Tuesday, April 23, 2019

Implementing Oracle WebCenter in Amazon Web Services (AWS)


Implementing Oracle Web Center in Amazon Web Services (AWS)
Oracle WebCenter is the center of engagement for business. It is a suite of tools (WebCenter Portal, Content, and Sites) that helps people work together more efficiently through contextual collaboration tools that optimize connections between people, information, and applications and ensures users have access to the right information in the context of the business process in which they are engaged. Oracle Tech can implement this amazing platform in AWS, one of the most popular and full-featured cloud website hosting solutions available. Through AWS, Oracle Tech can provide businesses, non-profits, and governmental organizations with a flexible, highly scalable, and low-cost way to deliver their WebCenter-based web applications.

We use Amazon Virtual Private Cloud (Amazon VPC) to host WebCenter as a suite of multi-tier web applications. Amazon VPC allows us to strictly enforce access and security restrictions between the front-end OHS tier webservers, the WebLogic application tier servers, and Oracle database data tier servers. OHS webservers are launched in a publicly accessible subnet while WebLogic application servers and databases are launched in non-publically accessible subnets. The application servers and databases can’t be directly accessed from the Internet, but they can still access the Internet via a NAT instance for maintenance purposes. Access between the servers and subnets is controlled using inbound and outbound packet filtering provided by network access control lists and security groups.



Most Hacked Passwords – Top 100,000 Common Passwords that Already Known to Hackers

most Hacked Passwords

Password plays a vital role in securing your account, a common password is easy to remember, but it will be easier for an attacker to guess the password. An analysis of most Hacked Passwords showing still people is using weak passwords.
Based on the UK’s National Cyber Security Centre breach analysis, the password ‘123456’ has been found 23 million times in the breaches. Next to that 123456789 found 7 million times.
Passwords like ashley, michael, qwerty and 1111111 are the most commonly used passwords by users for multiple accounts. The survey shows more than 70% always use PINs and passwords for smartphones and tablets.
If you have a weak password then it is a cake walk for hackers, they can gain access to your account easily by using brute force techniques.
The most terrible passwords used are “123456” and “password”, they continue to hold the #1 and #2 spots, respectively.
A strong password should have at least six characters that include a combination of upper and lowercase letters, symbols and numbers.
NCSC released the most hacked passwords list, in collaboration with Troy Hunt’s Have I Been Pwned data set. Here is the list of top 100,000 passwords that already known by hackers.
If you find your password in the list it is recommended to change the passwords immediately. The list obtained from “global breaches that are already in the public domain having been sold or shared by hackers,” 
“Using hard-to-guess passwords is a strong first step and we recommend combining three random but memorable words. Be creative and use words memorable to you, so people can’t guess your password,” Dr. Ian Levy, NCSC Technical Director, said.
“Given the growing global threat from cyber attacks, these findings underline the importance of using strong passwords at home and at work,” David Lidington, Chancellor of the Duchy of Lancaster and Minister for the Cabinet Office, said.

Tips to Stay Safe

  • Use a complex password, enforce strong password policy.
  • Check the password regularly, Use two-factor authentication(2FA) for vital sites like managing an account and Emails, make sure all the passwords are unique.
  • Change the Manufactures default Password that gadgets are issued before they are conveyed to the IT Department.
  • Configure using password Manager only for your less important websites and accounts.

Introduction to Hacking Wireless Networks


Introduction to Hacking Wireless Networks    
Wireless networks come with excellent advantages- connectivity beyond walls, wireless connection, easy to access internet even in areas where laying cables is difficult, speed and sharing. But, wireless networks have a few disadvantages, the major issue being- the questionable security.

Important Terms:
Access Point: The point where the mobile device, computers connect to the wireless network.
SSID: Service Set Identifier identifies the access point, it is a human-readable text which when broadcasted leads to the identification of an access point. 
BSSID: Mac address of the Access point.
Bandwidth: Amount of information that can be transferred over the connection.
There are various standards for wireless transmission:

Authentication:
Open Authentication:

When a client wants to connect to an open access point he/she sends a probe request, and the AP sends a probe response; the client then sends an authentication request. Upon receiving a response, the client establishes an association with the AP.
Shared Key Authentication Process:
Here, the client sends a probe request, and the access point sends the probe response; then, the client requests for an authentication request, the AP sends an authentication challenge to the client. The client needs to send the shared key as authentication challenge response. AP, then, verifies the client and authenticates him/her, who then establishes a connection with the access point.

Centralised Authentication:
In the corporate environment, instead of an Access point verifying client’s authentication details, a centralised server does the job of verifying the client. RADIUS is a centralised authentication server which verifies clients who want to connect with the access point.



Debunking the Discourse Around Cloud Security

Image result for Debunking the Discourse Around Cloud Security

ive through the recent Cloud Industry Forum (CIF) research and you’ll see that cloud spending has finally overtaken on-premise security spending, and this gap is expected to widen significantly over the next three years, according to the findings.
The research found that nine in ten UK businesses have formally adopted at least one cloud-based service into their IT estates, and combined with the fact that 82% of UK businesses believe that cloud is the key enabler of their organizations, this points to a future that is increasingly dominated by cloud-based services.
The widespread embrace of the cloud has brought with it ample benefits when it comes to collaboration and communication. It has provided new and flexible ways of working which have been found to greatly drive productivity and efficiency in a way that’s never been done before. It’s safe to say that it's definitely here to stay! 
While this research certainly suggests that things are moving in the right direction when it comes to the cloud, people’s opinions aren’t quite painting the same rosy picture. There still seems to be a widespread discourse surrounding safety concerns when it comes to storing data, apps and workloads in the cloud. 
The apprehension with which cloud safety is met is nothing short of ironic given the fact that in many ways, the cloud is actually more secure than on-premise, largely due to cloud providers collectively investing more into security controls than businesses can on their own. Take AWS for example. Its infrastructure hasn't been hacked in years, which is very good going, especially considering attackers are constantly targeting its infrastructure.

High-profile cases, such as the NSA data leak in 2017, which saw over 100GB of sensitive, classified data exposed, are seemingly adding validation to people’s fears. In this example, a hard drive was discovered on an unprotected public Amazon S3 server.
Although the leak came from shoddy security practices rather than a fault of the cloud provider, stories like this add fuel to the fire that ‘the cloud is not safe’.
While the lack of education around cloud protocol and safety is fairly widespread, it also seems to extend to CIOs and IT leaders. Rather worryingly, in our own research back in 2018, we found that over half (57%) of respondents falsely believed their on-premise security was superior to anything cloud security could offer. Now, I’m not saying that cloud is always the most secure option, but using a combination of the right technology, training and processes, the cloud has the potential to be even more secure.
We wanted to lift the lid on these misconceptions, so last year we conducted some global research. As part of this, we asked 164 respondents in EMEA about their experiences and attitudes when it comes to cloud security. We found that as well as an obvious lack of education, many still didn’t trust the cloud - at least not as much as the on-premise security architectures they’ve become accustomed to. 
Also, 82% admitted to having concerns when it came to deploying firewalls in the cloud, citing inappropriate pricing and licensing (41%) and a lack of centralized management creating a significant overhead (39%) as their primary concerns according to our own findings. Other responses raised concerns around next generation firewalls simply not being practical for cloud environments.
So what’s the key to cloud security? First things first, choose established public cloud players that you can rely on. They often have the resources and expertise to protect their own infrastructure. However, in terms of education, what we need is a complete paradigm shift when it comes to cloud safety, the key to which lies in understanding the shared responsibility model.
The shared responsibility model is universal among cloud providers: they ensure their infrastructure will be secure, but customers need to ensure whatever they do in the cloud is secure. In other words, both the cloud provider and the customers share the responsibility of security. 
So in practical terms, it means that in that the 2017 NSA data leak could have been entirely avoided if the shared security model had been used. The attack was solely based upon users not securing the data on the Amazon S3 server, rather than a result of Amazon S3’s security itself. Had the correct user procedures been taken, this highly sensitive and classified information would never have been exposed. 
There’s also a lot to be said for using technology that was built with the cloud in mind, rather than an on-premise solution that has retrospectively been forced to operate in a limited fashion, in an environment that it wasn’t purpose-built for. The cloud is a different beast, with many different ways of operating compared to on-premise environments. While some traditional solutions can be shoehorned into the cloud, security isn’t one of them.
Organizations need to eradicate the dangerous understanding that cloud vendors are solely responsible for their cloud security. Those organizations who are using cloud vendors, but not holding up their end of the bargain - knowingly or unknowingly - are leaving the floodgates open for all kinds of attacks. Users of Azure can sleep easy in the knowledge that their cloud infrastructure is secure from such attacks, but it’s useless if the very data, workloads and applications they’re moving in and out of their cloud environment are undefended to begin with. 
To summarize, as long as you uphold your part of the shared responsibility model, use large established cloud companies that you can rely on and look for cloud-native solutions, you can go to sleep safe in the knowledge that your cloud data, apps and workloads are secure. While the future might be cloud, it will only be cloud if we all learn to use it securely.

Monday, April 22, 2019

About Excel and Powerpoint


2. Microsoft Excel: – Microsoft Excel is my favorite application in Microsoft Office suite that anyone can use to perform daily life and business calculation by using logical and mathematical formulas in the spreadsheet. It’s a complete financial management application used by millions of people online and offline. It is very well used in data and information analytics by using filters, conditional formatting, and goal seek and pre-defined templates etc. It is also used to visualize data and information in charts, smart arts, pivot table and much more.


3. Microsoft PowerPoint: – PowerPoint another application of Microsoft packaged with Microsoft Office suite to create presentations using slides to present data and information in meetings, seminars. It means you can use PowerPoint to create project presentation, business plan presentation, school assignments and presentation for seminars etc.

Sunday, April 21, 2019

ITIL Problem Management – 2

Problem Management is an absolute requirement for any company interested in reducing the number of incidents occurring in their environment and help us in minimizing the impact of Incidents that cannot be prevented. Problem Management is responsible for managing the lifecycle of all problems.
 
An example
 
Say your laptop battery is not working properly & your laptop isn’t working without any battery backup. This is an incident because it disrupted the service- working on something. You fix it by keeping it connected with the charger for the time that you are working. This way you are able to work on your laptop & the incident is closed. But now, you have a problem- you always have to keep the laptop connected to charger if you intend to work.
 
To fix the problem, you need to change the battery of laptop.
 
Normally, an incident needs to be fixed within a specific timeline. Problems can be left indefinitely until an incident happens.
 
 
Do nothing - if the business is not affected by problem, or if benefits are less than the cost of fixing problem.
To deploy work around if determination of root cause exceeds the benefits.
Determine root cause and fix problem if the benefit is worth fixing.
 
How problem management works:
 
In Problem management, we use analysis techniques to identify the cause of the problem. For Incident management, we find the cure: Restoration of service. Thus, Problem management takes longer and should be done once the urgency of the incident has been dealt with: for example, removing a faulty office laptop and replacing it with a working spare laptop by IT Helpdesk, takes the urgency away and leaves the faulty laptop ready for repair.
 
Problem management can take time but within limits to lessen the cost of resolution.
 
Process workflow: The following is the standard problem management process flow outlined in ITIL Service Operation but represented as a swim lane chart with associated roles within OSF ISD.
 
 
 
Role of Problem Management Review Team: 
 
Problem logging:
 
Problem logging is critical as all the necessary information from the incidents has to be captured while creating the problem. Problems should be created from the Incidents, maintaining the link to the incident(s). Before creating of a new problem, search for similar existing problems to avoid duplication.
 
Categorization
 
Problem categorization is essential to avoid ambiguities and makes it simpler to search incidents and associated problem records.
 
Prioritization
 
Prioritization helps in identifying critical problems that need to be addressed. Impact and urgency associated with a problem decides which problems need to be addressed first. When a problem is created from an incident, the impact, urgency and priority values get assigned from it automatically and reduce the task of prioritizing the problem for technical staff.
 
 
Problem detection: Trend analysis is a proactive approach to problem management by which one can avoid the occurrence of the problem beforehand.
 
Investigation and diagnosis
 
Problem investigation gets to the root cause of the problem and initiates actions to resume the failed service. Analysis of impact, root cause and symptoms of the problem provide a resolution.
 
Workarounds 
 
If it’s possible to find a workaround to the incidents caused by the problem, a temporary way of overcoming the difficulties, it is important that the problem record remains open and details of the workaround are always documented within the Problem Record.
 
Raising a Known Error Record 
 
As soon as the diagnosis has progressed enough to know what the problem is even though the cause may not yet be identified, a Known Error Record must be raised and placed in the Known Error Database – so that if further incidents arise, they can be identified and related to the problem record.
 
As soon as a solution has been found and sufficiently tested, it should be fully documented and prepared for implementation.
 
Problem Management Review Team / Change Management / Solution Provider Group: Changes to production to implement the solution need to be scheduled and approved through the Change Management process.
 
Problem Management Review Team
 
When any change has been completed (and successfully reviewed), and the resolution been applied, the Problem Record should be formally closed – as should any related Incident Records that are still open. A check should be performed at this time to ensure that the record contains a full historical description of all events – and if not, the record should be updated.
 
The status of any related Known Error Record should be updated to shown that the resolution has been applied.

Popular Video Editing Software Website Hacked to Spread Banking Trojan

Image result for Popular Video Editing Software Website Hacked to Spread Banking Trojan

If you have downloaded the VSDC multimedia editing software between late February to late March this year, there are high chances that your computer has been infected with a banking trojan and an information stealer.

The official website of the VSDC software — one of the most popular, free video editing and converting app with over 1.3 million monthly visitors — was hacked, unfortunately once again.

According to a new report Dr. Web published today and shared with The Hacker News, hackers hijacked the VSDC website and replaced its software download links leading to malware versions, tricking visitors into installing dangerous Win32.Bolik.2 banking trojan and KPOT stealer.Even more ironic is that despite being so popular among the multimedia editors, the VSDC website is running and offering software downloads over an insecure HTTP connection.


Though it's unclear how hackers this time managed to hijack the website, researchers revealed that the breach was reportedly never intended to infect all users, unlike last year attack.

Instead, Dr.Web researchers found a malicious JavaScript code on the VSDC website that was designed to check visitor's geolocation and replace download links only for visitors from the UK, USA, Canada, and Australia.

Insecure VSDC Website Was Distributing Malware for a Month


The malicious code planted on the website went unnoticed for almost a month—between 21 February 2019 and 23 March 2019—until researcher discovered it and notified VSDC developers of the threat.
Targeted users were served with a dangerous banking trojan designed to perform "web injections, traffic intercepts, key-logging and stealing information from different bank-client systems."

Image result for Insecure VSDC Website Was Distributing Malware for a Month

Moreover, the attackers changed the Win32.Bolik.2 trojan to KPOT Stealer, a variant of Trojan.PWS.Stealer, on March 22, which steals information from web browsers, Microsoft accounts, several messenger services and some other programs.
According to the researchers, at least 565 visitors downloaded VSDC software infected with the banking trojan, while 83 users has had their systems infected with the information stealer.

VSDC site has been hacked several times in the past years. Just last year, unknown hackers managed to gain administrative access to its website and replaced the download links, eventually its visitors' computers with the AZORult Stealer, X-Key Keylogger and the DarkVNC backdoor.

What to Do If You're a Victim?


It should be noted that just installing the clean version of the software update over the malicious package would not remove the malware code from the infected systems.

So, in case you had downloaded the software between that period, you should immediately install antivirus software, with the latest up-to-date definitions, and scan your system for malware.

Beside this, affected users are also recommended to change their passwords for important social media and banking websites after cleaning the systems or from a separate device.

Friday, April 19, 2019

ITIL, PRINCE2 or PMP: Which is Right for You?

Image result for ITIL, PRINCE2 or PMP: Which is Right for You?
Three well known certifications available for professionals across the world are PRINCE2ITIL and PMP. These methodologies have gained immense reputation due to their contribution and usefulness in any business environment.
PRINCE2: Abbreviated for PRojects IN Controlled Environments, it is a process-based methodology that provides step-by-step and detailed procedures for delivering a successful project. It offers clear instructions and steps and templates for the users to follow, so that the success of the project becomes inevitable. This certification is recognized and valued all over the world for its imperative design of managing projects and improving upon their performance metrics. Having quite a presence in the European, Australian and other Northern American markets, the popularity of PRINCE2 can be validated through the increasing number of people opting for the same.
More than 1 million PRINCE2 examinations have been taken around the world and this figure is expected to grow across coming years. This certification serves to be a right choice if you are new to the field of project management and wish to grow professionally with the same. It would also be helpful for veterans desirous of improving their project’s performance metrics significantly. The course has three levels - Foundation, Practitioner and Professional. 
ITIL: It stands for Information Technology Infrastructure Library and is the most recognized framework for any IT service management in the world. It is process based and enables an organization to improve and manage IT services within the organizational system. This certification teaches aspirants to bring about enhancements in the effectiveness, quality and efficiency of a project. It is globally accepted and helps you in identifying various promising opportunities within the realm of IT services. ITIL would be the right certification if you are from the IT sector or want to focus mainly on the projects that focus on IT services. Foundation, Intermediate, Managing across the Lifecycle (MALC), Expert and Master are the different levels of ITIL certification.
PMP:This project management practice is based on the principles set by the Project Management Institute. This certification is predominant in the US and is valued worldwide. It is split into different expertise levels and is one of the most reputed project management practices. This option provides you with a number of tools and techniques to deliver successful projects. It focuses more on the skills and knowledge required for the effective management of projects. This is a right option for you if you are looking towards honing your skills, rather than learning about the framework of managing projects.
Based on the level of expertise that you are aiming for and the market you work in, any of the three certifications can be chosen. However, a combination of two of three of them can also help greatly. They not only focus on the management basics but also bring about significant improvements in a project’s performance.
Taking up PRINCE2 and PMP would help you learn about the framework and gain knowledge on the different skills required throughout the project’s lifecycle. Combining either of them with ITIL will give you an understanding of how to approach projects pertaining to IT services. If you think a combination of two would be ideal for your career graph, then opt for the same.

Reg:Difference Between Python and Java

Q1. What are the differences between Python and Java?
 

 

 

Python Vs Java
Comparison Python Java
Performance Speed Fast Not as much as Python
Indentation Must be followed Using proper flower braces is enough
Typing Dynamically typed Static typed
Accessability Simple and compact Not as much as Python
Platforms Not compatible to many Platform independent
Database Access Weak compared to JAVA Strong (JDBC)

Thursday, April 18, 2019

Machine Learning For A Stronger IoT Security Environment

Machine Learning For A Stronger IoT Security Environment

Internet of Things was a not so popular term just a few years ago. Many people did not hear about it. A lot many didn’t even know that it was soon going to be part of their everyday lives in the form of devices. Today IoT devices are a normal feature. Wearable devices like Fitbit are not just health indicators but also fashion quotients.
IoT devices are everywhere and in every sphere – homes, agricultural fields, automobile sector, health care and medical fields, education, the list is really endless. It is estimated that close to 50 billion IoT devices will be in use by 2020. That’s a huge number of devices!
IoT devices unlike computers are vulnerable to cyberattacks. They are smart but not smart enough to ward off security threats. Internet of things security is a growing concern with deepened use of IoT devices. Thankfully, machine learning can make internet of things security a reality.

How Does Machine Learning Make IoT Devices Safe?

Machine learning algorithms help computers find hidden insights in seemingly normal transactions. These algorithms are based on advanced data analysis and analytical model building. Machine learning and IoT security is a combination that will make using IoT devices safer.
IoT devices generate lot of data. Machine learning is applied to this data to gather insights. These insights are generally around improving customer satisfaction or reducing cost. This equation can be flipped to understand the aspects of this data that are harmful. The mechanics remain same but the focus needs to shift from customer centric analytics to security centric analytics.

Cloud as a Means of Aiding Machine Learning for IoT Security

An IoT device needs a security key to function. This is good news. Imagine a situation where you have a smart home with all smart appliances powered by IoT. Further imagine having a security key for each of these smart appliances. It is no longer good news. Instead it is a nightmare. A possible solution can be to have a unified security key. But, that leaves ample room for all kinds of hacking and security issues.
Let’s look at this situation in a different light. You have a smart home with all these smart IoT powered devices. Thankfully, because these are devices, they have unique set of functions and are predictable in outcomes. So you have a huge but still countable set of unique functions or formats of use that a device can be put to. If you find even a single anomaly in the way these functions happen, then you know there is a potential issue. So if you can house all these finite unique set of IoT device functions on a cloud and use machine learning to identify potential issues, you have a solution in hand. This is exactly how cloud computing and machine learning are used to build a IoT security environment.
All IoT devices need a stable internet connection to function. Anything connected to the net generates reports that reside on the network. Cloud computing can be a possible residence for all these reports generated by IoT devices. Machine learning algorithms can be used to identify potential issues on this centralized repository of diagnostic reports.
Routing machine learning for cyber security via a cloud works in the favor of IoT security as the amount of data available makes it easier to run the algorithms. Further, a solution patch can be reissued at a faster rate, making the use of IoT devices secure. Using the cloud as a means to host machine learning algorithms to fight IoT security issues is widely used across various organizations.

Machine Learning and Human Intervention

IoT devices are widespread. If there is a cyberattack, then the resultant chaos is wide spread too. Any solution for IoT security needs to be oriented to handle such large volume of devices in real time. Machine learning does a wonderful job of analyzing and identifying trends and threats. However, it has its limitations by the data that is used to design the algorithms.
Machine learning algorithms work based on the patterns that the IoT devices should follow, as input. A slight deviation may or may not be detected as a potential threat. So it might create a sense of false security too.
Clubbing machine learning along with human insight is a solution that will go a long way in IoT security. Machines can be used to dig, store, analyze and understand data. This data can be created as reports that are severely scrutinized by a trained analyst. What a human can detect as a pattern difference might not be understood by a machine and hence the need for this last measure defense in the battle for IoT security.
A combination of machine learning powered by cloud based data solutions and human intervention will pave the way for greater IoT security. 

Which Python course is best for beginners?

Level Up Your Python Prowess: Newbie Ninjas: Don't fret, little grasshoppers! Courses like "Learn Python 3" on Codecade...