Showing posts with label Hacks. Show all posts
Showing posts with label Hacks. Show all posts

January 21, 2011

Trapster hacked; 10 million users might be at risk

The popular online speed trap tracker, Trapster, has issued an email to its 10 million registered members, citing that their passwords may have been hacked. The mobile application is available on a number of smartphones, including the iPhone, a number of BlackBerry and Android headsets and other smartphones.

The website has over 10 million mobile users, who all might be at risk of having their password stolen. The company issued an email stating that users should change their passwords. Although the company still doesn't know exactly how much data was compromised, they can only assume the hacker acquired all of the online mobile data, which includes usernames, emails and passwords.

How do I know if my password was hacked?

We believe it's best to be cautious.  So, if you've registered your account with Trapster, then it's best to assume that your e-mail address and password were included among the compromised data.

With over 10 million email accounts and passwords stolen, it won't take long for a hacker, or team of hackers, to decrypt the encrypted passwords. It's recommended that users change their password on Trapster and any other account on the Internet they share the same password with.

This database leak comes just a month after Gawker had their database, source code and other private information stolen. A list of usernames and unencrypted passwords were later posted on the Internet.

January 18, 2011

Microsoft support scam continues to plague Australians

Australians continue to be contacted by scammers over the phone promoting themselves as official Microsoft support representatives and offering to fix their computer troubles.

The scam, which preys on the notion that most households have a computer running Windows, first began almost two years ago, and sees someone ring an Australian's home phone number claiming to be from Microsoft support and mentioning that a virus or problem has been discovered with their computer. The scammers then ask the person for remote access to their computer, assuring them the process is "completely safe" and that they'll do their best to fix the problem.

A short time later, after exploiting the computer and pretending to fix the problem which didn't exist in the first place, the scammers then ask the person to pay for the service with many Australians falling victim and handing the scammers their credit card details for payment.

According to the Sydney Morning Herald, "thousands" of Australians have been targeted by the scam which in recent months appears to have resurfaced after widespread publicity raised awareness of the scam late last year. In December, Microsoft Australia told the paper the company was receiving between 2 and 50 complaints per day about the scam, but remains powerless to act against it.

"There's a number of different organisations doing this and they're changing their names almost constantly - we hear new names every week," Stuart Strathdee, Microsoft Australia's chief security advisor told the Sydney Morning Herald in December.

Australian authorities remain powerless to act against the scammers, who are based overseas and difficult to track down. Instead, they're urging Australians to hang up on the scammers and not allow them access to their personal computer.

December 9, 2010

Anonymous takes up the fight for WikiLeaks

Members of infamous hacker group Anonymous have reportedly taken up WikiLeaks' cause, launching denial of service attacks on a range of sites connected to founder Julian Assange.


According to Ars Technica, Anonymous has attacked sites including PayPal, Swiss bank PostFinance and the site of the Swedish prosecutors in Mr Assange's sexual assault case. An Anonymous member going by the alias Coldblood has told the BBC that targets are being made of sites that are ''bowing down to government pressure''.


"As an organisation we have always taken a strong stance on censorship and freedom of expression on the internet and come out against those who seek to destroy it by any means,'' he said.


The group expressed a similar sentiment on their website, stating that they ''will find and will attack those who stand against Wikileaks and we will support WikiLeaks in everything they need.''


PayPal was reportedly the group's first target after the company cut off WikiLeaks' account - the PayPal blog went offline for a short time yesterday, though the main site appeared unaffected. Attacks against PostFinance, who closed Mr Assange's account earlier this week, appear to have been more successful - Ars Technica reports the bank's site went offline for more than 16 hours. It remained inaccessible as of 1AM EST, but had come back online by 4.45AM.


Further attacks are reportedly planned against Twitter, after it was claimed the site had prevented the #wikileaks hashtag from appearing in the trending topics list. Twitter has denied the claims, saying there are a number of factors that determine whether a topic is trending or not.


Seemingly in response to actions by Anonymous, the group's site was itself taken down by a denial of service attack late yesterday, but was online by 5AM EST after it was moved to a new server.

MasterCard website taken down by WikiLeaks supporters

After Amazon pulled the plug on WikiLeaks' hosting solution with the company, others soon followed suit. PayPal announced that they have cut off donation support for the whistleblowing site, and on Monday, MasterCard took the same stance as PayPal. Internet hacktivist group Anonymous decided to have their say in supporting WikiLeaks by DDoSing PayPal and MasterCard.

Neowin earlier today reported on several attacks to banking websites that were blocking donations to the WikiLeaks organization. Now, Anonymous has issued distributed denial of service attacks onto credit card site MasterCard after they stopped donation support for WikiLeaks as well. Attempts to reach MasterCard's main site are, at the time of this writing, met with either extremely long load times or a connection timeout.

Early this morning, the group Anon tweeted from @Anon_Operation this message: "WE ARE GLAD TO TELL YOU THAT http://www.mastercard.com/ is DOWN AND IT'S CONFIRMED." Twitter is also now a target for Anonymous as the social networking website reportedly are preventing the #wikileaks tag from showing up among trending topics.

While Anonymous is simply trying to get a point across, many innocent bystanders are getting caught in the crossfire. Users of MasterCard are not currently able to use the online services provided by the credit card company. With the arrest of Julian Assange, Anonymous has seemingly stepped up to fill in the hole and add support to the whistleblowing organization.

MasterCard does want to let users know that they "are working to restore normal speed of service. There is no impact whatsoever on Mastercard or Maestro cardholders' ability to use their cards for secure transactions." Anonymous has recently stepped up in number of attacks issued, from the recent takedown of the RIAA and MPAA websites, to the major banking and credit service websites highlighted in the past few days.

December 4, 2010

Wikileaks blocked? Access it through these mirror sites

Domain name provider EveryDNS has pulled the plug on Wikileaks citing reasons that the DDoS attack the site was attracting is taking strain on the system and the DNS service had to be terminated to protect half a million sites that EveryDNS has to serve. Typing Wikileaks.org in the browser’s address bar currently leads to nowhere.

In a statement on its Web site, EveryDNS.net said

EveryDNS.net provided domain name system (DNS) services to the wikileaks.org domain name until 10PM EST, December 2, 2010, when such services were terminated. As with other users of the EveryDNS.net network, this service was provided for free. The termination of services was effected pursuant to, and in accordance with, the EveryDNS.net Acceptable Use Policy.

More specifically, the services were terminated for violation of the provision which states that “Member shall not interfere with another Member’s use and enjoyment of the Service or another entity’s use and enjoyment of similar services.” The interference at issues arises from the fact that wikileaks.org has become the target of multiple distributed denial of service (DDOS) attacks. These attacks have, and future attacks would, threaten the stability of the EveryDNS.net infrastructure, which enables access to almost 500,000 other websites.

Thus, last night, at approximately 10PM EST, December 1, 2010 a 24 hour termination notification email was sent to the email address associated with the wikileaks.org account. In addition to this email, notices were sent to Wikileaks via Twitter and the chat function available through the wikileaks.org website. Any downtime of the wikileaks.org website has resulted from its failure to use another hosted DNS service provider.

After leaking secret US embassy cables, whistleblower website Wikileaks has been struggling to find a place on the Internet. The site was still fending off a DDoS attack when it was ousted by Amazon. With EveryDNS refusing to provide DNS service, the website came to a halt the third time this week.

However, just hours after the site was eliminated from the web, Wikileaks was back on another domain - Wikileaks.ch. The website is also available through a number of other suffixes and IP addresses:

IP mirrors

DNS mirrors

Proxy mirrors

October 15, 2010

iPad hack lets you download popular publications for free

Want to read Wired, the New Yorker, or another popular publication on your iPad for free? Well, it seems that you can.

According to the Huffington Post (via CrunchGear), the iPad has a security hole that allows anyone with a brain to freely download paid publications without dropping a cent. In just a few simple steps and a single word change, a user can make a bunch of publications show "download" instead of "buy." This will actually allow the user to download free of charge. The single word is located in a .plist file. Once changed from "purchasable" to "viewable" the iPad seems to be fooled into thinking that you don't have to pay to check out these apps. Similar types of vulnerabilities can be found with other, non-publication apps as well.

Adobe, who manages both the Wired and New Yorker iPad apps has told the Huffington Post that are very concerned about piracy issues on the iPad. In their statement, Adobe confirms the problem and vows to protect its content.

"We have confirmed that it is possible for experienced users with detailed instructions to access some digital publications on the iPad that have not been purchased. We are working on a fix and expect to deliver a new version of our Digital Content Viewer to publishers on Friday, October 8."

Seeing as it's already the 14th of October and the hack was still working a few days ago (when the Huffington Post posted their article), it would seem that the parties involved in the fix don't seem to be in too much of a rush. At the time of writing, no statement has been made by Apple. It seems that publishers will have to find a way to protect their content by their lonesome.

September 18, 2010

August 7, 2010

WikiLeaks posts huge 'insurance' file

As pressure mounts on whistle-blowing web site WikiLeaks, a huge encrypted file named 'Insurance' has appeared on its pages.

The 1.4GB file is lurking there ready to burst open should something unsavoury happen to leaker-in-chief Julian Assange and his pals, we surmise.

The organisation is known to have more US military secrets to reveal to us, following its exposure of 77,000 documents about Afghanistan that were posted in public last month.

Bonkers commentators in the US have been calling for Assange's head on a platter, claiming WikiLeaks' leaks endanger combat soldiers and Afghan informants' lives.

Such criticism seems to have prompted the whistle-blowing outfit to secure US Government help in filleting the files of such information, while enabling the rest of us to find out exactly how many people have died in our name.

WikiLeaks held back some 15,000 intelligence reports from exposure last month. It is also believed to have copies of around 260,000 classified diplomatic cables, over which Army intelligence analyst Bradley Manning finds himself currently gaoled.

WikiLeaks itself refuses to discuss security procedures.

Manning reckons the secret cables expose "almost criminal political back dealings" and said he thought Secretary of State Hillary Clinton would "have a heart attack" if the files were made public.

Government secrecy is, of course, the enemy of democracy.

May 21, 2010

Hackers Find Ways to Remotely Control Cars, Terror to Ensue

A team of researchers from the University of Washington and the University of San Diego have discovered a way to hack a car.

Engadget is reporting that a team of researchers have discovered a way to hack the onboard computer of certain cars. Once the hackers are in, they can access the car’s computer wirelessly, even while driving in another car next to the hacked vehicle. They can then affect the car by turning on hazard lights, flashing the brights, and even rolling down the windows. Or they could disable the brakes and lock the engine while you are driving at speed, sending you to a horrible death.

In our increasingly digital world, fear of the hacker has become all encompassing, one that acts as justification for the overreactions of many. Yes, malicious hackers are a problem- a nuisance to some, a criminal threat to others- but hackers are not magic. They can’t destroy cities (looking at you Live Free or Die Hard)- if they could, someone would have done it, then posted online how they just pwned a city. For the most part, hackers are just people that are curious to see how much they can get away with. It is a challenge to break the code of something- and the vast majority of hacks are harmless, and don’t really have any negative effects. Many are even useful and designed to test security, in the same way someone might push a door to make sure it is sound. And then there are some hacks that can scare the crap out of you.

The university researchers were testing to see how tight security of computers inside of cars are, and the answer is that there is hardly any security at all. The researchers needed to have a physical connection to initially access the car’s Engine Control Unit (ECU). Once they do have that access, they can control the entire operations of the car wirelessly, and tell the car to ignore the driver’s input.

For the test, researchers were able to connect wirelessly to a car’s ECU, and disable the brakes while it was driving. The test also proved that they could seize the engine, and even brake certain wheels, which would send the car sliding before potentially flipping over.

The test concluded that the security of ECUs is essentially nonexistent. If someone can gain access, you are in trouble. The good news is that the person hacking the ECU would need physical access to the car’s computer, so in that sense the security needed is the same as preventing car theft.

May 5, 2010

US Treasury websites hacked

Computerworld reports that three websites affiliated with the US Treasury department have been infected with code that distributes malware to visitors. Roger Thompson, a researcher at AVG, discovered on Monday that three domains belonging to the US Bureau of Engraving and Printing had malicious iframe HTML code that contained a redirect to a web site hosted in Ukraine.

The Ukrainian website, a site known for similar attacks, was using a commercially available malware distribution tool called Eleonore Exploit Pack to infect users' machines. The methodology of the infection of the website is currently unknown, but users are warned to stay away from the website until sufficient corrective actions are taken.

The IT staff at the websites are aware of the situation, and have taken them offline until cleanup has been completed. Visitors to the websites are greeted with a "Page Not Found" screen.

ComputerWorld was unable to reach the Treasury Department for comment.

April 23, 2010

Blizzard kicked over 320,000 hackers from Battle.net

Blizzard posted an official annoucement on their forums that they have kicked over 320,000 accounts from Battle.net they found were violating the terms of service.

We’ve recently banned over 320,000 Warcraft III and Diablo II accounts that were found to be violating the Battle.net Terms of Use. If this is a first offense, the CD key associated with the banned account will be suspended for 30 days, while repeat offenders will see their keys banned permanently. All account ban decisions are final.
We would like all players to remember that abuse of unintended mechanics and/or use of third party programs is a violation of the agreement made when signing on to Battle.net, and can subject your account to disciplinary action up to and including a permanent ban of its access to the service.
Many account closures come as the direct result of tips emailed to our hacks team by legitimate Battle.net users.

This is not the first time Blizzard has done something like this. In November of 2008 they banned over 350,000 accounts from Battle.net stating, "Cheating ruins the game experience for legitimate players, and we will not tolerate it."

April 22, 2010

Virus that steals bank information is on the rise

The BBC is reporting that Zues, a virus that steals your online bank account information is on the rise. Trusteer says of the 5.5 million computers that they monitor, one in 3,000 is infected with the Zues virus.

Zues 1.6 can infect users using both Internet Explorer and Firefox. Once infected the virus records your keystrokes when logging into your bank's website. The data is then sent to a remote server where it is used or sold by the cyber gang.

"We expect this new version of Zeus to significantly increase fraud losses, since nearly 30% of internet users bank online with Firefox and the infection is growing faster than we have ever seen before," said Amit Klein, chief technology officer at Trusteer.

In March 2010, parts of the primary control center for the Zeus botnet were taken offline when the Kazakhstani ISP that was being used to administer it was cut off. Unfortunately, though, it is back on the rise as the hackers have started to expand their botnet.

April 17, 2010

Hacker says Windows is more secure than Mac; calls Apple fans "ignorant"

Lifehacker pointed to an interesting piece over at CNet. In a Q and A interview by Elinor Mills, hacker extraordinaire, Marc Maiffret, has said what no one before him dare say--Windows is more secure than Mac OS. While Apple likes to claim a higher security standard than their rival Microsoft, Maiffret, who is now the Chief Security Architect at FireEye, begs to differ.

When asked about the current state of security in Microsoft products, Maiffret responded:

"Now when you look at Microsoft today they do more to secure their software than anyone. They're the model for how to do it. They're not perfect; there's room for improvement. But they are definitely doing more than anybody else in the industry, I would say"

In a follow up question, Maiffret was asked if he feels Apple is taking security seriously. In his response, Maiffret calls out Apple and its "ignorant" community saying:

"It's even a little scarier with them because they try to market themselves as more secure than the PC, that you don't have to worry about viruses, etc. Anytime there's been a hacking contest, within a few hours someone's found a new Apple vulnerability. If they were taking it seriously, they wouldn't claim to be more secure than Microsoft because they are very much not. And the Apple community is pretty ignorant to the risks that are out there as it relates to Apple. The reason we don't see more attacks out there compared to Microsoft is because their market share isn't near what Microsoft's is"

Marc Maiffret began hacking as a teenager. He was a lad of 17 when he started eEye--a company focused on product development and vulnerability research. Since then, Maiffret has become a revered expert in the world of software security.

April 16, 2010

Chinese cyberattack on Australia

A company in Australia came under a cyberattack from China that was intense enough to slow traffic on part of the country's second-largest broadband network, company officials said Thursday.

Among companies affected were Australian Associated Press, the national news agency, and the Australian branch of Rupert Murdoch's News Ltd., but they were not the targets, said the telecommunications company Optus.

Attackers in China flooded an international network link to one of Optus' large commercial clients in Australia in what is known as a denial-of-service attack, the company said. This caused congestion that significantly slowed Internet and e-mail links to other customers on that link, including AAP and News.

Optus declined to identify the company targeted, citing commercial confidentiality. News Ltd.'s The Australian newspaper reported that it was a multinational financial institution, but had no further details. Optus also declined to say how many customers were affected.

The attack was blocked after about 2 1/2 hours.

Denial-of-service attacks involve a flood of computers all trying to connect to a single site at the same time, overwhelming the server that handles the traffic.

Cyberattacks linked to China have gained more attention since Google Inc. accused Chinese hackers in January of trying to plunder its software coding and of hijacking the Gmail accounts of human rights activists protesting Beijing's policies.

Early this month, a foreign journalists' organisation in China had its Web site disrupted by attackers in China and the United States - the latest in a string of such cases.

Yahoo e-mail accounts belonging to foreign journalists in China have also apparently been hacked in recent weeks, and at least one rights group focusing on China says it has been hit by denial-of-service attacks.

Tony Gillies, editor-in-chief of AAP, said the company's e-mail and Internet services were slowed by the attack but delivery of its news services was not affected significantly.

"Our system protocols meant that we were OK," Gillies said. "We can't find any evidence that we were being targeted."

Optus is Australia's second-largest Internet Service Provider.

April 10, 2010

Windows Phone 7 Series emulator “unlocked”

wp7s_unlocked

It was not a question of if, but when. The Windows Phone 7 Series emulator ROM has been completely unlocked revealing more of the preproduction mobile operating system Microsoft didn’t want you to see.

Dan Ardelean who has been tinkering with the ROM for some time now has published a modified version of the “BIN” file which removes the locks Microsoft’s put in place to hide other components of the ROM.

Although there is definitely a lot to explore, to be devil’s advocate I must remind everyone that Windows Phone 7 Series and this ROM in particular is still a very early piece of work and the components in this emulator demo is not representative of what the final product will be. Play with it, have fun with it, but don’t build expectations on it.

March 29, 2010

Indian Web Address Used to Hack Bangladesh Websites

The Prime Minister's Office (PMO) in Bangladesh says it has traced an Indian IP (Internet Protocol) address used for hacking 20 district portals, but acknowledges that the real identity of the hacker could be concealed.


The hacked sites were operated by the PMO and the incident is considered to be a serious security lapse.


"We have initially detected an Indian IP address that belongs to Videsh Sanchar Nigam Limited (VSNL), one of the largest Internet service providers in India," said S.M. Akash, media manager of Access to Information (A2i) team of the PMO.
Professional hackers, however, use various methods to hide their real IP address and location, The Daily Star quoted him as saying.


The Bangladesh government will ask VSNL for details of the IP address and the hacker's location, said the official.


Twenty district websites operated by the PMO were hacked Saturday.


Some Hindi letters and "JAI HIND!" were posted on the hacked websites.


The hackers claiming to be Indians threatened Bangladesh with a cyber war if any Pakistani terrorist enters India via Bangladesh.


Home Secretary Abdus Sobhan Sikder said they restored the websites Saturday night.

March 26, 2010

iPhone hacked via Safari, SMS database stolen

The Pwn2Own hacking contest is well under way today and the iPhone has fallen victim to a previously undisclosed Safari flaw.

Security researchers Vincenzo Iozzo and Ralf Philipp Weinmann demonstrated hacking into an iPhone by luring a fully patched iPhone to a specifically crafted website. According to the ZDNet 0-day security blog, the exploit allowed the researchers to steal the entire SMS database, including text messages that had already been deleted.

The researchers built the exploit in just two weeks. They claim the exploit could also reveal the phone contact list, photos and iTunes files. Little details are known about the exploit but the flaw was demonstrated on a fully patched iPhone 3GS running firmware 3.1.3. The pair won a $15,000 cash prize and got to keep the hijacked iPhone. Full details of the exploit will remain undisclosed until the issue is reported to Apple and a patch is released.

At last years Pwn2own, Microsoft flaunted a very speedy response time to a bug, as well as Google's Chrome being the only browser to survive the first day. Four new major flaws were discovered in the three main browsers tested; IE, Firefox and Safari. Following up from Chrome's first day of attack, the browser never suffered any major vulnerabilities. In other news, Charlie Miller - a well known hacker, is expected to demonstrate a new security flaw, today at Pwn2own, on an Apple Macbook Pro running Mac OSX.

February 20, 2010

Report: Hackers attacked Google from China schools

The Associated Press reports: The Internet attacks that may end up driving Google Inc. out of China originated from two prominent schools in the country, according to a (New York Times) story published late Thursday.

continue reading at seattlepi.com

February 19, 2010

WordPress.com goes down, takes 9.2 million blogs with it

TheNextWeb reports that WordPress.com is currently down and affecting 9.2 million hosted blogs.

High profile hosted blogs include TechCrunch, GigaOM, CNN blogs, Redhat and Fail Blog, all of which are down at the time of writing. WordPress officials said the company was aware of the issues and that it was currently working to bring the blogs back online. On WordPress' official Twitter account an hour ago, a spokesperson commented "we're working on restoring service now".

WordPress is an open source blog publishing application that utilises PHP and MySQL. The service has seen an extraordinary rise in popularity since its introduction in 2003. According to statistics in September 2009, WordPress is being used by 202 million websites worldwide. Quantcast stats show that around 220 million people visit one or more WordPress.com blogs every month, and they view over a billion pages on those blogs.

November 19, 2009

21 Hacks Geeks must know

As a Geek you are expected to have a little more  Technical knowledge than the rest of the population. The following are Hacks that must be known by a Geek. All of the Hacks are related to Computing. I don’t pretend of having known all the hacks listed here.

  1. Know how many meanings does the word Hack has.
  2. Overclock a CPU.
  3. Overclock a GPU (Graphics Processing Unit).
  4. Connect a computer remotely.
  5. Use a Proxy (Anonymously surf the Web).
  6. Bypass the BIOS password.
  7. How to Leech Wi-fi.
  8. Know the Capabilities of your own computer.
  9. Bypass Web filter of Public computers.
  10. Crack WEP and WPA key.
  11. Bypass password on major Operating Systems.
  12. Install a network capable device for use in a network (like Printer, Router etc…).
  13. Boot a computer using a USB drive or a Live CD or a Network drive.
  14. Create a website (web page) using plain text editor like Notepad.
  15. Go to your Modem’s homepage.
  16. Install a Linux distro.
  17. Use CMD to perform basic to advanced Windows functions.
  18. Remove virus from a computer. Bonus: Disassemble the virus using OllyDbg (or similar software… Bonus: use debug command of Windows XP CMD) and make it work in reverse direction.
  19. Program the computer by using at least 2 Programming Languages.
  20. Disassemble a computer and assemble it properly.
  21. Don’t Laugh at other Geeks.