Google Search

Showing posts with label Worlds. Show all posts
Showing posts with label Worlds. Show all posts

Tuesday, August 6, 2013

The World’s First International Ethical Hacking, Computer Network Defense and Forensics Competition Global ...

Global CyberLympics an online Ethical Hacking game announces its newly formed Advisory Board, including but not limited to: Curtis Levinson United States NATO Cyber Defense Advisor, Sali Osman Cyber Security Advisor for GE Capital, and Balaji Venketeshwar the Vice President of Information Security at BA Continuum.

Albuquerque, NM (PRWEB) April 22, 2013

Global CyberLympics, an international ethical hacking, cyber security online game is proud to announce its newly formed advisory board. The Advisory Board is made up of the following members:

Sharvind Appiah, Chief Information Officer of GEODIS Group


Dr. Abu Hasan Ismail, CEO and Founder of Prestariang Berhad


Curtis Levinson, United States NATO Cyber Defense Advisor


Sali Osman, Cyber Security Advisor for GE Capital


Todd Salmon, Director of Security Assessments at FishNet


Marc Atayi, President and CEO of Techworld International


Balaji Venketeshwar, Vice President of Information Security at BA Continuum (A wholly owned subsidiary of Bank of America in Asia pacific and Latin America)


Roberto Puyó Vallardes, Chief Information Security Officer at ONP (Ministry of Economy of the Government of Peru)

Jay Bavisi, President of the Global CyberLympics Organization Committee stated “The Advisory Board is as diverse as our players, and are representative of different areas around the globe. With their feedback, we can improve the games.” The Advisory Board will counsel the Global CyberLympics Organization committee on the following topics: development of the games, proficiency of the games, sponsorships, game continuity, and promotion of the games.

For more information contact Janelle McLean -Program Coordinator of Global CyberLympics at Janelle.mclean(at)eccouncil(dot)org.

About the 2012 Global CyberLympics Games


The 2012 Global CyberLympics grew by over 200%, and increased the number of Countries that participated from 27 to 52. Last year’s world finals competition was an action packed 6 hours with hacker teams changing positions several times as they jockeyed for top honors. These final games drew a consistent crowd as Hacker Halted conference goers gathered to see which flags (servers) teams were capturing. In the end team Hack.ERS from the Netherlands were able to defend their World Championship title, as they reclaimed 1st place for the second year in a row. The 2nd place team was the University of Maryland University College (UMUC) Cyber Padawans of the USA and the 3rd place spot went to team gula.sh of Hungry.

About the EC-Council Foundation


EC-Council Foundation is a charitable and educational organization dedicated to educating and training individuals in security skills; it is the founding company for Global CyberLympics an international computer defense, and ethical hacking competition. EC-Council Foundation’s application for recognition of its exemption from federal income tax under §501(c)(3) of the Internal Revenue Code is pending with the Internal Revenue Service.

EC-Council Foundation was established in 2012 by the founders of the International Council of E-Commerce Consultants (EC-Council). The International Council of E-Commerce Consultants (EC-Council) a member-based organization that certifies individuals in e-business and information security skills. It is the owner and creator of the world famous Certified Ethical Hacker (CEH), Computer Hacking Forensics Investigator (CHFI), EC-Council Certified Security Analyst (ECSA), License Penetration Tester (LPT), and numerous others that are offered in over 87 countries through more than 450 training partners globally. EC-Council has trained over 90,000 individuals and certified more than 40,000 security professionals.

For more information about Global CyberLympics and EC-Council Foundation, please visit http://www.cyberlympics.org

Janelle McLean
EC-Council Foundation
505-922-2885
Email Information


View the original article here

Saturday, June 22, 2013

Scribd, "world's largest online library," admits to network intrusion, password breach

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

San Francisco-based document sharing site Scribd has admitted to a network intrusion.

Scribd bills itself as The World's Largest Online Library, and with a suggested 50 million users or more, it's hardly surprising that the site has attracted the attention of cybercriminals.

Details are scant, but a notification published on the company's online Support Desk states:

Earlier this week, Scribd's Operations team discovered and blocked suspicious activity on Scribd's network that appears to have been a deliberate attempt to access the email addresses and passwords of registered Scribd users.

Because of the way Scribd securely stores passwords, we believe that the passwords of less than 1% of our users were potentially compromised by this attack.

We have now emailed every user whose password was potentially compromised with details of the situation and instructions for resetting their password.

Therefore, if you did not receive an email from us, you are most likely unaffected.

The comment that less than 1% of users were potentially compromised "because of the way Scribd stores passwords" could probably have been made more clearly.

At first blush, I was inclined to interpret this to mean that 99% of passwords were stored securely, presumably by salting and hashing, leaving only a small proportion open to the scrutiny of intruders.

? We've seen cases before where websites have upgraded their password handling systems to make them safer, but seem to have failed to migrate all users to the new system in a timely fashion, leaving some users in an insecure limbo.

The good news, if you read on, is that it looks as though none of Scribd's passwords are stored in cleartext, as the company goes on to say that:

Our investigation indicates that no content, payment and sales-related data, or other information were accessed or compromised. We believe the information accessed was limited to general user information, which includes usernames, emails, and encrypted passwords.

Scribd isn't claiming any certainty in what was taken (the verb believe implies acceptance without proof), but that's not unexpected.

Determining precisely what was stolen after an electronic break-in is tricky, and pedantic readers will be quick to point out that, technically, nothing was stolen because the original copies of the data remained behind.

Scribd also isn't clarifying how the passwords were encrypted, and the company probably doesn't actually mean encrypted, either.

Salting and hashing passwords is supposed to be a one-way process that allows the passwords to be verified, but not decrypted to reveal the original cleartext.

Assuming they were hashed and salted, then, stealing the password database doesn't directly reveal anyone's password.

But it does let the crooks mount an offline attack on the database, hashing a dictionary of passwords one-by-one and noticing when a guessed password is verified against the database of hashes.

And since Scribd isn't saying what password security algorithm it used, you have little choice but to assume it was a hashing process that doesn't slow down determined attackers much.

That's why the following behaviours are important:

When you choose a password, don't pick anything obvious. Attackers put the most likely passwords at the top of their dictionary lists, so the tougher your password, the later it will fall, if at all.Don't use the same password on multiple sites. Doing so means that your login details on the most important site are at risk from an attack on the least secure one.If you store password databases, use a strong salt-and-hash system (e.g. bcrypt, scrypt or PBKDF2) that makes it much harder and slower for attackers to go through their password dictionary, but not so slow that it's impracticable to verify individual passwords when your users login.

Scribd has put up an online "breach checker" which lets you check individual email addresses against the list of probably-pwned accounts:

It would have been a nice touch if the company had used HTTPS for this particular page, rather than sending your email address, and the notification of whether it was on the at-risk list, via unencrypted HTTP:

On the other hand, since anyone can check anyone's email address anyway, and since you probably received an email advising you to change your password already if your account was potentially pwned, it probably doesn't matter.

To learn more about managing, choosing and policing passwords in your organisation, why not listen to our popular Techknow podcast on this very topic?

(If you prefer to listen offline, you can download the podcast for later.)

Follow @duckblog


View the original article here

Friday, September 30, 2011

IMAGES: World's 10 most famous hackers

Last updated on: September 28, 2011 09:28 ISTGary McKinnon.

While ethical hackers attack a security system to find out vulnerabilities that a malicious hacker could use to his advantage, unethical hackers discreetly wreck havoc on computer systems and steal confidential information.

In the 1970s, the United States government used groups of experts called red teams to hack its own computer systems.

Today, many companies hire ethical hackers to safeguard their vital computer systems.

Here's a look at the world's most famous hackers...

1. Gary McKinnon

Gary McKinnon, a Scottish systems administrator has been accused of the biggest military computer hacking exercise of all times by the US government.

McKinnon is also accused of copying data, account files and passwords into his own computer.

US authorities pegged the cost of tracking and rectifying the problems caused by his hacking at over $700,000.


Image: Gary McKinnon.
Photographs: Reuters.
Last updated on: September 28, 2011 09:28 ISTRobert Tappan Morris.

2. Robert Tappan Morris

Robert Tappan Morris is an American computer scientist, known for creating the first computer worm on the Internet called the Morris Worm in 1988.

He became the first person convicted under the Computer Fraud and Abuse Act.

He is a professor in the department of Electrical Engineering and Computer Science at the Massachusetts Institute of Technology.

Click NEXT to read more...
Image: Robert Tappan Morris. Last updated on: September 28, 2011 09:28 ISTKevin David Mitnick.

3. Kevin David Mitnick

Kevin David Mitnick is a computer security consultant, author, and hacker. In the late 20th century, he was convicted of various computer-related crimes.

When he was 12 years old, Mitnick used social engineering to bypass the punchcard system used in the Los Angeles bus system.

Click NEXT to read on . . .


Image: Kevin David Mitnick. Last updated on: September 28, 2011 09:28 ISTKevin Poulson.

4. Kevin Poulson

Kevin Lee Poulsen, a former black hat cracker, works as senior editor at Wired News.

He is well known for hacking all the telephone lines for Los Angeles radio station KIIS-FM, to make sure that he would be the 102nd caller and win the prize of a Porsche 944 S2.

Click NEXT to read on . . .


Image: Kevin Poulson. Last updated on: September 28, 2011 09:28 ISTJonathan James.

5. Jonathan James

Jonathan Joseph James who passed away in May 2008, was an American hacker.

He was the first juvenile to be imprisoned for cybercrime in the United States. He died as a result of a self-inflicted gunshot wound.

Click NEXT to read more...
Image: Jonathan James. Last updated on: September 28, 2011 09:28 ISTAdrian Lamo.

6. Adrian Lamo

Adrian Lamo a threat analyst gained popularity by hacking into several high-profile computer networks, including those of The New York Times, Yahoo!, and Microsoft. He was arrested in 2003.

Click NEXT to read more...
Image: Adrian Lamo. Last updated on: September 28, 2011 09:28 ISTVladimir Levin.

7. Vladimir Levin

Vladimir Levin, a businessman is known for his involvement in attempting to fraudulently transfer $10.7 million via Citibank's computers.

Currently, he does business in Lithuania.

Click NEXT to read on . . .


Image: Vladimir Levin. Last updated on: September 28, 2011 09:28 ISTRaphael Gray.

8. Raphael Gray

Raphael Gray was just 19 when he hacked computer systems around the world in 1999 as part of a multi-million pound credit card mission.

He published credit card details of over 6,500 cards to point out the weak security in consumer web sites.

Click NEXT to read on . . .


Image: Raphael Gray. Last updated on: September 28, 2011 09:28 ISTDeceptive Duo.

9. Deceptive Duo

A 20-year-old man from California was suspected of being a hacker and called himself, 'the Deceptive Duo'.

He faces several charges on hacking into government computers and defacing government websites.

In April 2002, the Deceptive Duo claimed to be a hacking group working to expose the lack of security within the US government's networks and other private-sector computer systems.

Click NEXT to read on . . .


Image: Deceptive Duo. Last updated on: September 28, 2011 09:28 ISTMichael Calce.

10. Michael Calce

Also known as MafiaBoy, Michael Calce, a high school student from West Island, Quebec launched a series of highly publicised denial-of-service attacks in February 2000 against large commercial websites including Yahoo!, Amazon.com, Dell, Inc, eBay, and CNN.


Image: Michael Calce.

View the original article here