<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ClubHack &#187; Articles</title>
	<atom:link href="http://www.clubhack.com/category/articles/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.clubhack.com</link>
	<description></description>
	<lastBuildDate>Mon, 02 Apr 2012 11:23:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>IE6 Countdown</title>
		<link>http://www.clubhack.com/ie6-countdown/</link>
		<comments>http://www.clubhack.com/ie6-countdown/#comments</comments>
		<pubDate>Wed, 09 Mar 2011 14:42:00 +0000</pubDate>
		<dc:creator>neelimag</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=945</guid>
		<description><![CDATA[Last week Microsoft launched a deathwatch for its 10 year old Internet Explorer 6 browser to ensure that IE6 is &#8220;gone for good&#8221;. According to Microsoft, IE6 still has a 12% global usage share, with almost half of that in China with 5.9% usage. Other countries with a higher-than-average IE6 share include South Korea, India [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Last week Microsoft launched a deathwatch for its 10 year old Internet Explorer 6 browser to ensure that IE6 is &#8220;gone for good&#8221;.</p>
<p>According to Microsoft, IE6 still has a 12% global usage share, with almost half of that in China with 5.9% usage. Other countries with a higher-than-average IE6 share include South Korea, India and Taiwan.</p>
<p>As part of this drive, Microsoft wants to bring IE6&#8242;s share under 1%. That site, ie6countdown.com , shows Net Applications&#8217; usage share numbers for IE6 in 43 countries, including the China, U.S., India, as well as the browser&#8217;s current global share.</p>
<p>For more details see:</p>
<p><a href="http://www.ie6countdown.com/">http://www.ie6countdown.com/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/ie6-countdown/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bruce Schneier and ClubHACK 2010 Event</title>
		<link>http://www.clubhack.com/bruce-schneier-and-clubhack-2010-event/</link>
		<comments>http://www.clubhack.com/bruce-schneier-and-clubhack-2010-event/#comments</comments>
		<pubDate>Wed, 05 Jan 2011 04:48:27 +0000</pubDate>
		<dc:creator>shrabasti</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Event]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Past Events]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=814</guid>
		<description><![CDATA[Bruce Schneier, a cryptographer, computer security specialist, and author graced ClubHack2010 as a special guest and keynote speaker and releasing CHMag Dec Edition. He was received at airport by a volunteer who didn&#8217;t took his name placard rather the volunteer took a print of Bruce Lee&#8217;s Picture. He loved it. Bruce Schneier was welcomed at ClubHack2010 [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Bruce Schneier, a cryptographer, computer security specialist, and author graced ClubHack2010 as a special guest and keynote speaker and releasing CHMag Dec Edition.</p>
<p><a href="http://clubhack.com/wp-content/uploads/2010/12/DSC_6373.jpg"><img class="aligncenter size-medium wp-image-837" title="DSC_6373" src="http://clubhack.com/wp-content/uploads/2010/12/DSC_6373-300x199.jpg" alt="" width="300" height="199" /></a></p>
<p>He was received at airport by a volunteer who didn&#8217;t took his name placard rather the volunteer took a print of Bruce Lee&#8217;s Picture.<br />
<a href="http://clubhack.com/wp-content/uploads/2010/12/bruce-lee.jpg"><img class="aligncenter size-medium wp-image-835" title="bruce-lee" src="http://clubhack.com/wp-content/uploads/2010/12/bruce-lee-180x300.jpg" alt="" height="150" /></a><br />
He loved it.</p>
<p>Bruce Schneier was welcomed at ClubHack2010 in traditional way &amp; sported the &#8220;pheta&#8221; at the whole conference.</p>
<p><img class="aligncenter" src="http://3.bp.blogspot.com/_IrNvKJwEsM0/TPulOhk3bRI/AAAAAAAAGL0/ylIl13IJyu0/s320/DSC_6339.JPG" alt="" width="320" height="213" /></p>
<p>During his welcome <a href="http://twitter.com/#/rohit11" target="_blank">@rohit11</a>, <a href="http://twitter.com/#/clubhack" target="_blank">@clubhack</a>&#8216;s founder told him the story of <a href="http://en.wikipedia.org/wiki/Dronacharya#Ekalavya_and_Karna">guru dronacharya &amp; eklavya</a> and told him that many people in India are eklavya for you and take you as guru Dronacharya can do anything to be your student.</p>
<p>After that he came on stage to give his talk on cyber war for an hour.</p>
<p>The total time Bruce spent in Pune was 7 hours but he and attendees of ClubHack2010 enjoyed every moment of it. Our official photographer was smart enough to take out his won time with Bruce to click some special photographs. Some of them are here for you</p>
<p><a href="http://clubhack.com/wp-content/uploads/2010/12/DSC_6514.jpg"><img class="size-thumbnail wp-image-846 alignleft" title="DSC_6514" src="http://clubhack.com/wp-content/uploads/2010/12/DSC_6514-150x150.jpg" alt="" width="150" height="150" /></a><a href="http://clubhack.com/wp-content/uploads/2010/12/DSC_6499.jpg"><img class="alignleft size-thumbnail wp-image-845" title="DSC_6499" src="http://clubhack.com/wp-content/uploads/2010/12/DSC_6499-150x150.jpg" alt="" width="150" height="150" /></a><a href="http://clubhack.com/wp-content/uploads/2010/12/DSC_6483.jpg"><img class="alignleft size-thumbnail wp-image-844" title="DSC_6483" src="http://clubhack.com/wp-content/uploads/2010/12/DSC_6483-150x150.jpg" alt="" width="150" height="150" /></a><a href="http://clubhack.com/wp-content/uploads/2010/12/DSC_6415.jpg"><img class="alignleft size-thumbnail wp-image-843" title="DSC_6415" src="http://clubhack.com/wp-content/uploads/2010/12/DSC_6415-150x150.jpg" alt="" width="150" height="150" /></a><a href="http://clubhack.com/wp-content/uploads/2010/12/DSC_6402.jpg"><img class="alignleft size-thumbnail wp-image-842" title="DSC_6402" src="http://clubhack.com/wp-content/uploads/2010/12/DSC_6402-150x150.jpg" alt="" width="150" height="150" /></a><a href="http://clubhack.com/wp-content/uploads/2010/12/DSC_6380.jpg"><img class="alignleft size-thumbnail wp-image-841" title="DSC_6380" src="http://clubhack.com/wp-content/uploads/2010/12/DSC_6380-150x150.jpg" alt="" width="150" height="150" /></a><a href="http://clubhack.com/wp-content/uploads/2010/12/DSC_6309.jpg"><img class="alignleft size-thumbnail wp-image-839" title="DSC_6309" src="http://clubhack.com/wp-content/uploads/2010/12/DSC_6309-150x150.jpg" alt="" width="150" height="150" /></a><a href="http://clubhack.com/wp-content/uploads/2010/12/Bruce2.png"><img class="alignleft size-thumbnail wp-image-838" title="Bruce2" src="http://clubhack.com/wp-content/uploads/2010/12/Bruce2-150x150.png" alt="" width="150" height="150" /></a><a href="http://clubhack.com/wp-content/uploads/2010/12/DSC_6317.jpg"><img class="alignleft size-thumbnail wp-image-840" title="DSC_6317" src="http://clubhack.com/wp-content/uploads/2010/12/DSC_6317-150x150.jpg" alt="" width="150" height="150" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/bruce-schneier-and-clubhack-2010-event/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Favorite Password Manager</title>
		<link>http://www.clubhack.com/favorite-password-manager/</link>
		<comments>http://www.clubhack.com/favorite-password-manager/#comments</comments>
		<pubDate>Wed, 05 Jan 2011 04:06:42 +0000</pubDate>
		<dc:creator>ClubHack</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=828</guid>
		<description><![CDATA[Few days back ClubHack started an anonymous survey of favorite password manager via twitter &#38; facebook. Check the survey @ http://j.mp/PassMgr Here is first cut report of the same As expected the most favorite password manager is &#8220;Brain&#8221; but beyond that LastPass is winning the race in products. There were some interesting entries in the [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Few days back ClubHack started an anonymous survey of favorite password manager via twitter &amp; facebook. Check the survey @ <a href="http://j.mp/PassMgr">http://j.mp/PassMgr</a></p>
<p><strong>Here is first cut report of the same</strong></p>
<p style="text-align: center;"><a href="http://clubhack.com/wp-content/uploads/2011/01/password-manager-chart.png"><img class="aligncenter size-full wp-image-829" title="password manager chart" src="http://clubhack.com/wp-content/uploads/2011/01/password-manager-chart.png" alt="Favorite Password Manager" width="630" height="419" /></a></p>
<p>As expected the most favorite password manager is &#8220;Brain&#8221; but beyond that LastPass is winning the race in products.</p>
<p><strong>There were some interesting entries in the password manager which we think are worth sharing</strong></p>
<blockquote><p># Notepad &#8211; Dude, now please let everyone know where you keep this notepad <img src='http://www.clubhack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p># PGP encrypted file</p>
<p># Winrar SXF</p>
<p># Draft in gmail</p></blockquote>
<p><strong>Few more products came into light which were not in our initial list</strong></p>
<blockquote><p># 1PasswordPro</p>
<p># PasswordCard- <a href="http://www.passwordcard.org/en">http://www.passwordcard.org</a> This is interesting</p>
<p># Xmarks &#8211;  still???</p>
<p># PasswordSafe</p></blockquote>
<p>The survey is still on  and you can give your anonymous views at <a href="http://j.mp/PassMgr">http://j.mp/PassMgr</a></p>
<p>We&#8217;ll keep updating this post with periodic results</p>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/favorite-password-manager/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ClubHack wallpapers</title>
		<link>http://www.clubhack.com/clubhack-wallpapers/</link>
		<comments>http://www.clubhack.com/clubhack-wallpapers/#comments</comments>
		<pubDate>Tue, 30 Nov 2010 03:36:41 +0000</pubDate>
		<dc:creator>ClubHack</dc:creator>
				<category><![CDATA[Articles]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=800</guid>
		<description><![CDATA[Here are few wallpapers for you Brought to you by deepranjan@chmag.in]]></description>
			<content:encoded><![CDATA[<p></p><p>Here are few wallpapers for you</p>
<p><img class="aligncenter size-medium wp-image-803" title="wallpaper3" src="http://clubhack.com/wp-content/uploads/2010/11/wallpaper3-300x225.jpg" alt="" width="300" height="225" /><br />
<img class="aligncenter size-medium wp-image-802" title="wallpaper2" src="http://clubhack.com/wp-content/uploads/2010/11/wallpaper2-300x225.jpg" alt="" width="300" height="225" /><a href="http://clubhack.com/wp-content/uploads/2010/11/wallpaper1.jpg"></a></p>
<p><a href="http://clubhack.com/wp-content/uploads/2010/11/wallpaper1.jpg"><img class="aligncenter size-medium wp-image-801" title="wallpaper1" src="http://clubhack.com/wp-content/uploads/2010/11/wallpaper1-300x225.jpg" alt="" width="300" height="225" /></a></p>
<p>Brought to you by deepranjan@chmag.in <img src='http://www.clubhack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/clubhack-wallpapers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beware :- Firesheep Firefox Add-on can hijack Facebook And Twitter Accounts over an open Wi-Fi connection</title>
		<link>http://www.clubhack.com/beware-firesheep-firefox-add-on-can-hijack-facebook-and-twitter-accounts-over-an-open-wi-fi-connection/</link>
		<comments>http://www.clubhack.com/beware-firesheep-firefox-add-on-can-hijack-facebook-and-twitter-accounts-over-an-open-wi-fi-connection/#comments</comments>
		<pubDate>Tue, 26 Oct 2010 09:05:44 +0000</pubDate>
		<dc:creator>shrabasti</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Attacks]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=776</guid>
		<description><![CDATA[The add-on, named &#8216;Firesheep&#8217;, was released by web application developer Eric Butler during the ToorCon security conference held in San Francisco and is designed to hijack a user&#8217;s current internet session over the unsecured Wi-Fi network. The main motive behind the release of the add-on is to make people aware of the dangers of accessing [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>The add-on, named &#8216;Firesheep&#8217;, was released  by web application developer Eric Butler during the ToorCon security conference held in San Francisco and is designed to hijack a user&#8217;s current internet session over the unsecured Wi-Fi network.</p>
<p>The main motive behind the release of the add-on is to make people aware of the dangers of accessing unencrypted websites from public Wi-Fi hotspots, Butler said.</p>
<p>More details :-</p>
<ul>
<li><span style="font-size: 13.2px"><a href="http://codebutler.com/firesheep" target="_blank">http://codebutler.com/firesheep</a></span></li>
<li><a href="http://links.visibli.com/links/517bbe" target="_blank">http://links.visibli.com/links/517bbe</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/beware-firesheep-firefox-add-on-can-hijack-facebook-and-twitter-accounts-over-an-open-wi-fi-connection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is your information in safe hands? Customer database threatened by insider leakages</title>
		<link>http://www.clubhack.com/is-your-information-in-safe-hands-customer-database-threatened-by-insider-leakages/</link>
		<comments>http://www.clubhack.com/is-your-information-in-safe-hands-customer-database-threatened-by-insider-leakages/#comments</comments>
		<pubDate>Thu, 16 Sep 2010 09:39:08 +0000</pubDate>
		<dc:creator>Amey Anekar</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=586</guid>
		<description><![CDATA[Have you ever received promotional calls by companies you have never heard of? Or are you sure that you have never agree to give your phone number to these companies? Customer database is the answers to these questions. Companies acquire your information by buying the database. Personal information values especially in market-driven economy. Who buy [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="separator" style="clear: both; text-align: center;"><a href="http://www.techkranti.com/2010/09/is-your-information-in-safe-hands.html"><img class="alignright" style="border: 0pt none;" src="http://2.bp.blogspot.com/_Kic0h6eqy-A/TImZlRGWbGI/AAAAAAAAAaw/-Tt_z8ZdcHo/s200/insider.jpg" border="0" alt="" width="200" height="138" /></a></div>
<p>Have you ever received promotional calls by companies you have never heard of? Or are you sure that you have never agree to give your phone number to these companies? Customer database is the answers to these questions. Companies acquire your information by buying the database.</p>
<p>Personal information values especially in market-driven economy. Who buy what kinds of products, formulates the marketing and promotion strategies of the companies. A list of personal date do value.</p>
<p>Data could be sold everywhere, by everyone, even from the insiders. Cisco conducted a global study on data security and leakage in businesses in 2008. The study showed ”insider threat” is the major threat to customer data. It means data loss or leakages resulting from employee behavior. It could be due to carelessness, such as forget to log off, share passwords among colleagues, or even fail to return company devices when quitting the job. The internal factor poses a greater threat to the data security far more than external factors such as hackers do.</p>
<p>The above excerpt is taken from hackinthebox.org. To add to it, I would like to describe an incidence with my friend.</p>
<p>I recently joined a technical course which had a tenure of 14 days. In the same batch was a guy named Shella from Italy. He had come to India to just pursue the course. And he had only visited Bangalore and Mumbai. He had bought a Vodafone SIM from Bangalore and no one had his number except two organisations, one, the institute where we were pursuing this course, and two, VODAFONE. One fine day he gets a promotional SMS on his cell from some college offering an MBA course. He narrates to me about this and says &#8220;I haven&#8217;t given my number to anyone in India, except  %#Solutions(The institute where we pursued our course), so I think these people might have provided my number to this promoter&#8221;. But, the SMS was from a college from Bangalore and there is no question of an institute in Mumbai to provide details to some college in Bangalore. So by now we should be pretty sure from where the data had been leaked. Yes, it could be someone from Vodafone, Bangalore.</p>
<p>This was just an example of insider data breaches. Organizations trust their employees to handle sensitive data and they need to do that because employees are the primary assets a company owns. In DEFCON this year a social engineering competition was held to see how creative hackers can be. Hackers demonstrated the idea of a fake interview to siphon information from a rival organization&#8217;s employee. First the employee in the rival company is called and told that we have a better offer for you than your current one. Then a fake interview is setup with the hacker who poses to be the employer. The place could be a plush lounge or restaurant where the employee feels that the employer is real and not making it all up. After all organizations can go to any extent to get their rival&#8217;s sensitive information. The hacker then starts siphoning information from the employee and it can be well understood that a human can be most  vulnerable when in an interview, because we generally tend to look at the interviewer being superior to us and we are very cautious about our speech. A normal human mind might think that If I am getting a better job just by giving out some information, then it won&#8217;t harm much. We recommend that the hacker be accompanied with a psychiatrist for better results.:-)</p>
<p>Customer data breaches have been prevalent in India since many years. In a sting operation about 5-6 years ago on a news show I heard that one contact number sells for Rs 7. I am sure the price must have at least been doubled by now looking at the competition for better marketing.</p>
<p>Information:<br />
(For Indian Subscribers)If you want to stop receiving promotional SMS&#8217; and calls send an SMS as:<br />
&#8216;START DND&#8217; without quotes and send it to 1909. This is a Do Not Disturb service and has been initiated by TRAI(Telecom Regulatory Authority of India).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/is-your-information-in-safe-hands-customer-database-threatened-by-insider-leakages/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Calcutta gets her first cyber crime police station</title>
		<link>http://www.clubhack.com/calcutta-gets-her-first-cyber-crime-police-station/</link>
		<comments>http://www.clubhack.com/calcutta-gets-her-first-cyber-crime-police-station/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 06:18:08 +0000</pubDate>
		<dc:creator>shrabasti</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Event]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=488</guid>
		<description><![CDATA[Infosys chairman N.R. Narayana Murthy inaugurated Calcutta’s first cyber crime police station and a technologically upgraded control room at Lalbazar along with chief minister Buddhadeb Bhattacharjee. “The computer makes people efficient, conquers distance and improves the quality of life. The new technology will definitely enhance the quality of crime detection in Calcutta,” he said. “He [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Infosys chairman N.R. Narayana Murthy inaugurated Calcutta’s first cyber crime police station and a technologically upgraded control room at Lalbazar along with chief minister Buddhadeb Bhattacharjee.</p>
<blockquote><p>“The computer makes people efficient, conquers distance and improves the quality of life. The new technology will definitely enhance the quality of crime detection in Calcutta,” he said.</p></blockquote>
<blockquote><p>“He put forward a number of interesting questions to the officers. His suggestions will help Calcutta police,” said Bhattacharjee.</p></blockquote>
<p>More details : <a href="http://www.telegraphindia.com/1100825/jsp/frontpage/story_12853385.jsp">http://www.telegraphindia.com/1100825/jsp/frontpage/story_12853385.jsp</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/calcutta-gets-her-first-cyber-crime-police-station/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>E-mail Hacking Anatomy</title>
		<link>http://www.clubhack.com/e-mail-hacking-anatomy/</link>
		<comments>http://www.clubhack.com/e-mail-hacking-anatomy/#comments</comments>
		<pubDate>Thu, 29 Jul 2010 19:49:05 +0000</pubDate>
		<dc:creator>shrabasti</dc:creator>
				<category><![CDATA[Articles]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=297</guid>
		<description><![CDATA[Written by a programmer or acquired by a criminal, an e-mail virus is a piece of computer code spread via email and designed to run on any computer. Occasionally, the code is nested in an attachment and installed after the victim opens it up. Once it gets its hooks into your computer, the virus can [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Written by a programmer or acquired by a criminal, an e-mail virus is a piece of computer code spread via email and designed to run on any computer.</p>
<p>Occasionally, the code is nested in an attachment and installed after the victim opens it up. </p>
<p>Once it gets its hooks into your computer, the virus can scan word documents, spreadsheets and address books, on the prowl for other active e-mail addresses to target.</p>
<p>For some victims, the telltale sign of a computer hijack is when the confused e-mail arrives from an estranged ex.</p>
<p>If the software has lapsed, its mandatory that one should install antivirus software from a full-service company that offers free updates with the program. If the virus is still present after running virus removal and scanning programs, we might have to reload the entire system.</p>
<p>If we wish to keep our computer and personal lives free of complications, experts say the most important piece of advice is to read our electronic mail with a healthy dose of apprehension.</p>
<p>More Details :- <a href="http://abcnews.go.com/Technology/anatomy-mail-hack/story?id=11101261">http://abcnews.go.com/Technology/anatomy-mail-hack/story?id=11101261</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/e-mail-hacking-anatomy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Engineering – Myth &amp; Reality</title>
		<link>http://www.clubhack.com/social-engineering-%e2%80%93-myth-reality/</link>
		<comments>http://www.clubhack.com/social-engineering-%e2%80%93-myth-reality/#comments</comments>
		<pubDate>Thu, 22 Jul 2010 16:43:55 +0000</pubDate>
		<dc:creator>VishalK™</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Network]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=241</guid>
		<description><![CDATA[Please note this article is for educational purpose only. What be your reaction if you get a mail in your corporate Inbox with from field as “HR Helpdesk” (assuming that’s how HR mail appears in your organization) with subject as “Best Employee Bonus of Rs. 1,50,000”? The mail reads that you have been awarded the [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>Please note this article is for educational purpose only. </strong></p>
<p>What be your reaction if you get a mail in your corporate Inbox with from field as “HR Helpdesk” (assuming that’s how HR mail appears in your organization) with subject as “Best Employee Bonus of Rs. 1,50,000”? The mail reads that you have been awarded the bonus because of your hard work, dedication etc. All you need to do is reply with some of your official &amp; personal details and the bonus is yours. If I were you I would jump on it and reply in matter of 30 seconds.</p>
<p>However, what you would have failed to notice is that the email ID in reply field would not be one of your HR’s corporate email ID’s but some malicious unknown email ID on the public domain. This is what we called Social Engineering.</p>
<p>Social Engineering is a term associated with attacker’s abilities to manipulate the natural human tendency of trust leading to malicious activities like unauthorized access, loss of confidential details, phishing etc. It’s actually an art of luring people in getting them to do what you desire. A child emotional pursuing his parents to buy her a toy, a sales person convincing the customer to buy his products or a phishing attack are all examples of Social Engineering.</p>
<p><strong><em>Social Engineering can be categorized as Physical &amp; Physiological. </em></strong></p>
<p>1        <strong>Physical</strong> – In this case an attacker attempts to circumvent physical security controls.</p>
<p>Amongst many, some of the examples dealing with Physical Social Engineering are:</p>
<ul>
<li>Bypassing the physical security checks and gaining unauthorized access to physical premises</li>
<li>As a visitor entering the cabin of a Top level executive in her / his absence</li>
<li>Impersonating as a courier agent and dropping off an unchecked parcel to a C-Suite executive’s cabin.</li>
<li>Entering restricted areas like data center and gain unauthorized access to critical details like network setup</li>
<li>Tailgating thru main entrance and other entry / exit points (Fire exits, smoking zones etc.)</li>
<li>Impersonating as a government official / person belonging to an authorized department (Electricity Board, Fire Department etc.) and conducting a site visit to gain critical information related to the facility</li>
</ul>
<p>2        <strong>Psychological</strong> – In this case attacker plays with victims trust basically uses a human psychological factor.</p>
<p>Amongst many, some of the examples of psychological social engineering are:</p>
<ul>
<li>An email from Public domain ID example ABC@goodsite.com (name in the INBOX could be displayed as HR@corporatenetwork.com / IT@corporatenetwork.com)</li>
</ul>
<p>The content of the mails could be:</p>
<p>1        “This is an automated employee detail collection form. In the view of current HINI Pandemic and heavy rains we are in process of updating and maintaining an up to date employee database. All the ‘CorporateNetwork’ employees are requested to cooperate and provide the necessary details at the earliest. Please fill in all the details and submit the form. This is an auto generated email, please do not reply to this email.”</p>
<p>2        “Virus Alert Recipient name: This is an automated alert sent by the virus update engine. A new virus which targets IT Services and Software Development organizations has been circulating the Internet. This particular virus requires an immediate software update to prevent infection. Please click the link below to update your workstation with necessary patches”</p>
<ul>
<li>Cold Calls to Employee’s impersonating as vendors or media personnel&#8217;s inquiring about the internal related details like Applications, IT Infrastructure, Physical Security etc.</li>
<li>Calls to employees impersonating as IT Helpdesk requesting for login credentials. The imposter could convince the victim by stating that the credentials are required for maintenance activities</li>
<li>Imposter could obtain employee details from Public domain and call up the organizations IT Helpdesk to reset the victims password and thus gain unauthorized access</li>
<li>Mails from forged Bank ID’s requesting for Internet Banking login credentials</li>
</ul>
<p>Don’t want to be victim to Social Engineering attacks, follow some basic thumb rules:</p>
<ul>
<li>Never allow people to tailgate with you.</li>
<li>Verify the identity of the visitor against his/her valid ID Card</li>
<li>Ensure all Entries / Exit points are secured at all times</li>
<li>Visitors should not be allowed in the office space without appointments. The could be requested to be at the reception.</li>
<li>Avoid use of corporate ID’s on public domain, blogs, discussion forums etc.</li>
<li>Do not share login credentials with anyone. IT Helpdesk or Banks do not need employees / customers login credentials for any of their operations.</li>
<li>Before replying to mails asking for sensitive / personal information verify the origin and sender’s details</li>
<li>Never click on unknown links / links contained in the mails of unknown origin. An innocent URL like www.goodsite.com could actually be linked to www.xyz.abc.net etc. which might infest your PC with Malwares, Trojans, Virus and worse Back-Doors giving complete remote access of your PC to attackers</li>
<li>Avoid accessing confidential and critical online details like corporate mail box, Bank accounts etc. in public places, hotels etc. where Internet security cannot be trusted</li>
<li>Read and follow the security guidelines dealing with Internet Banking issued by the Banks from time to time</li>
<li>Verify the SSL certificate of the Bank website before getting into any Internet Banking transaction</li>
<li>Use a strong and complex password</li>
<li>Do not note down the user ID &amp; passwords on piece of paper, notepads etc. which could be accessible to others</li>
<li>Use virtual keyboard where applicable</li>
<li>Avoid installing software’s / tools of unknown origin because these might open backdoors to your PC</li>
</ul>
<p>Educational Reference:</p>
<ul>
<li><a href="http://www.social-engineer.org/">http://www.social-engineer.org</a></li>
<li><a href="http://www.phishme.com/">http://www.phishme.com/</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/social-engineering-%e2%80%93-myth-reality/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Measuring WAN Performance</title>
		<link>http://www.clubhack.com/measuring-wan-performance/</link>
		<comments>http://www.clubhack.com/measuring-wan-performance/#comments</comments>
		<pubDate>Sun, 11 Jul 2010 04:51:24 +0000</pubDate>
		<dc:creator>VishalK™</dc:creator>
				<category><![CDATA[Network]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=19</guid>
		<description><![CDATA[Methodology to Measure the WAN Performance while selecting an optimum location for the Data Center (DC) Introduction: Network performance is one of the most critical factors to be considered while selecting the location for Data Centers. There are many factors that influence the network performance. These factors are highly dependent on the type of applications [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong><em>Methodology to Measure the WAN Performance while selecting an optimum location for the Data Center (DC)</em></strong></p>
<p><strong>Introduction: </strong></p>
<p>Network performance is one of the most critical factors to be considered while selecting the location for Data Centers. There are many factors that influence the network performance. These factors are highly dependent on the type of applications and services being hosted out of the data center. The Wide Area Network (WAN) factors which help in determining the network performance from the perspective of selecting a location for the data center are:</p>
<ul>
<li>Round Trip Time (RTT) from source to destination</li>
<li>Throughput</li>
<li>Theoretical Network Limit<strong></strong></li>
</ul>
<p><strong>1        </strong><strong>Round Trip Time (RTT): </strong></p>
<p>RTT is the time taken by the IP packet to transverse the path from the source to the destination and back. It is usually measured in milliseconds (ms).</p>
<p><strong>2        </strong><strong>Theoretical Network Limit :</strong></p>
<p>As the name suggests, theoretical network limit is the theoretical maximum (ideal) throughput possible on a given network link(s) between source and destination. It is typically expressed in Mbps. This limit is calculated based on RTT, Maximum Segment Size (MSS) and Loss rate in percent.</p>
<p><strong>3        </strong><strong>Throughput </strong></p>
<p>It is the amount of data transferred from one place to another or processed in a specified amount of time. Data transfer rates for networks are measured in terms of throughput. Typically, throughput is measured in kbps, Mbps and Gbps.</p>
<p><strong> </strong></p>
<p><strong>Methodology to calculate RTT, Theoretical Network Limit and Throughput</strong></p>
<p><strong>Step 1: Calculation of Round trip time (RTT)</strong></p>
<p>RTT can be calculated by sending ICMP Ping messages to the destination. Ping messages need to be sent between the source and destination between which the RTT needs to be calculated. Using Looking Glass utilities, Ping messages can be sent from different locations around the globe.</p>
<p>Looking Glass is a utility available on the internet using which Ping messages can be sent to the required destination from servers (or network devices) located in different locations around the world.</p>
<p>Thus, a very good approximate of RTT can be obtained between the source country * and the destination.</p>
<p><strong>Parameters required for measuring Theoretical Network Limit and Throughput:</strong></p>
<ul>
<li>Round trip time (RTT)</li>
<li>Maximum segment size (MSS) (typ.1460 Byte)</li>
<li>Loss rate in % (typ. &lt; 10<sup>-6</sup>% (&lt; 10<sup>-8</sup>))</li>
<li>TCP window size (typ. 64 Kbyte)</li>
</ul>
<p><strong>Step 2: Calculation of Theoretical Network limit </strong></p>
<p>The approximate Theoretical Network limit can be calculated using the following formula (based on the Mathis et.al. formula)</p>
<p>Theoretical Network rate &lt; (MSS/RTT)*(C/sqrt(Loss)) [ C=1. Loss is the Loss rate in %. typ. &lt; 10<sup>-6</sup>% (&lt; 10<sup>-8</sup>)  ]<strong></strong></p>
<p><strong>Step 3: Calculation of Throughput </strong></p>
<p>Throughput can be calculated using the formula</p>
<p>Throughput &lt;= TCP buffer size / RTT</p>
<p>Where, TCP Buffer size &gt; = TCP Window size, Typical TCP window size = 64 Kbyte</p>
<p>The theoretical network limit and throughput are dependent on the RTT. So, a very good approximation of RTT is imperative. RTT analysis should be carried out at different times, during the course of the day and an average should be taken, to get a good approximate.</p>
<p><strong>Note: </strong></p>
<p>1        Many looking glass utilities are available on <a href="http://www.traceroute.org/">www.traceroute.org</a></p>
<p>2        The calculator for theoretical Network limit and Throughput is available on <a href="http://www.switch.ch/network/tools">www.switch.ch/network/tools</a></p>
<p>* The exact location within the source country depends upon the location of the available network device (Looking Glass) from where Ping messages are being sent.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/measuring-wan-performance/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

