Friday, February 25, 2011


You may have heard of denial-of-service attacks launched against websites, but you can also be a victim of these attacks. Denial-of-service attacks can be difficult to distinguish from common network activity, but there are some indications that an attack is in progress.

What is a denial-of-service (DoS) attack?

In a denial-of-service (DoS) attack, an attacker attempts to prevent legitimate users from accessing information or services. By targeting your computer and its network connection, or the computers and network of the sites you are trying to use, an attacker may be able to prevent you from accessing email, websites, online accounts (banking, etc.), or other services that rely on the affected computer. 

The most common and obvious type of DoS attack occurs when an attacker "floods" a network with information. When you type a URL for a particular website into your browser, you are sending a request to that site's computer server to view the page. The server can only process a certain number of requests at once, so if an attacker overloads the server with requests, it can't process your request. This is a "denial of service" because you can't access that site. 

An attacker can use spam email messages to launch a similar attack on your email account. Whether you have an email account supplied by your employer or one available through a free service such as Yahoo or Hotmail, you are assigned a specific quota, which limits the amount of data you can have in your account at any given time. By sending many, or large, email messages to the account, an attacker can consume your quota, preventing you from receiving legitimate messages.

What is a distributed denial-of-service (DDoS) attack?

In a distributed denial-of-service (DDoS) attack, an attacker may use your computer to attack another computer. By taking advantage of security vulnerabilities or weaknesses, an attacker could take control of your computer. He or she could then force your computer to send huge amounts of data to a website or send spam to particular email addresses. The attack is "distributed" because the attacker is using multiple computers, including yours, to launch the denial-of-service attack.

How do you avoid being part of the problem?

Unfortunately, there are no effective ways to prevent being the victim of a DoS or DDoS attack, but there are steps you can take to reduce the likelihood that an attacker will use your computer to attack other computers:
  • Install and maintain anti-virus software).
  • Install a firewall, and configure it to restrict traffic coming into and leaving your computer.
  • Follow good security practices for distributing your email address. Applying email filters may help you manage unwanted traffic.

How do you know if an attack is happening?

Not all disruptions to service are the result of a denial-of-service attack. There may be technical problems with a particular network, or system administrators may be performing maintenance. However, the following symptoms could indicate a DoS or DDoS attack:
  • unusually slow network performance (opening files or accessing websites)
  • unavailability of a particular website
  • inability to access any website
  • dramatic increase in the amount of spam you receive in your account

What do you do if you think you are experiencing an attack?

Even if you do correctly identify a DoS or DDoS attack, it is unlikely that you will be able to determine the actual target or source of the attack. Contact the appropriate technical professionals for assistance.
  • If you notice that you cannot access your own files or reach any external websites from your work computer, contact your network administrators. This may indicate that your computer or your organization's network is being attacked.
  • If you are having a similar experience on your home computer, consider contacting your internet service provider (ISP). If there is a problem, the ISP might be able to advise you of an appropriate course of action.


Anti-virus software can identify and block many viruses before they can infect your computer. Once you install anti-virus software, it is important to keep it up to date.

What does anti-virus software do?

Although details may vary between packages, anti-virus software scans files or your computer's memory for certain patterns that may indicate an infection. The patterns it looks for are based on the signatures, or definitions, of known viruses. Virus authors are continually releasing new and updated viruses, so it is important that you have the latest definitions installed on your computer.
Once you have installed an anti-virus package, you should scan your entire computer periodically.
  • Automatic scans - Depending what software you choose, you may be able to configure it to automatically scan specific files or directories and prompt you at set intervals to perform complete scans.
  • Manual scans - It is also a good idea to manually scan files you receive from an outside source before opening them. This includes
    • saving and scanning email attachments or web downloads rather than selecting the option to open them directly from the source
    • scanning media, including CDs and DVDs, for viruses before opening any of the files

What happens if the software finds a virus?

Each package has its own method of response when it locates a virus, and the response may differ according to whether the software locates the virus during an automatic or a manual scan. Sometimes the software will produce a dialog box alerting you that it has found a virus and asking whether you want it to "clean" the file (to remove the virus). In other cases, the software may attempt to remove the virus without asking you first. When you select an anti-virus package, familiarize yourself with its features so you know what to expect.

Which software should you use?

There are many vendors who produce anti-virus software, and deciding which one to choose can be confusing. All anti-virus software performs the same function, so your decision may be driven by recommendations, particular features, availability, or price.
Installing any anti-virus software, regardless of which package you choose, increases your level of protection. Be careful, though, of email messages claiming to include anti-virus software. These messages, supposedly from your ISP's technical support department, contain an attachment that claims to be anti-virus software. However, the attachment itself is in fact a virus, so you could become infected by opening it.

How do you get the current virus information?

This process may differ depending what product you choose, so find out what your anti-virus software requires. Many anti-virus packages include an option to automatically receive updated virus definitions. Because new information is added frequently, it is a good idea to take advantage of this option. Resist believing email chain letters that claim that a well-known anti-virus vendor has recently detected the "worst virus in history" that will destroy your computer's hard drive. These emails are usually hoaxes. You can confirm virus information through your anti-virus vendor or through resources offered by other anti-virus vendors.
While installing anti-virus software is one of the easiest and most effective ways to protect your computer, it has its limitations. Because it relies on signatures, anti-virus software can only detect viruses that have signatures installed on your computer, so it is important to keep these signatures up to date. You will still be susceptible to viruses that circulate before the anti-virus vendors add their signatures.
When anyone or anything can access your computer at any time, your computer is more susceptible to being attacked. You can restrict outside access to your computer and the information on it with a firewall. 

What do firewalls do?

Firewalls provide protection against outside attackers by shielding your computer or network from malicious or unnecessary Internet traffic. Firewalls can be configured to block data from certain locations while allowing the relevant and necessary data through. They are especially important for users who rely on "always on" connections such as cable or DSL modems.

What type of firewall is best?

Firewalls are offered in two forms: hardware (external) and software (internal). While both have their advantages and disadvantages, the decision to use a firewall is far more important than deciding which type you use.
  • Hardware - Typically called network firewalls, these external devices are positioned between your computer or network and your cable or DSL modem. Many vendors and some Internet service providers (ISPs) offer devices called "routers" that also include firewall features. Hardware-based firewalls are particularly useful for protecting multiple computers but also offer a high degree of protection for a single computer. If you only have one computer behind the firewall, or if you are certain that all of the other computers on the network are up to date on patches and are free from viruses, worms, or other malicious code, you may not need the extra protection of a software firewall. Hardware-based firewalls have the advantage of being separate devices running their own operating systems, so they provide an additional line of defense against attacks. Their major drawback is cost, but many products are available for less than $100 (and there are even some for less than $50).
  • Software - Some operating systems include a built-in firewall; if yours does, consider enabling it to add another layer of protection even if you have an external firewall. If you don't have a built-in firewall, you can obtain a software firewall for relatively little or no cost from your local computer store, software vendors, or ISP. Because of the risks associated with downloading software from the Internet onto an unprotected computer, it is best to install the firewall from a CD or DVD. If you do download software from the Internet, make sure it is a reputable, secure website. Although relying on a software firewall alone does provide some protection, realize that having the firewall on the same computer as the information you're trying to protect may hinder the firewall's ability to catch malicious traffic before it enters your system.

How do you know what configuration settings to apply?

Most commercially available firewall products, both hardware- and software-based, come configured in a manner that is acceptably secure for most users. Since each firewall is different, you'll need to read and understand the documentation that comes with it to determine whether or not the default settings on your firewall are sufficient for your needs. Additional assistance may be available from your firewall vendor or your ISP (either from tech support or a website). Also, alerts about current viruses or worms  sometimes include information about restrictions you can implement through your firewall.

Unfortunately, while properly configured firewalls may be effective at blocking some attacks, don't be lulled into a false sense of security. Although they do offer a certain amount of protection, firewalls do not guarantee that your computer will not be attacked. In particular, a firewall offers little to no protection against viruses that work by having you run the infected program on your computer, as many email-borne viruses do. However, using a firewall in conjunction with other protective measures (such as anti-virus software and "safe" computing practices) will strengthen your resistance to attacks.

While email attachments are a popular and convenient way to send documents, they are also a common source of viruses. Use caution when opening attachments, even if they appear to have been sent by someone you know. 

 Why can email attachments be dangerous?

Some of the characteristics that make email attachments convenient and popular are also the ones that make them a common tool for attackers:
  • Email is easily circulated - Forwarding email is so simple that viruses can quickly infect many machines. Most viruses don't even require users to forward the email—they scan a users' computer for email addresses and automatically send the infected message to all of the addresses they find. Attackers take advantage of the reality that most users will automatically trust and open any message that comes from someone they know.
  • Email programs try to address all users' needs - Almost any type of file can be attached to an email message, so attackers have more freedom with the types of viruses they can send.
  • Email programs offer many "user-friendly" features - Some email programs have the option to automatically download email attachments, which immediately exposes your computer to any viruses within the attachments.

What steps can you take to protect yourself and others in your address book?

  • Be wary of unsolicited attachments, even from people you know - Just because an email message looks like it came from your mom, grandma, or boss doesn't mean that it did. Many viruses can "spoof" the return address, making it look like the message came from someone else. If you can, check with the person who supposedly sent the message to make sure it's legitimate before opening any attachments. This includes email messages that appear to be from your ISP or software vendor and claim to include patches or anti-virus software. ISPs and software vendors do not send patches or software in email.
  • Keep software up to date - Install software patches so that attackers can't take advantage of known problems or vulnerabilities . Many operating systems offer automatic updates. If this option is available, you should enable it.
  • Trust your instincts - If an email or email attachment seems suspicious, don't open it, even if your anti-virus software indicates that the message is clean. Attackers are constantly releasing new viruses, and the anti-virus software might not have the signature. At the very least, contact the person who supposedly sent the message to make sure it's legitimate before you open the attachment. However, especially in the case of forwards, even messages sent by a legitimate sender might contain a virus. If something about the email or the attachment makes you uncomfortable, there may be a good reason. Don't let your curiosity put your computer at risk.
  • Save and scan any attachments before opening them - If you have to open an attachment before you can verify the source, take the following steps:
    1. Be sure the signatures in your anti-virus software are up to date 
    2. Save the file to your computer or a disk.
    3. Manually scan the file using your anti-virus software.
    4. If the file is clean and doesn't seem suspicious, go ahead and open it.
  • Turn off the option to automatically download attachments - To simplify the process of reading email, many email programs offer the feature to automatically download attachments. Check your settings to see if your software offers the option, and make sure to disable it.
  • Consider creating separate accounts on your computer - Most operating systems give you the option of creating multiple user accounts with different privileges. Consider reading your email on an account with restricted privileges. Some viruses need "administrator" privileges to infect a computer.
  • Apply additional security practices - You may be able to filter certain types of attachments through your email software  or a firewall.

Both the Indian Cyber Squad(Reg.) and Indian Ethical Hackers have identified this topic as one of the top tips for home users.

Understanding Patches

When vendors become aware of vulnerabilities in their products, they often issue patches to fix the problem. Make sure to apply relevant patches to your computer as soon as possible so that your system is protected.

What are patches?

Similar to the way fabric patches are used to repair holes in clothing, software patches repair holes in software programs. Patches are updates that fix a particular problem or vulnerability within a program. Sometimes, instead of just releasing a patch, vendors will release an upgraded version of their software, although they may refer to the upgrade as a patch.

How do you find out what patches you need to install?

When patches are available, vendors usually put them on their websites for users to download. It is important to install a patch as soon as possible to protect your computer from attackers who would take advantage of the vulnerability. Attackers may target vulnerabilities for months or even years after patches are available. Some software will automatically check for updates, and many vendors offer users the option to receive automatic notification of updates through a mailing list. If these automatic options are available, we recommend that you take advantage of them. If they are not available, check your vendors' websites periodically for updates.

Make sure that you only download software or patches from websites that you trust. Do not trust a link in an email message—attackers have used email messages to direct users to malicious websites where users install viruses disguised as patches. Also, beware of email messages that claim that they have attached the patch to the message—these attachments are often viruses

You've heard the news stories about credit card numbers being stolen and email viruses spreading. Maybe you've even been a victim yourself. One of the best defenses is understanding the risks, what some of the basic terms mean, and what you can do to protect yourself against them.

 What is cyber security?

It seems that everything relies on computers and the internet now — communication (email, cellphones), entertainment (digital cable, mp3s), transportation (car engine systems, airplane navigation), shopping (online stores, credit cards), medicine (equipment, medical records), and the list goes on. How much of your daily life relies on computers? How much of your personal information is stored either on your own computer or on someone else's system?
Cyber security involves protecting that information by preventing, detecting, and responding to attacks.

What are the risks?

There are many risks, some more serious than others. Among these dangers are viruses erasing your entire system, someone breaking into your system and altering files, someone using your computer to attack others, or someone stealing your credit card information and making unauthorized purchases. Unfortunately, there's no 100% guarantee that even with the best precautions some of these things won't happen to you, but there are steps you can take to minimize the chances.

What can you do?

The first step in protecting yourself is to recognize the risks and become familiar with some of the terminology associated with them. Hacker, attacker, or intruder - These terms are applied to the people who seek to exploit weaknesses in software and computer systems for their own gain. Although their intentions are sometimes fairly benign and motivated solely by curiosity, their actions are typically in violation of the intended use of the systems they are exploiting. The results can range from mere mischief (creating a virus with no intentionally negative impact) to malicious activity (stealing or altering information). Malicious code - Malicious code, sometimes called malware, is a broad category that includes any code that could be used to attack your computer. Malicious code can have the following characteristics:
  • It might require you to actually do something before it infects your computer. This action could be opening an email attachment or going to a particular web page.
  • Some forms propagate without user intervention and typically start by exploiting a software vulnerability. Once the victim computer has been infected, the malicious code will attempt to find and infect other computers. This code can also propagate via email, websites, or network-based software.
  • Some malicious code claims to be one thing while in fact doing something different behind the scenes. For example, a program that claims it will speed up your computer may actually be sending confidential information to a remote intruder.
Viruses and worms are examples of malicious code.
Vulnerability - In most cases, vulnerabilities are caused by programming errors in software. Attackers might be able to take advantage of these errors to infect your computer, so it is important to apply updates or patches that address known vulnerabilities.

Thursday, February 24, 2011


This is an extreme example of Social Engineering technique, we need following things to do so.
1. Victim’s profile link ( you can get it easily )
2. His/Her Email which he/she uses to sign in
3. His/Her birth date which he/she has used in the profile
4. Make an Email ID on gmail or yahoo with the first name and last name same as on victim’s facebook profile.
* Now you will get this screen
Enter details. In the place of ‘ email address where you can be contacted ‘ enter the fake email u created.
* You will get a email on that ID in which facebook people will ask your problem. Reply to them that you are XYZ( victim’s name ) and you cant access your facebook account. Also you have lost access to your Email Address associated with the account. You dont know what to do now. The hacker is coming online regularly and using your account. If the victim is a girl also write ‘ I am a girl and it poses threat to my social life ‘ and write anything you want that could make them take action.
* After 2-3 days youu will get a reply. They will again ask you that you have access to your associated Email or not? Reply them that you still don’t have access to it. And repeat what all you wrote in first mail.
* Next Day or Same Day you will get an Email that your account is disabled.

This tutorial is for education purpose only, once deleted profile can never be recovered.

Thanks Tushar for this post.





Yes Guys, this is now possible, I’m not joking. Many of us think that this is not possible or we have to spend some money for such services but believe me that we don’t have to spend any money for getting this done. Yes, PhoneOnMap makes it possible. It’s a service that provides a free application that has to be installed in GPS cell phone and you are ready to track the phone from anywhere on the Internet.

This application can be useful for office work as well as family members. You can track your child as well as your girlfriend/wife too, LOL. This PhoneOnMap can be used worldwide and you can use it while traveling too. The data is stored on the company’s server for a period of one month. This can be an invaluable source for sales and marketing department of an organization to track the marketing agents.

If you are worried about the security and privacy of the service, let me tell that it is very secure and your cell phone can not be monitored by any Unauthorized User as in order to access the tracking system, you have to authenticate yourself through a personal code which was used as identification while installing application on cell phone.
Features of GPS cell phone tracking system:
  1. GPS cell phone tracker and locater will not work in the underground transportation.
  2. The application does not work when the phone is turned off.
  3. The data transmission outside provider’s coverage area will add roaming charges like any other phone service charge us.
  4. Once application is uninstalled from cell phone than you can’t do anything.
  5. On internet tracking system will show cell phone location between every 10 seconds to 10 minutes, which is depend on setting.
According to me this kind of service is very important for parents to track their children and from a business usage point of view an invaluable part of companies involved in supply and delivery system like Currier and Home delivery system. This will help them to get a real-time location of the object and provide an accurate time-frame for the delivery.
As of now this service does not provide the exact pin point location but the location determined s in the range of 10-20 meters. However with little intelligence the exact location can be easily determined especially when you wish to track your children or the cheating girlfriend ;)
www.phoneonmap.com

The Above article  posted by mr. tushar..

Your IP is exposed when ever you visit a website,when your Ip gets exposed it becomes easy to trace you and find out your personal information,Hackers can use your Ip to gain access to your personal files and documents and even can get into your paypal,alert etc accounts,Hide the Ip is a Software which masks your IP with one click and you can surf web anonymously,on the other hand Hackers can use this software to hide theiridentity and not get caught,its benificial for all and i recommend that every Pc should have this software installed
Hide the IP to be the best one. It’s ease of use, reliability, wide range of options, speed and unmatchable price were on top when compared to that of the remaining IP Hising softwares on the market.

Key Features of Hide the IP:

Hide IP Address »
Single click to completely hide your Online Identity. Others will see a fake IP address masking your real IP, thus, protecting your privacy.
Select Your Physical IP Location »
You decide which country will be indicated as your origin by simply choosing from a country list. We have hundreds, hourly updated, IP addresses available for use.
Anonymous Web Surfing »
You are protected from hackers who will be tricked by your fake IP instead of your real. They will never be able to find any information about you by tracing the fake IP.
Send Anonymous E-mails » Hide your IP in E-mail headers. Be protected while sending emails from Yahoo!, Hotmail, GMail. Upgrading to Platinum Service add-on will protect you in Outlook!
Bypass Website Country Restrictions »
Surf websites which are restricted for your country. Surf in forums on which you were banned.
Supports Internet Explorer, Firefox, Google Chrome, Safari, Opera.
So what are you waiting for? Download the free trial and test Hide the IP on your computer now! For more information on Hide the IP visit the following link.

Hide the IP


   http://www.ziddu.com/download/13003682/google_hack.pdf.html


  http://www.ziddu.com/download/13003681/Email_Spoofing.pdf.html


  http://www.ziddu.com/download/13003680/FTPExploitsByAnkitFadia.pdf.html


  http://www.ziddu.com/download/13003679/.html


   http://www.ziddu.com/download/13003678/DosAttacked.pdf.html


  http://www.ziddu.com/download/13003677/Corporate-security-excerpt.pdf.html


  http://www.ziddu.com/download/13003676/CREATINGWEBSITEINFLASH.pdf.html


  http://www.ziddu.com/download/13003675/DNS_CACHEPOISONING.pdf.html


  http://www.ziddu.com/download/13003674/ByStepProcessByAnkitFadiaHackingTruths_FTPExploits.pdf.html


  http://www.ziddu.com/download/13003673/FadiaAnkit-EncryptionAlgorithmsExplained.pdf.html


  http://www.ziddu.com/download/13002918/ABeginnersGuideToHackingComputerSystems.pdf.html


  http://www.ziddu.com/download/13002917/eBook-PDFHugoCornwall-TheHackersHandbook.pdf.html


  http://www.ziddu.com/download/13002916/ANKITFADIASBOOK.pdf.html


   http://www.ziddu.com/download/13002915/BookpdfHackingintocomputersystems-abeginnersguide.pdf.html 


   http://www.ziddu.com/download/13002914/Ebook-PdfUntoldWindowsTipsAndSecretsAnkitFadia.pdf.html


   http://www.ziddu.com/download/13002913/ebook_-_pdf_Hacking_IIS_Servers.pdf.html


   http://www.ziddu.com/download/13002912/AnkitFadiaHackingGuide.pdf.html


   http://www.ziddu.com/download/13002911/AttackingtheDNSProtocol.pdf.html


   http://www.ziddu.com/download/13002910/Ebook-ComputerHackingTheWindowsRegistry.pdf.html


   http://www.ziddu.com/download/13002909/BatchFileProgramming-AnkitFadia.pdf.html


  http://www.ziddu.com/download/13007277/hackingbook123456789.pdf.html


  http://www.ziddu.com/download/13007279/HackingforDummies-Wieley.pdf.html


  http://www.ziddu.com/download/13007280/HackingIntoComputerSystems-Beginners.pdf.html


 http://www.ziddu.com/download/13007281/g-FirewallsAndNetworksHowToHackIntoRemoteComputers.pdf.html


 http://www.ziddu.com/download/13007282/hackcrac.pdf.html


 http://www.ziddu.com/download/13007283/hacking-webapplicationshackingexposed.pdf.html


Use Windows 7 BitLocker to Password Protect, Encrypt USB  Drive Do you’ve some important data in your USB drive that you don’t want to share with anybody? It may be some documents, username/passwords or operating systems. Then why not encrypt the USB drive data with password? And if you’re using Windows7, you don’t even need any third party software for password protecting portable drives.
Windows 7 includes a program called BitLocker for encrypting any drive in 2-3 simple steps. Just follow the steps below… and you can secure you files inside USB flash drive but setting a password and encrypting data contents.

How to Use Windows 7 BitLocker to Password Protect USB, Potable Drives

Step 1 : Insert your USB drive, or any portable hard drive and Right click on it in explorer. Now choose “Turn on Bitlocker…“
Use Windows 7 BitLocker to Password Protect,  Encrypt USB Drive
Step 2 : A small window will appear and prompt you for choosing a password that will be required while opening it later. Proceed by clicking the “Next“.
Use Windows 7 BitLocker to Password Protect,  Encrypt USB Drive
Step 3 : Bitlocker will create and save a recovery key in your PC in case you forget password. Simply choose the first option to save the recovery key in a text file in a secure place.
Use Windows 7 BitLocker to Password Protect  USB, Potable Drives
Step 4 : Wait for few minutes while it will be encrypting the portable drive slowly.Depends upon the data volume in your removable drive.
Use Windows 7 BitLocker to Password Protect  USB, Potable Drives
Step 5 : Once done, plug-off and insert the USB drive again to see the encryption in action. BitLocker encryption will be automatically run up and prompt you for putting the password. You have to put the password for only once for accessing the data in it until you plug off.
Use Windows 7 BitLocker to Password Protect  USB, Potable Drives
The encryption is absolutely machine independent i.e. whenever you will insert the USB drive to any other computer, it will still prompt for the decryption password.
Very useful for locking USB drives with password and encrypting it to keep it secure.

The Above Artical posted by Mr. Tushar Patel (

With the sudden rise in the Internet usage across the globe over the past few years, there has also been a rise in the amount of online scams and frauds. Today most of the Internet users are unaware of the most prevailing online threats which pose a real challenge for their safe Internet usage. As a result, Online Security has become a questionable factor for the most Internet users. However it is still possible to effectively combat online insecurity provided that the users are well aware of the common scams and frauds and know how to protect themselves. A study shows that over 91% of the Internet users are unaware of the online scams and are worried about their security. Well if you are one among those 91% then here is a list of 10 tips to ensure your total online security.
1. Always install a good antivirus software and keep it up-to-date. Also install a good anti-spyware to keep your PC away from spywares. Click Here for a list of recommended anti-spyware softwares.
2. Always visit known and trusted websites. If you are about to visit an unknown website, ensure that you do not click on suspectable links and banners.
3. Perform a virus scan on the files/email attachments that you download before executing them.
4. Regularly Update your operating system and browser software. For a better security it is recommended that you surf the Internet through the latest version of your browser program.
5. Never share your password (email, bank logins etc.) with any one for any reason. Choose a strong password (A blend of alphanumeric+special symbols) and change it regularly, eg. every 3 months. Avoid using easy-to-guess passwords. (ex. pet's name or kid's name)
6. Always type the URL of the website in your browser's address bar to enter the login pages. For ex. To login to your Gmail account type http://mail.google.com
7. Before you enter your password on any login page, ensure that you see https instead of http. ex. https://mail.google.com instead of http://mail.google.com. HTTPS protocol implements SSL (Secure Sockets Layer) and provide better security than a normal HTTP.

8. Beware of phishing emails! Do not respond to any email that request you to update your login details by clicking on a link in the body of the email. Such links can lead to Fake Login Pages (Spoofed Pages).

9. Always hit the logout button to close your login session rather than abruptly terminating the browser window. And clear your web browser caches after every session to removethe temporary files stored in the memory and hard disk of your PC.
10. Avoid (Stop) using any public computers or computers in the Internet cafes to access any sensitive/confidential information. Also avoid such computers to login to your email/bank accounts. You cannot be sure if any spyware, keystroke-logger, password-sniffer and other malicious programs have not been installed on such a PC.
By following the above 10 tips your online security can be guaranteed upto 90%. I hope this will help my readers for keeping themselves safe from any of the online insecurities. Cheers! Pass your comments.




If you're worried about email security, here is a step by step guide to help you check and determine if your Gmail account has been hacked or compromised in any way

Step 1: Find the 'Last Account Activity' Section Your Inbox


At the bottom of your Gmail inbox there is a 'Last Account Activity' section. Click on 'details' to launch the full blown monitor.

Step 2: See who has accessed your Gmail account recently

Next, what you'll see is a table of the most recent activity from your Gmail account. It shows you
  • How it was accessed (Browser/mobile etc)
  • Where exactly the IP address is (So you can do some further digging)
  • When it was accessed
Step 3: Understand the IP addresses – Has your Gmail really been hacked?


If you see IP addresses from different countries, don't be too quick to panic. If you use any 3rd party services which hook-up to your Gmail account, they will almost certainly show up in your activity log. To do you own investigation, you can use DomainTools to identify the IP address. This will help you differentiate normal activity and your Gmail account being hacked.

Step 4: Understand the alerts – Google's way of highlighting suspicious activity


Google will also do it's fair share of monitoring, and will also alert you if it sees suspicious activity both in your inbox, as well as your recent activity log. When this happens, and the IP addresses look suspicious, it is advisable to play it safe, assume your Gmail account has been hacked, and change your passwords immediately.

Step 5: Sign Out All Other Sessions – If you forgot to sign out on a public computer


If you are worried you did not not sign out of a public computer, you can 'sign out all other sessions'. This won't fix any hacked Gmail accounts, but it will resolve any careless mistakes. This is also useful if you happen to lose your mobile phone and you want to ensure your email is not read by others.

Step 4: Understand the alerts – Google's way of highlighting suspicious activity


Google will also do it's fair share of monitoring, and will also alert you if it sees suspicious activity both in your inbox, as well as your recent activity log. When this happens, and the IP addresses look suspicious, it is advisable to play it safe, assume your Gmail account has been hacked, and change your passwords immediately.

Step 6: What to do if your Gmail account has really been hacked

The first thing you do is change both your password and security question right away. Then make sure your new choices are very secure. Google themselves have some really good tips . For example in the case of security questions:
  • Choose a question only you know the answer to – make sure the question isn't associated with your password.
  • Pick a question that can't be answered through research (for example, avoid your mother's maiden name, your birth date, your first or last name, your social security number, your phone number, your pet's name, etc.).
  • Make sure your answer is memorable, but not easy to guess. Use an answer that is a complete sentence for even more security.
So there you have it. A step-by-step guide on fully understanding Gmail's account activity log, and how to check if your Gmail account has been hacked

Step 6: What to do if your Gmail account has really been hacked

The first thing you do is change both your password and security question right away. Then make sure your new choices are very secure. Google themselves have some really good tips . For example in the case of security questions:
  • Choose a question only you know the answer to – make sure the question isn't associated with your password.
  • Pick a question that can't be answered through research (for example, avoid your mother's maiden name, your birth date, your first or last name, your social security number, your phone number, your pet's name, etc.).
  • Make sure your answer is memorable, but not easy to guess. Use an answer that is a complete sentence for even more security.
So there you have it. A step-by-step guide on fully understanding Gmail's account activity log, and how to check if your Gmail account has been hacked .



World's first hack-free software

MELBOURNE: A team of Australia's ICT Research Centre of Excellence's spinout company Open Kernel Labs (OK Labs) developed a microkernel The 'seL4' and claimed it to be the the world's first hack-free software which can protect systems from failure or malicious attacks.  It is a small operating system kernel which regulates access to a computer's hardware. Its unique feature is that it has been mathematically proven to operate correctly, enabling it to separate trusted from untrusted software, protecting critical services from a failure or a malicious attack, say the scientists.
In future applications, seL4 could ensure that trusted financial transaction software from secure sources like banks or stock exchanges can operate securely on a customer's mobile phone alongside "untrusted" software, such as games downloaded from the Internet, according to its developers.

Lead scientist Gerwin Klein said, "Our seL4 microkernel is the only operating system kernel in existence whose source code has been mathematically proven to implement its specification correctly. Under the assumptions of the proof, the seL4 kernel for ARM11 will always do precisely what its specification says it will do."
It only works on sites being hosted on Ms-IIS server. Now a days many boxes are patched so it'll not work on them !!

Steps for Xp-

open run
type-

%WINDIR%\EXPLORER.EXE ,::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{BDEAD
F00-C265-11d0-BCED-00A0C90AB50F}

and press enter !

A new window name "WEB FOLDER" gets open

Right click and click on New, Add Web Folder then enter your vulnerable website address.

then next....finish
# now You can insert your page with name index.html by simply copy pasting.

Also after getting access to the website...Many websites don't allows you to
add your page. so leave them.

Dork- "Powered by IIS" or use your own unique dork.
 
Above article posted by Mr. Vishal Shah (Cyber Crime Investigator & Ethical Hacker)