Sunday, 9 February 2014

How to stop hackers from getting your facebook account.

First and foremost, the easiest way for hackers to steal your account is by phishing schemes. All they have to do is create a legitimate looking page telling you that they need your user name and password to log in. There are two main ways this can happen, from within Facebook or via email. From within Facebook, here's the thing to remember... if you are logged in, you WON'T need to log in again short of losing your internet connection. If someone sends you a gift app that requires you to log in to see the gift, DON'T!!! I have made it a point to weed out the crAPPs (as I call them) by removing people from my friends list who send them. One crAPP posted to my wall means you're out!!
Via email, you may receive a legitimate looking email saying that your account has been compromised and have a link within the body of the email to log in. DON'T USE THE LINK!! Instead, go directly to Facebook and attempt to log in as usual. IF your account is truly compromised, you will receive a message from Facebook on attempted login.
To comment on someone's trade note, just navigate to their notes section and find it yourself. If they have multiple notes, ask which one to leave a comment on.
Also, stay away from trading within Facebook's chat or email. Scammers and hackers prefer to "trade" this way because it keeps them from prying eyes... like ours at KTM!

The next way any hacker can get your password is by brute force. These are simple hacking tools that use number/letter combination and try again and again until your password is found. They might need 2 things for this to work. 1) your user name (email account) and 2) possibly your date of birth. These are easily found within your info page within your profile. FIRST... hide these from prying eyes.

Go to Account>Account Settings>Privacy Settings and change your birthday settings to "Only Me".
Then go back to Privacy>Contact Information and set your email to "Only Me".
By doing this, you have just removed the most easily accessible 2/3 of the information any hacker needs.

The final step is your password. This is the single-most important piece of the equation... and you should follow this advice in ALL your important web sites you visit, especially banking, PayPal, eBay, Credit Cards and other critical sites.
MOST brute force hacking tools can only do number/letter combinations up to 8 digits... some can do more. The key here is the combinations of what they can do. I HIGHLY recommend the use of special characters in your password such as _ - + = / \ | * & ^ % $ # @ ! ~ etc. Brute force hackers CAN'T do these symbols! Also, make your password more than 8 characters. Use number/letter/special character combinations with the use of capital letters thrown in.

If you want to make sure you don't forget what it is, use common words, like your own name, but substitute numbers for letters that look similar.
e.g. my name is David Reedy. I can do a password using my name as an example like "Mah1_G33ri" or variations. Notice the underscore? The likelihood of this password being hacked by brute force is slim to none!
The variants make it so that if a brute force hacking tool was used, and it was able to try a new combination every second, it would take at least 12-billion seconds to crack it. How long is 12-billion seconds?? Almost 380 years!!! Long enough for me to not care less if and when they finally hack it!

I hope that this has given you some ideas to better safeguard your personal accounts. And remember, if YOU get hacked, you are going to lose more than your loot and lotto, you're going to potentially lose your well established name and reputation. And others who have come to trust your name and reputation will suffer also when they in turn get scammed by the hacker.

Make sure your personal identity; your email, birth date and password follow the rule of The Lord of the Rings... "Keep it secret. Keep it safe"!

Wednesday, 5 February 2014

Top 10 Ethical Hackers in India | Best Indian Hackers | Indian Ethical Hackers


Ankit Fadia  is an independent computer security and digital intelligence consultant with definitive experience in the field of Internet security based out of the Silicon Valley in California, USA. He has authored 14 internationally best-selling books on numerous topics related to Computer Security that have been widely appreciated by both professionals and industry leaders the world over. His books have sold a record 10 million copies across the globe, have been translated into Japanese, Korean, Portuguese and Polish and are also being used as reference textbooks in some of the most prestigious academic institutions around the world. He was one of eight people named MTV India's Youth Icon of the Year for the year 2008.

Sunny Vaghela is one of the countries pioneer Information Security & Cyber Crime Consultant. The young and dynamic personality of Sunny has not only assisted in solving complex cyber crime cases but has also played an instrumental role in creating awareness about information security and cyber crimes. During his graduation at Nirma University he developed projects like SMS Based Control System, Voice Recognition Based Control System exhibiting his sharp acumen for technology. At the age of 18, Sunny exposed loopholes like SMS & Call Forging in Mobile Networks. The technology that allowed to send SMS or Make Call to any International Number from any number of your choice. At Present, He is Director & Chief Technical Officer at TechDefence Consulting Pvt Ltd which is rapidly growing security services & investigation consulting organization focusing on Cyber Crime Investigations,Cyber Law Consulting,Vulnerability Assessment & Penetration Testing,Information Security Training.

#3 ) Trishneet Arora

Trishneet Arora has authored for book "The Hacking Era” with several technical manuals and given countless lectures, workshops and seminars throughout his career. He trained IPS Officers, Crime Branch Cell, Banks and IT Experts. He  solves cyber crime cases with agencies, Trishneet Arora also known as Social Networking Specialist, solved many cases like Fake Profiles, Tracing on Facebook, Email Tracing and money fraud investigations. He has been interviewed by Various Newspapers, News Channel’s, TV Channels, Blogs and Communities Namely The Economic Times, The Times of India, Indian Express, Dainik Bhaskar, Punjab Kesri, Daily Post, Fastway News, PTC News, The Tribune, Dainik Jagran, Punjabi Tribune, Punjabi Jagran and more. He is currently Chief Technical Officer at TAC Security Solutions. Trishneet and  Mr.Yashwant Sinha (Former Finance Minister of India) were keynote speakers at Bussines Relation Conference, Gujarat


#4 ) Vivek Ramchandran
Vivek Ramachandran is a world renowned security researcher and evangelist. His expertise includes computer and network security, exploit research, wireless security, computer forensics, embedded systems security, compliance and e-Governance. He is the author of the books – “Wireless Penetration Testing using Backtrack” and “The Metasploit Megaprimer”, both up for worldwide release in mid 2011. Vivek is a B.Tech from  and an advisor to the computer science department’s Security Lab. In 2006, Microsoft declared Vivek as one of the winners of the Microsoft Security Shootout Contest held in India among an estimated 65,000 participants. The competition was aimed at finding leading Security Experts in India. Vivek was also awarded a Team Achievement Award by Cisco Systems for his contribution to the 802.1x and Port Security modules in the Catalyst 6500 series of switches. These are high end security features used in Enterprises
#5 ) Koushik Dutta
Koushik Dutta is responsible for Clockworkmod recovery and Rom Manager for Android rooting and the core member of famed UnrEVOked team. He has been a .net developer from heart and had his internship initially at Microsoft and is a former MVP. He decided to leave Microsoft and hack Android cellphoneslike there was no tomorrow. Sony approached him after geohot humped them like anything but he politely declined .
#6 ) Aseem Jakhar
Aseem is a renowned security researcher with extensive experience in system programming, security research and consulting. He has worked on various security software including IBM ISS Proventia UTM appliance, Mirapoint messaging/security appliance, anti-spam engine, anti-virus software, multicast packet reflector, Transparent HTTPS proxy with captive portal, bayesian spam filter to name a few. He is well known in the hacking and security community as the founder of null - The open security community the largest security community in India. The focus and mission of null is advanced security research, sharing information, responsible vulnerability disclosure and assisting Govt./private organizations with security issues.His research includes Linux remote thread injection, automated web application detection and dynamic web filter. He has authored several software projects such as Jugaad, EyePee and Kunsa due to be released under an open source license.
#7 ) Sai Satish
Sai Satish is an young Entrepreneur, Founder & CEO of Indian Servers. Administrator of Andhrahackers (Top hacking awareness forum in INDIA).Author of “HACKING SECRETS” an Internationally sold hacking book, a renowned Ethical Hacker & Cyber Security Expert. Thousands of college students and professionals got benefited by his lectures which are delivered at 90+ colleges all over the WORLD. He worked as Microsoft Student Partner, Corporate .Net Trainer . He was rewarded by IAS officers for pentesting on government sites, which helped to them to improve security and safe transactions and Forensic Investigator. He was interviewed by Many International, national and regional news channels like Dap News(caombodia), AAjtak, The Hindu,Deccan Chronicle, Zee TV,TV9, NTV, Eenadu , Sakshi etc.
#8 ) Benild Joseph
Benild Joseph  the 20 years old world renowned Ethical Hacker | Information Security Consultant | Speaker | Author in Indian IT Industry was born in Calicut, A City of Kerala. Currently Acting as the Chief Executive Officer of “Th3 art of h@ckin9“ – International IT Security Project. He has his credit to many registered and pending patents in cyber forensic and information security domain. He specializes in Web Application security, Penetration testing and Forensic investigation. His research interests include Computer Security, Networking, Data Forensic, Virtualization, Web Application Vulnerability and Information Security. He has been interviewed by several print and online newspapers where he has shared his experiences relating to Ethical Hacking, Scope in Indian Information Security field, Cyber War and Cyber Crimes.
#9 ) Falgun Rathod
Falgun Rathod is one of the countries pioneer Information Security & Cyber Crime Consultant. Falgun has solved number of complex cyber crime cases and has also played an instrumental role in creating awareness about information security and cyber crimes. He is a Founder & Director of Cyber Octet Pvt Ltd - a Company providing Training on Ethical Hacking and Information Security as well as Cyber Crime Consultants. He has been assisting many agencies & companies and conducted numerous workshops and seminars in the Colleges about Information Security and Ethical Hacking. He is also the member of OWASP (open web application security project), invited member at ICTTF (International Cyber Threat Task Force), CSFI (Cyber Security Forum Initiative), DSCI (Data Security Council of India).He is also Invited Article Writer at PenTest Magazine based in Poland. He was featured in March 2012 Issue of PenTest Mag on the Cover Page of Magazine.
#10 ) Rahul  Tyagi 
Rahul  Tyagi  is  a  sovereign  computer  security  consultant  and  has state-of-the-art  familiarity  in the  field of computers.  Recently Tyagi conversed with several media channels to create consciousness in people regarding the threats and terror of hacking. He was also invited as a speaker in the principal ethical hacking conference DEF CON, Chennai where he presented his research paper amongst other security experts. His research paper has also been published globally on exploit-db and packetstormsecurity, which are world renowned research paper database communities. Rahul Tyagi is presently working as the brand ambassador of TCIL-IT Chandigarh as Corporate Ethical Hacking Trainer. He also provides his services to ‘Cyber Security & Anti hacking Organization of India’ as Vice-President. Additionally, he is the Technical Head of News Paper Association of India as well.

Snowden leaks: GCHQ 'attacked Anonymous' hackers

Snowden leaks: GCHQ 'attacked Anonymous' hackers

GCHQ disrupted "hacktivist" communications by using one of their own techniques against them, according to the latest Edward Snowden leaks.
Documents from the whistle-blower published by NBC indicate UK cyberspies used a denial of service attack (DoS) in 2011 to force a chatroom used by the Anonymous collective offline.
A spokeswoman for GCHQ said all the agency's activities were authorised and subject to rigorous oversight.
But others say it raises concerns.
Dr Steven Murdoch, a security researcher at the University of Cambridge, said using a DoS attack to overwhelm a computer server with traffic would have risked disrupting other services.

Introduction to GCHQ

The UK government's communications-focused intelligence agency, employing about 5,000 people.
It stands for Government Communications Headquarters.
The agency is based in Cheltenham, Gloucestershire, and also operates two smaller sites in Cornwall and North Yorkshire.
Its two key roles are:
  • To identify threats from intercepted communications. It says these include terrorism, the spread of nuclear weapons, regional conflicts around the world and threats to the economic prosperity of the UK.
  • To serve as an authority on information assurance - meaning that it advises the government and organisations running the UK's critical infrastructure how to safeguard their systems from interference and disruption.
The foreign secretary is answerable in Parliament for GCHQ's work.
"It's quite possible that the server was used for other purposes which would have been entirely unrelated to Anonymous," he said.
"It's also likely that most of the chat that was going on about Anonymous was not to do with hacking because the people who join Anonymous are fairly wide-ranging in what they think it is legitimate to do.
"Some have gone into criminality but many others just go out and organise protests, letter-writing campaigns and other things that are not criminal."
Campaign group Privacy International is also worried.
"There is no legislation that clearly authorises GCHQ to conduct cyber-attacks," said head of research Eric King.
"So, in the absence of any democratic mechanisms, it appears GCHQ has granted itself the power to carry out the very same offensive attacks politicians have criticised other states for conducting."
The UK government's Cyber Security Strategy document, published in 2011, says officials should take "proactive measures to disrupt threats to our information security", but also notes that any such action should be consistent with freedom of expression and privacy rights.
Hacker arrests The latest documents are published alongside an article part-written by Glenn Greenwald.
The journalist is one of only two people reported to have access to all whistle-blower Edward Snowden's leaked documents.
GCHQ GCHQ has not discussed the specifics of the operations included in the Snowden leaks
The article highlights that the Joint Threat Research Intelligence Group (JTRIG) is the division identified as being responsible for the DoS attack - a unit whose existence had not previously been publicly disclosed.
The documents indicate the unit also spied on and communicated with chatroom users to identify hackers who had stolen information.
In one case, agents are said to have tricked a hacker nicknamed P0ke who claimed to have stolen data from the US government. They did this by sending him a link to a BBC article entitled: "Who loves the hacktivists?"
"Sexy," P0ke is alleged to have commented.
But when he clicked the link it is reported that JTRIG was able to bypass measures he had taken to hide his identity, although it is not clear how.
BBC article GCHQ is said to have tricked one hacktivist by sending him a link to a BBC article
NBC reports that P0ke - a Scandinavian college student - was never arrested despite GCHQ learning his true name.
But the leaks indicate others were imprisoned as a result of JTRIG operations.
One paper highlights the case of Edward Pearson - a hacker known as GZero - who was sentenced to two years in jail in 2012 for illegally acquiring credit and debit card details registered with PayPal.
A transcript of a chatroom conversation indicates that Pearson had contacted GCHQ agents claiming he knew a hacktivist they were investigating, unaware of the agents' true identity.
'Grey area' In addition to Anonymous, the documents list LulzSec, the A-Team and the Syrian Cyber Army as hacktivist groups GCHQ was concerned about.
In one case it appears simply warning activists that carrying out their own DoS attacks was illegal had the desired effect.
NBC reports that the notice was posted via Facebook, Twitter, email, instant messenger and Skype.
One alleged GCHQ document states that one month later 80% of those contacted had stopped using a hacktivist chatroom.
LulzSec logo Several of the Lulzsec hackers have been arrested after carrying out DoS attacks
But the documents also indicate that GCHQ was willing to use DoS attacks itself as part of an operation codenamed Rolling Thunder, which prevented hacktivists using a chatroom for 30 hours in September 2011.
GCHQ has a longstanding policy of not commenting on specific intelligence-gathering procedures, but a spokeswoman said all its work was "carried out in accordance with a strict legal and policy framework".
Even so, one cybersecurity expert said he had mixed feelings about the latest leaks.
"We have to remember that cyberspooks within GCHQ are equally, if not more, skilled than many black-hat hackers, and the tools and techniques they are going to use to fight cybercrime are surely going to be similar to that of the bad guys," said Andrew Miller, chief operating officer at Corero Network.
"Legally, we enter a very grey area here; where members of Lulzsec were arrested and incarcerated for carrying out DoS attacks, but it seems that JTRIG are taking the same approach with impunity."

Wednesday, 22 January 2014

Benefits and Risks of Free Email Services

What is the appeal of free email services?

Many service providers offer free email accounts (e.g., Yahoo!, Hotmail, Gmail). These email services typically provide you with a browser interface to access your mail. In addition to the monetary savings, these services often offer other benefits:
  • accessibility - Because you can access your account(s) from any computer, these services are useful if you cannot be near your computer or are in the process of relocating and do not have an ISP. Even if you are able to access your ISP-based email account remotely, being able to rely on a free email account is ideal if you are using a public computer or a shared wireless hot spot and are concerned about exposing the details of your primary account.
  • competitive features - With so many of these service providers competing for users, they now offer additional features such as large amounts of storage, spam filtering, virus protection, and enhanced fonts and graphics.
  • additional capabilities - It is becoming more common for service providers to package additional software or services (e.g., instant messaging) with their free email accounts to attract customers.
Free email accounts are also effective tools for reducing the amount of spam you receive at your primary email address. Instead of submitting your primary address when shopping online, requesting services, or participating in online forums, you can set up a free secondary address to use (see Reducing Spam for more information).

What risks are associated with free email services?

Although free email services have many benefits, you should not use them to send sensitive information. Because you are not paying for the account, the organization may not have a strong commitment to protecting you from various threats or to offering you the best service. Some of the elements you risk are
  • security - If your login, password, or messages are sent in plain text, they may easily be intercepted. If a service provider offers SSL encryption, you should use it. You can find out whether this is available by looking for a "secure mode" or by replacing the "http:" in the URL with "https:" (see Protecting Your Privacy for more information).
  • privacy - You aren't paying for your email account, but the service provider has to find some way to recover the costs of providing the service. One way of generating revenue is to sell advertising space, but another is to sell or trade information. Make sure to read the service provider's privacy policy or terms of use to see if your name, your email address, the email addresses in your address book, or any of the information in your profile has the potential of being given to other organizations (see Protecting Your Privacy for more information). If you are considering forwarding your work email to a free email account, check with your employer first. You do not want to violate any established security policies.
  • reliability - Although you may be able to access your account from any computer, you need to make sure that the account is going to be available when you want to access it. Familiarize yourself with the service provider's terms of service so that you know exactly what they have committed to providing you. For example, if the service ends or your account disappears, can you retrieve your messages? Does the service provider give you the ability to download messages that you want to archive onto your machine? Also, if you happen to be in a different time zone than the provider, you may find that their server maintenance interferes with your normal email routine.

Shopping Safely Online

Why do online shoppers have to take special precautions?

The internet offers a convenience that is not available from any other shopping outlet. From the comfort of your home, you can search for items from countless vendors, compare prices with a few simple mouse clicks, and make purchases without waiting in line. However, the internet is also convenient for attackers, giving them multiple ways to access the personal and financial information of unsuspecting shoppers. Attackers who are able to obtain this information may use it for their own financial gain, either by making purchases themselves or by selling the information to someone else.

How do attackers target online shoppers?

There are three common ways that attackers can take advantage of online shoppers:
  • Targeting vulnerable computers - If you do not take steps to protect your computer from viruses or other malicious code, an attacker may be able to gain access to your computer and all of the information on it. It is also important for vendors to protect their computers to prevent attackers from accessing customer databases.
  • Creating fraudulent sites and email messages - Unlike traditional shopping, where you know that a store is actually the store it claims to be, attackers can create malicious websites that appear to be legitimate or email messages that appear to have been sent from a legitimate source. Charities may also be misrepresented in this way, especially after natural disasters or during holiday seasons. Attackers create these malicious sites and email messages to try to convince you to supply personal and financial information.
  • Intercepting insecure transactions - If a vendor does not use encryption, an attacker may be able to intercept your information as it is being transmitted.

How can you protect yourself?

  • Use and maintain anti-virus software, a firewall, and anti-spyware software - Protect yourself against viruses and Trojan horses that may steal or modify the data on your own computer and leave you vulnerable by using anti-virus software and a firewall (see Understanding Anti-Virus Software and Understanding Firewalls for more information). Make sure to keep your virus definitions up to date. Spyware or adware hidden in software programs may also give attackers access to your data, so use a legitimate anti-spyware program to scan your computer and remove any of these files (see Recognizing and Avoiding Spyware for more information).
  • Keep software, particularly your web browser, up to date - Install software updates so that attackers cannot take advantage of known problems or vulnerabilities (see Understanding Patches for more information). Many operating systems offer automatic updates. If this option is available, you should enable it.
  • Evaluate your software's settings - The default settings of most software enable all available functionality. However, attackers may be able to take advantage of this functionality to access your computer (see Evaluating Your Web Browser's Security Settings and the paper Securing Your Web Browser for more information). It is especially important to check the settings for software that connects to the internet (browsers, email clients, etc.). Apply the highest level of security available that still gives you the functionality you need.
  • Do business with reputable vendors - Before providing any personal or financial information, make sure that you are interacting with a reputable, established vendor. Some attackers may try to trick you by creating malicious websites that appear to be legitimate, so you should verify the legitimacy before supplying any information (see Avoiding Social Engineering and Phishing Attacks and Understanding Web Site Certificates for more information). Attackers may obtain a site certificate for a malicious website to appear more authentic, so review the certificate information, particularly the "issued to" information. Locate and note phone numbers and physical addresses of vendors in case there is a problem with your transaction or your bill.
  • Take advantage of security features - Passwords and other security features add layers of protection if used appropriately (see Choosing and Protecting Passwords and Supplementing Passwords for more information).
  • Be wary of emails requesting information - Attackers may attempt to gather information by sending emails requesting that you confirm purchase or account information (see Avoiding Social Engineering and Phishing Attacks for more information). Legitimate businesses will not solicit this type of information through email. Do not provide sensitive information through email, and use caution when clicking on links in email messages (see the paper Recognizing and Avoiding Email Scans for more information).
  • Check privacy policies - Before providing personal or financial information, check the website's privacy policy. Make sure you understand how your information will be stored and used (see Protecting Your Privacy for more information).
  • Make sure your information is being encrypted - Many sites use SSL, or secure sockets layer, to encrypt information. Indications that your information will be encrypted include a URL that begins with "https:" instead of "http:" and a padlock icon. If the padlock is closed, the information is encrypted. The location of the icon varies by browser; for example, it may be to the right of the address bar or at the bottom of the window. Some attackers try to trick users by adding a fake padlock icon, so make sure that the icon is in the appropriate location for your browser.
  • Use a credit card - There are laws to limit your liability for fraudulent credit card charges, and you may not have the same level of protection for your debit card. Additionally, because a debit card draws money directly from your bank account, unauthorized charges could leave you with insufficient funds to pay other bills. You can further minimize damage by using a single credit card with a low credit line for all of your online purchases.
  • Check your statements - Keep a record of your purchases and copies of confirmation pages, and compare them to your bank statements. If there is a discrepancy, report it immediately (see Preventing and Responding to Identity Theft for more information).

Risks of File-Sharing Technology

What is file sharing?

File sharing involves using technology that allows internet users to share files that are housed on their individual computers. Peer-to-peer (P2P) applications, such as those used to share music files, are some of the most common forms of file-sharing technology. However, P2P applications introduce security risks that may put your information or your computer in jeopardy.

What risks does file-sharing technology introduce?

  • Installation of malicious code - When you use P2P applications, it is difficult, if not impossible, to verify that the source of the files is trustworthy. These applications are often used by attackers to transmit malicious code. Attackers may incorporate spyware, viruses, Trojan horses, or worms into the files. When you download the files, your computer becomes infected (see Recognizing and Avoiding Spyware and Recovering from Viruses, Worms, and Trojan Horses for more information).
  • Exposure of sensitive or personal information - By using P2P applications, you may be giving other users access to personal information. Whether it's because certain directories are accessible or because you provide personal information to what you believe to be a trusted person or organization, unauthorized people may be able to access your financial or medical data, personal documents, sensitive corporate information, or other personal information. Once information has been exposed to unauthorized people, it's difficult to know how many people have accessed it. The availability of this information may increase your risk of identity theft (see Protecting Your Privacy and Avoiding Social Engineering and Phishing Attacks for more information).
  • Susceptibility to attack - Some P2P applications may ask you to open certain ports on your firewall to transmit the files. However, opening some of these ports may give attackers access to your computer or enable them to attack your computer by taking advantage of any vulnerabilities that may exist in the P2P application. There are some P2P applications that can modify and penetrate firewalls themselves, without your knowledge.
  • Denial of service - Downloading files causes a significant amount of traffic over the network. This activity may reduce the availability of certain programs on your computer or may limit your access to the internet (see Understanding Denial-of-Service Attacks for more information).
  • Prosecution - Files shared through P2P applications may include pirated software, copyrighted material, or pornography. If you download these, even unknowingly, you may be faced with fines or other legal action. If your computer is on a company network and exposes customer information, both you and your company may be liable.

How can you minimize these risks?

The best way to eliminate these risks is to avoid using P2P applications. However, if you choose to use this technology, you can follow some good security practices to minimize your risk:
  • use and maintain anti-virus software - Anti-virus software recognizes and protects your computer against most known viruses. However, attackers are continually writing new viruses, so it is important to keep your anti-virus software current (see Understanding Anti-Virus Software for more information).
  • install or enable a firewall - Firewalls may be able to prevent some types of infection by blocking malicious traffic before it can enter your computer (see Understanding Firewalls for more information). Some operating systems actually include a firewall, but you need to make sure it is enabled.

Recovering from Viruses, Worms, and Trojan Horses

How do you know your computer is infected?

Unfortunately, there is no particular way to identify that your computer has been infected with malicious code. Some infections may completely destroy files and shut down your computer, while others may only subtly affect your computer's normal operations. Be aware of any unusual or unexpected behaviors. If you are running anti-virus software, it may alert you that it has found malicious code on your computer. The anti-virus software may be able to clean the malicious code automatically, but if it can't, you will need to take additional steps.

What can you do if you are infected?

  1. Minimize the damage - If you are at work and have access to an IT department, contact them immediately. The sooner they can investigate and clean your computer, the less damage to your computer and other computers on the network. If you are on your home computer or a laptop, disconnect your computer from the internet. By removing the internet connection, you prevent an attacker or virus from being able to access your computer and perform tasks such as locating personal data, manipulating or deleting files, or using your computer to attack other computers.
  2. Remove the malicious code - If you have anti-virus software installed on your computer, update the virus definitions (if possible), and perform a manual scan of your entire system. If you do not have anti-virus software, you can purchase it at a local computer store (see Understanding Anti-Virus Software for more information). If the software can't locate and remove the infection, you may need to reinstall your operating system, usually with a system restore disk that is often supplied with a new computer. Note that reinstalling or restoring the operating system typically erases all of your files and any additional software that you have installed on your computer. After reinstalling the operating system and any other software, install all of the appropriate patches to fix known vulnerabilities (see Understanding Patches for more information).

How can you reduce the risk of another infection?

Dealing with the presence of malicious code on your computer can be a frustrating experience that can cost you time, money, and data. The following recommendations will build your defense against future infections:
  • use and maintain anti-virus software - Anti-virus software recognizes and protects your computer against most known viruses. However, attackers are continually writing new viruses, so it is important to keep your anti-virus software current (see Understanding Anti-Virus Software for more information).
  • change your passwords - Your original passwords may have been compromised during the infection, so you should change them. This includes passwords for web sites that may have been cached in your browser. Make the passwords difficult for attackers to guess (see Choosing and Protecting Passwords for more information).
  • keep software up to date - Install software patches so that attackers can't take advantage of known problems or vulnerabilities (see Understanding Patches for more information). Many operating systems offer automatic updates. If this option is available, you should enable it.
  • install or enable a firewall - Firewalls may be able to prevent some types of infection by blocking malicious traffic before it can enter your computer (see Understanding Firewalls for more information). Some operating systems actually include a firewall, but you need to make sure it is enabled.
  • use anti-spyware tools - Spyware is a common source of viruses, but you can minimize the number of infections by using a legitimate program that identifies and removes spyware (see Recognizing and Avoiding Spyware for more information).
  • follow good security practices - Take appropriate precautions when using email and web browsers so that you reduce the risk that your actions will trigger an infection (see other US-CERT security tips for more information).
As a precaution, maintain backups of your files on CDs or DVDs so that you have saved copies if you do get infected again.

Malware Targeting Point of Sale Systems

Systems Affected

Point of Sale Systems

Overview

Point of Sale Systems
When consumers purchase goods or services from a retailer, the transaction is processed through what are commonly referred to as Point of Sale (POS) systems. POS systems consist of the hardware (e.g. the equipment used to swipe a credit or debit card and the computer or mobile device attached to it) as well as the software that tells the hardware what to do with the information it captures.
When consumers use a credit or debit card at a POS system, the information stored on the magnetic stripe of the card is collected and processed by the attached computer or device. The data stored on the magnetic stripe is referred to as Track 1 and Track 2 data. Track 1 data is information associated with the actual account; it includes items such as the cardholder’s name as well as the account number. Track 2 data contains information such as the credit card number and expiration date.

Description

POS Targeting
For quite some time, cyber criminals have been targeting consumer data entered in POS systems. In some circumstances, criminals attach a physical device to the POS system to collect card data, which is referred to as skimming. In other cases, cyber criminals deliver malware which acquires card data as it passes through a POS system, eventually exfiltrating the desired data back to the criminal. Once the cybercriminal receives the data, it is often trafficked to other suspects who use the data to create fraudulent credit and debit cards.
As POS systems are connected to computers or devices, they are also often enabled to access the internet and email services. Therefore malicious links or attachments in emails as well as malicious websites can be accessed and malware may subsequently be downloaded by an end user of a POS system. The return on investment is much higher for a criminal to infect one POS system that will yield card data from multiple consumers.

Impact

There are several types of POS malware in use, many of which use a memory scraping technique to locate specific card data. Dexter, for example, parses memory dumps of specific POS software related processes looking for Track 1 and Track 2 data. Stardust, a variant of Dexter not only extracts the same track data from system memory, it also extracts the same type of information from internal network traffic. Researchers surmise that Dexter and some of its variants could be delivered to the POS systems via phishing emails or the malicious actors could be taking advantage of default credentials to access the systems remotely, both of which are common infection vectors. Network and host based vulnerabilities, such as weak credentials accessible over Remote Desktop, open wireless networks that include a POS machine and physical access (unauthorized or misuse) are all also candidates for infection.

Solution

POS System Owner Best Practices
Owners and operators of POS systems should follow best practices to increase the security of POS systems and prevent unauthorized access.
  • Use Strong Passwords: During the installation of POS systems, installers often use the default passwords for simplicity on initial setup. Unfortunately, the default passwords can be easily obtained online by cybercriminals. It is highly recommended that business owners change passwords to their POS systems on a regular basis, using unique account names and complex passwords.
  • Update POS Software Applications: Ensure that POS software applications are using the latest updated software applications and software application patches. POS systems, in the same way as computers, are vulnerable to malware attacks when required updates are not downloaded and installed on a timely basis.
  • Install a Firewall: Firewalls should be utilized to protect POS systems from outside attacks. A firewall can prevent unauthorized access to, or from, a private network by screening out traffic from hackers, viruses, worms, or other types of malware specifically designed to compromise a POS system.
  • Use Antivirus: Antivirus programs work to recognize software that fits its current definition of being malicious and attempts to restrict that malware’s access to the systems. It is important to continually update the antivirus programs for them to be effective on a POS network.
  • Restrict Access to Internet: Restrict access to POS system computers or terminals to prevent users from accidentally exposing the POS system to security threats existing on the internet. POS systems should only be utilized online to conduct POS related activities and not for general internet use.
  • Disallow Remote Access: Remote access allows a user to log into a system as an authorized user without being physically present. Cyber Criminals can exploit remote access configurations on POS systems to gain access to these networks. To prevent unauthorized access, it is important to disallow remote access to the POS network at all times.
Consumer Remediation
Fraudulent charges to a credit card can often be remediated quickly by the issuing financial institution with little to no impact on the consumer. However, unauthorized withdrawals from a debit card (which is tied to a checking account) could have a cascading impact to include bounced checks and late-payment fees.
Consumers should routinely change debit card PINs. Contact or visit your financial institutions website to learn more about available fraud liability protection programs for your debit and credit card accounts. Some institutions offer debit card protections similar to or the same as credit card protections.
If consumers have a reason to believe their credit or debit card information has been compromised, several cautionary steps to protect funds and prevent identity theft include changing online passwords and PINs used at ATMs and POS systems; requesting a replacement card; monitoring account activity closely; and placing a security freeze on all three national credit reports (Equifax, Experian and TransUnion). A freeze will block access to your credit file by lenders you do not already do business with. Under federal law, consumers are also entitled to one free copy of their credit report every twelve months through AnnualCreditReport.com.