A Practical Guide to SharePoint 2013

A Practical Guide to SharePoint 2013
A Practical Guide to SharePoint 2013 - Book by Saifullah Shafiq
Showing posts with label Cyber attacks. Show all posts
Showing posts with label Cyber attacks. Show all posts

Thursday, April 13, 2023

The Relentless LockBit Ransomware

All eyes are on LockBit

In recent times, LockBit Ransomware has gained momentum and made the headlines. Many of the high profile companies and enterprises have been under threat because of the spree of cyber-attacks made by this group through malicious software. There are a number of other notorious ransomware gangs like LockBit who are active and have steadily impacted thousands of organizations around the globe. DarkSide, Conti, REvil and DoppelPaymer are to name a few who have adopted aggressiveness, persistence and effectiveness to be successful in their vile mission. Countries such as the United States, France, China, India and the United Kingdom have been their major targets. Since LockBit has been driving the world crazy so it’s important for you to know more about it.

What is LockBit Ransomware? 

LockBit Ransomware, also known as the ABCD ransomware is a smart and prolific ransomware gang that has emerged lately. This group has professionally designed a malicious software through which they lock the user’s computer and demand ransom in return. If their target does not provide a ransom then LockBit automatically encrypts and gets access to all their files in their computers. With this aggressive approach and through their extortion tools, it has posed unique threats to large businesses and government organizations. The first high severity cyber-attack was made by them in September, 2019. The cycle of attacks has continued since then.

What’s more threatening?

Through LockBit, data theft, extortion and illegal publications are made by the hackers for monetary gains. Businesses face operational disruptions and with it their crucial processes come to a sudden halt. It is important to note that LockBit attacks are self-piloted. These cyber attackers have adopted various ways to target for example by email attachments or by cascading of files. Since LockBit integrates sophisticated technology, it is seen as a formidable adversary in the cyber realm. The gang is backed by ransomware groups which encourages them to carry on with the attacks. Moreover, with superior upgrading they have been able to introduce its new encryption tool called the StealBit which is far better than the prior versions. Initially, it attacked only the Windows systems but with time it evolved to target Linux computers as well. With the help of its malware, it targets the key data of both the operating systems by infiltrating into them. LockBit attacks are self-spreading and they are using highly advanced methods such as the double extortion and triple extortion techniques to exploit their victim by stealing or leaking their data. In future, DDoS attacks will be a further challenge for them.

Keeping the aforementioned threats in mind, it is essential for businesses to take protective measures to prevent themselves from falling into LockBit ransomware’s trap. A strong password, multi factor authentication, regular system wide backups and comprehensive cyber security solutions will act as a shield against them.

 

Wednesday, February 8, 2023

Ethical Hacking

With the escalation of global conflict, a number of subversive minded groups and individuals have emerged, threatening the national security systems of countries by funding and backing cyberpunks. Organizations are intimidated by these hackers too, who try their utmost to access and extort their data by means of malware. All the organizations, government/intelligence agencies, and national defense councils have to put in effort because viruses, malware and worms are active and making their way to their systems. To nip them from gaining access to networks they must work on new strategies, update their technologies and introduce hack preventing tactics. 

What is Ethical Hacking?

Ethical hacking is the lawful way of gaining an authorized access into the network or systems by penetrating into it. It is mainly done to improve and safeguard network security and shield against potential threats. During the process of intrusion, ethical hackers look for the weak points, identify threats from the system and later fix the vulnerabilities. All this is essential because if malicious attackers gain access to your network, it can result in data loss, sabotage the organization or institution and even result in financial losses.

Furthermore, there are few rules that ethical hackers must follow while performing their duties:

1.     Follow legal requirements: Before doing the security assessment, they must take prior approval from the relevant department of the organization.

2.     Determine the scope: They must give a detail account of the scope of assessment they will conduct so that everyone knows the parameters within which the ethical hacking is being performed. This will make sure that the work is done legally and with their approval.

3.     Inform about the vulnerabilities: After analyzing and determining the vulnerability, ethical hackers must keep the organization in the loop by reporting them about the vulnerabilities that they found out. Also, propose and give recommendations as to what corrective actions can be taken to resolve and deal with those vulnerabilities.

4.     Keep data confidential: There are certain agreements to which ethical hackers must abide. They should accept all the terms and conditions since data is sensitive and must not be disclosed. 

     There are some skills that certified ethical hackers should possess which include: 

       1. In-depth knowledge of information security

       2. Strong grasp over scripting language

       3. Network proficiency

       4. Competency in terms of operating systems


Other than that, there are many benefits of ethical hacking, the main ones include:

1.     Helps to combat attacks from cyber terrorists so that data cannot be misused, breached or stolen.

2.     Preventative action can be taken after finding the weak points and detecting the vulnerabilities from hackers POV

3.     Shields national security from external and internal threats or terrorists.

4.     Enhances the company's image in the eyes of customers and investors when company protects their personal data and provides them product security.

Now let’s move on to the different phases of ethical hacking that saves companies from attacker’s exploitation and falling in their trap.

1.     Reconnaissance: This is the first stage where all the information is gathered, prior to the launch of an attack. This information is mainly related to the target e.g. their password or job profile etc. Tools such as Maltego and Nmap are used to scan individual's network or to search about them.

2.     Scanning: In this stage the hackers try to access and gain the information of that target individual through different means such as exploring and searching for their IP addresses, essential records, accounts or credentials. To quickly go through their data, tools including sweeper, dialers, network mappers and even vulnerability scanners are used.

3.     Gaining access: Third step is about using means to get access to the person or organization's application, network or system. Attackers might install soft wares, applications or tools to exploit and steal sensitive data by getting access to the systems. Metasploit is one such tool. Certified ethical hackers will make sure that such vulnerable parts of the systems are protected by passwords and they use firewall to protect network infrastructure. They even check who are the gullible employees (can easily be targeted by hackers) by sending them fake emails.

4.     Maintaining Access: Once the hackers hijack the system, he continues to make DDOS attacks to gain access to the whole data base until they are fully successful in their malicious actions. The target in most cases doesn’t know about these activities. Penetration testers get to the depth of the system to find the susceptible areas by scanning the infrastructure of that company.

5.     Covering Tracks: Attackers try their best not to leave any traces behind. Thus, they remove and clear each and every clue and evidence through which they can be caught. Ethical hackers have to keep connections within the system. They use ICMP tunnels and HTTP Shells etc. In order to remove digital footprints, they delete all logs, history and cache so that they cannot be identified or traced back.

Businesses and nations must remain watchful at all times, since attackers are keeping an eye on their sensitive data. A strong ethical hacking system is mandatory in these times where everything is achievable through technology.