AIRLINK 195.60 Increased By ▲ 0.77 (0.4%)
BOP 9.80 Decreased By ▼ -0.01 (-0.1%)
CNERGY 7.31 Decreased By ▼ -0.05 (-0.68%)
FCCL 40.64 Increased By ▲ 2.06 (5.34%)
FFL 16.40 Decreased By ▼ -0.05 (-0.3%)
FLYNG 28.68 Increased By ▲ 1.14 (4.14%)
HUBC 132.62 Increased By ▲ 0.87 (0.66%)
HUMNL 13.95 Increased By ▲ 0.09 (0.65%)
KEL 4.65 Decreased By ▼ -0.01 (-0.21%)
KOSM 6.65 Decreased By ▼ -0.01 (-0.15%)
MLCF 46.40 Increased By ▲ 1.01 (2.23%)
OGDC 214.89 Increased By ▲ 0.90 (0.42%)
PACE 6.89 Increased By ▲ 0.03 (0.44%)
PAEL 40.50 Increased By ▲ 0.44 (1.1%)
PIAHCLA 16.70 Decreased By ▼ -0.09 (-0.54%)
PIBTL 8.41 Increased By ▲ 0.09 (1.08%)
POWER 9.84 Increased By ▲ 0.41 (4.35%)
PPL 183.50 Increased By ▲ 1.31 (0.72%)
PRL 42.01 Increased By ▲ 0.18 (0.43%)
PTC 24.75 Increased By ▲ 0.19 (0.77%)
SEARL 104.25 Increased By ▲ 1.72 (1.68%)
SILK 1.01 Increased By ▲ 0.01 (1%)
SSGC 39.59 Increased By ▲ 0.15 (0.38%)
SYM 17.42 Increased By ▲ 0.09 (0.52%)
TELE 8.77 Increased By ▲ 0.01 (0.11%)
TPLP 12.65 Decreased By ▼ -0.10 (-0.78%)
TRG 65.40 No Change ▼ 0.00 (0%)
WAVESAPP 11.15 Increased By ▲ 0.04 (0.36%)
WTL 1.71 Increased By ▲ 0.01 (0.59%)
YOUW 4.00 Increased By ▲ 0.06 (1.52%)
BR100 12,035 Increased By 61.6 (0.51%)
BR30 36,529 Increased By 382.1 (1.06%)
KSE100 113,611 Increased By 167.7 (0.15%)
KSE30 35,709 Increased By 73.9 (0.21%)

ISLAMABAD: Hostile elements may launch cyber attack on the occasion of Independence Day, i.e., 14th August, 2023 for disruption of services and defacement to tarnish the global image of Pakistan, warned the National Telecommunications and Information Security Board (NTISB).

The Board has issued advisory, “Prevention against Website Compromise on the Eve of National Days” noted that hostile elements/ state-sponsored malicious actors typically target government departments/ ministries and defence sector websites on the eve of the National Days for disruption of services and defacement to tarnish the global image of Pakistan. It is likely that hostile elements may launch cyber attack on the occasion of Independence Day, i.e., 14th August, 2023.

FBR under cyber attack?

Accordingly, an advisory is being sent to sensitise website administrators and Service Providers to take additional security precautions (such as web server hardening, traffic/ integrity monitoring, etc.) to avoid possible website defacement/ hacking attempts. NTISB has issued 47 advisories in 2023 so far with respect to cyber-attacks, hacking, fraudulent/fake email, etc., and protection guidelines for individuals, government employees as well as websites.

Further, web server administrators should be made mindful of cyber security guidelines including; Cyber Security Best Practices for Websites Protection; (a) Upgrade OS and web servers to latest version; (b) Website admin panel should only be accessible via white-listed IPs; (c) Defend your website against SQL injection attacks by using input validation technique; (d) Complete analysis and penetration testing of application be carried out to identify potential threats; (e) Complete website be deployed on inland servers including database and web infrastructure; (f) HTTPS protocol be used for communication between client and web server; (g) Application and database be installed on different machines with proper security hardening; (h) Sensitive data be stored in encrypted form with no direct public access; (i) DB users privileges be minimized and limited access be granted inside programming code; (j) Proper security hardening of endpoints and servers be performed and no unnecessary ports and applications be used; (k) Updated Antivirus tools/ firewalls be used on both endpoints and servers to safeguard from potential threats; (l) Enforce a strong password usage policy; (m) Remote management services like RDP and SSH must be disabled in production environment; (n) Deploy web application firewalls (WAF) for protection against web attacks; (o) Employ secure coding practices such as parameterized queries, proper input sanitization and validation to remove malicious scripts (p) Keep system and network devices up-to-date; (q) Log retention policy must be devised for at least 3x months on separate device for attacker’s reconnaissance.

Comments

Comments are closed.