Posts

Showing posts from November, 2023

Cyber attacks and breaches found in 2023

Image
  ICMR Indian Council of Medical Research: 815,000,000 breached records Date of breach:  9 October 2023 Breached organisation:  The ICMR (Indian Council of Medical Research) Incident details:  The personal data of 815 million Indian residents, apparently exfiltrated from the ICMR’s Covid-testing database, was sold on the dark web earlier this month.   According to the security company Security , which discovered the listing, the data included victims’ names, ages, genders, addresses, passport numbers and Aadhaar number (12-digit government identification numbers). Records breached:  815,000,000 According to the following attack, the threat is  improper network segmentation. I'll continue the threat modling for this.

Setting up Hackers Used # Port Scanner

Image
As simply Port scanning is like knocking on doors in a neighborhood to see who's home.  In the world of network security, it's a crucial step to identify open ports and potential vulnerabilities in your network.  Port scanning is a useful technique for exploring network systems and gathering information about their services.  Used Parties Security professionals and system administrators use port scanning to diagnose network problems, audit network security, or discover vulnerabilities. Why Port Scanning It's kind of a enumeration process that defines the ports on a network or targeted machines which open and receive or send. It's sending the crafted packet to analyse the response and determine software and associated vulnerabilities on each port. Socket Programming A socket is an endpoint of a two-way communication server with a socket and is bounded by a specific port number as an 80 network. These are bounded with specific port numbers and use backend software to rece