{"id":3703,"date":"2017-05-15T00:00:00","date_gmt":"2017-05-15T00:00:00","guid":{"rendered":"https:\/\/dev.abes.com.br\/?p=3703"},"modified":"2017-05-15T00:00:00","modified_gmt":"2017-05-15T00:00:00","slug":"outros-mega-ataques-hacker-virao-como-se-defender","status":"publish","type":"post","link":"https:\/\/dev.abes.com.br\/en\/outros-mega-ataques-hacker-virao-como-se-defender\/","title":{"rendered":"Other hacker mega-attacks will come. How to defend yourself?"},"content":{"rendered":"<div style=\"text-align: center;\">\n\t<br \/>\n\t<img decoding=\"async\" alt=\"\" src=\"\/wp-content\/uploads\/anterior\/Imagens\/francisco%20(3).jpg\" style=\"width: 300px; height: 258px;\" \/><br \/>\n\tBy Francisco Camargo, President of ABES<\/div>\n<div style=\"text-align: justify;\">\n\t&nbsp;<br \/>\n\tOn Friday (12\/05\/2017), the whole world was frightened by the scale and scope of the hacker attacks, which show that cybercriminals have a lot of resources, both financial and technological. Generally, data hijacking attacks (ramsoware) target specific victims, but this is not what happened this time, as they reached both governments and large companies, as well as home users, micro and small companies.<br \/>\n\t&nbsp;<br \/>\n\tIn a preliminary analysis, we know that it will be very difficult to identify the attackers, as this would require large-scale international collaboration, perhaps the creation of Interpol da Net and there are countries that are more closed and do not participate in these initiatives. The use of Bitcoin itself prevents the use of the most traditional line of research for criminals: following money.<br \/>\n\t&nbsp;<br \/>\n\tNowadays, in&nbsp;<a href=\"http:\/\/www.fatosdesconhecidos.com.br\/como-entrar-na-deep-web-e-o-que-vou-encontrar-la\/\" target=\"_blank\" rel=\"noopener noreferrer\">DeepWeb<\/a>&nbsp;(accessible via a specific browser), it is possible for people to buy viruses and malware for a variety of tasks, rent an armada of&nbsp;<a href=\"http:\/\/www.techtudo.com.br\/noticias\/noticia\/2013\/08\/saiba-o-que-um-computador-zumbi-infectado-por-um-botnet-pode-fazer.html\" target=\"_blank\" rel=\"noopener noreferrer\">zombie computers<\/a>&nbsp;to effect&nbsp;<a href=\"https:\/\/pt.wikipedia.org\/wiki\/Ataque_de_nega%C3%A7%C3%A3o_de_servi%C3%A7o\" target=\"_blank\" rel=\"noopener noreferrer\">denial of service attacks<\/a>, and sending&nbsp;<a href=\"http:\/\/antispam.br\/prevencao\/zombie\/\" target=\"_blank\" rel=\"noopener noreferrer\">thousands of emails<\/a>, among other practices. Even criminals with very little technical knowledge, but with financial resources, can make a cyber attack highly profitable.<br \/>\n\t&nbsp;<br \/>\n\tWe are experiencing the professionalization of the cybercrime market and the emergence of the concept of <em>cybercrime as a service.<\/em> Everything is similar to a systems engineering project and can be summarized in 7 stages of planning and execution: 1) the targets are defined; 2) the geographical extent and dispersion of the attack is established; 3) estimated revenue is estimated; 4) the costs of operating the attack are estimated; 5) choose the tools to be used; 6) people are hired, whether to provide \u201cconsultancy\u201d on money laundering, to establish a social engineering strategy, etc; 7) malware is purchased or developed that exploits a little-known and not yet fixed or under-corrected vulnerability in the operating system or other systems, such as ERP, CRM, Office, Content Manager, PDF, etc. E: let&#039;s go to the attack!<br \/>\n\t&nbsp;<br \/>\n\tOn the other hand, understanding the mechanisms of this attack helps to prevent the occurrence of similar ones. The question is not just whether other large-scale attacks will occur, but when they will occur and how to minimize their impacts. Another clear point in this latest attack is that, however small the amount collected by criminals, these actions cost hundreds of millions of dollars for companies and governments, even when the ransom is not paid because several systems go down and paralyze business and the management.<br \/>\n\t&nbsp;<br \/>\n\tWe remind you that all of this could be minimized if the \u201cEighth Layer of the OSI Model\u201d, the \u201cPeopleware\u201d, formed by the uninformed and unsuspecting users received guidance. The more users who are sensitized about the problem, the better, as it is like a vaccination campaign, in which for some viruses, it is enough to immunize 50 to 60% of the population to protect the entire population. Each conscientious and disciplined user avoids contamination by hundreds of other users.<br \/>\n\t&nbsp;<br \/>\n\tABES created the&nbsp;<a href=\"http:\/\/www.brasilpaisdigital.com.br\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Brazil Country Digital Initiative<\/strong><\/a>&nbsp;to discuss data usage, flow, privacy and security. Now, in the face of security problems and the growth of cybercrime, the entity will launch another initiative to inform the population about this type of crime and how it can be prevented.<br \/>\n\t&nbsp;<br \/>\n\tThere are also three simple and inexpensive measures that each user can take to protect themselves from ramsoware attacks.<br \/>\n\t&nbsp;<\/div>\n<div style=\"text-align: justify;\">\n\t<strong>BACKUP:<\/strong> daily backup your data, photos, documents. There are cheap and even free services for backing up to the cloud;<br \/>\n\t&nbsp;<\/div>\n<div style=\"text-align: justify;\">\n\t<strong>BE PARANOIC:<\/strong> be wary of websites and emails that try to influence your fear, your greed. Everything that was valid for the so-called \u201cVicar&#039;s tale\u201d, is now amplified in the digital world. Never open attachments or click on links without checking the source. Your bank will never send you an email, requiring you to update your data within 24 hours, nor will it send you a contract to be signed;<\/div>\n<div style=\"text-align: justify;\">\n\t&nbsp;<\/div>\n<div style=\"text-align: justify;\">\n\t<strong>UPDATE YOUR SOFTWARE:<\/strong> manufacturers invest a lot of time and money identifying vulnerabilities and periodically release Update Patches for their operating system, such as Windows, Apple, Office, Adobe, among others. Of course, this only applies to software that is not pirated. Never download pirated software, as they may have a hidden &quot;surprise&quot;.<\/div>\n<div style=\"text-align: justify;\">\n\t&nbsp;<br \/>\n\tWith this, the home user, the small merchant, the service provider will not only be protecting themselves, but will protect the whole society, as they will not be spreading viruses to other users. There are other additional measures that can and should be taken and we recommend:<br \/>\n\t&nbsp;<\/div>\n<div style=\"text-align: justify;\">\n\t<strong>ANTIVIRUS:<\/strong> they are cheap or even free on the internet and when updated they block almost all attacks;<\/div>\n<div style=\"text-align: justify;\">\n\t&nbsp;<\/div>\n<div style=\"text-align: justify;\">\n\t<strong>ANTISPAM:<\/strong> the best way to prevent the <em>phishing<\/em> is to reduce spam. Activate the AntiSpam functionality of your email provider or if you are a company buy a UTM or AntiSpam to protect users as a whole.<\/div>\n<div style=\"text-align: justify;\">\n\t&nbsp;<\/div>\n<div style=\"text-align: justify;\">\n\t<strong>FIREWALL:<\/strong> activate your Windows firewall, it will be a little slower, but this is the price of security. For companies, again UTMs or FIREWALLs are the best solution.<\/div>\n<div style=\"text-align: justify;\">\n\t&nbsp;<br \/>\n\tAnother specific weapon for developers and systems and for the customers of these companies is the <a href=\"http:\/\/www.abessoftware.com.br\/noticias\/abes-se-une-a-hpe-para-melhorar-a-seguranca-do-software-brasileiro\" target=\"_blank\" rel=\"noopener noreferrer\">Source Code Auditing<\/a>, which can accelerate the discovery of vulnerabilities in applications. In system programming, there are, on average, 15 errors per thousand lines of code, one at least creates a vulnerability. Large systems have up to 30 million lines of code, 30,000 vulnerabilities due to unintended errors. To learn a little more about attacks and how to protect yourself at low cost, see this&nbsp;<a href=\"http:\/\/g1.globo.com\/globo-news\/jornal-globo-news\/videos\/v\/francisco-camargo-%20analisa-ataque-cibernetico-que-atingiu-quase-100-paises\/5866879\/\" target=\"_blank\" rel=\"noopener noreferrer\">article in Globo News<\/a>.<br \/>\n\t&nbsp;<br \/>\n\tOn the internet, in the virtual environment, the security of one increases the security of all.<br \/>\n\t&nbsp;<br \/>\n\t<em>* Francisco Camargo is President of ABES. Production engineer from Escola Polit\u00e9cnica, the executive has a specialization from Harvard University. Francisco is also the Founder of the CLM Group, a Latin American distributor focused on Information Security, Advanced Infrastructure and Analytics.<\/em><\/div>","protected":false},"excerpt":{"rendered":"<p>By Francisco Camargo, president of ABES On Friday (12\/05\/2017), the whole world was frightened by the scale and scope of hacker attacks, which show that cybercriminals have a lot of financial and technological resources. Generally, data hijacking attacks (ramsoware) target specific victims, but that wasn&#039;t what happened this time, [\u2026]<\/p>","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[8,19],"tags":[],"class_list":["post-3703","post","type-post","status-publish","format-standard","hentry","category-artigos","category-ultimas-noticias"],"acf":[],"publishpress_future_action":{"enabled":false,"date":"2026-06-14 01:05:36","action":"change-status","newStatus":"draft","terms":[],"taxonomy":"category"},"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/posts\/3703","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/comments?post=3703"}],"version-history":[{"count":0,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/posts\/3703\/revisions"}],"wp:attachment":[{"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/media?parent=3703"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/categories?post=3703"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dev.abes.com.br\/en\/wp-json\/wp\/v2\/tags?post=3703"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}