Engadget

Hiển thị các bài đăng có nhãn News. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn News. Hiển thị tất cả bài đăng

XBox Live Hacked or Suffering Connection Issues

 tháng 3 30, 2010     Hacked, News     No comments   

Today Xbox Live users are suffering some Connection Issues and this is excepted as yesterday only the Xbox live account of Xbox’s Live Programming director’s was Hacked. So this points to the Xbox Live is been hacked aka compromised.

xboxlive

It is more likely that the Xbox live is hacked as the account of one of the makers of the Xbox live account was hacked yesterday only. While this can be a Connection issues too as the Expansion pack of Modern Warfare : “Stimulus Package” is out today which may have caused problems for the Xbox live servers as of large incensement in the connections ...

 

Xbox Support’s Twitter account is loaded with communications with customers about the problem, and the official support website at www.xbox.com/support is being bombarded by users.

 

“We’re aware of the issue and it is being worked on. Stay tuned for updates.”

 

An error code of 80150019 have been shown to the users of the Xbox live users. As the users are like not happy with this situation and would be likely as the Microsoft is in problems again.

 

… Talking about the Hacked account of Major Nelson’s of Xbox Live, Shortly after the hack happened, the Web site Lightzz took credit for the hack, posting a video of it, along with the hacker's Skype name. He is offering to hack other accounts as well.

 


Well whatever is going we will update this post as soon as Microsoft figures it out is it hacked or connection issues.

Read More
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg

MacOSX Gets Massive Security Update

 tháng 3 30, 2010     News     No comments   

This is kinda weird but safe for the users at the same time Apple have just launched the update for the Mac OSX with a severe patchment of 92 vulnerabilities. Well it have also breaked the previous record of the Mac OSX update released last year, when Apple 's largest patched 67 vulnerabilities .

 

security_mac

 

The update brings Snow Leopard to version 10.6.3, making this the third major update to the OS that Apple launched in August 2009. Apple also addressed a list of nearly 30 non-security issues in the 10.6.3 update. Leopard users, meanwhile, received only the security patches ..

 

As a matter of fact, most of the patches were for the QuickTime player for the Leopard OS and it was expected as we have already been knowing many of the Mp4 Zero Day exploitations etc and due to the Pwn2ownage conference the exploits shown there was a big reason for this turn out.

 

"The sheer number, it's almost so daunting that you don't even want to look," said Andrew Storms, director of security operations at nCircle Network Security.

 

Today on 30th Apple came out with a update of 42 security fixes which is about the 40% of the total number of the security apple is working onn. The other thing which is kinda in favour of apple is that they don't rate/score there patches like some of the other giants like Microsoft and Oracle.

 

RSnake’s Magic

 

The other news we got for you is that RSnake and his friends have done some research on this and found some of the exploitations in the safari browser which is regarding the port number float/integer overflow which can cause alot of damage.

 

Safari-3-2-Update-Crashes-the-Browser-Annoys-the-Users

“Safari has a typical integer overflow in the way they look at ports. So if you add the number 65,536 to the port you want to connect to (in this case 25 + 65,536 = 65,561) you can bypass their port blocking.”

 

And the best thing to note here is that Apple beat with the blacklist of ports or even whitelist of ports as it can be used in mass exploitation for hackers. Well lets see whats next.

 

Charlie Miller, the researcher who cracked Snow Leopard's security defenses to take down Safari, said today that Apple had not patched the vulnerability he used last Wednesday.

 

"New patch doesn't fix pwn2own bug," Miller said via Twitter .

"Sorry suckers, gonna have to wait for the next patch."

Read More
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg

VMWare Fusion 3.1 Beta On Grounds

 tháng 3 16, 2010     News, Tools     No comments   

Check out the VMWare Fusion 3.1 Beta which have been out just now. Its includes some of the significant features which many of the users have been waiting for. Some of them are really good which mostly includes graphic issues.

 

VMWare have been the major choice for the users to run Windows on Mac and pentesting for most of us on windows. The Beat 3.1 is out which have some major improvements in 3D application like games and windows Aero stuff…

 

OpenGL 2.1 is now also supported in this version for Windows 7 and Windows Vista. They claim better DirectX 9.0 SM3 performance as well (and hopefully that means more DirectX 9.0C app compatibility).

 

You can configure larger virtual machines as well, with the maximum virtual disk expanded from 950 GB to 2 TB. They now support up to 8-way symmetric multiprocessing as well. These are some of the features you will see in this Beat version.

 

VMware_fusion_windows_7_aero

You can download the beta here, test it, and have some of the nice features early for your use. If you want you can also give some tips to them and help them get doing the thing done fast for the final version.

 

So there you go - Download

Read More
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg

Ubisoft Hacked : Fake or Real ?

 tháng 3 15, 2010     Hacked, News     No comments   

Some days ago we got news about Ubisoft being hacked by some hackers and was being believed till yet but after then some news breached out that the images of the hack was fake.

Ubisoft Hacked : Fake or Real ?

 

So, this is kind of big story. The ubisoft is a company which is been known and you can say is good in DRM and Anti-Hackers activity, as you can see there games such as Assassin's Creed and many others have been out of cracked games folder and are a DRM king game…

 

But as you can see we and most ‘em gamers won't be happy with the Ubisoft’s way of gamming. So what they do they hacked the Ubisoft’s website for a short while some days ago on 14th March 2010.

 

Its right if you see it from my mindset :D but as they gamers are freaked out on the ubisoft for there way of gaming products. This is what would be happing as of crackers won't be so patient to crack some ubisoft shit.

Screen’s

 

Ubisoft Hacked : Fake or Real ?

 

Ubisoft Hacked : Fake or Real ?

 

When it Faked out

2nd part starts now when some news break out that the images of the hack were fake and The ubisoft’s was down just for the maintenance work. Well we don't know if the site was hacked or not but various sources are saying it was and some are saying it wasn't.

 

Whatever is the truth the thing here is that DRM is what lets every hacker to work against any company. You don't believe me then see iPhone, iPod, Halo, Call Of Duty etc are some victims of DRM which hackers and crackers have cracked out.

 

Screen’s

 

Ubisoft Hacked : Fake or Real ?

 

This image shows another story of the incident which Ubisoft would have gone through. Whatever happened.

 

What Do You Think Fake Or Real ?

Read More
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg

Mozilla Caught in a Bad Romance with Add-On

 tháng 2 08, 2010     News, Virus's     No comments   

Ok, i know the title of this post is kinda funny but that's what this news is all about, one of the greatest internet browsers of this time Mozilla Firefox and with other products also. This have been spread in the form of Add-on’s.

 feature-logo

 

These aren't just add-on’s the real problem is that they are infected with Malwares and they have downloaded by many of the people worldwide.

 

According to the researchers “Two Firefox add-on’s available for months on Mozilla’s website infected users with malware that stole passwords and opened a backdoor on Windows machines, the open-source browser maker has confirmed.”…

 

According to Mozilla, version 4.0 of So think Web Video Downloader is infected with password sniffer Win32.LdPinch.gen and Master Filer is infected with the backdoor trojan Win32.Bifrose.

 

Which is worst for a popular web browser company as it would spread rapidly and would be more dangerous. But this is where it gets embarrassing for Mozilla – the infected add-ons have been available from the official download site for several months and, according to Mozilla, have together been downloaded around 4,600 times.

 

mozilla-logo

These were discovered about on the days between 25th of Jan to somewhat near and sure they have removed them and working on it to remove them fast as many of the antivirus software's have already recognized and are removing them.

 

That script, designated HTML.Xorer also appears to have slipped past Mozilla's anti-virus scanner. As a result, Mozilla developers announced that the add-on directory would in future be checked for malware on a daily basis.

 

So, What do you think ? Is it just mozilla or Google Chrome would be next ?

Read More
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg

RSA Crypto 768-Bit Keys Cracked

 tháng 1 31, 2010     Guides, News     No comments   

Yes, you heard it right one of the most famous and which have been for years to encrypt the communication standards have been cracked by a bunch of scientists who took about two-and-a-half years and hundreds of general-purpose computers.

 rsa

 

This accomplishment was reached on December 12. In my eyes it would have been very much harder to crack this kind of cryptography because it is so much calculated and so much hard to to crack…

 

The team managed to factor the 232-digit number that RSA held out as a representative 768-bit modulus from a now-obsolete challenge. They spent half a year using 80 processors on polynomial selection.

 

Sieving took almost two years and was done on "many hundreds of machines". Using a single-core 2.2GHz AMD Opteron with 2GB RAM, sieving would have taken about 1,500 years, they estimated.

 

The only word come in my mouth right now is WOW.

"There's indisputable evidence here that 768-bit key are not enough. It's a pretty interesting way to close out a decade."

But as a matter of fact this is not the end as the new RSA crypto, which would be coming soon, is 1024 – Bit which would be much more harder to crack then all the previous one’s .

 

"If we are optimistic, it may be possible to factor a 1024-bit RSA modulus within the next decade by means of an academic effort on the same limited scale as the effort presented here," authors of the research wrote.

 

"From a practical security point of view this is not a big deal, given that standards recommend phasing out such moduli by the end of the year 2010."

 

Cryptography

So, its kinda like a win win for the scientists but not for the general purpose hackers as they cant be used until we get that amount of hardware to use and hence to crack that 768-bit crypto.

 

"It's an important milestone," said Benjamin Jun, vice president of technology at security consultancy Cryptography Research.

 

RSA 768 Bit Crypto Cracked

 

We have the research paper just for you guys, its all like maths thing if you want to read you can or you can download it too.

 

Happy Hacking @hackerthedude

Read More
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg

Gmail Goes https For Secure : Wi-Fi Protection

 tháng 1 14, 2010     email, News     No comments   

Google Just announced they are now moving to the Stable connection of https rather then the traditional connection of http. Gmail previously have also announced that they are making the Mails on https security but now Google is changing the whole connection to https.

Gmail Goes https For Secure : Wi-Fi Protection

 

The Reason are straight the Google is pretty much haded with the Chinese issues going onn. So its just the China which made this possible and special thanks to the hackers, as many of the people are now using SLL on their Gmail.

 

A group of 37 security and privacy specialists sent Google a letter (PDF) last June, urging the company to offer this feature. Gmail became the third-largest email provider last August, with more than 37 million unique visitors...

 logo2

You can also change the Default use of https on your Gmail account by going into settings and checking Not always use https. The new turn in this story of Gay is that, Google is making this because of the Wi-Fi owners as many people are now using wifi and making a secure connection will be good.

 

This is pretty obvious that Google is haded with its security and is on a way to change the way it is done. Lets see if this https stops us from Hacking.

 

What you say ?

 

Read More
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg

Angelina Jolie and Barack Obama #1 Choice of Spammers [Report]

 tháng 1 12, 2010     News     No comments   

MacAfee inc have just released there monthly report on the most Spammed people in the world and this month was special as it is the 1st month of the new year 2010.

Angelina Jolie and Barack Obama #1 Spammed [Report]
There are many others also included in the report published yesterday and you care right the most obvious subjects for spammers are none other then the president of United States "Barak Obama" and one of the most beautiful Actress "Angelina Jolie".

“Free-hosting” websites to provide spam URLs have also become a major target for spammers in this arena. As this to me is obvious as most of us want Free-Hosting for our files and web space.

McAfee Labs™ Discovers and Discusses Key Spam Trends By Adam Wosotowsky and Elan Winkler.  Going Straight away to the reports lets look at the Top Most Spammed Actress in the world...

Top Most Spammed  Women's


 Top Most Spammed  Women's
Well if you ask me then its brutal, just see the no. of spam's around the Angelina Jolie there is. But if you see the reports of Oprah Winfrey then its just about the same of the Angelina Jolie.

Top Most Spammed  Men's


Top Most Spammed  Mens
The Figure looks pretty mind Blowing as you can see the no #1 is Barak Obama and then comes Michael Jackson. But As a matter of fact the No. of spam's for the Angelina Jolie just are very behind the number of spam's for the US president Barak Obama.

Its a shame, We nailed it XD

Conclusion

Whosoever is the #1 or #2 doesn't matter as the number of spam's are increasing around the world and the most of them are popular people's around the world from the Barak Obama to Angelina Jolie.

Looking at the fact that the Free Hosting is the one most added spam's. It will always be there as many people are now getting aware of the web services and most of them wants it free and that's how the spamming would goes.
Read More
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg

iiScan : Security On The Cloud

 tháng 1 09, 2010     News, Tools     No comments   

iiScan the newly built tool for the pen testers is just cool as a cloud. This tool i pretty awesome as you can manage your security projects on a cloud and there are many surprises in it.

 iiScan : Security On The Cloud

What iiScan does is that, on the simple basis, you built and web App, it surely contains the Vulnerability in it, they found the vulnerabilities in them from Xss to Sql injections making it cloud, then you get the report of the vulnerabilities and then you can work on them or remove them.

 

 

iiScan provide a cloud-computing based security service which focus on web application security. With iiScan, you can get your web application assessed by iiScan expert and the only thing you have to do is clicking the START botton.

 

After that, a report contained all details of vulnerabilities or risks of your website will be sent to your mailbox. Then you can fix it and make your website safer.

 

Well you can register on their website and use the tool for your upcoming projects and web projects too...

 

iiScan can detect and test most Web Vulnerabilities without manual intervention :

  • SQL injection
  • Cross Site Scripting (XSS)
  • File Upload Vulnerability
  • Information Leakage
  • Insecure Direct Object References

    Buffer overflow

    and many more ..

     

    2010-01-09_204712

     

    The tool also have been very famous on twitter for few days between security guys. The tool is very powerful as it seem to be.

     

    The tool is easy to use, you can go there register and start your work. I have been looking forward to it and you should too.Your Website HealthCheck results will be emailed to you as a PDF report. You will receive a second and separate email with the password to open the PDF report.

     

    So what do you say about it.

  • Read More
    • Share This:  
    •  Facebook
    •  Twitter
    •  Google+
    •  Stumble
    •  Digg

    @purehate_ Launches Online WPA Cracker : 10$ For 540 Million Passwords

     tháng 1 06, 2010     News, Tools, Twitter     No comments   

    @purehate_  is a backtrack Developer and penetration tester too. He recently Developed a New Online WPA Kracker. For cracking the passwords of the hashed network key is exchanged and validated in a “four-way handshake”.

     @purehate_ Launches Online WPA Cracker : 10$ For 540 Million Passwords

    This tool is great as you can see it uses nearly about 540 Million passwords to crack the WPA, well i am not sure, as i am not experienced with the WPA cracking that much. But here is what it does.

     

    Ok i am sorry for the name, because i was unable to Find the Name, I hope to get to know his real name. but i got a guess would be Nick as it was written in the contact page as nick pure_hate. Nevermind...

     

    What exactly does service thing do?

    This is a research project, not a cracking tool. WPA-PSK is vulnerable during client association, during which the hashed network key is exchanged and validated in a “four-way handshake”. In order to use this web interface you will need the “four-way handshake”.

     

    2010-01-07_124002

    WPA-PSK is particularly susceptible to dictionary attacks against weak passphrases and this server can greatly improve the speed of the attack. Your cap file will be tested against a list consisting of about 540 million passwords and can take up to two hours to complete.

     

    A email will be sent along with the results to whichever email address you specify to the uploader.

     

     korek-progress-2

     

     

    Direct Link

    You Can Follow Him on twitter too @purehate_

    His Website Ph33rbot.com

    Read More
    • Share This:  
    •  Facebook
    •  Twitter
    •  Google+
    •  Stumble
    •  Digg

    How Youtube Got Hacked : How The F*ck She Did That ?

     tháng 1 06, 2010     News, Video's     No comments   

    As Mashable Reported this Evening the YouTube video On "twista ft. do or die-do you" Hacked the Number of views on YouTube. Which is near about 79 Billion Views Actually the time i wrote this article, it was 79,441,058,538 views, which in My view is Impossible kind of stuff.

    Over 79 billions views

     

    Actually the Number of Views Matter allot for the YouTube Freaks and hacking the number of views is something that everybody would want. But after reviewing the video i am pretty damn Sure its some kind of "Big Bug" in the YouTube CMS.

     

    This is some king "Glitch" in the YouTube i think :D Best would be if anybody found it before anybody else do. The video is a "Ft. Do or Die" and if u ever read the video comments you would only get one comment out all of them.

     

    How The F*ck She Did That ?

     

    Video

     

     

    Over 79 billions views

     

    How The F*ck She Did That ?

     

    Obviously the Engineers behind the Google would be working on it and would soon give the Reply to this hack or would release any news of it. As soon as they do that you can find that Glitch and Use it.

     

    And as a matter of fact i love this Ft.

    Read More
    • Share This:  
    •  Facebook
    •  Twitter
    •  Google+
    •  Stumble
    •  Digg

    Nir Goldshlager Founds XSS Vulnerability in Google And Twitter

     tháng 1 03, 2010     Hacked, News     No comments   

    A security researcher uncovered some holes in Google Calendar and Twitter that may allow an attacker to steal cookies and user session IDs.

     Nir Goldshlager Founds XSS Vulnerability in Google And Twitter

    Nir Goldshlageer is a security researcher, he recently found an Xss vulnerability in the Google Calendar and Twitter too. The HTML injection issue affecting Google Calendar as well that he said could be used to redirect a victim to an attack site anytime the user viewed his or her Google Calendar agenda events.

     

    “When the victim…(adds) this malicious code, his cookies (and) session ID will be stolen and will be sent to the attacker site," he said. "Then the attacker will be able to get full control of the victim’s Google accounts like: Google Calendar account, Google Groups, iGoogle, etc.”

     

    Obviously when the hacker, hacks the Google calendar account he will be able to easily hack the Google account as all the Google services are joint to each other. This is big vulnerability in the Google i am saying it from the starting but lets see what Google do next.

     

    "They should fix this immediately, because an attacker can redirect a victim to any site that he wants, and the XSS issue an attacker can steal the victim's cookies and get full control of his accounts," Nir Goldshlageer said.

     

    Whatever is the story the Google and twitter are a big targets that are continued to be a target for hackers like us.

     

    What do You think ?

    Read More
    • Share This:  
    •  Facebook
    •  Twitter
    •  Google+
    •  Stumble
    •  Digg

    Intel Website Hacked : Another SQL Injection From Unu

     tháng 1 03, 2010     Hacked, News     No comments   

    Intel Website HackedThis is kind of a luck because the amount of SQL injections are affecting the large website is just unbearable. This time the Hacker is one the best and my favorite hacker in the world "unu". unu have previously hacked some really popular website like The Wall Street Journal and Kaspersky Lab’s Websites.

     

    I know this news is petty late as the Intel website was down near 23rd of December of 2009. which you can say about 1 week ago.But when the website was hacked, it was lead down and was showing a message of “investigating the matter.”

     

    Not only is the website vulnerable to sql injection but it also allows load_file to be executed making it very dangerous because with a little patience, a writable directory can be found and injection a malicious code we get command line access with which we can do virtually anything we want with the website.

     

     

    Upload phpshells, redirects, infect pages with Trojan droppers, even deface the whole website.

     

    This is a kind of pity on the Intel security engineers,  but what can we do, if they don't pay to the security professionals....

     

    Screenshots : Telling the Story

    Screenshot tells everything, they reveal all the stuff and thus the story behind the hack of the Intel's website. Ok enjoy the story which is the based on the SQL injection.

     

    Intel Website Hacked

     

     

     

    Intel Website Hacked

     

     

     

    Intel Website Hacked

     

     

     

    Intel Website Hacked

     

     

     

    Intel Website Hacked

     

     

    Conclusion

    The growing number of SQL injections are growing and there is a need to look at the security against the SQL injection vulnerabilities or websites like Intel will grow to the attacked and be attacked several times.

     

    Happy Hacking @hackerthedude

    Read More
    • Share This:  
    •  Facebook
    •  Twitter
    •  Google+
    •  Stumble
    •  Digg

    The Anatomy Of GSM Encryption Hack

     tháng 12 31, 2009     Guides, News, Pro Hacks, Torrent     No comments   

    After Karsten Nohl hacked the GSM encryption, I thought to Digg this a bit in more detail. So i have written this whole guide in favor of it. So lets start.

     

    Karsten Nohl, A Germen Hacker have claimed that he have successfully cracked the GSM mobiles security algorithm. That we all know but the question that arises here is what he did to crack the GSM encryption which have been for years, actually from 1987.

     

    There was a conference know as 26th Chaos Communication Congress (26C3) , as we all know which is indeed the most respected and one of the most seeable conferences in Europe.

     

    3842740300_213911ed38_o

     

    It takes place from December 27th to December 30th 2009 at the bcc Berliner Congress Center in Berlin, Germany. which is quite recent and what was special this time on it was the GSM encryption crack details which were going to be demoed in the conference.

     

    The 26C3s slogan is "Here Be Dragons".

     

    As a matter of fact i was not there in the conference and thus missed all the stuff going on there. but some of my twitter friends helped me out with this. When twitters started to tweet with the hash tag of #26C3 all was going clear about it...

     

    Basics

     

    Ok lets began with the basic of the attack and what can be done with, what we need, what he cracked etc

     

    Karsten Nohl GSM Crack 26C3

    Here is the presentation or you can say the slides, which Nohl presented during the 26C3 which gives all the detail regarding the whole GSM encryption hack.

     

    “… the GSM call has to be identified and recorded from the radio interface. […] we strongly suspect the team developing the intercept approach has underestimated its practical complexity.


    A hacker would need a radio receiver system and the signal processing software necessary to process the raw radio data.”

    –GSMA, Aug.„09

    What a Hacker Need

    As written in the document a hacker would need a radio receive system and also a signal processing software which is necessary to produce the raw data to decrypt it.

     

    image

     

    A Radio Receiver System    -

     

     

     

     

    2010-01-01_120838

     

    A Signal processing software  -

     

     

    Ok this might explain you a bit about what a hacked need. Actually its not the kind of hack which you can perform with a laptop. you would need to decrypt which the Nohl have used the rainbow tables which were not explained in the previous hacks between 1995 to 2008 which were not quite successful.

     

    There are various different setting you would need to do in the radio and OpenBTS. and other configuration, mods. Its pretty complicated stuff there.

     

    Rainbow Tables

    The main reason why this crack with A5/1 attacks were not done in the previous years is because of the rainbow tables which the Nohl introduced in the cracking procedure.

     

    Previously the crack used some big system to decrypt but it was too expensive that it any hacked would not be able to crack it and that's why the hack was also not released in the internet.

     rainbow-table-bundle-medium

     

    But there come Nohl with his rainbow tables. They planned to do a workshop today, where you could bring your GSM data and they wanted to try to decrypt it. However, due to legal reasons they had to cancel it.

     

    http://events.ccc.de/congress/2009/wiki/The_demonstration_is

     

    The next step would be for someone to package the attack in the form of a script-kiddie-usable utility that would perform interception/decryption using an off-the-shelf GSM USB modem.

     

    That seems to be how these things go; they'll drag their feet as long as possible, until the public pressure becomes unbearable.

     

    So i guess most of you have to wait for the script-kiddies bundle to release so you can use it.

     

    Get a working copy of the table generator rainbow tables by either :

    A) Downloading binaries

    1. Linux 32bit

    2. Linux 64bit

    3. windows 32bit

    4. windows 64bit

    revision 58 from October 25 2009

    Or

    B) Compiling The Program

     

    Then, Running The Program

     

     

    Stuff We Got For You

    For more information i have made a list of papers, sildes, links, and videos of 26C3 presentation on the 26C3 for you.

     

    Slides - Karsten Nohl GSM Crack 26C3

     

    Videos - There are different sources of the videos. so i have written all the sources with the torrents.

     

    1. 26c3-3654-en-gsm_srsly.mp4

    2. 26c3-3654-en-gsm_srsly.mp4.md5

    3. 26c3-3654-en-gsm_srsly.mp4.torrent

     

    GSM: SRSLY? Part 1 - Part 2 - Part 3

     

    Links -

    1. http://rnmshot.dvrdns.org/

    2. ftp://ftp.ccc.de/congress/26C3/mp4/

    3. http://85.214.20.203/26C3/GSM/

    4. http://reflextor.com/torrents/

    5. http://reflextor.com/trac/a51

     

     

    Happy Hacking @hackerthedude

    Read More
    • Share This:  
    •  Facebook
    •  Twitter
    •  Google+
    •  Stumble
    •  Digg

    Your Mobile Is In Danger : Karsten Nohl Cracks GSM Mobiles Security Algorithm

     tháng 12 30, 2009     Mobie's, News     No comments   

    Karsten Nohl, A Germen Hacker have claimed that he have successfully cracked the GSM mobiles security algorithm. Which can effect the whole world even your moblie.

     Karsten_1_high_res_1

    I know what you might be thinking till now and its all true. Nohl was not alone in this whole arena of finding the vulnerability in the GSM phones. He was with another 24 friends teamed up to crack the worlds most used mobile security algorithm.

     

    GSM security algorithm is based on the such a frequesny that it changes it signals from one tower to another in seconds and then transfers the signals to the other frequency station. Yeah, I know its pretty complicated stuff there.

     

    Nohl claims that armed with the code, which has been published online, and a laptop with two network cards, an eavesdropper could be recording phone calls within 15 minutes...

    We also have live numbers of Victims !

     

    Nohl : "This shows that existing GSM security is inadequate"

     

    Nohl insisted that he had deciphered the code to force the global telecommunications industry to upgrade its security. Well this is a big security issue which is affecting many.. actually the whole world.

     

    The thing to think about in this whole chapter of security is that, the vulnerability is open and if any mad hacker like me, could try to hack this GSM network would i be get caught .With a total average of 4.3 Billion victims. what do you think, you would do with it.

    Read More
    • Share This:  
    •  Facebook
    •  Twitter
    •  Google+
    •  Stumble
    •  Digg

    FBI Is Watching You : Now On Facebook, Twitter, Youtube and More

     tháng 12 23, 2009     Misc, News     No comments   


    Ok did anybody told FBI about Privacy stuff that we need to live on this planet Earth full of some officers who just want to piss of Hackers.


     FBI

    Ya, Its FBI they are taking a new strategy focusing on the social media for spreading the Information or something whatever in their mind. Here is what they say :

    "Over the past few years we’ve rolled out a number of new web initiatives—including an e-mail alert service, syndicated news feeds, and a series of podcasts and widgets—that make it easier for you to help us track down wanted fugitives and missing kids, to submit tips on terrorism and crime, and to get our latest news and information."

    We are moving forward on other social media fronts as well.

    Where is FBI Till Now :

    • Facebook, where you can follow our news, check out our photos and videos, and become a “fan” of the FBI;
    • YouTube, where you can watch our videos and connect back to our main website for job postings and other content; and
    • Twitter, where you can receive our tweets on breaking news and other useful information....

    facebook051509

    FBI More On :

    More widgets :

    The new high-end widget was built using Flash, XML, and ActionScript and can be shared virally through social media websites such as Facebook, MySpace, and Blogger, says Michael Litchfield, the web developer who built it for the FBI. “I was excited to work on it and thought it was a great way to market the Bureau to a new generation.”
    Visit There widgets page.

     

    Fugitives at your fingertips :

    A company called NIC—founded by an ex-law enforcement officer—has built a free “Most Wanted” iPhone and iPod Touch application based on our newest widget and fueled by our RSS feeds.

     

    Virtual billboards and kiosks :

    They are doing pilot tests in Second Life—a free 3-D world inhabited by millions of people worldwide—for virtual billboards and kiosks that show the mugs of our Ten Most Wanted fugitives and connect people to FBI jobs, there Internet Crime Complaint Center, and the wanted posters of cyber criminals.

     

     

    fbi

     

    Happy Hacking Be Safe @hackerthdude

    Read More
    • Share This:  
    •  Facebook
    •  Twitter
    •  Google+
    •  Stumble
    •  Digg

    AWeber Hacked : Recent Data Compromise

     tháng 12 22, 2009     News     No comments   

    We just in a split second got news, The great and most popular email subscription and rss manager for Wordpress have been hacked. The recent reports says that they have been hacked by some kind of Third-party Software which they use. AWEBER_logo

     

    The general meaning of this would be the code would be hidden in the app they would be using their systems which took the ownage of there API might be. We are not sure till yet.

     

    It could be Local Buffer overflow on that third party software which they were using. The Apparent effects of this hack was that many spam email message were send to the subscribers. Here is the list of the things which were NOT compromised and are saved by the team.

    • AWeber customers’ personal information was not compromised.
    • No credit card data was compromised.
    • No customers’ names, “from” or contact email addresses, postal addresses, website URLs or any other profile information were compromised.
    • No affiliates’ names, contact email addresses, tax ID numbers, website URLs or postal addresses were compromised.

    We are looking into the details and will provide a further updates soon.

    You can read more about this Here

    Read More
    • Share This:  
    •  Facebook
    •  Twitter
    •  Google+
    •  Stumble
    •  Digg

    RSnake's 2nd Take On DNS Rebinding

     tháng 12 22, 2009     Hacking, News     No comments   

    Robert Hansen aka RSnake the father of Xss is back with a bang. With his latest research on DNS rebinding hacking which he also explained with a Video but he is all set to remove this DNS rebinding from the world.

     

    RSnake released a new podcast on DNS Rebinding after his previous release of video on it. Its a pretty good news that somebody is caring about the DNS hacking techniques as one we saw a couple of days ago Twitter was hacked, with some DNS resolution problems.

     

    You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.

     

    Dennis Fisher talks with security researcher Robert “Rsnake” Hansen about his recent work on DNS rebinding attacks, the poor state of browser security and his new book “Detecting Malice.”..

     

    *Podcast audio courtesy of sykboy65

    Subscribe to the Digital Underground podcast on

     

    How DNS Rebinding Works

    The attacker registers a domain which is delegated to a DNS server he controls. The server is configured to respond with a very short TTL parameter, which prevents the response from being cached.

     

    The first response contains the IP address of the server hosting the malicious code. Subsequent responses contain spoofed private network IP addresses (RFC1918), presumably behind a firewall, being target of the attacker.

     

    Because both are fully valid DNS responses, they authorize the sandboxed script to access hosts inside the private network. By returning multiple short-lived IP addresses, the DNS server enables the script to scan the local network or perform other malicious activities.

    *source Wikipedia

     

    Read More
    • Share This:  
    •  Facebook
    •  Twitter
    •  Google+
    •  Stumble
    •  Digg

    The Top Targeted Brands Of 2009 [Pic]

     tháng 12 21, 2009     News, Pics     No comments   

    The Year 2009 is almost over and as we noted the whole year 2009 Is The Year Of Biggest Data Breach's Ever Says Forbes and The Years Biggest Security Breach for the year 2009, But the question which exhibits now is, which were the most targeted brands of this year 2009.

     

    The Avira Tech Blog have released a new report based on there attacks by the cybercriminals. Which consist of the mostly targeted websites of 2009 and which might be in 2010.

     

    toptargets

    *Click on the image to View Full size

    Well with dawn of 2009, some most vulnerably websites from the forefront of hackers are Paypal, Chase Bank, Ebay, American Bank … after 3 more there is facebook.
    Yeah !, you are right ..

     

    In December, the situation was changed: Now PayPal is the most phished brand (32205 unique URLs) followed from far away by the Chase Bank (25901 unique URLs) and Ebay (18738 unique URLs).

     

    The Most Top Targeted brands are no other then Banks and some social media services come back to these banks.  Now what will be going to happen in 2010. Well we will cover all the news and Hacks just for you guys. So hang on with Hacker The Dude.

     Target

     

    Be safe during the winter holidays and always write the address of PayPal and other online banks in the browser by yourself and never click on links in emails.

     

    Happy Hacking Be Safe @hackerthedude

    Read More
    • Share This:  
    •  Facebook
    •  Twitter
    •  Google+
    •  Stumble
    •  Digg

    Bootkit : One Deadly Weapon In The Attacker Arsenal

     tháng 12 20, 2009     News, Virus's     No comments   

    There was a great presentation at BlackHat about Bootkit. Which is simply a rootkit being loaded from the MBR before the system starts.

     

    Stoned Bootkit

     

    This could be use to defeat full drive encryption where the system would be infected after it boot. Below you have a copy of the main page of the http://www.stoned-vienna.com/ web site with tons of great information on the subject:


    Stoned Bootkit


    Stoned Bootkit is a new Windows bootkit which attacks all Windows versions from XP up to 7. It is loaded before Windows starts and is memory resident up to the Windows kernel. Thus Stoned gains access to the entire system.

     

    It has exciting features like integrated file system drivers, automatic Windows pwning, plugins, boot applications and much much more. The project is partly published as open source under the European Union Public License. Like in 1987, 'Your PC is now Stoned! ..again'….


    Peter Kleissner, Software Dev. Guru in Vienna

    Your PC is now Stoned! ..again; Some links:

    http://www.stoned-vienna.com/ - Main site (this site, redirects here)
    http://stoned-bootkit.blogspot.com/ - Blog
    http://vimeo.com/5114740 - Short video introduction to the project
    http://www.pauldotcom.com Episode 155 - Interview and very good write up
    www.blackhat.com speakers & topics - Stoned Bootkit at Black Hat USA 2009

    Black Hat déjà vu - Stoned again
    TrueCrypt vs Peter Kleissner, Or Stoned BootKit Revisited..

    Download the Stoned Bootkit Paper

    • Paper
    • Black Hat USA 2009 Presentation
    • Open Source Framework
    • Infector file that was used in the Black Hat USA 2009 presentation

    'A bootkit is a rootkit that is able to load from a master boot record and persist in memory all the way through the transition to protected mode and the startup of the OS. It's a very interesting type of rootkit.' - Robert Hensing about bootkits


    Please take also a look on my upcoming Hacking at Random presentation "The Rise of MBR Rootkits & Bootkits in the Wild".


    Frequently Asked Questions


    What is Stoned Bootkit and why should you concern?

    A bootkit is a boot virus that is able to hook and patch Windows to get load into the Windows kernel, and thus getting unrestricted access to the entire computer. It is even able to bypass full volume encryption, because the master boot record (where Stoned is stored) is not encrypted. The master boot record contains the decryption software which asks for a password and decrypts the drive. This is the weak point, the master boot record, which will be used to pwn your whole system. No one's secure!

    For whom is Stoned Bootkit interesting?

    1. Black Hats
    2. Law enforcement agencies
    3. Microsoft


    Why is Stoned something new?
    Because it is the firts bootkit that..
    - attacks Windows XP, Sever 2003, Windows Vista, Windows 7 with one single master boot record
    - attacks TrueCrypt full volume encryption
    - has integrated FAT and NTFS drivers
    - has an integrated structure for plugins and boot applications (for future development)

    With Stoned Bootkit you can install any software (for example a trojan) on any computer running Windows without knowing any password, even when the hard disk is fully encrypted. Relate questions from the Black Hat presentation:

    1. Can the BIOS MBR protection prevent the attack?

    No, because the BIOS is not called to write the MBR to disk. Windows has its own native hard disk drivers that are directly accessing the hard disk. The MBR protection in the BIOS works only with DOS and Windows 95/98.

    2. Can hardware encryption prevent the attack?

    Only for physical access. The attack is still possible under a running Windows because the hardware encryption is a layer below. The Stoned software will be stored encrypted by the hardware encryption and decrypted on startup, so it will still become active when starting.

    TrueCrypt Attack


    Stoned is able to bypass the full volume encryption of True Crypt. It allows installing a Trojan to a computer that's hard disk is full encrypted. Let's take a look at the technical part. For True Crypt encryption there are two scenarios:


    1. Only the system partition is encrypted; the master boot record, unpartitioned space and the host protected area stay unencrypted.
    2. Full volume encryption, only the master boot record stays unencrypted.

    The trick is that the master boot record is never encrypted - and thus can be safely overwritten and used for our own boot 'software'. For the first case additional data such as plugins, the original master boot record backup or further code can be stored to unpartitioned space. For the second case the whole Windows attacking code must fit into the master boot record, into the 63 sectors minus the decryption software. TrueCrypt has free 7 sectors where Stoned Bootkit still fits, so even full volume encryption is no problem.


    My personal notebook has the system partition encrypted with TrueCrypt. I showed at Black Hat USA 2009 live that Stoned Bootkit was able to bypass that and could pwn my own system.


    cmd.exe Privilege Escalation


    Thanks to Vipin & Nitin Kumar for providing me their cmd.exe privilege escalation attack (source code together with some more detailed information). I rewrote a driver in C that does that job - overwriting the security token of cmd.exe with the one of services.exe. It waits until the image "whoami.exe" is loaded and escalates the rights of the cmd.exe process. An attacker can use this in the real world for example as root shell on a target system (with physical access). Take a look at the kernel debug output generated from the driver:


    Image Load: \Device\HarddiskVolume1\Programme\Support Tools\whoami.exe
    Found Process: System
    Found Process: smss.exe
    Found Process: csrss.exe
    Found Process: winlogon.exe
    Found Process: services.exe
    System Service Security Token: e17c04ea
    Overwriting old Security Token: e1445036
    cmd.exe privilege escalated successfully!

    (Left to right): Windows XP SP2, Windows Vista, Windows 7 RC pwned (take a look at whoami.exe, changes from Peter Kleissner to NT-AUTHORITY\SYSTEM and cmd.exe runs under SYSTEM rights as opposed in the task manager)


    Windows XP cmd.exe privilege escalation Windows Vista cmd.exe privilege escalation Windows Vista cmd.exe privilege escalation



    You may download the Windows 7 RC + TrueCrypt attack demonstration high quality video (11,7 MB) at http://www.stoned-vienna.com/downloads/TrueCrypt Windows 7 RC.avi.

     

    Please download and read TrueCrypt Foundation's mail about the attack at http://www.stoned-vienna.com/downloads/TrueCrypt Foundation Mail 18. Juli 2009.tif. The whole mailings with the TrueCrypt Foundation can be found in the Stoned framework in the directory 'TrueCrypt'.


    Local Infector


    An automated infector Live CD will be published soon. It allows infection of a local machine (requires physical access and the ability to boot from CD or USB stick, this is the second installation way, the first would be using the Windows infector executable). As boot base the Windows PE 2.0 from the Windows Automated Installation Kit is used for automatic deployment. Instructions of how to create your own Stoned Windows PE CD and a download for pre-configured iso will follow. For more information read the blog entry at http://stoned-bootkit.blogspot.com/2009/08/vipin-kumar-windows-pe-and-eminem.html.


    Stoned..

    • is a software in the Master Boot Record, with the target to be memory resident up to the Windows kernel
    • attacks Windows XP, Server 2003, Vista, Server 2008, 7
    • supporting architecture: IA32, AT Architecture (IBM-conforming)
    • full featured, including own file system drivers for FAT and NTFS!
    • supports different boot media, hard disk, removable-media, cd, dvd, flash drives, network..
    • there will be new versions, plugins and updates!

    It has been successfully tested and verified on following systems:


    1. Windows 2000 SP4
    2. Windows XP SP2
    3. Windows XP SP3
    4. Windows Server 2003
    5. Windows Server 2003 R2 SP2
    6. Windows Vista
    7. Windows Vista SP1
    8. Windows Server 2008
    9. Windows 7 Build 6801
    10. Windows 7 Beta
    11. Windows 7 RC
    12. DiskCryptor 0.8
    13. TrueCrypt 6.1a
    14. TrueCrypt 6.2
    15. TrueCrypt 6.2a
    16. Bochs 2.4.1
    17. VMware Workstation 6.5.0


    Stoned v2


    The next version of Stoned is currently under development. The next version is going to be more evil than ever.

    Features:

    - 64-bit support based on the implementation of vbootkit 2.0
    - infecting all local drives (including USB autorun spread)
    - Linux support - experimental
    - BIOS persistent infection - experimental

    The first beta will be released with Hacking at Random 2009. Other changes will be removal of the (under a lot of critics) selling notice. In future Stoned will be published by my startup company Insecurity Systems.

    Future ideas:

    - burning CDs with Stoned when they are inserted
    - using driver that is used by infector and kernel driver
    - infection on access
    - TPMkit
    - using more open source to get the things done

     

    Happy Hacking @itsmeafterall

    Read More
    • Share This:  
    •  Facebook
    •  Twitter
    •  Google+
    •  Stumble
    •  Digg
    Bài đăng cũ hơn Trang chủ

    Popular Posts

    • Proper use of English could get a virus past security
      “ Hackers evade most existing antivirus protection by hiding malicious code in texts, according to security researchers. ”
    • How to Rename Recycle Bin
      You can change the name of Recycle Bin Desktop Icon . 1-Click Start menu > Run > and type “regedit” (without quotes), to ru...
    • New BIOS Virus Which Can Make Your Anti-Virus Useless
      Hackers Have once again launched a Root kit Virus which loads directly into the BIOS memory of the computer and makes it prone . W...
    • Should You Use Hubitat to Automate Your Smarthome?
      The first step in building a smarthome is often choosing a hub, and there are many options. Hubitat is a unique cloud-independent hub. It...
    • 35+ Nokia Cheat Codes
      Nokia is a cell phone marketing company which is currently comes in world top rates mobile phones. Now its obvious that a company like No...
    • What’s the Difference Between Canon’s Regular and L-Series Lenses and Which Should You Buy
      Canon sells regular and L-series lenses (the "L" stands for luxury). While the lenses may have similar specs, you can usually exce...
    • Instructions to earn $ 10 / day to get Amazon Gift Card, Paypal
      You follow the steps below as well as for your Ref, please comment on how to make and receive money. The sponsor of this site is also Am...
    • Autodesk 3ds Max 2017 full + KeyGen - Professional 3D graphics
      Autodesk 3ds Max, formerly 3D Studio, then 3D Studio Max is a professional 3D graphics program for 3D animation, models, games and i...
    • INTRODUCTION AND GUIDANCE TO REGISTER VPS IN VULTR
      I. REGISTER VPS SERVER VULTR First we access the homepage of Vultr. Create a VPS account Here you need to enter email information to create ...
    • Download Adobe Photoshop PTS CS6 Full + Installation Guide
      As a designer, a photographer, or just a photo-editing enthusiast, no one is aware of adobe photoshop.  Adobe Photoshop CS6 was born long ag...

    The Best Penlights for Pocket-Friendly Illumination

    Your phone may have a built-in flashlight, but do you really feel comfortable propping your phone inside of your car's engine bay, or ag...

    Được tạo bởi Blogger.

    Copyright © Engadget | Powered by Blogger
    Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates