3 weeks ago
3 weeks ago
3 weeks ago
Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.
We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

With the advancement in technology of internet, criminal activities also got the pace. Most of the times attackers are one step ahead of Security Researchers. There are large number of platforms available for attackers to attack including Web Applications, Networks etc. Creating backdoors using malwares and getting remote access is one of the traditional techniques of attacking. With the advancement in technology attackers also devise new techniques. Somewhere or the other, motive of the attackers is to generate revenue whether directly or indirectly. Using ransomwares is one of the techniques of direct revenue generation. In this technique, access to files or system is denied by encrypting the data or locking the computer. Ransomwares are categorised into two categories that are Locker Ransomware and Crypto Ransomware.
In Locker Ransomware the user interface is generally blocked or the access is denied to computer resources. If the malware is removed it won’t affect the files or data stored in the computer as this ransomware is just blocking the interface not manipulating the files. Because of this it is less common. In this, attackers use social engineering techniques which forces the victim to pay.
In Crypto Ransomware technique, the valuable data is encrypted by the malware. This type of malwares do not warns until the valuable data is encrypted. The moment the task of encryption is completed it pops up asking victim to pay ransom to get the data back.
The first step of the ransomware is to get executed in the victim’s machine. This can be done in number of ways. Once it got executed in the victim’s machine then its action starts.
After the completion of encryption it pops up asking the victim to pay ransom within specified time otherwise the server will delete the private key.
This is the common mechanism used by ransomwares. Its overall working includes much more like how it got executed in victim’s computer, how strong the encryption algorithm is, how the transactions are carried out in an untraceable manner. Any weakness in this whole operation will not just lead to failure of operation but can lead to heavy legal action against all those who are involved.
Methods adopted by ransomware attackers to spread ransomwares are very common and almost same as that of normal malwares. The malicious file came with the extension .pdf as windows by default hides actual extension of the file. So trapping users in these kind of techniques attackers are able to execute the malware into the system. Some of the popular adopted methods to spread ransomware are:
This is very important part of the whole operation that how the transaction is carried out in an untraceable manner. There are number of ways to achieve this but a little mistake can take down everything. Techniques include usage of digital wallets which provide anonymity to the parties involved in the transactions. But with the evolution in the ransomwares, most of them have shifted to bitcoin. Bitcoin is a decentralized digital currency which is currently providing anonymity to attackers. It’s different from normal currency, its digital and the most important point is that the payment once done cannot be reversed. Bitcoin technology carry out transactions in form of addresses which are just random numbers. Being a decentralized currency all the transactions carried out on each address is public. But the identity of the person or group behind that address is anonymous until and unless identity related to that particular address is posted or revealed somewhere else on the internet. Attackers don’t use a single address instead they use large number of addresses. Moreover the transactions are carried out over the Tor network to provide further anonymity and their C&C servers are also located on the Tor network. So the ransomware operators use this technology to carry out transactions and hence not revealing their identity.
It’s always better to prevent rather to cure. Moreover in case of ransomwares once the encryption is done after that removing ransomware Trojan will not decrypt the files.
In case the trojan is executed by mistake and victim came to know that something wrong has been happened with the sytem, the first task is to disconnect system from the internet and local network and then remove the Trojan as soon as possible. This will terminate the connection with C&C server and the transfer of encyrption keys will not take place and hence saving the data.