الأربعاء، 2 مارس 2016

SpiderLabs/ModSecurity: A Open Source Web Application Firewall (WAF) Module


SpiderLabs/ModSecurity: A Open Source Web Application Firewall (WAF) Module


Definition: ModSecurity is an Apache web application firewall (WAF) engine, which is developed by Trustwave's SpiderLabs. ModSecurity is an open source, cross-platform engine. It is also for Nginx and IIS. A free certified rule set for ModSecurity 2.x. has been provided by the Trustwave's SpiderLabs.


Features: 

The features of ModSecurity are following:

  • It is an open source, cross-platform engine. 
  • It has a robust event-based programming language which provides protection against web applications.
  • It also allows for HTTP traffic monitoring, logging etc.
  • In order to implement advanced protections it provides a power rules language and API.

Principles of ModSecurity:

Exactly four principles are there on which ModSecurity is based, they are:

  • Flexibility.
  • Passiveness.
  • Quality over quantity.
  • Predictability.

Techniques used by the Core Rules:

The important techniques are following:

  • HTTP Protection and Denial Of Service Protections- that detect violations of the HTTP protocol and protects against HTTP Flooding respectively.
  • Automation Detection and Trojan Protection- it detects crawlers, scanners, bots etc and Trojan Protection detects access to Trojans horses.
  • Real-time Blacklist Lookups - it utilizes a 3rd Party IP Reputation.
  • Error Detection and Hiding - For error messages sent by the server.
  • Tracking Sensitive Data - it tracks Credit Card usage and blocks leakages.
  • Web-based Malware Detection - it identifies malicious web content.

What can ModSecurity do?

ModSecurity can do the following and its usage are:

  • Real-time application security monitoring and access control.
  • Continuous passive security assessment.
  • Virtual patching.
  • Full HTTP traffic logging.
  • Web application hardening.

For Installation:

In Ubuntu/Debian you have use these commands.
$ sudo apt-get install libapache2-mod-security
$ sudo a2enmod mod-security
$ sudo /etc/init.d/apache2 force-reload

In Fedora/CentOS you have use these commands.
$ sudo yum install mod_security
$ sudo /etc/init.d/httpd restart

In Microsoft IIS (MSI Installer) install the following:
ModSecurity v2.9.1 for IIS MSI Installer - 32bits (sha256)
ModSecurity v2.9.1 for IIS MSI Installer - 64bits (sha256)


Licence:

The Licence is Copyright (c) 2004-2013 Trustwave Holdings, Inc. 

IBM Confirms Plan To Acquire The Private Cyber Security Firm Resilient Systems

IBM Security


IBM Confirms Plan To Acquire The Private Cyber Security Firm Resilient Systems


The computing giant, IBM security confirmed plans to assume private Cyber Security firm Resilient Systems that is a Cambridge, MA-based cyber security to start with 100 employees for increasing the incident response at the market level. And you know what the Resilient Systems are partnering with endpoint cyber security provider Carbon Black.


Resilient will be a key component of IBM X-Force Incident Response Services that is a new beginning which was launched on last Monday and the important thing is that the terms and conditions of the deal were not unveiled. But according to a source of IBM, the price of the deal should be $100 million whereas according to another source the transaction will be probably in cash.

As I told you that cyber security designated with working 100 employees at Resilient Systems in which including also chief executive John Bruce that is a former vice president at Symantec and also its chief technology officer who is not only security blogger & author Bruce Schneier.

Marc van Zadelhoff who is a general manager of IBM Security said, “Our intent is all these guys are going to come on board. You acquire technology, but you really want to acquire people.”  

But according to a recent study by Ponemon Institute, it finds that 70% of US security executives do not have a cyber security incident response plan in place.  

Do you know that Resilient Systems are also known as Co3 Systems when it was established in 2010? One fact is found by PitchBook, the company has elevated up to $17.3 million through investors in which venture firm Fairhaven Capital, which led a $7.3 million round in 2012 also included.

According to a familiar source, Resilient Systems said in PitchBook, the 2014 round was done at a post-money valuation of $24.2 million that would suggest for the investors to own most of the company.

Jon Oltsik, who is a senior principal analyst at Enterprise Strategy Group, said that Resilient Systems has become a most popular and leading player in the high-demand field of incident response by helping private as well as government customers prepared for determine and extenuate cyber breaches. 

Oltsik also added in the incident response is, “hot link in the market.” That means “Customers are spending a lot of money on cyber security to address their shortcomings. ” 

On Monday IBM also said that this is making X-Force Incident Response Services that will purchase Resilient Systems technology and talent for helping in the identification process of clients and also in responds to cyber defects.

And the best thing is that the IBM said that X-Force service will also have faith in a new partnership with cyber firm Carbon Black which will help to conduct security forensics of its analysts security on compromised with the endpoint devices and finds where a breach first took place.

Email Phishing Scam Cause The Payroll, Sensitive Information Of SnapChat Workers Leaked

Snapchat Email Phishing Scam

Email Phishing Scam Cause The Payroll, Sensitive Information Of SnapChat Workers Leaked.


A Snapchat employee inadvertently spilled sensitive company information after falling for an email trick. SnapChat revealed in a blog post, which was published on Sunday that an unidentified worker has app received an email asking for payroll information on Friday, that unidentified worker was the maker of the popular photo and video sharing. 


According to the blog post it claimed that the email was from Snapchat CEO Evan Spiegel, but in reality, it was actually a phishing scam due to which pay and personal data of some employees leaked to the outsider.

According to SnapChat, neither the user sensitive information nor the company internal system was compromised. From 2011, the company's app gained more than 100 million daily active users, among them most are teens, millennials and more than 7 billion videos are boasted every day.

Email phishing relies on simple social engineering, unlike the other security threats. Anyone can easily make fool to those who may not even think before replying or responding to an email. That's why Email phishing is very common and it take the advantages of that kind of people. Many times this threat is done using a phone call instead of an email message. By this incident, it's easily proven that how easy it can be to fall for such scams.

The message seems to anyone as genuine, it seems that it come from a trusted source or a real company and this may be the reason also that they are not blocked by spam filtering software.  

According to SnapChat, the scam has been reported to the FBI and was also isolated. And those employees who are affected by this scam will get two years of free identity theft insurance and monitoring.

As this incident is under investigation now, so the company also refused to provide any further details regarding this scam.

"When something like this happens," Snapchat said, "all you can do is own up to your mistake, take care of the people affected, and learn from what went wrong."

Latest in Smart Textiles - A Musical Tablecloth


textiles

A Tablecloth – Turning Dinner into Musical Recital


A tablecloth with a drum kit as well as piano keys printed on the fabric turning dinner into a musical recital has been created by a Swedish company. Specialist Li Guo together with Mats Johansson from a technology company, Smart Textiles which is based in southern Swedish city of Boras,is responsible for the smart fabric conception. Johansson who has strong interest in music commented that the team desired to combine sounds and textiles in a fun way.

 Johansson informed Reuters that the special thing is that it is all from textile technologies. They had the woven cloth but on that were prints for the piano and haveadded together with other laminated textile structures for the drums which are from knitted fabrics.

It was then sewn as connectors or taping so it is the technologies that they are familiar with in textiles, now utilised for entertaining purpose in this case. Li, his colleague holds a doctorate in textile sensors and has been researching on how to integrate them in garments. The tablecloth is said to be made partly of conductive fibres which tends to carry current, converting it into signals. They have mentioned that turning a tablecloth into an instrument is all due to the sensors.

Integrate in Garments - Combine Sounds & Textiles


The team are investigating on how to integrate them into garment or to combine sounds and textiles. Lia has explained that one can see several different pins here which are actually functioning as sensors. When one tends to press one, it is actually switched on and the technology behind it all is sense capacitive coupling. It tends to sense any of the conductors where human beings are conductors and when one puts their finger on it, it seems to get switched on.

Lia seems to see several probable uses in the near future, though the technology is not yet totally established. She further adds that sensors could be of different types and now we have touch sensors. They have also been working with stretchable sensors as well as textile electronics which can obtain signals from heartbeats, for instance from the human body. It could thus be supportive with home-based health monitoring. Johansson has mentioned that the most difficult task was to connect the soft material with hard electronics and one of the main challenges in the smart textiles.

Future - Fabrics with Embedded Sensors


He adds that the problem currently is very much where one gets this change from the actual fabric to some type of electronics, from soft flexible substance to the rigid hardware, besides the electricity and the batteries. They seemed to be difficult to make from the real textiles though there are projects which tend to look also into that, to make it also lighter and flexible and so on.

Li had stated that in the future, smart fabrics with embedded sensors would be a common place. The team have forecast that in the near future, there would be sensors in clothing which would monitor as well as send data to fill the market, thus making what one tends to wear, a tool in keeping you healthy while also making a fashion statement.

الثلاثاء، 1 مارس 2016

Google Throws Down The Gauntlet

Dol

Demis Hassabis Prepares for Five Game Match against Lee Se-Dol


The chief executive of Google’s artificial intelligence start-up DeepMind, Demis Hassabis is making preparation for the session of its life, a five game match against Lee Se-Dol who is one of the strongest players in the world at the ancient game of Go. Last year in October, the company’s program AlphaGo had achieved a historic milestone beating Fan Hui who had been the highest ranking European player of the game, scoring 5-0.

It had been the first time a computer had beaten a professional Go player in an even match.However, Hui was ranked about 800th in the world prior to AlphaGo and is a two dan player where his rank on the dan sale of professional play that tends to start at one, rising to nine. In contrast, Lee is a nine dan player with the second highest number of international titles to his credit.

 Due to the marked increase in his skill, Hassabis had been prepared to only rate AlphaGo’s opportunity of winning at about 50%. Hassabis, speaking from DeepMind’s headquarters near Kings ‘Cross station in London, in a conference room that had been named after pioneering logician Kurt Godel, had explained that for his company, winning the match was not the most essential thing.

AlphaGo – Gain Valuable Feedback


The $1m prize pool which Google had put up for the match would be donated to Go and Stem charities as well as UNICEF, should DeepMind win and winning or losing, AlphaGo would gain valuable feedback from battling with one of the strongest players which the game has ever seen, besides the feedback, which no one working for DeepMind would be able to give, the machine having surpassed its developer long ago.

The vice-chairman of Korea’s Go association, Park Chi-Moon had inserted a note of caution for humanity that `DeepMind was of the belief that Alphago has 50% chance of winning and that they believe they are in fact more confident.

However, Lee himself was more confident in his skills and standing on stage visibly nervous in front of the crowd in Korea, said that he will not be too comfortable in approaching the challenge and will not be too arrogant in his preparation. However, he added that the company had only five months in improving the system since its game again FanHui.

Possibility of a Clean Sweep


He commented that due to the time limits, he does not think that it would be a close match and believes that it will be 5-0 or perhaps 4-1 and the critical point for him would be not to lose the match. There could be a possibility for him of taking a clean sweep.

Hassabis agreed that the system seems to have various weak points and that part of the cause for the game against Lee was to gain more information on how to progress in those conditions. However he refrained from divulging in more details for fear of handing the game to his challenger.

But behind the fight for mastery over Go is a broader aim. The game seems to be a perfect test-bed for the machine learning techniques of DeepMind and the same systems which it had mastered Go would be soon put to use, enhancing the voice-controlled assistants on the smartphones of Google.

 In the longer term on tackling issues, regarding climate as well as healthcare modelling, an announcement on the latter would come later this week.

New Malware Targeting Mac OS X


New Malware Targeting The Second Most Widely Used Desktop OS "Mac OS X" 


From Palo Alto Networks, SentinelOne, and Synack, who are security researchers by profession have been analyzing a new malware sample from the past few weeks. That new malware sample is targeting Mac OS X.


Around the world, the HackingTeam sells surveillance software (a legal term for malware) to governments. The HackingTeam is a controversial Italian Company.

A series of malware has been discovered by the Claud Xiao, a security researcher from Palo Alto, that seems to him very suspicious. Once they had shared the binaries with infosec community, these all ended up in the hands of some OS X security specialists. According to both (SentinelOne's Pedro Vilaca and Synack's) the researchers, the new malware contains the malicious binaries which resembled same as the malware which was uncovered by the HackingTeam data breach last summer. Both are not sure at the moment that behind all these, Hacking Team is involved, but soon they will find it out.

According to the researcher, malicious binaries that are contained by the malware are only droppers, not anything complex. If we talk about Droppers then it can be defined as the computer viruses classes that contain functions. They possess a capability to infect computers and are able to communicate with a C&C server and also the specific piece of malware variant can be downloaded, based on infected system details. When the researchers were analyzing the malware, they also found that, at that time antivirus engines in Google's VirusTotal service weren't flagging it as malicious.

The HackingTeam's Remote Control System (RCS) has been installed by the malware onto the computer, as this time malware is a "dropper". The code of "dropper" is also same as the code which was prior to their hack last year.

When the network of a HackingTeam in July 2015 was hacked, that time almost 400GB of confidential information was leaked which include emails, firms-government relationship, and many more sensitive information. 

Now, this time, the target is Mac OS, the second most widely used desktop OS after Windows.

How to check whether you are affected or not?

To check if you are infected or not look for Bs-V7qIU.cYL or _9g4cBUb.psr which is dropped into the ~/Library/Preferences/8pHbqThW/ directory.
If you find any of these codes then delete that entire directory, and remove the ~/Library/LaunchAgents/com.apple.FinderExtAvt.plist file.


Raspberry Pi3 adds Wi-Fi and Bluetooth

Raspberry Pi3

Raspberry Pi featuring Quicker 64-Bit Processor/Wi-Fi/Bluetooth


The most well-known British computer so far is the Raspberry Pi and the title was previously held by the Amstrad PCW which is believed to have sold around eight million units. The sale of Raspberry Pi will exceed that amount this month according to Eben Upton the founder of Raspberry Pi project. The breakthrough has come as the Raspberry Pi 3 had been unveiled featuring a quicker 64-bit processor as well as a built-in Wi-Fi and Bluetooth connections.

Mr Upton had stated that they are the best-selling UK computer. He mentioned that the Pi Foundation originally believed that it had won the title last year when the sales had gone past the total set in 1980s by Sinclair machines. But he mentioned it had appeared that the Amstrad machine had been sold in great numbers and that the total too had exceeded.

He added that the curve tends to keep trending upwards and the sales will get a lift from the release of the Raspberry Pi 3 by the end of February. The sale price would be $35 and a few hundred thousand units would be available on launch day from the online stores. The Raspberry Pi 3 retains the form factor of the Raspberry Pi 3 and works well with the latest version.

Utilise as PC Replacement/Embedded Computer


He had informed BBC that the two main things which people tend to do with their Pi are utilising it as PC replacement or use it as an embedded computer. The Pi 3 is doubling down on both these things instead of going looking for new things to do.

The updated device tends to have a 64-bit processor on-board which provides the Pi 3 a performance of 50% improvement on the Pi 2. Besides this the built in to the latest device are the Wi-Fi as well as the Bluetooth connections. He mentioned that for hobbyists, who use the Pi, it tends to act as a hub for home gadgets who would be able to use Bluetooth to connect devices as well as sensors together.

 He said that this is the first Pi one can stick behind the TV and tend to forget about it completely. There have been indications that the Pi had been successful in achieving one of its formation focus that is to make computer science as a more well-known option at degree level.

Being Used Extensively in Schools


Mr Upton had mentioned that the Pi’s popularity together with the other coding projects were arousing interest in the technical subject. He mentioned that in some of the institutions the number of individuals enrolling on computer science courses had improved from the low points that were seen in 2008-9.

 But he admitted that it may yet be too early to see the complete effect of the Pi on the people who tend to pursue coding or their technical skill, considering that the first Pi was released only in 2012. He said that the gadgets had begun being used extensively in schools and the merger of the Pi foundation with the Code Club initiative could ensure that it reaches more children and with children in the age of 9 – 11, would be seeing a lot of people getting excited about it at that level.