Posts

Showing posts with the label infosec

WARNING: GCash Phishing Leveraging the SIM Registration Act

Image
A lot has happened since the Philippine SIM Registration Act has been implemented.  There are people who are for and against its implementation.  That is an issue that can only be resolved in time.  However there is a bigger issue has stemmed from it.  The law is now being leveraged by threat actors that seeks to gather personal information from their potential victims. While reviewing my SPAM folder for legitimate messages that have slipped into the cracks, I noticed this interesting sender. A casual look makes it appear as if it came from GCash, a service I use for my digital wallet needs.  Although the display name says "admin@gcashmobile.com", it was sent "via sendgrid".  Just to let you know, legitimate emails from GCash comes from the "@gcash.com" email domain so this is already a big red flag.   Here is the body of the message: Looks convincing, right?  However, one thing that everyone should be aware of is this: Companies will always refer...

Work from Home and Distance Learning During the COVID-19 Pandemic

Image
In a world ravaged by COVID-19, the reliance on the internet has been magnified. Majority of the workforce who can perform their mundane office tasks remotely are now allowed to work from home. Schools are virtually ghost towns as most of them opt to conduct classes online. Banking and other financial transactions are also mostly done from home. This unexpected "digital transformation" is well and good as it encouraged work from home and distance learning.  However, this also opens up home computers and home networks to more threats than ever.  One sad fact that needs to be addressed is that most home computer users (those who work or study from home) have not taken steps to secure their home computers, home network and their network-connected devices.  Securing all these will take a lot of time and a whole lot more time "researching".  As a public service, I will be writing a series of posts that should address this. What are the particular threats that faces peopl...

TACHYON VPN: Internet Privacy Made Easy

Image
During this difficult time of "enhanced community quarantine", one of the things I do is muck around my gadgets to play games, research. and yes, blog.  During one of those gaming sessions on my phone, I noticed a simple and unobtrusive ad for a VPN.  The ad was about Tachyon VPN .  My initial reaction is that of indifference because ads for VPN service is a dime a dozen, especially when playing games on either iOS or Android.  A lot of them doesn't even work at all. However, I was strangely compelled to click on the ad and I was redirected to the App store amd since I was already there, I threw caution to the wind and clicked on install, ready to immediately delete the app once my device flags it as suspicious or malicious. I was pleasantly surprised when I was greeted by a rather clean interface and since no alarm bells rang, I decided to try it out and connect.  Upon connection, I was checked if the VPN was working.  I did this by going to https://www.wh...

IMOW: The Need to be Anonymous Onlne

Image
If you have among the 5 readers who has been taking time to read articles from this site, you may notice that I have been discussing Personal Technology Security and I have been concentrating a lot on personal data privacy.  This is because most of the online scams I have encountered in the practice of my profession stems from either the careless handling or the (un)intentional leakage of personal information. But there is an aspect in Personal Technology Security that is just as important but is often overlooked, even ignored.  I am talking about Online Anonymity .  Internet technology is now so advanced that it can now track the activities of each individual online -- what one purchases, searches for, reads, and even writes in emails/message boards. Majority of people would dismiss the concept of anonymity outright because apparently "they have nothing to hide".  These people cannot be more wrong in their assumption. Let me put it this way: Have you ever sear...

New Malware (virus) Infects Chrome and Targets Banks

Image
This will be the first of a series of posts I will call "IMOW" or In My Own Words.  The objective of this is to explain tech stuff such that it will be, hopefully, understandable to not-to-technically-inclined users.  Feel free to comment/criticize if you find me going too technical/geeky so I can adjust accordingly. I came across this news item this morning and it is sort of alarming considering that I used to work for a large local bank and it may affect thousands of clients if it reaches our shores.  The news reports of a new malware that infects a computer when a user opens video that is supposed to be about the "Corona Virus".  This video is hosted on a compromised internet server which in turn infects everyone who attempts to open the Corona Virus video.  Security researchers named this malware " Grandoreiro ". Now, it the infected computer happens to be using Google Chrome and visits an internet banking site, the malware will generate an ...

Personal Data Protection

Image
If you have been reading my Personal Technology Security Series posts, you now know that online fraud and cybercrime are mostly done with minimal or even no hacking involved.  A lot of victims' accounts were compromised through social engineering -- the victims were somehow tricked into disclosing enough information so that allowed fraudsters to perform transactions in their name.  I know of a lot of cases where the victims themselves disclosed their passwords through phishing/SMISHING/VISHING and their savings go missing in front of their eyes.  Credit/debit card holders unwittingly disclosing their card numbers and watch as their debts rack up. But social engineering is not the only way cybercriminals and fraudsters gather information that they can use to do their nefarious jobs.  One way they get useful information is through carelessy trashed account statements from banks and credit card companies.  This document contains everything that a cybercri...

Best Antivirus for 2020?

Image
A few days ago, a former colleague messaged me asking for a recommendation for Antivirus for his presumably new Windows 10 installation. If this question came my way 5 years ago, I would have recommended a veritable laundry list of reputable anti-virus for him . However, technology moved on and I personally believe that 3rd party anti-virus is no longer necessary for personal PCs.  Let me explain myself.  Nowadays, threats from convetional computer viruses is no longer as dangerous as it was years ago.  Most malicious behaviour of conventional computer virus are automagically detected by most modern Operating Systems, including Windows 10 (as long as it is updated).  Real threats nowadays are not as obvious as computer viruses.  These new threats include Phishing, Ransomware ,  Drive-by Downloads , Malvertising , etc. and most of these are not necessarily detected and "fixed" by antiviruses. So that we have established that conversional antiviruses ar...

Personal Technology Security: What Exactly is Social Engineering? Part II

Image
Yesterday, I discussed two most successful and most prevalent social engineering tactics used nowadays. One emerging tactic that may not be as widespread but just as damaging is VISHING.  What is VISHING? According to wikipedia, VISHING is a form of criminal phone fraud, using social engineering over the telephone system to gain access to private personal and financial information for the purpose of financial gains. How does it work? Unsuspecting victims will receive a phone call from someone claiming to work for their bank.  The caller will claim that the victim's credit/debit or ATM card needs to be verified to prevent it from being deactivated.  The caller will then ask for the victim's personal information for "verification".  The caller will also ask for the card's CVV/CVC number (it is the three-digit number at the back of the card). To make the conversation appear legitimate, other questions may be asked but all the fraudster actually need from the ...

Personal Technology Security: What Exactly is Social Engineering?

Image
Fun fact: Not all malicious "Hacking" incidents involves actual hacking actiities.  In fact, a large perceentage of so-called "hacking" victims in fact does not involve any computer hacking whatsoever. Before I continue, let me first define what hacking really is. Hacking is a series of activities including surveying target systems and identifying and exploiting any vulnerabilites identified on the target system.  Sounds rather exciting but actual hacking activities invloves a lot of patience and a little bit of luck to be successful.  Depending on the implemented security of the system that is targetted for a hack, the activity will take at least a few hours up to a couple of days even weeks!  Imagine taking weeks in order to compromise accounts. That being said, we can safely say that hacking is not an easy thing to pull off in order to be "profitable". The easier way to steal enough information to compromise accounts.  This is where "Social Eng...

Personal Technology Security: Malware and How it Affect Every Juan

Image
In my previous post, I mentioned the dangers posed by "malware".  What is "malware" and do we really need to worry about it? Malware is a portmanteau of "Malicious" and "Software".  it is a piece of computer code that is written specifically to perform malicious actions.  Computer virus , trojan horses , ransomware , keyloggers , etc. are all considered Malware. With that in mind, are we all in danger from Malware?  The short answer is a resounding YES.  Can we do anything to protect ourselves from Malware?  Another short answer to this is another resounding YES. Given this, how do we protect ourselves from the dangers posed by Malware? Preventing damage done by Malware infection can either be simple or complex.  Here are some simple steps from protect ourselves from Malware: Keep your devices updated as much as possible, as soon as possible.  Malware easily penetrate devices (computers, laptops, tablets and cellphones).  Do n...

Personal Technology Security Series: What Do We Need to Secure

Image
In my last article, I discussed how wonderful it is to live in a time when technology gives us an unprecedented access to information and services right at the comfort of our homes and even at the palm of our hands. I also discussed how most of this technology becomes accessible to almost everyone. It is no longer a novelty seeing a sidewalk vendor playing mobile games on a smartphone or a security guard watching a videostream of his favorite NBA team. Teenagers often share their OOTDs, foodography and other activities on social media. Busy people often do their banking using the mobile banking application on their cellphones. Free wifi on malls and other public places are a godsend for people who do not have data plans on their mobile devices because it allows them to do all these at virtually no cost at all. As mundane as those activity may appear, each one of them poses a risk to both the users and the device that is in use.  I will enumerate the risks that a person opens ...