Showing posts with label Hacked. Show all posts
Showing posts with label Hacked. Show all posts
Sunday, April 10, 2011
Forum Hacker Suspect Arrested in Ukraine
The Ukrainian Secret Service (SBU) has announced the arrest of a suspected hacker, aged 19, from Odessa who is alleged to have hacked into a popular Internet forum to steal the personal information of more than 190 thousand users.
hacker gained access to the forum to place malicious code on the bulletin board and of using anonymous proxy servers to disguise the origin of the virus. The virus copied the database, grabbing the personal information of the registered users.
The alleged hacker is being questioned in relation to Part 1 Article 361 of the Criminal Code of Ukraine, which encompasses the unlawful interference with the operation of computers, computer systems, or networks resulting in confusion or destruction of computer information or information media. Additionally this includes the dissemination of computer viruses by means of software or hardware which are intended for the unlawful penetration into computers, computer systems or networks and which are capable of confusing or destroying computer information or information media. -
hacker gained access to the forum to place malicious code on the bulletin board and of using anonymous proxy servers to disguise the origin of the virus. The virus copied the database, grabbing the personal information of the registered users.
The alleged hacker is being questioned in relation to Part 1 Article 361 of the Criminal Code of Ukraine, which encompasses the unlawful interference with the operation of computers, computer systems, or networks resulting in confusion or destruction of computer information or information media. Additionally this includes the dissemination of computer viruses by means of software or hardware which are intended for the unlawful penetration into computers, computer systems or networks and which are capable of confusing or destroying computer information or information media. -
4:18 AM by Shubham Mittal · 0
Wednesday, April 6, 2011
LizaMoon SQL Injection Attack Hitting Websites
The scareware sends users to a bogus Web page warning them that their PCs are infected with malware and tries to sell them an anti-virus application.
Hundreds of thousands of website URLs have been compromised in a massive malware attack that tries to trick people into buying fake anti-virus software to remove bogus infections, security experts said.
Security firm Websense says a Google search shows more than 1.5 million URLs with the nasty script. Because Google counts unique URLs and not domains or websites, the number is likely inflated. "It's safe to say it's in the hundreds of thousands," Websense said Thursday in a blog post. The attack is worldwide, with U.S. PC users making up roughly half those getting redirected to the bogus warning page.
LizaMoon, named after the first domain Websense discovered with the malicious script March 29, is believed to be a SQL injection, which is when hackers get their script into a Microsoft SQL Server database that then adds it to a site's URL. SQL injections is one of the most common forms of attacking Web sites and back end databases.
LizaMoon code has been found in SQL Server 2003 and 2005. Websense does not believe hackers are exploiting a vulnerability in the database. They are more likely penetrating Web systems used by the sites, such as outdated content management and blog systems. Security experts are still trying to determine exactly how the SQL injection occurs.
Hundreds of thousands of website URLs have been compromised in a massive malware attack that tries to trick people into buying fake anti-virus software to remove bogus infections, security experts said.
Security firm Websense says a Google search shows more than 1.5 million URLs with the nasty script. Because Google counts unique URLs and not domains or websites, the number is likely inflated. "It's safe to say it's in the hundreds of thousands," Websense said Thursday in a blog post. The attack is worldwide, with U.S. PC users making up roughly half those getting redirected to the bogus warning page.
LizaMoon, named after the first domain Websense discovered with the malicious script March 29, is believed to be a SQL injection, which is when hackers get their script into a Microsoft SQL Server database that then adds it to a site's URL. SQL injections is one of the most common forms of attacking Web sites and back end databases.
LizaMoon code has been found in SQL Server 2003 and 2005. Websense does not believe hackers are exploiting a vulnerability in the database. They are more likely penetrating Web systems used by the sites, such as outdated content management and blog systems. Security experts are still trying to determine exactly how the SQL injection occurs.
11:10 PM by Shubham Mittal · 0
46 People Charged in Operation ‘Phish Phry’
LOS ANGELES – Five people were convicted today of federal charges for their
roles in an international “phishing” operation that used spam emails and bogus websites
to collect personal information that was used to defraud American banks.
The five found guilty this afternoon by a federal jury were among 53 defendants
charged in the fall of 2009 as part of Operation “Phish Phry,” a multinational
investigation conducted in the United States and Egypt that led to charges against 100
individuals – the largest number of defendants ever charged in a cybercrime case. With
today’s guilty verdicts, 46 people have been convicted in federal court in Los Angeles
as a result of Phish Phry.
A portion of the illegally obtained funds withdrawn were then transferred
via wire services to the Egyptian co-conspirators who had originally provided the bank
account information obtained via phishing.
The defendants found guilty today were:
- Nichole Michelle Merzi, 25, of Oceanside, who was found guilty of conspiracy,computer fraud, bank fraud and aggravated identity theft;
- Tramond S. Davis, 21, of Las Vegas, Nevada, who was found guilty of conspiracy;
- Shontovia D. Debose, 22, of Las Vegas, Nevada, who was found guilty of conspiracy;
- Anthony Donnel Fuller, 22, of Corona, who was found guilty of conspiracy and two counts of bank fraud; and
- Me Arlene Settle, 22, of Garden Grover, who was found guilty of conspiracy and two counts of bank fraud.
Valerie Baker Fairbank on October 31.
7:15 AM by Shubham Mittal · 0
Two men arrested in Phone-hacking scandal
Two men have been arrested on suspicion of unlawfully intercepting mobile phone voicemail messages in connection with the News of the World phone-hacking inquiry.
They are understood to be the newspaper's chief reporter Neville Thurlbeck and former news editor Ian Edmondson.
The men, aged 50 and 42, were detained and questioned after attending separate police stations in south west London.
Both were released on police bail until September.
It comes as Sky sources revealed former Tory party treasurer Michael Spencer has asked the Metropolitan Police to look into whether he was also a victim of phone hacking.
They are understood to be the newspaper's chief reporter Neville Thurlbeck and former news editor Ian Edmondson.
The men, aged 50 and 42, were detained and questioned after attending separate police stations in south west London.
Both were released on police bail until September.
It comes as Sky sources revealed former Tory party treasurer Michael Spencer has asked the Metropolitan Police to look into whether he was also a victim of phone hacking.
7:07 AM by Shubham Mittal · 0
Subscribe to:
Posts (Atom)