Showing posts with label news. Show all posts
Showing posts with label news. Show all posts
Tuesday, May 17, 2011
The Daily Jang - The Online Pakistani Newspaper Jang.com.pk Compromised
Websense Security Labs™ ThreatSeeker® network has determined that the popular online Pakistani newspaper Web site the 'Daily Jang' (at jang.com.pk) has been compromised.
The Web site has been injected with malicious code in several locations. The code redirects visitor browsers to exploit Web sites. At the time this writing, the exploit sites that the Daily Jang redirects to are active and serve malicious code.
The paper is one of the most popular and oldest newspapers in Pakistan. The Web site gets a lot of daily traffic from its many loyal readers, both within and outside Pakistan. It also links to many other Web sites (Alexa report). Some reports indicate an average of more than 40,000 unique visits to the Web site a month.
An infection can occur while visiting the main page of the site. The visiting user's browser is redirected silently, in the background, to an exploit site loaded with an exploit kit called 'g01pack' (we blogged not long ago about mass injections leading to this exploit kit). If one of the kit's many exploit attempts is successful, a Trojan Backdoor file is dropped onto the user's machine. The backdoor file currently holds a detection rate of 26%.
Fireshark can map exactly what happens to the browser when surfing to a Web address. When jang.com.pk is loaded to Fireshark, at the end of the process Fireshark creates a visual map of all of the connections made by the browser during the site visit. In the image below, the malicious Web site that the browser connects to when visiting jang.com.pk is marked with the color red and the string TLD vv.cc(jang.com.pk is also marked in red because it is compromised).
6:47 AM by Shubham Mittal · 0
Sunday, May 1, 2011
Verona woman charged with felony for hacking into Facebook account
A 28-year-old Verona woman has been charged with a felony for hacking into another person’s Facebook account and making unauthorized changes to the account, according to the Oneida County Sheriff’s Office.
Following a weeklong investigation by the Sheriff’s Office, Courtney Klahs was charged with third-degree computer tampering, which is a class E felony, and unauthorized use of a computer, which is a class A misdemeanor, according to the Sheriff’s Office.
Klahs was released on an appearance ticket and is scheduled to appear in Verona Town Court at a later date, according to the Sheriff’s office.
Following a weeklong investigation by the Sheriff’s Office, Courtney Klahs was charged with third-degree computer tampering, which is a class E felony, and unauthorized use of a computer, which is a class A misdemeanor, according to the Sheriff’s Office.
Klahs was released on an appearance ticket and is scheduled to appear in Verona Town Court at a later date, according to the Sheriff’s office.
2:27 PM by Shubham Mittal · 0
Hacker broke into Sony , 77 million Playstation Network Accounts data stolen
Sony has revealed that 10 million credit card accounts may have been exposed two weeks ago when a hacker broke into the company's computers in San Diego and stole data from 77 million PlayStation Network accounts.
Sony last week said it had encrypted credit card data, but not other account information, including names, addresses, email addresses and birth dates.
The break-in, which occurred between April 17 and April 19 but was not disclosed until April 25, drew furor from U.S. lawmakers, who last week demanded more information from Sony about the intrusion and why the company took a week before notifying its customers.
Sony has maintained that the company acted as quickly as it could to ascertain the nature of the break-in, hire security experts and assess the scope of the damage. During the news conference, Hirai offered a time line of the events, saying the company was notified of the intrusion on April 19 and shut down the service on April 20 to investigate. It hired three firms to conduct a forensic analysis of its computers.
Source : http://latimesblogs.latimes.com/technology/2011/05/sony-apologizes-says-10-million-credit-card-accounts-may-have-been-exposed-in-network-attack.html
Sony last week said it had encrypted credit card data, but not other account information, including names, addresses, email addresses and birth dates.
The break-in, which occurred between April 17 and April 19 but was not disclosed until April 25, drew furor from U.S. lawmakers, who last week demanded more information from Sony about the intrusion and why the company took a week before notifying its customers.
Sony has maintained that the company acted as quickly as it could to ascertain the nature of the break-in, hire security experts and assess the scope of the damage. During the news conference, Hirai offered a time line of the events, saying the company was notified of the intrusion on April 19 and shut down the service on April 20 to investigate. It hired three firms to conduct a forensic analysis of its computers.
Source : http://latimesblogs.latimes.com/technology/2011/05/sony-apologizes-says-10-million-credit-card-accounts-may-have-been-exposed-in-network-attack.html
2:21 PM by Shubham Mittal · 0
Thursday, April 28, 2011
Al-Qaeda's Encryption Software - Mujahideen Secrets 2.0
Al-Qaeda support group Al-Ekhlaas has improved the encryption software it now provides to its online members, according to one security researcher who examined the software, known as "Mujahideen Secrets 2.0"
"They have improved the operation of the graphical user interface and it will now encrypt chat communications," says Henry, who adds that the Arabic translation suggests the software is encouraged for use by Al-Ekhlaas members to evade U.S. government efforts at surveillance.
Tampa-based ISP NOC4Hosts and Rochester, Minn.,-based SiteGenesis in January found out their operations were being used to host the Al-Ekhlaas Web sites where Mujahideen Secrets 2 can be found. Both hosting firms pulled the plug on the Web sites after receiving specific technical information about the content.
HERE are the screenshots :)

3:28 PM by Shubham Mittal · 0
Sunday, April 10, 2011
Forum Hacker Suspect Arrested in Ukraine
The Ukrainian Secret Service (SBU) has announced the arrest of a suspected hacker, aged 19, from Odessa who is alleged to have hacked into a popular Internet forum to steal the personal information of more than 190 thousand users.
hacker gained access to the forum to place malicious code on the bulletin board and of using anonymous proxy servers to disguise the origin of the virus. The virus copied the database, grabbing the personal information of the registered users.
The alleged hacker is being questioned in relation to Part 1 Article 361 of the Criminal Code of Ukraine, which encompasses the unlawful interference with the operation of computers, computer systems, or networks resulting in confusion or destruction of computer information or information media. Additionally this includes the dissemination of computer viruses by means of software or hardware which are intended for the unlawful penetration into computers, computer systems or networks and which are capable of confusing or destroying computer information or information media. -
hacker gained access to the forum to place malicious code on the bulletin board and of using anonymous proxy servers to disguise the origin of the virus. The virus copied the database, grabbing the personal information of the registered users.
The alleged hacker is being questioned in relation to Part 1 Article 361 of the Criminal Code of Ukraine, which encompasses the unlawful interference with the operation of computers, computer systems, or networks resulting in confusion or destruction of computer information or information media. Additionally this includes the dissemination of computer viruses by means of software or hardware which are intended for the unlawful penetration into computers, computer systems or networks and which are capable of confusing or destroying computer information or information media. -
4:18 AM by Shubham Mittal · 0
A Cool cute and small Young Girl on the Internet
Last July the story of Jessi ‘Slaughter’ became one of the hottest subjects on social networking and video sharing websites, but for many of the wrong reasons. With Safer Internet Day just recently, this event serves as an excellent example to children (and others!) of how not to behave online. I decided to take a closer look at the Jessi Slaughter incident.
4:17 AM by Shubham Mittal · 0
Microsoft Releasing some patches on 12th April
Microsoft has given advance notice of its upcoming ‘Patch Tuesday’ with fixes planned for 64 vulnerabilities, nine of which are critical and eight important. A further six are being fixed due to a hole that enables remote code execution, one which allows privilege escalation and another that can lead to information disclosure. Following the updates a mandatory restart is recommended in seven of the bulletins.
The vulnerability that is similar to server-side cross-site scripting (XSS), whereby an attacker could cause a victim to run malicious scripts when visiting various Web sites and rated as important, will be closed in this next batch of fixes. Microsoft had already issued an automated solution but this depended on users applying the patch themselves. The next release will finally close the MHTML vulnerability in Windows and the ability for attackers to launch ‘limited, targeted attacks’ though this hole.
The bulletin release is scheduled for Tuesday April 12, at approximately 11 a.m. PDT (18.00 UCT).
Microsoft will host a webcast to address customer questions on the security bulletins on April 13, 2011, at 11:00 AM Pacific Time (US & Canada).
4:15 AM by Shubham Mittal · 0
Subscribe to:
Posts (Atom)

