twitter
    Find out what I'm doing, Follow Me :)
Showing posts with label Hacking News. Show all posts
Showing posts with label Hacking News. Show all posts

Friday, December 30, 2011

2011 is the Year of the Hacktivist, Verizon Report Suggests

Verizon Business's Bryan Sartin, who investigates corporate break-ins, saw red this year over hacktivist threats to clients.

Postal workers, department store clerks and elves aren’t the only ones working like crazy this holiday season. For Bryan Sartin, it’s the busiest time of year.

Sartin is a director of investigative response with Verizon Business. He’s the guy you call when you’ve been hacked and he usually doesn’t get much of a Christmas vacation.

“Right before big holidays, particularly Christmas and New Year’s is when the very vast majority of people seem to find out that they’ve been hacked,” he says. “We’ll do as much as 20 percent of our annual caseload during this part of December.”

In 2010, about 92 percent of those cases involved criminals trying to steal money over the internet, but this year everything changed.

The first signs emerged in December 2010, when activists with the online collective Anonymous called for digital sit-ins — known as distributed denial of service attacks — on the websites of companies that had refused to process payments for Wikileaks. Then, in early 2011, attacks on Sony, HBGary and many law enforcement agencies hit the headlines. None of them appear to have been financially motivated.
That’s meant big changes in the kinds of threats that companies are preparing for.

Sartin helps compile a widely watched yearly study of data breaches, and he says that hacktivist and state-sponsored attacks will show up in this year’s report, big time. “That trend has certainly continued this year and it will embody itself in a big way in our upcoming study.”


But for all the high-profile LulzSec and Anonymous attacks this year, Sartin still believes the hacktivist threat — long ignored by corporate IT — is now frequently overhyped.

He says clients often approach Verizon after they see a Twitter message or an internet post threatening an attack on a pre-determined day. The company gears up for an event, bringing consultants on site, and ordering technical staff to be at the ready.

It’s not cheap, and most of the time, nothing happens. “Very commonly, when companies are receiving these kinds of threats in advance, no one ever makes good on them,” he says.

Last year, reported cyber-threats to the New York Stock Exchange, the Federal Reserve, and Facebook never materialized.

In one actual attack — Sartin wouldn’t name the company — criminals broke in and got access to a database filled with encrypted client data. Looking at the logs, Verizon investigators could see that the attackers had downloaded all of the encrypted data — something that would force the company to notify its customers that their data had been accessed. But they didn’t download the one most useful table of all — an unencrypted list of the encryption keys that could be used to decrypt all of the data they had stolen.

“They were stealing data with no interest in deciphering the encryption,” he says. “They were just stealing it to force this company into making a disclosure.”

While the hacktivists may be overhyped, Sartin says they’re often better than the other hackers out there. According to him, many attacks that are thought to be state sponsored, are surprisingly unsophisticated. Known as advanced persistent threat attacks, Sartin calls them “awfully persistent, but not so advanced.”
There’s one more surprise that will show up in the 2012 Data Breach Report, which will include a lot more data sources from Europe and Asia than previous reports.

“In this part of the world, China is the source of a lot of our crimes, but if you go to China … the U.S. is the number one source of electronic crimes,” Sartin says. “Over here we think that all of these advanced persistent threats and things come from China. Over there, they think they all come from here.”

Saturday, November 12, 2011

Malaysian hacker gets 10 years in US prison

http://www.flickr.com/photos/sercasey/251142094/
A US District judge sentenced a Malaysian to 10 years in prison for hacking into the US Federal Reserve and other banks.

Lin Mun Poo, a Malaysian citizen, had admitted earlier this year to hacking into the US central bank, various private financial institutions and possessing stolen bank card and credit card numbers, officials said.
According to AFP, he also admitted to hacking into a Fed computer server and installing a malicious software code there. Lin, who is from Ipoh, travelled to the United States in October last year “for the purpose of selling stolen credit card and bank card numbers” but a purchaser was in fact an undercover US agent, according to prosecutors. When he was arrested, Lin held over 122,000 stolen bank card and credit card numbers.
 

Friday, November 11, 2011

'Hacked server' claims another certificate authority casualty - KPN

http://i.zdnet.com/blogs/kpn-website-hack-lc-zaw2.jpg
Credit: ZDNet
Dutch certificate authority KPN has issued a statement, confirming that it will cease issuing operations after a security breach was discovered.

KPN, formerly known as Getronics, which issues SSL-certificates to validate the authenticity of secure websites, will cease issuing certificates after one of its servers had been hacked, thought to be as far back as four years ago.

It’s another major blow to the integrity of the web, only a month since Dutch certificate authority Diginotar was hacked, potentially compromising the security of websites belonging to the Dutch government, Google, Facebook and even state intelligence services. In the statement, while “existing certificates already issued remain valid”, it cannot rule out that the production of certificates — including pre-existing certificates — have not been compromised.

Wednesday, August 24, 2011

A Website that Ranks your Hacks

So you think you can hack?

Some 700 hackers looking to show off their talents have piled into an upstart Web site called RankMyHack.com in the last month. Emerging from the shadowy underground, they have submitted evidence of more than 1,200 Web site hacks, eager to have their feats measured against those of their peers.

The site was created by a hacker nicknamed Solar to bring a little accountability to the online forums and chat rooms where hackers gather to learn tricks of the trade, buy and sell contraband and form alliances. There, eBay-style ratings systems meant to establish reputations are routinely abused, morality tends to be fluid and anonymous young people often talk big while carrying a small stick.

RankMyHack offers a way to separate the skilled from the so-called script kiddies by verifying hacks using codes that participants must plant somewhere on sites they have compromised. As in a video game, RankMyHack awards points, which are based on the popularity of the hacked site and the technical difficulty of the hack. Total scores determine hackers’ ranks on the “leader board of legends.” Players can even challenge one another to duels.

“So have you got what it takes to be the best?” Solar taunts on the site’s home page, which has a distinctively retro design.

Participants can also win “bo

Friday, August 19, 2011

Vanguard Defense: New Target for AntiSec Hackers

The hacktivist group AntiSec says it has released a gigabyte of private documents from Vanguard Defense Industries, including e-mails from an executive connected with an organization it has targeted previously.
In a post on Pastebin this morning, AntiSec said the e-mails belong to Richard Garcia, a senior vice president at Vanguard who is also a board member at InfraGard, an FBI program that teams up public and private cybersecurity efforts. In June, AntiSec affiliate LulzSec hacked the Web site of InfraGard Atlanta, releasing passwords and other sensitive information. 

Describing InfraGard as "a sinister alliance," AntiSec gloated about this latest breach:
It is our pleasure to make a mockery of InfraGard for the third time, once again dumping their internal meeting notes, membership rosters, and other private business matters.
Within the booty you may find lots of shiny things as we did not have time to follow up on all the data. Safe to say, that despite previous disclosure in the media...Mr. Garcia did not bother to change any of his many many passwords found in his spool at the time of this release. So here's also a shoutout to all Lulz Lizards still following our mischiefs: Have fun with the data of Mr. Garcia, former Assistant Director to the L.A. FBI office who now sells his cybersecurity "skills" to the Military and Government for brazen amounts of money.
Vanguard, based in Conroe, Texas, makes an unmanned aerial vehicle called the ShadowHawk, used in commercial as well as law enforcement and military settings, and also provides security consulting services.
Representatives of Vanguard were not immediately available for comment.

AntiSec said the new breach was perpetrated "not only to cause embarrassment and disruption to Vanguard Defense Industries, but to send a strong message to the hacker community" that it will continue to target military contractors, law enforcement agencies, and "white hat sellouts," a reference to hackers who work with police and other establishment groups.

Earlier this month, AntiSec issued a "Shooting Sheriffs Saturday Release" of what it said was 10GB of data stolen from U.S. law enforcement agencies, including private e-mails, passwords, data from informants, Social Security numbers, and credit card information.

Sunday, August 14, 2011

Phones Running Google's Android are Prone to Hacking: Experts

A mobile security expert says he has found new ways for hackers to attack phones running Google Inc's Android operating system.

Riley Hassell, who caused a stir when he called off an appearance at a hacker's conference last week, told Reuters that he and his colleague Shane Macaulay decided not to lay out their research at the gathering for fear criminals would use it attack Android phones.

He said in an interview he identified more than a dozen widely used Android applications that make the phones vulnerable to attack.

"App developers frequently fail to follow security guidelines and write applications properly," he said.

"Some apps expose themselves to outside contact. If these apps are vulnerable, then an attacker can remotely compromise that app and potentially the phone using something as simple as a text message."

He declined to identify those apps, saying he fears hackers might exploit the vulnerabilities.

"When you release a threat and there's no patch ready, then there is mayhem," said Hassell, founder of boutique security firm Privateer Labs.

Hassell said he and Macaulay alerted Google to the software shortcomings they unearthed.

Google spokesman Jay Nancarrow said Android security experts discussed the research with Hassell and did not believe he had uncovered problems with Android.

"The identified bugs are not present in Android," he said, declining to elaborate.

It was the first public explanation for the failure of Hassell and Macaulay to make a scheduled presentation at the annual Black Hat hacking conference in Las Vegas, the hacking community's largest annual gathering.

They had been scheduled to talk about "Hacking Androids for Profit." Hundreds of people waited for them to show up at a crowded conference room.

Hassell said in an interview late on Thursday the pair also learned -- at the last minute -- that some of their work may have replicated previously published research and they wanted to make sure they properly acknowledged that work.

"This was a choice we made, to prevent an unacceptable window of risk to consumers worldwide and to guarantee credit where it was due," he said.

A mobile security researcher familiar with the work of Hassell and Macaulay said he understood why the pair decided not to disclose their findings.

"When something can be used for exploitation and there is no way to fix it, it is very dangerous to go out publicly with that information," the researcher said. "When there is not a lot that people can do to protect themselves, disclosure is sometimes not the best policy."

Hassell said he plans to give his talk at the Hack in The Box security conference in Kuala Lumpur in October.

Saturday, August 13, 2011

Download Your Favorite Security Software With New Free "Security Software Downloader"

The first version of Security Software Downloader was released in 2010. The program allows Windows users to download security software comfortably from the program interface. That’s handy especially on new systems, on systems that need a change in security software and PCs that are infected by malware that the installed antivirus software cannot remove.

Security Software Downloader 2 has just been released by its developers. The program itself is still Open Source and compatible with all 32-bit and 64-bit editions of the Windows XP, Vista and Windows 7 operating system.

The first change that users will notice is the new and improved user interface which now separates security software in groups like free antivirus, malware removal or firewalls.
That’s better than the all on one page approach of the program’s predecessors.

security software downloader

The program is set to auto detect the operating system and version of the operating system. Users can make the changes manually which is helpful if the auto detection did not detect the correct OS and version.

Software can be selected with a click in the adjacent check box. It is possible to select multiple programs at once. A click on the download button downloads all selected security applications to the operating system. Windows users who do not want the programs to be downloaded to their desktop should click on the 

Change Download Dir button to change the save location.
The program is not providing any information about the security software in its interface. A website button next to each program links directly to the program homepage on the Internet.

So what is new in Security Software Downlader? The developer has added support for additional programs, raising the number of applications to over 50. Among the new tools are Panda Internet Security, the password manager LastPass, Spybot Search & Destroy and CyberGhost VPN.

ssdownloader

Security Software Downloader is still a handy program for users who would like to download multiple security applications at once from the Internet. It can also be handy for users who want to discover and test new products.
SSDownloader can be downloaded from the project website over at Sourceforge.

Sunday, August 7, 2011

War Texting Allows Hackers To Unlock Car Doors Via SMS





Senior iSec researcher Don Bailey has developed an exploit which can allow the attacker to unlock car doors, hack car alarm system and even start their car, this method has been named as "War Texting", it took a time span of less than two hours for Don Bailey to hijack into Car's Alaram system and remotely start the car.


Resources claim that bailey will demonstrate this hack next week in Black Hat Security Conference at Los vegas where he will show the live demonstration of this attack. The presentation is named as "War Texting"



According To ISEC partners

We are seeing more GSM [Global System for Mobile Communications]-enabled systems popping up in consumer culture and industrial control systems. They're not just in Zoombak [Global Positioning System] location devices and personal security control systems, but also in sensors deployed for waste treatment facilities, SCADA [Supervisory Control and Data Acquisition] and call-back systems, physical security systems, industrial control systems

Shaify Mehta -  Hacker, Programmer, Cracker.

Black Hole Exploit Kit - A Deadly Russian Crimeware

Russian hackers have a very strong history with Malware development, Infact russians hackers currently own world's most dangerous malwares. One of those dangerous and popular malware's we have is the "Black Hole Exploit Kit". Black hole exploit kit is basically a collection of tons of browser exploit which takes advantage of the vulnerability on user browser in order to infect your computer.




How Does It Works?

When ever a user visits a clean website, the malicious Iframe then redirects the user to the blackhole exploit server, Which then triggers out all the well known exploits on victims browser and gives remote access to the attacker.

Cost

The annual license for blackhole exploit kit costs around 1500$, the semi annual license costs 700$ and the quarterly license costs 700$. The author also gives you option to rent the exploit kit as well as you can host the exploit kit on authors server for a small fee.

Shaify Mehta - Hacker, Programmer, Cracker.

Saturday, August 6, 2011

From A Minor Bug To Zero Day - Exploit Development




While searching on Youtube related to buffer overflow vulnerabilities, I came across an excellent presentation by Math Ahroni on Defcon which explains the complete life cycle of the exploit development, from a simple bug  to a Zero day, The presentation explains the whole process of exploit development from the process of fuzzing, location a bug, use of egg hunters etc.


The vulnerability explained in this presentation at Defcon is a HP NNM buffer overflow exploit, however it's not as easy as it looks at first, The author had to go in lots of pain and complications in order to make this exploit working.





Backtrack 5R1 Arriving On 10th August

Well here is another exciting news for all penetration testers and backtrack lovers, Backtrack will launch backtrack r1(release one) on 10th august, According to offensive security team backtrack r1 will come with around 100 bug fixes and in addition to it backtrack 5 rc1 will also include over 30 tools and numerous package updates.

bt5-r1-backtrack

According to offensive security team:


We have a few exciting items to announce in the upcoming month, one of them being BackTrack 5 R1 (Release one) which will be available for download on the 10th of August,2011. This will complete our first 3 month cycle since the last release. With over 100 bug fixes, numerous package updates and the addition of over 30 new tools and scripts – BackTrack 5 R1 will rock. We will have a pre-release event of BackTrack 5 R1 at the BlackHat / Defcon Conference a few days earlier.

Sunday, April 10, 2011

Top ten Best Hacks

Here is a list off the top 10 hacks of all time.

-->Kevin Mitnick, often incorrectly called by many as god of hackers, broke into the computer systems of the world's top technology and telecommunications companies Nokia, Fujitsu, Motorola, and Sun Microsystems. He was arrested by the FBI in 1995, but later released on parole in 2000. He never termed his activity hacking, instead he called it social engineering.
November 2002

-->Englishman Gary McKinnon was arrested in November 2002 following an accusation that he hacked into more than 90 US military computer systems in the UK. He is currently undergoing trial in a British court for a "fast-track extradition" to the US where he is a wanted man. The next hearing in the case is slated for today.
1995

-->Russian computer geek Vladimir Levin effected what can easily be called The Italian Job online - he was the first person to hack into a bank to extract money. Early 1995, he hacked into Citibank and robbed $10 million. Interpol arrested him in the UK in 1995, after he had transferred money to his accounts in the US, Finland, Holland, Germany and Israel.
1990

-->When a Los Angeles area radio station announced a contest that awarded a Porsche 944S2 for the 102nd caller, Kevin Poulsen took control of the entire city's telephone network, ensured he is the 102nd caller, and took away the Porsche beauty. He was arrested later that year and sentenced to three years in prison. He is currently a senior editor at Wired
1983

-->Kevin Poulsen again. A little-known incident when Poulsen, then just a student, hacked into Arpanet, the precursor to the Internet was hacked into. Arpanet was a global network of computers, and Poulsen took advantage of a loophole in its architecture to gain temporary control of the US-wide network.
1996

-->US hacker Timothy Lloyd planted six lines of malicious software code in the computer network of Omega Engineering which was a prime supplier of components for NASA and the US Navy. The code allowed a "logic bomb" to explode that deleted software running Omega's manufacturing operations. Omega lost $10 million due to the attack.
1988

-->Twenty-three-year-old Cornell University graduate Robert Morris unleashed the first Internet worm on to the world. Morris released 99 lines of code to the internet as an experiment, but realised that his program infected machines as it went along. Computers crashed across the US and elsewhere. He was arrested and sentenced in 1990.
1999

-->The Melissa virus was the first of its kind to wreak damage on a global scale. Written by David Smith (then 30), Melissa spread to more than 300 companies across the world completely destroying their computer networks. Damages reported amounted to nearly $400 million. Smith was arrested and sentenced to five years in prison.
2000

-->MafiaBoy, whose real identity has been kept under wraps because he is a minor, hacked into some of the largest sites in the world, including eBay, Amazon and Yahoo between February 6 and Valentine's Day in 2000. He gained access to 75 computers in 52 networks, and ordered a Denial of Service attack on them. He was arrested in 2000.
1993

-->They called themselves Masters of Deception, targeting US phone systems. The group hacked into the National Security Agency, AT&T, and Bank of America. It created a system that let them bypass long-distance phone call systems, and gain access to the pbx of major carriers

Monday, April 4, 2011

Newton’s law of gravity.Does it also apply to google?

Google gravity:- We all have read the Newton’s law of gravity.Does it also apply to google?To test it follow the instructions

Go to google.com

Type Google Gravity

Click on I’m feeling Lucky

Now you will see the effect of gravity on google.The google icon will fall down automatically.You can even pickup and throw google icon anyware.

Sunday, April 3, 2011

Google homepage will look if it gets hacked ..!!!

Google Hacker:-want to see how the google homepage will look if it gets hacked .Follow the instructions below

Go to google.com

Type Google Hacker

Click on I’m feeling Lucky