Alaa Kharfan, a senior sales engineer with Trend Micro, says it is to hack a computer using a tool that is easy to find online. Pawan Singh / The National
Alaa Kharfan, a senior sales engineer with Trend Micro, says it is to hack a computer using a tool that is easy to find online. Pawan Singh / The National

Log on but be on your guard



On a sunny Tuesday morning last month, Alaa Kharfan was sitting at his laptop, scrolling down a list of possible cyberattacks he could unleash.

After dismissing a "spear-phishing attack", as well as a run-of-the-mill website-cloning scam, he settled on a social-engineering attack.

But Mr Kharfan is not a hacker. He is a senior sales engineer with Trend Micro, a global computer security company with a branch in Dubai. And he was demonstrating during a workshop just how easy it is to hack a computer using a tool that is easy to find online and free to download.

The programme, which is designed to help IT administrators check the vulnerabilities of a network, includes a list of commands that take people step-by-step through the process of hacking into a computer.

"They have a kit for social engineering," says Mr Kharfan.

This week, Gulf Air from Bahrain posted a notice online advising its customers that its official Facebook page had been hacked.

"Right now, the page is not under our control, so kindly ignore any messages, videos or pictures that may be posted," the airline warned.

Estimates for the prevalence of cyberattacks in the UAE range widely.

One hundred phishing attacks were registered in the Emirates last year, with 72 of them conducted against banks, according to aeCERT, an agency tasked with overseeing internet security in the country.

But IT Matrix, an online anti-fraud company, said it detected 1,145 unique phishing attacks in the UAE in 2010, the most in the Arab world.

Some cybercriminals use "bots" to perform automated tasks such as sending spam emails.

"If you want to bring down a website, you fire up these machines and get them to send a mail bomb to a specific website," says Nick Black, the senior technical manager with Trend Micro.

That means spam is more than just irritating. "It is really the vehicle to deliver malicious content," says Mr Black.

One spam emailpurporting to be from the social-networking site Facebook recently urged people to follow a link and update their accounts. It prompted them unwittingly to install a Trojan horse virus designed to steal bank account details.

Digital security companies may not be quick to advertise this to consumers, and antivirus software will not always pick up the problem.

Even spam that claims to include a link to a website that turns out to be a harmless-looking advertisement can be more sinister than it appears.

Some spam emails of this type include malicious computer code that gives cybercriminals permission to access a computer to steal information or even capture video footage of the user through his or her own camera.

But the most frightening part may be how easy it is to hack into someone's computer.

Last year, a hacker infiltrated the US-based computer security firm RSA. The hacker sent out an email called "2011 Recruitment Plan" that was automatically marked as junk. That fooled an RSA employee into opening it, thereby installing a virus in the company's network, allowing the hacker to do anything remotely that employees could do locally.

Back in Dubai last month, Mr Kharfan cloned a Facebook log-in page during his workshop. The cloned page was used as a link in a message saying "please check this out on Facebook".

Those who followed the link would enter their log-in details, which then appeared in the programme Mr Kharfan was using.

In the UAE, organisations such as aeCERT work to raise security awareness, "a never-ending exercise", says Ahmad Hassan, who heads research and analysis at aeCERT.

So how can people best protect themselves?

Strong passwords are a must, Mr Hassan advises.

"Another method is the use of antivirus [software] and regularly updating it," he suggests. "New viruses are developed all the time."

And people should always install the latest security updates and patches to their operating systems and programmes.

"These updates fix weak points in the computers that the hackers make use of to perform their attacks," he says.

twitter: Follow our breaking business news and retweet to your followers. Follow us

Key facilities
  • Olympic-size swimming pool with a split bulkhead for multi-use configurations, including water polo and 50m/25m training lanes
  • Premier League-standard football pitch
  • 400m Olympic running track
  • NBA-spec basketball court with auditorium
  • 600-seat auditorium
  • Spaces for historical and cultural exploration
  • An elevated football field that doubles as a helipad
  • Specialist robotics and science laboratories
  • AR and VR-enabled learning centres
  • Disruption Lab and Research Centre for developing entrepreneurial skills
MATCH INFO

Asian Champions League, last 16, first leg:

Al Jazira 3 Persepolis 2

Second leg:

Monday, Azizi Stadium, Tehran. Kick off 7pm

The specs
Engine: 4.0-litre flat-six
Power: 510hp at 9,000rpm
Torque: 450Nm at 6,100rpm
Transmission: 7-speed PDK auto or 6-speed manual
Fuel economy, combined: 13.8L/100km
On sale: Available to order now
Price: From Dh801,800
Brown/Black belt finals

3pm: 49kg female: Mayssa Bastos (BRA) v Thamires Aquino (BRA)
3.07pm: 56kg male: Hiago George (BRA) v Carlos Alberto da Silva (BRA)
3.14pm: 55kg female: Amal Amjahid (BEL) v Bianca Basilio (BRA)
3.21pm: 62kg male: Gabriel de Sousa (BRA) v Joao Miyao (BRA)
3.28pm: 62kg female: Beatriz Mesquita (BRA) v Ffion Davies (GBR)
3.35pm: 69kg male: Isaac Doederlein (BRA) v Paulo Miyao (BRA)
3.42pm: 70kg female: Thamara Silva (BRA) v Alessandra Moss (AUS)
3.49pm: 77kg male: Oliver Lovell (GBR) v Tommy Langarkar (NOR)
3.56pm: 85kg male: Faisal Al Ketbi (UAE) v Rudson Mateus Teles (BRA)
4.03pm: 90kg female: Claire-France Thevenon (FRA) v Gabreili Passanha (BRA)
4.10pm: 94kg male: Adam Wardzinski (POL) v Kaynan Duarte (BRA)
4.17pm: 110kg male: Yahia Mansoor Al Hammadi (UAE) v Joao Rocha (BRA

BUNDESLIGA FIXTURES

Saturday (UAE kick-off times)

Cologne v Union Berlin (5.30pm)

Fortuna Dusseldorf v Borussia Dortmund (5.30pm)

Hertha Berlin v Eintracht Frankfurt (5.30pm)

Paderborn v Werder Bremen (5.30pm)

Wolfsburg v Freiburg (5.30pm)

Bayern Munich v Borussia Monchengladbach (8.30pm)

Sunday

Mainz v Augsburg (5.30pm)

Schalke v Bayer Leverkusen (8pm)

Electric scooters: some rules to remember
  • Riders must be 14-years-old or over
  • Wear a protective helmet
  • Park the electric scooter in designated parking lots (if any)
  • Do not leave electric scooter in locations that obstruct traffic or pedestrians
  • Solo riders only, no passengers allowed
  • Do not drive outside designated lanes
Formula Middle East Calendar (Formula Regional and Formula 4)
Round 1: January 17-19, Yas Marina Circuit – Abu Dhabi
 
Round 2: January 22-23, Yas Marina Circuit – Abu Dhabi
 
Round 3: February 7-9, Dubai Autodrome – Dubai
 
Round 4: February 14-16, Yas Marina Circuit – Abu Dhabi
 
Round 5: February 25-27, Jeddah Corniche Circuit – Saudi Arabia
The White Lotus: Season three

Creator: Mike White

Starring: Walton Goggins, Jason Isaacs, Natasha Rothwell

Rating: 4.5/5

PROFILE OF SWVL

Started: April 2017

Founders: Mostafa Kandil, Ahmed Sabbah and Mahmoud Nouh

Based: Cairo, Egypt

Sector: transport

Size: 450 employees

Investment: approximately $80 million

Investors include: Dubai’s Beco Capital, US’s Endeavor Catalyst, China’s MSA, Egypt’s Sawari Ventures, Sweden’s Vostok New Ventures, Property Finder CEO Michael Lahyani