Login Register






Computer Scientists Develop Tool to Tell if Website is Breached filter_list
Author
Message
Computer Scientists Develop Tool to Tell if Website is Breached #1
University of California - San Diego computer scientists have built and successfully tested a tool designed to detect when websites are hacked by monitoring the activity of email accounts associated with them.
The researchers were surprised to find that almost 1 percent of the websites they tested had suffered a data breach during their 18-month study period, regardless of how big the companies' reach and audience are.
"No one is above this -- companies or nation states -- it's going to happen; it's just a question of when," said Alex C. Snoeren, the paper's senior author and a professor of computer science at the Jacobs School of Engineering at the University of California San Diego.
Given that there are more than one billion sites on the Internet, this means tens of millions of websites could be breached every year, said Joe DeBlasio, one of Snoeren's Ph.D. students and the paper's first author.
The researchers found that popular sites were just as likely to be hacked as unpopular ones. This means that out of the top-1,000 most visited sites on the Internet, ten are likely to be hacked every year:

https://www.securitymagazine.com/articles/88576-computer-scientists-develop-tool-to-tell-if-website-is-breached

Reply

RE: Computer Scientists Develop Tool to Tell if Website is Breached #2
I doubt there's many people disillusioned about the risks of hacking. Preventing it and knowing what to do next should be important.
[Image: 4GNsK67.png]

Reply

RE: Computer Scientists Develop Tool to Tell if Website is Breached #3
Quote:The researchers found that popular sites were just as likely to be hacked as unpopular ones.

Really? It takes a so-called computer scientist to determine this?

Quote:University of California - San Diego computer scientists have built and successfully tested a tool designed to detect when websites are hacked by monitoring the activity of email accounts associated with them.

In terms of websites being compromised, this barely touches the surface. In my views, It's a waste of time.

From a security standpoint, you need to Identify and patch "every" vulnerability, flaw and loophole. It doesn't stop at email addresses. From a hacker's perspective, all you need Is "one" gateway and you're In.

For example, this Is a major construction company that I've compromised around an hour ago. It did request for email confirmation (which I had no knowledge of, nor any Interest In pursuing), but that was Immaterial to my objective. I had full raid on their email servers.
Spoiler:
[Image: BKSwD0k.png]


And If I was someone with malicious Intent, there's no telling what I can achieve.
Spoiler:
[Image: aSFUmPY.png]


Spoiler:
[Image: shAowSj.png]


Back to the article, this Is not only the responsibility of the end user:
Quote:The computer scientists had a few pieces of advice for Internet users: don't reuse passwords

Corporations need to Implement It server-side, whereby you cannot reuse old passwords- Irrespective of the age of the password Itself. This alone, will solve the Issue In It's entirety. Furthermore, a password complexity requirement should also be In place, so too an account lockout policy hence the account Is locked for ex-amount of time due to a certain number of Invalid login attempts.
There's heaps more I can add, but let's leave It at that for now.
[Image: AD83g1A.png]

Reply