First there was Metrobank Direct, then BPI, Asia United Bank, Equitable -PCI (now Banco de Oro) that got hit by phishers wishing to earn money the wrong way from unsuspecting online bankers
I predicted my own bank to be targetted by phishing people and there it was...a phishing email was sent to numerous email recipients where the senders kept their fingers crossed that a few uninformed souls will actually login to their Chinabank Online account.
For your info, China bank Online requires two passwords: one for login and another for transactions (called transaction password). The two can be made the same (i know it's weird, but it can really be set to be the same thus defeating the purpose)
Using two passwords is not the same as two-factor authentication...
Chinabank released advisories warning their clients that they won't send emails requiring acount holders to login to their account.
No bank does that, only evil miscreants do!
Related Post:
Chinabank Swift Code
Chinabank Bank Code for Paypal
Uncomplicating the Complicated stuff from a guy who's not can be really technical, with lots of ideas on hand but no time to blog.
Monday, December 22, 2008
Believe It Or Not, Chris Tiu is a Boring Host
I'm a big fan of Ripley's Believe or Not, from the great Jack Palance to the later Dean Cain (of Lois and Clark) as hosts.
On Philippine TV, the show is anchored by Ateneo Basketball star Chris Tiu. While he's a very good basketball player, his hosting skills need lots of polishing...to the point of being boring with an almost monotonous tone reminiscent of AM radio station hosts.
Didn't you notice it? Try to listen to the way he presents each Believe It or Not feature and you'll see...he also depends too much on the teleprompter...
On Philippine TV, the show is anchored by Ateneo Basketball star Chris Tiu. While he's a very good basketball player, his hosting skills need lots of polishing...to the point of being boring with an almost monotonous tone reminiscent of AM radio station hosts.
Didn't you notice it? Try to listen to the way he presents each Believe It or Not feature and you'll see...he also depends too much on the teleprompter...
Saturday, December 20, 2008
Microsoft Internet Explorer Flaw: Patch Tuesday and Exploit Wednesday (MS08-078)
The just released patch for critical IE flaw by Microsoft, released out-of-band and not along with the regular batch of Patch Tuesday schedules just makes you realize that the vulnerability being corrected is really critical.
Normally, MS will release patches on the second Tuesday of the month, that's why it's called Patch Tuesday.
When I got wind of the vulnerability release, I immediately had the patch tested for bugs and rolled out to PCs and laptops with Internet access. It's a good thing that most users in the office don't have Internet Access (was cut off on September 21, an ominous date indeed) and also most of those who have use Firefox.
After a vulnerability's made public (though this exploit has been making the rounds of the underground hacker community for a while now), crackers and miscreants race to develop proof-of-concept codes and exploit the vulnerability, zero day or the next day, aptly called Exploit Wednesday.
For those looking download the latest patch, it's filename is IE7-WindowsXP-KB960714-x86-ENU.exe available at Microsoft Update Website (direct link here)
As for me, I don't use Internet Explorer except for testing and accessing stupid IE-only online banks and websites.
Normally, MS will release patches on the second Tuesday of the month, that's why it's called Patch Tuesday.
When I got wind of the vulnerability release, I immediately had the patch tested for bugs and rolled out to PCs and laptops with Internet access. It's a good thing that most users in the office don't have Internet Access (was cut off on September 21, an ominous date indeed) and also most of those who have use Firefox.
After a vulnerability's made public (though this exploit has been making the rounds of the underground hacker community for a while now), crackers and miscreants race to develop proof-of-concept codes and exploit the vulnerability, zero day or the next day, aptly called Exploit Wednesday.
For those looking download the latest patch, it's filename is IE7-WindowsXP-KB960714-x86-ENU.exe available at Microsoft Update Website (direct link here)
As for me, I don't use Internet Explorer except for testing and accessing stupid IE-only online banks and websites.
Clickjacking: Attack, Defense and Proof of Concept
Clickjacking, the latest of the seemingly endless attacks concocted by security researchers and crackers where unsuspecting visitors of a website are forced to click on invisible buttons and execute scripts, program, malware to steal passwords, cookies, listen to you , even activate your webcam to see what you're doing.
Almost presented by researchers at OWASP (Open Web Application Security Project) and also presented at the Hack in the Box security conference in KL.
For users, it's so dangerous that you'll never know what hit you just by clicking your mouse on a clickjacker's website.
Vulnerable browsers to Clickjacking: ALL (Internet Explorer, Opera, Google Chrome, Firefox, Safari)
Clickjacking Countermeasure: Firefox with NoScript add-on.
The only thing that will protect you from a clickjacking website is Firefox with NoScript Add-on, something I've been using be default when browsing the Internet. Just don't set NoScript to "Allow Scripts Globally" for it's useless defense.
For security awareness seminars, I always remind people refrain from visiting untrusted websites but it's hard for them to actually determine which sites are fine to access.
Later, I will test various clickjacking proof of concept codes/scripts to analyze, but not to be one of the miscreants.
Almost presented by researchers at OWASP (Open Web Application Security Project) and also presented at the Hack in the Box security conference in KL.
For users, it's so dangerous that you'll never know what hit you just by clicking your mouse on a clickjacker's website.
Vulnerable browsers to Clickjacking: ALL (Internet Explorer, Opera, Google Chrome, Firefox, Safari)
Clickjacking Countermeasure: Firefox with NoScript add-on.
The only thing that will protect you from a clickjacking website is Firefox with NoScript Add-on, something I've been using be default when browsing the Internet. Just don't set NoScript to "Allow Scripts Globally" for it's useless defense.
For security awareness seminars, I always remind people refrain from visiting untrusted websites but it's hard for them to actually determine which sites are fine to access.
Later, I will test various clickjacking proof of concept codes/scripts to analyze, but not to be one of the miscreants.
Subscribe to:
Posts (Atom)