‏إظهار الرسائل ذات التسميات hacking. إظهار كافة الرسائل
‏إظهار الرسائل ذات التسميات hacking. إظهار كافة الرسائل

الأربعاء، 14 ديسمبر 2016

new details of 1 billion yahoo accounts compromised by hackers ,emerges

"the cost of fighting cyber crime security"

"new details of  1 billion  yahoo accounts compromised by hackers ,emerges"

 
Shocking details of Yahoo Hacking revealed: It seemed Yahoo  has lost count over how many " of its user accounts were compromised  as hackers managed to get details of more than than 1 billion user accounts. That's double the number affected by a hack revealed by the company in September 2016. According to Yahoo" Stolen data included" users' names, email addresses, telephone numbers, dates of birth, and encrypted passwords. Those passwords are scrambled up with an encryption tool called MD5, which experts say is possible to crack with some patience. The data also included some security questions and answers, some of which weren't encrypted.The stolen data is believed to include information for over 150,000 US government and military employees according to Bloomberg . These include former White House staff, congressmen and their aides, FBI agents, officials at the National Security Agency, the Central Intelligence Agency, the Office of the Director of National Intelligence, and each branch of the US military.

This enormous data hacked apparently happened in 2013. Earlier Yahoo announced a separate data breach in September this year, in which hackers in 2014 swiped user information from half a billion accounts, it was said to be the biggest cybersecurity breach ever.
Meanwhile a security researcher Jouko Pynnönen had reported a vulnerability in Yahoo! Mail via bug-bounty organizers HackerOne and bagged $10k after discovering and reporting a serious flaw in Yahoo! Mail that could have been exploited by crooks to read victims' messages.The flaw – fixed in production late last month– could be exploited simply by tricking your target into opening a booby-trapped mail. The same vulnerability could also be abuse to spread malware, as a blog post by Pynnönen explains: The flaw allowed an attacker to read a victim's email or create a virus infecting Yahoo Mail accounts, among other things. The attack required the victim to view an email sent by the attacker. No further interaction (such as clicking on a link or opening an attachment) was required


 Andrew Komarov  who was working with InfoArmor saw a  Eastern European hacker group sell the  Yahoo database three times - and he intercepted the database  and notified to to the Government reports dailymail
In the meanwhile Yahoo's chief information security officer Bob Lord says that the company hasn’t been able to determine how the data from the one billion accounts was stolen. 'Yahoo badly screwed up,' Bruce Schneier, a cryptologist and one of the world's most respected security experts, said after the internet company's latest disclosure.

الجمعة، 23 سبتمبر 2016

Affected by the Yahoo hack? Here’s what you need to do:

If you have a Yahoo account, you should act fast. Just yesterday it was confirmed that hackers stole the personal data of half a billion Yahoo accounts in the most recent cyber-catastrophe. 

Details, including names, email addresses, phone numbers and security questions were stolen from the company’s network in late 2014. It's also now been revealed that passwords were also taken, but in a “hashed” form, with the company reporting they believe the financial information held with it remains safe, unless the hashed passwords are decrypted.


Yahoo believe this was a state-sponsored act – an increasingly common scapegoat following cyber hacks today. Although Yahoo are currently notifying those potentially affected by the hack, as a precaution you can take steps now to protect your data.

Below, we will identify these steps in order to secure your information now and in the future.

This is what you need to do:


Take back your account: If your Yahoo account has been compromised, the first thing you need to do is take it back. Hackers, may have also gone after your linked accounts so check them also. Below are a series of links to the most common social and mail platforms where you can take back your account.
·         Yahoo
·         Apple
·         Facebook
·         Google
·         Microsoft
·         Twitter

Report it to the police: If you believe you have been hacked and are now the victim of identity theft or fraud, file a report with Action Fraud

Change your passwords and security questions: Even if you haven't been hacked, change your password and security questions immediately. This is especially important if your email is connected in any way to your bank or a PayPal account. 

Additionally, you should look to change the passwords in any other account that uses the same or similar security information. This ensures hackers cannot access other accounts through your Yahoo information. It is also sensible to check your password recovery settings and ensure they have not been changed to a third party. 

Tell everyone you know: In this situation it is a common tactic for hackers to target friends and family of compromised accounts to extract financial gains. So spread the news to your friends and family. Not only will this help them inform you if they see unusual activity, but it may also spare them falling victim to a similar hack.

Be wary of emails from Yahoo: Now is the perfect time for cyber criminals to strike through a phishing attack. Avoid downloading or clicking links in any emails coming from Yahoo. Almost all malware is installed unknowingly by the victims themselves. 

Update your security settings and run a security scan: Make sure you run a virus scan and have the most recent security updates on your operating system. If you don't have an anti-virus application, invest in a high quality one like McAfee or Norton Antivirus. This is something you should be doing as best practice regardless of the issue.

Continue to review your activity: Just because you’ve gotten your account back, doesn’t mean you’re safe. Hackers often leave ‘backdoors’ so they or other hackers can regain access at a later date. Make sure you continually review any activity to make sure no emails are being forwarded or security questions have been changed.

De-authorise applications: Although it may be frustrating, de-authorising accounts that are in any way linked to your Yahoo account will be essential. Although many may deem this unnecessary, it certainly is a better idea than leaving an unknown individual in your system – even if it is just precautionary.   


How serious is this? And what does it mean for Yahoo?

The most serious concern for you as a Yahoo users is if the cryptographically hashed passwords were deciphered and used maliciously. Although the hashing scheme used to encrypt the passwords is known to be relatively tough, Yahoo have yet to release any details on it.

For Yahoo, this breach comes at the worst possible time. Earlier this summer, Yahoo had announced it was investigating a breach reported to involve 200m customers. The sudden increase to 500m means “Yahoo may be facing an existential crisis” with their “already besieged business execution issues and an enduring fire sale to Verizon, this may be the straw that breaks the camel’s back” according to Corey Williams from identity management software company Centrify.

Security researcher Kurt Baumgartner from Kaspersky Labs believes that Yahoo’s failings hardly come as a surprise: “It’s unfortunate that when we are talking about this organisation, a massive breach doesn’t come as a big surprise”. Baumgartner has also criticised Yahoo’s delayed response, citing it as characteristic if we look at their “delay in encrypting IM communications, implementing https for its web properties and more”.


الثلاثاء، 29 أبريل 2014

The Biggest Challenger to Internet Economy" is not Government but" Data Vulnerability

Online Giant Target   announced that credit and debit card information for 40 million of its customers had been compromised.  In January, Nieman Marcus reported the theft of 1.1 million credit and debit cards by hackers who had invaded its systems with malware 
DATA VULNERABILITY AND DIGITAL ECONOMY




The latest findings from the Pew Research Center suggest that Americans are concerned about online security and a quite a few believe that they had important personal information stolen and many have had an account compromised. 


Findings from a January 2014 survey show that 18% of online adults have had important personal information stolen such as their Social Security Number, credit card, or bank account information. 

That’s an increase from the 11% who reported personal information theft in July 2013. 21% of online adults said they had an email or social networking account compromised or taken over without their permission.The same number reported this experience in a July 2013 survey. 

 The recently discovered Heartbleed security flaw is the latest in a long string  data vulnerability and breach of " online users privacy"

The Heartbleed  bug starts  affecting a widely-used encryption technology ,intended to protect online transactions and accounts, went undetected for more than two years. Security researchers are unsure whether or not hackers have been exploiting the problem, but the scope of the problem is estimated to affect up to 66% of active sites on the Internet.

The extent  to which " the online economy"  is being targeted , specially those  dealing in   online shopping  transaction and ecommerce gateways   has seen a rapid increases

Online Giant Target   announced that credit and debit card information for 40 million of its customers had been compromised.  In January, Nieman Marcus reported the theft of 1.1 million credit and debit cards by hackers who had invaded its systems with malware

الأربعاء، 19 مارس 2014

Windows XP retirement puts ATMs at risk


By 

As we mentioned in an earlier post, Microsoft will be discontinuing the support of Windows XP on 8th April. Windows XP has been one of the most popular operating systems ever created and its endgame is certainly going to impact more than just individual users. According to Gartner’s experts, around 10-15% of XP-using businesses will fail to migrate to a different operating system, but this is not the most worrying news.

ATMs at risk as XP is set to retire

This may come as a shocker, but over 2 million (95% of all) ATMs in the world are running on Windows XP and they will become easy targets for hackers and viruses once the support for XP has to come to its end.
To make matters worse, only about 1/3 of these ATMs are ready for an upgrade and preparing the remaining 2/3 would cost about £60 million.

However, we must also point out that ATMs are equipped with sophisticated, customised additional security. Therefore it is unlikely that they’d just “start shooting out money into the streets or things like that,” said James Lyne, Director of Technology Strategy at Sophos.

They knew the day would come

Microsoft already announced its plans to stop issuing security fixes for Windows XP in 2007. So it really shouldn’t have struck any bank as a surprise, yet quite a few failed to take action. Banking giants like RBS, Santander UK, Lloyds or HSBC have decided to sign up for three years of custom support, before migrating their ATM operations to Windows 7.

According to James Lyne, these changes have been hanging around for so long, so banks really should have thought about addressing them a long time ago. 

About the Author:       
Sarah writes for Firebrand Training on a number of IT related topics. This includes exams, training, certification trends, project management, certification, careers advice and the industry itself. Sarah has 11 years of experience in the IT industry. 

الاثنين، 13 يناير 2014

Hacking with LinkedIn. The next battlefield in Cyber-warfare


By 


Social engineering by definition is “a non-technical kind of intrusion that relies heavily on human interaction and often involves tricking other people to break normal security procedures.” Social engineers often referred to as con artists, have been around for hundreds of years and their methods have evolved alongside the World’s technological developments.

Social engineering expert Sharon Conheady delivered a presentation entitled the “Future of Social Engineering” at DeepSec 2010. In her presentation she outlined how social networks, such as LinkedIn may be used for social engineering in the future. Well, the time has come, more and more scams are surfacing LinkedIn. Here’s the latest one:


How to spot the signs

As you can see the message follows the pattern of the well-known 419 Scams, also known as advance-fee frauds. However, it has one important characteristic that most scam emails don’t: a well-designed LinkedIn profile to give credibility to the message. 
  
The sender claims to have been Senior Accountant at Lloyds Banking Group for over 9 years now; however her profile states over 15 years spent at the role. Perhaps the body of the message would need an update?

There are also formatting errors, such as the spelling of “AleX Jones”, which clearly suggest that the message is unlikely to have come from a legitimate source. And of course we shouldn’t ignore the message either. Which bank would give away any money to someone who shares the same surname as a client? None.

If you'd like to know more about social engineering, watch the full presentation of Sharon Conheady, including stories of LinkedIn attacks, starting at 25:16. 



Please be alert and look out for scams like this. If you found this article useful share it, so that your friends and family won’t have the slightest chance of falling victim to it. 

About the Author:       
Sarah writes for Firebrand Training on a number of IT related topics. This includes exams, training, certification trends, project management, certification, careers advice and the industry itself. Sarah has 11 years of experience in the IT industry. 

الخميس، 19 ديسمبر 2013

Christmas scams - four tips to keep your personal information safe


By 


With the festive period approaching, many people are eagerly browsing the web to find some last minute deals on gadgets. Word of advice: if a deal is "too good to be true", it probably isn't.

Kaspersky Lab issued the following warning this week: "As we get ready for the latest round of Christmas-themed status updates, we should also prepare for a barrage of scams on social networks in the coming weeks too".

In the lead to Christmas, more and more gullible Facebook users are becoming targets and victims of scammers. There are hundreds of pages offering free gadgets such as PlayStation 4s, and insanely good deals on new Apple products, in exchange for your personal information.

Despite the fact that the majority of these scam posts rarely look legitimate, many people are falling for them. The below give-away received 646 entries. 



Kaspersky’s four tips to keep your social profile and personal data safe:
  • Don’t give away too much. Sharing is caring, especially at Christmas, but it doesn’t mean you have to share your personal information. Try keeping it safe by not sharing too much. If you lose control of your social media account to a hacker, it could mean more than just having your privacy infringed upon. They can also use your information to potentially breach other accounts, such as online banking services or e-commerce accounts, like Amazon.
  • Don’t click on untrusted links. Scammers use various techniques to get people to give away their Facebook login details. Clicking on an email link entitled "Facebook X-mas Specials", for example, could lead to a fake Facebook portal which invites users to enter their credentials. Since the interface seems identical to the real entry page, users don’t realise what’s happening until it’s too late. Once the victims have entered their details, the hacker has their passwords. You should, therefore, never click links that don’t come from trusted sources. But even if a link has been posted from a friend, still watch out - they may have been hacked.
  • Use two-factor authentication. Social media sites, such as Facebook and Twitter are becoming more and more security-conscious. They both have introduced two-factor authentication, which means the user can give another credential, such as a unique number sent to them via text or an application, when logging in. So even if someone gets hold of your details, they won’t be able to login as they won’t have that extra credential.
  • Get the right security. Different types of malware are circulating the web trying to steal social media passwords, such as the innocent-sounding Pony virus. Others, like Kelihos, are spread across Facebook and attempt to steal other personal data. Outside of taking precautionary measures, such as thinking before clicking on links, users need to invest in a decent anti-virus solution that can deal with the latest and most prevalent threats. A properly configured firewall is also essential. 

About the Author:        
Sarah writes for Firebrand Training on a number of IT related topics. This includes exams, training, certification trends, project management, certification, careers advice and the industry itself. Sarah has 11 years of experience in the IT industry. 

الجمعة، 22 نوفمبر 2013

What the future holds – eight IT security predictions for next year


By 


Hope for the best and prepare for the worst. It may sound like an old cliché, but being prepared is the foundation of great IT security. This year we’ve seen some high-profile data breaches, ransom-demandingmalware and prominent cybercriminal arrests. After an eventful 2013, we are curious about what 2014 brings, and so are cyber-security researchers from Websense Security Labs, who compiled a list of their predictions* for the New Year.

Lower levels of advanced malware

According to Websense ThreatSeeker Intelligence Cloud, the quantity of new malware is heading towards a decline. However, this is bad news for companies, because cybercriminals are likely to switch to lower volume, more targeted attacks to decrease the risk of detection. Long story short, there’ll be less attacks, but they’ll bear greater risk.

There’s a major data-destruction attack on the horizon

In the past, network breaches have mostly been about selling information for money. In 2014, enterprises should be concerned about hackers destroying data. Small and medium-sized companies should also stay alert, as ransomware attacks are expected to target them.

Cloud data over network

Loads of sensitive business data have been moved to the cloud in the last few years. Therefore, it seems logical and perhaps even convenient for hackers to adopt a new approach, and target clouds rather than on-premise servers.

Power struggle in the exploit kit market

Following the arrest of “Paunch”, the alleged creator of the Blackhole exploit kit, the market is likely to see a power struggle for the leading position. The Neutrino and Redkit exploit kits are expected to consolidate their positions in 2014.

Java will remain exploitable and therefore exploited

As most end point will continue running older versions of Java, they’ll be highly exploitable. Next year, cybercriminals will put great effort into developing new, multi-stage attacks, as well as making us of tried-and-true methods.

BreachedIn aka compromising organisations via social networks

Cybercriminals are expected to come up with more and more ways of luring executives and compromising networks, with the help of professional social media platforms, such as LinkedIn.

Only the strong ones will survive

This may sound a bit over the top, but similarly to a food chain, the weakest ones will be the primary targets. Obviously, they do not have to be afraid of being eaten, but if they’re the “weakest links”, they must watch their backs to avoid serious breaches.

“Offensive” security mistakes are likely to happen

Retaliatory actions against (alleged) attackers are the basis of “offensive” security. However, as in real warfare, tactical mistakes can happen, which might put innocent organisations in the crossfire.

*Original article written by Information Age editor, Ben Rossi. 

About the Author:        
Sarah writes for Firebrand Training on a number of IT related topics. This includes exams, training, certification trends, project management, certification, careers advice and the industry itself. Sarah has 11 years of experience in the IT industry. 

الأربعاء، 20 نوفمبر 2013

CryptoLocker attacks on the rise – SMEs in danger


By 


Imagine the following scenario: you are surfing on the web, checking your emails, opening the attachments and then suddenly your monitor displays a splash screen with a countdown timer and the message “Private key will be destroyed on [date]“, unless you pay. Your PC has just been infected by a relatively new, increasingly common Trojan horse malware, called CryptoLocker. All your photos, videos, documents and other important files have been encrypted and your only option appears to be to satisfy the demands of this ransomware and its creators by paying, hoping that your files will be decrypted and the nightmare ends.


The UK’s National Crime Agency has issued an urgent alert to PC users about CryptoLocker and the threats it poses. As described in the statement, tens of millions of UK customers are receiving emails that appear to be from banks and other financial institutions. However, the primary targets appear to be small and medium businesses.

According to recent reports and the NCA’s warning, the amount of “ransom” demanded by CryptoLocker is 2 Bitcoins (£550 as at 18/11/13).

What can you do against it?

Similarly to many other cases, preventive measures are more useful than trying to find a cure, especially when it’s too late. So what can we do? According to Graham Cluley’s extensive article on the matter, the answer is three-fold.
  • Keep your PC up-to-date with anti-virus and security patches and don’t open unsolicited email attachments.
  • Set a software restriction policy on your PC to prevent executables from running from certain location on your hard drive.
  • Make regular backups of your important data and keep them separate from your computer.
To learn more about CryptoLocker, read the full article on grahamcluley.com

About the Author:       
Peter writes for Firebrand Training on a number of IT related topics. This includes exams, training, certification trends, project management, certification, careers advice and the industry itself.

الأربعاء، 6 نوفمبر 2013

A story about how your life can get hacked


By 


Have you ever wondered about what it’s like to be hacked? Investigative journalist Adam Penenberg has too, so he hired a group of hackers to find out how vulnerable he is. The ground rules to this experiment forbade the hackers to do anything unlawful, for instance breaking into Adam’s house, and they also had to leave his children out of it. Other than these two conditions, the hackers, led by SpiderLabs founder Nicholas J. Percoco, were allowed any technique to breach Penenberg’s privacy as much as possible.

“It’s my first class of the semester at New York University. I’m discussing the evils of plagiarism and falsifying sources with 11 graduate journalism students when, without warning, my computer freezes. I fruitlessly tap on the keyboard as my laptop takes on a life of its own and reboots. Seconds later the screen flashes a message. To receive the four-digit code I need to unlock it I’ll have to dial a number with a 312 area code. Then my iPhone, set on vibrate and sitting idly on the table, beeps madly.
I’m being hacked — and only have myself to blame.” – extract from Adam L. Penenberg’s article.

Percoco with his team spent a few weeks trying to hack Penenberg and despite some initial difficulties, their efforts were eventually rewarded. Within a relatively short period of time, the attackers gained all the information, including passwords, usernames, credit card details, etc. that would be more than enough to ruin someone’s life.

Facebook profile, Twitter account, Amazon account, online banking, you name it. The hackers gained access to all of them. They even did a little shopping on Amazon and ordered 100 plastic spiders to Penenberg’s house, at his expense of course.

At the end of the experiment Percoco gave a report to Penenberg, which listed their plans, as well as a log of their progress. To see the chilling results, read the full article

About the Author:       
Sarah writes for Firebrand Training on a number of IT related topics. This includes exams, training, certification trends, project management, certification, careers advice and the industry itself. Sarah has 11 years of experience in the IT industry. 

الثلاثاء، 8 يناير 2013

Can I hack your password in 10 minutes?


By 


2011 saw some of the worst passwords ever recorded! In a previous post, we found that the five worst passwords of that year were:
  1. password
  2. 123456
  3. 12345678
  4. qwerty
  5. abc123
‘password’ is the number one password?

The report was made by Splashdata which gathered data from the millions of stolen passwords posted online by hackers in 2011.

But a new year has passed and with MI5 battling "astonishing" levels of cyber-attacks in the UK industry and Symantec stating in their 2011 report that they recorded thousands of hacking events every second, we have surely learnt from our mistakes, right?

According to the list below, we’re still as lazy as it gets. In the 2012 report released by Splashdata, ‘password’ is still the most popular password…

Here's the full list with comparison to 2011:

1.    password (Unchanged)
2.    123456 (Unchanged)
3.    12345678 (Unchanged)
4.    abc123 (Up 1)
5.    qwerty (Down 1)
6.    monkey (Unchanged)
7.    letmein (Up 1)
8.    dragon (Up 2)
9.    111111 (Up 3)
10.   baseball (Up 1)
11.   iloveyou (Up 2)
12.   trustno1 (Down 3)
13.   1234567 (Down 6)
14.   sunshine (Up 1)
15.   master (Down 1)
16.   123123 (Up 4)
17.   welcome (New)
18.   shadow (Up 1)
19.   ashley (Down 3)
20.   football (Up 5)
21.   jesus (New)
22.   michael (Up 2)
23.   ninja (New)
24.   mustang (New)
25.   password1 (New)

Source: Gizmodo - The 25 most popular passwords of 2012


But are we really that lazy? No and here’s why


As mentioned, this data is gathered from millions of stolen passwords posted online by hackers.

There’s a reason ‘123456’ is on this list!

Many hackers use tools to randomly guess your password, and depending on its length and characters contained, it can take the tool anywhere from 10 minutes to (in my case) 44,530 years to get!


How to make hackers wait 44,530 years to get your password


Simply make your password 9 characters, add a symbol and a number. Below you can see how long it takes to hack your current password.

Length: 6 characters
Lowercase: 10 minutes
+ Uppercase: 10 hours
+ Nos. & Symbols: 18 days

Length: 7 characters
Lowercase: 4 hours
+ Uppercase: 23 days
+ Nos. & Symbols: 4 years

Length: 8 characters
Lowercase: 4 days
+ Uppercase: 3 years
+ Nos. & Symbols: 463 years

Length: 9 characters
Lowercase: 4 months
+ Uppercase: 178 years
+ Nos. & Symbols: 44,530 years


As you can see, it’s obvious why the simple passwords are on the list. It only takes 10 minutes for hackers to get any of them. Hackers aren’t going to wait more than two days to get your ‘real’ password. So relax, the world is not as lazy as it seems… unless for reasons you won’t discuss, you are concerned to see "monkey" so close to the top.

Will 2013 bring a more creative list of passwords? let us know in the comment section below.

Lets at least hope 'password' won't still be at the top.

About the Author:
Julian writes for Firebrand Training on a number of IT related topics. This includes exams, training, certification trends, project management, certification, careers advice and the industry itself. Julian is the companies Digital Marketer.

الخميس، 20 ديسمبر 2012

The FBI holding computers for ransom?

Hackers have started to exploit the FBI’s name to take computers for ransom. It's part of latest scam in the US to come out of the creative hacker’s pot of tricks and is just in time for the festive season.

FBI RansomwareThe owners of the computers that have been targeted are greeted with a pop-up message pretending to be from the Federal Bureau of Investigation.

The message states that their computer has been locked by the FBI and that they must click to pay a fee in order to release it.

The hack is known as a ‘ransomware trap’ and is effective at what it does; holding your computer hostage until you pay the amount stated... and it works. People are believing that it really is the FBI. And the logo is just one of the many being used by criminals.

The computer security company Symantec released a report last month which claimed that 2.9% of the computers infected, have the owners cough up the money. Meaning that this one scam is worth about £3 million a year!

Ransomware is the second most popular type of malware being installed by criminals using popular exploit kits, which are designed to infect computers. But this is not just confined to the US. In the UK there have been reports of hackers using the Metropolitan Police logo to trick victims into paying £100 electronically to free their computer.

The ransomware application Reventon is the most well-known kit. It’s a Trojan programme that pops up warning messages using a respected logo depending on the country the vistim is in.

Elad Sharf, lead senior security researcher at Websense stated: “Ransomware is an increasingly common type of malware that attempts to extort money from a computer user by infecting and taking control of the victim’s machine, taking the files or documents stored on it hostage’.

He added that ransomware Trojans make it into a computer through malicious email attachments, clicking a suspicious link in an email or even on a social networking site; just like we saw on Tumblr a few weeks ago (Tumblr Hacked by GNAA).

If you or someone you know falls victim to this attack, do not pay the fine. Often times the hackers do not live up to their word of freeing your computer. And even if they do, they’ll often leave malicious software behind which gives them access to any documents or information you might have in that particular computer. There are several ways of removing the malware. You can visit an IT security professional to unlock it for you or you could even do it yourself, just watch the below how to video:



Mr Sharf also stated something you should keep in mind: “Remember also that the legitimate sources in Britain won’t use these tactics to tell you of a local compromise and then demand a financial reward to remediate the issue”.

Find out your seven deadly sins, how hackers exploit them and how you can avoid falling victim to their scams: Hackers & how they exploit 'the seven deadly sins'.

To learn to how to protect yourself and/or your company, why not take the world renowned CISSP course and gain your certification. The Certified Information Systems Security Professional (CISSP) is offered by (ISC)2. CISSP professionals are in very strong demand; it’s one of the key certs employers look for to fill management-level information security positions. To find out more click here.

For more information about security courses, and to find the right one for you, follow this link: http://www.firebrandtraining.co.uk/courses/security. You can also find information about the top 5 IT security certifications here: http://www.crisp360.com/news/top-5-it-security-certifications



About the Author:
Sarah writes for Firebrand Training on a number of IT related topics. This includes exams, IT training, , IT certification trends, project management, certification, careers advice and the IT industry itself. Sarah has 11 years of experience in the IT industry.

الاثنين، 3 ديسمبر 2012

Dearest Tumblr users - Tumblr Hacked by GNAA

Tumblr Hacked

Dearest 'Tumblr' users,  We have taken the liberty of upgrading your (rather tasteless, we must say) blog to our premier GNAA Deluxe Gary Niger (pictured to the left) Signed Edition! This is in response to the seemingly pandemic growth and world-wide propagation of the most FUCKING WORTHLESS, CONTRIVED, BOURGEOISIE, SELF-CONGRATULATING AND DECADENT BULLSHIT THE INTERNET EVER HAD THE MISFORTUNE OF FACILITATING. However, we do not believe you are beyond redemption! All you have to do is DRINK BLEACH AND DIE YOU EMO, SELF-INSISTING, SELF DEPRECATING, SELF-INDULGENT EMPTY HUSKS OF HUMAN BEINGS. REPEAT AFTER ME: I WISH I WAS PROFOUND, BUT I'M NOT! I WISH I WAS ORIGINAL, BUT I'M NOT! I WISH MY IMPENDING DEATH WAS OF ANY CONSEQUENCE, BUT IT IS MOST CERTAINLY NOT! Your last chance for redemption hinges upon your death; your death which was most fortunately prescribed by your most unfortunate birth. Fret not, dear emo, your death will be regarded as a sacrifice to humanity; to die a martyr is a glorious death, and will likely be your highest contribution to society.  SHOUTZ: LITERALKA - DOLPHIN/DZL - BERRY/BRR - RORY - INFID3L - INCOG  P.S. Attempting to delete these posts will delete your tumblr account ;] But, by all means, go ahead!Tumblr accounts are currently under attack and are being shut down. If you click on the wrong post, yours will go down too.

The exploit spreading on Tumblr was developed by the anti-blogging hacker group GNAA (Gay N***** Association of America). Many of the more popular blogs have also fallen prey to the worm such as USA Today, CNET and the Daily Dot. The Dashboard of millions of users is currently being flooded with the following unflattering message:

Dearest 'Tumblr' users,

We have taken the liberty of upgrading your (rather tasteless, we must say) blog to our premier GNAA Deluxe Gary Niger (pictured to the left) Signed Edition! This is in response to the seemingly pandemic growth and world-wide propagation of the most F****** WORTHLESS, CONTRIVED, BOURGEOISIE, SELF-CONGRATULATING AND DECADENT BULLS*** THE INTERNET EVER HAD THE MISFORTUNE OF FACILITATING. However, we do not believe you are beyond redemption! All you have to do is DRINK BLEACH AND DIE YOU EMO, SELF-INSISTING, SELF DEPRECATING, SELF-INDULGENT EMPTY HUSKS OF HUMAN BEINGS. REPEAT AFTER ME: I WISH I WAS PROFOUND, BUT I'M NOT! I WISH I WAS ORIGINAL, BUT I'M NOT! I WISH MY IMPENDING DEATH WAS OF ANY CONSEQUENCE, BUT IT IS MOST CERTAINLY NOT! Your last chance for redemption hinges upon your death; your death which was most fortunately prescribed by your most unfortunate birth. Fret not, dear emo, your death will be regarded as a sacrifice to humanity; to die a martyr is a glorious death, and will likely be your highest contribution to society.

SHOUTZ: LITERALKA- DOLPHIN/DZL - BERRY/BRR - RORY - INFID3L - INCOG

P.S. Attempting to delete these posts will delete your tumblr account ;] But, by all means, go ahead!


**We’ve taken the liberty of editing some of the offensive text of the original message 


DO NOT CLICK IF YOU SEE THE ABOVE POST, AND DO NOT TWEET A LINK TO IT as you’ll get infected too if you signed in to Tumblr.

It has been reported that 8,600 Tumblr users have been infected and counting.

What to do if you’ve been infected

Don’t worry, there’s a quick fix. All you’ll have to do is go to the Tumblr mass editor, delete the post and refresh. You should also change your password for security.

A developer has suggested that the exploit uses a"data-uri script tag" in the video embed field.

So it runs a script through the section of the site that's supposed to only allow video embed codes from sites like YouTube and Vimeo.

Dearest Tumblr usersTumblr has taken to twitter to report that they are working on resolving the issue "as swiftly as possible".