Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts
0
[postlink]https://tenderhub.blogspot.com/2011/12/facebook-scams-now-spread-by-dodgy.html[/postlink]

Cybercrooks deploy new weapon to pollute profiles

Con men have developed a new approach towards spreading scams on Facebook.

Instead of using status updates as a lure, the latest generation of Facebook scams attempt to trick marks into installing malicious browser extensions. The plug-ins are supposedly needed to view non-existent video clips supposedly posted by an earlier victim.

Once installed, these malign browser ad-ons spread the scam from one user's profile to another's profiles.

Elad Sharf, security researcher at Websense Security labs, explains: “Scam pages typically utilise social engineering tricks such as enticing you with videos or a free voucher. In this new scam you’re encouraged to install a browser plugin.

"The plugin is an integral part of how the scam is spread and has the ability to propagate by posting in your name on friends' pages. As much as these offers look tempting, if you’re asked to install plug-ins in order to get vouchers or watch a video – remember it could be a trick to spread scams, spam and malware.”

The bogus extensions come as add-ons for both Firefox and Chrome. More details of the scam, including screenshots, can be found in a blog post by Websense here. ®

Facebook scams now spread by dodgy browser plug-ins

0
[postlink]https://tenderhub.blogspot.com/2011/12/iranian-engineer-hijack-us-drone-by-gps.html[/postlink]


An Iranian engineer working on the captured US drone has said that Iran exploited a weakness in the craft’s navigation system to hijack it. The aircraft was downed through a relatively unsophisticated cyber-attack that tricked its global positioning systems (GPS).
The technique, known as “GPS spoofing” has been around for several years, and the Iranians began studying it in 2007, the engineer reportedly said. The U.S. Department of Energy notes that GPS is widely used, but insecure, although few users have taken note. GPS signals for the U.S. military are similarly insecure, and drones often rely on signals from multiple satellites. It’s possible to spoof unencrypted civilian GPS systems. But military GPS receivers, such as the one likely installed on the missing drone, use the encrypted P(Y)-code to communicate with satellites.

With spoofing, an adversary provides fake GPS signals. This convinces the GPS receiver that it is located in the wrong place and/or time,” the vulnerability assessment team at Argonne National Laboratory explained. “Remarkably, spoofing can be accomplished without having much knowledge about electronics, computers, or GPS itself.
Other drone vulnerabilities have also highlighted security fears. In October, Danger Room broke the news that the cockpits at the Air Force’s drone fleet based out of Creech Air Force Base in Nevada were infected with a virus. Malware had apparently made its way onto computers because someone had been using one to play the Mafia Wars game a stunning security faux pas.
The RQ-170 Sentinel has been seen on display by Iran's gloating military after it went missing along the Afghan-Iran border earlier this month - but a former Pentagon official said it seems to be a fake. However the engineer working on the CIA drone’s system told the Christian Science Monitor that his country fooled the aircraft into touching down in Iran - instead of its programmed destination.The engineer claimed the electronic attack made it 'land on its own where we wanted it to, without having to crack the remote-control signals and communications' from the U.S. control centre.

The drone was used for covert surveillance such as the operation to spy on the Pakistan compound of Osama Bin Laden before he was killed in a U.S. raid in May.Iranian officials have said the drone came down over eastern Iran, hundreds of miles from the cluster of nuclear sites in the central and north-west of the country.They believe they can 'mass produce' the captured drone by 'reverse engineering' the aircraft.

Iranian engineer hijack U.S. drone by GPS hack [Video Explanation]

0
[postlink]https://tenderhub.blogspot.com/2011/12/apple-crash-reports-help-hackers-to.html[/postlink]

Apple Crash Reports Help Hackers to create a jailbreak exploit
iPhone "jailbreaking" has been a hot topic since Apple released its smartphone more than two years ago. According to the Latest report posted by BBC that Thousands of iPhone owners have joined forces with a team of hackers to help them find new ways to jailbreak Apple's phone software & Jailbreakers use Apple crash reports to unlock iPhones.
You may be wondering and hearing alot on “What Is Jailbreaking an Iphone? How do you do that?” Jailbreaking is basically modifying the iPhone’s firmware so that you can get access to the internals of its operating system and install a whole slew of third-party applications on your iPhone that are not otherwise available through official channels.Jailbreaking your iPhone in and of itself doesn’t normally make much difference in your operation of it, but it does allow you to install other third-party applications that are not blessed by Apple.
A collective of hackers known as the iPhone Dev-Team publishes easy-to-use, cross-platform tools that allow you to install third-party apps on your iPhone that Apple won't admit into its App Store. The latest version of the iPhone's operating system is proving to be extremely hard to jailbreak fully, according to Joshua Hill, a member of the Chronic Dev hacker team."Apple is really making it tough for us. The iPhone is now better protected than most nuclear missile facilities," he says.
Jailbreaking your iOS device also enables you to change your phone’s behavior and even add some nifty extra features. One such feature that Apple prohibited was FaceTime or any demanding data tasks over 3G.


How Hackers Develop a Jailbreak application ? Well, Hackers like Mr Hill hunt for programming errors, or bugs, in Apple's software. Bugs may result in a program crashing or shutting down, and they are like gold dust to hackers because sometimes they can be exploited to create a jailbreak. Hackers may have to crash a particular program thousands of times as they work out how to exploit a bug successfully, but this alerts Apple that the bug exists and that hackers may be investigating it.
Phone manufacturers don’t want you to do it because of the small number of cases in which it can make the phone unstable or open it up to security breaches. It then makes them look bad because it’s their phone that’s crashing or introducing malware to your network. 
But Users Hate hate it even more because it can cost them money. They even go so far as to cripple features that the phone makers build in, so they can charge you an extra fee for the same service. One example is Wi-Fi hotspot capability, for which carriers charge up to $30 per month when you can do the same thing on a rooted phone with no extra fees using a free or low, one-time-cost app. Some carriers also don’t want you running apps like Skype to make phone calls instead of using expensive cellular voice minutes.
Chronic Dev is ready to turn this little information battle into an all-out, no-holds-barred information WAR. A program called CDevreporter that iPhone users can download to their PC or Mac. The program intercepts crash reports from their phones destined for Apple and sends them to the Chronic Dev team. "In the first couple of days after we released CDevreporter we received about twelve million crash reports," he says. "I can open up a crash report and pretty much tell if it will be useful or not for developing a jailbreak, but we have so many that I am working on an automated system to help me analyse them."
Is Jailbreaking Legal ? In July,2010 The United States government announced that jailbreaking and unlocking iPhones, rooting of Android phones and ripping DVDs (for educational purposes) is completely legal as long as they are not violating copyright law.  It is also apparently not illegal to jailbreak devices in the UK, although it does invalidate product warranties, according to Simon Halberstam, technology law expert and partner at Kingsley Napley.
Apple tries to prevent jailbreaking for security reasons  once a phone has been jailbroken users could unwittingly install malware that might not get past Apple's approval process. Mr Hill rejects this argument: "I am trying to make sure that my phone is safe and your phone is safe. Apple cares about money, not your safety."
As yet the Chronic Dev team has not announced that it has found any bugs that it can exploit, but a member of the team called pod2g claims to have found a way to create an untethered jailbreak anyway. Even if Apple fixes the bug that makes this jailbreak possible, Mr Hill is confident that the hackers will find more ways.

Apple Crash Reports Help Hackers to create a jailbreak exploit

0
[postlink]https://tenderhub.blogspot.com/2011/12/18-million-accounts-hacked-from-square.html[/postlink]

1.8 Million Accounts Hacked from Square Enix Japanese Game Company

Square Enix stated yesterday that somebody "may have gained unauthorized access to a particular Square Enix server" and took its members service offline in both Japan and the U.S. Today, the company clarified that 1.8 million customer's accounts had been affected.

The company said it noticed that unknown parties had accessed the server for its free "Square Enix Members" site on Tuesday afternoon, and decided to shut down the service the same day. Users register on the server with their email addresses and sometimes their names, addresses and phone numbers, but the server holds no credit card information, a spokesman said.

1.8 Million Accounts Hacked from Square Enix Japanese Game Company

0
[postlink]https://tenderhub.blogspot.com/2011/12/jolt-in-wikileaks-case-feds-found.html[/postlink]

A government digital forensic expert examing the computer of accused WikiLeaks source Bradley Manning retrieved communications between Manning and an online chat user identified on Manning’s computer as “Julian Assange,” the name of the founder of the secret-spilling site that published hundreds of thousands of U.S. diplomatic cables.
Investigators also found an Icelandic phone number for Assange, and a chat with a hacker located in the U.S., in which Manning says he’s responsible for the leaking of the “Collateral Murder” Apache helicopter video released by WikiLeaks in spring 2010.
Until Monday’s revelation, there have been no reports that the government had evidence linking Manning and Assange, other than chat logs provided to the FBI by hacker Adrian Lamo last year. Assange is being investigated by a federal grand jury, but has not been charged with any crime, since publishing classified information is not generally considered a crime in the U.S. But if prosecutors could show that Assange directed Manning in leaking government documents that he then published, this could complicate Assange’s defense that WikiLeaks is simply a journalistic endeavor.
The news of the chat logs between Manning and Assange came on the fourth day of Manning’s pre-trial hearing being held to determine whether he’ll face court martial on 22 charges of violating military law for allegedly abusing his position as an intelligence analyst in Iraq in order to feed a treasure trove of classified and sensitive documents to WikiLeaks.
Mark Johnson, a digital forensics contractor for ManTech International who works for the Army’s Computer Crime Investigative Unit, examined an image of Manning’s personal MacBook Pro and said he found 14 to 15 pages of chats in unallocated space on the hard drive that were discussions of unspecified government info between Manning and a person believed to be Assange, which specifically made a reference to re-sending info.
While the chat logs were encrypted, Johnson said that he was able to retrieve the MacBook’s login password from the hard drive and found that the same password “TWink1492!!” was also used as the encryption key.
Assange’s name was attached to a chat handle “dawgnetwork@jabber.ccc.de” listed in Manning’s buddy list in the Adium chat program on his computer. That Jabber address uses the same domain name allegedly mentioned by Manning in the chat logs that ex-hacker Adrian Lamo gave to the FBI and to Wired.com last year. In that earlier chat log, Manning was making reference to a domain that Assange was known to use.
In Manning’s buddy list there was also a second handle, “pressassociation@jabber.ccc.de,” which had two aliases associated with it: Julian Assange and Nathaniel Frank. CCC.de in the domain refers to the Chaos Computer Club, a hacker club in Germany that operates the Jabber server.
When asked about the two aliases, Johnson said it was odd for a user to assign two names to one account, implying that some subterfuge might have been at play.
The chat logs mention a request to re-send some unspecified data, showing that the parties had talked before, Johnson said, as well as discussion about using SFTP for uploading data securely to an FTP server.
Johnson testified that he also found SSH logs on Manning’s computer that showed an SFTP connection from a Verizon IP address, that resolved to Manning’s aunt’s house in the U.S., to an IP address associated with a Swedish ISP called PRQ that is known to have links to WikiLeaks.
In a separate chat with Eric Schmiedl, who appears to be a photographer, lock picker and member of the hacker scene who lives in the U.S., Manning confesses that he leaked the Apache attack video, which documented the deaths of two Reuters employees.
Manning: Are you familiar with WikiLeaks?
Schmiedl: Yeah, I am
Manning: I was the source of the 12 Jul 07 video from the Apache Weapons Team which killed two journalists and injured two kids
Johnson testified that he found two attempts to delete data on Manning’s laptop. Sometime in January 2010, the computer’s OS was re-installed, deleting information prior to that time. Then, on or around Jan. 31, someone attempted to erase the drive by doing what’s called a “zerofill” — a process of overwriting data with zeroes. Whoever initiated the process chose an option for overwriting the data 35 times — a high-security option that results in thorough deletion — but that operation was canceled. Later, the operation was initiated again, but the person chose the option to overwrite the information only once — a much less secure and less thorough option.
All the data that Johnson was able to retrieve from un-allocated space came after that overwrite, he said.
Johnson says he also examined an external hard drive found in Manning’s bunk room in Iraq that contained a text file called wl-press.txt that was created on Nov. 30, 2009, right around the time that Manning told Lamo that he first made contact with WikiLeaks.
The file included the line: “You can currently contact our investigations editor directly in Iceland at 354.862.3481 : 24 hour service : ask for Julian Assange.”
During re-direct with Johnson, government attorney Joe Morrow referred Johnson to one of the charges against Manning that relates to the “United States Forces -Iraq Microsoft Outlook / SharePoint Exchange Server global address list belonging to the United States government,” which Manning allegedly stole between May 11-27, 2010.
Morrow asked Johnson if he’d found any evidence related to the global address list (GAL) and he replied that investigators found a text file in unallocated space that contained a task instruction to obtain the global address list for U.S. forces in Iraq. He also found thousands of Exchange-formatted email addresses on the computer. Asked if there was any evidence that the GAL had been released, Johnson replied, “I did not discover that, no.”
We would like a list of as many .mil email addresses as possible. Please contact editor@wikileaks.org or submit

Johnson didn’t mention any date in relation to the GAL evidence he found on Manning’s computer, but on May 11, 2010, WikiLeaks had tweeted a request for people to send it .mil email addresses.
“We would like a list of as many .mil email addresses as possible. Please contact editor@wikileaks.org or submit,” the Tweet read.
Also testifying today, was Special Agent David Shaver, who revealed that he examined an SD card found at Manning’s aunt’s house, where Manning had lived for a while, and found an encrypted zip file on it that contained three files he was able to open, and references to two files that had been deleted and were no longer accessible. The two deleted files were named “Nathan2_events.tar.br2″ and “Nathan2_event.”
Of the three files he was able to open, one file “Irq_events.csv” was created on Jan. 5, 2010 and contained more than 400,000 action reports from Iraq, pulled from the Combined Information Data Network Exchange, or CIDNE. The other file, “Afg_events.csv,” was created on Jan. 8, 2010 and contained about 91,000 action reports from Afghanistan. The third file, a readme.txt file, appeared to be a message to someone, likely WikiLeaks.
Items of historical significance of two wars Iraq and Afghanistan Significant Activity, Sigacts, between 00001 January 2004 and 2359 31 Dec 2009 extracts from CSV documents from Department of Defense and CDNE database. These items have already been sanitized of any source identity information.
You might need to sit on this information for 90 to 180 days to best send and distribute such a large amount of data to a large audience and protect the source.
This is one of the most significant documents of our time removing the fog of war and revealing the true nature of 21st century asymmetric warfare.
Have a good day.
Shaver said he was able to open those encrypted files using the same password he extracted from the MacBook.
“You got kind of lucky?” asked the prosecutor.
“Yes, sir,” Shaver replied.
In the summer and fall of 2010 WikiLeaks, and several media partners in the U.S. and Europe, published what WikiLeaks referred to as the Afghan War Diary – a cache of more than 400,000 so-called Sigact reports from the Afghan War – as well as the Iraq War Diary, a trove of some 91,000 Sigacts from the Iraq War.

Jolt in WikiLeaks Case: Feds Found Manning-Assange Chat Logs on Laptop