Showing posts with label hacking news. Show all posts
Showing posts with label hacking news. Show all posts

Friday, 9 May 2014

Get job at the NSA by cracking coded tweets

Decode NSA Tweet to get a job
 It is known that job applicants can extremely ingenious when it comes to finding new ways to make their CV’s stand out of the crowd but it’s not that common to hear about unconventional methods when it comes to employers methods of hiring.

This is the case of the National Security Agency (NSA) which are interested in hiring people with outstanding potential. Their method is at least interesting as they cut off the classic process: the typical job application, the CV and the covering letter. These been said, you might ask yourself how could you take a shot at a job at NSA.

Your answer awaitson Tweeter as NSA posted last night onits @NSACareers account a tweet containing a series of what seemed at first sight random letters and spacing followed by the hashtags #MissionMonday #NSA #News. At first this lead to confusion, some users even suggested that he feed was hacked or maybe an employee played a prank.

Later, the NSA confirmed the tweet and stated that it was part of a month long campaign of coded tweets to “explore careers essential to protecting our nation”. “As part of our recruitment efforts to attract the best and the brightest, we will post mission related coded Tweets on Mondays in the month of May” an NSA representative said. Well, NSA is known as the code makers and code breakers.

Within minutes after the tweet was posted, the code was cracked and translated simply as: “Want to know what it takes to work at NSA? Check back each Monday in May as we explore career essentials to protect our nation.”

The puzzles are expected to get harder in the coming weeks. Those who are able to crack the most complex codes are likely to be of interest to the NSA’s recruiters.

Wednesday, 22 January 2014

23-Tear-old Russian Hacker admitted to be unique creator of Blackpos Malware

Russian Hacker
 In the past reports of Cyber Intelligence firm "Intelcrawler" named Sergey Tarasov, a 17-year-old teen behind the handle "ree[4]", as the designer of Blackpos malware.

Blackpos otherwise called "reedum" or "Kaptoxa" is a viable crimeware unit, utilized as a part of the huge heist of perhaps 110 million shoppers' Credit-Debit cards, and individual data from the TARGET.

Later Researchers' examination uncovered that the definitive coder of Blackpos Malware was really a 23-year-old junior programmer named Rinat Shabayev and the youngster, Sergey Taraspov is the incharge for the specialized help office.

In a meeting with Russian channel 'Lifenews', Rinat Shabayev conceded that he had advanced the Blackpos crimeware unit. He elucidated that the system advanced by him was not implied for any sort of information robbery, rather the project was composed for the security testing.

He advanced the malware with the assistance of an alternate programmer with unknown character, whom he had met on the web. His unique arrangement was simply to offer the adventure, not to utilize it for pernicious aim without anyone else present.

His companion took the readymate codes from him and added more characteristics to it. Notwithstanding this data, he additionally admitted that the endeavor could be utilized for malignant purposes as well.

Analysts at Intelcrawler say that the same malware may have likewise been included in the Neiman Marcus ambush as well.

Whatever be the expectation of the programmer, however now more than 110 million individuals are enduring Visa burglary on account of his programming. Significantly in the wake of realizing that the malware has capability to order an enormous fiscal robbery, his supports are insufficient to be guiltless.

Monday, 13 January 2014

How to hack a Wireless DSL Router, Exploit posted online


Hack Wireless DSL Router

A hacker from France named “Eloi Vanderbeken”found a way to hack NetGear and Linksys wireless routers on Christmas, and as well as, he distributed that secret exploit in public also.
The secret exploit allows an attacker to change the admin panel password to default without any admin authentication.

Eloi forgot his Linksys WAG200G router’s password and was trying to crack that , he scanned that and found a suspicious open TCP port. He researched on the part deeply and downloaded the copy Linksys firmware and then reverse-engineered that.

After a research 0n that port, he found that was a secret backdoor that allows anyone to send commands on admin basis without admin authentication. Well, it’s a cool exploit for- who really forgot the password, but may be dangerous for them where- Near-by “Hackers situated.”

 Eloi tried to describe you what and how he found the secret exploit, below are the routers which are affected by the Exploit:
  • Cisco RVS4000 fwv 2.0.3.2
  • Cisco WAP4410N
  • Cisco WRVS4400N
  • Cisco WRVS4400N
  • Diamond DSL642WLG / SerComm IP806Gx v2 TI
  • LevelOne WBR3460B
  • Linksys RVS4000 Firmware V1.3.3.5
  • Linksys WAG120N
  • Linksys WAG160n v1 and v2
  • Linksys WAG200G
  • Linksys WAG320N
  • Linksys WAG54G2
  • Linksys WAG54GS
  • Linksys WRT350N v2 fw 2.00.19
  • Linksys WRT300N fw 2.00.17
  • Netgear DG834[, GB, N, PN, GT] version < 5
  • Netgear DGN1000
  • Netgear DGN1000[B] N150
  • Netgear DGN2000B
  • Netgear DGN3500
  • Netgear DGND3300
  • Netgear DGND3300Bv2 fwv 2.1.00.53_1.00.53GR
  • Netgear DM111Pv2
  • Netgear JNR3210
May be affected:
  • all SerComm manufactured devices
  • Linksys WAG160N
  • Netgear DG934 probability: probability: 99.99%
  • Netgear WG602, WGR614 (v3 doesn’t work, maybe others…)
  • Netgear WPNT834
Here is the Exploit code, if you are looking for, and you can find a detailed list of routers which are affected or not HERE.

Thursday, 19 December 2013

Nowadays it’s easy to hack a website in just four steps

Hackers (extremexploit.com)

Till yesteryears it required Tech Geeks to have an above average knowledge to hack a website but these days it has become a child’s play. Like conventional searches, you can Google out the tools required to plan a Hack-Attack on a website and with a little effort you can execute the same with ease. Here it is, in 4 easy steps, how hackers execute it.

Step 1: Identifying

The Hacktivists first identify their target website which they want to attack upon. They first qualify the website, according to the vulnerability level, they wish to attack. Checking the vulnerability of the website allows the hacker to prepare tools and techniques required to bring down the website.

Hackers generally use Google Dork, or Google Hacking, to execute a vulnerability check against these easy-to-hack websites. It was very recent that a hacker posted a list of 5,000 such websites which were really easy to be attacked. If they don’t wish to Google it out, they can Bing it. This tool is heaven for hackers as it helps in qualifying such websites.

Hackers have a ready-to-refer index of Dorks which points out the websites having a particular vulnerability. Right from passwords to Login credentials, there is Dork available for everything. They would Google “intitle:”Index of” master.passwd” which will return them a file containing the passwords and then they have the list of potential victims ready with them to execute the hack.

Step 2: Spotting the vulnerabilities

Acunetix – a Windows based application to test the website – developed by a UK based company, was designed and is still in prominent use by developers to test the vulnerabilities in the website, but the technical expertise of hackers to this tool allows them access to point out the weakness levels of the website. Once the site is identified for attack, this tool is used by hackers to check the vulnerability of the website, as all websites qualified in level 1 may not be susceptible to attack.

Since the hackers have in-depth knowledge of the above mentioned software, they can not only crack the version from a trial one, but the cracked version is also available freely amongst the hacker community. Once they enter the URL or website address in this software they are able to point out the loopholes in the website and all they do is, move to step 3.

Step 3: The Attack on the website – SQL Injection

The SQL injection is the easiest and the most used way by hackers to hack into a website. It is used by hackers to hack into user accounts and steal information stored into its databases. This attack aims at information stealing using some lines of code of SQL (Structured Query List) which is a database programming language. The hacker’s don’t even have to learn the language for this attack, as there is an available software called “Havij” in the hacker forums where it is available free of cost. It comes as an easily useable application. Havij is originally a development from Iran. The word itself means carrot, a bad-slang for the word penis, ultimately meaning that the hack-ware helps penetrating a website.

Havij has 2 versions – paid and unpaid, both of them differential in powers of penetrating, although the paid version can be cracked and downloaded from other hacker forums. The interface of this software completely simple like any other windows application, which does its work when a newbie hacker just copies the link of the website needed to hack and pastes it into the application.

The tasks Havij can perform are very surprising. The best one for them and worst for the users of the website is called “Get”. It fetches all the data stored in the target website’s databases which range from usernames, passwords to phone numbers and bank details.

It is so easy for hackers that within a couple of minutes of their time, in which they can search, download, and use one or two automated hack-wares that allows them to access websites which are vulnerable to such attacks. Very much assured, that the websites of high profile companies like Google, Microsoft and Facebook are completely safe from such tools. As mentioned before, the vulnerability of the web is displayed by the attack made on Sony’s PlayStation Network which led to the leaking of their customers’ personal information in a very similar way.

Step 4: The DDoS – The A Game

SQL Injection has been used by the infamous hacktivist community – Anonymous for over a year now, but they tend to go forth with the DDoS when simple tools like the Havij don’t work. Again like the SQL (pronounced Sequel) Injection attack there are freely available tools for the DDoS as well.

As it appears, the DDoS is also as simple as the SQL Injection attack. The program used here is called the Low Orbit Ion Cannon (LOIC), which was brought to life by web developers for stress testing their own websites, but was later hijacked by hackers to attack the websites for non-social use.

The LOIC is available to the hackers freely on the website Source Forge. Again as simple as the Havij, the hackers just have to type in the link of the website they want to DDoS and the application does the rest. LOIC overloads the server of the target website with upto 200 requests per second.

Now again, the bigger websites can easily cope up with this type of an attack without crashing, most of the other websites cannot. Surely if a group of hackers, although newborn, dedicates itself to the job, it is very easy for them to complete it.

This type of technology horrifies the readers, but it is very simple to use by the hackers that they can even control it from their phones, meaning that they could well be watching a movie with their buddies in the cinema while attacking the website they want to bring down.

This is not an exhaustive list and processes how the hackers execute the act but there are many a tutorials on various hacking forums that teach how to perform the attack. There is no end to this notoriousness, in many cases a heinous crime, which has caused a loss of millions and millions of dollars to the world. So are you going to get your website checked through your developer today? May be today would be a real good day to get it done.

Wednesday, 18 December 2013

Android Hack to make your phone faster and battery last longer

Android Kitkat
Android Kitkat

The ‘ART’istic Android: Making your Smart Phone Smarter

Android’s ‘KitKat’ version just replaced their penultimate update ‘Jelly Bean’ on October 31 and very recently, at the start of December, update 4.4.2 was released. What was the idea behind releasing updates in such a quick succession? What was there which Google couldn’t hold back till the New Year? Was it a sinister bug which required a fix or a Christmas goodie? The answer is ART; an update that would really position Android differently, if not ahead, of the competition.

ART or Android Run Time is responsible for running all the applications on the Android system. It has ousted its predecessor ‘Dalvik’ (named after the village of Dan Bornstein, Android’s Creator, in Iceland) which was performing the similar task since the time Android was first released. Compared to ART, as per the tech gurus across the globe, Dalvik was “not that great”. The update will provide the following benefits to the users:


1.      Speed

The previous version of the executer used the ‘Just-In-Time’ (JIT) process, which means that the app source of the application had to be converted into the executable program, every time the application started. Don’t be bewildered! Yes it does, in a jiffy.

Whereas, the new version uses ‘Ahead-Of-Time’ (AOT) process and the application is assembled and ready to be executed when the app is installed. To increase your bemusement, Dalvik’s jiffy is not that fast anymore. The application start time will be reduced by a further 50% and will have ‘The Fast Effect’ on the speed of your smart phone.

2.      Reduced Battery Downtime

The background processes will be running faster than before and the phone will actually work smart than working hard to run those background apps and processes. While using the phone you will not be able to see much of a difference, however, the battery which used to drain in the efforts to keep the processes running will now cool down, thus leaving a positive impact on the juice.

Reports from Google claimed an improved 30% boost in the IST (Idle Standby Time) however the users and the critics have their own point of view. Quoting the Technical Gurus the improvement was visible in the IST, however, not at 30% as claimed by the developer but to a significant 20%, keeping in mind the continuous updates and refinements.

The after effects of ART

As usual, the pros are always accompanied by the cons; the ART also has couple of ‘em attached to it.

1.      More Storage

The applications not only took a little long to be installed on the smart phone but they also ate up more space. In the previous version, due to the availability of JIT process the application freed-up the space when they were closed, however, with the use of ART the space acquired was 10%-20% more. This is due to the programs written in such a manner that this problem was visible and predictable. But if a 3 MB (Mega Bytes) application uses 3.3 MB or 3.5 MB, at max, space on your 32 GB smart phone, you would not worry much about it.

2.      Compatibility Issues

With the release of ART and the critics using it, it was cited that at the initial stages many applications were having compatibility issues including WhatsApp, however, with the latest update 4.4.2 the compatibility issues have been fixed. 99% of the major applications were found running smoothly with the fixed version. The list of the compatible apps is long and robust. For those finding any trouble with any frequently used applications, you may switch to and fro between Dalvik and ART.

How to use ART on the phone

If you run Android 4.4 on your handset, which should be a Google Nexus Series or a tailor-made ROM on an embedded device then you can easily upgrade the same, however, the other handset majors have planned to switch to Android ‘KitKat’ 4.4 in the first Quarter of 2014, a version which is more friendly to budget phones in contradiction to the predecessor versions. This is how you can change the phone settings:

    Go to settings then ‘About Phone’
    Tap the ‘Build Number’ repeatedly until you get the announcement you’re a developer
    Go back to settings where you will see a new ‘Developer options’ section
    In Developer options change ‘Select runtime’ to ‘Use ART’

The phone shall take 10-20 minutes for performing the reboot, in which it will convert the applications into ART compatible mode. Your data shall remain safe, however, be sure to back it up before applying these changes. Repeat the similar process should you wish to switch back to Dalvik.

Now sit back and enjoy being ‘ART’istic!

Saturday, 30 November 2013

1295 Bitcoins stolen by hackers by breaking into BIPS

Bitcoin

A group of hackers cracked Denmark BIPS accounts and stole 1,295 Bitcoins – more than a million dollars in equal. An incident outraged many of Bitcoins owners; they blamed BIPS’ leadership of carelessness and frivolity.

One of suffers who said he’s lost 90 bitcoins has created an online forum to let others sign up for possible legal action against BIPS.

The website made a statement that “BIPS will temporarily close down the wallet initiative to focus on real-time merchant processing business which does not include storing of Bitcoins”.

BIPS founder and CEO Kris Henrikson explained the situation at bitcointalk.org forums.
“On Nov. 15th BIPS was the target of a massive distributed denial-of-service (DDoS) attack, which is now believed to have been the initial preparation for a subsequent attack on Nov. 17th that overloaded our managed switches and disconnected the iSCSI connection to the SAN on BIPS servers”.

“Regrettably, despite several layers of protection, the attack caused vulnerability to the system, which has then enabled the attacker/s to gain access and compromise several wallets.” – he added.

Affected individuals will be contacted – no matter how many Bitcoins were stored in their wallets – and merchants will be contacted too if automatic conversion of Bitcoin was not enabled, – Henrikson reassured Bit users.

It is third big theft for this month. Another $1.4 million concerned an online wallet service known as Inputs.io. And $4 million stolen from Chinese exchange.

Wednesday, 30 October 2013

iOS apps vulnerable to HTTP Request Hijacking attacks over WiFi

iOS apps vulnerable to HTTP Request Hijacking
Security researchers Adi Sharabani and Yair Amit have disclosed details about a widespread vulnerability in iOS apps, that could allow hackers to force the apps to send and receive data from the hackers' own servers rather than the legitimate ones they were coded to connect to.
Speaking about the issue at RSA Conference Europe 2013 in Amsterdam, researchers have provided details on this vulnerability, which stems from a commonly used approach to URL caching.

Demonstration shows that insecure public networks can also provide stealth access to our iOS apps to potential attackers using HTTP request hijacking methods.
The researchers put together a short video demonstrating, in which they use what is called a 301 directive to redirect the traffic flow from an app to an app maker’s server to the attacker’s server.

There are two limitations also, that the attacker needs to be physically near the victim for the initial poisoning to perform this attack and the flaw works only against HTTP traffic.

A victim walks into Starbucks, connects to the Wi-Fi and uses her favorite apps,” explains an example. “Everything looks and behaves as normal, however an attacker is sitting at a nearby table and performs a silent HRH attack on her apps. The next day, she wakes up at home and logs in to read the news, but she’s now reading the attacker’s news!

They estimate that at least 10,000 iOS apps in the Apple App Store are vulnerable to the hack. As a result, apps that display news, stock quotes, social media content, or even some online banking details can be manipulated to display fraudulent information and intercept data sent by the end user.
Victims can uninstall apps to scrub their devices clean, and Skycure has released app code that prevents the web caching from taking place. It may be a while until developers can get this fix implemented, so connect to those public networks with extreme caution.

Tuesday, 15 October 2013

Antivirus firm ESET and BitDefender website defaced by Pro-Palestinian Hackers

A pro-Palestinian hacktivist group 'KDMS Team', who recently managed to briefly hijack the Metasploit website of security firm Rapid7 and become popular after Hacking World's largest Web Hosting Network Leaseweb website and antivirus vendors AVG, Avira as well as mobile messaging service WhatsApp's websites.

Now even I have to say that - Security is just an Illusion, because just now the group aligned with Anonymous has successfully hijacked another two Antivirus firm website - ESET and Bitdefender.
The KDMS Team successfully changed the DNS records of both sites to redirect people to a website playing the Palestinian national anthem and displaying a political message under the title "You Got Pwned".
Message posted on Bitdefender and Eset website says:
Hello bitdefender
Touched By KDMS team
We was thinking about quitting hacking and disappear again ..!
But we said : there is some sites must be hacked
You are one of our targets Therefore we are here ..
And there is another thing .. do you know Palestine ?
There is a land called Palestine on the earth This land has been stolen by Zionist Do you know it ?
Palestinian people has the right to live in peace Deserve to liberate their land and release all prisoners from israeli jails We want peace Long Live Palestine
Both affected domains are registered from REGISTER.COM, INC. by companies, which is also a domain registrar for Metasploit website -- was hijacked yesterday via a spoofed change request faxed to Register.com. But the technical details on how hackers managed to hijack the ESET and Bitdefender website is not yet available, we are in contact with hackers.. Will update the article in a few hours. Stay Tuned !
Defacement of Security companies is really embarrassing and hacker's tactics allowed them to get their political message to millions of users. One of their team members tweeted, "When it's a matter of resistance no one will blame you. . Free Palestine .. Fight for Palestine"

Scammers once again take Advantage of Deepavali Festival

Deepavali
CyberCriminals always try to take advantage of festivals.  As expected, cyber criminals have started to sending Diwali themed scam emails.  Diwali/Deepavali is a Hindu festival which is being celebrated in Nov 2,this year.

One of the scam email spotted by Symantec experts which is purportedly from Reserve Bank of India(RBI) informs the users that they have been awarded a prize of 4 crore and 70 Lac Indian rupees(US$763,609) as a Diwali celebration promotion.

"Dear Lucky Winner, The Reserve Bank of India(RBI) Governor, Secretary-General of the United Nations met with the Senate Tax committee on Finance RBI Mumbai/Delhi branch. You have been awarded the total sum of 4 Crore, 70 Lac Indian Ruppes in the up-coming diwali celebration promotion " The scam email reads.

The recipients are asked to contact the RBI Regional director by sending email to a given email address to claim their winnings. Keep in mind, there is no such kind of promotion.

Those who contact the scammers either will be asked to pay certain fees to get the prize money or will be asked to give certain personal/financial information.

Tuesday, 8 October 2013

Chinese hackers miss Google network, but the checks go on

Google exec Schmidt says U.S. government networks are in danger 'because no one is there' during the shutdown to stop hackers - See more at: http://www.computerworld.com/s/article/9243040/Chinese_hackers_miss_Google_network_but_the_checks_go_on#sthash.a3ec9xiO.dpuf
Google

 Google exec Schmidt says U.S. government networks are in danger 'because no one is there' during the shutdown to stop hackers.

He put a question to an audience Gartner's Symposium ITxpo here on Monday. "Raise [your] hand if you're sure the Chinese are not inside your corporate network."

Many of the 8,500 attendees were in the hall to hear the question, but only five hands were raised. "Congratulations," Schmidt said from the stage.

Getting more serious, Schmidt lamented the open pathways in corporate networks, letting hackers slip in via NT servers.

Schmidt suggested a better network would eliminate the corporate intranet.

"We're going to have just a network. We're going to make sure that gaining access is application to application," he said.

In an interview on stage with Gartner analysts David Willis and Drue Reeves, Schmidt was asked whether he's sure that Chinese hackers haven't penetrated Google's corporate network.

"We're quite sure they are not right now," said Schmidt of the Chinese, "although every second we check." The audience chuckled.

"I can be quite sure that the Chinese are visiting the U.S. government at the moment because no one is there," said Schmidt, a reference to the federal government shutdown.

Major vendors, and other companies, have faced attacks from China.

Meanwhile, when asked about the security of mobile devices running the Google built Android operating system, Schmidt said "it's more secure than the iPhone."
Eric Schmidt, Google's executive chairman, put a question to an audience Gartner's Symposium ITxpo here on Monday. "Raise [your] hand if you're sure the Chinese are not inside your corporate network."
Many of the 8,500 attendees were in the hall to hear the question, but only five hands were raised. "Congratulations," Schmidt said from the stage.
Getting more serious, Schmidt lamented the open pathways in corporate networks, letting hackers slip in via NT servers.
Schmidt suggested a better network would eliminate the corporate intranet.
"We're going to have just a network. We're going to make sure that gaining access is application to application," he said.
In an interview on stage with Gartner analysts David Willis and Drue Reeves, Schmidt was asked whether he's sure that Chinese hackers haven't penetrated Google's corporate network.
"We're quite sure they are not right now," said Schmidt of the Chinese, "although every second we check." The audience chuckled.
"I can be quite sure that the Chinese are visiting the U.S. government at the moment because no one is there," said Schmidt, a reference to the federal government shutdown.
Major vendors, and other companies, have faced attacks from China.
Meanwhile, when asked about the security of mobile devices running the Google built Android operating system, Schmidt said "it's more secure than the iPhone."
- See more at: http://www.computerworld.com/s/article/9243040/Chinese_hackers_miss_Google_network_but_the_checks_go_on#sthash.a3ec9xiO.dpuf

WhatsApp Website defaced by KDMS team

WhatsApp Defaced Page
WhatsApp Defaced Page          
The Web site of WhatsApp, a widely used messaging app, appeared to have been defaced Tuesday.
The site showed a pro-Palestinian message at 2:40 a.m. PT Tuesday and was given the title "You Got Pwned." A group called KDMS Team claimed credit for the attack.

According to the Whois database, which can be used to see what numeric Internet Protocol (IP) address is assigned to a given Internet domain, the whatsapp IP address record was changed on Tuesday. Such a change, made through the Internet's Domain Name Service (DNS) system, is one way that users who typed in the whatsapp.com name would be redirected to a different Web site.
It wasn't immediately clear if there were any problems with WhatsApp's customer data or services. CNET contacted the company for comment and will update this story with its reply.
WhatsApp is used to send billions of messages a day using mobile apps.

AVG Antivirus and Avira Websites defaced by Palestinian Hackers

AVG Antivirus Hack Screenshot
AVG Antivirus Hack Screenshot

The Website of Word's most popular Antivirus Firm - AVG were hacked this morning and defaced by a new Palestinian Hacker group - KDMS Team, affiliated with Anonymous Group.
The Defacement page titled 'You got Pwned', with Anonymous Logo and playing Palestinian national anthem in the page background, says: 

we want to tell you that there is a land called Palestine on the earth
this land has been stolen by Zionist
do you know it ?
Palestinian people has the right to live in peace
Deserve to liberate their land and release all prisoners from israeli jails
we want peace
and "There Is No Full Security We Can Catch You !"
Avira Website Defaced Page
Avira Website Defaced Page

More than 1000 Indian government websites hacked in the past three years

H4x0r HuSsY

 H4x0r HuSsY, famous for hacking Indian govt sites hit again. This time The official website of Public Works Department, Punjab with 10 other Indian Govt sites hacked by H4x0r HuSsY.
Anatomy of the attack on the Indian server is unknown. The hacked sites belongs to different name servers.

Two weeks before, Indian BioResource Information Network was hacked by the same hacker. h4x0r HuSsY also hacked Indian Goa Government Server last month.
rm -rf /planet/world/earth/india  echo “The world is a better place now!”, The hacker wrote on the deface page.

Hacked Sites:
  • pwdpunjab.gov.in/1337.html
  • pscst.gov.in/1337.html
  • http://jnvcalicut.gov.in/1337.html
  • pbforestdevcorp.gov.in/1337.html
  • prbdb.gov.in/1337.html
  • mcludhiana.gov.in/1337.html
  • esuwidha.mcludhiana.gov.in/upload
  • www.jnvmahe.gov.in/123
  • http://arogyasri.bbmp.gov.in/1337.html
  • www.tnschools.gov.in/RMSA
Mirrors of hacked sites:
  • http://www.zone-h.org/mirror/id/20896977
  • http://www.zone-h.org/mirror/id/20888936
  • http://www.zone-h.org/mirror/id/20888938
  • http://www.zone-h.org/mirror/id/20888937
  • http://www.zone-h.org/mirror/id/20888935
  • http://www.zone-h.org/mirror/id/20885932
  • http://www.zone-h.org/mirror/id/20885850
  • http://www.zone-h.org/mirror/id/20885463
  • http://www.zone-h.org/mirror/id/20880949
At the time of publishing, most of the are still defaced and showing the message left by the hackers.

Official Delhi Education Board Website hacked by Anonymous Kashmir -Protests against Indian Brutality in Kashmir

Board of Higher Secondary Education Delhi, India has been hacked and defaced by Anonymous Kashmir. Anonymous hacktivists protested against Indian brutality in occupied Kashmir.
Hacked Websites:
  • http://bhsdelhi.com/index.html
  • http://results.bhsdelhi.com/index.html
Mirrors of the hacked sites:
  • http://zone-hc.com/archive/mirror/7512def_bhsdelhi.com_mirror_.html
  • http://zone-hc.com/archive/mirror/e918dfe_results.bhsdelhi.com_mirror_.html
The complete message left by the hacker on the deface page can be found below.
Congratulations! India, Congratulation Your Brutality Continue In Kashmir. Recently You Killed Several Persons At Shopian Area Of Kashmir And Labelled Them As Terrorists. Without Knowing They Were Innocent Youths Who Even do Not Know What Is Real Meaning Of Terrorist. You Not only Killed Those But You Are Killing From 1970′s. You Killed Kashmiri Youth In Hundreds Just To Prove That There Are Still Militants In Kashmir From Last Couple oF mONTHS You Are Wondering Young Youth Joining Terrorist Orgaisations. It’s Just Output Of Your Doings. Every Day Kashmiri Shout For Injustice….Every Day A Kashmiri Saying Save Me Save Me. But No 1 Is Hearing. Recently You Hanged Shahhed Afzal Guru For No Reason???Y Only Injustice With People Of kashmir?Not Only You Hanged Him But U Also Hanged Shaheed Maqbool Bhat. This Is Not Yet Finish ?You Forget You Killed Two Persons at ganderbal for no reason?when u will do justice with people of kashmir?

Saturday, 7 September 2013

FBI Cyber Division put 'Syrian Electronic Army' Hackers in wanted list


FBI Cyber Division put Syrian Electronic Army Hackers in wanted list

 
The Syrian Electronic Army (SEA), a pro-regime hacker group that emerged during Syrian anti-government protests in 2011, and involved in cyber attacks against western media organizations are now in the FBI's wanted list.

The Federal Bureau of Investigation has issued an alert warning of cyber attacks by the Syrian Electronic Army and finally put them on its radar. "The SEA'S primary capabilities include spear-phishing, web defacements, and hijacking social media accounts to spread propaganda." they said. The FBI also has increased its surveillance of Syrians living in the US.
According to some anti-Assad activists, the group was founded by former intelligence agents and hardcore Assad supporters. SEA had compromised social media profiles for Western news organizations by sending fake email messages to news staff in an attempt to gain access to login credentials.
 
FBI Cyber Division put Syrian Electronic Army Hackers in wanted list

Most recently, the group grabbed international attention after commandeering the websites of the New York Times, Washington Post and this week the recruitment website for the US Marine Corps.

The group's was able to compromise the multiple Associated Press (AP) Twitter feeds, then using them to issue bogus messages, including the following alert on April 23 i.e. "Breaking: Two Explosions in the White House and Barack Obama is injured." In the wake of that tweet, the White House confirmed that the president was unharmed, that there had been no explosions and that the FBI was investigating the hoax tweets.

So how did the SEA get better in only a few months? ''I don't think it would be unreasonable to suspect someone more skilled is helping them out,'' says Adam Myers, vice president of intelligence for security firm CrowdStrike.

Is the Syrian Electronic Army based in Syria? After Syria reestablished its Internet connection last week, following a blackout that lasted approximately 24 hours. Security Experts noticed that Syrian Electronic Army Hackers were online on twitter. These kinds of cuts do not affect the terrorists operating in Syria as they have their own US-supplied communication equipment.

The Syrian Electronic Army has multiple domains seized by its domain registration firm. Interestingly, The Syrian Electronic Army's first domain name was registered by the Syrian Computer Society, hosted on the network of the Syrian government.

Please maintain heightened awareness of your network traffic and take appropriate steps to maintain your network security,” the FBI memo said. FBI request anyone who suspects they're under attack to call its CyWatch division at 855-292-3937.

Researchers Discover 'Hesperbot' - A New and Potent Banking Trojan


Hesperbot   A New Banking Trojan that can create hidden VNC server on infected systems

 
Security firm ESET has discovered a new and effective banking trojan, targeting online banking users and designed to beat the mobile multi-factor authentication systems.
Hesperbot detected as Win32/Spy.Hesperbot is very identical to the infamous Zeus and SpyEye Banking Malwares and infects users in Turkey, the Czech Republic, Portugal, and the United Kingdom.
Trojan has functionalities such as keystroke logging, creation of screenshots and video capture, and setting up a remote proxy.

The attackers aim to obtain login credentials giving them access to the victim’s bank account and getting them to install a mobile component of the malware on their Symbian, Blackberry or Android phone.
Some other advanced tricks are also included in this banking Trojan, such as creating a hidden VNC server on the infected system and can do network traffic interception with HTML injection capabilities.
The trojan also harvests email addresses from the infected system and sends them to a remote server. It is possible that these collected addresses were also targeted by the malware-spreading campaigns.
 
So far, the Trojan hasn't spread too far. The campaign was first detected in the Czech Republic where the attackers had used phishing emails impersonating the country’s postal service. Armed with this information, the crooks can try to log into victims' online bank accounts to siphon off their cash.

As for the UK, a special variant of the malware has been created, but ESET said it could not provide any further detail on it.

Hacking Facebook to delete any account; Facebook again refuses to pay Bounty


Hacking Facebook to delete any account; Facebook again refuses to pay Bounty

In the past few days, Facebook refused to pay bounty to Khalil Shreateh, the security researcher who used the bug he discovered to post directly on Facebook CEO Mark Zuckerberg’s Timeline after Facebook Security rejected his attempts to report it.
Ehraz Ahmed, an independent Security Researcher claimed that he reported a critical vulnerability to the Facebook Security team, which allows the attacker to delete any account from Facebook.
But Facebook refuses to Pay Bug Bounty, because he tested flaw once on his friend's account, "I reported this bug to Facebook, I'm really not happy with them. After waiting for such a long time for their reply, they denied it saying that you used this bug only works for test accounts, where as I used it for removing real accounts and now the vulnerability is also fixed after their email." he said on his blog.
Vulnerable URL:
https://www.facebook.com/ajax/whitehat/delete_test_users.php? fb_dtsg=AQA1E-WE&selected_users[0]=[Victems Profile ID]&__user=[Attackers Profile ID]&__a=1
Where selected_users[0] and __user parameters are vulnerable to run exploit.
 

Secunia launches the next generation of Complete Patch Management: The Secunia CSI 7.0


Patch Management

Cybercrime costs organizations millions of dollars and to protect business from the consequences of security breaches, vulnerability intelligence and patch management are basic necessities in the toolbox of any IT team, as emphasized by organizations like the SANS Institute and the National Institute of Standards and Technology under the US Department of Commerce (NIST).
The Secunia CSI 7.0 is the Total Package: Vulnerability Intelligence, Vulnerability Scanning with Patch Creation and Patch Deployment Integration.
Secunia CSI 7.0
To help IT teams counter the threat, vulnerability research company Secunia merges the in-house vulnerability expertise with a sophisticated patch management solution into the Secunia Corporate Software Inspector (CSI 7.0). The foundation of the Secunia CSI is a unique combination of vulnerability intelligence and vulnerability scanning, with patch creation and patch deployment integration.

Friday, 6 September 2013

Fake 'Grand Theft Auto V' Torrent Spreads Malware


Fake Grand Theft Auto V torrent spreading malware

Excitement continues .. Rockstar Games schedule the release of latest The Grand Theft Auto series, GTA 5 on September 17, but Cyber Criminals has already released a fake version of GTA 5 contains malware on torrent networks.
Romanian security firm BitDefender issued warning that GTA V hasn’t been leaked, and during installation you will be asked to complete a survey and send off a text message to gain the serial number. You will then be charged €1 per day on your phone bill and will be infected by a virus.
The PC version has yet to be announced, so trying to install it on your PC is a ridiculous idea; but that seems to be what a lot of people are doing.
"The survey opens in a web browser and, therefore, is able to perform a geographic redirect to the web page that corresponds to the area you are located in," said, Bitdefender Senior E-Threat Analyst Bogdan Botezatu.
This malware is a generic Trojan Trojan.GenericKDV.1134859, which can steal user information, tamper with system files or draft a computer into a botnet. This will result in you being charged for premium rate text messages sent by bogus firms.
The easiest way to avoid this malicious software is to not illegally download copies of GTA V, especially when the game isn't yet launched.

Code-sharing site GitHub now offers two-factor authentication to its users

Code repository GitHub offers two-factor authentication to beef up security around its users’ accounts. Github is a coding repository where developers used to build their projects projects that may turn out to be valued knowledgeable assets.
Two-Factor Authentication adds another layer of authentication to the login process, Now users have to enter their username and password, and a secret code in the second step, to complete the sign in. If a hacker manages to steal a user's credentials through phishing or trojans, cannot do anything, as they do need a second key to enter.
We strongly urge you to turn on 2FA for the safety of your account, not only on GitHub, but on other websites that support it,” the company says. This two-factor authentication for Githu can be turned on in your account settings.
Code Repository %2527Github%2527 offers Two Factor Authentication
GitHub hit 3.5 million users’ landmark along with 6 million repositories deposited on its 5th anniversary in April. Two-factor authentication can protect you from phishing attacks, where hackers try to trick you into giving over your information.
For receiving the second authentication factor, users can either choose to receive it via a text message or can use dedicated authentication mobile app i.e. Google Authenticator for Android/iPhone/BlackBerry or Duo Mobile for Android/iPhone or Authenticator for Windows Phone 7.