레이블이 mail인 게시물을 표시합니다. 모든 게시물 표시
레이블이 mail인 게시물을 표시합니다. 모든 게시물 표시

2016년 5월 27일 금요일

Gmail SMTP에 대해서 SSLv3/RC4 지원 중단

카페 > 뉴딜코리아 홈페이지 | 뉴딜코리아
http://cafe.naver.com/rapid7/2463


 Gmail SMTP에 대해서 SSLv3/RC4 지원 중단



2016년 6월 6일
Disabling support for SSLv3 and RC4 for Gmail SMTP in 30 days

Last September, we announced plans to no longer support two very old security systems called SSLv3 and RC4. As mentioned in Adam Langley’s announcement, these systems are no longer secure and pose a risk to those still using them:

SSLv3 has been obsolete for over 16 years and is so full of known problems that the Internet Engineering Task Force (IETF) has decided that it must no longer be used.

RC4 is a 28-year-old cipher that has done remarkably well, but is now the subject of multiple attacks at security conferences. The IETF has decided that RC4 also warrants a statement that it too must no longer be used.

Because of these issues, after June 16, 2016, we will disable both SSLv3 and RC4 support at Google’s SMTP servers and on Gmail’s web servers.


▶ If you are still using SSLv3 or RC4: 


. 사용중인 SSLv3 및 RC4를 중지 하고 최신 TLS 구성으로 업데이트
 
  Most organizations on Google Apps have already stopped using SSLv3 and RC4; however, if you are still on these older systems, we recommend reviewing the suggested actions in the Security Blog announcement and updating to modern TLS configurations.

  Some common systems that may still be using SSLv3: inbound/outbound gateways, third-party emailers, and systems using SMTP relay.

 

이후는 SSLv3 and RC4 이용한 Google’s SMTP servers 접속이 제한됩니다
  
 After this change, servers sending messages via SSLv3 and RC4 will no longer be able to exchange mail with Google’s SMTP servers, and some users using older and insecure mail clients won't be able to send mail.

More InformationDisabling SSLv3 and RC4


2016년 4월 11일 월요일

이메일 피싱 캠페인을 통한 핑싱 공격 방어 | 메타스플로잇(Metasploit)

카페 > 뉴딜코리아 홈페이지 | 뉴딜코리아
http://cafe.naver.com/rapid7/2341

Combating Phishing Attacks

How to Design an Effective Program to Protect Your Organization
Against Social Engineering
오늘날의 데이터 침해의 대부분은 외부에 악성코드를 포함된 피싱 이메일로 시작한다 ~
이것은 기업이 가정 먼저 해결해야 할 문제 이다 ~
​


이메일 방어 훈련 및 모의 침투 Test 수행
 뉴딜딜코리아 컨설팅사업부 (070-7867-3721, ismsbok@gmail.com)

Most of today’s data breaches start with a phishing email, giving company-confidential data to malicious outsiders.

This is a real problem that companies need to address. Phishing attacks are the most frequently used form of social engineering.

They work because they take advantage of cognitive biases, or how people make decisions. These techniques prey on human emotion by appealing to greed, curiosity, anxiety or trust. Phishing means that attackers are fishing for your private information.

Attackers attempt to acquire information such as usernames, passwords, and credit card details by masquerading as a trustworthy entity in an electronic communication.

Many times this is done to steal a victim’s login credentials and other confidential information. Phishing continues to grow and become more widespread with attacks up 37% year over year, and 1 in every 300 emails on the web containing elements pointing to phishing.

1 So, how can you combat phishing attacks and protect your company and its employees?

This paper will discuss the problem of social engineering and phishing along with its consequences, and will outline approaches for solutions to safeguard your organization.


 웹비나 동영상  :