server URL in what is called the WWW-Authenticate header field. This URL is in part defined by the realm value and, according to Raff, it is possible for an attacker to create a specially crafted realm value that will look as if the authentication dialogue came from a trusted website. This is due to Firefox failing to sanitise single quotes and spaces in the WWW-Authenticate header field, after a legitimate realm value enclosed in double quotes has been given.

At least two possible attack vectors are opened by this reported flaw, according to Raff. Man-in-the-middle attackers could create a web page with a link to a trusted website such as a bank. When a victim clicks on the link on the malicious page, the trusted web page would be opened in a new window. A script would be executed to redirect the newly opened window to the attacker’s web server, allowing username and password details to be compromised.

Alternatively, an attacker could embed an image in an email or web page which, when clicked on, would return a specially crafted dialogue login from the attacker’s web server, again allowing authentication details to be compromised.

President of Mozilla Europe, Tristan Nitot, told ZDNet.co.uk that Mozilla is in the process of investigating the report, and so could not comment further at this time.

“We take security seriously,” said Nitot. “We are taking this report seriously, and are investigating.”