Wednesday, June 21, 2023

The Importance of Cybersecurity Certifications: Building a Strong Foundation in the Digital Age

 Introduction:

In today's interconnected world, where cyber threats are increasingly sophisticated and pervasive, organizations and individuals alike are recognizing the critical need for robust cybersecurity measures. As cyber attacks become more prevalent and damaging, the demand for cybersecurity professionals with relevant skills and knowledge is soaring. In this blog post, we will explore the significance of cybersecurity certifications and how they can empower individuals to build a strong foundation in the field of cybersecurity.


Understanding the Landscape of Cybersecurity Certifications:

Before diving into the details of various certifications, it's important to understand the cybersecurity certification landscape. There are several reputable certification bodies that offer a wide range of certifications, such as CompTIA, (ISC)², ISACA, EC-Council, and more. These certifications cover various domains within cybersecurity, including network security, ethical hacking, incident response, risk management, and governance.


Enhancing Knowledge and Expertise:

Cybersecurity certifications provide a structured learning path that covers essential concepts, techniques, and best practices in the field. They offer comprehensive training and resources, allowing professionals to develop a deep understanding of cybersecurity principles and methodologies. By pursuing certifications, individuals can expand their knowledge base and stay up-to-date with the latest industry trends, emerging threats, and evolving technologies.


Validating Skills and Competencies:

One of the primary benefits of obtaining cybersecurity certifications is the validation of skills and competencies. Certifications serve as tangible proof of an individual's expertise and demonstrate their commitment to the cybersecurity profession. They provide employers and clients with the assurance that certified professionals possess the necessary knowledge and skills to protect sensitive information, secure networks, and mitigate cyber risks effectively.


Career Advancement Opportunities:

Cybersecurity certifications significantly enhance career prospects for professionals in the field. As the demand for skilled cybersecurity experts continues to rise, many organizations prioritize hiring candidates with recognized certifications. Certifications act as differentiators in a competitive job market, increasing the chances of landing desirable job roles and promotions. Furthermore, certified professionals often command higher salaries due to their specialized expertise and industry-recognized credentials.


Industry Recognition and Credibility:

Certifications from reputable bodies are widely recognized and respected within the cybersecurity industry. They enhance an individual's professional credibility and reputation, opening doors to networking opportunities, speaking engagements, and collaborations with industry peers. Certified professionals gain access to exclusive communities and forums, enabling them to exchange ideas, share experiences, and stay connected with the latest industry developments.


Compliance and Regulatory Requirements:

Many industries, such as healthcare, finance, and government, have specific cybersecurity compliance and regulatory requirements. Cybersecurity certifications often align with these industry standards and frameworks, making them essential for professionals working in regulated sectors. By obtaining the relevant certifications, individuals can demonstrate compliance with industry-specific security standards and contribute to maintaining a secure digital environment.


Final words:

In an era where cyber threats pose significant risks to individuals, organizations, and societies, the importance of cybersecurity certifications cannot be overstated. These certifications provide a structured learning path, validate skills and competencies, enhance career prospects, and establish professional credibility. By obtaining cybersecurity certifications, individuals can build a solid foundation in the field and contribute to the collective effort of safeguarding sensitive information and maintaining a secure digital landscape.

Remember, cybersecurity is an ever-evolving field, and continuous learning and professional development are crucial to staying ahead of emerging threats and technologies. Invest in cybersecurity certifications to continuously update your skills and knowledge, and position yourself as a trusted expert in this critical domain.


Sources:

CompTIA: https://www.comptia.org/

(ISC)²: https://www.isc2.org/

ISACA: https://www.isaca.org/

EC-Council: https://www.eccouncil.org/


PS: This post is for providing basic idea about cyber security certifications and not recommending any specific certification

Wednesday, August 2, 2017

Blue Whale - A Game


            In this cyber world, everyday there is a sensational news. Ransomware, Malware, Data Leak, Company Hack and so on. Today there is a most sensational news came up that is related to Cyber bullying. Cyber bullying is the mechanism of targeting one through social media or computer and make them feel depressed or giving mental torture. The news that came today is just about a game. Yea its just a game.

            The game is actually like a dare game, you will be given with tasks to complete and send proof to your assigned curator. 50 tasks, 50 days thats it. The last task that is 50th task is KILL YOURSELF. It is real that many committed suicide, a teenager from Mumbai committed suicide who is a school going boy.

             The game is #Bluewhale and it has been there since 2013 hosted in Russian social networking site. It is an app now one can download the app to play, first the app will throw you a warning "Do you really want to play? If you start, there is no going back". If the player replies YES then a link will be sent upon clicking a new curator will be assigned. Tasks will start coming everyday. Initial tasks are acceptable but as moving ahead the tasks are like

Cut your lips.
Hurt you and make yourself sick.
Cut your body at various places.
Last but not least 50th task - Kill yourself by jumping from building or going under train like that.

              Ok what if the player is not accepting the tasks, he / she will be given a warning "All your information are with us we will kill your family members" Its like a blackmail from that point and initial term is that you should not disclose about this game to anyone.

              According to many sources, the link sent by them during curator assigning is a malware link and collecting data from the mobile and also it is a spyware that track victim activities.

              Many posted blood pictures, hand cut, lip cut and many more. After the guy suicide in Mumbai it has become a serious issue and need to be addressed. Instagram restricting viewing of hashtag #bluewhale and #blue_whale by showing a warning "It may contain irrelevant post" and also there is a override button by which you can view the posts anyway if you wish.

               The below screenshot consists of few sample tasks



                     Nearly 130 people committed suicide till date as per many sources and users are requested not to play the game or to download the app that may cause damage to user directly.

P.S: The post is to create awareness only and author of this post is not responsible for any damage if occurred. Be cautious and never ever try to play the game out of curiosity.

Thursday, June 1, 2017

Mining Cryptocurrency.


          After the cyber attack #Wannacry, it is not ransomware that hit people a lot but also Bitcoin. Earlier post was just a walkthrough about cryptocurrency. Let's have a detailed look about mining cryptocurrency.

          Cryptocurrencies are distributed and maintained by peer to peer concept across globe. There are many coins for which the source is also available. More famous coins are Bitcoin, Litecoin, Dash coin, Zcash and Ethereum. All transactions made using cryptocurrency must be validated by someone (node in network) so that no fake transaction will be carried out (Think of forged cheque).

            For validating the transaction a hash must be cracked. For those who has no idea every transaction will have a secret number hidden in the form of hash, one who cracks the hidden number gets rewarded. The reward is the cryptocurrency. Cracking hash requires enormous amount of computing power since it is purely a brute force analysis.

            There are three types of mining: Pool mining, Solo Mining and Cloud mining.

Solo Mining: If you crack a block using your resource you will get a bulk reward, but the probability is very low and if you use low computation machine even after 10 years you won't even earn a penny...

Pool Mining: Preferred by many since we can get a routine income based on your computation power, the greater the computation power the greater the reward, but it involves pool fees that has to be paid.

Cloud Mining: For those who cannot afford for resource they can get the service and get paid for what package they choose during subscription. Imagine it as Azure or any other cloud where we pay for what we use.

           The transaction that needs to be validated are in the form of block. A block can contain more transactions. Each time you crack a hash, difficulty of hash increases, so if you maintain same resource but peers across globe are updating their resource then your earning will drastically fall.

           Earlier days people used Computer CPU to mine, then they started using GPU which is more powerful than CPU and there are now many ASIC (Application Specific Integrated Circuit) available for mining which are capable of only mining, they cant do any other job.

           Can you imagine what is the world power used for Bitcoin mining... Its 1.4 PetaHash/Sec.. World power changes from currency to currency. Mining is not illegal but holding cryptocurrency is illegal in many countries.

            Almost entire Darkweb is driven by Cryptocurrency only and there are also many exchange service available which will take your cryptocurrency and pay you equivalent real money. If you are having any question or suggestion you can post a comment.

P.S: The post is to create awareness and not to create any negative impact.

Friday, May 26, 2017

Cryptocurrency - A small walkthrough.


          Everyone must be knowing about cryptocurrency by now, atleast heard of Bitcoins. It is the currency that acts as  ransom for mostly all ransomwares available. Let's have a short walkthrough about cryptocurrency.

          Consider INR, they are issued by Reserve Bank of India and they regulate amount of currency that is in circulation, whereas these cryptocurrencies are not owned by any Government or Bank, they are decentralised.

           Ok you are telling me it is decentralised then how someone is telling i own this much bitcoin? All transactions are managed by ledgers. If you are sending money to me it will be marked in ledger. Ok who owns the ledger? There are millions of nodes (Computers) having the ledger across globe, one entry made to the ledger will be updated in all the ledgers available across globe.

           What are all the ways to own cryptocurrency?

1. You can purchase it with real money.

2. You can MINE it.

           Second choice is preferred by many.. but i am not gonna deal mining topic due to some reasons...

           Can i exchange bitcoin if i mine or buy in future to real money? Yes you can for sure unless you forget your wallet id and Government don't ban exchange services..

           Is cryptocurrency safe? Since there is no centralised party and its purely machine dependent one can't provide 100 percent safety but it is safe..

          Is there any coin other than Bitcoin? There are many many coins like Bitcoin...

         Any other doubts or comments or suggestions.. mostly welcome. Thank you

P.S: This post is to create awareness only and not to create any negative impact.

Should I know about Wannacry ?


           Its been a long time since i blogged. Time to continue again i guess due to the havoc created by the latest virus or malware or to be specific ransomware. You got it... #Wannacry Ransomware.

           Ransomware is not new to cyber world it has been there for atleast 3 years. By this time I am sure all must be knowing about working of ransomware and its impact towards data.

            If you are affected by Wannacry Ransomware.. you must be thankful since it is just first alarm for cyber warfare, make sure you are safe hereafter by making some changes. Anyhow one cant be 100 percent safe but can recover fastly.

            Steps to follow to avoid ransomware attack is as follows

1. Backup! Backup! Backup!... Oh wait dont copy data in internal hard disk. Do it with external HDD

2. Get a paid.. you heard paid.. not cracked Antivirus

3. Update! Update! .. Update your Windows or any applications you use. If you know Microsoft released patch for this vulnerability before itself those who failed to update are the victim.

4. No one in cyber world is so generous to give you free offers or say 1 crore through mail which you are not even aware of.

             I know this post is too late for wannacry ransomware but one can prevent future attacks if they take actions now. 

P.S: This post is to create awareness only and not to be missued.

Tuesday, October 25, 2016

WhatsApp Video Calling.


         WhatsApp being one of the most commonly used application across globe. It almost replaced the traditional message feature available in the phone and now after the launch of the calling feature many are using it. Recently WhatsApp announced a new feature.

          WhatsApp being one of the End to End Encryption enabled application have billions of users. Now WhatsApp released the video calling feature to all its users with End to End Encryption.

           This feature is available in the beta version so one has to register themselves as a beta tester and then can update their application through Play Store. Other way around is to use the APK Mirror of the WhatsApp beta version and use it.

             To use Video Calling feature one has to press the same call button upon which the user will be provided with Voice Call, Video Call option and it is mandatory that the other use should also use the updated version to support voice call, otherwise it will throw an error.

             There are many malicious APKs emerging to fool people it is highly recommended to download or update the applications using Play Store or download it from the official site.

P.S: The post is to create awareness and not to be misused.

Wednesday, October 19, 2016

Amazon Offers, Free Wifi, Lucky Prizes.


             Before proceeding to the post it is the name of the post that attracts many and made them read the post to grab some offers or free wifi. It is the root cause for losing your private details (Passwords, Bank Account Number etc.). There has been a rapid increase in the number of cyber crimes recorded these days and they are not due to computer error but purely due to the user's mistake.

              One such this that attracts everything is FREE OFFERS, In India Amazon has introduced Diwali Sale and its on full speed. Recently there has been a scam that is circulating around social platforms. You can see the picture below


                 The above link has a cloned site of Amazon.in where the users will be asked to enter the card details for the payment and then users card details are abused.

                 Another strategy is that to steal the credentials of Amazon website users it is accomplished by the following mail


                   This mail is one of the awesome work you can see the same amazon.com without any mistake. The only this is HTTP not HTTPS but the real site is something else which is hided within this link.

                   Why stealing card details indirectly lets steal it using their bank site. You wanna see that too ?



                    All the mistakes has been pointed out by one of the researcher. Upon clicking the link will steal your bank credentials.

                     Oh man come on lets install a malware in the victim's mobile so that one can monitor his/her activities 24*7. Wi-Fi is one of the essential thing everyone needed so just exploit them



                      Worst case, everyone is addicted to money so why cant steal the credentials by fooling them by telling one that you won huge money.


        

                   The pictures posted in this blog are pure malware and everything has been validated. The intention of the post is to avoid users from losing their credentials or information to these fake materials.

P.S: The post is to create awareness and not to create any negative impact.

Thursday, October 6, 2016

Secret Conversation on Facebook Messenger.


            Eavesdropping and spying is one of the most common issue in Cyber space and many people are concerned about their privacy. Cryptography solves this problem to atmost extent by providing Encryption. Recently another giant rolled out Encryption feature.

             Apple incorporated End to End Encryption in iMessages, then WhatsApp rolled out End to End Encryption for its users. Now Facebook messenger supports End to End Encryption for its users.

             It is labelled as "Secret Conversation" in Facebook messenger and users with updated app version can use this. To enable End to End Encryption 

             Open Existing Conversation and click on Information icon and enable "Secret Conversations". Once enabled the chat is Encrypted on channel. One thing to be noted is you cant send gif, video through Secret Conversations.

              Another thing is that these providers are storing the Metadata about the chat which will be revealed when law enforcement asks for it. 

               The End to End Encryption on Facebook messenger is based on Signal Protocol. If you are so keen that not even your metadata should be revealed then you have to use Signal app which provides more privacy than these applications.

P.S: The post is to create awareness and not to create any negative impact.

Tuesday, October 4, 2016

Hack a computer with an image.


        Taking control over computer is a real time challenge for hackers these days. Hacking a computer is a tedious job if configured properly but the only way one can gain access is to use the well known weak link.

         Users are considered to be the weakest link in the cyber domain because one cant change the functionality of the system if configured well and in operation, whereas user who operate the system can do anything and has no restrictions.

         There is a separate section known as Social Engineering which exploits human trust and therby taking control over computer or device.

         Consider you are receiving an email stating "You have won 3.5 crores as prize and to redeem fill the form" 5 out of 10 will give away details as per survey conducted. Even a blank PDF file can be a malware in cyber space.

          It is now JPEG as it is easy to transmit and easy to fool users. Using malicious JPEG an attacker can take control over your system. Best way to spread Ransomware is to send malware through email attachment.

          Many are falling to Ransomware these days it is recommended to have a backup of files always. Use offline storage or Cloud storage to save sensitive data. 

          Users are recommended not to open email from unknown sources and simply delete them if it contains any attachment in any form (PDF, JPEG, DOC). Even a doc file with macro enabled can harm your system.

P.S: The post is to create an awareness and not to create any negative impact.

Wednesday, September 21, 2016

Using RAM booster for Android Mobiles.


        Android being one of the largest smartphone operating system is used by many people across globe. Millions of applications are there in Android Play Store and many of them are commonly used by many people. One among them is RAM booster or Cache Cleaner applications.

       In this blog post I am going to discuss the findings of one such common application used by almost more than 50 million users across globe. It falls under RAM booster category and cleaner application.

       One thing that has to be made clear is that Android has good RAM management and cache management program. Almost all the devices comes with average of 2 Gigabytes of RAM so there are 2 Gb available for applications.

       Unused RAM memory is Wasted memory according to many researchers. Ok lets see the functioning of any RAM cleaner application.

        Consider you are running a RAM cleaner application, it will kill the application that is dormant and also delete cache files. After that a nice GUI will tell you that almost 300 Mb has been restored. Ok in background after quitting the application or after the cleaning the application that has been killed will be again assigned to RAM and will create all deleted files again which takes more resources than before.

        Some applications will have cache files with some important data before saving in DB file or in backgorund file before that running RAM cleaner may delete the files and the application if required will download data from Internet which costs Mobile Data.

        Another nice thing is while analysing I came across an application that upon opening sharing IMEI number, Mobile model, Phone Build, Brand Name, Carrier Name and many more to famous Advertising company. 

         As a final thing using these types of RAM cleaner or Cache Cleaner will only take more resources and drain your battery and also may steal your details about device. Think before using it next time.

        For security reasons I am not disclosing the application name, here RAM cleaner referes to normal cleaner application. 

P.S: The post is to create awareness and not to create any negative impact.

Monday, September 12, 2016

Hack Windows / Mac Login Password using USB.


           It is not the new story that the USB drives has been used to steal credentials. There has been USB drives that explodes when connected and there are drives that will steal the credentials when plugged in. Recently yet another evil USB has been developed by a researcher.

           A security researcher developed a USB drive that will identify themselve as a network gateway and also as DNS server using the ethernet port. USB drive in USB port will have some restrictions before loading but the ethernet port will be whitelisted in the machine for sure.

           The device dubbed as evil USB upon inserting in the ethernet port will identify itself even the computer is locked out and then the drive will try to sniff the hashed credentials and stores them in the SQLite Database.

           After that the database entries can be cracked to find the password stored. The researcher tested this in many versions of Windows machine and also Mac running EI Captian and also Mavericks. 

           The only limitation for this attack is that the attacker need to have physical access to the computer for almost 13 seconds.

P.S: The post is to create awareness and not to create any negative impact.

Wednesday, August 31, 2016

1.9 Gbps Internet Speed in 4G.

             
             Internet has become one of the basic element of life and it is a backbone for many industries. Internet Speed is the major factor that determines the quality for any ISP. Recently an ISP has made a record breaking speed in 4G network.

             Top speed achieved in 4G network as of now is 300 Mbps but ISP named #Elisa, Finnish ISP with the help of Chinese technology Huawei achieved 1.9 Gbps (Gigabit per second) in 4G network.

             Actually the top speed achieved in 5G network is 1 Tbps (Terabit per second) by researchers from University and International Telecommunication Union achieved 20 Gbps in 5G network.

             Vodafone Germany is also planning to offer 1 Gbps by the end of 2016. It is stated that using Elisa the real time maximum possible speed is 450 Mbps where existing is 300 Mbps.

             It is to be noted that using Elisa 4G network one can download a Blu-ray film in the time period of 40-45 seconds.

P.S: The post is to create awareness and not to create any negative impact.

Friday, August 26, 2016

WhatsApp to share Data with Facebook.


             WhatsApp one of the famous application used for messaging introduced End to End Encryption for all the users to maintain confidentiality for the chats. Recently they have decided to share the data with Facebook.

            Facebook acquired WhatsApp before and at that time WhatsApp stated that they will not share the data with their Parent company Facebook and will maintain user privacy but now the company has decided to share the user data with Facebook.

           Since they have implemented End to End Encryption no user data that are sent such as text or media files can be shared as they are encrypted, they can share contact number and other information. Parent Company Facebook inturn may sell the data to the advertisers to target users with targeted Ads.

          All users who updated WhatsApp application will be pushed with Agree to License Agreement which automatically gives permission to share your data with Facebook. Those who has done that may opt out of that feature within 30 days.

          To stop sharing of data go to Settings -> Account -> Uncheck the checkbox with text "Share Personal Info". This will popup a message and click Dont Share to stop sharing of data with Facebook.

          There are many other applications that provide all and more features than WhatsApp like Telegram and Signal. 

P.S: The Post is to create awareness and not to create any negative impact.

Friday, August 19, 2016

Microsoft Open Sources PowerShell.


          Microsoft has been slowly moving towards Ubuntu and Open sources these days. Recently there is a big move made by Microsoft. They have Open sourced the PowerShell. 

          Almost all kernel has a shell to interact with. In Windows based we have Command prompt as CLI utility and all Ubuntu based will have Bash (Bourne Again Shell) to interact with. In addition to Command prompt, Windows also has a powerful utility known as #PowerShell.

          PowerShell is a scripting language that is mostly used by power users such as administrators and other users to automate kernel tasks. One who masters PowerShell can unleash the real power in Windows Kernel.

         PowerShell is based on .NET framework and all the commands executed will return an object. Recently Microsoft open sources Powershell by making its source code to GitHub under permissive MIT license.

         They have made the binaries available for CentOS, Mac OS X, Linux kernels and Red Hat platforms. They have made the version of PowerShell based on .NET Core which is a cross platform so as to run on both Linux and Mac.

         It has been released as a community based and alpha version. The official version is yet to be released by Microsoft.

P.S: The post is to create awareness and not to create any negative impact.

Wednesday, August 17, 2016

Google's Video Calling App - Duo.


            It has been already posted that Google is about to roll out two apps in the name #Allo - Smart messaging application and #Duo - Video calling application. Recently they rolled out the Duo application for both Android and iOS users.

            Google rolled out the new application Duo that is for video calling. It uses only the mobile number to activate and it also displays the username based on the contacts saved in the mobile. It uses #End to End Encryption to avoid any attack in between.

             Duo is also powered with a feature known as #knock-knock by which the recipient of the call will get the video feed of the caller before even answering the call in the locked screen.

            Duo also has the feature of switching between Wi-Fi and Mobile Data. It also has the feature of downgrading resolution automatically so as to prevent dropping or lagging of video due to bandwidth latency.

            Duo is now available for Android and iOS platforms but the official version is yet to be released by Google. If you are so keen in getting the application you can download Android Apk here. 

P.S: The post is to create awareness and not to be misused.

Tuesday, August 16, 2016

NSA's Hacking tools leaked online.


           United States of America leading one of the largest and sophisticated cyber intelligence agency in the name of NSA. Few days back a hacker group claimed to hack the #Equation Group - Cyber attack division of NSA. Recently the data and private tools has been leaked online.

           It is claimed by the hacker group #The Shadow Brokers that they have hacked the Equation Group and gained many private hacking tools used by the agency.

           Some of the exploits are published online and some security researchers considers the exploits to be legitimate and the group #The Shadow Brokers claims 1 Million bitcoins (568 Million USD) to dump the entire tools which includes installation scripts, exploits for famous vendor products such as Cisco and Firewall and so on.

            There is a news in the past that this Equation Group is responsible for Stuxnet attack but is not proved and the hackers claims that #Topsec, Chinese company is also target of Equation Group. 

            Some security researchers also claims that some of the code names relates to the documents leaked by the whistleblower #Edward snowden such as #BANANAGLEE and #EPICBANANA.

            The breach is not yet confirmed and there is a news that it may be a well organized hoax to gain Bitcoin in large amount and also to gain media attention. If this is proved, it will be historical hack in cyber history.

P.S: The post is to create awareness and not to create any negative impact.

Wednesday, August 3, 2016

#Use WhatsApp without Original Number.


              WhatsApp is the most popularly used application among smartphone users to send messages and also for calling. It almost replaced the traditional texting system. There is a way of using WhatsApp without using your original number.

              WhatsApp upon installation will ask for the mobile number to use and once the verification code has been verified, the application will startup with chat box. WhatsApp can not be used without this mobile activation step.

               If you are keen in using WhatsApp but not intended to reveal the original phone number then there is a way for you. Before proceeding it is purely for educational purpose and the author of this post is not responsible for any damage occured.

              Install WhatsApp freshly, it will prompt for the mobile verification and ask you to enter the mobile number along with the country code. Download and install Primo Application from play store. Enter the details and verify mobile number in Primo application.

              Once verification done with Primo application you will be displayed with Primo home where upon clicking on the menu button on top left corner a popup dialog will appear, find a number at the bottom of the menu displayed.

              It will be above the credits display and surely will not be your mobile number (Usually starts with +1 country code, may also be different) note that number. Go to WhatsApp application and enter the number with respective country code.

               Try to verify mobile number via phone call you will receive the call from primo application attend it and note the verification code. Enter the code and you are verified, now you can use WhatsApp without using original mobile number.

P.S: The post is to create awareness and not to be misused. Author of this post is not responsible for any act done by readers of this post.

Friday, July 29, 2016

#QRLJacking - Hijack QRL Code.


          Authentication is one of the crucial parameter in Information security. It is achieved by passwords, biometrics and 2FA and many other means. One of the feature considered to be much secure is QR code. Recently a security researcher hijacked the QR Code.

           QR code is the two dimensional data that has secret information including secret keys and session details. QR codes has been used by many sites including WhatsApp for authentication WhatsApp Web in browser or in desktop client.

           The security researcher produced a fake login page which resembles the one as WhatsApp web and then he made a script to change the QR code which will change every 20 seconds in Original site. So whenever the QR code changes it will reflect in the fake page. The technique is dubbed as #QRLJacking.

           If the user scans the QR code using his/her mobile then the account will be hijacked and the session will be opened in the Attacker machine with full authentication.

           This can be done if the page has been faked and then the QR code which changes in the period of time should also be updated in the fake page. 

           The security researcher has also created a PoC and it can be viewed public here.

P.S: The post is to create awareness and not to be misused.

Saturday, July 23, 2016

Verified Boot - Android Nougat.


          Technology giant Google is about to roll out their new mobile operating system version in the name of #Android Nougat. It has many new cool features and now another cool feature has been released.

           Being a huge platform it is one of the most targeted platform for attackers and for spreading malwares and rootkits. Normal user will not be aware of the malware until its action goes abnormal. Inorder to help them a new feature #Verified Boot has been enabled by Android.

            Upto Android 6.0, the device will boot up even if the device is compromised by malware by popping up an alert to users but now they are strictly enforcing verified boot.

            After the installation of Android Nougat if your device has been affected by malware or any rootkit your device wont even boot up by showing you an error. This state is merely similar to bricking the device.

            Data corruption caused due to hardware or software failure will also fail in verified boot and so the device wont boot but Android is having a special program to detect if the problem in data corruption.

            Due to this enforcement, Rooting the device and customizing the kernel may be tedious for users. This feature is considered to be nice for normal people but not for those who want to play with Android Kernel.

P.S: The post is to create awareness and not to create any negative impact.

Monday, July 4, 2016

Earning $500,000 per day through Android.


      Android makes a major share in smartphone operating system which is also a targeted platform for hackers. There are numerous malwares that has been released in the market to exploit users. Recently the revenue made by hackers using Android malware has been released.

       Dubbed #Hummer is one of the Android malware that targets devices and installs itself,roots the device and then download unwanted apps by gaining admin privileges.

       Once this malware has been installed, the developer will get 50 cents and it may seem to be a small money but they are making 500000 USD on daily basis by having 1 million downloads daily.

        The activities of the app will be once installed, it has many rooting exploits which allows themselves to root the device. Then after rooting it will download all the unwanted apps thus consuming bandwidth.

       #Hummer comes in the form of fake apps like facebook, Linkedin and also famous games, utilities and many more.

        The company released the top 5 countries affected by Hummer along with the user numbers

1. India - 154,248
2. Indonesia - 92,889
3. Turkey - 63,906
4. China - 63,285
5. Mexico - 59,192

        Users of Android are recommended not to download any apps through links and even in Play store review the developer before downloading applications.

P.S: The post is to create awareness and not to create any negative impact.