Hacking, Security & Privacy - Page 55
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 55
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Is too much technology a bad thing?
We live in a modern age where technology seems to be taking over everything we do, from e-mails taking over for letters, to Turbo Tax taking over handwritten taxes. But, where do we draw the line? Can all of this technology be bad? Well, in one man's case, it is. A bug in the Norwegian's tax web portal has allowed anyone who went there to see his, his wife's, and his employer's information.
Users hoping to get an early start on their taxes went to the site, which resulted in a crash. When the servers were brought back up, everybody was inexplicably logged in as Kennith, the man in question. It seems that his login details were stored in the server's cache when the system went down, and after it was brought back up, logged everyone in as him.
The bug lasted only 15 minutes because they brought the servers back down, however, during that time period, anyone was able to log on and see his very private tax information. This isn't the first time the service has had issues. In response to the recent issues, the managing company has admitted that there were bugs when the system first launched and that they lacked the expertise to properly manage it.
Continue reading: Is too much technology a bad thing? (full post)
Microsoft may have leaked code capable of attacking critical Windows bug
No, I'm not trying to use scare tactics. No, I don't want you to rip out your link to the internet. I just want you to beware: Microsoft may have had a hand in leaking executable code that was used in a proof-of-concept (PoC). The data packet that was used was the same that Luigi Auriemma, an Italian security researcher, discovered and reported way back in May of 2011. Last Tuesday, Microsoft updated all flavors of Windows to patch the critical RDP vulnerability. Both Microsoft, and I, strongly recommend that you update and patch all of your machines running Windows.
Auriemma has stated:
Other researchers have said that the RDP proof-of-concept was unreliable, and only crashed Windows. The existing code, however, would be a good starting point for a successful exploit, they noted. "Microsoft has spread the potential starting point for an unauthenticated kernel-level worm,"Auriemma charged. "Weren't they here to protect the users?" The Microsoft patch MS12-020 is available via Windows Update and Windows Server Update. It is highly recommended to install the patch as soon as possible, because Gun.io, which bills itself as a place to "Hire the best hackers," is offering a reward to the first working exploit of the bug.
More Sony hacking problems - Michael Jackson's back catalog reportedly stolen last year
Sony are having a bad time with this hacking news, it just feels like a bad smell that won't go away for them. The latest news is Michael Jackson's entire music catalog was stolen during the hack, which reportedly accounts for some 50,000 individual tracks and a wide variety of unreleased material.
This was known in May of last year, in the aftermath of the hack which left the PlayStation Network and Qriocity (which is now known as Sony Entertainment Network Music Unlimited) users without a server for nearly an entire month. There were two men based in the UK who were arrested with the theft, and have appeared in court where they denied the charges.
The two men were released on bail and are now due to stand trial in January 2013. Sony had originally paid $250 million to the Jackson estate back in 2010 for the rights to literally everything that Michael had recorded, and whilst Sony haven't told us how widespread the theft is, multiple 'sources' have reported that the entire collection was taken.
Hackers continue attacking Israel, begins to get serious
Last Friday, a group of purportedly Gazan hackers defaced Israel's Fire and Rescue Services website. They didn't just do any old hack, but added a "death to Israel" message on the website and a tweaked picture of Israel's Deputy Foreign Minister, Danny Ayalon, where they superimposed foot prints over his face.
Ayalon is the public official responsible for a strongly worded statement denouncing hacking, likening it to terrorism and threatening (bad move) that:
Now, I'm sure you can imagine that the hackers were not happy with Ayalon's choice of words. The statement was made as a response to a cyber attack against Israel where hackers claimed to have taken 400,000 "Zionist" credit cards, including addresses, names and Israeli ID numbers (like Social Security). It has been reported that at least several thousand of those credit card numbers were verified as legitimate cards.
Continue reading: Hackers continue attacking Israel, begins to get serious (full post)
Apple, Nokia and RIM supply backdoors for government intercept, according to hacked memo
First up - this does not surprise me. I've thought for a very long time that this happens, as with most things, right under our noses and no one even knows. I'm sure it goes much deeper than this, and we'll never find out just how deep the rabbit hole goes, but on with the news. A group of Indian hackers known as "The Lords of Dharmaraja" had posted documents that were pillaged during the hack of an Indian military network. It was removed, but thanks to Google Cache, you can see an image of it below, and if that's not good enough, click here to read it directly.
Slashdot had reported on it too, and unveils some more info:
Then we have the actual document here, with points one and two not that interesting, but three and four are some eye-openers:
Anonymous hack US think tank, use stolen credit cards to make Christmas donations
Anonymous don't rest during the holidays like most people, they've donned their Santa hats and hacked their way into thousands of credit card numbers and other personal information belonging to clients of a U.S.-based security think tank, Stratfor.
One of the hackers said their goal was to take the funds from individuals' accounts to give away as Christmas donations. Anonymous boasted of stealing Stratfor's confidential client list, which includes entities including Apple, the U.S. Air Force, and even where Dexter Morgan works, the Miami Police Department. They mined it for more than 4,000 credit card numbers, passwords and home addresses.
Stratfor is an Austin, Texas-based company which provides political, economic and military analysis to help clients reduce risk, according to their YouTube page. They charge subscribers for its reports and analysis, which are delivered through the web, e-mail and videos.
Just a handful Chinese hacking groups responsible for most US attacks
U.S. cyber security analysts and experts are reporting that fewer than 12 different Chinese groups are responsible for most of the China-based cyber attacks that have resulted in critical data being stolen from U.S. companies and government agencies. The analysts spoke to The Associated press where they've said the intrusions have resulted in the loss of billions of dollars of intellectual property and other critical data.
The attacks may have been stealthy, agressive and somewhat ninja, but the distinct signatures the hackers leave behind make it possible for U.S. cyber security investigators to more or less accurately identify which teams were responsible for the attacks. According to the report, the U.S. gives unique names or numbers to the attackers, and at times can tell where the hackers are and even who they may be.
It's virtually impossible, however, to prosecute hackers based in China due to the lack of any form of agreement between the two countries. Even if it were 100-percent possible to provide definitive proof of where and who the attacks came from, China would most likely not even bat an eyelid. Given that at least a handful of the groups are believed to have financial backing from the Chinese government or military.
Continue reading: Just a handful Chinese hacking groups responsible for most US attacks (full post)
UN hacked, details of over 1,000 accounts released
Teampoison are reportedly behind an intrusion into the United Nations, in which they gained access to at least one of the UN's servers, where they stole over 1,000 e-mail addresses, usernames and passwords during the hack.
Teampoison posted their hacked goodies online through Pastebin, along with messages explaining the reasoning behind the attack, where they've said:
This was in reference to a previous statement made by Brock Chisolm, where he claimed that to achieve a One World Government, it is necessary to reove from the minds of men their individualism, their loyalty to family traditions and national identification.
Continue reading: UN hacked, details of over 1,000 accounts released (full post)
X-ray body scanners banned in European airports
Airport body scanners that use X-ray technology have been banned across Europe. Officials have said in a press release that the X-ray technology is now deemed off-limits in order to not risk jeopardizing citizens' health and safety.
Tiny bits of radiation emits from X-rays and have long since been connected to cancer in rare instances by physically damaging DNA. In a letter to ProPublica from the FDA, the agency claims that the risk of fatal cancer from scanners is 1 in 400 million.
Another report from ProPublica says that anywhere between six and 100 US airline passengers could develop cancer each year from walking through the machines. The TSA has responded to the EU's decision to ban the X-ray scanners, revealing that 300 dangerous or illegal items have been found on passengers by using the X-ray scanners. One would think that over the entire course of years using the scanners that finding 300 dangerous or illegal items, is worth the better chance of not getting cancer from the scanners?
Continue reading: X-ray body scanners banned in European airports (full post)
Intel and MasterCard join forces, want to enhance security and consumer payment experience for online shopping
Intel and MasterCard have just shaken hands on a new deal for a multi-year strategic collaboration to further enhance the security and consumer payment experience for online shopping. The new collaboration is set to combine MasterCard's expertise in payment processing and commerce with Intel's strengths in silicon innovation and chip-based security.
The deal will provide more options for a safer and simpler checkout process for online merchants and consumers using Ultrabook devices and future generations of Intel-based PCs. Intel and MasterCard are working together to optimize a variety of emerging payments technologies which include MasterCard's PayPass and Intel Identity Protection Technology (IPT). IPT can enable consumers to use strong two-factor authentication and hardware-based display protection.
What this does is provide increased online security against malware, and additionally, when used with an Intel Identity Protection Technology-enabled reader, consumers will be able to pay for online purchases with a simple tap of their PayPass-enabled card, tag or smartphone on an Ultrabook device. The idea is for simplicity-meets-security.
Valve confirms Steam hack, credit card and personal details may have been stolen
A few days ago I reported about the Steam forums being down for "maintenance", but today Valve have confirmed that a recent Steam hack is the result of this. The recent Steam hack may have compromised users' credit card details and other personal information according to a message sent to Steam users from Valve God, Gabe Newell.
Valve is certain hackers gained access to a database that contained encrypted information, but don't know if they took it or will be able to crack its encryption. The database that was hacked contained information such as user names, hashed and salted passwords, game purchases, e-mail addresses, billing addresses and encrypted credit card information.
Gabe says that Valve don't have evidence that the encrypted credit card numbers or personal info were taken by the intruders, and the company is "still investigating." He adds that there is also no evidence of credit card misuse, but implores Steam users to "watch your credit card activity and statements closely."
U.S. calls China the "most active and persistent" country in the world for cyber-espionage
The Office of the National Counterintelligence Executive have released a critical report labeling China as the "most active an persistent" country in the world when it comes to cyber-espionage. Oh snapz is what our VGA editor would say, and I would agree with that statement. Russia also slipped into the list, together with China are "the most aggressive collectors" of U.S. trade secrets, overall.
The purpose of the report is to highlight the increasing importance cyber-espionage plays in the undermining of both private and government interests. Robert Bryant, the U.S. Counterintelligence Executive, claims cyber-espionage is a "national, long-term strategic threat to the United States" and that "failure is not an option" when it comes to dealing with those matters. In the report, there is a special focus on the undesirable consequences stolen trade secrets may impart upon the U.S. and partner economies.
The Chinese government has been accused multiple times for noteworthy acts of both high-tech and low-tech espionage. This includes infamously penetrating Google's servers, corroborating with a Ford engineer working as a spy (the engineer is a spy! TF2 joke), gaining unauthorized server access at a long list of companies that include Yahoo, Northrop Grumman, Adobe, Symantec, ciphering information from British Unive
Mac OS X Trojan uses your GPU to mine Bitcoins, also steals data
Most people not familiar with IT (and even some who are!) think that Apple's, and more specifically, Mac OS X are impenetrable, Terminator-like machines. But, they are not. Not only can spyware and malware attach to your browser, and not through an executable, but now there's news of a newly discovered malware threat that targets Mac OS X systems.
It comes in the pirated copies of image editing software "Graphic Converter". The malware is known by DevilRobber or Miner-D, and attempts to steal personal information and uses your machine's GPU to generate Bitcoins. If you didn't know what Bitcoins were, they are a digital currency that can be exchanged by online by users without the need for an intermediary bank or payment service.
Intego, a security vendor, says that the malware was a combination of a Trojan horse, as it is hidden inside other applications; a backdoor, as it opens ports and can accept commands from command and control servers; a stealer, as it steals data and Bitcoin virtual money; and spyware, as it sends personal data to remote servers.
Continue reading: Mac OS X Trojan uses your GPU to mine Bitcoins, also steals data (full post)
Evoz intros the next-generation of baby monitoring
Have a baby at home and use traditional baby monitors? I feel your pain. They are slow, drop out, have limited options and are usually clunky. This is where Evoz have stepped in with the next-generation of baby monitoring. Evoz use a system that works over iOS and will ship on October 4. No separate receiver is required, all you need is an iOS-based device like an iPhone, iPad or iPod Touch and they can function as both the receiver and monitor.
Alternatively, you could purchase the Evoz hardware monitor and use your iOS device as the receiver. The app alerts you to cries, monitors bubs sleeping behavior to derive patterns and even connects you to a network of experts to help you with your concerns. It works from Wi-Fi and cellular connections because it is based on the iOS operating system, thus it will work anywhere you have Internet access.
In addition to this, the system tracks your child's sleeping and crying patterns, matches the information to the data anonymously collected from others of the same age and shows you where your child fits in. How awesome is that? Evoz has gone as far as partnering with sleep consultants and will be adding additional "baby experts" and behavior specialists to its network, allowing parents to rech out with questions. At first, this will be available over email only, but later down the track over the phone will be added.
Continue reading: Evoz intros the next-generation of baby monitoring (full post)
Police arrest 19-year old LulzSec hacker 'Topiary'
A member of both "Anonymous Operations" and "Lulz Security", 'Topiary' has been arrested on Wednesday, news coming from the Metropolitan Police Service. 'Topiary' served as the publicist of both hacker groups and often posted press releases and statements via Twitter. He had an apartment in Shetland Islands, Scotland and the apartment is currently being searched. A second 17-year old person in Lincolnshire, England is also being interviewed by has not yet been arrested.
The FBI began raiding apartments and arresting a number of people believed to be involved with Anonymous and LulzSec starting on July 19th. The hacker groups have said in response to the arrests that there is "nothing - absolutely nothing - you can possibly do to make us stop." During that time, Topiary is said to have tweeted "Arresting people won't stop us, FBI. We will only cease fire when you all wear shoes on your head. That's the only way this is ending," which is from the official LulzSec Twitter account.
Continue reading: Police arrest 19-year old LulzSec hacker 'Topiary' (full post)
Google now detecting viruses from its end for one form of Windows-specific malware
Google just don't stop, they've just announced that they're using their own data to detect viruses and will (as of today) be using Google Search results pages to warn users if their computers are infected with a specific form of malware. If a user has the virus, which is reportedly rerouting traffic to Google and other sites through a proxy will see the warning shown below.
A Google blog post titled "Using data to protect people from malware" says:
Google's Matt Cutts has shed light on the subject via his Twitter account saying that it only affects Windows-based systems and hijacks Google results. "That's how we learned about it," Cutts says about the "results hacking", without offering more detail on the subject. This is the first time a major search engine turns its results pages into a virtual malware alarm. This is a great step by Google as it causes headaches on their side if they just sit on their hands.
Anonymous now using #OpESR to engage in a class action lawsuit against the Federal Reserve
Anonymous is inviting all, Anonymous and non-anons to join OpESR in demanding Federal Reserve accountability. Instead of just hacking random companies and websites like other Lulz-orientated hacking groups, Anonymous are grabbing the Fed by the balls and asking "why?". Obviously this might not end up in any serious court, or even reach the mainstream media, but we're finally seeing a group large enough to make a difference, try.
Trying is better than nothing and we'll see how this one goes. For those who don't want to watch the video and would like the TL;DR, look below or click into the news story for a full read.
Hello American People,
LulzSec, Anonymous launch 'Operation Anti-Security' or #AntiSec
LulzSec and Anonymous have joined forces in an open declaration of war against the "freedom-snatching moderators of 2011." The attack is called Operation Anti-Security (#AntiSec), LulzSec called for like-minded individuals to open fire against any government or agency that crosses their path. The group have encouraged users to vandalize the opposition by plastering the word "AntiSec" on any government website or through physical graffiti.
Continue reading: LulzSec, Anonymous launch 'Operation Anti-Security' or #AntiSec (full post)
Sony hacked, again - this time 1 million user accounts stolen
I don't believe I'm writing about this again, but it appears Sony has been hacked, again. Just after they were getting full restoration of their PSN network up, LulzSec has hit Sony again with an SQL injection tactic which gave them access to Sony Pictures account database. This hack let LulzSec obtain 1 million user accounts (inclusive of passwords, email and home addresses as well as DOB), all admin account details and passwords, 75,000 music codes and 3.5 million music coupons.
Continue reading: Sony hacked, again - this time 1 million user accounts stolen (full post)
More Sony hacking news, why aren't these hackers using their powers for good?
This is something I just don't understand, these hackers are targeting Sony - for whatever reason I don't care, that is not my business and I'm not employed by Sony. But, another hack has just happened and it appears Sony BMG Greece was hacked on Sunday using an SQL injection attack and lost more than 8000 customer records. LulzSecurity, known for hacking fox.com's login database are responsible and it seems that Sony just aren't really caring about the amount of attacks happening to them.


