Showing posts with label Security News. Show all posts
Showing posts with label Security News. Show all posts

Wednesday, 25 April 2012

Facebook Offers free Antivirus Service to protect their users at AV Market Place

The social networking giant, Facebook announced its partnership with a number of security vendors to protect its users from spam and malicious content.

Facebook teams up with Microsoft, McAfee, TrendMicro, Sophos, and Symantec and launched the Antivirus Marketplace where facebook users can download Antivirus softwares for free.

The Antivirus Marketplace offers the following software for download: McAfee Internet Security (PC), Microsoft Security Essentials (PC), Norton Antivirus (PC and Mac), Trend Micro (PC and Mac), and Sophos Antivirus (Mac). Six months of free updates are included with each download, but users are limited to just one free antivirus application per Facebook account.

Download your favorite Antivirus software for free of cost from here:
http://on.fb.me/FBAVMarketplace

We are thankful to Facebook for providing protection against spam and malwares.
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

VMWare Source Code Leaked by Anonymous Hackers


VMware on Tuesday announced that a single file from its ESX server hypervisor source code has been posted online, and it held out the possibility that more proprietary files could be leaked in the future. "The fact that the source code may have been publicly shared does not necessarily mean that there is any increased risk to VMware customers," VMware said in a statement.

"Hardcore Charlie" - who claims to have downloaded some 300 Megabytes of VMWare source code.

Anonymous tweeted:
@AnonymousIRC: Oops, VMWare source leaked? Not good http://pastebin.com/JGxdK6vw to Anonymous contributors. May the Pirate Bay always sail strong!
The leaked documents include what appear to be internal VMWare communications, pasted onto CEIEC letterhead and with official looking stamps. One email exchange, dated June 5, 2003 is from Jeffrey Sheldon to an internal VMWare listserv and has the subject "code review:untruncating segments.

Given the large number of service providers that run vSphere, security issues in ESX could potentially have a broad and widespread impact, according to security researchers. VMware says it is looking into the matter and will be canvassing its industry partners and developers in order to determine the source of the breach.
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Saturday, 28 January 2012

Universal Music Portugal Hacked and Database Dumped

 
 
 
 
 
 
 
 
Another Latest Tip come in my Inbox today about the leak of Database of Universal Music Portugal's website. Hacker did not mention his name,or Codename, But he enumerate the Database and Extract it by Hacking the Site.

100's of Tables from Database and Users Data has been leaked via a pastebin File. It includes the Usernames, Passwords and Emails ID's of Users of Site.

Immediate after the Hack, The Universal Group taken down the site for maintenance.
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

FBI will Monitor Social Media using Crawl Application

FBI+will+Monitor+Social+Media+using+Crawl+Application



The Federal Bureau of Investigation is looking for a better way to spy on Facebook and Twitter users. The Bureau is asking companies to build software that can effectively scan social media online for significant words, phrases and behavior so that agents can respond.A paper posted on the FBI website asks for companies to build programs that will map sentiment and wrongdoing.

The application must be infinitely flexible and have the ability to adapt quickly to changing threats to maintain the strategic and tactical advantage,” the Request for Information said, “The purpose of this effort is to meet the outlined objectives…for the enhancement [of] FBI SOIC’s overall situation awareness and improved strategic decision making.”The tool would be used in “reconnaisance and surveillance missions, National Special Security Events (NSS) planning, NSSE operations, SOIC operations, counter intelligence, terrorism, and more.

Although the police, including in Britain, already use Facebook routinely to ascertain the whereabouts of criminals, automatically filtering out irrelevant information remains challenging. The new FBI application will be able to automatically highlight the most relevant information. The FBI is seeking responses by 10 February.
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

XSS Vulnerability in Bloggers.com













Hacker Group "GodOfHackers" discovered XSS[Cross site scripting] security flaw in one of high profile site bloggers.com. Bloggers.com is one of best bloggers community , it will help to know the best bloggers around the world, discover them and connect yourself with this friendly bloggers community. It has Alexa Rank 3,519.

Vulnerability Details:

    Type: Non-Persistent XSS
    Alert-Level: Medium
    Author: GodOfHackers
    Vulnerable Link: http://bloggers.com/topics/


Proof of Concept :-

http://bloggers.com/topics/%3Cscript%3Ealert%28%22XSS+By+GOH%22%29%3C%2Fscript%3E
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Anonymous threatened to Shutdown CNN.com - #OpDebateBlackout













The protest against Internet censorship by Anonymous continues. Now they have called another operation named #OpDebateBlackout. According to a YouTube video Anon vows to shutdown famous media CNN during yesterday night debate.
Anon said:- 
"Shut down CNN.com during the Florida debate. In response to the establishment media blackout of Ron Paul, and specifically to the lack of equal time given to him in the debates, we the people will be blacking out the responses of all candidates except Ron Paul in the upcoming CNN debate in Jacksonville Florida on Thursday, January 26 at 8PM eastern standard time. This is a call to all who are willing and able to join this effort to show the establishment media that we will not tolerate the continued media blackout of Ron Paul, and that we will, in return, shut down the cnn website and their live stream of the debate."

Video Released by Anonymous :-





Earlier for #SOPAblackout issue anon has performed massive cyber attack. And also for #OpMegaupload they have bring down Federal Authorities, US Govt, Brazil Govt, Ireland's Dept of Finance & Justice, CBS TV Network, UFC.com and many more. We would also like to give you reminder that this is not the first time earlier Anon also threatened another media (FOX News) in the #OpFoxHunt.
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

XSS Vulnerability found in Photobucket






XSS [cross site scripting] vulnerability found in photobucket.com by God Of Hackers the Hacker group n0caReTeAm also found a xss vulnerability in photobucket.com . It seems to be two vulnerabilities are same

Here is the vulnerable link found by GodofHackers:
http://media.photobucket.com/image/hacker/ahsanulkarim/Tech%20Zons/wordpress-hacked-290x160.jpg?o=%22%3E%3Cscript%3Ealert%28%22XSS%20By%20GOH%22%29%3C/script%3E
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Thursday, 26 January 2012

Ghana Bank Websites hacked and Database leaked by SEPO








Hacker anon_4freedom continue their cyber attack on Ghana ,recently they break into the Commercial Bank of Ethiopia website and leaked the database. He focused on Ghana's bank website , for the last four days he hacked around five bank websites. Also he hacked FidelityBank Ghana, UT Bank and dumped the database in his own blog.

"It is very important, becouse other admins read all of this and they understand that everything in the internet can be hacked" Hacker said

The following bank sites are hacked:
http://www.utbankghana.com/
http://www.combanketh.com/
http://www.fidelitybank.com.gh/

The dumped database belong to Commercial Bank of Ethiopia contains the username, encrypted password ,email id and user role.

The dumped database belong to UT Bank contains the the admin userid, encrypted password and email id .

The dumped database belong to UT Bank contains the user countr, phone number and other details.

    The Commercial Bank of Ethiopia (CBE) is the largest commercial bank in Ethiopia and had about Birr 73.7 billion (US$4.45 billion), in assets at the end of June 2010. At the time, the bank held approximately 63.5% of deposits and about 38% of all bank loans in the country. The bank has about 9, 000 employees who staff the headquarters and 301 branches positioned in the main cities and regional towns, including 45 branches in Addis Ababa. CBE recently opened new branches in the remote towns of Injibara and Humera.

    UT Bank Ghana Limited, commonly known as UT Bank (UTB), is a commercial bank inGhana. As of February 2011, the bank is one of twenty-seven (27) licensed commercial banks in Ghana.
    UTB is a medium-sized financial services provider headquartered in Ghana with subsidiaries inwest Africa and Western Europe. The bank's total assets in December 2009 were valued at nearly US$140 million, with shareholders' equity of approximately US$15 million.
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Wednesday, 25 January 2012

#OPMegaupload - OnGuardOnline.gov Hacked by Antisec













Hackers under auspices of the AntiSec group claimed responsibility for hacking OnGuardOnline.gov, the U.S. federal government's online security website, in protest of various internet-related legislation including ACTA, SOPA and PIPA. OnGuardOnline.gov is managed by the U.S. Federal Trade Commission (FTC) in cooperation with 14 other agencies.
In a message left on the OnGuardOnline website and on Pastebin, hackers threatened to continue "a relentless war against the corporate internet", and promised to destroy "dozens upon dozens" of government and corporate websites, if the aforementioned legislation are made into law.
Much like Anonymous’s actions against Polish government websites hacked over the weekend, the group promised to release sensitive data including emails, passwords, bank accounts, and other information from hacked websites.
"We are sitting on hundreds of rooted servers getting ready to drop all your mysql dumps and mail spools," the Anonymous-affiliated hacker group said.
The FTC did not comment on the attack.

Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Tuesday, 24 January 2012

Imagedoll.com Hacked & 1300 + User info leaked by aKfortyseven










After Many days Indian hacker named akfortyseven from League of Assassins [Code104] pawned a website and leaked more than 1300 user data of website ! This effected the users also ! , passwords that are leaked from Imagedoll.com might be similar to the passwords of their other accounts on Facebook, G-mail etc. !We can say that From 1300 users almost 40% of them have the same passwords !

Hacker says that he leaked the passwords using SQLi Vulnerability he found  in that website. 

Imagedoll is a Image hosting website used by many users to upload images, and its having a Alexa World Wide Rank is 610,758 & Google Pagerank -2 . It is a High profile website.

He leaked user details in a pastehtml release !
Here it is :- http://pastehtml.com/view/bltmj993d.html

Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Tor Vulnerable to Remote arbitrary code Execution


Tor+Vulnerable+to+Remote+arbitrary+code+Execution


According to latest post of Gentoo Linux Security Advisory, There are multiple vulnerabilities have been found in TOR, the most severe ofwhich may allow a remote attacker to execute arbitrary code. TOR is an implementation of second generation Onion Routing, a connection-oriented anonymizing communication service.

Using this Vulnerability remote attacker could possibly execute arbitrary code or cause a Denial of Service. Furthermore, a remote relay the user is directly connected to may be able to disclose anonymous information about that user or enumerate bridges in the user's connection.

Advisory explain that , Affected Vulnerable packages are < 0.2.2.35 . Multiple vulnerabilities have been discovered in Tor are listed below:

* When configured as client or bridge, Tor uses the same TLS certificate chain for all outgoing connections (CVE-2011-2768).
* When configured as a bridge, Tor relays can distinguish incoming bridge connections from client connections (CVE-2011-2769).
* An error in or/buffers.c could result in a heap-based buffer overflow (CVE-2011-2778).

All Tor users should upgrade to the latest version.
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Zone-H server rooted and Website hacked !



Zone-H, the Biggest mirror site that hosts hacked sites' defacement mirror, hacked.  by HcJ & Cyb3R-1sT & Egyptian.H4x0rZ & Sas-TerrOrisT & H311 c0d3.
 The defacement page is still there. This is interesting hacking news, a defacement hosting server hacked by Hackers.

The mirror can be found here:

http://legend-h.org/mirror/317627/zone-h.com/


Hacker Message:

    To be OR not TO be

    Note : It's Unacceptable when we tried to notify defaced.zone-h.net and found tNote : It's Unacceptable when we tried to notify defaced.zone-h.net and found this message " nice try" it's not a try it's a real! your server rooted, all the websites hacked, all people knew that ! and it's the third time to hack your websites 2 of them in 2010( 2010/04/02 > brazilian domains + 06/2010 zone-h.com defacement database ),and now ! you should have the courage and allow the defacers to notify your sites, it's the real courage !
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Monday, 23 January 2012

Phishing Google Users with the Help of Google !



Phishing+Google+Users+with+the+Help+of+Google+%2521

How Hackers are phishing Gmail/Google users successfully ? Christy Philip Mathew, an Information Security Instructor from India shared a perfect trick with us. He just exploit human psychology. Lets see how:

He Created a phishing Page of Google and Uploaded to : http://www.keepbacktrack.net84.net/ . Now How to make this URL legit for Victims ? Simple, Using Google translation Tool.

Google translation has got a vulnerability that if an attacker plan out translating a fake gmail login page he would get a perfectly crafted link that can be used for malicious purposes or Phishing. Above Shown Image the example of this Trick. New Phishing URL is Here after using Translation tool. This is Art of psychological manipulation using Google to Hack Google Users.
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Panasonic China website hacked and Redirected



Panasonic+China

Latest notification by DarkDevilz Crew to THN , They hack Panasonic's China websites and Redirect users to a Black color Deface Page as shown. "3spi0n" named Hacker from team take responsibility to perform this Hack.

Hacker compromise the URL : http://pro2.panasonic.cn/autodoor/ , and add Refresh Meta tag in source code to redirect the page to a new location i.e. http://www.kutanhosting.com/r3.html .
hacked
Mirror of Hack is also available, in case Site fixed before you see this , here : Mirror 1 & Mirror 2
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

#OPMegaupload :- CBS Broadcasting Hacked by Anonymous Hackers



CBS+Broadcasting+Hacked

Anonymous Hackers are claiming to Hack the official website of CBS Broadcasting (CBS), major US commercial broadcasting television network, which started as a radio network.

Hacker hack the server , entire web directory has been deleted and There is only a Single blank file named "foundry.html" as shown.
CBS+hacked

Even Brazil also Under Anonymous Attack, Today Tangara da Serra city site also defaced by them. Get update about all Anonymous Hacks Here.
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Sunday, 22 January 2012

"Rock Paper Shotgun(RPS)" popular gaming Forum hacked


Rock Paper Shotgun (RPS), a popular gaming site's server hacked. RPS is notifying their customers about the attack via email.

According to their notification, Hackers break into their server on Jan 14 and gained access to server for five days. Researchers are not sure whether hackers compromised the user details or not.

If they got to those files, they will have got customer's emails, usernames, and encrypted passwords. Though the passwords are encrypted, hackers are able to break the hash codes.  So users recommends to change their passwords immediately.  If you use the same password anywhere else, change the password for them also.

    "We're tremendously sorry. We learned about the attack on Thursday afternoon, and the tech people at Positive closed it off immediately, and have been sorting it out since, working out what they could have found. We learned the information reported above this evening, and have told you as quickly as we can." said in their report.
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Saturday, 21 January 2012

DreamHost Hacked - Change Your Passwords Now !


DreamHost+Hacked+-+Change+Your+Passwords+Now

All Dreamhost customers should read this post immediately and change all related passwords (including WordPress ones). Dreamhost said "Last night we detected some unauthorized activity within one of our databases." They say there's "no evidence that customer passwords were taken", but they''re pushing out password changes to everyone just to be safe. In addition, you should change any of your other passwords just to be safe that is, if they're at all similar to your DreamHost password. 

To edit your password in the panel, please log into the web panel and go to Manage Users. Click edit next to the FTP/shell user on the right and you can change your password there. 

This is the second time within week, when hackers targeted to these big websites, Dreamhost don’t give any clue of the hack.
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Tuesday, 17 January 2012

Sophos explains how five members of the Koobface malware gang were unmasked


Facebook is making public Identity of Five people who responsible for spreading the notorious Koobface worm on social networks and earned millions of dollars.

The five men are named as Anton Korotchenko, Alexander Koltyshev,Roman Koturbach, Syvatoslav Polinchuk, and Stanislav Avdeiko, and are said to be involved in the Koobface malware gang.

Sophos explains how these individuals were identified as part of the Koobface gang, in a detailed investigation conducted by independent researcher Jan Drömer, and Dirk Kollberg of SophosLabs between early October 2009 and February 2010.




About Koobface worm:
Koobface is a computer worm which spreads via social networking sites.Koobface knows how to create itsown social networking accounts so that it can aggressively post links helping it to spread further.

Infection: The most common infection method is through a fake video player.
If you click on one of the links which Koobface has posted on-line, you’ll end up at a web page – typically a fake YouTube orFacebook Video page – pretending to offer you a clip to watch. But first, claims the web page, you need a Flash update.
The video player update is as fake as the web page: it’s actually just an installer for the Koobface virus
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Zappos.com Server Breached, 24 Million customer data compromised !


Hackers breached Zappos.com server(Kentucky server) and compromised 24 million customer data , the shoe-and-apparel-selling division of Amazon. Tony Hsieh , the CEO of Zappos.com informed about the cyber attack via mail.

According to Zappos report, the following details may compromised: your name, e-mail address, billing and shipping addresses, phone number, the last four digits of your credit card number (the standard information you find on receipts), and/or your encrypted password (but not your actual password).

Zappos said that critical credit card and other payment data was not compromised. Zappos recommends all user to change their passwords,also they reset/expired their old passwords.

"We've spent over 12 years building our reputation, brand and trust with our customers," Tony Hsieh said. "It's painful to see us take so many steps back due to a single incident."
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Monday, 16 January 2012

Hacker will release full Norton Antivirus code on Tuesday






A hacker with code name of 'Yama Tough' announce via Twitter that on Tuesday he will leak the full source code for Symantec Corp's flagship Norton Antivirus software which is 1,7Gb src.

Last week Yama Tough has released fragments of source code from Symantec products along with a cache of emails. The hacker says all the data was taken from Indian government servers. Yama Tough is trying to prove that Indian government was snooping on America and China.

YamaTough said via Twitter "Pass it on to forensics and win the lawsuit,".He has offered support to an American man who filed a lawsuit against Symantec Corp by publishing source code from a 2006 version of Norton Utilities, a software program at the heart of the legal dispute. It was not immediately clear how the source code might help the case.

A Symantec spokesperson commented on the incident:
"We are still gathering information on the details and are not in a position to provide specifics on the third party involved. Presently, we have no indication that the code disclosure impacts the functionality or security of Symantec’s solutions. Furthermore, there are no indications that customer information has been impacted or exposed at this time."

Symantec has confirmed that hackers have managed to steal a portion of Norton Antivirus’ source code, used in two discontinued enterprise products. According to Symantec, the company’s servers weren’t hacked, but the hackers managed to get the code from a third-party server.
Get Free Updates:
*Please click on the confirmation link sent in your Spam folder of Email*
read more

Related Posts Plugin for WordPress, Blogger...
Back to TOP