WISH YOU A HAPPY AND SECURE YEAR 2009

Wednesday, July 15, 2009

Quote of the day

Quote of the day

The period of greatest gain in knowledge and experience is the most difficult period in one’s life.

Dalai Lama

New IT Term of the day

New IT Term of the day


photoshopping


A slang term used to describe any image that has been digitally manipulated or altered.

EXTRADITED : Indian Hacker Extradited to US

EXTRADITED : Indian Hacker Extradited to US

Three men allegedly made millions manipulating prices of several stocks, including Google

By Robert McMillan

IDG News Service

July 08, 2009

An Indian man has pleaded not guilty to charges that he hacked into online brokerage accounts in order to manipulate stock prices.

Jaisankar Marimuthu, 34, of Chennai, was extradited to the US from Hong Kong on June 20, making him the latest to face charges in what authorities described as an international "hack, pump and dump" scheme. He entered a not guilty plea in US District Court for the District of Nebraska on June 25, according to court records.

Marimuthu had already been arrested by Hong Kong police on similar charges, the US Department of Justice (DoJ) said.

Another man, Thirugnanam Ramanathan, pleaded guilty to fraud charges stemming from the scheme and was sentenced to two years in prison in September. However, he was deported on Jan. 29, before serving his full sentence, according to Ian McCaleb, a DoJ spokesman.

A third man, Chockalingam Ramanathan, has been charged in the US but is still at large, McCaleb said.

The three were charged two years ago for a 2006 scheme in which they allegedly hacked into online brokerages or created new accounts using stolen identities, then bought and sold stocks in order to manipulate prices to their benefit.

They hacked into more than 60 accounts in nine brokerage firms, including ETrade and TD Ameritrade, according to authorities. One firm lost more than US$2 million because of the scam.

The men allegedly drove up prices of low-volume stocks they owned, such as Acordia Therapeutics, Pacel and IGI, by buying shares with the hacked accounts, then dumping the stocks before the price dropped, authorities said. In October 2006, they also manipulated the price of near-worthless "put" options for Google, which gave buyers the option of selling Google stock for $240 (about half its value at the time), authorities said.

How Marimuthu and his associates allegedly gained access to the brokerage accounts is unclear, but court filings suggest that he may have obtained them from Internet cafés used by American and European visitors to Bangkok. Marimuthu and the others stayed at the Raja Hotel in Bangkok in 2006, prosecutors said.

Wireless networks at hotels and Internet cafés can be a security risk, especially if they are unencrypted or use the cracked Wired Equivalent Privacy (WEP) system to secure network traffic.

BOOKED : Pakistani Lady MPA booked for credit card theft

BOOKED : Pakistani Lady MPA booked for credit card theft

July 13, 2009

http://www.thenews.com.pk/top_story_detail.asp?Id=23239

LAHORE: Ghalib Market Police on Sunday registered a theft case against a Pakistan Muslim League-N MPA, Shumaila Anjum Rana, for allegedly stealing two credit cards from a woman’s purse, doing shopping and paying Rs 80,000 through the stolen cards.

An FIR No 551/09 has been registered against the MPA under Section 379 of the Pakistan Penal Code on the complaint of Muqeet Salam, the brother-in-law of Zaira Malik of Canal Bank, the owner of the credit cards.

Investigation Officer Sub-Inspector Maqsood told The News he tried to contact the accused MPA by telephone several times, but she was not available. He said Muqeet alleged in the application that his sister-in-law, Zaira Malik, was present in a fitness club on July 7 when she found her credit cards, issued by the United Bank Limited and Bank Alfalah Limited, missing from her purse. He said Zaira contacted the banks concerned and was informed that transactions worth Rs 80,000 had been made through her credit cards. He alleged that the banks also informed her that the ‘thief’ had purchased goods from a shop at the Siddique Trade Centre.

The police quoted the complainant as saying that the shop owner also showed the CCTV footage to them and finally Zaira recognised MPA Shumaila, who was not a member of the fitness club. He said they had also got records of transactions from the shopkeeper in which the use of Zaira Malik’s credit cards was mentioned.

A police official said that raids would be conducted to arrest the accused if she didn’t surrender to the police. On Saturday, the Ghalib Market police had denied receiving any application against the said MPA. However, after it was proven from witnesses and evidence, a case was registered with the consent of senior police officials.

Meanwhile, Punjab Chief Minister Shahbaz Sharif has said legal action will be taken against MPA Shumaila Anjum Rana.He was talking to media persons at the Ittefaq Hospital here on Sunday. Answering a question regarding MPA Shumaila Anjum Rana, he said law has started taking its course and all legal requirements will be fulfilled in this regard.

REPORT : 73 Percent of U.S. Businesses Breached

REPORT : 73 Percent of U.S. Businesses Breached

The report has a recommendation for organizations that fear a breach and the reporting requirements that go with it.

July 13, 2009

By Alex Goldman

http://www.internetnews.com/security/article.php/3829391

The fourth annual U.S. Encryption Trends Study was released today by The Ponemon Institute. The study says that 73 percent of surveyed businesses have experienced a data breach in the past year, up from 60 percent in the 2008 study. The report was sponsored by encryption supplier PGP Corp.

"A data breach is defined as the loss or theft of confidential or sensitive data including information about people and households," said Dr. Larry Ponemon, chairman and founder of The Ponemon Institute, in an e-mail to InternetNews.com.

The numbers are comparable to a similar study released last week concerning UK businesses. There, the Ponemon Institute found that 70 percent had been breached in the last year.

The report was based on surveys with nearly a thousand (997) U.S.-based executives.

Organizations need to have a holistic data encryption strategy, according to the report.

"For the second year in a row, organizations with no encryption strategy accounted for all the organizations that suffered five or more data breaches (13 percent)," the report said.

Organizations are adopting encryption to comply with industry regulations and state and federal laws, the report explained.

A flood of data breaches

The news comes as reporting requirements are becoming more burdensome. For example, a recent change to reporting requirements for healthcare organizations in California has resulted in a flood of data breach reports there.

Businesses can expect closer scrutiny of security issues -- and failures -- as the government ponders new privacy laws.

The report touts the platform approach to encryption. The use of "encryption applications managed via a platform continues to be a best practice approach to an overall data protection strategy in 2009," said Dr. Ponemon in a statement.

Also today, PGP Corporation released two new products. PGP Portable is designed to help encrypt removable storage devices, while PGP Mobile helps organizations encrypt data on mobile devices. Pricing for the new products was not disclosed.

According to the report, organizations see a need to protect mobile devices. "More than 59 percent of respondents say it is very important or important to encrypt employees' mobile devices -- a sign that organizations recognize that valuable data is more mobile than ever," the report said

Companies are right to be concerned about breaches, the report said, referring to an earlier study by The Ponemon Institute that found that breaches cost businesses, on average, $202 per record and, in total, an average of $6.6 million.

FALSE POSITIVE : Glitch in antivirus software troubles PC users

FALSE POSITIVE : Glitch in antivirus software troubles PC users

By JORDAN ROBERTSON

AP Technology Writer

Jul 10, 2009

http://tech.yahoo.com/news/ap/20090710/ap_on_hi_te/us_tec_antivirus_false_positive

Antivirus software cuts two ways. It's great at blocking known viruses, but it can sometimes misfire, mistakenly flagging clean files as malicious. That sends a computer into a tailspin trying to clean up stuff that's supposed to be on there.

The problem can crash a computer, and fixing it can be a bear.

An example emerged this week when users of antivirus software made by Islandia, N.Y.-based CA Inc. watched as their machines warned of an infection and started quarantining files that turned out to be legitimate.

Lee Jay Mandell, a 60-year-old retired computer consultant and patent attorney from the Los Angeles area, said the problem popped up on his computer Wednesday night. He knew something was wrong because he recognized the types of files that were being quarantined were parts of Microsoft Corp.'s Windows operating system.

He drew on his technical experience to restore the machine, but says less adept users might stumble.

"I'm back, but it took me about six hours to get back," he said Friday.

Every antivirus company deals with false positives, and it's an embarrassment for companies whose job is to protect people's machines from sabotage. It happens because legitimate files sometimes have programming code or behaviors that are identical to those of viruses. The antivirus software spots files it believes are malicious and starts plucking them out.

The results can range from annoyance to outright meltdown of the machine if critical files are targeted. Last week some people using McAfee Inc.'s antivirus software said their computers crashed because of a false positive.

McAfee said the false positive only happened on older versions of its software that are no longer supported by the company. Newer versions won't have the problem.

CA apologized for the problem Mandell and others encountered and said its last major false positive was three years ago.

"Minor false positives happen periodically, but CA has historically maintained an industry low rate of false positives," the company said in a statement.

Cleaning up a false positive detection isn't always easy. The program might do it for you. But sometimes a user might need to go into the list of quarantined files and manually rename them, or call the company to request software to do the task automatically.

CA emphasized that the files that its software wrongly spotted as viruses this week were quarantined or renamed, not deleted, and "are recoverable."

The lesson: Pay close attention to your computer if it's telling you it's found a virus and is cleaning it up. You might need to call your antivirus vendor's customer support to help you make sure your machine is totally clean — or to help you recover files if the cleanup was a false alarm.

This Day in History

Thanks for your Visit