Tuesday, June 3, 2014

Tuesday, May 27, 2014

Avast community forum hacked, user names and passwords stolen

Antivirus firm Avast said it took its community forum offline following a hacking attack compromised its database.


User names, email addresses,nick names and passwords were compromised in this attack.  The breach did not involve any financial data, license or any other data
While the passwords are hashed(one way encryption), it will not take much time for a hacker to crack the hashes. The longer the password, the harder it is to crack.

According to Avast blog post, the security breach affects less than 0.2% (about 400,000) of Avast's 200 million users.

People who uses the same password on other websites are advised to change those passwords immediately.

Until now, their forum used an open source community software called "Simple Machines Forum(SMF)".  It appears the Avast is using an outdated version of SMF.



Avast said it is now "We are now rebuilding the forum and moving it to a different software platform" which will be secure one.

Source: http://www.ehackingnews.com/

Saturday, April 19, 2014

HEART BLEED BUG EXPLOTATION

HEART BLEED BUG



The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the information protected, under normal conditions, by the SSL/TLS encryption used to secure the Internet. SSL/TLS provides communication security and privacy over the Internet for applications such as web, email, instant messaging (IM) and some virtual private networks (VPNs).
The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content. This allows attackers to eavesdrop on communications, steal data directly from the services and users and to impersonate services and users.

What leaks in practice?
We have tested some of our own services from attacker's perspective. We attacked ourselves from outside, without leaving a trace. Without using any privileged information or credentials we were able steal from ourselves the secret keys used for our X.509 certificates, user names and passwords, instant messages, emails and business critical documents and communication.
How to stop the leak?
As long as the vulnerable version of OpenSSL is in use it can be abused. Fixed OpenSSL has been released and now it has to be deployed. Operating system vendors and distribution, appliance vendors, independent software vendors have to adopt the fix and notify their users. Service providers and users have to install the fix as it becomes available for the operating systems, networked appliances and software they use.

You Can Check Your Website here : https://filippo.io/Heartbleed/

Thursday, March 6, 2014

Dendroid, a new Android malware toolkit

Number of malware for Android platform is increasing day by day. Cybercriminals trying to sell android-malware toolkit to others. The first Android Remote admin tool is AndroRAT which is believed to first ever malware APK binder.


Symantec researchers have come to know another android malware toolkit called "Dendroid" is being sold in the underground forums.

A cybercriminal going by online handle "soccer" in the underground forum is selling this HTTP based RAT which is said to be having many malicious features.

The toolkit is able to create malicious apk file capable of 'deleting call logs', 'call to any number', 'open webpages', 'record calls', 'intercept sms', 'take and upload photos&videos', 'dos attack'.

Researchers say the cybercriminal also offer 24/7 support for this RAT. Others can buy this toolkit by paying $300 through crypto currencies such as Bitcoins, Litecoins.

Experts have mentioned that this RAT has some link with the previous AndroRAT saying "the author of the Dendroid APK binder included with this package had assistance writing this APK binder from the author of the original AndroRAT APK binder. "

Tuesday, February 11, 2014

Dear Internet, Today is 'The Day We Fight Back', Biggest protest against NSA Surveillance




The US Government has allotted a large share of its 'Black Budget' for secret military research and weapons programs, along with surveillance programs, that is harvesting hundreds of millions of Metadata from emails, web activity, chats, social networks, and everything else around the world. To make this happen, NSA has used a number of unethical ways, but labeled as legal solutions. 
Today, on February 11th, we all unite to fight against the Government intrusion on the privacy of innocent people worldwide, under one banner of 'The Day We Fight Back', along with other 7000 websites by hosting a large banner at the bottom of the websites; reading “Dear Internet, we’re standing with 300+ nonprofits worldwide in demanding an end to mass, suspicionless surveillance”, asking people of the world to vote against proposed NSA reforms that the American Civil Liberties Union has labeled “Bad for Privacy”.
The Banner, you can see at the bottom of this page, enables you to contact the members of Congress directly via email or a computer telephone call link using Twilio Voice. 
You can ask the legislators to oppose the FISA Improvements Act, which would strengthen the NSA surveillance legality and to support the USA Freedom Act. At the time of writing, the petition has already been signed by more than 60,000 people.
Hundreds of Digital rights and Privacy groups come together to protest surveillance by governments and you can also participate in our efforts by using hashtags - #STOPTHENSA and #DayWeFightBack on social networking sites.
Back in January 2012, the largest online protest in the history of the Internet; known as 'The Black-Out Day', was carried out by Google, Wikipedia, Wordpress and many other companies to kill SOPA, but later the US government molded its Foreign Intelligence Surveillance Act in such a way that, now it legally allowed them to monitor Billions of calls in a day and tracking a million of the devices.
Despite running such mass surveillance program, the US government has shown its helplessness in preventing massive cyber-attacks like data breaches at TARGET, Neiman Marcus, and Michael Stores etc. Somehow, such activities by an Intelligence agency today are motivating the cyber criminals to do the same.
The Day We Fight Back was started in the memory of Aaron Swartz, a 26 year-old information transparency activist, who took his own life just over a year ago, having faced a standoff with the government.
Dear Internet, we’re standing with millions of people and 300+ non-profit organizations worldwide and demanding an end to this Mass and Suspicion-less Surveillance.


source : http://thehackernews.com/