This media is not supported in your browser
VIEW IN TELEGRAM
هذا الفديو هو الاجابة على السؤال اعلاه:
😁2
Forwarded from الاستاذة طيبة ولاء الدين خيري
١٠ أدوات ومواقع تساعد الباحثين
1. Mendeley: A reference manager and academic social network that helps researchers organize, share, and discover research papers.
2. Zotero: A free, open-source reference manager that allows users to collect, organize, cite, and share research sources.
3. Grammarly: An online grammar and spelling checker that helps researchers improve the quality of their writing.
4. Canva: A graphic design tool that allows researchers to create professional-looking posters, infographics, and other visual materials.
5. Prezi: A web-based presentation software that allows users to create dynamic, interactive presentations.
6. Evernote: A note-taking tool that allows researchers to capture ideas, organize notes, and collaborate with others.
7. SurveyMonkey: A tool that allows researchers to design and conduct online surveys to gather data.
8. Tableau: A data visualization tool that helps researchers to create interactive and meaningful visualizations from large data sets.
9. GitHub: A web-based platform that allows researchers to collaborate on software development projects and share code with others.
10. Google Forms: A free survey tool that allows researchers to create and share surveys, collect and analyze responses, and export data in various formats.
1. Mendeley: A reference manager and academic social network that helps researchers organize, share, and discover research papers.
2. Zotero: A free, open-source reference manager that allows users to collect, organize, cite, and share research sources.
3. Grammarly: An online grammar and spelling checker that helps researchers improve the quality of their writing.
4. Canva: A graphic design tool that allows researchers to create professional-looking posters, infographics, and other visual materials.
5. Prezi: A web-based presentation software that allows users to create dynamic, interactive presentations.
6. Evernote: A note-taking tool that allows researchers to capture ideas, organize notes, and collaborate with others.
7. SurveyMonkey: A tool that allows researchers to design and conduct online surveys to gather data.
8. Tableau: A data visualization tool that helps researchers to create interactive and meaningful visualizations from large data sets.
9. GitHub: A web-based platform that allows researchers to collaborate on software development projects and share code with others.
10. Google Forms: A free survey tool that allows researchers to create and share surveys, collect and analyze responses, and export data in various formats.
هل يمكن الاختراق من خلال وصلة شاحن الهاتف؟
نعم، يمكن الاختراق من خلال وصلة شاحن الهاتف في حالة تم استخدام شاحن غير موثوق به أو مصدر طاقة غير موثوق به. يمكن أن يتم استخدام شاحن مزيف أو يحتوي على برمجيات خبيثة (مثل فيروسات أو برامج التجسس) التي تستغل الثغرات في نظام التشغيل للهاتف الذكي. ويمكن أن يؤدي ذلك إلى تعريض البيانات الشخصية والحساسة للخطر.
من الأفضل استخدام الشواحن الرسمية للهواتف الذكية أو الشواحن المعتمدة من قبل الشركة المصنعة للجهاز، وتجنب استخدام الشواحن المشبوهة أو المجهولة المصدر. كما ينصح بعدم توصيل الهاتف بأي جهاز غير موثوق به أو مجهول، وتحديث الهاتف بانتظام بأحدث التحديثات لتصحيح أي ثغرات في نظام التشغيل.
#منقول
نعم، يمكن الاختراق من خلال وصلة شاحن الهاتف في حالة تم استخدام شاحن غير موثوق به أو مصدر طاقة غير موثوق به. يمكن أن يتم استخدام شاحن مزيف أو يحتوي على برمجيات خبيثة (مثل فيروسات أو برامج التجسس) التي تستغل الثغرات في نظام التشغيل للهاتف الذكي. ويمكن أن يؤدي ذلك إلى تعريض البيانات الشخصية والحساسة للخطر.
من الأفضل استخدام الشواحن الرسمية للهواتف الذكية أو الشواحن المعتمدة من قبل الشركة المصنعة للجهاز، وتجنب استخدام الشواحن المشبوهة أو المجهولة المصدر. كما ينصح بعدم توصيل الهاتف بأي جهاز غير موثوق به أو مجهول، وتحديث الهاتف بانتظام بأحدث التحديثات لتصحيح أي ثغرات في نظام التشغيل.
#منقول
👏3
السلام عليكم ورحمة الله وبركاته، بسبب مشكلة فنية في موقع التواصل الاجتماعي الفيسبوك تم إرسال طلبات صداقة من بعض حساباتكم الى حسابات اخرى بدون علمكم.
ادناه رابط لحذف هذه الطلبات ان وجدت .. مع التقدير
https://m.facebook.com/friends/center/requests/outgoing
ادناه رابط لحذف هذه الطلبات ان وجدت .. مع التقدير
https://m.facebook.com/friends/center/requests/outgoing
Forwarded from Cyber Security News
Apple and Google Join Forces to Stop Unauthorized Tracking Alert System
The goal is to standardize the alerting mechanisms and minimize opportunities for misuse across Bluetooth location-tracking devices from different vendors. To that end, Samsung, Tile, Chipolo, eufy Security, and Pebblebee have all come on board.
A crucial aspect of the proposed specification is the use of a pairing registry, which contains verifiable (but obfuscated) identity information of the owner of an accessory (e.g., phone number or email address) along with the serial number of the accessory.
📸 Photo: Apple com
@Cyber_Security_Channel
The goal is to standardize the alerting mechanisms and minimize opportunities for misuse across Bluetooth location-tracking devices from different vendors. To that end, Samsung, Tile, Chipolo, eufy Security, and Pebblebee have all come on board.
A crucial aspect of the proposed specification is the use of a pairing registry, which contains verifiable (but obfuscated) identity information of the owner of an accessory (e.g., phone number or email address) along with the serial number of the accessory.
📸 Photo: Apple com
@Cyber_Security_Channel
👍1
دفعت إدارة عمدة مقاطعة سان برناردينو 1.1 مليون دولار فدية
على الرغم من أن مكتب التحقيقات الفيدرالي وهيئات إنفاذ القانون يوصون دائمًا بعدم دفع فدية في هذه الهجمات ، في هذه الحالة ، اختارت الإدارة الدفع على الأرجح لأنه لم يكن لديهم طريقة أخرى لاستعادة الأنظمة المشفرة أو لتجنب الكشف عن البيانات الحساسة.
قال كليفورد نيومان ، مدير مركز USC لأمن أنظمة الكمبيوتر ، لصحيفة Los Angeles Times: "إذا كنت تدفع من خلال عملة مشفرة ، فأنت لا تعرف لمن تدفعها". "يمكن أن يكون كيانًا خاضعًا للعقوبات ، سواء كانت إيران ، أو كوريا الشمالية ، أو منظمة إرهابية".
San Bernardino County Sheriff’s Department Paid a $1.1M Ransom
Despite the FBI and law enforcement bodies always recommend not paying ransom in these attacks, in this case, the department opted to pay likely because they had no other way to recover the encrypted systems or to avoid the disclosure of sensitive data.
“If you’re paying through cryptocurrency, you don’t know who you’re paying it to,” Clifford Neuman, the director of USC’s Center for Computer Systems Security, told the Los Angeles Times. “It could be a sanctioned entity, whether it’s Iran, whether it’s North Korea, whether it’s a terrorist organization”.
@OgluF
على الرغم من أن مكتب التحقيقات الفيدرالي وهيئات إنفاذ القانون يوصون دائمًا بعدم دفع فدية في هذه الهجمات ، في هذه الحالة ، اختارت الإدارة الدفع على الأرجح لأنه لم يكن لديهم طريقة أخرى لاستعادة الأنظمة المشفرة أو لتجنب الكشف عن البيانات الحساسة.
قال كليفورد نيومان ، مدير مركز USC لأمن أنظمة الكمبيوتر ، لصحيفة Los Angeles Times: "إذا كنت تدفع من خلال عملة مشفرة ، فأنت لا تعرف لمن تدفعها". "يمكن أن يكون كيانًا خاضعًا للعقوبات ، سواء كانت إيران ، أو كوريا الشمالية ، أو منظمة إرهابية".
San Bernardino County Sheriff’s Department Paid a $1.1M Ransom
Despite the FBI and law enforcement bodies always recommend not paying ransom in these attacks, in this case, the department opted to pay likely because they had no other way to recover the encrypted systems or to avoid the disclosure of sensitive data.
“If you’re paying through cryptocurrency, you don’t know who you’re paying it to,” Clifford Neuman, the director of USC’s Center for Computer Systems Security, told the Los Angeles Times. “It could be a sanctioned entity, whether it’s Iran, whether it’s North Korea, whether it’s a terrorist organization”.
@OgluF
Security Affairs
San Bernardino County Sheriff’s Department paid a $1.1M ransom
The San Bernardino County Sheriff’s Department confirmed that it has paid a $1.1-million ransom after the April ransomware attack.
خبر مهم لمستخدمي #WordPress
يعرض البرنامج المساعد WordPress Advanced Custom Fields XSS + 2M موقع للهجمات
وأشار الباحثون إلى أن المشكلة قابلة للاستغلال بغض النظر عما إذا كانت منافذ إدارة cPanel (2080 ، 2082 ، 2083 ، 2086) معرضة خارجيًا أم لا. أفاد الباحثون أن المشكلة قابلة للاستغلال أيضًا لاستهداف مواقع الويب على المنفذين 80 و 443 إذا كانت تدار بواسطة cPanel.
يمكن للمهاجم استغلال المشكلة لاختطاف جلسة cPanel لمستخدم شرعي وتنفيذ أنشطة ضارة ، بما في ذلك تحميل قذيفة ويب والحصول على تنفيذ الأوامر.
WordPress Advanced Custom Fields plugin XSS exposes +2M Sites to Attacks
The researchers pointed out that the issue is exploitable regardless of whether or not the cPanel management ports (2080, 2082, 2083, 2086) are exposed externally. The researchers reported that the issue is also exploitable to target websites on ports 80 and 443 if they are being managed by cPanel.
The attacker can exploit the issue to hijack a legitimate user’s cPanel session and carry out malicious activities, including uploading a web shell and gaining command execution.
@OgluF
يعرض البرنامج المساعد WordPress Advanced Custom Fields XSS + 2M موقع للهجمات
وأشار الباحثون إلى أن المشكلة قابلة للاستغلال بغض النظر عما إذا كانت منافذ إدارة cPanel (2080 ، 2082 ، 2083 ، 2086) معرضة خارجيًا أم لا. أفاد الباحثون أن المشكلة قابلة للاستغلال أيضًا لاستهداف مواقع الويب على المنفذين 80 و 443 إذا كانت تدار بواسطة cPanel.
يمكن للمهاجم استغلال المشكلة لاختطاف جلسة cPanel لمستخدم شرعي وتنفيذ أنشطة ضارة ، بما في ذلك تحميل قذيفة ويب والحصول على تنفيذ الأوامر.
WordPress Advanced Custom Fields plugin XSS exposes +2M Sites to Attacks
The researchers pointed out that the issue is exploitable regardless of whether or not the cPanel management ports (2080, 2082, 2083, 2086) are exposed externally. The researchers reported that the issue is also exploitable to target websites on ports 80 and 443 if they are being managed by cPanel.
The attacker can exploit the issue to hijack a legitimate user’s cPanel session and carry out malicious activities, including uploading a web shell and gaining command execution.
@OgluF
Security Affairs
WordPress Advanced Custom Fields plugin XSS exposes +2M sites to attacks
A reflected cross-site scripting vulnerability is the Advanced Custom Fields plugin for WordPress exposed over 2 million sites to hacking.