Friday, 22 April 2016

Ransomware and the threat to Business

The higher the security becomes, the threats become more harmful. This is significantly true in the computer world where there are new vulnerabilities discovered every now and then. One of the most daunting threats in the past few years is Ransomware. It is a growing threat for many businesses as well as computer users.
Each month, you will hear about several ransomware attacks that take place and millions of dollars are made by those online criminals. Usually ransomware attacks are done through poisoned email attachments as well as malicious website ads. If you don�t have a good Internet security antivirus, it would be very difficult to prevent and be immune to these malicious attacks.
One of the best security companies in the world Bitdefender had predicted that such ransomware attacks will soon spread to Operating systems other than Windows and Android. This prediction is largely turning out to be true.


A major security firm Tripwire recently shared that an extremely small number of businesses believe that they can completely recover from a ransomware attack. This is generally very true because the nature of such attacks is difficult to decipher and it can prove to be harmful for the business.
A recent survey was conducted for 200 security professionals who attended the RSA 2016 conference. Through this survey, it was concluded that around 38% businesses are very confident about recovering from a harmful ransomware attack. 49% of people were doubtful over the recovery of the important data and 13% fully admitted that they were not at all confident on the recovery of data. This is certainly a worrying statistic.
These statistics indicate that companies are not using the best practices to avoid a ransomware attack. If they try to tighten their security, it would be difficult for ransomware attackers to attack their systems. Most of the businesses fear and just pay up the extortionists when they can actually recover their data from a safe back. This is one of the things major businesses are lacking and it is high time to implement the right security measures.
Any business would not want their hard earned money go into the hands of criminals who have erased all the company�s data and are seeking ransom to give it back. If you don�t want to be a victim of ransomware attacks happening these days, you can simply take secure, easy-to-store backups frequently. This will ensure that even if you lose the data, you can recover it with ease.

All phones prone to a Global cellular network vulnerability

Almost everyone in the current world uses a phone, as it is a technological device it stands a chance of being exposed to vulnerabilities. We have seen recent threats to some of the most popular operating systems including security loopholes in Android and iOS. But the devices of these operating systems are in a limited people�s hands. The biggest threat that can arise is when there is a threat to the whole global cellular network. It includes every single phone that is running on a network.


It has been found by some of the most prolific security researchers that a vulnerability in the Signaling System Seven (SS7) has been exploited to track location, see messages and phone calls on any type of smart phone in the planet. This is one of the biggest potential threats that has found its way through phones. Through this vulnerability, anyone sitting from anywhere can track a phone without the consent of the person who is the owner of the device. It is certainly very risky and can put a lot of people in trouble.
A German hacker named Karsten Nohl demonstrated very efficiently on how he leveraged this loophole to track the personal details of the iPhone which is owned by US Congressman Ted Lieu. This hack proved that no smart phone is safe and a hacker with proficiency can easily attack any phone device he wants.
To this tracking scene, Ted Lieu gave a comment on national television that said, �First, it�s really creepy, and second, it makes me angry�
The major problem that has occurred is in the SS7 or the Signaling System Number 7. It is the only telephony signaling protocol that is widely used by more than 800 operators throughout the world. This protocol is used to exchange information with one another and other major features include cross carrier billing and enabling roaming. This means that almost all the phones use this protocol to get even the simplest things done.
Even if one of the telecom operators is hacked, it means everyone who is using the service is exposed to the vulnerability. This also lets the hacker access all the information on a large scale including all the phone calls, text messages, billing information, relaying meta data and subscribers data.
According to major reports these vulnerabilities have been existing in the SS7 since the 2014 roll out. This is quite a serious problem which should have been addressed till now but experts are working on it.
Ted Lieu further stated that, �The people who knew about this flaw [or flaws] should be fired, you can�t have 300-some Million Americans�and really, right, the global citizenry � be at risk of having their phone conversations intercepted with a known flaw, simply because some intelligence agencies might get some data.�
The only way to be safe of this loophole is to encrypt all your data before it leaves your smart phone.

Thursday, 3 July 2014

Snapdeal is vulnerable to Xss(Reflected)

 Snapdeal.com is an online marketplace, headquartered in New DelhiIndia. The company was started by Kunal Bahl, a Whartongraduate as part of the dual degree M&T Engineering and Business program at Penn, and Rohit Bansal, an alumnus of IIT Delhi in February 2010.Snapdeal.com was started in February 2010 as a daily deals platform but expanded in September 2011 to become an e-commerce company via a marketplace model. With 20 million registered users, Snapdeal is one of the first and largest online marketplaces in India offering an assortment of 4 million+ products across diverse categories from over 20,000 sellers, shipping to 4,000 towns and cities in India.

Further on testing i found Xss vulnerability in m.snapdeal.com 

Affected Url:







































Regards: gd 4TT4CK3R !!!!

Saturday, 10 May 2014

Bangladesh Railways is vulnerable to XSS

Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted web sites. XSS attacks occur when an attacker uses, a web application to send malicious code, generally in the form of a browser side script, to a different end user. Flaws that allow these attacks to succeed are quite widespread and occur anywhere a web application uses input from a user within the output it generates without validating or encoding it.An attacker can use XSS to send a malicious script to an unsuspecting user. The end user�s browser has no way to know that the script should not be trusted, and will execute the script. Because it thinks the script came from a trusted source, the malicious script can access any cookies, session tokens, or other sensitive information retained by the browser and used by that site.








Regards: GD 4TT4CK3R

Tuesday, 15 April 2014

PC Jeweller is vulnerable to SQL injection

PC Jeweller started operations in April 2005 with one showroom at Karol Bagh Delhi. It is a first generation business promoted by two brothers- Sh Padam Chand Gupta and Sh Balram Garg. The company, however, had a vision of expanding its presence in the retail segment .

The company's business model consists of opening large format, stand alone stores at high street locations. It's stores stock a wide range of jewelry across all price points, with an increasing focus on diamond jewellery. The company sells only hallmarked jewelry and certified diamond jewelry. This assurance on quality & purity along with transparent & customer friendly policies has enabled PCJ to become an established and trusted brand name in a short time span.

It has accordingly been opening showrooms at regular intervals and today has a strength of 41 stores spread over 33 cities.

The most valued asset is our relationship with the clients, which has been built over years by giving certified quality, latest designs, transparency in dealings and best personalized customer service. Proactive and timely research and creation of world class jewelry and also guidance to its customers to enable them to take correct purchase decisions.

The company is confident that its trust on diamond and other high margin jewellery along with customer oriented marketing initiatives would continue to help grow its top line as well as the bottom line.

Mr. Padam Chand Gupta, Chairman of the Company has our three decades experience in jewelry.

Mr. Balram Garg, Managing Director of the Company can easily be called the goodwill ambassador of this group. A man of clear vision and strong decision, Mr. Garg's approach in business rests on his belief that nothing is impossible.


 Ok, Further on tesing i found a vulnerability of SQL injection in it.



Injection flaws, such as SQL, OS, and LDAP injection occur when untrusted data is sent to an interpreter as part of a command or query. The attacker�s hostile data can trick the interpreter into executing unintended commands or accessing data without proper authorization.











































Regards:GD 4TT4CK3R



Monday, 14 April 2014

Andhra Pradesh Grameena Vikas Bank is vulnerable to SQL injection

APGVB Formation




 By amalgamation, on the 31st March 2006, of the following 5 banks, sponsored by SBI, to participate more energetically, with synergy, in the uplift and development of Rural Farm Sector and Rural Non-Farm Sector, with emphasis on the deprived, the Rural Poor, Rural ISB and Rural Crafts.

 Further on testing i found vulnerability in http://www.apgvbank.in 


Hope they will patch the vulnerability  as soon as possible.





Regards:GD 5TT5CK3R


Friday, 11 April 2014

Jammu University is Vulnerable to SQL Injection

Ok Guys,Further on testing I found vulnerability in Jammu University



 



Regards: GD 4TT4CK3R

Thursday, 10 April 2014

Pakistan Geo Tv News is Vulnerable to XSS

Further on testing i found vulnerability in Geo TV News of Pakistan

Affected URL:   http://geo.tv/SearchNews.aspx?URL=%3Cscript%3Ealert%28%27test%27%29;%3C/script%3E







Regards:GD 4TT4CK3R

IIPM College is Vulnerable is XSS

Founded in 1973, The Indian Institute of Planning and Management has grown to become one of the most respected business schools in South Asia . Its unique focus on national economic planning and highly researched management process control techniques has rewarded it with having the most exhaustive linkages with all facets of the corporate world. The Integrated and Full Time Programme in National Economic Planning and Entrepreneurship provided by IIPM (which are superior to standard MBA and BBA programs), alongwith IIPM's Fellowship, Executive Education (and Global Opportunities and Threats Analysis programs where students visit organizations like the United Nations (Geneva), World Bank, ILO, Nestle S.A. Vevey, IMD Lausanne, Credit Suisse etc.) have created some of the highest standards in the management field.

Further on testing i found vulnerability








Regards: GD 4TT4CK3R

Wednesday, 9 April 2014

Nivia Sports is Vulnerable to XSS

NIVIA � India�s leading Sports Brand, influential and intimately involved in shaping the sports in the country. As the originator of breakthrough technologies & innovative products , for decades NIVIA has produced legendary classics and earned nation-wide legitimacy in each sport that it has participated in. Backed by generations of sportsmen, NIVIA is the true INDIAN Iconic Sports Brand. NIVIA is Indian leading manufacturer of sports equipment, footwear & accessories. Our core sports are Football, Volleyball, Basketball, Cricket, Tennis, Hockey, Badminton and Squash.
Established since 1934, NIVIA is Headquartered in Jalandhar, India, NIVIA employee force is more than 2000, our dedicated sales network spreads to more than 1200 Dealers across India.

NIVIA is an Freewill Sports Pvt Ltd Brand.

Further on testing i found xss 

Affected url:
http://www.niviasports.com/search.php?keywords=<script>alert('test')</script>
























Regards: GD 4TT4CK3R

Tuesday, 8 April 2014

Sumpoorna Portfolio Limited is Vulnerable to SQL injection

Sumpoorna Portfolio Limited (�Sumpoorna Stock�/ �The company�) represents the equities arm of the Sumpoorna group. The company is a corporate member of both The National Stock Exchange of India Limited and The Bombay Stock Exchange, providing equity broking and research services, and catering to retail clients, domestic and foreign institutional investors. The company is focused on providing products, strategies and services to Corporates, HNIs, and retail clientele. We have a pan-India presence through our various channels, providing clients with the tools and services they need to maximize their investments performance and attracting new sources of capital.
Sumpoorna Stock spearheads the Capital Markets broking division of the Group, which provides services range from offline & online trading in equity, commodities and currency derivatives to debt market. 












Regards by GD 4TT4CK3R


Saturday, 21 December 2013

Zee Cinema is Vulnerable to LFI(local file inclusion) + iframe Injection.

Local File Inclusion (LFI) is a type of vulnerability which is mostly found in websites. It allows hacker to include a local file, usually through a script on the web server. The vulnerability occurs due to the use of user-supplied input without proper validation.  LFI Vulnerability allows an attacker to add any local file to Website Server through script. LFI is very dangerous vulnerability which can lead to website Defacement, Command Execution and many more........

Here are some of the common parameters which are vulnerable to local file inclusion or remote file inclusion attacks

read.html?link=
index.php?homepage=index.php?

page=index.php?index2=

But recent days I was testing Zee Cinema for vulnerabilities and i found that it is vulnerable to local file inclusion.









Enjoy!!!!!!!!!!!!!

Wednesday, 2 October 2013

Wireshark (what's on your network) and how to analyse packets in it???

 Wireshark is the world's foremost network protocol analyzer. It lets you see  what's happening on your network at a microscopic level. It is used across  many industries and educational institutions.It is a network packet analyzer. A  network packet analyzer will try to capture network packets and tries to  display that packet data as detailed as possible.You could think of a network    packet analyzer as a measuring device used to  examine what's going on inside  a network cable, just like a voltmeter is used  by an electrician to examine  what's going on inside an electric cable. 
However, with the advent of Wireshark, all that has changed. Wireshark is perhaps one of the best open source packet analyzers available today.

 

 Features of Wireshark:

  • Available for UNIX and Windows.
  • Capture live packet data from a network interface.
  • Open files containing packet data captured with tcpdump/WinDump, Wireshark, and a number of other packet capture programs.
  • Import packets from text files containing hex dumps of packet data.
  • Display packets with very detailed protocol information.
  • Save packet data captured.
  • Export some or all packets in a number of capture file formats.
  • Filter packets on many criteria.
  • Search for packets on many criteria.
  • Colorize packet display based on filters.
  • ... and a lot more!

    For more information visit http://www.wireshark.org/


    How to Analyse a Packet in Wireshark:

    First of all download the .pcap file here which has to be open in wireshark.

    Now Open the downloaded file analyst.pcap in the wireshark as shown below image:


    So lets analyse from the above diagram::::
    Line 1 - the internal host at 192.168.1.100 has successfully connected to an outside server at 5.4.3.2 listing microsoft-ds (file sharing). Analysis - looks suspicious as internal hosts should not be sharing files outside the network.
    Line 2 - the internal host at 192.168.1.100 has successfully connected to an outside server at 5.192.78.3 on TCP port 31337.
    Analysis - looks suspicious as this port is known to be used by multiple Trojans, namely, Back Orifice.

    Line 3 - the internal host at 192.168.2.142 has sent an ICMP echo (ping) request to an outside server at 5.255.255.255 (broadcast).
    Analysis - this looks suspicious as malware will perform certain basic functions, after infecting the internal system they need to phone home and let their owner know that he/she has another satisfied customer.


    Line 4 - the internal host at 192.168.2.142 has connected to an outside server at 64.157.165.182 and looks to be infected spyware.
    Analysis - "Gator.exe" belongs to the Claria advertising program, it's running process on your system may be "Adware.W32.Claria". This process monitors your browsing habits and distributes the data back to the author's servers for analysis. This also prompts advertising popups. This process is a security risk and should be removed from your system.


    Line 5 - the internal host at 192.168.2.142 has connected to outside server at 5.192.33.34 listing "sunrpc".
    Analysis - Sun's Remote Proceedure Call forms the basis of many UNIX services, especially NFS (Network File System). However, RPC is extremely dangerous when left exposed to the Internet, which leads to frequent compromise of servers based upon Sun Solaris and Linux. RPC should never be exposed to the Internet.


    Line 6 - the internal host at 192.168.1.100 has attempted to connect to outside server at 66.75.160.13 using SMTP.
    Analysis - this looks suspicious as this host appears to be infected, though secureinfo.com is a company that performs vulnerability assessments, penetration testing and security auditing services. If I was not informed of this in advance, I would still treat this as suspicious until confirmed otherwise. It could also represent an infected host sending an email worm. 
    The next step is to remove this host from the network, review any compliance regulations if any apply (i.e. PCI, SOX, HIPAA, GLBA), perform a complete virus scan to remove all malware, update and apply all patches. Next, I would recommend reviewing all log files to determine the origin of the infection to prevent further problems.


    Line 7 - the internal host at 192.168.2.142 has connected to outside server at 66.136.57.21 containing "winnt/system32/cmd.exe".
    Analysis - This tells me that this internal host may be infected with the Nimbda worm, which unlike the Code Red worm spreads as an email attachment and can infect everyone in your email client's contact list by sending a malicious attachment sometimes named "readme.exe"


    Line 8 - the internal host at 192.168.0.68 has sent a syn packet to an internal host with the same ip address 192.168.0.68 listing microsoft ds (file sharing). 
    Analysis - This is suspicious as it could represent ip spoofing attempt to gain access to internal file shares.


    Line 9 - the internal host at 192.168.0.68 has sent a request to an outside server at 5.222.3.1 using IRC protocol.
    Analysis - This is suspicious as it may be an infected internal host phoning home to tell it's master that it is infected.


    Line 10 - the internal host at 192.168.0.68 has requested a file (test.exe) transfer from an outside server at 5.234.7.2 using the TFTP protocol.
    Analysis - This is suspicious. TFTP uses UDP port 69, rather then tcp port 21 like ftp, and can cause DOS. It uses no authentication or encryption mechanisms, and is used to read files from, or write files to, a remote server. "Due to the lack of security, it is dangerous over the open Internet. Thus, TFTP is generally only used on private, local networks."
    Also, based on the previous events with this internal host, it appears to be malicious activity.


    Overall analysis is to perform complete anti virus scans of hosts 192.168.1.100, 192.168.2.142 and 192.168.0.68. and carefully check the running processes and services for anything not listed as a Microsoft service or authorized application (located in c:/Windows or c:/Windows/System32 folders). Also, check for unauthorized services and startup programs.

    Enjoy!!!!!!!!!!!!!!!!!!!1