Lebanon lax Web security allows easy hacking, cyber attacks

Lebanon: With a few clicks, Hussein Hazimeh demonstrates how he can go onto a local company’s website and pay $1 for a $300 product. “Compared with other countries, the major ISPs (Internet service providers) in Lebanon are vulnerable to attacks.

 
They have weak coding for Web applications,” says the second-year American University of Beirut computer engineering student as he sits at an outdoor cafe with his laptop, sifting through local websites and pointing out their various security flaws.

Now working on a school research project on hacking, Hazimeh started using his skills at the age of 12 to cheat in online games and test the vulnerability of local websites, which he learned through online forums and YouTube videos.

In the past 10 years, he believes that not much has changed in terms of online security in Lebanon.

Today, the majority of company websites in Lebanon are hosted overseas for security reasons: The country’s low credit card penetration is in part due to a public perception of low online security for financial transactions; and public sector websites, which had planned to begin e-government at least 10 years ago, have yet to offer such services to their citizens.

Because of this, or perhaps in spite of it, in April the hacker organization Raise Your Voice attacked 16 government websites, replacing the homepages with a caricature of “The people,” an emaciated man in a cloth diaper spoon-feeding “The government,” an overweight man in a suit.

While the message was clearly to show an incompetent and indulgent government role in alleviating poverty, perhaps an inadvertent one was also to show the country’s lack of Internet security at key ministries.

Of course, there’s no such thing as total Internet security. But this is even truer in Lebanon than many other countries, experts say.

There are several types of IT security breaches. Hackers can attack the computer system (i.e., laptop, PC, server, smartphone), the website of the victim, or the data sent by the victim over the network. They can then can violate the confidentiality of information and modify or delete information, and in some cases steal money. However, the most high-profile type is when well-known websites are hacked.

“The majority of websites in Lebanon are done by amateurs,” says Haidar Harmanani, a computer science professor at the Lebanese American University.

“In Lebanon, people haven’t realized the importance of web programing and applications. They think anyone can do it. They’re not willing to pay the money for a proper company, so they end up hiring amateurs to do websites.”

These include both government and private sector websites, where he says Web developers tend to be hired on their low bid, rather than their security qualifications.

However, one institution that has paid special attention to its online security is the banking sector, the backbone of the Lebanese economy renowned for its customer secrecy.

At IBL (the Intercontinental Bank of Lebanon), IT manager Elie Hlayel says they use two anti-virus systems in place, in addition to a firewall and a twice-a-year Web IT vulnerability assessment from an outside security company.

He adds that because of security concerns no Lebanese bank currently allows its customers to transfer money outside the country electronically, although foreign banks such as HSBC in Lebanon are able to do so.

“In Lebanon, we have a security agreement with clients. If we don’t have good security, customers would be vulnerable,” Hlayel explains. “Right now, Lebanon is the only country in the region with [this level of] banking secrecy.”

Still, in general, companies, particularly smaller ones, tend to pay the lowest bidder to develop their websites, leaving aside security considerations, say experts.

“If you don’t appreciate the importance of technical know-how behind building a website, there’s no way you could justify paying $5,000 and not $500,” Harmanani says.

But that might change soon as more security vulnerabilities are exposed, and as people’s daily lives become more digital. As LAU computer science professor Azzam Mourad notes, with our increasing usage and dependence on technology, including mobile phones that are essentially handheld computers, both the number of attacks and the level of sophistication will rise.

“4G will be like having a computer on your phone. With open communication, there are more threats,” Mourad says. “Everything is now done on the Internet. It used to be that tens of thousands of people could attack. Now millions can.”

With both the public and private sectors likely to continue facing tight budgets for the foreseeable future, and with a low public opinion of the government, we will see more security breaches, say experts.

But Harmanani believes there are still things Lebanon can do, including raising awareness through the government and education and through companies doing security audits, as they do in Europe and the U.S.

As for the hacked government websites, “I like it when hackers do that. It sends a strong message about security. In this case there was a nice social message. It shows the frustration of the youth with Lebanese government.”

For now, at least, he’s not too worried about the security breach. “I don’t think there was much data on those [government] websites anyways.” Source: zawya.com

Add comment

Login or register to post comments
  • 09-Jun-2012 09:53
  • Haider Awan
  • Insight, Lebanon
  • Event Date
    «  

    May

      »
    S S M T W T F
     
     
     
     
    1
     
    2
     
    3
     
    4
     
    5
     
    6
     
    7
     
    8
     
    9
     
    10
     
    11
     
    12
     
    13
     
    14
     
    15
     
    16
     
    17
     
    18
     
    19
     
    20
     
    21
     
    22
     
    23
     
    24
     
    25
     
    26
     
    27
     
    28
     
    29
     
    30
     
    31
     
    Add to calendar
     
     
    More IT INSIGHTme

     

     

    IT

    المعارضة السورية : "فيسبوك تآمر مع النظام علينا"

    قام موقع التواصل الاجتماعي "فيسبوك" بإغلاق عدد كبير من صفحات المعارضة السورية التي تنشط على الموقع.

    جوجل توفر البحث الصوتي على متصفح "كروم"

    أعلنت جوجل عن توفيرها خدمة البحث الصوتي على متصفحها الشهير "كروم" بالإصدار رقم 27.

    تحذير : مايكروسوفت تحتفظ بجميع المراسلات النصية على "سكايب"

    كشف عدد من خبراء أنمن الانترنت أن شركة "مايكروسوفت" تقوم بفحص جميع المحادثات المكتوبة على برنامج الدردشة الشهير "سكايب"ن للتأكد من خلوها من أي برامج خبيثة أو فيروسات.

    KSA plans Gulf e-govt network

    The government is planning to build an electronic governance network that will link the Gulf Cooperation Council members to one another and also include a unified traffic system. 
    The United Arab Emirates (UAE), however, has expressed some reservations regarding certain articles in the proposed system, pointing out that it interferes with its national policies. Accordingly, the UAE has called for the amendment of three articles in order for it to acquiesce to the new unified traffic system.

    Telecom

    غيرة آبل تدفعها إلى ضم "جالاكسي إس 4" إلى مجموعة الأجهزة التي تحاربها في المحاكم

    قامت آبل اليوم بضم الهاتف جالاكسي إس4 لقضية براءات الاختراع التي رفعتها مؤخراً على شركة سامسونج الكورية.

    الإعلان عن الهاتف الجديد "إتش تي سي ديزاير 600" الداعم لشريحتي اتصال

    كشفت شركة "إتش تي سي" التايوانية عن هاتفها الجديد "إتش تي سي ديزاير 600"، بمعالج رباعي النوى بسرعة 1.2 جيجاهرتز وسعر مناسب للميزانيات المتوسطة.

    Tecom Investments announces new structure

    Renewed focus on its core business of developing and operating business parks
    Tecom Investments, a subsidiary of Dubai Holding, has announced a new operational structure, which will allow the company to further focus on its core business of developing and operating business parks.

    The implementation of a new structure comes at a time when the region's macroeconomic fundamentals are increasingly positive, offering an opportunity for Tecom Investments to ensure it is strongly positioned to capitalise on Dubai's future growth prospects.

    GSMA PUTS THE CONNECTED CITY AT THE HEART OF MOBILE ASIA EXPO 2013

    London: At Mobile Asia Expo 2013 in Shanghai, t

    Media

    Spiky sales patterns impact UAE retail channel

    The UAE retail channel for ICT and consumer electronics (CE) products is witnessing increasingly spiky sales patterns, experiencing major peaks and troughs from one month to the next, as the impact of specific sales events exacerbates market volatility. The UAE retail channel has already experienced Dubai Shopping Festival (DSF) and Abu Dhabi Electronics Shopper in 2013, and the inaugural Gitex Shopper Spring – dubbed mini-Gitex by some vendors – is currently taking place in Dubai.

    Jacky’s Electronics sees Gitex Shopper Spring Edition fuelling sales across all IT categories

    Jacky’s Electronics, the UAE’s leading multi-brand consumer electronics retailer, is expecting a surge of product sales, from the usual off-peak period during the month of April, brought in by the four-day event of the first Gitex Shopper Spring Edition.

    du Live! presents Kadim Al Saher and Sherine at 3rd du World Music Festival

    du Live! is pleased to present two of the Arab world’s most-loved musicians, Kadim Al Saher and Sherine, live on stage as part of the 3rddu World Music Festival! They will perform on 28 March at Dubai Media City Amphitheatre.

    Gadgets

    ZOTAC Supercharges the TITAN

    Dubai, UAE, May 2, 2013 – ZOTAC International, a global innovator and manufacturer of graphics cards, mainboards, mini-PCs and accessories, today supercharges the TITAN with the ZOTAC GeForce GTX TITAN AMP! Edition, the world’s fastest single GPU graphics card.

     

    Robocops to patrol LA by 2025

    In 1987, the film RoboCop debuted and featured a half-man half-robot cop patrolling the streets of Detroit, but now some car companies are planning on replacing cop cars in Los Angeles with drone cars by 2025.

    Saudi prince buys $485 million ‘flying palace’

    Dubai: Saudi billionaire Prince Al Waleed Bin Talal will soon take delivery of the world’s first customised A380 superjumbo, dubbed “the flying palace” for its luxury.

    Insight

    BYOD: Keep Your ‘Eyes on the Enterprise’

    Article Author: Paul Wright, manager of professional services and investigation team, Middle East, India and Africa

    Comguard unveils world’s most rugged and powerful firewall in Middle East

    Comguard, a Dubai based leading value added distributor for IT products and part of the Spectrum group announced the launch of world’s most rugged and powerful firewall, the Clavister X8 which can withstand harsh, industrial environments to deliver outstanding performance, offering unified security management between office environment and industry environment.

    IT INSIGHT-me (ITINme) at MWC 2013.....

    IT has been an enabler all along and now it is playing the same role in the mobile domain. Hence expect other verticles to be represented at the MWC 2013... in addition to the usual vendors, operators watch out for new buzz words such as big data, mobile cloud, mWallets, NFC, small cells and smart cities, as well as the role of mobile in other industries like advertising, automotive (YES cars), finance and retail.

    Smartphones galore this holiday season

     

    SAMSUNG GALAXY S III
    Samsung Electronics flagship product – Galaxy S3 – is powered by 1.4GHz quad core Exynos processor and features 1GB of RAM.

    People

    Wataniya names new CEO

    DOHA: Ooredoo subsidiary Wataniya Telecom's current Deputy CEO Abdulaziz Fakhroo has been appointed as CEO for Wataniya Telecom, replacing Dr Bassam Hannoun who has resigned for personal reasons. Ooredoo Group Chairman Sheikh Abdullah bin Mohammed bin Saud Al Thani said:

    "We thank Dr Hannoun for his contribution during his tenure. We look forward to having Abdulaziz lead Wataniya Kuwait as it enters an exciting new phase in its development including the launch of 4G services this year." Source:http://www.zawya.com

    Huawei appoints regional VP for ME Device group

    China-based telecoms equipment maker Huawei today announced the appointment of Ashraf Fawakherji to the newly created role of regional vice president, Middle East for Huawei's consumer business group Huawei Device.

    Hire a professional company to get the best landscape designs

    Springs are considered as the best landscaping season. This is the time when homeowners and office bearers shape up their surroundings to refresh themselves with flowers and gardens, refill the backyard ponds and enhance their lawns. However, people who do not have experience in handing these things on their own best option to rely on the option of calling the landscape architects Raleigh NC at their places. The fact is even the seasoned DIY landscaper could also benefit from the professionals to make their places from better to the best.

    AlcaLu names former Vodafone exec as new CEO

    Troubled network vendor Alcatel-Lucent has announced that former Vodafone exec Michel Combes will become its new CEO from April 1. Combes will replace Ben Verwaayen, who announced his resignation earlier this month after failing to deliver a turnaround at the company.
    Combes, 51, recently spent four years (2008-2012) as CEO of Vodafone Europe. He had been named to take over as chief executive of Vivendi’s SFR last year, France’s second-biggest mobile operator, but the appointment was aborted after a management shake-up at the parent company.