Tuesday, 20 December 2011

Despite being 10 years old, Windows XP is still running on a third of all computers




With Microsoft announcing that it will start auto-updating Internet Explorer from January, it seems that we’re finally dragging the digital dawdlers into the modern Internet age. Right? Erm…right. But what about operating systems?
Windows accounts for over 80% of all computer operating systems, but recent figures show that Windows XP – launched initially way back in August 2001 – is still running on almost a third (32.8%) of all machines.
The figures are according to W3Schools, a Web developer’s portal containing tutorials and data relevant to Web development. The stats were collected from W3Schools’ log-files over a period of seven years.
Delving a little deeper, in November 2010 Windows XP constituted almost half (47%) of all operating systems, and it seems that the massive drop is likely to do with users buying new machines with Windows 7 installed, as that has shot up over the same time-frame from 28.5% to 45.5%. Though of course some users will have merely upgraded the OS on their existing machine.
Whilst Linux remained roughly static at around 5%, Mac OS gained some ground, rising from 7.7% in November 2010 to 8.8% this year. This is at odds with reports from last month, however, that Apple’s Mac platform commands a 5.2% share of the global PC market, according to analysis by Needham & Co.
The short-lived Windows Vista dropped from 9.5% to 5.5%, with Windows 2003 still running on 0.7% of computers. There’s no sign of Windows 98 or 2000 in this year’s figures though, which I guess can only be a good thing.
Mainstream support for Windows XP ended in April 2009, but extended support will be available until April 2014 for Windows XP with Service Pack 3 and Windows XP x64 Edition with Service Pack 2. But going by the current downwards trajectory, by 2014 XP will likely constitute a small fraction of personal computers.





Monday, 19 December 2011

Apple Retina Display Heading To MacBook Pros



The Apple rumour mill continues to churn with a new report saying it will extend its high-resolution Retina Display to MacBook Pros.“Apple is likely to launch its new MacBook Pro lineup with a display resolution of 2880 by 1800 in the second quarter of 2012,” read the 14 December piece in the Taiwanese publication DigiTimes, which quoted unnamed sources in the supply chain for its information.“While the prevailing MacBook models have displays with resolutions ranging from 1680 by 1050 to 1280 by 800, the ultra-high resolution for the MacBook Pro will further differentiate Apple’s products.”Retina Display Apple’s Retina Display first appeared as part of the iPhone 4, then spread to the iPod Touch. Current rumours suggest that the next version of the iPad could feature a Retina Display-caliber screen, although Apple will almost certainly decline to confirm this before an official unveiling.Apple’s innovations in its mobile products have a habit of finding their way into the company’s Macs. Apple recently launched the Mac App Store, an apps storefront modelled after the highly successful one for iOS. Its laptops have become progressively thinner and lighter, their software more reliant on the cloud, to the point where they feel more like offshoots of Apple’s mobile efforts.In that spirit, a higher resolution screen leaping from iPhones to MacBooks would seem totally reasonable. As with the iPad 3, though, Apple will surely keep a feature like that under wraps until it wants it revealed.MacBook Pro Apple’s last MacBook Pro refresh offered Intel’s 2nd Generation “Sandy Bridge” processors, including the option of the quad-core Core i7 for certain models.In benchmark testing, eWEEK found the current version of the Pro notably faster than its predecessors. It also included Thunderbolt technology, for data-transfer rates between peripherals of up to 10 Gbps.Mac OS X continues to hold a relatively small portion of the overall operating system market, which is overwhelmingly dominated by Microsoft’s Windows. In mobility, though, Apple continues to maintain a sizable presence: its iOS is currently battling Google Android for the lion’s share of the smartphone market, and the iPad thoroughly dominates tablets.





New Hacker Tools Crack Hashed Passwords


Cyber-attackers have access to various tools to launch their campaigns, such as scanning websites and applications for vulnerabilities, crafting malicious emails and launching drive-by-download web portals. They have a growing body of information and automated password cracking tools to breach systems and networks, Imperva said in a report.Cyber-attackers have greater access to rainbow tables and dictionaries to aid them in cracking passwords, Imperva researchers wrote in their monthly Hacker Intelligence Initiative report released on 14 December.Security practicesOrganisations have to beef up their password security practices to prevent attackers from successfully guessing passwords and getting access to the network, Imperva said.Imperva analysed a list of nearly 100,000 passwords that were exposed by a data breach at film enthusiast website FilmRadar.com.The site had stored user passwords using the SHA1 hash function, which is a common method used to secure applications, but it wasn't enough, according to Imperva. The strength of a cryptographic hash is irrelevant because attackers can bypass the protections and guess what the password is, Imperva found."Contrary to common belief, cryptographic hash functions in general - whether they are SHA-1 or any other cryptographic function - are not impervious to hackers," Imperva researchers wrote in the report.Password cracking tools that make use of rainbow tables and dictionaries are readily available, and most of them are free for anyone to download, Imperva said. Some popular cracking tools include MD5 decrypter, Cyberwar Zone, Cain and Able, and John the Ripper, according to the report. Many of the tools also rely on hacker forums as a way to request and get additional tables and dictionaries."With enough determination, a hacker can easily find tools and multiple dictionaries for password cracking," Imperva researchers wrote.Rainbow tables contain hash values that have already been precomputed for a large number of alphanumeric text. Although creating these tables is generally a lengthy process, once created, they can be reused over and over again.Strong passwordsIf the attacker has a hashed value of a password for a specific service, all that needs to be done is to look up the hash in the table and find the corresponding alphanumeric string. Imperva found a hacker website that makes a rainbow table with more than 50 billion hashed values available to the public.Strong passwords - those with multiple character types, such as both lowercase and uppercase letters, numbers and special characters, as well as long ones - make it computationally difficult to look up the hash in the rainbow table.However, researchers have recently shown that harnessing the power of cloud, such as renting out computing resources from Amazon Elastic Compute Cloud (EC2) can reduce the time required.Dictionaries are similar in that they list common passwords with a precalculated hash value. Dictionary-based attacks are effective because as people are still using simple and common passwords, such as "Hello123" and "abcd123".Imperva ran some of the publicly available tools against the FilmRadar passwords. The team managed to uncover 77 of the 100 most popular passwords in less than 10 minutes using rainbow tables hosted on an online service, according to the report.The 100 most common passwords on the list accounted for 10 percent of the list. Nearly 5 percent of all passwords were guessed in less than two days using dictionaries. Even though it was a slow process, hackers could figure out passwords using multiple dictionaries, Imperva said."When it comes to consumers implementing good passwords, we give up. Instead of consumers, [the] responsibility rests on enterprises to put in place proper password security policies and procedures as a part of a comprehensive data security discipline," Imperva researchers said. IT and security teams should consider passwords as highly valuable data, even if PCI and other regulations don't apply, according to Imperva.Salt valuesImperva recommends that enterprises not rely on just cryptographic hashes, but to "salt" the entries to protect against rainbow table attacks. A salt value is a random value that is added to the beginning of the password before it gets encrypted, making it even harder to crack the password.A salt of just three-bit length increases the storage and precomputation time for rainbow tables eightfold, according to Imperva.Enterprises should use passphrases, longer passwords that are easier to remember. Passphrases result in long passwords, but users don't need to worry about writing them down on to a Post-It.Password security should also be enforced, by comparing the password against the same dictionaries being used by attackers. Microsoft recently banned common passwords on its Hotmail webmail service."Advice to users is to choose strong passwords. The rest is up to the business," Imperva said.The "Imperva Enterprise Password Worst Practices" report follows an earlier report from 2009 on poor consumer password practices.





Saturday, 17 December 2011

California unveils cyber crime unit




California has a new eCrime Unit devoted to catching and prosecuting Internet Age crooks.
State attorney general Kamala Harris created the team, which is comprised of 20 attorneys and investigators specializing in identity theft and cyber crime.
"Today's criminals increasingly use the Internet, smartphones, and other digital devices to victimize people online and offline," Harris said while unveiling the unit in the Silicon Valley city of San Jose.
"I am creating the eCrime Unit so that California can be a leader in using innovative law enforcement techniques to target these criminals."
Crimes targeted include email scams, online fraud, piracy, child porn, and real-world heists of computer gear by organized gangs, according to Harris.
Cases handled by the unit, which was formed in August but whose existence was only revealed on Tueseday, include a man sentenced to prison for hacking email and Facebook accounts to get embarrassing pictures used to blackmail victims in Britain and the United States.
Another case involved a group that secretly installed card scanners and hidden cameras at bank teller machines to get account information and passwords to steal an estimated two million dollars.
"As the importance of the Internet to our economy has grown, criminals have moved online to steal valuable information and goods from individuals and businesses," said Jeffrey Rosen, district attorney of the county in which San Jose is located.
"In the 21st Century, law enforcement will be increasingly combating online criminal activity."





British Student Admits Facebook Hack




A software development student from New York has appeared in court charged with hacking into Facebook.

Glenn Mangham admitted hacking into the social network between April and May of this year, but argued that he only wanted to show Facebook how to improve its security as he had done for Yahoo.
“Considerable expertise”
Prosecutor Sandip Patel said that his actions had caused a number of American authorities, including the FBI, to fear an industrial espionage attack and that he had hacked into the site with “considerable expertise.”

Mangham was charged in August with offences relating to the Computer Misue Act, including three counts of unauthorised access to computer material, unauthorised acts with intent to impair the operation of a computer and making supplying or obtaining articles for use in an offence, as a result of what was described at the time as one of the first investigations into attempts to illegally access Facebook.

Mangham downloaded his own programs onto Facebook’s servers and saved “highly sensitive intellectual data property” onto his hard drive for offline use. Facebook discovered his actions during a system check, even though he deleted his electronic footprint.

Patel described Mangham’s actions as the “most effective and egregious example of hacking into social media that has come before a British court.”

Mangham’s lawyer Tom Ventham claimed that the defendant was an ethical hacker who had a high moral stance and that Yahoo had been grateful to him for pointing out its vulnerabilities. He also argued that Mangham was simply trying to help Facebook do the same, but that his “was found by accident.”
No one is safe
The case is the latest in a number of security issues which have plagued the social network, which has over 500 million users.

In February, Facebook was forced to close a loophole which allowed attackers to gain access to user data, while a malicious piece of software known as Dorkbot took advantage of a vulnerability in the site’s chat feature.

An embarrassing incident earlier this month proved that no one was safe from potential threats when a tool that was intended to flag inappropriate content was exploited in order to expose CEO Mark Zuckerberg’s private photos. This followed an incident in January when a hacker gained control of Zuckeberg’s fan page and posted messages on his wall.





Romanian hackers steal millions from Subway


Romanian hackers have had an indictment served upon them in the US, after an investigation uncovered the hacking of 150 Subway stores, along with 50 other unnamed retailers.
It is thought that the attacks compromised the credit card details of over 80,000 customers and millions of dollars worth of unauthorised purchases were carried out.
The indictment names four Romanians as the perpetrators as well as two unnamed defendants who are at an “unknown location”, and it includes the hacker’s online monikers.
The attackers first scanned the internet for point of sale (POS) systems which were vulnerable and then used password crackers to obtain entry.
They then installed keyloggers in order to record the information, which was processed using the machines.
This included customer details such as credit card numbers and PINs as well as store information which was inputted.
The hackers also installed a back door trojan which gave them future access and allowed them to install further malicious programs designed to help carry out the fraud.
Once the required information was obtained, the attackers uploaded these to US-based “dump sites” which had been specially created. These were computers owned by US consumers who had no idea that their machines were being used for other purposes.
Once the stolen data had been successfully stored, it was then transferred to overseas computers where the defendants “monetized” it by making unauthorised charges or selling the data.
The hackers also made phoney credit cards with the information stored on them by using magnetic strip readers/ writers and card embossers, before making purchases with them across Europe.
The thieves were tracked down through email and online chats in which they talked about selling the stolen data and various targets. They also discussed obtaining card numbers with higher credit limits so that the cards could be used in certain outlets in Europe.
The fraud is thought to have been carried out between 2008 and 2010.



Hackers breach servers of Japan's Square Enix

Japanese game developer Square Enix said that servers containing data on 1.8 million customers had been hacked, but said the extent of the damage was not yet known.

The producer of hit titles such as Final Fantasy and Dragon Quest pulled down the Square Enix Members service shortly after discovering evidence of an intruder, a spokeswoman said on Thursday.
The intruder breached an unknown number of servers that could hold data for the service's one million members in Japan and 800,000 members in North America, but left untouched the servers with its 300,000 European members, she said.
Earlier this year entertainment giant Sony came under a series of attacks, affecting more than 100 million customer accounts in one of the largest data breaches ever.
In May, Square Enix said the email addresses of 25,000 customers as well as resumes of 250 job applicants were leaked after a hacker attack on its European subsidiary.
This time, Square Enix found evidence of an intruder around noon (0300 GMT) Tuesday, and pulled down the service about an hour later, the spokeswoman said.
The company notified its clients about the incident Wednesday, although details and the extent of the actual damage were not yet clear, with a probe continuing, she said.
The affected servers stored the customers' names and email addresses.