Category: Application Development

  • To be RFC 3986 or not to be RFC 3986

    Heard that new discovered phishing technique can fool tech-savvy people. The bad guy conducted a technique so called white space in URL in cyber space. The objective is mislead the computer users includes savvy technical persons. But we are not going to focus how was hackers use phishing email compromise victim workstation in this article.…

  • Descendant of VSAM File Organization,that is blockchain technology today

    Old school boy might remember fundamental of Virtual storage access method (VSAM). I object, banking and financial institution are close with VSAM technologies day to day. Yes, they are using mainframe computer. For instance IBM S390. People discontentment of proprietary payment solution (SWIFT) sounds high! Hackers targeted payment system via the SWIFT, no significant figures…

  • Do you think 64 bit OS can secure critical facilities in your country?

    Few years ago, heard that 64 bit version of windows is more secure. Expert was told, 64-bit operating systems aren’t immune to malware but security features are stronger. Address Space Layout Randomization – incorrect guess may result in the program crashing Mandatory Driver Signing – prevents unsigned drivers provided by malware from running on the…

  • Next Generation C&C – Google docs

    Malware C&C server looks exposed to security vendor for a period of time. Hacker have difficulties to implant malware to workstations once malware detector install (layer 3) network backbone routing area. Sure that Hacker won’t be announced defeat then such a way disappear forever. A smart way utilize cloud resources We understand that cloud computing…

  • Android mobile phone user alert! AdUps software,he is a voyeur!

    Technical writer (Miss Swati Khandelwal) write a technical article alerts Android users around the world they are under cyber attack. What’s going on? It seems that a suspicious software bundle with mobile phone (ZTE and Huawei) together export to US market. The goal is going to collect the mobile phone data. The data includes SMS…

  • CVE-2016-7255 – Google Chrome is the Instigator

    IT world encounters Storm in a tea cup from weekly. Heard that Microsoft blame Google mistaken on their web browser (chrome) design mistake causes vulnerability occurs (CVE-2016-7255). On hand information described that hacker would like to find back door in web browser (Google chrome), they found a privileges escalation at the end. It looks that…

  • Is Single Sign on a Security Risk?

    Is Single Sign on a Security Risk? The majority of computer operators and people alike maintained one user ID and password. The single sign on facility fulfill their operation requirements. From security point of view, there are inherent risks for company deploys single sign-on function on their network infrastructure. Single sign on infrastructure Let take a…

  • Android bad luck this year! Do you think iPhone is Invulnerability?

    Keep heard that vulnerability found on Android phone recently. For instance Dirty Cow attack, Drammer attack and Dangerous Pork Explosion backdoor. Do you think Linux operating system not secure anymore? As far as I remember vulnerabilities found on Apple IOS not less than Android operation system. Can you imagine in what circumstance, XNU (X is…

  • Part 1:Blockchain technology situation – A Tales of Two Cities

      Quotes from A Tales of Two Cities – “It was the best of times, it was the worst of times,.. Charles Dicken Read the fiction from my view point looks boring, however a famous quotes written by Charles Dicken can correctly describe the current situation of Blockchain technology. It was the best of the…

  • The 2nd stricken region of cyber attack vector – Embedded malicious code applies to everywhere causes memory overflow

    Headline news alert that malware embedded to picture file boil up hijack storm to android world. Sound horrible! No need involve phishing technique lure victim engage click url action and such a way compromise your android phone. No safe world! The vulnerability (CVE-2016-3862) fix immediately. Resolution is that enforce IPC Router to check if the…