Give your Desktop a Mozaic Touch

Experience the Windows 8 Metro Stlye UI on your Computer

Windows 7 God Mode

Get an Advanced Control Panel in Windows7 by enabling God Mode

Download Internet Explorer 9

Enjoy The Internet in a New and Secure Way

Microsoft Office 2010 Professional Activation

Activator for Microsoft Office 2010 Professional 100% Working..!!

Flash Wallpapers for Mobile

More than 175 Flash/SWF wallpapers for Mobile with System Info

Showing posts with label Hacking news. Show all posts
Showing posts with label Hacking news. Show all posts

Wednesday, May 2, 2012

Skype IP address Vulnerability may not be so new

Skype+Vulnerability+Exposing+User+IP+Addresses          Skype is warning users following the launch of a site devoted to harvesting user IP addresses.The Skype IP-Finder site allowed third-parties to see a user's last known IP address by simply typing in a user name.
 
          A script has been uploaded to Github that offers these options. According to the page, it can be used to lookup IP addresses of online Skype accounts, and return both the remote and the local IP of that account on a website.

          The script is available. You need to just enter the user name of a Skype user, fill out the captcha, and click the search button to initiate the lookup. You will receive the user’s remote IP and port, as well as the local IP and port.

          Adrian Asher, director of product Security, Skype “We are investigating reports of a new tool that captures a Skype user’s last known IP address. This is an ongoing, industry-wide issue faced by all peer-to-peer software companies. We are committed to the safety and security of our customers and we are takings measures to help protect them.” The proof of concept is fairly simple. All an attacker needs to do is download a special Skype variant and alter a few registry keys to enable debug-log file creation.When adding a Skype contact, before sending the actual request, the victim’s information card can be viewed. At this point, the log file records the user’s IP address.

          The software, posted on Pastebin, works on a patched version of Skype 5.5 and involves adding a few registry keys that allow the attacker to check the IP address of users currently online. Services like Whois will then give some other details on the city, country, internet provider and/or the internal IP-address of the target.

          This particular flaw was discussed in a paper presented by an international team of researchers in November at the Internet Measurement Conference 2011 in Berlin.

          There is currently no way of protecting yourself against the lookup of the IP address, other than not logging in to Skype when the software is not needed. The only other option would be the use of a virtual private network or proxy to hide the IP address from users who look it up.

Is $10,000 per day from Google Ads less for the Flashback malware Creator?

Flashback+malware+Creater+earning+$10,000+per+day+from+Google+Ads
          In a recent analysis of the business model behind the Flashback Trojan, Symantec security researchers reported that the main objective of the malware is revenue generation through an ad-clicking component. Security researchers at Symantec are estimating that the cyber-crimibals behind the Flashback Mac OS X botnet may have raked in about $10,000 a day.

           Dr. Web, the Russian security firm that firm discovered the massive Flashback botnet last month, has provided new data on the number of Macs still infected with the software. The results show that while close to 460,000 machines remain infected, the botnet is shrinking at a rate of close to a hundred thousand machines a week as Mac users get around to downloading Apple’s tool for disinfecting their machines or installing antivirus.

           When an infected user conducts a Google search, Google will return its normal search results. Flashback waits for someone to click on an ad, and once this happens the user is silently directed to another, irrelevant ad that generates revenue for the attackers. As a result, Google doesn't know someone has clicked into its client's ad, and the client never knows its ad wasn't delivered. Ultimately, Google's advertising clients are paying for Flashback's attackers to host ads on Google.

Story Posted on Symantec’s blog:
          The Flashback ad-clicking component is loaded into Chrome, Firefox, and Safari where it can intercept all GET and POST requests from the browser. Flashback specifically targets search queries made on Google and, depending on the search query, may redirect users to another page of the attacker’s choosing, where they receive revenue from the click . (Google never receives the intended ad click.)

          The ad click component parses out requests resulting from an ad click on Google Search and determines if it is on a whitelist. If not, it forwards the request to a malicious server.

Hackers tricked Mac users into downloading the virus by disguising it as an update to Adobe Flash video viewing software.

Tuesday, April 3, 2012

Chinese hacker targeting Indian government and Tibetan activists Sites

Chinese+hacker+targeting+Indian+government+and+Tibetan+activists+Sites
        Websites of Indian government and Tibetan activists in the country are under attack in a cyber attack campaign engineered by a Chinese hacker, working with one of the world's largest e-tailers Tencent.

          The cyber criminal in question is Gu Kaiyuan, once a graduate student at a Chinese university that receives government financial support for its computer security program and currently an employee at Chinese portal Tencent. Before Kaiyuan initiated the exploits, collectively called the Luckycat campaign, he was involved in recruiting students for his school’s computer security and defense research.

          The Luckycat cyber campaign, has been linked to 90 attacks in recent past against targets in India and Japan, as well as against Tibetan activists, said the report released by the Japanese network security firm. 'Luckycat' has been able to compromise about 233 computers many of which are in India. A report on the campaign from cloud security company Trend Micro shows that the Luckycat perpetrators began around June 2011.

Also, Trend Micro was able to find a set of campaign codes used to monitor compromised systems. “The campaign codes often contain dates that indicate when each malware attack was launched. This demonstrates how actively and frequently the attackers launched attacks,” the report reads. “The campaign codes also reveal the attackers’ intent, as some of these referenced the intended targets.”

The report did not directly implicate the Chinese government, but security researchers believed that the style of the attacks and the types of targets indicated state-sponsored spying.

50K Cards Compromised using Credit Card Processor

50K+Cards+Compromised+using+Credit+Card+Processor
          Some 50,000 credit and debit cardholders may have their information exposed following a security breach at Global Payments. The breach occurred sometime between between Jan. 21, 2012 and Feb. 25, 2012.

          Both Visa and MasterCard have confirmed they have warned U.S. banks that a credit card processor was reportedly breached. Both firms say their own security systems were not compromised. MasterCard said law enforcement has been notified of the matter and an "independent data security organization" is conducting a forensic review of the matter. "MasterCard's own systems have not been compromised in any manner," a company spokesman said in a statement. The company will "continue to both monitor this event and take steps to safeguard account information."

           Because it sits in this middle ground directing where payment information goes, an attack on its system would leave a lot of private financial data exposed. Alerts sent out to U.S. banks late last week advised them that certain cards may have been compromised.

          "While the scope and details of the attack are not yet known, it shows that three years after the Heartland Payment Systems breach of 130 million credit card numbers, credit card data is still vulnerable," Roiter said.

Friday, March 30, 2012

Kelihos Botnet with 110,000 PCs take down finally

Kelihos+Botnet+with+110,000+PCs+take+down+finally
       Botnets are particularly insidious, using thousands of virus-infected computers which their owners are unaware are being used for sending out spam, launching denial-of-service attacks and stealing data. But taking down a botnet poses challenges. The main problem is that legitimate security companies can’t use the same type of weapons as criminals.

          A group of malware experts from security companies Kaspersky Lab, CrowdStrike, Dell SecureWorks and the Honeynet Project, have worked together to disable the second version of the Kelihos botnet, which is significantly bigger than the one shut down by Microsoft and its partners.

          Kelihos is used to send spam, carry out DDoS attacks, and steal online currency such as bitcoin wallets. It operates as a so-called "peer-to-peer" bot network, which are more difficult to take down than those with a centralized command and control servers (C&C), according to Tillmann Werner, a senior researcher at CrowdStrike.

          Seculert reports that Kelihos-B, which was distributed as a Facebook worm over recent weeks, is still active and spreading - even after the shutdown attempt by CrowdStrike and Kaspersky Labs this week. The peer-to-peer Kelihos botnet, also known as Hlux, was sucked into a 'sinkhole' by a small group of security experts from Kaspersky Lab, Dell SecureWorks, CrowdStrike Intelligence Team and the Honeynet Project.

          It's unclear who is behind Kelihos, he said. It was created last October after Microsoft used a sinkhole to halt the original Kelihos botnet, which had infected about 41,000 computers. The latest Kelihos used servers with hosts registered in Sweden, Russia and Ukraine that were controlled by a botmaster, according to CrowdStrike.

     The machines are still infected, and the researchers are relying on ISPs to inform affected users. What is to say this botnet won’t just morph itself again? “That is a possibility,” said Crowdstrike’s Mr. Meyers. “But when that happens, we’ll be there to take it back down.”

A Russian Zeus attacker Sentenced from Million Dollar Fraud

 A+Russian+Zeus+attacker+Sentenced+from+Million+Dollar+Fraud
       A Russian Hacker, who was part of an elaborate Cyber attack that used Zeus Banking Trojan in U.S. visas to move cash stolen from U.S. businesses out of the country was sentenced on March 23 to two years in U.S. federal prison.

        Nikokay Garifulin received a two-year prison term for his involvement in a global bank fraud scheme that used hundreds of phone bank accounts to steal over $3 million from dozens of U.S.accounts that were compromised by malware attacks.
 
           According to court documents and statements, Garifulin was part of a cyber bank fraud scheme, backed by Eastern European hackers to steal money from the bank accounts of small and mid-sized businesses throughout the U.S. The cyber attacks included Zeus Trojan, would embed itself in victims’ computers and record keystrokes as they logged into their online bank accounts.

          The hackers responsible for the malware then used the account information to take over the victims’ bank accounts and make unauthorized transfers of thousands of dollars at a time to accounts controlled by co-conspirators, including Garifulin, who were members of a money mule organization.

         Garifulin collected money that had been withdrawn by mules from the phony accounts in the United States and, under the direction of the organization’s leader, distributed it to other co-conspirators and transported it back to Eastern Europe. GARIFULIN also arranged for fake passports to be transferred from Eastern Europe to mules in the United States.

         In addition to his prison term, Garifulin, 23, of Volgograd, Russia, was sentenced to three years of supervised release. He was also ordered to forfeit $100,000 and to pay $192,123,122 in restitution.

Return of Lulzsec, Dump 170937 accounts from Military Dating Site

        Another Hacking group after Lulzsec, comes with name LulzsecReborn has posted names, usernames, passwords, and emails of 170,937 accounts on MilitarySingles.com on Pastebin as part of the group’s Operation Digiturk. LulzSec was a major ticket item last year as the group hacked a number of high profile Web sites all in the name of the “lulz.” After their so called “50 Day Cruise,” the group broke up and went their separate ways.Hacker claim that, There are emails such as @us.army.mil ; @carney.navy.mil ; @greatlakes.cnet.navy.mil ; @microsoft.com ; etc.. in dump.
 
         In response to a query by the Office of Inadequate Security, ESingles, the parent company of MilitarySingles.com, said that there is “no actual evidence that MilitarySingles.com was hacked and it is possible that the Tweet from Operation Digiturk is simply a false claim.”. LulzSecReborn hack the site and added his deface page here, (as shown in above page) and replied “Stupid Administrator: ‘There is no evidence MilitarySingles is hacked’. Well guess what?”Commenting on the breach, the Office of Inadequate Security said: “If you know a member of the military who uses or has used the site, do them a favor and suggest they change their password on any site where they may have reused it – including their mil.gov email account.”

          In a video posted to YouTube last weekend and titled LulzSec Returns, the group says it decided to "bring back our humble hacking group and set sail towards the interwebs again". Referring to the arrests, it said these had "merely disrupted the active faction".

Thursday, March 29, 2012

Breaching Hundreds of KPN Servers

          Dutch Police Arrest 17-year-old Suspected of The Dutch High Tech Crime Team has arrested a 17-year-old suspected of compromising customer account data on hundreds of servers belonging to telecommunications operator KPN. The teenager was arrested last Tuesday in the Dutch town of Barendrecht, where police seized an encrypted computer, two laptops and other storage media including external hard drives, DVDs and USB sticks, the Dutch Public Prosecution Service announced on Monday.

          "He has made a confession," said Wim de Bruin, spokesman for the Public Prosecution Service.
The arrested teenager called himself "xS", "Yoshioka" and "Yui" online, and is suspected of breaching the security of hundreds of KPN servers last January, compromising user data and damaging KPN's infrastructure, said the Prosecution Service.

          KPN, the biggest telecom operator in the Netherlands, was forced to overhaul its systems to get rid of installed malicious software after the hack was discovered. The National Cyber Security Center of the Netherlands also assessed the security breach and concluded that national security was not compromised.In the wake of the hack, KPN suspended access to 2 million email accounts and asked users to change their passwords, after account details of KPN customers were leaked on Pastebin in early February. The KPN data that appeared online was filtered from the captured database.

          The arrested teenager was followed online for weeks and the Dutch police collaborated closely with the Cyber Terror Response Center in South Korea and the Australian Federal Police, according to the Prosecution Service. A person using the aliases "Yui", "Yoshiaka' and "xS", appeared to have bragged about the KPN hack in a chat channel for students at the Korea Advanced Institute of Science and Technology (KAIST), the prosecution said.

          Besides hacking KPN the 17-year-old is also suspected of hacking computers at KAIST and at Trondheim University in Norway, and of breaching the security of Tokohu University in Japan. He is also thought to have been running a website used for selling stolen credit card data, according to the prosecution.
According to De Bruin the teenager did not confess to the other allegations. "Those are still being investigated," he said.

          After the teenager's arrest, a judge ruled that he was to be kept in custody for at least two weeks. After that period, the Prosecution Service will assess if he has to be kept in custody, or can be freed until his trial. The suspect has legal support from a solicitor and was visited by the Dutch council for child protection, said the Prosecution Service. According to De Bruin, the maximum penalty the teenager faces is two years in prison. The maximum penalty is reduced due to his age. "For an adult the maximum penalty would be six years imprisonment," De Bruin said.

           In the wake of the hacking, KPN said last week it will appoint a Chief Security Officer (CSO), and later this year will set up a permanent control center to monitor its systems. The company has replaced the compromised systems and will spend months checking the security of all its other systems.

Justin Bieber's Twitter account - hacked!

          Lend a little sympathy to pop star Justin Bieber today, after his Twitter account was hacked and an unauthorised message was sent to his 19 million fans.
Justin Bieber hacked on Twitter
19 million my ass. #biebermyballs
          Fortunately the message was rapidly deleted, and it appears that the account was compromised more to spread embarrassing graffiti rather than with more malicious intention. Just imagine how much worse things would have been if millions of Justin Bieber fans had seen a tweet from their hero offering, say, free concert tickets - and the link had really pointed to a website designed to strike their computers with malware.
Justin BieberThat's not to say that the hacker didn't do any serious damage at all, of course. According to reports whoever broke into Justin Bieber's Twitter account, also began to unfollow and block some of the folks that the Canadian singer follows.

          If you're one of Justin Bieber's many fans, please learn something from your idol's misfortune. Always choose a strong, secure password for your Twitter account and make sure that you are not using it on any other websites, and never share it with anyone else.

          Furthermore, be careful that you only log into your Twitter account from a computer that is properly protected with up-to-date anti-virus software and security patches - in other words, maybe you shouldn't trust that computer in a hotel lobby or your friend's PC. Keylogging spyware can grab your password without you knowing, and pass it onto malicious hackers.
And remember that just because a Twitter account is "verified", doesn't necessarily mean you can trust every message that is posted to it.

Friday, March 23, 2012

User IDs and Clear-Text Passwords Leaked from US Army’s CECOM

          Black Jester, the hacker who yesterday demonstrated that he managed to gain unauthorized access to a NASA site, leaked sensitive contract information from a site connected to the US Army Communications and Electronics Command (CECOM).

           A number of 30 record sets that include names, user IDs, physical addresses, email addresses, telephone numbers, and clear-text passwords were published in a Pastebin document. “Old crappy server, but has good info inside it. The list is not complete due the lazy condition and msaccess db , enjoy!” the hacker wrote next to the data dump.

           The Pastebin post doesn’t contain the name of the site from where the data was leaked, but the hacker provided us with the IP address associated with it. That IP address led us to a Software Engineering Services site on which only “eligible users” may register.

           We couldn’t reach the hacker for further comment, but he told us on a different occasion that the names of such sites would not be disclosed to the public to prevent “script kiddiez” from breaching them.
We have sent an email to the webmaster of the site in question and notified him on the incident, but so far we haven’t received any response.

           Black Jester is known in the hacker community as the one who wanted to help the United Nations patch up a couple of its public websites. Instead of doing what most security researchers do in this situation and send an email, he went down to their offices in person.

           His other hacks, which he claims are unrelated to the UN incident, targeted NASA and a Qwest datacenter, whose servers he held hostage with the purpose of forcing the company to patch up the vulnerabilities.

Carberp Banking Trojan Scam - 8 Arrested in Russia

Carberp+Banking+Trojan+Scam+-+8+Arrested+in+Russia     8 Men suspected of being involved in the Carberp phishing scam have been arrested in Russia. The men were arrested after a joint investigation by the Russian Ministry of Internal Affairs (MVD) and Federal Security Service (FSB).

    According to the MVD, the investigation found that two brothers were the ringleaders of the gang, and developed a plan to steal money from the accounts of online banking customers. The eight suspects allegedly stole more than 60 million Rubles ($2 million) from 90 victims using the Carberp Trojan.

     Russian security firm who assisted with the investigation, pegged the stolen loot at 130 million Rubles ($4.5 million). Police confiscated computers, bank cards, notary equipment, fake documentation, and more than 7 million Rubles ($240,000) in cash during the raid.

     The gang used the Carberp and RDP-door Trojans to snare victims. Carberp is a well-known Trojan that was recently seen on Facebook as part of a scam where attackers notify Facebook users that their accounts are temporarily locked. All they had to do to get them back was provide their first and last names, email addresses, dates of birth, passwords, and a 20-euro Ukash voucher.

     The suspects will be accused of creating, using and disseminating of harmful computer programs, theft and illegal access to computer information and, if convicted, could be jailed for up to 10 years. In addition to bank fraud, the gang was also involved in distributed denial-of-service attacks, the security firm found.

Friday, January 20, 2012

Tit for Tat - Anonymous Hackers Brings Down FBI website for #OpMegaupload

          Megaupload.com, one of the world's most popular sources of online piracy, has been shut down by a federal indictment issued Thursday, which seized and charged seven people connected with it with running an international enterprise based on internet piracy. Online piracy by the two companies - Megaupload Ltd and Vestor Ltd - generated more than $ 175 million in criminal proceeds and caused more than half a billion dollars in harm to copyright owners
FBI+HACKED
          Hacking group Anonymous said Thursday it knocked out the websites of the FBI, U.S. Department of Justice, and several entertainment industry sites as retribution for anti-piracy efforts by both the government and the entertainment industry. Anonymous said it was "the largest attack ever," with 5,635 participants involved in bringing down the sites. The two government sites were up and running again after several hours.

          Megaupload stood as one of the most popular file storage services on the internet, allowing users to upload and share files that included movies and music, among other media. With a timeliness that borders on satirical, public uproars over antipiracy bills SOPA and PIPA in Congress ran in tandem with the arrests and seizure.
Motion+Picture+Association+of+America+%2528MPAA%2529+and+US+Democratic+party+leaders           Anonymous have compiled and published a dossier containing personal information about employees of the Motion Picture Association of America (MPAA) and US Democratic party leaders and their families.

          Megaupload has preemptively defended these charges with the following assertion:

Anonymous+Hackers+Brings+Down+FBI+website+for+%2523OpMegaupload
          Mega has over 150 million registered users and over 50 million daily unique visitors. Employees of over 70% of the world’s Fortune 500 companies have accounts with us. We have become the de-facto standard for sending files that are too big to email. We are the most popular hard disk in the cloud. We host more backups than any other company. If Mega is a rogue operator as we have been unfairly labelled by the MPAA and RIAA, then what about Google? What about Yahoo? And every single ISP? At any given time, they all host pirated, illegal or even criminal content for which they are not liable nor legally obliged to prevent their users from posting. They are, like Megaupload, online service providers who are in no position to monitor or restrict their users’ activities. There are technical, practical and legal reasons why these entities as a whole enjoy safe harbor protection all over the world. Service providers like Megaupload are simply better off focusing on providing a better service to their customers than fending off lawsuits from third parties unhappy about content.

          That said, all service providers have to deal with the challenge of online piracy, just like us. Google probably hosts the world’s largest index of pirated content and yet no one has characterized them as rogue. Why not sue the manufacturers of external USB hard drives or burnable DVDs? They can be used for illegal purposes, too. Microsoft’s Windows operating system is the world’s largest enabler of piracy. Windows is used to transfer and consume pirated content on a massive scale every day. And yet Microsoft is not rogue. This double standard should not be imposed on Megaupload since it finds no basis in either logic or the law. All we want is equal treatment.

Wednesday, January 18, 2012

Hackers Plan to Launch Satellite for Internet to Bypass SOPA

Hackers Satellite internet
          The term hacker can be used to mean a several understandings amongst them there are two major’s one which include “positivity” and the “negativity”. The hackers on facing the internet ban from the United states as a result of SOPA (Stop Online Piracy Act) have made a plan to launch there own satellite in the space for providing an internet which may be free from all kinds of bans and restrictions. This group of hackers belong to Germany.

 

 

What is this Plan and How is this Satellite going to work?

          The plan majorly includes on launching a single satellite in the space and which will be a low orbit satellite. That will surely work under the solar power as per the satellite general rule of operation and will communicate with ground stations to make a network. This network will operate like a GPS system and will be called as “Hackerspace Global Grid (HGG)”. When any station will be under the satellite range then it will take the signals and will direct it to the other stations also and a user can gain permanent access to the network. This theory seems to be applied but there are certain hurdles in the plan and which needs to be resolved first.

Some Major Basic Hurdles:-

          As we know that with the advancement of the technology we all are able to travel in the space and are able to send the satellites in the orbit of earth using rockets. But still this technology is hell costly also. Plus! There are no vital rules for the space like in case of earth and no single country can govern the space so anyone can make this satellite to stop work without any specific legal permission.
In order to make it a geo synchronous the radius of the orbit will surely get decreased and it will move in a fast manner and for the HGG project this distance seems to be large for the signals to be transmitted with a 100% quality aspect.

So what’s next with this HGG project?

          The team is still moving forward to make this possible and its deciding to make the ground stations. If you are fascinated with this project and want such a network for the world them go here: Constellation to join this project. A project joined by HGG for collaboration.

Monday, January 9, 2012

Ramgen-Janelle Scandal video posted on deface page of Philippines Premiere Bank

          A defaced linked of the website of the Premiere Bank Philippines which contains a video of Ramgen-Janelle Sex Video Scandal is the talk of the town and widely spread in the IRC and Facebook today. The defacer who uploaded the video claims to be kenjie miranda of h4ckz0n3. The defacer who uploaded the video claims to be kenjie miranda of h4ckz0n3.

          Regarding with the case of this video which violates the ANTI- VOYEURISM LAW OF 2009, Senator Revilla Jr. already asked the National Bureau of Investigation to investigate the spread of Ramgen-Janelle intimate video. The video is already viral in torrent sites and forums sites.

Hackers selling cheap BOTNETs and DDOS on forums


          The Internet has revolutionized shopping around the world. Security researchers F-Secure reported recently in a post that hackers are Selling Cheap DDOS services on Various Forums. Hackers are offering services like distributed denial of service attacks (DDoS), which can be used to knock website offline in just 1 - 2 hours / 2$ per hour. They Posted a  Youtube Video in which a young woman advertises DDoS services.

          "We are here to provide you a cheap professional ddos service.We can hit most large websites/forums game servers. We will test the website/server before accepting your money. Due to the nature of the business we dont offer refunds." Offer said. 
          There is another Interesting Hacker's Shop ! Moreover, for their assaults, the hackers chiefly utilize botnets, while ignorant operators of computers remain unaware that they've gotten contaminated with malware as also being controlled remotely.
       
          "Do you want to be king of the internet? If your answer is yes, then you are in the true place. All of programs has been made by professional coders." This website selling Local Botnet, Irc Botnet, Web Botnet and Keyloggers at 59$ only.

M86 Security detected Web exploitation attacks using AJAX

          Security researchers from Web filtering vendor M86 Security have detected Web exploitation attacks that use AJAX (Asynchronous JavaScript and XML) to fragment the payload into small pieces of code that are harder to detect by antivirus programs and intrusion prevention systems.

          The Web browser is your portal to the world -- as well as the conduit that lets in many security threats. The attack starts on a page that contains an unsuspicious piece of JavaScript code that is similar to that commonly found on legitimate AJAX-using websites. This code is responsible for fetching the payload in multiple chunks and assembling it back together on the client before executing it. Different pages found by M86 on the attack server exploited vulnerabilities in unpatched versions of Flash Player and Internet Explorer.

          This payload fragmentation technique makes it harder for signature-based security programs to detect the attacks. Many Web filtering mechanisms are implemented as network filter drivers and monitor traffic as it passes through the network interface. However, when there are chunks of legitimate-looking code that only become malicious when combined in the browser's memory, it's much harder to build a signature and detect the attack at network interface level. "The main reason that malware authors use AJAX is the ability to write generic attack pages which look benign and become malicious only once the dynamic content is loaded," Basanchig said.

          "This attack scenario definitely has its advantages: by passing the payload in several distinct chunks, the offending packets would likely avoid interception as they pass through the firewall," said Bogdan Botezatu, an e-threats analyst at antivirus vendor BitDefender. However, according to Botezatu, other protection layers found in antivirus programs might detect and block the code when it gets re-assembled in memory or when it's executed. In order to avoid becoming a victim when automated detection methods fail, though, users should keep their browsers and plug-ins like Flash Player, Adobe Reader or Java, up to date.

          "Last, but not least, it is essential for the user to stay away from Web resources they are not familiar with, such as URLs included in spam mail," Botezatu said.

Israel treating hackers like terrorists


          The message from Deputy Foreign Minister Dany Ayalon came after a self-defined "Saudi hacker" from a cabal known as "group-xp" published details of more than 6,000 Israeli credit cards online that "The US has announced that any attack on its cybernetic space would be considered a declaration of war and that it would go as far as firing missiles to respond to such an attack. This is a good criterion for us all".

           Israel said that it will respond to cyber-attacks in the same way it responds to violent terrorist acts, by striking back with force against hackers who threaten the Jewish state. Almost immediately after an Israeli computer expert declared the hacker's true identity to be 19-year-old Mexican waiter Omar Habib, the Israeli website Ynet claimed the real hacker contacted them via email to mock the false identification.

          “If a stupid student thinks he can find me (within) 8 hours of work, what will Mossad do? But I'm still here and no one can find me, make sure, no worries,” said by Saudi hacker 0xOmar of “group-XP”. "It is necessary to send a message to everyone who attacks or tries to attack Israel, including in cyberspace, that they are putting themselves in danger and that they will not benefit from any immunity against reprisal actions from Israel" Ayalon said.

          After examining the details, Israel's major credit card companies said only 14,000 valid cards had been exposed.

Anonymous expose email addresses of British military staff & Nato officials

          Anonymous Hackers expose email addresses of 221 British military staff with encrypted passwords, including those of defence, intelligence and police officials as well as politicians and 242 Nato advisers. "Civil servants working at the heart of the UK government including several in the Cabinet Office as well as advisers to the Joint Intelligence Organisation, which acts as the prime minister's eyes and ears on sensitive information have also been exposed." from Guardian .

Friday, December 30, 2011

Kaspersky Internet Security Memory Corruption Vulnerability

          Vulnerability-Lab Team discovered a Memory & Pointer Corruption Vulnerability on Kaspersky Internet Security 2011/2012 & Kaspersky Anti-Virus 2011/2012. A Memory Corruption vulnerability is detected on Kaspersky Internet Security 2011/2012 & Kaspersky Anti-Virus 2011/2012.
          The vulnerability is caused by an invalid pointer corruption when processing a corrupt .cfg file through the kaspersky exception filters,which could be exploited by attackers to crash he complete software process. The bug is located over the basegui.ppl & basegui.dll when processing a .cfg file import.
 
Affected Version(s):
  • Kaspersky Anti-Virus 2012 & Kaspersky Internet Security 2012
    • KIS 2012 v12.0.0.374
    • KAV 2012 v12.x
  • Kaspersky Anti-Virus 2011 & Kaspersky Internet Security 2011
    • KIS 2011 v11.0.0.232 (a.b)
    • KAV 11.0.0.400
    • KIS 2011 v12.0.0.374
  • Kaspersky Anti-Virus 2010 & Kaspersky Internet Security 2010
          The kaspersky .cfg file import exception-handling filters wrong or manipulated file imports like one this first test ... (wrong-way.png). The PoC is not affected by the import exception-handling & get through without any problems. A invalid pointer write & read allows an local attacker to crash the software via memory corruption. The technic & software to detect the bug in the binary is private tool.

Wednesday, December 28, 2011

US Chamber Of Commerce Hit by Chinese Hackers

         A group of hackers in China breached the computer defenses of America's top business-lobbying group and gained access to everything stored on its systems, including information about its three million members. The hackers may have broken into the Chamber’s network more than a year before they were discovered. It is not confirm when the initial break-in occurred but security officials from the Chamber quietly shut the breech down in May of 2010.
 
          "What was unusual about it was that this was clearly somebody very sophisticated, who knew exactly who we are and who targeted specific people and used sophisticated tools to try to gather intelligence," the Chamber's chief operating officer David Chavern told the Journal in an interview published today.

          It isn't clear how much of the compromised data was viewed by the hackers. Chamber officials said the hackers had focused on four Chamber employees who worked on Asia policy, and stolen six weeks of their email. The Chamber learned of the break in when the FBI told the group that servers in China were stealing its information. The Chamber put a stop to the attacks by unplugging and destroying several computers and overhauling its security system.
 
A Chinese Embassy official, based in Washington, Geng Shuang, said cyberattacks are prohibited by Chinese law and China itself is a victim of attacks and that claims the hacking originated in China, “lacks proof and evidence and is irresponsible,” adding that the hacking issue shouldn’t be “politicized.” . People close to the case told the Journal the emails revealed names of key firms and individuals in contact with the Chamber, policy documents, meeting notes, trip reports and schedules.

The U.S. has charged China with waging a clandestine hacking war for years now. Last year, the U.S.-China Economic and Security Review Commission (USCC) said that the Chinese government is attacking the U.S. on a "massive scale." Each time the U.S. charges China with hacking into networks, servers, or Web sites, the Chinese say they're innocent. After the U.S. charged China with hacking into satellites earlier this year in another USCC report, for example, China Foreign Ministry spokesman Hong Lei said that the the claims were simply "untrue."

Suspicious activity is still found on a regular basis. A thermostat at a town house the Chamber owns on Capitol Hill at one point was communicating with an internet address in China, they say, and a printer used by Chamber executives spontaneously began printing pages with Chinese characters.“It’s nearly impossible to keep people out. The best thing you can do is have something that tells you when they get in,” said Mr. Chavern, the chief operating officer. “It’s the new normal. I expect this to continue for the foreseeable future. I expect to be surprised again.”