Saturday, 21 May 2016

How to stop wimdows 10 from stealing your bandwidth

peer-to-peer-p2p-update-microsoft-windows-10 Windows 10 steals your internet bandwidth without your knowledge to share updates with others. This option is enabled by default in Windows 10 Home and Windows 10 Pro. You can turn this feature off in your update settings. Read more to know detailed instructions.
Long back, fossBytes reported that Windows 10 will be downloading and distributing updates to others using peer-to-peer (P2P) protocol. Now that Windows 10 is released, and you can grab with even without any upgrade icon, Windows 10 is busy using your internet connection to distribute updates to other people on the Internet. Actually, Microsoft has done this to reduce the stress on its servers.  Earlier, it was expected that this feature will only work for PCs on your local networks.
Windows 10 steals your internet bandwidth due to a feature called Windows Update Delivery Optimization. It is enabled in Windows 10 Home and Windows 10 Pro versions. Windows 10 Enterprise and Education have this feature enabled, but it works only for the PCs on your own local network.

Just like torrents, everyone having Windows 10 on their PCs, by default distributes some updates to the people who need it. This makes the update process for other fast and less troublesome for Microsoft. Using your data connection to share updates may seem like a good gesture, but what if your data connection isn’t unlimited?
Also read: How to Regain Up To 20GB Disk Space After Windows 10 Upgrade
For those who are having a limited data connection, this feature will use lots of your allotted data and you won’t even realize it. Microsoft has said that this feature will only share updates and it won’t download or send any personal data.

Windows 10 steals your Internet Bandwidth, How to Stop It?

Follow these simple steps to turn off the Windows Update Delivery Optimization feature in Windows 10 to save your data:
  • Search for “Windows update settings” in the Start menu and click on the desktop app.
windows-10-steals-internet-bandwidth-update4
  • Under the “Windows Update”, find and click on “Advanced options.”
windows-10-steals-internet-bandwidth-update4
  • Now under “Choose how updates are installed” click “Choose how updates are delivered.”
windows-10-steals-internet-bandwidth-update4
  • Disable the toggle under “Updated from more than one place.”
windows-10-steals-internet-bandwidth-update4
This looks a great feature for getting updates quickly and sharing updates with your local network PCs if you are running Windows 10 Enterprise and Windows 10 Education. But knowing that Windows 10 steals your Internet bandwidth on Windows 10 Home and Windows 10 Pro versions, and spends your data without your knowledge, it doesn’t feel that great.

Friday, 13 May 2016

Second Bank hit by Malware attack similar to $81 Million Bangladesh Heist

Second Bank hit by Malware attack similar to $81 Million Bangladesh Heist
SWIFT, the global Society for Worldwide Interbank Financial Telecommunications, warned on Thursday of a second malware attack similar to the Bangladesh central bank hack one that led to $81 million cyber heist.

In February, $81 Million cyberheist at the Bangladesh central bank was carried out by hacking into SWIFT, the global financial messaging system that thousands of banks and companies around the world use to transfer billions of dollars every day.

However, the hackers behind the cyber heist appear to be part of a comprehensive online attack on global banking and financial infrastructure.

The second attack involving SWIFT targeted a commercial bank, which the company declined to identify. SWIFT also did not immediately clear how much money, if any, was stolen in the attack.

However, SWIFT spokeswoman Natasha de Teran said that the second attack and the Bangladesh bank heist contained numerous similarities and were very likely part of a "wider and highly adaptive campaign targeting banks," the NY Times reported.

The malware involved in the Bangladesh cyber heist was used to manipulate logs and erase the history of the fraudulent transactions, and even prevented printers from printing the fraudulent transactions.

The malware used in the attack also has the capability to intercept and destroy incoming messages confirming the money transfers, preventing hackers to remain undetected.
SWIFT said in a statement that the attackers clearly exhibited "a deep and sophisticated knowledge of specific operation controls within the targeted banks — knowledge that may have been gained from malicious insiders or cyber attacks, or a combination of both."
News of a second attack involving SWIFT comes as law enforcement authorities in Bangladesh and elsewhere investigate the February's $81 Million cyberheist at the Bangladesh central bank account at the New York Federal Reserve Bank.

The hackers had attempted to steal $951 Million in total from Bangladesh central bank account using fraudulent transactions, but a simple typo by hackers halted the further transfers of the $850 Million funds.

SWIFT has acknowledged that the scheme involved Bangladesh cyberheist did not harm its core messaging system.

However in both the cases, insiders or hackers had successfully penetrated the targeted banks' systems, pilfering user credentials and submitting fraudulent messages that correspond with money transfers.

Facebook Open Sources its Capture the Flag (CTF) Platform

facebook-capture-the-flag-ctfHacking into computer, networks and websites could easily land you in jail. But what if you could freely test and practice your hacking skills in a legally safe environment?

Facebook just open-sourced its Capture The Flag (CTF) platform to encourage students as well as developers to learn about cyber security and secure coding practices.

Capture the Flag hacking competitions are conducted at various cyber security events and conferences, including Def Con, in order to highlight the real-world exploits and cyber attacks.

The CTF program is an effective way of identifying young people with exceptional computer skills, as well as teaching beginners about common and advanced exploitation techniques to ensure they develop secure programs that cannot be easily compromised.

Facebook  CTF Video Demo:

Since 2013, Facebook has itself hosted CTF competitions at events across the world and now, it is opening the platform to masses by releasing its source code on GitHub.
"We built a free platform for everyone to use that takes care of the backend requirements of running a CTF, including the game map, team registration, and scoring," said Gulshan Singh, Software Engineer at Facebook Threat Infrastructure.

In general, Capture The Flag competition hosts a series of security challenges, where participants have to hack into defined targets and then defending them from other skilled hackers.
"The current set of challenges include problems in reverse-engineering, forensics, web application security, cryptography, and binary exploitation. You can also build your own challenges to use with the Facebook platform for a customized competition," Mr. Singh said.

Many institutions and organizations now have realized that gamification of cyber security and hacking is beyond the traditional ways to train your mental muscles and keep sharp your skills that otherwise only come up when doomsday scenarios happen.

Courtesy: THN

Saturday, 2 April 2016

Here's the Exploit to Bypass Apple Security Feature that Fits in a Tweet

Here's Exploit to Bypass Apple Security Mechanism that Fits in a Tweet
Did you install the latest update OS X 10.11.4?

If yes, then you might be wondering with a fact that the Apple had delivered an ineffective patch update this time.

Yes! This news would definitely disappoint many Apple users, as the latest update of OS X El Capitan 10.11.4 and iOS 9.3 still contain a privilege escalation vulnerability that could affect 130 Million Apple customers.

Just last week, we reported about a critical privilege escalation vulnerability in Apple's popular System Integrity Protection (SIP) security mechanism, affecting all versions of OS X operating system.

Even after Apple had fixed the critical flaw in the latest round of patches for Macs and iThings, the SIP can still be bypassed in the most recent version of operating system, leaving Apple users vulnerable to flaws that could remotely hijack their machines.

SIP Bypass Exploit Code Fits in a Tweet


Interestingly, Stefan Esser, a security researcher from Germany, has released a new exploit code to bypass latest patched version of SIP application, which just fits in a Tweet.

Here's the exploit code -- It can be used to modify a crucial OS X configuration file that not even root user is allowed to touch, reported The Register.
ln -s /S*/*/E*/A*Li*/*/I* /dev/diskX;fsck_cs /dev/diskX 1>&-;touch /Li*/Ex*/;reboot
The above code actually expands to:
ln -s /System/Library/Extensions/AppleKextExcludeList.kext/Contents/Info.plist /dev/diskX
fsck_cs /dev/diskX 1>&-
touch /Library/Extensions/
Reboot
The above exploit code successfully bypasses Apple's SIP technology, allowing one to run processes as it is pleased.

What is System Integrity Protection (SIP)?


Apple introduced SIP, a security protection feature to the OS X kernel, with the release of OS X El Capitan, which is designed to restrict the root account of OS X machines and limit the actions a root user can perform on protected parts of the system.

Besides this, System Integrity Protection (SIP) also helps prevent software from changing your startup volume, blocks certain kernel extensions from being loaded and limits the debugging of certain apps.

System Integrity Protection or SIP, by default, protects these folders: /System, /usr, /bin, /sbin, along with applications that come pre-installed with OS X.

This is really a bad time for Apple and its users. Now, let's hope that the company would be more vigilant with its upcoming patch update.

How to disable windows 10 upgrade permanently with just one click

If you are a Windows 7 or Windows 8.1 user, who don't want to upgrade to Windows 10 now or anytime soon, you might be sick of Microsoft constantly pestering you to upgrade your OS.

Aren't you?

With its goal to deploy Windows 10 on over 1 Billion devices worldwide, Microsoft is becoming more aggressive to convince Windows 7 and 8.1 users to upgrade to its newest operating system, and it is getting harder for users to prevent the OS being installed.

But if you're worried that this out of control Windows 10 upgrade process will force you into downloading an unwanted OS; I have an easier solution to block Windows 10 upgrade on your PCs.

A new free tool, dubbed Never10, provides the user a one-click solution to disable Windows 10 upgrade until the user explicitly gives permission to install Windows 10.

Never10 has been developed by Steve Gibson, the well-known software developer and founder of Gibson Research, which is why the tool is also known as "Gibson's Never10."

How to Disable Windows 10 Upgrade on Your PCs


  1. Go to Gibson's Never10 official site and click on the Download.
  2. Once downloaded, the program detects if the upgrade to Windows 10 is enabled or disabled on your system and then shows a pop-up. If enabled, Click 'Disable Win10 Upgrade' button.
  3. You’ll again see a pop-up that now shows Windows 10 upgrade is disabled on your system, with two buttons to 'Enable Win10 Upgrade' and 'Exit.' Click on Exit button.

disable-windows10-upgrade
That's it, and you have successfully disabled Windows 10 Upgrade on your PC.

Here's the kicker:

The best part of this tool is that you don't have to install an application on your PC to do this. Gibson’s Never 10 is an executable. So you just need to run it, and it doesn’t install anything on your computer. You can delete it when you're done.
"The elegance of this 'Never 10' utility is that it does not install ANY software of its own. It simply and quickly performs the required system editing for its user," Gibson writes on his page about the new utility.
According to Gibson, Never10 will be a great help to inexperienced users while advanced users will likely appreciate the fact that no additional software is installed and will be able to refer their family and friends to this easy-to-use utility.

For more technical details on how this tool works, you can head on to this link.

Unlike other available Windows 10 blocker tools, Never10 blocks the Windows 10 upgrade, but at the same time, the tool allows you to start the update process in case you change your mind, according to Windows watcher Paul Thurrott.

However, the primary purpose of Gibson's Never10 is to prevent Windows 7 and Windows 8.1 operating system from being upgraded to Windows 10. As Gibson says:
"Many users of Windows 7 and 8.1 are happy with their current version of Windows and have no wish to upgrade to Windows 10." 
"There are many reasons for this, but among them is the fact that Windows 10 has become quite controversial due to Microsoft's evolution of their Windows OS platform into a service which, among other things, aggressively monitors and reports on its users' activities."
Moreover, just a month ago, Microsoft was caught displaying unsolicited advertisements on its Windows 10 users' desktops.

These reasons are enough for many users to stay on their previous versions of the Windows operating system.

Tuesday, 1 March 2016

How to turn windows 10 lock screen ads off

Although the ads are not as annoying as the Windows 10 privacy concerns related to the way Microsoft collects your personal data, the good news is that you can turn the ads OFF.

Here's How to Turn the Ads OFF
Disable Windows 10 Lock Screen Advertisement
The advertisements are because of the Windows Spotlight feature in your Personalization settings.

If you don't want to see these intrusive ads, follow the steps given below to disable Windows Spotlight:
  • Open the Start Menu and look for 'Lock Screen Settings.'
  • Under 'Background,' Choose either 'Picture' or 'Slideshow,' instead of Windows Spotlight.
  • Now, Scroll down to 'Get fun facts, tips, tricks, and more on your lock screen' and uncheck this box.
The advertisements are turned ON for your lock screen by default, which is definitely a clever way to offer companies to reach their customers, without mentioning the word 'advertisements' to the Windows users.
windows-10-settings


As I previously said: Nothing comes for Free, as "Free" is just a relative term. Everything comes with its own price.

As warned last year, Microsoft also started pushing Windows 10 upgrades onto its user's computers much harder by re-categorizing Windows 10 as a "Recommended Update" in Windows Update, instead of an "optional update."

Raspberry Pi 3 — New $35 MicroComputer with Built-in Wi-Fi and Bluetooth

While celebrating its computer's fourth birthday, the Raspberry Pi Foundation has launched a brand new Raspberry Pi today.

Great news for all Micro-computing fans – A new, powerful Raspberry Pi 3 Model B in town.

Months after introducing just $5 Raspberry Pi Zero, Raspberry Pi Foundation has introduced its third major version of the Raspberry Pi, the successor of the Raspberry Pi 2 that was launched back in February last year.

The Raspberry Pi is a highly simple computer that looks and feels very basic, but could be built into a number of geeky projects. Due to its low-cost appeal, the Raspberry Pi has become the most popular computer yet with 8 Million units already sold.

Raspberry Pi 3 — Built-in Wi-Fi and Bluetooth


Although previous versions of Raspberry Pi needed USB adapters to get Wi-Fi and Bluetooth connectivity, credit card-sized Raspberry Pi 3 Model B has built-in Wi-Fi and Bluetoothconnectivity.

The new version of the Pi supports 802.11n Wi-Fi (2.4GHz only) and Bluetooth 4.1, freeing up its four USB ports for other purposes.

The Raspberry Pi 3 is also getting a speed jump from a 32-bit processor, 900MHz quad-core ARM Cortex A7, to a faster 64-bit processor, quad-core 1.2GHz ARM Cortex-A53 CPU.

The new Raspberry Pi is expected to give 50 percent faster performance than the previous version due to architectural improvements and increase in clock speeds, says Eben Upton, CEO of Raspberry Pi.

At a launch event today the Raspberry Pi Foundation said it has worked closely with Microsoft to ensure full compatibility between the new Pi 3 board and Windows 10 IoT.

Raspberry Pi 3 Model B: The $35 MicroComputer

raspberry-pi-3-microcomputer
The Raspberry Pi 3 is still just $35, but might be the biggest when looking at its specifications:
  • 1.2GHz Quad-Core Broadcom BCM2387 ARM Cortex-A53 processor
  • Graphics upgrade from 250MHz to 400MHz Dual Core VideoCore IV GPU
  • 802.11n Wi-Fi
  • Bluetooth 4.1 (Bluetooth Classic and LE)
  • Support 1080p video at 60fps using the H.264 format, up from 30fps
  • 1GB RAM (same as the previous version)
  • MicroSD Card Slot
  • Operating System: Operating System Boots from Micro SD card, running a version of the Linux operating system or Windows 10 IoT
  • Ethernet connectivity remains at 100Mbps
  • Requires a 2.5A input power
  • Video Output: HDMI (rev 1.3 & 1.4, Composite RCA (PAL and NTSC)
  • Audio Output: 3.5mm jack, HDMI, USB 4 x USB 2.0
The all-new and powerful version of Raspberry Pi 3 brings a host of new hardware that makes it a much more powerful computer.

The Raspberry Pi 3 costs $35/£30 only (nearly Rs. 2,400), same as the Raspberry Pi 2 and is available for sale from its partners Element14 and RS Components.

The company said it will also introduce a Raspberry Pi BCM2837-based Compute Module 3, an even smaller board designed for industrial applications, in the next few months. The Compute Module won't include any WiFi connectivity, but will have the same 1.2GHz Cortex A53 processor and 1GB RAM as the Raspberry Pi 3.

Wednesday, 27 January 2016

Critical Flaws in Magento leave Millions of E-Commerce Sites at Risk



Critical Flaw in Magento leave Millions of E-Commerce Sites at Risk
If you are using Magento to run your e-commerce website, it's time for you to update the CMS (content management system) now.
Millions of online merchants are at risk of hijacking attacks due to a number of critical cross-site scripting (XSS) vulnerabilities in the Magento, the most popular e-commerce platform owned by eBay.

Why the Bugs are So Serious?

Virtually all versions of Magento Community Edition 1.9.2.2 and earlier as well as Enterprise Edition 1.14.2.2 and earlier, are vulnerable to the Stored Cross-Site Scripting (XSS) flaws.
The stored XSS flaws are awful as they allow attackers to:
  • Effectively take over a Magento-based online store
  • Escalate user privileges
  • Siphon customers’ data
  • Steal credit card information
  • Control the website via administrator accounts
However, the good news is that the vulnerabilities are patched, and an update has been made available to the public after security firm Sucuri discovered and privately reported the vulnerability to the company.

How Easy it is to Exploit the Flaw

The XSS bugs are quite easy to exploit. All an attacker need to do is embed malicious JavaScript code inside customer registration forms in place of email address.
Magento then runs and executes this email containing JavaScript code in the context of the administrator account, making it possible for an attacker to steal administrator session and completely take over the server running Magento.
Cybersecurity firm Sucuri describes the bug as the worst hole, saying:
"The buggy snippet is located inside Magento core libraries, more specifically within the administrator's backend. Unless you are behind a WAF or you have a very heavily modified administration panel, you are at risk."
"As this is a Stored XSS vulnerability, this issue could be used by attackers to take over your site, create new administrator accounts, steal client information, anything a legitimate administrator account is allowed to do."

Patch your Software Now!

To prevent websites from exploitation, webmasters are recommended to apply the latest patch bundle SUPEE-7405 as soon as possible.
Since the latest patch resolves the issue for Magento version 1.14.1 and 1.9.1 and earlier, problems impacting Magento versions 1.14.2.3 and 1.9.2.3 have already been resolved.
With Alexa top one million e-commerce websites and over all ten Million websites using the internet's fourth most popular CMS, Magento has become a valuable target for attackers nowadays.
So, patch your websites now to stay safe!

Popular Posts