AGL 40.00 Decreased By ▼ -0.16 (-0.4%)
AIRLINK 129.53 Decreased By ▼ -2.20 (-1.67%)
BOP 6.68 Decreased By ▼ -0.01 (-0.15%)
CNERGY 4.63 Increased By ▲ 0.16 (3.58%)
DCL 8.94 Increased By ▲ 0.12 (1.36%)
DFML 41.69 Increased By ▲ 1.08 (2.66%)
DGKC 83.77 Decreased By ▼ -0.31 (-0.37%)
FCCL 32.77 Increased By ▲ 0.43 (1.33%)
FFBL 75.47 Increased By ▲ 6.86 (10%)
FFL 11.47 Increased By ▲ 0.12 (1.06%)
HUBC 110.55 Decreased By ▼ -1.21 (-1.08%)
HUMNL 14.56 Increased By ▲ 0.25 (1.75%)
KEL 5.39 Increased By ▲ 0.17 (3.26%)
KOSM 8.40 Decreased By ▼ -0.58 (-6.46%)
MLCF 39.79 Increased By ▲ 0.36 (0.91%)
NBP 60.29 No Change ▼ 0.00 (0%)
OGDC 199.66 Increased By ▲ 4.72 (2.42%)
PAEL 26.65 Decreased By ▼ -0.04 (-0.15%)
PIBTL 7.66 Increased By ▲ 0.18 (2.41%)
PPL 157.92 Increased By ▲ 2.15 (1.38%)
PRL 26.73 Increased By ▲ 0.05 (0.19%)
PTC 18.46 Increased By ▲ 0.16 (0.87%)
SEARL 82.44 Decreased By ▼ -0.58 (-0.7%)
TELE 8.31 Increased By ▲ 0.08 (0.97%)
TOMCL 34.51 Decreased By ▼ -0.04 (-0.12%)
TPLP 9.06 Increased By ▲ 0.25 (2.84%)
TREET 17.47 Increased By ▲ 0.77 (4.61%)
TRG 61.32 Decreased By ▼ -1.13 (-1.81%)
UNITY 27.43 Decreased By ▼ -0.01 (-0.04%)
WTL 1.38 Increased By ▲ 0.10 (7.81%)
BR100 10,407 Increased By 220 (2.16%)
BR30 31,713 Increased By 377.1 (1.2%)
KSE100 97,328 Increased By 1781.9 (1.86%)
KSE30 30,192 Increased By 614.4 (2.08%)

ISLAMABAD: Hostile elements may launch cyber attack on the occasion of Independence Day, i.e., 14th August, 2023 for disruption of services and defacement to tarnish the global image of Pakistan, warned the National Telecommunications and Information Security Board (NTISB).

The Board has issued advisory, “Prevention against Website Compromise on the Eve of National Days” noted that hostile elements/ state-sponsored malicious actors typically target government departments/ ministries and defence sector websites on the eve of the National Days for disruption of services and defacement to tarnish the global image of Pakistan. It is likely that hostile elements may launch cyber attack on the occasion of Independence Day, i.e., 14th August, 2023.

FBR under cyber attack?

Accordingly, an advisory is being sent to sensitise website administrators and Service Providers to take additional security precautions (such as web server hardening, traffic/ integrity monitoring, etc.) to avoid possible website defacement/ hacking attempts. NTISB has issued 47 advisories in 2023 so far with respect to cyber-attacks, hacking, fraudulent/fake email, etc., and protection guidelines for individuals, government employees as well as websites.

Further, web server administrators should be made mindful of cyber security guidelines including; Cyber Security Best Practices for Websites Protection; (a) Upgrade OS and web servers to latest version; (b) Website admin panel should only be accessible via white-listed IPs; (c) Defend your website against SQL injection attacks by using input validation technique; (d) Complete analysis and penetration testing of application be carried out to identify potential threats; (e) Complete website be deployed on inland servers including database and web infrastructure; (f) HTTPS protocol be used for communication between client and web server; (g) Application and database be installed on different machines with proper security hardening; (h) Sensitive data be stored in encrypted form with no direct public access; (i) DB users privileges be minimized and limited access be granted inside programming code; (j) Proper security hardening of endpoints and servers be performed and no unnecessary ports and applications be used; (k) Updated Antivirus tools/ firewalls be used on both endpoints and servers to safeguard from potential threats; (l) Enforce a strong password usage policy; (m) Remote management services like RDP and SSH must be disabled in production environment; (n) Deploy web application firewalls (WAF) for protection against web attacks; (o) Employ secure coding practices such as parameterized queries, proper input sanitization and validation to remove malicious scripts (p) Keep system and network devices up-to-date; (q) Log retention policy must be devised for at least 3x months on separate device for attacker’s reconnaissance.

Comments

Comments are closed.