Skip to main content

Posts

Showing posts with the label security

Self Signed SSL Certificates

Ever wondered how to enable SSL or HTTPS on your site? If you dont want to pay for commercial SSL certificates, you could create self signed certificates for your site by following the instructions here: https://www.digitalocean.com/community/articles/how-to-create-a-ssl-certificate-on-apache-for-ubuntu-12-04 The instructions in the site above will make your default site HTTPS enabled. If you prefer having a commercial SSL, save your certificate files and key files in your server and edit the location on the /etc/apache2/sites-enabled/default to point to the directory where you stored those files.

One of the Oldest Phishing Tricks

I got surprised when I saw this email. I didn't know that these tricks were still being used. Its a dangerous world out there people, be careful! One of the oldest phishing trick.

Credit Card Phone Policies, Social Engineering and You

I called my credit card company earlier this evening to either have my credit card discontinued or have my annual fee waived. Due to the problems I had with that company, it was not really my loss if they didn't waive my annual fee. Everything went smoothly and as the transaction completed, got home, started browsing, I came across this very nice article about cyber security (ironically) courtesy of Microsoft and (more ironically) released for free. 12.3MB downloadable here . Then I thought, I think there's a bit of a security hole in those companies policies. I remember Kevin Mitnick and his book, The Art of Deception. You see, banks asks about details which identity thieves could easily obtain. Take for example, I was asked for my credit card number and my full name. Credit card numbers could be easily listed down by some employee of a merchant you bought some goods on, so is your full name (its on the card Sherlock). Even that 3 digit CVV2 code behind the card. So make...

SMS and Social Networks

For several months, ive been looking for a secure way of updating my status messages through SMS. Though there has been several options, ive considered their approach to be significantly flawed. As my friend started posting his updates through sms, I checked the website on how they go about updating your status. I find it very alarming and perhaps, its a good time to share my thoughts as an IT professional. I. Existing Services and Their Flaws Ok, first in my list is the one recently subscribed to by my friend. @tweetitow ( http://tweetitow.com ) Ive looked at how I could subscribe and guess what welcomed me: I already have a twitter account. Now, how can I register to @tweetitow? Simply text/send from your mobile phone your twitter username and password in this following format: REG tweetitow veryverysecret to following gateway numbers: Globe/TM users: 09273389183 Smart/TNT users: 0918-419-4904 Sun users: 0923-986-0673 Text your password? When they get your password ...