Lost in Translation...

9th

Dec-2007

Security of an IT Company and YOU…

Jerry Posted in Advice, Banking and Finance, Computer Security, Computer and Internet, Geekiness, IT Industry, Law and Order, Linux & OpenSource, Network and Security, Security, Windows/Microsoft, work 1 Comment »

Security is still a big issue in India. Since there are terrorists ready to blow up anything here, we must be aware of the fact that we are vulnerable and take all means in avoiding it. Of lately when the security measures in my company was stepped up, many employees expressed dissatisfaction and where highly irritated. Sadly they dont realize the threat. They all complained that the Security at the main gates and buildings scrutinized their belongings and treated them equally like terrorists. To a mail sent by my colleague to the Security in charge, part of the reply went like this

… We (the security and the company) are not bothered about what the employee takes unauthorized from the company(hardware and documents). But more worried about the a much more grave situation… The attack at IISc Bangalore was first planned against IT companies as they (Terrorists) realize that a well planned strike at the heart of the Silicon Valley of India, will send India’s market crashing and the country will be in a chaos in no time. Sadly our company was also in their list. They were outside our gates, looking at every move and they found the security tight even for a normal employee. Thus we were spared. Else the AKs would have gone in any of the leading IT company…

A normal Techie, works from 8-to-8 and is completely oblivious to much of the things shaping up in the outside world, spare may be Bipasha’s curves or SRK’s Abs. He doesnt realize that the Bad Guys have really turned ugly and they are recruiting Graduates and Post Grads, like most IT companies, to do the dirty job (both ways its true for the Terror Organization and IT Company). I was surprised one Monday morning when i was asked to stop at the gates and the security guy checked my ID to verify its me. After 2 years, that day i entered the campus a bit happy, coz i found the Security doing their job properly.

Sadly, the fact is, the Security at majority of the IT Companies are a bit inadequate. They in most of the cases doesn’t realize the force they are up against. Everyday i see the security at all the companies on my way to office and i bet i can breach their physical security. I dont know why i do that. But i like doing it. Every time i face a security at a gate, i think of a way of beating him without raising the slightest suspicion.

Leave alone the physical security, its the Cyber age and are we prepared against an attack via the net. No!!! Network security, if you look at most of the intranets, is getting internally compromised by the employees. Simply coz a fair number of people will click the “You won a million dollars“, flashing ad on a web page. In most of the case, that will lead to a pornographic site, at times they open up the pandora’s box for the network of the company. E-mails in particular can bring a network down. A well placed attachment asking the user to open it is more than required. Remember “I love you” or you dont coz you remember it as what your lover told you.

I have had friends approach me saying “I think my damn system is affected with virus. I have the latest in anti-virus updated everyday, the latest pop-up blocker (how did that ever block a virus), a bazooka and an entire army guarding my system… but still. Damn windows … its all because of Windows.” Let me tell you there is nothing wrong with Windows (may be not entirely and probably this will be the only time i’ll be talking for Windows and Microsoft), what is wrong is YOU. Couldn’t resist visiting the site that flashed “Sexy savvy teens… going dirty…”, or couldnt resist opening the attachment that told you how to increase what ever you have or may be had. Think before what you click on or open. They are out there to make money and they will make it any way possible.

Knowing all this what can you do … if u cant make that out by your self, then how lame are you???

“How lame are you???”, the words that lead the world’s biggest Hacker Kevin Mitnik to his fall.


20th

Dec-2006

Top 10 Web Hacks of 2006

Jerry Posted in Banking and Finance, Computer Security, Computer and Internet, Freedom, Geekiness, In My Readings, Linux & OpenSource, Network and Security, News and politics, Science and Tech., Security, Windows/Microsoft No Comments »

Quoting from ha.ckers and Jeremiah Grossman here is the list of the Top 10 Web Hacks of 2006

Top 10

  1. Web Browser Intranet Hacking / Port Scanning - (with JavaScript and with HTML-only and the improved model)
  2. Internet Explorer 7 “mhtml:” Redirection Information Disclosure
  3. Anti-DNS Pinning and Circumventing Anti-Anti DNS pinning
  4. Web Browser History Stealing - (with CSS, evil marketing, JS login-detection, and authenticated images)
  5. Backdooring Media Files (QuickTime, Flash, PDF, Images, Word [2], and MP3’s)
  6. Forging HTTP request headers with Flash
  7. Exponential XSS
  8. Encoding Filter Bypass (UTF-7, Variable Width, US-ASCII)
  9. Web Worms - (AdultSpace, MySpace, Xanga)
  10. Hacking RSS Feeds


24th

Oct-2006

A bank called Citibank

Jerry Posted in Banking and Finance, Nation No Comments »

prueba_citibank A bank called CitibankI have a serious problem in remembering my passwords. So that resulted in my citibank internet pin getting reset. I call up the customer care executive, he tell me that i have to send in a mail by post to their branch requesting for that. or i can request for a telephonic password and through that request an IPIN.

Ok, i said, place a request for TPIN. The official says “Sir i need to confirm some details… what is your DoB…. what is your card No:” and finally he asks “.. can you give me details of any latest transaction you did…”. I didnt had taht detail. So i go to the touch screen and retrieve the transactions for the last 3 months … The slip read “No Transactions”. When i said this to him he says, he needs details.

Then i had to transfer the some money from one a/c to another and i called them… Now its complete, request placed for TPIN, and then i have to do for IPIN…

BANKS .. they make you come to your knees…