☺ Summer Nights

And city Lights ☺

Showing posts with label Vulnerability. Show all posts
Showing posts with label Vulnerability. Show all posts
Saturday, October 19, 2013
Qatar Down, SEA hijack Major Qatar Websites.

0



The Syrian Electronic Army (SEA) is at it again. The hacktivist group, who are known to back Syrian President Bashar al-Assad, has hacked many high profile Qatar based websites, including the Google, Facebook, Aljazeera and Government - Military websites.

Starting at about 4:25 am (GMT 5:30+), the Syrian Electronic Army shared this message on Twitter: Qatar is #down and following that, they went about switching off government and private websites using the .qa extension.

The domains are managed by Qatar’s Ministry of Information and Communication (ictQatar). Apparently, the Syrian Electronic Army gained access to Qatar Domain Registrar (portal.registry.qa) and modifies the DNS entires to redirects the targeted websites to servers controlled by hackers serving defacement page, that include a picture of Assad and the groups logo, as shown.

The List of the targeted websites is posted on Twitter by hackers - these include:

moi.gov.qa 
facebook.qa 
gov.qa 
vodafone.qa 
aljazeera.net.qa 
google.com.qa 
ooredoo.com.qa 
diwan.gov.qa 
qaf.mil.qa 
mofa.gov.qa 


Another tweet from SEA shows that they have unauthorized access to Domain Registrar of Qatar:

The SEA's high-profile media hacking spree began earlier this year. Among the victims of the group are The Financial Times, The Guardian, and the Associated Press. Most recently, the Washington Post got hit. The common running theme: the papers reported stories SEA didn't like.

At the time of reporting, most of the hijacked websites are still showing the deface page while other are now down. These attacks are one more example of why companies need to implement properly layered defense strategies.

Read More
Friday, October 18, 2013
Facebook Is Losing Teens. Why ?, find out.

0

Facebook Is Losing Teens, And New Privacy Settings Won't Bring Them Back-


There’s no question that Facebook FB +3.85% is quickly losing teenage users to other social networks. In February, Facebook admitted in its annual 10-K report filed with the Securities and Exchange Commission that it was aware that younger users were less engaged with the social network than previously. Facebook stated:
knowledgehutt.blogspot.in
“We believe that some of our users, particularly our younger users, are aware of and actively engaging with other products and services similar to, or as a substitute for, Facebook. For example, we believe that some of our users have reduced their engagement with Facebook in favor of increased engagement with other products and services such as Instagram. In the event that our users increasingly engage with other products and services, we may experience a decline in user engagement and our business could be harmed.”

In fact, many teens attest to the fact they are abandoning Facebook. In August, 13 year-old Ruby Karp wrote an Op-Ed for Mashable declaring “I’m 13 and None of My Friends Use Facebook”. Karp wrote that all of her friends are using Instagram and Snapchat, and she only has a Facebook account herself “just to see what it was all about. I soon discovered that Facebook is useless without friends. My only friend is, like, my grandma.” She also discovered the dark side of Facebook for the teens who do use it: Bullying. “Kids might comment something mean on a photo of you, or message you mean things. This isn’t Facebook’s fault, but again, it does happen there. If my mom heard I was getting bullied on Facebook, she would tell me to quit right away.” The impact of bullying via social networks on today’s young women – especially sexual harassment – was recently detailed in Vanity Fair.

But Facebook is apparently desperate to keep teenagers and bring back those who have left in droves. Earlier this week, it made a major change to its privacy policy for its 13-17 year-old users (whom must agree to a different privacy policy and have different settings than adult users). Now, teenagers are allowed to post publicly for the world to see, as well as allow followers. Previously, Facebook prevented teenagers from sharing posts with more than just friends-of-friends, which was designed to protect teenagers from not only strangers, but also themselves. However, teenagers have made it clear with their quick adoption of social networks such as Instagram and Snapchat they want to share everything and with as many people as possible. Does Facebook really think enabling its teenage users to share everything on Facebook, too, will bring back this demographic?

Unfortunately, a simple privacy setting is not Facebook’s problem. Today’s teens are primarily mobile users, spending the majority of their time on their phones and tablets. If teens are using Facebook, it’s via Facebook’s mobile app. Compared to other social apps such as Instagram and Snapchat, Facebook’s app is cumbersome and simply posting an update just takes too much time for these teens. While teens might be spending more time on their phones and tablets than you and me, they don’t want to spend extra time navigating through apps to do what they want. Remember – this generation was raised on technology and doesn’t know life without it. The experience that apps such as Snapchat and Instagram delivers has created an expectation of instant gratification for teens that the current Facebook app just can’t meet.


Though Facebook is making great strides in its mobile strategy, it has a long way to go if it wants to retain the teenage demographic it still has – let alone bring back those that have left. If Facebook can’t do this (and fast) the residual effect may have a drastic impact on the future of the social network, as advertisers will have a decreasing audience they can potential reach — thereby impacting Facebook’s revenue and potential to keep profiting.
Read More
Unbreakable Apples iMessage encryption is vulnerable to eavesdropping attack

0
Knowledgehutt.blogspot.com

Though Apple claims iMessage has end-to-end encryption, But researchers claimed at a security conference that Apple’s iMessage system is not protected and the company can easily access it.


Cyril Cattiaux - better known as pod2g, who has developed iOS jailbreak software, said that the company’s claim about iMessage protection by unbreakable encryption is just a lie, because the weakness is in the key infrastructure as it is controlled by Apple: they can change a key anytime they want, thus read the content of our iMessage.


Basically, when you send an iMessage to someone, you grab their public key from Apple, and encrypt your message using that public key. On the other end, recipients have their own private key that they use to decrypt this message. A third-party won’t be able to see the actual message unless they have access to the private key.


Trust and public keys always have a problem, but the researchers noted that there's no evidence that Apple or the NSA is actually reading iMessages, but say that it's possible. "Apple has no reason to do so. But what of intelligence agencies?" he said.


The researchers were able to create a bogus certificate authority and then add it to an iPhone Keychain to proxify SSL encrypted communications to and from the device, and in the process discovered that their AppleID and password was being transmitted in clear text.


He says that since Apple controls the public key directory that gives you the public key for every user, it could perform a man-in-the-middle (MITM) attack to intercept your messages if asked to by a government agency.

A solution for Apple would be to store public keys locally in a protected database within iOS, as then the keys could be compared.



Read More
Thursday, October 17, 2013
Importance of logs and log Management for IT Security

0

Importance of Logs and Log Management for IT Security
IT Security is the name of the game and no matter how big or small the size of your organization, you will always invest enough on securing certain aspects of your IT network. In many organizations, it starts with monitoring your network for vulnerabilities that may enter the network to access potentially sensitive information in the form of security attacks.

For example, you may have firewalls as your first line of defense, followed by vulnerability management, intrusion detection and prevention systems, managing your network configurations and so on. 
 
These are crucial because:
  • Your routers can be easily breached without proper configuration and restrictions. 
  • If a firewall isn’t configured correctly, a hacker can easily spot a port that is accidentally left open and can gain access to the network. 
  • Rogue access points, botnet malware and social engineering can make your wireless a porthole into your LAN.
Why Logs?
The very purpose of IT security is to be proactive and the above measures make it more difficult for someone who attempts to compromise the network. This might just not be enough and you need to able to detect the actual breaches as they are being attempted. This is where log data really help.
To expose an attack or identify the damage caused, you need to analyze the log events on your network in real-time. By collecting and analyzing logs, you can understand what transpires within your network. Each log file contains many pieces of information that can be invaluable, especially if you know how to read them and analyze them. With proper analysis of this actionable data you can identify intrusion attempts, mis-configured equipment, and many more. Also for managing compliance, especially for PCI DSS – you need to retain logs and review them.
Monitoring and Analyzing Event Logs
When you know what is normal on your network, you can easily spot what is abnormal by monitoring the logon activity. It is very critical to analyze the event to understand the root cause and to make log analysis & log management more efficient, you need to collect and consolidate log data across the IT environment, and correlate events from multiple devices in real-time.
Importance of Logs & Log Management for IT Security
Apart from monitoring the activities across your web server, firewalls and other network devices, it becomes very crucial to monitor your workstation logs. For example, a workstation log can give you some key information like when a USB was connected, by whom and whether he belongs to the group that is authorized, etc. Log file analysis is best done with an SIEM software, when it comes to reading all of the events and being able to analyze and correlate activity across the various components of IT.
How SolarWinds Log & Event Manager can help you?
SolarWinds Log & Event Manager (LEM) completely monitor event logs across and acts as a central collection point for system log data, automatically aggregates and normalizes this data into a consistent format. LEM also performs multiple event correlation and has the distinct ability to set independent activity thresholds per event or per group to understand relationships between dramatically different activities. With its proactive approach, it helps you identify and respond to threats in real time.
Key areas where SolarWinds LEM helps you:
  • Monitoring Security Events: Event correlation allows you to effectively troubleshoot issues by understanding the relationship between various activities using multiple event correlations and alerts you as and when it encounters a security threat.
  • Threat Remediation: Active responses help you in responding timely to policy violations and troubleshooting issues. Some key active responses include:
    • Delete User Account and User Group
    • Block IP address
    • Log Off User
    • Restart/Shutdown Machine
    • Disable USB devices
  • Event forensics help you identify suspicious behavior patterns on your network.


Read More
Underground Hacking Exploit Kits

0

exploist233435345
List of Hacking Exploit Kits :
  1. Unknow
  2. Tor
  3. Target-Exploit
  4. Smart pack
  5. RDS
  6. My poly sploit
  7. multisploit
  8. mypack-009
  9. mypack-091
  10. mypack-086
  11. mypack-081
  12. Mpack
  13. Infector
  14. Ice-pack-1
  15. Ice-pack-2
  16. Ice-pack-3
  17. G-pack
  18. Fire pack -1
  19. Fire Pack -2
  20. Fiesta -1
  21. Fiesta -2
  22. Cry 217
  23. Armitage
  24. Adpack -1
  25. Adpack -2
  26. 0x88


Read More
Cracking 16 Character long Password In less then an hour

0


Cracking 16 Character Strong passwords in less than an hour
The Password serves to protect your financial transactions, your social networking sites, and a host of other nominally secure websites online. People often say, "don't use dictionary words as passwords. They are horribly unsecure", but what if hackers also managed to crack any 16 character password ?
Criminals or trespassers who want to crack into your digital figurative backyard will always find a way. A team of hackers has managed to crack more than 14,800 supposedly random passwords from a list of 16,449 converted into hashes using the MD5 cryptographic hash function.
The problem is the relatively weak method of encrypting passwords called hashing. Hashing takes each user's plain text password and runs it through a one-way mathematical function. This creates a unique string of numbers and letters called the hash.
The article reports that, using a commodity computer with a single AMD Radeon 7970 graphics card, it took him 20 hours to crack 14,734 of the hashes, a 90-percent success rate using Brute force method. Brute-force attacks is when a computer tries every possible combination of characters.
In December it was unveiled by Jeremi Gosney, the founder and CEO of Stricture Consulting Group, that   a 25-computer cluster can cracks passwords by making 350 billion guesses per second. It can try every possible word in less than six hours to get plain text passwords from lists of hashed passwords.
Cracking 16 Character Strong passwords in less than an hour
Using passwords that contained only numbers, 12 digits long, hackers managed to bruteforce such 312 passwords in 3 minutes.  Anyway password doesn't have to be a word at all. A whole phrase or sentence, a passphrase, offers more security. A correctly chosen passphrase is easy for you to remember but difficult for anyone else to guess.
Also the strongest password in the world isn't secure if you use it for every one of your secure sites. If one site is compromised and hackers are able to crack your password and you've reused it they could then gain access to your details on other websites.
The general public has no control over which hashing process websites use and therefore are at the mercy of an algorithm which they may know nothing about. If you are concerned about security, long passwords are the best defense.

Read More
facebook Graph Search become more powerful then ever, Revie your private setting Again.

0

Facebook Updates Graph Search
Facebook Graph Search is more powerful than ever, has been updated to allow people to search in greater depth on Facebook. 
Facebook expanded its Graph Search to include posts and status updates, which means everything you’ve been posting is way easier to find than ever before.
"Now you will be able to search for status updates, photo captions, check-ins and comments to find things shared with you,” says Facebook.
For example, you could enter "Posts by my friends from last month," or "Posts written at The White House" in order to find that specific information.
Facebook Updates Graph Search, Let's Tweak our Privacy Settings Again
Facebook’s search is increasing in power much faster than people are realizing that their life is being digitally sorted and indexed.
As Facebook widens its scope of searchable information, questions about privacy continue to rise. Facebook users should check their privacy settings if they want to limit the people who can search every post or status update they have ever made.
Review the settings shown at below sections:

Facebook Updates Graph Search

Privacy Settings
Here are some ways to protect your privacy on Facebook:

  1. Review photos you have shared or are tagged in.
  2. Check your Activity Log.
  3. Remove tags from photos and posts you’re tagged with that you don’t want to be searchable.
  4. If you don’t want to adjust settings for old posts individually, just Limit old posts.
  5. If you want to keep strangers out of your conversations and unaware of your activity, then don’t use hashtags.
  6. Graph Search also indexes all of your comments, whether you've made them on your own profile or a friend's profile. To review your comments, navigate to your Activity Log and sort it by Comments, found on the left-side navigation.
The most important thing you can do is to check your privacy settings often, especially after new features are released.


Read More
Hijacking Apple Id Using Flight Mode

0
A German security firm SRL claims a vulnerability in Touch ID Fingerprint Scanner and iCloud allows a hacker to access a locked device and potentially gain control over an owner’s Apple ID.

SRL points out that Airplane mode can be enabled on a stolen phone from the lockscreen, which turns off wireless connectivity and so defeats the remote wipe facility.


This can be accessed without requiring a passcode, could be a major vulnerability when it comes to physically stolen devices.

In a video demonstration, they point out that while Apple lets users locate and remotely wipe a device using the Find My iPhone app.

Since Find My iPhone can only perform a wipe if a device is connected to the Internet, but because airplane mode will disable Internet Connectivity, that may give a thief enough time to get fingerprints off of the device and eventually log in. An attacker can create a fake fingerprint on a laminated sheet and later attached to one of their fingers, as already explained by another researcher.

SRLabs suggests several things Apple could do to mitigate the problem. These include making Airplane Mode inaccessible from the lockscreen by default, and warning people not to keep a password reset email account active on a mobile device.

Read More
Another facebook hack exposes primary email address facebook users.

0
Last week we explained a critical vulnerability in Facebook that discloses the primary email address of facebook user. Later the bug was patched by Facebook Security Team.

Today another similar interesting Facebook hack disclosed by another bug hunter, Roy Castillo. On his blog he explained a new facebook hack method that allows anyone to grab primary emails addresses of billions of Facebook users easily.

Facebook Provides a App Dashboard for creating and managing your Facebook apps, with a range of tools to help you configure, build and debug your Facebook apps.

The flaw exists in App settings, where application admin can add developer's profile also, but if the user is not a verified user, a error messages on page will disclose his primary email address.

Using following mentioned steps, one was able to grab email addresses of all facebook users:
  1. Collect profile links of all facebook users from Facebook People Directory i.e http://www.facebook.com/directory/people/
  2. Collect Numerical Facebook ID for each Profile from facebook Graph API i.e http://graph.facebook.com/xyz.**  where extracted user ID is 1251386282
  3. Create a Facebook Application -> Go to Settings -> Developer Roles and add try to add a Developer profile, if its a valid ID, application will accept that, otherwise a error message will display the email address of that profile.
  4. To submit profile ID directly from URL parameters : https://developers.facebook.com/apps/APPLICATION_ID/roles?unverified_groups[1][0]=VICTIM_UID
Another Facebook hack exposes primary email address facebook users
Where APPLICATION_ID is application ID and VICTIM_UID is numerical id of facebook profiles collected from step 2.

To submit more profiles in bulk:
https://developers.facebook.com/apps/APPLICATION_ID/roles
?unverified_groups[1][0]=VICTIM_UID1
&unverified_groups[2][0]=VICTIM_UID2
&unverified_groups[3][0]=VICTIM_UID3
&unverified_groups[4][0]=VICTIM_UID4
&unverified_groups[5][0]=VICTIM_UID5
&unverified_groups[6][0]=VICTIM_UID6
&unverified_groups[7][0]=VICTIM_UID7
&unverified_groups[8][0]=VICTIM_UID8
&unverified_groups[9][0]=VICTIM_UID9
&unverified_groups[10][0]=VICTIM_UID10
and so forth...
Another Facebook hack exposes primary email address facebook users




This way attacker is able to dump the primary email address of any number of facebook users at once.
But was reported to facebook security team by Roy and he is rewarded with $4500 under bug bounty program.




Read More
Tuesday, October 1, 2013
no image

0
Hello There, Welcome to my Blog.
Simply Follow These Step to Disable Right click first

  • Add HTML/JAVA script Gadget And paste following Code in it:
<script language=javascript>
<!--
var message="Function Disabled!";
///////////////////////////////////
function clickIE4(){
if (event.button==2){
alert(message);
return false;
}
}
function clickNS4(e){
if (document.layers||document.getElementById&&!document.all){
if (e.which==2||e.which==3){
alert(message);
return false;
}
}
}
if (document.layers){
document.captureEvents(Event.MOUSEDOWN);
document.onmousedown=clickNS4;
}
else if (document.all&&!document.getElementById){
document.onmousedown=clickIE4;
}
document.oncontextmenu=new Function("alert(message);return false")
// -->
</script>

  • Now Disable CTRL+U As follow
Replace <body> Tag with this code:
<body onkeydown='return false'>


  • Save Your Changes and See It Works, Please Ask if any Problem.

Read More