Thursday, September 23, 2021

Encryption or Cryptography basics

Encryption or Cryptography

This is one of life changing technology, ever introduced. It helps in providing data security for sensitive information. Encryption or cryptography both carries same meaning. Cryptography is like secure communications techniques by encoding the message using encryption. Encryption is a process of scrambling data or information so that only authorized receiver can understand the information. 

Encryption is a way of encoding data in secure way so that only authorized parties can understand or read it. Technically, it is the process of converting human readable plaintext to inexplicable text, which is known as ciphertext. In simpler terms, encryption takes readable data and alters it in a way so that it appears random data. 

It can help in protecting the data you send, receive, and store, using a system or device. Such information is including of text messages stored on your smartphone, media files and personal files at your personal systems, running logs in the fitness watch, health data from smart watch and banking information sent through your online account, computer log files etc.

Encryption requires the use of a cryptographic key. There are two types of encryption available in market, i.e. Symmetric key and asymmetric key encryption.

  • Symmetric encryption uses a single password or key to encrypt and decrypt data and all communicating parties use the same secret key.
  • Asymmetric encryption uses two keys for encryption and decryption. one password or key is used for encryption, and a different key is used for decryption. 

A key

A cryptographic key is a string of characters used within an encryption algorithm for altering data so that it appears random. Same as a physical key, it locks (encrypts) data so that only someone with the right key can unlock (decrypt) it.

Similarly, two types of key used is known as public key and private key. A public key, which is shared among users, encrypts the data. A private key, which is not shared, decrypts the data.

Why needed

It is mostly required for privacy, defending hacking and attacks, regulatory requirements, authentication, availability and data integrity etc. Encryption is essential to help protect your sensitive personal information. Users should always encrypt any messages they send, preferably using a form of public key encryption. It is also a good idea to encrypt critical or sensitive files anything from personal photos, sets of family photos, company data like personnel records or accounting history, health data etc. However, most drawback of encryption is, it can be used against users in form of ransomwares attacks which is presently a trending attack.

Many organizations, technology firms were using encryption since a long time. Big software and application firms have also implemented encryption at multiple environments. Most legitimate websites use what is called secure sockets layer (SSL), which is a form of encrypting data when it is being sent to and from a website. This keeps attackers away from accessing that data in transit. Windows offers full disk encryption with Windows 10 pro edition. Mac OS X Yosemite wants you to set up encryption by default when you install it. Linux distros also provides encryption at the time of installation. Many encryption tools are available to use for disk encryption, os encryption, file encryption etc.

Common Encryption types

There are common encryption types or encryption algorithms used are as; AES, DES, SNOW, Elliptic curve cryptography, RSA, Triple DES, TwoFish and encryption using SSL etc. on a brief lets look below,

DES

Data Encryption Standard (DES) was introduced at 1977 by U.S Govt. a low level encryption standard. DES has a smaller key size which makes it less secure to overcome this triple DES was introduced but it turns out to be slower. DES takes input as 64-bit plain text and 56-bit key to produce 64-bit Ciphertext.

AES

Advanced Encryption Standard introduced in 2001 by NIST and is widely used now a days which is advanced encryption. AES have 128,192, or 256-bit secret key.

RSA 

Rivest-Shamir-Adleman (RSA) is an asymmetric encryption algorithm that is based on the factorization of the product of two large prime numbers.

Twofish

Twofish is considered one of the fastest encryption algorithms and is free to use. It uses the method that ciphers data blocks of 128 bits. 

In this cloud technology era, the cloud platform are also coming with encryption by default. For example: Data stored in AWS is secure by default; only AWS owners have access to the AWS resources they create. However, customers who have sensitive data may require additional protection by encrypting the data when it is stored on AWS.

Finally, this is just basic understanding on encryption. Secure end to end encryption makes life easier and safer for everyone. So use encrypted service and use encryption to protect yourself. 

Many tools are there for the encryption whether for file and folder encryption or full disk encryption. 

Windows pro comes with bitlocker by default encryption standard. 

similarly 96Crypt (shareware), Advanced encryption package, Bitcrypt, PGP, etc. 

Please feel free to share your comments.

-DR


Thursday, August 26, 2021

SCAM! And Phishing mail Alert | Latest Mails on Sextortion

 SCAM and Phishing Alert!!! 

This is what you are worried about in last couple of days, after receiving an email in your personal inbox. 

I know, XXXXX, is your password. You may not know me and you're most likely wondering why you are getting this e mail, correct?

In fact, I placed a malware on the adult videos (porn material) web-site and you know what, you visited this website to have fun (you know what I mean). While you were watching video clips, your internet browser initiated operating as a RDP (Remote Desktop) that has a keylogger which provided me access to your screen and also webcam. Immediately after that, my software program/ key logger gathered your entire contacts from your Messenger, FB, social networks, as well as email.

What did I do?

I made a double-screen video. 1st part shows the video you were watching (you have a good taste omg), and 2nd part shows the recording of your webcam.

exactly what should you do?

Well, I believe, $2900 is a fair price for our little secret. You'll make the payment by Bitcoin (if you don't know this, search "how to buy bitcoin" in Google).

BTC Address: 1MQNUSnquwPM9eQgs7KtjDcQZBfaW7iVge

(It is cAsE sensitive, so copy and paste it)

Note:

You have one day in order to make the payment. (I have a specific pixel in this email message, and at this moment I know that you have read through this email message). If I do not get the BitCoins, I will definitely send out your video recording to all of your contacts including family members, coworkers, etc. However, if I do get paid, I'll destroy the video immediately. If you want to have evidence, reply with "Yes!" and I will certainly send out your video to your 14 contacts. This is the non-negotiable offer, so please don't waste my personal time and yours by responding to this email message.

If you go to law and enforcement, no value will be there as this email is also hacked one. 

This is the message/ email you have received right? The amount hacker demanded may differ from victim to victim. 

So first of all, you need not to be worry. Don’t panic. Contrary to the claims in your email, you haven't been hacked (or at least, that's not what prompted that email). This is merely a new variation on an old scam which is popularly being called "sextortion." This is a type of online phishing that is targeting people around the world and aggressive on digital fears since 2018 year and continuing.

Reason you get this mail because, your mail id at somewhere may have breached. You may have registered at some website, forum, online training site, ecommerce site, etc. and that page may have been breached along with the user credential. As per the CERT-In advisory, although the listed passwords, shown as evidence that your account is hacked could be actual passwords that you used in the past, the attacker does not know them by hacking your account, but rather through leaked data breaches shared online.

So, the advice here is never ever pay them. 

If you pay the amount, you are not only losing your money but you are inspiring the scammers to continue phishing other people. If you do pay, then the scammers may also use that as a pain point to continue the blackmail with you, knowing that you are susceptible.

What you need to do:

  • Immediately change the same password related to the account if you have.
  • Change your password at regular interval of time. 
  • Add multifactor authentication to all social and email accounts.
  • Never send compromising images of yourself to anyone, no matter who they are.
  • Don’t open attachments from people you don’t know, and in general be wary of opening attachments even from those you do know.
  • Turn off [and/or cover] any web cameras when you are not using them.
  • If possible, report the scam at nearest govt. cyber investigation office.



Stay Safe!

-DR



Cyber Security | Mobile Security & Malware

Mobile Security & Malware Attacks

Malware attack on smart phones, malicious dot apk files, Trojans, ransomware and viruses are known threats to mobile devices now a days. Rapidly increasing the use of mobile devices resulted in, mobile devices are becoming an increasingly attractive target of Cyber attackers or hackers. 

In case of Android mobiles, all the applications are available at Google Play store only. In that case, those are again verified or vetted by third party or google team before available on play store. Still there are some malware based payloads come through image file, video file, pdf files, etc. in hidden format unknowingly. As applications allowing users to view and make transactions on financial accounts, auction listings, paying bills, subscription renewals and shopping accounts linked to credit cards/ debit cards / Internet banking are becoming commonplace. The functionality of such applications are expanding to the certain point where they will be an favorite target for online cyber criminals. 

Again there are many associated risk of exposure of credentials to critical online services, banking apps, payment wallets, mobile devices can also expose information such as business contacts, call logs, geographic data, personal information including private photos and internal company information. 

Present malwares automatically sends SMS, pays self bills, destroys data, takes remote control on devices, installing key loggers, harvests tracking information on users, and even uses desktop computers to spread itself. Worms have expanded to use hardware ports such as Bluetooth, memory cards, and Wi-Fi as replication channels.

Even many worms and Trojans have been subjected of widely published press releases by security and antivirus vendors with their POC, which has made it somewhat unclear what the real threats posed are.  There are in fact a large number of mobile viruses and malicious programs, but few have succeeded in terms of infection rate.

Below are few examples on mobile device malware software:

Cabir

The first ever discovered mobile malware was planned for the Symbian OS in the form of the Cabir worm, and was largely analogous to early PC viruses the purpose was simple replication or vandalism. Cabir spread over Bluetooth connections, prompting users within range to install an application and asking repeatedly until the user accepted. The worm then made system modifications and began to scan for other Bluetooth peers within range. However, Cabir never gained a significant foothold in the market.

Beselo.B

The first worm that was used media files to spread was Beselo.B. This worm sent either JPG, MP3, or RM files over Bluetooth and MMS. It also copied itself onto Multi Media Cards (MMC), where it would infect any other phone into which the card was inserted. But it was not spreaded extensively.

WinCE/Brador.a

The Brador.a Trojan infected earlier Windows Mobile devices (2003), notifying the Trojan’s owner of the compromise and then listening on a TCP port for remote instructions. It had simple backdoor capabilities, that was allowing for uploading and downloading files, self executing commands, and sending list of directories and trees.

Finally the best practices are to keep your mobile safe and secure;

  • Always keep your applications updated from trusted sites.
  • Use antiviruses in mobiles
  • Do not click unknown links and unverified links
  • Do not believe on forward links always, without checking HTTPs
  • Padlock symbol need to be watched also.
  • For more on security tips you can check another post in this blog.

Do you have further queries and suggestions, feel free to add in comment section.

-DR


Network Scanning Tools

Network Scanning through Nmap and Nessus Network scanning is a process used to troubleshoot active devices on a network for vulnerabilities....