Showing posts with label Google. Show all posts
Showing posts with label Google. Show all posts

Monday, 23 January 2012

Phishing Google Users with the Help of Google !



Phishing+Google+Users+with+the+Help+of+Google+%2521

How Hackers are phishing Gmail/Google users successfully ? Christy Philip Mathew, an Information Security Instructor from India shared a perfect trick with us. He just exploit human psychology. Lets see how:

He Created a phishing Page of Google and Uploaded to : http://www.keepbacktrack.net84.net/ . Now How to make this URL legit for Victims ? Simple, Using Google translation Tool.

Google translation has got a vulnerability that if an attacker plan out translating a fake gmail login page he would get a perfectly crafted link that can be used for malicious purposes or Phishing. Above Shown Image the example of this Trick. New Phishing URL is Here after using Translation tool. This is Art of psychological manipulation using Google to Hack Google Users.
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Monday, 16 January 2012

Angry Birds[FAKE] Game spreading Malware from Android Market



From last week premium rate SMS Trojans surfaced in the Android Market. Google has pulled 22 apps that are masquerading as legitimate versions of popular games like Angry Birds and Cut the Rope. Security researchers have discovered a way to bypass an Android smartphone owner's permissions and access private data stored on their smartphone.

Avast Blog explain this as - For example, if someone tried to look for “Cut the rope free”, this malicious application was in the fourth place in the search results. Apps published by the developer Miriada Production may look like well known Android games (Angry birds, Need for speed, World of Goo and others) and users could be easily confused. 

The fake apps include "Cut the Rope", "Need for Speed", "Assassins Creed", "Where's My Water? ","Riptide GP", "Great Little War Game", "World of Goo", "Angry Birds", "Shoot The Birds", "Talking Tom Cat 2", "Bag It!" and "Talking Larry the Bird". The apps have been pulled from the Android Market.

The fraudulent apps would install a premium rate SMS Trojan that would rack up hidden charges on the user's phone bill. The apps would lure customers into clicking on options that would send text messages to premium line numbers leaving the user to foot the bill. According to Lookout Mobile Security, the new threat called RuFraud has been found in an initial batch of apps on the Android Market that include horoscope apps, wallpapers, and game apps that pretend to be legitimate games like Angry Birds.

What will happens if these threats are installed in your mobile devices? 
It will attempts to send text messages containing the string “798657” to premium-rate numbers using the infected device’s current default SMS Center (SMSC) by exploiting the Permissions function (android.permission.SEND_SMS), Capable of sending an affected user’s GPS location via HTTP POST, Opens several ports and connects to specific URLs to receive and execute commands from a remote user, Gathers information like International Mobile Equipment Identity (IMEI) and International Mobile Subscriber Identity (IMSI) numbers from infected systems, which is then sent to a specific site and Secretly forwards all incoming text messages to a remote user.

How do users get these threats?
Trend Micro has reported several incidents wherein malware came disguised as Android apps. Samples of Android malware found in the wild include:
  • ANDROIDOS_DROIDSMS.A: Came disguised as Windows Media Player.
  • ANDROIDOS_DROISNAKE.A: Came in the form of a game known as Tap Snake.
  • ANDROIDOS_GEINIMI.A: Came in the form of Trojanized apps hosted in certain third-party app stores in China.
  • ANDROIDOS_ADRD.A: Comes in the form of a Trojanized wallpaper app.
  • ANDROIDOS_LOTOOR.A: Trend Micro’s detection for Trojanized versions of legitimate apps like “Falling Down”.
  • ANDROIDOS_BGSERV.A: Trojanized version of Android Market Security Tool, which was released to address the modifications done by AndroidOS_LOTOOR.A.
Trend Micro Suggest "Users can also check the developer’s profile for other apps. Google also offers developer ratings, as well as the status 'Editor’s Choice' that can further validate the developer’s legitimacy. It is also a good practice to check app ratings and user feedback for more verification. The user rating and feedback feature give people a more accurate view of the experiences users have when using or installing the app. You can find it just below the app icon.,".
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Sunday, 15 January 2012

URL redirection Vulnerability in Google & Facebook




An open redirect is a vulnerability that exists when a script allows redirectionto an external site by directly calling a specific URL in an unfiltered,unmanaged fashion, which could be used to redirect victims to unintended,malicious web sites. A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect.

A similar vulnerability is reported in Google by "Ucha Gobejishvili ( longrifle0x )". This problem may assist an attacker to conduct phishing attacks, trojan distribution, spammers.
Url: https://accounts.google.com/o/oauth2/auth?redirect_uri=http://www.something.com

Same vulnerability in Facebook, Discovered by ZeRtOx from Devitel group:
http://www.facebook.com/l.php?h=5AQH8ROsPAQEOTSTw7sgoW1LhviRUBr6iFCcj4C8YmUcC8A&u=www.something.com


Impact of Vulnerability  :
  • The user may be redirected to an untrusted page that contains malware which may then compromise the user's machine. This will expose the user to extensive risk and the user's interaction with the web server may also be compromised if the malware conducts keylogging or other attacks that steal credentials, personally identifiable information (PII), or other important data.
  • The user may be subjected to phishing attacks by being redirected to an untrusted page. The phishing attack may point to an attacker controlled web page that appears to be a trusted web site. The phishers may then steal the user's credentials and then use these credentials to access the legitimate web site.
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Thursday, 5 January 2012

22k Youtube Related Accounts Hacked


EazySubs, known for it's "sub4sub" service offering youtube users to gain subscribers has been hacked by security researcher "Dan" from Team Intra.

Eazysubs has more than 22k active members, and most of which have linked to a youtube account, twitter account or facebook account.

The hacker who also goes by the name "Dan" has made a small leak, proving that he does have access to the accounts. This can be found at - http://pastebin.com/pBJD90UN

The leak contains username and encrypted passwords.


Dan has contacted the owner of eazysubs, and claims that the vulnerability stood within simple remote SQL Injection. The owner has not responded.
 He also claims to have access to the userlist of sites - http://socialjumbo.com , containing 6000+ users, with linked facebook/twitters. and http://socialclump.com with more linked facebook and twitters.
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Saturday, 3 December 2011

Blog Import News !


I have decided to import my old news blog 'TECHPANELS' to 'Code104' So don't be shocked if you get more than 400+ posts in a minute !
I am doing this to add old news also in this blog, if someone searches for it on google then we can be indexed !
No more info about this IMPORTATION !
Thank you 
Regards
Team Code104
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Saturday, 19 November 2011

Google's 'Google Chrome' Security Hole 15 Patched


Vulnerability found in the last release of one of the most popular web-browser Google Chrome 15.0.874.121. The vulnerability contains to address a high-risk out-of-bounds write vulnerability in the V8 JavaScript engine. As part of its Chromium Security Rewards programme, Google paid security researcher Christian Holler $1,000 for discovering and reporting the hole. Additional details of the vulnerability are being withheld until "a majority of users are up-to-date with the fix". The maintenance and security update to the WebKit-based browser also upgrades the V8 engine to version 3.5.10.24 and fixes a regression related to SVG in iframes.

To Download Google Chrome For Linux, Windows & Mac Click 

Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Monday, 7 November 2011

Google Low Security Xss Bug Found by Kyle Osborne

Security Researcher Kyle osborne found a xss low security bug in Google Map.  he disclosed iframe can be injected in Send Mail Header through Google map. if user open this infected email his Email database or his personal info can be compromised . he submitted this vulnerability to Google Expert Team. You can see the out put that  vulnerability Here : 
Status: Unknown
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Related Posts Plugin for WordPress, Blogger...
Back to TOP