Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

FIFA President Blatter's Twitter account hacked


FIFA President Sepp Blatter's Twitter account was hacked on Monday with a series of bizarre tweets saying he was stepping down and was involved in corruption.

A statement from FIFA confirmed the account had been hacked, saying: "Some FIFA accounts, incl. @SeppBlatter and @fifaworldcup, have been hacked. If in doubt, please verify any info with FIFA office."

The bogus messages on Blatter's account included a retweet from FIFA World Cup saying: "It was decided that the president Sepp Blatter is to step down due to corruption charges.

Blatter's Twitter account has been vandalised (image credit: Wikimedia Commons)

Another tweet on Blatter's page said: "So what if I took money from Qatari prince? I am the family's bread earner," before declaring himself unrepentant.

"His excellency the Emir of Qatar has been the most generous figure I have ever met," and "I do not apologize for my decision. I have done the best for Fifa. For almost 15 years I have toiled for this organization."

The official World Cup Twitter account also fell victim to the hackers with several fake messages, including: "Sepp Blatter has been investigated for multiple charges of bribery."

A group calling themselves the Syrian Electronic Army, supportive of the country's leader, Bashar Al-Assad, claimed responsibility for hacking the accounts, tweeting: "Syrian Electronic Army Was Here" and "Twitter #Failure... You can't stop us!"

Blatter, 77, has been president of FIFA since 1998 and has not yet announced whether he will be standing for a fifth term when his current mandate ends in 2015.

Report by : Reuters

Hack Your iPhone With These 3 Tricks


Have you ever needed to charge your phone in a hurry before heading out the door? Or do you want to discover the little-known tricks you can pull to personalize and further protect your device?

Our smartphones are incredibly complex little machines, and though we know them intimately, there's probably something you haven't discovered yet. There's always something you can do to make your phone feel more complete — more yours.

As always, HackCollege can help you out, with the first installment in its new series: Hack Tricks. Here, you'll find three more ways to get the most out of your mobile phone.

Got any tricks up your sleeve? Share them in the comments section.

Report by : Bob Al-Greene

British hacker Kayla admits to attacks on Sony, Murdoch, Nintendo


A British computer hacker pleaded guilty on Tuesday to cyber attacks on targets including Sony, Nintendo, Rupert Murdoch's News International and the Arizona State Police.

Ryan Ackroyd's plea meant his planned jury trial did not go ahead and, as a result, the court did not hear any evidence on the motivation behind the attacks he made using the persona of a 16-year-old girl named Kayla as part of hacking group LulzSec.

Dressed in a tracksuit bottom and t-shirt, with a large tattoo on his arm and crew-cut hair, Ackroyd spoke only to identify himself and to enter his plea. Ackroyd, 26, was arrested in 2011 with three other British young men in connection with an international cyber crime spree by LulzSec, a splinter group of hacking collective Anonymous.

Cracking down on hacking

The other three had already pleaded guilty to several charges including cyber attacks on the CIA and Britain's Serious Organised Crime Agency (SOCA).

Anonymous, and LulzSec in particular, made international headlines in late 2010 when they launched what they called the "first cyber war" in retaliation for attempts to shut down the WikiLeaks website.

Ackroyd faced four charges but pleaded guilty to just one. Prosecutors said they would not pursue the other charges. Ackroyd and his three fellow hackers will be sentenced on May 14, judge Deborah Taylor said.

Mustafa Al-Bassam, 18, and Jake Davis, 20, had both pleaded guilty to two counts while Ryan Cleary, 21, had pleaded guilty to six counts including that he attacked Pentagon computers operated by the U.S. Air Force.

Cleary, Al-Bassam and Davis admitted to launching so-called distributed denial of service (DDoS) attacks in which websites are flooded with traffic to make them crash.

Ackroyd denied taking part in DDoS attacks but admitted, as did the three others, to hacking into computer systems, obtaining confidential data and redirecting legitimate website visitors to sites hosted by the hackers.

The targets listed in the charge to which Ackroyd pleaded guilty also included Britain's National Health Service, the U.S. public broadcaster PBS and 20th Century Fox.

The defendants are free on bail pending their sentencing, under the condition that they do not access the Internet.

Cleary was indicted by a federal grand jury in Los Angeles last June but U.S. authorities have indicated they would not seek his extradition as he was being prosecuted in Britain on the same charges.

Report by : Reuters

Vulnerability Gives Hackers Access to Locked iPhones



Think your iPhone 5 is safe and secure with your password lock set up nicely? A new vulnerability has been discovered which could allow hackers to bypass password locks and gain access to users' personal information.

First detected by Vulnerability Lab in a Full Disclosure report and further detailed on Kaspersky Labs' Threatpost blog, hackers can get around the iPhone's lock screen by using the Emergency Call function. The workaround gives the user access to contact lists, voicemails and photos.

"The exploit involves manipulating the phone’s screenshot function, its emergency call function and its power button," Threatpost.com writes. "Users can make an emergency call (911 for example) on the phone and then cancel it while toggling the power on and off to get temporary access to the phone."

From there, a hacker can attach a USB cord to the smartphone and access data on the phone via a computer. The exploit works on iPhone 5 devices running iOS 6.1 software.

"The vulnerability allows the local attacker to bypass the code lock in iTunes and via USB when a black screen bug occurs," the Full Disclosure report notes. "Successful exploitation of the vulnerability results in unauthorized device access and information disclosure."

Apple has not yet responded to a request for comment.

For a deeper look at how the exploit works, check out the video below. The first part of the video demonstrates a vulnerability detected earlier this month.

Report by : Samantha Murphy

Hackers target European governments via Adobe bug


Hackers targeted dozens of computer systems at government agencies across Europe in a series of attacks that exploited a recently discovered security flaw in Adobe Systems Inc's software, security researchers reported on Wednesday.

Russia's Kaspersky Lab and Hungary's Laboratory of Cryptography and System Security, or CrySyS, said the targets of the campaign included government computers in the Czech Republic, Ireland, Portugal and Romania.

Dozens of European government agnecies were targetted by hackers (Image credit: Getty Images)
They also said that a think tank, research institute and healthcare provider in the United States were among those targeted by the malicious software, which they have dubbed 'MiniDuke'. The MiniDuke hackers attacked their victims by exploiting recently discovered security bugs in Adobe's Reader and Acrobat software. They sent their targets PDF documents tainted with malware, an approach that hackers commonly use to infect PCs.

The two research groups declined to elaborate on the identity of the victims, but said they have reported the case to relevant authorities.

Boldizsár Bencsáth, a cyber security expert who runs the malware research team at CrySyS, told Reuters he believed the attackers installed "back doors" at dozens of victim organizations that would enable them to view information on those systems, then siphon off data they found interesting.

He said researchers have yet to uncover evidence that the operation had moved on to a second stage, where the operators had begun to exfiltrate data from their victims.

"This is a unique, fresh and very different type of attack," said Kurt Baumgartner, a senior security researcher with Kaspersky Lab. "The technical indicators show this is a new type of threat actor that hasn't been reported on before."

He said he would not speculate on who that actor -- the hackers -- might be. Bencsáth, however, said he believed a nation state was behind the attack because of the level of sophistication and the identity of the targets, adding that it was difficult to identify which country was involved.

The MiniDuke hackers exploited security bugs in Reader and Acrobat software that were first identified two weeks ago by Silicon Valley security firm FireEye. The firm reported that hackers were infecting machines by circulating PDFs tainted with malicious software.

Adobe last week released an update that fixes the security bugs in Reader and Acrobat. Bencsáth said that the hackers discovered by FireEye had used tainted PDFs that appeared to be applications for visas to enter Turkey.

The MiniDuke hackers also employed several seemingly innocuous documents, including research papers on Ukraine's foreign policy and one on a human rights seminar.

Report by : Reuters
<h1>Hacker finds second Chrome bug, wins $60,000 prize </h1>

Google hosted its Pwnium 2 competition at Hack in the Box 2012 in Kuala Lumpur yesterday. The winner, Pinkie Pie, went home with a $60,000 prize and a free Chromebook. Pie, incidentally had also won $60,000 in the first Pwnium competition held earlier this year. The bug that Pie had discovered relies on a WebKit Scalable Vector Graphics (SVG) compromise to exploit the renderer process. This time, he found a bug in the IPC layer to escape the Chrome sandbox.

In an official blog post on the Chromium blog, Software Engineer, Chris Evans shares that Pie took home the prize since this exploit fell within the parameters of a "“full Chrome exploit,” - thereby deserving the prize comprising - $60,000 and a free Chromebook. A “full Chrome exploit”, as Evans explains in the post “depends entirely on bugs within Chrome to achieve code execution.”

The fresh patch is now available

Google started working on fixing the bug as soon as it was submitted. In fact, Evans shares that in less than 10 hours after Pwnium 2 concluded, they were already updating users with a freshly patched version of Chrome.

“One of Chrome’s most effective security defenses is our fast response time and ability to update users with critical patches, quickly. These bugs were no exception,” he wrote.

He writes further, “We’d like to thank Pinkie Pie for his hard work in assembling another great Pwnium submission. We’ll post an in-depth look at the bugs used and subsequent mitigations once other platforms have been patched.”

Recently, Google rolled out the first post-beta update for its Chrome browser for the Android platform. The update addressed various security issues and brings improvements for Chrome’s sandboxing technology, besides fixing other moderate bugs. The update was for devices running Android v4.0 (Ice Cream Sandwich) and later. Chrome is available only for devices running Android v4.0 or later.

Chrome’s sandbox technology helps ensure malicious mobile websites are contained and do not impact the entire browser. A post on the Google Chrome blog by software engineer Jay Civelli states that this is made possible by “the innovative multi-process architecture in Chrome for Android, in conjunction with Android’s User ID (UID) isolation technology”. He adds that Jelly Bean devices would automatically use this more in-depth sandboxing technology.

In March this year, a group French hackers at the Pwn2own competition in Canada, the co-founder and head of research of Vupen, Chaouki Bekrar, and his team managed to break into Google Chrome in less than 5 minutes, in the process quashing talks about the browser's unquestionable security. They used "a pair of zero-day vulnerabilities to take complete control of a fully patched 64-bit Windows 7 (SP1) machine". For the successful break-in, Vupen has won itself 32 points.


Report by: tech2 News Staff

To Keep Passwords Safe from Hackers, Just Break Them into Bits

Millions of passwords have been stolen from companies such as LinkedIn and Yahoo. A new approach aims to prevent future heists.

A new way for websites and other online services to store passwords could prevent breaches like the one that resulted in 6.5 million LinkedIn users having their passwords posted online earlier this year.
That kind of data dump happens when an attacker gains access to the server storing user passwords. Researchers at computer security company RSA have created a system that splits passwords in two and stores each half in different locations. The two halves never come together, even when a person logs in and has his password verified. That should make it harder for someone to steal them, because a thief would need to break into both those servers, which can be protected in different ways.

"Password storage is increasingly problematic because of the increasing frequency of breaches but also because the consequences of them have increased," says Ari Juels, who heads RSA's research labs in Cambridge, Massachusetts. Juels says losing control of one online account can provide attackers with information to help break into others, and many people simply reuse passwords on multiple accounts anyway.

Although LinkedIn and many other companies encrypt passwords—so their servers don't contain the exact string that a user types—attackers have a range of tools that can reverse this encryption, says Juels. Even the very best practices, which LinkedIn didn't use, can be broken.

"Our view is that it's better for passwords and other credentials not to be stored in one place," Juels says, making it more difficult for an attacker to get hold of everything he needs to re-create a person's password.

RSA's new scheme works by breaking a password into many small pieces and storing half of those pieces—selected at random—in one place, and the rest in another. RSA calls the approach distributed credential protection. "If one location is attacked, the passwords are still safe," says Juels. "Where the magic comes in is the ability of the system to check passwords without reassembling them."

When a person logs into a system using distributed credential protection, the password he or she provides is split into two encrypted strings of data. Each string is then sent to one of the two password servers, where it is combined with the half of the password stored on that server to create a new string. The two servers then compare these two new strings to determine whether the password is correct or not. The mathematics involved means that it is impossible to determine the password from either of these strings, or both of them combined—so the password remains unknown even if an attacker can capture the strings.

The two servers involved can be set up with different operating systems and in different locations, says Juels, so stealing passwords requires mounting two separate attacks successfully. These would have to happen in short order, too, because the system periodically refreshes which random half of the snippets of a password are stored on each server.

The software will go on sale later this year, says Juels.

RSA's new approach is a version of a technique known as threshold cryptography, which has long been explored by researchers. "The concept is not new, but this would be the first time that it is deployed to the general public," says Dan Boneh, a professor at Stanford University who has researched such designs. Threshold cryptography is used behind the scenes by the companies, known as certificate authorities, that issue the digital security certificates that help computers and Web browsers know which servers to trust—for example, when logging onto a banking website.

One way to boost the effectiveness of the approach would be to split passwords or secrets across more than just two servers, says Boneh. Juels says RSA plans to make that possible in the future, and to release software that makes it possible to use the secret-splitting approach to protect encrypted data, for example, for files stored in a cloud service.

However, Boneh notes, there are other ways for a person's secrets to be stolen. "With password management, often the main concern is the end user—if the user's machine is infected with malware, then there is little than can be done to secure them without resorting to a physical token," says Boneh, referring to systems that require people to carry a key fob, or use a phone app, to supply a temporary password each time they log in.

This approach, known as two-factor authentication, is usually required only for corporate or financial accounts, but Google and Facebook now offer it for their online accounts due to the brisk trade in compromising such accounts.


Report by: By Tom Simonite

Hackers using Skype to attack Windows PCs


Free internet-calling service Skype is being used by hackers to distribute a 'worm' that infects users Windows PCs

LONDON: Free internet-calling service Skype is being used by hackers to distribute a 'worm' that infects users Windows PCs.

On clicking an instant message saying "lol is this your new profile pic?" users are unwittingly downloading a file containing a Trojan horse malware file.

This opens a backdoor allowing hackers to hijack infected PCs and recruit them into a "botnet army".

Users can be locked out of their machines and held to ransom, the BBC reports.

According to the report, Skype said in a statement that they 'are aware of this malicious activity and are working quickly to mitigate its impact.'

"We strongly recommend upgrading to the newest Skype version and applying updated security features on your computer," the firm said in a statement.

"Additionally, following links - even when from your contacts - that look strange or are unexpected is not advisable," it added.


Report by: ANI

New phone app can help hackers spy on your home


A new phone app, created by US military experts, can make your phone camera take secret pictures, and in turn help hackers spy on you and your home. The "PlaiceRaider" app was created at the US Naval Surface Warfare Center in Crane, Indiana, to show how cyber criminals could operate in the future, the Daily Mail reported.

The creators even demonstrated how they could read the numbers of a cheque book when they tested the Android software on 20 volunteers.

The app can turn on a phone's camera, and personal data and private moments can be gleaned from images.

The software can build up a 3D model of a home, from which hackers can inspect rooms, and even take information about valuables in homes.

The military team gave infected phone instruments to 20 individuals, who did not know about the malicious app, and asked them to continue operating in their normal environment.

The team said they could glean vital information from all 20 users, and that the 3D reconstruction made it much easier to steal information than by just using the images alone.

Researcher Robert Templeman said the app can run in the background of any smartphone using the Android operating system, the daily said.

The team, however, offered various ways in which phone manufacturers could secure their systems, for instance making it impossible to disable the shutter sound on phones so that a user will know if a picture is being taken.


Report by: Indo-Asian News Service