Wednesday, September 19, 2018
Tuesday, August 20, 2013
Thursday, August 9, 2012
Near Field Communication (NFC) Attack
Most attacks to user systems (laptops or mobiles) are usually a result of some user action like opening an email attachment, surfing to malicious websites, downloading malicious files or accepting bluetooth messages. But now a user can be attacked WITHOUT DOING ANYTHING. This is with the help of the new technology "Near Field Communication" (NFC) that an attacker can use to instruct someone's mobile device to open the web browser and go to an attacker specified web link. Unlike other attacks where the attacker may be sitting miles away or even a few meters away in case of bluetooth, here in the case of NFC the attacking device has to be in very close proximity (a few centimeters) probably touching each other.
If you are hearing about NFC for the first time, it is a new standard for radio communication between mobile devices touching each other or being at a very close proximity. It is available today in many handsets from major vendors like Nokia, Blackberry, Samsung, Motorola, LG etc. NFC can be used to make payments by swiping mobile device at stores, buying train / bus tickets or just sharing information with friends by bumping phones.
A well known security researcher Charlie Miller has figured out a way to break into some devices like Google/Samsung Nexus S and Nokia N9 by means of NFC, this was demonstrated at a recent Black Hat Conference. According to NFC Forum there is no inherent flaw with NFC, however implementation issues need to be addressed as attackers can exploit operating systems and applications that implement NFC like the Android Beam and Nokia's content sharing and Bluetooth pairing.
We need to wait and watch for more security vulnerabilities related to this new technology.
For more reading on this topic:
http://www.networkworld.com/news/2012/072612-researcher-wows-black-hat-with-261162.html
http://www.informationweek.com/byte/news/personal-tech/wireless/240004386
http://www.nfcworld.com/2012/08/01/317100/forum-responds-to-black-hat-presentation-on-nfc-vulnerabilities/
Nitin Gaur scores 95% in CCSA R75
Nitin wins a 50% discount on CCSE R75 training fees for any batch at K-Secure Mumbai in 2012
Some tips from Nitin
Saturday, March 31, 2012
Check Point CCSA R75 exams
Congratulations Anand and all others who have passed the exam
Quick Tips on passing CCSA R75 exam
Based on the feedback we received from our students who passed this exam, here are some tips to be noted.
- Take a proper training
- Study from the official course material thoroughly
- Use the practice tests available from Check Point and other sources
- Additionally read about Identity Awareness from product manuals
- Also ensure that you make proper notes on the VPN fundamentals which is covered at K-Secure trainings. If trained elsewhere, refer to some white papers on IPSec VPN standards
- Before registering for the exam, take the K-Secure's online practice test to find out where you stand
Saturday, March 17, 2012
Article on ethical hacking

Thursday, January 12, 2012
See the face of a botnet master and his BMW
Dancho Danchev exposes the master of Koobface (anagram of Facebook) botnet
See his blog post here :http://ddanchev.blogspot.com/2012/01/whos-behind-koobface-botnet-osint.html
Thursday, December 15, 2011
50% off on Check Point exam re-takes
To encourage and support your certification goals, Check Point has implemented automatic 50%-off re-takes for the following exams at Pearson VUE
CCSA R71
CCSE R71
VSX
CCEPE
CCSA R75 (coming soon)
CCSE R75 (coming soon)
Note: All R70 exams will be retiring on 31 December, 2011
Tuesday, November 15, 2011
Inspecting HTTPS traffic on gateways
INTRODUCTION
In the past, security devices inspecting application content for attack patterns, misuse or malware, had been blind to encrypted traffic and due to this encrypted protocols like Hypertext Transfer Protocol Secure (HTTPS) have been a safe method used by attackers to bypass security inspection. Though reverse proxies and Web Server modules have been there for long, but they only inspect incoming traffic i.e. connections made to protected web servers in the organization. Inspecting outgoing traffic or traffic of connections made by users to outside world servers, not protected by the device, had been on the wish lists. Devices these days come with the capability to inspect Secure Sockets Layer (SSL) based outgoing traffic, however there are some concerns enabling such kind of inspection. In this article we cover some basics of SSL, the challenges in inspecting SSL traffic, and also see how Check Point's HTTPS Inspection feature starting from R75.20 is able to inspect HTTPS traffic at the gateway. After reading this article you will know the pros and cons of enabling SSL inspection on a gateway.
Read further or download the entire document in PDF format below:
Inspecting HTTPS Traffic on Gateways
Friday, May 27, 2011
SPG - informal meeting
Saturday, February 26, 2011
Hackers meet at Nullcon 2, GOA
2.4 Million email account passwords leaked
Hackers have got 2.4 million email account passwords of gmail, hotmail, yahoo, live etc. The no. is expected to go up to 24 mil soon and as this is not likely to be the result of compromising all the providers at a go, hence it seems to be data from 3rd party sites in possession of the password. If you like to see if you are one of the victims, you can check your email id here - http://dhamaka.nullcon.net
Saturday, December 11, 2010
Writing Snort Rules
Writing Snort Rulesby Kishin Fatnani
Snort, as you would know, is a tool used to detect intrusions on a network. Though the tool can also be used for packet logging, sniffing or as an IPS, however in this article we will look more into the concept of rules by which Snort detects interesting traffic for us, basically the kind of traffic we are looking for, like a network attack, a policy violation or may be traffic from a network application or device that you are troubleshooting. For instance, if someone is doing XMAS port scan to our network using nmap with the -sX option, Snort will give us the following alert message.
[**] [1:2000546:6] ET SCAN NMAP -f -sX [**]
[Classification: Attempted Information Leak] [Priority: 2]
10/15-08:51:46.970325 192.168.0.111:62202 -> 192.168.0.1:132
TCP TTL:53 TOS:0x0 ID:28031 IpLen:20 DgmLen:40
**U*P**F Seq: 0xD70FB1F3 Ack: 0x0 Win: 0x800 TcpLen: 20 UrgPtr: 0x0
[Xref => http://www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/SCAN/SCAN_NMAP][Xref => http://doc.emergingthreats.net/2000546]
If the use of P2P or IM applications is against the corporate policy, Snort can detect their use on the network and provide alerts with messages similar to these:
To read the complete article, download the magazine from here:
http://hakin9.org/magazine/1576-hakin9-starterkit-snort-exposed
Monday, December 6, 2010

Interest in information security or may be hacking seems to be really growing in India. Immediately after the first malware conference ended in Mumbai, another conference 'ClubHack' commenced in Pune. ClubHack is not new, it is India's first hacking convention and this was their 4th year. It's one of my favourite events and I make sure to attend every year, however this year I could just attend the technical briefings and missed the workshops and panel discussions.
The briefings surely had enough of good quality stuff to make it worth travelling all the way to Pune. It was great to learn about Android issues from an expert who has developed the most popular Android app 'Antivirus Free'. The session on Firefox security was also an eye-opener making us understand how easy it was to write a malicious extension for the browser and even easier was their installation. Another interesting presentation was about cloud computing for forensics in which it was demonstrated how to make the time consuming tasks in forensic analysis quicker and that to at a highly reduced cost.
Rohit and his team have been doing a fabulous job of conducting the conference each year and regularly publishing the ClubHack Magazine.
Saturday, December 4, 2010

'Malcon' that is the name of the first ever malware conference which was held in Mumbai in Dec 2010. I was very excited when I heard about this conference and immediately decided to attend this. The number of people that showed up for this conference were beyond my expectation and surprised me a lot, though it can in no way be compared with the crowd I've seen at DefCon, however as a new comer it was a great success. The audience was a mix of students, security pros, government officials, teachers, cops and may be the real bad guys too. There were a couple of pre-conference workshops, of which I attended the malware analysis by Atul Alex. It was good to hear all the low level stuff like assembly instructions, opcodes, interrupts etc and see a demonstration of writing malware.
Atul Alex also presented a paper in the conference which was about taking over control of Symbian phones which was an eye opener. The other presentations were also quite good and so was the panel discussion at the end of the conference. One of the panelists was Alok Vijayant, Director NTRO who has been backing the organizers of most of the security conferences and encouraging the young Indian hackers. He believes that having the best protection is not just enough but we also need to have the capability to attack back. The conference has done a good job of making people aware of the malware capabilities and how it is created, there is also a threat of people getting the wrong message or misusing their skills. It is actually debatable whether such conferences will help the nation by spreading awareness and have better skills or creating more malware making it difficult for the entire world to cope with. Well I would hope for the better but it will have some kind of side effects too.
During the panel discussion, a teacher stood up and said that now she can give a Green signal to her students to GO AND HACK, though the panelists explained her the right way to go about it. There was another interesting question about reporting a vulnerability on some government website, if someone finds a vulnerability on a website that means he might be trying to attack the site or must have done something which he was not supposed to be doing, in that case will he be arrested for the misconduct or awarded for reporting the bug. An example of the EVM machines was given by the participant. Taking the case of downloading data using SQL injection, which was mentioned by the participant, the panelist answered that if he downloads the data then he is at fault so he can just report the SQL injection vulnerability. This seemed perfectly fine to me while i was there but then I thought if he was testing a DoS attack, it can be detected only if there is actually a denial of some service, unlike SQL injection where an alert message will prove that the vulnerability exists. What will happen in that case?
Well to end this note, I would just say Malcon was great, I enjoyed being there and I hope we see it happening every year and growing always. I also hope that the government always supports such events and hope Alok is always part of it.
Friday, November 26, 2010
New Check Point Provider-1 courseware
Monday, November 15, 2010
Launch of Packet Master
Monday, October 25, 2010
Learn how to analyze and craft packets
The skill of analyzing packets is the most essential skill required if you are a pentester / ethical hacker, a network or security administrator, intrusion analyst, forensic analyst, application security tester, researcher of vulnerabilities, or you deploy or audit firewalls and IDS, or you write custom IDS signatures. If you already acquire the skill to analyze packets, learning Scapy would just do wonders in doing your job much more efficiently and making your organizations more secure.
K-Secure's Packet Master training program would be a great help if you:
- Want to audit or test your firewall rules
- Do pentest on networks or applications
- Like to test if your IDS signature / rule works
- Wondered if your pentesting tools like nmap, arpspoof, hping etc. can give you more control and information





