Showing posts with label Hacking News. Show all posts

Ultra-secure Blackphone Vulnerability lets Hackers Decrypt Texts

The makers of ultra secure BlackPhone titled by Silent Circle as, "world’s first Smartphone which places privacy and control directly in the hands of its users," have recently fixed a critical vulnerability in the instant messaging application that allows hackers to run malicious code on the handsets.


BlackPhone was also hacked last year at the BlackHat security conference, but the interesting factor about the recent hack was that the attackers only needed to send just a message on a targeted phone number in order to compromise the device.


The vulnerability was first discovered and disclosed by Mark Dowd, a principal security researcher at the Australia-based consultancy firm Azimuth Security. Dowd discovered the issue late in 2014, but waited to disclose it until Blackphone got their patches and fixes in place.


The flaw actually resides in Silent Text application — the secure text messaging application bundled with the BlackPhone handsets, which is also freely available as Android App on Google Play Store.

View Source

17-Year-Old Found Bugs in WhatsApp Web and Mobile App Thursday, January29, 2015 Swati Khandelwal

Last week, the most popular mobile messaging application WhatsApp finally arrived on the web — dubbedWhatsApp Web, but unfortunately it needs some improvements in its web version.


An independent 17-year-old security researcher Indrajeet Bhuyan reported two security holes in the WhatsApp web client that in some way exposes its users’ privacy. Bhuyan called the first hole, WhatsApp photo privacy bug and the other WhatsApp Web Photo Sync Bug.


Bhuyan is the same security researcher who reported us the vulnerability in the widely popular mobile messaging app which allowed anyone to remotely crash WhatsApp by sending a specially crafted message of just 2kb in size, resulting in the loss of conversations.


Whatsapp Photo Privacy Bug

According to him, the new version of WhatsApp Web allows us to view a user’s profile image even if we are not on the contact list of that user. Even if the user has set the profile image privacy setting to "Contacts Only," the profile picture can be viewed by out of contacts people as well.






Basically, if we set the profile image privacy to Contacts Only, only the people in our contact list are able to view our profile picture, and nobody else. But, this is not in the case of WhatsApp Web.


WhatsApp Web Photo Sync Bug

The second security hole points out the WhatsApp Web Photo Syncing functionality. Bhuyan noticed that whenever a user deletes a photo that was sent via the mobile version of WhatsApp application, the photo appears blurred and can’t be viewed.


However, the same photo, which has already been deleted by the user from mobile WhatsApp version, can be accessible by Whatsapp Web as the photo does not get deleted from its web client, revealing the fact that mobile and web clients of the service are not synced properly.


This is no surprise, as WhatsApp Web introduced just a couple of days before and these small security and implementation flaws could be expected at this time, as well as some other bugs could also be revealed in the near future.


However, the company will surely fix the issues and will definitely make its users’ messaging experience secure. As partnered with Open Whisper Systems, WhatsApp recently made end-to-end encryption a default feature on Android platform, stepping a way forward for the online privacy of its users around the world.



View Source

This List Of 2014’s Worst Passwords, Including ‘123456,’ Is Embarrassing

passwordsThe year of 2014, in many respects, was all about digital security. It wasn’t just tech pundits or early adopters who were victimized – Snapchat, Target, and Sony Entertainment all showed us that no one is immune. And don’t get me started on theNSA. It’s our responsibility as internet explorers to protect ourselves. But according to SplashData’s yearly list of the worst passwords on the internet (as compiled by more than 3 million leaked passwords from 2014), we are kind of lazy about the whole “digital security” thing. At least when it comes to properly locking the gates with a strong password.
View Original

Google offers security tips for staying safe online

google-securityBe it the ubiquity of hacking or widespread government surveillance, better online security is something that we could all use more of these days.

Google is pushing to educate users on how to stay safe online. The company released a batch of security tips on Thursday. They can help you better protect your identifying information (like passwords, for one) and sensitive files, as well as fend off hackers.

View Original

Website Backdoor Scripts Leverage the Pastebin Service

pastebin-wordpress-website-hackingThe popular copy and paste website 'Pastebin' created a decade ago for software developers and even by hackers groups to share source code, dumps and stolen data, has more recently been leveraged by cyber criminals to target millions of users.


Compromising a website and then hosting malware on it has become an old tactic for hackers, and now they are trying their hands in compromising vast majority of users in a single stroke. Researchers have discovered that hackers are now using Pastebin to spread malicious backdoor code.

View Original

FBI Director says 'Sloppy' Sony Hackers Left Clues that Point to North Korea!

fbi-sony-hacker-north-koreaThe hackers group responsible for the last year’s largest hacking attack on Sony Pictures Entertainment left many clues which proves that the Sony's hackers, who called themselves Guardians of Peace (GOP), linked to North Korea, as claimed by the Federal Bureau of Investigation (FBI).


Speaking at the International Conference on Cyber Security (ICCS) at Fordham University in New York on Wednesday, the director of the FBI defended his bureau's claim and said that the North Korean government was involved in the massive cyber attack against Sony Pictures – saying skeptics "don't have the facts that I have."

View Original

Bitstamp loses $5 million in BTC after security breach, suspends service

WiFiPhisher — Automated Phishing Attacks Against Wi-Fi Networks

Wi-Fi-Hacking-tool-1A Greek security researcher, named George Chatzisofroniou, has developed a WiFi social engineering tool that is designed to steal credentials from users of secure Wi-Fi networks.


The tool, dubbed WiFiPhisher, has been released on the software development website GitHub on Sunday and is freely available for users.

"It's a social engineering attack that does not use brute forcing in contrast to other methods. It's an easy way to get WPA passwords," said George Chatzisofroniou.

Read more at:

http://thehackernews.com/2015/01/wifiphisher-automated-phishing-attacks_5.html

Thunderstrike — Infecting Apple MacBooks with EFI Bootkit via Thunderbolt Ports

Thunderstrike-AttackA security researcher has discovered an easy way to infect Apple’s Macintosh computers with an unusual kind of malware using its own Thunderbolt port.


The hack was presented by programming expert Trammell Hudson at the annual Chaos Computer Congress (30C3) in Hamburg Germany. He demonstrated that it is possible to rewrite the firmware of an Intel Thunderbolt Mac.


The hack, dubbed Thunderstrike, actually takes advantage of a years-old vulnerability in the Thunderbolt Option ROM that was first disclosed in 2012 but is yet to be patched. Thunderstrike can infect the Apple Extensible Firmware Interface (EFI) by allocating a malicious code into the boot ROM of an Apple computer through infected Thunderbolt devices.

Read more at:

http://thehackernews.com/2015/01/thunderstrike-infecting-apple-macbooks.html



Hacker Leaks Xbox One SDK that could let Developers make Homebrew Apps

xbox-sdk-leakJust a week ago on Christmas, the massive Distributed Denial of Service (DDoS) attack from the notorious hacking group Lizard Squad knocked Sony’s PlayStation Network and Microsoft’s Xbox Live offline, but as if it wasn't the end of disaster for Microsoft.


This time it isn't a case of services being taken down — instead, the software development kit (SDK) for the Xbox Live is being freely circulated over the Internet. Another group calling itself H4LT has apparently managed to leak the Microsoft’s official Xbox One developer SDK, potentially opening the door for homemade applications and allowing unapproved developers to create unofficial software for the system.

Read more at:

http://thehackernews.com/2015/01/hacker-leaks-xbox-one-sdk-that-could.html

Bitstamp Bitcoin Exchange Hacked, $5 Million Stolen in Hack Attack

Bitstamp-Bitcoin-Exchange-HackedOne of the biggest, reliable and most trusted Bitcoin exchange — Bitstamp — on Monday announced that it has been a target of a hacking attack, which lead to the theft of "less than 19,000 BTC" (worth about $5 million in virtual currency; one BTC is about $270).


Bitstamp issued a statement on its official website in which the company warned its users not to deposit any Bitcoin to previously issued addresses, so as to prevent further losses. While the investigation is going on, the company has frozen its user accounts, blocked deposits as well as other transactions and suspended the trading business.

Read more at:

http://thehackernews.com/2015/01/bitstamp-bitcoin-exchange-hacked.html



Gogo In-flight Internet issues Fake SSL Certificates to its own Customers

gogo-fake-ssl-certificateGogo — one of the largest providers of in-flight Internet service — has been caught issuing fake SSL certificates, allowing the inflight broadband provider to launch man-in-the-middle (MITM) attacks on its own users, view passwords and other sensitive information.


The news came to light when security engineer Adrienne Porter Felt, who works on Google Chrome’s security team, was served the phony SSL certificate while trying to connect to Google's video service YouTube. She noticed that the SSL certificate was signed by an untrusted issuer and wasn’t issued by Google, but rather by Gogo itself.

Read more at:

http://thehackernews.com/2015/01/gogo-fake-ssl-certificate.html

Hacker Released 'iDict' Tool That Can Hack Your iCloud Account

iDict-icloud-password-hacking-toolHackers have a great start of new year 2015, giving a public threat to Apple’s online iCloud service. A hacker using the handle "Pr0x13" has released a password-hacking tool to GitHub website that assures attackers to break into any iCloud account, potentially giving them free access to victims’ iOS devices.


The tool, dubbed iDict, actually makes use of an exploit in Apple's iCloud security infrastructure to bypass restrictions and two-factor authentication security that prevents brute force attacks and keeps most hackers away from gaining access to users’ iCloud accounts.

http://thehackernews.com/2015/01/iDict-icloud-password-hacking-tool.html

Hackers claiming credit for PlayStation outage let anyone use their DDoS tool

[caption id="attachment_187" align="alignright" width="355"]IMAGE: FLICKR, NORLANDO POBR IMAGE: FLICKR, NORLANDO POBR[/caption]

Lizard Squad, the group who claimed credit for taking down Sony's PlayStation Network and Microsoft's Xbox Live systems on Christmas, plans to turns its misdeeds into profits.

The group released a commercial variant of its DDoS (distributed denial of service) tool, which they say lets anyone take down networks — at a price. It was this tool that Lizard Squad says was responsible for the outages on PlayStation and Xbox Live.

Read more at:

http://mashable.com/2014/12/31/lizard-squad-ddos/

Fake Android 'The Interview' app steals bank account details

[caption id="attachment_142" align="alignright" width="300"]IMAGE: GRAHAM CLULEY IMAGE: GRAHAM CLULEY[/caption]

The Interview, a highly controversial movie that was pulled from major cinemas and distributed mostly online (and only in the U.S.), sounds like a dream come true for scammers.

It is no wonder, then, that a fake Android app has been making the rounds in South Korea, promising to download a copy of the movie but actually stealing users' bank account details instead.

Read more at:

http://mashable.com/2014/12/31/interview-android-app/

2014 was the year hacking became the norm

[caption id="attachment_122" align="alignright" width="300"]hacking bombs IMAGE: GETTY IMAGES[/caption]

Information security — or the lack thereof — was one of the biggest stories of 2014. From Heartbleed to Kmart to JPMorgan to Snapchat to iCloud to Sony Pictures to countless others, data breaches and software vulnerabilities made news nearly every single week.
Even without the North Korean government, the Sony story would be a big deal, but with it? Massive.

Read more at:

http://mashable.com/2014/12/30/infosec-2014-hacking/

The Pirate Bay crew reportedly 'couldn't care less' about weeklong outage

[caption id="attachment_116" align="alignright" width="300"]The-Pirate-Bay IMAGE: FLICKR, METHODSHOP.COM[/caption]

The crew currently running the BitTorrent search site The Pirate Bay apparently doesn't care about the recent police raid on the site's servers.

“We were not that surprised by the raid. That is something that is a part of this game. We couldn’t care less really,” said a person associated with the site, according to TorrentFreak. The person was known only as "Mr 10100100000."

Read more at:

http://mashable.com/2014/12/16/pirate-bay-crew-raid/

PlayStation Network and Xbox Live still have outages as hackers claim credit

[caption id="attachment_113" align="alignright" width="300"]sony-playstation IMAGE: FLICKR, JOEY[/caption]

After failing on Christmas, Sony's PlayStation Network and Microsoft's Xbox Live are still experiencing problems that are preventing many users from signing on to the services, just as gamers are hoping to try out their new gifts. At least one hacker group is taking credit for bringing down the services, though there's been no confirmation as to whether the problems are due to an outside attack or a simple Christmas overload.

Read more at:

http://mashable.com/2014/12/26/playstation-network-xbox-live-down/

Hacker Clones German Defense Minister's Fingerprint Using Just her Photos

Hackers have already bypassedclone-fingerprint-scanner

Apple's fingerprint scanner using fake fingerprints, and now they have found a way to reproduce your fingerprints by using just a couple of photos of your fingers.


Special Fingerprint sensors have already been used by Apple and Samsung in their smartphones for authentication purposes and in near future fingerprints sensors are believed to be the part of plenty of other locked devices that can be unlocked using fingerprints, just to add an extra layer of authentication. But, How secure are your fingerprints?

Read more at:

http://thehackernews.com/2014/12/hacker-clone-fingerprint-scanner.html

Hackers claim they can copy fingerprints from photos

3595771919_a3b77eb2c2_bAccording to the Chaos Computer Club — the same Berlin-based group that claimed it cracked Apple's Touch ID fingerprint sensor last year — it's possible to replicate a thumbprint using only photos and commercially available software. Theoretically, identity thieves could break into iPhones or other biometrically protected technology using the method.
After this talk, politicians will presumably wear gloves when talking in public,

Read more at:

http://mashable.com/2014/12/29/fingerprint-photo-copy/