Bài đăng

Đang hiển thị bài đăng từ Tháng 12, 2009

The Anatomy Of GSM Encryption Hack

Hình ảnh
After Karsten Nohl hacked the GSM encryption , I thought to Digg this a bit in more detail. So i have written this whole guide in favor of it. So lets start.   Karsten Nohl , A Germen Hacker have claimed that he have successfully cracked the GSM mobiles security algorithm. That we all know but the question that arises here is what he did to crack the GSM encryption which have been for years, actually from 1987.   There was a conference know as 26th Chaos Communication Congress (26C3) , as we all know which is indeed the most respected and one of the most seeable conferences in Europe.     It takes place from December 27th to December 30th 2009 at the bcc Berliner Congress Center in Berlin , Germany. which is quite recent and what was special this time on it was the GSM encryption crack details which were going to be demoed in the conference.   The 26C3s slogan is "Here Be Dragons".   As a matter of fact i was not there in ...

Your Mobile Is In Danger : Karsten Nohl Cracks GSM Mobiles Security Algorithm

Hình ảnh
Karsten Nohl , A Germen Hacker have claimed that he have successfully cracked the GSM mobiles security algorithm. Which can effect the whole world even your moblie.   I know what you might be thinking till now and its all true. Nohl was not alone in this whole arena of finding the vulnerability in the GSM phones. He was with another 24 friends teamed up to crack the worlds most used mobile security algorithm.   GSM security algorithm is based on the such a frequesny that it changes it signals from one tower to another in seconds and then transfers the signals to the other frequency station. Yeah, I know its pretty complicated stuff there.   Nohl claims that armed with the code, which has been published online , and a laptop with two network cards, an eavesdropper could be recording phone calls within 15 minutes... We also have live numbers of Victims !   Nohl : "This shows that existing GSM security is inadequate"   Nohl insis...

WinScanX : A Simple, Fast and Portable Windows Auditing Tool

Hình ảnh
WinScanX is a state-of-the-art Windows auditing tool designed to help you get your Windows audit done quickly. It's easy to use and no installation is required.   WinScanX was released recently and its the one of the best resource released in 2009 . Its Fast, Simple, Portable and efficient tool for every security professional out there. Its really pa state of art tool.     WindScanX is released in two versions, one which is free to download and use and have some features in it which includes the GUI Front-End, Command-Line Interface, Easy-to-Use Reporting, Online Documentation etc and the other PRO version includes these and Quick Domain Audit, Multi-Host Scanning.     Download WinScanX here                                          WinScanX Scre...

Total Round Up For "Top 10 Sexy Hackers of 2009"

Hình ảnh
Well many of the guys have already guessed and made the list of the sexiest hackers in the world and i also know i am pretty late in this news but i know what made this more special is that many were satisfied and many infosec geek s wasn't. So i just thought to make a whole roundup of the lists.   1. Violet Blue ’s list of the Top 10 Sexy Geeks . 2. Michael Dahn 's list of Top 10 Sexy Infosec Geeks of 2009 .   The long hour discussion nearly took down twitter for about an hour. Surely i wasn't in the list :( and see you should i always respect your seniors decisions and that's what i am doing.   People Who Made The Hackers Choices : 20.  Tammer Saleh 19.  Crystal Williams 18.   Brady Forrest 17.  Amanda Coolong 16 .  Sirus ... 15.  Jack Dan8iel 14.   Angela Natividad 13.   Jacob Appelbaum 12.  Paul Carr 11.   Christopher Hoff 10.  Jeff Moss (Dark Tangent) 9.   Gia...

Christmas Present For Hackers [Pic]

Hình ảnh
This is just a nice Christmas present that my friend ophelia want this Christmas. May she get this gift. I was just thinking what if Santa Clause was a hacker. Ok Get the Santa here !! :D Happy Christmas @hackerthedude Image Credit : ophelia

Net Wars : New Challenge For Hackers [Video]

Hình ảnh
Net Wars are a new talent hunt for hackers that are good in hacking field and if they win they are given a job of ethical hacking. or if they not they can even get a handful of contacts and goodies too.   Some days ago CNN covered the story of this challenge which is currently taking place in U.S. These challenges are taken under by SANS : The most trusted source for computer security ... Ya we all know the big SANS . if u dont know who are sans, its a organization of high end ethical hacking teachers and they provide some qualifications in US for ethical Hacking... The United States Cyber Challenge A national competition and talent search to find and develop 10,000 cyber security specialists to help the United States regain the lead in cyberspace [ 5/8/09 ]. The web pages for the US Cyber Challenge will be posted on May 29 at www.sans.org/uscc and at other sites. To learn more about the program prior to May 29, email USCC@sans.org 1.The Need 2.The Competi...

FBI Is Watching You : Now On Facebook, Twitter, Youtube and More

Hình ảnh
Ok did anybody told FBI about Privacy stuff that we need to live on this planet Earth full of some officers who just want to piss of Hackers .   Ya, Its FBI they are taking a new strategy focusing on the social media for spreading the Information or something whatever in their mind. Here is what they say : "Over the past few years we’ve rolled out a number of new web initiatives—including an e-mail alert service , syndicated news feeds, and a series of podcasts and widgets—that make it easier for you to help us track down wanted fugitives and missing kids, to submit tips on terrorism and crime , and to get our latest news and information." We are moving forward on other social media fronts as well. Where is FBI Till Now : Facebook , where you can follow our news, check out our photos and videos, and become a “fan” of the FBI; YouTube , where you can watch our videos and connect back to our main website for job postings and other content; and Twitter , where you c...

Process Hacker V1.9 Released

Hình ảnh
Process Hacker is a great tool or you can say a piece of software which acts as a more advance and more reliable software in front of default task manager. it creates a more detailed and a more understandable version of task manager .   You may remember we have earlier featured it in Process Hacker : Power Packed Task Manager , ok i know the spelling is wrong but don't worry about that we all are humans except the Google bot here :D.   Lets move on with Process Hacker, recently the people behind this software released the new Version of Process Hacker V1.9...   New Stuff : Ability to set I/O priority for processes and threads No more separate Assistant.exe executable required Signature verification now works on x64 Now shows signer names (plus a Verified Signer column) Added proper x64 support to structs reader Added basic preprocessor to structs reader WOW64 modules now appear in Handle/DLL searches Small performance i...

AWeber Hacked : Recent Data Compromise

Hình ảnh
We just in a split second got news, The great and most popular email subscription and rss manager for Wordpress have been hacked. The recent reports says that they have been hacked by some kind of Third-party Software which they use.   The general meaning of this would be the code would be hidden in the app they would be using their systems which took the ownage of there API might be. We are not sure till yet.   It could be Local Buffer overflow on that third party software which they were using. The Apparent effects of this hack was that many spam email message were send to the subscribers. Here is the list of the things which were NOT compromised and are saved by the team. AWeber customers’ personal information was not compromised. No credit card data was compromised. No customers’ names, “from” or contact email addresses, postal addresses, website URLs or any other profile information were compromised. No affiliates’ names, contact email addr...

RSnake's 2nd Take On DNS Rebinding

Hình ảnh
Robert Hansen aka RSnake the father of Xss is back with a bang. With his latest research on DNS rebinding hacking which he also explained with a Video but he is all set to remove this DNS rebinding from the world.   RSnake released a new podcast on DNS Rebinding after his previous release of video on it. Its a pretty good news that somebody is caring about the DNS hacking techniques as one we saw a couple of days ago Twitter was hacked , with some DNS resolution problems.   You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.   Dennis Fisher talks with security researcher Robert “Rsnake” Hansen about his recent work on DNS rebinding attacks, the poor state of browser security and his new book “Detecting Malice.” ..   *Podcast audio courtesy of sykboy65 Subscribe to the Digital Undergroun...

Finding IP address in Gmail From Email Header's

Hình ảnh
Email headers determine where a message is sent, and records the specific path the message follows as it passes through each mail server.   When You send an email to any of your friends or others could be your Girl friends Never mind. But When you send the email through any email client like Gmail , Yahoo Mail , Hotmail, AOL, Outlook Express, etc it also sends the Email Header which contains Some important information for Us i.e.Hackers.   Basically it is a feature of Mailing protocol. Now when the victim sends you a Email through any , Gmail, Yahoo mail etc doesn't matter, then mail comes to your inbox in the form of Email Header but the your Email client changes it and shows only readable part of it.   Well This article is based on how to view Email headers in Gmail . We Will talk about others in Future too. Yeah its a kind of easy tutorial....   Finding IP address in Gmail Login to your Gmail account with your username and password. ...

The Top Targeted Brands Of 2009 [Pic]

Hình ảnh
The Year 2009 is almost over and as we noted the whole year 2009 Is The Year Of Biggest Data Breach's Ever Says Forbes and The Years Biggest Security Breach for the year 2009, But the question which exhibits now is, which were the most targeted brands of this year 2009.   The Avira Tech Blog have released a new report based on there attacks by the cybercriminals. Which consist of the mostly targeted websites of 2009 and which might be in 2010.   *Click on the image to View Full size Well with dawn of 2009, some most vulnerably websites from the forefront of hackers are Paypal , Chase Bank , Ebay , American Bank … after 3 more there is facebook . Yeah !, you are right ..   In December, the situation was changed: Now PayPal is the most phished brand (32205 unique URLs) followed from far away by the Chase Bank (25901 unique URLs) and Ebay (18738 unique URLs).   The Most Top Targeted brands are no other then Banks and some social media servic...

Bootkit : One Deadly Weapon In The Attacker Arsenal

Hình ảnh
There was a great presentation at BlackHat about Bootkit . Which is simply a rootkit being loaded from the MBR before the system starts.     This could be use to defeat full drive encryption where the system would be infected after it boot. Below you have a copy of the main page of the http://www.stoned-vienna.com/ web site with tons of great information on the subject: Stoned Bootkit Stoned Bootkit is a new Windows bootkit which attacks all Windows versions from XP up to 7. It is loaded before Windows starts and is memory resident up to the Windows kernel. Thus Stoned gains access to the entire system.   It has exciting features like integrated file system drivers, automatic Windows pwning, plugins, boot applications and much much more. The project is partly published as open source under the European Union Public License. Like in 1987 , 'Your PC is now Stoned! ..again'…. Peter Kleissner, Software Dev. Guru in Vienna Your PC is now Stoned! ..again; Some links...

Is Google Public DNS Safe ?

Hình ảnh
Is Google's new Public DNS server safe? Google opened their new DNS service to the public. Google's strategy appears to be an attempt to compete with the popular free service called OpenDNS .   In light of the ongoing slaught of DDOS attacks on sites such as Facebook and under 48 hours ago, Twitter, the infosec industry is (and they should be) concerned about Google's DNS vulnerability.   So far, as this like below documents, the relatively small amount of research that has been done suggests that Google's port usage is sufficiently randomized so as to reduce the risk of an attack…. My opinion on this though? It most definitely will be some hacker's gold star target due to the fact that Google is getting a lot of press right now. However, you would have to be totally and completely brain dead/flatlining to attempt to crack this honeypot right now. But, hey, that's why we all love dumb criminals - they have high entertainment val...

New Html 5 XSS Vector’s By Gareth Heyes

Hình ảnh
Gareth Heyes is a great security guy, as you can also visit his blog The Spanner . The newly released HTML 5 is now under the eyes of hackers and it wasn't late that the New Xss vectors have been released by Gareth Heyes .     These New Xss vectors according to Gareth are automatic in major Web Browsers from Safari, Chrome to Opera all support them. And its a matter of fact that Gareth also featured them on twitter too.   The injection looks something like:- <input type="text" USER_INPUT>   The new HTML 5 works on some other vectors and uses, but the great thing in there is that you don't need to bind your Xss into a css style in here. HTML5 however lets us execute like expressions but without css styles….   For example:-   <input type="text" AUTOFOCUS onfocus=alert(1)>   We use the “autofocus” feature to focus our element and then the onfocus event to execute our XSS. This works w...

Keep Your Encrypted Notes Safe With Fsekrit

Hình ảnh
fSekrit is a small application for keeping encrypted notes.   This software is a good tool to keep Your encrypted codes or even data safe, from any external usage.   The great note about this great tool is that its a really small utility, it portable , that means you can keep it in your pen drive and take it with you to any other place.   Another advantage of using fSekrit is that your un-encrypted data is never stored on your hard disk .   With a traditional encryption utility you would have to decrypt your file to disk, view or edit it, and then re-encrypt it, and unless you use secure file wiping tools, it would be a trivial matter for someone to to retrieve your un-encrypted data, even though you have deleted it…   This can't be done with fSekrit , though, since it never stores your un-encrypted data on disk. fSekrit uses very strong encryption ( 256-bit AES/Rijndael in CBC mode ) to ensure that your data is never at risk. Self contai...

The Anatomy of the Twitter Hack - Twitter's DNS Servers Hacked Yet Again Last Night

Hình ảnh
  ~ via Tech Crunch During and after Twittergate , when a hacker broke into a few hosted email accounts and obtained a number of internal documents, I had an opportunity to spend hours speaking to the actual attacker and document how he carried out the attack. The article was called The Anatomy of The Twitter Attack, and today we unfortunately find ourselves with a sequel to that post as the Twitter DNS servers were compromised last night and the site was redirected to a defacement page. Unlike last time, on this occasion I have not had the benefit of speaking directly to the attackers, but have spoken to a number of people within the underground security scene familiar with matters and have constructed other parts of the story from public sources .  The incident last night was perpetrated by a group called the Iranian Cyber Army – and we have been told that this group is working with the Iranian government... The attack occurred at the same time as a number of other diplom...

Wireshark v1.2.5 Released

Hình ảnh
Wireshark is the world's foremost network protocol analyzer, and is the standard across many industries and educational institutions for security stuff. Wireshark is the world’s most popular network protocol analyzer.   It has a rich and powerful feature set and runs on most computing platforms including Windows, OS X, Linux, and UNIX . Network professionals, security experts, developers, and educators around the world use it regularly.   It is freely available as open source , and is released under the GNU General Public License version 2 Wireshark uses pcap to capture packets from supported protocols. Data can be captured "from the wire" from a live network connection or read from a file that records the already-captured packets. Live data can be read from a number of types of network, including Ethernet, IEEE 802.11, PPP, and loop-back. Captured network data can be browsed via a GUI , or via the terminal (command line) version of the util...

30 Million Facebook, MySpace, and Orkut ID’s Hacked

Hình ảnh
Hackers Have crossed the security boundaries of a widget and multi-social networking based company RockYou.com which host many users from some famous social networking websites such as MySpace, Face book and Orkut.etc With this Hack over 30 Million users have been affected.   The most troubling aspect of this incident is that RockYou apparently stored the information in plain text, rather than following industry standards by encrypting it. The hackers have claimed also that they have hacked the whole Database full of Usernames and  passwords and some private information as well.   Hacker appears to be forcing RockYou to admit to certain vulnerabilities in its data security. "Don't lie to your customers, or I will publish everything" The hacker wrote as an obvious reprimand to Rock You. This seems to be strong words which hacker said in reply to company officials in terms to the matter of encryption. The RockYou is pretty upset it a...

Hackers Slays Microsoft’s Forensics Toolkit

Hình ảnh
Ok this is kind of good news for all of us. The Well Know Tool For Law Enforces Used ,Not Mostly, Microsoft-packaged forensic toolkit is now attackable.   The Tool is used by Law Enforcement agencies to keep a track on a computer of a hacker. But the great thing the Twist here is that a hacker or might be a group of hackers had worked hard on this tool to crack it down.   They were successful with a crack they built named DECAF . Its good to see here in this whole matter is that how the government use such a piece of crap that was cracked.   They should had made their own tool for the forensic usage and does not rely on the software which combines a suite of 150 bundled scripts , piled in one single script.   The tools scan files and gather information about activities performed on the machine, such as where the user surfed on the internet or what files were downloaded…   Someone submitted the COFEE suite to the whistleblower site Cr...

Torpig Domain Generator : Hackers Using Twitter Trending Topics

Hình ảnh
Torpig botnet uses Twitter API (trends) to generate new pseudo-random domain names of attack sites where infected websites silently redirect visitors to. Active domain names change at least twice a day. This real-time tool generates a domain name of the currently active attack site and two domain names that hackers should activate in upcoming 24 hours.   This tool is a initiative by a hacker Denis or you can say a security guy. The tool uses JavaScript and Twitters API to find a domain for attacking using the twitters Trending topics. Well its big hole in the whole twitter’s API and the way this tool have predicted the domain names are right one so far. Its now the all up to the twitter API developers hand…   What is Torpig Botnet Botnets , networks of malware-infected machines that are controlled by an adversary, are the root cause of a large number of security threats on the Internet.   A particularly sophisticated and insidious type of bot is ...