Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Sunday, August 4, 2013

Defcon 21 - Wi-Fi Routers: More Security Risks Than Ever


The research team that discovered significant security holes in more than a dozen home Wi-Fi routers adds more devices to that list at Defcon 21.

PCWorld - LAS VEGAS -- More major brand-name Wi-Fi router vulnerabilities continue to be discovered, and continue to go unpatched, a security researcher has revealed at Defcon 21.

Jake Holcomb, a security researcher at the Baltimore, Md.-based firm Independent Security Evaluators and the lead researcher into Wi-Fi router vulnerabilities, said that problem is worse than when ISE released its original findings in April.

The latest study continues to show that the small office and home office Wi-Fi routers are "very vulnerable to attack," Holcomb said.

"They're not a means to protect your network and your digital assets," he cautioned.
Holcomb is a relatively young researcher, in his mid-20s, who turned his lifelong interest in computer security into a professional career only in the past year. Previously, he was doing network security for a school district in Ohio.   More

Wednesday, April 18, 2012

You Got Hacked! What Now?





PCMag.Com - The phone rings. It’s your sweetheart, in tears. Why, oh why, did you change your status on Facebook to Single? Are you moving to Dubuque? Facebook says you live in Dubuque.

First things first; offer all necessary reassurance that you’re not breaking up and moving away. Then face the facts—you’ve been hacked.

The evidence might come out in other ways. Your friends may ask why you sent them that stupid email ad for Viagra. You may find one day that you simply can’t log in to your email or social media account. It’s an awful feeling, but you can recover.

How Did It Happen?

It’s conceivable that a cyber-criminal mastermind targeted you personally for a hack attack. A “spear-phishing” email message specially crafted using your personal information might have tricked you into connecting with a malicious site. Or perhaps an active hacker in some Moscow basement exploited a vulnerability in your OS.

Yes, these scenarios are conceivable, but they’re almost inexpressibly unlikely. You’re special, of course, but you’re not that special. It’s much more likely that you just weren’t careful, or weren’t lucky. Perhaps you logged in to your email from a public computer without taking proper precautions. Maybe you shared your password with a friend who’s turned out not to be such a friend after all. A valid website that’s been compromised by injected malware can infest your system with a data-stealing Trojan, and that doesn’t require any personal attention from cyber-spies.   More

Thursday, October 13, 2011

Guidelines for Securing Open Source Software



Our recent security audit of libpurple and related libraries got us thinking about the general problem of open source security auditing, and we wanted to share what we’ve learned. Free and open source software that happens to be community-supported can be challenging from a security perspective. There is a fair amount of recent literature on this topic, and it is debatable whether openly readable source code helps defenders more than it helps attackers.

The key issue is not about source code but the fact that community-based open source software projects often lack the organized resources of their corporate cousins. If large corporate projects choose to prioritize security, they can usually afford to hire experts to do regular security reviews; community projects need to find and coordinate volunteers with this specialized focus. In an environment where developers are stretched thin and often have a wide array of responsibilities, the search for security bugs may be less organized and lag behind. How do we combat this problem? How can we ensure good security in a world where vulnerabilities in important open source software can have disastrous consequences for users all over the world?

These are hard questions without simple answers. Yet although there are weaknesses to free, community-supported open source, there are also strengths: one can take advantage of crowdsourcing, open discussion, and can often give integrated updates with less hassle due to friendlier and sane licensing. In order to take advantage of the strengths while mitigating the weaknesses, we think that there are some design choices that these projects can make to drastically cut down on the amount of effort that will be required to do security auditing. These suggestions are by no means original, but we think are even more important to emphasize within the framework of the community-supported open source.
  • Make the code as simple, modular, and easy to understand as possible. To take advantage of volunteer effort to crowdsource security auditing, the barrier to entry for understanding the code has to be quite low. Modularity in itself helps improve security, but it also helps people take a look at one aspect of the code without having to digest the possibly complicated way that it all hangs together.                 More

Monday, October 10, 2011

‘We Are Anonymous, We Are Legion’ The hacker collective is far more evil than you ever imagined



Anonymous utilizes murderous pop culture figures 
in its imagery. Here the group references the 
"Hitman" video game series. In other 
communications the anarchist terrorist V 
from Alan Moore's "V for Vendetta" is the 
inspiration.


Pajamas Media - It was in 2008, during their inappropriately celebrated “War on Scientology,” that the hacker collective known as Anonymous first began using the phrase “We are Legion” in their communiques. Not being a Christian myself, it is usually hard for me to get too worked up over this sort of ham-fisted, pop-culture pseudo-Satanism. In most cases it is window dressing designed to distract people from the vapid and lazy “thought” that too many young people think is provocative. With Anonymous however, it’s different. Anonymous, often heralded as heroic defenders of freedom and transparency, have a history of activities that go beyond the realms of subversive or even revolutionary and are quite simply evil.

I first became aware of Anonymous in 2008 when I read about a case in which the group posted the address and phone number of a middle-aged couple they mistakenly believed were “pro-Scientology” hackers. The couple was inundated with death threats and feared for their lives:
John Lawson, who lives in Stockton, California with his wife Julia, began receiving threatening phone calls around 2 a.m. Saturday morning. He didn’t know why until THREAT LEVEL explained that a hacking group calling itself the g00ns (goons spelled with zeros, not goons with the letter o) posted his home address, phone number and cell numbers, as well as Julia’s Social Security number, online. The obscene and threatening calls have continued through Tuesday, according to Lawson.

The calls are just one small offshoot of an ongoing, larger attack on the Church of Scientology by a ragtag group of internet troublemakers who call themselves Anonymous. The group says it is targeting Scientology in part for its use of litigation to suppress unflattering documents on the internet.

Over the weekend, the g00ns thought they had caught a hacker who had busted into a server being used to help coordinate the online attacks and real world protests against Scientology.  But Lawson says the callers have the wrong guy.
“I don’t even really know how to use a computer,” Lawson said.

His phone just keeps ringing, Lawson said, and when he answers, callers spout vulgarities and threats and then hang up. On Monday, he got a call that seemed to originate from the Virgin Islands. The caller  threatened to kill him.

“They have got the wife really scared because they have my address,” Lawson said. “I think I am going to buy me a gun today just in case.”
But that was mild compared to their next stunt.          More

Wednesday, October 5, 2011

Hacker Group Anonymous Threatens to Attack NY Stock Exchange



A digital flier released by someone claiming to be the hacker group Anonymous in which they ask others to join them this coming monday to hack the NYSE website and remove it from the internet

The FBI is investigating threats purportedly from the hacking collective that calls itself Anonymous to bring down the New York Stock Exchange on Monday by hacking into its computer system.

Members of the notorious hacker group appear to be threatening to bring the Occupy Wall Street protests in New York to a dangerous new level, sounding a call to “declare war on the New York Stock Exchange” on Monday by “erasing” it from the Internet.

“The FBI is aware of these schemes and threats and is looking into the matter,” FBI spokesman Tim Flannelly told FoxNews.com.

The hackers say they plan to launch a DDoS (or distributed denial of service) attack on the NYSE’s computer systems — the same type of computer attack that brought down numerous websites last Spring, making them inaccessible.

Anonymous has also separately declared the Stock Exchange announcement a hoax, and it remains unclear whether this is an official effort by Anonymous, a group of rogue hackers or someone else entirely.

Either way, the FBI is investigating.

“It is a crime to show the intent to carry out a hack when you are in possession of software or computer applications to do so and we take it seriously,” FBI spokesman Flannelly said.

In one of the videos, which was addressed to the media, a narrator states, “We can no longer stay silent as the population is being exploited and forced to make sacrifices in the name of profit. We will show the world that we are true to our word. On October 10, NYSE shall be erased from the Internet … expect a day that will never, ever, be forgotten.”

In a video addressed to the public, the narrator states, “We are the 99 percent. You have complained that something needs to be done. You now have an opportunity to make a difference. Join the protests. Organize your own. Watch online. Be a part of the movement.”              More

Wednesday, September 21, 2011

Sony Forces Gamers to Promise They Won’t Sue En-Masse for Hacks



Wired - After being spectacularly hacked multiple times earlier this year, Sony has decided it’s tired of being sued for its security failures and other issues and is requiring gamers on its Play Station Network to sign an agreement saying they won’t join class-action lawsuits to take the tech giant to court in the future.

Sony quietly updated its terms of service (.pdf) last week to require online gamers to agree to waive their right to any class-action lawsuit in order to log in to their network accounts. Updates to the 21-page, 10,000-word agreement would force current and new players alike to take any grievances to an arbitrator instead. An exclusion exists for disputes that would normally be filed and resolved in small-claims court.

Players have 30 days after signing the agreement to void the arbitration agreement and retain their right to file a class-action lawsuit, but only if they send a letter to Sony, via regular post, asserting they do not consent to the arbitration clause.

Class-action bans are becoming standard in terms-of-service agreements offered by large corporations. The Supreme Court ruled last April that companies can ban class-action suits from customers as long as their agreements allow arbitration to settle disputes. Companies know, however, that consumers are less likely to pursue arbitration or court action – or attract the interest of an attorney – if they have to do so individually.

Sony’s move comes four months after hackers breached its PlayStation Network in April and stole data pertaining to more than 75 million customers. This was followed by another breach at Sony Online Entertainment, which compromised an additional 25 million customers, and still more breaches at Sony Pictures and Sony BMG. The initial intrusion forced Sony to take its Play Station Network offline for 40 days.                  More

Monday, August 22, 2011

Advanced Encryption Standard cracked - AES secures most online transactions & wireless communications


 h/t - @FurryStoat

Boffins from Microsoft and the Katholieke Universiteit Leuven in Belgium have cracked the Advanced Encryption Standard (AES), the encryption algorithm.

AES is used to secure most all online transactions and wireless communications so breaking the system is bad news for anything dependant on it.

Their method can recover an AES secret key from three to five times faster than previously thought possible and do not need to assume related-keys.

"Most of our attacks only need a very small part of the codebook and have small memory requirements, and are practically verified to a large extent. As our attacks are of high computational complexity, they do not threaten the practical use of AES in any way," the report said.          More

Thursday, July 28, 2011

Scotland Yard Busts Suspected LulzSec Spokesman


The London Metropolitan Police on Wednesday arrested a 19-year-old Shetland Islands man who they say is “Topiary,” the most visible figure in LulzSec.


The police news release doesn’t name the suspect. The bust is the second high-profile arrest of an alleged member of the six-man hacking gang. British police last week arrested a 16-year-old they say is “T-Flow” — another prominent member. In June they arrested 19-year-old Ryan Cleary of Wickford, Essex, who allegedly ran an IRC channel used by the group.

LulzSec’s leader, “Sabu,” remained active on Twitter Wednesday morning, but did not immediately acknowledge the arrest of his purported frontman.       More

Monday, June 27, 2011

iPhone and PS3 Hacker Heads to Facebook


PCMag.Com - From gray hat to white hat, one of the Internet's more well-known celebrity hackers as of late has decided to take up shop at one of the Web's biggest social properties: Famed PlayStation hacker George "GeoHot" Hotz has gone to Facebook.

It's unclear what exactly Hotz is working on over at Facebook headquarters, but it's rumored that he's involved with product development for the company's alleged iPad app. The news of Hotz's brand-new job first broke when Joshua Hill—a member of the Chronic-Dev Team responsible for a variety of Apple product jailbreaks–noted that Hotz had backed out of an iPad 2 hacking challenge between the two.

The news was confirmed—where else?—from a quick visit to Hotz's Facebook page, where he's listed himself as working as a Facebook software engineer starting in May 2011. His first official day on the job was May 9.

According to Hill, Hotz now prefers to stay out of the public light when it comes to hacks or exploits. But it's unclear whether Hotz's shift to the corporate world will keep him from investigating new exploits for Apple products or other devices in the future.


More