Tuesday, April 18, 2017

Tech Tip Tuesday – Homograph Attacks

This is straight out of Wikipedia. https://en.wikipedia.org/wiki/IDN_homograph_attack

“The internationalized domain name (IDN) homograph attack is a way a malicious party may deceive computer users about what remote system they are communicating with, by exploiting the fact that many different characters look alike, (i.e., they are homographs, hence the term for the attack). For example, a person frequenting citibank.com may be lured to click a link in which the Latin C is replaced with the Cyrillic ะก.”

This vulnerability coupled with convincing phishing campaign could easily dupe the savviest of users. Bad guys/gals can make it even more convincing by getting valid certificates for their domain. Chrome 59 is patched and Firefox has a workaround by not providing a user friendly way of reading IDNs. https://www.xudongz.com/blog/2017/idn-phishing/

If you have a Tech Tip you want to share, send them to info@cyberhui.org and we'll get them out next #TechTipTuesday.

Wednesday, April 12, 2017

Tech Tip Tuesday - Protect Yourself from Your ISP

If you still have concerns over the new found rights of ISPs to sell or use your private data for their benefit, the Electronic Frontier Foundation (EFF) put together a list of measures you can take to keep your private information… private.

https://www.eff.org/deeplinks/2017/04/heres-how-protect-your-privacy-your-internet-service-provider

If you have a Tech Tip you want to share, send them to info@cyberhui.org and we'll get them out next #TechTipTuesday.

Tuesday, April 4, 2017

Tech Tip Tuesday – Just Say No Thank You

Who reads their EULA (end user licensing agreement) or any other privacy notice for services they use their services? Maybe we should before (or in addition to) installing a VPN and user TOR to browse. Your ISP should give you the ability to Opt Out of (Customer Proprietary Network Information) CPNI which they use to market communications-related services. They basically monitor you web traffic to customize what advertisements you receive. I’m not saying you shouldn’t share your information. I think you should just be aware of what you are implicitly agreeing to.

https://www.usatoday.com/story/tech/columnist/2017/04/02/take-these-5-steps-help-protect-your-privacy-online/99953034/

If you have a Tech Tip you want to share, send them to info@cyberhui.org and we'll get them out next #TechTipTuesday.

Tuesday, March 28, 2017

Tech Tip Tuesday - Network Penetration Testing Checklist

There are many ways to perform a network penetration test. This checklist gets you started and even suggests some popular tools. Are these in your toolbox?

https://gbhackers.com/network-penetration-testing-checklist-examples/

If you have a Tech Tip you want to share, send them to info@cyberhui.org and we'll get them out next #TechTipTuesday.

Tuesday, March 21, 2017

Tech Tip Tuesday – Cheat Sheet for Windows Machine Intrusion Detection

Is your Windows machine pwned? How do you know? Where do you start? This cheat sheet identifies seven areas to look at as a jumping off point. Happy hunting! https://gbhackers.com/penetration-testing-cheat-sheet-windows-machine-intrusion-detection/ If you have a #CyberPatriot Tech Tip you want to share, send them to info@cyberhui.org and we'll get them out next #TechTipTuesday.

Tuesday, March 14, 2017

Tech Tip Tuesday – Vuln Hub

Vuln Hub is a repository of vulnerable virtual machines for you to download and get your hacking on. There are varying levels of difficulty and some even have walkthroughs. The resources page is a great place to get started.

https://www.vulnhub.com/resources/

If you have a Tech Tip you want to share, send them to info@cyberhui.org and we'll get them out next #TechTipTuesday.

Tuesday, March 7, 2017

Tech Tip Tuesday – Web Penetration Testing (XSS and XSRF)

Here’s a preview to the SANS SEC642: Advanced Web App Penetration Testing, Ethical Hacking, and Exploitation Techniques course. The on demand virtual course goes for $5,910, so it’s nice to get a sneak peek for you sign up. The author goes over the techniques, tools and procedures (TTPs) to combine exploits in cross-site scripting (XSS) and cross-site request forgery (XSRF) for greater effects.

https://pen-testing.sans.org/blog/2017/03/02/modern-web-application-penetration-testing-part-1-xss-and-xsrf-together/

If you have a Tech Tip you want to share, send them to info@cyberhui.org and we'll get them out next #TechTipTuesday.