Skip to main content

Posts

Showing posts with the label hacking

7 million Dropbox passwords boxed by hackers

Personally , i have a thing about trusting the security of cloud services , although i don't use it to store personal data and other valuable information in the fear of a privacy violation and because i don't have a unlimited data connection ,millions of users dont share my opinion and they use such services and keep using them on a daily basis , DropBox - one of the most popular cloud storing sites are now acknowledging a new mega- incident where hackers stole passwords of 7 million DropBox passwords .The incident was denied by Dropbox at first , but after hackers demanded ransom via bit coin - and posting 400 passwords on PasteBin , Quote - Here is another batch of Hacked Dropbox accounts from the massive hack of 7,000,000 accounts To see plenty more, just search on [redacted] for the term Dropbox hack. More to come, keep showing your support things started to get a little serious as hackers claim that the remaining 6.9 million passwords and accounts will be vi...

iCloud leaks it all ....

The Cloud , a service that basically becomes a dump to store all your data online can be beneficial as you can sync the data to multiple devices almost anywhere but like everything , there is a catch , and this catch is privacy .Personally , i rarely use the cloud , and my usage usually revolves around me syncing mostly not so useful documents , but the majority tend to upload many other things , such as pictures , which may be scandalous at times , and such a scandal did happen today as a new iCloud leak dumped nude #nsfw photographs of 101 famous stars including some pictures from popular ones such as Jennifer Lawrence ,Avril lavigne and even unexpected ones like  Ariana Grande and Victoria Justice . The leak , or lets say the file dump was first released to 4Chan and then Reddit .the photos , which were downloaded off celebrity iCloud accounts , quickly spread around the #nsfw community and now , some of the stars who's alleged photos were leaked have started to express their ...

China bans Apple products from government use

Apple has always been regarded as being safe for work , but the walled garden policy has now come under fire in China as the company ,along with many other non-Chinese tech companies such as Microsoft ,Symantec and Russia's Kaspersky labs have been effectively banned from being used in the Chinese government . Apple is the latest addition to the list , and the main fear comes from the threat of Espionage which have been exposed after "Snowden Effect" that took place last year . Government of China has effectively left out iPad's and Macbooks in its July procurement list . According to China , Apple computers , along with computers running Microsoft's Windows 8 software are said to have backdoors which allow for espionage and therefore both systems have been effectively banned . China's latest action to boycott Apple products over fear of espionage comes right after Russia's action to replace their iPads with Android tablets after Apple failed to hand o...

MasHD Autonews - Tesla Model S is vulnerable to internet hacking

As we step into the technocratic future , the influx of technology is virtually unavoidable , but the auto industry was immune for some time but now with the introduction of battery and hybrid technologies and clever automation , that gap is slowly diminishing and most modern cars are now full of computers . But with all these new gizmos and gadgets , there is always a hidden danger , this danger sadly is not something like a loose cable or a flat tire , but instead it is completely out of the drivers reach ,and as technology goes forward , the amount of people using it for negative purposes also increase , making a simple task like driving even more scarier . Via - Computerworld The latest revelation comes from a Tesla Model S owner named Nitesh Dhanjani,who by the way is a computer security consultant attending Black Hat Asia security conference in Singapore .Using the internet and a free internet account hacking software , he was able to hack into the Tesla's onboard c...

Newly discovered exploit lets 3rd parties access and modify your personal data on Samsung smartphones ....

Samsung is not new to the world of vulnerabilities , just a few months ago , certain backdoors were found with the KNOX security system and a severe exploit was found with the design of the Exynos chipsets as well . however as Samsung continues to gain large portions of the smartphone market some vulnerabilities follow with it , and the recent one was found just yesterday Our smartphones have two processors , one is the general purpose processor that we all fight about (Snapdragon , Exynos,Tegra ,AX...) but behind the layers of silicon you find the baseband processor , this handles the modem operations such as connecting to service provider networks and so on . but according to Replicant developers , the software running on this system has serious loopholes that lets 3rd parties access personal data without any party knowing what's going on Over the course of their discovery ,Paul Kocialkowski and the team Replicant found out that 9 Samsung devices are affected by this vulne...

NSA's project TURBINE can basically command and control itself

An NSA project to install spying malware on "millions" of computers around the world, dubbed TURBINE, could allow the clandestine US agency unprecedented access to "industrial-scale exploitation" in the battle for internet dominance. The spyware, which is said to have already been installed on as many as 100,000 systems after first being deployed in mid-2010, is described as both smart and aggressive, automating much of what would have previously needed a trained operative. That, The Intercept's insiders say, makes it the perfect tool for broadly infecting a huge number of machines and casting a wide net for data collection. Rather than limit such actions to human operatives, TURBINE is an "intelligent command and control capability" that can run its own deployment and make its own decisions on which gathered data is important. What makes TURBINE particularly interesting for the NSA is how little staff would have to know technically about infecte...

Apple patches major iOS security flaw , OSX to be given a security patch soon

Apple has released a patch for its iOS mobile operating system, which runs on iPhones and iPads, after security researchers uncovered a major vulnerability that could allow hackers to intercept encrypted emails and other communications. The flaw, which was first identified by security firm Crowdstrike, meant that critical checks on the validity of a website’s security (SSL) certificate were overlooked when users tried to establish a secure connection. This meant that a hacker could potentially masquerade as a trusted site, such as Gmail or Facebook, and intercept encrypted traffic or modify the data in transit, in addition to breaching financial data or finding other sensitive information. "It's as bad as you could imagine, that's all I can say," Johns Hopkins University cryptography professor Matthew Green told Reuters. In a statement on its support website, Apple admitted that the software "failed to validate the authenticity of the connection". The ...

Blackphone - Wow , So Privacy , Such Android ,Much Secure

One of the biggest problems in recent times is the digital surveillance by that invades our personal privacy. Well, with the upcoming smartphone named Blackphone, you can breathe a sigh of relief. Silent Circle in association with Geeksphone has announced Blackphone, which according to the firm is the world's first smartphone that gives you full control over your privacy. So, what platform does the smartphone run on? Blackphone is powered by a custom build security oriented operating system called PrivatOS that is based on the popular Android software. The new secured version of the Android OS allows you to receive phone calls, exchange texts, transfer and store files and video chat without having to compromise any of your data stored on the smartphone. The newest invention is said to be a result of several careers' worth of effort. Phil Zimmermann, who is one of the creators, said "I have spent my whole career working towards the launch of secure telephony products....

"Quantum" program gives the NSA access to 100,000 offline computers

Three days before President Barack Obama will allegedly announce major changes to the NSA's surveillance programs, The New York Times has a story addressing one particularly controversial practice: intercepting laptops purchased online to insert bugs that can phone home — or even give remote access — to the US government. According to the Times, not only does that practice take place, but the bugs are now installed in nearly 100,000 computers around the world as part of a program code-named Quantum. However, the publication's government sources say they aren't being used inside the United States, but rather to spy on allleged Chinese and Russian military hacker groups, Mexican drug cartels, European "trade institutions," and alleged terrorists. Since the devices have their own radios, they can allegedly tap into computers that aren't connected to the internet. While officials reportedly told the Times that the devices are mainly intended for defense, their...

Developer ports iOS core to Nokia N900

Developer Winocm has been busy on a special project of his, and today announced on his website that he recently achieved “one of the core milestones” of the mission: successfully porting the iOS core to a Nokia N900 smartphone, among other devices. He has a couple images to prove it, and goes on to detail the other hardware that can boot the system, giving developers some porting opportunities. As you might have guessed from the image, the port doesn’t include any of the user interface, and says the developer, he doesn’t have any plans right now to support for the UI, saying tongue-in-cheek that it is the Core that is most important. As mentioned, it runs on more than the Nokia, which is imaged above, among the other offerings: ARM RealView Emulation Baseboard (ARMPBA8_ALT) ARM RealView Platform Baseboard for Cortex-A8 (ARMPBA8) Texas Instruments OMAP3530 (BeagleBoard/BeagleBoard xM) (OMAP3530) Texas Instruments OMAP3430 (Nokia N900) (OMAP3430_RX51) Texas Instruments AM335x (Be...

Internet connected Philips HUE light bulbs are easily hackable

Philips kind of blew our minds with the hue, which is an LED lightbulb that can be controlled with your smartphone or computer. Of course, though, there had to be a catch, and it seems like that catch is that the lightbulb is easily hackable, allowing users with a dark mind to put the lights out on an unsuspecting Philips hue owner. How does the hack work, exactly? Research by Nitesh Dhanjani reveals that hue’s control system uses a less-than-secure authentication system that’s used to communicate with devices in order to turn on and off lights. How secure is this authentication system? Well, it just uses the MAC address, which is highly easy to breach into. All it takes is a little bit of malware to be installed into the control system and hackers will be able to reveal the lightbulb’s MAC address. From there, they can turn the lightbulb on and off without having the owner’s device on hand. Of course, the hack won’t steal any personal information (unless you store your personal i...

Newly discovered exploit leaves 750 million sim card users prone to hacking

Almost every phone in existence uses a SIM card, especially GSM-based devices. It turns out, that while SIM cards are encrypted, they can easily be breached with just a couple of text messages, and it apparently takes only a couple of minutes. The hack allows someone to listen in on calls and steal mobile data from a phone The hack consists of cloaking a text message so that it looks like it was sent from the carrier, and about a quarter of the time, an error message is sent back containing information about the SIM card that can be used to break into it. After that, another text can be sent that officially finishes the job, allowing hackers into your phone. Security researcher Karsten Nohl of Security Research Labs discovered the exploit and says that up to 750 million handsets could be vulnerable to the hack. However, he notes that only SIM cards using older data encryption methods are at risk, while SIM cards using the newer Triple DES encryption are safe. Out of all the mob...

Club Nintendo gets hacked .....

Nintendo Japan has warned Club Nintendo users to change their passwords, after revealing that the member rewards site was hacked back in June, leading to tens of thousands of unauthorized logins. The first Nintendo realized of the compromised security was a dramatic increase in errors spotted on July 2, with subsequent investigation turning up 23,926 stolen logins and almost 15.5m attempts. However, the first of the hacks apparently begin on June 9, continuing up to July 4, Nintendo Japan says. All passwords for the Club Nintendo service have been reset, and users will need to create new credentials when they next try to log in. Club Nintendo is the company’s membership scheme, which offers rewards – including both in-game content, special limited edition games, warranty extensions, and real promotional gifts – in return for playing games on the Wii U, Wii, 3DS, and other Nintendo consoles. There’s no indication that Club Nintendo US or Club Nintendo UK have been compromised. F...

Ubisoft gets hacked - usernames and email addresses stolen

It’s been a bit of awhile since we’ve heard about a large online service hack, but we should’ve knocked on wood when we had the chance. Ubisoft has confirmed that some of its “online systems” were hacked, with only usernames, email addresses, and passwords stolen. The game publisher says that financial information is safe, since that info isn’t kept by Ubisoft. Obviously, Ubisoft is recommending that all account holders change their passwords on ubi.com, as well as on other websites where they use the same password. Of course, it’s good practice to not use the same password for everything, as that could start a chain reaction if your password gets stolen on one service. However, Ubisoft says that the passwords are encrypted on their servers, so while the hackers didn’t have the passwords themselves at the time of the breach, Ubisoft says they “could be cracked, in particular if the password chosen is weak,” which is why the company is recommending that its users change their pass...

Android App can allow its user to hack into a aircraft on autopilot - and control it !

Next episode of "Mayday" might feature this app  The Hack in the Box security conference is taking place in Amsterdam this week, and one of the talks was fairly interesting. Hugo Teso, who is a security professional as well as a licensed pilot demonstrated how one could remotely hijack an airplane using nothing but an Android device as the tool. It turns out that two important aviation systems — the Automated Dependent Surveillance-Broadcast (ADS-B) and the Aircraft Communications Addressing and Reporting System (ACARS) — are completely unencrypted and unauthenticated, allowing anyone with the right tools and a little know-how to access the system remotely without too much trouble. Teso simply hit up eBay for “actual flight code software” that’s normally used for training pilots, as well as nabbing a radio transmitter. During the demonstration, Teso audited real aircraft code by searching for vulnerabilities on a fleet of virtual aircrafts (using real airplanes in ...

First-Known Targeted Malware Attack On Android Phones Steals Contacts And Text Messages

Malicious software is nothing new to the cyber security world. So-called malware is what unscrupulous folk use to disrupt or gather sensitive data from our desktop computers. Targeted attacks with malware have been relatively unseen on smartphones, those other computers we carry around that are teeming with personal data. Now, however, security researchers at Kaspersky Labs say they’ve uncovered the first-known targeted malware attack on Android phones. The victims were specifically Tibetan activists, but the disclosure underlines the broader possibilities for targeted cyber attacks on smartphones. The attack relied heavily on social engineering, a kind of verbal manipulation, to hack into their targets’ devices. Kaspersky explains that on March 24, the attackers infiltrated the email account of a high-profile Tibetan activist, and used that account to send a spear-phishing email to their contacts list. The email looked like this: Notice that it included an attachment, calle...

South Korea hacked - North Korea suspected

A huge cyberattack on South Korean banks, broadcasters and others, believed to be one of the most serious in the country’s history, has left investigators hunting for evidence of North Korean involvement as infrastructure struggled back online. Systems at multiple banks and two insurance companies were either forced offline or severely impacted in the attack, which began at roughly 2pm local time; three TV stations were also targeted and suffered downtime. However, despite strong suspicions at North Korean involvement, spokespersons from South Korean agencies insist it’s too early to lay the blame at their insular northern neighbours. “We’re looking into the cause of the shutdown,” a spokesperson for South Korea’s president told the WSJ, “but we can’t say North Korea is behind it.” The country’s communications agency described the attacks as the result of “malicious code” though held off suggesting potential culprits. Some reports have suggested that skulls were seen on the impac...