Follow us on RSS or Twitter for the latest updates.

August 7, 2012

Apple and Amazon Falls Prey to Social Engineering


icloud
WiReD writer's Apple iCloud account was compromised and his iPhone, iPad and MacBook remotely erased. The writer's Google Mail and Twitter accounts were also hacked.

Although Honan blames himself for not having two-factor authentication enabled on his Gmail login, he also said that Amazon made it "remarkably easy" for the miscreant to gain control of his Apple iCloud account. He added that Apple had its own "security flaws" after allowing the hijacker to bypass Honan's preset security questions on his iCloud account.

"Apple tech support gave the hackers access to my iCloud account. Amazon tech support gave them the ability to see a piece of information - a partial credit card number - that Apple used to release information," he wrote in a postmortem examination of the digital attack.

"In short, the very four digits that Amazon considers unimportant enough to display in the clear on the web are precisely the same ones that Apple considers secure enough to perform identity verification."

Honan claims that he later chatted to his hacker via Twitter, email and AIM, and after Honan agreed not to press charges, the hijacker revealed how he broke into the Twitter, Google and Apple accounts.

The hacker, who called himself Phobia, said he didn't have to use brute force to figure out Honan's passwords for the accounts, but instead used clever social engineering to work his way from call centre to call centre.

Phobia said that the whole intrusion was designed to take control of Honan's Twitter feed because it had a three-character handle: @mat.

He followed the Twitter account's profile page to Honan's website, where he learned of his Gmail address. Phobia then started a password reset process for the Gmail account and thereby bagged another of Honan's email addresses: the Gmail account was setup to send a password reset message to the scribe's @me.com inbox. Although that address was partly obscured by Google (m••••n@me.com), Phobia guessed what it was because it had the same starting character as Honan's Gmail username.

Now that Phobia knew Honan had an AppleID account (associated with the @me inbox), he knew he could take over his iDevices.

Amazon pulled into epic hack attack

Phobia phoned Amazon masquerading as Honan and used his email address and billing address (found in Honan's Whois records for his website) to add a fake credit card to his Amazon account. The hacker hung up and then phoned Amazon again, claiming he'd been locked out of his account and used the fake credit card number, plus real email and address, to persuade Amazon tech support to let him into the account.

Once in Honan's Amazon account, Phobia could read the last four digits of the writer's real credit card in the payment settings page. Unfortunately, those four numbers, along with the addresses, were all Apple tech support needed in a subsequent phone call to allow Phobia to reset Honan's iCloud backup storage login, giving him access to pretty much every account and device Honan owned.

Graham Cluley, senior technology consultant at Sophos, told The Reg that Amazon's verification process for adding the credit card wasn't thorough enough. "A billing address and email address are probably too easy to dig out," he said.

But, as Honan himself admitted, it's normal practice for retailers to star out all but the last four digits of credit or debit cards, so Amazon had no reason not to do the same for an online account.

"Amazon made it too easy for someone to add a credit card to an account (and subsequently gain access to the account), but Apple made it too easy to access account information using the final four digits," Cluley said.

"There's any number of questions Apple could have asked - either extra support questions or they could have asked about recent purchases on iTunes or the App Store."

Apple said that its "internal policies were not followed completely" and it was reviewing its processes for password resets. Amazon had not returned a request for comment at the time of publication.

Have you enable two-factor authentication on your gmail account, are you still using the same password across all the websites you visit, and when last did you change your password. We'll like to hear your experience

Author: dfgdfg,

July 21, 2012

Hacker Arrested for 2008 DDoS Attacks on Amazon.com


amazon-ddos-attack
A 25-year-old Russian hacker has been arrested for allegedly orchestrating two DDoS (Denial-of-Service) attacks on Amazon.com and eBay in 2008.

"Cyber bandit" Dmitry Olegovich Zubakha was indicted in 2011, but he was just arrested in Cyprus on Wednesday. Zubakha was arrested on an international warrant and is currently in custody pending extradition to the United States.

According to the indictment, which was unsealed on Thursday, Zubakha, with the help of another Russian hacker, planned and executed DDoS attacks against Amazon.com, eBay, and Priceline in June 2008. Zubakha and his co-conspirator launched the attack by programming botnet computers to request "large and resource intensive web pages." According to a press release by the U.S. Department of Justice (DOJ), the attacks made it "difficult for Amazon customers to complete their business on line."

Zubakha and his friend claimed credit for the attacks on online hacker forums, and law enforcement traced 28,000 stolen credit card numbers to the pair in 2009. For that reason, Zubakha and his partner are also charged with aggravated identity theft for illegally using the credit card of at least one person.

"These cyber bandits do serious harm to our businesses and their customers," said U.S. Attorney Jenny Durkan in a statement. "But the old adage is true: the arm of the law is long. This defendant could not hide in cyberspace, and I congratulate the international law enforcement agencies who tracked him down and made this arrest."

At present, the charges in the indictment -- conspiracy, intentionally causing damage toa protected computer resulting in a loss of more than $5000, possession of more than 15 unauthorized access devices (credit card numbers), and aggravated identity theft -- are just allegations. Zubakha faces up to five years in prison for conspiracy, up to teh years in prison and a $250,000 fine for intentionally causing damage to a protected computer, up to ten years in prison and a $250,000 fine for possessing unauthorized access devices, and an additional two years in prison (on top of any other sentence) for aggravated identity theft.

Author: dfgdfg,

Categories: , ,

August 10, 2011

Amazon Launches Kindle Web Based Cloud Reader


Amazon Launches Kindle Web Based Cloud Reader
Amazon has been working on a web client for its Kindle ebook store for quite a while now. It debuted a first iteration late last year, albeit with a different scope, but is now introducing a new product which brings the entire Kindle experience to the browser.

Amazon Kindle Cloud Reader enables users to read books from the Kindle store entirely in their browsers, bypassing the need for a dedicated app.

This is the same route that Google went for its own eBooks store, but Amazon was spurred especially by Apple's latest changes to the App Store terms of service for app developers which meant that the company would have to fork over 30 percent of Kindle book sales revenue to Apple.

"Today, Amazon.com announced Kindle Cloud Reader, its latest Kindle reading application that leverages HTML5 and enables customers to read Kindle books instantly using only their web browser - online or offline - with no downloading or installation required," Amazon announced.

The app is made possible by HTML5 and advanced capabilities, like local storage, available in modern browsers alone.

For now, the Kindle Cloud reader works on Safari, on the iPad and on Macs, as well as in Google Chrome regardless of the operating system.

Uses will feel at home in the new web app, all of their books will be available instantly. Kindle Cloud Reader enables users to do anything they can do with a native Kindle app or the device itself.

"As with all Kindle apps, Kindle Cloud Reader automatically synchronizes your Kindle library, as well as your last page read, bookmarks, notes, and highlights for all of your Kindle books, no matter how you choose to read them," Amazon explained.

While the Kindle Cloud Reader works in any (supported) browser, one of the advantages of the web, it's clear that Amazon is targeting the iPad in particular especially since it won't be able to sell books via its native Kindle app, unless it agrees to pay Apple a 30 percent cut.

Author: dfgdfg,