Showing posts with label Hack. Show all posts
Showing posts with label Hack. Show all posts

Sunday, December 5, 2010

Pakistan Army Site was Hacked By Indian Hacker!!!

The official website of the Central Bureau of Investigation was hacked late on Friday, on December 4th, by a group calling itself the 'Pakistani cyber army'.

The home page of India's premier investigating agency's website had a message from the 'Pakistani cyber army' warning the 'Indian cyber army' not to attack Pakistani websites.

In response to this embarrassing incident, An Indian hacker named, tango_charlie, hacked the pakistan army official website within no time of the later cyber attack. 


A side note: An advise to all the system admins, pls monitor your websites regularly and check for vulnerability.

Sunday, September 26, 2010

How to Stop Bom Sabado Worm? Here is the way!

Everyone whose orkut account has been affected with the Sabado Worm, can use this simple trick to get out of this issue. People whose account is not yet affected, please follow the below steps to keep this worm away from your accounts.

The worm injects a hidden iframe containing a malicious javascript [do not click this] http: //tptools. org/ worm . js [do not click this], which steals the user cookie which contains the password in an encoded form. Even though the attacker does not get to know your password, they can login to your account using your credentials by impersonating the cookie to fool the identification system. 



So a trivial solution is to diable javascript, another solution is to disable iframes or u can take an advanced measure by blocking the domain http : // tptools . org / by editing your hosts file and redirecting it to a safe address, say 127.0.0.1 go to C:>windows>system32>driversetc There is a file named %u2018hosts%u2019. It is a read-only file. Go to it's properties and un-check the read-only option and edit it with you favourite editor. add this line at the end of it 127.0.0.1 tptools.org save it. and then restart your network interface. ( in simple words, just reconnect your internet connection ). Bingo!! the worm%u2019ll became useless!!!! 

Friday, September 24, 2010

Orkut is attached by Bom Sabado Worm!!!

In a major XSS (cross-site scripting) attack this week, Google owned Orkut was flooded with "Bom Sabado" scraps.

The word "Bom Sabado" means "Good Saturday" in Portuguese, which is the also the official language of Brazil, one of the last remaining Orkut bastions in the world.

The worm seems to be posting scraps with the text "Bom Sabado" and also adding affected users to new Orkut groups. Such XSS attacks have targeted Orkut in the past too.

Experts have advised users to avoid logging on to Orkut till Orkut engineers fix the hole and also not to click on any suspicious links. Orkut had just last month announced new updates to the website.

Earlier this week, the popular microblogging website Twitter was also at the receiving end of an XSS exploit. The attack, which emerged and was shut down within hours Tuesday morning, involved a XSS flaw that allowed users to run JavaScript programs on other computers.

Earlier on Sep 2010, the most popular social networking hub with more than 500 million users, Facebook, also faced networking glitches due to an outside technical problem. It was Facebook's most tragic outrage in its history.

Thursday, September 9, 2010

Here you have' e-mail worm hits corporate world!!

A new virus based in e-mails with the subject line "Here You have" began running rampant Thursday, hitting corporate America hard.

So far, the virus has already been sighted at ABC/Disney, Google, Coca Cola and NASA, several individuals with knowledge of the situation told. Comcast was forced to shut down its e-mail servers entirely after being hit, a spokesperson said on Twitter.

E-mails that carry the virus contain a link that encourages readers to click on a PDF document file. But rather than a PDF, the file  contains a Windows script that transmits a virus and spams the entire contact list of the person who opened the file.



The worm is similar to the ILoveYou and Anna Kournikova worms, which spread in 2000 and 2001, and is a type of malware that has not been a major problem since around 2002, according to David Cowings, a senior manager with Symantec Security Response. "It looks like we've had a resurgence of mass-mailing worms," he said.

This latest worm seems to do nothing more than send itself out, using the victim's contact list. Cowings said "It appears to be mailing itself to all of the mailing lists that are in someone's contacts. It may also go to individuals," he said. The worm appeared to be affecting Outlook e-mail users, but it's not clear if it is also affecting users of other mail programs.

The body of the e-mail typically says something like, "Hello... this is the document I told you about, you can find it here." Because the worm is spreading via contact lists, the e-mail often comes from someone the victim knows.

A note posted on the McAfee site Thursday afternoon said: "It looks like multiple variants may be spreading and may take some time to work through them all to paint a clearer picture."

Sunday, September 5, 2010

A Strong Password Isn't The Strongest Security

Make your password strong, with a unique jumble of letters, numbers and punctuation marks. But memorize it, never write it down. And, oh yes, change it every few months. These instructions are supposed to protect us. But they don’t!

Some computer security experts are advancing the heretical thought that passwords might not need to be “strong,” or changed constantly. They say onerous requirements for passwords have given us a false sense of protection against potential attacks. In fact, they say, we aren’t paying enough attention to more potent threats.


Here’s one threat to keep you awake at night: Keylogging software, which is deposited on a PC by a virus, records all keystrokes — including the strongest passwords you can concoct — and then sends it surreptitiously to a remote location.

“Keeping a keylogger off your machine is about a trillion times more important than the strength of any one of your passwords,” says Cormac Herley, a principal researcher at Microsoft Research who specializes in security-related topics. He said antivirus software could detect and block many kinds of keyloggers, but “there’s no guarantee that it gets everything.”

After investigating password requirements in a variety of settings, Mr. Herley is critical not of users but of system administrators who aren’t paying enough attention to the inconvenience of making people comply with arcane rules. “It is not users who need to be better educated on the risks of various attacks, but the security community,” he said at a meeting of security professionals, the New Security Paradigms Workshop, at Queen’s College in Oxford, England. “Security advice simply offers a bad cost-benefit tradeoff to users.”

One might guess that heavily trafficked Web sites — especially those that provide access to users’ financial information — would have requirements for strong passwords. But it turns out that password policies of many such sites are among the most relaxed. These sites don’t publicly discuss security breaches, but Mr. Herley said it “isn’t plausible” that these sites would use such policies if their users weren’t adequately protected from attacks by those who do not know the password.

Mr. Herley, working with Dinei FlorĂȘncio, also at Microsoft Research, looked at the password policies of 75 Web sites. At the Symposium on Usable Privacy and Security, held in July in Redmond, Wash., they reported that the sites that allowed relatively weak passwords were busy commercial destinations, including PayPal, Amazon.com and Fidelity Investments. The sites that insisted on very complex passwords were mostly government and university sites. What accounts for the difference? They suggest that “when the voices that advocate for usability are absent or weak, security measures become needlessly restrictive.”

Donald A. Norman, a co-founder of the Nielsen Norman Group, a design consulting firm in Fremont, Calif., makes a similar case. In “When Security Gets in the Way,” an essay published last year, he noted the password rules of Northwestern University, where he then taught. It was a daunting list of 15 requirements. He said unreasonable rules can end up rendering a system less secure: users end up writing down passwords and storing them in places that can be readily discovered.

“These requirements keep out the good guys without deterring the bad guys,” he said.

Northwestern has reduced its password requirements to eight, but they still constitute a challenging maze. For example, the password can’t have more than four sequential characters from the previous seven passwords, and a new password is required every 120 days.

By contrast, Amazon has only one requirement: that the password be at least six characters. That’s it. And hold on to it as long as you like.

A short password wouldn’t work well if an attacker could try every possible combination in quick succession. But as Mr. Herley and Mr. FlorĂȘncio note, commercial sites can block “brute-force attacks” by locking an account after a given number of failed log-in attempts. “If an account is locked for 24 hours after three unsuccessful attempts,” they write, “a six-digit PIN can withstand 100 years of sustained attack.”

Roger A. Safian, a senior data security analyst at Northwestern, says that unlike Amazon, the university is unfortunately vulnerable to brute-force attacks in that it doesn’t lock out accounts after failed log-ins. The reason, he says, is that anyone could use a lockout policy to try logging in to a victim’s account, “knowing that you won’t succeed, but also knowing that the victim won’t be able to use the account, either.” (Such thoughts may occur to a student facing an unwelcome exam, who could block a professor from preparations.)

Very short passwords, taken directly from the dictionary, would be permitted in a password system that Mr. Herley and Stuart Schechter at Microsoft Research developed with Michael Mitzenmacher at Harvard.

At the Usenix Workshop on Hot Topics in Security conference, held last month in Washington, the three suggested that Web sites with tens or hundreds of millions of users, could let users choose any password they liked — as long as only a tiny percentage selected the same one. That would render a list of most often used passwords useless: by limiting a single password to, say, 100 users among 10 million, the odds of an attacker getting lucky on one attempt per account are astronomically long, Mr. Herley explained in a conversation last month.

Mr. Herley said the proposed system hadn’t been tested and that users might become frustrated in trying to select a password that was no longer available. But he said he believed an anything-is-permitted password system would be welcomed by users sick of being told, “Eat your broccoli; a strong password is good for security.”

Wednesday, August 25, 2010

Pentagon: Computers Attacked With Flash Drive!!

A foreign spy agency pulled off the most serious breach of Pentagon computer networks ever by inserting a flash drive into a US military laptop, a top defense official said Wednesday. The previously classified incident, which took place in 2008 in the Middle East, was disclosed in a magazine article by Deputy Defense Secretary William J Lynn and released by the Pentagon Wednesday. He said a "malicious code" on the flash drive spread undetected on both classified and unclassified Pentagon systems, "establishing what amounted to a digital beachhead, from which data could be transferred to servers under foreign control." "It was a network administrator's worst fear: a rogue program operating silently, poised to deliver operational plans into the hands of an unknown adversary," Lynn wrote in an article for Foreign Affairs. "This ... was the most significant breach of US military computers ever and it served as an important wake-up call." The Pentagon operation to counter the attack, known as Operation Buckshot Yankee, marked a turning point in US cyberdefense strategy, Lynn said. 







In November 2008, the Defense Department banned the use of the small high-tech storage devices that are used to move data from one computer to another. The ban was partially lifted early this year with the approval of limited use of the devices. Lynn did not disclose what, if any, military secrets may have been stolen in the 2008 penetration of the system, what nation orchestrated the attack, nor whether there were any other repercussions. The article went on to warn that US adversaries can threaten American military might without building stealth fighters, aircraft carriers or other expensive weapons systems. "A dozen determined computer programmers can, if they find a vulnerability to exploit, threaten the United States' global logistics network, steal its operational plans, blind its intelligence capabilities, or hinder its ability to deliver weapons on target," Lynn wrote.

"Knowing this, many militaries are developing offensive capabilities in cyberspace, and more than 100 foreign intelligence organizations are trying to break into US networks," he said.

Defense officials have said repeatedly that the military system of some 15,000 computer networks and seven million computers suffers millions of probes a day with threats coming from a range of attackers from routine hackers to foreign governments looking to steal sensitive information or bring down critical, life-sustaining systems.

Tuesday, August 17, 2010

Android Game Isn't Actually a Game

Another malicious application has been found from the Android Market. A game called Tap Snake isn't just a game, it turns out to be a client for a commercial spying application called GPS SPY.

The Tap Snake game looks like an average "Snake" clone. However, there are two hidden features. First, the game won't exit. Once installed, it runs in the background forever, and restarts automatically when you boot the phone. And secondly, every 15 minutes the game secretly reports the GPS location of the phone to a server.







GPS SPY is a simple mobile spying tool and only costs $4.99. When bought, the application advises you to download and install the "Tap Snake game" to the phone you want to spy on. During installation, the game is registered with a keycode to enable spying. This means that the spy has to have physical access to the phone he wants to spy on.




In many ways, GPS SPY / Tap Snake can be seen as a little brother of mobile spying tools like FlexiSPY. GPS SPY is developed by a Russian developer based in Texas, Mr. Max Lifshin ("Maxicom").

We expect Google to remove Tap Snake from Android Market soon.

As we noted above, we fully expect that Google will pull Tap Snake from the Android Market. But it's also possible that they'll once again flip Android's kill switch and it will be interesting to see if Tap Snake meets Google's kill criteria. 

Wednesday, August 11, 2010

Gmail makes changes to it account!

Google has made some updates to the Gmail experience with a heavy focus on contacts. The company says that out of all of the feedback it gets about Gmail, most of it is about improving the contacts experience. 


New contacts features include:


Keyboard shortcuts (go to Contacts and hit "?" for the full list)
Sort by last name (look under "More actions")
Custom labels for phone numbers and other fields
The ability to undo changes you've just made
Automatic saving
Structured name fields, so you can adjust titles, suffixes, and other name components
A bigger, more prominent notes field
In addition to these, Google has slightly altered the look of Gmail. Mail, Contacts, and Tasks links have been moved to the top left. Compose Mail is now a button rather than a link. A smaller header area puts the first message in your inbox higher on the screen. Finally, the select all, none, read, unread, and starred links that used to be above messages are now in a drop-down menu, next to the archive button. 


The features has been rolled out in everyone's account. The company also says that Google Apps users will have to wait because they're working on making domain-specific features work well with the new interface. The company seems to be paying more attention to the security piece as well. The users are asked to verify their alternate email account and the phone number to overcome several attempts to hack the Google account across the globe.


I am excited to see the new changes. It looks like my favorite Gmail would become my favorite email account for ever! :)

Tuesday, June 15, 2010

Security experts release tool to hack Android phones!

Two security experts said on Friday they released a tool for attacking smartphones that use Google Inc's Android operating system to persuade manufacturers to fix a bug that lets hackers read a victim's email and text messages.

"It wasn't difficult to build," said Nicholas Percoco, head of Spider Labs, who along with a colleague, released the tool at the Defcon hacker's conference in Las Vegas on Friday.

Percoco said it took about two weeks to build the malicious software that could allow criminals to steal precious information from Android smartphones.

"There are people who are much more motivated to do these things than we are," he added.

The tool is a so-called root kit that, once installed, allows its developer to gain total control of Android devices, which are being activated by consumers at a rate of about 160,000 units per day, according to Google.

"We could be doing what we want to do and there is no clue that we are there," Percoco said.

The test attacks were conducted on HTC Corp's Android-based Legend and Desire phones, but he believed it could be conducted on other Android phones.

The tool was released on a DVD given to conference attendees. Percoco was scheduled to discuss it during a talk on Saturday.

Google and HTC did not immediately return calls for comment.

Some 10,000 hackers and security experts are attending the Defcon conference, the world's largest gathering of its type, where computer geeks mix with federal security officials.

Attendees pay $ 140 in cash to attend and are not required to provide their names to attend the conference. Law enforcement posts under cover agents in the audience to spot criminals and government officials recruit workers to fight computer crimes and for the Department of Defense.

Organizers of the conference say presenters release tools such as Percoco's root kit to pressure manufacturers to fix bugs.

Friday, January 22, 2010

Electronic Clearing System of the Income Tax Department, India hacked: Hacker Diverted around Rs 15 crore

The Electronic Clearing System (ECS) of the Income Tax (I-T) Department has been hacked into, jeopardising the functioning of department across Mumbai. On Wednesday, three days after the incident, the I-T department handed over the investigation to the Central Bureau of Investigation (CBI).

Sources revealed that the ECS of the I-T department, which facilitates tax refunds of Mumbaikars has been hacked into. It is believed, the hacker also managed to divert crores of rupees from the system. Following this incident, the entire system that processes income tax payment has been shut down since Monday. To prevent further damage, the department has now changed the passwords of all the senior officers with access to the ECS.

Chief Commissioner of Income Tax, R K Singh confirmed the report, stating, “The matter has been transferred to Central Bureau of Investigation (CBI).”

According to I-T sources, the incident came to light last week when an additional commissioner level officer discovered unauthorised remittance made from his section. The officer informed his seniors about it and investigations revealed the ECS had been hacked into.

“It seems that more than Rs 15 crore has been siphoned off from the ECS. Investigations are on to ascertain the total amount,” an officer from the I-T Department said requesting anonymity.

ECS system of the I-T was launched recently to clear the refunds of taxpayers in bulk and cut down the tedious paperwork. Sources said that the department has cleared the refunds of one lakh more assesses in a short span of a month through ECS.

“The remittance was made by computers. Now, to check the source and officer who has cleared the refunds, one has to manually go through the entire process which will take a really long time,” said an assessing officer from the I-T department.

In a parallel inquiry, the investigation wing of the I-T is also on a trail of bogus PAN cardholders. Sources said a businessman from suburban Mumbai had filed an income tax return with the help of bogus PAN card. The I-T official got suspicious and found that the card was made in the name of two boys. I-T officials interrogated the boys who revealed that they never applied for any PAN card.

Further inquiries revealed that their father’s employers had managed the fake PAN cards in the name of boys. The I-T officials then approached the local police, but police refused to register the offence. Inquiries are still on in the matter.

I-T payment system has been shut down since Monday following the incident

Sunday, January 17, 2010

China tried to hack India's computers: NSA

Chinese hackers have tried to penetrate computers in the offices of National Security Adviser M K Narayanan, a British paper on Monday quoted him as saying.

Narayanan said his office and other Government departments were targeted on December 15, the same date that US defence, finance and technology companies, including Google, reported cyber attacks from China.

"This was not the first instance of an attempt to hack into our computers," Narayanan told The Times in an interview, adding the would-be hackers sent an e-mail with a PDF attachment containing a Trojan virus.

The virus, which allows hackers to download or delete files, was detected and officials were told not to log on until it was eliminated, Narayanan said.

"People seem to be fairly sure it was the Chinese. It is difficult to find the exact source but this is the main suspicion. It seems well founded," he told The Times, adding that India was cooperating with the US and Britain to bolster its cyber defences.

The Chinese government has denied any role in the attacks, with a foreign ministry spokeswoman saying: "Hacking in whatever form is prohibited by law in China."

Narayanan said that while he expected China to be an increasingly high security priority for India, the main threat still came from militants based in Pakistan.

He said Islamabad had done nothing to dismantle militant groups since the 26/11 Mumbai attacks, and criticised Britain for accepting its excuse that such groups were beyond its control.

"The British are still blinkered on this. We believe Pakistan's policy of using terror as a policy weapon remains," Narayanan said, adding India is anxious to prevent an attack from Pakistan during the Commonwealth Games in October.

"From Pakistan's point of view, it's important to disrupt the Games so you can claim that India is not a safe place," Narayanan said

Wednesday, January 13, 2010

Google threatens to leave China

Google has threatened to close its operations and offices in China after hacking of email accounts of many human rights activists.

In a statement on its blog on Tuesday, the world's second biggest corporate said it has detected in December "a highly sophisticated and targeted attack on our corporate infrastructure originating from China that resulted in the theft of intellectual property from Google.''

The main goal of the attackers was access the Gmail accounts of Chinese human rights activists, the statement said. But they didn't succeed as "only two Gmail accounts appear to have been accessed, and that activity was limited to account information (such as the date the account was created) and subject line, rather than the content of emails themselves,'' Google said.

But independent of this attack, Google said it has "discovered that the accounts of dozens of US, China and Europe based Gmail users who are advocates of human rights in China appear to have been routinely accessed by third parties.

"These accounts have not been accessed through any security breach at Google, but most likely via phishing scams or malware placed on the users' computers.''

The Mountain View-based company said it has made "infrastructure and architectural improvements that enhance security for Google'' and urged users to deploy anti-virus and anti-spy ware programmes. These attacks, Google said, have forced it to "review the feasibility of our business operations in China.''

The company, which had agreed to censor of Google.cn at its launch in 2006, said it was "no longer willing to continue censoring our results on Google.cn.''

Google said it will soon hold discussions the Chinese soon whether it can operate an unfiltered search engine. "We recognize that this may well mean having to shut down Google.cn, and potentially our offices in China,'' the blog warned.

Monday, August 10, 2009

Was Google Earth Search Engine Hacked? Google says it's a 'mistake'!

Search engine Google has admitted its "mistake" of wrong depiction of certain areas of Arunachal Pradesh (Part of India) as parts of China and said its maps would be rectified shortly.

"Earlier, this week, as part of routine update to Google Earth, we published new data for the Arunachal Pradesh region that changed the depiction of certain place names in the product. The change was a result of a mistake in our processing of new map data," a spokesperson for the search giant said in a statement.

The spokesperson was reacting after a media report which highlighted that Google maps showed certain areas of Arunachal Pradesh (south sharing border with Assam and North sharing border with China) outlined with a dotted line while its borders with Bhutan and Burma are shown in a continuous line. The media report had raised suspicion about the search engine being hacked by Chinese considering that Beijing has been laying claim over entire Arunachal Pradesh, which India rejects.

Monday, January 5, 2009

Orkut is barned. Muhahaha!! Here is the solution!

Are you not able to use Orkut from your home computer??

"Orkut is banned you fool, The administrators didnt write this program
guess who did?? MUHAHAHA!!"

Are you not able to use Firefox on your computer??

Here is the solution!

If you find those messages when you try to brows; chances are your computer is affected with a virus called w32.USB worm...

w32.USB Worm

It is spreading through Pen,USB,Thump disk thats why the name

It shows messages like

"I DNT HATE MOZILLA BUT USE IE OR ELSE..."

"USE INTERNET EXPLORER U DOPE"

"Orkut is banned you fool, The administrators didnt write this program
guess who did?? MUHAHAHA!!" with title ORKUT IS BANNED

hi if u c any of the following msgs while u r working on your pc

you are possibly infected with a worm "w32.usb worm"

solution:
*********

1. Press CTRL+ALT+DEL and go to the processes tab

2. Look for "svchost.exe" under the image name. There will be many but
look for the ones which have your username under the username
[username : it is ur login name or default user name which you might have
provided. if you are still not sure open start button. the one that
appears on the top is your "username"]

3. Press DEL to kill these files. It will give you a warning, Press Yes

4. Repeat for more svchost.exe files with your username and repeat. Do
not kill svchost.exe with system, local service or network service!

5. Now open run command start>run> and type "command" without quotes

now you will see the command prompt.
x:\docume~1\
where x [mostly c] is your main drive and is the login name.
now in the command prompt type as follows

c:\docume~1\ cd\
[this will send u to the root directory i.e. C: in this case]

now

c:\attrib heap41a -s -h
[will remove the system and hidden attributes of the folder "heap41a"
which is the main worm planted folder for autorun]

c:\rem heap41a
this will remove the heap41a folder from ur system.
if it is not allowed try logoff n login again n go to the command
promt again n C:\rem heap41a
now it must b removed

now the final part
open run command type "regedit"
search for "heap41a" without quotes [use f3 function key for searching]
and delete them

now you are free to open orkut.

finally also check one more thg.
i.e. open my computer>tools> folder options>view tab>
check vit the hidden folders n files
check if unhide is working
if it is not working then possibly u might have been infected vit
"Ravmon.exe"

try installing some anti spyware software like "adaware" and scan your pc
for removal.

thats it.

Don't forget to update your anti virus regularly.....

Search The Fire Seal

Random Post: I'm feeling lucky!!!