Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
How To Stay Safe On The Black Hat Network: Dont Connect To It
Threaded  |  Newest First  |  Oldest First
mike776
mike776,
User Rank: Apprentice
7/28/2016 | 2:26:46 PM
Thanks!
Hey mate,

Thanks for your kind information but I would also suggest all the user to use best VPN to Stay Safe on the Black Hat Network because VPN always protect our identity and it's completely safe to surf web by using VPN.

You can find the list of VPNs by google this query "Best VPN for USA"

 

dealthereviews.com/best-vpn-for-usa/

 

Thanks!

 

 
RonM039
RonM039,
User Rank: Apprentice
7/28/2016 | 4:40:09 PM
Re: Thanks!
I would also suggest that you turn off your Google Now / Siri and Alexa.

Disable these while at Blackhat / DefCon as it has been demonstrated that all of them are suseptable to High Frequency signals that can be used by hackers to dump your contacts list/ history and direct your device to infected websites
RyanSepe
RyanSepe,
User Rank: Ninja
7/29/2016 | 1:23:11 PM
Re: Thanks!
This is a good tip. Even when locked this mechanisms can access data within the phone. It may be beneficial for the companies that provide these virtual assistants to scale back some of their access while locked.
LisaJ227
LisaJ227,
User Rank: Apprentice
8/2/2016 | 10:32:42 AM
The best wishes
Actually the article is informative enough! As for the first aid for your protection, it is vpn, which can help you to enhance your security and stay private when it is necessary for you. Some people say that it doesn't protect your system, but to be exact it is the only service which can try to do it and do it well. As for me, I prefer expressvpn  https://www.bestvpnrating.com/service/expressvpn the cost is rather high, but at the same time the result satisfies me.

As for the suggestion not to pay vie the net, nowadays it is impossible as it is the most convenient and the fastest way as you can avoid a lot of problems concerning queues.

On the whole, for staying secure you should just follow all the tips, as there is no flexible decision yet.
RyanSepe
RyanSepe,
User Rank: Ninja
7/29/2016 | 1:24:59 PM
General Consensus
From most of the pen testers and white hatters that I have spoken to in the past they recommend not connecting as much as possible while at blackhat.
GonzSTL
GonzSTL,
User Rank: Ninja
7/29/2016 | 4:03:26 PM
Re: General Consensus
Anytime I am at a security conference (or any IT conference for that matter), two features I turn off are wifi and bluetooth. I know too much, have done too much, and I am paranoid to the nth degree.
String46
String46,
User Rank: Apprentice
8/1/2016 | 9:22:57 PM
Stay Safe
This reminds of when I was training rookies at the State prison where I worked as an Officer for 10 years. One asked how he could minimize the risk of being attacked by an inmate or inmates.  He wasn't too pleased when I replied, "Simple. Don't show up for work."

They got the picture.

Great post.
Joe Stanganelli
Joe Stanganelli,
User Rank: Ninja
8/3/2016 | 5:18:07 PM
Yep
This is precisely my thinking and strategy whenever I attend an event at MIT.  I'm sure as shootin' not connecting to the network of the university with some of the brightest hacking minds in the world.

Actually, I don't ever connect to the network at any conference I go to.  It's just best practice -- and having 4G helps.
rdusek483
rdusek483,
User Rank: Apprentice
8/8/2016 | 9:41:09 AM
Re: Definitely beware ATMs
I wonder if anyone is selling RFID-security wallets that read the cards in them and send the data 'home'?
Ventamepacher3E
Ventamepacher3E,
User Rank: Apprentice
9/15/2016 | 12:08:30 PM
2016
Stay safe and anonyme is The difficulty in 2016
katetaylor
katetaylor,
User Rank: Apprentice
10/1/2016 | 4:35:11 PM
Re: 2016
I totally agree with you getting exposed to cyber threats is very common these days and the best thing we can do is to go anonymous over the internet on all the devices, the best tool is a VPN service to safeguard your privacy and security and it also helps us to bypass all the geo-restrictions and gives us the power to access all the blocked websites from anywhere in the world.
lorraine89
lorraine89,
User Rank: Ninja
10/20/2016 | 10:14:18 AM
Identity theft
Staying safe is not something that the user should stop using a certain website or a tool for staying safe and secure. The web is a bad place as of now in terms like you never who is spying on your online activites. It is therefore advisable to stay safe from these hacking attempts and to secure your IP with PureVPN that provides encrypted online connection and also offers 5 plus multi logins so that is a plus. 
EmmaM384
EmmaM384,
User Rank: Apprentice
10/23/2016 | 7:44:35 PM
The Black Network Safe?
People those mostly looking any information in online but the black hat users getting such like information.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Creating an Effective Incident Response Plan
Security teams are realizing their organizations will experience a cyber incident at some point. An effective incident response plan that takes into account their specific requirements and has been tested is critical. This issue of Tech Insights also includes: -a look at the newly signed cyber-incident law, -how organizations can apply behavioral psychology to incident response, -and an overview of the Open Cybersecurity Schema Framework.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-45343
PUBLISHED: 2022-11-29
GPAC v2.1-DEV-rev478-g696e6f868-master was discovered to contain a heap use-after-free via the Q_IsTypeOn function at /gpac/src/bifs/unquantize.c.
CVE-2022-44635
PUBLISHED: 2022-11-29
Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code. This issue affects Apache Fineract version 1.8.0 and prior versions. We recommend users to upgr...
CVE-2022-46146
PUBLISHED: 2022-11-29
Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, i someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the built-in authentication cache. Versions 0.7.2 and 0.8.2 contain a fix for...
CVE-2022-36433
PUBLISHED: 2022-11-29
The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript code in the short_content and full_content fields, leading to XSS attacks against admin panel users via posts/preview or posts/save.
CVE-2022-4202
PUBLISHED: 2022-11-29
A vulnerability, which was classified as problematic, was found in GPAC 2.1-DEV-rev490-g68064e101-master. Affected is the function lsr_translate_coords of the file laser/lsr_dec.c. The manipulation leads to integer overflow. It is possible to launch the attack remotely. The exploit has been disclose...