This is default featured slide 1 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

Saturday, December 20, 2014

Instagram deletes millions of junk accounts

Photo-sharing app Instagram has removed millions of accounts believed to be posting spam, angering many legitimate users. Last week Instagram announced that it was going to crack down hard on spammers and fake accounts.

A mass campaign to unfollow the official Instagram account has ensued. In the past 24 hours the Instagram Instagram account has lost 30% of their following.

One social-media marketer said that it would be “chaos” and speculated that over 10 million accounts could be deleted.

Not all users are angry about the update however. Some are thankful that Instagram is leveling the playing field and trying to clean up junk accounts. By the end of December 2014, it should be fixed for the remaining members of the Instagram community.






“This can show which celebrity has THE REAL fans instead of a fan who made up a few accounts just to get their favorite celebrity many followers. Good job.”

Rapper Akon reportedly lost 56% of his followers in the cull.

The big losers were Justin Bieber (minus 3,538,228 followers), and an online marketing specialist called Wellington Campos, which lost 3,284,304 followers overnight.

One account, chiragchirag78, lost 99% of his followers - 3,660,460 - before he himself was deleted.

 Sam Pinto lost 14,000+ of his followers

Instagram's own account on the site lost 18,880,211 followers overnight.

 source:https://help.instagram.com/566399886839044





Friday, December 19, 2014

Facts About Balikbayan Box

 What is Balikbayan Box?

Balikbayan Boxes are packages of personal effects and/or “pasalubongs” sent by Filipinos residing or working abroad to their families or relatives in the Philippines to enhance Philippine tradition and culture for the promotion and preservation of strong family ties through love and caring expressed in gift-giving. A balikbayan box (Filipino luggage) is an ubiquitous corrugated box containing any number of small items and sent by an overseas Filipino known as a “balikbayan”. Though often shipped by freight forwarders specializing in balikbayan boxes by sea, such boxes can be brought by Filipinos returning to the Philippines by air.

The balikbayan box arose in the 1980s when Section 105 of the Tariff and Customs Code of the Philippines as amended by Executive Order No. 206 provides duty and tax free privileges to overseas foreign workers ( OFW ) enacted by former Philippine President Ferdinand Marcos due to resurgence of Filipinos working overseas.

The Philippine Bureau of Customs Circular allowed tax-free entry of personal goods in the country from Filipinos overseas. People then began sending items through friends and co-workers who were returning to the Philippines.



Balikbayan boxes may contain items the sender thinks the recipient would like, regardless of whether those items can be bought cheaply in the Philippines, such as non-perishable food, toiletries, household items, electronics, toys, designer clothing, or items difficult to find in the Philippines.

A balikbayan box intended for air travel is designed to conform to airline luggage restrictions and many Filipino stores sell them. Some boxes come with a cloth cover and side handles. Others are tightly secured with tape or rope, and thus not confused with an ordinary moving box that is lightly wrapped.


The balikbayan boxes come in four standard sizes:
  • Medium: 18 x 16 x 18 inches
  • Large: 18 x 18 x 24 inches
  • Extra large: 24 x 18 x 24 inches
  • Small  7 x 7 x 7 inches
Shipped boxes are delivered directly to the recipient, usually the family of the overseas Filipino.




1. WHAT ARE ALLOWED IN “BALIKBAYAN BOXES”?
Non-commercial goods or goods not in commercial quantity strictly for personal use only, such as: wearing apparel, clothing, foodstuffs/grocery items/canned goods; the value of which must not exceed US$500.00.

2. HOW OFTEN CAN FILIPINOS RESIDING OR WORKING ABROAD SEND A “BALIKBAYAN BOX” TO THEIR FAMILIES AND RELATIVES IN THE PHILIPPINES?
One consignor/sender is allowed to send one (1) box during a six (6) -month period.

3. WHAT IS A CONSOLIDATED DOOR-TO-DOOR SHIPMENT?
Two (2) or more balikbayan boxes from two (2) or more individual consignors/senders abroad, assembled and consolidated at one point of origin/exportation and shipped together under a single master ocean bill of lading or master airway bill by a freight forwarder/consolidator to its breakbulk/consolidator agent in the Philippines.

4. WHO IS ALLOWED TO CONSOLIDATE “BALIKBAYAN BOXES” ABROAD?
A foreign freight forwarding entity/ consolidator duly licensed and registered with the Philippine consular office.

5. WHO IS ALLOWED TO RELEASE A CONSOLIDATED DOOR-TO-DOOR SHIPMENTS FROM THE PHILIPPINE BUREAU OF CUSTOMS?
The Philippine agent/representative of a freight forwarder/consolidator named in a master bill of lading or master airway bill as consignee of a consolidated shipment duly licensed by the Philippine Shippers’ Bureau (PSB) of the Department of Trade and Industry (DTI).

6. ARE THE “BALIKBAYAN BOXES OPENED BY THE PHILIPPINE CUSTOMS?
Yes, a 100% examination of the consolidated shipment is required by law:
  1. To protect the legitimate interests of consignors/senders and their consignees, in particular, and the transacting public, in general;
  2. To protect the interest of the government;
  3. To prevent and suppress smuggling and other fraud upon customs.
7. WHERE CAN WE CHECK AND VERIFY THE LIST OF LEGITIMATE AND PHILIPPINE SHIPPERS’ BUREAU-ACCREDITED FREIGHT FORWARDERS/BROKERS?
Verification can be made with the Philippine Shippers’ Bureau (PSB) under the Department of Trade and Industry on their website: www.dti.gov.ph/consumerwelfare/accreditationoffreightforwarders/listofaccredited or by calling these numbers during office hours: (632) 7513304 or (632) 7513307, contact person: Mr. Jun Bernal.
8. WHO DELIVERS THE “BALIKBAYAN BOXES” TO THE ULTIMATE CONSIGNEES/RECIPIENTS?
The Philippine agent/representative of a freight forwarder/consolidator named in a master bill of lading or master airway bill as consignee of a consolidated shipment duly licensed by the Philippine Shippers’ Bureau (PSB) of the Department of Trade and Industry (DTI) and/or a local delivery company hired by the Philippine agent.
9. WHAT CAUSES THE DELAY/NON-DELIVERY OF THE BOXES TO THEIR ULTIMATE CONSIGNEES?
Any of the following can cause delays/non-delivery of “balikbayan boxes” to their ultimate consignees:
  1. Unforseen circumstances and/or natural calamity like typhoon that sets back the arrival of cargo carrying vessels;
  2. Consolidated shipments are tainted by:
    1. Undeclared and/or misdeclared goods;
    2. Banned or regulated cargoes like firearms and ammunitions, prohibited drugs, pornographic materials, gambling materials/apparatus;
    3. Goods in commercial quantity;
  3. Consolidated shipments that are abandoned by the Philippine agent/ representative/ broker for reasons of non-remittance of funds by the foreign freight forwarding entity/ consolidator.
10. ARE COMPLETELY-KNOCKED DOWN (CKD) MOTORCYCLES OR PART OF MOTOR VEHICLES (ALSO KNOWN AS CHOP-CHOP MOTORCYCLES OR VEHICLES) THAT ARE FOR PERSONAL USE, ALLOWED IN “BALIKBAYAN” BOXES?
No, these are not allowed in “Balikbayan” Boxes. These are not considered personal effects or household good and are thus treated differently; other documentary requirements are needed for these to be brought into the Philippines without which these vehicles cannot be registered with the land Transportation Office (LTO).

11.Do I have to pay customs tax?
Balikbayan box is for shipping personal (non-commercial) goods only and is not taxable with some exceptions.  Philippine customs may impose customs duty if they inspect your box and feel that your items are intended for resale. Electronic items and appliances are taxable. The recipient is responsible for paying customs duties.

Example:

Electronic items or appliances are considered taxable calculating additional taxes, please see the Electronic/Appliance Price Schedule as your guide.

Special Handling Item Handling Fees
Regular TV
TV 20″ or Below USD 46
TV 24″ to 27″ USD 46
TV 28″ to 32″ USD 69
TV 30″ to 46″ USD 140
LED/LCD
20″ to 21″ USD 140
25″ USD 230
29″ USD 262
30″ to 46″ USD 315
Microwave USD 24
Blu-Ray USD 22
VCR/VCD/DVD USD 13
Printer USD 24
Fax Machine USD 24
Stereo (Mini Comp) USD 35
A/C USD 35
Computer-CPU/Monitor/Kb/Mouse USD 69
Computer CPU only w/Mouse/Keyboard USD 24
Camera USD 15
Cellphone USD 13
SmartPhone USD 15
Home Theater USD 36
Laptop/Notebook/IPad/Tablet USD 46
LCD Monitor USD 46
2 Way Radio USD 15
Game Consoles (SONY/XBOX/Nintendo) USD 32
Handhelds (PSP/Nintendo DS) USD 17
Digital SLR Camera USD 32


* Other items not listed above which will be considered as electronic items will  be charged 40%-200% tax based on the invoice price.
* Electronic items or appliances are shipped at owner’s risk.  Shipper does not  assume liability for damages incurred in shipping these items.


Commercial Quantity – We cannot ship any items of the same  kind in commercial quantities.  Quantity of the same kind greater than 12 is considered commercial quantity. Considered Smuggling kapag more than 12 pcs

After the 9-11 event and the passing of Patriot Act, balikbayan boxes have been subjected to rigorous inspections by US Homeland Security Out-Bound Exam Team that caused massive delays that goes up to three weeks at US Customs inspection facility alone, plus the sailing time that was also extended from 21 days to 30 plus days. The inspections also resulted in opened packaging and complaints of mishandling. The Philippine Bureau of Customs also conducts 100% inspections that added to the burden of delayed shipments.

 ( My Bad Experience Customs and Air port after they open our package some item are missing  like 4 pair Nike Shoes , Chocolates and Perfumes . We just notice the lost item when we got home the other box  have no longer secured with blue tape and rope )

In 2014, this delays was further aggravated by the decision of the City of Manila to impose truck ban along the pier route causing backlogs in releasing and transporting not only balikbayan boxes but all cargoes, domestic and international. Most of the balikbayan box companies, which are based in Paranaque City close to the airport, are heavily affected by this as the truck ban starts from Port area to Roxas Blvd.


180 days of free storage from the time you purchased your first box item
There’s a storage fee of $5 per month after the 180th days



DTI UPDATE: Who receive balikbayan boxes from abroad: the Bureau of Customs (BOC) will no longer collect the import processing fee of P250 for packages arriving in the country’s ports.



BOC has waived the import processing fee for packages sent by sea freight through Customs Administrative Order (CAO) No. 08-2014 which took effect last 15 November.

No amount shall be collected as import processing fee on any importation filed through informal entry,” Commissioner John P. Sevilla said in the recent order.

The BOC shall cease to collect the import processing fee,” he added.

In the same order, he reduced the “amount of Documentary Stamp Tax for Informal Entry” from P265 to P15. He said that an amount of P15 shall be collected from each importation filed through the informal entry.

Around 5.5M balikbayan boxes are shipped to the country every year and the bulk enters the ports from September until yearend.

More than half of those packages enter the Manila International Container Port (MICP), while the rest arrive at the Port of Manila, Cebu, Davao and Subic.

The BOC has launched an online tracking system that will enable the recipients to check the status of their packages from abroad.

With the tracker, Sevilla said, “The public will not be given the run-around by people responsible for delivering their balikbayan boxes.”

Sevilla issued the CAO, approved by Finance Secretary Cesar Purisima, in pursuant to Section 608 and Sections 3301 and 3304 of the Tariff and Customs Code of the Philippines (TCCP), in relation to Section 36 of the Administrative Code of 1987.


Tuesday, December 16, 2014

Chrome Mark HTTP web pages as insecure

The Chromium Project's security team has marked all HTTP web pages as insecure and is planning to explicitly and actively inform users that HTTP connections provide no data security protections.
There are also projects like Let's Encrypt, launched by the non-profit foundation EFF (Electronic Frontier Foundation) in collaboration with big and reputed companies including Mozilla, Cisco, and Akamai to offer free HTTPS/SSL certificates for those running servers on the Internet at the beginning of 2015.

Google is taking initiative to encourage website owners to switch to HTTPS by default. Few months ago, the web Internet giant also made changes in its search engine algorithm in an effort to give a slight ranking boost to the websites that use encrypted HTTPS connections.




Posted on their blog post

Marking HTTP As Non-Secure

Proposal

We, the Chrome Security Team, propose that user agents (UAs) gradually change their UX to display non-secure origins as affirmatively non-secure. We intend to devise and begin deploying a transition plan for Chrome in 2015.

The goal of this proposal is to more clearly display to users that HTTP provides no data security.

Request

We’d like to hear everyone’s thoughts on this proposal, and to discuss with the web community about how different transition plans might serve users.

Background

We all need data communication on the web to be secure (private, authenticated, untampered). When there is no data security, the UA should explicitly display that, so users can make informed decisions about how to interact with an origin.



Roughly speaking, there are three basic transport layer security states for web origins:

  • Secure (valid HTTPS, other origins like (*, localhost, *));
  • Dubious (valid HTTPS but with mixed passive resources, valid HTTPS with minor TLS errors); and
  • Non-secure (broken HTTPS, HTTP).

For more precise definitions of secure and non-secure, see Requirements for Powerful Features and Mixed Content.

We know that active tampering and surveillance attacks, as well as passive surveillance attacks, are not theoretical but are in fact commonplace on the web.

Particulars

UA vendors who agree with this proposal should decide how best to phase in the UX changes given the needs of their users and their product design constraints. Generally, we suggest a phased approach to marking non-secure origins as non-secure. For example, a UA vendor might decide that in the medium term, they will represent non-secure origins in the same way that they represent Dubious origins. Then, in the long term, the vendor might decide to represent non-secure origins in the same way that they represent Bad origins.

Ultimately, we can even imagine a long term in which secure origins are so widely deployed that we can leave them unmarked (as HTTP is today), and mark only the rare non-secure origins.

There are several ways vendors might decide to transition from one phase to the next. For example, the transition plan could be time-based:

  1. T0 (now): Non-secure origins unmarked
  2. T1: Non-secure origins marked as Dubious
  3. T2: Non-secure origins marked as Non-secure
  4. T3: Secure origins unmarked

Or, vendors might set thresholds based on telemetry that measures the ratios of user interaction with secure origins vs. non-secure. Consider this strawman proposal:

  1. Secure > 65%: Non-secure origins marked as Dubious
  2. Secure > 75%: Non-secure origins marked as Non-secure
  3. Secure > 85%: Secure origins unmarked

The particular thresholds or transition dates are very much up for discussion. Additionally, how to define “ratios of user interaction” is also up for discussion; ideas include the ratio of secure to non-secure page loads, the ratio of secure to non-secure resource loads, or the ratio of total time spent interacting with secure vs. non-secure origins.

We’d love to hear what UA vendors, web developers, and users think. Thanks for reading! We are discussing the proposal on web standards mailing lists:



source: https://www.chromium.org/Home/chromium-security/marking-http-as-non-secure














Trojan on Pirated Assassins Creed app

Internet security firm ZScaler.com said the malware appears to target users of devices running Google's Android.

The malware in question will install a pirated version of the Assassins Creed game that functions normally, making end user oblivious to the malicious activities it performs in background.

The malicious application is capable of sending multi-part text messages, harvesting text messages from a victim's device, and sending stolen information to a remote Command & Control (C2) server. We were able to locate phone numbers belonging to Russian bank "Volga-Vyatka Bank of Sberbank of Russia" in the malicious application code for which SMS messages are being intercepted to steal sensitive information. 
Another interesting feature we saw is the usage of AES encryption for all the C2 communication. It also harvests the mobile number and Subscriber ID information from the victim device for tracking purposes.
Application information:
 Permissions:
android.permission.ACCESS_NETWORK_STATE
android.permission.GET_ACCOUNTS
android.permission.INTERNET
android.permission.PROCESS_OUTGOING_CALLS
android.permission.READ_EXTERNAL_STORAGE
android.permission.READ_PHONE_STATE
android.permission.READ_SMS
android.permission.RECEIVE_BOOT_COMPLETED
android.permission.RECEIVE_SMS
android.permission.SEND_SMS
android.permission.WAKE_LOCK
android.permission.WRITE_EXTERNAL_STORAGE
android.permission.WRITE_SMS


"The malware in question will install a pirated version of the Assassins Creed game that functions normally, making end user oblivious to the malicious activities it performs in background," it said.
"Upon installation, the user will see the game icon on the screen, that disappears shortly thereafter with the malicious process still running in the background," it added.
Zscaler said the app can send multi-part text messages and harvest text messages from a victim's device.
It can then send the stolen information to a remote Command and Control server.
Also, it can use AES encryption for all the command and control communication.
"It also harvests the mobile number and Subscriber ID information from the victim device for tracking purposes," it said.
The malicious app performs the activity of harvesting sensitive information and sending it to the remote server on a regular interval.

Recommendation:

Cybercriminals often lure users with pirated versions of popular paid mobile applications that are Trojanized to steal sensitive information. It is strongly recommended that users stay away from such offers and download mobile app only from the trusted sources like the Google Play store.






Monday, December 15, 2014

11,000 Wordpress websites infected with ‘SoakSoak Malware’

The news broke throughout the WordPress community earlier Sunday morning when Google blacklisted over 11,000 domains due to the latest malware campaign, that has been brought by SoakSoak.ru, thus being dubbed the ‘SoakSoak Malware’ epidemic.
While there are more than 70 million websites on the Internet currently running WordPress, so this malware campaign could be a great threat to those running their websites on WordPress.

The users of WordPress, a free and open source blogging tool as well as content management system (CMS), are being informed of a widespread malware attack campaign that has already compromised more than 100,000 websites worldwide and still counting.

Once infected, you may experience irregular website behavior including unexpected redirects to SoakSoak.ru web pages. You may also end up downloading malicious files onto your computer systems automatically without any knowledge.



The search engine giant has already been on top of this infection and has added over 11,000 websites to their blacklist that could have seriously affected the revenue potential of website owners, running those blacklisted websites.

The security team at the security firm Sucuri, which is actively investigating the potential vector of the malware, said that the infections are not targeted only at WordPress websites, but it appears that the impact seems to be affecting most hosts across the WordPress hosting spectrum.
SoakSoak malware modifies the file located at wp-includes/template-loader.php which causes wp-includes/js/swobject.js to be loaded on every page view on the website and this “swobject.js” file includes a malicious java encoded script malware.

If you run any website and are worried about the potential risk of the infection to your website, Sucuri has provided a Free SiteCheck scanner that will check your website for the malware. The exact method of intrusion has not been pointed out at this time, but numerous signals led to believe us all that many WordPress users could have fallen victim to this attack.

However, if you are behind the Website Firewall, CloudProxy, you are being protected from the SoakSoak malware campaign.

If you believe you are infected you can use our Free SiteCheck scanner, signatures have all been updated to detect the latest redirection



source: http://blog.sucuri.net/2014/12/soaksoak-malware-compromises-100000-wordpress-websites.html



Google Earth API, Google is withdrawing support for it.

Google Maps API product manager Ken Hoetmer said the current API is based on the aging NPAPI plugin framework, which will no longer be supported by Chrome and Firefox.
 
"(A)fter careful consideration, we have decided to retire the Google Earth API. Per our deprecation policy, the API will be supported until one year from today and will be turned off on December 12, 2015," Hoetmer said.
 
"Google Earth has a proud legacy, which continues with the new Google Earth for Android, powered by a brand new renderer. 3D is in our blood, and while we can’t announce anything just now, we look forward to sharing more exciting product news in the future," he added.
 
 
 
He noted the API was introduced in 2008, and allowed developers to build rich 3D mapping applications in the browser using JavaScript.
 
But he also cited security issues with the NPAPI-based plugins, as well as "dwindling" cross-platform support for them, especially on mobile devices.
 
During the one-year period before shutdown, suppored browsers include:
 
  • Microsoft Windows (XP, Vista, 7, and 8)
  • Google Chrome 5.0-39.0 (32-bit)
  • Internet Explorer 7-9, and 10-11 with Compatibility View (32-bit)
  • Firefox 11.0-34.0
  • Apple Mac OS X 10.6 or later (any Intel Mac)
  • Google Chrome 5.0-39.0 (32-bit)
  • Safari 3.1+
  • Firefox 11.0-34

source: http://googlegeodevelopers.blogspot.com/2014/12/announcing-deprecation-of-google-earth.html