Showing posts with label Hacking News. Show all posts
Showing posts with label Hacking News. Show all posts

Monday, 29 October 2012

Virus threat hit Israeli Foreign Ministry computers


Cyber attacks on websites run by government have very common and in nearly every country many such incidents are reported every now and then. These attacks are the proof of the increasing audacity of the hackers worldwide and their expertise in gaining confidential information from government channels. This is the reason why most government agencies today are concerned more about this new form of attack rather than the conventional ones as hackers can do much more than just breaking into some servers or user accounts. Hackers today love to exploit the smallest of weaknesses in the security setup and flaunt their acts as achievements on the internet and given the speed with which such news spreads on the internet, it soon becomes a national embarrassment for the concerned government.


In the latest incident, a number of the offices of the Israel Government have become victims of a cyber attack in the past week when an attack which aimed at slipping a Trojan horse into the servers of some ministries. The Trojan horse was supposedly sent as an attachment to emails which bear the name of the Israel Defence Forces Chief of Staff Benny Gantz in the subject line. After learning of the threat, the Israeli Police pulled the national computer network from the public internet for fear of a cyber attack. A senior government official later commented that the incident was being investigated and it is quite possible that it is an isolated incident.

Sources who have gained access to the internal communications of the Foreign Ministry’s defence department have claimed that the communication mentions the appearance of unusual e-mails in the various embassies and delegations etc. during the past week. Most of those emails either contain a mention of the IDF Chief Benny Gantz or are sent from an address bearing his name. The content portion of the emails consists of statements made by politicians and some emails consisted of facebook friend requests and some links to Gant’s website. A lot of such emails were sent on Wednesday to various departments and embassies in the country and abroad also but were rejected this time by an automated system, which declared them as offensive with possibility of containing Trojans or viruses and also warned that they could be activated upon opening and could damage the central computer system.

To curb this problem effectively, the Foreign Ministry issued warnings to employees about using emails and facebook accounts and cautioned them that the malicious content could reach them through emails or facebook and that they should report any suspicious email or activity to the defence department.

It is believed that the Israel police had received an intelligence tip concerning the possible cyber attack and had information that a virus could be inserted using a USB drive or CD into the central computer system of the police.

The intelligence update did not mention anything about the identity of the culprits responsible for the attack. Moreover, it could not be confirmed whether the attack was made on a few systems or the complete networks and whether any system had been hacked actually. However, Israel government will have to be alert and cautious regarding this cyber threat during the coming days.

Hacker leaks source code of NASA website belongs to US Government computer


A hacker who calls himself LegitHacker97 has made a claim that he has hacked one of the sub domains of the website of the National Aeronautics and Space Organisation (NASA), which actually belongs to a computer of the U.S. Government. This is  the most recent in a long list of such incidents where hackers have broken into many important government websites to steal information or to reveal the vulnerabilities that are there and this is not the first time that the NASA website has been hacked or somebody has exposed the security weaknesses of the space organisation. In fact it has been officially been confirmed by NASA officials that their website was hacked 13 times in the last year so this hack should come as no surprise.


The hacker has pasted a compressed archive file of 82.52 MB on the net five days ago, which includes the complete coding of  the website in ASP. After downloading the file from the link posted by the hacker, it was found that the files included in the dump were the same that belonged to the NASA sub domain website https://nsckn.nasa.gov and the same address has been mentioned by the hacker. This leaves one to speculate how a hacker got entry into a sub domain that can be accessed only by authorised users.

Actually the domain https://nsckn.nasa.gov belongs to the NASA’s NSC Know Now centre which contains the information and access to the aerospace contractor community technical documentation related to the Space Launch System (SLS). To get the login, a contractor has to contact the designated official and create a profile. After creation of the profile, the contractor has to submit proof to the designated official that it is a U.S. based company and attach an affidavit for the same after which the access is provided as soon as possible by the designated officer Joseph McCollister.

When enquired about the way the hacker got access to the site, the hacker mentioned that he exploited the Local File Inclusion vulnerability in the site and gained access by uploading the backdoor to the site. Local File Inclusion vulnerabilities are commonly exploited by the hackers to gain access to such websites as these vulnerabilities allow hackers to add files of their own to the website server.

This means that hacker gained access by first establishing rapport with the designated officer of the NSC Know Now centre which helped in creating the profile. After which the hacker exploited the vulnerability and accessed the server which means that the hacker used social engineering to gain the trust of the officials. This is quite possible since a human error is practically irreparable and no cure is available for a little carelessness  and it can become the weakest link in the security. However,  the officials at NASA will have to make sure that such acts of fallacy in reasoning are not repeated and NASA will have to review its online security setup  so that hackers are not allowed to gain access. This is because it is always a source of concern if government sites are blatantly hacked every now and then.

Anonymous hacks 20 million accounts to promote Operation Jubilee



Anonymous, the famous hacktivist group which has been planning and executing incidents for nearly a decade now with their philosophy of being the change in the world whist staying anonymous is up and roaring once again as the group who has been involved in several cyber attacks in the past few days. The Anonymous has recently claimed to have hacked over 20 million user accounts this year and have done this to promote their large scale project called the Operation Jubilee. The hacking of these accounts, they say, was done to gain access to contact information so as to gather more and more support for the Operation Jubilee. The hackers attacked large community web sites to achieve their objectives and gained user account information while the web administrators kept stating that no data had been stolen from their websites while they having been hacking their sites for nearly a year or so. This is the most recent in the series of attacks Anonymous has executed in connection with their Operation Jubilee which has received great public attention after some recent incidents carried out by the Anonymous.

Operation Jubilee is supposedly one of the biggest and ambitious projects of the Anonymous and they plan to execute it on the 5th November, 2012. It is a massive public gathering organised by the group who will protest outside the Parliament Building in London. The objective of the Operation Jubilee is to end the economic crisis and to bring an end to all debt, wars and poverty. This is based on the realisation of the potential that a congregation of people possesses in order to bring the much required change in the world. The most recent incident in the Operation Jubilee was when the Anonymous hacked and defaced the UK Police forums and sent out emails to the police officers urging them to join the operation Jubilee and help as they were also one of the general public beneath their uniforms.

This has lead to intense speculation about the exact nature of the protests that are going to be part of the Operation Jubilee as the public opinion varies in this regard. While some take it to be a genuine endeavour on part of the group, while some have commented that it will be nothing but another riot planned by the Anonymous. To clear such apprehensions, the hackers have sent millions of emails to people and police officers in which they have stated the Rules Of Engagement if they join Operation Jubilee. Notably, the hackers have mentioned that the protesters will confiscate any weapons possessed either by the public or the police and will execute a citizen’s arrest if a situation of violence arises as they want the protests to be peaceful and will subdue anybody who turns violent. Well, given the unsatisfactory success of their earlier protests in Greece etc. it seems to be a good move but the success of the operation will be judged only on the 5th November, 2012.

Furthermore, considering the nature of Anonymous and their association with hack attacks and protests, it becomes difficult to assess the outcome of Operation Jubilee at present and whether it will succeed in being a peaceful gathering or not.

Friday, 26 October 2012

Windows 8 security focuses detecting malware early | Microsoft has greatly improved the operating system's ability



In Windows 8, Microsoft has greatly improved the operating system's ability to detect malware before it has a chance to run, experts say. Windows 8 should also make it more difficult for people to unknowingly install malware in the first place.

The latest version of the OS, officially launched Thursday in a splashy event in New York, includes two key features to detect malware that tries to run while Windows is booting up. Hackers typically like to get their software running before the OS is fully loaded in order to remain hidden from antivirus applications.

Rootkits are a class of stealthy malware that opens a backdoor, so cybercriminals can control a PC. To avoid detection, the malware will replace the code used to start a computer with itself and disable antivirus software.

To battle rootkits, Microsoft has required computer manufacturers to drop the use of the 30-year-old BIOS firmware and replace it with the Unified Extensible Firmware Interface (UEFI). The BIOS sets up communications between the OS and computer hardware before handing over control to the OS.

[Bill Brenner in Salted Hash: Windows 8 - Security pros and cons]

UEFI makes loading rootkits more difficult by requiring that the initial boot up code be digitally signed with a certificate derived from a key in the UEFI firmware. The feature, called Secure Boot, helps ensure that the code is from a trusted source.

"This is a big step in the right direction of ensuring that no malware can install itself," said Wolfgang Kandek, chief technology officer of Qualys.

The push against rootkits comes as more sophisticated versions of the malware are being used in targeted attacks to steal documents and intellectual property from government agencies and large corporations, such as defense contractors.

This month, a House committee recommended against using products from Chinese company Huawei, saying such malware could be used in its networking gear. Experts believe China is a hotbed of cyber-espionage activity.

"Nearly all security products lack the ability to peer below the operating system to detect malware," said Paul Henry, a computer forensics expert and vice president of VNet Security. "Perhaps these new capabilities from Microsoft in Windows 8 will bring about that needed capability."

Another early-detection feature is Early Launch Anti Malware. ELAM improves security by allowing anti-virus vendors to run software while the OS is still loading, something that only Microsoft software could do before. Early loading gives antivirus vendors a chance to get their software in place before malware is activated.

While many security experts believe Windows 8 is the most secure version of the OS to date, it doesn't mean malware won't evolve to focus on other weaknesses. Security areas not addressed in Windows 8 include a better system for detecting malware before the user installs it. Such a scenario would happen if a person were tricked into opening an email attachment.

With the latest version of Mac OS X, Mountain Lion, Apple introduced a feature called Gatekeeper. The feature gives the user several options in downloading software from the web, including limiting all installations to apps downloaded from the Mac App Store.

Kandek believes Microsoft may eventually head in the same direction. "With the introduction of the Windows 8 app store, they're trying to steer people more toward approved applications," Kandek said. "But it's not as strong as it is on the [Apple] iPhone platform where you get everything from the App Store."

Besides having trusted consumer app stores available, Kandek said he believes Microsoft should make it possible for companies to manage employee-only stores.

While blocking software from an unknown source would be good from a security standpoint, such a feature may be difficult on Windows because of the huge amount of software built for the OS, said Aryeh Goretsky, a security researcher at ESET.

"The Windows Store is going to allow them to create a very large ecosystem," Goretsky said. "But I don't know if it's ever going to be on the desktop Windows side at the point where you can only go through the Windows Store."

Antivirus vendors are particularly interested in the impact the new version of Windows Defender in Windows 8 will have on their business. Windows Defender includes antivirus protection.

In a recent white paper, ESET said Defender was better than free versions of antivirus products, but lacked advanced features found in paid software, such as task scheduling, centralized management and reporting.

However, a big change in Windows 8 when it comes to antivirus software is Microsoft's requirement that vendors provide a clean uninstall, which means no more leaving files, drivers, registry entries and other remnants that use to cause conflicts with other software and headaches for users. Microsoft's edict should also make installing and uninstalling antivirus software much easier.

Windows 8 also includes a new version of Internet Explorer. Version 10 of the browser includes running Adobe Flash in a sandbox, which is the architecture used in Google Chrome. In addition, Microsoft will push updates to Flash automatically, so people will no longer have to deal with a second vendor for updates.

By Antone Gonsalves

$400,000 looted from city bank account by Cyberthieves


Officials have notified hundreds of employees and residents that their bank account information was compromised last week when hackers broke into city systems and stole more than $400,000 from a city account at Bank of America.

In an alert issued this morning, city administrator Bryan Harrison said all autopay customers should assume that their name, bank account number and routing number was comprised following an intrusion into a city utility billing system.

Among those impacted by the breach are employees participating in Burlington's electronic payroll deposit program and utility customers enrolled in the city's autopay program for sewer and storm drain charges.



The city immediately reviewed the activity and noticed at least three "significant transactions" from its Bank of America account to accounts at the east coast bank. In all, over $400,000 was illegally transferred to business and personal accounts around the country over a two-day period, Harrison said.

The theft could have been much worse because the affected account contained a lot more cash, he said.. "There was much more in that specific account. We don't know if [the hackers] just didn't have the time" to steal more funds.

Investigators are trying to figure out how the intruders gained access to the Bank of America account. The account has been frozen and all of the city's money has been temporarily moved out of Bank of America as a precaution.

Numerous other small town, municipalities and small businesses have been victimized by similar online heists over the past three or four years.

In most incidents, the cybercrooks first stole usernames and passwords used by to gain access to bank accounts. The stolen credentials were then used to log into the online accounts and wire transfer money to mule accounts in the United States and abroad.

The FBI has estimated that U.S. businesses and banks have lost hundreds of millions of dollars due to such thefts in recent years.

The Burlington theft came just days after security firm RSA warned of cybercriminals plotting a massive and concerted campaign to steal money from the online accounts of thousands of consumers at 30 or more major U.S. banks.

In an advisory posted earlier this month, RSA said it had information suggesting that a criminal gang planned to unleash a Trojan program called Gozi Prinimalka that would infiltrate computers belonging to U.S. banking customers and to initiate fraudulent wire transfers from their accounts.

According to RSA, the organizers of the attack are currently recruiting about 100 botmasters to launch and coordinate the attacks.

Since RSA's alert, several other security experts have reported seeing the signs of preparation of an imminent and massive attack against U.S banking customers.

By  Jaikumar Vijayan

US Military Detention policies Hacked and Released by WikiLeaks

The whistleblowing website Wikileaks from tonight releasing more than 100 U.S. Defense Department files detailing military detention policies in camps in Iraq and at Guantanamo Bay in the years after the September 11 attacks on U.S. targets - "The Detainee Policies"


In a statement, WikiLeaks criticized regulations it said had led to abuse and impunity and urged human rights activists to use the documents to research what it called policies of unaccountability. WikiLeaks says it plans to release the files in chronological order to paint a picture of the evolution of America’s military detainee practices.

WikiLeaks founder Julian Assange said: "The ’Detainee Policies’ show the anatomy of the beast that is post-9/11 detention, the carving out of a dark space where law and rights do not apply, where persons can be detained without a trace at the convenience of the U.S. Department of Defense. It shows the excesses of the early days of war against an unknown ’enemy’ and how these policies matured and evolved, ultimately deriving into the permanent state of exception that the United States now finds itself in, a decade later."

In January, U.N. human rights chief Navi Pillay said the United States was still flouting international law at Guantanamo Bay by arbitrarily and indefinitely detaining individuals. Almost 3,000 people were killed in 2001 when militants from Osama bin Laden's al Qaeda flew hijacked airliners into the World Trade Center towers in New York, the Pentagon and a field in Pennsylvania. - Reuters said.

WikiLeaks said a number of documents it was releasing related to interrogation of detainees, and these showed direct physical violence was prohibited. But it added the documents showed "a formal policy of terrorizing detainees during interrogations, combined with a policy of destroying interrogation recordings, has led to abuse and impunity."

According to Forbes, WikiLeaks latest publication breaks with its two previous releases of 2012 from the private intelligence firm Stratfor and the Syrian government, both of which consisted of millions of hacked emails rather than a small collection of leaked documents. Just how WikiLeaks obtained the new documents isn’t clear its anonymous submission system has been down for more than two years, with no new conduit for secure document leaks in sight.

Wednesday, 24 October 2012

UK Police forum and Dating Portal Defaced by Anonymous


Anonymous deface the UK Police Online web forum (http://www.ukpoliceonline.co.uk) and stole the private emails addresses of various members. The Metropolitan Police's e-Crime unit is investigating the hack and said that no computer system run by the police force had been hacked.

The Hack was originally announced by an Anonymous Twitter account - Operation Jubilee (OpJubilee), they post a mirror url of defaced page. This hack was one of the part of OpJubilee.

ANONYMOUS OPERATION JUBILEE: Under this there will be Rally of Millions people To Parliament, London on 5th of November 2012. As planned this will be a peaceful gathering at the Parliament Building in London to declare the true jubilee

Hackers send out emails to the former officers whose details were obtained during hack, with a subject line: "A message to the police and armed forces".

Message body: "Hello members of our UK police and armed forces" and called for recipients to "stand with us, not against us. Under your uniform you are one of us and we are you. United we stand and can make this world a better place for all of us. We are not against you, only against the evil system that you defend, and we appeal to your consciences to stop protecting the traitors and banksters, and protect us from them instead.”

The hacktivists have previously been linked with compromised security on police websites in the US and other countries. They end the mail with, “Brothers in arms, join us and end wars and poverty. United we stand.”

This online forum actually include, a discussion board on homepage, Police Dating site, Gallery, Downloads and a police equipment estore.

MET police said, "It would appear that a third party forum has been compromised and personal email details retrieved,". Before under Operation Jubilee, Hackers deface some other UK police forums also.

Anonymous hits HSBC by Cyber attack and claims to have 20,000 debit card details


HSBC has blamed a denial of service attack for the downtime of many of its websites worldwide on Thursday night and the Anonymous group has been quick to take credit.

HSBC said, "This denial-of-service attack did not affect any customer data, but did prevent customers using HSBC online services, including Internet banking. We are taking appropriate action, working hard to restore service. We are pleased to say that some sites are now back up and running. We are cooperating with the relevant authorities and will cooperate with other organizations that have been similarly affected by such criminal acts."

HSBC itself confirmed the claim that some of their websites had suffered a large scale cyber attack and that a slowdown or denial of services had occurred as a result. This attack is indeed one of the biggest attacks in recent times and first time in HSBC history and has shocked many and forced many to speculate the future of web security. Many groups have claimed responsibility for the attacks but it is one of the two groups who are actually believed to be responsible. One of the groups is called FawkesSecurity and the other group is the Izz ad-Din Al Qassam group who have both claimed responsibility for the cyber attack on HSBC bank.

Veritably both groups have cited their reasons for this heist. The FawkesSecurity group has stated that they committed this cyber attack because they believe that the British Banking system is corrupt and helpful only for those in high places. The Al Qassam group cites a completely different reason for the attack on HSBC. They claim that the release of the controversial Anti Islam film, “The Innocence of Muslims” is the reason as they wanted to retaliate against the same. Whatever the reasons might have been, the truth is that businesses are under highest risk from such cyber attacks and this is surely a reason for worry and introspection.

Sony PlayStation 3 hacked using custom Firmware


Amazing PlayStation 3 has been hacked recently, originally with the PSJailbreak dongle and fail0verflow, but Sony managed to fight back with Firmware 3.60 which managed to ingeniously re-secure the console.

PS 3 security was undermined in early 2011 after hacking team Fail0verflow detailed a technique to get unauthorized code running on Sony’s console. At the time, the group said they attacked the console’s security as a response to Sony removing the Other OS feature that allowed installation of the Linux operating system on the PS3.
However, the newly released custom firmware contains the current PSN passphrase security protocol. And even if Sony changes that with new firmware, the release of the LV0 decryption keys means that hackers should be able to easily lay bare future security measures in system updates.

According to Eurogamer, Chinese hacking group BlueDiskCFW had planned to sell the custom firmware circumventions, which prompted another group called The Three Tuskateers to release the LV0 keys. They also released a statement claiming to have discovered the keys some time ago, adding, “only the fear of our work being used by others to make money out of it has forced us to release this now.”

The team of hackers released the following announcement:
As this was a group effort, we wouldn’t normally have lost a word about it ever, but as we’re done with PS3 now anyways, we think it doesn’t matter anymore. Congratulations to the guy that leaked stuff, you, sir, are a 1337 haxx0r, jk, you’re an asshole.

People should know that crooked personalities are widespread in this so called ‘scene’. Some people try to achieve something for fun together and make the wrong decision to trust others and share their results with them, but ofc there got to be the attention seeking fame wh*** that has to leak stuff to feel a little bit better about him-/herself. Now the catch is that it works like this in every ‘scene’, just that in others it usually doesn’t come to light.The only sad thing is, that the others who worked on this won’t get the attention they deserve because they probably want to remain anonymous (also they don’t care about E-fame <3 data-blogger-escaped-br="br">

Anonymous going to launch project called TYLER like Wikileaks


In an exclusive interview to the Voice of Russia a member of Anonymous talks about the conflict that revolves around the coercive fund raising techniques and a lack of transparency regarding WikiLeaks. He also mentions the possible release of a list of what they view as WikiLeaks ethical violations. On December 21, 2012 Anonymous is planning to launch a secure, no cost and decentralized online leaks release platform called TYLER to circumvent to problems inherent in WikiLeaks and to continue to disclose information that governments, including US, are hiding from people.

They have scheduled this new project to December 21 this year. According to the hacker, who requested anonymity, the conflict between Anonymous and the website of Julian Assange revolves around the forced funding techniques and lack of transparency around money to WikiLeaks.

So far Anonymous defends WikiLeaks and Assange personally and supported the mission of the site to share information, news and classified information with the public. They even helped to publish more than 2 million emails, known as the Syrian file.
Anonymous: It is important that these questions are being answered as “Anonymous”. At a later time if you would like to interview me regarding my own situation that might be possible, but on this issue I am acting as part of the Anonymous collective.
Robles: “Can you tell us any other reasons that have not been publicized as to why Anonymous has decided to part ways with WikiLeaks?”

Anonymous: No I think we were fairly clear and straightforward in the press release we forwarded to you. Assange’s reply to us via his public statement on Twitter did not help the situation, as it was generally viewed as condescending and arrogant. So I would say that has exasperated the rift. Beyond that the conflict revolves around the coercive fund raising techniques and a lack of transparency regarding WikiLeaks finances.
Robles: “There have been statements that Anonymous plans to release secret files about WikiLeaks, can you give us a few details about these files and what kind of revelations they will provide?”
In this case, it is unclear whether the hacker to interview to Russian media reflect the views of the entire community of anonymous or its individual fragments as haktivistite not acting in an organized group with a recognized leader.