SlideShare une entreprise Scribd logo
1  sur  25
Télécharger pour lire hors ligne
NewsBytes
-Aishwarya Iyer
 Graduate from Mumbai University
 Interested in Programming and Information
Security
 Pursuing certification course in core java
followed by advanced java.
 Serious TCP/IP Bug allows traffic Hijacking
 Hitler Ransomware
 Australia online census shutdown after
cyber attacks
 Data Breach at Oracle’s MICROS Point-of-Sale
 Miscellaneous
//OVERVIEW:
o Vulnerability in TCP implementation in Linux
version 3.6
o Can affect many linux devices, embedded
computers, mobile phones etc..
o Can be done by anyone in the world if attack
machine allows IP spoofing
//Vulnerability
o Allows blind off-path attacker to infer
between 2 hosts communicating on TCP
o Leading to connection termination and data
injection
o TCP assembles data in a series of data
packets identified by Sequence numbers
o Side-channel attack
o an attacker with spoofed IP address does not
need a man-in-the-middle (MITM) position
//However the good news is…..
Patches have been developed and distributed
for the current linux Kernel.
//Technical Analysis
o Main executable is a batch file with other
bundled apps
o Removes all extensions for files under various
folders like %UserProfile%/Desktop etc..
o 3 files are extracted: chrst.exe, erOne.vbs,
firefox32.exe and copied to %temp%
//Lastly
It will look for any processes named taskmgr,
cmd etc,, and terminate it
//Overview
o Australian census every 5 years
o As they headed to the website, a series of
DOS attacks took place
o “It was an attack from the overseas” – David
Kalisch,ABS
//Furtunately but,
o PM-Malcolm Turnbull-”no data has been
compromised”
o ABS- data is secure
o Kalisch-Data is encrypted and in the ABS and
noone else has it
//Simple Drawbacks
o Embarrassment to Australian Government
o Labor opposition-”Worst run census in the
history of Australia”
o Mass-discontent
//Overview
o Breached 100’s of security systems at Oracle
o Compromised customer support portal
MICROS:
o Top 3 POS vendors globallly
o Oracle-”detected and addressed malicious
code in some legacy systems”
o Size and scope of attack unclear
o 700 security Systems infected
//Whois???
o 2 security researchers pointed out
Carbanak Gang:
• Russian
• Known to have stolen 1 billion$ from banks,
retailer firms etc..
//Oracle
o Forced password Reset
o Attackers failed to grasp enormity of access
o Pokemon Go! Creator’s twitter Hacked!!
o Microsoft accidently leaks backdoor keys to
bypass UEFI secure boot
o O2 confirms USBs distributed in marketing
campaign contain virus
o Fake Windows Activation is actually a
ransomware Trojan
o http://thehackernews.com/2016/08/linux-
tcp-packet-hacking.html
o http://www.bleepingcomputer.com/news/sec
urity/development-version-of-the-hitler-
ransomware-discovered/
o http://www.securityweek.com/australia-
online-census-shutdown-after-cyber-
attacks?utm_source=feedburner&utm_mediu
m=feed&utm_campaign=Feed:+Securityweek
+(SecurityWeek+RSS+Feed)
o https://www.facebook.com/ethicalhackingne
wsandtutorials/?notif_t=notify_me_page&noti
f_id=1470887131517196
o https://www.facebook.com/InfoSecInstitute/?
fref=ts
o http://cyberwarzone.com/fake-windows-
activation-actually-ransomware-trojan/
o www.scmagazine.com/o2-confirms-usbs-
distributed-in-marketing-campaign-contain-
virus/article/514719/
NewsByte by Aishwarya Iyer

Contenu connexe

En vedette

Les trucs et astuces d'un bon référencement - Pilot'in
Les trucs et astuces d'un bon référencement - Pilot'inLes trucs et astuces d'un bon référencement - Pilot'in
Les trucs et astuces d'un bon référencement - Pilot'inJulien Dereumaux
 
Catalogo herramientas (1) (2)
Catalogo herramientas (1) (2)Catalogo herramientas (1) (2)
Catalogo herramientas (1) (2)Dissan2014
 
Eine Behavioral-Marketing-Plattform ermöglicht den Dialog mit dem Individuum
Eine Behavioral-Marketing-Plattform ermöglicht den Dialog mit dem IndividuumEine Behavioral-Marketing-Plattform ermöglicht den Dialog mit dem Individuum
Eine Behavioral-Marketing-Plattform ermöglicht den Dialog mit dem IndividuumTWT
 
Cultura e identidad
Cultura e identidadCultura e identidad
Cultura e identidadAriMaya900
 
Reserva natural y eco turística la posada de los andakíes
Reserva natural y eco turística la posada de los andakíesReserva natural y eco turística la posada de los andakíes
Reserva natural y eco turística la posada de los andakíesleidy Carvajal
 
Data in Motion: Streaming Static Data Efficiently
Data in Motion: Streaming Static Data EfficientlyData in Motion: Streaming Static Data Efficiently
Data in Motion: Streaming Static Data EfficientlyMartin Zapletal
 
La Consumer Experience nel Web Sociale. Case History settore Coiffure
La Consumer Experience nel Web Sociale. Case History settore CoiffureLa Consumer Experience nel Web Sociale. Case History settore Coiffure
La Consumer Experience nel Web Sociale. Case History settore CoiffureGioia Feliziani
 
Puertas cortafuego, características y uso
Puertas cortafuego, características y usoPuertas cortafuego, características y uso
Puertas cortafuego, características y usoPuertas Roper
 
Ivis - Agencia de Prospección y Venta de Soluciones B2B. Servicios de desarro...
Ivis - Agencia de Prospección y Venta de Soluciones B2B. Servicios de desarro...Ivis - Agencia de Prospección y Venta de Soluciones B2B. Servicios de desarro...
Ivis - Agencia de Prospección y Venta de Soluciones B2B. Servicios de desarro...IVIS Estrategia, Márketing y Ventas SL
 
2011 martinarodaro x garmont
2011 martinarodaro x garmont2011 martinarodaro x garmont
2011 martinarodaro x garmontmartinarodaro
 
Plants - Our Older Siblings - A message from the Andes
Plants - Our Older Siblings - A message from the AndesPlants - Our Older Siblings - A message from the Andes
Plants - Our Older Siblings - A message from the AndesComunidad Mallqui
 
Manual de mantenimiento indura
Manual de mantenimiento induraManual de mantenimiento indura
Manual de mantenimiento indurayeferson andres
 

En vedette (17)

CASO NATURAL HAIR CALI
CASO NATURAL HAIR CALICASO NATURAL HAIR CALI
CASO NATURAL HAIR CALI
 
Les trucs et astuces d'un bon référencement - Pilot'in
Les trucs et astuces d'un bon référencement - Pilot'inLes trucs et astuces d'un bon référencement - Pilot'in
Les trucs et astuces d'un bon référencement - Pilot'in
 
VariPad - Empower Your Mobility
VariPad - Empower Your MobilityVariPad - Empower Your Mobility
VariPad - Empower Your Mobility
 
Catalogo herramientas (1) (2)
Catalogo herramientas (1) (2)Catalogo herramientas (1) (2)
Catalogo herramientas (1) (2)
 
Eine Behavioral-Marketing-Plattform ermöglicht den Dialog mit dem Individuum
Eine Behavioral-Marketing-Plattform ermöglicht den Dialog mit dem IndividuumEine Behavioral-Marketing-Plattform ermöglicht den Dialog mit dem Individuum
Eine Behavioral-Marketing-Plattform ermöglicht den Dialog mit dem Individuum
 
Cultura e identidad
Cultura e identidadCultura e identidad
Cultura e identidad
 
L'olivo
L'olivoL'olivo
L'olivo
 
Reserva natural y eco turística la posada de los andakíes
Reserva natural y eco turística la posada de los andakíesReserva natural y eco turística la posada de los andakíes
Reserva natural y eco turística la posada de los andakíes
 
Data in Motion: Streaming Static Data Efficiently
Data in Motion: Streaming Static Data EfficientlyData in Motion: Streaming Static Data Efficiently
Data in Motion: Streaming Static Data Efficiently
 
La Consumer Experience nel Web Sociale. Case History settore Coiffure
La Consumer Experience nel Web Sociale. Case History settore CoiffureLa Consumer Experience nel Web Sociale. Case History settore Coiffure
La Consumer Experience nel Web Sociale. Case History settore Coiffure
 
Puertas cortafuego, características y uso
Puertas cortafuego, características y usoPuertas cortafuego, características y uso
Puertas cortafuego, características y uso
 
Ivis - Agencia de Prospección y Venta de Soluciones B2B. Servicios de desarro...
Ivis - Agencia de Prospección y Venta de Soluciones B2B. Servicios de desarro...Ivis - Agencia de Prospección y Venta de Soluciones B2B. Servicios de desarro...
Ivis - Agencia de Prospección y Venta de Soluciones B2B. Servicios de desarro...
 
Newsletter décembre 2015
Newsletter décembre 2015Newsletter décembre 2015
Newsletter décembre 2015
 
2011 martinarodaro x garmont
2011 martinarodaro x garmont2011 martinarodaro x garmont
2011 martinarodaro x garmont
 
Poemas
PoemasPoemas
Poemas
 
Plants - Our Older Siblings - A message from the Andes
Plants - Our Older Siblings - A message from the AndesPlants - Our Older Siblings - A message from the Andes
Plants - Our Older Siblings - A message from the Andes
 
Manual de mantenimiento indura
Manual de mantenimiento induraManual de mantenimiento indura
Manual de mantenimiento indura
 

Plus de nullowaspmumbai

Plus de nullowaspmumbai (20)

Xxe
XxeXxe
Xxe
 
ELK in Security Analytics
ELK in Security Analytics ELK in Security Analytics
ELK in Security Analytics
 
Switch security
Switch securitySwitch security
Switch security
 
Radio hacking - Part 1
Radio hacking - Part 1 Radio hacking - Part 1
Radio hacking - Part 1
 
How I got my First CVE
How I got my First CVE How I got my First CVE
How I got my First CVE
 
Power forensics
Power forensicsPower forensics
Power forensics
 
Infrastructure security & Incident Management
Infrastructure security & Incident Management Infrastructure security & Incident Management
Infrastructure security & Incident Management
 
Middleware hacking
Middleware hackingMiddleware hacking
Middleware hacking
 
Internet censorship circumvention techniques
Internet censorship circumvention techniquesInternet censorship circumvention techniques
Internet censorship circumvention techniques
 
How i got my first cve
How i got my first cveHow i got my first cve
How i got my first cve
 
Adversarial machine learning updated
Adversarial machine learning updatedAdversarial machine learning updated
Adversarial machine learning updated
 
Commix
Commix Commix
Commix
 
Adversarial machine learning
Adversarial machine learning Adversarial machine learning
Adversarial machine learning
 
Dll Hijacking
Dll Hijacking Dll Hijacking
Dll Hijacking
 
Abusing Target
Abusing Target Abusing Target
Abusing Target
 
NTFS Forensics
NTFS Forensics NTFS Forensics
NTFS Forensics
 
Drozer - An Android Application Security Tool
Drozer - An Android Application Security Tool Drozer - An Android Application Security Tool
Drozer - An Android Application Security Tool
 
Middleware hacking
Middleware hackingMiddleware hacking
Middleware hacking
 
Ganesh naik linux_kernel_internals
Ganesh naik linux_kernel_internalsGanesh naik linux_kernel_internals
Ganesh naik linux_kernel_internals
 
Buffer overflow null
Buffer overflow nullBuffer overflow null
Buffer overflow null
 

Dernier

ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
Evaluating the top large language models.pdf
Evaluating the top large language models.pdfEvaluating the top large language models.pdf
Evaluating the top large language models.pdfChristopherTHyatt
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdflior mazor
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 

Dernier (20)

ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Evaluating the top large language models.pdf
Evaluating the top large language models.pdfEvaluating the top large language models.pdf
Evaluating the top large language models.pdf
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 

NewsByte by Aishwarya Iyer