• Facebook Rocks

    Go to Blogger edit html and replace these slide 1 description with your own words. ...

  • Facebook vs Twitter

    Go to Blogger edit html and replace these slide 2 description with your own words. ...

  • Facebook Marketing

    Go to Blogger edit html and replace these slide 3 description with your own words. ...

  • Facebook and Google

    Go to Blogger edit html and replace these slide 4 description with your own words. ...

  • Facebook Tips

    Go to Blogger edit html and replace these slide 5 description with your own words. ...

Showing posts with label HackingZone. Show all posts
Showing posts with label HackingZone. Show all posts

Source Code of Crypo.com Available to Download


The Source Code of Crypo.com , One of the Famous Free Online Encryption Service is now available todownload form a File sharing website. This Script will encrypt your messages using a strong encryption algorithm, and then your information will be secure for sending.

US ,Israel or Russia , Who is Behind Stuxnet?





Initially After Symantec did a little reverse engineering on the now infamous Stuxnet worm, many started pointing the finger at the US and Israel, especially since it was concluded that the piece of malware was designed to target a specific version of the Siemens SCADA programmable logic controls (PLC) operating in certain nuclear facilities from Iran. Ralph Langner told a conference in California that the malicious software was designed to cripple systems that could help build an Iranian bomb.Mr Langner was one of the first researchers to show how Stuxnet could take control of industrial equipment.


Dr. Panayotis A. Yannakogeorgos is a cyber defense analyst with the U.S. Air Force Research Institute. He told the Diplomat that the one weak point in the theory that the US and Israel hit the Iranian nuclear problem with Stuxnet is that both sides denied it when they would not have had to. Yannakogeorgos said that the Russians could have equally carried out the attack. Apparenly the Russians are not that happy about an Iranian indigenous nuclear capability even if they are helping build it.



In brief, the case for the United States having designed and developed Stuxnet is as follows: First, neither the United States nor Israel wants Iran to develop nuclear weapons. The worm, then, is seen as likely part of a covert strategy to delay or destroy Iran’s nuclear infrastructure while stopping short of war. The weapon was designed to target a specific version of the Siemens SCADA programmable logic controls (PLC) operating a specific configuration and number of cascading centrifuges found in Iran. Some analysts point to the fact that there were vulnerability assessments being run at Idaho National Labs on Siemens PLC software. Others note that the design of the cyber weapon closely fit Richard Clark’s description in Cyber War of a well-designed and ethically thought out weapon limiting collateral damage due to a vast army of lawyers scrutinizing the effects. The malware-analyst community, meanwhile, points to digital code strings such as “b:\myrtus\” taken from biblical events important to Israeli identity. And, as the story goes, after the political decisions, vulnerability assessments, and weapon design took place, either an Iranian agent was found to take the USB memory stick into the nuclear facility, or all the computers around the plants were infected with Stuxnet via the conficker worm.


Russia has a good reason not to want Iran to get its paws on nuclear technology. In 1995, for example, Chechen rebels planted a "dirty bomb" in Moscow's Izmailovsky Park. Nuclear material is much more secure in Russia but if Iran develops a full-blown nuclear capability, Chechen or other violent extremist and nationalist rebels go to Iran to buy the material.



The Stuxnet attack may be coupled with an assassination campaign targeting Iranian nuclear and computer scientists and various leaks suggesting covert action, all made for a compelling case of U.S. involvement. But whether it was the United States or Russia behind it, it’s clear that in Stuxnet’s aftermath, and with the emergence of other worms within their systems, Iranian nuclear engineers have less confidence in the accuracy of sensor information on digital displays. All this means that there’s now no need for the U.S. or Russia to say anything on the issue internal conflict in the minds of those responsible for Iran’s nuclear program is doing a perfectly good job of delaying progress.

Government organised 12 Chinese Hacker Groups behind all Attacks




About 12 different Chinese groups largely directed by the government there, do the bulk of the China based cyber attacks stealing critical data from U.S. companies and government agencies, according to U.S. cyber security analysts and experts. US online security companies are suggesting that it should have the right to force them to stop "by any means possible".


Sketched out by analysts who have worked with U.S. companies and the government on computer intrusions, the details illuminate recent claims by American intelligence officials about the escalating cyber threat emanating from China. And the widening expanse of targets, coupled with the expensive and sensitive technologies they are losing, is putting increased pressure on the U.S. to take a much harder stand against the communist giant.


The report states that many of the attacks carry tell-tale signatures of particular hacking groups being tracked by intelligence and cybersecurity teams in the U.S., contrary to many expert opinions which indicate that accurate attribution is nearly impossible if the attackers are savvy enough.


James Cartwright, a former vice chairman of the Joint Chiefs of Staff who advocates for increasing measures to hold China and other nation-states responsible for intrusion operations, said that "industry is already feeling that they are at war."


"Right now we have the worst of worlds. If you want to attack me you can do it all you want, because I can't do anything about it. It's risk free, and you're willing to take almost any risk to come after me," said Cartwright.


Cartwright believes the U.S. should be aggressive in their response to attacks that originate overseas, in essence establishing that "if you come after me [the U.S.], I'm going to find you, I'm going to do something about it. It will be proportional, but I'm going to do something... and if you're hiding in a third country, I'm going to tell that country you're there, if they don't stop you from doing it, I'm going to come and get you."


The government "needs to do more to increase the risk," said Jon Ramsey, head of the counter threat unit at the Atlanta-based Dell SecureWorks, a computer security consulting company. "In the private sector we're always on defense. We can't do something about it, but someone has to. There is no deterrent not to attack the U.S."


According to experts, the malicious software or high-tech tools used by the Chinese haven't gotten much more sophisticated in recent years. But the threat is persistent, often burying malware deep in computer networks so it can be used again and again over the course of several months or even years.The tools include malware that can record keystrokes, steal and decrypt passwords, and copy and compress data so it can be transferred back to the attacker's computer. The malware can then delete itself or disappear until needed again.


For the first time, U.S. intelligence officials called out China and Russia last month, saying they are systematically stealing American high-tech data for their own economic gain. The unusually forceful public report seemed to signal a new, more vocal U.S. government campaign against the cyberattacks.

Carrier IQ acting as Special Agent for FBI ?





The Carrier IQ Privacy issue continues today with a new, albeit not a really surprising, episode. Apparently the FBI was aware of what the Carrier IQ technology is able to do, and the Bureau is not willing to reveal anything regarding Carrier IQ just yet. Whereas, The FBI denies the release of information about their use of Carrier IQ, Wikipedia founder asks for input about a site-wide blackout, and the Kindle Fire will get a pre-Christmas software update to improve performance.


Government watchdog site MuckRock believes Carrier IQ data is being used by the FBI in an investigation. If so, the worries over Carrier IQ will rise up again. Carrier IQ is installed in about 150 million handsets globally, according to the company. MuckRock sent an Freedom of Information Act request to the FBI, asking for "manuals, documents or other written guidance used to access or analyze data gathered by programs developed or deployed by Carrier IQ." That FOIA request was met with what MuckRock called a "telling denial."


The very first page of the denial letter specifically states that the information they have in the exempt file is for law enforcement purposes and that they cannot release information that will jeopardize any ongoing investigation.


Carrier IQ and several wireless carriers and handset makers have admitted to installing the software in handsets, but insist the software is benign and designed primarily to collect data for optimizing network and device performance. Critics of Carrier IQ's software, who include Google executive chairman Eric Schmidt, have claimed the software enables keylogging and extensive data capture.


Hopefully future investigations into Carrier IQ practices will offer us more details about the way Carrier IQ data was used by the FBI, if that’s the case, and we’re certainly interested to see what various U.S. and international officials will have to say about the FBI’s proven involvement with this matter.


In the meantime, if you wish not to be monitored by corporations and the government, we politely remind you to stay off the Internet, stop using all proprietary software and hardware, disconnect your cell phone and land line immediately, and ensure a snug fit on your tin foil helmet.

Russian hackers hit Twitter with automated hashtags tweets




Russian hackers have taken aim at Twitter in recent days to hamper communication between opposition activists as outrage against the conduct of last week's general elections grows. The pro-government messages were generated by thousands of Twitter accounts that had little activity beforehand. The hashtag is #триумфальная (Triumfalnaya), the name of the square where many protesters gathered.

Maxim Goncharov, a senior threat researcher at Trend Micro, observed that “if you currently check this hash tag on twitter you’ll see a flood of 5-7 identical tweets from accounts that have been inactive for month and that only had 10-20 tweets before this day. To this point those hacked accounts have already posted 10-20 more tweets in just one hour.”


Brian Krebs, the author of the blog Krebs on Security, noted that the ‘bot accounts he lists themhere appear to follow a single account called @master_boot, as well as following each other. The accounts were also all created in July of this year. Besides pro-government tweets many of the messages are gibberish.

Getting the software for such attacks isn’t that hard, about $150 one can get the automated Twittering software, and a “Twitter blasting machine” totals about $300. Social networks are becoming an increasingly important stage for conflict between governments and their people. Occupy Wall Street has made effective use of Tumblr, and protests in Egypt were often organized using Twitter and Facebook.

Anonymous claims new Monsanto-related hack



http://youranonnews.tumblr.com/







The Anonymous hacktivist group claims it is responsible for putting a Washington, D.C. public relations firm out of business.

But a former executive at the now-defunct company, known as The Bivings Group, denies the allegations.

Anonymous defaced the firm's website and hacked into a database, spilling the contents, including hundreds of corporate emails, the collective said in a Pastebin document, posted Monday. Anonymous targeted The Bivings Group as part of "Operation End Monsanto," a campaign designed to go after the multinational maker of genetically engineered seeds and growth hormones.



Microsoft: We Can Remotely Delete Windows 8 Apps



http://www.flickr.com/photos/magn3tik/6146437141/







Microsoft will be able to throw a "kill switch" to disable or even remove an app from users' Windows 8 devices, the company revealed in documentation released earlier this week for its upcoming Windows Store.

Kill switches -- so called because a simple command can deactivate or delete an app -- are common in mobile app stores. Both Apple and Google can flip such a switch for apps distributed by the iOS App Store and Android Market, respectively.

In the Windows Store terms of use , Microsoft made it clear that it can pull the kill switch at its discretion. "In cases where your security is at risk, or where we're required to do so for legal reasons, you may not be able to run apps or access content that you previously acquired or purchased a license for," said Microsoft in the Windows Store terms.



Six arrested for Million Pounds phishing scam


Six people from London and the North West were being questioned by police on Friday in connection with a £1 million phishing scam that drained the bank accounts of hundreds of UK students. That is a lot of beer and book money, and the police said that hundreds of students had been caught out by the scammers. Today the Metropolitan Police said its Police Central e-Crime Unit (PCeU) arrested the suspects yesterday after four months of investigation.

On Thursday, the police arrested a 38 year old man in Bolton; a 26 year old man and a 25 year old woman in Manchester; a 25 year old man in Deptford, London; and a 49 year old woman and a 31 year old man in Stratford, London. Police also seized computers and equipment from premises in London, Manchester and Bolton.

The police said that on average the scammers, four men and two women, took amounts of money ranging from £1,000 to £5,000 at a time. They have been arrested on suspicion of conspiracy to defraud and committing Computer Misuse Act and money laundering offences.

Traditional phishing attacks occur when online fraudsters try to access personal data such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an online exchange, while malware is malicious software installed on a computer, which enables cybercriminals to access and use that computer for criminal purposes.

Social network poisoning - They are Following you Everywhere !


Note : This Article is taken from Most Comprehensive and Informative IT Security Magazine by The Hacker News - December Edition [ Download Here ]



"Be Social" is the imperative of the last years. We live alternative lives, weave dense networks of relationships; we feel the irrepressible urge to be part of a group, to fill the void that we carry within. But this human propensity to aggregation is now the foundation of the concept of "social network", a community of people, each of them defined “node” by researches, which are united by friendship, kinship, passions, interests, religious beliefs. The whole world is represented by a lattice structure that scientists have long taken to study, to achieve the classification of that human "node", classify its customs, and especially to predict the behavior and through it influence the response of the community a particular event. The philosophy is that of the control.

In May Pierluigi Paganini defined the term “Social network poisoning” writing before to Wikipedia EN and also to Italian Wiki.

The term social network refers to the poisoning effect produced by the application of methods designed to make unreliable the knowledge related to a profile and its relationships. The application of this kind of attack on large-scale could lead to the collapse of Social Networking platforms affect its value for commercial purposes, as well as the utility in terms of knowledge and correlation of data provided by users, with a significant impact on its economic value.

In the same way as the "route poisoning" (affecting the telecommunications network), the "poisoning action" are conducted with the aim to pollute the contents of this social network profiles typically introducing artifacts and relationships exist between them and real ones thus making the information unreliable. The result is the consequent failure of the chain of trust which are based on all social networks, in order not to allow search engines specifically developed to retrieve information of any kind relating to a particular profile.

Starting from the assumption that Internet and in particular the social network lacks a coherent and safe management of digital identity, it is possible to introduce the main tools currently poisoning and to hypothesize a new and viable in a future scenario:

Current tools

Replacement of identity, or the ability to impersonate another user to the wide variety of purposes intelligence social engineering.

Simulation of identity, creating a false profile, which does not correspond to any existing person, for malicious purposes or simply to remain anonymous.

Fuzzing profile, the voluntary introduction of elements false and / or non-matching to your profile to deceive intelligence systems, to prevent OSINT activities or other forms of personal gain.

Fuzzing social graph, the association intended to groups and individuals that have nothing to do with their interests and relations with the intention of introducing "noise" in their social graph.

Future instruments:

Personal /social bots , creating a large number of fake profiles (e.g. millions of fake profiles) managed by machines, able to interact with real users in a way likely, thus changing the "sentiment" and "conversation "large-scale as well as altering all the social graph and to preclude meaningful correlations on the data.

Black curation, the use of real users "holes" or fictitious to speak on topics of which you want to change the meaning, or to create new one ad-hoc, in analogy to the black SEO (search engine optimization) already use on search engines.

How easy to understand the interest in social networks are the stars. Complex systems analyze information, scan faces and places, building new relationships and providing new information. Government agencies and companies have realized the full potential of the medium, a real gold mine in which the imperative is the power, information, and control of a at the expense of a user too distracted and inattentive to the dangers ahead.

What to suggest to a friend node, be social, but sparingly. Be human first!

Hack a webcam and a film camera into a USB microscope


Have you ever wanted to inspect or photograph something up close, but could not find amagnifying glass or did not have enough light on your subject? Well read on, because this project will do the job for you at little or no cost called “My Inspector Gadget”.

Most of you probably have a webcam sitting around somewhere, and after all the high voltage projects you’ve done using disposable cameras, we bet you have some camera lenses too. In a contest entryButch shows how to make your very own computer enabled microscope out of stuff that many of you will have lying around your house. What is basically involved is tearing apart a web cam, adding additional lighting and a lens assembly from an old film camera.

In is project he shows how to harvest the lens from the film camera and mount it, as well as where he added the LED. You can see in the picture above, his results are pretty good.

Protecting Your BlackBerry Smartphone with Security Wipe



The BlackBerry device is a wonderful thing. We load our BlackBerries with various softwares and applications to increase our productivity and customize them with interesting themes and ringtones. We watch movies and play games and track day to day activities. All of these things require passwords and usually involve storing data on our devices that is sensitive in nature.


So what if you want to wipe your BlackBerry clean?

There are a number of reasons why you might want to wipe out your Blackberry. Perhaps you have switched jobs and need to submit your BlackBerry into your new IT department so they can set it up for their network. You wouldn’t want them to have access to your previous employers data would you?

Perhaps you have purchased a new model of BlackBerry and would like to gift your previous model to a friend or sell it on ebay. The same rule applies, you do not want them to see what you were using your Blackberry for prior to handing it over.

How to Use security wipe ?

Before using this function, it is recommended that you back up any data and applications that you like to use on your new BlackBerry smartphone.


  • On the BlackBerry smartphone, select Options from the home screen.

  • Select Security Settings, then Security Wipe.

  • Specify what items will be wiped during this process by checking off the boxes.

  • Enter “blackberry” (field is not case-sensitive) and select Wipe.

  • The BlackBerry smartphone will reset a few times, and after this process is complete, it will no longer contain any of your personal data.


Android Bloatware, Another Serious Android Privacy Issue





Researchers have found that some Android smartphones are more vulnerable to attacks than others, thanks to add-on software and skins that get installed by handset makers before they ship their smartphones to subscribers. It’s not just Carrier IQ that Android users need to be worried about.

A team of researchers from North Carolina State University discovered the security vulnerability on eight different smartphones from Google, HTC, Motorola and Samsung. Black hat hacker can exploit these vulnerabilities to record phone calls (see proof of concept video below), wipe out your phone, call or text premium rate numbers, and read your private messages and emails, all without your permission, of course. According to the paper published by the team.

"Our results with eight phone images show that among 13 privileged permissions examined so far, 11 were leaked, with individual phones leaking up to eight permissions. By exploiting them, an untrusted application can manage to wipe out the user data, send out SMS messages, or record user conversation on the affected phones - all without asking for any permission". According to the researchers, certain system configurations added on top of the Android OS by manufacturers, contain a backdoor to this personal information.

Android permissions are cornerstone of Android security and user privacy. For example, if an application requests permission to use a user's location--perhaps as part of an advertiser-backed effort to track their online behavior--the smartphone owner can deny that request. Likewise, permissions serve as a last line of defense against malicious applications that may end up on their phones. For example, if an application attempts to access both the Internet and a user's address book, but shouldn't need to do so, it could indicate that the application in question is attempting to steal data and phone home.

To test the permission-enforcement security model on Android smartphones, the researchers built a tool, dubbed Woodpecker, that subjects images of Android operating systems to permission tests. As a baseline, they first studied the Google Nexus One and Nexus S smartphones which come with a vanilla version of Android installed as well as the Motorola Droid, which is "close to the reference Android design," they said.

The university researchers explained in their paper, as well as in a YouTube video, that the code that allows these apps to sidestep Android's permission system lies in the interfaces and services phone manufacturers add on to their devices to supplement Google's firmware.



To Ensure your Privacy ,You can use custom ROM To Protect your Privacy on Android Phones By rooting your phone.

The Spy Files: Wikileaks expose Mobile Phone, Email Hacking capability



“Today we release over 287 files documenting the reality of the international mass surveillance industry – an industry which now sells equipment to dictators and democracies alike in order to intercept entire populations” Assange told reporters.

 
Another leaked document from 2011 shows how one UK firm is depended upon by the government, including “law enforcement agencies, intelligence and military agencies & special forces”. Such technologies can be “integrated into bespoke solutions for static, tracking and mobile overt and covert surveillance”.

The UK, one of the most surveilled countries in the world, with more CCTV cameras per person than any other major city, is one of the most prevalent in Internet monitoring, phone and text messaging analysis, GPS tracking and speech analysis technologies. Last month, it was found that Leeds-based company Datong plc. sold phone tracking and remote-disability technology to Scotland Yard, home of London’s Metropolitan Police, which could then be used to track protestors or disable remotely shut-off mobile phones en masse.

Wikileaks recently celebrated the first anniversary of the controversial publication of US diplomatic cable leaks a publication that made Julian Assange a household name.Assange is currently under house arrest in London, where he is planning to launch an appeal against the recent ruling of a British court, which decided to extradite the journalist to Sweden, where he is accused of sexually harassing two women. Assange fears that his extradition to Sweden may eventually end up being one to the United States and will be appealing the ruling once again next Monday.

McAfee drafted Five Steps to Avoiding bad apps on Pc & Mobile





Malicious applications are one of the most serious threats to smartphone users today. Not only can a dangerous app infect your phone and steal your personal information, it can even spy on you. Read our five easy tips for avoiding bad apps, and keep your device and information safe.

An Android developer recently discovered a clandestine application called Carrier IQ built into most smartphones that doesn't just track your location; it secretly records your keystrokes, and there's nothing you can do about it. In this digital age, privacy is more important than ever. Just because you “don’t have anything to hide,” does not mean that you shouldn’t value your privacy or fight for it when companies do things like this, especially with something as personal as your cell phone.

McAfee has come up with five “Common sense” practices that you might not have thought about before, but they actually do make sense for the most part.


Here’s a look:


  • For the moment, the amount of detected smartphone malware is relatively low compared to malware that targets desktop or laptop PCs; but being aware that it exists is the first step toward protecting yourself and your data.

  • Research apps and their publishers thoroughly and check the ratings - better to install apps that are broadly used in the market and/or are recommended by your circle of friends and colleagues

  • It is wise to purchase from a well-known reputable app store market, such as the Android Market. One way for Android users to avoid installation of non-market applications is to de-select the “Unknown sources” option in the Applications Settings menu on their device. If the option is not listed, it means your mobile service provider has already done this for the user.

  • When you install an app, you’ll see a list of permissions for services that are granted access to the hardware and software components on your device, like contacts, camera and location. If something in the permissions screen doesn’t look right, don’t install that app! For example, a game or alarm clock app probably shouldn’t need to access your contacts or have the ability to transmit that data from your device.

  • Install antivirus software on your phone. It is a good idea to install an antivirus program when you get a new mobile device before you add any other apps.


This last one actually be the most crucial one that people are missing. McAfee argues now that because smartphone and tablet sales are eclipsing those of desktops and laptops, cyber crime is surging in the mobile sector.

Nullcon GOA 2012 - International Security Conference


The open security community is a registered non-profit society and by far the largest security community in India with more than 2000 members comprising of information security professionals, ethical hackers and law enforcement professionals that focuses on Infosec research and assisting Govt. and private organizations with cyber security issues. null has 7 chapters through out India - Pune, Bangalore, Mumbai, Hyderabad, Delhi, Chennai and Bhopal, interacting with around 5000-6000 people by various activities like monthly meets, security camps, workshops, talks at various events & organizations and executing security projects.

Our portal http://null.co.in provides free information on security research, responsible vulnerability disclosure, open source security software project, white papers, presentations, monthly chapter meets.

We see that currently there is a disconnect between the Govt. agencies and private organizations when it comes to cyber security and aim to fill the gap in a vendor neutral way. We have many projects running that help organizations tighten their security infrastructure, including Keeda Project and nullcon - International

Security Conference and Training.

Keeda Project is a database of vulnerabilities found in the wild which are reported to us by the members or anonymous researchers and we take action by immediately contacting the concerned organization and the respective CERT with information on the vulnerability and assist them in mitigating the threats.

As a part of null initiatives we organize nullcon - International Security Conference (http://nullcon.net), our annual flag-ship event. It is held in Goa in the month of February. At nullcon we call upon security experts from around the world to deliver talks and workshops on the latest technology and techniques in the security

and hacking world. The talks range from web hacking, security & hacking tools, smart phone hacking, cyber warfare to zero day vulnerabilities.

The year 2012 marks a revolutionary change and unprecedented expansion in the way nullcon is organized. With the overwhelming support of our esteemed sponsors, enthusiastic participants and volunteers - null is organizing TWO conferences in 2012 - nullcon Goa on 15-18th Feb 2012 and nullcon Delhi in Oct 2012

 

  • Nullcon Goa continues to be a mix of hacking, security and business briefings with a lot of technical events for all the security geeks.

  • Nullcon Delhi will focus more on the Corporate and the Government sector. It will include events geared towards business prospects in information security such as the exquisite Exhibit Space and Demo Zone for cutting-edge technology and products, business networking events and parties.