Viber came again under attack of Syrian Electronic Army



Viber’s Apple App store is again under cyber attack of Syrian Electronic Army. It is time to rethink for cyber world because hackers are in mood to debase credibility of cyber world. If we see in the past two weeks, we have seen many hackers debasing giant companies’ account and their development center like Instagram account, Apple’s Dev Center, and famous Viber app.

Viber is a cross platform VOIP (voice over internet protocol) was established for iPhone in Dec 2010. Viber features text, image, and video messaging around all platforms like iPhone, Android and Microsoft’s Windows Phone. At present Viber holds 30 languages and is now compatible with window and Apple PC.

Moreover, Viber is the latest example of such a malicious action performed by Syrian Electronic Army that attacked on Viber’s Apple App Store account by changing the description of Viber’s IOS app.

"We created this app to spy on you, Please Download IT”

According to 9to5Mac report hackers have taken responsibility of this attack and tried to reach to Viber authority for further clarification. Last week we noticed the attack on Viber done by the same authority called Syrian Electronic Army. It is assumed that hackers have also access to other developing functions that is indeed a serious issue for company and its customers as well. 9to5Mac’s Mark Gurman proposes the hackers could have reached access to Viber’s iTunes Connect account by a phishing fraud.

Viber authority persons gave statement in previous attack that no sensitive data was exposed and only two systems: a customer support panel and a support administration system were under attack. Below are two images of Viber spokesperson’s statement.
The two statements clearly states that the two statements are differed it seems Viber is not showing transparency to its customers. Viber was hacked on 23 July 2013 by Syrian Electronic Army intimated users to stay away from Viber. Viber has 200 million users globally.


We are facing duos situation in this cyber world as we see technology development and on other side emerging threat of hackers. A common person who relies on technology cannot understand the technical language of hackers instead rely on companies’ products by putting complete trust. Therefore, it clearly states that it is time to wake up from dream that no one seems to be secure in this unpredictable technology world, it is an alarm for the whole cyber world as you could be the next target of these culprits.
[Read More...]


Syrian Electronic Army attacked Viber - A free calling software



Viber is a free call and messaging service used for Apple and Android Platform suffered from Syrian Electronic Army’s hacking attack, yesterday on 23 July 2013 Syrian Electronic Army hacked support page and left the page with message that is shown in the below image.

Viber is a cross platform VOIP (voice over internet protocol) was launched for iPhone in Dec 2010. Viber involves text, image, and video messaging throughout all platforms iPhone, Android and Microsoft’s Windows Phone. It currently supports 30 languages and now available on window and Apple PC. Even hackers also disclosed some phone numbers, email addresses of Viber admin department and told that they have captured and downloaded some part of data backups. Viber support page now appears like this.
Hackers also said that they still possess control over the system and have deleted the page “https://wa.viber.com/csrapp/home.html”used for account management and hosted on address. Hackers have provided a screenshot that reveals phone numbers, UDID, IP address and registration details. It is really a serious damage caused to Viber. If we see the defaced webpage, all the numbers carry dialing code 963 that is of Syria.

Hackers also tweeted on Twitter “http://support.viber.com#SEA #SyrianElectronicArmy" that if you have Viber we advise you to uninstall it. Still there is no confirmation of this attack has been received from Viber’s authority persons, though Syrian Electronic Army has accepted the responsibility of this attack. Viber has more than 200 million users.

The news of Viber came out after Tango’s news revealed. Tango is also a messaging App whose data cybercriminals stole. It is guessed that attackers made some phishing page pretended to be Viber and succeed to get the username and password of admin staff then they able to use this information in hacking Viber. Viber said in report, the system breached was our CSR, used to help clients for any technical issues, the data stolen was basic, and they are working on it, and promising our clients that this will not happen again in future.

Syrian Electronic Army was previously succeeded in stealing data of True Caller and Tango app websites and deleted an article published in Daily Dot website and warned Daily Dot that if they publish any article in future, they will delete the whole website.

Cyber attacks are evolving day by day and have not even left giant social media and search engines; it causes serious concern over user’s data. It affects the credibility of a company. Phishing, man in middle attack, certificate breach, DDoS attacks are some recent attacks that have affected cyber world and forced giant corporate and social media to think over these attacks. It is a sure question arises in our mind “Do we live in hacker’s world or else hackers live in our world”.

Some sort of cyber policies should be there to fight against such hackers otherwise; the days are not far, where people avoid dealing with internet and social media.
[Read More...]


Symantec: SMBs gets benefits through Strategic IT



This info-graphics discloses about the Global SMB IT Confidence Index that was carried by ReRez in Feb-march 2013. Symantec declared this report which demonstrates the ratio of IT implementation and security prospective in top-tier and bottom-tier SMBs (Small and medium businesses).

The survey shows the attempts of SMB in matching the progressively technology-centric business world. The findings are as under. They reviewed 2452 SMBs across 20 countries includes Americas, Western Europe/the Middle East and the Asia Pacific region including 10 to 250 employees who are conducting company’s technology management. The reliability of this survey is about 95% with a 5% marginal difference.


Get SSL Certificate at lowest price from ClickSSL.com
[Read More...]


Protect your Organizations against Online Attacks



To get protection against online attacks and vulnerabilities online merchants must have SSL (secure socket layer) security, which is in interest of business and customers. Different types of attackers (serious hackers, computer beginners, or dissatisfied current or former employee) could induce a possible threat into organization’s information security. Many attackers take advantage of poor policy and procedure related to information security. Today with the help of internet, anyone can find the information regarding how to manipulate the system by exploiting security weakness on your online business. Attackers may also break security by applying automated tools to look into network systems, and exploits any known security weaknesses to get illegal access to the network.

Attacks and Threat Trend: Symantec has published “Threat Trend report 2013” in which some shocking facts have come out which is worth thinking for online industries. The facts are as below:

  • The average number of malicious website-blocked ratio is increased by 30% in 2012. There were 247,350 websites were in the list of blocked website in 2012 compared to 190370 websites in second half of 2011.
  • The number of malicious blocks ratio was 37% higher than its annual average.
  • The most exploited website categories and (percentage) of infected website are as below.
  • There are 7.7% websites were malicious was assorted in blogging category.
  • 43% compromised religion websites were infected with fraud antivirus attacks.
  • 28% compromised business sites were infected with fake antivirus attack.

What is Online Attack: Attack is a term where attacker plays role of a genuine verifier and changes the authentication channel to access the network authentication. There are different types of network attacks, which can bring disasters in network system.

We would like to share the latest security attacks and steps to protect your online business from such attacks.

Backdoor Attack:

Back door also called trap door. It is a part of program code, which is written into application without the awareness of the users and the administrator. It allows fast access to programmers to make easy debugging or monitoring the program. Backdoors typically allow programmers to make use of the software or hardware with the most important rights such as root or administrator. When programmer neglects to remove backdoor after debugging then, a backdoor becomes a serious trouble. Backdoors work mutely in the background and are tough to find out.

Steps against Backdoor: There are some tips to save your system against backdoor attacks.
  • You can run antivirus to close the backdoor attacks.
  • Turn your firewall protection to get alert of any backdoor attack.
  • Regular checks the entire program integrity.
  • Make rigorous control process and system development.

Brute Force:


Brute Force attack is used against encrypted data then using software to crack the code and gain right to use of USER ID and password. With user ID attacker gains access of privileges and can generate a backdoor for future approach. Brute-force attack includes tries multiple key combination to discover the right password that will unlock the encryption. The higher the encryption is the longer it will take time.

Steps against Backdoor: There are some tips to save your system against backdoor attacks.
  • Use strong encryption technology and effectual key management technology to protect User ID, password.
  • Periodically change your password
  • Run penetration testing to discover vulnerability.
  • Give enough education to customers and employees on security precautions.

Denial of Service(DOS):


Denial of Service is a disrupting attack which do not target network access but disturb the network traffic flow by injecting more information on the server than it can control. This kind of attack can be generated at single or multiple sources. Dos attack makes web resources unavailable for common users by flooding the URL with numerous requests.

Steps against DOS: Some tips which can help you to prevent DOS attack and save your system.
  • Tell Internet service provider to arrange traffic from authorized sources only.
  • Arrange sufficient backup and recovery arrangements.
  • Perform penetration testing for assessing the network ability.
In recent time, DDOS attack brings down the internet speed with enormous unnecessary request flaws or dummy traffic. DDOS attack was targeted at Spamhaus, a spam filter company that maintains filters email spammers. The DNS requests used in this attack was 300Gbps.

Hijacking Attack:


It is a network security attack that allows attacker to take control of an established connection during its running process. Hijacking attacks generally happen on a remote computer like personal computer. The attacker intercepts the message in a public key exchange and replaces his own public key for the requested message. Therefore, two original parties will appear for communication with each other like server to the client and the client to the server. Thus, attacker seems to be legitimate connection can interpret the message during the transmission.

Steps against Hijacking: Below are steps that can be put into practice for the system to save from hijacking.
  • Apply strong authentication methods like implementation of SSL security for sending sensitive data.
  • Apply firewall setting wherever it fits.
  • Monitor network traffic and use scanning tools.
  • Implement enough network security.
  • Get more.

Sniffers Attack:


Sniffer attack catches network packets it is also called network protocol analyzers that is also applied by hackers for hacking network. Hackers can capture network traffic if it is not encrypted. Once the packet is taken over then attacker can read the message of that particular packet. The message contains passwords, account information, or other confidential information, etc.

Steps against Sniffers: Below are steps that can be placed into practice for the system to save from sniffer attack.
  • Apply strong SSL security for sensitive sessions.
  • Regularly monitor network traffic and use scanning tools.
  • Apply enough network security.
  • Provide guidance to customers and employees about security precautions.

Spoofing Attack:


Spoofing attack means to do trick or betray network system. Spoofing allow attackers to hide their identity or communicate with a fake identity which pretend to be a legal identity. Therefore, network recognizes the unauthorized network as an authorized network. Attacker can easily gain access the sensitive data. Spoofing can be done through email spoofing, IP spoofing, fake identity.

Steps against Spoofing: Spoofing is a simple way to make others victim by making a fake username. To prevent from it user can take following steps.
  • Apply firewall setting wherever it fits.
  • Apply strong SSL security for sensitive sessions.
  • Regularly monitor network traffic and use scanning tools.

Man in the Middle Attack:

Man in the middle (MITM) attack also refers to bucket brigade attack in this case attacker sniffs the information transferring between the sender and the receiver like the server and the browser or between two servers. Such information is not encrypted. Attacker collects the information and intercepts it then sends it to the receiver.

Steps against MITM: Following are some useful steps to avoid MITM attack.
  • Download the latest version of high security web browsers.
  • Use Extended Validation (EV) certificate for the highest protection against MITM attack.
  • Use two-factor authentication for sensitive accounts.
  • Never respond unknown or spam emails.

Phishing Attack:

In Phishing attack, attacker personates to be a legal person or business through fraud emails or websites and illegally acquire sensitive information like username, passwords, credit card information, and bank account details. There should be SSL security (EV certificate) that can provide protection against phishing. Besides, user training and technical measures also need to be implemented.

From the above discussion about different online attacks, we can definitely understand that how much essential the SSL is not only from preventing online threats but also helps gain fame and trust from the visitors. It is therefore required to have a strong security called SSL protocol for your online business.

SSL - Secure bridge of Online information:

Now we can imagine that how online attacks have influenced online industries. In this situation, SSL (secure socket layer) can secure your entire website with robust security. SSL is an encrypted technology, enabling the server and the browser to transfer the information in a secure environment. SSL encrypts the information so the hacker could not identify it and user information will remain secure over the web. SSL uses public key and private key to encrypt and decrypt the information.

How SSL Works?: What comes out when a Web browser connects to an SSL secured Website?
  • The first step is that the browser attempts to connect to the website.
  • The browser demands the Web server to confirm whether the web site is equipped with SSL security or not.
  • The server of the site transmits a copy of the SSL certificate for the visitor's web browser confirmation.
  • The next step is confirmation of the SSL security certificate.
  • The browser assures that the certificate sent by the SSL web server is trustworthy.
  • If the certificate is legitimate, the browser transmits a message to the web server.
  • However, if it fails, the browser makes a warning and stimulates the user to authorize or deny the legitimacy of the web server certificate.

At the end, we can summaries that online attacks are expanding their horizon and it is sensible to have a strong network security to prevent online attacks. In this case, SSL stands alone in security criteria that have utmost protection for described online attacks. It allows a secure bridge in which the sender and the receiver can transmit data in a secure environment.
[Read More...]


9 Reasons to Choose ClickSSL



1. Important of Consumer Convenience
ClickSSL provides quick and easy to obtain an SSL certificates. Before consumers enter credit card or sensitive personal information online they want to confirm that they are on the intended site and that their information is protected. Our SSL Certificates are trusted and secure. We help you protect sensitive information during transmission when your customers, business partners, and employees connect with you online.
2. Best Products – Lowest Price : Price Match Guarantee
Our SSL Certificates prices are cheap but products are best in SSL Industries. Our SSL Certificate supports 99+ % of all browsers and most mobile browsers and enable up to 256-bit encryption. We proudly guarantee the lowest pricing of all our brand SSL certificates. We always want you buy and renew SSL Certificates from us only. We guarantee lowest pricing and clock around quality support services what make us choice of smart buyers like you
3. One Stop Solution for Renew SSL Certificates
We offer you to renew your existing SSL Certificate at the lowest price in the market place. This would help securing your website online transactions at low price. We will bring continuity of cost effective internet security solutions to you. We offer an exclusive discount of Renew SSL Certificates. It makes renewal very easy and fast. You can get many benefits when you renew your SSL Certificate from the site. You will get 90 days extra validity on regular renewals or earlier renewals. You can also get special discounts for multiyear renewals from this site. This is about to give more discount to the customer and make them safe from internet fraud.
4. Get Free "SSL Secured Site Seal"
The “secured site seal” helps to establish your online authenticity by showing your visitors that your site has verified by most trusted Certificate Authorities on the Internet. When visitors to your web site see the “secured site seal”, they feel more confident to complete their online business and you will notice a marked reduction in abandonment rates and boost your online business.
5. Delivered by Leading Certificate Authorities
ClickSSL is Platinum Partner Company of RapidSSL, Thawte, GeoTust and VeriSign. We authorized to resell and renew all SSL Certificates. We offers highly secured and widely trusted SSL certificates at lowest price to support ecommerce security.
6. Broad range of online security products
ClickSSL has broad range of SSL products like Domain Validation SSL, Business Validation SSL, Wildcard SSL, EV SSL, SAN SSL, SGC- enable SSL Certificate and Code Signing Certificates.

7. 24x7 technical and sales supports
When you need help to setting up, managing and renewing your SSL Certificate. Our security experts give you easy and straightforward solution. Our professional administrator always analyses on ecommerce security. ClickSSL has helps companies and organizations of every size around the globe secure their e-commerce and Internet communications. A leader in Internet security solutions, ClickSSL offers affordable SSL Certificates, 24 x 7 support and advanced e-commerce products that are easy to use.
8. Get FREE Warranty
We importance our consumers, so we have guaranteed to offer SSL Certificates that include a warranty in the happening an SSL Certificate is mis-issued. The warranties range from $5,000 to $1,500,000 on all of our SSL Certificates, correct warranty information offered by all Certificate Authorities is available here.
9. Money-back guarantee
Our main goal is provide excellent consumers service, here at we are looking for completely clients satisfaction. We offer 100% refund of order amount on any SSL certificate purchase up on order cancellation request. If you are not satisfied, you can easily get your money back without any question.

[Read More...]


SGC SSL Certificate: Enabling Strong Encryption for the Most Site Visitors




If your reputation in the online community depends upon the stringent safeguarding of information processed through your Web site, then your Internet security solution should include the strongest encryption available to each Web site visitor.
Encryption is the process whereby data is transformed into a code that will be indecipherable to an unauthorized viewer. The stronger the encryption, the more difficult it is for someone to eavesdrop on your online communications. This is especially important if you accept any kind of online payments, connect to a bank or brokerage account, transmit health records, must meet a governmental or other regulatory organization’s privacy and security standards, or process any kind of potentially sensitive information.

Industry experts recommend a minimum of 128-bit encryption be used for all secure online sessions. Some Web server-client browser configurations enable sessions with up to 256-bit encryption protection, the strongest level of encryption commercially available today.
The strength of encryption enabled for any session depends on what your customer’s browser and operating system support, as well as what your host server systems will support. If your consumer’s browser or operating system does not support higher levels of encryption, the session will default down to the highest level that it can support.
Regular 128-256 bit SSL Certificates intended for securing leading sites over usual browsers, where SGC SSL Certificates upgrade the encryption capabilities of older browsers from 40-bit encryption into full 128- or 256-bit encryption.
Server Gated Cryptography (SGC) enabled SSL Certificates upgrade the encryption capabilities of older browsers from 40-bit encryption into full 128/256 bit encryption – ensuring your website protects and is trusted by the highest number of internet users possible.
With SGC SSL Certificate, encryption levels are controlled by the server and not dependent on the client system. Once these original export restrictions were lifted, SGC-enabled SSL Certificates are now issued to all types of Web sites, not just authorized financial institutions.
VeriSign offers market-leading SGC-enabled SSL Certificates so virtually every visitor to your Web site will be protected by the industry recommended minimum of 128-bit encryption.
[Read More...]


Installation Guideline: SSL Certificates on Tomcat Server



SSL – Secure Socket Layer is a security Protocol. SSL Certificate is a digital signature. SSL Certificate is also known as Public Key Identity certificate. SSL is a protocol for securing communication between a web browser, and web server. Whenever you access a web server using https, the page you are sent is encrypted, and any information you send to that server is also encrypted
  • Install Root CA Certificate
1) Download your SSL Certificates from SSL Certificate Authorities like RapidSSL, Thawte, GeoTrust or VeriSign. 
2) Use the Primary and Secondary Intermediate CA contents into a text file. (Use a text editor - Notepad or Vi.)
3) Primary Intermediate CA (file name as primary_inter.cer)
4) Use the below control  to import this Certificate in the keystore:
keytool -import -trustcacerts -alias primaryIntermediate -keystore (your_keystore_filename) -file primary_inter.cer
5) For the Secondary Intermediate CA, (file name as secondary_inter.cer)
6) Use the below control  to import this Certificate in the keystore:

keytool -import -trustcacerts -alias primaryIntermediate -keystore (your_keystore_filename) -file primary_inter.cer
  • Install the SSL Certificate
SSL CA email your Certificate. Use an attachment file(Cert.cer). Copy and paste it into a text file.
Use the below control  to import your SSL Certificate:
keytool -import -alias -keystore (your_keystore_filename) -trustcacerts -file (your_certificate_filename)
  • configure the SSL in Tomcat with server.xml
1) Close the Tomcat Server, when it is running. While it is started, Changes to the file /conf/server.xml are read by Tomcat Server.
2) Open the file < NPJBMK _HOME>/conf/server.xml in a text editor.
3) Detect the following section of code in the file. Remove comment tags around the Connector entry. The comment tags that are to be removed are shown below.
4) Save and restart Tomcat server


About ClickSSL:

ClickSSL.com is SSL Certificates Reseller and the platinum partner of Leading Certificates Authorities such as VeriSign, GeoTrust, Thawte and RapidSSL. Buy or Renew Wildcard SSL, EV SSL, Multi-Domain SSL Certificates and many more from ClickSSL at Cheapest Prices in the Industry.

Why ClickSSL? We offer internet business owners to buy or renew SSL Certificates for their internet based business at very low cost. Why We Sell Cheap SSL Certificates? We buy bunch SSL Certificates from leading authorities and pass discounts to internet business owners. For more information visit ClickSSL.com
[Read More...]


SSL - Single Root Vs Chained Root



SSL certificates are basically two types.
  1. Single Root Level SSL Certificate
  2. Chain Root SSL Certificate

When connecting to a web server over SSL, the visitor's browser decides whether or not to trust the website's SSL certificate based on which SSL Certification Authority has issued the SSL certificate. To determine this, the browser looks at its list of trusted issuing authorities - represented by a collection of Trusted Root CA certificates added into the browser by the browser vendor (such as Microsoft, Linux, UNIX, Sun and Netscape, Mozilla, Safari).

Where is this list of CA in your computer?

When browsers and operating systems are developed / installed, most CA Root certificates will be installed. As all Root CA are required to authenticate SSL certificate on any website. When you browse any website on HTTPS://, browser will automatically identify Root Certificate as defined earlier. If browser fails to identify CS then there would be an error message.

Most SSL certificates are issued by CAs who own and use their own Trusted Root CA certificates, such as those issued by VeriSign, RapidSSL, Thawte, and GeoTrust. As all of these are known to browser vendors as a trusted issuing authority, its Trusted Root CA certificate has already been added to all popular browsers like Internet Explore (IE 4.0, 5.0, 6.0, 7.0, 8.0), Mozilla Firefox, Safari, Netscape and hence is already trusted. These SSL certificates are known as "single root" SSL certificates. RapidSSL and GeoTrust own the Equifax root used to issue its certificates. As well VeriSign and Thawte have own Root to issue SSL certificates.

What is Chained Root SSL Certificate?

Some Certification Authorities do not have a Trusted Root CA certificate present in browsers, or do not use the root they do own. In place they use a "chained root" in order for their SSL certificates to be trusted - essentially a CA with a Trusted Root CA certificate issues a "chained" certificate which "inherits" the browser recognition of the Trusted Root CA. These SSL certificates are known as "chained root" SSL certificates. However chained root certificates installation is more complex and some web servers and applications are not compatible with chained root certificates. Chained root certificates require additional effort to install as the web server must also have the chained root installed. This is not necessary for single root certificates.

For a Certification Authority to have and use its own Trusted Root CA certificate already present in browsers is a clear sign that they are long-time, stable and credible organizations who have long term relationships with the browser for the inclusion of their Trusted Root CA certificates. For this reason, such CAs are seen as being considerably more credible and stable than chained root certificate providers who do not have a direct relationship with the browser vendors, or do not use their own root certificates to issue SSL certificates.

ClickSSL.com provides only Single Root SSL Certificates.
[Read More...]


What is ClickSSL Reseller Program?




What is CLICKSSL Reseller Program?
  • CLICKSSL Reseller program is specially developed for online SSL certificate reselling.
Is this Reseller Program Free?
  • Yes - ClickSSL offers FREE reseller program.
  • Reseller account and API - 100% FREE.
  • No upfront payments. Only Pay As you Buy.
What are Reseller account benefits?
  • Reseller Account is FREE!
  • Reseller will be offered discounted price than regular price.
Who can register for SSL reseller program?
  • Companies who having business domain in SSL certificate selling, website hosting, website development, website designing, domain registration provider and all type of IT services.
My business does not belong from any of above domain; shall I enroll for Reseller Account?
  • Yes – You can enroll for FREE SSL Reseller Account. You will get $0 set up reseller account.
[Read More...]


 
Return to top of page ClickSSL - Start your E-Business with SSL Certificates