security for hacking

10 Most Common Web Security Vulnerabilities by Toptal.com

Topal.com is one of the top web site which writes on web application security research. Here is post written by GERGELY KALMAN - Security specialist about

"10 Most Common Web Security Vulnerabilities"


For all too many companies, it’s not until after a breach has occurred that web security becomes a priority. During my years working as an IT Security professional, I have seen time and time again how obscure the world of IT Security is to so many of my fellow programmers.
An effective approach to IT security must, by definition, be proactive and defensive. Toward that end, this post is aimed at sparking a security mindset, hopefully injecting the reader with a healthy dose of paranoia.
In particular, this guide focuses on 10 common and significant web security pitfalls to be aware of, including recommendations on how they can be avoided. The focus is on the Top 10 Web Vulnerabilities identified by the Open Web Application Security Project (OWASP), an international, non-profit organization whose goal is to improve software security across the globe.

A little web security primer before we start – authentication and authorization

When speaking with other programmers and IT professionals, I often encounter confusion regarding the distinction between authorization and authentication. And of course, the fact the abbreviation auth is often used for both helps aggravate this common confusion. This confusion is so common that maybe this issue should be included in this post as “Common Web Vulnerability Zero”.
So before we proceed, let’s clearly the distinction between these two terms:
  • Authentication: Verifying that a person is (or at least appears to be) a specific user, since he/she has correctly provided their security credentials (password, answers to security questions, fingerprint scan, etc.).
  • Authorization: Confirming that a particular user has access to a specific resource or is granted permission to perform a particular action.
Stated another way, authentication is knowing who an entity is, while authorization is knowing what a given entity can do.

How to prevent facebook account from hacking attack

  1. Here are some steps to prevent your facebook account from hackers attack!
  2. Protect Your Facebook Account from Hackers Step 2 Version 2.jpg
    2
    Never share your passwords with anyone including your friends and family. Browsing through a secure connection is always advisable.
  3. Protect Your Facebook Account from Hackers Step 3 Version 2.jpg
    3
    Don’t get your news feed flooded with suspicious links. Ensure that you don’t click on any links of games, apps, and others that you are not sure of. Avoid permitting third party apps accessing your information. If you are not using any apps, it’s better to disable or remove those apps.
  4. Protect Your Facebook Account from Hackers Step 4 Version 3.jpg
    4
    Add a secondary email ID to your account. In case your profile is hacked, Facebook will send account recovery information to the secondary email ID also. Before these steps, understand the privacy policy of Facebook.
  5. Protect Your Facebook Account from Hackers Step 5 Version 3.jpg
    5
    Ensure that you accept only persons you know as your friends as when you accept strangers, you allow them to access your personal information. It’s always better to avoid posting any financial or personal details.
  6. Protect Your Facebook Account from Hackers Step 6.jpg
    6
    Change your passwords regularly and use unique passwords. Don’t forget to activate your login notifications.
  7. Protect Your Facebook Account from Hackers Step 7.jpg
    7
    For many of us, Facebook is our best buddy, a chronicle of our life, our diary of sorts and an outlet for our creativity. We can’t risk our Facebook account at any cost and we certainly try all the possible ways to keep it as personal and secure as we can.

How to do phishing? How to Protect Yourself from phising

What is Phishing?

There's a new type of Internet piracy called "phishing." It's pronounced "fishing," and that's exactly what these thieves are doing: "fishing" for your personal financial information. What they want are account numbers, passwords, Social Security numbers, and other confidential information that they can use to loot your checking account or run up bills on your credit cards.
In the worst case, you could find yourself a victim of identity theft. With the sensitive information obtained from a successful phishing scam, these thieves can take out loans or obtain credit cards and even driver's licenses in your name. They can do damage to your financial history and personal reputation that can take years to unravel. But if you understand how phishing works and how to protect yourself, you can help stop this crime.

How Phishing Works

In a typical case, you'll receive an email that appears to come from a reputable company that you recognize and do business with, such as your financial institution. In some cases, the email may appear to come from a government agency, including one of the federal financial institution regulatory agencies.
The email will probably warn you of a serious problem that requires your immediate attention. It may use phrases, such as "Immediate attention required," or "Please contact us immediately about your account." The email will then encourage you to click on a button to go to the institution's web site. In a phishing scam, you could be redirected to a phony web site that may look exactly like the real thing. Sometimes, in fact, it may be the company's actual web site. In those cases, a pop-up window will quickly appear for the purpose of harvesting your financial information.
In either case, you may be asked to update your account information or to provide information for verification purposes: your Social Security number, your account number, your password, or the information you use to verify your identity when speaking to a real financial institution, such as your mother's maiden name or your place of birth. WARNING: If you provide the requested information, you may find yourself the victim of identity theft.

How to Protect Yourself

Never provide your personal information in response to an unsolicited request, whether it is over the phone or over the Internet or even a fax or letter. Emails and Internet pages created by phishers may look exactly like the real thing. They may even have a fake padlock icon that ordinarily is used to denote a secure site. (It's important to keep anti-virus and anti-spam filtering software up-to-date on your computer.) If you did not initiate the communication, you should not provide any information.
If you believe the contact may be legitimate, contact the financial institution yourself. You can find phone numbers and web sites on the monthly statements you receive from your financial institution, or you can look the company up in a phone book or on the Internet. The key is that you should be the one to initiate the contact, using contact information that you have verified yourself.
Never provide your password over the phone or in response to an unsolicited Internet request. A financial institution would never ask you to verify your account information online. Thieves armed with this information and your account number can help themselves to your savings. (It is a good idea to periodically change your passwords and PIN numbers to improve security.)
Review account statements regularly to ensure all charges are correct. If your account statement is late in arriving, call your financial institution to find out why. If your financial institution offers electronic account access, periodically review activity online to catch suspicious activity.

PSN Hacking – The law-suit is closed, Sony paid the charges

The lawsuit that was filed against Sony for the famous hacker attacks suffered by the NDP in 2011, or at least one of those organized in the United States, has been closed by Judge Anthony Battaglia, Sony released all the charges. The reason being that none of the plaintiffs in the law-suit signed up for any premium subscription on Playstation network, and used the services for free.

PSN Logo1 PSN Hacking   The law suit is closed, Sony paid the charges
In addition to receiving the free service, there is another point that free Sony accusations: the same formulation of the cause is hereby given that the service has been suspended for an illegal attack brought from outside intrusion into the Network which Sony is not responsible for. Addition to the agreement signed by the use of PSN users it is reported that if the system is not perfect and that errors and problems can emerge, then the person signing the agreement does so at his own risk with regard to any failure.

ID card-based criminal record checks get thumbs up

Plans for a new service using the government’s controversial ID cards scheme to speed up criminal record checks have met with approval from volunteers involved in a trial of the technology. The volunteers piloted two potential online services developed by the Identity and Passport Service (IPS) and the Criminal Records Bureau (CRB) which could be used to authenticate the identities of and information supplied by job applicants.

At the trials, all volunteers went through a simulated experience of applying for a position requiring a CRB check. The participants met a prospective employer, filled out the CRB disclosure application form and had their identity authenticated by a counter-signatory. Their criminal record information was then disclosed to the company requesting it.
Each volunteer completed two legs in the trial — one using a passport and one using an ID card.
The passport-based system would use an applicant’s UK passport with information from the IPS to make sure the data provided is correct — with this system likely to come into effect before the second system. The second online service would use ID cards issued to UK citizens and foreign nationals residing in the UK for more than three months with information from the IPS to check application data. This system could be introduced in the longer term.
Nearly all (96 percent) of the 160 volunteers said the passport-related service is an improvement on the current arrangement and 71 percent rated it as a “great improvement”.
Nearly nine out of 10 volunteers said the ID card-linked service is even more robust than the passport-linked process.
But Phil Booth, national co-ordinator of the NO2ID anti-ID card campaign, criticised the trial because he said it tested the customer experience of the CRB check in isolation, while “glossing over the inconvenience and intrusiveness of the ID system as a whole”.
Booth said: “IPS is trying to sell a so-called benefit without any reference to actual cost or reality.”

Back to Top