Engadget

Hiển thị các bài đăng có nhãn cyberwar. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn cyberwar. Hiển thị tất cả bài đăng

Net Wars : New Challenge For Hackers [Video]

 tháng 12 26, 2009     cyberwar, Video's     No comments   

Net Wars are a new talent hunt for hackers that are good in hacking field and if they win Darth_Vader-3d-2they are given a job of ethical hacking. or if they not they can even get a handful of contacts and goodies too.

 

Some days ago CNN covered the story of this challenge which is currently taking place in U.S. These challenges are taken under by SANS : The most trusted source for computer security... Ya we all know the big SANS. if u dont know who are sans, its a organization of high end ethical hacking teachers and they provide some qualifications in US for ethical Hacking...

The United States Cyber Challenge

A national competition and talent search to find and develop 10,000 cyber security specialists to help the United States regain the lead in cyberspace [ 5/8/09 ].


The web pages for the US Cyber Challenge will be posted on May 29 at www.sans.org/uscc and at other sites. To learn more about the program prior to May 29, email USCC@sans.org


1.The Need
2.The Competition and Skills Programs
3.The Sponsorship...

 

 

Here is what they said about, why they need some hackers aka great security guys in there force and why now.

“The cyber threat to the United States affects all aspects of society, business, and government, but there is neither a broad cadre of cyber experts nor an established cyber career field to build upon, particularly within the Federal Government. [Using an] airplane analogy, we have a shortage of ‘pilots’ (and ‘ground crews’ to support them) for cyberspace.” (Center for Strategic and International Studies, Report of the Commission on Cybersecurity for the 44th Presidency, December 2008)


“The provisioning of adequate cyber forces to execute our assigned missions remains our greatest need.” (Gen. Kevin P. Chilton, Commander, U.S. Strategic Command, March 17, 2009, in testimony before the House Armed Services Committee)


“I cannot get the technical security people I need.” (Gen. Charles Croome, Commander, Joint Task Force ‐ Global Network Operations, in response to a question from a CSIS Commissioner asking what is the most critical problem he faces in meeting the growing cyber challenge. May 28, 2008)

“There are about 1,000 security people in the US who have the specialized security skills to operate effectively in cyberspace. We need 10,000 to 30,000.” (Jim Gosler, Sandia Fellow, NSA Visiting Scientist, and the founding Director of the CIA’s Clandestine Information Technology Office, October 3, 2008.)

Happy Hacking @hackerthdude

Read More
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg

The Anatomy of the Twitter Hack - Twitter's DNS Servers Hacked Yet Again Last Night

 tháng 12 18, 2009     cyberwar, News, Twitter     No comments   


 ~ via Tech Crunch

During and after Twittergate, when a hacker broke into a few hosted email accounts and obtained a number of internal documents, I had an opportunity to spend hours speaking to the actual attacker and document how he carried out the attack.

The article was called The Anatomy of The Twitter Attack, and today we unfortunately find ourselves with a sequel to that post as the Twitter DNS servers were compromised last night and the site was redirected to a defacement page.

Unlike last time, on this occasion I have not had the benefit of speaking directly to the attackers, but have spoken to a number of people within the underground security scene familiar with matters and have constructed other parts of the story from public sources. 

The incident last night was perpetrated by a group called the Iranian Cyber Army – and we have been told that this group is working with the Iranian government...

The attack occurred at the same time as a number of other diplomatic incidents, including the escalation of diplomatic hostilities between Iran and the US/EU as well as an incursion by Iranian troops into a disputed border area containing an oil field....


The defacement was carried out by hijacking the servers hosting the DNS records for the twitter.com domain (this is the server that maps the domain name to an IP address). The attackers modified the DNS records to point to an IP address with a web server hosting the defacement page. The twitter.com domain (registered with NetworkSolutions) was not hijacked, nor were its records altered.

The DNS records for Twitter are hosted at Dyn. A company that provides DNS hosting for over 100,000 domain names and provides other services for companies. We have been told, but have yet to confirm, that the account password recovery feature was used to reset the password for the Twitter account at Dyn. When we checked the password recovery page, it contains a request to contact Dyn directly – there is no form of any type. We have not been able to confirm is there was an automated process at this page which has since been taken down.






To reset the password to gain access to the account hosting DNS records, the attacker had access to the email address associated with the account. Twitter hosts all email on Google Apps for Domain, which played a central role in the previous attack on Twitter not because of any vulnerability within the application itself, but because of a lapse in password policies which lead to a minor account being compromised, which lead to other accounts being compromised.

The attackers gained access to the Twitter account at Dyn, and changed the DNS records for Twitter.com to point to an IP address that was on the anonymous Tor network. The attackers seemed to have changed all the records at Twitter.com, including sub-domains used for the API, the status page, etc. but because of varying caching levels and the fact that some clients were using a direct IP address not all services were affected immediately.

For most users the main Twitter web application was displaying the defacement page for just under an hour.

This type of attack is not very sophisticated, but it is extremely effective. It was not a direct vulnerability with the DNS server but rather with the accounts system and email addresses. While the Twitter application was not compromised, desktop applications and websites that directly send a users username and password back to Twitter over plain HTTP would have sent this information to the attackers IP address, from where it could easily have been harvested.

The solution to similar problems revolves around the management of account passwords, especially with critical services such as DNS hosting. Further, since the status page for Twitter was hosted on the same domain as the main site, it was also inactive during the period of time that the defacement was up on the site and for a short time afterwards while Twitter responded to the attack.
Read More
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Bài đăng cũ hơn Trang chủ

Popular Posts

  • Proper use of English could get a virus past security
    “ Hackers evade most existing antivirus protection by hiding malicious code in texts, according to security researchers. ”
  • How to Rename Recycle Bin
    You can change the name of Recycle Bin Desktop Icon . 1-Click Start menu > Run > and type “regedit” (without quotes), to ru...
  • New BIOS Virus Which Can Make Your Anti-Virus Useless
    Hackers Have once again launched a Root kit Virus which loads directly into the BIOS memory of the computer and makes it prone . W...
  • Should You Use Hubitat to Automate Your Smarthome?
    The first step in building a smarthome is often choosing a hub, and there are many options. Hubitat is a unique cloud-independent hub. It...
  • 35+ Nokia Cheat Codes
    Nokia is a cell phone marketing company which is currently comes in world top rates mobile phones. Now its obvious that a company like No...
  • What’s the Difference Between Canon’s Regular and L-Series Lenses and Which Should You Buy
    Canon sells regular and L-series lenses (the "L" stands for luxury). While the lenses may have similar specs, you can usually exce...
  • Instructions to earn $ 10 / day to get Amazon Gift Card, Paypal
    You follow the steps below as well as for your Ref, please comment on how to make and receive money. The sponsor of this site is also Am...
  • Autodesk 3ds Max 2017 full + KeyGen - Professional 3D graphics
    Autodesk 3ds Max, formerly 3D Studio, then 3D Studio Max is a professional 3D graphics program for 3D animation, models, games and i...
  • INTRODUCTION AND GUIDANCE TO REGISTER VPS IN VULTR
    I. REGISTER VPS SERVER VULTR First we access the homepage of Vultr. Create a VPS account Here you need to enter email information to create ...
  • Download Adobe Photoshop PTS CS6 Full + Installation Guide
    As a designer, a photographer, or just a photo-editing enthusiast, no one is aware of adobe photoshop.  Adobe Photoshop CS6 was born long ag...

The Best Penlights for Pocket-Friendly Illumination

Your phone may have a built-in flashlight, but do you really feel comfortable propping your phone inside of your car's engine bay, or ag...

Được tạo bởi Blogger.

Copyright © Engadget | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates