Welcome

Welcome to this site dedicated to the IST MODEL Technology, an innovative PATENTED technology designed to guarantee the highest levels of security during communications and transactions over the Internet.

Benvenuti in questo sito dedicato alla Tecnologia IST MODEL, progettata per garantire il più alto livello di sicurezza nelle comunicazioni e transazioni su Internet.
IST MODEL è una tecnologia innovativa brevettata.

IST Model - A short Introduction.pdf

Visualizzazione post con etichetta Cracked Security. Mostra tutti i post
Visualizzazione post con etichetta Cracked Security. Mostra tutti i post

sabato 28 novembre 2020

Blockchain attacks

Blockchain can be attacked in a number of different ways. Many of the most famous attacks focus on issues with either the theoretical blockchain protocol (such as the 51% attack) or smart contracts (such as reentrancy and access control vulnerabilities).

However, even a theoretically secure blockchain protocol can be vulnerable to attack when implemented. Blockchain is typically implemented using traditional computers and networks, and attacks against this infrastructure level can impact the security of the blockchain system itself.


La Blockchain può essere attaccata in differenti modi. Molti degli attacchi più famosi si concentrano o sul protocollo teorico (come l'attacco del 51%) o sui contratti intelligenti (come le vulnerabilità di rientro e del controllo degli accessi).

Tuttavia, anche un protocollo blockchain teoricamente sicuro può essere vulnerabile agli attacchi quando questo viene implementato. La blockchain viene in genere implementata utilizzando computer e reti tradizionali e gli attacchi contro questo livello di infrastruttura possono influire sulla sicurezza del sistema blockchain stesso.

Reference

https://securityboulevard.com/2020/09/attacks-on-blockchain/

https://www.investopedia.com/terms/1/51-attack.asp

lunedì 2 dicembre 2019

DMSniff, Hackers continue to attack POS


A Point-of-Sale (POS) malware which uses a domain generation algorithm to create command-and-control domains on the fly was deployed in attacks against small and medium-sized businesses during the last past four years—since at least 2016—according to a team of security researchers from Flashpoint. It is named DMSniff and it is hard to detect.

Un malaware che attacca i POS (Poit-Of-Sale) e che utilizza un Domain Generation Algorithm (un algoritmo cioè che periodicamente genera un grande numero di nomi di dominio) per creare domini command-and-control. Il suo nome è DMSniff e secondo un team di ricercatori di Flashpoint sta attaccando business delle piccole e medie aziende sin dal 2016.

Reference

mercoledì 30 ottobre 2019

How far is quantum computing from cracking cryptosecurity based on 2048 bit RSA key lenght?

(Credit Denis Rothman via Linkedin)

In an article published recently by Denis Rothman on Linkedin an interest topic has been posed. Recent advancements in Quantum Computing may pose a risk in cryptosecurity based on 2048-bit-RSA-key-length. How far is quantum computing from running Shor's factorization algorithm ?

Let's make a Google Search with "Shor's quantum algorithm RSA"

In un articolo pubblicato recentemente da Denis Rothman su Linkedin, viene posto un argomento integerssante.I recenti progressi nel QUantum Computing potrebbero prre a rischio la criptografia basata su chiavi RSA di lunghezza 2048 bit. Quanto è lontano il quantum computing da far girare l'algoritmo di fattorizzazione di Shor?

Cerchiamo notizie su Google con "Shor's quantum algorithm RSA"

Reference

mercoledì 10 ottobre 2018

BlockChain and 51% Attack, a real threat?


At least five cryptocurrencies have recently been hit with an attack that used to be more theoretical than actual. In each case, attackers have been able to amass enough computing power to compromise these smaller networks, rearrange their transactions and abscond with millions of dollars in an effort that's perhaps the crypto equivalent of a bank heist. More surprising, though, may be that so-called 51% attacks are a well-known and dangerous cryptocurrency attack vector.
A 51% attack or double-spend attack is a miner or group of miners on a blockchain trying to spend their crypto’s on that blockchain twice. The goal of this isn’t always to double spend crypto’s, but more often to cast discredit over a certain crypto or blockchain by affecting its integrity.

Almeno cinque criptovalute sono state recentemente colpite da un attacco che era ritenuto essere più teorico che reale. In ogni caso, gli aggressori sono stati in grado di accumulare abbastanza potenza di calcolo per compromettere alcune reti più piccole, riorganizzare le proprie transazioni e scappare con milioni di dollari in uno sforzo che è forse l'equivalente criptografico di una rapina in banca. Più sorprendente, tuttavia, potrebbe essere che i cosiddetti attacchi del 51% sono un ben noto e pericoloso vettore di attacco di criptovaluta.
Un attacco del 51% o un attacco a doppia spesa è un attacco che un miner o un gruppo di miner effettuano su di una blockchain, nel tentativo di spendere due volte la propria criptovaluta su quella stessa blockchain. L'obiettivo di questo attacco non è sempre quello di raddoppiare la spesa di criptovaluta, ma più spesso di gettare discredito su una determinata criptovaluta o blockchain influenzandone l'integrità.

Reference

martedì 9 ottobre 2018

Phishing for Cryptocurrency in 2018


Bitcoin.com reported that $1.36 billion worth of cryptocurrency was stolen in the first two months of 2018 ($9 million each day). Even if you exclude the huge “outlier” thefts involving Coincheck, Bitconnect, and Bitgrail, that amount still exceeds half a billion dollars in sixty days. And this astonishing figure only accounts for thefts above a minimum threshold of $400,000; so-called “micro-scams” on social media (such as the infamous Twitter celebrity impersonation con) are not included in the statistic because they are too difficult to measure.

Bitcoin.com ha pubblicato che un valore pari a 1,36 miliardi di dollari di criptovaluta è stato rubato nei primi due mesi del 2018 (9 milioni dollari al giorno). Anche escludendo gli enormi furti "anomali" che coinvolgono Coincheck, Bitconnect e Bitgrail, tale somma supera ancora mezzo miliardo di dollari in sessanta giorni. E questa cifra stupefacente è relativa solo a furti al di sopra di una soglia minima di $ 400.000; le cosiddette "micro-truffe" sui social media (come la famigerata imitazione di celebrità di Twitter con) non sono incluse nella statistica perché sono troppo difficili da misurare.

Reference
https://medium.com/trustroot/phishing-for-cryptocurrency-why-we-need-wallet-level-verification-protocols-to-restore-trust-to-28a39ac9e59f

mercoledì 3 ottobre 2018

How secure is Blockchain technology really?


This is a very interesting article from MIT Technolgy Review examining possible weaknesses in Blockchain technology, the new trending word for security in Internet.
If you are told that Blockchain is secure, please read this post first.

Questo è un articolo molto interessante del MIT Technology Review che esamina possibili punti deboli nella tecnologia Blockchain, ultima tecnologia di tendenza per la sicurezza su Internet.
Se vi viene detto che Blockchain è sicuro, leggete prima questo post.

Reference
https://www.technologyreview.com/s/610836/how-secure-is-blockchain-really/

60 Must-Know Cybersecurity Statistics for 2018


Cybersecurity issues are becoming a day-to-day struggle for businesses. Trends show a huge increase in hacked and breached data from sources that are increasingly common in the workplace, like mobile and IoT devices.
Additionally, recent research suggests that most companies have unprotected data and poor cybersecurity practices in place, making them vulnerable to data lass.

I problemi legati alla sicurezza informatica stanno diventando una lotta quotidiana per le imprese. Le tendenze mostrano un enorme aumento dei dati violati da fonti sempre più diffuse sul luogo di lavoro, come i dispositivi mobili e IoT.
Inoltre, recenti ricerche suggeriscono che la maggior parte delle aziende ha dati non protetti e pratiche di cyber-sicurezza inadeguate, rendendole vulnerabili agli attacchi.

Reference
https://blog.varonis.com/cybersecurity-statistics/

giovedì 30 novembre 2017

Point Of Sale are not immune to cybercrime, they are attacked on a daily basis


Several malware are specialized in attacking Point Of Sale (POS) used to pay with credit card. In 2014 there were more than 50 different malware variant.
POS are attacked on a daily basis. Just a few name of them:  BlackPOS, Alina, Dexter, JackPOS, VSkimmer

Molti software maligni sono specializzati nell'attaccare i Point Of Sale (POS) utilizzari per pagare con carta di credito. Nel 2014 vi erano più di 50 differenti varianti di malware.
I POS sono attaccati giornalmente. Solo alcuni nomi: BlackPOS, Alina, Dexter, JackPOS, VSkimmer

Reference
https://en.wikipedia.org/wiki/BlackPOS_Malware
https://www.theinnovationgroup.it/wp-content/uploads/2015/04/Cybersecurity-Summit-2015-Milano-Raoul-Chiesa-PUBLIC.pdf
https://en.wikipedia.org/wiki/Alina_(malware)
https://www.cnet.com/news/new-dexter-malware-strikes-point-of-sale-systems/
https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/jackpos
http://www.xylibox.com/2013/01/vskimmer.html
https://www.agendadigitale.eu/infrastrutture/pos-allarme-malware-in-italia-ecco-i-pericoli/

venerdì 17 novembre 2017

Phishing over SSL/TSL, Phishing sites exploit trust in valid SSL certificates


Certificate authorities aren’t scrutinizing who gets their SSL certificates, and now a large number of phishing sites have legitimate certificates, said Netcraft.
Netcraft has blocked phishing attacks on more than 47,500 sites with a valid TLS certificate between 1st January and 31st March 2017. On 19,700 of these, Netcraft blocked the whole site rather than a specific subdirectory. 61% of the sites that were entirely blocked were using certificates issued by Let's Encrypt, and 36% by Comodo.

Le autorità di certificazione non esaminano chi ottiene i loro certificati SSL, e ora un gran numero di siti di phishing hanno certificati legittimi, ha affermato Netcraft.
Netcraft ha bloccato gli attacchi di phishing su oltre 47.500 siti con un certificato TLS valido tra il 1 ° Gennaio e il 31 Marzo 2017. Su 19.700 di questi, Netcraft ha bloccato l'intero sito anziché una sottodirectory specifica. Il 61% dei siti completamente bloccati utilizzava i certificati emessi da Let's Encrypt e il 36% da Comodo.

Reference
https://news.netcraft.com/archives/2017/04/12/lets-encrypt-and-comodo-issue-thousands-of-certificates-for-phishing.html
https://www.infoworld.com/article/2992605/security/phishing-sites-exploit-trust-in-valid-ssl-certificates.html
https://www.scmagazineuk.com/ssl-encrypted-malware-doubles-this-year-phishing-over-ssltls-up-400/article/679607/

lunedì 30 ottobre 2017

Are 95% of HTTPS web servers still vulnerable to MITM attacks?


Encrypted communications are an essential requirement for banks and other financial websites, but HTTPS alone is not sufficient to defend these sites against man-in-the-middle attacks. Astonishingly, many banking websites lurk amongst the 95% of HTTPS servers that lack a simple feature that renders them still vulnerable to pharming and man-in-the-middle attacks. This missing feature is HTTP Strict Transport Security (HSTS), and only 1 in 20 secure servers currently make use of it, even though it is supported by practically all modern browsers.
Each secure website that does not implement an HSTS policy can be attacked simply by hijacking an HTTP connection that is destined for it. This is a surprisingly feasible attack vector, as there are many ways in which a user can inadvertently end up connecting via HTTP instead of HTTPS.

Le comunicazioni criptate sono un requisito essenziale per le banche e per altri siti finanziari, ma HTTPS da solo non è sufficiente per difendere questi siti da attacchi Man In The Middle. Sorprendentemente molti siti web bancari fanno parte di quel circa 95% di server HTTPS che non dispongono di una semplice funzionalità che li rende ancora vulnerabili ad attacchi pharming e Man In The Middle. Questa funzionalità mancante è HTTP Strict Transport Security (HSTS) ed attualmente solamente 1 su 20 server sicuri ne fanno uso, anche se è supportata da praticamente tutti i browser.
Ogni sito web sicuro che non implementa la policy HSTS può essere attaccato semplicemente dirottando una connessione HTTP a lui destinata. Questo è un vettore di attacco sorprendentemente fattibile, poiché vi sono molti modi con cui un utente può inavvertitamente connettersi con HTTP invece che con HTTPS. 

Reference

lunedì 11 settembre 2017

Disconcerting news about Cloud Storage with no security


Disconcerting news regarding security of some of the major Cloud infrastructures
  • Thousands of files containing personal data from former US military, intelligence and contractor personnel have been exposed online without any protection for months
  • Thousands of sensitive files have been found without protection on an Amazon cloud server
  • 600GB of sensitive data available on the Internet by the BroadSoft communications company, including millions of Time Warner customer records


Notizie sconcertanti sulla sicurezza di alcune tra le maggiori infrastruture Cloud
  • Migliaia di file contenenti i dati personali di ex militari statunitensi, personale dell’intelligence e contractor sono stati esposti online senza alcuna protezione per mesi
  • Ancora, migliaia di file sensibili sono stati trovati senza protezione su un server cloud di Amazon
  • 600 GB di dati sensibili disponibili su Internet dall’azienda di comunicazione BroadSoft, tra cui milioni di record dei clienti dell’azienda Time Warner


Reference
http://cybersecurity.startupitalia.eu/55464-20170908-cloud-storage-dati-senza-protezione-una-lunga-lista-di-incidenti-che-impone-una-riflessione
https://www.upguard.com/breaches/cloud-leak-tigerswan
http://gizmodo.com/thousands-of-job-applicants-citing-top-secret-us-govern-1798733354
http://securityaffairs.co/wordpress/56919/breaking-news/1-37bn-records-data-leak.html

mercoledì 19 luglio 2017

Hackshit platform, phishing as a service for "everyone"


Experts from the security company Netskop have discovered a new platform PhaaS (Phishing-as-a-Service) named Hackshit which can enable less experienced cybercriminal with poor skills to launch phishing campaigns.

Gli esperti dell'azienda di sicurezza Netskop hanno individuato una nuova piattaforma PhaaS (Phishing-as-a-Service) di nome Hackshit, che può consentire a cybercriminali anche senza esperienza tecnica di lanciare campagne di phishing.

Reference

venerdì 31 marzo 2017

Security Summit 2017, the Clusit alarm: more investments in Cybersecurity



According to the Clusit Report 2017 presented at the Security Summit 2017, it is necessary to invest more in technology and training for Cyberecurity in our country, following a strong increment of phishing and social engineering attacks.
The human factor continues to be the weak link in the security chain, together with the low propensity to invest for increasing current levels of security.

Secondo il Rapporto Clusit 2017 presentato al Security Summit 2017, è necessario investire di più in tecnologia e formazione per Cyberecurity nel nostro paese, a seguito di incrementi a quattro cifre degli attacchi di phishing e social engineering.
Il fattore umano continua ad essere l’anello debole della catena della sicurezza, insieme alla scarsa propensione ad effettuare investimenti per aumentare gli attuali livelli di sicurezza.

Reference

lunedì 16 gennaio 2017

The most harmful cyber attacks of 2016


Richard Stennion (author of There Will Be Cyberwar) said that "2016 will be remembered as the most important year in the evolution of the nation state attacks," and that the cyber espionage has long been one of the most important tools for hackers and intelligence, inviting everyone to improve their computer security level for the new year.

Richard Stennion (autore di There Will Be Cyberwar) ha detto che “il 2016 sarà ricordato come l’anno più importante per l’evoluzione dei nation state attacks,” e che lo spionaggio cibernetico è da tempo uno degli strumenti più importanti per hacker e servizi segreti, invitando tutti a migliorare il proprio livello di sicurezza informatica per il nuovo anno.

Reference
http://cybersecurity.startupitalia.eu/53770-20161230-gmail-yahoo-linkedin-attacchi-informatici-2016

giovedì 20 ottobre 2016

Two threats for mobile banking in the Top 10 of the Kaspersky Security Bulletin 2015


In the Top 10 of the Kaspersky Security Bulletin 2015 there are two threats for mobile banking

The 1° is a Faketoken, a Trojan family for smartphones that intercepts mTAN unique code to authorize a generic transaction.
The 2° is a Marcher, a Trojan family for smartphones that monitors activities and if you access the Android marketplace opens a fake window to steal your credit card data.

Nella Top 10 del Security Bullettin 2015 di Kaspersky vi sono due minacce per il mobile banking.
La 1° è un Faketoken, una famiglia di Trojan per smartphone che intercetta il codice univoco mTAN per autorizzare una generica transazione.
La 2° è Marcher, una famiglia di Trojan per smartphone che controlla le attività dello smartphone, e se l'utente accede al marketplace di Android apre una finta finestra per rubare i dati della carta di credito.

Reference

martedì 11 ottobre 2016

Side Channel attacks, to steal data from a NFC tag, contactless cards


NFC Technology may offer a new attack surface, a new way to attack and stole our data. IST Model can protect NFC communications.

La tecnologia NFC può offrire una nuova superficie di attacco, una nuova strada per attaccare e rubare i nostri dati. IST Model può proteggere le comunicazioni NFC.

Reference
http://smartmoney.startupitalia.eu/payments/52648-20160307-clonare-carta-contactless-1-secondo
https://en.wikipedia.org/wiki/Side-channel_attack
http://link.springer.com/chapter/10.1007%2F978-3-642-29912-4_2#page-1
https://holyhash.com/tag/nfc/

NFC cards, stealing money with cheap devices?


NFC cards are very easy to use, but this could let a mobile POS to steal money. And this device can be bought for only 10 euros. A NFC payment system based on IST Model offers complete protection from this fraud.

Le carte NFC sono semplicissime da usare, ma questa semplicità potrebbe consentire ad un POS mobile di sottrarre denaro. E questo dipositivo costa appena 10 euro. Un sistema di pagamanento NFC basato su IST Model protegge da questo pericolo.

Reference
http://www.dailymail.co.uk/news/article-3451307/The-electronic-pickpocket-Scammer-steals-hundreds-pounds-touching-victims-pockets-sales-device-transferring-cash-contactless-payment-credit-cards.html

http://smartmoney.startupitalia.eu/payments/52144-20160227-rubare-soldi-carta-contactless-spiegazione

lunedì 19 settembre 2016

Decrypting 4096 RSA Key with Acoustic Cryptanalysis


Security researchers have successfully broken one of the most secure encryption algorithms, 4096-bit RSA, by listening (with a microphone) the CPU of  a computer as it decrypts some encrypted data. This attack technique is named Acoustic Cryptanalysis.

Ricercatori hanno violato con successo uno dei più sicuri algoritmi di criptazione, RSA con chiave a 4096 bit. La tecnica utilizzata è detta Acoustic Cryptanalysis e si basa nell'ascoltare (con un microfono) il suono (particolari frequenze) che emette una CPU mentre esegue una decriptazione.

Reference
http://www.extremetech.com/extreme/173108-researchers-crack-the-worlds-toughest-encryption-by-listening-to-the-tiny-sounds-made-by-your-computers-cpu
http://securityaffairs.co/wordpress/20637/hacking/acoustic-cryptanalysis-attack.html
https://www.tau.ac.il/~tromer/acoustic/

mercoledì 31 agosto 2016

Cyber-Crime, 1 million victims each day

A study of Cybersecurity Ventures funded by Herjavec Group demonstrates how the cybercrime phenomenon is tremendous rise and that neither the companies nor their CEO are prepared to face it. While the cost for the damages caused by cybercrime in 2015 was 400 billion USD, by 2021 this cost will reach 6 trillion USD. Among the most affected realities are the medical facilities and the Internet of things.

Uno studio di Cybersecurity Ventures finanziato dal gruppo Herjavec dimostra come il fenomeno del crimine informatico sia in tremenda ascesa e che né le aziende, né i loro Ceo sono preparati ad affrontarlo. Mentre la spesa per i danni provocati dal cybercrime nel 2015 è stata di 400 miliardi, di dollari entro il 2021 questa spesa arriverà a 6 trilioni di dollari. Tra le realtà più colpite ci sono le strutture sanitarie e l’Internet delle cose.

(Credit Cybersecurity Ventures, Herjavec Group)

Reference
http://cybersecurity.startupitalia.eu/52725-20160830-infografica-cybercrime-investimenti-cybersecurity

mercoledì 27 luglio 2016

Phishing, probability higher of 50% to encounter a phishing site in 2016

An user is surfing the web. The probability that he will encounter a phishing site during 2015 was 50%, against 30% in 2014. And in 2016 will be above 50%, as stated by Webroot.
They analyzed 27 billion URLs and more than 600 million domains.
The report says that the most phishing-cloned companies are the financial and technology ones.

Un utente naviga nel web. La probabilità di incappare in un di di phishing nel corso del 2015 è stata del 50%, contro il 30% del 2014. E nel 2016 sarà superiore al 50%, come dichiarato da Webroot.
Sono stati analizzati 27 miliardi di URL e più di 600 milioni di domini.

Secondo il report le maggiori aziende bersaglio del phishing sono quelle finanziarie e tecnologiche.

Reference
http://cybersecurity.startupitalia.eu/52291-20160614-pmi-e-sicurezza-phishing-malware-e-trojan-nellinfografica-di-webroot
https://webroot-cms-cdn.s3.amazonaws.com/7814/5617/2382/Webroot-2016-Threat-Brief.pdf