World cyber news is online news media.we bought daily hottest news occuring in the world related to cyber.. We propogate news specially related to hacking, technology updates , cyber world updates....

Wednesday, May 18, 2011

How to Protect your Mac from Recent Malware

4:59 PM Posted by Anonymous

Recently a new series of Trojan horse attempts have targeted OS X users with downloadable malware applications that try to lure you to providing personal information, and with malicious Web sites that trick you into downloading malware onto your systems. Despite warnings about these new malware attempts, numerous people have fallen for these efforts and have downloaded and installed the malware distributed by these sites.

In the past few days since these scams surfaced, a number of MacFixIt readers have contacted us wondering about whether or not their systems are safe after having seen the site on their systems or even downloading the files to their computers. They want to know what they can do to check for and remove the malware.

What the recent malware does
If you have seen the "Apple Security Center" Web site and have clicked on the "Remove All" button, the site will download an installer file for malware that runs locally on your system. The program is distributed in several forms that so far have taken the names "Mac Defender," "Mac Security," and "Mac Protector." When installed it will run in the background and launch pornographic Web sites and other unwanted content, and show a fairly clean and crisp-looking scanner interface that will ask you to purchase an upgrade.

If you provide your information to the program, you chance identity theft and charges to your credit cards.


Removing it!
Luckily the malware is fairly easy to remove, as it basically runs as a background process on your system that is launched by an action the user takes (logging in, etc.). If you have not installed any programs or opened any files downloaded from these sites, then you should be good to go and can just delete the downloaded files. If you have only visited the site and have not downloaded any files, then you do not need to do anything.

However, if you have opened the downloaded files and especially if you are seeing the malicious behaivor (unwanted pornographic sites randomly opening), or the scanner program launching and saying you have infected files, then you will need to check for and remove the program. To remove it, follow these steps:

  1. Shut it down.
    Open the Activity Monitor utility and perform a search for the malware (or browse through the list of running processes for it--sort by name to prevent the list from jumping around). The malware should be called "MacDefender," "MacSecurity," or "MacProtector" and will be running under the current user's name (see the "User" column of activity monitor). Reputable antivirus software for your system will be running under the user name "root" and will have required a full installation that required you to supply your administrator credentials.

    With the malware selected in Activity Monitor, click the "Quit Process" button and confirm to quit it (use the force-quit option if it will not quit).

    If you want to use the Terminal to do this, you can run the following command to kill the processes by name (the "sudo" portion may not be needed, but this will ensure the system can fully kill the running processes):

    sudo killall macdefender macsecurity macprotector

  2. Remove the program.
    Go to the /Applications folder and move the program to the trash (it should likewise be called "MacDefender," "Mac Security," or "Mac Protector"). Also locate the installer file (likely in your Downloads directory, or wherever you have Safari store downloaded items) and move it to the trash as well. When you have done this, empty the trash.

  3. Remove references to the program.
    So far the program is launched at log-in by the system's "Login Items" feature. Go to the "Accounts" system preferences and choose your account name. Then go to the "Login Items" tab and remove any reference to the software from that list.

Ongoing protection
With the malware removed your system should be good to go; however, there is always the possibility that the malware will change in the future and adopt a new name or a new method of trying to trick users. Generally malware is more prevalent on underground, software piracy, and pornographic Web sites, but numerous people have reported the current Trojans showing up when browsing MSN and other reputable sites. Therefore, in order to better protect yourself you may need more than basic Internet "street smarts." To better protect your system, try some of the following suggestions:

  1. Disable auto-handling of files
    Apple supplies a few options to automatically handle files, including the option in Safari to automatically open "Safe" files. Unfortunately the files that Safari considers to be "Safe" are not always so. Therefore, go to Safari's preferences and uncheck the option to open safe files.

  2. Always manually install programs or open documents

    In addition to Safari, check your other Internet-based programs such as e-mail clients, chat programs, and Web browsers to see if they automatically launch files received from the Internet. For instance, Mail has an option to automatically add iCal invites to your calendars. Turn this feature off and manually click on any received invitations only after you have confirmed they are legitimate. Do this for all files received on your system.

  3. Install a reputable malware scanner.

    There are a number of reputable malware scanners out there, so purchase one, install it, and keep it updated with the latest malware definitions. Some of these scanners are free, and others are commercial products (this list is not complete):

    1. Sophos Antivirus (Mac Home edition)--This is a reputable package that has a free "Home" version available for Mac users.
    2. MacScan--This is distributed by the "SecureMac" developers who run the SecureMac.com blog on Mac malware and other security threats.
    3. Intego VirusBarrier--Another long-standing Mac antivirus utility, VirusBarrier has tackled this threat from when it first came out.
    4. Kapersky--Kapersky is a reuptable program for Windows and Linux, and also has an option for OS X users. Some virtualization programs for OS X ship with trials of Kapersky antivirus.
    5. ClamXav--This is a popular and free open-source antivirus scanner.
    6. iAntivirus--this is a free Mac-specific virus scanner for OS X users.
    7. Avast--This is a commercial antivirus suite that has been developed for OS X, and is a reputable option for Windows as well.
    8. MacKeeper--This is a maintenance and OS tweaking tool that has a ClamAV client
    9. Norton Antivirus--One of the longest-standing antivirus and security suites for OS X.
    10. McAfee VirusScan--McAfee's VirusScan developed from the original "Virex" for Mac, and has been developed since into a solid option for OS X users.
  4. Set up specific downloads folders
    Know where your programs download files on your system. By default most will use the system's Downloads folder; however, some will place files in other locations on your system. Here are some common folders where files may be downloaded:

    1. /username/Downloads
    2. /username/Public
    3. /username/Documents/FOLDER
    4. /username/Library/Mail Downloads
    5. /username/Library/Application Support
    6. /username/Library/FOLDER

    In these paths, the name "FOLDER" can be the name of the application or a designated downloads folder for that application. For instance, the downloads folder for Mail is called "Mail Downloads" where various attachments are stored. If possible, set up your programs to download files to the same folder so files can be easily managed. Do this for chat programs, e-mail clients, and Web browsers.

    Protect your backups by excluding these download folders from them. This can be done in Time Machine's preferences or in the settings for a drive cloning utility if you use one.

    Additionally, set up an antivirus utility to regularly scan these download folders for threats. If you set your scanner, do check these folders "on access," then they will check files as they are added to the folders. Currently it is not necessary to scan your whole system "on access" (though this is an option) but I would recommend regularly scanning the entire user folder periodically (once a week, or once a month) to cover all the less commonly used download folders that may have been set up by various programs you use.



Source:-
http://reviews.cnet.com/8301-13727_7-20063683-263.html

Cyber-Crooks Eye Apple Macs with Fake Anti-Malware

4:55 PM Posted by Anonymous

(Reuters) - The days when Mac users need not worry about their computers getting infected with malicious software may be coming to an end.

Internet security experts say that cyber-criminals have begun targeting users of the increasingly popular computers from Apple Inc with one of the most pernicious types of malware: fake anti-virus programs.

To date, hackers have focused on writing malicious software for machines running Microsoft Corp's Windows operating system, which inhabits more than nine of every 10 PCs.

But Macs grow in number, they are becoming more attractive targets.

"Only once a platform has a certain level of market share does it become profitable for malware to attack it," said Dino Dai Zovi, co-author of The Mac Hacker's Handbook. "As the Mac becomes more popular there will be more and more threats."

Security firm McAfee has seen "a steady stream" of these anti-malware viruses appear over the Internet in the past week as it scours the Web for malicious software, said Dave Marcus, one of the company's top researchers.

The fake anti-virus malware is downloaded when people click on links from tainted search engine results for popular queries, Marcus said. It also spreads when users click on links to malicious sites that might be included in emails, Tweets or Facebook messages.

A spokesman for Apple declined comment.

Enforcing cybersecurity is becoming increasingly difficult with the proliferation in recent years of interconnected devices. The hacking of Sony's PlayStation Network -- which unearthed data on more than 100 million users in the largest single Internet hacking scheme ever -- underscored how exposed consumers can be.

Malware ranges from software that runs in the background to break into private data, to programs such as fake anti-virus software intended to help hackers profit.

These programs cause messages to pop up saying a machine has been infected with a virus. They offer to sell a fake anti-virus software package to clean up the problem. If the user pays the $80 to $100 for the software, the messages generally disappear.

But if the user fails to pony up, the annoying messages persist.

"This is the first time we've seen something hit en masse," said Chet Wisniewski, senior security adviser with anti-virus software maker Sophos, a rival of McAfee.

Wisniewski's company located a version of the fake anti-virus software for Macs that caused pornography to show up on a machine's screen every few minutes, to convince users their machines did indeed need to be cleaned of malware.

Sophos is one of a handful of security firms that sell anti-virus software for Macs. Others include McAfee and Symantec Corp. Apple already includes basic anti-virus software as part of its Mac OS X operating system.

Independent Mac security experts believe there is enough security built into the OS X operating system to protect users, given the current level of risk.

If users want extra protection, they should obtain anti-virus software from a company that they are sure is a legitimate vendor, said Dino Dai Zovi, co-author of The Mac Hacker's Handbook. He advised users to obtain that software through the Mac App Store.

One day, he said, it will become necessary to purchase special protection for Macs, but that time has not yet arrived.

Source:- http://www.reuters.com/article/2011/05/17/us-apple-malware-idUSTRE74G60M20110517

Cyberwarfare May Be A Bust For Many Defense Contractors

4:48 PM Posted by Anonymous

Source: Loren Thomson Forbes

As federal spending on national security has leveled off in recent years, big defense contractors have worked hard to secure a role in one of the few market segments expected to keep growing: cyberwarfare. It’s a relatively new field where the terminology hasn’t stabilized yet, but for the purposes of this posting, cyberwarfare means three things: attacking enemy networks, exploiting enemy information flows, and defending friendly networks. Most of the money Washington is currently spending on cyberwarfare goes to the latter activity — securing friendly networks — but offensive activities seem to be growing faster over time. They’re really just different sides of the same coin, since it’s hard to be good at defending computer networks if you don’t have a thorough understanding of how to attack them.

The cyber goldrush was sparked in 2008 when President Bush signed two directives establishing a Comprehensive National Cybersecurity Initiative in response to the growing number of digital assaults on federal networks. The initiative was a signal to industry that a new demand driver had appeared in the marketplace just as everyone was getting ready for a prolonged downturn in military purchases. Seeing few other domestic opportunities on which to place bets with the cash they had accumulated during flush years, military contractors poured into the cyberwarfare field, building operations centers, purchasing niche players, and competing aggressively for contracts. The thinking was that cyber threats would keep proliferating for the foreseeable future, and defense companies were more likely to have the necessary clearances and market knowledge to compete in cyberwarfare than outsiders like Google or Microsoft.

No doubt about it, the cyberwarfare market has grown fast, helped along by an Obama Administration commitment to expand and refine the digital security efforts of its predecessors. Within months after taking office, President Obama established an executive-branch cybersecurity coordinator and a new Cyber Command colocated with the super-secret National Security Agency at Fort Meade, MD. NSA does most of the government’s eavesdropping, so putting the command nearby and making its head the same general who runs the spy agency was a no brainer: NSA already had the ability to monitor internet traffic for hackers and other malefactors. Setting up the new command, staffing components from each military service, and implementing more stringent network security procedures at each federal agency will generate about $9 billion in federal outlays this year. Additional billions will be spent on classified programs to probe and monitor foreign networks, such as those in China.

But even as the government’s cyberwarfare effort expands, some industry executives are beginning to wonder just how lucrative this new opportunity is likely to be. They already know it can’t fill the revenue hole created by cancellation of dozens of weapons programs in recent years, and now they’re starting to suspect the cyber field is so hyper-competitive and volatile they can’t even count on it for significant earnings anytime soon. Once you get past all the fashionable rhetoric about information-age warfare and anarchy on the web, it’s easy to see why they might be having second thoughts. Let’s consider the many ways in which the cyberwarfare market should raise red flags for investors.

The first thing to understand about the cyberwarfare market is that, at least by federal standards, it just isn’t very big. The $9 billion being spent this year on so-called information assurance and security activities is barely one day of federal spending at present rates, and it is fragmented among numerous agencies. It’s true that the lion’s share of funding goes to the Department of Defense, which oversees additional billions spent on network attack and exploitation, but in an organization that annually passes out $400 billion in contracts, it still doesn’t amount to much. Market research firm Input projects federal cybersecurity funding will increase 9% annually through 2015, but the government is entering a period of severe fiscal austerity and there are many other claimants for government dollars. With every major contractor in the business straining to get a piece of this relatively small pie, the prospects for making a killing are not high.

A second problem with the cyberwarfare business is that threats are diverse and continuously evolving, which means it is hard for contractors to establish durable franchises. When companies compete to build military hardware, they expect that once a contract is won they will be the sole supplier of a weapon system for a decade or longer. But in cyberwarfare the government’s needs keep changing because new threats emerge on a weekly basis. For instance, the deluge of WikiLeaks that has embarrassed policymakers in recent months has shifted attention from keeping hackers out of networks to keeping information in, which turns out to be a rather different challenge. The dynamism of cyber threats combined with the slow pace of federal acquisition procedures is a prescription for continuous frustration among contractors.

A third issue facing companies pursuing cyberwarfare opportunities is the relatively low barriers to entry in the current market. That’s probably less true in the offensive segment of the market, where activities are so secret that companies must have special qualifications to bid, but on the defensive side of the ledger there are dozens of contractors and new niche players are constantly emerging. The cyberwarfare space is still wide open to any company that comes up with a point solution to an urgent problem, which means yesterday’s winners can turn into today’s losers. That’s good for aggressive, agile companies like Raytheon that are willing to take risks and buy up niche players as they prove themselves, but some of the bigger companies in the defense business aren’t accustomed to having so many competitors jostling for attention.

A fourth and related problem in the cyberwarfare space is the shortage of available talent, particularly in network attack and exploitation skills. The cyberwarfare market grew so fast that it outstripped available labor pools, so companies now find themselves bidding against each other and the federal customer for scarce skills. It’s not that finding cyber specialists is hard, but securing the necessary clearances (foreigners need not apply) and keeping them trained so they can respond to the latest requirements is a constant challenge. This probably works to the advantage of Lockheed Martin, which is the biggest player in the federal information services market, because it has the mass and resources to keep up with changing needs, but for smaller players it’s a big problem. Lockheed has recently won several major cyberwarfare awards at the expense of competitors, and seems to be a preferred destination for many specialists in the field.

A fifth difficulty in the government cyberwarfare market is the variability of management quality from agency to agency on network-related matters. Industry insiders generally agree that the National Security Agency has the greatest depth and breadth of expertise, because it has been working cyber issues far longer than other agencies. Executive expertise at the Department of Defense is more uneven, and at the Department of Homeland Security it is frequently deficient. These problems are most apparent at the program manager level, where middle-level executives may lack the experience to select among competing solutions to a problem. The job classification process and compensation levels prevailing in the federal civil service are not well suited for putting the best people into positions overseeing cyberwarfare work.

A final, chronic defect in the cyberwarfare market is the loose coordination of federal efforts to secure networks, not just between agencies but even within them. For example, at the same time that the Navy has stood up a cyber command to protect its warfighting nets, it has begun implementing a new information architecture called the Next Generation Enterprise Network likely to be more vulnerable to hackers and spies. The new network replaces a single system integrator with multiple teams of contractors who must compete annually for work, creating the kinds of seams and discontinuities intruders might seek to exploit. The fact a military service that invented the concept of network-centric warfare could pursue such an architecture at this late date suggests that in some parts of the federal government, nobody is really in charge of cyber policy or has the authority to mandate security standards.

So far, these various drawbacks have not discouraged big contractors from continuing to pursue cyberwarfare opportunities. The most aggressive players at present seem to be Raytheon, Science Applications International, General Dynamics and Lockheed Martin, but other players like BAE Systems and Boeing are rapidly bulking up. In other segments of the national-security marketplace, two or three of these companies would eventually emerge as the dominant players, and the rest would move on. But cyberwarfare isn’t like other market segments — it is still in flux, and may remain that way for a long time to come. That means even if government spending on cyberwarfare keeps growing, some players straining to get into the business are not going to be happy with how this new opportunity works out.

Tuesday, May 17, 2011

Higher Internet Penetration May Open Up Nigeria to Cyber Attacks

8:32 PM Posted by Anonymous

Nigeria’s rising internet penetration rate poses a significant threat to critical sectors of the economy as the level of cybercrime activities may increase tremendously in the coming years, analysts told Business Day

Though the nation’s internet penetration rate remains low at 28.9 percent according to internetworldstats, Nigeria is still

ranked amongst the top ten perpetuators of cybercrime globally.

“The United States (US) and the United Kingdom (UK) lead the global cybercrime index but that’s understandable considering their high internet penetration rate at 77.3 percent and 82.5 percent respectively. In our case, we have a low penetration rate and still we are most known for cybercrime. This is a worrying situation because growth in the number of internet users in Nigeria would also translate into an explosion of cybercrime activities”, a prominent analyst told Business Day.

Echoing the views of the analyst, Farida Waziri, chairman, Economic and Financial Crimes Commission (EFCC) told Business Day in an interview recently that the challenge for Nigeria was how to put in place remedial measures that will ensure that with higher internet connectivity, crime does not necessarily follow suit. “What should be frightening for us is that only about 20 percent of the West African population has access to internet connectivity.

“It may well mean that if we have the level of connectivity of Europe and America, Nigeria will perpetually remain on the top 10 global cyber crime index”, she added. Giving in sight into how the internet access market had fared with regard to the coming of the cables, Mohammed Rudman, managing director, Internet Exchange Point of Nigeria (IXPN) told Business Day that the internet submarine fibre capacity would increase by a whooping 3, 967 percent by the end of 2011.

This is in light of the arrival of the much anticipated West African Cable System (WACS) being constructed from Europe to Africa – an initiative operated by nine countries (MTN Group inclusive), and expected to berth on the coast of Nigeria by the end of the first quarter of 2011. In the preceding year however, submarine fibre capacity had increased by 1, 683 percent. According to IXPN MD, the low cost of internet access will allow for very high internet penetration in the country.

Industry watchers say that with growing internet penetration, Nigeria appears increasingly vulnerable to cyber attacks due to government’s inability to put in place requisite laws necessary to prosecute cybercriminals. According to the analyst, top companies and even banks have also failed to brand themselves as cybersecurity conscious, leaving them exposed to online attacks.

Stakeholders have warned that for the future of Nigeria’s Information Technology (IT) sector to be effectively guaranteed, proper legal and institutional framework to secure computer systems and networks in the country should be put in place. According to them, the fact that cybercrime is not denoted in the constitution as a crime poses challenges and dilemmas for cyber-security in Nigeria.

Business Day gathered that preparation for the April general elections had delayed the passage of the cybercrime bill by the National Assembly. Informed sources told Business Day that the upper legislative chamber would likely pass the bill in the second quarter of 2011. “The structure of fighting cybercrime is the law. The foundation of the law in fighting any crime is the evidence.

“With all the evidence in the world and an Evidence law that does not recognise the existence of a computer; all cases brought to court will be dead on arrival. The bill had gone through second reading but unfortunately with the elections and the consequent constitutional amendment that were required most amendments in the National Assembly took the back burner”, one source told Business Day.

Gbenga Adesanya, a telecom analyst, maintained that Nigeria’s notoriety for cybercrime is already raising fears that the country may face a slow down in foreign direct investment in the telecoms as well as the financial sectors. Another analyst say that cybercrime laws are necessary today because intelligent networks and systems are increasingly been employed to run mission critical services and sensitive processes in a number of sectors that are vital to our national economy.

“Given the nexus between these vital sectors and our national economy, they constitute critical sectors to our national economic and security interests. Thus, computer systems and networks running those sectors constitute critical information infrastructure – because their impairment would have a direct and expansive negative impact on our overall economy and wellbeing”, Basil Udotai, managing partner, Technology Advisor, posited.

Cyber Crime Pays – And Now You Can Profit From It, Too

8:29 PM Posted by Anonymous ,

Do you want to score big in the stock market? Then recognize an unstoppable trend and get on the gravy train before it’s too late.

In the 80s, for example, investors scored big in cable television and cellphones. Huge money was made again in the 90s on internet and technology shares. Commodities like oil and gas – and gold and silver – made investors millions over the past decade. Now an even bigger trend is emerging. Yet I estimate that not one investor in 10 has a nickel invested yet.

Consider this your wake-up call.

The internet was originally intended for a few thousand researchers, not billions of users who don’t know or trust each other. The designers placed a premium on ease of use and decentralization, not privacy and security. They never dreamed the internet would ultimately be used for trillions of commercial transactions.

And where there are great gobs of money, you will always find thieves…

Cyber Crime Tops Physical Crime in 2011

Last year, for example, one out of every four companies had information, goods or money successfully stolen by cyber criminals. (For the first year ever, the total cost of electronic theft actually topped that of physical theft.) Your social security number, personal history and medical information, your credit card numbers, even the cash you have in trusted financial institutions are all at potential risk.

You may have read the reports a few weeks ago that Sony was forced to shut down its PlayStation network due to hackers who stole users’ information. Even top technology companies are often powerless to stop cyber crime. Sony recently admitted that it had already been hacked several times before.

This is not unusual. Companies are reluctant to admit that they have been violated by cyber criminals. Why? Number one, they don’t want to reveal their vulnerabilities to other potential hackers. Even more importantly, they are scared – and for good reason – that they’ll lose the confidence of their customers.

Yet that’s about to change. I expect the SEC to soon compel public companies to disclose their cyber-attack vulnerabilities. A group of lawmakers – including Jay Rockefeller, the powerful Chairman of the Senate Commerce Committee – has already sent a letter to the SEC asking it to issue guidance on cyber security.

The letter says, “In light of the growing threat and the national security and economic ramifications of successful attacks against American businesses, it is essential that corporate leaders know their responsibility for managing and disclosing information security risk.”

This is no idle threat. A 2009 study by insurance underwriter Hiscox found that 38 percent of Fortune 500 companies neglected to disclose the risk of data-security breaches in their public filings.

Capitalize on Cyber Security Before SEC Moves In

Does anyone really believe the SEC is not going to move on this issue? The questions that you should be asking as an investor are, “Who is likely to benefit from this development?” and, “Where should I invest to capitalize on this trend?”

A small cadre of companies is working to protect consumers, businesses and government agencies against a wide array of cyber threats. Most of them are already highly profitable.

But tens of billions more of government money will soon be spent beefing up national security, protecting U.S. infrastructure and safeguarding the financial system. And businesses – increasingly aware that everything from research papers to client lists are being targeted by criminals and corporate spies – will soon spend billions more in this area, too.

Oxford Club Members are already making a bundle on our cyber security recommendations. But this threat is still gathering momentum. Expect the SEC to soon demand greater disclosure. That will cause business – and profits – at cyber security firms to race higher.

This is a ride you won’t want to miss.

Source:- http://www.investmentu.com/2011/May/cyber-crime-gains-momentum.html

Android Major Cyber Crime Target: Warns Security Head

8:25 PM Posted by Anonymous ,
    The flexibility of Google OS could be its downfall, the head of one of the largest IT security providers warned today.


    Click to enlarge

    Although the open nature of Android platform has always been celebrated as its disctinct advantage, it also open the doors to cybercrme, CEO and co-founder of Kaspersky Lab, Eugene Kaspersky, told AusCERT IT conference today.

    "The Android operating system is flexible and easily adapted, which makes it easy for software developers, as well as cyber criminals, to use, " he warned.

    Speaking at the Gold Coast event, Kaspersky also brought attention to the whole area of digital fraud and says we are now in the "golden age of cybercrime" and delivering his keynote address, Kaspersky said the "digital world is under attack." And it appears he's right.

    Just recently, the Sony PlayStation online network was hacked by an unknown group and threat researcher Kevin Stevens claims the hackers could be intent on selling the captured data for large sums of money.

    And Kaspersky isn't the only security expert crying louder about unsecure online applicaitons.

    Ty Miller, Chief Technology Officer ofPure Hacking, told ChannelNews last week that social networking sites including Facebook frequently fall prey to "weak access controls" so it's no surprise personal information leaks that hit the network last week occured.

    "Cybercrime is low risk, low investment and high profit. It's relatively easy to get started – all you need is a laptop and some knowledge."

    And it's not just PC's criminals are targeting. Smartphones and tablets are now also highly susceptible particularly Android's.

    Digital crime industry is now estimated to be worth $100 billion worldwide and the number of malware samples that appear on the web have dramatically increased: from five every two minutes to one every two seconds in the last three years.

    So what can be done to counter the crims? Advanced cloud security, which should become an industry standard.

    "Innovation in securing cloud technologies is a quick solution to suppress the current global cybercrime threat," Kaspersky believes.
    Source:-http://www.channelnews.com.au/Software/Industry/L4D8D5J7
    Kaspersky's Lab is the world's largest privately anti-malware company.

Cyber Camps For Children

1:31 PM Posted by Anonymous ,

PUNE: A series of unique cyber camps are being conducted for children aged 8 years and upwards. These camps are being conducted by city-based Asian School of Cyber Laws (ASCL) and Data 64 Techno Solutions Pvt. Ltd, a company dealing in cyber laws and cyber crime investigation.

"The internet is a world full of information, friends, fun, education and sports. It is also a world full of drug dealers, porn freaks, cyber stalkers, psychopaths, kidnappers, cyber bullies and even recipes to make bombs," said Sagar Rahurkar, project coordinator, Pune.

"There are several threats that children face on-line. One of these is cyber bullying, which can lead to depression, substance abuse and even suicide. Another threat is from on-line buddies who can turn out to be psychopaths, kidnappers or even child molesters," he said.

"Often children inadvertently give away vital details like their parents' incomes, their address, even credit card information! This information can then be misused by criminals to make illegal purchases and run up huge bills," said Rahurkar.

"The solution is to make children CyberSmart. We would be making children cyber smart by acquainting them with basics of how the Internet works, IP addresses and the domain name system, an introduction to wireless networks, Firefox, guide to safe on-line shopping, among other things," he said.

Source:- http://articles.timesofindia.indiatimes.com/2011-05-15/pune/29545515_1_cyber-laws-asian-school-cyber-crime-investigation

Graphics Cards Drivers New Target For Cyber Attacks

12:03 PM Posted by Anonymous
It seems like nothing is safe from Internet attacks these days after a security consultancy warned that now graphics card drivers could be a new target for cyber hackers.

British security consultancy Context disclosed in an advisory Thursday that security issues in WebGL, a browser Web standard designed to bring 3D graphics to Web pages on the Internet could leave users susceptible to denial of service and other cyber attacks.


WebGL is on by default in Firefox 4 and the recently hackable Google Chrome, and can be turned on in the latest versions of Safari.


The security issues enable hackers to execute malicious code on users' computers via a Web browser, which allows attacks on the GPU and graphics drivers that could render the entire machine unusable.

"These issues are inherent to the WebGL specification and would require significant architectural changes in order to remediate in the platform design," security researcher James Forshaw wrote oin the Context advisory.


The problem occurs in the way that the WebGL is implemented, and the way current PC and Graphics Processor architectures are designed, Forshaw said.


Unlike other browser content, WebGL provides direct access to the graphics hardware, employing shader code that's uploaded then executed directly on the system. However, current hardware and graphics pipeline implementations are not designed to maintain security boundaries, experts say.


"Once a display list has been placed on the GPU by the schedule, it can be difficult to stop it, at least without causing obvious, system-wide visual corruption and instabilities," Forshaw wrote.


Subsequently, hackers could obtain access to the hardware drivers by crafting malicious code, and tricking a victim into installing it by opening a malicious Web page or clicking on infected content embedded on a legitimate site.


In addition, the WebGL API's direct access to the hardware also flings the door wide open for denial of service attacks. Unlike typical DoS attacks, in which the user's Web experience is blocked, the WebGL DoS exploit would crash the operating system or prevent users from being able to access their computer.


Windows 7 and Vista are less susceptible to attacks than XP due to the fact that their OS will be forced to reset if the GPU locks up for around two seconds, stopping all applications from using 3D graphics.


In response to Context's advisory, the 3 to 5 Khronos Group, the open standards consortium that maintains WebGL specification, said it has developed a WebGL extension, called OpenGL, GL_ARB_robustness, "specifically designed to prevent denial of service and out-of-range memory access attacks from WebGL content."


Khronos Group says the extension has already been deployed by some GPU vendors, and predicts that it will rapidly gain adoption down the road. "Browsers can check for the presence of this extension before enabling WebGL content. This is likely to become the deployment mode for WebGL in the near future," Khronos Group said on its Web site.


However, Context said that the extension doesn't go far enough to address the issue, noting that resetting the graphics card and driver "should be seen as a crutch to OS stability" and not standard security mechanism.


Ultimately, Context said that WebGL wasn't ready for mass distribution, while recommending that users disable WebGL in their browsers.


"While there is certainly a demand for high-performance 3D content to be made available over the Web, the way in which WebGL has been specified insufficiently takes into account the infrastructure required to support it securely," according to the Context blog. 'Perhaps the best approach would be to design a specification for 3D graphics from the ground up with these issues in mind."