World cyber news is online news media.we bought daily hottest news occuring in the world related to cyber.. We propogate news specially related to hacking, technology updates , cyber world updates....

Saturday, May 28, 2011

Cyber crime cell launches DVD for police personnel

1:42 PM Posted by Anonymous

Pune: The Pune cyber crime police have launched a DVD 'Useful website and tools for police officers' to educate the police personnel about the laws, methods to trace suspects and their mobile location.

The cyber police have chosen 100 different subjects related to crime and police. And each subject has at least five different websites links that would enable a police officer to get the desired information. The DVD contains website links and information on all bare acts, cyber laws, competitive examinations, how should the police behave with children, how to identify fake university certificates and credit card frauds, how to identify an absconding criminal in disguise and how to identify a missing person.

Besides, the cyber police have also given names of the software in the DVD, so, if the police officer has any doubts he can install the software and get the related information. Deputy Commissioner of Police (cyber crime), DGP Rajendra Dahale, said, "This is a unique project that was taken up by our police inspector Sangeeta Alfonso and assistant police inspector Sanjay Tungar. Our aim is to save the time of the police, while registering a case."

The DVD has been distributed to 30 police inspectors in the city. Moreover, the other commissionerates are also asking for it. Dahale further said, "We will give the DVD to the DG's office then it would be distributed to other parts of the state."

Alfonso said, "We have been working on this project for the past two months. Initially, we studied different areas, where the police encountered difficulties. We studied the problem areas and added the websites links in the DVD." Most of the time, police officers have to take help from the cyber crime cell while dealing with cyber crime but now they can get the information directly, Alfonso added. "Moreover, we have given different links. For example, if a police officer wants to discuss the case with experts. He just needs to click on that website and speak with the experts. Besides, most of the time police personal have problem in reading the post mortem report because of the medical terminology. A website link has been provided for such a situation also, where they can read it in their language," Alfonso further said.

The police can get information about a private security agency in case of a credit card fraud or net banking fraud. "Many times a police officer is unable to trace the mobile of a suspect. In this case, they just need to click on the related topic to get information," Alfonso said.

A police inspector with the cyber crime cell said, "The Mumbai police have also asked for the DVD."

Monday, May 23, 2011

Cybercrime Statistics Expose Five Industries Most Susceptible to Phishing Attacks

CLEARWATER, Fla., May 23, 2011 /PRNewswire/ -- Internet Security Awareness Training (ISAT) firm KnowBe4 has released new cybercrime statistics that identify the nation's most Phish-prone™ industry sectors, which are those most susceptible to cybercrime ploys. The top five industries vulnerable to cybercrime include travel, education, financial services, government services and IT services. These findings are based on a recent phishing experiment KnowBe4 conducted among small and medium enterprises (SMEs) featured in the latest Inc. 500 and Inc. 5000 listings.

Using the Inc.com website to obtain domain names and a free data-gathering service to find publicly available email addresses, KnowBe4 sent out a simulated phishing email to employees at more than 3,500 companies. Individuals who clicked the link were directed to a landing page that informed them they had just taken part in phishing research. The emails were successfully delivered to about 29,000 recipients at 3,037 businesses; and in nearly 500 of those companies, one or more employees clicked the link. Because of the potential for Internet security breaches among these businesses, KnowBe4 dubbed them the FAIL500.

"Any business that provides access to email or access to its networks via the Internet is only as safe from cybercrime to the degree that its employees are trained to avoid phishing emails and other cyberheist schemes. The more employees within an organization that use email or go online, the greater the risk of exposure to cybercrime," said KnowBe4 founder and CEO Stu Sjouwerman (pronounced "shower-man").

KnowBe4 conducted a comprehensive data analysis of its FAIL500 study results, which included categorizing the companies into 25 industry sectors. The findings revealed that some industries are particularly vulnerable to cybercrime. Based on the percentage of companies in each sector that responded to the phishing email, the most Phish-prone industries are:

  • Travel - 25%
  • Education - 22.92%
  • Financial Services - 22.69%
  • Government Services - 21.23%
  • IT Services - 20.44%

"Our cybercrime statistics should serve as a wake-up call to SMEs nationwide," noted Sjouwerman. "Not only are these businesses at risk for financial loss through a cyberheist, but their susceptibility to phishing tactics could compromise sensitive customer data such as credit card, bank account and social security numbers."

Sjouwerman cites a "false sense of security" as the primary reason companies are vulnerable to cybercrime. "Most people assume that antivirus software and an in-house IT team provide sufficient data security. But considering that IT is among the most Phish-prone industries, it's clear that's a very dangerous assumption to make."

Cybercriminals have become very sophisticated in their tactics, and Sjouwerman notes that they often target businesses through official-looking emails that appear to be sent by government agencies, business partners or even company executives. "Many of the top Phish-prone industries are regulated and subject to compliance rules, so well-meaning employees can be tricked into clicking a link if they believe an email was sent by a government or law enforcement agency, or by someone they know and trust. And with just one click, malware can be instantly uploaded to a system - bypassing both antivirus software and IT firewalls. A cyberheist can be underway within minutes."

According to YourMoneyIsNotSafeInTheBank.org, small-business accounts suffered more than $40 million in cybercrime losses as of 2009. The website also cites FDIC figures indicating this type of crime increased five-fold within a 12-month period, and notes that the FBI is tracking hundreds of related cases. Small and medium-sized organizations have become the primary targets of the Eastern European hacker gangs behind this frightening new crime wave. These cybercriminals tend to prey on smaller businesses and banks that lack the cyber-fraud controls many larger institutions have in place.

To help SMEs combat the growing threat of cybercrime, Sjouwerman recently published his fourth book, Cyberheist: The Biggest Financial Threat Facing American Businesses Since the Meltdown of 2008. In addition to highlighting the results of the FAIL500 project, Cyberheist explores the business of cybercrime, examines a number of cybercrime cases and empowers readers with effective strategies for countering cyber attacks.

For more details on the KnowBe4 phishing study - including the Phish-prone percentages for all 25 industry sectors - visithttp://www.knowbe4.com/fail500. Future announcements from KnowBe4 will provide further analysis on the experiment, including projections based on the FAIL500 research findings. To learn more about Cyberheist, or to order the paperback or e-book edition, visit http://www.cyberheist.com.

About Stu Sjouwerman and KnowBe4

Stu Sjouwerman is the founder and CEO of KnowBe4, LLC, which provides web-based Internet Security Awareness Training (ISAT) to small and medium enterprises. A data security expert with more than 30 years in the IT industry, Sjouwerman was the co-founder of Sunbelt Software, an award-winning anti-malware software company that he and his partner sold to GFI Software in 2010. Realizing that the human element of security was being seriously neglected, Sjouwerman decided to help entrepreneurs tackle cybercrime tactics through advanced Internet security awareness training. He is the author of four books, including Cyberheist: The Biggest Financial Threat Facing American Businesses Since the Meltdown of 2008. For more information on Sjouwerman and KnowBe4, visit http://www.knowbe4.com.

Media Inquires:

Karla Jo Helms
CEO and PR Strategist
JoTo Extreme PR
Phone: 888-202-4614
http://www.JoToPR.com

This press release was issued through eReleases(R). For more information, visit eReleases Press Release Distribution athttp://www.ereleases.com.

SOURCE KnowBe4, LLC

Sunday, May 22, 2011

Where Are the Ethics in Hacking?

8:38 PM Posted by Anonymous
A recent news story begs the question: What is "ethical" hacking?

You may have heard about Australian security researcher Christian Heinrich, who hacked live into Facebook's privacy controls at an IT security conference and accessed private photographs of rival security professional Chris Gatford and his family, including the image of a child. The incident led to a journalist being arrested and having his iPad seized after he published some of the images online.

A lot of people don't understand the difference between hacking and ethical hacking.

Following the event, detective superintendent Brian Hay, head of the Fraud and Corporate Crime Group of the Queensland Police Service, criticized the demonstration of a so-called ethical hacking. "I think cultures have built up where hacking, in the past, has been a part of a competition, and you have black-hat conferences around the world. The technical reality is that on those occasions crimes may well have been committed."

This latest incident has left many questioning what role ethics play in ethical hacking, and what this activity really is about.

"The reason ethical hacking exists is because somebody less ethical in a different country will hack your systems and not tell you - that is going to happen no matter what," says Jeremiah Grossman, Founder and CTO of WhiteHat Security. "So, ethical hacking is conducted to hack yourself first and fix the issues and vulnerabilities that remain to avoid being a headline like Sony."

Ethical hackers, then, attempt to exploit the IT security of a system on behalf of its owners by following certain polite rules, like getting a written or verbal consent from the owner of the system before the professional conducts the test.

"What the Australian researcher did is not ethical hacking," says Jay Bavisi, President of EC-Council, a global certification and training organization for ethical hackers. "A lot of people don't understand the difference between hacking and ethical hacking."

Terms like penetration testing, ethical hacking and hacking are interchangeably used, and Bavisi defines each:

  • Hacker: simply a person who invades or interferes with another system with the intent to cause harm, without having any permission from the system owner.
  • Ethical hacker: a professional hired by an organization to review its security posture. The whole process involves a written consent and rules of engagement from the client, which clearly spell what they can or cannot do, "This is basically our 'get out of jail free' card," Bavisi says.
  • Penetration tester: a professional who goes a step beyond the ethical hacker and provides an active analysis of the system for any potential vulnerabilities that could result from poor or improper system configuration, both known and unknown hardware or software flaws, or operational weaknesses. These individuals are largely involved in the remediation process.

Still, Ian Glover, president of the UK's Council of Registered Ethical Security Testers (CREST) , a global organization that assesses the skill and competence of professionals working in the penetration testing industry, says, "I don't like the term ethical hacking." According to him, the term is misleading as hacking immediately presents a negative view of people mounting unsolicited illegal attacks.

The professional penetration industry provides an invaluable service to government and business validating security controls. While individuals who believe they can work illegally still exist, the professional penetration testing industry acts in a responsible manner within a strict legal and ethical framework.

"In the past there was the opportunity to be a hacker, to do inappropriate things and then people would employ you. In the future that is not going to be the case, as neither the industry nor the buying community will accept individuals who have operated illegally," Glover says.

The industry has matured, he says, and because of that the bar of entry is much higher for prospective testers. In this case, he adds that if Heinrich were to be a member of a professional organization like CREST, he would be immediately removed for his actions.

There are ethics and morals involved when ethical hackers take up such contracts or positions. They clearly understand their limits dictated by the letter of authorization where the client specifies the scope of engagement. For instance, the servers that can or cannot be tested, the IP range ethical hackers can use etc. These professionals are aware of the legal framework and understand the requirement for full disclosure to the client. "Without permission, no ethical hacker will touch the job and go beyond the scope in any form. This is standard security practice," Bavisi says.

The latest incident is just an example of a bad hacker, adds Grossman. "The researcher made a rather common mistake of demonstrating a live vulnerability on stage without permission. Would I have done it? No!"

One of the key lessons in this case is the need for better education within the industry to highlight the differences among hackers, ethical hackers and penetration testers.

"People must understand the difference between a cop and a thief," Bavisi says.

Source:- http://blogs.bankinfosecurity.com

Parents Should Keep a Tab On Child's Activities On Internet

8:34 PM Posted by Anonymous ,

We now can relate easily to social networking in India, having much familiarity with it as these events have started to pop up very often. Recently, in Gujarat, a student pursuing MTech from renowned Nirma University was caught unawares, after he was found guilty of hacking into a girl's Facebook account and putting up obscene pictures on the same. He was caught very quickly, but he is just only single percent of the whole lot. Let me explain to you, via some of my favourite statistics and analysis.

Every day, we get at least ten calls on an average, which have reports ranging from fake profile impersonation to cyber pornography and posting of malicious content by minors, especially students from schools and colleges. Apart from that, there is a vicious rise of 10 % in such cases since beginning of year 2011, as compared to last year's cases. With increase in cyber crime cases in India, these contribute heavily to the number of registered cyber crime cases, as 50% of cases coming to police stations are having more or less the same tune to play.

So, are there any problems with the students or the youth culture of India? Well, to say the least, such cases have also been largely reported in various other countries including developed countries. The case here is not about the youth and the growing technology, but the tyranny lies in the very basic thing, which is nurturing of youth. There are some very strict and yet very essential and genuine steps for parents to take here, because, with effect of these steps, they can avoid falling in such situations and exempt the disrespect as well as the problems which they face later on.

What parents should do is like, they need not keep constant vigil on the child, but they need to know, on which sites he is creating a profile, where he is posting his photos, what he is sharing with his friends. The parents need to know and monitor the activities, but not by spying but by having a nice and easy-go relationship with them, so that they don't feel embarrassed to show you their profiles, and thus also they will avoid putting unnecessary information, data, as well as content, which may harm their profiles on the net, out in the open. Parents need to gather information about the social networking cyber space through seminars and expert lectures, organised at various centres in the city and across the country.

It is also the duty of the government to impose laws and regulations over the cyber space ventures of overseas companies, which actually don't physically exists in India, but are virtually present. The laws should abide each and every such company operating websites over Indian space. The government needs to close and create boundaries of Indian cyber space, which should be regulated each and every moment, to avoid such mishaps.

Apart from that, it is duty of the website operators, to see into such cases, as soon as a legal complaint is filed, and handover the culprit or any sufficient and required details on the case, to the authorities. But, help from Facebook, and many other such networking websites, still looks like a faraway dream, as there is still no hope of improvement in their behaviour and cooperation towards us.


Sunny Vaghela
The author is a city-based ethical hacker and specialises in cyber crime investigations and forensics.


Source:- http://www.dnaindia.com

Saturday, May 21, 2011

Sony Servers Now Hit By Phishing Scam

12:12 PM Posted by Anonymous

Sony’s cyber security woes are continuing. Security player F-Secure has discovered the presence of a phishing site on certain Sony websites in Thailand and Italy.

This latest attack is separate to the hacking attack that forced the PlayStation Network’s closure in recent weeks.

F-Secure discovered the phishing site running on Sony’s official Thailand website that redirected users to a phishing site that purported to be an Italian credit card company.

“Basically, this means that Sony has been hacked, again. Although in this case the server is probably not very important. Sony has been notified. The malicious URL is blocked for our customers,” F-Secure said.

F-Secure specialises in analysing and defending against virus, phishing, spyware and spam attacks.

The PlayStation Network was taken offline in recent weeks following a devastating cyber attack on Sony's servers that saw hackers access information on more than Link77m users. The Sony Online Network (SOE) was also hit in an attack and a further 25m users' details were accessed, including 24,000 credit and debit card details.

On Saturday, Sony confirmed its PlayStation Network was gradually coming back online, starting in the US. It said users needed to update the firmware and change their passwords.

Source:- http://www.siliconrepublic.com/strategy/item/21893-sony-servers-now-hit-by/

DMCA Policy of World Cyber News

12:18 AM Posted by Anonymous

www.worldcybernews.com is in compliance with 17 U.S.C. § 512 and the Digital Millennium Copyright Act ("DMCA"). It is our policy to respond to any infringement notices and take appropriate actions under the Digital Millennium Copyright Act ("DMCA") and other applicable intellectual property laws.

If your copyrighted material has been posted on www.thehackernews.com or if hyperlinks to your copyrighted material are returned through our search engine and you want this material removed, you must provide a written communication that details the information listed in the following section. Please be aware that you will be liable for damages (including costs and attorneys' fees) if you misrepresent information listed on our site that is infringing on your copyrights. We suggest that you first contact an attorney for legal assistance on this matter.

The following elements must be included in your copyright infringement claim:

  • Provide evidence of the authorized person to act on behalf of the owner of an exclusive right that is allegedly infringed.
  • Provide sufficient contact information so that we may contact you. You must also include a valid email address.
  • You must identify in sufficient detail the copyrighted work claimed to have been infringed and including at least one search term under which the material appears in www.thehackernews.com search results.
  • A statement that the complaining party has a good faith belief that use of the material in the manner complained of is not authorized by the copyright owner, its agent, or the law.
  • A statement that the information in the notification is accurate, and under penalty of perjury, that the complaining party is authorized to act on behalf of the owner of an exclusive right that is allegedly infringed.
  • Must be signed by the authorized person to act on behalf of the owner of an exclusive right that is allegedly being infringed.


Send the infringement notice via email to worldcybernews[at]yahoo.com



Submit Your News on World Cyber News

12:07 AM Posted by Anonymous

We The World Cyber News Cordially invites your Article For Our News Website. Please support us ,All Hacker Friends and People from Cyber World to make this Website for most Authenticated place for News. please email (thecybernews@gmail.com) us yourself, your websites, your aim, your skills and your achievements. Tthe articles sent by you will be published in our official news site : http://www.worldcybernews.com/


News Article Format
1.) Title
2.) Description
3.) Article + Suitable Images + Links
4.) Source Link (If any)
5.) Submitted By ( Name + Pic + website link + Codename )


Email Us you article in the form of a MS word file as attachment to : thecybernews@gmail.com

Regards
World Cyber News.

Friday, May 20, 2011

Businesses Most at Risk for Internet Hacking

9:40 PM Posted by Anonymous
Career criminal Willie Sutton is credited with saying that he robbed banks, “because that’s where the money is,” and while Sutton later claimed to have never uttered that infamous line, he did say in his autobiography that criminals “go where the money is … and go there often.”

Nick Rowe | Photodisc | Getty Images

Unfortunately for many businesses, today’s Internet criminals seem to be going where the money is and they are, indeed, going there often—as the recent hacking of Sony’s [SNE 27.07 -0.15 (-0.55%) ] PlayStation Network has proven. Cyber crime experts say that virtually all businesses online are targets.

“Money attracts criminals,” says Melih Abdulhayoglu, CEO of Comodo, the maker of antivirus and firewall solutions for business. “The financial industry continues to suffer a lot from cyber crime attacks.”

Abdulhayoglu says that high-profile companies that rely on Internet for revenue are seeing an increase in attacks. One of the reasons this is happening is that there has been a shift from the lone hacker or specialized cyber criminal to criminal enterprises that are looking to make online attacks part of a new business model.

See Show DetailsCode Wars: America's Cyber Threat -- See Show Details

“Cyber crime has become a more lucrative industry than trying to smuggle drugs across the border,” says Abdulhayoglu, “and it is actually far less risky.”

Moreover, just as criminals in the off-line world have specialties and thus unique skill sets that target specific businesses, so too are there specialized cyber criminals, putting more businesses at risk.

“It isn’t so much that some industries are more susceptible,” says Mark Bell, Executive Vice President of Operations for Digital Defense, “but there are now different threats based on particular industries.”

Money remains a big target, putting banks, credit unions and other financial institutions that move money in the cyber crosshairs, but money isn’t the only target. Defense industries and governmental institutions are also being targeted by cyber criminals and terrorists looking to gain information and find other vulnerabilities.

But regardless of whether money is the directly target, it is still all about the money in the end.

“There is the threat against intellectual property,” says John Kindervag, Senior Analyst at Forrester Research. “There are hackers who are looking to steal another companies R&D because they can sell the information to a company that has a small R&D budget. So it may be about intellectual capital or money, or just something you can turn into money.”

The threat is also increasing for smaller businesses and entities. While these had been largely ignored by cyber criminals, small and medium sized businesses have become the low hanging fruit for hackers.

“They don’t have the budget to be as diligent as larger companies,” says Kindervag, “But they still have data that can be monetized. It is like robbing a small bank or robbing a large bank. The smaller bank might have less guards and just as much money to steal.”

Doug Johnson, Vice President, Risk Management Policy, American Bankers Association agrees that smaller banks are indeed targets, just as much as larger institutions.

“We’re accustomed to being a target,” says Johnson, who adds “you are only as secure as your weakest link. It is up to the institution to conduct risk assessment and to mitigate risks, along with transaction monitoring. What is important is that the financial institutions have multiple layers of security.”

Johnson says that while threats do run down hill, and that cyber criminals may target larger banks before moving to community banks, the protection is also passed down.

“We represent the entire industry, so while we represent the largest banks, we also work with community banks around the country. This ensures that the larger threats to the big institutions are known to community banks. That protects the entire environment.”

Regardless of the size of the institution, there is concern that handheld devices are now opening new holes. A recent study from Origin Storage found that 41 percent of what should be a security savvy audience are carrying sensitive data on mobile devices unprotected. The study also found that 19 percent of respondent organizations suffered a data breach following the loss of a portable device that contains unencrypted data.

“Mobile devices are opening new holes to networks, and the addition of apps means corporate data is being put at risk,” says Tom DeSot, Executive Vice President and Chief Information Officer for Digital Defense, noting this is increasing a problem with small and medium sized businesses. “Things that connect wirelessly or via a USB tether are further adding new issues. It is hard for a small business to stay on top of everything.”

Protecting from cyber crime is also unfortunately becoming ever more difficult, in part because too many people are far too trusting online.

“When is the last time you opened the door blindfolded to someone you don’t know,” asks Abdulhayoglu? “Most people would never do this at home or work, but we do it every day in the digital world.”

Source:-http://www.cnbc.com

Crime Reporting Systems 'Incredible Police Burden'

9:39 PM Posted by Anonymous
Police resources are being stretched by onerous and unnecessarily complex crime reporting systems, according to a British crime expert.

Former detective superintendent John Gillon worked for 30 years in the Scottish police force, specialising in intelligence, cyber crime and information systems.

Mr Gillon now works with Memex Technology, a security consultancy firm. He was in Canberra this week to help its parent company, the SAS Institute, set up a public security centre in the Asia-Pacific.

Mr Gillon's research focuses largely on the way in which police officers record crimes on internal police information systems.

Those studies have shown that, since the mid-1990s, the process of creating crime reports had become increasingly onerous.

Mr Gillon said that for any single incident, a police officer was typically forced to enter reports in a range of separate records systems, including a crime reporting system, custodial records and a sex offenders register.

''[In] a piece of analysis that I did ... a simple domestic violence incident, an officer was required to input a free text explanation of what had happened into 11 different systems,'' Mr Gillon said.

''It means it can be an incredible burden, so it screams out for a more holistic approach.

''We also looked at the amount of time it took officers to input intelligence ... and it will surprise you to know that, in a very, very simple scenario, it took officers over four hours to input that information.''

He said by streamlining an officer's reporting requirements, and by creating a single, seamless police information system, forces would also greatly improve their ability to analyse intelligence.

Such a system, he said, would help intelligence analysts make connections between different crimes.

''They've all got this burden of disconnect between these key systems,'' Mr Gillon said.

''Ideally, you want to put information in once and once only, and carry that information forward,'' he said.

Source:- http://www.canberratimes.com.au

Anti-Cyber Crime: Eight Arrested

9:37 PM Posted by Anonymous

MANILA, Philippines — Operatives of the National Bureau of Investigation (NBI) Friday swooped down a posh village in Pasig City and arrested at least eight foreign nationals allegedly being hunted by the Taiwanese government for alleged cyber crime.

But NBI-National Capital Region (NCR) chief lawyer Constantino Joson declined in an informal news conference to give the identities of the arrested suspects. He said that they have yet to establish if the suspects are indeed Chinese, or Taiwanese or Hong Kong nationals.

“We are in the process of determining the real identifies and nationalities of the arrested suspects.” Joson said.

He said they have to be very cautious in their investigation to avoid any lapses.

Joson said the NBI agents, who were armed with a search warrant issued by a Manila court, raided the house at 421 Valle Verde IV in Pasig City, at around 12 noon last Friday.

NBI agent Lawyer Eduardo Ramos, in an interview, said the arrest of the eight foreign nationals stemmed from the request of Taiwanese Economic Cultural Office (TECO) that several natives from Taiwan, who were wanted for cybercrimes, were in the country.

In a letter sent to the NBI last April, TECO Police Liaison Officer Bart Lee informed the bureau that at least 10 groups, made up of 5 or more persons, had illegally put up a call-center like stations in different posh subdivisions which were used to victimized Taiwanese nationals.

Ramos, citing the letter of TECO, said that the foreign syndicates had transferred their operations in the country from different Southeast Asian countries due to the country's lax law enforcement.

“The information we received further stated that the group were allegedly involved in different cyber crimes like cyber sex and online lottery fraud among others,” he told the Manila Bulletin.

But even before they received the tip from TECO, Joson said that they had place the said residence under surveillance for three months already.

According to Joson, they were initially tipped by informants about the presence of the suspects in the area under very suspicious conditions.

Source:- http://www.mb.com.ph