Ethical is something what you do and what you thought which makes you good among everyone! what if there is no one watches you in the internet world what you do is ethical be a hacker!!
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 89 today we're going to discuss about The first part of securing your organization is maintaining a good perimeter defense around your building.Now based on your organization this is going to have different requirements based on what kind of work you do.For example, if you work for the government or the military, you may be dealing with classified information and if that's the case you may see a big eight foot tall chain link fence with barbed wire at the top surrounding the building.You may have access control points that are guarded by soldiers with guns.There might be vehicle barricades, there might be other such things that are going to keep people away from the building unless they're authorized to be there.This makes sense for them right because they're dealing with secret and top secret information and they want to make sure nobody gets access to it that shouldn't Now your company probably doesn't have this level of security though. And instead they're going to rely on surveillance cameras and closed circuit TV.Now when we talk about closed circuit TV or CCTV as it's also called, these come in lots of different solutions.The first two types are wired and wireless.A wired solution means that this TV camera that's being placed around your building is going to be physically cabled from its device all the way to a central monitoring station.Now if you're using a wireless solution, these are a lot easier to install but because they're wireless they could have interference with other systems and an attacker could try to jam them. There's also indoor and outdoor,some CCTV systems are only designed to work indoors and others are used for outdoors. If you're going to be monitoring the parking lot, you need an outdoor camera that's going to be able to stand up to the elements like rain and snow and things like that.If you're going to be monitoring things indoors,like access to and from server room access to and from the lobby, this would be something you could use an indoor camera for.They're a lot cheaper because they don't have to be held up to that standard that works in the outside. Another feature you might want to look at with your CCTV is what's known as PTZ which is pan, tilt, and zoom. This is what you might've seen in some movies.If there's a security guard as in part of the bank heist and he's able to take a joystick and move the camera to look a different direction and tilt it up and down, pan it left and right, or zoom in or zoom out.That's a PTZ system. Another type of system we have is what's known as an infrared system which looks at things based on their heat, as you can see in this image.You could see the laptop is producing heat and we'd be able to see it. The final type is what's known as ultrasonic which is used for sound-based detection.If you've ever watched the Mission Impossible movies,they had an ultrasonic system that would sit there and listen, if even a pin dropped on the floor,it would set off the alarm and that way this guards could come running in and arrest the perpetrator.Now when you place your cameras, placement is really importantand you have to figure out what are you trying to guard.Most of the time you're trying to guard your entrances and your exits.If you're pointing the cameras at the entrance or exits, you'll be able to see when people enter or leave the facility.This would be both the entrance and exit of your building but also of your server room and other secure locations.
Hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 88 today we're going to discuss about Physical security.Physical security is really important to your organization's network security.After all, if an attacker is able to touch your network,your server, or your work stations,they can take control over those devices and do whatever they want with them.While we've been talking a lot in this course about all of the logical protections you can put in place,things like firewalls and intrusion detection systems,router ACLs, passwords, encryption,and all sorts of things like that,our physical security is just as important.Now, physical security is usually broken down into three main areas.We have the perimeter,we have the building,and then we have the room itself.So when I start talking about the perimeter,I'm talking about, as I approach your building, what is in my way?Are there fences?Are there guards?Is there some sort of vehicle access point?All of those type of things, that's our perimeter.What keeps us at bay and away from the building? Next, we get to the building security. Is the front door unlocked? Can I walk right in? Do I have to show my ID? Do I have to check in with somebody? What are the different controls you're putting in place to secure that building?And then finally we have the security of the room where your equipment is located.Now, if this is an office, this is going to be someplace that people actually work, and so people have to be able to get in there to access those terminals.How are you keeping unauthorized people out of those offices?And if you're dealing with a server room or a networking closet, those are places that people don't normally work inside of.And so when nobody's in there, we should be locking those using some sort of locking mechanism,whether that's a door lock, an electronic lock,or some other mechanism.Now, we'll talk about that all inside this section of the episode.
Hello everyone welcome to the show "Ethical Hacking" episode 87 today we are going to discuss about We just spent a lot of time talking about wireless networks, but there are other wireless networks out there besides Wi-Fi.These include things like Bluetooth,RFID, Near Field Communication, cellular,GPS, and satellite communications.Previously, we've talked about some vulnerabilities with Bluetooth.I want to remind you of two big terms when it comes to Bluetooth.This is bluejacking and bluesnarfing.I'm covering these again because I guarantee you're going to get at least one question on test day about either bluejacking or bluesnarfing really loves to ask that for some reason.Bluejacking is the sending of unsolicited messages to Bluetooth-enabled devices such as mobile phones and tablets.Bluesnarfing, on the other hand,is the unauthorized access of information from a wireless device through a Bluetooth connection.So, to simplify this for the I want you to remember this.Bluejacking sends information to a device where Bluesnarfing takes information from a device.If you remember those two things,you'll do great on the exam.Also, when it comes to Bluetooth,remember you don't want to allow your device to use the default PIN for its pairing operations You should always change the PIN to something more secure than 1234 or 0000.Next, we have Radio Frequency Identification or RFID.RFID devices have an embedded radio frequency signal that's used to transmit identifying information about the device or the token to a reader that's trying to pick it up.RFID refers to a large category of devices and technologies,but, for the exam, the specifics of RFID are not that important.Instead, you need to focus on the fact that RFID devices can send information from a card to a reader to provide authentication or identification.For example, one of the most common devices that we use RFID for is a card that looks like a credit card,and can be used as part of your alarm system or door access system.So, with these cards, you can swipe your card over the reader, and it identifies you and allows you to enter the building.Because there are so many different types of RFID devices, RFID can operatein either very close environments or very far environments.It can be as close as 10 centimeters from the reader or as high as 200 meters from the reader depending on the particular device and technology in use.Because of that large distance,RFID is subject to eavesdropping,the ability to capture, replay, and rebroadcast its radio frequency as part of a larger attack.To minimize the ability to eavesdrop on RFID, an idea called Near Field Communication was invented.Near Field Communication or NFC allows two devices to transmits information when they're in close proximity to each other.This occurs using an automated pairing process and transmission process of that data.For example, some cellphones have the ability where you can touch the cellphones together to pass photographs back and forth.Other uses of NFC are common place in payment systems.For example, I have an iPhone,and I can hold it over a credit card terminal to pay with my credit card that's linked through Apple Pay.This is an example of a Near Field Communication device.Just like RFID, we do have to worry about the possibility of interception of that wireless information though because it could be replayed and rebroadcast Now, luckily for us, NFC does require the devices to be very close for the communication to work.
Hello everyone welcome to the show "Ethical Hacking" episode 86 today we are going to discuss about So we've talked about securing our wireless networks.Let's now spend a few minutes talking about the different types of attacks that focus on our wireless networks.The first is war driving.War driving is the act of searching for wireless networks by driving around until you find them.You could try this tonight. You can go sit in the backseat of your car,have your friend or your wife,drive you around the neighborhood and see which networks you can connect to.That's the idea here.They're simply going to drive around and hunt for networks.Now the attackers here are going to use different tools to do this.They can use wireless survey tools or other open source attack tools, but the common theme here is just finding out what networks are around and where you can access them from.Why would an attacker want to find open wireless networks or networks that they can get on to?It's not necessarily to attack your network,but it's to attack other networks through your network.So that way if they are doing some hacking or something like that,it traces back to your home and your home network,as opposed to tracing it back to them.The next type of attack is called war chalking.War chalking is the act of physically drawing symbols in public places to denote the open, closed, or protected networks that are in range.It gets its name because in the early days,people would actually take chalk and draw on a telephone pole different symbols to tell other people what it is.Now an example of this might be as you're doing a war driving,you might find an open network.If you did, you could find a telephone pole nearby,you can mark it down with a symbol like this.We have two open half circles faced back to back with the SSID of it written above them and the number below to signify the bandwidth of the network.Afterall, attackers can be nice people too.And they like to share their findings with others and they wouldn't want somebody else wasting their time looking for a network,only to find it has low bandwidth.So by marking that down,you can help other people avoid that network.Now in addition to open networks, you may find closed networks If you find a closed network,it's going to be a closed circle with an SSID written above it and bandwidth written below it.This tells us that network has some kind of encryption,it's closed,but we haven't quite figured out the password yet.Now if we do figure out the password,we can actually use this other symbol.We have the closed circle,we have the SSID on the top left left,we have the password on the top right,and the bandwidth below it.Inside the circle we might write something like W or WEP or WPA2,so people know what type of encryption they need to connect to that network.Now as I said war chalking is not nearly as popular as it used to be.In fact we don't really see a lot of these symbols around in the city anymore.Instead, most of this is being done digitally. This is being done as part of websites or other apps that hackers use and share their finds,so people know what other kind of WiFi is out there.The next attack we have is known as an IV attack.An IV attack occurs when an attack observes the operation of a cipher being used with several different keys and they findthis mathematical relationship between those keys to determine the clear text data.Now I know that sounds really complicated,but the good news is you don't have to do the math to do it.There's programs that do it for you.This happened with WEP because of that 24 bit initialization vector.It makes it very easy to crack WEP because there's programs that do it for us.
Hello everyone welcome to the show "Ethical Hacking" episode 85 today we are going to discuss about Wireless access points.In addition to selecting the right encryption,it's also important to select the right placement and configuration of your wireless access points,in order for you to achieve a good security posture.Most small office, home office wireless system rely on a single point to multi-point setup.This relies on having a single access point that services all of the wireless clients.For example, on this floor plan,you can see the strongest signal is the red spot,that's centered around a single wireless access point,and all of the other office cubicles are connecting back into it.In this next example,you can see a multi-point to multi-point system.This has multiple access points that are going to be used to provide the wireless network services in an ESS,or extended service set configuration.They're all going to work together to provide one common network that's supported by these multiple access points.Now, in both of the previous examples,the wireless access points are using an omnidirectional antenna.This means that the access point is going to radiate out its signal equally in every single direction.Now, this can be good from a coverage perspective,but it also is dangerous.You may want to control which direction the signal is actually radiated, and if you do,you can do that using a bidirectional or a unidirectional antenna.For example, in a unidirectional antenna,all of the transmission power is going to be focused at a single direction.This allows you to choose which areas receive the signals,and which ones don't.So in this example,we're using a left-side focused antenna and it only transmits out to computers on that side of the building,while the computers on the right are going to remain in an uncovered area and not get any signal.Now, we've talked about this back in our network plus curriculum as well,but from an operational standpoint,we're trying to increase the coverage to all areas,when we're talking network plus.Now, from a security perspective, though,we may actually want to limit the area of coverage.Let's look at our heat map once more.Here you can see an extended service set configuration with two access points.Each of those access points has omnidirectional antennas.This is giving us good,adequate coverage around the office base,as you can see inside the floor plan.So our network technician for network plus did a good job here.Now, for this office,each cubicle also has a wired physical connection,but the access point there is just to provide the employees access while they're sitting at those conference tables in the middle,or if they're walking around using their cellphones.Now, all of this is great,and there's good coverage,meaning that it's meeting our operational needs.But, you'll also notice that orange and yellow area,which represents the medium and lower signal areas that are radiating outside the walls of the building.
Hello everyone welcome to the show "Ethical Hacking" episode 84 today we are going to discuss about Wireless encryption. Another huge vulnerability in wireless networks is the encryption that you choose to use.In this lesson, we're going to do a quick review of wireless encryption types,that you learned back in your Network Plus studies.The reason for this is because encryption of your data being transmitted is going to be paramount to increasing the security of your wireless networks.Now, most wireless encryption schemes rely on a pre-shared key.This is when the access point and the client use the same encryption key to encrypt and decrypt the data.The problem with this is scalability becomes difficult.Think about it, when a friend comes over to your house,to use your WiFi.You have to tell him your password.Now, if you have 50 friends come over,you're going to tell 50 different people your password,and now, all 50 of them know your password.And so, this is one of the first problems that we have with wireless encryption,is that if you're going to use a pre-shared key,you've got to figure out a secure way to distribute that key to everybody,and keep it secret.If all 50 people know your password,then it's probably not that secret anymore.Now, there are three main types of encryption that are in use from wireless networks.We have WEP, WPA, and WPA2.WEP is our first one.WEP is the Wired Equivalent Privacy.This came from the original 802.11 wireless security standard,and it claimed to be as secure as a wired network.I'm going to prove this wrong to you in our demonstration later,because we're going to brute-force WEP,and break it in about three minutes.WEP was originally used with a static 40-bit pre-shared encryption key,but later it was upgraded to a 64-bit key,and, then again, to a 128-bit key.This isn't the main problem with WEP, though.The main problem is a 24-bit Initialization Vector,or IV, that it uses in establishing the connection,and it's sent in clear text.As I said, WEP is not very secure,and because of this weak Initialization Vector,we're going to be able to brute-force WEP in just a couple of minutes,using using Aircrack-Ng and other tools.So, to replace WEP, they came up with WPA.WPA is the WiFi Protected Access standard.It uses a Temporal Key Integrity Protocol, or TKIP,which uses a 48-bit Initialization Vector,instead of the 24-bit Initialization Vector used by WEP.The encryption that it uses is the Rivest Cipher 4,or RC4, and it added Message Integrity Checking, or MIC.And, it uses all of this to make sure that the data is secure,and ensuring that it's not modified in transit.Overall, it's a pretty good standard,but it does have some flaws,and so version 2 was released to fix those.WPA version 2, or WiFi Protected Access version 2 was created as part of the 802.11i standard,to provide stronger encryption and better integrity checking.The integrity checking is conducted through CCMP,which is the Counter Mode with Cipher Block Chaining Message Authentication Code Protocol.And, the encryption uses AES,the Advanced Encryption Standard.AES supports a 128-bit key, or higher,and WPA2 uses either a personal mode,with pretty short keys,or an enterprise mode,with centralized authentication via a radio server,or another centralized server,to handle that password distribution we were talking about.Now, I want to pause here for a second,and before we go any further,give you a couple of quick exam tips.First, if you're asked about WiFi,and it uses the word, Open, in the question, it's usually looking for some kind of answer that says the network has no security, or no protection.
Hello everyone welcome to the show "Ethical Hacking" episode 83 today we are going to discuss about Securing WiFi devices.Wireless devices are much less secure than our traditional networks because their data streams are simply flying through the air,waiting to be gobbled up by some attacker sitting out there.When we talked about wire tapping in the last lesson,we talked about having to gain access to the network physically.Well, with a wireless network that challenge is eliminated because the network is literally floating in the airways.In this lesson we're going to discuss some of the basic vulnerabilities associated with wireless networks and how you can combat them.First, the administrative access on the wireless access point is a vulnerability.Usually these have default user names and passwords like admin, admin like we discussed before.And you have to make sure you secure them.Also, remote administration should be disabled on your wireless access points.Remote administration is something that allows you to connect over the internet and then make changes to your wireless access point.You don't need that.Instead you should turn it off and make sure that you're doing it locally inside your network only to minimize that risk.The second vulnerability we have to think about is the service set identifier,or the SSID.Back in network plus you learned that the SSID is what uniquely identifies the network and it acts as the name of the wireless access point that the clients are going to use to connect to it.For example, if you came by my offices,you would see that my network is the oh so hard name to guess of vijay.Anyone who sees that might think hey that might be vijay kumar's WiFi, right?Well, that's the SSIDs job.It sits there and it broadcasts out hey I'm here,I'm here, I'm vijay, I'm vijay I'm vijay Now, according to you should disable the broadcast.So clients have to already know the name of it prior to connecting to it.They say this is a way to slow down the bad guy from attacking your network.As an ethical hacker myself,I can tell you that it isn't really going to slow me down.If you aren't broadcasting openly,your clients are still sending the same wireless access point information and that SSID with every single communication they make.It takes me about five seconds to find out your SSID if you're not broadcasting.So by disabling it you're just making operations harder for yourself and you're not really gaining any security here.Now all of that said,if you're asked disable SSID broadcast is considered good security in the security and you should implement it.In the real world, it really doesn't matter that much.Now the next one we're going to talk about is rogue access points.Rogue access points are another vulnerability out there.A rogue access point is an unauthorized wireless access point or wireless router that somebody connected to your network and it's going to give access to your secure network.For example, if you walk around your office and somebody decided that they didn't want to plug into that RJ45 jack all the way in the back wall over there,so they put a wireless access point so they can access it throughout the whole room.That makes operations easy for them,but that wireless access point wasn't properly configured.This is going to extend your wired network into the wireless realm,and it can introduce it's own DHCP server and cause all sorts of other issues.To prevent this you should enable MAC filtering on the network,network access control and run a good IDS or IPS on your network that can detect or prevent these devices when they initially try to connect.
Hello everyone welcome to the show "Ethical Hacking" episode 82 today we are going to discuss about Securing network media.Network media is the cabling that makes up our network.This can be copper,fiber optic, or coaxial.And they're going to be used as a connectivity method inside of our wired networks.Now, in addition to all the cables there's other parts of the cabling plant we have to think about.All those intermediate devices like patch panels, punch-down blocks,and network jacks all make up this cabling plant that runs throughout our organization.And each part of that can be a vulnerability for us.The first vulnerability I want to discuss is EMI.This stands for electromagnetic interference.Electromagnetic interference is a disturbance that can affect electrical circuits,devices, and cables due to radiation or electromagnetic conduction that occurs.Now, EMI is something that happens normally inside our businesses and inside our homes.EMI is caused by all sorts of things, like televisions,microwaves, cordless phones, baby monitors,motors like inside your vacuum, and other devices.Anything that is really a powered device,even handheld drills can cause electromagnetic interference.Now, to minimize EMI you need to install shielding around the source, for instance,your air conditioner lets off a lot of EMI.You could put shielding around that.Or you can shield the cable itself by choosing shielded twisted-pair.Now, STP cables, or shielded twisted-pair,have foil around either each twisted-pair in the cable or around the entire bundle of twisted-pairs to prevent emanations out of the cable or interference entering into the cable.STP gives you double benefit, it keeps things out, and it keeps things in.This is good for security and helps minimize this vulnerability.Now, the next vulnerability we have is called radio frequency interference, or RFI.RFI is just another type of interference like EMI.Like EMI it's a disturbance that can affect your electrical circuits,your devices, and your cables.But instead of being caused by electrical waves it's caused by radio waves.Most often from AM and FM transmission towers or cellular phone towers.Now, cell towers and radio towers near your office can be a big source of RFI in your wireless networks.And when you have a significant amount of RFI this can cause to network connectivity problems for your wired networks, as well as disturbing your wireless networks too.Now, this is something that you're going to have to address.And a lot of it is going to be addressed by shielding the building or getting stronger devices that can overcome the radio frequency interference that's occurring.Another vulnerability we have is what's known as crosstalk.Crosstalk occurs when a signal is transmitted on one copper wire, and it creates an undesired effect on another copper wire.So, when we think about having two copper wires,like inside of a twisted-pair cable,if the shielding inside that protects those wires comes off,then we can actually have crossover from one wire to another.And that causes interference because of the data emanations and EMI.Crosstalk is essentially that,but in very close proximity.Now, this becomes very common with older cable network types, things like Cat3 networks,or even some early Cat5 networks.Most of our Cat5E and Cat6A networks aren't really subject to crosstalk nearly as much.Another place is see crosstalk happen a lot is if you have punch-down blocks,and you decide to use an older terminal,like the old 66 blocks that were used for phone lines,and tried to use that for networks.Networks should always use a 110 block,like you learned back in Network because it gives more spacing and prevents crosstalk from occurring.The next thing you want to talk about here is STP cables because STP cables are really helpful to our networks.They can prevent some of that RFI, they can prevent EMI.And they can help with crosstalk.
Hello everyone welcome to the show "Ethical Hacking" episode 81 today we are going to discuss about Securing network devices.Network devices include things like switches, routers,firewalls, IDS, IPS, and more.Each of these different devices has its own vulnerabilities that have to be addressed.But for the security.we're going to focus on the most common vulnerabilities across all of these different devices.The first vulnerability we're going to talk about is default accounts.These are accounts that exist on a device straight out of the box when you buy it.So for example, if you buy a small office,home office wireless access point.Like a Linksys or a D-Link, or something like that,it's going to have some accounts already established on there.It might have one like admin or administrator or user,or something of that nature.All of these default accounts are very easy to figure out and very easy to guess.And so it's important for you to actually change these names so that they're not something that an attacker can easily guess.And then all they have to do is guess your password.Now, this applies to your organizations as well.You want to make sure that your naming schemes aren't really easy to guess.Unfortunately, though, most organizations are going to use a common naming scheme for all of their users.For example, most organizations like to use first name dot last name.So if your name was vijay kumar like me,you're vijaykumar@yourcompany.com.Or sometimes they'll do something like vkumar@yourcompany.com, where it's the first letter and the last name.Any of these make for a great,normal, easy to understand naming scheme.That makes operations very easy.But it also makes it fairly easy to guess.Because if I see that Jason.Dion@whatever.com is one email,then I can probably guess that Susan.Smith is also there.Or whoever else I'm dealing with.You want to make sure you're thinking about this and you're starting to add diversity,and making sure that those default user names are changed.Now, the next thing you want to think about is the device user name as well.There's defaults for this too.I've seen people call them router or switch as the user names.That's not a good plan either.When you're creating a device account,you want it to be something more complex.So maybe it's rtr for router with a couple of numbers after it.Something that's not easily guessable.That's what I'm talking about here as we try to change these default accounts.The next issue we have goes right along with default accounts,it's weak passwords.Don't leave passwords as their default.For instance, those Linksys routers we all have,they're admin for user, admin for password.That is horrible.We also don't want to use any words that are in the dictionary.Your passwords need to be long, strong and complex with at least 14 characters long, upper case, lower case, special characters and numbers.By having this mixture, it's going to increase the time it takes to brute force that password,and make it much harder for an attacker to break in to your network.So for example, if I have the password of password,which is all lower case, I'm only using 26 different options because lower case letters are A through Z.And so if I look at that, that's considered a weak password.If I add some upper case to it, now I have 52 characters because I have upper case and lower case.So I have something like password,where the P, the S's and the D's are upper case and the other letters are lower case.If I want to make it even more secure,I can add numbers to that.And I'll change out the S's for fives and the Os for zeroes, things like that.And this is going to give us more choices, again,because we have 26 lower case, 26 upper case and 10 numbers, zero through nine.But if we want it to be the best and most secure that it possibly can be, we want to add symbols to this too.And so now we're going to get something like 70 different options.
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 80 today we're going to discuss about In this section of the course,we're going to talk about securing your wired and wireless networks.We're going to start out with wired network devices,things like switches and routers,and then we'll move into the cabling that helps put all these networks together.After that, we're going to start talking about wireless networks and how we can better secure them and all the different types of attacks that exist for wireless networks.We'll even go through a demonstration in this section where I'm going to show you how easy it is to break wireless encryption and we'll be able to do that in about just two or three minutes.So it's really important to understand how to secure your networks properly so attackers can't do this to you.Now finally, we're going to round out this section by covering other types of wireless technology in addition to wifi,things like RFID,near-field communications,bluetooth, satellite communication,GPS, cellular, and others.So let's get started.
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 79 today we're going to discuss about In the last lesson, we talked about the concept of DNS poisoning.In this lesson, I want to cover the concept of ARP poisoning with you fairly quickly.Now ARP stands for the address resolution protocol,like you learned back in Network Plus,and it's used to convert an IP address into a MAC address.If you remember back from Network Plus and our OSI model lesson,as data moves down the OSI stack, it uses IP addresses to transmit packets all over the world from router to router.But once it finds the right router,that router converts that IP address into a MAC address and passes it on to the switches inside of its own network,and that is going to help it to deliver the information using frames inside the data link layer.Now ARP poisoning is going to exploit the way that an ethernet network works.It's going to enable an attacker to steal,modify, or redirect frames of information on the network.The concept here is that the attacker's going to associate their MAC address with the IP address of another device within the network.This way, whenever the router asks for the MAC address that's associated with that IP,they get the attacker's MAC address instead of the legitimate user's.This allows the attacker to essentially take over any session that would involve MAC addresses at the layer two of the OSI model.Also, if the attacker wanted to get really creative here,they could set up a man in the middle using this technique by taking over the MAC address first,then passing the data back and forth between the victim and the rest of the network.To prevent ARP poisoning,you should set up good VLAN segmentation within your network,and also set up DHCP snooping to ensure that IP addresses aren't being stolen and taken over by an attacker.
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 78 today we're going to discuss about DNS attacks.There are four different DNS attacks that you have to know for the security.There're DNS poisoning, unauthorized zone transfers,altered hosts files, and domain name kiting.Now, DNS poisoning occurs when the name resolution information is modified in the DNS server's cache.This modification of the data is done to redirect client computers to fraudulent or incorrect websites usually as part of follow-on attacks.The DNS system was designed without a lot of security embedded into it originally.This open architecture assumed a level of trust with all the other servers which I already told you is a pretty bad idea,but that has been taken advantage of by malicious attackers because trusting is a bad idea.Now, DNS poisoning usually occurs on a company's internal DNS servers instead of on public-facing DNS servers around the internet.With this type of attack, the internal client on the network has to make a request to go to a website like diontraining.com and whenever they make that request the client first checks with their local network's primary DNS server to see if it knows the IP address for that URL.If someone has gone there recently that IP address is already going to be stored in the local cache but if the cache was poisoned that user's now going to be redirected to a malicious website instead of the desired one.To counter act DNS poisoning, secure DNS also know as DNSSEC, has been created.DNSSEC uses encrypted digital signatures when passing DNS information between servers to help protect it from poisoning.You can also prevent your DNS servers from being poisoned by insuring that you're running the latest patches and the latest updates to make sure it's protected.Our next type of DNS attack is called an unauthorized zone transfer.DNS servers are normally configured to provide DNS data to a zone transfer which replicates information to other servers. With an unauthorized transfer though an attacker requests a copy of that zone transfer information and if they receive it they now have a list of all of your server names and IP addresses and this helps them plan for future attacks.Because of this, zone transfers should always be restricted between two known and trusted servers only and not let other people ask for zone transfers. The third type of DNS attack is focused on the client itself. Every computer and workstation has a file on it called the host file.The host file is a plain text file and it contains IP addresses and names.This is a reference that the operating system is going to check every time a DNS lookup is requested prior to going to a DNS server.So if the host file has a domain name being requested,it's simply going to provide the host file version of that DNS information instead of going out to a DNS server requesting it.So for example, one day my son was not doing his school work and it was really upsetting me.Instead I kept going up there and seeing he was watching YouTube.So, I logged into his computer and I added the URL for YouTube into his host list and I pointed that to the IP address for his school's website. Now, anytime my son typed in youtube.com instead of getting the DNS lookup for YouTube and getting redirected to their server he instead got the one from the host file that I maliciously put in there and it served up the home page for his school.Now, every time he tried to watch a video he was told hey you got to go to school, right? I think this is pretty funny and you may think it's funny too but he was not very happy about this change and he couldn't for the life of him figure out why YouTube wouldn't come up on his laptop.
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 77 today we're going to discuss about Transitive attacks.Transitive attacks aren't really an actual type of attack but more of a conceptual method.It gets its name from the Transitive Property we learned back in mathematics.Essentially, the Transitive Property says that if A equals B and B equals C,then by all logic, A also equals C.Now, when it comes to Security ,and they talk about the idea of a transitive attack,they're really focusing on the idea of trust.If one network trusts a second network and that second network trusts a third network, then that first network really trusts the third network, and so, if an attacker can get into any one of those three networks,he can then get into the other two as well.This is based on that transitive trust.This is really important in the world of security because whoever you trust,you're also trusting everyone else that they've ever trusted. Whenever you connect your network to somebody else's network using a trust relationship, you're inherently assuming all of the risk of their security posture or the lack of their security posture in addition to your own security posture.Now, often in large enterprise networks, we reuse trust relationships between different domain controllers because this helps us minimize the amount of times that someone has to authenticate over and over for a resource,but, remember, whenever you sacrifice security in order to afford yourself better or quicker operations,there is a risk associated with it.So if your organization wishes to maintain a strong security posture,your systems should not assume trust but instead, should question and re-question every device and network that it wishes to connect to.
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 76 today we're going to discuss about Replay attacks.A replay attack is a network-based attack where valid data transmissions are fraudulently or maliciously re-broadcast,repeated or delayed.This works a lot like a session hijack but it's a little bit different.With a session hijack,the attacker is trying to modify the information being sent and received at real time but with a replay attack,we're simply trying to intercept it,analyze it and decid whether or not to let it be passed on later again.Now, for example, if I were able to capture the session that occurs when you went in to log into your bank with your username and password,I could then replay that session to the bank later on in an attempt to log in as you.That's the idea of a replay attack.Now, to combat a replay attack,you should ensure that websites and devices are using session tokens to uniquely identify when an authentication session is occurring.Also, if you use multi-factor authentication,this can help prevent the ability of a log on session to be replayed because it doesn't have that token that has that random data that's changed every 30 to 60 seconds if you're using something like a one-time use password as part of your multi-factor authentication.One place where replay attacks have been used quite successfully though is in the world of wireless authentication.By capturing a device's handshake onto the wireless network,you can replay it later to gain access to that network yourself as if you were them.This is extremely common in the older protocols,especially the wired equivalent privacy or WEP when using a wireless network. So, you should be using the latest protocols like WPA2 to help prevent and minimize your risk.
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 75 today we're going to discuss about Hijacking, next we have hijacking which is the exploitation of a computer session in an attempt to gain unauthorized access to data,services, or other resources on a computer or server.There are eight types of session hijacking that can be performed.Session theft, TCP/IP hijacking, blind hijacking,clickjacking, Man-in-the-Middle,Man-in-the-Browser, the watering hole attack and cross-site-scripting attacks.The first type of hijacking is known as session theft.With session theft the attacker is going to guess the session ID for a web session and that enables them to takeover the already authorized and established session of that client.Each session is uniquely identified with a random string but if the attacker can determine or guess that string they can take over the authenticated session with the server.And this example, you can see this is occurring at the session layer of the OSI model but it can also occur at the network or transport layer too.Now when it does it's called TCP/IP hijacking.Because it occurs when an attacker takes over a TCP session between two computers without the need of a cookie or other host access.Because TCP sessions only authenticate during the initial three-way handshake the attacker can jump into the session at any time they want if they can guess the next number in the packet sequence.This can also be used to create a denial of service attack against the initial host that way they can take it over and not let that person jump back into the session.Now, the next type of hijacking is called blind hijacking because it occurs when the attacker blindly injects data into a communication stream and won't be able to see the results whether they're successful or not.Clickjacking is our next type.This attack uses multiple transparent layers to trick a user into clicking on a button or link on a page when they were intending to click on something else.Basically the hyperlink to the malicious content is hidden under some legitimate clickable content.So you think you're clicking on an image and you're actually clicking on some link that takes you elsewhere.Now a Man-in-the-Middle attack is probably the attack you've heard most before.This is also one that is commonly used in session hijacking.A Man-in-the-Middle attack causes data to flow through the attacker's computer where it can then be intercepted or manipulated as it passes through.This is considered an active type of interception.So let's pretend that you've got some kind of malware on your computer and now all of your traffic is going to route through this attacker's machine. Well, if you wanted to transfer $50 from your bank account to your friend's but the attacker changes the amount and the destination of the account you may now be sending $5000 to the attacker instead of the $50 to your friend.This is the idea of a Man-in-the-Middle.Since the attacker is sitting right in the middle of that connection they can see and manipulate any data as it's being sent back and forth.Now a Man-in-the-Browser is very similar to the Man-in-the-Middle except it's limited to your browser's web communication instead of looking at the entire communication.This can occur because you have a Trojan that's infected your vulnerable web browser and it modifies web pages or transactions that are being done within that browser.To prevent this you should insure you have a good anti-malware solution installed and you have the latest security updates for your web browser because this will pretty much eliminate the Man-in-the-Browser attack.Next you have a watering hole.And a watering hole is something that we described all the way back in the beginning of this course.It occurs when malware is laced on a website that the attacker knows his potential victims are going to access.
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 74 today we're going to discuss about Spoofing, spoofing is a category of network attacks that occur when an attacker masquerades as another person by falsifying their identity.Just like a person uses a mask to cover up their face to hide their true identity,spoofing is the electronic equivalent.We have briefly discussed spoofing a few times already,such as in the case of the DNS amplification attack when attempting a distributed denial of service by spoofing the IP address of the victim's server when making that request.Or we've talked about it before when we talked about fishing,where an attacker is trying to get you to click on a link in an email by falsifying their identity to trick you into clicking that link thinking that it's trusted.Anything that identifies a user or system can be spoofed, though.For example, each network interface card has a unique MAC address that's assigned to it,but MAC spoofing allows the attacker to change their MAC address to pretend that they're using a different device.IP addresses are also commonly used to identify a system, but with IP spoofing, the attacker can use somebody else's IP address as part of their attacks.So, how do we prevent spoofing from being effectively used against our systems?Well, the best way is to proper authentication,preferably multi-factor.Now when you use proper authentication,you're going to be able to identify a system or user more accurately and prevent the spoofing.If you can do this,you're going to be able to detect and stop spoofing quite easily.
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 73 today we're going to discuss about We talked about a denial of service attack involving the continual flooding of a victim system with a request for services that causes a system to crash and run out of memory.Now, this usually happens when you're talking about one system attacking one system.But that wasn't enough with modern computers,so we moved up to the distributed denial of service attack,where hundreds or thousands of people target a single server to take it down.Now, in March of 2018, the website GitHub was actually hit by the largest DDoS that we've clocked to date.This is where tens of thousands of unique endpoints conducted a coordinated attack to hit that server with a spike in traffic,and the spike in traffic went up to 1.35 terabits per second.This took the website offline for all of five minutes.So you can see how these DDoSes are really hard on a server and can take them down,but not for very long if you can stop 'em.So your real question probably is,how can you survive one of these attacks?And how can you prevent it from taking down your organization's servers? Well, we have a couple of techniques.The first one is called blackholing or sinkholing.This technique identifies attacking IP addresses and routes all of their trafficto a non-existent server through a null interface.This effectively will stop the attack.Unfortunately, the attackers can move to a new IP and restart the attack all over again,and so this is only a temporary solution.Intrusion prevention systems can also be used to identify and respond to denial of service attacks.This can work for small scale attacks against your network,but you're not going to have enough processing power to handle a large scale attack or a big DDoS.Now, one of the most effective methods to utilize is to have an elastic cloud infrastructure.If you've built your infrastructure so that it can scale up when demand increases,you can ride out a DDoS attack.Now, the problem with this strategy, though,is that most service providers are going to charge you based on the capacity and resources that you used, so when you scale up,you're going to get a much larger bill from that service provider than you normally were expecting.And you're not getting a return on this investment,because this traffic was all wasted.It wasn't generating any revenue for you.So there's actually some specialized cloud providers out there that have taken on this challenge.People like Cloudflare and Akamai are designed to help you ride out these DDoS attacks.They provide web application filtering and content distribution on behalf of your organization. These service providers are focused on ensuring that you have highly robust, highly available networks that can ensure that they can ride out these DDoS attacks and these high bandwidth attacks.This is going to also give you additional layer defenses throughout your OSI model, and it's going to help provide you additional protections.
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 72 today we're going to discuss about In the last lesson we discussed the concept of a denial of service attack,and we went over all of the different types of them, but most modern systems can't be taken down by a single machine attempting a denial of service anymore,so attackers got smarter and they created a distributed denial of service, or DDoS.Now a distributed denial of service attack,instead of using a single attack targeting one server they use hundreds or even thousands of machines to launch an attack simultaneously against a single server,and force it offline to create that denial of service condition.Usually these machines that conduct the attack don't even realize that they're a part of it though.Generally these machines have become zombies or bots inside a large bot net and then when they receive that command to attack,they all simultaneously send all their payloadsagainst a single victim.Now, in addition to most basic forms of DDoS attacks,there is one specific type of DDoS attack called a DNS amplification attack that could be performed.This specialized DDoS allows an attacker to generate a high volume of packets that's intended to flood a victim's website by initiating DNS requests from a spoof version of the target's IP address.This causes the DNS servers to respond to that request and send the response back to the server thinking that it's valid, because a DNS request uses very little bandwidth to send,but the response usually takes up a lot more bandwidth,this allows the attack to be amplified against the victim's server.Also if this is happening because thousands of simultaneous requests are being made by a bunch of zombies and a bot net on behalf of your victim's server,you can easily become overwhelmed with a lot of information and eat up lots of bandwidth pretty quickly causing that denial of service condition to occur.
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 71 today we're going to discuss about we're going to focus on the concept of a Denial of Service attack.Now, a Denial of Service attack isn't a specific attack in and of itself,but instead is this category or type of attack that's carried out in a number of different ways.Essentially, the term Denial of Service is used to describe any attack which attempts to make a computer or service resources unavailable,but it can also be extended to network devices,like switches and routers as well.There are five subcategories of Denial of Service attacks,Flooding Attacks, the Ping of Death, the Teardrop,the Permanent Denial of Service attack, and the Fork Bomb.The first category is called a Flood Attack.This is a specialized type of Denial of Service which attempts to send more packets to a single server or host than it can handle.So, in this example,we see an attacker sending 12 requests at a time to a server.Now, normally a server wouldn't be overloaded with just 12 requests,but if I could send 12 hundred or 12,000 that might allow me to flood that server and take it down.Now, under a Flood Attack we have a few different specialized varieties that you're going to come across The first is called a Ping Flood,this attack is going to happen when somebody attempts to flood your server by sending too many pings.Now a ping is technically an ICMP echo request packet,but they like to call it a ping Because a Ping Flood has become so commonplace though,many organizations are now simply blocking echo replies,and simply having the firewall dropping these requests whenever they're received.This results in the attacker simply getting a request timed out message,and the service remains online,and the Denial of Service is stopped.Next we have a Smurf Attack.This is like a Ping Flood,but instead of trying to flood a server by sending out pings directly to it,the attacker instead tries to amplify this attack by sending a ping to a subnet broadcast address instead,using the spoofed IP of the target server.This causes all of the devices on that subnet to reply back to the victimized server with those ICMP echo replies,and it's going to eat up a lot of bandwidth,and processing power.Now, you can see how this looks here,with the attacker sending the ping request with the IP of that server being spoofed into the request,and now the destination is sent to the broadcast of that subnet.In this example, all three PCs in the subnet are going to reply back to that ping request thinking it's from the server,and the server gets three times the amount of ping replies than if the attacker had sent it to them directly.Now, this allows that attack to be amplified,especially if the attacker can get a large subnet,like a /16 or a /8 used in this attack.The next kind of Flood Attack is what we call Fraggle.Fraggle is a throwback reference to the kids show Fraggle Rock from the 1980s,which aired around the same time as the Smurf TV show.So you can guess that Fraggle and Smurf are kind of related.Well with Fraggle, instead of using an ICP echo reply,Fraggle uses a UDP echo instead.This traffic is directed to the UDP port of seven,which is the echo port for UDP, and the UDP port of 19,which is the character generation port.This is an older attack,and most networks don't have this vulnerability anymore,and both of these ports are usually closed,'cause again, they're unnecessary.Notice that I didn't have them in your port memorization chart either.Now, because of this,Fraggle attacks are considered very uncommon today.That said, a UDP Flood Attack,which is a variant of Fraggle,is still heavily used these days.It works basically the same way as a Fraggle attack,but it uses different UDP ports.
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 70 today we're going to discuss about Unnecessary ports.As we've already discussed,there are a lot of ports available for use by your computers and your networks.We started out with 65,536 ports available back in our ports and protocol lesson.Then, we narrowed it down to 35 port that you just had to memorize in the last lesson.But does that mean that all 35 of those are necessary for your computer to function? Well, the answer is no.When it comes down to it,you aren't using all of those services,at least not all of the time.Also, if you're running a server,you wouldn't want to have all 35 of those ports open either.Why?Because many of them are unnecessary.Now, that begs the question, what makes a port unnecessary? Well, an unnecessary port is simply one that's associated with a service or a function that you don't need or is considered non-essential.For example, if you have a server whose entire function is to act as a mail relay server,all it's designed to do is send mail out,then the only thing it needs is a couple of ports open.It needs port 25 for SMTP and port 465 or 587 for SMTP over SSL and TLS.Now, every other port on that server can be shut or disabled or closed and you wouldn't care,because only those three ports are the ones you need.Remember, every open port represents an unnecessary vulnerability being left exposed if you didn't need to have that port open.So you want to close anything you're not using.Because of this, security professionals and analysts routinely scan their servers,their routers, and their firewalls to ensure that they understand exactly what ports are open in their networks and which ones they can disable or close.For example, this is a result from one of my scans and you can see there's three hosts that have ports 139 and 445 open in the network.Now, thinking back to our last lesson where you memorized all the ports,can you guess which services these machines might be running?Well, port 139 is used for net bios and port 445 is used for SMB.This means these three machines are most likely running the Windows operating system and they have file sharing enabled over the local network.Now, if these machines don't need to have file sharing enabled over the local network,we can disable these ports and remove the possible vulnerabilities that are inherent within the Windows file-sharing system.To close an unnecessary port,there are three methods you can use.First, you can stop the service that uses that port from the operating system's graphical user interface.To do that in Windows, simply open up the computer management console,select Services and Applications,and then select Services.From here, you double-click on the particular service that you want to turn off,and it's going to open up a dialog box as shown here.Now, in this example, I've stopped the Windows update service in Windows 10 from running,which will also prevent any associated open ports from remaining open because of this service running.The second method is to do this from the command line interface.As I showed you back in our operating system hardening lessons,you can turn off a service by using the net stop command and the name of the service.On a Linux server, you can do this by entering sudo stop and the name of the service at the command line.Now, the third way to do this is to block the ports at your firewall,whether this is a software or hardware-based firewall,or on the server itself.Now, usually, a firewall's going to block ports by default,and it requires you to open the port when you want to install a particular service or function.Now, for example, let's say you installed the Apache web server at one point,and this opened up port 80 on your firewall.
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 69 today we're going to discuss about In security one of the most important things is to ensure that you understand,what openings you have created in your systems.When it comes to computers and networks,most of these openings are going to be created by ports.Now a port is simply a logical communication endpoint that exists on your computer or your server.For example, if you're running a web server,you're going to have port 80 open and listening for inbound requests from your potential visitors.Now ports are classified as either inbound or outbound ports.An inbound port is used when your computer or server is listening for a connection.Just as in my earlier example,the web server had port 80 open, that's an inbound port.It's just waiting for somebody to come along and connect to it.An outbound port on the other hand, is opened by a computer whenever it wants to connect to a server.If my computer is attempting to make a connection to your web server over port 80,well, then my computer is going to open up a random high number port such as port 52363 and it's going to make an outbound request to that web server.Now, what does all this look like in the real world?Well, let's look at an example of how an inbound and outbound port are used when my laptop attempts to connect to a remote server over SSH.First, we have a server at the top of the screen and it has a public IP address assigned to it,and it's listening on port 22,so port 22 is the inbound port awaiting new connections.And in this case, port 22 is open.At the bottom of the screen,I have my laptop that wants to make the connection.Now, my laptop has a private IP address assigned because my network is using NAT at the router and that gives me some additional protections.So, notice at this point my laptop doesn't have any ports opened yet.So now my laptop wants to go and establish the SSH connection.It's going to open up an outbound port on itself,which is going to be some random high number port like 51233 and it's going to send a request to the SSH server over port 22 which is the server's inbound ports and destined for it's IP address in this case, 46.124.63.13.Now once a server receives this request,it has to respond to it.So, it's going to send a packet of information back to my laptop's IP in the outbound port that was open.In this case that's port 51233 and in reality it would be the public facing IP address of my router but for our example, I'm going to use the private IP address of 192.168.1.45.Now, that my laptop has made the request to the server and the server answered that request,we now have a session established and both devices can communicate back and forth as needed.Once that session is over,the connection is going to be closed,my laptop is going to close it's outbound port because it's no longer needed and the server will keep that inbound port open so they can receive requests from the next user who wants to use it.So now that we showed how ports work in the real world,let's talk a little bit more about the ports themselves.In addition to being called inbound and outbound ports,the ports are going to be assigned a number.Now, the number can be anywhere between 0 and 65,535 but this big range is actually divided into three smaller groups.The first group is called the Well-Known ports.This is for any ports that are between 0 and 1023.These are called Well-Known ports because they are designated by IANA the Internet Assigned Numbers Authority and they are going to assign it to commonly used protocols and ports.
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 68 today we're going to discuss about In this section of the course,we're going to discuss network attacks.There are many different types of threats out there and many of them carry out their attacks over your networks.These attacks include things like denial of service attacks,spoofing, hijacking, replays,transitive attacks, DNS attacks,and ARP poisoning.Now, before we get into all of those different types of attacks though,it's important for us to do a quick review of the basics of ports and protocols that you learned back in Network.After all, the exam is going to focus on particular ports and protocols and how it's best to secure them.So let's get started with our review of ports and protocols in the next lesson.
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 67 today we're going to discuss about We have spent a lot of time discussing the cloud in this section.But the cloud is made up of a lot of different types of servers.In this lesson we're going to discuss a few specific types of servers that may be hosted in the cloud,and how you can best secure them.First, we have file servers.File servers are used to store,transfer, migrate, synchronize and archive your files.Any computer can act as a file server in the real world.The server might be running Windows, Linux or Mac OSX as its operating system. And it really doesn't matter which.Either way, you want to make sure the file server is using proper data encryption for its files when they're at rest,that the server has monitoring and logging being performed on it,and a good host based intrusion detection system.You might also want to use data loss prevention applications to ensure the data isn't stolen and all of the normal configuration hardening and patching that we've already discussed in the past during this course.Second, we have email servers.These servers are a frequent target of attacks because they contain a lot of valuable data from within your organization.In a Windows environment,the most common email server is Microsoft Exchange.Microsoft Exchange and its Unix and Linux counterparts all support the POP3 IMAP and SMTP protocols for receiving and sending email.This means that at a minimum,we have at least three open ports and services running,but usually, there are many, many more.Because email servers are frequently a target of attacks,it's important that you insure that they are securely configured using the hardening techniques discussed earlier in this course.That you have spam filtering applications installed,and antivirus, not just for the server itself,but also to scan and quarantine all of the attachments being sent or received by your users.Next, we have a web server.In the Windows environment,this is usually hosted by Internet Information Services or IIS server.For Linux or Mac,this is usually going to be an Apache web server.Either way, web servers are by default open to the internet to perform their job.So, it's important for us to properly secure them.They should always be placed in your organizations DMZ.They should be properly firewalled,monitored, logged, audited and patched to insure their security.Always insure that your web server is up to date with the latest patches.If you aren't sure what patches need to be applied you can always visit the common vulnerability and exposure website or CVE that's hosted by the Mitre corporation.This site maintains an up to date list of every known vulnerability for every type of software that's on the market.Our fourth type of server is an FTP server.An FTP server is a specialized type of file server that's used to host files for distribution across the web.These servers can be setup to allow anonymous login and receipt of files or they can be secured with a username, password or other credentials.You might want an anonymous FTP setup,if you're distributing your software for example,or you may want a secure FTP server setup so that your remote offices can upload and download large files over the internet to your network.If you're setting up an FTP server,remember to always force an encrypted connection using the transport layer security or TLS.Because if you're going to require a username or password,you want to make sure it's protected during transmission.By default, FTP runs over ports 20 and 21,and it passes its information across the web in an unencrypted format.
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 66 today we're going to discuss about cloud security.Once we begin to rely on virtualization and cloud computing for our deployments,it becomes very important to recognize that our data might be hosted on the same physical server as another organization's data.By doing so, we introduce some vulnerabilities into the security of our systems.First, if the physical server crashes due to something one organization does,it can affect all of the organizations hosted on that same physical server.Similarly, if one organization has not maintained the security of their virtual environments being hosted on that server,there is a possibility that an attacker could utilize that to the detriment of all organizations based on that same server being hosted.Just as there are concerns when you conduct the interconnection of your networks with somebody else's,there are concerns with hosting multiple organizations' data on the same physical server that's being run by a given cloud provider.It's important for us to properly configure, manage,and audit user access to the virtual servers being hosted.Also, you should ensure that your cloud-based servers have the latest patches,anti-virus, anti-malware,and access control in place,if you're going to be using infrastructure as a service as your model.To minimize the risk of having a single physical server's resources being overwhelmed,it's a good idea to set up your virtual servers in the cloud with proper failover, redundancy,and elasticity.By monitoring the network's performance and the physical server's resources,you should be able to balance the load across several physical machines instead of relying on a single one.After all, elasticity is one of the main benefits of migrating to the cloud in the first place.Most of cloud security relies on the same security practices that you would perform for other servers,such as ensuring complex passwords are used,strong authentication mechanisms are in place,and strong encryption being used to protect your data at rest,in transit, or in process.Also, your cloud environment should have strong policies in place to ensure that it's clear what things a user may do and may not do with that cloud service.Finally, remember that the data that you're hosting in the cloud is on somebody else's physical server.If you're using a public cloud model,you need to be concerned about data remnants that could be left behind when a cloud server is deprovisioned after demand for the service is reduced.This could lead to a vulnerability where your data is available to other organizations using that same server.To prevent this, data should always be encrypted when placed in the cloud server,including the virtual hard disk files for those virtual servers that are being hosted.
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 65 today we're going to discuss about As a Service. Cloud computing also comes as four different types of services.I like to refer to these by the generalized term of as a service because as you're going to see,everything in the cloud is something as a service.The four types you need to be aware of are Software as a Service,Infrastructure as a Service,Platform as a Service,and Security as a Service.With Software as a Service,you're going to be provided with a complete solution.This includes the hardware,the operating system,the software, the applications,everything that's needed for that service to be delivered.For example, if you use Office 365 for Microsoft,this is considered Software as a Service,and it allows your end users to access their email,their Word documents, their PowerPoint presentations,and all of that directly from within their web browser.Sometimes though, you're going to have to build a customized piece of software to meet your particular service needs.In this case you might only need the service provider to give you the hardware, the operating system,and the backend server software.With Infrastructure as a Service,you get the benefit of this dynamic allocation of additional resources known as elasticity,but you don't have to deal with the headache of long-term commitments and contracts, buying the hardware,and installing the underlying operating systems.For example, you might want to contract for a new cloud-based web host to host your company's website upon.The server might be built and hosted by the cloud service provider,and come with a pre-installed Linux operating system and an Apache web server.Now, your programmers can simply create a custom application for your customers that's run on top of this web server without having to worry about the underlying operating system and hardware.The third type of service is called Platform as a Service.Under this model, the third party vendor will provide your organization with all the hardware and software needed for a specific service to operate.For example, if you're company is developing a new piece of software, they might have a development platform that's provided by a third party cloud provider.This might be an example of Platform as a Service.Now, if we want to summarize these three types,remember that Infrastructure as a Service,you're provided with everything you need to run a server,including the power, the space, the cooling,the network, the firewalls, the physical servers,and the virtualization layer.With Platform as a Service,the operating system and the infrastructure software is added to that list I just gave you.Now infrastructure software includes things like an Apache web server, a MySQL database,programming languages and lots more.With Software as a Service,the hosted application software is added to top of this infrastructure and platform portions.As you can see, Software as a Service is much closer to your end user than either Platform as a Service, or Infrastructure as a Service.Now, at the beginning of this lesson,I said that there was four types of as a service that you had to know for the exam.The fourth one is Security as a Service.
Hello everyone my name is vijay kumar Devireddy and I am glad to have you back on my episode 64 today we're going to discuss about Cloud computing isn't a single thing though,because there are many different ways to implement the cloud you should know that there are four different cloud types.Public, private, hybrid and community.The most common type of cloud architecture is the public cloud.Under this model, a service provider makes resources available to the end user over the internet.There are numerous public cloud solutions available today,including those from google,Microsoft and Amazon.For example, google drive is a public cloud service that's offered both as a free and pay for use model.Public clouds can often be an inexpensive way for an organization to gain the required capability and service they need quickly and efficiently.The second option is what's known as a private cloud.This service requires that a company create its own cloud environment that only it can utilize as an internal enterprise resource to manage its cloud.With a private cloud, your organizations responsible for the design, implementation and operation of the cloud resources, and the servers that host them.For example, the United States Government runs a private cloud for use by different organizations within the government.But my company and yours, can't get access to it like we could with google drive.Generally, a private cloud is chosen when security is more important to the organization than cost.A hybrid cloud solution combines the benefits of both the public cloud and the private cloud options. Under this architecture,some resources are developed and operated by the organization itself like a private cloud would be but the organization can also utilize the publicly available resources or outsource services to another service provider like a public cloud does! Because of this mixture of private and public cloud resources, strict rules should be applied for what type of data is hosted in each portion of this hybrid cloud.For example, any confidential information should always be hosted on the organization's private cloud portion.Our fourth option is known as a community cloud.Under this model, the resources and cost are shared among several different organizations who have a common service need, this is similar to taking several private clouds and connecting them together.Now, the security challenge here is that each organization may have their own security controls,remember if you connect your network to another network,you inherit their security risks as well.This doesn't change just because we've moved to the cloud environment.So, which of these four models or combination of models is right for your organization?Well, there's no clear cut answer,because it really depends on your security needs,your cost restrictions and your risk tolerance.Generally, it's cheapest to use a public cloud model,but this also increases the risk to your information's confidentiality and availability.Well, there's many other things you need to consider as a security practitioner, there is going to be no single right answer here, instead it's our job to weigh the benefits and the drawbacks of each other these models to decide which one is right for our organization's security needs and their concerns.
Hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 63 today we're going to discuss about Cloud Computing.These days,could computing seems to be the big trend within our industry.But what exactly is cloud computing? Well, cloud computing is defined as a way of offering on-demand services that extend the traditional capabilities of a computer or a network,out into the Internet.With the promise of increased availability,higher resiliency,and unlimited elasticity, the cloud definitely can provide our organizations a lot of advantages over our traditional network architectures. But, cloud computing can also bring a number of unique security challenges into our environments, too.For cloud computing to gain its intended cost savings and efficiencies, though,it relies heavily on the concept of virtualization.By using virtualization,numerous logical servers can be placed on a single physical server.This, in turn,can help us reduce the amount of physical space,power, and cooling,that's needed inside your data center.Additionally, by using virtualization,we can achieve higher levels of availability by spinning up additional virtual servers when necessary.This ability to dynamically provision memory and CPU resources, is one of the key benefits to cloud computing.While there are a lot of benefits to cloud computing,such as decreased cost,increased scalability,and unlimited elasticity,there are also numerous security issues that we have to consider.Most of the same security issues that we have with physical servers also get carried over into the cloud computing environment, too.Often times,I hear executives think that all of their problems will be solved by moving to the cloud.This is simply not the case.To gain these efficiencies,cloud providers rely on virtualization to allow multiple logical serversto be placed on that single physical server,as we said before.Many cloud service providers, though,have taken virtualization a step further with the concept of hyper-converged infrastructure.This allows providers to fully integrate the storage,network, and servers,without having to perform hardware changes.Instead,they rely on a software and virtualization technology to perform all of the needed integrations. All of this can be managed from a single interface or a device,without any worry about the underlying vendor solutions.Many cloud providers are also offering Virtual Desktop Infrastructure as one of their services.VDI allows a cloud provider to offer a full desktop operating system to an end user from a centralized server.There are a lot of security benefits to this approach.For example,one organization that I worked with creates a new virtual desktop image for each user,every time they log on in the morning.This desktop is non-persistent. So even if it's exploited by an attacker,it is destroyed as soon as the user logs off at the end of the day,or at midnight each night.This effectively destroys the attacker's ability to remain persistent on the end user's desktop,and adds a lot of security for us.Now, when we look at these numerous logical servers being stored on a single physical server,we also have to consider that there has to be a way to keep the data confidential and separated from the other logical servers, too.To do this,we use Secure Enclaves and Secure Volumes.Secure Enclaves utilize two distinct areas that the data may be stored and accessed from Each enclave can be accessed by the proper processor.This is a technique that's used by Microsoft Azure and many other cloud service providers.Secure volumes, on the other hand,are a method of keeping data at rest,secure from prying eyes.
Hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 62 today we're going to discuss about Unified threat management,the unified threat management or UTM system is a newer concept that was introduced in the last five to 10 years.Basically, security professionals realized as I'm sure you're realizing now too,that relying on a single firewall is not enough to protect our networks,and so a UTM was created, now a unified threat management system is a combination of network security devices and technologies that are added to a network to better protect it.Simply put a UTM is a single device that combines many other devices and technologies into it.For example your UTM might include a firewall,a network intrusion detection system,or a network intrusion prevention system,a content filter or a proxy, an antivirus or anti-malware gateway, a data loss prevention system,and maybe even a site to site VPN if you have the need.Now these devices are designed to make it easier for a security administrator to use them.And instead of relying on a command line interface,with all the tech space commands,they get a graphical user interface instead.It allows them to make policies, rules, and signatures,that makes it much easier and much quicker to use.Now UTM's provide a singular package with multiple protections.And they are essentially a defense in depth strategy within a single device or system.Because of this often these devices will replace your firewall, and it's usually placed as the outer most device in your local area network.To provide its' perimeter defense and its' protections.You may have also heard the term, Next Gen Firewall,or Next Generation Firewall, also known as NGFW.If you've heard this term, it's because it's being used in the industry instead of using the term UTM or unified threat management.These are those all in one security devices and that's all a Next Generation Firewall is.This is a marketing ploy because people weren't understanding the UTM concept,but they understood firewalls,and so calling it a Next Generation Firewall helped them increase sales.
Hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 61 today we're going to discuss about NIDS versus NIPS.Now, we've already spoken a little bit about intrusion detection and intrusion prevention systems earlier on in this course.In this lesson though, we're going to focus on the differences between a network based IDS and a network based IPS.A Network Intrusion Detection System,or a NIDS, is a type of IDS that attempts to detect malicious network activities.For example, port scans and denial of service attacks.Now, this is a device that's usually placed either before the firewall, so that it can be directly exposed to all of the traffic that's coming in,or right behind the firewall.Personally though, I like to have my NIDS placed behind the firewall, as this helps filter the amount of traffic that we'd have to see and review, since the firewall is already going to block a lot of it for us.Generally, your Network Intrusion Detection System will be placed into what's known as promiscuous mode.This allows it to see all of the traffic that crosses the network instead of just the traffic that's destined for it's own Mac address This is easily done through the configuration of the NIDS, and by placing your NIDS on a span port of your network switch so that it can receive all of the traffic moving through that switch, and not just the traffic on it's own switch port.A NIDS can only detect, monitor, and alert on traffic based on signature base rules or heuristics,and, it won't do anything to actually stop an attack from occurring.When you're dealing with a NIDS,all it's going to do is log it,and let you know about it.A Network Intrusion Prevention System, or NIPS on the other hand, is a type that's designed to inspect traffic and based on it's configuration or security policy,it can also remove, detain, or redirect that malicious traffic.That means a NIPS can not only detect it and log it like an IDS does,but it can also stop that ongoing attack by blocking the IP address that's causing issues or shutting down the connection.But, to be able to effectively take these actions,the NIPS has to be installed in line,in your network.Again, I like to place my NIPS in line,just behind the firewall.This way it's just inside the network perimeter and it allows me to have a good vantage point for it.Remember, when you're using a NIPS to block an ongoing attack,you want to ensure that the NIPS is properly tuned.If you didn't tune it properly with the right signatures, you could have a lot of false positives, and since these would be terminated, it could cause an inadvertent denial of service for your network if it tries to prevent what it thinks is malicious traffic from flowing into the network.Now, because a NIPS is an in line device,you also have to think about what's going to happen if that device fails.Should that device fail open, or should it fail shut?If you set the device to be configured to fail open, this means that the NIPS is going to simply let all of the traffic through it whenever it fails.This is less secure obviously,and so you have to think about if this is really what you want.Now, if you choose to fail shut on the other hand,the device is going to block all the traffic if it fails for some reason.This means that it's going to create a denial of service condition for your entire network,which is also pretty bad.For this reason, most organizations choose to fail open with their Network Intrusion Prevention Systems, and rely on other defensive layers to provide some layer of protection, until the NIPS can be brought online again and fixed.Now, in addition to providing their NIDS and NIPS functions, these devicesalso can be used as a protocol analyzer.
Hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 60 today we're going to discuss about Data loss prevention.Data loss prevention, or DLP systems,are designed to protect data by conducting content inspection of your data as it's being sent out of your organization's network.While data loss prevention is the most commonly used term,it's also referred to as ILP for Information Leak Prevention or EPS, Extrusion Prevention Systems.Usually these systems are installed as a network based DLP or a Cloud based DLP.For example, my company happens to use a Cloud based DLP through Google's G Suite.Anytime one of our employees tries to send information outside of our own domain through email,that email is flagged and they have to verify that they understand the data is being sent outside of security.com We have our DLP set to low because we communicate with so many people outside of our organization on a daily basis.But if we wanted to, we could force a higher security level and make each email being sent be checked and verified by a third employee before it was sent out to ensure that no confidential data was being left outside of our network.Now, there's also automated ways to do this,so you can flag particular emails based on key words or a no-no list and prevent any files or emails from being transferred with those keywords inside of them.It all depends on how you want to configure your DLP.DLPs are used to ensure your data stays within your network,that it isn't leaked out to outsiders,and that the privacy of your confidential data remains private.That's the whole goal here.We want to make sure that data isn't being sent outside of your network over and over again and have this massive data exfiltration going on.DLP systems can help you with that.
Hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 59 today we're going to discuss about Honeypots and honeynets.Honeypots and honeynets are used to attract and trap potential attackers to counteract any attempts at unauthorized access to your organization's network.Now, a honeypot is generally a single computer,but it could also be a file, a group of files, or an area of unused IP address space that might be considered attractive to a would-be attacker.A honeynet, on the other hand,is one or more computers, servers,or an area of the network.And often, this is used when a single honeypot is not deemed to be sufficient for your purposes.Now, why would we use honeynets and honeypots in our network?Well, this is usually used as a form of research,to try to learn about attackers.For example, the Honeynet Project at honeynet.org is a well-known honeynet that's in use today.It's used to learn the tools, tactics,and motives involved in computer and network attacks.And then they share what they learned with all of the different organizations out there.Your organization likely isn't going to put up a honeypot on it's own, unless you're part of a security operation center for a large company who's trying to develop better countermeasures.For example, security researchers at companies like Microsoft, Google, and Apple might run a honeypot or a honeynet to try to better be prepared in the defense of their systems,and better understand the bad guys' techniques and tactics.But for most of us,honeypots and honeynets are just something we have to memorize.
Hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 58 today we're going to discuss Proxy Servers.A proxy server is a device that acts as a middle man for your clients.For example, if you're at work and you wanted to connect to ,your work computer's likely going to go from itself, to a proxy server within your company's LAN.And then, that proxy server makes the connection to Dion Training to get the information that you requested.And then it will hand it back to you.This middle man approach allows the company to log everything that's being requested,who made them, and to filter out things they don't want you to access.There are four types of proxies in use today.IP Proxy, Caching Proxy, Content Filter,and Web Security Gateways.An IP Proxy is used to secure a network by keeping machines behind it anonymous.When your work computer decides to connect to through the proxy in my example above,my server doesn't know which particular computer is actually connected to it from your company's network.All I see is the proxy server itself.This is because your proxy is using NAT to translate your request from your machine into a request from the proxy.If you had 20 different computers on there tryin' to access my web server,it would still just look like one machine to my server, not 20.The next type is called a Caching Proxy.Caching Proxies are used to attempt to serve client requests without actually connecting to the remote server each time.Let's say that you went to my website at diontraining.com,and then your coworker,five minutes later, tried to go to diontraining.com,just like you did.Well, the proxy, if it's using a cache,is going to be able to keep a copy of my webpage from the first time it fulfilled your request.Then, when your coworker requested it,it would simply give it from its cache instead of going and getting a new copy from my site.This will allow your company to save on bandwidth costs,and increase the speed of delivery for your coworker, because it already has it locally,inside your network.The most common caching proxy is known as an HTTP Proxy,which attempts to cache the web pages that are visited by users, such as the example I just gave you.Caching proxies are not as effective as they used to be, though,because we all live in a Web 2.0 world with lots of customized content being served up to us.So, for example, if you went to Facebook.com and your coworker went to Facebook.com,both of your Facebook feeds look drastically different, don't they?This is because you each get different information based on your friends and your likes and your desires.So caching here isn't very helpful because of this Web 2.0 structure.Also, most caching proxies only keep a copy of the information they get for about 24 hours.And after 24 hours, they're going to go back out and request a new copy to ensure that they get the latest information.Now, to simplify the installation and configuration of a caching proxy in your web browser,there's a special type of file called a PAC, a Proxy Auto-Configuration file.This file contains the settings needed for a host to connect to the proxy server.Unfortunately though,these files are subject to modification, and could be used to redirect the user to an attacker's control proxy instead of your organization's.For this reason, it is better to disable the PAC files, and manually configure your proxy settings on your host machines, or you can push these out using a global policy object, or GPO update.Now, the third type of proxy is called an Internet Content Filter.These are used in large organizations as a way to prevent users from getting to stuff that they don't want you to access at work..
Hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 58 today we're going to discuss Firewalls. Firewalls are primarily used to section off and protect one network from another.Now when we talk about firewalls, there's three main types.There's software-based, hardware-based,and embedded firewalls.Software-based firewalls are run as a piece of software on a host or a server.In fact, if you're running a Windows server,those have a built-in Windows Firewall that you can enable.Hardware firewalls, on the other hand,are a standalone device that's actually an appliance that's installed into your network.It looks like another switch or another router that goes into your network stack.The third type of firewall is known as an embedded firewall.Embedded firewalls work as a single function out of many on a single device.So if you have a small office home office router or a unified threat management device,these are examples of an embedded firewall.It's one piece of the larger device that does many different functions.Firewalls can operate in many different ways.The first one is packet filtering.Packet filtering is going to inspect each packet as it passes through the firewall, and it'll accept it or reject it based on the rules that it's been given.This relies on the firewall's configuration and the access control list that's been installed.If I'm running a web server, for example,I would configure my firewall to allow traffic inbound on port 80 and port 443 but close all of the other ports because port 80 gives web traffic,and port 443 gives secure web traffic,and so, those are expected to be used.There are two types of packet filtering,stateless and stateful.With stateless packet filtering,it's simply going to accept or reject packets based on the IP address and the port number that was requested.So if I'm running a web server and you requested to come in on port 80,I would allow that,but if you requested to come in on port 53,I would deny it because it's not in my access control list.Now a stateful packet filter, on the other hand,is going to keep track of requests that leave through the firewall.So if I make a request from a host through the firewall,it will temporarily open up a port number that I made the request from,some random high port number like 50,000 or 56,000.By using stateful packet inspection,you can almost entirely eliminate IP spoofing as a threat because the firewall is going to inspect the header of each packet being received.It's then going to compare that against what it was expecting based on the request that recently went out,and then, it's going to make its accept or reject decisions based on this addition information.This is a much more in-depth inspection than a stateless one does.Now, NAT filtering is another type of filtering we can do.This is going to filter traffic according to the port,whether it's a TCP or UDP port.This filtering can be done by simply checking the endpoint connections, by matching the incoming traffic to the requesting IP,and by matching the incoming traffic to the requesting IP address and port.Now, the next one we have is an application-layer gateway,or ALG.This is going to apply security mechanisms to specific applications such as FDP or Telnet.Now, instead of blocking traffic based on the Telnet port of port 23, instead, it's going to inspect each packet and determine which application it was meant for,and if it finds out that it was meant for Telnet,it would block it because that was unauthorized.This is a resource-intensive process,but it is a powerful layer of security that can be added on into your network.These are also known as Layer 7 firewalls because they operate at the application layer..Now, once that connection is established,the packets can then be sent or received without any further inspection or checks because all of that was done during the session establishment.
Hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 57 today we're going to discuss perimeter security.Now, when we talk about perimeter security,we're focused on the outer layer of our defense-in-depth posture for our networks.This is the boundary where we segment our LAN form the WAN and from the internet at large.When we focus on the boundary, or perimeter defenses,we utilize many different devices.In this section, you're going to learn all about firewalls,proxy servers, honey pots and honey nets,data loss prevention systems,network intrusion detection systems and network intrusion prevention systems,and combination devices,like a unified threat management system, or UTM.A lot of this is going to be review from your Network Plus studies so we're going to cover this section fairly quickly,pointing out the things you need to know for the Security. So let's get started with our exploration of perimeter security devices.
Hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 56 today we are discussing about Telephony devices.Telephony is a term that's used for a device that provides voice communication to your end users.Originally, telephony was used in networks to make connections with the outside world such us through your modem.So a modem was this old device that we used to use that would allow us to modulate and demodulate digital information into an analog signal that could transmit over a standard dial-up connection. So if you used AOL as a dial-up connection way back in the day,you would put your phone line into your computer,it would take your ones and zeros,convert them into signals of sound and transmit that over the phone line.Now, modems were a great attack vector though from the security perspective.And for the Security you need to know the concept of war dialing.War dialing is simply when an attacker starts dialing random phone numbers to see if any modems would answer on the other side. So a lot of servers back in those days will have dial-up modems so that remote technicians could dial into the server,gain access and make changes to due support.Well, if I was an attacker and I started dialing random numbers like 555-1234,nobody there.555-1235 and just keep adding numbers,eventually, I'll find some server that answers.And if they do, I now have a way into that network. So how do we protect modems in our systems for any dialog resources that we may have from this type of thing like war dialing?Well, one of the main things to do is use a callback feature.If you still have modems, which most of us don't in our networks anymore, but if you do,you want to make them set so that when somebody calls in,they would then hang up and the modem, if it recognize that phone number based on caller ID will then call them back and initiate the connection.This will verify that the person is who they think they are and who they say they are.Now, you always want to also use some form of authentication,like a username or password.But preferably, you want to use something more complex like two factor or multi-factor authentication.The best practice though is to do what most of us have done,and that's eliminate modems where possible and switch to remote access to using things like an SSH connection over VPN tunnels.Now, while it's great to try to eliminate all your modems,sometimes, you still have old systems and you simply can't do that.If you have to maintain a dial-up modem for some reason,you want to make sure you keep that dial-up number a secret.And so somebody's going to have to work hard to be able to find it and be able to get into your system.Again, if you have a dial-up modem,you want to use good authentication.You want to be able to use things that will help prevent it like callbacks and other things to help secure it,because these are prime targets for attackers.Now, the next type of telephony equipment I want to talk about is a PBX system. A PBX equipment is something you're going to find much more often in your networks than you are going to find modems.A PBX system stands for a Public Branch Exchange.Essentially, this is the telephone system that runs all of the internal phone lines for your company.If you're sitting in your office and you want to call your accountant inside the office and you dial the last four digits of his phone number only to get him, that internal call is being routed through your PBX system,through that public branch exchange.
Hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 56 today we are discussing about Network Address Translation Network Address Translation or NAT is the process of changing an IP address while it transits across a router.Now, in network plus we discussed how this was used because we wanted to conserve public IP addresses because they were limited in IPv4.In security plus though we are going to gain an additional benefit when we use NAT,we can actually hide our internal networks from attackers.Now, the most commonly used type of NAT is what we call Port Address Translation or PAT.This is where we have a single public IP address assigned to a router and all of the private IP addresses that are assigned inside to our host.In your small office, home office network,this is most likely what you are using.Now, when a host wants to communicate out over the WAN,it's going to send the request to the router and the router is then going to forward the request out to the internet to the server that its trying to get to,on behalf of the host.And when it does this, it keeps track of the translation it does by using a unique random high port number for each request. This means if the attacker is getting your network from the outside,they are only going to see that single public IP address of the router and they are not going to see the fact that you have one, five ten or 100 hosts inside of your network, and they are not going to be able to exactly know how many devices there are or what kind they are.So, for the Security plus exam,in addition to knowing about NAT and PAT,you should remember that there is public and private IP scopes.Now, when you start talking about private IP ranges,you should have learnt those back in A plus and Network plus.If you didn't, I'm going to give you a quick review.Class A is anything that starts with a 10, so 10.0.0.0 all the way up through 10.255.255.255 Now in class B, we have IP address that start with 172.16.0.0 all the way up through 172.31.0.0 Essentially anything that starts with a 172.16 all the way up through 172.31 Class C is really easy to remember as well,and its probably what you are using at home its 192.168.0.0 all the way up to 192.168.255.255 So if its starts with a 192.168,it is also a private IP address.Remember, private IP addresses cannot be transmitted over the internet So instead, once they hit your external router,it's going to use either PAT or NAT to give it a public IP address and a port number to send the information out to the internet and then receive it back.
Hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 55 today we are discussing about Subnetting.Subnetting is the act of creating subnetworks logically through the manipulation of IP addresses.So if I take a large chunk of IPs,like a 256 block, I can break it down into four blocks of 64 IPs,or eight blocks of 32 IPs, however you want to break it down in your subnetting,which you learned back in Network Plus.Now, subnetting has some benefits to our network. First, it allows us to more efficiently use the IP address space that we've been given,and it's going to reduce the broadcast traffic and the number of collisions,because there's less hosts on any given network.But it also can increase our security by making our networks more compartmentalized and allows them to be in smaller sections.Any time information wants to go from one subnet to another,it has to be routed through. And that gives us an additional place to place access control lists and other things to our router to give us additional security.Now, you can use subnets to help secure your network by doing a couple of different things.First, you want to assign different policies to each subnet.For example, I might have a subnet that's associated with my printers,and those have different policies than the ones associated with my servers,and those have different policies than the ones associated with my office workers' desktop computers. Each of those can have different policies for each subnet. Also, you want to be able to monitor all of your subnets and check the traffic that's going into and out of them.By using subnets, we can help isolate an attack, as well,because all traffic has to be routed before it can enter or exit a subnet.And therefore, if somebody breaks into say,the secretary's computer, they're going to be trapped in that subnet, unless they have permission to go into some of the other more secured subnets that we have out there.Each time it goes through a router again,it's going to be checked by the access control list, and that secretary's laptop may not have access to the database server, for example,which has more confidential and secured information.So they're going to be limited in what they can do once they've broken in.
Hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 54 today we are discussing about Switches can also provide the ability to create virtual local area networks.This adds a layer of separation to our networks without requiring us to buy additional switches that have to be configured and installed on the network.VLANs are implemented to segment our network,reduce collisions, organize our networks,boost performance and increase security.Unfortunately attackers have created VLAN hopping which allows them to break out of our VLANs and access other VLAN data though.There's a couple of mechanisms to do this. The first method is known as switch spoofing. In this attack, an attacker essentially configures their device to pretend that it's a switch and they connect to a switch port to negotiate a trunk link and break out of the VLAN. To prevent this, you can disable dynamic trunking protocol or DTP on all your switch ports,place all your unplugged ports into an unused VLAN,explicitly forward frames and avoid default VLAN names.The second method is what's known as double tagging.As traffic goes across a switch,it reads the outermost VLAN tag first,strips it off and then routes the trafficto the proper VLAN.In double tagging though,an attacker actually adds two VLAN tags,an outer tag and an inner tag,so as traffic goes through the first switch,it removes the outer tag and is then forwarded to the destination of the inner tag.You can prevent this by moving all the ports out of the default VLAN group.Double tagging can also be prevented by upgrading your switch's firmware,utilizing an unused VLAN as the default VLAN and redesigning the VLAN structures.
Hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 53 today we are discussing about Network Access Control Network Access Control or NAC is used to protect your network from both known and unknown devices.With NAC, a device is scanned to determine its current state of security prior to it being allowed access to your network.Now, NAC can be used for computers that are within your internal network that are physically located in your buildings and connected to it or it can be applied to devices that are connected into your network remotely through a VPN.When a device attempts to connect to the network,it's placed into a virtual holding area while it's being scanned.Now, the device here can be checked for a number of different factors,including its antivirus definitions to make sure they're up to date,the status of its security patching,and other items that might introduce security threats into the network if you allowed it to connect.Now, if a device passes this examination,it's allowed to enter and receive access to all of the organizational resources that are provided by your network.If the device fails the inspection, though,it's instead placed into a digital quarantine area.And it awaits remediation. While it's in this area, the device can receive its antivirus updates,it can get its operating system patches,and any other security configurations and services it needs. But it can't logically communicate with other portions of the network.That's why it's been placed in quarantine.Like a bad child, the device has been placed in time out until it can be rehabilitated and meet the requirements of the initial NAC examination.Once it successfully meets those requirements,it's then moved into the network and receives full access, again,to your organizational resources.Now, NAC's solutions can be run either using Persistent or Non-Persistent Agents.Persistent Agents are a piece of software that's installed on a device that's requesting access to the network.This works well in a corporate environment because the organization owns all the devices and controls their software baselines,but it doesn't work really well if you're using an environment where people bring their own devices.Instead, you might want to use a Non-Persistent Agent for this.A Non-Persistent Agent solution was developed and is very popular in college campuses where people bring their own devices in.These solutions require the users to connect to the network, usually over wifi,and then they go to a web-based portal for log in,and they have to click a link.When they click that link, the link then downloads an Agent onto their computer, scans the device for compliance,and deletes itself from the user machine once it's done.Network Access Control can be offered as a hardware or a software solution.One of the most commonly used Network Access Control mechanisms is called the IEEE Standard 802.1x and it's used in port-based Network Access Control.Now, most NAC is actually built on top of this 802.1x standard.We're going to discuss the 802.1x standard in more detail in a future lesson, though.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 52 today we are discussing about Network Zones When considering the architecture of your internal network,it's important to consider breaking your network up into multiple security zones.These can be further broken up into sub-zones through the use of subnetting,ACLs, firewall rules,and other isolation methods that will help us prevent or shape the flow of data between thedifferent portions of our network.Most networks are segmented into at least three different zones:the LAN, the WAN, and the DMZ.LANs can be secured using private IPs,using anti-malware programs,and by placing your clients behind a router and its associated ACLs.WAN connections, on the other hand,should be monitored and firewalled to secure your networks against the threats of those contained.The Internet is the world's largest WAN.And traffic crossing across the Internet should be tunneled through a virtual private network when you want to keep it safe from prying eyes.This will increase your confidentiality.In fact, the TLS tunnels that are used inHTTPS connections are a type of VPN.So any time you're going to a website and you see that secure lock,there's actually a VPN being used between your web browser and the web server you're visiting.In addition to our LAN and our WAN,the most most common security zone that we use is what's known a DMZ, or a De-Militarized Zone.This zone is focused on providing controlled access to publicly-available servers that are hosted within your organizational network.For example, if you're self-hosting your web serverand email servers inside your organization,it's a best practice to place them within your DMZ,and this is a tightly controlled zone with proper access control rules.This allows you to maintain precise control of the traffic that's going to be allowed between the inside, your LAN; the outside, the WAN,and the DMZ portions of the network.To create a DMZ, multiple interfaces are used on your organization's firewall. You'll have a strict set of access control list rules that are going to be applied to those interfaces,and a public IP address is required for each server hosted within your DMZ.The purpose of creating security zones like a DMZ is to create this separation of critical assets.Not all devices in your network require the same level of protection.Some resources, such as file servers,are going to contain confidential information,like employee data, and this is going to require additional security being placed there.Instead of protecting every device to the same high level,we can create sub-zones inside of our networks based on the level of protection required.In addition to these internal sub-zones,there may be also be additional external zones that you need to create, such as an Extranet.Now, an Extranet is a specialized type of DMZ that's created for your partner organizations to access over a wide area network.It acts much like a DMZ, but it's not publicly accessible.This Extranet is also placed under additional network monitoring and scrutiny.For example, I access an Extranet every time I need to go to Excelous to order exam vouchers for my students in my ITIL and Prince2 courses.It's a part of their network that only their externalpartners, training partners like us,can have access to, and not the general public.Conversely, on the other side,we have what's known as an Intranet.An Intranet is something that allows you to expand your internal network within your organization across multiple areas.This is usually done using VPN tunnels.So for example here, I have a couple of employees who work on the other side of the world.If they need to get access to our file servers, they can do that by logging in to our Intranet and get access to it through that secure connection.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 51 today we are discussing about Routers, now while switches operate at layer two of the OSI model by making their decisions based on MAC addresses,routers operate at layer three, making their decisions based on IP addresses.Routers are used to connect two or more network to form an internetwork. Such as when you connect your small office home office router, your internal network,out to the internet.It connects your office's network out to other office's network over the internet.Now, routers are devices that make routing decisions and they do this by using IP addresses. These layer three IP addresses are used to determine what network a particular host is on and what path the traffic should take to go across the wide area network until it reaches its destination network.Once the traffic reaches the destination network or the final router that's involved, that particular router will conduct ARP broadcast to locate the correct host on its local network and pass the traffic to it using its MAC address at the layer two which is known as that physical address.In addition to this important routing function,routers also provide us with some security functions too, access control lists or ACLs can be configured on the router's interface to control the flow of traffic into or out of a certain part of the network.ACLs are an ordered set of rules that will either permit or deny traffic based upon certain characteristics,like it's source or destination IP address,the source or destination port number associated with it and the application or service being run.Now in an effort to get past these access control lists,attackers will often conduct IP spoofing. If they can spoof the IP, they can trick the access control list to think they're on the approved list and let them in or let them out.Since routers are on the external interface for a network, they're commonly a target for attack as well. And so out of the box, routers tend to be very insecure and you need to configure them properly for security.This includes changing this like your default username and password, changing the default routing tables,and changing those default IP internal addresses.To help protect our routers and our internal networks,we use a lot of other network devices and technologies,such as firewalls, intrusion prevention systems,virtual private network connections, content filters,and access control lists.By layering all these defenses, we create a better defense in depth posture.Now, we're going to cover all of these protective devices and technologies throughout this course but for now, it's sufficient to realize that using these things helps add up our security.And that helps us to secure our routers from various attack methods.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 50 today we are discussing about Switches.Now hubs were originally used to connect devices on a network.All of the devices will be connected to a hub,and anytime something went into one port of the hub,it would then repeat that out all of the other ports.This was known as a broadcast message.Now this is because hubs were dumb.They had no intelligence.As networks got larger,hubs caused a lot of collisions and slowed down the network.To solve this problem,something came along called a bridge,and this was used to separate physical LANs or WANs into two logical networks,or connect two logical networks together.Now switches are the evolution of hubs and bridges.Essentially every single port on a switch acts as if it was a bridged hub on each one.This means that it improves the data transfer and security through the intelligent use of MAC addresses.Being able to figure out where a device is and only sending the information out that particular port of the switch and ignoring the rest.This reduces traffic and increases security.Now switches are subject to three main types of attack though.They are subject to MAC flooding, MAC spoofing,and physical tampering.This is because they're trying to overcome that logic and intelligence that the switch has.MAC flooding is an attempt to overwhelm the limited switch memory that's set aside to store the MAC addresses for each port,and this is known as the content addressable memory,or CAM table.Now if a switch is flooded, it can fail-open and begin to start acting like a hub and broadcasting data out every single port.This is a problem that can start causing confidentiality to be breached inside your local network.Now MAC spoofing, on the other hand,occurs when an attacker masks their own MAC address to pretend that they are having the MAC address of some other machine on the network.For example, wireless access points may use MAC filtering to prevent devices that are unknown from joining the wireless network.They do this my looking at their MAC address that's being reported,and if it's not inside their access control list,they'll block it from connecting.Now if I switch my MAC address to a known or allowed device,I can gain access to that network though by spoofing.I pretend that I am an authorized device using a known good MAC address,and I pass right through that ACL.MAC spoofing is also sometimes combined with ARP spoofing.ARP is an address resolution protocol,and it relies on the MAC addresses as a way of combining what MAC address goes to which IP,and which IP goes to which MAC address.So they often combine a MAC address spoof with an ARP spoof as an attempt to be able to have the attacker appear that they are the destination that somebody is trying to send information to,and use that as a way to steal that information.Now to prevent this,you have to configure your switch to accept limited numbers of static MAC addresses,limit the duration of time that an ARP entry is allowed on a host,and conduct ARP inspections.To keep track of what ARP is being used with which MAC address and which IPs.The third type of way to overwhelm a switch is to use physical tampering.Physical tampering occurs when an attacker attempts to gain physical access to the switch,because if you can touch a device,you can pretty much configure it to do whatever you want.Now to prevent physical tampering,the switch should be locked up in a network rack, or a network closet,or behind closed doors so that, that room is secure using good physical security practices.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 49 today we are discussing about The OSI Model.The Open Systems Interconnection,or OSI Model is used to explain how network communications occur between a host and a remote device over a local area network or a LAN.Now the OSI Model is very useful to help use categorize different communication protocols that are used in networks,and gives us a common lexicon that we can use to use to describe the functions of different devices.you probably remember the pneumonic of Please Do Not Throw Sausage Pizza Away.This represents the seven layers of the OSI Model,going from the bottom to the top.This is: Physical, Data Link, Network, Transport,Session, Presentation, and Application.The first layer is the physical Layer.This is the layer that represents the actual network cables and radio waves that are used to carry data over a network.Data carried over the network at the Physical Layer is known as bits.And they can be electrical signal or radio wave.Examples of some of the things that operate at the Layer One or Physical Layer,are the things like our network cables whether they're fiber optic,or copper, or coaxial.It could be radio waves like Wi-Fi and Bluetooth.It can be a hub or repeater,which are dumb devices that simply take inputs in and then repeat them out the other side.Our second layer is the Data Link Layer.This is the layer that describes how a connection is established, maintained and transferred over that physical layer.Addressing here is done using physical addresses.Like MAC addresses.Now, at this layer the bits are going to be grouped into frames and then sent over the network.Examples of some things that operate at Layer Two or the Data Link Layer, includes things like MAC addresses,switches and bridges.Now, bridges are an earlier device that have later on evolved into switches.Switches use MAC addresses as their form of physical addressing.This allows a switch to decide where to send that frame of information based on the MAC address it's designed to go to.And so, it's smarter than a hub because it will decide where that particular frame goes as opposed to just repeating it out every single port that it has.Now, as we move up the ladder we get to the third layer which is the Network Layer.This is the layer where logical addressing is actually performed.And this includes things like routing and switching information between hosts, the network and the internetworks.At this layer, the frames are now taken and grouped up into packets, so bits became frames, frames become packets.Now, examples of this include things like the addresses which are IP addresses.This allows us to tell where a piece of information,where a packet is going to be sent over our network.We also use things like Layer Three switches,which in addition to using MAC addresses to decide where things go,they can use the IP addresses at Layer Three.And of course routers which are by far the most common Layer Three device,because they're used to connect all of our networks together around the world.Our fourth layer is the Transport Layer.This layer manages and ensures transmission of the packets occur from the host to the destination it wants.This uses either a TCP, known as a Connection Full Protocol or UDP which is a Connection Less Protocol.You might remember from Network+,TCP has that three way handshake,and it says, hey I'm ready to send you something,okay I'm ready to be sent something.All right, let's start sending it.And then they send the information.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 48 today we are discussing about In this episode, we're going to talk about some of the different devices that make up our networks and some of the different attacks that are used against them.But before we do that, we're going to cover quickly the basics of the networks by going through the OSI model.Now in this section of the course,we're going to do this as a quick review because you should have already learned the OSI model and the basics of networking or not, the information contained in that curriculum is really important to understand so you can better understand the security that we're talking about throughout this week.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 47 today we are discussing about SQL Injection.What is SQL?SQL, or Sequel, stands for the structured query language.And it's the way that a web application communicates to a database server to ask for information.Because this is the language used to communicate with the databases and the databases hold lotsof valuable information,this has become a popular target for attacks.This brings us to the concept of an SQL Injection,which is an attack consisting of the insertion or injection of an SQL query via input data form that the client sends to the web application.SQL injections are just a specific typeof code injection though.A generalized injection attack is the insertion of additional information or code through data input from a client to an application.This code injection can occur using any type of code though.But the most common are SQL, HTML,XML, and LDAP injections.By far though, SQL injections are by far the most common.And so we're going to talk about that in this lesson as we go through.Just as SQL injections are used to insert SQL statements into a web application, these other types of code injection can also be used as an attack method, too.And so keep that in mind.Now before we start to discuss how an SQL injection works,it's important to know how a normal SQL query or request is performed.Let's pretend that you wanted to log into this website.First, you have to enter your username.So, I'm going to enter jason as mine and then you have to enter your password.So I'm going to enter my oh so super secure password of pass123 for this example.With both of those entered in, I go and click on the Login button,and the website will send my username and password to the database to verify if the username matches the password stored in the database.This is done by sending a SQL or structured query that says select any records from the user table in the database where the user_id = 'jason',and the password = 'pass123'.So, if the query finds a record in the table that has both the username of jason and the password of pass123,it's going to return the value of true to the web application.And the web application can perform whatever the next action it's supposed to do in.In this case, it logs me into the website and displays whatever the authenticated user homepage is.Now, if the username and password combination weren't foundin that database table called users,then it's going to return false,and the web application would give me some kindof a message saying please enter your password again.This is how it's supposed to work.But how does it work with an SQL injection?Let's try logging into this website again.But this time, I'm going to perform an SQL injection.So, we go back to the Login page,and I'm going to enter the username of jason once more.Then instead of entering my password,I'm going to enter the Escape character,which is a backward single quote mark,and the statement, OR 1=1;.Now, this isn't my password, obviously.But instead, this is some code that I'm trying to inject into the SQL statement that the web application is going to send to the database when I click Login.So, let's click the Login button,and you can now see the full SQL statement that the web application has generated and sent to the database.Select any records from the user table in the database where the user\_id = 'jason'.So far this is the same as our earlier legitimate login attempt. And where the password = ' OR 1=1 ;'.What is happening here?Well, this is showing us that the statement is now being sent to the database,but when it reaches that Escape character,that backward single quote,it's going to treat every thing after it as a command to process.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 46 today we are discussing about The next two exploits we're going to discuss are types of web application vulnerabilities.These are known as cross-site scripting and cross site request forgery. Cross-site scripting occurs when an attacker embeds malicious scripting commands into a trusted website.When this occurs the attacker's trying to gain elevated privileges, steal information from the victims cookies or gain other information stored by the victims web browser.During a cross-site scripting attack,the victim is the user, not the web server.The web server's already been compromised possibly.A cross-site scripting attack exploits the trust that exists between a user's web browser,and the web server that they're visiting.This often happens because the attacker's able to insert some malicious code into a web page that's being delivered from the server to the victim or client.There are three types ofcross-site scripting attacks:stored and persistent, reflected, and DOM-based attacks.A stored and persistent cross-site scripting attack attempts to get data provide by the attackerto be saved on to the web server by the victim.Now in a reflected cross-site scripting attack, the attempt here is to have a non-persistent effect which is activated by the victim clicking on a link on that site.In a DOM-based attack, this is going to attempt to exploit the victim's web browser itself and it's often called a clientside cross-site scripting attack.This comes from the fact that the user's document object model or DOM is vulnerable to the attack.The DOM is part of the user's web browser.To prevent cross-site scripting attacks,programmers should use output encoding of their web applications, to prevent codes from being injected into them during delivery and they should also use proper input validation to prevent the ability for HTML tags to be inserted by users when they're entering information on a web form. As a user, you can help protect yourself from cross-site scripting attacks by increasing the security settings from your cookie storage and disabling scripting language when you're browsing the web.Just like we talked about back in the webbrowser configuration lesson of application security. Whereas cross-site scripting focuses on exploiting the trust between a user's web browser and a website. Cross-site request forgery instead exploits the trust that a website has in a user.In a cross-site request forgery,the attacker forces the user to execute actions on a web server that they already have been authenticated to.For example, let's say that you've already logged into your banks website and provided your username and your password.At this point you're already authenticated and the website trusts you.If an attacker can send a command to the web server through your authenticating session,they are forging the request to make it look like it came from you.The attacker in this case will be unable to see the web server's response to his request or commands but he could still use this to transport funds from the victim, change their password or do a myriad of other requests on the victims behalf. To prevent cross-site request forgery from being successful, programers should require specialized tokens on web pages that contain forms.Such as captions, utilize special authentication and encryption techniques, scan any XML file submitted by a user, and requiring cookies to be submitted twice for verification to ensure they both match and have the proper integrity.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 45 today we are discussing about The next type of exploit that were going to cover is called a buffer overflow.A buffer overflow occurs when a process in a program stores data outside the memory range allocated by the developer.Now, this begs the question, what exactly is a buffer?Well, a buffer is simply a temporary storage area that a program uses to store its data. Let's pretend that you have a glass sitting on a table.It can hold a certain amount of water, right?If it's designed to hold 16 ounces of liquid,but you pour 20 ounces in, well, the cup is going to overflow with water and the table is going to get wet.In this example, the glass is our buffer,and when we overflow it with our data, in our case water,the extra is going to spill out onto the table and make a huge mess.Buffer overflows in the IT world can also create a big mess for us.In fact, 85% of the data breaches were caused by a buffer overflow attack being used as the initial attack vector.So, let's take closer look at how a buffer overflow attack really works.Let's pretend you wanted to store my phone number into your contacts list.Here in the United States, our phone numbers consistof 10 digits.The first three digits are for our area code,which represents the city we live in.And the last seven digits represent the person's unique phone number.Before we had cell phones,you would simply pick up the phone and dial seven digits of your phone number because the telephone company assumed you wanted to place a local call within your own city or area code.So, let's pretend that the person who designed the contact list application on your phone decided they wanted to save some memory space and they wanted to use the smallest buffer possible,so they decided to use an eight-digit buffer because they are going to assume that you don't need to store an area code because you're going to make local calls.So, let's store my made-up phone number, 555-1234,into an eight-digit buffer called A.When I do this, you'll see that it takes up the first seven boxes labeled zero through six,because computers always start counting with zero,like you learned back in binary classes at happens, though, if we try to enter a number that's too long?Well, Buffer A isn't the only memory buffer that your contact list application can use.Right after Buffer A is Buffer B and then Buffer C and so on.So, let's consider how we store a longer phone number.For example, let's say you're out on vacation and you meet somebody but they don't live in your city.Well in this case, you need to store the area code and the phone number, like 410-555-1234.Since this now includes the area code for Annapolis, Maryland, we now have ten digits we need to store, but each buffer is only eight digits long because our programmer didn't quite think though all of the different types of phone numbers that one might need to store in their list.So, our contact list application tries to storethis ten-digit number in an eight-digit buffer.But the last two digits overflow Buffer A and go into Buffer B.This is exactly what happens with a buffer overflow.Now, why is this a bad thing? Well, to explain that, we have to get a little bit technical, so bear with me. Each program reserves a chunk of system memory when it's run.This allows it to have a place to store data that it needs during processing.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 44 today we are discussing about Software vulnerabilities and exploits. Now that we've covered how software should be securely coded,let's cover a few of the exploits that are used against improperly coded programs.First, we have backdoors. Backdoors consist of software code that's been placed in a computer programs to bypass on normal authentication and other securing mechanisms. These are often created by developers themselves in order to make it easier for them to update custom programs in the future. But, this is a horrible practice in terms of security.All secure coding and program methodologies consider backdoors a poor coding practice and they state that it should never be utilized by programmers.Because of this, most developers have phased out the use of backdoors. But some backdoors can be created in our systems by attackers, too.For example, if a system is infected with a remote access Trojan,this is also considered a backdoor into that system.The next type of exploit that we hav is what's called a directory traversal,which is going to exploit insecurely coded web applications and servers.A directory traversal is a method of accessing unauthorized directories by moving through the directory structure on a remote server.Let's pretend, for example, that my website Diontraining.com was poorly coded and was subject to this type of an exploit. Of course, we've gone ahead and secured our website against this type of vulnerability, so this is just going to be a theoretical discussion to explain the context of a directory traversal. Normally, you could access our website by going to www.kicktraveller.weebly.com Or, you might access it by going to a dynamic sub-page like diontraining.com/menus,or something like that.If you wanted to attempt a directory traversal,you're going to have to add something to the directory path that has an input variable inside the URL.Something like menu=../../../../etc/password.This attempts to move up four levels through the directory structure from the web server's public folder into it's root folder and then back down into the etc folder and then attempts to access the password file.If this was successful, the text based password file would be displayed inside your web browser.anytime you see that there's a series of ../ in them,you know that this is most likely a directory traversal and it's being used as part of an exploit.Often, a directory traversal is used as a way to access a file on a web server and sometimes you can even use it to conduct an arbitrary code execution on that server.Arbitrary code execution occurs when an attackeris able to execute or run commands on a victim computer. This might occur if someonewalks by your desk at work,sees you're logged into the computer,but you're away from your desk.They start running a program on your computer.This would be classified as an arbitrary code execution.This is pretty bad for security, as you can imagine.But, what's even worst, is a specialized type of arbitrary code execution called an RCE or remote code execution.A remote code execution occurs when the attacker is able to execute or run commands on a remote computer.Notice the key difference here between an arbitrary and a remote code execution.With a remote code execution,the attacker can run the commands remotely;such as through an interactive shell session or some other kind of attack.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 43 today we are discussing about In this lesson we're going to focus on the different testing methods that you may use to help your organization's developers secure their code.Most security analysts are not programmers themself,so the Security+ exam isn't focused on the specific types of code reviews like pair programming, over the shoulder reviews,and others.Instead the episode focuses on just a handful of testing methods that an entry level security analyst might conduct.The first type of testing is known as system testing.This comes in three varieties:black-box testing, white-box testing, and gray-box testing.Black-box testing occurs when a tester is not given any information about the system or program before beginning their test.For example, if I create a program and I wanted you to conduct this type of a test,I might simply hand you a copy of the executable program on a disk and then it's up to you to figure out how it functions, how to bypass any security I may have coded into it,and if you can crash it by entering in incorrect information.Essentially you're going to be getting your testing without any sense of what the program does or how it functions.As a tester, you're essentially blind to start with and you discover your way around the program or system through your testing.White-box testing on the other hand is the exact opposite.In white-box testing, the tester is given the details of the inner workings of the program or system.This may even include access to the full source code of that program, diagrams of the system,user access credentials, logons, and more.The third type of testing is called gray-box testing.This is a mixture of black-box and white-box where the tester is given some amount of information about the system and conducts his testing as if he doesn't have full access to it.For example, a gray-box tester might be given user level credentials to test a system,but not given administrative credentials.If you're testing a network system,you may be given some information like the IP address of different devices,but you're not given the version of the software that's running on each device.As a part of these system tests,you're often attempting to break the system by attempting to stress that system or create an exception.It's important that programmers have coded their applications to fail securely,and to ensure this happens you're going to purposely create error conditions to cause an error to occur and see how the system is going to react to it.If the program is running when the error occurs, the error is known as a runtime error.If the program fails to run because of a coding error,this is known as a syntax error.This is because the most common cause of this type of error in programming is when a programmer doesn't put the proper syntax expected by that programming language,such as leaving out a closing parenthese or missing a semicolon inside their code.As a security analyst, you're much more likely to experience a runtime error than a syntax error you're testing these things on a live environment.Now,when you create an error, this is also known as an exception,you need to be able to have a way to handle this properly and gather the details of the error and what caused it.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 43 today we are discussing about As we move through the seven phases of the software development lifecycle,it's important for not to forget the fundamentals of good security.Our developers should always remember the three tenets of the CIA triad:confidentiality, integrity, and availability.Remember, confidentiality ensures that only authorized users can access the data being processed by an application.The most common of ensuring confidentiality is to include the use of encryption to maintain the secrecy of the data being stored.Integrity is focused on ensuring the data is not modified or altered without permission. The two main ways that we do this as developers is by utilizing hash algorithms as a method of integrity check for the data or by using journaling and logging functions to create audit trail showing the integrity of the data has not been comprised.When developers are attempting to ensure availability,they're focused on ensuring that the data is available to authorized users when it's needed.The most common way of doing this is by creating redundancy in the overall system design,by ensuring their software code is error-free,or by ensuring that their software can conduct error handling appropriately to prevent crashes.During the testing phase, it's important to conduct an in-depth code review to ensure that there are no vulnerabilities that might affect the confidentiality, integrity,or availability of the software or the integrated system.These code reviews are generally performed by programmers, not by security analysts though.On the other hand, security analysts do help during the software development lifecycle by conducting threat modeling.Threat modeling helps to prioritize vulnerability identification and patching throughout the SDLC.By helping to prioritize the threats,the security analysts can help with the identification of applications or systems that should receive additional protections,which threats are more likely to affect them,and which ones have known vulnerabilities that exist.Based on this, additional effort and funding can be applied in the most efficient way to fix the issues before an attack happens or an attacker can exploit them.After all, there are a lot of threats out there and a lot of ways to attack a system if you want to breach an area of the CIA triad.To best protect applications, we should ensure that good security is programmed in from the beginning back during the requirements,analysis, and implementation phases.Numerous studies have proven that it's much cheaper to utilize secure coding practices and to conduct more thorough testing before releasing a product than to try to fix insecure code after releasing the product,as well as trying to clean up from the mess of an attack.What secure coding practices should our programmers use during development?First, we should ensure that we design our applications with the concept of least privilege.Least privilege means that user or processes should be run using the least amount of access necessary to perform the given function.Does your application require administrative permissions to run?If so, why?Developers should always try to use the lowest permission level when they're performing a function.So whenever it's possible, the program should be run as a user level person instead of an administrator or root level one.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 42 today we are discussing about In this section of the course,we're going to talk about software development.When a piece of software is created, it requires a lot of work.Each and every function that's performed by that software has to be written to be able to do its intended role.This often requires the work of dozens of programmers and hundreds of thousands of lines of code.Often, when a bug is found in a piece of software,I hear people ask why that company didn't figure it out before the software was released.Well, there's lots of different ways to conduct software testing,and we're going to talk about them later on in the section.But bugs are still going to find their way into code because our software is so complex these days.Let's take, for example, the Windows 10 operating system.It consists of over 50 million lines of code and took the involvement of hundreds of different programmers.With that much complexity, there's always a chance that an error is going to be introduced into the code base.Now, to try and counteract the complexity of our software development,many models and methods have been introduced,the most common of which is known as the software development life cycle or SLDC.The software development life cycle is an organized process of developing a secure software application throughout its life cycle throughout the project.This process covers everything from the initial idea of the software,through its coding and testing,and even into its deployment and retirement.The software development life cycle is based on a generic Waterfall model of development.Each phase of a life cycle is broken down into smaller portions.As each one is finished, the next one has begun.The reason this model is termed the Waterfall is that information and the software product itself flows from the top stage all the way down to the bottom stage,getting more developed as it progresses downward.Visually, this looks like a waterfall,as shown in this example on the screen.Different organizations use different phases or stages as part of their software development life cycle though,you need to know the seven phases.Now, let's cover each of theses seven phases.The first phase is planning and analysis.During this stage, the goals of the software project are determined, the stakeholder needs are assessed,and all of the high level planning work is conducted.Essentially, this is where things go from a rough idea that someone had for a piece of software into a bit more formalized and well developed concept that we can plan the rest of our development cycle against.Once all the requirements have been gathered,we can move into the phase that's known as software or systems design.It's during this stage that the application or system is defined, outlined, and diagrammed in detail.Essentially, this is where we focus on the overarching inputs and outputs of each function that are going to make up the final software that's going to be released to our customer.At this point, we still haven't created any programming code though.This brings us to the third phase,which is called implementation.During implementation, programmers will begin to code all of the various functions that are needed for the final product.As each piece of the code is developed,the programmers will conduct some basic debugging and testing to ensure that its functionality is working properly.But, at this point,there's been no formal testing completed yet.The fourth phase is reserved for that formalized testing of the application.It's during this phase that we get the code and we check it through a myriad of different testing methodologies.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 41 today we are discussing about Securing applications.By far the most commonly used productivity suitein the world is Microsoft Office.This includes Word for word processing,Excel for Spreadsheets, PowerPoint for slide presentation,Outlook for email, and many others.Now, how can we protect the applications themselves,and the files that they create?Well, that's what we're going to cover in this lesson.First, let's talk about the obvious.If you have a document and you want to protect its content,you should use a password to do it.It's a really simple built in feature across the Office suite.To create a password to protect your files from modification, or even being viewed,you can do this using the password protect feature under the tools menu bar option.As shown here on the screen, this is an example from Microsoft Word, but it works in Word,Excel and PowerPoint.Also, your files can be set to read only if you desire.This will prevent any of your contents from being modified by unauthorized users. Another thing you want to think about when it comes to security is macros.And we talked about that a bit back when we talked about macro viruses.You want to make sure you check your macro settings. You can find this under your preferences or your tools options, and then going to the security tab.By default, you should want to disable macros,with or without notification. This will increase the security of your organization. Now, when it's installed originally by Microsoft, macros are enabled, so you want to take the time to disable this in your baseline image.Most organizations are going to decide to disable macros completely and not even give their user an option to be able to enable them.To do this, you can set that through your group policy inside the Windows server and push that out to all of your clients. Another way to secure your information is to use digital certificates.If your organization is already using digital certificates as part of its organizational security, you should enable your documents to be locked down and only be opened by the person presenting a valid digital certificate. This again is another option that you can find inside of Word.Additionally, you want to think about how you're going to encrypt your documents to protect their contents.This can be done within the Microsoft Office products themselves, or you can use the underlying system capabilities,something like Bitlocker to Go.So at this point, we have some pretty secure files.We've disabled our macros, we've password protected them and we've encrypted them. Let's go and shift our focus over to email for a moment. Inside the Microsoft Office suite,there's a program called MS Outlook. Microsoft Outlook is used for email and if you embed your digital signatures and digital certificate configurations into Microsoft Outlook, you can haveincreased email security.This relies on a PKI or public key infrastructure.We'll talk about that when we get into the cryptography section of this course later on.Now, another thing when we start talking about Microsoft Outlook is that our emails start getting to be overwhelming sometimes,and we have to start saving space by archiving them off.In Microsoft Outlook, the way we do this is by archiving them to a PST file.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 40 today we are discussing about In the last lesson, we covered a lot of the basics of web browser security.In this lesson, we're going to go a bit more in depth and talk about some additional concerns that you need to think about within your organization when we start talking about web browser security.And the first one is cookies.Cookies are text files that are placed on a client's computer to store information about the user's browsing habits,their credentials, and other data.Cookies are used for authentication into websites,session tracking, your shopping carts,and many other purposes.Most organizations these days, though,will block the storage of cookies because they're concerned about privacy and security.You should know there are two different types of cookies,though, that are asked about on the exam.There are tracking cookies and session cookies.Now, a tracking cookie is usually used by spyware to gather details on you.They're trying to learn what websites you go to,for how long, and what type of things you click on.Now, session cookies, on the other hand,are used to keep track of users and their preferences and maybe even the things that they're putting into their shopping carts.This is being used not as much to track you but instead to maintain the connection and the session between you and the server versus me and the server. Now, many sites are realizing that cookies are not something that people like anymore, and so they're starting to migrate over to what's called server-side tracking instead.This allows them to do the same types of tracking for your shopping carts and things of that nature while allowing you to block cookiee and not have to have them on your machine,because again, you might be afraid that your cookies are going to get stolen and people will get personal information about you.The second thing we want to cover in this lesson is locally shared objects, or LSOs.These are also known as Flash cookies, and they're stored in your Windows user profile under the Flash folder inside your roaming AppData folder.This is used by Adobe's Flash Player and it's less of an issue these days because Adobe Flash is being phased out in favor of HTML5.LSOs can be disabled within your Flash Player settings if you're still using Flash, and this is also found inside the local settings manager in most of today's operating systems.Next we have add-ons, and add-ons are small browser extensions or plugins that'll provide you additional functionality.Now, there are some examples of this,would be things like Adobe Flash or Adobe Shockwave that allow you to run active content within your browser.You might have a browser extension for a password manager that will load in your password when you visit a site.Now, these add-ons are not necessarily bad, but any time you're adding additional code,there could be some malicious code being added.Or if you're downloading an untrusted add-on, you could be installing malicious code into your browser as well.Organizations, for this reason, most of the time,will block additional add-ons,and they try to keep their browser as slimmed down as possible, because that eliminates some of the additional issues that you might have.The last concern we're going to talk about is advanced security options. Every browser has a way for you to configure it and set the different settings you want for the security of your browser.For example, do you want to use an SSL or TLS to be able to make your secure connection? How about your local storage or cache sizes? How big or small do you want those to be? Do you want your browsing history to be kept or deleted once you turn off the browser?Each of these things are things you can configure through the browser through its own tool and through group policy.I'm going to show you both of these in the next lesson.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 39 today we are discussing about Web Browser Security.Your web browser is your gateway to the internet and all of the wonders that it has,but it's also your gateway to the internet and all of the dangers that are out there lurking for you. This is why web browser security is really important.And in our organizations it's becoming more and more important everyday. In the old days when I first got started,if there was a custom application that need to be built,a company would hire a software firm and they would create something specifically for the Windows operating system that we could use inside our organization.Those days are pretty much gone, instead most people are going to use web apps instead, and this allows us to do quicker deployment as well as cross-platform functionality because it'll work on either Linux, Mac, or Windows, but it does rely on having a good secure web browser, so it makes this lesson even more important when your company uses web apps.So how do we ensure that our web browser is secure?The first thing you need to do is ensure your web browser is always up to date with the latest security patches.If an attacker has found a way to exploit a browser, you know that the manufacturer is going to figure that out, create a security patch and deploy it out into the environment. For us, that means we want to get that patch tested and then install it throughout our network. But when you're installing these patches, I want you to remember I said the patches. I don't want you to jump on and be the first to upgrade to a new browser,instead let other people upgrade to the newest browser immediately while they can figure out what all the bugs are and the issues,while you're staying on a nice stable browser.What do I mean by this? Well, for example, let's say there was Internet Explorer 11,and there's all these security bugs in Internet Explorer 11, there's patches that have been released, those are good, you want to get those, test those, and install those in your network.But if they decide to jump up to version 12,you want to let that go out for a little while into the open market first before deploying that in your organization because new browsers tend to be a little bit more buggy and they're not very stable.So we want to make sure that we have something stable and reliable,and let other people be out on the bleeding edge with the latest technology. Now the next thing we want to look at is updating our browsers. Whenever you're going to update your browser,if you're doing it in a home environment, you're probably going to be doing this through Windows Update.You're going to get the latest security patche and install them on your machine. But if you're going to be doing this in an enterprise environment, you're more likely going to be downloading that patch separately,testing it in your lab, and then deploying it through your patch management system. Either way you do want to make sure that your web browsers are getting those security fixes though,they are really important to have.The other question I get a lot from students is which web browser should I actually use?Well, this is a great question.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 38 today we are discussing about Welcome to application security.In this section of the course,we are going to move up into the software realm and start looking at the different applications that are used on our desktop devices.These applications bring to us a world of functionality,whether that's browsing the internet,conducting productivity by creating Word documents and spreadsheets, or by doing a host of other things.But each piece of software does introduce additional vulnerabilities to our system,and we're going to talk about that throughout this section.First, we'll spend some time talking about web browsers.When we talk about web browsers, this is really important,because web browsers are a conduit to the internet.That gives us a lot of capability,but it also brings a lot of vulnerability and all of those dangers from the internet,such as malicious websites, web apps, and more.As we go through this section, we're going to cover the various different types of web browsers that are used,how we can best secure them, and any other concerns that we should be thinking about as we're dealing with web browsers.Then we're going to get into the productivity space,and we're going to talk about the world's most popular productivity applications, specifically the Microsoft Office suite of tools.This includes things like word processing with Microsoft Word, spreadsheets with Microsoft Excel,and presentations using things like Microsoft PowerPoint.But we won't stop there.We'll move into the other category, which is going to cover all of the other applications out there.Now, obviously, we're not going to be able to cover each application in depth, but instead, we're going to talk about the best way to set up the right permissions and the right way to conduct application white listing and black listing to ensure that your computer is safe from the different types of software that you may wish to install.So let's get started with application security.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 37 today we are discussing about So, now that I scared you with all of the threats that exists against virtual machines let's talk about how we can best secure them.Most of the things that we need to do to secure a virtual machine are very similar to things we need to do to secure a regular physical server too.This includes things like updating your operating system in your applications.Also, you need to ensure that each virtual machine has a good anti-virus solution installed.With its own software firewall, good strong passwords and good policies and all of the other security features that we're going to discuss throughout this course.For this lesson, let's focus specifically on how to secure virtual machines though.First, remember that the hypervisor whether it's a type one,type two or application containerization based model,needs to be updated and secured whenever the manufacturer releases a new security patch.For example, if an export have been discovered then you can now conduct a VM escape against VM ware, you can be certain that accompanying like VM ware is going to quickly release a patch to fix this critical vulnerability. Next you want to ensure that you limit the type of connections that is existing between the virtual machine and the physical machine.This can be represented by a virtualized network card,or even as network shares.As I'm going to demonstrate in the next lesson.Remember if a virtual machine gets infected with malware it should remain isolated from all the other virtual machine hosted by the same hypervisor. But only if you implement your configurations for isolation correctly.Just like a physical server anytime there is a connection between a virtual machine and a shared resource, something like a network file server. This is an opportunity for data to be passed between the different virtual machines, and this would break down the isolation that you may be achieving.Just like we discussed back in handling our operating systems we want to minimize and remove any features that are not needed to support our operations.When dealing with the virtual machine,remember that hardware is emilated and it can be removed just like a piece of softare would be under normal machine.If don't your virtual machine to have an emilated flappy disk or CD drive for example,you can simply remove those features.This in turn will minimize your text surface and remove potential vulnerabilities.All of your virtual machines are hosted on physical computers or servers.And so if you had many virtual machine residing on a same physical server,and an attack is able to compromise one of those virtual machines,they maybe able to force it to use a large amount of physical server resources.If they do this can affect the other virtual machines hosted on that same server.In fact this could result and denial servers for one or more of the virtual machines being hosted.To minimize this threat you should consider spreading out your virtual machines among several physical servers. In steady of relying on one single physical server to host every single virtual machine.As assessment administrator,its also important to keep tracking your virtual machines and where they are being deployed.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 36 today we are discussing about When using virtualization, each emulated server runs its own operating system inside of a virtual machine, but the virtual machines are run on top of what's known as a hypervisor.A hypervisor may adjust the distribution of the physical resources of the server to the virtual machines.This includes the processor, the memory and the hard disk space.Hypervisors come in two distinct flavors,Type 1 and Type 2. A Type 1 hypervisor is known as bare metal, or native,since it runs directly on the host hardware and functions as a type of operating system.Microsoft's Hyper-V, Citrix's XenServer and VMWare's ESXi,and vSphere are all considered Type 1 hypervisors.A Type 2 hypervisor runs from within a normal operating system,something like Windows, Mac or Linux. For example, in the next lesson I'm going to demonstrate how we can install Windows 10 as an emulated desktop computer inside of a virtual machine that's being run by the software virtual box on my personal computer.Now, my personal computer is a Mac OS X desktop.But we're still going to be able to run windows inside of it.That's the power of using something like virtual box,because virtual box is an example of a Type 2 hypervisor.Another good Type 2 hypervisor is known as VMware.A Type 1, or a bare metal, hypervisor is faster and more efficient than a Type 2, or hosted, hypervisor.This is because a bare metal hypervisor doesn't have to waste any of the physical computer's resources by running a full desktop operating system,like Windows or Mac, first.Instead, a Type 1 hypervisor acts as a stripped-down, specialized operating system to provide the physical resources to the virtual machines that it hosts.Now, I know I said there's only two types of hypervisors.But there is a third type of virtualization that's becoming popular in our networks today.This is called Application Container-Based Virtualization.With this type of virtualization,the operating system kernel is shared across multiple virtual machines,but the user space for each of these virtual machines is uniquely created and managed.Often called Application Containerization, this allows an organization to deploy and run distributed applications without launching a resource-heavy, full virtual machine with a full operating system.This makes Application Containerization much more efficient than either a Type 1 or a Type 2 hypervisor,if it can meet the needs of your business and your organization.Container Virtualization is commonly used with Linux servers, and some examples of Container-Based Virtualization software include things like Docker,Parallels Virtuozzo,and the OpenVZ project.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 35 today we are discussing about While virtualization brings with it a lot of capability to add separations inside of our servers and bring in some additional security,there are some unique vulnerabilities that can be exploited by attackerswhen it comes to virtualization.These include VM escape, data remnants,privilege elevation and live VM migration.Virtual machines are segmented and separated by default so if an attacker is able to exploit the operating system being run inside one virtual machine,it doesn't necessarily mean that they can get into the other virtual machines being hosted by the same physical server.Virtual machine escape, or VM escape,occurs when an attacker is able to break out of one of these normally isolated virtual machines and they can begin to interact directly with the underlying hypervisor.From this position, the attacker could migrate themselves out, and into another virtual machine being hosted on the same physical server.Now VM escape techniques are extremely difficult to conduct.They rely on exploiting the physical resources that are shared between the VMs.But it is still a vulnerability you need to be aware of.To mitigate this vulnerability,virtual servers should be hosted on the same physical server as other virtual machines in the same network or network segment based on its classification. One of the main benefits of using virtualized servers within a cloud-based environment is their ability to rapidly scale up and scale down.This is known as elasticity.While operationally, this is a wonderful thing,it does lead to a vulnerability that has to be addressed and this is called data remnants.When a server is scaled up, a new virtual instance is created on a physical server.This instance takes up some hard drive space for all those files that represent the virtual hard disk and the configurations. When this is no longer needed because the load has decreased the virtual machine can be deprovisioned,which means it's shut down and the files are deleted.When this occurs, the confidential files from that virtual machine are left on the physical server.This is known as a data remnant.These data remnants could be recovered by an attacker,and therefore it could breach the confidentiality of that data.For this reason, cloud infrastructures that rely upon virtualization can introduce a data remnant vulnerability to your company,since the physical servers are not controlled by your organization.Privilege elevation occurs when a user is able to grant themselves the ability to run functions as a higher-level user, such as the root or the administrator.While this can be bad on a single server,it can be catastrophic on a physical server if the attacker is able to perform this on the hypervisor itself.A few years ago VMwear had a flaw on their hypervisor and this allowed a user to escalate privileges into any of the guest operating systems hosted by that hypervisor.To prevent this, it's important to remain current on your hot fixes and your service packs for your virtualization software.Another vulnerability to consider is one associated with live migration of virtual machines.When a virtual machine needs to move from one physical host to another,this is called a live migration.If an attacker can gain a foothold into your network and place themselves between these two physical machines they can implement a form of a man in the middle attack where they can capture the data being sent between the two physical servers.If this data has not been encrypted,this can allow the attacker to breach the confidentiality of the servers being hosted as virtual machines when they're transmitted over the network.Finally, when we're specifically relying upon application containerization as our virtualization method it's important to realize that the containers are all sharing a single common operating system.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 34 today we are discussing about Welcome to this episode on virtualization.Up to this point in the course,we've talked about a lot of different types of hackers and malicious software that are attempting to affect our systems.Then we started talking about how you can secure your hardware.And in the last section,we discussed securing your operating system.Now, we're going to talk about how you can use virtualization to emulate your physical hardware in order for you to run an operating system in a protected and sandboxed environment. First, let's define virtualization.Virtualization is the creation of a virtual resource.Now, I know that's pretty broad,but that's because virtualization itself is a broad category.We can virtualize anything.This includes servers, desktops, file systems,hard drives, and even an entire network.The most common use of virtualization these days is the use of a virtual machine.A virtual machine is a container that contains an emulated computer that can run an entire operating system inside of it.This includes emulation of all of the hardware that's required to run the system.This means you have the hard drives, the optical drives, video cards, processors,and even the BIOS being emulated.Later in this section, I'm goingto show you in a demonstration how to install Windows 10 inside of a virtual machine that's going to be hosted on a Mac OS X-powered desktop computer.Now, there are two main types of virtual machines:System virtual machines, and processor virtual machines.A system virtual machine is a complete platform that's designed to take the place of an entire computer.That means you can run the entire operating system virtually,just like I'm going to show you with my Windows 10 example later on.A processor virtual machine on the other hand is designed to run a single application. Often, this is used to run something like a web browser or possibly even a simple web server.Virtualization is important to both the security of our on-premise and our virtual servers,because it's heavily used by both of those.Virtualization has continued to increase in recent years,helping to reduce the need for additional power,space, and cooling for our server rooms and our data centers,and thereby reducing the hysical architecture involved in supporting our IT operations.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 33 today we are discussing about File systems and hard drives.Another aspect of hardening your operating system is determining exactly what file system it should utilize.The level of security of your system is effected by its file system type.There are many different file systems available to choose from.We have things like NTFS, FAT32,ext4, the Hierarchical File System Plus,and the Apple File System.Windows systems can utilize either NTFS or FAT32 file systems.It's highly recommended, though,that you use the NTFS file system.NTFS stands for the New Technology File System,and it's the default file system format for Windows because it's more secure than FAT32.It supports, logging, encryption, larger partition sizes,and larger file sizes than FAT32 does.If your Windows system is running FAT32,you can convert it to NTFS without losing any data, though.The easiest method to do this is to open a command prompt,and type convert, the drive letter,and then /FS:NTFS and hit enter.This technique is something you should have learned during your A+ studies. If you're using a Linux system, you should format the hard drive as ext4.If you're using a MacOSX system, you should use Apple's File System, since it is the newest, and most secure one supported by Apple.In addition to choosing the right type of file system, as we just discussed,it's also important to use whole disc encryption.This will help increase the security of your system.It's also important for you to realize that hard drives will eventually fail.But there are five things you can do to help postpone that failure, and ease your recovery from it.First, you should remove any temporary files from your system by using a disc cleanup utility.Second, you should conduct periodic file system checks.If you're running Windows, you can do this by running Check Disc, and the System File Checker.If you're using Linux, you should do a file system check by typing fsck in the terminal.If you're using OSX, you can run first aid from within the disc utility application. The third thing you should do is perform a disc drive defragmentation periodically.On a Windows system, you can use the defrag command from the command line, or run the disc defragmenter from within the graphical user interface.The fourth thing you should do is ensure you have a good backup of you're data. After all, every hard drive will fail one day,so it's important to have a good backup copy.This can be performed using different types of software or cloud solutions, depending on your business needs.The fifth and final thing you should do is ensure that you understand how to use different restoration techniques and actually practice them.This includes restoring from a system restore point within Windows, restoring a system from a tape backup, or backing up a hard drive, and even restoring an individual file from your backups.After all, the only way to truly verify that your backup copy is good, is to attempt a restore from it.In one organization I consulted with,they had years worth of backup tapes.They spent countless hours and a lot of money on this take back of system.But, when they actually need to restore from one of those tape back ups, they weren't able to do it,because the tape that they needed was corrupted.If they had practiced restoring that data to a test server,they would have known earlier that that data wasn't really there, and they didn't have a good backup copy.Thankyou and bye...
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 32 today we are discussing about Group Policies.A Group Policy is a set of rules or policies that can be applied to a set of users or computer accounts within an operating system.Now, to Access the Group Policy Editor simply go to the run prompt and enter gpedit.The Local Group Policy editor will then launch and this is used to create and manage policies within a Windows environment.Each policy acts as a security template that can apply a set of rules to different users.These rules can contain things like Password complexity requirements, Account lockout policies,Software restrictions, and Application restrictions.If you're using an Active Directory domain controller in a Windows environment, you actually have access to a more advanced version of the Group Policy Editor as well.In corporate environments, it's common to create a Security Template with predefined rules based upon your Organization'sAdministrative Policies.This Security Template is a group of policies that can be loaded through a single procedure within the group policy editor. A large part of hardening the operating system occurs through loading different Group Policy objectives or GPOs against the workstation or against the server.These Group Policies are also used to create a secure baseline as part of your larger Configuration Management Program.Using them, new accounts and computers can quickly be configured with all of your organizational requirements. After creating your secure baseline,it's important to conduct Baselining.Baselining is a process of measuring changes in the network,hardware or software environment. Effectively baseline helps establish what normal is for your organization.By knowing what normal is, you can then identify what abnormal or a deviation looks like. For example, if you're looking at your network utilization over a period of time, you can identify high periods and low periods.If you normally have low periods of activity during a Saturday afternoon, for example, but this Saturday afternoon, you saw an excessively high amount of activity.You should look into that and investigate it.For example, in this image, we can see one very high spike of activity. We would compare this to a known baseline and then determine this spike is expected or if it should be investigated further.Every deviation should be looked at and categorized as either acceptable and expected or an issue to investigate further.Many data breaches have been discovered by investigating higher than expected network utilization during periods of time that should have been relatively low.By looking at this they have found things like data exfiltration and other problems that have happened through the network.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 31 today we are discussing about What is patch management?Patch management is the planning, testing,implementing, and auditing of software patches.Why is patch management so important?Well, there are a lot of patches out there.Each manufacturer is going to create their own patches for their own applications.Part of patch management is keeping track of all of the various updates, and ensuring that they get installed properly throughout your environment.But it's also important to have a patch management system in place to ensure that a patch that is designed to fix one problem doesn't create multiple,new problems for you as well.After all, patches can have bugs in them too.There are fours steps to patch management.Planning, testing,implementing, and auditing.Planning consist of creating policies, procedures,and systems to track available patches and updates,and a method to verify that they are compatible with your systems.Planning is also used to determine how you're going to test and deploy each patch.Microsoft actually provides a useful tool that can help us in determining the status of our system,and whether or not a patch needs to be applied.This is known as the Microsoft Baseline Security Analyzer or MBSA.This tool can help identify security misconfigurations within your network's workstations.After planning, the next thing is testing.It's important to test any patch you receive prior to automating its deployment throughout the network. As I said before, while a patch is designed to solve one problem, it can often create new ones for you.Within your organization, you should have a small test network or lab or, at the very least,a single machine that you use for testing,where you deploy the patch first and ensure it's working properly.After all, many of our organizations have unique configurations within our networks.And while manufacturers attempt to ensure patches will not cause harm to our systems, this can't be guaranteed.It's better to find out in your lab that a patch is causing issues than to push it out across 10,000 workstations,and then have all your end users yelling and screaming when their systems crashed.After testing the patch,it's time to deploy it to all of the workstations that might require it.You can do this manually or automatically by deploying that patch to your clients' workstations to implement it.If you have a small network, you may choose to manually install the patch across the network.If you have a large network, though,you're going to want to use some sort of a tool.Microsoft provides us with the Microsoft System Center Configuration Manager,but you can use third-party patch management tools as well.Some organizations rely on automatic updates from the Windows Update system,while others decide they want to have complete control over the installation of patches. For large organizations, it is highly recommended to centrally manage updates through an update server instead of using the Windows Update tool.This will allow you to test the patch prior to deploying it in your environment.To disable Windows Update,you simply need to disable the Windows Update service from running automatically on the workstation.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 30 today we are discussing about In order to maintain the security of our software, it's important for us to implement updates and patches.But, what exactly is a Patch? A patch is a single problem-fixing piece of software designed for an operating system or an application.Essentially, when we find a bug in the code,this is going to create a problem for us.And a patch is used to correct it.You may have also heard the term Hotfix.What's a hotfix? Well, it's a single problem-fixing piece of software designed for an operating system or application.Now, wait a minute.That's the exact same definition as a patch.Jason, are you trying to confuse us? Well, no.Originally a hotfix was different than a patch.A hotfix could be installed without requiring a reboot of your system.But a patch, required a system reboot.Over time, patches and hotfixes began to be used interchangeably by most manufacturers.Today, whether you call it a patch or a hotfix,it really refers to the same thing.Patches and hotfixes are both considered a general term.But there are more specific types of updates as well.Let's look at five categories of updates.First, we have a Security Update.Security updates are a type of software code that's specifically issued from a product-specific security-related vulnerability.So, if a hacker finds a bug in the code for Microsoft Word,that may allow them to breach your security.Microsoft would release a security update that contains a patch to correct the bug in the code.The second type of update, is a Critical Update.A critical update is a piece of software that's designed for a specific problem that addresses a critical,non-security bug in a piece of software.For example, if Google Chrome kept crashing every time you tried to load Facebook, Google would release a critical update that patches this non-security focused bug.A third type of update we have, is a Service Pack.A service pack is actually a grouping of other patches.It contains hotfixes, security updates, critical updates,and possibly even some feature or design changes.Service packs are commonly seen with an operating system update.As you can imagine, Windows has a lot of security and critical updates that have been released since the initial version comes out. If I installed a brand new copy of Windows 7 today, there would be several hundred patches and updates that I would have to install, to bring it up to the most current and up-to-date version.Service packs provide a single installation file that contains hundreds of these individual updates that can be installed.Generally, a service pack is only released once every other year.Any updates that have been released since the last service pack,would still have to be installed individually. The next type, is called a Windows Update. This is a recommended update to fix a non-critical problem that certain users have found, and it may also provide some additional features or capabilities.For example, if Microsoft wanted to add a new way to display animated background images on your desktop,they could do this as part of a windows update.The final type of update, is a Driver Update.Driver updates provide either a security fix,or additional features for a supported piece of hardware. For example, you might receive a driver update for your network card. And this can help you increase the efficiency in how it sends and receives data.In Windows 10, the windows update program is used to manage all of the different types of updates directly from Microsoft.And it can be configured to allow automated updates to occur as well.This is what most home users will do to increase their security. And ThankYou ...
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 29 today we are discussing about Large organizations like the Federal Government process a lot of sensitive information,and they want to ensure that their operating systems are truly trusted.To provide organizations with a level of assurance, the classification of a Trusted Operating System was created.A Trusted Operating System is any operating system that meets the requirements set forth by the government and it contains multilevel security.For the Security+ exam,you don't need to learn the specific requirements, but you should know that the government has a long list of them.What operating systems meet the criteria to be called a Trusted Operating System? Well, every version of Windows since Windows 7 is considered a Trusted Operating System.This includes Windows 8, Windows 10,Windows Server 2012, and Windows Server 2016.Also, every version of Mac OS X since version 10.6 is classified as a Trusted Operating System.If you're using FreeBSD,if you load the TrustedBSD extensions,this is also considered trusted,as well as Red Hat Enterprise Server.There are other Trusted Operating Systems out there as well,but those are much less popular than the ones listed here.To remain a Trusted Operating System, the software manufacturer must routinely provide patches and updates to the software in order to maintain its security. This is one of the reasons that both Mac and Windows provide frequent security updates,to patch any vulnerabilities that have been discovered. Prior to installing any patches or updates though,you should first verify the current version and build of your operating system.This is done by going to the system information program within your computer.For a Windows machine,you simply run the msinfo32.exe program from the Command Prompt and it'll display the exact version and build of the software.In this example, the computer is running Windows 10,version 10.0.10240.This contains all the patches and updates to the software code through Build 10240.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 28 today we are discussing about Let me ask you a question.How many applications do you have installed on your computer right now?Now I don't mean how many are currently running.But how many exist on your computer in total?Do you have five? 50? 500? Or maybe more?Each application that's installed on your device takes up valuable disk space,but more importantly, it introduces additional code and therefore additional vulnerabilities.To combat this system administers attempt to practice known as least functionality.Least functionality is the process of configuring a work station or a server to only provide essential applications and services that are required by the user.To create an environment of least functionality administrators should restrict unneeded applications, services, ports and protocols.Another method of doing this is to uninstall any unneeded applications.After all, every application that's installed on a computer must be managed, updated and it provides yet another chance for a vulnerability to be introduced into our system.Now, our computers at work are often under a process known as configuration management.Most of our personal computers though have become mess with unnecessary programs being installed and accumulated over time.For example, if you open up your programs and features section of the control panel,take a look at all of the various programs you have installed.You might surprised at just how many are on your computer.For this example this computer had 132 different programs installed that took over 400 gigabytes of disk space looking through that list, there is a lot of unnecessary programs that user could have uninstalled.As we previously mentioned, it's important to keep your programs and you software up to date.Sometimes though, new programs are installed the old version is simply not removed.Recently we updated our video editing software from Adobe Premiere 2018 to Adobe Premiere 2019 after the installation was complete we saw that both versions remained installed on the computer.To eliminate the vulnerabilities from the 2018 version we had to go back and manually uninstall it from our systems now this may be easy to do when you have a small network of just few machines.But how do you do this when you're managing a huge enterprise network? For example one network I used to manage had over 10,000 computers spread across four countries.It would have been impossible for me to send a system administrator to check the installed programs on each and every computer throughout the network.In large networks like this, preventing excessive installations is the best solution.In our corporate networks, it's common for us to create a secure baseline image that we use for all of the work stations across the company.This image will hae the operating system,the minimum applications required and strict configuration policies that are set up for all of those machines.These polices though do have to be updated and changed over time, based on changing business requirements.We can use the Microsoft's system center configuration management or the SCCM tool that allows us as admins to manage large amounts of software across the network as well as push out new configurations and policy updates to all of our PCs.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 27 today we are discussing about In this episode we're going to discuss the 10 best ways to increase the security of your mobile devices.This is known as mobile device hardening.Number one, update your device to use the latest version of the software, whether this is your operating system,your apps or your firmware,you should always be updating it.By updating it, you're making sure that you have all known vulnerabilities patched and secured.Just like your desktop,most devices are hacked because they're not patched from a known vulnerability,so when an update comes out, make sure you apply it.Number two, install antivirus.A lot of people figure that it's a mobile device and it's not a computer so it doesn't need antivirus.But, just like a computer,your mobile devices do need to have antivirus and antimalware installed.Number three, train your users on proper security and use of the device.This includes showing them how to use social media appropriately,what sites are safe to browse and what apps are allowed to be installed.Remember, these are all vulnerabilities that your employee,who's holding the device,can install and use on your device.You have a right to train them the correct way.Next, number four, only install applications from the official mobile stores.At least if you've done that,they have malware checks and security checks and you're much less likely to have issues.Again, this is the App Store for Apple and the Google Play store for Android.Number five, don't root or jailbreak your device.That's going to bypass the security and the built-in protections that Apple and Android have already put in there for you.If you do this, you're asking for trouble.Number six, only use version two SIM cards with your devices.As we talked about in the SIM cloning lecture,version two is very hard to clone but version one is actually quite easy.So you should always use version two SIM cards to help counter SIM cloning.Next, we have number seven,turn off all unnecessary features.Whether this is Wi-Fi, Bluetooth,near-field communication,mobile hotspots, tethering,location tracking, and more.Turn it off if you're not going to use it.If you do have to use Bluetooth,make it undiscoverable.Number eight, turn on encryption for your voice and data.This'll ensure things like Bluetooth,near-field communications, Wi-Fi,and others have encryption enabled whenever you're using them.Number nine, use strong passwords or biometrics for log on.That means you shouldn't be using a four digit PIN.You want to use things like a thumbprint,a face scan, or long, strong passwords,whichever of those three your device supports.Also, you should turn on Find My Phone,enable remote lockout, and remote wipe capabilities before you need them.Number ten, don't allow BYOD.I know I talked about in the BYOD lecture,that you can allow your organization to make the choice, but let's just be honest:bring your own device means bring your own disaster.It introduces a ton of risk; if you use it you need to ensure that you have storage segmentation,and good mobile device management and having your employees allow you to install it.And Thankyou
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 26 today we are discussing about Bring Your Own Device is a policy that a lot of organizations have been adopting.This means when you come to work,you can bring your own device, and use it on their network.This may be your laptop, your tablet, your cellphone,keyboards, mice, or any other type of device.Some organizations have fully adopted Bring Your Own Device,and others are fully against it.We're going to talk about both,and why you should consider it,or decide not to use it in your organization.Now, when you use Bring Your Own Device,it brings a lot of security issues for you to consider.If I have somebody's laptop that now gets plugged into my network,I'm also introducing all of the vulnerabilities that device had.So, if you took your laptop home,plugged it into your network, downloaded a game,installed the game, and got malware and now you plug it into work the next day,you can bring that malware into work with you.This is a major concern with Bring Your Own Device because as an organization, I don't control your device,and so I don't know the security of it.And, that's one of the major risks with Bring Your Own Device.Now, on the flip side, a lot of companies really like Bring Your Own Device because it means they don't have to buy laptops, and cellphones,and all those type of devices for their employees because the employee is bringing their own.And, while that might save them money,and it's good for the bottom line, there are concerns.When the data goes on your device, who's data is it?Is it the company's data, or do you have rights to it?Where do you draw the line between what's personal data,and what's business data? A lot of organizations that have adopted Bring Your Own Device, will use storage segmentation.This will create a clear separation between personal,and company data on a single device.Now, there's lots of different ways to create this segmentation.There are highly technical solutions,and then there's highly procedural solutions.For example, you might have an application on your phone that says work, and when you click on that,it opens up a virtual environment, and all of your work is done from within there.And, when you exit that, you're now back into your personal device.That would be a clear technological limitation between the two.Now, you don't always have to use a highly technical solution.In my company, we're very small,we use personal devices as work devices,and so on my phone in particular, I have two email clients.I have one that's on Apple Mail that I use for my personal email, and then I have another one,which is Gmail, using the Gmail app that I use for my company email.That gives me a clear separation between my personal stuff,and my business stuff, and keeps them in separate buckets.Now, again, there's nothing really that would prevent me from loading up my business email inside Apple Mail if I wanted to.Except that we have a policy that says we won't do that.So, we've chosen an administrative control,as opposed to a technical control.Another concern you have with mobile devices under the Bring Your Own Device policy,is how do you ensure that device is always up to date?We talked about how important it is for patches,and updates to be installed on your mobile devices.I can push out software policies to you,prevent you from installing applications,and install updates remotely without your use.But, when I do Bring Your Own Device,are you going to let me install Mobile Device Management on your system?You might not.And, so this is why a lot of companies are now switching from a Bring Your Own Device,because of all those security issues,into a Choose Your Own Device, or CYOD model.CYOD gives the employee a choice of a couple of phones.We might have four, or five models that we support,and we say you can pick any one of these,and we'll pay for it for you. And Thankyou byebye
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 25 today we are discussing about Security of Apps.How do you know the app you want to install is secure?How do you know it's not going to be spying on you?How do you know there's no malware embedded in it?Well, you don't.But the best way to ensure that you don't get those type of things is by installing applications from the official mobile stores only.If you're using an Android device,that's the Google Play store.If you're using an Iphone,that's going to be the App Store.Now, some people have taken their phones and done what's called jail breaking it or rooting it.On an Apple device,jail breaking it means you're going to remove the security protections that Apple has put in place so that you can take it from your wireless carrier to a different wireless carrier or install third party apps outside of the App Store.As you can probably guess,these are both bad security practices and should not be done.Now, we you have an Android device we don't call jail breaking it,we call it rooting it.The reason is because Android is at heart a Linux operating system.So if you root the device,you now have administrative permissions over it.And you can install whatever applications you want and make the phone do things that it wasn't necessarily designed to do.Again, making sure that you don't jail break or root your device is a good first step to ensuring you have a secure device.Next, you want to think about what browser and what applications you're actually running.For example, if you're using the Chrome browser,that's a fairly secure web browser.But if you decide to get a third party web browser,you don't know who it is that put that out there and if you can trust them.Maybe they're giving you this web browser but they're also taking a copy of all your data going through it.To avoid those type of issues,always get official applications when possible.And speaking of web browsers,one of the things you want to ensure is whenever browsing the web on your mobile device,you're always going to the secure version of a website.That's denoted by the https at the front of the web address.This ensures that you have a TLS tunnel created between your phone and the server.What's TLS?Well, it's Transport Layer Security.It's going to put a encryption layer and a tunnel between your device and the server to ensure you have confidentiality and nobody is conducting a man in the middle attack from you.Now as businesses, we are increasingly going mobile all of the time.An Enterprise Mobility has a couple of things that we need to think about when we talk about securing our apps as well.One of those, is making sure we have control over those devices and what apps are installed.If your organization is going to be providing the cellphone to its employees,you have the right to install mobile device management software. MDM or Mobile Device Management is a centralized software solution that allows your system administrators to create and enforce policies across all of the mobile devices.This can ensure that people don't install games like Angry Birds or they don't put a third party apps or that they could only go to certain websites.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 24 today we are discussing about Mobile devices are an increasingly large part of our life.They are doing everything with us these days.When we're on travel, we have 'em with us.And sometimes if we're not careful, someone can steal 'em. For example, this guy's about to get his iPad stolen out of his backpack.It's not going to be a very good day for him.Now, we have to think about all of the data that's on that device.Let's say you were on a family trip and you just took a whole bunch of pictures from your vacation.And now you're returning to the United States,you're going through the airport,and somebody steals your phone.You're not just losing the value of your phone,but you're losing the value of all of those memories that may be irreplaceable.So when you think about what's on your device,one of the most important things is to always ensure that you have a good device backup. And the reason is, the memories, the photos,your files, that's irreplaceable.The device itself, you may have cell phone insurance for or you'll just go buy a new one.But the information on it is what's really critical.Now, let's take it to a darker side.What else is on your device? Well, if you're like most people,you also do mobile banking on your device.And so if you don't have your device encrypted and locked and protected, somebody can take that device and access your account.That's another big issue.So what do we do about this?Well, the first thing is we want to encrypt our device.We want to use full disk encryption on our cell phones and our tablets.By doing this, even if someone is able to steal the device, they won't be able to access the information on the device without the proper PIN and encryption key.Additionally, we want to make sure that we're thinking about setting up tracking on our device.If the device is lost or stolen, you should be able to be pulling the information from that phone and where its GPS location is to determine where it is.Now, just because you know where it is,doesn't mean you should go get it yourself.In fact, police recommend that you don't try to recover your device alone if it's stolen.Instead, you should go to the police and have them go with you to the location of your device that you've been able to find based on its location tracking.And how exactly can you find out where your phone is?Well, if you're using an Apple device,you can use Find my iPhone.If you're using Android, you can use Find my Phone.These are websites that connect to your phone based on its data location and its GPS signal and it will tell you where that phone is located.Now, these sites also have some additional features.One of them is the remote lock option. This will allow you to remotely lock you phone from the website.This will make it so it requires a PIN or a password before the person who has your device can actually log in to it and get access to your data. Another great feature of these sites is the ability to conduct a remote wipe.A remote wipe is going to allow you to remotely erase the contents of the device to ensure that no information is recovered by the thief.Now, why would you want to remotely wipe your device?Because maybe you have some personal things on that,maybe you have personal text messages or photographs or banking information that you don't want anybody seeing.By using remote wipe, even if the criminal has your device, they're not going to be able to see anything on it because you've already formatted the device, even from a remote location.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 23 today we are discussing about Bluetooth attacks.In this lesson, I want to talk about wireless connectivity and some of the attacks that go against it,specifically we're not going to focus on the 3G, 4G or LTE cell phone part of it,we're going to focus on Bluetooth.Now, when we talk about Bluetooth,there are two terms that you have to know for the exam.Bluejacking and bluesnarfing.Bluejacking is sending unsolicited messages to Bluetooth-enabled devices.This often happens by having somebody who will pair to your device and then send the data to you,so if your car isn't paired up with your cell phone,somebody who's sitting next to you in the parking lot,can pair to your car and send messages to you or if your phone is in discoverable mode,they can go and connect to your phone and send you messages that way.Now when we talk about bluesnarfing, on the other hand,this is unauthorized access of information from a wireless device over a Bluetooth connection.Did you notice the key distinction here?When we talked about bluejacking,we're talking about sending information to a device but when we talk about bluesnarfing,we're taking information from a device.That's the main difference here.Now, one of the ways that you have to worry about this is you have to consider what the Bluetooth-pairing key is.Most devices come with a default of 0000 or 1234.If your devices are set up to use a default key,you are asking for an attack.You're going to become a victim of either bluesnarfing or bluejacking, so make sure you're not using the default pairing key.The other thing is if you're not using Bluetooth,you can go ahead and turn it off on your phone.A lot of us don't use Bluetooth.Instead we use wired headphones,we use a USB cable that connects our phone to our car stereo and if you're no using Bluetooth,it's better to turn it off.If you are using Bluetooth,at least turn it so it's not in discoverable mode.By turning off the discovery feature,it's not there sitting and waiting to accept connections from any devices that come in the area.Instead it will only remain connected to the ones you've already paired.Taking these actions will help secure your mobile device and prevent bluejacking and bluesnarfing. And Thankyou bye bye.....
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 22 today we are discussing about SIM cloning and ID theft.If you've gone and bought a new cell phone recently,you've gone to the store, they've pulled out a little chip our of your phone and placed it into your new phone.What is that chip? Well, that's a SIM card.It's stands for subscriber identity module.This is an integrated circuit that securely stores the international mobile subscriber identity, your IMSI number,and its related key.This is what tels the cellphone towers which device is assigned to which number.Now, if someone is able to clone your SIM card,they can pretend they're you.This was very popular in the early days of cellphones because if I could pretend that I was you,I could rack up lots of long distance calls and lots of minutes used on cellular and not get charged for them.Because you would get charged for them.And so people would go through and impersonate you and they would do this by cloning your SIM card.Now SIM cloning allows two cellphones to utilize the same service.And allows the attacker to gain access to the phone's personal data.So if I'm cloning your SIM card the towers think I'm you.So if somebody sends you a text message,I get a copy and you get a copy.And so now I'm able to keep track of what you're getting.Now this is very dangerous for you.The good news is that SIM has changed its ways over the years.The first versions of SIM cards were very easy to clone,but the newer SIM version 2 cards are much, much harder.So this gives us a lot more security.Now, one of the second problems we have with mobile phones and SIM cards and phone numbers is when people try to take over your phone.And so you may think, all right, great,SIM card cloning is almost a thing of the past,version 2 has taken care of it.Well, attackers are smart and they find other ways to hijack your cellphone account.What they started doing now, is they will call up your cellphone provider and pretend to be you.This is a social engineering scheme.They'll say, I just bought a new phone and I need to get it activated.And the nice customer service agent will ask them some basic questions about themselves,like maybe their date of birth,where they went to high school, their name and address,things that you can usually find online.So the attacker pretends to be you and gives that information.The customer service agent is wonderfully helpful,and they transfer your phone service from you to the attacker.Now the attacker has a phone and a new SIM card that is now attached to your number.Why are they doing this?Why do they want your phone number?Well, it comes down to two-step authentication.A lot of websites now are using two-factor authentication where you long in and they send you a text message with a secret code that you then put into the website to verify that you are who you say you are.If the attacker is able to take over your phone number,they can now pretend to be you and long into your bank, your Facebook, your Gmail,or whatever else you have for two-factor authentication.This is becoming a big problem.And so you have to be careful where you post your phone number.Because if somebody now has your phone number,and they've already stolen your account,your email, and maybe your password,they can now take over your phone number and then take over your accounts.So this is what we call ID theft, or account takeover.So, how do we combat this?Well, one of the ways is to be careful where your post your phone number.Because if you are a victim of a data breach,and somebody has stolen your name and your address and your email,and now they have your phone number,they can preform this account takeover against you.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 21 today we are discussing about These days we work all over the place.We're not just stuck in our cubicles behind a computer.Instead we can be working no matter where we are.When I'm sitting in the line at the grocery store,I can be checking my email and answering student questions.If I'm sitting on an airplane,I can be texting to my friend while I'm at 35,000 feet. Mobile devices are great and they give us a lot of capability and a lot of connectivity but we also store a lot of personal information in these.We do our banking, our email,our pictures, even our online shopping,all from the palm of our hand and while that's all wonderful and it's great,we have to consider the fact that there is mobile malware out there.These devices are not immune to it and so, how are we going to protect ourself against these mobile variants?Well, the first thing we want to do is ensure that we have an antivirus solution on our devices.There are third-party products out there for both iPhones and Android devices that will allow you to have an anti-malware or antivirus solution on your phone.It will scan any attachments you have that are in your email,as well as check the device to ensure it's running properly.In addition to that, one of the biggest things you can do is always ensure your mobile device is patched and updated.That's right, just like your operating system on your computer, you need to ensure your phone is patched and updated.So, if you're one of those people that always hits Remind Me Later, don't do that because what happens is if there is a patch out there,that means that attackers have already been able to reverse engineer it and they know what the vulnerability is.If there's a patch, there's also an exploit,so always patch your devices and ensure your applications are updated.Now, if you're talking about your operating system,how do you update an operating system on your phone?Well, if you're using an iPhone,it's fairly easy.Apple will actually push a notification to you and say the latest version of iOS is out,click here to update or it'll ask if you want to do it in the middle of the night because that way,it doesn't take away valuable time that you're using it.Either way, you want to make sure you're updating your device so that you always have the latest operating system.Now, when we talk about Android,it's a little bit more complicated. Google puts out the base operating system and when there's a vulnerability found,they create the patches for it and then they pass it out to the different manufacturers.The problem is most people aren't running a Google-based Android device.Instead you may have a Samsung device or a Huawei device or an HTC.And each of these manufacturers has taken that base code and modified it in some way.So, usually you have to get your operating system update from your manufacturer, so if Google founds out there's a bug today and they release a patch tomorrow,it could be two, three, four months before Motorola or HTC pushes that patch out to your Android device. For this reason, Apple is a little bit more secure if you keep it updated because they do have a quicker patch and release cycle since they only have to support their own handsetsand not a bunch of other manufacturers.When we look at that, we also to consider our applications. ThankYou....
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 20 today we are discussing about We all use wireless devices these days.Whether it's your laptop, your tablet, or your smartphone,all of these have the ability to communicate wirelessly.How can we best secure these devices?Well, there's two main things we have to think about when we talk about wireless with these devices:wifi and Bluetooth.First, wifi, is there internet connectivity? If we're using wifi, we want to make sure the wifi is set to be protected at the highest levels.Currently, that's WPA2, or Wifi Protected Access Version Two.This relies on the advanced encryption standard for its encryption algorithm, also known as AES.In addition to securing our wifi, we also have to consider the peripherals that connect to these devices.For example, if you have a smartphone and it connects to a Bluetooth to your car,how is that link being secured?Well, by default, Bluetooth requires you to pair the device and when you pair the device, the two devices will communicate via that shared link in giving each other a shared link key.They use that key to encrypt their data.Unfortunately, some of these devices use weaker encryption than others, so if you're really worried about your confidentiality, you should always try to avoid wireless devices when possible.If you have to use a wireless device like headphones or connecting to your car, you should look at the manufacturer specifications to determine what type of encryption is being used and if they're not using AES with a strong key, you might want to pass on using that device and buy a replacement.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 19 today we are discussing about Disk encryption, encryption is a process that scrambles data into unreadable information.It does this to ensure that nobody can read it,except the person who holds the secret key.This ensures confidentiality.If you have the key you can unlock that randomized data and translate it back into something readable.Think about it like a magic machine.The information goes in one side,and out the other side comes a jumbled mess.Without that key you don't know how to read the jumbled mess.Another example of this is actually language.I'm speaking English right now.If I spoke English into my machine and out the other side came Spanish,and you didn't understand Spanish,it would be encrypted, and you wouldn't understand it.But if you knew the key,meaning you understood Spanish,you could understand everything that was being said.There are two different types of encryption,hardware-based and software-based.The first one we're going to talk about is hardware-based encryption.A great example of this is a self-encrypting drive.It looks like an external hard drive,and it has embedded hardware that performs full disk, or whole disk encryption.These are very fast, unfortunately,they're also very expensive, so they're not commonly used.Instead, most people use software-based encryption in the marketplace and in our organizations. Luckily for us, there are two forms of whole disk encryption already embedded into our operating systems if we're using Mac or Windows.In a Mac we have a system called FileVault where we can turn on whole disk encryption with a single click.This is located under your system preferences and under the security tab.On Windows we use a system called BitLocker.BitLocker, again, is very easy to turn on.If I want to encrypt my D drive I simply right-click it,turn on BitLocker, and then I'll be able to encrypt the entire drive with a single click.As I said previously, encryption requires a key.And when you're using BitLocker specifically you're actually going to be using a hardware key that resides on your motherboard.It's called the Trusted Platform Module, or TPM.This TPM chip resides on the motherboard,and it contains the encryption key inside of it.This is what BitLocker is going to use to encrypt your drive.So if you're going to take that hard drive out and put it into another system you have to decrypt that drive first,otherwise you're not going to be able to decrypt it on the other system because it has a different TPM module and different secret key.If your motherboard doesn't have TPM you still can use BitLocker, but instead you have to use an external USB drive as a key.It'll store the key on that USB drive.But if you use that USB drive you're never going to be able to unlock that hard drive again.Because every time you boot up that computer you have to make sure you have that USB key inserted so it can unlock the drive.Both BitLocker and FileVault use the same type of encryption. They use Advanced Encryption Standard, also known as AES.AES is a symmetric key encryption that supports 128-bit and 256-bit keys, and is considered unbreakable as of the time of this recording.Encryption sounds like a wonderful thing, and it is.It secures our data and keeps prying eyes out.It secures our data and keeps prying eyes out.But it does have some drawbacks.Encryption adds additional security for us,but it comes with a lower performance for your system.If I'm doing whole disk encryption that means before I can even boot up the computer and read things from that drive I have to decrypt it,and that takes time and processing.So you have to remember there is a sacrifice in speed and performance when you're using full disk encryption.Because of this performance hit some people decide not to use full disk encryption.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 18 today we are discussing about Securing the storage Devices There are a lot of ways to store data in your network and on your computers.In addition to your internal hard drive,most computers have the ability to use removable media as well.Removable media comes in many different formats.In the old days, we had our simple floppy disks.Then we moved up to CDs and then DVDs and those held a lot more information.Next, we had external hard drives that plug in through USB.And finally, we had USB thumb sticks which are very small but hold a ton of information.When you're placing your information onto one of these removable media formats or external devices,you have to make sure that it stays safe from prying eyes.We want to ensure confidentiality.To do this, we always want to encrypt our files.You can do this in one of two ways.On Windows 10, you can use BitLocker To Go which will allow you to encrypt files using a software encryption.Also, you could buy a USB thumb stick that already has hardware encryption built-in,something like an IronKey USB shown here.Some organizations are a little more paranoid though and they want to ensure that nothing gets out of their organization.And they also want to make sure that nothing gets into their organization.To do that, they've implemented removable media controls.These controls are technical limitations that are placed on a system in regards to the way the USB storage devices and other media can be accessed. For example, this can be done using technical controls inside your group policies by denying read access from USB drives or denying write access to a CD or DVD.In addition to these technical controls, you also need to consider which administrative controls such as policies you want to create and guide those technical controls that are going to be used inside your organization.In addition to external devices and removable media,we also can store our data on our networks and we might do something called a NAS.If we use a NAS, that's a Network Attached Storage device.These storage devices connect directly into your organization's network.They often look like a big rack of hard drives with a network cable coming out of the back of them.Most of the time,NAS systems are going to implement some form of a RAID array that gives you high availability.Because these devices need to be accessed at all times because they're acting as file servers for your organization,this high availability is important.Oftentimes, we'll take different NAS'and we'll connect them together into what's known as a Storage Area Network or a SAN.A SAN is a network designed specifically to perform block storage functions and it may consist of many NAS devices connected together.Now if you're using a single NAS device in your organization or at your home,there are three tips I want to give you to make sure that you secure it properly.First, always use data encryption.If your NAS supports full disk data encryption,you should turn it on and implement it.Second, you should always use proper authentication.These things are acting as file servers.You want to make sure that it asks for credentials such as a username and password and that is individualized to each user so no one is sharing access across the organization.The third thing is to make sure you're logging access to your NAS device.This way if something goes wrong,you can go back and figure out who was the last person who accessed the NAS?Who downloaded those hundred terabytes worth of files?And what may have gone wrong?These are important things to know and without logs,you won't be able to figure it out. And Thankyou bye-bye.....
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 17 today we are discussing about Securing the BIOS.What is the BIOS?Well, if you remember back to your CompTIA A plus studies,BIOS is a type of firmware which is software on a chip.The BIOS stands for the basic input output system..It's firmware that provides the computer's instructions for how it's going to accept input and send output.So anytime the motherboard is going to talk to a keyboard,a mouse, a network card, a hard drive,a video card, whatever it is,it has to have instructions on how to do that.That's what the BIOS provides.Now, most modern computers don't have a traditional or legacy BIOS anymore.Instead, they use a U-E-F-I, or UEFI,known as the Unified Extensible Firmware Interface,but it's essentially the same thing.It's just more of an updated and robust version of it.Throughout this lesson I'm going to refer to both of these as BIOS collectively instead of one or the other because for our purposes they're equivalent.Now, when your computer boots up, it loads the BIOS,and the BIOS tells it how it'sgoing to check the hard driveand figure out what the boot order is.Should it boot from the hard drive,the floppy disk, the CD,or the USB drive first?The BIOS controls that.Then, it's going to load the machine.Once it does that, it loads the operating system.And then, Windows is going to start taking over and be able to do a lot of the functions for the BIOS.The BIOS is very low level.As such, it only deals with very basic tasks.Once the operating system has loaded,it gives you a ton of additional capability to your computer.Now, how are we going to secure this computer?Well, when we're talking about securing the BIOS,we're talking about securing everything up to the point when Windows is loaded.The first thing we want to do is what's called flashing the BIOS.Flashing the BIOS is simply ensuring that it has the most up to date software on that chip.Because it's firmware, you have to do a process called flashing the BIOS to upgrade the BIOS.This allows you to remove what's currently on the chip and replace it with a newer, more updated version.Any time there's going to be a new update to the BIOS,the manufacturer releases it on their website.Generally, they'll give you a process that you can install it to a thumb drive,boot from that thumb drive,and then run a program to flash the BIOS.The next thing we want to do to help secure the BIOS is ensuring that you've set a BIOS password.This'll prevent anyone from being able to log into the BIOS and change the boot order or other settings without having this administrative password.You want to make sure that you're using a good long and strong password,just like you would for your Windows machine.But it should be one that's unique to your BIOS and not the same as your Windows machine.Next, you want to configure your BIOS's boot order.As you can see here on the screen,I've deselected the disk drive,the CD drive, and the USB drive.I only want to be able to boot from the internal hard disk and then from the network card.This helps me protect somebody from putting in a bootable distribution of a Linux CD or something like that and taking control of my computer.f I control the boot order,I control what's loaded.The fourth thing you can do to help secure your BIOS is disable any external ports and devices that you're not going to need.For example, do you still use a parallel port?Most people don't, and so you should disable it.The same thing happens with a serial port.No one really uses them anymore.We use USB, so you can disable it.You might have an onboard network card that you don't use.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 16 today we are discussing about Data loss prevention.Data loss prevention is set up to monitor the data of a system while it's in use,in transit, or at rest.It does this, in order to detect any attempts to steal the data.Let's think about when we had data stored,20 or 30 years ago.Where did they store most of it?Well, most businesses stored it printed off,and in a filing cabinet.And if somebody wanted to get it,they'd have to break into your offices,open the filing cabinet, and physically take the files.This limited the amount of information that somebody could steal from you,because they really could only steal,what they could carry with them.Then, we started allowing people to work remotely,and a lot of data was stored on laptops.If you happened to stop for lunch and you left your laptop sitting in your car,somebody could've broken in your car,and stolen your laptop.And they now have access to all the data that was on it.The next evolution in data theft occurred when we started using external hard drives.These started being used,all throughout our offices.These hard drives could hold large amounts of data.We could plug it into the network, through our laptop,and download a ton of information and data,and then walk out of the building with it.But, these were kind of large and easy to detect.Next, we started seeing thumb drives,that hold just as much as these external hard drives,carrying billions of documents out the front door with no one knowing it,because they're so small,and fit right in your pocket.But wait, we don't even need to do that nowadays,because we have things like Dropbox and Google Drive,where we get terabytes of storage available to you,hooked up to the network.And I could sit there and upload everything your company has,and get access to it,anywhere in the world.This is a huge problem for businesses,because our data and our intellectual property is what the currency of business is these days.To protect it, we have to use data loss prevention systems.These systems come as either software or hardware solutions.The first data loss prevention system we're going to talk about is an endpoint DLP system.An endpoint system, is usually a piece of software that's installed on a workstation or a laptop,and it's going to monitor the data that's in use on that computer.And if someone tries to do a file transfer,it'll either stop that file transfer,or it'll alert the admin of the occurrence based on certain rules and policies.Very much liked an IDS or an IPS would, but focused on data.DLPs can be set to detection mode, or prevention mode.The next one we have,is a network DLP system.This is a piece of software or hardware,that's a solution placed at the perimeter of your network.It's sole function in life,is to check all of the data going into,and out of your network,with a special focus on things going out of the network.They want to detect data in transit,that shouldn't be leaving the building.The third type we have,is called storage DLP.This is a software that's installed on a server in the data center and inspects the data while its at rest, on the server.This is usually because they've encrypted it or watermarked it,and we want to make sure that nobody's accessing the data at times that they shouldn't be.For example, if someone starts downloading large amounts of data at two in the morning,that's probably against your policy,and the DLP could catch it.The fourth type of DLP, is a cloud-based DLP system.These systems are usually offered as software, as a service,and it's part of your cloud service and storage needs.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 15 today we are discussing about If you're like most people,at some point during your internet surfing,you've come across and window that has a pop-up jump up in front of your browser.Usually, this is something trying to grab your attention like an ad or something else that they want you to click on.Now, while this is annoying,it can also be dangerous to your machine.And we're going to talk about that in this lesson.First, let me mention that you can block a lot of these pop-ups.For example, in Google Chrome,if you go under Settings,there's a pop-up and redirect blocker that you can enable.While most web-browsers have started having the ability to block JavaScript created pop-ups,advertisers are constantly finding new ways of creating pop-ups using Flash and other technologies.Also, if you block pop-up windows,you may run into a problem because some legitimate websites need it as a way for their website to function.For example, I used to teach at a University that their payroll system used these pop-ups and they had to be enabled.If you didn't have them enabled,you couldn't see you paycheck stub.And that way, you couldn't see how much you were earning.So, while you had to enable pop-ups for certain websites,you probably shouldn't enable it for all websites.Now, another concern with these pop-up ads is that a lot of times, they're being done through ad distribution networks.And these are based on a pay per click model.Malicious attackers can purchase pay per click advertisements through these networks as well.And sometimes, they can embed either a link to their website or a link to malicious code.This can be a really big problem for us.And so, a lot of people have gone through and started blocking the ads completely.You can do this using something like Adblock.Adblock will go through the code as it's being delivered from the website server and go into your web browser and remove all of the advertisements.Unfortunately, there's a problem with using Adblock too.And that's that some websites you want to go to may not serve up content if you're blocking advertisements.A lot of websites are working under a free model and their advertiser supported.So, if you're blocking the ads,they're not making any money giving you content.And so a lot of them have coded it so they won't deliver the content you're looking for unless you turn off your Adblocker.Another thing you can do is use a content filter.Now, content filters will block external file types like JavaScript, images, or even web pages from loading in a browser.You might be familiar with content filters from your work environment.If you go to school or you go to work,they usually have content filters on their network.This prevents you from accessing certain types of websites that they deem inappropriate.This might be things like gambling or pornography or other types of websites that they feel are inappropriate or a waste of time in the workplace.These all get blocked by a content filter.So, in summary, there's a lot of issues when you start dealing with advertisements and pop-ups.Unfortunately, there's no single solution to this problem because if you block the ads or you block the pop-ups,you may not be able to use the function of the website you're desiring.The best defense against unscrupulous advertisers though,is to also ensure your browser and its extensions are updated regularly.This will be the best protection for you.You should then also disable pop-ups when possible and specifically allow only the sites you need and if it doesn't affect your web browsing ability,you might want to disable your advertisements as well using an Adblocker and thankyou...
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 14 today we are discussing about What is an IDS?Well, an IDS stands for the Intrusion Detection System.This is a device or a piece of software that's installed on a system or a network,and it will analyze all of the data that passes through it.It does this so that it can try to identify any incidents or attacks.Intrusion Detection Systems come in two different varieties,the host-based Intrusion Detection System and the network-based Intrusion Detection System.The first one we're going to talk about is a host-based Intrusion Detection System,also called an H-I-D-S.This usually takes the form as a piece of software that's installed on your computer or on a server and it will protect it.Now, the host-based Intrusion Detection System will sit there and log everything that it thinks is suspicious.We'll talk about what might be suspicious in just a moment.The second type is what's known as a network-based Intrusion Detection System,or a NIDS, N-I-D-S.This is a piece of hardware that's installed on your network.And all the traffic goes through that switch,and then it will get a copy of that sent down to the Network Intrusion Detection System.If it's suspicious, it'll log it and it'll alert on it.Now, how do we know what these systems will alert on?Well, they're going to use one of three different methods.They're either going to use signature-based,policy-based, or anomaly-based detection.Signature-based detection is where the system is looking for a specific string of bytes that'll trigger the alert.This works like any other signature-based product.This computer is going to continually search over and over for a known specific key.And any time it sees that combination of letters or bytes,it knows that it's malicious.It'll flag it and it will alert on it.The next type is what's known as policy-based detection.This is going to rely on a specific declaration of the security policy.For example, if your company has a policy that no one is allowed to use Telnet,any time this system sees somebody trying to connect on port 23, which is the port for Telnet,it's going to flag it,log it, and alert on it The third type is statistical anomaly-based detection. Often, this is referred to as just anomaly-based detection or statistical-based detection.This is going to analyze all of the current traffic patterns against an established baseline,and anytime it sees something that goes outside the statistical norm,it's going to alert on it.So if I've been watching your network for a while and I know what normal looks like,and everybody always works from nine in the morning until five in the afternoon,and now I start seeing somebody downloading large amounts of data around two o'clock in the morning,that's outside our normal baseline and we would flag that and alert on that.Now, speaking of alerts,let's talk about what these alerts me There are four different types of alerts.They're either true positive, true negative,false positive, or false negative.Now, a true positive means something bad happened and the system flagged it and alerted on it.That's good because it means our system is tuned properly.A true negative means something good or normal happened and the system didn't flag it.Again, that's good,because our system's working like it should.But when we get into something like false positives,this is where some legitimate activity is being as identified as an attack.For example, if you log on the computer and you start up Microsoft Word, that's authorized.But if the system thought that was malicious and flagged it and alerted on it,that's considered a false positive.Now, next we have what's called a false negative.This is when something bad happens but it's identified as legitimate activity.In other words, it isn't flagged and it wasn't alerted on.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 13 today we are discussing about firewalls and we will be talking about them from a network perspective where they were dedicated pieces of hardware that sat at the edge of your network and controlled what went in and what went out. we're going to talk about personal firewalls.These are software based applications that protect just a single computer or server from unwanted internet traffic.Now these are also referred to as host-based firewalls.These firewalls work by applying a set of rules and policies against traffic that's attempting to come into or go out of our protected computer.For example, if there's a computer that's a web server then it should be accepting incoming traffic on port 80 and port 443 but if it's a desktop computer there's likely no need for these ports to be left open.Instead, the firewall should reject any inbound attempts to access these ports.Because we're talking about software based firewalls we also have to consider what operating systems are being used whether it' Windows, Mac OSX or Linux.With Windows we have the windows firewall.With OSX with have PF and IPFW firewalls.And with we Linux we have iptables.First, let's discuss Windows.In every version of Windows, there's its own software based firewall already built in and available.There's usually two types included.One is a basic version that's found within your control panel and then there's a more advanced version called the Windows firewall with advanced security.This advanced firewall can accessed by typing WF.MCS at the command prompt.The basic firewall is useful for most home users,while the more advanced version is well suited for businesses and systems where more in-depth configurations of you inbound and outbound traffic is required.Next, we have Apple's operating system, the OSX,which has a built in software firewall for Mac users.A basic version of the firewall is accessed through the system preference panel under the security and privacy panel.In addition to the graphic user interface based firewall there's also a command line version. This version is called PF for packet filter.It's available is OSX 10.10 and higher operating systems.Packet filter is the name because it's essentially what a firewall is designed to do.It filters packets.In older versions of OSX there was a different command line firewall used called IPFW, which stood for internet protocol fire wall,but that program was replaced by PF for most modern versions of the OSX operating system.Both PF and IPFW are also used in the free BSD operating system,which is what OSX is actually based on.Just like Windows and OSX, Linux has its own built in firewall too.In Linux systems, this program is called iptables and can be configured from the command line using different accept and reject rules based upon the type of network traffic that's expected and the port being utilized for that communication.Besides these built in firewalls for each of these operating systems many anti-malware suites also have their own software firewalls included too.For example, if you're using Windows,you may have a firewall from Symantec, Mcafee,or Zonealarm.Software firewalls, like all software,does need to be updated though.All software is vulnerable to attack and therefore you need to ensure your host-based firewalls are regularly updated with service packs and software updates to ensure that they remain safe and secure.Some users don't like using host-based firewalls though because they do end up using some of your computer's processing power.This has to happen so that it can check all of that network traffic against each of the rules and policies that it's been assigned,Because of this some organizations instead like to rely on dedicated hardware and network based firewalls as their first line of defense.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 12 today I am going to give you a couple of tips on how to prevent malware from infecting your system.This includes malware like viruses, worms, Trojans,ransomware, spyware, rootkits, and spam.Let's talk about viruses first, viruses are most commonly detected using a good antivirus software.These can be either third-party solutions like Norton or McAfee, or using the included Windows Defender from your operating system.In addition to antivirus software,you'll also want to make sure that you're continually doing your service packs and updates for your operating system.Most viruses are going to infect you by taking advantage of some known exploit, and if it's a known exploit,your operating system vendor, like Microsoft,is probably going to already have a patch ready for you.If you don't patch your system,or update it and use those service packs,you're basically asking yourself to get infected.In addition to having a good antivirus software that's continually being updated,you also want to have a good host-based firewall that will help prevent outside people from connecting to your machine.Additionally, whenever you're surfing the internet,websites, this will ensure that there's no man-in-the-middle connection between you and the destination that you're trying to get data from.When we talk about worms, Trojans,and ransomware, much like viruses,these are best detected using anti-malware solutions.Now, ransomware is usually going to be detected,not in its fully ransomware form, but instead,through its delivery mechanism,which is most commonly a Trojan horse.Remember, it's always important to ensure that your anti-malware solution is current and up-to-date,both for its definitions and for its scanning engine.Spyware is software that's installed on your machine that snoops on you.It collects data and sends it back to its owners.Well, if you want to stop spyware,you need a good anti-spyware product.There are third-party ones available out there,but again, Windows Defender has this capability built in.Just like anti-malware solutions, you need to ensure that your definitions are up-to-date so it can scan and detect most types of spyware out there.Also, when you're browsing the internet,you want to make sure that your web browser's security settings are set to a non-trusted method,meaning that you have a very low level of trust for the sites on the internet.This will ensure that you don't accept cookies,that you don't allow pop-ups and other things that may get you more spyware installed onto your system.Now, how do you know if you've been infected with spyware?Well, there's a couple of common giveaways.The first one is if you see a lot of pop-up ads.If you're getting a lot of advertisements based on traffic that you've done in the past,someone is looking at your information somehow.That could be through spyware,it could be through cookies,or it could be through database retention settings on their side of the server.Additionally, another dead giveaway that you've gotten some adware or some spyware installed on your machine is when you go to your home page of your browser and it's no longer your home page.For example, if whenever you open up your web browseryou default to Google.com, and now,when you open up your web browser,you're seeing some other page,that means somebody has adjusted your web browser settings,and that could be a sign that you've been infected with some kind of spyware.Next, let's talk about rootkits.Rootkits are a type of malware that installs itself and tries to bypass the operating system functions,and it acts as a go-between between the operating system and the kernel.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 11 today we are going to discuss about Once you've identified that there's a symptom of malware that may be existing on your computer what should you do about it? Well, the first thing you should do is scan the computer to see if there's actually malware on it. In this case we have a virus that's been detected.How are we going to clean out that system from this virus or other types of malware? Well, before we take any action to try to clean up the virus we want to make sure we have a good backup of our current system. As we go through, we try to clean up the malware, we may have to change file systems. We may have to delete everything and start all over. We may have to change different configurations. And so making sure that we have a good backup of all of our files is critically important. The first thing we're going to do is identify the symptoms of the malware infection. What is your computer doing that makes you think that it's been infected? Have new files been created? Is the computer acting slowly?Do you have gibberish showing on your screen? Whatever the things are you need to notate that. And because that will help you determine what type of virus or malware has been infecting your machine. Next, we're going to quarantine the infected systems. Now what does that mean exactly? It means that we want to prevent this system from communicating with other systems so that the malware from this system can't spread to others.Most commonly we do this by turning off the network card or unplugging the network cable to remove your computer from your production network. The third step to removing malware is to disable your system restore if you're using a Windows machine. The reason we want to do this is we want to make sure Windows isn't continuing to take snapshots of our infected machine. This makes a lot of sense if you think about it. Let's say we go and we clean out this piece of malware and a couple of months go by or even a year and we have an issue with our system. We decide to revert to a good backup. And we end up choosing one of those snapshots that was taken while the malware was enabled. This is going to be a mistake that we did, but by doing so we're reintroducing and reinfecting ourselves. And for this reason we want to go and turn off our Windows Restore. Also, we want to go back and delete any of the snapshot that may have been taken during the time the computer was infected. The fourth step to removing malware is to remediate the infected machine. This includes updating our antivirus and anti-malware software on the machine, using its scanning capabilities, quarantining capabilities, and removal techniques to our advantage. Now what are some of these techniques? Well, this includes doing things like rebooting your machine into safe mode and going into a pre-installation environment and then running the scans from your anti-malware software. Now this is important because if you're using a normal Windows machine a lot of the files are in use when you're normally booted up. And so to remove that virus you need to make sure that that file isn't in use. But when you reboot yourself into safe mode, you're able to minimize the amount of files that are in use and allows the anti-malware solution to more effectively remove the malware much more cleanly. Our fifth step is to schedule automatic updates and scans. This will ensure that we've removed the malware and we can prevent it from coming back. The most common way of getting malware into your system is because you don't have an updated anti-malware solution on there.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 10 today we are going to discuss about Symptoms of Infection.How do you know your computer has been infected with malware? Well, the most common thing is to notice that it starts beginning to act strange. That could be a myriad of different things, though. For example, your computer might start running slower than normal.Why might this occur? Well, if you have a worm for example, it's using up processor resources and network resources to spread itself throughout the system and throughout the network. If you happen to be getting spam, that again is something that's going to tax your system. Lots of different malware will start making your computer act slower than normal. And this is one of the indications that you have a problem. Another symptom of infection is that your computer starts locking up or stops responding to you frequently. Maybe you're seeing more 'blue screens of death' than you've ever seen before. Well, this again is something that is a common symptom of malware. If a virus goes in and overwrites a critical system file by mistake, that can cause the computer to crash or lock up. This brings us to our third thing. If your computer restarts or crashes a lot, this again is another symptom that you may have a malware infection. Next, if your hard drive, files or applications aren't accessible anymore, this could be a symptom of a malware infection. Because if a virus or piece of malware takes over a file, it's going to change its permissions. And by doing that, it can remove your permissions that allow you to run it or delete it or change it. This is one of the ways that the malware will keep persistence in your system. Another symptom of malware is if your computer starts to make strange noises, or you start to see unusual error messages, or your computer, the display starts looking strange, or when you print something, it looks like gibberish or gobbledygook, and it uses symbols instead of normal letters. All of these things can happen when you get a virus or you get malware, depending on the way the virus or malware starts infecting your system. Another sign that you might have an infection is if you start to see new icons appear on your desktop or conversely, icons from your desktop start to disappear. Again, as any additional programs are added, new icons might show up, and if you start deleting programs, that can remove those as well. Another way that malware tries to hide itself when it's in your system is by using double file extensions. This is because in Windows, by default, if there's a know file extension, such as .exe for executable, or .txt for text files, that part won't be shown on the icon's name. So if you have something that says textfile.txt on your desktop, it could have a hidden .exe at the end of it. And when you double-click that file that looks like a text file, it's actually going to run this executable file. And that can actually embed malware into your system even further. Another symptom that you may have had something bad happen is if you try to run your antivirus software but it just won't run. A lot of malware is programmed to attack your antivirus software, and that way it can prevent it from running and maintain persistence longer. The reason for this is that malware doesn't want to be taken out of your system. And if you're able to run your antivirus you might be able to clean up the malware. But if they can attack your antivirus and keep it from running, that means that they can stay on your computer for longer and dig in deeper. Yet another symptom is when your files or folders are corrupted, or you may see new files and folders that have been created. Again, as a piece of malware goes and infects your files this corruption can make them be deleted, or it'll create new files for it to hide in.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 09 today we are going to discuss about Backdoors and logic bombs.A backdoor was originally placed in computer programs to bypass the normal security and authentication functions. Now, if this sounds like a horrible idea to you, it really is, and it's a horrible security practice. This is something that was originally created back in the 80's, by manufacturers and programmers as a way for them to get back into the system to do maintenance and repairs, without having to go through all the authentications and going through the firewalls and the layers of security that they would if they went in the front door. Now, this is a horrible and bad practice, and it should not be used in current networks. And these days, it's actually considered a breach of good, secure coding practices. But, back in the 80's and the 90's, and even into the early 2000's, backdoors were a commonplace thing that were put in by programmers. Now these days, most software does not have a backdoor. It's been patched up and cleared up because they know how bad these are for security. But, there is something that acts just like a backdoor. What do you think that might be? Well, it's a remote access trojan. A remote access trojan can be placed by an attacker to maintain their persistent access to your system. So if I'm able to trick you into clicking a spearfishing link, and then you install malware based on clicking that link, now I have something that can make a call back to me. That can give me that remote access. I have a way to bypass your system's natural security and use that remote access trojan as a backdoor, to gain access to your system anytime I want. Another insecure coding practice that was used by programmers is what we refer to as an Easter Egg. An Easter Egg would be placed in the code as a joke or a form of gag gift. Essentially, there would be different things that would happen in different video games, or different pieces of software when certain code was executed. For example, a few years ago, you could go to Google.com and type in do a barrel roll, and the whole page would do a 360 degree rotation as if it was doing a barrel roll in an airplane. There was no real function to doing that except it was a joke, it was a gag. It was a joke that Google programmers decided to put into the code. Now, Easter Eggs are generally harmless but they do add additional code, that can have additional vulnerabilities. The reason for this is because their code, because it's a joke, is usually put in at the last minute and it doesn't undergo rigorous security testing. Now, why am I talking about Easter Eggs in this lesson? Well, it's because it brings us up to the subject of logic bombs. Logic bombs are a descendant of those earlier Easter Eggs. But logic bombs were designed with malicious intent in mind. Logic bombs are malicious code that's inserted into a program, and it will execute only when certain conditions have been met. For example, a disgruntled employee may insert a logic bomb into the server's code so that if that employee isn't on the payroll anymore, a bad action, like deleting all the files, could occur. One of my favorite examples of a logic bomb actually comes from the movie Jurassic Park. In the movie, the park's programmer, Dennis Nedry, decides he's going to put a logic bomb into the power grid system, so that it will go off at a certain time.He does this so that when the power gets turned off by the logic bomb, he's able to sneak out of the room, go past all the alarms and get into the nursery and steal some of the dinosaur embryos. He thinks he's going to get off and sell those embryos and become a millionaire.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 08 today we are going to discuss about Active Interception and Privilege Escalation.What is active interception? Active interception occurs when a computer Is placed between your sending computer and your receiving computer.Because of that position it's able to capture or modify the traffic that's going between the two computers. Now what does that really mean? We'll let's take a field trip. You and I are going to go meet at the local coffee shop. You're going to bring your laptop and I'm going to bring mine. We order a cup of coffee and we sit down at the table and we connect to the wireless network. We think we're connected to Pete's Coffee or Starbucks, or whatever your favorite coffee shop is. But in actuality we're not connected to the coffee shop wifi.Instead, we're connecting to an attacker who's sitting in the back of the room with their laptop. This attacker has set up their laptop and is putting out a signal stronger than the coffee shop's signal. So our machines are connecting to them. Now whenever we're trying to go to the internet we're actually going from our laptops to the hackers laptop and from the hackers laptop out to the internet. To us it still looks like we're connected and we can go online and everything is fine with the world. But because of the placement of the attackers laptop in between us and our final destination they can capture anything that we're doing. They can see the emails that we're sending. They may be able to capture usernames and passwords. They may be able to modify what's coming back to us as well and embed malware into the files that we'd been requesting. That's what active interception is. It's when somebody gets in between you and the destination server and they can modify things based on that position. The second thing I want to cover in this lesson is Privilege Escalation. Now privilege escalation occurs when you're able to exploit a design flaw or a bug in a system to gain access to resources that a normal user isn't able to access. As an attacker, anytime I'm trying to break into a system I'm going to do that in a myriad of different ways. It may involve malware or a phishing attack, or an impersonation. Whatever the method is, most likely, I'm going to get into that system as a user, because I'm going to trick some ang user into doing something for me. When I do that, I now have user level credentials. But that's not going to allow me to do everything on the system that I want to do. My goal is to go from having that user level credential all the way up to administrative or root level credentials. To do that, I'm going to do a privilege escalation. There's a lot of ways to do a privilege escalation. Most of them involve exploiting some sort of bug in the software, the operating system, or the application and that let's me get closer to the kernel and being able to operate as an administrative or root user and stay tune for next episode and thankyou...
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 07 today we are going to discuss about Botnets and zombies. What happens to your computer if it becomes the victim of a botnet? Well, let's say that your computer has picked up some kind of malware and that malware, it's purpose is to change your computer into it's victim, into what we call a zombie. That's right, a zombie becomes part of the botnet and a botnet is simply a collection of compromised computers under the control of a master node. So, what does this really look like? Well, if your computer becomes a zombie, it becomes under the control of some attacker and that attacker has what they call the command and control node or C2 node. That command and control node controls not just your computer but hundreds or thousands or hundreds of thousands of other computers that are part of their botnet. What kind of things can these zombies do? Well, they might be used as a pivot point so that when they get a new victim, or if they're attacking a server, they can access it through your computer and it looks like you're doing the attack instead of the master node. They'll jump from their command and control node into one of the zombies and from the zombie over to the victim and they might go out and use those zombies to host files that are illegal, like child pornography so they don't get caught with them and all sorts of things like that. They may use them to spam other people and send out phishing campaigns and other malware or, most commonly, they can use this botnet to conduct a DDoS, a distributed denial-of-service attack. What exactly is a distributed denial-of-service attack? Well, a distributed denial-of-service attack occurs when many machines target a single victim and attack them at the exact same time. So let's assume that I'm the bad guy and I control a botnet of 100,000 machines and I want to go and take down somebody's website, I can make all 100,000 of my victims, my zombies, target that victim's server and make the request simultaneously. That type of load could end up forcing the web server offline, causing it to crash and not be able to serve its real customers. That is denying it the ability to do its normal functions or its service. That makes it a denial of service and a distributed denial-of-service is just that, it's the most common use of botnets and it's been that way for a long time but these days attackers aren't just doing it for fun and games. Instead they want to make money and so they're using zombies to do things that are processor intensive like bitcoin mining or other cryptomining on their behalf. That's right, when you have a botnet with lots and lots of zombies, you have a lot of processing power at your disposal because each of those machines can give you some of its resources and then they can work in a distributive manner. So, I can set them off and let them start mining coins for me and thankyou..
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 06 today we are going to discuss about Common Delivery Methods of malware and how do they get into your machines .There are number of ways that your computer can get infected with malware. But by far, the most common ones come from software, messaging, and media. Software and messaging are things like email programs, peer- to-peer networks like BitTorrent, FTP servers, and pretty much any other way that we communicate from one computer to another. When I'm
talking about media, we're talking about things like CDs and DVDs, USB thumb drives, external hard
drives, tape backups, and even old school floppy disks.Now, I know what you're thinking. vijay, I'm smart enough not to pick up some USB drive off the ground and take some disks that I don't know where they came from, and slide it into
my work computer.But guess what? This stuff happens every single day. Often it's because our human nature is to be nice,and we're trusting and we want to be helpful to people. So somebody comes over to your cubicle with a USB drive and
says, hey I got three minutes before I got to give this presentation.Can you please print out my slide deck for me? Will you take that and put it in your drive? Well, you might.A lot of people do.And when they do that, there could be
malware on that USB drive and we just infected the network. So, beyond plugging in a USB drive or a CD that you found on the floor, what's another place that you can get infected from? Well, there's a thing known as a watering hole.But
before we talk about in computers, let's talk about a watering hole in the real world. If you go to Africa, there's a lot of desert there, and the animals need water. And so when they find a lake or an oasis, the animals will gather
there and they'll drink the water, and then they'll go off and they'll do what animals do all day. And eventually they'll come back because they need more water again. And they'll do this time and time again. So watering holes are a
place that people have to return to,or in this case, animals.Now, what does this have to do with your business and with computers? Well, it's the exact same concept. There's a lot of us who have routine habits, where we do the same
thing day in and day out. And those places that we go are our watering holes. For example, every morning my friend gets up, he get a cup of coffee,he logs into Facebook and he starts scrolling his feed. For him, that would be a
watering hole.It's something he goes to every single day. Are there those type of things inside your business? Maybe there's a supplier that you go to every single day to check your invoices. Well, if you think about this, an attacker
can figure out where that website is that you go to every day. And if they can go and attack that company and embed viruses or malware into their website, when you go to the website to do regular work, like pulling your invoices,you
can also be pulling that virus. So their website now becomes a watering hole for malware.And the malware that sits there behind that website will get potential victims. Now, if they got your supplier and they got all the people who
visit the supplier,they can ultimately get you too. There are lots of things that can create watering holes for us.There's an automated toolkit called an exploit kit that makes this really easy to do as an attacker. Fortunately for us,
a lot of websites that are watering holes and places that we go every single day, are very well secured.
hello everyone my name is vijay kumar Devireddy and i am glad to have you back on my episode 05 Today we're going to talk about malware infections,malware doesn't just appear on your computer.It doesn't just show up out of thin air.Somebody has to deliver it somehow and install it on your machine.Malware can be delivered in lots of different ways,including through software,messaging and media,from a botnet or zombies.It can have activate interception that's going to put malware into your network,or it can have a privilege escalation.Where somebody goes from being a regular user to a super user and infects your computer.Also, there's back doors and logic bombs.There is a lot of different ways
to get malicious software onto your machine.In fact, one of the simplest delivery methods is when somebody has physical access to your machine and plugs in something like a thumb drive that's already infected.
So, when we think about malware there's really two pieces of how malware gets onto your machine.The first, is what we call a threat vector. A threat vector is the method used by an attacker
to access a victims machine.Some examples of threat vectors are unpatched software, installation from a USB thumb drive, a fishing campaign,where one of your users clicks on a link to install a program, and many other
different methods that are out there.After we figure out what the threat vector is the next piece is what we call the attack vector.An attack vector is the means by which the attacker is going to gain access to that computer,
in order to affect you with malware.Now I know these two terms sound very similar, but there is a key difference.A threat vector is how we get to the machine itself, but the attack vector includes both the way we got to the machine
and how we're going to infect it. Let me provide you an example,to hopefully simply this just a little bit.Let's pretend that your house is a computer and I have a cupcake that's going to represent malware.My job as the attacker
is to get the cupcake from my house to your house and put it on your kitchen table.Now, that's my goal, as the attacker.You are going to try and defend against it.The threat vector I use might be that I can drive right up to your house,because your house isn't inside a gated community and there's no security guards looking for me.This would be a threat vector, your unguarded neighborhood. Now if I walk up to your door,and I start picking your lock,
and I enter your house,and I place the cupcake on your kitchen table, this represents the attack vector.It's all the things I did from driving to your house, to picking your lock, and delivering that poison
cupcake onto your kitchen table.That's the difference between the threat vector and the attack vector.Now, let's go back to the world of computers for a moment. Let's pretend that you have an old computer
that's running Windows 7 and you haven't bothered installing or downloading the latest security patches, because you've just been busy and haven't had time. Well, maybe you haven't installed these patches,in quite a long while.
So you have a computer that's missing a critical patch, like the Microsoft 17-010 patch, which came out in 2017. This was an essential security patch for the Eternal Blue vulnerability, this is a threat vector.This is your un-patched computer, but I don't yet have an attack vector, not yet.Now, as an attacker, I'm sitting there and I'm scanning the internet. I'm trying to find unpatched computers and lo and behold I find your computer and I determine that it's
missing this critical patch and therefore, you're vulnerable to an exploit against your file and printer services, which are known as SMB. Once I run this exploit, I'm going to be able to gain access to your machine
and install some kind of malware on it.This series of events now becomes my attack vector.
hello everyone my name is vijay kumar devireddy and i am glad to have you back on my episode 04 well we had discussed about cryptography and how it helps us to protect the information in the internet world in this episode we are going to discuss about how it had evolved . for that we will jump into the history to know it briefly .
Sending secret messages has been a documented human activity for thousands of years. The earliest example I am aware of can be found in the bible, from approximately 2600 years ago. it was named as The AT BASH cipher which we call it as substitution ciper now in this Encryption works by substituting each letter in the alphabet by another letter.
Caesar’s Cipher Another substitution cipher from the ancient world is “Caesar’s Cipher”, named after Julius Caesar who used it in his private correspondence, about 500 years after ATBASH cipher. To encrypt a message with Caesar’s cipher, each letter is replaced by a letter 3 places earlier in the alphabet: “shifting back by 3” - so D becomes A, E becomes B, and wrapping around so A becomes X.
For many centuries cryptography was used quite extensively - as a “dark art”, employed by royals, diplomats, spies, and the military. It played an important role in many historical events. Probably the most famous in modern history is the story of the Enigma cipher used by the Germans in World War 2, and the allied forces’ success in breaking that cipher. This all changed in the 1970s. By then important and sensitive electronic communication systems emerged in the civilian market - most notably “Automatic Teller Machines” (ATMs) allowing cash withdrawals. Motivated by the need to protect civilian communications from criminals, the US standards body (which is now called NIST), realized that a cipher is needed to protect sensitive (but non-classified) information.
The result was the design, and public standardization, of the first civilian cipher, called the Data Encryption Standard (DES). DES was designed by IBM in the 1970s and became a US federal standard in 1977. and des was used for 30 years and later found it as vulnerable to protect the sensitive information with the modern technologies we will discuss this later
hello every one my name is vijay kumar deviredy and i am glad to have you on my episode 03 today we are going to disscuss about how to protect your information in the internet world
with the help of cryptography before going into deep let see where it is started with little drama.
In 1586, Mary, Queen of Scots,was convicted of treason against Queen Elizabeth.She was found guilty of plotting to overthrow the English monarch,and not long afterwards she was
beheaded.Did you know that the evidence that convicted her was obtained by the English spymaster's ability to break Mary's secret correspondence
with her supporters? What can we learn from this drama? Well, that you better know how to protect your secrets.
When we started discussing information security,
we learned that there are two types of parties involved. The defenders and the adversaries.we call it as attackers
The defenders have a variety of goals that they need to achieve,and the adversaries try to disrupt their efforts.
In this episode we will focus on the confidentiality defensive goal,and on attacks against it.
The techniques used to achieve both defensive and offensive goals belong to the body of knowledge
called cryptography.The word "cryptography" comes from ancient Greek, and translates to "secret writing".
Cryptography also includes solutions to more advanced goals, like digital signatures and key exchange,
which we will discuss in a later episodes which will be a continuation of this .The starting point of the confidentiality goal
is that our defender, who we shall call lara , has some secret information.But just having a secret
is not very interesting right.lara needs to send this information,as a secret message, to rakesh,who is also on
the defenders' side.The idea of a secret message implicitly introduces the adversary,who we shall call vijay.vijay can eavesdrop on the communications between lara and rakesh.
So, lara needs a wayto send a secret message to rakesh,in a way that rakesh will understand,but vijay will not,
despite the fact that vijay can hear,or read, the communicated message.In the 1587 drama,Mary played the role of lara,her supporters were rakesh,and Queen Elizabeth's spymaster played vijay,
To achieve their joint goal,lara and rakesh need to agree upon a special communication mechanism that is resistant to eavesdropping.
The mechanism lara usesto construct the secret message is called encryption.rakesh uses the inverse mechanism, decryption. Together, the encryption and decryption mechanisms
form a cryptographic primitive called a cipher.More specifically, a symmetric cipher.A cryptographic primitiveis a cryptographic capability, or mechanism,that can be used by itself,
and can also be used as a building block in a larger context.Symmetric ciphers are the firstcryptographic primitive we will learn about.
We will meet more primitives later in the continuation episodes. until then take rest and beaware about what we had discussed in episode and thankyou...
malware is short term of malicious software.
▪ it is kind of Software designed to infiltrate a computer system and possibly damage it
without the user’s knowledge or consent. we had different types of malware as well such as
• Viruses
• Worms
• Trojan horses
• Ransomware
• Spyware
• Rootkits
• Spam
Viruses o Virus ▪ Malicious code that runs on a machine without the user’s knowledge and infects the computer when executed ▪ Viruses require a user action in order to reproduce and spread • Boot sector o Boot sector viruses are stored in the first sector of a hard drive and are loaded into memory upon boot up • Macro o Virus embedded into a document and is executed when the document is opened by the user • Program o Program viruses infect an executable or application • Multipartite o Virus that combines boot and program viruses to first attach itself to the boot sector and system files before attacking other files on the computer • Encrypted • Polymorphic o Advanced version of an encrypted virus that changes itself every time it is executed by altering the decryption module to avoid detection
Metamorphic o Virus that is able to rewrite itself entirely before it attempts to infect a file (advanced version of polymorphic virus) • Stealth • Armored o Armored viruses have a layer of protection to confuse a program or person analyzing it • Hoax
Worms o Worm ▪ Malicious software, like a virus, but is able to replicate itself without user interaction ▪ Worms self-replicate and spread without a user’s consent or action ▪ Worms can cause disruption to normal network traffic and computing activities ▪ Example • 2009: 9-15 million computers infected with conficker .
How many types of hackers we have white hat,balck hat, blue hat, elite, script kiddie and what they do with your information ??