Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Thursday, August 15, 2013

Thousands of Israeli websites hacked by Pakistani hackers for Palestine supports



A cyber attack campaign  is ongoing and targeting thousands of Israeli websites by Pakistani hackers, in support of Palestine people.

They had already infiltrated reportedly 650 Israel websites listen on Pastebin and upload their page with custom messages on servers. The hacker claimed and told 'The Hacker News' that they will release more hacked websites list soon.

The hacker behind the massive attack mentioned his online name as "H4x0r HuSsY" and the message says, "LONG LIVE PALESTINE - PAKISTAN ZINDABAD HAPPY INDEPENDENCE DAY TO & FROM TEAM MADLEETS".

Hacked websites belong to Semi-Government, Personal and Israeli Corporates. At the time of writing, most of the websites still having deface page uploaded to their server.

A few months back World wide Hackers and especially Anonymous group declared massive 'cyber war' on Israel after IDF threatens to cut off internet in Gaza.

Source : thehackrnews

Sunday, December 11, 2011

Hackers exploit zero day vulnerability in Adobe Reader and Acrobat


adobe, acrobat, reader, adobe reader, hacking, exploit, zero day, vulnerability
The company issued a critical security advisoryand confirmed the flaw affects multiple operating systems and various versions of its software, though using the latest release in Protected Mode or Protective View reportedly prevents the vulnerability from being exploited.

"This vulnerability (CVE-2011-2462) could cause a crash and potentially allow an attacker to take control of the affected system," Adobe said in its security advisory. The affected software and operating systems are:

• Reader X 10.1.1 and earlier 10.x versions for Windows and Apple OS X
• Reader 9.4.6 and earlier 9.x versions for Windows, Apple OS X and Unix
• Acrobat X 10.1.1 and earlier 10.x versions for Windows and Apple OS X
• Acrobat 9.4.6 and earlier 9.x versions for Windows and Apple OS X

Adobe was also keen to point out its Reader for Android and Adobe Flash player are not affected.  The firm plans to update Windows versions of its 9.x software by no later than the week ending December 12. All other affected versions will receive a patch by January 10, 2012. 

Those using Adobe's Reader X and Acrobat X versions are advised to either avoid opening unknown files or use protected mode or protected to access them if necessary until the patch is available in the New Year.

The company was recently in the news at the beginning of November after revealing its shock decision to terminate further development of Flash for mobile browsers. Instead, it will focus solely on HTML5 and other web technologies.

Tuesday, November 29, 2011

FBI arrests four hackers hired to infiltrate AT T


fbi, att, hacking, security, terrorism, philippines, al qaeda, cidg, atccd, muhammad zamir, paul michael kwan
Earlier this week, AT&T claimed to be investigating an intrusion attempt on its system. However, the company said it did not believe any accounts were compromised. Reports are now surfacing that AT&T has been working with the FBI and Philippine law enforcement to apprehend attackers, although a link between the two events has not been confirmed.
The Philippine's Criminal Investigation and Detection Group (CIDG) stated, "The hacking activity resulted in almost $2 million in losses incurred by the company", referring to AT&T's involvement as a target of the attack.
However, AT&T spokeswoman, Jan Rasmussen, denied any breach of security by claiming, "AT&T and its network were neither targeted nor breached by the hackers. AT&T only assisted law enforcement in the investigation that led to the arrest of a group of hackers." 
This seems to directly contradict the earlier statement by the CIDG and another statement by AT&T saying the company, "ended up writing off some fraudulent charges that appeared on customer bills". As a result, it is impossible to determine to what extent AT&T's network was hacked, if at all.
Earlier this year, the FBI discovered a Saudi group had funded hackers to target AT&T. The FBI enlisted the help of CIDG's International cyber-crime division (ATCCD) as early as March 2011. The group was suspected of having ties to other terrorist organizations, although details were never officially disclosed.
The four men arrested were Filipino and funded by a group formerly headed by Muhammad Zamir, a South East Asian militant. Zamir has a colorful history with financial ties to al Qaeda and funding the terrorist bombing of Mumbai, India, on November 26, 2008. One of the men detained was identified as Paul Michael Kwan, a suspect previously convicted of illegal militant activity in 2007.
The CIDG said suspects hacked PBX lines from various telecommunications companies to steal money and divert it into the bank accounts of terrorists. The hackers were to be paid commission, based upon how much money they could funnel to accounts.

Friday, November 25, 2011

FBI says hackers not responsible for Illinois water pump failure


fbi, department of homeland security, water pump, feds, scada, supervisory control and data acquisition system, illinois
The Federal Bureau of Investigation and the Department of Homeland Security are nowsaying that a water pump failure at a Springfield, Illinois water utility plant was not destroyed by hackers. This contradicts an earlier report on November 10 from the Illinois fusion center that claimed someone had hacked into the Supervisory  Control and Data Acquisition System (SCADA) and repeatedly turned a water pump on and off, resulting in the burnout of said pump.

To gain access, the attacker(s) obtained multiple usernames and passwords from SCADA that were used to access the water facility. The detailed report, which shows the IP addresses were traced to Russia, suggested that the hacker(s) could have had access to the system for a few months prior to the attack.

But now, the FBI and DHS say they have found no evidence of a cyber intrusion into the SCADA system at the Curran-Gardner Public Water District. In fact, they further elaborate and say there was no evidence to support the claim in the initial report. The raw and unconfirmed data was leaked to the media and should have never been made public.

Joe Weiss, a control system expert and the person that first reported the data from the fusion report, believes something doesn’t quite add up.

“This smells to high holy heaven, because when you look at the Illinois report, nowhere was the word preliminary ever used,” Weiss said. “It was just laying out facts. How do the facts all of a sudden all fall apart? There’s a lot of black and white stuff in that report. Either there is or there isn’t a Russian IP address in there. It’s hard to miss that. This stuff about the vendor being hacked… How can two government agencies be so at odds at what’s going on here? Did the fusion center screw up, or is the fusion center being thrown under the bus?”
As of writing, the investigation is ongoing and additional relevant information will be released at it becomes available. No other explanation has been provided thus far.

Thursday, November 24, 2011

AT T targeted by hackers, no accounts breached


mobile, att, hacking, security breach
AT&T notified some of its customers yesterday that it had detected attempts to hack into their servers and obtain customer account information, although America's second biggest mobile carrier was quick to point out that no accounts were breached.

"We recently detected what could have been an organized attempt to obtain information on a number of customer accounts," AT&T spokesman Mark Siegel said in a statement to Cnet. "The people in question appear to have used autoscript technology to determine whether AT&T telephone numbers were linked to online AT&T accounts."

The company stated it has sent an email to those affected, but pointed out at the same time that less than one percent of the company's users were at risk. While one percent might sound a small figure that equates to potentially one million affected users going by its reported 100.7-million wireless subscribers at the end of the third quarter.

"Our investigation is ongoing to determine the source or intent of the attempt to gather this information," Siegel said. "In the meantime, out of an abundance of caution, we are advising the account holders involved."

Those that were contacted have been advised to be very cautious of any emails or text messages they may get because there "may be an increased risk of fraudulent attempts to access" account information. It is vital all subscribers remain vigilant in either case though, as it is uncommon for any service provider to request personal or financial information via those methods.

AT&T remained tight lipped about the finer details of the incident, but it's likely the hackers were aiming to gain access to customer information to use to steal credit card information from those affected in future phishing attacks. Had they gained access to customer account numbers, personal information and the phone numbers of subscribers, it could have been easier to trick users into believing they were AT&T.

This incident closely follows the intrusion at a Illinois-based water utility last week where hackers gained access to the pumps control system, operating a pump by turning it on and off until it burnt out.

Tuesday, November 15, 2011

Hackers reverse-engineer Siri to work with any device



apple, hacking, siri, reverse-engineer
Hackers have supposedly managed to reverse-engineer the exclusive Apple Siri personal assistant feature that debuted in last month's iPhone 4S release. They claim the feat enables them to make the service work with virtually any device, including the competition's Android handsets.
"Today, we managed to crack open Siri’s protocol. As a result, we are able to use Siri’s recognition engine from any device. Yes, that means anyone could now write an Android app that uses the real Siri! Or use Siri on an iPad! And we’re going to share this know-how with you," Applidiumcommented in a blog post about their newly discovered hack.
The team discovered that the service requires a HTTPS connection and identified the Siri server as guzzoni.apple.com. It also required a valid certificate but they found, surprisingly, that a self-signed certificate could be used in place of the valid Apple supplied certificate. “Seems like someone at Apple missed something!”, the researchers wrote.
Security protocols aside, the service works by compressing and then sending the audio to the server. The server then uses a variety of methods to validate the device is trusted, including an identifier unique to each iPhone 4S. Once this stage is complete the servers then send the processed data to the handset.
As evidence of the hack, the folks at Applidium provided a recording of them trying out Siri’s speech-to-text feature (in French) and a text file with the decoded request. The sound sample never went through any iPhone, but nonetheless they were able to get Siri to analyze it.
For developers and those generally curious it offers a good insight into how the service works, and more crucially, how it communicates with Apple's servers. Applidium also released the tools that helped them gain access, which will no doubt prove useful to developers wanting to integrate apps functions into Siri.
However, while they did crack Siri they also realized that each iPhone 4S features a unique identifier used when connecting to the Cupertino-based servers that provide the service. So in order to hack it  you would need to first purchase an iPhone4S, or at least have a willing friend hand out there unique identifier. There is yet another catch, though: Apple has stated they can blacklist any phone from the Siri service if it is flagged for excessive traffic, so finding a willing participant might end up rather fruitless.
Apple has a very proactive, somewhat aggressive approach when it comes to security and exploits so it is uncertain how long this exploit will remain valid. Less than a week ago a developer was booted from Apple's developer program for demonstrating an exploit in the App Store.

Saturday, October 29, 2011

Hackers port trojan from Linux to work on Mac OS X


Researchers at security firms ESET and Sophos have discovered that hackers have ported an old Linux backdoor Trojan to work on Apple's Mac OS X platform in an effort to expand the reach of their botnets. The new Trojan, named Tsunami, is derived from the old Linux Trojan Kaiten, which worked in an almost identical manner. Early speculation suggests it is a denial-of-service (DDoS) tool, although security firms are still investigating.

"As you can see by the portion of OSX/Tsunami's source code that I have reproduced below, the bash script can be given a variety of different instructions and can be used to remotely access an affected computer," said Graham Cluley in a post at the security firm's website.
Once it is running on the host machine, it connects to an IRC channel and awaits further commands from the hackers. They can then use the combined connections of the all the computers in the botnet to flood servers with requests, bringing them down in DDoS attacks. Hackers are able to download files to the infected computer for it to update itself or install additional malware, and gives complete control of the host machine to execute any command they choose.
"Mac users are reminded that even though there is far less malware in existence for Mac OS X than for Windows, that doesn't mean the problem is non-existent," said Cluley of Sophos. He also reminded users of OS X that participating in a DDoS attack is illegal, whether it is intentional or not, and you certainly would not want anyone having remote control of your computer.

Monday, August 1, 2011

Sony may offer reward to help catch hackers

sony logo 11 Sony may offer reward to help catch hackers

With an attack that has compromised as much as 100 million users accounts on the PlayStation Network Sony may be looking for more help. According to Cnet, Sony may be looking into offering a reward to someone who can provide more information on who the attackers are. The information of’course must also lead to the arrest and conviction of who is involved in the attacks.

Also according to the Financial Times, the group Anonymous may have actually been involved in some of the attacks against Sony despite their initial denials. The hacker involved with Anonymous was acting against Sony and it’s attack against George Hotz, they said in a statement:

“The hacker that did this was supporting OpSony’s movements,”

And also stated that:

“If you say you are Anonymous, and do something as Anonymous, then Anonymous did it,” “Just because the rest of Anonymous might not agree with it, doesn’t mean Anonymous didn’t do it.”

The rest of the members of Anonymous may not have agreed with the actions that certain members carried out but this attack gets the entire group involved. Anonymous does not plan to release any of the credit card information that was found or make it public in any way. According to Anonymous nothing was downloaded in a statement they made:

“No credit card information was ever exposed, neither was over 100 million accounts,” the Anon said. “They had access to their databases, yes, but nothing was downloaded except a few admin accounts. Nothing has been exposed, no one is selling anything.”

Rumors have also been circulating that a third attack may take place sometime soon but has not been confirmed or proven yet. If Sony does offer a reward for information we will have to see if anyone outs the person or persons that made the attack.