Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 56

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 56

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

Chinese hackers launch cyberattack on Canadian government

| Feb 17, 2011 11:24 PM CST

Chinese hackers have recently launched a massive cyberattack on Canadian government websites and employees, gaining access to a cache of highly classified federal information. The attack was detected last month and was claimed by the government to only be an attempt to access their computers - however the CBC is stating this as innaccurate.

Continue reading: Chinese hackers launch cyberattack on Canadian government (full post)

Hacker selling access to government websites for under $500

| Jan 24, 2011 10:16 AM CST

When you make the laws and rules that govern data security and safety online, you expect that the rule makers will follow them. That isn't always the case though. Hackers are always trying to find their way though the security around websites in the private and government sectors for all sorts of nefarious uses. Apparently, one hacker has succeeded in getting around the security on some government websites and is selling the access to the highest bidder.

Continue reading: Hacker selling access to government websites for under $500 (full post)

Stay away from Twitter.com; it's being exploited with simple code

| Sep 21, 2010 8:41 AM CDT

If you haven't seen already, Twitter.com is under attack exploiting a flaw in its system with a simple code called "onmouseover" that is used to execute code or a command when your mouse cursor is moved over the bad area.

My @camwilmot account has personally been affected just now and as far as I can see, it only affects the front page of Twitter.com and not other pages such as your profile page.

Continue reading: Stay away from Twitter.com; it's being exploited with simple code (full post)

TKIP WPA cracked in 60 Seconds

| Aug 27, 2009 9:47 PM CDT

Wow this one sort of sent a chill down my spine until I remembered that my home network is protected by WPA-2 enterprise with a RADIUS server, 4096-bit certificates, (machine and user) and a bunch of tin foil hats and black radar repelling spray paint.

If you are wondering what I am so paranoid about well there is this group of scientists in Japan that have figured out how to break the WPA protocol as long as you are using the Temporal Key Integrity Protocol TKIP. If you are using the Advanced Encryption Standard (AES) you are safe for now.

The problem lies in the fact that not all wireless devices support AES. Yes most new ones do but you still see a smattering of TKIP only or devices that default to auto for the encryption standard.

Now while breaking this key is significant, it is not a first. WPA with TKIP has been broken before. To crack it took roughly 15 minutes. This time, well it took about 60 seconds.

Toshihiro Ohigashi of Hiroshima University and Masakatu Morii of Kobe University, the tow people responsible for this new fast hack plan on releasing the details at a technical conference on September 25th.

Now, I will say that while this is scary, it is the "scientists" that never reveal their methods that actually scare me more.

Continue reading: TKIP WPA cracked in 60 Seconds (full post)

IE 8 comes out tops in Security test

| Aug 24, 2009 9:44 PM CDT

Wow, I know this little bit of news is sure to annoy a few people out there. As Mozilla complains that a browser election when Windows 7 is installed is just not enough it is having a hard time competing with IE 8 in terms of security.

According to a recent Study performed by NSS Labs Internet Explorer is more secure than FireFox 3, Chrome, Safari 4, and even Opera.

The test was to see if each browser was capable of withstanding common Web-Based attacks.

The numbers were pretty telling. IE 8 was able to block about 81% while FireFox only caught 54%. Chrome V2 only caught 7%, Safari 4 Caught 21% and Opera only managed to stop 1% of the attacks. The success of IE 8 is mostly attributed to the built in SmartScreen technology that screens websites for common attack vectors. Granted you can get something similar for FireFox but even so it still did not outperform the built in one in IE 8.

This test, while not the end all of security tests is still not good news for Mozilla and Opera, they are telling the EU commission that they are not able to get market share because MS is locking them out. But with security like this it is possible that people will chose MS' IE over them for the security.

Continue reading: IE 8 comes out tops in Security test (full post)

Apple Claims Jailbreaking is a National Threat

| Jul 29, 2009 12:58 PM CDT

Ok this is a good one, it also shows that Apple is really desperate to control the iPhone. According to a report over at Wired; Apple is trying to get the DCMA to believe that Jailbreaking can lead to terrorist attacks on the national cell tower network.

The logic goes something like this;
An Evil Doer jailbreaks the iPhone, uses Ultrasn0w to alter the phones baseband, then using the alterations forces a DDoS attack on a cell tower crashing the service.

Chaos ensues, dogs start dating cats, and the world collapses.

In short a whole lot of FUD by Apple to try and turn jailbreaking into a criminal offense. This argument completely ignores open source phone OSes like Android, Unlocked phones sold by companies and even Apple's own Unlocking process.

It is also funny that Apple says that they have "technological protection measures" built into the iPhone. I guess this is like the shoddy encryption they are trying to push on users.

I hate to break this to Apple, a hacker or terrorist is not going to worry about the legality of jailbreaking before attempting to crash the national cell service.

So I guess everyone that owns an iPhone is a potential national security threat just waiting to happen...but that is not the worst, apparently jailbreaking is good for drug dealers too.

Where is my tin foil hat?

Continue reading: Apple Claims Jailbreaking is a National Threat (full post)

New Attacks and Malware evolve with our usage

| Jul 10, 2009 11:16 AM CDT

Expect another round of patches from Microsoft this coming Tuesday.

Microsoft has released the details of these patches, most of which fall into the remote code execution or elevated privileges category.

Two of the six patches will be for DirectX. It was a couple of months ago that Microsoft finally admitted they had been tracking attacks targeting DX. The loop hole the attacks were using allowed for complete, system wide, control through the use of a malformed QuickTime video.

This predates the announcement that the Video ActiveX control for IE could be exploited through the use of DirectShow filters. This announcement was made just this week and shows again the way malicious coders use our own habits against us.

It seems that as we consume more and more online video content the malware creators are moving towards that medium. After all it was not that long ago that .zip files were the big thing for inserting malware as .jpg files were before that and office files before that.

While these flaws probably should have been detected and corrected before this, it is still interesting to see how the patterns for malware change and evolve with our online usage. Just look at the increase in Twitter spam and malware inserted in tiny URL links. The increase in Skype Spam and the number of attacks and expoits in AIM and Live Messenger.

Continue reading: New Attacks and Malware evolve with our usage (full post)

SMS security hole found in iPhone OS 3.0

| Jul 2, 2009 10:21 AM CDT

Although this is more Apple news it seems that there is a flaw (everyone stop to gasp) in the new iPhone OS 3.0 Software. This flaw revolves around how the iPhone handles SMS messaging.

According to very limited details it seems that the undisclosed flaw could allow malicious code to be inserted giving an evildoer root access to the thermally challenged device.

Charlie Miller, the person who discovered the flaw went on to say that despite the SMS flaw that the iPhone OS is still very secure. He praised Apple's decision to remove Flash and Java (despite advertising a full and "real" internet experience) stating that they are potential vectors for attack.

Others disagree with Mr. Miller as there are always ways to protect from flaws in add-ons and say that Apple's removal of these features, requiring signed code and restricting applications is just a way to control the phone and of course generate more revenue.

With the release of the SDK for iPhone OS 3.1 and the beta version of the OS we know that Apple will be releasing the sometime very soon (rumors put it out on July 17th). Although many other fixes and features were mentioned with the new OS, this was one that got past the official release.

Continue reading: SMS security hole found in iPhone OS 3.0 (full post)

Black Hat/Defcon ATM Security Flaw Talk Canceled

| Jul 2, 2009 9:35 AM CDT

This is an issue in the world of security. It seems that many companies do not want people to know about gaps in their security or planning.

For the second year running a talk at Defcon/Black Hat covering a security hole in an automated service has been canceled. Last year it was after the Boston Transit Authority filed an injunction on three MIT students for exposing a flaw in their smart card payment system. This year it is a talk exposing a flaw in something that everyone uses, the Automated Teller.

It seems that there is a serious flaw in the software used in some ATMs that can allow a malicious person to access the internal network and to steal pin and account numbers. Barnaby Jack was going to discuss this at length and was also going to demonstrate both remote and local attacks on an unmodified ATM.

As you can imagine the vendor that manufactures the ATM line was upset and asked that the talk be pulled. Their reasoning is that they want to have sufficient time to address the issue before the flaw is exposed to the public.

While their stated goal of addressing the issue is great, it still make me wonder how a hole got there in the first place and if these companies actually test their systems to make sure they are protected against intrusion.

Continue reading: Black Hat/Defcon ATM Security Flaw Talk Canceled (full post)

The importance of data security

| Jan 29, 2009 10:26 PM CST

A piece on internet/data security has been published using Google Docs and it certainly makes for some interesting reading. Entitled "Data Security - A Balance Between Convenience, Privacy, Stupidity", this could be quite the eye opener for many who often sweep the issue under the carpet and say "naaah, won't happen to me" whilst adding some fitting humour and sarcasm into the mix.

Continue reading: The importance of data security (full post)

ElcomSoft releases ultimate GPGPU hacking tool

| Jan 15, 2009 8:23 AM CST

The GPGPU has become the ultimate hacking tool. At least that is what Theo Valich is saying.

In his blog he shows off a new piece of software from ElcomSoft a Russian company that is usually associated with security. Previously they have released software that is designed to recover passwords from files and systems that was Cuda Enabled. But now they have extended their support to ATi with their new Wireless Secutiy Auditor 1.0.

This handy little tool uses the parallel processing power of a GPU to attempt to recover wireless encryption passwords. Considering the number of Cuda enabled notebooks out this handy little tool is sure to make wireless networks everywhere a little less secure.

Read more here

Continue reading: ElcomSoft releases ultimate GPGPU hacking tool (full post)

Cooler Master at CES, more cases, more security

| Jan 11, 2009 2:08 PM CST

Cooler Master invited us to their suite in the Palms Hotel and Casino along with 200 or so of their closest friends. Among the products on display were the new V10 peltier assisted CPU cooler and various pieces from the new Sniper Collection.

Chad Sebring is anxiously waiting on the first V10 sample to arrive at the TweakTown Lab and a preview should be ready by the middle of next week. The cooler was so impressive that our pictures didn't turn out so you will just have to wait on Chad's exclusive preview.

Continue reading: Cooler Master at CES, more cases, more security (full post)

Proposed Australian ISP Filters are Security Holes

| Dec 17, 2008 10:32 AM CST

I have been following the Australian ISP filtering issue (as have many of you) with interest. I personally do not like the idea and feel that it is dangerous in many ways.

To understand why filters on this scale are so dangerous it is important to know that all traffic would have to pass through them. This gives a hacker the chance to intercept all internet traffic from a single location.

BanThisURL.com recently sat down with Matthew Strahan, a security expert at Securus Global and asked them about these new filters. In his opinion the filters are extremely dangerous and provide (as I mentioned) a single point of attack and a single point of failure.

Read the full interview here.

Continue reading: Proposed Australian ISP Filters are Security Holes (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription