Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Online threats are part-and-parcel of life on the Web -- but the end of the year proves to be a lucrative time to give cybercriminals the gift of your bank details or personal data.. As the holiday season comes in to full swing, more consumers use online banking and retail sites to complete their Christmas shopping. However, consumers are often duped by a number of tactics employed by criminals to profit from a lack of security awareness. The link for this article located at ZDNet Blogs is no longer available. . As the holiday season comes in to full swing, more consumers use online banking and retail sites to . online, threats, part-and-parcel, proves. . LinuxSecurity.com Team
Flaws in the way web applications handle encrypted session cookies might leave online banking accounts open to attack. The security risk stems from a cryptographic weakness in web applications developed using Microsoft's ASP.Net framework. . ASP.Net uses the US government-approved AES encryption algorithm to secure the cookies generated by applications during online banking sessions and the like. However implementation flaws in how ASP.NET handles errors when the encrypted data in a cookie has been modified give clues to a potential attacker that would allow him to narrow down the possible range of the keys used in an online banking session. Attacks based on this weakness might allow a hacker to decrypt sniffed cookies or forge authentications tickets, among other attacks. The link for this article located at The Register UK is no longer available. . Weaknesses in ASP.Net’s management of encrypted cookies could potentially put online banking at risk of cyber threats.. AES Encryption, Online Banking Threats, Application Security, Cybersecurity Risks, Cryptographic Vulnerabilities. . LinuxSecurity.com Team
Read on for "The Ubuntu Option" for increased online banking security. Jay McLaughlin has me worried. I do my online banking from the same home computer the rest of the family uses for Web surfing and online games. I have the McAfee security suite loaded and do regular scans so accessing online banking should be protected. Right? . Not really, says McLaughlin, a Certified Information Security Professional and CIO of CNL Bank. Accessing online banking from your everyday PC is just asking for trouble, he says. In fact, the CIO of the St. Mary, Florida-based regional bank would like to see all of his customers - both consumers and businesses - access online banking either from a dedicated machine or from a self-booting CD-ROM running Ubuntu Linux and Firefox. The Ubuntu option Recognizing that most consumers don't want to buy a separate computer for online banking, CNL is seriously considering making available free Ubuntu Linux bootable "live CD" discs in its branches and by mail. The discs would boot up Linux, run Firefox and be configured to go directly to CNL Bank's Web site. "Everything you need to do will be sandboxed within that CD," he says. That should protect customers from increasingly common drive-by downloads and other vectors for malicious code that may infect and lurk on PCs, waiting to steal the user account names, passwords and challenge questions normally required to access online banking. A bootable CD works because it's isolated from the host PC environment. Malware on the host can't touch it - and any malware picked up when running from the CD-ROM goes away once the CD is ejected. "When you eject the CD you have removed everything off the machine," McLaughlin says. The link for this article located at Computer World is no longer available. . Not really, says McLaughlin, a Certified Information Security Professional and CIO of CNL Bank. Acce. ubuntu, option', increased, online, banking, security, mclaughlin, worried. . LinuxSecurity.com Team
Is this the future of online banking? US company IronKey has come up with a USB drive that can be used to access accounts virtually without involving the operating system or applications that cause so many of today's security problems.. Aimed at companies that want to protect corporate bank accounts, Trusted Access for Banking is actually a standard IronKey USB drive that runs a walled or The link for this article located at Tech World is no longer available. . IronKey's USB drive features advanced security for online banking, including hardware encryption and independent operation, ensuring data safety against malware threats. USB Security, Online Banking, Data Protection, Anti-Keylogger, Trusted Access. . LinuxSecurity.com Team
Officials at Suffolk County National Bank in Long Island, N.Y. this week are warning more than 8,000 customers that their account login information was likely compromised in November, when a hacker illegally accessed a server hosting its online banking system.. SCNB officials discovered the breach during a routine internal security review in late December. Investigators determined the unauthorized intrusion occurred during a six-day period between Nov. 18 and Nov. 23 of last year. "The security of customers' information is of utmost importance to SCNB," Suffolk Bancorp CEO J. Gordon Huszagh said in a statement. "While we know that our diligence in this regard allowed us to uncover this incident, and to take action rapidly to protect our customers, we also recognize that the provision of financial services over the Internet requires our dedication to continuous monitoring and security." Unlike other banks and financial institutions victimized by online hackers, Suffolk Bancorp (NASDAQ: SUBK), the parent company of SCNB, is telling investors just how much it will cost to investigate the data breach and improve security controls and technology to prevent future intrusions. The link for this article located at eSecurity Planet is no longer available. . SCNB officials discovered the breach during a routine internal security review in late December. Inv. officials, suffolk, county, national, island, warning. . LinuxSecurity.com Team
Two-factor authentication -- used to protect online bank accounts with both a password and a computer-generated one-time passcode -- is supposed to be more secure than relying on a single password. But Gartner Research VP Avivah Litan warns that cyber criminals have had success defeating two-factor authentication systems in Web browsing sessions using Trojan-based man-in-the-middle attacks.. Confidential information is everywhere, so it must be protected Typo Squatting and Cross Site Scripting are just a couple of the recent threats facing the presidential candidate web sites, according to researcher Oliver Friedrichs. Confidential information is everywhere, so it must be protected A Gartner Research note written by Litan explains that in the past few months, Gartner has heard from many banks around the world that rely on one-time-password authentication systems. Accounts at these banks have been compromised by man-in-the-middle attacks -- the report uses the term "man-in-the-browser" -- despite the use of two-factor security. One technique that the fraudsters have been using to bypass security controls is call forwarding. "[B]anks that rely on voice telephony for user transaction verification have seen those systems and processes compromised by thieves who persuade telecom carriers to forward legitimate user phone calls to the thief's cell phone," the report says. "These targeted attacks have resulted in theft of money and/or information, if the bank has no other defenses sufficient to prevent unauthorized access to their applications and customer accounts." The link for this article located at Dark Reading is no longer available. . Hackers are bypassing web protection systems such as biometric scans through interception methods, presenting a significant danger.. Two-Factor Authentication, Cybercrime Techniques, Banking Security, Fraud Prevention. . LinuxSecurity.com Team
Two-factor authentication -- used to protect online bank accounts with both a password and a computer-generated one-time passcode -- is supposed to be more secure than relying on a single password. But Gartner Research VP Avivah Litan warns that cyber criminals have had success defeating two-factor authentication systems in Web browsing sessions using Trojan-based man-in-the-middle attacks. . A Gartner Research note written by Litan explains that in the past few months, Gartner has heard from many banks around the world that rely on one-time-password authentication systems. Accounts at these banks have been compromised by man-in-the-middle attacks -- the report uses the term "man-in-the-browser" -- despite the use of two-factor security. One technique that the fraudsters have been using to bypass security controls is call forwarding. The link for this article located at Information Week is no longer available. . Digital assailants take advantage of dual-authentication measures in their operations, even though these are designed to bolster security for financial transactions.. Two-Factor Authentication,Risk Management,Cybersecurity. . LinuxSecurity.com Team
An attack this week that targeted online customers of at least 50 financial institutions in the U.S., Europe, and Asia-Pacific has been shut down, a security expert said Thursday. The attack was notable for the extra effort put into it by the hackers, who constructed a separate look-alike Web site for each financial institution they targeted, said Henry Gonzalez, senior security researcher for Websense Inc. . To be infected, a user had to be lured to a Web site that hosted malicious code exploiting a critical vulnerability revealed last year in Microsoft's software, Websense said. The vulnerability, for which Microsoft had issued a patch, is particularly dangerous since it requires a user merely to visit a Web site rigged with the malicious code. The link for this article located at Infoworld is no longer available. . To be infected, a user had to be lured to a Web site that hosted malicious code exploiting a critica. attack, targeted, online, customers, least, financial, institutions. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.