Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Friday, January 27, 2017

Now Secure Your Facebook accounts With A Physical USB Key

Facebook Security Key

Facebook has introduced a new login authentication mechanism to allow user accounts to be secured with a physical USB key. Securing accounts with a physical key is considered one of the best ways that users can take control of the security of their accounts.

However, not just any USB can be converted to a USB key required for Facebook login authentication. Currently, USB keys supporting the U2F standard are supported and users will have to get one of these to use the physical USB key security feature on Facebook.

Facebook U2F Security Key

The U2F standard has been developed by Google and Yubico, hosted by an industry association created specifically for overseeing the specifications of an open authentication system known as the Fido Alliance. U2F provides strong two-factor authentication using public key cryptography. You can find a number of U2F keys in India. The FIDO U2F Security Key from HyperFido has a tiny form factor and is available for just Rs 1,482 while the YubiKey Tricolour Pack from Yubico has three USB keys in the colours of the Indian tricolour flag, and is available for Rs 5,000.

The keys can only be used to authenticate Facebook logins on the Google Chrome and Opera browsers. Mozilla is working to add U2F support to its browser. The physical security option is, only available to desktop users. U2F keys with NFC tags can be used to authenticate Facebook logins from select Android devices that have NFC capabilities. The latest version of Chrome and Google Authenticator have to be installed on the device for U2F keys to work. In the security settings menu, under login approvals, users can add a number of physical USB keys to authenticate logins.

The additional safety feature is particularly useful for sensitive accounts such as activists, social workers and government officials. Sensitive accounts being compromised can lead to far-reaching consequences that can affect groups or communities of people instead of just one individual. Regular users can secure their accounts with two-factor authentication, where a code is sent via SMS to the mobile phone of the person. The USB security key can be used for people with spotty SMS coverage, or when using a mobile phone is not an option.


The physical security key prevents digital attempts to compromise accounts, such as social engineering or phishing scams. The USB key provides cryptographic proof that the intended user is accessing the account. The login process is simple, the button on the USB keys have to be pressed on login, and the physical verification is done. The same key can be used to authenticate access to GitHub, Salesforce, Gmail and DropBox. Logging into other services is secure, as the key itself does not keep track of where it has been used.

Buy the FIDO U2F Security Key from Amazon.in
Buy the YubiKey Tricolour Pack from Yubico from Amazon.in

Source: Facebook
Follow Me on Twitter>>>> @iamBhavish
And like us on Facebook>>> The Gud1

Wednesday, December 7, 2016

Dailymotion Suffers Massive Data Breach; Over 85 Million Accounts Said to have been Compromised


Media group Vivendi-owned, popular video streaming website, Dailymotion has been hit by a cyber-attack that is said to have led to a massive data breach of more than 85 million user accounts. The data breach occurred on October 20, according to data breach monitoring company LeakedSource. After its report, Dailymotion on Tuesday came into action to issue an advisory to its users to change their passwords, in addition to denying any compromise of user data.

Dailymotion took this issue to its blog, where it has maintained that the hack is limited and there has been no data breach. "It has come to our attention that a potential security risk, coming from outside Dailymotion may have compromised the passwords for a certain number of accounts. The hack appears to be limited, and no personal data has been comprised." the blog post said.

The data breach is said to have supposedly stolen 85.2 million usernames and email addresses, along with 18 million scrambled passwords on October 20, LeakedSource said, BBC reports.

However, just for the safety of the users, Dailymotion has advised them to change their passwords to something that is not as obvious as 'password1234' or some other alphanumeric combination that can be guessed easily. For its partners, Dailymotion has laid down a recommendation to use its refresh-token method to authenticate their apps and services.

If you use Dailymotion, you should change your password by following these simple steps:


  1. Go to Dailymotion website either on the Web or mobile
  2. Log into your account, as you normally do
  3. You'd see the Settings option in the drop-down menu on the top right corner, click or hover on it
  4. Now, select the Account Settings
  5. Replace the old password with a new and stronger password, and you're set

With this latest cyber-attack, the number of Internet security breach has risen to an alarming number with LinkedIn, TalkTalk, and Indian payment card system as some of the recent victims of cyber-attacks.

Source: LeakedSource
Follow Me on Twitter>>>> @iamBhavish
And like us on Facebook>>> The Gud1

Thursday, February 21, 2013

[WAppEx v2.0] Web Application Exploitation Tool

WAppEx is an integrated Web Application security assessment and exploitation platform designed with the whole spectrum of security professionals to web application hobbyists in mind. It suggests a security assessment model which revolves around an extensible exploit database. Further, it complements the power with various tools required to perform all stages of a web application attack.


Updates in 2.0
  • Auto-detect feature deleted from exploits
  • Browser tool deleted
  • Exploits and payloads view changed
  • Exploit Database with the following features added:
    • New script syntax and structure
    • Searching, selecting, and executing of exploits.
    • Add/remove database entries (exploits or payloads)
    • Add exploits or payloads to the database using either the Exploit Wizard or the script file
    • Batch testing of multiple targets against multiple exploits
    • Execute multiple instances of one or more payloads (for every running exploit) simultaneously.
  • Following tools added:
    • Manual Request
    • Dork Finder
    • Exploit Editor
    • Hidden File Checker
    • Neighbor Site Finder
  • Local File Inclusion analyzer script updated
  • 24 new payloads for LFI, RFI, and PHP Code Execution vulnerabilities added:
    • Directory Explorer
    • CodeExec Bind
    • 3 connect-back shells
    • Code Execution
    • MySQL Dump
    • ServerInfo
    • 4 command execution payloads
  • Bug-fixes:
    • Find Login Page crashed on start
    • Problem with software registration
    • Stop button did not work when retrieving data from SQL server
    • Problem with saving SQL results
    • Crashed when closing Find Login Page
    • Status icons were not displayed properly in exploit tabs

lfi

The full list features is as below:
  • An exploit database covering a wide range of vulnerabilities.
  • A set of tools useful for penetration testing:
    • Manual Request
    • Dork Finder
    • Exploit Editor
    • Hidden File Checker
    • Neighbor Site Finder
    • Find Login Page
    • Online Hash Cracker
    • Encoder/Decoder
  • Execute multiple instances of one or more exploits simultaneously.
  • Execute multiple instances of one or more payloads (for every running exploit) simultaneously.
  • Test a list of target URL’s against a number of selected exploits.
  • Allows you to create your own exploits and payloads and share them online.
  • A number of featured exploits (6) and payloads (39) bundled within the software exploit database:
    • Testing and exploiting of Local File Inclusion vulnerabilities
    • Testing and exploiting of Local File Disclosure vulnerabilities
    • Testing and exploiting of Remote File Inclusion vulnerabilities
    • Testing and exploiting of SQL Injection vulnerabilities
    • Testing and exploiting of Remote Command Execution Inclusion vulnerabilities
    • Testing and exploiting of Server-side Code Injection vulnerabilities

[SoftPerfect WiFi Guard] Proteger y Detectar Quién se Conecta a tu Red Wifi

Tener una conexión Wi-Fi ya es algo común en nuestro hogar u oficina, pero si eres una novato (no hay que de qué apenarse), es posible que no sepas cómo proteger o saber quién puede estar conectado a tu red si tu permiso.


WiFi Guard es una aplicación para Mac, Windows o Linux capaz de ayudarnos a organizar y enviarnos alertas para cuando alguien se conecte a nuestra red. Detallemos las funcionalidades de esta aplicación:

  • Detecta en tiempo real de equipos conectados
  • Detacta equipos con firewall
  • Permite escanear de forma automático los equipos conectados
  • Envía alertas cuando un equipo desconocido se conecte.


Para poder recibir una alerta cuando alguien se conecte a nuestra red es necesario marcarlo como desconocido. Para ello debemos abrir el programa, ejecutar el escaneo, y marcar como conocidos nuestros equipos, por ejemplo el ordenador, la consola y el smartphone.

Las alertas de este programa nos pueden ser útiles si vemos que alguien se conectó a nuestra red, de ser así podemos recurrir a cambiar la clave. Lamentablemente no permite expulsarlo, pero al cambiar la contraseña serviría si actuamos rápidamente.


[Fuente]

Tuesday, January 22, 2013

[Browserscan] Scan Online para Comprobar tu Seguridad

Dado que los cibercriminales aprovecharán cualquier fallo en la parte de cliente para explotar vulnerabilidades, mas vale asegurarnos que tenemos las versiones adecuadas.

Existen servicios en la red donde podremos navegar con nuestro browser preferido para comprobar por ejemplo que tenemos todos los plugins actualizados. Uno de estos servicios es BrowserScan, del equipo de Rapid7. Accediendo a la URL de BrowserScan comprobaremos si tenemos Java, Adobe y el plugin de quick time actualizado.


En mi caso parece que tengo la versión de Java desactualizada, mas vale que la actualice sino quiero caer en los exploits que están aprovechando la vulnerabilidad 0day.

El uso de este tipo de webs nos ayudarán a tener una de las partes mas importante actualizadas, el navegador y algunos plugins. Ya que los criminales están aprovechando las páginas webs para poder explotar las vulnerabilidades.


[Fuente]

Wednesday, January 9, 2013

[Katana] Suite de Seguridad Portable


Katana una herramienta, bueno mas que herramienta un arma de doble filo que no deberia de faltarnos, la cual viene con distribuciones que se encuentran orientada al Pen-Testing, Auditoría Forense, Recuperación del Sistema, Análisis de Redes y Malware.

Otro pro que tiene Katana es que también viene con aplicaciones portátiles de Windows, como Wireshark, Metasploit y mas...

Distribuciones:


  •     Backtrack
  •     Ophcrack
  •     CAINE
  •     Tails
  •     Ultimate Boot CD
  •     Trinity Rescue Kit
  •     Puppy Linux
  •     Derik’s Boot and Nuke
  •     Kon-Boot




Aplicaciones Portables para ejecutar en Windows:

  •     Metasploit
  •     NMAP
  •     Cain & Able
  •     Cygwin
  •     Wireshark
  •     Firefox
  •     PuTTY
  •     the Unstoppable Copier
  •     OllyDBG
  •     ProcessActivityView
  •     SniffPass Password Sniffer
  •     ClamAV
  •     IECookiesView
  •     MozillaCacheView
  •     FreeOTFE
  •     FindSSN
  •     The Sleuth Kit
  •     OpenOffice



Download

Name: Katana v2.0
File: katana-v2.0.rar
Size: ~ 4 GB
MD5: d77f1fec607657b6d82264e8b5ca47a4
DOWNLOAD:

TORRENT: katana-v2.0.torrent (preferred method)

MIRRORS:


MirrorStatusProviderLocation
http://sourceforge.net/projects/katana-usb/files/CurrentSourceForge
http://mirror.cc.vt.edu/pub/katana/CurrentVirginia TechBlacksburg, Virginia, USA
http://mirror.ece.vt.edu/pub/katana/CurrentVirginia Tech LUUGBlacksburg, Virginia, USA
http://public.acetolyne.net/katana-v2.0.rarCurrent

Saturday, November 10, 2012

[PwnPi v2.0] A Pen Test Drop Box distro for the Raspberry Pi

PwnPi is a Linux-based penetration testing dropbox distribution for the Raspberry Pi. It currently has 114 network security tools pre-installed to aid the penetration tester. It is built on the debian squeeze image from the raspberry pi foundation’s website and uses Xfce as the window manager

Login username and password is root:root
download

Tools List:
list

Download Here