|
|
|
|
|
|
|
Computers › Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by danski(op): 10:12am On Oct 10, 2021 |
KingOfAmebo: "Oga, As long as people like clicking they can never escape being a victim of attacks and this includes you...no just let hackers reason your matter, when they do na sorry be your matter...IT gurus also get hacked". - Village People spokesperson. Use ur sense well so u won't have to write dis rubbish u did here |
|
Computers › Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by danski(op): 4:22pm On Oct 09, 2021 |
lonelydora: Ok Sorry I can't access d email now Contact me Wit dis email danskidollarbill4@gmail.com Wit ur WhatsApp no let's talk |
Crime › Re: Anambra Security Operatives Accused Of Shooting People Returning From Mortuary by danski: 3:51pm On Oct 09, 2021 |
Justbehave: You lack logical reasoning.Carry a tinted window car and when you get to a military check point zoom off don't stop and don't wine down,if they kill you,Oga,you die for nothing. Na for only social media we go mourn you since you don't have sense to know that everywhere is boiling because of insecurity. U and sense is like DAT of bihari and good governance I have only one tin I have to say May u b killed like dem |
Crime › Re: Anambra Security Operatives Accused Of Shooting People Returning From Mortuary by danski: 2:36pm On Oct 09, 2021 |
Originalsly: Knowing the insecurity .... why would he be even trying to get away from security operatives ... in a car with tinted windows? I can't blame the security. It was OK for him to lose his life because of his foolishness....but not that of his wife. May ur life be like DAT of the man May u die hopelessly May ur body Neva b found after you get shot |
Crime › Re: Anambra Security Operatives Accused Of Shooting People Returning From Mortuary by danski: 2:34pm On Oct 09, 2021 |
Justbehave: Sorry to say this but they caused their death. Why were they running and making the security men to give them a chase before shooting them? There's insecurity everywhere and we all should be wise. If you are in a military or police checking point and suddenly you started runing especially if the car glasses is tinted. What do you expect? Or are you expecting they should fold their arms and get killed? Don't they too have families and loved ones that will miss them if they are killed? RIP to them. Shut up May ur life be like DAT of dem Amen |
Education › Re: Two Siblings Who Make Love Together Receive Parents' Blessing by danski: 2:28pm On Oct 09, 2021 |
|
Education › Re: Ogun Sec. School Student Squeezes Bo*bs Of Female Classmate In After-exam Photo by danski: 2:25pm On Oct 09, 2021 |
|
Education › Re: Ogun Sec. School Student Squeezes Bo*bs Of Female Classmate In After-exam Photo by danski: 2:24pm On Oct 09, 2021 |
Hi |
Politics › Re: Urgent: How Do I Contact Bukavu Barracks In Kano?. by danski: 2:23pm On Oct 09, 2021 |
|
|
NYSC › Re: Urgent Answers Needed Please by danski: 2:21pm On Oct 09, 2021 |
|
Romance › Re: .... by danski: 2:20pm On Oct 09, 2021 |
|
Computers › Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by danski(op): 11:30am On Oct 09, 2021 |
lonelydora: Yes. I have his number Ok simply message us on the email |
Crime › Re: What I Noticed On Nairaland by danski(op): 11:30pm On Oct 08, 2021 |
jaeyking: It's simple the audience what's topic about snakes, bobrisky, ipob, bubu, Tonto, our celebrities, Boko, bandits and ungun known men, men/women wanting advice for marital problems
Any other topic hardly gets to front page..
Ask yourself when last did you see topics on health related issues like how to keep fit, stay healthy, jokes, school scholarships make front page Yes This forum is losing it value |
Computers › Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by danski(op): 11:27pm On Oct 08, 2021 |
lonelydora: A scammer hacked my sister's WhatsApp number and he is currently using the account below to collect money from her friends.
After many efforts to get back the WhatsApp account, the WhatsApp Help Desk asked us to wait for 6 days.
Please, is there anything we can at the moment?
This is the account her friends are sending money to.
Account number: Oluwasean Olasnkanmi Adekunle. Acct number: 1484403350 Bank name: Access Bank
OAM4J and Mynd44 Please help push to front page. There's a lot you could do Do you wanna track the person phone |
Computers › Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by danski(op): 11:21pm On Oct 08, 2021 |
Ajenikoko89: Using social engineering method to do information gathering. Ok |
Computers › How To Hide Your File by danski(op): 9:42pm On Oct 08, 2021 |
|
Crime › Re: What I Noticed On Nairaland by danski(op): 9:16pm On Oct 08, 2021 |
|
Crime › What I Noticed On Nairaland by danski(op): 9:15pm On Oct 08, 2021 |
Am sure u all have noticed this but I will go to d Point
Lately news that reach FP is usually useless and the news which should be reaching FP and being deleted and the account suspended
Lately I posted something about how to protect phones from criminals I was suspended with my post deleted But if it where to be. Bbn am sure it won't take a minute to get there
Please mods who approve posts should please do the needful Because nairaland value is dropping
Mods please move this to FP let's hear peoples reactions
What do you guys think.....give ur opinion |
Politics › Re: Shocking!!! Unknown Gunman Killed By Police In Imo Turns Out A Nigerian DSS by danski: 3:01am On Oct 07, 2021 |
Chqi |
Computers › Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by danski(op): 9:39am On Oct 05, 2021 |
The Customer service week which holds every 1st week of the month of October has come to be recognized as the week we celebrate the importance of customer service and importance of the people who serve and support customers on a daily basis.
However in all of these celebrations lest we get carried away, do you know that the customer service desk is one of the most vulnerable channels through which a hacker could strike an organization, company or firm as the case maybe harvesting a large amount of data and informations about workers, customers and business partners in association with the attacked entity?.
Microsoft sometime in June 2021 suffered a cyber attack in which a device used by one of its customer service agents was breached and account details of customers were stolen and used to launch “highly targeted” attacks on customers.
When hackers strike companies like this, data such as Social Security Number, National Identification number, Bank Verification Number, Date of birth, Email addresses, Financial information, phone numbers and passwords which is generally known as Personally Identifiable Information (PII) gets stolen and sold to Identity thieves who possess the ability to do and undo with the details he/she has just acquired.
As an example, a cybercriminal manages to get hold of a user’s email credentials. Unfortunately for the victim, this email also contains banking informations with which unauthorized transactions can be done. This email also contains the user’s Facebook account, which also uses the same password as his email. In a single attack, the cybercriminal already gains access to a wide array of information—enough to perform multiple types of identity fraud.
Do not feel you run a small company so you have no reason to worry about data theft, you are wrong! Are you a law firm, logistics firm, gift card trading company, online dating business website, e-commerce store, hotel owner, school owner, hospital owner, church owner etc and you one way or the other receive even the littlest of details from the general public such as name, email addresses, phone numbers etc then the protection of your customers data is your utmost responsibility and this is predicated on the CIA Triad.
MEDIUMS THROUGH WHICH CUSTOMER SERVICE STAFFS MAYBE VULNERABLE
The Phone: Attackers usually obtain phone numbers from an organization’s website, in addition to any specific routing emails used for customer support. Attackers may call from a spoofed, blocked, or private phone number. An attacker posing as a customer can usually cull enough information from social media platforms and other sites to answer simple security questions. The attacker could also ask for a password reset. They may also try to change something on a customer’s account in order to have access to it themselves. They could also pose as fellow staffs and try to gain unauthorized privilege in the name of distress.
In a Pentest I was hired to do on a company in Lagos, all it took to get the Wifi Password was a spoof call to the IT guy and i was in their network ready to scan and exploit their system. As simple as it may sound, hacking an organization may most times not require complex techniques.
Email: Opening an email attachment from an unknown recipient as innocent as it may look may not be a good idea even where it seems to be from a known recipient, it just may be a spoofed email. For the helpdesk/customer service representative, however, it may be a necessary part of their job in the process of providing customer support. The attachment may be just an innocent screenshot documenting an order or transaction details which failed. However, there is every possibility that a malware is lurking in the attachment, and a social engineering attack is in progress.
In another job I had done in Ghana, access to one of the top level staff’s company email address simply required a spoof email from a supposed Project Manager handling a project for the company.
Bring Your Own Device (BYOD): Do you really want a ‘personal device on a private network linked to customers data’s? As a company, you may think of BYOD as a cost saving method but this is also dangerous as it leaves your organization vulnerable more especially where a malicious application has been written by threat actors to get into the network of an organization and spread over a local network with the customer service staff who brought his/her device to work as the main point of distribution. A classical medium through which ransomware could also spread if you ask me.
HOW TO PROTECT YOUR CUSTOMER SERVICE DESK FROM SUCH TYPE OF EXPLOITATION
These are not foolproof methods but an extra bit of carefulness would go a long way in securing data.
Adequate sensitization should be done on a regular basis. Letting help desk staffs know about the latest happenings in the world of Cybersecurity and how APT are being perpetrated by threat actors would go a long way.
Advising staffs against clicking unnecessary links and downloading of just about any attachments from customers and even fellow colleagues.
Sensitizing staffs about how they go about giving out just about any sort of information over a phone call from a supposed customer as this could be done by a person pretending to be an owner of an account they intend to attack.
As a Company Executive, the responsibility still falls on you as well to hire Cybersecurity firms, Pentesters and Ethical Hackers to conduct a regular Penetration Test on your organization in order to uncover vulnerabilities.
Make sure to make use of up to date versions of Softwares, Antivirus and a host of other applications which would see to the protection of your network and systems. Fake antivirus abound in the market created by Hackers as seen in the fake Amnesty International Antivirus so go for known and established brands.
When a staff is relieved of his/her job, endeavor to change passwords of any company related email that was controlled by the relieved staff as well as totally closing down of the email address. Employment of the doctrine of least privilege in your organization would go a long way.
Cybersecurity is important in the emergence of cyber attacks anybody can get hacked as long as there is a system, there is a vulnerability waiting to be exploited. All hands must be on deck to see to the protection of data of staffs and customers with the customer service desk being one of the channels requiring protection, attention and dedication towards a safer company.
With this I say, Happy Customer Service week!!!
This article was written by Sylvester Uduosa Esq. a Certified Ethical Hacker and founder of SLYTECH Entp. a Cybersecurity firm based in Nigeria which assists companies with Pentesting their networks and security with the sole aim of discovering vulnerabilities before criminals do and saving companies from losses that maybe incurred as a result of such vulnerability. https://slytech.org/2021/10/04/customer-service-desk-an-easy-access-for-hackers-to-exploit-your-organization/
|
Computers › British Payroll Firm Suffers Cyber-attack by danski(op): 11:53am On Oct 03, 2021 |
Contractors have been left unpaid after a “sophisticated” cyber-attack forced British payroll company shut down. This was confirmed on September 24 by Giant Group that it had taken its network and its fully integrated IT infrastructure, phone and email systems offline last Wednesday after detecting suspicious activity In a statement published on its website September 27, the company said: “We can confirm that Giant Group was the victim of a sophisticated cyber-attack on September 22nd. International law firm Crowell & Moring immediately put in place a team of experts in the US, UK and Brussels who have been carrying out necessary steps as part of the ongoing investigation. “Together, we continue to work with our insurers, the ICO and the NCA on the investigation, alongside a number of other specialist advisers and have been sharing updates as soon as we are advised that it is safe to do so.” Giant Screening was not affected, and the company said that its precision portals and Giant Finance+ services were now operational. This cyber-attack has however prevented an unspecified number of people from receiving their pay at a period when the UK is suffering from a panic buying-induced fuel shortage. “Although we had no portals to operate from, we managed to pay over 8,000 workers last week,” stated Giant Group. “We appreciate that not everyone would have received their expected payment and for that we are sincerely sorry. We are aiming to be able to process your payroll and pay you by Friday.” The company hasn’t stated whether any sensitive information was accessed by the threat actor(s) behind the attack but did confirm that “our databases are encrypted.” Announcements Giant Group made concerning the incident on Twitter have been greeted with angry comments. On September 25, @tiggy_ayoub tweeted: “Upset is hardly the word for what you are doing to us, Giant Group. No update today, no pay in my account, no food in my kitchen and no fuel in my car. Thanks to you, unable to go to work next week. Wow. Source: https://slytech.org/2021/09/29/british-payroll-firm-suffers-cyber-attack/
|
Science/Technology › A Current Flaw In Apple Pay Is Enabling Attackers Perform Unauthorized Contactle by danski(op): 11:17am On Oct 03, 2021 |
An unpatched flaw in Apple Pay has been disclosed by Cybersecurity researchers giving attackers the ability to make an unauthorized Visa payment with a locked iPhone via the Express Travel mode setup in the device’s wallet. All that is needed is the mobile phone to be on and also transactions could be relayed from an iPhone inside someone’s bag without the phone owners knowledge. No assistance whatsoever is needed from the merchant and backend fraud detection checks have not stopped any test payments made thus far by the researchers. Express Travel feature allows users of iPhone and Apple Watch to make quick contactless payments for pubblic transit without the need to unlock the phone, validate Face ID or a passcode. This is a classical example of a man-in-the-middle (MitM) replay and relay attack involving bypassing the lock screen to make payment to any EMV reader illicitly and this is possible due to a combination of flaws in both Apple Pay and Visa’s system however it does not impact Mastercard on Apple Pay or Visa cards on Samsung Pay. The success of this attack is hinged on imitating a transit gate transaction by using a Proxmark device that acts as an EMV card reader communicating with a victim’s iPhone and an NFC-enabled Android app that functions as a card emulator to relay signals to a payment terminal. Specifically, it takes advantage of a unique code — aka Magic Bytes — broadcast by the transit gates to unlock Apple Pay, resulting in a scenario whereby replaying the sequence of bytes, the Apple device is deceived into authorizing a rogue transaction as if it’s originated from the ticket barrier, when, in reality, it’s been triggered via a contactless payment terminal under the attacker’s control. The EMV reader is simultaneously tricked into believing that on-device user authentication has been performed thereby enabling payments of any amount to be made without the iPhone user’s knowledge. This vulnerability was made known to Apple and Visa in October 2020 and May 2021, respectively, the researchers said, adding, “both parties acknowledge the seriousness of the vulnerability, but have not come to an agreement on which party should implement a fix.” In a statement shared with the BBC, Visa said this type of attack was “impractical,” adding, “Variations of contactless fraud schemes have been studied in laboratory settings for more than a decade and have proven to be impractical to execute at scale in the real world.” Visa in a statement shared with BBC said this type of attack was “impractical”, adding, “Variations of contactless fraud schemes have been studied in laboratory settings more than a decade and it has been proven to be impractical to execute at scale in the real world.” “This is a concern with a Visa system but Visa does not believe this kind of fraud is likely to take place in the real world given the multiple layers of security in place,” an Apple spokesperson was quoted as saying to the U.K. national broadcaster. However reseachers at SLYTECH opine that there is no such thing as an impractical vulnerability as a vulnerability remains what it is i.e a flaw sitting in wait for the right threat actors to take huge advantage of and cause a greater damage. Source: https://slytech.org/2021/10/02/a-current-flaw-in-apple-pay-is-enabling-unauthorized-contactless-payments/
|
Sports › Re: Late Linegaard Strike & Penalty Drama As Man Utd Beat West Ham by danski: 8:37am On Sep 20, 2021 |
Tissaia: The referee is IPOB. probably share same corrupt DNA with IPOB. He denied 3 penalty to Man U and give west ham penalty but..... Still Man U won Even though am a man utd fan U r a dumb fuuuuu u dont have sense i swr Wetin IPOB do u Skull minners |