AGL 38.02 Increased By ▲ 0.08 (0.21%)
AIRLINK 197.36 Increased By ▲ 3.45 (1.78%)
BOP 9.54 Increased By ▲ 0.22 (2.36%)
CNERGY 5.91 Increased By ▲ 0.07 (1.2%)
DCL 8.82 Increased By ▲ 0.14 (1.61%)
DFML 35.74 Decreased By ▼ -0.72 (-1.97%)
DGKC 96.86 Increased By ▲ 4.32 (4.67%)
FCCL 35.25 Increased By ▲ 1.28 (3.77%)
FFBL 88.94 Increased By ▲ 6.64 (8.07%)
FFL 13.17 Increased By ▲ 0.42 (3.29%)
HUBC 127.55 Increased By ▲ 6.94 (5.75%)
HUMNL 13.50 Decreased By ▼ -0.10 (-0.74%)
KEL 5.32 Increased By ▲ 0.10 (1.92%)
KOSM 7.00 Increased By ▲ 0.48 (7.36%)
MLCF 44.70 Increased By ▲ 2.59 (6.15%)
NBP 61.42 Increased By ▲ 1.61 (2.69%)
OGDC 214.67 Increased By ▲ 3.50 (1.66%)
PAEL 38.79 Increased By ▲ 1.21 (3.22%)
PIBTL 8.25 Increased By ▲ 0.18 (2.23%)
PPL 193.08 Increased By ▲ 2.76 (1.45%)
PRL 38.66 Increased By ▲ 0.49 (1.28%)
PTC 25.80 Increased By ▲ 2.35 (10.02%)
SEARL 103.60 Increased By ▲ 5.66 (5.78%)
TELE 8.30 Increased By ▲ 0.08 (0.97%)
TOMCL 35.00 Decreased By ▼ -0.03 (-0.09%)
TPLP 13.30 Decreased By ▼ -0.25 (-1.85%)
TREET 22.16 Decreased By ▼ -0.57 (-2.51%)
TRG 55.59 Increased By ▲ 2.72 (5.14%)
UNITY 32.97 Increased By ▲ 0.01 (0.03%)
WTL 1.60 Increased By ▲ 0.08 (5.26%)
BR100 11,727 Increased By 342.7 (3.01%)
BR30 36,377 Increased By 1165.1 (3.31%)
KSE100 109,513 Increased By 3238.2 (3.05%)
KSE30 34,513 Increased By 1160.1 (3.48%)

ISLAMABAD: Hostile elements may launch cyber attack on the occasion of Independence Day, i.e., 14th August, 2023 for disruption of services and defacement to tarnish the global image of Pakistan, warned the National Telecommunications and Information Security Board (NTISB).

The Board has issued advisory, “Prevention against Website Compromise on the Eve of National Days” noted that hostile elements/ state-sponsored malicious actors typically target government departments/ ministries and defence sector websites on the eve of the National Days for disruption of services and defacement to tarnish the global image of Pakistan. It is likely that hostile elements may launch cyber attack on the occasion of Independence Day, i.e., 14th August, 2023.

FBR under cyber attack?

Accordingly, an advisory is being sent to sensitise website administrators and Service Providers to take additional security precautions (such as web server hardening, traffic/ integrity monitoring, etc.) to avoid possible website defacement/ hacking attempts. NTISB has issued 47 advisories in 2023 so far with respect to cyber-attacks, hacking, fraudulent/fake email, etc., and protection guidelines for individuals, government employees as well as websites.

Further, web server administrators should be made mindful of cyber security guidelines including; Cyber Security Best Practices for Websites Protection; (a) Upgrade OS and web servers to latest version; (b) Website admin panel should only be accessible via white-listed IPs; (c) Defend your website against SQL injection attacks by using input validation technique; (d) Complete analysis and penetration testing of application be carried out to identify potential threats; (e) Complete website be deployed on inland servers including database and web infrastructure; (f) HTTPS protocol be used for communication between client and web server; (g) Application and database be installed on different machines with proper security hardening; (h) Sensitive data be stored in encrypted form with no direct public access; (i) DB users privileges be minimized and limited access be granted inside programming code; (j) Proper security hardening of endpoints and servers be performed and no unnecessary ports and applications be used; (k) Updated Antivirus tools/ firewalls be used on both endpoints and servers to safeguard from potential threats; (l) Enforce a strong password usage policy; (m) Remote management services like RDP and SSH must be disabled in production environment; (n) Deploy web application firewalls (WAF) for protection against web attacks; (o) Employ secure coding practices such as parameterized queries, proper input sanitization and validation to remove malicious scripts (p) Keep system and network devices up-to-date; (q) Log retention policy must be devised for at least 3x months on separate device for attacker’s reconnaissance.

Comments

Comments are closed.