Showing posts with label Hacker. Show all posts
Showing posts with label Hacker. Show all posts

Wednesday, 11 January 2012

Hackers hit ArcelorMittal's Belgian website




The online piracy group Anonymous hacked into the Belgian website of industrial giant ArcelorMittal on Friday, posting a video to protest the closure of two blast furnaces in Belgium.
"Anonymous has done its work by attacking the ArcelorMittal site and, as you can see, it was a success," said a message posted alongside the video on the hacked homepage.
The website was blocked in the morning before returning to service in the afternoon.

Tuesday, 10 January 2012

'Saudi' hacker targets Israel with Trojan horse virus




A self-defined "Saudi hacker" who twice this week posted details of thousands of Israeli credit cards hit again on Friday with a new Internet file containing a Trojan horse virus, public radio said.
According to the report, the hacker who goes by the name "0xOmar" posted what appeared to be credit card details, but was in fact malware that could seriously damage users who downloaded it.
On Thursday, the Saudi hacker from group-xp published details of more than 6,000 Israeli credit cards online in the second such incident in three days, army radio reported.

Hackers in India Leak Symantec Source Code




Last night Imperva sent along an email stating that hacker group Lords of Dharmaraja is threatening to release the source code of Symantec's flagship product, Norton Antivirus. The group's original threat posted on Pastebin is now gone, but a Google cached version claims that the source code was retrieved during a hack of India's military and intelligence servers.

Apple Files Patent For Password Recovering Charger



Apple has filed a patent for a charger which could act as a physical key to unlock a laptop if a user forgets a password. The patent application (US patent 2012/0005747) claims that it would protect users who have their devices stolen while they are “out and about” and that, in theory, the technology could be applied to any piece of equipment that is regularly used with the computer.
Positively charged
According to the patent, users who forget their password could plug in the cord and it would provide a unique ID number stored in the memory chip of the adapter that serves as a decryption key, unscrambling a backup copy of the password stored on the machine.

Thursday, 5 January 2012

Alleged Saudi Hackers Nab Israeli Credit Card Data

 


In an attack that may either be epic or inconsequential, depending on who is consulted, the ongoing conflict over Israel went digital this week when it was confirmed that the credit card data of 'thousands' of Israelis has been compromised. On Monday, the credit card information was briefly posted to an Israeli sports site, One.co.il, by a hacker group calling itself Group-XP. Ynet has reported that a message associated with the attack called it a "gift to the world for the New Year," one they hoped "would hurt the Zionist pocket". Soon after this, a hacker who claims to speak for the group, operating under the alias OxOmar, posted a lengthy message to PasteBay bragging about the attack.

Two iOS5 Security Flaws Exploited By Apple Jailbreak Tool



                             A researcher has released a new jailbreak tool that would allow iPhone users to run code from sources other than Apple's iTunes App Store.The new jailbreak, dubbed Corona, takes advantage of two different bugs in iOS 5 to untether iPhones and other devices running iOS 5.01, a researcher, Pod2g, wrote on his iOS Research blog. One flaw exists in the iOS binary and the other was a heap overflow in the kernel, according to the post.

Monday, 2 January 2012

Japan developing ‘virus' to identify and neutralise cyber threats


Japanese technology firm Fujitsu is developing a ‘seek and destroy’ virus which could identify and combat hacking and other cyber threats in a more effective way, according to a report from The Times of India.

The work is ongoing as part of a three year initiative which has seen the Japanese government invest a reported $2.3 million to combat Internet-based threats. According to local media, the weapon is in fact a virus which monitors and analyse attacks, before identifying the source and closing down the threat to prevent further problems.

Friday, 30 December 2011

Anonymous Loots $1m From Clients' Credit Cards In Stratfor Hack


         

                             US security firm Stratfor’s Website was compromised over Christmas by the Anonymous group of hackers as part of a “Robin Hood” rampage. Named LulzXmas, the campaign is aimed at robbing the rich “one percent” and giving to the poor “99 percent”.The Stratfor site went offline on 24 December and the company’s clients whose names, addresses and payment card details were published online by Anonymous were notified of their exposure.Charity Donations Anonymous has claimed to have stolen $1m (£649,000) from the compromised accounts and to have deposited the money with charities. A faction of Anonymous has posted screenshots of money being transferred to the Red Cross, Save the Children, and Care.Many of Stratfor’s customers are major companies and government agencies, including the US Department of Defense. The Bank of America, and Lockheed Martin – which was itself the victim of hackers earlier this year.Other companies affected by the intrusion are said to include Google, Microsoft, Sony, Coca-Cola, Boeing and American Express, according to Anonymous’ postings. 

McAfee Reports Mobile Phone Users Remain Casual About Security


     
                             Mobile users have a false sense of security when it comes to their devices, according to a recent report from McAfee.About 70 percent of smartphone owners said they considered their devices to be safe from cyber-crime, according to a report from the National Cyber-Security Alliance (NCSA) and McAfee. Even though the report was primarily consumer-oriented, the findings provide insight into how mobile users could impact the country's collective digital infrastructure, McAfee said.No security, no worries A little over 70 percent of the respondents said they had never installed any form of security software or data protection applications on their device. Respondents said they considered their device to be safe from data theft and other cyber-threats.

Thursday, 29 December 2011

HP Issues Firmware to Address Printer Vulnerability

Hewlett-Packard

Last month researchers at Columbia University discovered a new class of security flaws that could allow hackers to remotely control printers over the internet. The discovery even indicated that hackers could cause actual physical damage to the device by heating up its fuser to dangerous levels, possibly causing a fire.


Thursday, 22 December 2011

Twitter To Open Source Encrypted Text Software For Android



                              Less than a month after being brought into the Twitter fold, Whisper Systems’ Android secure text-messaging client TextSecure is being made open source.According to Twitter’s Chris Aniszczyk, the company, a supporter of open source, plans to do the same with other Whisper Systems software.We love open source According to a blog post, he said that putting the source code onto GitHub, its resource for developers, was not a decision Twitter made lightly or on a whim.“Before we fully release Whisper Systems’ code to the public in the coming months, we need to make sure it meets legal requirements and is consumable by the open source community," he said. "The plan is to open source the code in an iterative fashion, starting today with TextSecure, which provides support for encrypted texts on Android devices. We hope individuals will continue to find it useful and build upon it."“We’ve always been interested in the ability for individuals and organisations to communicate freely and securely," read a Whsiper Systems statement. "In the year and a half since Whisper Systems launched TextSecure, we've received an enormous amount of thanks, feedback, and encouraging stories from users who have employed TextSecure towards those ends. We hope that as an open source project, TextSecure will be able to reach even more people, with an even larger number of contributors working to make it a great product.”At the time of its acquisition, Whisper Systems said that some of its products would be taken offline, including its RedPhone voice encryption service and its FlashBack encrypted backup offering. Whisper Systems also develops encryption and security software for mobile devices, including WhisperCore, WhisperMonitor, Flashback and RedPhone for Android phones.


BullGuard highlights emerging threats for 2012



 BullGuard, specialists in PC and mobile security solutions for consumers, has gazed into its crystal ball to predict the nature of a growing range of threats consumers may encounter in 2012.
Over the last few years it has become apparent that the range of handheld devices and services designed to bring convenience and flexibility to our everyday lives can also yield opportunities for malicious users to intercept data, potentially resulting in identity theft, fraud and access to sensitive information. It’s more important than ever for modern consumers to be aware of the threats that exist, and with 2012 set to expand remote access and control even further, BullGuard is encouraging users to stay one step ahead of malicious parties by highlighting the sorts of threats we can expect to encounter.
BullGuard sees five key areas that are likely targets for internet criminals in 2012:

1. The Cloud: Bringing with it the promise of remote data access, backup and storage for your files, cloud computing has now become mainstream and is essential to the future development of mobile services and support. Unfortunately it also brings with it the hidden dangers of malicious users accessing your data without permission. In 2011 we’ve seen high-profile examples of security being breached when hackers gained access to sensitive data of 77 million subscribers to the Sony Playstation network, and since then researchers have shown just how easy it can be to crack Wi-Fi passwords with the right equipment to gain access to data as it is being transmitted. It is the responsibility of the service provider to produce a safe, secure environment on which data can be stored, but those concerned about security would do well to avoid leaving any sensitive information, such as credit card or bank account details, in the “cloud”.

2. QR Codes: These square, barcode-type images are popping up with increasing regularity, and are likely to see more mainstream use in 2012. Designed to offer quick access to software, websites or services by scanning the code with a phone’s camera, the downside of the speed and convenience on offer is that they could become a prime target for hackers. It would be relatively easy to direct a phone towards a malicious website or application, which could then encourage the entry of sensitive data to proceed or start a download of malicious software that could infect a phone to track its location, send SMS messages to premium rate numbers, or reveal credit card or bank account information. It’s vital that users are aware of the service they’re accessing and only attempt to scan a QR code provided by a legitimate and trusted source.

3. Internet-connected TVs: With over 40 million internet-accessible TVs shipped worldwide in 2010, and this number set to grow to 118 million by 2014, it seems likely that these multi-functional sets will become commonplace in the near future. What many consumers may not consider is the potential security issues surrounding their use. In 2011 researchers demonstrated how it was possible to gain control over a television to limit its functionality, access sensitive information such as credit card details, or carry out “phishing” attempts by encouraging users to enter personal data into an online form. The A/V industry has been relatively slow at recognising the importance of security so it’s important that consumers are aware of the threat, and again avoid entering or storing any sensitive data where possible.

4. Smartphones and tablets: 2011 saw a number of instances of security issues across most mobile platforms, from apps infected with malware to Wi-Fi hacking and theft. 2012 is likely to see a continued threat to Smartphone and connected tablet users as hackers look to exploit their growing popularity. The increase in social media activity and desire to always be connected leaves many users storing a range of sensitive data on handhelds, all of which could be accessible to malicious parties if not properly protected. Consumers should remain vigilant about what sort of data they choose to store or share from a mobile, and investing in a dedicated security suite can help protect against an ever-evolving range of threats.

5. Windows 8: For the first time, Windows will come bundled with anti-virus and a firewall when version 8 hits the shelves in 2012. While this will mean that everybody has a degree of protection as standard, the downside is that these tools may not be as effective as dedicated security suites, and may not offer comparable protection. Additionally, if a significant proportion of users rely on Microsoft’s solution this could make it a prime target for hackers looking to circumvent security – never underestimate the effectiveness of a dedicated suite from an experienced vendor.

Now revealed: US Chamber data was accessed by Chinese hackers last year



It has been alleged that Chinese hackers gained access to the US Chamber of Commerce’s entire collection of online data last year, according to a report from the Wall Street Journal.
Sources close to the organisation claim that the attack on the chamber, which is America’s leading business lobbying group, saw the infiltraters gain access to all of the data within its servers. While it is not known exactly what data was access, the break in exposed a range of data from its 3 million members, with emails and other data thought to have been stolen.

The operation, which was coordinated from more than 300 separate Internet addresses, was shut down without a public announcement upon being discovered in May 2010. Details of the incident have only emerged after anonymous sources contacted the WSJ.

Reports of cyber attacks have become common this year, with a great many assaults suspected to have come from China, a great number of which are thought to be related to business. Earlier this year the head of Britain’s Ministry of Defence’s cyber security programme told the Daily Telegraph that “the biggest threat to [the] country by cyber is not military, it is economic”.

US firms remain a significant hacking target, as a report from security firm Symantec recently revealed. The company published details of Nitro, a campaign waged by Chinese cyber spies, who targeted 48 US based companies, and a series of other firms from the UK and Asia, during a six month campaign earlier this year.
Speculation over China’s cyber threat has seen Chinese firms Huawei and ZTE come under pressure in the US. The government has begun an investigation to assess any possible threat that both companies’ increasing business, and access to data, may pose to national security.





Monday, 19 December 2011

New Hacker Tools Crack Hashed Passwords


Cyber-attackers have access to various tools to launch their campaigns, such as scanning websites and applications for vulnerabilities, crafting malicious emails and launching drive-by-download web portals. They have a growing body of information and automated password cracking tools to breach systems and networks, Imperva said in a report.Cyber-attackers have greater access to rainbow tables and dictionaries to aid them in cracking passwords, Imperva researchers wrote in their monthly Hacker Intelligence Initiative report released on 14 December.Security practicesOrganisations have to beef up their password security practices to prevent attackers from successfully guessing passwords and getting access to the network, Imperva said.Imperva analysed a list of nearly 100,000 passwords that were exposed by a data breach at film enthusiast website FilmRadar.com.The site had stored user passwords using the SHA1 hash function, which is a common method used to secure applications, but it wasn't enough, according to Imperva. The strength of a cryptographic hash is irrelevant because attackers can bypass the protections and guess what the password is, Imperva found."Contrary to common belief, cryptographic hash functions in general - whether they are SHA-1 or any other cryptographic function - are not impervious to hackers," Imperva researchers wrote in the report.Password cracking tools that make use of rainbow tables and dictionaries are readily available, and most of them are free for anyone to download, Imperva said. Some popular cracking tools include MD5 decrypter, Cyberwar Zone, Cain and Able, and John the Ripper, according to the report. Many of the tools also rely on hacker forums as a way to request and get additional tables and dictionaries."With enough determination, a hacker can easily find tools and multiple dictionaries for password cracking," Imperva researchers wrote.Rainbow tables contain hash values that have already been precomputed for a large number of alphanumeric text. Although creating these tables is generally a lengthy process, once created, they can be reused over and over again.Strong passwordsIf the attacker has a hashed value of a password for a specific service, all that needs to be done is to look up the hash in the table and find the corresponding alphanumeric string. Imperva found a hacker website that makes a rainbow table with more than 50 billion hashed values available to the public.Strong passwords - those with multiple character types, such as both lowercase and uppercase letters, numbers and special characters, as well as long ones - make it computationally difficult to look up the hash in the rainbow table.However, researchers have recently shown that harnessing the power of cloud, such as renting out computing resources from Amazon Elastic Compute Cloud (EC2) can reduce the time required.Dictionaries are similar in that they list common passwords with a precalculated hash value. Dictionary-based attacks are effective because as people are still using simple and common passwords, such as "Hello123" and "abcd123".Imperva ran some of the publicly available tools against the FilmRadar passwords. The team managed to uncover 77 of the 100 most popular passwords in less than 10 minutes using rainbow tables hosted on an online service, according to the report.The 100 most common passwords on the list accounted for 10 percent of the list. Nearly 5 percent of all passwords were guessed in less than two days using dictionaries. Even though it was a slow process, hackers could figure out passwords using multiple dictionaries, Imperva said."When it comes to consumers implementing good passwords, we give up. Instead of consumers, [the] responsibility rests on enterprises to put in place proper password security policies and procedures as a part of a comprehensive data security discipline," Imperva researchers said. IT and security teams should consider passwords as highly valuable data, even if PCI and other regulations don't apply, according to Imperva.Salt valuesImperva recommends that enterprises not rely on just cryptographic hashes, but to "salt" the entries to protect against rainbow table attacks. A salt value is a random value that is added to the beginning of the password before it gets encrypted, making it even harder to crack the password.A salt of just three-bit length increases the storage and precomputation time for rainbow tables eightfold, according to Imperva.Enterprises should use passphrases, longer passwords that are easier to remember. Passphrases result in long passwords, but users don't need to worry about writing them down on to a Post-It.Password security should also be enforced, by comparing the password against the same dictionaries being used by attackers. Microsoft recently banned common passwords on its Hotmail webmail service."Advice to users is to choose strong passwords. The rest is up to the business," Imperva said.The "Imperva Enterprise Password Worst Practices" report follows an earlier report from 2009 on poor consumer password practices.





Saturday, 17 December 2011

California unveils cyber crime unit




California has a new eCrime Unit devoted to catching and prosecuting Internet Age crooks.
State attorney general Kamala Harris created the team, which is comprised of 20 attorneys and investigators specializing in identity theft and cyber crime.
"Today's criminals increasingly use the Internet, smartphones, and other digital devices to victimize people online and offline," Harris said while unveiling the unit in the Silicon Valley city of San Jose.
"I am creating the eCrime Unit so that California can be a leader in using innovative law enforcement techniques to target these criminals."
Crimes targeted include email scams, online fraud, piracy, child porn, and real-world heists of computer gear by organized gangs, according to Harris.
Cases handled by the unit, which was formed in August but whose existence was only revealed on Tueseday, include a man sentenced to prison for hacking email and Facebook accounts to get embarrassing pictures used to blackmail victims in Britain and the United States.
Another case involved a group that secretly installed card scanners and hidden cameras at bank teller machines to get account information and passwords to steal an estimated two million dollars.
"As the importance of the Internet to our economy has grown, criminals have moved online to steal valuable information and goods from individuals and businesses," said Jeffrey Rosen, district attorney of the county in which San Jose is located.
"In the 21st Century, law enforcement will be increasingly combating online criminal activity."





British Student Admits Facebook Hack




A software development student from New York has appeared in court charged with hacking into Facebook.

Glenn Mangham admitted hacking into the social network between April and May of this year, but argued that he only wanted to show Facebook how to improve its security as he had done for Yahoo.
“Considerable expertise”
Prosecutor Sandip Patel said that his actions had caused a number of American authorities, including the FBI, to fear an industrial espionage attack and that he had hacked into the site with “considerable expertise.”

Mangham was charged in August with offences relating to the Computer Misue Act, including three counts of unauthorised access to computer material, unauthorised acts with intent to impair the operation of a computer and making supplying or obtaining articles for use in an offence, as a result of what was described at the time as one of the first investigations into attempts to illegally access Facebook.

Mangham downloaded his own programs onto Facebook’s servers and saved “highly sensitive intellectual data property” onto his hard drive for offline use. Facebook discovered his actions during a system check, even though he deleted his electronic footprint.

Patel described Mangham’s actions as the “most effective and egregious example of hacking into social media that has come before a British court.”

Mangham’s lawyer Tom Ventham claimed that the defendant was an ethical hacker who had a high moral stance and that Yahoo had been grateful to him for pointing out its vulnerabilities. He also argued that Mangham was simply trying to help Facebook do the same, but that his “was found by accident.”
No one is safe
The case is the latest in a number of security issues which have plagued the social network, which has over 500 million users.

In February, Facebook was forced to close a loophole which allowed attackers to gain access to user data, while a malicious piece of software known as Dorkbot took advantage of a vulnerability in the site’s chat feature.

An embarrassing incident earlier this month proved that no one was safe from potential threats when a tool that was intended to flag inappropriate content was exploited in order to expose CEO Mark Zuckerberg’s private photos. This followed an incident in January when a hacker gained control of Zuckeberg’s fan page and posted messages on his wall.





Romanian hackers steal millions from Subway


Romanian hackers have had an indictment served upon them in the US, after an investigation uncovered the hacking of 150 Subway stores, along with 50 other unnamed retailers.
It is thought that the attacks compromised the credit card details of over 80,000 customers and millions of dollars worth of unauthorised purchases were carried out.
The indictment names four Romanians as the perpetrators as well as two unnamed defendants who are at an “unknown location”, and it includes the hacker’s online monikers.
The attackers first scanned the internet for point of sale (POS) systems which were vulnerable and then used password crackers to obtain entry.
They then installed keyloggers in order to record the information, which was processed using the machines.
This included customer details such as credit card numbers and PINs as well as store information which was inputted.
The hackers also installed a back door trojan which gave them future access and allowed them to install further malicious programs designed to help carry out the fraud.
Once the required information was obtained, the attackers uploaded these to US-based “dump sites” which had been specially created. These were computers owned by US consumers who had no idea that their machines were being used for other purposes.
Once the stolen data had been successfully stored, it was then transferred to overseas computers where the defendants “monetized” it by making unauthorised charges or selling the data.
The hackers also made phoney credit cards with the information stored on them by using magnetic strip readers/ writers and card embossers, before making purchases with them across Europe.
The thieves were tracked down through email and online chats in which they talked about selling the stolen data and various targets. They also discussed obtaining card numbers with higher credit limits so that the cards could be used in certain outlets in Europe.
The fraud is thought to have been carried out between 2008 and 2010.



Hackers breach servers of Japan's Square Enix

Japanese game developer Square Enix said that servers containing data on 1.8 million customers had been hacked, but said the extent of the damage was not yet known.

The producer of hit titles such as Final Fantasy and Dragon Quest pulled down the Square Enix Members service shortly after discovering evidence of an intruder, a spokeswoman said on Thursday.
The intruder breached an unknown number of servers that could hold data for the service's one million members in Japan and 800,000 members in North America, but left untouched the servers with its 300,000 European members, she said.
Earlier this year entertainment giant Sony came under a series of attacks, affecting more than 100 million customer accounts in one of the largest data breaches ever.
In May, Square Enix said the email addresses of 25,000 customers as well as resumes of 250 job applicants were leaked after a hacker attack on its European subsidiary.
This time, Square Enix found evidence of an intruder around noon (0300 GMT) Tuesday, and pulled down the service about an hour later, the spokeswoman said.
The company notified its clients about the incident Wednesday, although details and the extent of the actual damage were not yet clear, with a probe continuing, she said.
The affected servers stored the customers' names and email addresses.