AGL 38.54 Increased By ▲ 0.97 (2.58%)
AIRLINK 129.50 Decreased By ▼ -3.00 (-2.26%)
BOP 5.61 Decreased By ▼ -0.03 (-0.53%)
CNERGY 3.86 Increased By ▲ 0.09 (2.39%)
DCL 8.73 Decreased By ▼ -0.14 (-1.58%)
DFML 41.76 Increased By ▲ 0.76 (1.85%)
DGKC 88.30 Decreased By ▼ -1.86 (-2.06%)
FCCL 35.00 Decreased By ▼ -0.08 (-0.23%)
FFBL 67.35 Increased By ▲ 0.85 (1.28%)
FFL 10.61 Increased By ▲ 0.46 (4.53%)
HUBC 108.76 Increased By ▲ 2.36 (2.22%)
HUMNL 14.66 Increased By ▲ 1.26 (9.4%)
KEL 4.75 Decreased By ▼ -0.11 (-2.26%)
KOSM 6.95 Increased By ▲ 0.10 (1.46%)
MLCF 41.65 Decreased By ▼ -0.15 (-0.36%)
NBP 59.60 Increased By ▲ 1.02 (1.74%)
OGDC 183.00 Increased By ▲ 1.75 (0.97%)
PAEL 26.25 Increased By ▲ 0.55 (2.14%)
PIBTL 5.97 Increased By ▲ 0.14 (2.4%)
PPL 146.70 Decreased By ▼ -1.70 (-1.15%)
PRL 23.61 Increased By ▲ 0.39 (1.68%)
PTC 16.56 Increased By ▲ 1.32 (8.66%)
SEARL 68.30 Decreased By ▼ -0.49 (-0.71%)
TELE 7.23 Decreased By ▼ -0.01 (-0.14%)
TOMCL 35.95 Decreased By ▼ -0.05 (-0.14%)
TPLP 7.85 Increased By ▲ 0.45 (6.08%)
TREET 14.20 Decreased By ▼ -0.04 (-0.28%)
TRG 50.45 Decreased By ▼ -0.40 (-0.79%)
UNITY 26.75 Increased By ▲ 0.35 (1.33%)
WTL 1.21 No Change ▼ 0.00 (0%)
BR100 9,806 Increased By 37.8 (0.39%)
BR30 29,678 Increased By 278.1 (0.95%)
KSE100 92,304 Increased By 366.3 (0.4%)
KSE30 28,840 Increased By 96.6 (0.34%)

ISLAMABAD: Hostile elements may launch cyber attack on the occasion of Independence Day, i.e., 14th August, 2023 for disruption of services and defacement to tarnish the global image of Pakistan, warned the National Telecommunications and Information Security Board (NTISB).

The Board has issued advisory, “Prevention against Website Compromise on the Eve of National Days” noted that hostile elements/ state-sponsored malicious actors typically target government departments/ ministries and defence sector websites on the eve of the National Days for disruption of services and defacement to tarnish the global image of Pakistan. It is likely that hostile elements may launch cyber attack on the occasion of Independence Day, i.e., 14th August, 2023.

FBR under cyber attack?

Accordingly, an advisory is being sent to sensitise website administrators and Service Providers to take additional security precautions (such as web server hardening, traffic/ integrity monitoring, etc.) to avoid possible website defacement/ hacking attempts. NTISB has issued 47 advisories in 2023 so far with respect to cyber-attacks, hacking, fraudulent/fake email, etc., and protection guidelines for individuals, government employees as well as websites.

Further, web server administrators should be made mindful of cyber security guidelines including; Cyber Security Best Practices for Websites Protection; (a) Upgrade OS and web servers to latest version; (b) Website admin panel should only be accessible via white-listed IPs; (c) Defend your website against SQL injection attacks by using input validation technique; (d) Complete analysis and penetration testing of application be carried out to identify potential threats; (e) Complete website be deployed on inland servers including database and web infrastructure; (f) HTTPS protocol be used for communication between client and web server; (g) Application and database be installed on different machines with proper security hardening; (h) Sensitive data be stored in encrypted form with no direct public access; (i) DB users privileges be minimized and limited access be granted inside programming code; (j) Proper security hardening of endpoints and servers be performed and no unnecessary ports and applications be used; (k) Updated Antivirus tools/ firewalls be used on both endpoints and servers to safeguard from potential threats; (l) Enforce a strong password usage policy; (m) Remote management services like RDP and SSH must be disabled in production environment; (n) Deploy web application firewalls (WAF) for protection against web attacks; (o) Employ secure coding practices such as parameterized queries, proper input sanitization and validation to remove malicious scripts (p) Keep system and network devices up-to-date; (q) Log retention policy must be devised for at least 3x months on separate device for attacker’s reconnaissance.

Comments

Comments are closed.