Tuesday, January 17, 2023

How to get into DevOps?

 Getting into the field of DevOps can be challenging, but with the right skills, experience, and mindset, you can begin a successful career in this field. Here are a few steps you can take to start your journey in DevOps:

Learn the basics: Familiarize yourself with the basic concepts of DevOps, such as continuous integration, continuous delivery,

Guide to a Cyber Secure Home

 As technology continues to advance and more and more devices become connected to the internet, it's important to take steps to ensure the security of your home. Here are a few tips to help you create a more cyber-secure home:

  • Use strong and unique passwords: Strong passwords are essential for keeping your devices and accounts secure. Use a mix of letters, numbers, and special characters, and avoid using easily guessed information like your name or birthdate.

Thursday, February 14, 2019

CISA Review Question, Answers and Explanations 11th Edition









The manual consists of 1000 MCQs, answers and explanations.










CISA Review Manual 26th Edition

ISACA is pleased to offer the 26'h edition of the CISA® Review Manual.111e purpose of this manual is to provide CISA candidates with updated technical information and references to assist in preparation and study for the Certified Information Systems Auditor exam.

The content in the manual has been substantially updated. Most of the changes made were to recognize and map to the new task and knowledge statements that resulted from the new CISA job practice analysis. Fmiher details regarding the new job practice can be found in the section titled NEW-CISA Job Practice and can be viewed at www.isaca.org/cisajobpractice and in the ISACA Exam Candidate Information Guide at www.isaca.org/examguide. The exam is based on the task and knowledge statements in the job practice. The development of the task and knowledge statements involved thousands of CISAs and other industry professionals worldwide who served as committee members, focus group participants, subject matter experts and survey respondents.

Differences between On-prem Infra and Different Clouds

On premises infrastructure is something that most organizations believe is the best strategy but there are options that need to be considered given that what major cloud service providers are offering

Major players in CSP business are:

AWS
AZURE
GOOGLE
ORACLE
IBM
ALI BABA

Common Banking Frauds

Hottest target for Fraud and stealing money for hackers and thieves is Banking Industry, that is also hot in news now a days too. A bank is available to get defrauded via multiple channels but most common channels are:

Electronic Banking
Bank Cards
Occupational Fraud
Settlement
Lending
Financial Instruments

CISSP for Dummies - ISC2 Approved



The CISSP certification is widely held as the professional standard for information security professionals. It enables security professionals to distinguish themselves from others in the information security field by validating both their knowledge and experience. Likewise, it enables businesses and other organizations to identify qualified information security professionals and verify the knowledge and experience of candidates for critical information security roles in their respective organizations. Thus, the CISSP certification is more relevant and important than ever before.

Wednesday, February 13, 2019

CIS Controls Cloud Companion Guide




The CIS Controls™ are a prioritized set of actions that collectively form a defense-in-depth set of best practices that mitigate the most common attacks against systems and networks. The CIS Controls are developed by a community of IT experts who apply their first-hand experience as cyber defenders to create these globally accepted security best practices. The experts who develop the CIS Controls come from a wide range of sectors including, retail, manufacturing, healthcare, education, government, defense, and others.

Wednesday, September 27, 2017

How 'the invisible network' poses a major security threat

If a hacker managed to switch off a life-support machine, the results could be fatal
Imagine a hacker remotely turning off a life support machine in a hospital, or shutting down a power station. These are the nightmare scenarios we face because many organizations haven't a clue how many unsecured devices are connected to their networks, cyber-security experts warn.
It was an ordinary day at a busy hospital - doctors, nurses and surgeons rushed about attending to the health of their patients.
For Hussein Syed, chief information security officer for the largest health provider in New Jersey, it was the health of his IT network that was keeping him busy.

Sunday, September 24, 2017

Web Server Penetration Testing Checklist


Web server pen testing performing under 3 major category which is identity, Analyse, Report Vulnerabilities such as authentication weakness, configuration errors, protocol Relation vulnerabilities.

1. “Conduct a serial of methodical and Repeatable tests “ is the best way to test the web server along with this to work through all of the different application Vulnerabilities.

Active Directory - DNS and DHCP Security Checklists - Basic

 

Active Directory 

• Review the domain controller disk space reports.
• Backups of – AD, backup includes capturing system state, information related to AD database, logs, registry, boot files, SYSVOL and other system files.
• Evidence for AD replication is working correctly.
• Snapshot of event logs for persistent errors.
• Is defragmentation is done to increase performance as large directories running for long time can get large and fragmented.
• Proof of integrity of AD DS database files with respect to AD semantics using NTDSUTIL.
• Where password files are kept and who is responsible.
• Is there any formal method exists for adding new users?
• Is there any formal method of notifying the Administrator of staff changes exists, with access levels being amended without delay (particularly if staff are required to leave the organisation)?
• Any formal mechanism exists for changing users / access rights to the files.
• What is the User account/ID lockout due to invalid passwords attempts
• Are the IT Administrator users are also complying with these policies and IS there any generic IDs created in Active Directory?

Singapore leads the world in cyber attacks

More cyber attacks are launched from Singapore than anywhere else in the world, according to a report from Israeli data security firm Check Point Software Technologies.

The small Southeast Asian country has overtaken Russia, China and the US as the top attacking nation.

Eying Wee, Check Point's Asia-Pacific spokeswoman, told Bloomberg that it was not unusual for Singapore to be featured among the top attacking countries as much of the internet traffic flowing through Singapore doesn't actually originate there.

46,000 new phishing sites are created every day

An average of 1.385 million new, unique phishing sites are created each month, with a high of 2.3 million sites created in May. The data collected by Webroot shows today’s phishing attacks are highly targeted, sophisticated, hard to detect, and difficult for users to avoid. The latest phishing sites employ realistic web pages that are hard to find using web crawlers, and they trick victims into providing personal and business information.

Finally Kaspersky Security Softwares Ban to Use all US Government Agencies

Finally, US Government Decide to Bans all the Kaspersky  Security Software Products that is using by United States federal agencies since a lot of Spying Activity Controversy against the Kaspersky Products.

Kaspersky is Moscow, Russia Based Leading Cybersecurity Firm who Provides Many Security Products such as Anti-Virus, Internet Security, Endpoint Security, Cloud Security which claims to have 400 million users worldwide.

Department of Homeland Security (DHS) Release Immediate Order to Federal Executive Branch departments and agencies to take actions related to the use or presence of information security products, solutions, and services supplied directly or indirectly by AO Kaspersky Lab or related entities.

Friday, March 3, 2017

Bank Alfalah

Bank Alfalah is back online!

Bank Alfalah Internet Banking is Down!


Bank Alfalah's Internet banking is down since more than 2 hours now. No bank official is taking responsibility of the downtime. It is reported to State Bank by Lantech's team.

Wednesday, February 22, 2017

Trump’s website allegedly defaced by Iraqi hacker


A secure web server of Donald Trump’s campaign website has been purportedly hijacked by a hacker from Iraq.

Donald Trump, 45th President of the United States of America, won the Elections last year and held the office last month. Many of his decisions are criticized worldwide such as immigration ban on Muslims from 7 countries including Iraq.

A hacker from Iraq, who identified himself as “Pro_Mast3r”, defaced a server of a website linked to Trump’s presidential fundraising campaign, donaldjtrump.com, on Sunday. The hijacked web page displayed a picture of a man in fedora and a message that read,

“Hacked By Pro_Mast3r ~
Attacker Gov
Nothing Is Impossible
Peace From Iraq”





According to Arstechnica, the server, secure2.donaldjtrump.com, is apparently an actual Trump campaign server because its certificate is legitimate. It further stated that the hosting of this website is provided by US-based internet security company, Cloudflare. When a reference link to an image on another site was clicked, Chrome and Firefox prompted that the connection is not secure, Arstechnica reported.

The source code contains a link to JavaScript on a Google Code account, masterendi, which has been previously associated with the hack of about three websites. The account does not exist anymore.

The server of Trump’s website is now offline. There are no comments from Trump Pence Campaign and Cloudflare yet.

Source:TechJuice

Tuesday, February 21, 2017

50 GB of Free and encrypted Cloud Storage Mega.nz


If you want free Cloud Storage, safe, secure and want to keep your files encrypted over the cloud and make sure that no one access them without your permission. Mega.nz is your answer.

You can even share your files with MD5 key and with separate MD5 key so you can share it separately with anyone you are sharing your files with.