Wednesday, December 31, 2014

Kajal Majhi

Micromax Canvas Tab P666

By     No comments:

Yesterday I was at Kolkata and thought to spend some time at E MALL ,  hopefully I passed by a corner where a demo model of Micromax Canvas P666 was there for display . Thanks to that boy whom I told that I will not buy now but he still didn’t felt bad to show me the handset . For tablet I always tend for something looks elegant , durable,  equipped to give power performance and features to play the multimedia applications and that’s what Micromax Canvas P666 does it.  Its first look was so attractive for me, If I say honestly that if I had that much of money I would have brought it yesterday. 

 Well, here is why this Micromax Canvas P666 meets my expectation and how it will help me to archive my needs.
The real thing of every tablet or smartphone is it’s processor , and with the trust of Intel, Micromax has put the splendid Intel Atom processor with the processing speed of 1.2GHz which is also featured with Hyper Thread technology for multitasking . What I need is a fast hyper processor and Intel Atom suits my requirement . Wait, only a fast processor is not enough, I need enough RAM to run highly threaded apps , and yes Micromax Canvas P666 is married with 1 GB RAM which combines with 1.2 GHz processor and Android Kitkat OS to give lightning performance . It also have 8GB storage space which is enough for me to keep my data and also have storage expandable option via micro SD card.

Well I am a gaming addict , I watch a lot of movies , for gaming first I need good support of graphics, yes as It is powered by Intel, it has Intel Graphics Media Accelerator for superior graphics. The 8 inch width screen with 800 * 1280 pixel resolution and 16m color depth combines to give graphics performance much better. No doubt I can play my favorite games and movies much better .
Hold on, high performance processor and a huge screen needs enough power to run I need a battery with well equipped mAh, and yes Micromax P666 doesn’t let me down as it is equipped with 4400mAh battery which gives 325hrs standby and runs up to 6 to 8rs on playing high end games which really suits my expectation.

One of my hobby is photography and when I don’t carry my camera I need something simple that won’t disappoint my hobby . Yes it is equipped with 5MP primary rear camera with which I can click some great snaps , it has 1080P HD recording that won’t disappoint me. Oh yes it is also equipped with 2MP front camera that is great for video chat and when its time for selfie just click and share .

Connectivity is the one of the important thing in todays’ life .  I am a cyber-security personnel and I need of connectivity at any time  and it does support multiple connectivity option. It is enabled with WIFI connectivity , it also supports 3G connectivity and voice calling which is a great option. It is also featured with Bluetooth 4.0 and GPS. It also has micro USB port to connect with my pc.

Oh yes the design , because of which I was attracted towards this device. It has glass finished slim body which looks elegant in class and cool in hand.


This post has been written for Happy hours campaign held at Indiblogger for more details please follow the link  Micromax Canvas Tab P666
Read More

Monday, November 10, 2014

Kajal Majhi

Careto the most sophisticated malware

By     No comments:

Get yourself introduced with the world’s yet most advance and sophisticated malware that has been discovered by Kaspersky  and It has infected many systems in more than 31 countries .  Instead of attacking the common users or consumers, it targets the government institutions , oil and gas companies , embassies and research companies and because of this behavior sometimes it is assumed as a sponsored attack or campaign to run a new form of surveillance or to collect foreign data.  Careto was live for many years until it was unmasked and then it’s centralized server went offline , but still there are many possibilities of Careto that can be run privately for any planned attack .

Careto was written by highly professional people which consist of a sophisticated malware, a rootkit, a boot kit , MacOS X, some version of Linux as well as mobile platform of iOS and android . Which mean it can act according to the victims’ system architecture.

CARETO STRING

How does Careto work?
It consists of phishing email with a link to malicious website ,  the malicious website contains many exploits which inject according to the victim’s OS architecture as the malware has been already designed for dynamic platform. When an user click on the link  , then the malcious website inject the exploits into the user’s system and after successfully injecting , it redirect the user to the original website that was stated in the phished email.

It capture nearly 50 file types including doc , pdf, encryption key, server SSH key and RDP files which are used to identify the users and build remote desktop connection , and many more file types .
This malware is highly modular that it can interact with almost all communication channels , it support plugins as well as it can also intercept with flash players .

The game of malware, virus and other threats will never end as each and every hacker and criminals builds new and new type of threats and many people will be victims  till it is discovered by the security researcher  . So  it is better to protect you system and device from day to day cyber threats .

It is very important to Install a security software in your system .

Avoid attachment from unknown senders

Download music, videos, apps, eBooks from only official and trusted sources .

Check the link sent by anyone and think twice before you click .

Stay updated with cyber threats , virus, malware by subscribing to security blogs .

If you find any unknown weird activates in your system or in someone system then report it to security researcher , it may help them to discover new threats .



Read More

Wednesday, September 24, 2014

Kajal Majhi

If you are a celebrity, you are vulnerable to hack

By     No comments:

celebrity, celebrity logo, celebrity account compromised
No doubt that celebrities are more talented , good looking and intelligent than us but they are damn vulnerable to hack.For example, lets take the Oscar winner Jennifer Lawrence , recently whose’ extremely private photos were leaked by hackers from the Apple’s cloud storage service. Celebrities are being targeted because their private data are extremely valuable in the underground markets as well as many hackers try to show their skills to the world.

Why Celebrities are vulnerable to hack?That’s what this topic is about. When we forget our password of some websites we try to recover them from the ‘forget Password’ option, and there we have two or three option two reset or retrieve our password , first by receiving a password rest link in our email id, secondly we have to enter the ‘one time password’ received on our cellphone else we have to answer the security questions.Skip the first two options and lets try to answer the security questions.  Most of the account’s security questions based on the followings :

  • The place where you were`
  • In which year you were born?
  • Your childhood nickname ?
  • Which High school did you attend?
  • Your Childhood best friend name?
  • Your birth year?




If you are a celebrity or a popular person then all the answers of the security questions are already out there around the internet . Turn on the Wikipedia pages you will get all the biographical information from the birth year to yearly life story.A celebrity has to face different questions which belongs to their personal life, likes dislikes, hobbies as well as career . Hit the search engines and it will retrieve all the information published on the online portal of news and entertainment channels .   Their social profiles also yells various internal information about their daily life activities which can be the key of the security questions.

Well, nothing is secured in internet but one should adopt latest security features which are availe by their service provider such as Dual authentication systems , fingerprint recognition system etc so that a hacker have to access the celebrity’s device or have to plant malware to see the one time password which is not impossible but a difficult task.
Read More

Wednesday, September 3, 2014

Kajal Majhi

Story of cloud storage security

By     No comments:
keyhole, digital keyhole, internet security wallpaper

The recent phenomenon of compromising the cloud account of Hollywood stars and leaking their private pictures around the internet , has been the hottest topic from last few days. As this incident has tickled the medulla of website moderators , security analytics and cloud service provider  that what to do. Really it is a million dollar question “What to do? “   Because it is the matter about security and privacy of the users.

Yes we can do a lot of things , but there is an one strong point which everyone should know. “Nothing is 100% secured in the internet”  Not mine, not yours and nor even the geeks who designs security protocols .  Internet is the game of codes, hardware, connectivity and we users . The things we human knows to build , does also know to break it, If it is not possible by punctual manner then there are lots of hammering and destructive way to break it.

Understanding the cloud storage

Cloud storage service has been built to bring flexibility of data sharing and migration anytime and anywhere. Once you upload your data then you can retrieve it from anywhere in the world. You don’t have to carry your own storage device , you just need an computing device with an internet connectivity .

So, here I have a question, where does you upload your files?
Sorry, don’t get me wrong,  but I have to say this.  Point to the line above “you don’t have to carry your own storage device” . So you are uploading your data to someone else’ storage media isn’t it? Where you don’t have any idea and control other than accessing your files and configuring your account’s digital security.  You don’t know where the storage media is,  about the physical security in the data warehouse of cloud service provider and so on. Its like handing over your important things to someone else.

Is your cloud account secured?

cloud storage service, cloud security

Keeping the point in mind “Nothing is secured in the internet” . But there are lots of way by which we can prevent or extend the duration to crack the security . Almost every cloud service provider has multiple security option some of them are by default and few of them have to configure by the user itself.

Two step authentication is one of the most important security measures that should be adopted by everyone , for not only your could account but also for your email and social accounts. In dual step authentication , first you have to enter your primary password and then the server will send you a text with a code, that’s your secondary password.

Authenticate by generating code using your smartphones cloud apps.

Pincode : It is generally generated once during enabling this feature. You will need to remember this incase you have enabled dual step authentication but you don’t have your cellphone with you.

Security question : Never choose an security question and answer which are know by anyone other than you.

Enable the SSL encryption.  Many cloud service has SSL by default and few have to configure by the user itself that he wants SSL encryption or not.

Secure your computer first

computer security, localhost security, hacker eye

What is your primary computing device? Your laptop, desktop, tablet, iPad, or smartphone?  Do a proper maintenance of your device on a regular basis. Don’t keep the unusual applications and programs as it may bring security flaws.  Use a total security program consist of anti virus, anti malware, firewall , spam/phishing detection system etc. Do the updates of your operating system once in a month to get security patches .
Apart from these, spend your little more precious time over internet to learn about worms, malware, virus and information security threats . It will help you to deal with daily life phenomenon.

How is your smartphone?

Smartphone is one of the most important daily life gadgets , without it we feel like we are out of this living world isn’t it?
 Yes it is,  it has more secret information than your social id does and can be the target for your competitors and malicious hackers.  Never Jailbreak or root your smartphone if you want to keep it safe. Root and Jailbreak can break the security level of your smartphone and becomes vulnerable to information security threats.  Keep a security program in your smartphone , by which you can wife the storage remotely if you ever lose it.


Few lines from my opinion.
Cloud storage is great innovation and technology for this developing IT infrastructure of this world. You can backup your data for emergency purpose, you can share work and office documents with clients and workmates , and much more. But I don’t recommend it keep your extreme private data on cloud storage as cloud storage device are not managed by yourself . If it’s the matter for your extreme privacy and security then there is no safer storage device  in the world other than your own isolated hard drive.




Did you get bored? Sorry about this :)  please express your anger by dropping your comment below :) 
Read More

Wednesday, August 20, 2014

Kajal Majhi

How to remove RAMNIT malware

By     No comments:


Ramnit is one of the most dangerous threat which is active today, it is a form of malware which is integrated with social engineering and because of which an user can be victim of this malware very easily. Usually it infects the .exe , .dill , .html files and also steals banking and financial information.

It is a multi component malware which spreads through removal devices such as USB Flash drive and stays stable until an user logged into his account.
It opens a backdoor which becomes easy for remote attackers to access your system remotely and make sudden changes as per their wish.

It makes some terrify changes in your computer , due to which it becomes difficult to make any changes such as OS updates, install security software or any anti malware programs.

Its steals browser cookies

Its steals login data and saved FTP and financial credentials.


How RAMNIT infect and work in a windows system?
When an user logged in into his Online bank account , then RAMNIT inject into a page where the user has to configure a phone number for one time password (OTP) or any other page to “set transfer processing system”  where it execute a temporary phone number. Then it connect to the command server designed by the attacker where it dispatch the details . Then the user receive a temporary number via RAMNIT and a OTP from the bank’s server. When the user enter the both his is right in the traps because he has authorized a money transfer to the attacker’s account unknowingly .
How to detect RAMNIT in your system?
You can diagonanis your system by various system diagonis tools and can see the infected output below:

REG:system.ini: UserInit=c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe”


How to get ride of RAMNIT malware?
Its is not easy to get ride of such type of malware which makes difficult to install security suit , but we have many options  to try.
Microsoft has many free tools which can detect and remove such threats .

Windows Defender  for Windows 8 and Windows8.1
Microsoft security Essentials for  Windows 7 and Windows Vista

Option two:
Download eScan antivirus toolkit.
Start your PC in safe mode  ( You can get the Safe mode option in BIOS under Boot settings )
Lunch the Toolkit and scan the complete hard drive.

Advice for user :
Always use a strong password
Use a good Firewall software
Always scan the removal storage media
Perform system updates at least once in a month.


Read More

Tuesday, August 19, 2014

Kajal Majhi

How to know your location history using Google Map

By     No comments:

Google location history, Google location map, google map

Do you remember Google latitude from the past? Where we could share our location data with our friends , we could ping our friends at place on map to gather all together there. Google location and Location history was evolved with Google latitude and now its is much devolved with new features .

Yes Google knows it all, If you ever have used Android or any Other Google apps then Google knows you location . Not only android and apps. But if you use any Google products such as Gmail, Adsense etc then Google has been constantly tracking your approximate location. You can find your location history from Google server by using your phone's browser here https://maps.google.com/locationhistory/b/0   . You can see a map with red dotted points and lines with few timelines at the bottom. The dotted points are the places where your device has been tracked .


Deleting the location history 
If you want to delete some or specific location history data, you can do it from dashboard , click on the date and select “Delete history from this time period”


Enable/disable Google location history
If you are highly concerned about the privacy of your personal life and tech life then you can turn off this features , simple by change its settings from dashboard. Android devices comes with integrated location access setting under the personal panel settings.

Android location access settings, google location acees settings, android snapshot
Screenshot of Google location settings




Read More

Tuesday, August 5, 2014

Kajal Majhi

How to identify scam emails

By     No comments:


What you are going to do with $1 or $2 ? May be you will buy a bubble gum, candy or donate it in the temple, isn’t it? But this is the enough money for a hacker/spammer to create a fake email and send it to millions of email ids around the world and may be one will drop in your inbox , then how you will identify it as a scam email?
You may also receive emails about unusual advertisement and promotion of products and services even if you have not subscribed to their newsletters , so how do they get your email ids?  It is hard to believe anyone , as some greedy website owners sell their customers’  email database for a huge sum of money and the spammers and advertisers take advantages of this email marketing .
Here are some sample fake/scam email that you may have or you may receive in your inbox. 

LOTTERY  SCAMS
You may receive bulk email with subject “YOU WON A GRAND LOTTERY PRIZE” . They will inform you that “You have won a grand cash prizes of 250,000,000 Pounds for British Lottery Associations, and they need your personal details such as email id, bank account numbers, phone no address etc. so the association can contact you” first they will greed you by telling that huge sum of money , then they will ask you to pay some service charges, if you pay they will claim money again pretending with different charges .  So ignore such emails and mark it as spam as it will help the email server to protect other users from such fake emails.


REFUGEE SCAMS
You may receive bulk emails from a girl , she claims that her parents has died at civil war in some country and she is residing at a refugee camp as she have no home.   First she will contact with such emotional emails, if you give response to her emails she will act like a pen pal , she will share her self created emotional story with you as well as her father has left some huge amount of money in his  bank   account and that can only be withdrawn with a foreign partner , then she will ask your details such as personal email id, bank account number, address etc.  She is not she, it’s the spammers who try to fool people to steal money.



FOREIGN TRANSFER SCAM
You may receive a spam email the person will claim that he/she is from Reserve Bank/ Central Bank of the nation, and you are lucky one to be chosen as foreign exchange beneficiary of 500,000 pounds for outstanding incurred by foreign government  and as a rule of your central bank you have to pay about 19,000/ as handling and service fees to proceed the official transactions . If you pay the fees then they will claim some different fees as the Lottery scams and by the time its too late.



FAKE PAYMENT GATEWAY
Hackers and spammers are always trying new ideas to take down users and their information. As online education and online purchase are being more popular among people, so hackers found this a fair way to attract users, they send bulk email claiming that it’s a invitation  from a reputed foreign university for a higher degree or they send advertisement of personal medecines like pills for enlargement of organs , loose weight and fat etc. When a user is attracted toward this and he is willing to pay, then he got redirect to the spoofed payment gateway and if they enter their credit card number, cvv number, email id, billing address etc, Oh man! You are in trap!
We can identify such scam email by various things , but now a days most of the email servers has their own email detection system by which such emails directly goes to your spam folder, but if still it is in your inbox then you can detect by the followings:


Incorrect Spellings:
Spammers usually do mistakes while typing , but they try their most of the efforts to express originality and take down users but still their quality of language used will be very poor.

Plain Text
Most of the scam and phished emails are poorly written in plain text with weird unusual logos and  commonly used fonts. But if you receive emails from legitimate company you can see its written on HTML, images and high end font which looks like almost a banner.

Sender’s email id:
Hackers/spammers usually use free based email service or unusual email server to attempt such things. You can detect the email id in a weird form such as aghs-327@axnbe@com .


Website URL & Security:
Most of the spoofed webpages has weird url which is weird to read as well as to stare at them. They claims that their website is ssl secured, geo trust, certified by MasterCard/visa but actually it’s the only copied logo , if you hover your mouse and click on those logo it will show nothing, but a legitimate website and payment gateway is SSL secured which you can see it a secured logo with green colour at the address bar of your browser. If you click on the logo of visa/MasterCard , geo trust it will open a new popup secured window and display the website’s licence status.




USE YOUR COMMON SENSE
This is going to be the rude paragraph from my side , Ok if you don’t understand all of the above then use your common sense.  If you have to pick a lottery then go to the local lottery agency and pick any one and test your fortune. Why those gain company will give you such huge amount of money and that is in pounds ?  if you have to purchase medicine online for your extremely personal use then Google it you will get a lots of legit website that have some 
legit review about those medicines.  If you want to study abroad then first search details about the university online, no university is will to charge you to view their details and course structure in a first go. And Your central bank  much more work to do than informing you individually about the foreign beneficiary .


 




Read More