Hacking, Security & Privacy - Page 54
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 54
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Spam being sent from a botnet composed of Android devices
Spam e-mail is nothing new. Most users have figured out ways to combat it either through the use of spam boxes or spam blockers on the e-mail servers themselves. This spam is traditionally sent out via compromised computers that have been pulled together into a botnet. The botnet can be ordered to do whatever nefarious activities its commander wants.
With Windows becoming more secure, however, it has been harder for hackers to gain these computers for botnets. Terry Zink of Terry Zink's Cyber Security Blog on the MSDN noticed something interesting about the spam he has been receiving lately. At the bottom of the message it says "Sent from Yahoo! Mail on Android."
Furthermore, he examined the headers of the e-mail and found "Message-ID: 1341147286.19774.androidMobile(at)web140302.mail.bf1.yahoo.com" I'm sure you can see where this is going. A spammer somewhere has a botnet that lives on Android devices, much like the rumors we've all heard. What's even more interesting is where these devices are located.
Continue reading: Spam being sent from a botnet composed of Android devices (full post)
Another new Mac OS X backdoor found, further proves OS X not as secure as previously thought
Once again, Apple's OS X is being confronted with a security risk. The latest backdoor has been discovered by Russian security firm Kaspersky Labs and is being used as part of a Advanced Persistent Threat campaign. This is just the latest in a series of security risks present in the Mac OS X operating system.
Kaspersky researchers found that Uyghur activists in China were being targeted by hackers. These hackers sent e-mails with a compromised attachment that was in the form of a JPEG. The code hidden inside the JPEG was a new form of the MaControl backdoor and is compatible with both the PowerPC and i386 Mac variants.
Costin Raiu, Director of Global Research & Analysis at Kaspersky Lab:
Espionage virus sent blueprints to China
In case you needed more examples of why the United States needs to focus on cyber security, take a look at a virus discovered in Peru. "ACAD/Medre.A" is a virus that is committing espionage by sending blueprints to China from companies in Peru. It has already stolen tens of thousands of blueprints, according to ESET.
The virus targeted the software AutoCAD which is a primary tool used by industrial designers and architects. It is believed the virus was first distributed to Peruvian companies through the use of an AutoCAD template given to public bodies. The virus was detected several months ago but has just seen a spike in usage.
The virus sends back blueprints to e-mail accounts provided by two Chinese internet firms, 163.com and qq.com. However, this doesn't prove China or the Chinese were behind the virus. What it does prove is that companies and governments alike need to strengthen their cyber security measures to prevent things like this from happening.
Continue reading: Espionage virus sent blueprints to China (full post)
Iran is the target of the U.S. and Israel-made Flame virus, according to sources
Flame, a highly sophisticated virus that was first discovered in Iranian oil refineries, and is supposedly the result of a U.S. and Israel joint effort to slow down Iran's nuclear program, reports The Washington Post. The information comes from multiple Western officials who purportedly have knowledge of the project, but of course want to remain anonymous.
This shouldn't come as a surprise considering the U.S. were unveiled as using the volatile Stuxnet virus, where The New York Times reported about Operation: Olympic Games, which is a project that used Stuxnet and Duqu, both sophisticated viruses. These viruses targeted Iranian SCADA systems, that allowed the creators of this virus to gather intelligence and even control aspects of Iran's nuclear and oil refining facilities.
Stuxnet code has been found within the Flame virus, according to security researchers, which is an unofficial confirmation that the creators of the Stuxnet virus (the U.S. government) are also behind this new nasty virus. Once this was discovered, in Get Smart fashion, the virus began to self-destruct, hastily removing itself from infected computers... not suss, huh?
LulzSec hacks again, claims responsibility for leaking 10,000 Twitter accounts on Pastebin
LulzSec, a hacking group responsible for many hacks last year, has been fairly quiet this year after their leader allegedly worked with law enforcement to bring charges against its members. Now, however, LulzSec Reborn has taken over and started hacking, mainly compromising user accounts and leaking the details.
LulzSec Reborn has had two major hacks this year and otherwise has been quiet. The first was a leaking of 170,000 MilitarySingles accounts on Pastebin and now they are taking responsibility for the leaking of 10,000 Twitter accounts on Pastebin. The latter, today's leak, features much more information than a traditional password hack.
The leak comes in the form of an SQL dump which features usernames, passwords, real names, bios, locations, avatars, security tokens used by the service for authentication with Twitter and the user's most recent Tweet. The hack comes from compromising a third-party site that required the login information to work.
US military chip made in China has security backdoor, massive national security concerns
A new discovery has been made by a Cambridge University researcher that a chip used by the US military features a security backdoor which could have massive implications on on national security. The chip, which was built in China, cannot simply be reprogrammed as the security backdoor is physically present on the silicon.
Sergei Skorobogatov of Quo Vadis Labs at Cambridge University said:
Now, let's be fair: it isn't a sure thing that the backdoor was introduced by the Chinese. It's more probable that the backdoor was present in the original design as a debugging tool for the designer. This is a common practice and these backdoors are often present and not malicious. As such it is unlikely that it was put in by the Chinese.
Exploit allows administrator command prompt to launch at login screen
Microsoft has left an unpatched exploit in Windows 8 Consumer Preview. The exploit works on Windows 7, Windows Server 2008 R2 and Windows 8 Consumer Preview and has been documented and known for a while. The details of the exploit are pretty simple and can be done in under a minute if one is a fast typist.
The general idea behind the exploit is to be able to run an elevated command prompt without even being logged in. It works by making a simple change in the registry so that when sticky keys is activated it launches the command prompt instead. The hack is virtually undetectable as all it is is a simple change in registry value.
To do the exploit one only needs to open command prompt once on the target PC and enter the code below. Once done, the hacker can return to the workstation at any point later in time and launch an administrator level command prompt just by pressing shift 5 times in a row. This could be of a serious nature for many different people, especially a business.
Continue reading: Exploit allows administrator command prompt to launch at login screen (full post)
Anonymous release 1.7GB belonging to the US Department of Justice
Anonymous have dumped 1.7GB of data belonging to the US Department of Justice, and on the flip side, the DoJ have downplayed the sensitivity of the data siphoned from their website. Anonymous says that the information they have includes "internal e-mails", and "the entire database dump" from the website.
Anonymous' leak was announced alongside a torrent with the 1.7GB of data inside, as well as a statement:
The reason for the attack is unknown, but Anonymous say that it's releasing the data to "spread information, to allow the people to be heard and to know the corruption in their government". The flip side has a DoJ spokesperson fanning out the flames, where they've said to ZDNet that a website with public information had been accessed, and that they were looking into the matter in more depth:
Continue reading: Anonymous release 1.7GB belonging to the US Department of Justice (full post)
The Netherlands becomes the first country to pass net neutrality law
Well, the government of the Netherlands have become the first European country to pass a net neutrality law. What this does is prevents internet service providers (ISPs) from traffic management except in the cases of congestion and network security, it also includes restrictions on ISPs performing deep packet inspection and other similar wiretapping techniques.
June 2011 was when the law was formed, where the Netherland's parliament passed a motion to stop mobile operators from blocking VoiP calls over their networks, with the bill only re cently passing the Dutch senate. The provisions in the law extend to anyone providing Internet access services, forbidding the use of traffic-shaping based on application usage, unless they hinder access for other users by causing congestion.
This means that equal types of traffic will be treated equally, with an example like video streaming services owned by a provider cannot have unrestricted access, where Hulu may be restricted. If a user chews up too much bandwidth, before the ISP can take any action, the user must be alerted so that they have the time to remedy the situation.
Continue reading: The Netherlands becomes the first country to pass net neutrality law (full post)
New type of malware, "ransomware," locks up computers unless ransom is paid
Once again, I get to be the bearer of bad news in order to keep you, our reader, safe. This time I bring news of a new malware that is going around dubbed "ransomware" due to the fact it locks up your computer until you pay the ransom amount demanded. This isn't a completely new idea, but this is a new strain and variation.
This latest campaign is mainly targeting the UK and a few other European countries and claims that illegally downloaded music has been found on the computer. Due to this illegal material, the malware claims that "to unlock your computer and to avoid other legal consequences, your are obligated to pay a release fee of 50 pounds."
The malware was spotted by security watch blog abuse.ch. According to them, the malware is delivered through an exploit known as "Blackhole." The ransomware also carries a payload of Aldi Bot which steals banking information. The message to take away here is to keep all your browsers and their add-ons up to date, as this is how Blackhole functions. Anti-virus isn't a bad idea either.
Another Mac security issue exposes Lion login passwords in plaintext
This year, so far, has not exactly been a stunning display for Macs. Between the Flashback malware and now this, it really shows just how weak the security of Mac OSX is. The latest blunder by Apple and its security team is that they turned on a debug log file which stores the user's password outside of the encrypted area.
If you were using FileVault prior to upgrading to Lion, it may be time to think about changing your passwords as this would affect you. FileValut 2 users (whole drive encryption) are not affected by this accident. Additionally, if you have Time Machine backups, the plaintext log file has stored your password for the long term.
Security researcher David Emery explains:
Continue reading: Another Mac security issue exposes Lion login passwords in plaintext (full post)
Kaspersky says Apple is 10 years behind Microsoft in terms of security
I'm sure there will be plenty of people who get up in arms over this, but I tend to agree. Apple is years behind Microsoft in terms of security because they have never had to worry about it since no one ever bothered to write malware or viruses for Macs due to their small market share. As it has increased, Macs has become a more attractive target.
Eugene Kaspersky, CEO of the influential Kaspersky security firm said:
Several security breaches have brought Mac security to the attention of the public and Apple will have a bit of a public relations crisis on their hands if they continue. One in five Mac computers carry Windows malware but only 2.7% have Mac OS X malware. Kaspersky says "cyber criminals have now recognised that Mac is an interesting area. Now we have more, it's not just Flashback or Flashfake. Welcome to Microsoft's world, Mac. It's full of malware."
Continue reading: Kaspersky says Apple is 10 years behind Microsoft in terms of security (full post)
20% of Macs house Windows malware
Most people think Macs are safe, and it's definitely a decision that sways some people when purchasing their latest kit. But, according to Sophos, one in five Macs actually harbors some kind of Windows-orientated malware.
The company looked at results over seven days from 100,000 Apple machines using its free anti-virus program, with 20-percent having one or more instances of Windows-based malware. Sophos have warned of this before, where last year they tested 50 USB drives lost in public. To their surprise, as well as mine, two thirds of these were infected. That's 33-percent! Seven of these owners of lost USB flash drives owned a Mac.
In their latest study, Sophos found that just 2.7-percent of the infected Macs actually contained harmful malware, with 75-percent of it being Flashback variants. Of the 20-percent harboring Windows malware, 12.2-percent carried Bredo, a three-year-old Trojan. Sophos does note that some machines contain malware samples that go back to 2007. Sophos have said the following:
Continue reading: 20% of Macs house Windows malware (full post)
A new Mac OSX Trojan exploits Word, not Java
A second Mac OSX Trojan has been discovered, but is likely not to be as widespread as the Flashback Trojan due to the process by which it infects the computer. As opposed to the Flashback Trojan which could be caught simply by surfing the internet, this new Trojan requires users to download a malformed Word doc.
Similar to the Flashback Trojan, this new Trojan requires no entering of a username and password so it could catch Mac users off guard. This Trojan should be less widespread due to the fact that users have to download a malformed Word document file. Once opened, it exploits Word and opens a backdoor for hackers to steal information or install further code.
The security vulnerability is actually pretty old. It comes from June 2009, so as long as you keep your Microsoft software up to date, you should be safe from this Trojan. With all of the recent outbreaks of Trojans, it won't surprise me if they start coming more frequently with more capabilities to do destructive things.
Continue reading: A new Mac OSX Trojan exploits Word, not Java (full post)
WARNING: Facebook Mobile for iOS and Android allows easy access to your login information
Once again, I get to be the bearer of bad news just to keep you, our reader, safe. Facebook's Mobile app for iOS and Android store your login information in a plaintext file that doesn't expire until the year 4001. The Facebook .plist file where your login data is stored could easily be swiped by a USB connection or via malicious apps.
Gareth Wright, a U.K.-based app developer for Android and iOS, is the discoverer of this bug. He discovered it after poking around in the application directories using the free tool iexplorer. He first found a plaintext Facebook Access token that was stored by DrawSomething and was able to query all of his data.
He then took a look at Facebook's directory where he found the .plist in question. He passed this file over to his friend and fellow blogger who, in the next few minutes, started posting status updates, sending private messages, and even liking websites. In other words, he had full control over the account.
Anonymous is up to no good: hacks Chinese government sites in protest
The group that everyone has secretly been cheering for has a new branch in China. An Anonymous China Twitter account was created late last month and endorsed by the official Anonymous account. Shortly after all of this, they went to work. Now hundreds of Chinese government, corporation, and other websites have been hacked.
A Pastebin post explains why they are doing this:
Many of the hacked websites were just defaced, however, others were slightly more serious. On one of the websites hacked, Anonymous released a list of e-mails and phone numbers as well as the admin login details to the site. The hacks went for several days on some of the sites, at last check, were still defaced.
Continue reading: Anonymous is up to no good: hacks Chinese government sites in protest (full post)
Anonymous at it again, this time threaten Operation: BLACKOUT, where they'll take the Internet down on March 31
Collective hacking group Anonymous are at it again, this time threatening more than just SOPA, PIPA or Facebook. This time they're threatening to take down the entire Internet. This is said to be as a protest to SOPA, Wall Street, the world's irresponsible leaders, and the beloved bankers who are starving the world for their own selfish needs out of sheer sadistic fun.
While I agree with most of those points, why threaten if you can't go through with it? I shouldn't laugh, but I'd cry if the Internet went down on March 31st. So, Anonymous are now saying they "will shut the Internet down" on March 31st. They go into detail, where "in order to shut the Internet down, one thing is to be done. Down the 13 root DNS servers of the Internet, those servers are as follows:"
A 198.41.0.4
iPhone password cracking easier than you think
A report was released last fall that claimed using a single repeating digit was a stronger pin code for your iPhone than using unique digits. All bets are off, however, when you are dealing with Micro Systemation, a Swedish security firm that helps police and military around the world crack digital security systems.
Just last week, the company released a video showing just how simple it is to crack an iPhone or Android device that is password protected. The video, which you can see below, documents a process where the company spokesperson uses an application called XRY and accesses the contents of the mobile phone in less than two minutes.
Immediately, all user information becomes available. This information includes GPS location, call history, contacts, and messages. The software doesn't use a flaw put there by the manufacturer. Instead it uses a brute-force method to try all of the combinations to guess the correct password. It's more akin to jailbreaking than hacking.
Continue reading: iPhone password cracking easier than you think (full post)
Microsoft raids office building, combats online crime
Instead of just sitting around waiting for the police to take action against online crime, Microsoft filed a civil suit in order to gain a warrant to sweep two office buildings in Pennsylvania and Illinois. The sweeps occurred Friday and resulted in a bunch of evidence, deactivated servers, and Microsoft seizing control of hundreds of Web addresses.
Why would Microsoft waste their money filing these civil suits and attacking cyber crime? Well, as it stands, Microsoft has a vested interest in taking down these cyber criminals. Many computers are powered by Windows, and since it has such a large market share, it is a main target for hackers. If Microsoft can make Windows more secure, they can combat Apple's main claim that OSX is more secure and stop losing market share.
Additionally, they can provide a better end-user experience, which Microsoft's customers would appreciate. "Taking the disruption into the courthouse was a brilliant idea and is helping the rest of the industry to reconsider what actions are possible, and that action is needed and can succeed," said Richard Perlotto, director at the Shadowserver Foundation.
Continue reading: Microsoft raids office building, combats online crime (full post)
iOS 5 contains Safari bug, opens users to malicious sites
This is a cautionary story for all of those iOS 5 users out there, including the new iPad 3 users. Germany security firm MajorSecurity discovered a bug earlier this month that can be used to trick you into visiting potentially malicious Web sites. The bug was first discovered in iOS 5 and was replicated in iOS 5.1. Apple was informed of the bug by MajorSecurity on March 3, but has not yet issued a patch.
"The weakness is caused due to an error within the handling of URLs when using javascript's window.open() method," explained David Vieira-Kurz of MajorSecurity. "This can be exploited to potentially trick users into supplying sensitive information to a malicious Web site, because information displayed in the address bar can be constructed in a certain way, which may lead users to believe that they're visiting another web site than the displayed web site."
Apple has acknowledged the bug, so they should be able to produce a patch, and I would encourage you to upgrade when it becomes available. Until then, watch the sites you go to, as it may not be where the URL bar is telling you you are at. If you would like to see for yourself, go here on your mobile device, select Demo in the upper left corner. This will open a new page that says Apple and looks like Apple but is still on MajorSecurity's server.
Continue reading: iOS 5 contains Safari bug, opens users to malicious sites (full post)


