Showing posts with label Security News. Show all posts
Showing posts with label Security News. Show all posts

Thursday, April 21, 2016

5 Types of Cyber Crime in Nepal You should know About

The internet is a medium which enables the spread of information and communication between people at a world-wide level. The internet is a ‘free’ medium, with no international laws and regulations upon it, therefore, it is extremely difficult to both monitor and prohibit transactions that occur within it. A Cyber Crime is an act of creating, distributing, altering, stealing, misusing and destroying information through the computer manipulation of cyberspace; without the use of physical force and against the will or interest of the victim.

5 Main Cyber Crime in Nepal

Social Media Related Cyber Crime

Social Media related cyber crime in Nepal includes using Porn Content in social Media or creating fake profiles to intentionally harm someone with the use of Facebook, Twitter, Instagram or any social Media Platform.
In the year 2070, a total of 19 cases of Social Media Cybercrimes were reported. With the trending use of Social Media, the number of cases has increased to 35 in 2072. It has been seen that the number of female victims is more. Using Naked Pictures in social Media to take revenge has been the most cases according to Crime Investigation Bureau (CIB) Nepal.
A Government staff name Raju Shah was under police custody when a comment against the contemporaneous home minister Bam Dev Gautam was tracked on Facebook. Raju Shah was found guilty when he demanded death sentence against Minister Bam Dev Gautam who was caught in a photo breaking a traffic rule.
download (1)

Piracy Related crime

Any Content which has been copied to make a duplicate copy is considered as Piracy. Using unauthorized trademarks and copying source code without having the License to use it is considered Piracy Crime.
Example, the font used in Company logos can also be related to piracy crime, if the font is not listed free for business purposes. Even though this related crime is not a possibility in today’s context of Nepal, but we can see a various example of Font piracy. Read a story of Font Piracy.
Also, Source Code piracy case have been heard in Nepal lately. Since the case has not been solved, the whole story is an unsolved mystery. It has been allegedly reported that a software company filed a case against a Media House for copying their source code.

Fake Profile Marketing

Creating or using a fake profile, fake website or email to create a bad image or inappropriate marketing is also considered as cybercrime. We can see various examples of fake profiles, fake websites, and spam emails. Spreading unwanted and inappropriate message using fake profile is considered a Fake Profile Marketing. This rule also implies to businesses where a fake product is sold. Marketing of fake duplicate product using the name of a different brand also comes under the Fake Marketing Cyber Crime.
Cyber Crime in Nepal
Threatening Using Email
Email threat is not much common cybercrime in Nepal. If an email contains a threat or warning in mentality to harm or disturb any individual or any organisation, this is considered as a cyber crime.

Website Hacking

Website Hacking means taking control from the website owner to a person who hacks the website. Nowadays most of the government websites are attacked by hackers. Many governmental websites including the president’s website were hacked. Any complaint on website hacking can be a serious offence in terms of the cyber law in Nepal.
Recently, a group of Nepalese hacker named Anonymous opnep breached into the server of Nepal Telecom. Hackers gained access to all the details of NTC users that include username, citizenship name, father’s name as well as other private information. Metropolitan Crime Division recently tracked the hackers down and arrested 18-year-old Bikash Paudel for hacking over 200 websites including the NTC website.

Unauthorized Access

Unauthorised access is one of the common issues in cybercrime world. Getting access to a website, programme, server, service, or other system using someone else’s account or other methods is called Unauthorized Access.
cyber crime nepal
Examples of the unauthorised use of computers include an employee using a company computer to send a personal e-mail or someone gaining access to a bank computer and  performing an unauthorised transfer.

Online Business of Restricted Materials

The business involving the buying and selling of illegal or restricted materials can be a case of cyber crime. One interesting case had come up when a Nepali citizen named Kirtan Pokhrel was arrested for creating an event related to sexual tourism. The Event was named Bunga Bunga which promised to have girls of ages 13 to 17.
Continue Reading →

Nepal Telecom ADSL Users Username/Password Hacked



A group of Nepalese hacker has claimed to have breached the Nepal Telecom ADSL server and have gained access to user’s WiFi SSID and password. They claim that more than 47300 Nepal Telecom TP-LINK Routers are vulnerable to Hackers. TP-LINK is an electronics manufacturer famous for its budget-oriented ADSL and DSL routers.

Moreover, these hacker has published the list of ADSL username and their respective password in this link here. This is not the first time that the NTC’s server was hacked. Last month, a group called Anonymous ‪opnep gained access to all the details of NTC users that include username, citizenship name, father’s name as well as other private information which you have to fill up during new SIM registration. Metropolitan Crime Division recently tracked the hackers down and arrested 18-year-old Bikash Paudel for hacking over 200 websites including the NTC website.
The series of hacks points out to the fact on how insecure NTC’s server are. The hackers even mocked at the low security of NTC’s websites and had threatened of more such cyberattacks. If Nepal Telecom, the largest telecommunication service provider in Nepal, wants to enhance its digital advancement, it should also be prepared for the cyber battle and should be armed with security and cyber experts to avoid such breach. Please Wakeup NTC!
Continue Reading →

Enable this New Setting to Secure your Computer from Macro-based Malware


secure-windows-computer


Do you deal with MS Word files on the daily basis?


If yes, then are you aware that even opening a simple doc file could compromise your system?


It is a matter to think that the virus does not directly affect you, but it is you who let the virus carry out the attack by enabling deadly "Macros" to view the doc contents that are generally on eye-catching subjects like bank invoice.


How Macros are Crippling your System?


The concept of Macros dates back to 1990s. You must be familiar with this message: "Warning: This document contains macros."

A Macro is a series of commands and actions that help to automate some tasks. Microsoft Office programs support Macros written in Visual Basic for Applications (VBA), but they can also be used for malicious activities like installing malware.


Hackers are cleverly using this technique on the shade of social engineering by sending the malicious Macros through doc file or spreadsheet with an eye-catching subject in the mail to the corporate networks.


Once a user opens the malicious Word document, the doc file gets downloaded to its system. However, danger comes in when the user opens the file, and a popup window appears that states "Enable Editing" to view the content.

microsoft-office-macro-protected-view
Once the users click Enable Editing, the malicious file then begins to perform the notorious activities in the system such as to get embedded into other doc files to proliferate the attacking rate that results in crippling your system network.


All those actions would depend upon payload program defines inside the Macro.


Dridex and Locky are Warning Bells!!!


No other incidents could get you the clear picture on the potential threat of Macro viruses apart from Dridex Malware and Locky Ransomware. Both malware had made use of the malicious Macros to hijack systems.


Over 20 Million Euro had been stolen from the UK banks with the Dridex Malware, which got triggered via a nasty macro virus. The infectious bar of Locky ransomware had also seen an exponential growth in a couple of hours.


How to Protect Yourself from Macro-based Malware?


Step 1: Configure Trusted Location

Since disabling Macros is not a feasible option, especially in an office environment where Macros are designed to simplify the complex task with automation.


So, if your organization relies on Macros, you can move files that use Macros into the company’s DMZ (Demilitarized Zone), also called Trusted Location.

To configure the trusted location, you can navigate via:

User Configuration/Administrative Templates/Microsoft Office XXX 20XX/Application Settings/Security/Trust Center/Trusted Locations
Once configured, the Macros that does not belong to the trusted location would not run in any way, beefing up your system’s security.


Step 2: Block Macros in Office Files that came from the Internet

Block-Macros-Office
Microsoft had recently unveiled a novel method by implementing a new tactical security feature to limit the Macro execution attack in MS Office 2016, ultimately preventing your system from hijacking.


The new feature is a group policy setting that lets enterprise administrators to disable macros from running in Office files that come from the Internet.


The new setting is called, "Block macros from running in Office files from the Internet" and can be navigated through the group policy management editor under:

User configuration > Administrative templates > Microsoft Word 2016 > Word Options > Security > Trust Center
It can be configured for each Office application.


By enabling this option, macros that come from the Internet are blocked from running even if you have 'enable all macros' in the Macros Settings.

microsoft-office-macro-security
Moreover, instead of having the option to 'Enable Editing,' you'll receive a notification that macros are blocked from running, as the document comes from an Untrusted Source.


The only way to run that particular Office file is to save it to a trusted location, allowing macros to run.
Continue Reading →

Hackers can spy on your calls and track location, using just your phone number


Hackers can spy on your calls and track location using just your phone number

 IN BRIEF

The famous ‘60 Minutes’ television show shocked some viewers Sunday evening when ateam of German hackers demonstrated how they spied on an iPhone used by U.S. Congressman, then recorded his phone calls and tracked his movement through LosAngeles.


Hackers leverage a security flaw in SS7 (Signalling System Seven) protocol that allowshackers to track phone locations, listen in on calls and text messages.

The global telecom network SS7 is still vulnerable to several security flaws that could let hackers andspy agencies listen to personal phone calls and intercept SMSes on a potentially massive scale, despite the most advanced encryption used by cellular networks.

All one need is the target's phone number to track him/her anywhere on the planet and eveneavesdrop on the conversations.

SS7 or Signalling System Number 7 is a telephony signaling protocol used by more than 800telecommunication operators around the world to exchange information with one another, cross-carrier billing, enabling roaming, and other features.

Hackers Spied on US Congressman's Smartphone


With US Congressman Ted Lieu's permission for a piece broadcast Sunday night by 60 Minutes, Karsten Nohl of German Security Research Labs was able to intercept his iPhone, record phone call made from his phone to a reporter, and track his precise location in real-time.

During the phone call about the cell phone network hacking, Lieu said: "First, it's really creepy, and second, it makes me angry."
"Last year, the President of the United States called me on my phone, and we discussed some issues," he added. "So if hackers were listening in, they'd know that phone conversation, and that is immensely troubling."
What's more awful is that the designing flaws in SS7 have been in circulation since 2014, when the same German researchers' team alerted the world to it. Some flaws were patched, but few apparently remain or intentionally left, as some observers argue, for governments to snoop on its targets.

The major problem with SS7 is that if any one of the telecom operators is hacked or employs a rogue admin, a large scale of information, including voice calls, text messages, billing information, relaying metadata and subscriber data, is wide open to interception.

The weakness affects all phones, whether it's iOS, Android, or whatever, and is a major security issue. Although the network operators are unwilling or unable to patch the hole, there is little the smartphone users can do.

How Can You Avoid this Hack?


The best mitigation is to use communication apps – that offers "end-to-end encryption" to encrypt your data before it leaves your smartphone – over your phone's standard calling feature.

Lieu, who sits on House subcommittees for information technology and national security, also argues for Strong Encryption that, according to the Federal Bureau of Investigation (FBI), make itharder to solve crimes.

Lieu strongly criticized the United States agencies, if any, that may have ignored such serious vulnerabilities that affect Billions of cellular customers.
"The people who knew about this flaw [or flaws] should be fired," Lieu said on the show. "You can't have 300-some Million Americans—and really, right, the global citizenry — be at risk of having their phone conversations intercepted with a known flaw, simply because some intelligence agencies might get some data."
Few of such apps that are popular and offers end-to-end encryption are Signal, WhatsApp, and Apple's iMessage service that keep users communications safe from prying eyes and ears.
Continue Reading →

Viber adds End-to-End Encryption and PIN protected Hidden Chats features

viber-secure-chat

 IN BRIEF

Viber, the popular mobile messaging app announced Tuesday that it has added full end-to-end encryption for video, voice and text message services for its millions of users.


Here, the end-to-end encryption means only you and the person you are communicating with can read the content, and nobody in between, not even the company and if court orders company to provide user data, they will get only the heaps of encrypted data.

Viber is the latest messaging platform to join WhatsAppTelegram, and Apple iMessage, who strengthened their default privacy features in recent times.

Founded in 2010 and acquired by Japanese e-commerce titan Rakuten for $900 Million in 2014, Viber is currently being used by more than 700 Million users globally across Android, iOS, Windows Phone, and desktop, the company claimed in a blog post published today.


The move comes just a couple of weeks after Facebook-owned Whatsapp messaging app implemented full end-to-end encryption by default for its one billion users.


Besides offering end-to-end encryption on all communication, the company will also provide a new PIN-protected hidden chat feature to help its users hide conversations from the main chat list, as well as Contact Authentication feature to verify contacts you're talking to.

All users need to update their app with the latest version of the company's software, Viber 6.0, take advantage of the features.


Once installed, your Viber app will now show you a padlock in conversations to confirm that your one-to-one and group messages are end-to-end encrypted.

However, users will probably need to wait few weeks before everyone's app updates to add the new end-to-end encryption on Android and iOS.



In the wake of Apple’s months-long battle with the Federal Bureau of Investigation (FBI) over aniPhone used by a San Bernardino terrorist, it seems like end-to-end encryption has become a trend and you’ll continue to see this in more applications and services.
Continue Reading →

Thursday, March 24, 2016

बैशाखदेखि यसकारण ब्लक हुन सक्छ तपाईंको जुनसुकै मोबाइल


तपाईंले विदेशबाट ल्याउनुभएको वा अवैध रुपमा आयात भएको मोबाइल सेट बोक्नुभएको त छैन ? यदि त्यसो हो भने होस् गर्नुहोस्, तपाईंको मोबाइल फोन ब्लक नै हुन सक्छ । तपाईंले बोकेको मोबाइल सेटको विशिष्ट पहिचान अंक आइएमईआई नम्बर नहुन पनि सक्छ । आइएमइआई नम्बर नभएका मोबाइल सेट ब्लक गराउने तयारी नेपाल दूरसञ्चार प्राधिकरणले गरेको छ ।
प्राधिकरणले तयार पारेको राष्ट्रिय उपकरण पहिचान दर्ताको अन्तरिम कार्यविधिमा आधिकारिक आइएमइआई नम्बर नभएका मोबाइल ब्लक गरिने उल्लेख छ । तर, हाल नेपालभर प्रयोगमा रहेका सेटले भने ६ महिनाको म्याद पाउनेछन् । अर्थात्, हालसम्म नेपाल भित्रिएका सेटमा आधिकारिक आइएमइआई नम्बर नभएको पाइएमा सेवाप्रदायकले ६ महिनाभित्र त्यसको जानकारी प्रयोगकर्तालाई दिनेछन् । त्यसपछि प्रयोगकर्ताले प्राधिकरणमा गएर मोबाइलको आइएमइआई नम्बर लिन सक्नेछन् । आजको नयाँ पत्रिका दैनिकमा समाचार छ ।


Continue Reading →

Sunday, March 20, 2016

7 Reasons to buy Samsung Galaxy S7 Edge


Galaxy S7 edge has been crowned as the number one smartphone of 2016 or at least for the time being. S7 Edge manages a very precise balance between aesthetic and performance. It has now a lot of improvements compared to edge models of last year; especially the size. Both the Galaxy S7 and S7 Edge were launched in Nepal last week, despite being a great phone many people might have their doubts about why they should buy this phone. Here are 7 reasons why you should consider buying the Samsung Galaxy S7 Edge.

1. The Edge Display:

Believe it or not, the edge display on a phone is one of the most pleasing things you can see today. While using the device it gives you a kind of immersive experience where icons and other stuff just flows through the edges of the display giving a really natural vibe to it. It is also really helpful to launch to quick contacts, quick settings, and other important apps without bothering to turn on the actual display of the phone.
gs7ensituntumat_screenshot4_2

2. Super AMOLED Screen:

Galaxy S7 Edge now sports a rather bigger display of 5.5-inch (1440 x 2560) with the pixel density of 534ppi, which is way more than our eyes can tell. Samsung has a streak of making the best displays on their flagship phone and the AMOLED display on the S7 Edge is no different. The viewing angles are great, colors are really sharp, outdoor visibility is good as well, also the VR experience using this phone is really awesome.
gs7ensituntumat_9

3. Water Resistant:

S7 Edge is now IP68 dust and water resistance which makes it one of the sturdiest flagship phone. Not to mention its glass and metal body provides additional protection. We have seen the phone withstand underwater for a really long time without any issues. It’s a great addition if you’re used to handling your phone roughly.
S7 -edge- water

4. Camera

The camera of both the S7 and S7 edge has been titled as the best camera on any smartphone. It has one of the fastest and most accurate camera sensors and with f1.7 aperture S7 edge can capture good quality pictures even in low light. Also, the larger pixels of 12MP rear camera captures a lot of details. S7 Edge also has one of the fastest autofocus seen on any smartphone. It is also capable of shooting 4K videos with optical image stabilization. Double tap on the home button to launch the camera app is a very neat feature which makes taking pictures instantly a joy. Talking about the Front Facing camera, the 5MP camera also has f1.7 aperture along with wide angle lens where you can fit a lot of objects or people to the canvas and does an excellent job of capturing high details like the rear camera.
gs7ensituntumat_6

5. Expandable Storage:

S7 Edge brings back the Micro SD support which is a huge deal as many of the users have complained about storage on the previous galaxy flagships. Now you have the support of expandable storage up to 200GB where you can store a lot of high-quality pictures and videos taken from the stunning camera. Also, since the internal storage has some room to breathe, you’ll see some slight improvement in the performance as well.
gs7ensituntumat_5

6. Battery Life and Wireless Fast Charging:

Battery life has always been an issue with a flagship phone as the phone has to handle powerful processors and background apps for fluid user experience. S7 Edge now comes with a bigger battery than before and also few added optimizations on TouchWiz which provides plenty of screens ON time for a normal user. And even if you manage to drain all of the 3600mAh battery with heavy usage, you have the option to fast charge your phone with either standard charger or a wireless charger with Quick Charge 2.0 which charges your phone from 0 to 60% at mere 30mins.
Galaxy-S7-Wireless-Charger

7. Lighter TouchWiz:

TouchWiz has been one of the most resource hogging UI of all time, there were always a lot of unnecessary apps and services running in the background which made the phone sluggish and battery life inefficient. TouchWiz now has a facelift where a lot of unnecessary services has been removed which has significantly improved the overall performance, multitasking and battery life of the phone. But we still have few helpful options like the Always ON Display, Multi Screen, SHealth, Theme Store etc. TouchWiz is now lighter in terms of both looks and weight making the device a pleasure to use.
Galaxy S7
Source : Click Here
Continue Reading →

The Best Way to Send and Receive End-to-End Encrypted Emails

How many of you know the fact that your daily e-mails are passaged through a deep espionage filter?

This was unknown until the whistleblower Edward Snowden broke all the surveillance secrets, which made privacy and security important for all Internet users than ever before.

I often get asked "How to send encrypted email?", "How can I protect my emails from prying eyes?" and "Which is the best encrypted email service?".

Although, there are a number of encryption tools that offers encrypted email service to ensure that no one can see what you are sending to someone else.

One such tool to send encrypted emails is PGP (Pretty Good Privacy), an encryption tool designed to protect users’ emails from snooping.

However, setting up a PGP Environment for non-tech users is quite a difficult task, so more than 97% of the Internet users, including government officials, are still communicating via unencrypted email services i.e. Gmail, Yahoo, and other.

But here is good news for all those non-techies, but privacy-conscious Internet users, who wish to use encrypted e-mail communication without any hassle.

Solution — ProtonMail.

ProtonMail, developed by CERN and MIT scientists, is a free, open source and end-to-end encrypted email service that offers the simplest and best way to maintain secure communications to keep user's personal data secure.

ProtonMail Now Available for iOS and Android Users


ProtonMail has been invite-only since 2014, but now the email service has made itself available to everyone and launched new mobile apps.

If you opt for a free account, you'll get all of the basic features including:
  • A smart-looking app to access your end-to-end encrypted emails easily
  • 500MB of storage capacity
  • Sending 150 Messages per day
  • Two-factor authentication to access your encrypted email inbox
To increase storage capacity, you can purchase ProtonMail's paid accounts.

NOTE – Always remember your password to decrypt the email inbox. Once forgot, you would no longer retrieve your encrypted emails.

Key Features:

secure-encrypted-email-service-providers-security
Even if someone intercepts your communication, he/she can not read your conversations because all emails you send or receive with other ProtonMail users are automatically encrypted end-to-end by the service.

In addition, for communicating with non-ProtonMail email addresses i.e. Gmail users, all you need to do is:
  • Create a message
  • Just click the encryption button
  • Set a random password
Once done, your encrypted email recipient will get a link to the message with a prompt to enter his/her same password in order to read it.

Another friendly feature that ProtonMail offers is Self-destructing emails. All you need to do is set an expiration date for an encrypted email you send, and it will get self-deleted from the recipient’s inbox once the date arrives.

Why ProtonMail won't have to comply with American Laws?


In a previous article, I explained that ProtonMail is based in Switzerland, so it won't have to comply with American courts’ demands to provide users data.

In worst case, if a Swiss court ordered ProtonMail to provide data, they will get only the heaps of encrypted data as the company doesn’t store the encryption keys.

ProtonMail has gained an enormous amount of popularity during its developing stages.

ProtonMail encrypts the data on the browser before it communicates with the server, therefore only encrypted data is stored in the email service servers, making it significantly more secure for those looking for an extra layer of privacy.
Source : Click Here
Continue Reading →

Flag Counter

Flag Counter

Popular Posts