Sunday, May 17, 2015

"Mac" and "Windows" file transfer issue solved

Bought a new Mac? First thing you may do is attach your external hard disk and copy your existing data to your brand new, clean Mac! But hold on, you'll be frustrated to the core if bought Mac without consulting any Techie about "Why not Mac" or "Mac Vs. Windows". When you spend at least $900-1000 on your new Mac, you'll have to spend some more on a tool, popularly known as "Tuxera NTFS for Mac" for a little more $31.

Unless you have a tool like Tuxera, you may not be able to edit/delete/write on your external Hard disk (assuming you have been a Windows user for life and your hard disk is on NTFS file system). By default Mac allows you to only "read" from your NTFS based external hard disk, that means you can copy from your hard disk and can't "copy to" your hard disk.

Mac OS supports HFS+ filesystem, while Windows is generally on FAT32, majorly on NTFS these days! So you either have to buy a tool like Tuxera or format your external hard disk to HFS+, but in that case Windows won't allow you to write on the external hard disk!

Faced this problem exactly on the first day when I bought my Mac, but a friend saved me from all the frustration!

Mac is Sexy but it costs you a lot even after the first big purchase. 

Sunday, May 10, 2015

Start ups and issues with software licensing

Today 1 of my 10 friends already have or want to have a start up of their own, be it a Tech or creative/media or even a small restro. They have all the information that they need on their fingertips, god bless internet! All they want to do is implement their ideas and roll out them as soon as possible, capture market and be the boss for rest of their life time.

Be it USA or India, Tech start ups are growing at tremendous speed. This is an era of mobile apps, the world is getting closer and closer, a well connected cyber world. While building the idea of their own, start ups tend to make use of free stuff as much as possible, to keep the expenses low, which I believe is absolutely brilliant idea. They are more focused and concerned about the shaping of idea and making it commercially sell able.

I have seen many of my friends telling others that it's not always about money but all you need is an idea and a computer with internet to kick start a start up, which is absolutely right in my opinion as well. When it comes to software products, start ups tend to make use of beta/evaluation version, if no option of "Open Source" is available. Another cool thing with start ups is they try to keep it "low" when it comes to IT spend, so you can bring in your laptop/tab to the office and work from it. No need to carry the military grade, bulky "corporate" laptops. So all they do is work on their ideas, have amazing people working in some fancy and even garage looking offices, stack up kitchen full of awesome food, sell the product/service and keep on minting money, isn't it fancy? Yes, indeed it is!

But hold on it isn't that simple these days, you can't just have an idea and a laptop to code unless you have a legit software to play with! Just like you [start ups], even software publishers like Microsoft, Adobe, IBM etc. have to run their businesses. There is a very thin line between free stuff and piracy. When you run a start up, you have 1000s of things to manage and hence there is possibility that you don't even  care if your new(kick ass) programer has a genuine operating system and the legit software to code. As the years pass, you concentrate on increasing revenues, meeting new investors and hiring new people. And one fine day you get a mail from one of these software publishers, asking you how many licenses of their fancy software product do you own?

"Damnnn, what the heck is it? I don't know, I have 40 people using 40 laptops and 30 tabs, it's BYOD, we don't own any of these, why would I care if they have purchased the software that they use or downloaded from torrent??!!??"

Well here's the thing, "With great power comes great responsibility." Its your start up, your employees, your code that they are running on to those 40 laptops and 30 tabs, it's your responsibility to manage the software licensing compliance! It's not difficult these days for software publishers to find out if you have purchased genuine software or you are minting money by using pirated software. You can be sued and your startup's reputation can go for a toss! After all there ain't no such thing as a free lunch. 


So what can you[start up] do?

Rule 1: Play fair, you got to spend some hard cash to procure the software licenses which help you to code and mint the cash.
Rule 2: No exception policy, be it an intern or HR of your start up, a legit operating system with software product should not have any exception policy!
Rule 3: Hygiene checkup, no matter how busy you are in cracking business deals and meeting new highs in revenue, you should ask your IT guy to have surprise checks on the devices that connects to your company's network.
Rule 4: Read licensing agreements, yes those pages filled with jargon are for you to read! You shouldn't "forget" to read the licensing agreements, no matter how heavy they are on your head and eyes, after all you should know what you bought and how it should be used. A sales guy may have exaggerated "few" things that you should know!
Rule 5:  Deploy ITAM tools, you can implement solutions like IT asset management tools, which capture every detail about the software deployed on devices connecting to your network. 
Rule 6: Independent review, it's always advised to have an independent review of your policies and procedures, licensing posture from independent bodies (http://www.ey.com/IE/en/Services/Advisory/IT/EY-software-licensing-assurance) An independent review may not only tell you about your "over usage" but it can also tell you your "under utilization".

It's difficult for a start up to gain confidence of it's customers and investors. Software publishers can sue you for big bucks if you caught up playing with their software licensing. So you better pay for what you use!  


   


Tuesday, September 30, 2014

ISACA Cybersecurity Nexus (CSX)

It's been hardly six months that I "again" stepped into the professional career as Information Security Consultant with one of my dream company. I have been studying Information Systems since last 10 years. And I would say life after MBA is different and far more better!

It's almost two years that I have been closely associated with ISACA. I started off as President for ISACA's first student group in India and after that I'm serving ISACA as International member of Student & Academic subcommittee.

Many a times students ask me, "what should I do to enter into Information Security/ Information Systems Audits and related field". I used to suggest them trainings and certifications like CEH, ISO 27001LA/LI, CISA etc. I personally have high regards for Certified Information Systems Auditor (CISA) which is ISACA's most recognized certification in the world.

CISA is indeed the best certification but when it comes college students or recent graduates they find it difficult to prepare for CISA. As CISA not only tests your theoretical understanding but emphasis a lot on practical experience.
 
ISACA has now introduced Cybersecurity Nexus, a new security knowledge platform and professional program by considering the high demand of cybersecurity skills. 


Cybersecurity Fundamentals Certificate exam tests following aspects of cybersecurity. 
  • Cybersecurity concepts
  • Cybersecurity architecture principles
  • Cybersecurity of networks, systems, applications and data
  • The security implications of the adoption of the emerging technologies
  • Incident responses
This certification is comparatively cheaper, exam fees - $150, introductory price for the study guide is $15 members/$25 non-members (till 30th September). Unlike CISA you don't have to wait for an exam date, you can appear for CSX certification online. 75 questions to solve in 2 hours, you need to secure 65% in order to pass the test.

In order to prepare for CSX certification one can refer
  • Cybersecurity Fundamentals Study Guide - An excellent stand-alone document for individual study of the core concepts and terms that frame and define the fast-changing and increasingly important field of cybersecurity, the guide was compiled and written by cybersecurity experts. The guide explores in detail the four key areas covered in the exam and Includes self-assessment questions and explanations of the answers.
  • Download the complimentary Exam Guide for step-by-step details about the exam process
  • ISACA conference workshops and sessions, CSX webinars, whitepapers, books and other publications
If you are a college student or a recent graduate, I would strongly recommend CSX certification.

For detailed information of CSX certification and program, kindly visit:
www.isaca.org/cyber/Pages/Cybersecurity-Fundamentals-aCertificate.aspx



Saturday, August 3, 2013

Why hire, just pay Bounty?

Lets go five years back, year 2007-08 major news in Information Security industry were:

1. Estonia recovers from massive Denial of Service attack
2. Spear phishing attack at Office of the Secretary of Defense
3. United Nations website hacked
4. Trend Micro website hacked

Strange that even after having Top in Class IT Security infrastructure & talented resources from the area of Security, premier organizations got hacked! Does it mean the Infrastructure and/or 'Security' human resources are useless?

Lets come back to year 2012-13

Organizations like Facebook, Google, Microsoft, Paypal, ebay and many more are allowing hackers to hack their websites! Well there's no trap, you find vulnerabilities, exploit them, give proof of concept to Security teams of those organizations *that's it*

So your next question might be, whats next? Why would a hacker give POC to Facebook? Answer is simple, to earn Bug Bounties! I hate numbers but let me give you some statistics, as per one source Facebook itself paid 329 people across 51 countries total bounty amount that exceed $1 million!

Check out this website which gives a list of Organizations who have bug bounty program https://bugcrowd.com/list-of-bug-bounty-programs/

Just imagine, Facebook pays minimum $500 for a valid bug and there is no upper cap! Severe the vulnerability, the richer you become!

I'm sure you might be thinking, what should i do to be a Bounty Hunter? Well let me tell you, it's not difficult at all to find these bugs. The only thing you need is knowledge of how internet works , if you can play well with technology like - php, javascripts, asp.net, python, shell etc. the list goes on, another best thing is awareness about OWASP Top 10 vulnerabilities And last but not the least - Patience! You might just find a bug in your College's website within minutes, but it may take months to find out a bug in Facebook!

So my point is, even after having kick ass security professionals in your organization why do you still have to pay bounties? Aren't they effective in securing your organization's website? Why don't you just fire them and pay only bug bounties?

Well In my opinion it's difficult to 'Why hire, just pay Bounty', no one/no organization on this planet earth can claim to provide 100% security. Risk is uncertain, technology changes very often so there is absolutely no option than having dedicated security professionals to monitor, plan, act your organization's perimeter security! Lets talk about Java, one of the most widely used technology, platform. Lately Java has been in news, every now and then because of the vulnerability in the platform. So if Java Version XX is vulnerable to certain attack (know to public) and if your Application is built on Java Version XX then your application is vulnerable! Then Java releases an update, if your IT/security team fails to apply it to your application - possibly you'll get Royally Hacked even by a Script Kiddie.

I really liked the concept of Bug Bounty, it's more or less similar to crowd sourcing where in you openly ask general public to hack you! It may happen, you'll get tons of security bugs identified by kids which your 5yrs+ experienced Security Tester missed out very easily. So you pay the hacker, who are termed as White Hat Hackers and he spreads it on Social Network. Few more hackers read it & try hacking into your application, finding more bugs for you. In this way even after being in production, you application get tested by people every now and then. They contribute to your application making it more secured than earlier & in return they get paid for their efforts.

I would conclude by stating, our Ecosystem is becoming matured day by day and programs like Bug Bounties are helping organizations to strengthen their fences not by it's employees but by intruders itself!

NOTE: I'm strictly against differentiating hackers into White/Black, they are just 'hackers'. If a so called White Hat Hacker can't think like Black Hat Hacker (Cracker), he'll never be able to help you in protecting yourself from Black Hat Hackers(Cracker).  

Happy (bug) Hunting!

Thursday, June 20, 2013

True Caller, breach of Privacy?

Me to Friend: "Hey I got a missed calls from this XXXXXX number, almost 10 times yesterday."
Friend to Me: "Give me 10 seconds & I'll find out who that is! I have True Caller App on my Android Phone"


Quite typical scenario, you may just feel - WoW that's awesome, very helpful app it is; But don't get too excited, there's a catch! Any unknown person can randomly search by a telephone number, that whom the number belongs to.

So what I did is, I changed last two digits of the ten digit mobile number series & I could get the name of the person to whom that number belongs. 

770 919 6001
770 919 6002
770 919 6003
770 919 6004
770 919 6005

I'm sure you might not be happy with this feature which you may call, 'search by Number'. TeleMarketing Companies must be making most use of this app, as they are getting 'Free' dump of potential leads all around the globe.

I don't want to touch any other Pros/Cons of True Caller, as I'm mainly interested in 'Search by Number' feature.

Let me give you an idea about, How True Caller gets you details?
Somebody who has your mobile number & name saved in his mobile number installs True Caller App. And he does nothing, his contact list gets sync with True Caller's Database! Basically you do not have the control on saving yourself from getting Listed in this Global Directory!

But don't get panic, True Caller offers you freedom to get unlisted from their Database/Global Directory. All you need to do is visit http://www.truecaller.com/unlist If you are very much concerned about your privacy, just unlist yourself!

True Caller in my view is 'New Generation Mobile Yellow Pages' which is being used all over the world. I often heard/saw people making Fuss about True Caller & breach of Privacy. But after reading http://www.truecaller.com/how-it-works/ one can understand why it's not really a 'Breach of Privacy'.

But there's still a catch, I'm unsure whether Unlisting from True Caller, really unlist you from True Caller's Database? They might be having a flag set next to every telephone number in their database which tells the app to show the number in search listing or not. So the number might not be actually deleted from True Caller's Database. In this case, yes this a MAJOR Privacy/Security breach. And I highly suspect that must be the case with True Caller.

Finally I would conclude, in this Digital & Connected world it is difficult to keep yourself 'Private'. The word Privacy holds literally no meaning, when you do not control the data/information that is flowing through web of interconnected electronic devices. If you want to hide yourself in the True Caller's Listing just Unlist yourself, but it might not actually Unlisting you from True Callers Database! So curse people for saving your telephone number in their Contact List, well that would be silly isn't it?

Friday, June 14, 2013

Compliance - The Dark Side

[Specific to Information Security]

Before touching main point, let me give you an idea about 'What exactly is Compliance'.

In simple words, compliance is nothing but Standard Rules that are accepted all over the world. Entities related with a particular industry has to comply to certain standards, to gain licenses/ customer trust in order to operate & generate cash flow.

For example, if you are an eCommerece Entrepreneur who deals heavily with Online Money  by using Third Party Payment solution which is PCI DSS compliant. If you want & if you have sufficient capability to operate Online Transaction on your own then you have to comply to PCI DSS standard, get your facility certified and you are ready to do business on your own!

Sounds simple, right? But this isn't simple at all!

Roughly I would say there are few steps
  1. Identify your business vertical.
  2. Find out different compliance/standards which may be mandate/help you to win customers! (Some of your customers may explicitly ask you to comply to certain standards like ISO 9001 - Quality, ISO 27001 - Information Security etc. before dealing with you)
  3. Identify the scope for which you would like to go ahead and get certified. (Scope can be a department within the company or whole company)
  4. Hire consultant, get the standard implemented & get it Certified from Certifying Authorities!
 Lets talk specifically about Information Security related compliance/standards like ISO 27001, PCI DSS etc.

Ideally once an organization get itself certified for the first time, it has to follow the guidelines/processes that are defined & then it has to undergo recertifications after stipulated time period, say after every 2 years. This ensures that organization comply with Industry best practices - standards.

But what exactly happens?

Case 1: XYZ, a software development firm contacts ABC, Information security consulting firm. Ask them to help them in getting ISO 27001 certified. ABC deploys it's resource on XYZ's premise and make sure all the processes are as per the required standard. Once implementation is done, Lead Auditor visits the firm, XYZ. Audits the processes with respect to ISO 27001 standard and eventually XYZ earns ISO 27001 Certification. Barely a month & they start operating how they used to do prior to earning the ISO 27001 certification. As if they have never heard of ISO 27001 compliance.
Meanwhile They keep winning customers by showing they comply to ISO 27001 & certified too!
Just before the Certification is expiring they contact XYZ & ask them to help in re certification. IT manager asks every Department head to make sure every body is following all the policies & again for a while the process document starts getting followed.

So why this *fuss* about Compliance? Organizations today worry about Compliance & not security but they forget, Merely getting a certificate to your organization doesn't guarantee you Security! Unless your people, your employee actually follow the processes religiously.

Hardening the servers, updating Log books just before Audit can fool the auditor but not the hackers. Today hackers are sophisticated, they do proper reconnaissance before attacking your organizations assets. They know your weak links, your people. It might be easy for you to Harden the Servers but it's a pain when it comes to Harden the People.

So how do you tackle this situation? A Surprise Audit, may be yes! This should be done by the Certifying Bodies (CBs) who gives out the Certification to Organizations. Once an Organization is Certified after some period CBs, should do a Surprise Audit to check if Organization is following the standard that is set! I have heard it from experts that - Audit's are never Surprise. But in my opinion there has to be a separate term called 'Surprise Audit' which should be done by the CBs in order to have certain discipline.

 In my opinion Flow should be as:
Compliance Implementation(Day 0 to Day 30) --> Internal Audit (Day 31) -->Patching of NCs(Day 32 to Day 36) --> Final Audit (Day 40) --> Surprise Audit (~ Day 110) 

Post Security Audit, CBs should produce NCs to Organization along with a Warning. Organization should patch the NCs and produce the report to CB. Any further NCs and Organization's Certificate should be revoked by the CB.

Though this will also not give guarantee of 100% security but it'll at least ensure things are more Harden than what they were earlier.This will help the overall Security Ecosystem.

*** IMPORTANT NOTE: THESE ARE MY PERSONAL VIEWS, THIS HAS NOTHING TO DO WITH ANY PARTICULAR ORGANIZATION THAT I WAS/AM ASSOCIATED WITH ***


Wednesday, March 6, 2013

Smart Phones, are they really Smart? [InfoSec Perspective]

It was a pleasant night, I was having dinner and I got call from my friend that she lost her Phone! If it was 2005-08 no body would have got panic but this is Droid Age! And I left my dinner half done, to search her lost phone.

How many of you use smart phones? Today you will rarely find some one who is not using Android/WP/Blackberry, smart isn't it? But it's correctly said, with great power comes great responsibility. In case of smart phones it's Responsibility of Protecting the data within them.

Let's take a scenario, when you buy a droid phone the very first step you do is 'Configure Google Account' with the device. By doing so you are downloading your email headers directly on phone, syncing Contacts with/out email IDs, mobile numbers and what not. What is it? It's a data, which holds tremendous value untapped (unless somebody sells it in market!). Most of the people don't realize it unless it falls in wrong hands.
Another scenario, you flaunt your Droid phone with 5/8/12 mega pixel camera with blah blah features and lens. And off course you click 1000s of pics, to hide some candid and *strictly private* photos you make Folders inside Folders and put it [General Case]. These smart phones gives you extra power of storing location of the photos that you have clicked! Great isn't it? But imagine if you lost your phone and somebody copy all your photos on computer and make Great use out of it!

So what to do? Come on I'm not going to suggest you not to use *Smart Phones* but all you need to do is be little smart in order to use one!

My suggestions:

Step 1: Use Invisible Pattern (1000 times better than visible patterns, protects you from shoulder surfing) or pass code to implement basic security to your smart phone.
Step 2: Go for free version Antiviruses that are available in market place, many of them have feature of *Theft Protection* The moment somebody takes out sim card from your mobile and puts another, presetted mobile numbers gets the alert about loss of your mobile, some of them also provides current location of phone!
Step 3: Now a days SD Card Locker apps are available in market for free, do use it. Most of the photos,messages and other app data are stored on SD card. If you apply another layer of security, it'll be hard to retrieve the data & false password try will eventually erase the data on SD Card.
Step 4: RemoteWipe - This is a part of Mobile Device Management (MDM), it's of great help which can erase your data remotely if you happen to loose your phone.

If preventive measures are taken already then it's most likely that you'll worry only about Mobile Device and not the data, if you lose your phone somewhere!

Smart Phones are not Smart without you being it first!


I don't want to claim that implementing above controls will make your phone Risk Free but it'll definitely make it less vulnerable to data theft/loss.

Saturday, January 5, 2013

Is your Website Secured?

For the first time I started playing with HTML when I was in Junior College (Post School - 11th Standard). I learn HTML & basics of scripting - Java, asp, vb at that tender age, heh! In my educational life, I always loved programing languages even though I couldn't master any but I loved playing with them! I always loved creating simple websites, mostly static because I couldn't do much hands on when it comes to scripting. By the way I created a website for my Girl (back in 2008/09) with funky love songs running in the background, I ended up taking that website down when her mother saw it! Funny isn't it, well it wasn't! :-D

So since then whenever I come across any website I have a habit of looking at it's source code, just like that! And I still continued that habit ;-)

There are two recent incidents that happened because of which I thought to write this post. I being a student of MBA - IT Business Management with special interest and specialization in Information Security, I always try to find out vulnerabilities in everything around me, this includes people as well! Jokes apart, I came across two websites of Premier B-Schools from India. These B-Schools are very renowned and people from all around India participate in it. One of these comes in top 20 B-Schools of India *cough* *cough*

So when I heard about event arranged by this 'One of the Top 20 B-Schools of India' say College 'ABC_1', I came to my hostel and started browsing through it. Trust me the user experience was pathetic! And as usual I right clicked >> View Page Source. I noticed a strange thing in this website, there were couple of places where they had commented many things. Mostly images & links of sponsors. I felt bit unusual, I browsed more and finally I thought to check its directory listings. I expected it to be *Access Denied to Public* but to my surprise I could see www.ABC_1.com/images to be opened, exclusively for me may be ;-) And I tried hitting some common directory names but my bad, they didn't had any of those.

I again started going through the source code and I found out one director called /manage. And I realized that may be this the one which will be the gateway for the admin panel. And it worked, due to careless directory permissions I could see Admin Panel infront of my eyes! Very unprofessional web designing, by the way did I tell you this website is created by a Web Development company who is having around 10/15 clients. After seeing Admin Panel I thought I will have to use some SQL Injections but before that I thought to use some common ID/Password combinations and to my surprise with one very common combination I got through! *Yaaaayyy*

I got access to Admin section where I could manage photos and contents on the website. I could even see the list of registrations that are done for various competitions in that event. I could even change the passowrd and admin details.

But I have got my basics clear about Information Security, so I stopped myself and informed the respective people regarding this vulnerability. Following is the report that I sent to the B-School.


Website URL
Type of Website
Vulnerability
Risk
Counter measures
http://ABC_1.com
National  Level Event Website
           Improper directory        permission (http://ABC_1.com/manage)
      
      Poor authentication for Admin Panel
         Website can be modified all together – loss of integrity.

          If somebody puts up offensive content, it can degrade ABC's image & in turn University's. 

       If details of participants is leaked (Contact Numbers, Email IDs) it may result in loss of personal data.
            Restrict permission to sub directories (http://ABC_1.com/manage) 

           Strong password policy to Admin Panel (Most IMP), even a newbie can get access to the Admin Panel very easily
 
After reporting this incident, the vulnerability got patched. Directory is no more accessible to public, I couldn't check admin panel though!

After this incident, I started looking carefully into other B-School's Event websites. Today when I was browsing through source code of another B-School, again it comes in Top 50 B-School's in India. I could exploit it's Vulnerability. Poor directory permissions and authentication is the reason behind it. I have reported it to the concern people, again!

There's another website that I recently observed, this belongs to investment consultants from Pune. This website was created in ASP.net while earlier two were coded in PHP. The Investment Consultant's website had a pathetic security mechanism when it comes to user authentication. 

I tried commonly used UserID/Password combinations but I failed, so I checked forgot password page. Surprisingly it was a worst password retrieval mechanism I have ever seen. You just need to put user-id, it asks you for Hint Question & Answer and if you guess it correct. Dialogue box is prompted with valid passoword, WORST isn't it?

So conclusion out of these three incident is no matter how much you invest in Technology, if your builders/architects are careless when it comes to Security. You are ultimately going to fail, BIG TIME.
If website developers take proper care, such vulnerabilities will never arise!

Do let me know your views/suggestions on my Risk Analysis ;-)

Sunday, December 16, 2012

Facebook Photos, Privacy Breach?

Do you upload photos to facebook, create album and set privacy settings to it? I do it, but surprisingly today I found out that it may be hidden from people present on facebook but those personal photos/albums are not really protected.

To give you a demo[use Firefox], Open any of your album. Click on the photo, once opened right click on it and select View Image. Here try to notice the change in url or in more techie terms the connectionstring.

For instance STEP#1

I have opened one of my private album and opened the photo which is: https://www.facebook.com/photo.php?fbid=2495739472781&set=a.2495734472656.144476.1231669070&type=3&theater
If you copy and paste this url in browser, without or even by logging into facebook you won't see the picture. Ideally you'll get error as



This album is shared only with one person than me. So ideally no body else than her can see this photo/album.

STEP #2

If I right click and select view image I get a new connectionstring/url which is
https://fbcdn-sphotos-d-a.akamaihd.net/hphotos-ak-ash4/314985_2495739472781_50463433_n.jpg

Try copy/paste in browser and you'll clearly see the photo, even without logging into Facebook.





I feel if hackers will be able to decrypt the connection string and understand the pattern it might be easy to see all such photos which are shared privately on facebook, even without logging into it.

I would like to know your views/comments on this, prolly from Techie perspective!

Thursday, November 15, 2012

Beware from Check in/geo tagging | Twitter | Foursquare | Flickr

I'm sure many people who know me personally or follow me on Twitter will be surprise to see Gaurav Thorat saying 'Beware from Check ins'! Well, I being a newbie product of Symbiosis's Information Security MBA happened to study a subject called, 'Vulnerability Analysis and Penetration Testing'. Sounds very techie isn't it? But frankly speaking this subject needs a lot of common sense along with good technical understanding of Networks and Information Systems.

Foursquare, as many of you must be knowing is a wonderful mobile application by which you can find near by places like hotels, malls, theaters and what not. It's like where ever you go, you just take out your phone and Check in to the place. Let's say I go to Esquare Multiplex in Pune to watch movie, so the moment I go there I'll take out my mobile. Open foursquare app, it'll find my current location with the help of GPS. It'll show me the nearby places along with Esquare Multiplex, I'll just Click on Equare and it'll notify my friends on Foursquare and Twitter/Facebook (if you have allowed foursquare and twitter/facebook integration). So whats the use of it? Well personally, I use Foursquare because It tells my friends about my where about. So if anybody is around me can just drop by for a quick meetup! Secondly, many a times merchants register with Foursquare and give away some really nice offers/discounts. So you check in to merchant's shop and you get discount on your shopping. More the check ins, you unlock Foursquare badges to flaunt within the community!

So whenever I used to Check in, it used to appear like this on twitter


As part of our VAPT subject's assignment we were told to search some security assessment tools and present it infront of students. I being more interested in Social Media, wanted to present a tool which is unique that no body else can think of! And just as I expected all the students choose hardcore technical tools like snort, sniffers and network analyzer. Nobody thought that something called as 'Social Engineering' should also be considered which is comparatively less technical but if used against the targets, can cause huge loss! I find people are still very ignorant about 'Social Engineering' which exploits the weakest link in security that is Human/User behavior.

Tool which I'm going to discuss over here is one, which can help hacker/cracker to perform passive type of Social Engineering attack which often seek to acquire seed information for further active social engineering or network-based attacks.
Active Social Engineering attacks are more of Direct kind which may involve direct interaction with target to obtain security relevant information, gain access privileges, persuade someone to commit a policy violation or act as a proxy on attacker’s behalf. While Passive as described earlier is more of Indirect type of attack which involves eavesdropping, observation and subsequent analysis of the results.
Tool which may allow an hacker/cracker in Passive Social Engineering attack is called Creepy Tool which is developed in python that allows you to gather geo location related information about users from social networking platforms and image hosting services.
Details
Website  : http://ilektrojohn.github.com/creepy/
Platforms  : Linux, Windows
License  : GPLv3
Author  : Yiannis Kakavas
Contact Email  : jkakavas@gmail.com

So what does application do?
If you Check in to Foursquare which redirects it to Twitter. Or if you take photos with geo tagging allowed in it, chipping in the data about where have you taken the pictures you are vulnerable for a passive Social Engineering attack with the help of Creepy tool.
Hacker/cracker all they need is your username on twitter/flickr and they can track you down. With the help of you check ins they can study the pattern/routine of your day like when do you leave from home to office, where is your home & office located. What do you generally do on weekends, which places to do you visit. Some people also supply information like what food/drink they love the most along with the Hotel's Check in. You may not realize that why would  somebody need and find this information important but let me remind you this why Social Engineering attacks are more risky and cause more damage than any other hacking attack because we are tend to be ignorant about Social Engineering attacks, most of us never worry about all these simple information.

So Creepy tool can integrate all these check in/ geo tagging related information at a one place, supplied with a map, google map! So hacker/cracker might not be knowing Pune city very well but with the help of Google maps within the Creepy tool can easily supply them with necessary information for a further strong Social Engineering attack.


If you see above image is Creepy's interface. I checked one user from flickr who has uploaded photos of Military aircrafts. All I did is put his username in Creepy and you can see where did he take that photo! This is passive social engineering, which a terrorist group may use for destructive and dangerous attack. I hope you are getting the seriousness and why I said Beware from Check ins and geo tagging.

Same is the case with Check ins which appear on Twitter, with all the aggregated information about your daily/weekend check ins hacker/cracker or any person with bad intention can plant more dangerous attack on you/your organization/home.

So how will you save yourself from such type of Passive Engineering attack?
1. Be aware, keep your eyes/ears open.
2. Common Sense
3. If not required disable Geo Tagging feature while you take photos from your smartphone/camera.
4. If you care then stop posting your Check ins on Twitter, you may want to continue using Foursquare but don't integrate it with Twitter.
 
That's all from me, I will be waiting to hear some comments from you!

Sunday, November 11, 2012

Diwali Then & now!

One of the biggest festival which is celebrated all over India, right from Kashmir to Kanyakumari! The festival of light, crackers and last but not the least Sweets and namkeens. Hindu, muslim, Christan, Sikh each and every religion in India enjoy this wonderful festival!

I remember Diwali that I celebrated when I was a kid, I was more interested in cracker guns than crackers which makes noise. I always loved shopping cloths, right from my childhood and I still do! For me Diwali used to be about Holidays, lazy holidays. Lots of shopping - Cloths and Crackers. Meeting relatives, exchange of sweets/namkeens. And not to forget, our school used to give us homework that we had to complete before we step back into school.

Then School to College, transition! Interests/choices changed. Total cut off from crackers and mainly from relatives, spent most of the times with friends. Instead of mom's choice, I started buying branded clothes which were meant to flaunt nothing else :-) Unlike school, I never waited for holidays because I hardly cared about lectures. Every day in college was not less than a holiday itself!

Finally got to taste the real Life, when I started working! We used to get hardly 21 days holiday/year, damn it. Especially festival time, I hardly spent it with my friends/family. And no surprise, Diwali was not an exception :-)

Today, after working for almost two years I am back to study. But things have changed, while writing this blog post I'm thinking about the pending project that is opened one my desktop, book of IT Project Management opened right in front of me. Eating Diwali special sweets, listening to the noise that kids and crackers are making right out of the window. Thinking about somebody, dreaming about life :-)

So now what do I like about Diwali? Well shopping but now not just buying cloths but I also enjoy decorating the house (I mean I bring whatever I like, whatever mom/dad wants). I still love eating Diwali sweets/namkeen, but these days you get them in stores all the year so there's nothing called as 'Diwali Special'. I love going out early in the morning during Diwali time to Sarasbaug (Famous Garden) in Pune, India. Where people gather early in the morning, new cloths, fresh faces and fragrance. You get to meet many people, whom you might not have met in years! Everybody ignites diyas, click photos and then head to Vaishali/Vaadeshwar/Rupali for a special breakfast :-)

Wishing you and your family a prosperous Diwali!

Monday, October 1, 2012

Innovative Ideators, platform for B-School students to showcase their Talent!

When I first saw an email stating 'Need Campus Ambassador for Innovative Ideators' in my college's newly created email inbox, I was excited to know what the heck is this 'Innovative Ideators'?

Frankly I always look forward in participating for branding/marketing activities so whenever I see an opportunity to become Campus Ambassador, I jump into it. But this time it was different unlike my previous experience with Microsoft and Naukri.com. 'Innovative Ideators' is not about any product /service but a team of wonderful individuals who have created a platform for B-School students to participate in  management related competitions. Best thing about it is, it's not a one time competition but series of competitions all over the year!

'Innovative Ideators' help students to showcase their talent and at the same time provide amazing and fresh ideas to Corporate Houses. How? Let me give you the idea!
'Innovative Ideators' use a funda called 'Crowdsourcing' well not quite similar to outsourcing but they are similar in some aspects. Consider a Company, 'NeGa Technology' a pune based IT startup who wants to emerge as a Product Based company in near future but they lack in idea generation. They are clueless as in what product they should develop which will help to earn them reputation and revenue! Even being a start up they had angel investors who had faith in the founders, a team of three IT Professionals. So 'NeGa Technology' hired some creative heads to help the founders in developing that 'Unique' product. They launched a website which gives daily information of 'Events happening today in Colleges around Pune'. The website got huge success, NeGa Technology earned reputation as well as revenue but founders were still not satisfied. As they could target only college crowd, they needed something BIG from teenagers to oldies!
One of the founder read an article about 'Crowdsourcing', a new trend in Business World'. They found a money saving way to generate idea for their 'Unique' product!

So the very next day they gave an advertisement in Daily newspaper saying 'Do you have an 'e'-idea but unable to implement it? We'll show you the way! Mail/Call us NOW!'
From very next day, NeGa Technology received hundreds of emails and phone calls. Within a week they had 300 ideas out of which they shortlisted 80 which were unique! All of this with almost no or little money, the only cost was 'Advertisement in Daily'. They finally decided to merge five ideas into one and designed an innovative e-commerce portal. They offered some share of revenue earned in first year with the people whose ideas were used. While rest of the ideas were not scrapped but NeGa Technology informed other start ups that they have some ideas which can be implemented and shared the same to new start ups asking them to give some profit share to the idea generator if his/her idea is implemented. Win - Win situation isn't it?

Now how does 'Innovative Ideators' fit in this example? Well they arrange competitions which are based on the 'Live Case Study' or simply problems faced by the Corporate Houses for which they need help from a common man/consumer/crowd. In 'Innovative Ideators' case the ideas will be generated from talented and creative minds of students studying in prominent B-Schools! If the idea gets selected there are BIG Prizes and wonderful career opportunities that will be offered by the partner companies!

So why to think, just reach out to your 'Innovative Ideators' Campus Ambassador and get the more clear idea about the competitions!
 

Thursday, August 30, 2012

How to Set Microsoft Outlook (For SCIT Students)

What do you do when you need urgent access to your old emails and you don't have Internet Connectivity?
Don't you get bored seeing the same Google Email Inbox everyday?

Switch to the Best Email Management Application by Microsoft! It not just manages the email but help you to organize your work. Setting reminders, manage your events/Project Submission deadlines/assignment deadlines with the help of Calender! Don't worry about missing an important email - you get a instant pop up if you get any email! Beautiful integration with other Office applications will actually make your life better :-)

Following are the steps to configure your Outlook with 'associates ID'/ Gmail ID.

1. Open Microsoft Outlook 07/10. You'll see 'Add New Account' Wizard, Select 'Manually configure server settings or additional server types' Click on Next.

2. Select 'Internet E-mail' and Click on Next


3. Fill required details as given below.Tick appropriate option shown it the image.


4. Click on More Settings, do not click on Next! You should see a new Window 'Internet Email Settings',Click on tab - 'Outgoing Server'. Put appropriate tick 



5. Click on Tab - Advanced. Ensure you put only what is shown in image below. Do not tick 'Remove from Server after ---- days' you may loose all your emails, I did it once :-(


 6. Click on Ok, you'll see 'Internet E-mail Settings' Window. Click on Next and you are done!

Congrats you setup your own outlook account, successfully!

Let me know if any issue :-)



Tuesday, August 28, 2012

Custom Made Laptop - unReal, why?

I always need customized 'things' in my Life let it be food, bikes even I chose my MBA course which is customizable! The only thing that eats my head every time is, Why can't we have 'Complete' Custom Made Laptops? Don't tell me that you consider Dell Online Store, A place for customizable laptop. I hate Dell, because they do not allow you to customize everything in 'your' Laptop!
Consider a 'Subway Melt' sub prepared at Subway outlets, you can customize it right from bread, veggies, sauces anything and everything in the sub.Why can't we have it in Laptops?

My Idea about Laptop Customization -
It should start from Laptop's outer body - some people like Laptops to be slim like MacBook Air while some likes it Sturdy like Lenovo Thinkpad.
Another best part is keypad - i prefer a keypad with num keys/pad on right side just like the keyboards that we use for PCs.
Most importantly battery - I have a Gateway ID58 Laptop, it earlier had 6 Cell battery but now as I make heavy use of my Laptop I wanted to go for 9 Cell battery. I asked Acer's Vendor (after sales in India for Gateway) but he said my Laptop doesn't support it.
I have seen some of my female friends who rejected some nice Laptops just because they didn't like the color of the panel, too much huh? But I would say, yes they can demand for it and they should!

Why don't we have a Laptop Vendor who can help us in getting an assembled laptop just like we have it for PCs? I understand it's not easy for a Supply Chain to establish in order to procure different things for a single laptop which can vary a lot from one order to second. But if you see the idea has a lot of potential in it. People would definitely buy a 'Custom' made Laptop which may be or mostly will be 'Heavy on Pocket', but they will buy it, just because they get exactly what they want!

I agree it wouldn't be possible for a Vendor like Dell to allow people choose whatever they want and make their laptop ready for use. But entrepreneurs they can definitely think over it, as I really feel that this unnoticed area can really get you 'Real Money'! And the idea - first of it's kind :-)

Do Let me know your views and opinions about my idea! 


Sunday, August 12, 2012

Play Safe with Disgruntled Employees

'Information Security' this word has got a lot of power in it! In my MBA Curriculum (Information Security) at Symbiosis Institute, I often heard terminologies like Threats, Risks, Vulnerabilities and many more.

One of the Threat, i would say the most interesting one is - Disgruntled Employees. The reason i call it as interesting because I wonder how can one predict the intention of a Disgruntled Employee. Definitely it could be a risk for an organization but how can you control them? Just by disabling their access rights and controls? Do you think this would be enough?

Disabling/Revoking the access rights of a Disgruntled Employee can be one of the control measure but according to me the most critical and beyond an organization's control is something different - The Knowledge/insights learn by a Disgruntled Employee during his tenure at the organization. 

Let me take an example: Ajay, a recent college graduate from a Well Known Technical Institute joined Fysat Technology Ltd. a small scale (50-80 employees) IT company into Services. Ajay was interested into Java Development, he also had sound knowledge of Java. But like every other IT Company, he was put into a Support project. Ajay was disheartened but he took interest and started learning things, he was a quick learner so soon he became one of the best knowledgeable resource of his team. But some senior members of the team couldn't digest the fact, they started troubling the newbie. The poor soul couldn't fight back and he fall prey to dirty office politics. 
Time came when the Management announced Yearly Increment, Ajay received least increment, hardly 2%. Reason - His performance was degraded very much, due to some dirty tricks of his seniors Clients escalated many issues about Ajay to Fysat's Management.
Ajay got frustrated within a year though he had good knowledge and technical insights about the work but he couldn't understand and handle managerial things which comes by Experience. 
Finally the day came, one fine morning Ajay put his resignation to his manager. Unaware of the facts manager simply accepted it as he thought Ajay is not worthy resource as he was portrayed by his Seniors to the manager. Even his exit interview was not done properly as the HR felt that this a case of inefficient resource getting kicked out of the company.
Ajay was disheartened, frustrated and angry. But his talent and knowledge that he had gain while working at Fysat helped him to get a decent job at Fysat's competitor Eryat IT Solutions.
Eryat is working into same market where Fysat is operating - South East Asia. Eryat is a market leader but since last few months due to a product launched by Fysat, Eryat was feeling the heat. Fortunately for Eryat, Ajay was the guy who worked extensively in supporting the product for some Big Clients of Fysat.

Now what do you think, by just disabling Ajay's accesses on Client Servers/DBs Fysat will get rid of their 'Disgruntled Employee' ? Can Ajay's knowledge and anger about Fysat help Eryat to beat Fysat?

I feel it's responsibility of Ajay's Manager at Fysat to understand the issues faced by Ajay instead of relying on opinions/view given by senior members of Ajay's team. At least HR should had identified the problems faced by the trainee and if possible change his mind to retain him. But as the person was just a year old at Fysat, HR didn't bother about it.

(I have seen IT industry not much but at least for two years such things happen at many of the IT Companies all over the globe)

For Eryat, Ajay might not prove to be the expert to beat Fysat's special product but his knowledge will definitely be used by Eryat to develop something better than Fysat, something which lacks in Fysat's product.

Disgruntled Employee can potentially impact a lot on the companies, I feel there has to be done something more than just worrying about the Access Control of the Disgruntled Employees. 
What do you think should be done to prevent such losses which may impact organizations terribly!  Do comment to respond :-)

[NOTE: Company names and character name in the above post is fictitious.]

Saturday, July 21, 2012

Learning Phases

I remember when my dad used to tell me, how his friend's son can mug up everything, remembers everything and off course better than me! Since my childhood I'm fan of selective learning ;-) I used to hate to mug up the things but thanks to our Traditional Indian Education System which teaches us - more the marks, better you are! I always used to like practical things - science, never got attracted towards mathematics because I never met a teacher who could taught me why the hell do i need to learn it, how I will be able to use it in my life.I used to hate mathematics because it was more of a mechanical thing for me - you remember the formula fill in the values and get the answer.I never liked it and I still don't like it, thanks to my Statistics Professor at B-School - he make sure only people who 'know' statistics only those will be able to learn the subject which he teaches, rest of us - we just look at the whiteboard!

When I was in Higher Secondary School, I used to love Biology, IT and Chemistry. I used to hate physics too, because it belongs to the same family that of Mathematics! Biology because I used to actually see the things (Botany+Zoology), understand them and used to relate them with day to day life. IT because I used to write HTML, VB code and get something meaningful. Chemistry because I used to enjoy the Lab practicals of mixing different things in each other and get something out of it, it was fun! :)

Somehow I couldn't go for medical studies as I performed worst in my Higher Secondary School Exams.Then came the 'Actual' College life - Graduation period.I had decided that I will either dissect human bodies by doing medical studies or I would go for computer studies, and finally I choose computers rather I had to choose Computers :)

In my graduation, I realized that apart from technology I am good at interacting with people. Thanks to Microsoft Student Partner Program that I got the opportunity to mix both People + Technology and I started evangelize Microsoft's Technologies within students communities. Got appreciation from many people, it boosted my confidence. In my graduation college I never had to explicitly study because I choose something which I loved to do - playing with Technology.

Then came the professional life, where in I explored myself more! I knew that I'll enjoy working in IT industry but I wanted to be on the business side - where in I can gel up with business yet work on technical aspects of it.After spending two years in amdocs, I choose to join the Business Administration program with specialization in IT Business Management.This was the phase when I realized that I actually want to Learn something, not for the sake of earning money but for a better life, new goals and completely new responsibilities!

I feel the change in myself, I was completely different earlier - relaxed, care free (not careless!), had limited aspirations and short term goals. But then came a phase where I realized that I need something bigger and better, I need to attain new professional and personal heights! In my MBA I won't and I don't study for getting good grades, I'm studying for understanding things in different aspects. I'm more focused about learning than grading. I still enjoy subjects like Information Security, ERP than Statistics & Accounts ;) I want to be a Techno managerial IT Professional and not a manager who will sit in his Air Conditioned cabin playing with excels. I want to be a manager who will understand how it works at grass root level than worrying about how to climb the professional ladder fast!

I feel good that I can think about all these things at the age of 23 and I'm sure at the end of two years - once I'm done with my MBA, I'll be completely new person with quality knowledge & new ideas, innovations to implement in the IT industry!

At this moment, I'm clueless of what I have written because I scribbled whatever was there on my mind :)

Thursday, July 12, 2012

Start of a new Journey - MBA

I never ever went to any premier school/college, I always had this weird feeling. A guy with average academics and so called 'Non Engineering Graduate' but never wanted to follow a traditional path.

A traditional Indian Educational Path according to me - Pass school with bad or average or descent marks, get into a College with Science stream get done with it then irrespective of whether you like it or not, whether you have that caliber or not Straight away get into an Engineering College - spend time over there and join the labor force!

I hated it, literally!

The company called amdocs, changed my life literally. Almost two years of stint in amdocs -India, taught me many lessons Worst/Bad/Good/Best everything! Met many talented people, saw tiffs between people, received appreciations - more from Clients than my very own manager, learned how to handle different situations/people. In due course I was still facing sarcasm of being a Non Engineering Graduate - but I was in the best phase of my life, I was with amdocs!

I had earlier decided to learn the technicality in IT Industry for couple of years and then go back to B-School to learn management. I was always attracted to Symbiosis International University -Pune, right from my graduation - I applied for their graduation course of Computer Application but got rejected (back in 2007)! So after 5 years I tried again, but this time for something bigger - MBA. Things worked out and I got a call from Symbiosis Center for Information Technology, Pune to join their 2 year long residential course of MBA - IT Business Management. A wonderfully crafted syllabus with a right blend of IT + Management.

Though I was doing well in my job at amdocs but I knew that some or the other day I'll have to quit and join B-School. So left the wonderful company in June 2012, with a hope and a belief to return back with better and bigger responsibility :)

Symbiosis Center for Information Technology - a premier IT Business School, my next two years in this place is definitely going to change me, my perspective of looking at things. I call it a new beginning - where I'll be getting two long years to study, learn, innovate and enjoy!

Monday, May 21, 2012

Laptop Requirement for SCIT Batch 2012-14

Hi friends, please fill the below form, let's hope to get the best and affordable deal :-)

Friday, April 27, 2012

My Type of 'Tablet'

It's been a quite long time that Tablet or Tablet Computers that has entered into the market. But let me clarify one thing, for me Tablet is not Asus's Eeepad Transformer but iPad or Samsung Galaxy Tab.

Tablet for me is something that can manage everything - be my Mobile Phone, it should allow me to watch HD Videos as well it should be capable of docking the pen drive in it. And I want this whole package to be affordable ~ $200-$250 but NO i just couldn't find such a great deal yet :-(

iPad - I just love the body, color and the feeling when you hold it in hand! It's just superb :-) The OS is fantastic, the app store is huge (But they AngryBird cost you here, noway!!) I have never used Sony's headphones or the music players so for me Apple is the Beast when it comes about Sound :-) I know you people might be thinking, what an A$$ - saying Apple is the Beast ;-)
But the major Turn Off for me about this Sexy white Gadget is - I can't insert the Sim Card in it and try calling somebody. For me a Tablet should have the calling facility, yes I need IT!

Why would you carry an iPad and iPhone at a time, where in the Tablet should have reduced the dependency on a Mobile Phone, I Strongly feel so! I understand that these Tablet/Phone manufacturers wouldn't like if people would start buying a Tablet instead of a phone but this is what a Consumer wants in today's Technological and always Connected World.

Carrying the tablet where ever you go is a pain,Yes I understand that! You don't need a tablet to check the emails/chat with colleagues or friends, a phone definitely can satisfy the need. But then I feel there is something called as User Experience - A User would definitely like to read the email on a 7" or 9" tablet screen, he would love to use the multi-touch Display compared to the 3" or 4" screen of a mobile phone.
Just compare the experience of Video Calling from a mobile with the one by using an iPad (Skype via Wifi)

Many of my friends say to me - how would you receive a voice call from a tab, it's so uneasy to hold the 7" or 9" Tab to your ear. I would say most of the time you can do it by using a hands free but yes there can be some scenarios where it's not possible to use the hands free. But I feel the probability is less! I own a good Bluetooth handsfree by Dell. I've used a Samsung tab and the Dell  handsfree and it works flawless!

The biggest problem with Tab that I feel is - They are BIG. You can't just carry them but you have to CARRY them carefully :-) They aren't that much handy! That's the only and the biggest concern when it comes to buying a Tab :-)

Though price is another concern but if at all the price of an iPad would fall again below $250 :-P I would surely pick one :-)

Another tab that I often think of, 'Let's give it a shot' is Blackberry Playbook. In India the 16GB comes in around $250. It has a USB 2.0 port too! A nice BB OS but again the same problem - I can't call from the Playbook :-( I'll have to enable the WiFi and then by using some App i would have to call to the other mobile phone - this seriously Sucks! Though it isn't cool if you compare it's design with iPad but I can manage ;-) After all it's a good deal in $250.

Then comes the SAMSUNG Galaxy Tab which has everything that I want - I can call from it, I can surf and watch movies on it straight from a youtube too! Just Check this out - Samsung GALAXY Tab 7.7
It's a XXX BOMB, i must admit this! Wonderful device and finally a My Type of Tablet but this beast would cost heavy on the pocket - it's around $700 :-(

But I will surely buy a Tab ;-) My WishList has been updated already!

Friday, April 6, 2012

Google's Project Glass replacement of Smartphone?

It was a nice day in the office when I suddenly saw a Tweet on my phone that quickly diverted my attention from what I was doing ;-) I jumped of from my chair when I saw the video of  Google's 'Project Glass' but I also thought it might be an April Fool prank but then I saw my Twitter timeline started flooding by Project Glass related tweets!!

I'm always fascinated by the electronic gadgets that ranges from a Toy Car to Sexy and Sleek phones ;-) So Google's Project Glass amused me the very first time when I saw the demo of it. I feel if this Technology is not just a concept or a April Fool Prank then I think in coming years this can easily replace the Smartphones. You can call people, text them and can even do a video chat with them without holding any handheld device in your hand. You won't need to wait for Google map to load and then show you the 'How to reach there..' You won't forget to book tickets for your favorite show because by using Google Glasses you can book the tickets on the Go! This is fabulous :-)

I do not wish to comment on the H/W specs or the AI software which might be used in the Google Glasses but I would encourage you to watch the video and post your comments/opinions about it over here :-) And not to forget I'll surely talk about the technical aspects of it, once I hear/see it officially coming from Google! Till then enjoy the video

Google's Project Glass
http://www.youtube.com/watch?feature=player_embedded&v=9c6W4CCU9M4