Thursday, March 12, 2020

HOW TO CHOOSE A PENETRATION TESTER OR PENETRATION TESTING COMPANY?

How do you choose penetration tester or penetration testing company? Is it by his/her certification or by his/her experience? 

We bet you'll choose both. But how do we differentiate a good pentester and a bad pentester? We would like to discuss this and do leave us a comment below. Experience is needed in any industry especially in IT security field. Nowadays, a lot of platforms are given to the hackers to test their ability in a safe environment and helps an organization to secure their organization. These hackers can make millions of dollars even without any certificate at their hands!" link..." 

Certificates are indeed important. They're the standard and a quality control method in selecting your IT security consultant vendor. "link" But to get the best service, there is much more to look at beyond that fancy certificates, marketing, ads etc as a famous quote saying: "don't judge a book by its cover"

Here are our steps to help you to get the best out of the penetration testing service: 

1. Get to know your pentester 
You don't know how good they are until you meet them personally. Client should do some research and prepare a set of both technical and soft skills related pre-questionnaires relevant to your project prior to meeting the penetration tester. The important key here is to check the balance between the technical skill and soft skill of the penetration tester. You'll know later why both are important. You surely don't want your future vendor to just beat around the bush and left you thinking you've chosen the best IT security service provider. 

2. Understand your own scope
Sometimes defining a scope can be mission critical before starting penetration testing assessment. Most of the clients do not know what they truly need and just make an assumption based on their budget. Consult your pentester on this. If he can give a good suggestion to help you formulate your scope, there is a chance that you're dealing with the right person. Good and genuine pentester will recommend things you need, a salesperson will recommend things they want you to have. 

3. How much do pentester charge? 
An expensive service is not necessarily the best and a cheap service does not guarantee you'll get a quality service. One thing one must know is that good and quality penetration testing service requires time and time spent is equivalent to cost spent. A dark hacker took weeks or even months to hack a good system, so realistically don't expect a pentester to find the same vulnerabilities within just one or two days! If they promise such thing, you'll probably ended up getting just a automated scan instead of a thorough and detail penetration testing. Every pentester has their own rates. Let them calculate the cost for you and ask you can ask them to justify their pricing. A standard rate may be applied using man-days. 

4. You know the cost, but how do you define the quality of penetration service? 
Money alone does not solve everthing. If you spend too much, it doesn't necessarily guarantee you a good quality service, and likewise. Keep in mind, quality is subjective. The most important thing is that your objective is achieved. It is a good idea to ask your pentester to explain what level of quality that they can deliver to your organization. One of the best ways to know how good is your pentester is to ask them to give a demo or Proof of Concept (P.O.C) then you'll know how authentic their skill/experience is aside from their fancy certificates. 

5. Communication is vital
Once you've confirmed that your pentester skill set is acceptable and authentic, the next thing is to know if he/she can effectively communicate his/her findings during penetration testing to your organization.Here is when soft skills come to play. A good pentester can explicitly communicate technical findings during findings presentation in a language that is understandable to their client and thus ultimately come out with an effective solution to remediate vulnerabilities and develop a good action plan for their client. 

6. Report is mission critical 
Last, the penetration testing report. Don't get too excited if the pentester can deliver the report to you in a short period of time. Sometimes, pentester need to allocate longer timeline to complete the assessment so they can provide a better insight of their findings and also come up with a better solution. So the important key is constant communication during penetration testing project. 

That's all folks, we hope this brief guide can help you choose your IT security vendor, happy pentesting!

NATIONAL CYBER SECURITY POLICY

KUALA LUMPUR: The Government plans to establish a National Cybersecurity policy to better secure the nation against threats, says Gobind Singh Deo (pic).
The Communications and Multimedia Minister said his ministry will be spearheading the policy in collaboration with the National Cybersecurity Agency and the Malaysian Communications and Multimedia Commission.
"With Malaysia's digital economy growing by leaps and bounds, it is inevitable that there will be unintended consequences.
"Threats like data breaches and theft, sabotage, intrusion, and cyber espionage can have adverse impacts on organisations and the state," he said.
One of the areas is to develop more local cybersecurity talents.
"Developing the right talent is a very important aspect of cybersecurity preparedness.
"It is crucial that we establish a sustainable model with the cooperation of various government agencies (along with) academic and private institutions," he said.
Gobind added that he will suggest amending laws to combat cyberbullying and cybercrimes.
"We could introduce new provisions in the Penal Code, for example, so that such crimes could be investigated by the police.
"But before we do all these, I am in the process of discussing it with the police to get their views," he said.

Read more at https://www.thestar.com.my/news/nation/2018/12/03/national-cybersecurity-policy-for-online-threats-being-discussed-says-gobind/#cksoZWUpPFHYmTcb.99 

Tuesday, December 4, 2018

Marriott hotels hacked, credit card details and data of 500 million guests stolen: All you need to know

Hackers have stolen data of nearly 500 million guests who stayed at Marriott group hotels. This data includes in some cases credit card details, addresses and passport scans that people submitted to Marriott.

ADVERTISEMENT
JW Marriott

HIGHLIGHTS

  • The attack had been taking place since 2014 on Marriott's Starwood reservation system and has affected nearly 500 million guests.
  • As of now, according to a research by the cybersecurity firm Recorded Future, the stolen data from Starwood's servers have not been spotted anywhere on the dark web.
  • Guests can head over to a dedicated website that Marriott has set on this matter or call up the group's customer care support.
If you have ever stayed a Marriott hotel or a hotel that the group operates, chances are that some of your data have been stolen by hackers. According to the hotel group, its servers and database were breached, probably multiple times, before September 10 this year. In the breach data of nearly 500 million guests have been stolen, and this data in many cases includes credit card information, passport scans, addresses, phone numbers and email IDs.
On November 30, the Marriott announced that their entire chain of hotels was affected by the massive cybersecurity breach. The attack had been taking place since 2014 on Marriott's Starwood reservation system and has affected nearly 500 million guests. The group was unaware of the ongoing attack for the last four years. It found the data breach only in September this year when one of the security measures in its server alerted IT staff of an unauthorised access to the database. The hotel group has acknowledged the mistakes on its part and is trying multiple ways to ensure the stolen data isn't misused anywhere.
As of now, according to a research by the cybersecurity firm Recorded Future, the stolen data from Starwood's servers have not been spotted anywhere on the dark web - a place where hackers and cybercriminals sell data illegally in lieu of monetary benefits. Therefore, this suggests the hackers were not looking to sell the data to anyone.
Source: https://www.indiatoday.in/technology/features/story/marriott-hotels-hacked-credit-card-details-and-data-of-500-million-guests-stolen-all-you-need-to-know-1400263-2018-12-01

Thursday, October 4, 2018

Police, AG targeted by Russian hacker

Report: Police, AG targeted by Russian hackers

Russian hackers’ activities were exposed following the seizure of laptops from four suspects briefly detained in the Netherlands. — Reuters pic
Russian hackers’ activities were exposed following the seizure of laptops from four suspects briefly detained in the Netherlands. — Reuters pic
KUALA LUMPUR, Oct 5 — A global investigation into Russian state-sponsored cyber espionage revealed that the Attorney General’s Chambers (AGC) and Royal Malaysia Police were also targeted by the hackers.
According to a report by British state broadcaster BBC, the motive for the cyber attacks on Malaysian authorities was over the multinational investigation into Russia’s role in the downing of Malaysia Airlines Flight MH17.

Russian hackers’ activities were exposed following the seizure of laptops from four suspects briefly detained in the Netherlands, from which investigators discovered their use in four global locations including Malaysia.
From one confiscated machine, investigators extracted information that one Dutch official said contained details of a cyber-operation based here that targeted the AGC and PDRM.
The report did not reveal the nature of the cyber-attacks or whether these were successful.
Russia stands accused of various espionage schemes, both in cyberspace and in the real world, that includes attempts to mask the extent of its involvement in the missile launch that brought down the Malaysian plane in 2014.

The BBC report also said countries worldwide including the US, the UK, Canada, and the Netherlands suspect that Moscow coordinated various espionage attacks that span election hacking, disrupting anti-doping probes, and an attack on an American nuclear power firm.
Suspicions of Russian state involvement were heightened as the four suspects carried Russian diplomatic passports, which prevented Dutch authorities from arresting them.
A US national security official told the media in Washington that the attacks were meant to discredit and delegitimize agencies investigating Russia over various matters.

Russia has denied all the claims, insisting that Western rivals were prejudiced in their view of the country.
“It’s unclear who is supposed to believe these statements accusing Russian citizens of attempting to mount cyber-attacks against the OPCW and trying to obtain data related to the Malaysian flight MH17, as if it is necessary to be near the target of your attack,” Moscow said in a statement.
“Any Russian citizen carrying a mobile device is seen as a spy.”
MH17 was shot down on July 17, 2014, while flying over eastern Ukraine as it was heading from Amsterdam to Kuala Lumpur. All 283 passengers and 15 crew members were killed.

The Joint Investigation Team headed by the Dutch Ministry of Justice, eventually indicated the plane may have been down by pro-Russian rebels fighting against the Ukrainian government, which Moscow has denied.

Tuesday, October 2, 2018

Almost 10,000 online incidents reported to CyberSecurity Malaysia each year

PUTRAJAYA: CyberSecurity Malaysia receives between 9,000 and 10,000 incident reports each year on various matters of contention happening in cyberspace.
Its chief executive officer Datuk Dr Amirudin Abdul Wahab said one of the reported incidents were data breaches, classified under the intrusion category.
"This category also includes hacking. For data breaches, we are seeing a rising trend (over the last few years). In 2015, we received seven data breach reported incidents and six cases last year.
"This year until September, however, we have seen a four-fold increase with 22 reported incidents on data breaches (alone).
"It shows now that data breaches are a concern. Individuals as well as organisations would do well to adopt best practices," he said.
He was speaking to reporters after the signing of a memorandum of understanding between CyberSecurity Malaysia and Turkey's May Cyber Teknoloji.
The MoU identifies three areas of collaboration- research and development covering the areas of cyber security technical, tools, methods and processes; capacity building through competency training programmes as well as cyber security skills, and develop marketing strategies to promote cyber security.
Amirudin said data breaches are not a local phenomenon, noting that cyber threats, data breaches and cyber crime had been listed as the top three global risks last year.
For the past five to six years, he said, CyberSecurity has seen a growing number of cyber incidents with fraud topping the list followed by intrusion, malicious codes and cyber harassment.
As of October, the cyber security specialist agency has received 3,240 reported incidents on fraud; 1,781 on intrusion; 694 on malicious codes and 499 on cyber harassment.
"We have so far received 6,891 incident reports in total as of October this year," said Amirudin.
Meanwhile, chairman of the CyberSecurity Board of Directors, General Tan Sri Mohd Azumi Mohamed says the recent data leak involving data of 46.2 million Malaysian mobile phone customers is now a police case.
"As we are fully aware, the police are investigating (it). So let us leave it to the police," he said, declining to elaborate on the case.
It was reported recently that a data comprising mobile phone numbers, identification card numbers, home addresses, IMEI and SIM card data had been leaked.
The data breach was first reported last month by public online forum Lowyat.net, which said it had received information that someone was trying to sell huge databases of personal information.
The databases are also believed to contain private information of more than 80,000 individuals, leaked from records of the Malaysian Medical Council, the Malaysian Medical Association, and the Malaysian Dental Association, Lowyat.net reportedly said.
Amirudin said CyberSecurity is always ready to provide its technical support and expertise to any enforcement agencies, which it had done before.
"For example, if there is a (data) breach, they can report to our Cyber999 or call us at 1-300-88-2999," he said, adding that the statistics he gave earlier did not include the data leak incident of more than 40 million telco customers.

Report: Malaysia's cybersecurity is third best globally

PETALING JAYA: Malaysia is ranked third among 193 countries in terms of its commitment to cybersecurity, according to the Global Cybersecurity Index (GCI) 2017.
According to the report released on Thursday, Malaysia achieved a score of 0.89, behind Singapore and the United States.
The report cited Malaysia's creation of the Information Security Certification Body, a department in Cybersecurity Malaysia, as one of the reasons behind its excellent commitment in ensuring a safe cyberspace.
According to Cybersecurity Malaysia CEO Datuk Dr Amirudin Abdul Wahab, this is the second time the International Telecommunication Union has conducted such a study.
"The previous one was done in 2014 and produced in early 2015, where Malaysia also ranked third globally.
"Malaysia has maintained its ranking for two consecutive reports," said Dr Amirudin in a WhatsApp reply to The Star.
Countries in the top 10 include Oman, Estonia, Mauritius, Australia, Georgia, France and Canada.
The GCI is a survey that measures the commitment of 193 member states to cybersecurity.
It assesses a country based on five pillars, namely legal, technical, organisational, capacity building, and cooperation.
Launched in 2014, the GCI aims to foster a global culture of cybersecurity.
According to the report, nearly 1% of all emails sent in 2016 were malicious attacks.
Ransomware attackers are demanding more from victims, with the average rising to US$1,000 (RM4,305) from just US$300 (RM1,291) a year before.
In May, the ransomware WannaCry wreaked havoc across 150 countries, causing disruption to companies and even hospitals.
Just a few weeks later in June, another ransomware called NoPetra broke out in Europe, crippling thousands of machines.
The report called for greater cooperation around the world to fend off and prevent such attacks.
The top ten countries are:
1. Singapore (GCI score of 0.92)
2. United States (0.91)
3. Malaysia (0.89)
4. Oman (0.87)
5. Estonia (0.84)
6. Mauritius (0.82)
7. Australia (0.82)
8. Georgia (0.81)
9. France (0.81)
10. Canada (0.81)

Read more at https://www.thestar.com.my/news/nation/2017/07/06/malaysia-rank-high-cybersecurity-commitment/#pxfkCgFJPApU2vVa.99

Countries with the highest commitment to cyber security based on the Global Cybersecurity Index (GCI) as of September 2016

This statistic presents a ranking of the countries with the highest commitment to cyber security based on the Global Cybersecurity Index (GCI) as of September 2016. During the measured period, Singapore ranked first with a GCI score of 0.92. The United States were ranked second with a GCI score of 0.91 index points.


GCI ScoreLegalTechnicalOrganizationalCapacity BuildingCooperation
Singapore0.920.950.960.880.970.87
United States0.9110.960.9210.73
Malaysia0.890.870.960.7710.87
Oman0.870.980.820.850.950.75
Estonia0.840.990.820.850.940.64
Mauritius0.820.850.960.740.910.7
Australia0.820.940.960.860.940.44
Georgia0.810.910.770.820.90.7
France0.810.940.960.610.61
Canada0.810.940.930.710.820.7

Cybersecurity needs AI as much as AI needs cybersecurity - Techzine Europe

Cybersecurity needs AI as much as AI needs cybersecurity  Techzine Europe http://dlvr.it/TDY1dr