Showing posts with label hacker. Show all posts
Showing posts with label hacker. Show all posts

1/14/13

Computer hackers who stole Michael Jackson music sentenced






Two men charged with hacking into Sony Music's computers and stealing Michael Jackson's back catalogue have been sentenced to 100 hours community punishment.
Sony record company bosses purchased the music collection from the Bad hitmaker's estate for £156 million back in 2010, but the label's archive was infiltrated by cyber crooks a year later.
James Marks and James McCormick were taken into custody and charged with computer misuse and copyright offences after allegedly illegally downloading 8,000 digital files and never-before-heard Jackson songs.
Both British men pleaded not guilty in 2012 and were sentenced at Leicester Crown Court on Friday.

Spy agency ASIO wants powers to hack into personal computers







SPY agency ASIO wants to hack into Australians' personal computers and commandeer their smartphones to transmit viruses to terrorists.
The Attorney-General's Department is pushing for new powers for the Australian Security Intelligence Organisation to hijack the computers of suspected terrorists.
But privacy groups are attacking the ''police state'' plan as ''extraordinarily broad and intrusive''.
A spokesman for the Attorney-General's Department said it was proposing that ASIO be authorised to ''use a third party computer for the specific purpose of gaining access to a target computer''.
''The purpose of this power is to allow ASIO to access the computer of suspected terrorists and other security interests,'' he told News Limited.
''(It would be used) in extremely limited circumstances and only when explicitly approved by the Attorney-General through a warrant.
''Importantly, the warrant would not authorise ASIO to obtain intelligence material from the third party computer.''
The Attorney-General's Department refused to explain yesterday how third-party computers would be used, ''as this may divulge operationally sensitive information and methods used by ASIO in sensitive national security investigations.''
But cyber specialist Andrew Pam, a board member of the Electronic Frontiers lobby group, predicted ASIO could copy the tactics of criminal hackers to seize control of target computers.
Australians' personal computers might be used to send a malicious email with a virus attached, or to load ''malware'' onto a website frequently visited by the target.
''This stuff goes on already in the commercial and criminal world, and security agencies could be using the same techniques to commandeer people's computers and use them to monitor a target,'' Mr Pam said.
''Once you get control of a computer and connect to their network you can do whatever you want.''
The ASIO Act now bans spies from doing anything that ''adds, deletes or alters data or interferes with, interrupts or obstructs the lawful use of the target computer by other persons''.
But ASIO wants the ban lifted, so Attorney-General Nicola Roxon can issue a warrant for spies to secretly intercept third-party computers to disrupt their target.
The departmental spokesman said the federal government had made ''no decisions'' about whether to grant ASIO the new power.
The government would first consider advice from the federal Parliamentary Joint Committee on Intelligence and Security, which is reviewing national security legislation.
Victoria's acting Privacy Commissioner, Dr Anthony Bendall, has told the committee that ASIO's proposed new powers are ''characteristic of a police state.''
''To access a third party's computer, which has no connection with the target, is extraordinarily broad and intrusive,'' his submission states.
But the Attorney-General's Department insists that ASIO will not examine the content of third-party computers.
''The use of the third party computer is essentially like using a third party premises to gain access to the premises to be searched, where direct access is not possible,'' it states in response to questions from the committee.
''It involves no power to search or conduct surveillance on the third party.''
The department said technological advances had made it ''increasingly difficult'' for ASIO to execute search warrants directly on target computers, ''particularly where a person of interest is security conscious.''
Australian Council for Civil Liberties president Terry O'Gorman yesterday said ASIO should have to seek a warrant from an independent judge, rather than a politician.
He warned that ASIO might be able to spy on individuals - including journalists protecting a whistleblower - by tapping into their computers.
''I'm concerned they will access all sorts of information on a computer that has nothing to do with terrorism,'' he said.

MasterCard WorldWide Insights Blog hacked by Syrian Electronic Army

Earlier Today, we reported that the Syrian Electronic Army has hacked Saudi Arabian Ministry of Defense and other Government websites. Now , we have come to know that the MasterCard blog got hacked by the same hacker group.

The hack was initially identified by Eduard Kovacs from Softpedia. The hackers appear to have breached the Payments Perspective Blog from MasterCard’s Insights site(insights.mastercard.com).
  
They have added a post with title  “Hacked By Syrian Electronic Army.” The post has been removed ,at the time of writing. But you can see the post made by the hackers in Google cache: "http://webcache.googleusercontent.com/search?q=cache:https://insights.mastercard.com/2013/01/05/hacked-by-syrian-electronic-army-3/"


The google Evidence shows that the cache recorded on Jan 6 and post has been added on 5th Jan.

It appears that the Site uses the outdated Worpress version. If you check the source code of the blog, you can identify the blog uses the old version 3.3.2 of Wordpress.

"Baby please check my facebook profile" Spam mail leads to Trojan infection




A new spam campaign with the subject "I miss you , Check my new video please" targeting social media users, Report from HotForSecurity says. 

"Hi baby please check my facebook profile, i send you friend request please add me from friends.  I miss you , check my video please [LINK]" The spam mail reads. 

When a user click the bogus facebook link provided in the mail, he will be redirected to a malicious page where a java code is automatically downloaded and installs Trojan.

According to BitDefender researchers, the malicious application has been written in java script language that can compromise user's personal information.

Android malwares hosted in Google Play by "apkdeveloper"


android malware
List of malicious apps hosted by apkdeveloper


Once again, Malicious android apps have been found in Google Play.  A developer named "apkdeveloper" hosted a number of android malware in the Google Play.

The malware author used popular app names for his malicious apps by adding "super" at the end of the name . He also posted fake reviews to lure innocent users into downloading the malware .

"Obviously faked from the app either by asking people to give 5 stars to unlock the game (quite a common trick) or the people that made the app have found a way to publish reviews to the play store automatically. Wouldn't surprise me to be honest." One of the Reddit user's comment reads.

According one of the Reddit comment, the fake apps asked permissions for 'approximate location', 'percise location', 'full network access', 'read phone calls', 'mod or delete data on your sd card', 'find accounts', 'control vibration', ladies, 'run at startup', 'test access to protected storage'.

The malware author has been banned from google Play, after a Reddit post drew attention to the malware infested apps.

We are not sure how many users have been affected by this malicious app. Make sure you didn't install one of these malicious app.

Stored XSS vulnerability in Facebook and researcher got $3,500 Bug Bounty









A security Researcher Frans Rosén has discovered Cross Site Scripting vulnerability in Facebook and DropBox.

Initially , the researcher was working on finding security flaws on DropBox.  He noticed that when using their web interface there were some restrictions on what filenames that were allowed.  He tried to rename the file with '"><img src=x onerror=alert(document.domain)>.txt  But he got error message that some special characters are not allowed.

"But, if you instead, connected a local directory, created a file there and synced it, you got it inside Dropbox without any problems."The researcherexplained in his blog. "Using this method I was able to find two issues with their notification messages showing unescaped filenames."

He notified DropBox about the vulnerability and they have successfully patched the flaw.

After some time, he noticed that there is connection between DropBox and Facebook. You can add files directly from DropBox to your Facebook groups. So he was curious to test the vulnerability in Facebook also.




In his Facebook group, he tried to add the previously uploaded file in the DropBox.  After he posted in the group, the xss attack didn't work.  But when he clicked the 'Share' link in the post, he got alert message.  Yes, Successfully, he managed to run the Script in Facebook.  The XSS also worked when he shared the crafted pin from the Pinterest.

Researcher got $3,500 USD bug bounty for notifying the vulnerability, facebook fixed the vulnerability now.

Cyber attack in Japan : Malware steals 3k confidential documents from farm ministry



In a suspected Cyber attack against the Japan, Foreign hackers might have compromised more than 3000  confidential data from the country's Ministry of Agriculture,Forestry and Fishery by infecting the ministry's system with a malware.

Investigators from the governemnt revealed that malware used in the suspected cyber-attack to be HTran, a connection bouncer program believed to have been developed by a Chinese hacker group around 2003, The report from The Daily Yomiuri says.

HTran is often used in cyber-attacks to steal information, as it can send data secretly.

"The programme was also used to steal data from the Finance Ministry, as HTran data transmissions were discovered to have taken place from October 2010 to November 2011" The report says.

Initially, the ministry did not inform the police, despite the fact that the intrusion fell under the Unauthorized Access Prohibition Law. However, now, the police have launched their own investigation to determine what information has been compromised.

12/11/12

Facebook Is Down, Mobile Apps Still Working For Some — Second Big Tech Outage Of The Day (Update: It’s Back)





According to our own tests, as well as reports on Twitter, Facebook is down for a vast number of users. It’s the second big outage of the day after Google’s.
While mobile apps are still working for some — some of our writers can load everything with their phones — it’s not the case for everyone. It appears to be a DNS issue. If the address is cached on your phone, you can still access Facebook. Users who can use the mobile apps can apparently load the mobile website, as well.
Facebook experienced some downtime on November 30, making this the second time in two weeks that the site has had reliability issues.
We reached out to Facebook and will update as we learn more.
Update: It’s back after approximately 15 minutes of outage. Even though a 15-minute outage seems minor, it becomes a very important issue when it affects big services, such as Facebook and Google.
When seeing how people react to those outages on Twitter, they forget instantly that the service was down and get back to what they used to do. Outages don’t hurt a company’s reputation if it happens every now and then — unlike during Twitter’s early days.
Yet, Gmail and Facebook are two important communications tools in most people’s workflow. Facebook is a procrastination service, but a way to chat with friends, families and sometimes important work contacts. When an outage occurs, users realize that they rely so much on uptime and service reliability.
There is nothing users can do to make the service come back. It gives a glimpse of what it would be like to live without Facebook or Gmail, giving you a chance to measure the power of those companies. Love them or hate them, many need Facebook and email as much as they need a car.


11/5/12

Nov. 5 Hacks Target PayPal, Symantec,imageshack,vmware More








It's Nov. 5. Is your website still standing? According to reports, the websites of PayPal, Symantec, NBC, and more have come under fire, with many looking toward hacker collective Anonymous. But there are conflicting reports about who actually perpetrated the hacks - if at all.
November 5 is Guy Fawkes Day, named for the man who unsuccessfully tried to blow up Parliament in 1605. Alan Moore's graphic novel, V for Vendetta turned Fawkes into an anarchist anti-hero, and the Fawkes mask has become synonymous with the Anonymous hacker collective. As such, Nov. 5 now brings with it a number of high-profile hacks.
Late last night, several Anonymous-related Twitter feeds tweeted: "Paypal hacked by Anonymous as part of our November 5th protest." The tweets included a link to privatepaste.com, which reportedly included the private details of 28,000 PayPal users. At this point, however, that link is dead.
Anuj Nayarm, PayPal's head of PR, tweeted today that the company is investigating, but has thus far "been unable to find any evidence that validates this claim."
Anonymous and PayPal have tangled before. In the wake of payment services like PayPal, Visa, and MasterCard withdrawing their support for Wikileaks, Anonymous organized a distributed denial of service attack against all three firms. The attacks led to temporary outages or website slowdowns, but did not do significant damage.
Hackers are also reportedly targeting Symantec. Security Week reported that hackers dumped database and marketing details from the security firm via a zine that also went after image hosting site ImageShack. Symantec did not immediately respond to a request for comment, but told Security Week that it is investigating, but has no other details.
According to the Twitter account @doxbin, the Symantec hack was not carried out by Anonymous, but by a group known as Hack the Planet (HTP). "Anon didn't do Symantec. HTP is not affiliated with Anonymous. Do some basic fact checking," doxbin tweeted at a reporter today.
Of course, given the nature of Anonymous, anyone can actually become a member of the group simpy by saying they belong.
Over the weekend, meanwhile, NBC suffered a hacking attack by an individual (or group of individuals) running under the name Pyknic. Anonymous denied any involvement with that attack, too.

7/29/12

Microsoft Just Gave This Hacker $200,000


Microsoft Just Gave This Hacker $200,000




Microsoft gave away $260,000 to a bunch of hackers last night.
That's "hackers" in the good sense—here, the clever programmers who won its Blue Hat security contest, including a grand prize of $200,000.
The big prize was awarded to a PhD student at Columbia University, Vasilis Pappas, who was handed the check in an American Idol-style contest finale complete with loud music and confetti. The winners were announced during a party at the Black Hat hackers conference that happened this week in Las Vegas.
Two other guys took home significant prizes, too. Ivan Fratric, a researcher at the University of Zagreb in Croatia, got $50,000 and Jared DeMott, a Security Researcher for Harris Corp., won $10,000.
They all submitted ideas to help solve a really hard security problem called Return-Oriented Programming. ROP is a hacker technique that is often used to disable or circumvent a program's computer security controls. Twenty people submitted ideas in the contest.
Without getting into too much technical detail, Pappas came up with something called kBouncer which blocks anything that looks like an ROP attack from running.
It's become popular these days to pay security researchers bounties. But what's cool about the Blue Hat contest is that it paid the researcher for actually coming up with a fix to a problem.
Other companies have "bug bounty" programs that reward researchers for simply identifying flaws. Google pays hackers up to $20,000 a pop for reporting bugs found in Google's software to Google instead of, say, selling them to the bad guys. Mozilla and Facebook also have bug bounty programs.
Microsoft and Adobe, by contrast, don't pay bounties.
But Microsoft promised that this first Blue Hat prize won't be its last. So this may be a sign of a smart new approach to engaging with security researchers for the software giant.


Related Posts Plugin for WordPress, Blogger...