Showing posts with label DR note. Show all posts
Showing posts with label DR note. Show all posts

Monday, June 27, 2022

Welcome to DR's note, your weekly dose of knowledge from Circuit Stitch Blog.

 

This week we take about open source.

    We hear open source all over the place, but do you know what it is?  Open source refers to software that can be modified and shared because its design is publicly accessible.  The simplified version is the source code (the part that makes up the software) can be accessed easily and minimal to no cost, then you can add, remove, or replace any of that code to make it your own.  So if you hear that some software is open source, then it was created by means to be distributed and used free of cost.  They some times will have a donation page asking for donations to help cover the cost of running, maintaining, and updating the software. 

    Is all open source software safe to use?  The short answer is no, but the long answer is nnnnnooooooooooooo.  Basically it is a two-edged sword, on the one side you (or a programmer) have the ability to check the source code for anything malicious, on the other side someone malicious could have put something in that source code you don't know about.  That is one reason why you should only download software directly from the company that created the software.  When you download from third party sites, you run the risk of downloading a tainted file. 

    So what are the advantages and disadvantages of using open source software?  Let us start with the advantages, firstly it is created by people that are very talented and enjoy what they do.  If these people didn't like what they do, then they would not have created it.  Secondly, it tends to be cheaper than commercial versions.  They are either free, ask for a lower cost, or ask for a donation to the project.  Thirdly, the software is reliable, which goes hand in hand with the created by talented people.  Lastly it is flexible, since you are not tied to a proprietary software architecture, it can be used or configured for many platforms.

    Now let us look at the disadvantages, firstly it is more easily editable and could have malicious code hidden in it.  This would go with download it from a reputable site.  Secondly, it might not be as user-friendly as it is a proprietary counterpart.  Thirdly, when it comes to support it is more community based.  You might  not be able to go to the creators website and get a solution to your problems, you'll probably have to check out forums and different post from people that had the same issue as you and how they fixed it.  Sometimes you'll find a solution, sometimes you won't. 

    We all use open source software daily, Thunderbird our email client is open source.  Sometimes you just need to do a little research to vet if the software is good and legitimate.  As always if you have any questions feel free to email me, and if you have any topic you'd like me to talk about.  Have a great week.





If you'd like to read more about open source, this is where I got some of my information
https://connectusfund.org/7-main-advantages-and-disadvantages-of-open-source-software

https://opensource.com/resources/what-open-source

Tuesday, June 21, 2022

Welcome to DR's note, your weekly dose of knowledge from Circuit Stitch Blog.


 Today we will talk about OSINT.

 

            What is OSINT and how do you pronounce that?  Let’s start with the latter and work our way from there.  It is pronounced O SIN T, start with the O and say SIN, and end it with a T.  So what is OSINT, it stands for Open Source Intelligence, the meaning which is coming from Wikipedia is, “the collection and analysis of data gathered from open sources (overt and publicly available sources) to produce actionable intelligence.”  Basically, it means any source of information you can gather by publicly available means.  It’s the beginning steps that some hackers would take to investigate you and find out all they can so that hack or take advantage of you. 

 

            Are hackers the only ones that do this? Nope, it is not just hackers that use OSINT, it is business’s, law enforcement, or nation-state actors.  Businesses use OSINT to gather knowledge about consumers as to better market to them and thus increase profits.  Law enforcement use it to gather knowledge people they are trying to arrest, to build a better case on them.  Nation-state actors use this info to do all sorts of malicious things spear phishing (target phishing campaign) to industrial sabotage.  Nation-state actors can be some of the most highly trained and devoted hackers out there. 

 

            Your are probably asking yourself, how does this pertain to me?  OSINT can be used to learn more about you!  This is one reason I say to keep all your account private as much as possible and don’t overshare on social media.  But how do they find all this out?  Nowadays they have software out there that can do sweeps of the internet for certain usernames, email addresses, etc.  But the most common thing used today is called Google hacking or more commonly known as Google Dorking.  Techopedia defines Google Dorking as “a hacking technique that makes use of Google's advanced search services to locate valuable data or hard-to-find content.”  So you use advanced search services that are already baked into Google’s search engine,  In the next paragraph we will look into how this is done and ways you can use it to your benefit.

 

            So let say you wanted to search a website (lets say Target) for an item or items(lets say Pokemon), you could type in the Google search bar pokemon target and you’ll get things from Pokemon cards to toys to youtubers that went to target for Pokemon.  Now if we put in the Google search bar site:target.com “Pokemon”, this will search the Target website for anything that has the word Pokemon in it.  You can do this with any website and and search terms, I used this process when looking for ink for printers here at SMC.  There are tons that you can do with Google Dorking, I’ve linked a google dork cheat sheet in the sources if you care to look.

 

            Other the Google Dorking what are some other ways that people find OSINT.  Well once someone gets your name or even a username that you use on social media, video games, etc. they can start to build their OSINT on you by searching either of those terms and as they find more info it will give them more to search.  It’s like a snowball effect or an even more strange analogy where the person takes a penny and trades up to eventually have a car.  It is reasons like these I advocate that you use a Password Manager, 2FA, change accounts to private, and never trust anyone online or on the phone.  If you just do a couple of these then you will be ahead of so many people.

 

            I hope this has been eye-opening and gives you a better understanding of what OSINT is and how it can be used to help or harm you.  As always if you have a questions or concerns feel free to call or email me, I’d love to talk about it.  Also if you have any DR note topics you want me to discuss please let me know.  Until next week, I hope you have a great week and Be Awesome.

 


Source:

Open-source intelligence: https://en.wikipedia.org/wiki/Open-source_intelligence

Nation State Threat Actors: From a Security Awareness Perspective: https://www.sans.org/blog/nation-state-threat-actors-from-a-security-awareness-perspective/

What is Spear Phishing: https://www.knowbe4.com/spear-phishing/

Google Dorking: https://www.techopedia.com/definition/30938/google-dorking

Google Dork Cheatsheet: https://gist.github.com/sundowndev/283efaddbcf896ab405488330d1bbc06

OSINT Framework: https://osintframework.com

Tuesday, June 14, 2022

Welcome to DR's note, your weekly dose of knowledge from Circuit Stitch Blog.


 Today we will talk about the "GoodWill" ransomware

 

Have you heard of this ransomware?  It is called "GoodWill" and it seems to aim at making you a better person.  You may be asking yourself how does it do this?  Well, I shall discuss with you how it is done.  First, your computer will need to be infected with this ransomware, this can be done like any other virus you get on your PC.  You clicked on a link you shouldn’t have, downloaded a pirated movie or game, went to that porn site, etc.  But now your computer is infected and there is only one way to get it decrypted.

 

Technically there are several "Activities" in this one way but we shall look at them one at a time.  The first "Activity" they require you to do is to cloth a roadside homeless person.  But you not only have to give them clothing, but you must also create a Facebook, Instagram, or Whatsapp story about clothing the homeless.  You must also use the photo frame they give you and encourage others to do it as well.  Once you do this then you have to send them an email with a screenshot of the post and the post link, here is my favorite part, it says and I quote "later our team will verify the whole case and promotes you for the next activity".  So then you have to wait till their team verifies what you have done, then you can move on to the next "Activity".  Let's look at the next "Activity" to see what our "GoodWill" entail.

 

The next "Activity" is to pick up 5 poor children from your neighborhood and take them out for dinner at Dominos, Pizza Hut, or KFC.  Then once again you will have to make a story post on your social media, this time though the kids have to be in the picture and have smiles on their faces.  You must again use their picture frame and take screenshots of the post, this time though you will need to take a picture of your receipt to send along with to the ransomware people.  Also again you will have to wait to have it verified before you can move on to the third and final "Activity".

 

The final "Activity", now requires you to go to your nearest hospital, and find someone that needs their care paid for because they don't have the money and pay their medical bill.  That's correct, you must go pay their medical bill, or as the ransomware states "provide them maximum part of the required amount."  You will also need to get selfies with the person you just paid their medical bill, record the whole conversation between you and them and send it back to the ransomware people.  But you’re not done yet, after you have done everything above you then need to and I quote, "Write a beautiful article on your Facebook and Instagram by sharing your wonderful experience to other people that how you transform yourself into a kind human being by becoming victim of a ransomware called Good Will".  So you not only have to do all these "goodwill" acts but at the end, you have to create a post saying that this ransomware has changed your life for the better.  Then hopefully this ransomware group with send you a decryption key that you can decrypt your files.

 

Well, I don't know about you but I don't need ransomware forcing me into performing "activities" and making me post about it on social media to create awareness about the plight of being a human.  Are these things happening, yes. Do you wish more people would help with these issues, yep.  Should you hi-jack someone’s files and force them into this position in the hope it will make them a better person in the end, nope.  Ransomware in any form no matter have "pure" your intentions are, is illegal.  The easiest way to fight against ransomware is to keep your computer up-to-date with the latest security updates and to have a good anti-virus in place.

 

I hope this has informed you about some of the newest ransomware that could not only impact your work system but even your computer at home.  If you have any questions feel free to leave a comment below.  If you have any ideas for future DR notes please let me know, and maybe it will be a future DR note.  I hope you are having a great week and Be Awesome!

 

 

 

Funny Tweets About Chuck E. Cheese

 

Sources:

 

New 'GoodWill' Ransomware Forces Victims to Donate Money and Clothes to the Poor: https://thehackernews.com/2022/05/new-goodwill-ransomware-forces-victims.html

 

Eerie GoodWill ransomware forces victims to publish videos of good deeds on social media: https://blog.malwarebytes.com/ransomware/2022/05/eerie-goodwill-ransomware-forces-victims-to-publish-videos-of-good-deeds-on-social-media/#:~:text=GoodWill%20ransomware%20functions%20like%20any,to%20recover%20your%20locked%20files.




Tuesday, June 7, 2022

Welcome to DR's note, your weekly dose of knowledge from the Circuit Stitch Blog

 This week we will talk about autocorrect, spell checker, and grammar checkers.

    To start off, I am not going to talk about how autocorrect, spell check, or grammar check works (even though it might be fascinating to look under the hood on it).  What we are going to talk about are these programs actually making us dumber?  If you think about it, how often do we misspell words and autocorrect is right there fixing them without you intervening.  The problem I see most frequently is the work gets fixed, and I didn't learn how I misspelled the word wrong.  The reason is by the time I notice it was misspelled, it was changed, and I forgot how I spelled it.  Now that might just be me, but I feel that might be many of you out there as well.  How often do you have to google a word in hopes that Google knows what you're trying to type so that gives you the correct spelling, or asking our phones how to spell a word.  I've done it countless times.  Grammar is one of my weakest point and has been since I was a kid.  In fact, after I finish typing up this email, I will run it through an application to check my spelling and grammar.  But are they all bad?

    Let us look at a program I use to help me with my spelling and grammar, it is called Grammarly.  They have a free version (which is the one I use) that not only can help with spelling, but can even see what you are trying to convey and make sure you are using proper grammar.  The program is pretty neat, and is the one I use to check these emails along with other items I write up.  In the settings of Grammarly you can choose; I write in, and choose what language you type in, detect tone in my writing, and writing style.  Detect tone in my writing is Grammarly's way of check to see if you are conveying what you're trying to convey, and if the grammar is correct in that.  Writing style is the personal dictionary, this is where you can add word that you may use all the time but are not maybe spelled properly.  An example of this would be SMC, now it will say that is misspelled, but I can add that to the dictionary, and it won't catch it every time you use it.  This would work for first or last names as well, if they get hit by the spell check every time(I know mine does). 

    So the burning question is, how do these make us dumb?  To answer it simple, the only time I think that it is a detriment to us is when the correction happens automatically.  When it happens automatically, yes it save some time but at the cost of you learning your mistake.  When we make mistakes, they can be used to help us grow and learn.  Does it suck to make mistakes?  Yes, sometimes more than others, but it is in these mistakes that make us who we are.  I know you never hear about people's mistakes only successes, but if you think about it, how many times did they have to make mistakes to get to that success.  A famous quote by Thomas Edison, “I have not failed. I've just found 10,000 ways that won't work.”  Who know, maybe one of those mistakes will make you realize something, then down the road you'll remember those mistakes and maybe learn something new from it. 

    I hope you learned a little about grammar programs and maybe a little about yourself.  If you have a questions or concerns, please leave a comment below.  Also, if you have any topics you want to know more about, let me know, and maybe I'll do a DR note on them.  Have a great week!!

Futurama Fry memes | quickmeme

Tuesday, May 31, 2022

Welcome to DR's note, your weekly dose of knowledge from Circuit Stitch.

 Today we will talk about Follina 

                What is Follina?  Follina or CVE-2022-30190 is a zero-day exploit that uses Microsoft Word documents to execute Powershell code on your computer.  In the original document, the file has other hidden files inside of it by the use of compression, it is a .rar file.  So that once the document file is executed or run, you would reach out to a website to grab an HTML file.  This file would then run automatically, it would start a hidden command prompt window.  This hidden window would shut down the msdt (Microsoft Diagnostic Tool) program, it would then go through looking for a certain file that is encoded.  It would then save that file, decode that file, bring that file to the current directory, and execute a file called rgb.exe.  At the moment the rgb.exe file is unknown, meaning the infosec community isn’t sure what this file did, but what we do know is this is a form of RCE.

                 What is RCE?  RCE stands for remote code execution, it basically means that an attacker can create a file or program which I will refer to in the rest of this as a payload.  The payload will then be transferred over to someone else’s computer via any number of ways; i.e. email, USB stick, download, etc.  Once the payload is on the target system, it will need to be executed for the RCE to take effect.  Now RCE can be a lot of things, once it’s executed it could create a shell that gives the attacker access to your machine, it could execute ransomware, could add your machine to a bot-net (a future DR note), a bitcoin miner. Suffice it to say a lot can happen to your machine if it is run.

                 Do we need to worry about Follina?  Yes and no, at the time of writing this Microsoft is saying that it will be detected by Defender (Microsoft’s anti-virus) and will be labeled as “Mesdetty” and “Mesdetty Launch”.  Now let me explain why you should and shouldn’t worry about this.  Like all modern cyber threats, you should have concern enough to keep an eye out for it, but as of right now it doesn’t seem to be much of a threat because it hasn’t been used against anyone.  Not saying it won’t be used in the future but currently, it was pointed out that at the time of writing this no one has been a victim of this attack. 

                If you want to know more about Follina or CVE-2022-30190, check out my sources at the bottom of the email.  Also if you have any questions or if you have any topics you’d like me to discuss on a future DR note, please email me and let me know.  I hope everyone has a great week and Be Awesome!

Tuesday, May 24, 2022

Welcome to DR's note, your weekly dose of knowledge from Circuit Stitch.

 This week we talk about the Dark Web.

    We hear about the dark web from different places like commercials trying to spook you into thinking your personal info is on it.  But let us look at Wikipedia, as I like the way the definition is on there.  The dark web is the World Wide Web content that exists on dark nets.  Dark nets are overlay networks that use the internet but require specific software, configurations, or authorization to access.  Basically, it means that the Dark Web exists in the same space as the regular internet that you know and love.  You can't get there though by just googling take me to the Dark Web, no, you need to install special software that will be able to take you to these dark nets.  One such software that you can download and install is called the Tor browser.  The Tor browser uses the Tor dark net to explore the different websites, there are other dark nets like Freenet, I2P, and Riffle.  To conclude this section, I think it is worth stating that there is a difference between the Dark Web and the Deep Web.  The Deep Web is parts of the web not indexed or searchable by search engines, basically, they want to remain as anonymous as possible and only if you know how to get to the address is how to get to it.  Most Deep websites aren't something you want to go to anyway.

    So, what type of content is on the Dark Web?  So, one of the most prolific things on the Dark Web is CP, that is all I am going to say, and will not be going into it further as it is not something that needs discussing here.  Next would be black markets where you can buy anything from fakes IDs, drugs, guns, cyber-attacks, and so much more.  You can also find social media, message boards, and bitcoin services.  Bitcoin is the currency of the Dark Web; the biggest reason also ties into why people use the Dark Web.

    Why do people use the Dark Web?  Anonymity, plain and simple.  When you access a dark net, your identity and location are anonymous to an extent.  With the encryption used you are by all accounts anonymous, but if you were to log into something like Facebook then it kind of defeats the purpose of using the Dark Web.  I mean you can create an account on other sites while using the Dark Web and still remain anonymous, but if you log into something that was created on the clear net (regular internet) then there was no reason why you even are using the Dark Web, I hope that made sense to you. 

    I hope this has opened your eyes to what the Dark Web is and taught you about what can happen just below the surface of your internet.  As always, if you have questions please comment below.  If you have any ideas for future DR notes, please let me know, I'd love to hear about them.  Thank you and have a great week.




Monday, May 16, 2022

Welcome to DR's note, your weekly dose of knowledge from Circuit Stitch.

This week we will be talking about QR codes.

    Why do we need to talk about these, they are harmless, right?  Wrong!!  These little codes can lead to different places or even download malicious code to your devices.  You should never scan an unknown QR code, if you see one out in the wild on a bulletin board or on a phone pole, never scan it.  If someone you don't know starts to talk to you and then says oh do you want my contact info, then tries to get you to scan a QR code, DON'T. 

    So how does the QR code work then, let me break down the step.  First off, QR stands for Quick Response code, it was developed back in 1994 by a Japanese developer.  Smartphone camera software usually has some lines of code in it to be able to scan QR codes.    QR codes have multiple parts, but three are the most important, and you will see them on most if not all QR codes.  The three parts are the Data module, the Position marker, and the Quiet Zone.  The data module is the black and white area inside QR codes that are scanned, this is the part that will then tell the software where to go once scanned.  The position maker is the three-square boxes you see on all QR codes, they are used to tell the camera what position the QR code is in, so it can be scanned properly.  The last is the quiet zone, which is the white area around the entire QR code.  That blank area is used to let the camera know where the QR code starts and ends.  Now we know the parts of the QR code, it makes it a little simpler how they are scanned.  To put it in its basic terms, they are fancy barcodes, plain and simple. 

    QR codes can do a number of things, both good and bad.  I tend to err on the side of caution and not scan QR codes, all it takes is for someone to replace that good QR code with one that downloads malware or goes to a malicious site.  I hope this has informed you of the dangers we face from QR codes.  If you have any questions, please email me or call.  Thank you and have a great week.

go ahead scan it you know you want too 😈

Wednesday, May 11, 2022

Welcome to DR's note, your weekly dose of knowledge from the Circuit Stitch.

This week we discuss and discover, What is the Cloud?

    So what is the cloud?  The simplest answer I can give is this, the cloud is someone else's computer.  Now by someone else's computer, it could be Google, Microsoft, basically any place that host servers that is storing your data in the cloud.  When you hear the term server, it is not some fancy piece of equipment that is foreign and unknown, it is just a computer that is running an operating system geared towards whatever its main function is.  So if you have a server that is for emails, then you will run an OS (operating system) with software gear to do the sending the receiving of emails.  Then, if you have a Cloud server, you would run an OS designed to save information on it. 

    The cloud server is just glorified online storage, basically a NAS (network attached storage) that is attached to the internet and not just your network at home or at work.  A NAS at home or at work is only able to accessible by being on that network or connecting to that network via VPN.  But the biggest difference is that when you have a NAS, then you are in control of the physical device that stores your data.  You have to take care of it, check to see if it is still functioning properly, etc.  With cloud storage, all of that is handed over to the cloud storage provider to take care of.  They have redundancies to ensure that your data doesn't get erased (by them, not by you, if  you erase it then it's gone) or lost.  Plus, the convenience of cloud storage is that it can be accessed anywhere you have a connection.  Cloud storage is also pretty inexpensive compared to the upfront cost of a NAS, decent NAS units could cost anywhere from $300-$1000.  While cloud storage is either free or maybe a buck a month.  To me, using the cloud is a no brainier.

    I do think it's worth mentioning that if you have copious amounts of data, you might want to invest in a good external hard drive, preferably an SSD (solid state drive) kind.  That way It could help save on cloud cost, and you can take it anywhere, you don't need an internet connection.  You just plug the USB (universal serial bus) into your computer, then you can move over what you need to help clear up space. 

 I hope this has helped you understand what Cloud storage is, and if you have any questions, feel free to ask away.  Also, if you have any topics you'd like me to discus here, please leave a comment, I want to know what you want to know more about.  Thank you and have a great week.

The Tech Recruiters Guide to: Cloud Professionals ...

Monday, April 18, 2022

Welcome to DR's note, your weekly dose of knowledge from Circuit Stitch Blog

This week we will talk about email and how it works.

    At my job I had a snafu with email a couple of weeks ago, this made me think about emails and how they work.  So I researched it and thought I'd share my findings with you and give you a glimpse behind the curtain of what happens after you send an email out.  As we discover about email, we will use my email as an example to help understand it better.

   So what is an email?  Well email literally means electronic email, email is also a very old technology that is still used today.  At one point email was the equivalent of a text message today, now we use it for many reasons that I couldn't even list all of them here.  It may seem as simple as type out the sender, subject, and body.  Click send and off it goes straight to the sender, but there is a little more to it than that.  Let me explain, so after you do your part of putting in the sender, subject, and body of the email.  You click send, the magic happens.  First stop is the SMTP server.  SMTP stands for simple mail transfer protocol(the internet is made up of many protocols that dictate how things work and what purpose those things have, but that is a discussion for another day).  The SMTP server is like the post office, it will check your message to find out where it needs to go.  Unfortunately, this post office doesn't have a list of domains (address's, basically what is after the @ symbol).  So the SMTP server sends a message to the DNS (Domain Name System) server asking what the IP (Internet protocol) address is for, let's say hotmail.com.  If the DNS server knows the IP address it will send it back to the SMTP server, if not it has to go out to the internet to discover what the IP address for hotmail.com is.  Once it gets the IP address, it will also check out to see if that IP address has an MX (mail exchange) server, which means that that IP address is able to receive emails.  So now that the DNS server has all this info, it will go back to the SMTP server with it and hand over that information.  The SMTP server will then use that info to send the email over to the hotmail.com.com or 204.79.197.212 which is the IP address.  Once there it is redirected to the MX server, the MX server then directs it to the user's account.  The user's account will then use either IMAP (Internet Message Access Protocol) or POP (Post Office Protocol) in its retrieval of emails.  By user account, I mean what you use to access your email, whether it is Thunderbird or through the browser.  Then your user account will inform you that “You've Got Mail”.  Then you can read and access that email, simple, right?

    I hope this has helped you to understand what goes into sending an email, and had you gain a better knowledge of how these boxes we work with daily actually work.  If you have any topics you're interested in, let me know, maybe I do a DR note in the future on it.  Until next week, have a great day.

https://www.howtogeek.com/56002/htg-explains-how-does-email-work/

TryHackMe Write-Up | Sysinternals Task 9  Miscellaneous

BgInfo "It automatically displays relevant information about a Windows computer on the desktop's background, such as the computer ...