Follow us on RSS or Twitter for the latest updates.

March 19, 2013

AT&T Hacker Sentenced to 41 Months in Prison


Andrew Auernheimer – aka “Weev,” the Internet activist found guilty in November 2012 of hacking into the systems of AT&T and stealing the details of around 120,000 iPad owners – has been reportedly sentenced to 41 months in prison and three years of supervised release.

Tweets are being posted from the courthouse where the trial is taking place.

Tim Pool of Timcast, who has been following the trial from the court, says Auernheimer and his co-defendant Daniel Spitler will also have to pay $73,000 (56,000 EUR) in restitution to AT&T.

“Judge stated the sentence she administered would help weev down a ‘positive path’ and give him ‘respect for the law’,” Pool wrote.

One noteworthy aspect is the fact that the prosecution apparently used Auernheimer's Reddit AMA (ask-me-anything) to justify the sentencing.

In addition, at one point in the trial, court agents asked Weev to hand over his phone. He gave the device to his lawyer instead, after which he was “quickly grabbed, pinned, and cuffed.”

Auernheimer maintained his innocence up until the last minute. He has highlighted on numerous occasions that he wasn’t trying to cause any harm.

His tweet just before the trial.

Author: dfgdfg,

Categories: , , ,

March 8, 2013

Pwn2Own ends with Oracle Java, Reader and Adobe Flash exploits


Day two of the Pwn2Own competition at CanSecWest was again successful for French Vupen security, as they succeeded in exploiting Adobe Flash on Internet Explorer 9 on Windows 7 by chaining together three zero-days (an overflow, a ASLR bypass technique and a IE9 sandbox memory corruption) and earning themselves another $70,000.

George Hotz exploited Adobe Reader XI (also on IE 9 on Win7), and Ben Murphy - the last contestant to target Java - has also managed to earn a prize even though he wasn't there, because James Forshaw, a winner from the previous day, agreed to serve as proxy and demonstrate the attack.

All in all, ZDI has awarded over half a million dollars in cash prizes and, of course, the compromised laptops and ZDI reward points.

The Google financed Pwnium hacking contest - also held at CanSecWest - this year requires contestants to "break" Chrome OS but has so far not witnessed a successful exploitation.

In the meantime, Mozilla has already fixed the use-after-free zero-day flaw exploited yesterday by Vupen Security, and Google has issued a Chrome update that fixes the flaws discovered by the MWR Labs team.

Author: dfgdfg,

February 23, 2013

Pakistani Cyber Army Defaces 7 Indian Government Website


Hackers of the Pakistan Cyber Army (PCA) have breached and defaced 7 websites owned by the Indian government.

The affected websites are the ones of the Bihar Tourism from Ministry of Tourism India (bihartourism.gov.in), Mitigating Poverty in Western Rajasthan (mpowerraj.gov.in), the Directorate of Medical Education of the Government of Kerala (nurses.kerala.gov.in), the Salary Revision Commission of Government of Kerala (src.kerala.gov.in).

Other victims are the Customs, Excise & Service Tax Appellate Tribunal in New Delhi (cdrcestat.gov.in), the Works Information & Monitoring System (pwddelhi.gov.in) and the Society for Applied Microwave Electronics Engineering & Research (sameer.gov.in)

The hack comes in response to the attacks launched by Indian hackers against Pakistani websites. According to the deface message.
Here u g0 KiDs! Indian Government Servers Own3D! Hello GaY HinD People! Now Where’s SecuritY? ;) Listen U Fucked Up Indishell Kids! We Were Trying To Be in Peace! BuT We Don’t Think U Want It to Be Like That Anymore! So Here comes The Fuck From Us.

U abused All Pakistanis ( Which Includes Our Parents as Well )..I Had Told U AlreadY We have access to more than 50% of Indian GOV servers! BuT U ThoughT We MighT Be Kidding & U KepT Trying ur Lame ShiTs on .PK siTeS! When I see ur lame ShiTTy defaces on .PK SiTeS, It Drives me Real CrazY..Shame on U kids! :D

I Also Told U noT To Hack .PK Otherwise U will see Zone-h Full Of StarWhite Indian FLAG :D..Now Is The Time For Doing ThaT ShiT! In Other Words! We have Done this ShiT..
At the time of writing, three of the websites were restored, two of them were still defaced, while the last two were taken offline altogether.

It appears the site’s administrators haven’t patched the vulnerabilities, since the sameer.gov.in has been defaced for the second time.

Author: dfgdfg,

January 14, 2013

Lithuanian Online Game Site Miestukarai Hacked, 24,000 Users Data Leaked


A hacker called AnonVoldemort claims to have gained access to the databases of Miestukarai.lt, a Lithuanian online game that appears to have almost 35,000 players.

In the tweet announcing the hack, AnonVoldemort revealed that he had leaked over 24,000 accounts, both free and premium.

The data has been removed since from Pastebin. It’s possible that the site’s administrators have learned of the leak and have requested Pastebin to remove the information.

However, according to CWN – who had analyzed the leak before it was removed –, usernames, email addresses, IP addresses and hashed passwords were published by the hacker.

If there are any Miestukarai players reading this, I advise them to immediately change their passwords. Not only the ones protecting their game accounts, but all the passwords that are the same with the one leaked by the hacker.

Author: dfgdfg,

Anonymous hacks MIT after Aaron Swartz's Suicide


On Sunday, the official site of the Massachusetts Institute of Technology (MIT) went offline. On a couple of the website’s subdomains, Anonymous hackers published a message in memory of Aaron Swartz, the Reddit co-founder and activist who recently committed suicide.

“Whether or not the government contributed to his suicide, the government's prosecution of Swartz was a grotesque miscarriage of justice, a distorted and perverse shadow of the justice that Aaron died fighting for […],” the hacktivists wrote on the defaced pages.

“Moreover, the situation Aaron found himself in highlights the injustice of U.S. computer crime laws, particularly their punishment regimes, and the highly-questionable justice of pre-trial bargaining. Aaron's act was undoubtedly political activism; it had tragic consequences,” they added.

The hackers ask the government to “reform” computer crime and copyright and intellectual property laws.

“We call for this tragedy to be a basis for greater recognition of the oppression and injustices heaped daily by certain persons and institutions of authority upon anyone who dares to stand up and be counted for their beliefs, and for greater solidarity and mutual aid in response,” they wrote.

“We call for this tragedy to be a basis for a renewed and unwavering commitment to a free and unfettered internet, spared from censorship with equality of access and franchise for all.”

They concluded their statement by apologizing to MIT administrators for temporarily taking over the website.

MIT has ordered an internal investigation into the case of Swartz. Furthermore, JSTOR – the digital library that accused him of illegally downloading content – has released its own statement regarding Swartz’s death.

At the time of writing, the main MIT site appeared to be working properly. The subdomains that hosted the hacktivists’ message have been taken offline.

In the meantime, a petition to remove United States District Attorney Carmen Ortiz from office for overreach in the case of Aaron Swartz has been created. The petition appears to be supported by both Anonymous and the controversial Kim Dotcom.
Add me on Google+
FILED UNDER:MIT ANONYMOUS HACKTIVISM PROTEST DEFACED WEBSITE

Author: dfgdfg,

January 10, 2013

Anonymous Wants Obama Administration to make DDOS Attacks a Legal Form of Protesting



In a petition submitted to the White House’s “We the People” website, Anonymous hacktivists are asking the Obama administration to make distributed denial-of-service (DDOS) attacks a legal form of protesting.

“With the advance in internet techonology, comes new grounds for protesting. Distributed denial-of-service (DDoS), is not any form of hacking in any way. It is the equivalent of repeatedly hitting the refresh button on a webpage,” the initiators of the petition wrote.

“It is, in that way, no different than any ‘occupy’ protest. Instead of a group of people standing outside a building to occupy the area, they are having their computer occupy a website to slow (or deny) service of that particular website for a short time,” they added.

“As part of this petition, those who have been jailed for DDoS should be immediately released and have anything regarding a DDoS, that is on their ‘records’, cleared.”

Hacktivists have often used DDOS attacks in their protests. It was their “weapon” of choice when US authorities took down the popular Megaupload file sharing service.

At the time, they disrupted numerous high-profile websites, including the ones of the FBI, the US Department of Justice, the White House, and ones belonging to the motion picture industry.

They've also utilized DDOS attacks to protest against Israel and the Syrian government.

The petition, created on January 7, has been signed by 814 individuals. However, in order for it to be taken into consideration, it needs to be signed by 25,000 people by February 6.

Official Anonymous communication channels have hundreds of thousands of followers, so getting 25,000 signatures shouldn’t really be an issue. However, some supporters might be discouraged to do so because those who sign the petition are required to create a whitehouse.gov account.

Author: dfgdfg,

January 2, 2013

'Expect us 2013', Anonymous Issues threat


The hacking collective Anonymous has clarified that it has no plans to fade away in the New Year. It issued a statement over the weekend that warned the world to "Expect us 2013."

Along with the statement, the group created a video that boasts of its campaigns and exploits carried out in 2012. The video details the group's temporary shutdown of the U.S. Department of Justice, the FBI, Universal Music, and the Motion Picture Association of America's Web sites in protest of the U.S. government's indictment of the operators of popular file-hosting site MegaUpload.

The video also shows newsreels of Anonymous' campaign against Syrian government Web sites because of that government's alleged shutdown of the Internet, along with Anonymous' "cyberwar" against the Israeli government in protest of government attacks on Gaza. The group also recounts its hack into the Web site of the Westboro Baptist Church in response to plans by the controversial church to picket the funerals of those massacred at the elementary school in Newtown, Conn.

"The operations which are listed in the video are only examples, there are far more operations," Anonymous wrote in the statement. "Some of them still running, like Operation Syria. We are still here."

Despite the hacking group's threats, some believe that the collective may not actually make a big impact in the online world in the coming year. Security firm McAfee Labs released its "2013 Threat Predictions" last week and claimed the decline of Anonymous.

The firm argued that a lack of structure and organization, false claims, and hacking for the simple joy of it has affected the group's reputation. McAfee also said, however, that higher-level professional hacking groups may take up the slack, and promote a rise in military, religious, political, and "extreme" campaign attacks.

Author: dfgdfg,

December 21, 2012

10,000 Emails of Indian Government and Military Hacked


India’s government and military have suffered one of the worst cyber attacks in the nation’s history, after over 10,000 email accounts belonging to top officials were compromised, despite a warning from the country’s cyber security agency.

The attack came on 12 July, four days after the government was warned by the National Critical Information Infrastructure Protection Centre (NCIIPC), part of the National Technical Research Organisation (NTRO), that some sophisticated malware was spotted targeting specific individuals and organisations.

News of the attack was revealed at a day-long NCIIPC meeting in New Delhi this week, according to the Indian Express.

Email addresses belonging to officials working at the Prime Minister’s Office, defence, home, finance and external affairs ministries and intelligence agencies were nabbed in the attack, which has been blamed on state actors.
“The Ministry of External Affairs and Ministry of Home Affairs took the biggest hit, plus strategic information related to critical sectors, including troop deployment, was compromised,” an NTRO official told the Express.

“Paramilitary forces were also badly hit, especially the Indo Tibetan Border Police (ITBP), as deployments were revealed. There were serious cases of negligence, the involvement of insiders, if any, is also being checked.”
India’s most prolific foe in cyber space is thought to be Pakistan, but the frequent skirmishes between the two tend to involve web site defacements and the occasional DDoS attack from various hacktivist groups.

Back in March, minister for communications and IT, Sachin Pilot, revealed that over 100 government sites had been compromised in this manner between December 2011 and February 2012, while the India CERT said there were 834 defacements of .in sites in January alone.

However, the attack in July appears to have been more co-ordinated and carried out with the aim of obtaining specific information.

The NTRO was tight-lipped on the source of the attack.

“We would not like to name the state actors but D4 — destroy, disrupt, deny and degrade — process was initiated and counter offensive launched,” the NTRO official told the Express.

Back in June reports emerged that India’s National Security Council was finalising plans to give the NTRO and Defence Intelligence Agency (DIA) the power to carry out unspecified offensive operations if necessary.

Author: dfgdfg,

Categories: ,

November 28, 2012

International Atomic Energy Agency server hacked


A group of hackers leaked email contact information of experts working with the International Atomic Energy Agency (IAEA) after breaking into one of the agency's servers.

The group published a list of 167 email addresses along with its manifesto on Sunday in a post on Pastebin.

IAEA hacked
"Some contact details related to experts working with the IAEA were posted on a hacker site on 25 November 2012," IAEA spokeswoman Gill Tudor said Wednesday in an emailed statement. "The IAEA deeply regrets this publication of information stolen from an old server that was shut down some time ago. In fact, measures had already been taken to address concern over possible vulnerability in this server."
The hacker group calls itself Parastoo and wants the IAEA to investigate Israel's nuclear activities at the Negev Nuclear Research Center near Dimona, an Israeli city located in the Negev desert. "Israel owns a practical nuclear arsenal tied to a growing military body and it is not a member of internationally respected nuclear, biochemical and chemical agreements," the group said.

Israel has long had a policy of nondisclosure regarding its nuclear military capabilities and has never signed the international Treaty on the Non-Proliferation of Nuclear Weapons (NPT).

The experts whose email addresses were leaked should sign a petition demanding that IAEA investigate the activities at Dimona, the hacker group said, claiming that it has evidence of "beyond-harmful operations" taking place at the site.

Parastoo threatened to published information on the whereabouts of every single individual on the list together with their personal and professional details, saying that all of them could be considered responsible if an accident was to happen at Dimona.

"The IAEA's technical and security teams are continuing to analyse the situation and do everything possible to help ensure that no further information is vulnerable," Tudor said. "The Agency treats information security, including cybersecurity, as a top priority and takes all possible steps to ensure its computer systems and data are fully protected."
The IAEA is an international organization that promotes the safe and peaceful use of nuclear energy and discourages the proliferation of nuclear weapons. The agency reports issues of non-compliance by states to the United Nations General Assembly and Security Council.

Author: dfgdfg,

November 10, 2012

Teenage Hacker ‘Cosmo the God’ sentenced to six years – WITH NO INTERNET


“Cosmo the God” in a park near his home in Long Beach, California.

A 15-year-old hacker convicted of multiple felonies was handed an unusual sentence by a Long Beach, California juvenile court on Wednesday, one that will see him all but banned from the internet until his twenty-first birthday.

The hacker's real name was not disclosed because he is a minor, but according to a report, he goes by the handles "Cosmo" or "Cosmo the God."

As a member of the notorious UG Nazi hacker collective, Cosmo participated in an online reign of terror involving many of the year's most significant hacking events, including a DDoS attack that brought down Twitter for several hours.

Cosmo was finally nabbed in June, following a coordinated law enforcement action that also led to 23 other arrests, spread across eight US states and 13 countries. He was eventually arraigned on a laundry list of charges, ranging from credit card fraud, to identity theft and online impersonation, to making bomb threats.

Had he stood trial and been convicted, he faced a sentence of three years in prison. Instead, he pleaded guilty to all of the charges against him, in exchange for a six-year probation that will allow him to avoid incarceration – for a price.

Under the terms of his plea bargain agreement, Cosmo cannot use the internet without the prior consent of his parole officer, for the duration of his probation. Even then, he cannot go online "in an unsupervised manner," and he cannot use the internet for anything but education-related purposes.

Furthermore, he must turn over the usernames and passwords for all of his online accounts, and if he has access to any devices that are capable of connecting to a network, he must identify them to the court in writing. The devices the court already knows about – the ones that were seized in the FBI raid on his home – won't be returned.

Finally, Cosmo is to have no contact with any members of UG Nazi or Anonymous, nor their associates, nor a list of "other individuals," as specified by the court.

Violate any of those terms, and he goes straight to the slammer for the full three-year bid.

Author: dfgdfg,

August 7, 2012

Apple and Amazon Falls Prey to Social Engineering


icloud
WiReD writer's Apple iCloud account was compromised and his iPhone, iPad and MacBook remotely erased. The writer's Google Mail and Twitter accounts were also hacked.

Although Honan blames himself for not having two-factor authentication enabled on his Gmail login, he also said that Amazon made it "remarkably easy" for the miscreant to gain control of his Apple iCloud account. He added that Apple had its own "security flaws" after allowing the hijacker to bypass Honan's preset security questions on his iCloud account.

"Apple tech support gave the hackers access to my iCloud account. Amazon tech support gave them the ability to see a piece of information - a partial credit card number - that Apple used to release information," he wrote in a postmortem examination of the digital attack.

"In short, the very four digits that Amazon considers unimportant enough to display in the clear on the web are precisely the same ones that Apple considers secure enough to perform identity verification."

Honan claims that he later chatted to his hacker via Twitter, email and AIM, and after Honan agreed not to press charges, the hijacker revealed how he broke into the Twitter, Google and Apple accounts.

The hacker, who called himself Phobia, said he didn't have to use brute force to figure out Honan's passwords for the accounts, but instead used clever social engineering to work his way from call centre to call centre.

Phobia said that the whole intrusion was designed to take control of Honan's Twitter feed because it had a three-character handle: @mat.

He followed the Twitter account's profile page to Honan's website, where he learned of his Gmail address. Phobia then started a password reset process for the Gmail account and thereby bagged another of Honan's email addresses: the Gmail account was setup to send a password reset message to the scribe's @me.com inbox. Although that address was partly obscured by Google (m••••n@me.com), Phobia guessed what it was because it had the same starting character as Honan's Gmail username.

Now that Phobia knew Honan had an AppleID account (associated with the @me inbox), he knew he could take over his iDevices.

Amazon pulled into epic hack attack

Phobia phoned Amazon masquerading as Honan and used his email address and billing address (found in Honan's Whois records for his website) to add a fake credit card to his Amazon account. The hacker hung up and then phoned Amazon again, claiming he'd been locked out of his account and used the fake credit card number, plus real email and address, to persuade Amazon tech support to let him into the account.

Once in Honan's Amazon account, Phobia could read the last four digits of the writer's real credit card in the payment settings page. Unfortunately, those four numbers, along with the addresses, were all Apple tech support needed in a subsequent phone call to allow Phobia to reset Honan's iCloud backup storage login, giving him access to pretty much every account and device Honan owned.

Graham Cluley, senior technology consultant at Sophos, told The Reg that Amazon's verification process for adding the credit card wasn't thorough enough. "A billing address and email address are probably too easy to dig out," he said.

But, as Honan himself admitted, it's normal practice for retailers to star out all but the last four digits of credit or debit cards, so Amazon had no reason not to do the same for an online account.

"Amazon made it too easy for someone to add a credit card to an account (and subsequently gain access to the account), but Apple made it too easy to access account information using the final four digits," Cluley said.

"There's any number of questions Apple could have asked - either extra support questions or they could have asked about recent purchases on iTunes or the App Store."

Apple said that its "internal policies were not followed completely" and it was reviewing its processes for password resets. Amazon had not returned a request for comment at the time of publication.

Have you enable two-factor authentication on your gmail account, are you still using the same password across all the websites you visit, and when last did you change your password. We'll like to hear your experience

Author: dfgdfg,

July 12, 2012

Hackers expose 453,000 login data allegedly taken from Yahoo service


Hackers posted what appear to be login credentials for more than 453,000 user accounts that they said they retrieved in plaintext from an unidentified service on Yahoo.

The dump, posted on a public website by a hacking collective known as D33Ds Company, said it penetrated the Yahoo subdomain using what's known as a union-based SQL injection. The hacking technique preys on poorly secured web applications that don't properly scrutinize text entered into search boxes and other user input fields. By injecting powerful database commands into them, attackers can trick back-end servers into dumping huge amounts of sensitive information.

To support their claim, the hackers posted what they said were the plaintext credentials for 453,492 Yahoo accounts, more than 2,700 database table or column names, and 298 MySQL variables, all of which they claim to have obtained in the exploit.

"We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call, and not as a threat," a brief note at the end of the dump stated. "There have been many security holes exploited in webservers belonging to Yahoo! Inc. that have caused far greater damage than our disclosure. Please do not take them lightly. The subdomain and vulnerable parameters have not been posted to avoid further damage."

Attempts to reach Yahoo representatives for comment weren't immediately successful. Because many people use the same credentials for multiple accounts, PHT isn't identifying the address of the website that published the disclosure. But at time of writing, the URL wasn't hard to find.

The TrustedSec blog is reporting that the hacked service may be Yahoo Voice, aka Associated Content. That speculation is based on the string "dbb1.ac.bf1.yahoo.com" included in the dump. The subdomain is associated with the voice service, the post said.

Author: dfgdfg,

Categories: , ,

June 6, 2012

Linkedin hacked; 6.46 million Passwords Leaked Online


Linkedin-hacked
A user on a Russian forum has claimed to have downloaded 6.46 million user hashed passwords from LinkedIn.

It looks as though some of the weaker passwords — around 300,000 of them — may have been cracked already. Other users have been seen reaching out to fellow hackers in an apparent bid to seek help in cracking the encryption.

Finnish security firm CERT-FI is warning that the hackers may have access to user email addresses also, though they appear encrypted and unreadable.

A source said they had searched and discovered their password in the cache. It has been reported that the passwords were encrypted using the SHA-1 algorithm — which is known for its flaws — but unless a password is weak, it may take a while to decrypt the remaining cache.

LinkedIn has more than 150 million users worldwide. This apparent hack could affect less than 10 percent of its user base, but it will strike a damaging blow to the ‘professional’ social network’s reputation.

It is advised users change their passwords as a precautionary measure.

LinkedIn said it was “looking into reports of stolen passwords” on its official Twitter account.

Author: dfgdfg,

April 5, 2012

Chinese websites 'defaced in Anonymous attack'


The Anonymous hacking group claims to have defaced almost 500 websites in China.

Targets hit in the mass defacement included government sites, its official agencies, trade groups and many others.

A message put on the hacked sites said the attack was carried out to protest against the Chinese government's strict control of its citizens.

It urged Chinese people to join Anonymous and stage their own protests against the regime.


Attack pattern

The announcement about the defacements was made via an Anonymous China account that was established in March. A list of the 485 sites affected was put on the Pastebin website. Separate Pastebin messages posted email addresses and other personal details stolen when sites were penetrated.

Sites defaced had the same message posted to them that chided the nation's government for its repressive policies.

It read: "Dear Chinese government, you are not infallible, today websites are hacked, tomorrow it will be your vile regime that will fall."

China has one of the most comprehensive web surveillance systems in the world, known as the Great Firewall of China, that reinforces its broader social controls. The system polices where Chinese people can go online and tries to restrict what they can talk about.

On defaced pages, the Anonymous attackers also posted links to advice that could help people avoid official scrutiny of what they do and say online. Much of the advice was in English so it is unclear how much help it would be.

There has been no official confirmation of the defacements. News wires reported that government officials had denied any had taken place.

However, many of the sites listed are now offline and a few others displayed a hacked page for a long time rather than their own homepage.

Author: dfgdfg,

Categories: , ,

February 9, 2012

Swagg Security hackers hit Foxconn, release usernames and passwords


foxconn hacked
A group of hackers known as Swagg Security is taking credit for a breach of Foxconn network security, resulting in the theft of usernames, passwords, and other private information.

In a series of Twitter posts yesterday, the group boasted that it publicly released the information on the Pirate Bay Web site as well as on Pastebin. The attack grabbed the credentials of every Foxconn employee, according to 9to5Mac, including Terry Gou, CEO of parent Hon Hai Industries.

Beyond damaging Foxconn internally, the stolen information could also create trouble for some of the company's technology partners.

"The passwords inside these files could allow individuals to make fraudulent orders under big companies like Microsoft, Apple, IBM, Intel, and Dell," Swagg Security said on its Pastebin page. Be careful ; )"

In response, Foxconn has taken down a Web site (Google cached version) explaining the services it provides to some of its key partners, including Apple, HP, Cisco, and Acer.

The group apparently was able to sneak past Foxconn's security by taking advantage of vulnerabilites in an outdated version of Internet Explorer used by one of the company's workers. Swagg Security even warned its intended victim on January 26 to make sure its browsers were up-to-date though it didn't name Foxconn as that victim.

Accessing some of the log-in information, 9to5Mac confirmed that the usernames and passwords did provide access to several Foxconn servers, most of them hosting intranet sites for company clients.

Why Foxconn? Simple answer.

Swagg Security staged its attack in response to all the reports of poor and demeaning working conditions at the manufacturer's factories across China.

"So Foxconn thinks they got 'em some swagger because they work with the Big Boys from Intel, Microsoft, IBM, and Apple? Fool, You don't know what swagger is," the group boasted on its Pastebin page. "They say you got your employees all worked up, committing suicide 'n stuff. They say you hire chinese workers 'cause you think the taiwanese are elite. We got somethin' served up good...real good. Your not gonna' know what hit you by the time you finish this release. Your company gonna' crumble, and you deserve it."

Author: dfgdfg,

October 26, 2011

Anonymous Plans to Hit Fox News on November 5


The hactivist group Anonymous plans to take down the Fox News Web site on November 5, according to a new video released recently by the group.

The group said it targeted the network for what it called biased news coverage of the Occupy Wall Street protests occurring in cities across the country.

The network's "continued right-wing, conservative propaganda against the occupations" is the group's catalyst for its intention of "destroying the Fox News Web site," a digitally generated voice on the video explains. "Since they will not stop belittling the occupiers, we will simply shut them down."

The group had earlier vowed to take down Facebook on November 5 as well, although there was some question about the credibility of that threat within the hacktivist group.

The date--November 5--is commonly referred to as Guy Fawkes day in honor of the Brit who tried to blow up parliament in the Gunpowder Plot of 1604. Fawkes was immortalized in "V For Vendetta," a 2006 movie about a freedom fighter who uses terrorist tactics against a totalitarian society, and the mask that Fawkes wears has become a symbol for Anonymous.

Author: dfgdfg,

October 20, 2011

Nepal Hackers posts 10,000 stolen Facebook accounts online


A hacking group from Nepal known as TeamSwaStika, has published 10,000 stolen Facebook accounts on Pastebin for everyone to see and take advantage of.

The group appears to have obtained the stolen accounting data, through either phishing, or data mining malware-infected hosts for Facebook credentials. Another alternative would be that they have purchased the cache containing the stolen credentials from a specific service reselling accounting data, as these services are quite popular within the cybercrime ecosystem nowadays.

As a precaution, Facebook users are advised to periodically change their passwords from a malware-free host.

Author: dfgdfg,

October 18, 2011

Hackers exposes Citibank CEO's private datas


citigroup
Hacktivists have published a dossier of personal information on the head of Citigroup in retaliation for the cuffing of protesters at an Occupy Wall Street demo.

Members of a group called CabinCr3w, a hacking gang affiliated with Anonymous, revealed phone numbers, an address, email address and financial information on Vikram Pandit, Citigroup's chief executive officer.

The exposé follows the arrest of a group of anti-capitalist protesters who allegedly sparked a ruckus inside a Citibank branch while withdrawing funds and closing their accounts. About 24 people were detained and charged with criminal trespass on Saturday afternoon, The Wall Street Journal reports.

In a statement, Citibank said only one of the protesters was actually trying to close an account, a request that it said was accommodated. The rest of the group were causing a nuisance and were repeatedly asked to leave before the New York City plod were called.

Last week Citigroup supremo Pandit offered to meet protesters, telling Businessweek that their sentiments were "completely understandable".

CabinCr3w previously published the personal information on the chief executives of JP Morgan Chase and Goldman Sachs. It also published the details of an NYPD officer accused of pepper-spraying Occupy Wall Street protesters.

The Citibank branch hubbub, whatever the rights and wrongs of what actually happened, has spawned a new campaign within the Occupy Wall Street umbrella. Op Take Back is encouraging people to close their accounts at high street banks and deposit their money with credit unions instead.

Author: dfgdfg,

September 22, 2011

Anonymous Declares 'Day of Vengeance' on Sept. 24


AnonymousLogo_270x265.png
Hacktivist group Anonymous is planning to hold a special "Day of Vengeance" in several cities around the U.S. on Saturday.

Late last night, Anonymous--or at least people claiming to be from Anonymous--posted a press release on Pastebin, saying that Saturday will be marked by peaceful protests in cities across the U.S. combined with cyberattacks on "various targets, including Wall Street, Corrupt Banking Institutions, and the New York City Police Department."

The group suggests following Twitter account @PLF2012, which it says will publish “ongoing reports” throughout the day.


The full press release:

Wednesday – September 21, 2011

On September 17, 2011 approximately 15,000 peaceful demonstrators
in dozens of cities around the USA gathered, marched – and occupied
public space to protest the unjust policies of the US government
and the corruption in our financial institutions. The central
protest site was in the financial district of New York City, where
peaceful protesters faced phalanxes of heavily armed paramilitary
police officers from local and federal jurisdictions. The arrests
began almost immediately, many for violating the 1845 so called
“mask” laws.

Later that day, and according to plan – many of these protests
ended with a peaceful occupation of public space. Again, the
central occupation occurred in NYC. More arrests continued to take
place. All of this was expected, it is part of progressive
activism. Anonymous was content to challenge these stupid “mask”
laws in court. Not only is the Guy Fawlkes mask covered under
freedom expression as a symbol of our movement, but we believe that
everyone has a right to protest anonymously using bandanas, masks -
etc.

But then on Tuesday – September 20, 2011 everything changed in a
flash of police instigated violence. As rain began to fall on the
NYC encampment, heavily armed police moved in; Removing tarps used
to cover media equipment, arresting independent journalists,
confiscating media equipment – and using excessive force against
and arresting innocent peaceful protesters, several of whom were
abused and injured.

http://youtu.be/dyvbI6Eq-qA

This year, we heard President Barack Obama and Secretary Hillary
Clinton say over and over in country after country from the Balkans
through the mid-east to Africa that the right to peacefully protest
and occupy public space is a right that MUST be respected in every
instance. And they are correct, and this also applies to the USA.
In fact, even more so. In the USA of all countries in the world,
the police should have been deployed to PROTECT the protesters -
not a giant brass bull that is the ultimate symbol of greed and
corruption in America. And yet we were treated to the grotesque
picture of dozens of armored police surrounding this brass bull,
while thousands more police were deployed solely to harass, arrest -
and abuse peaceful protesters.

http://bit.ly/qdvYAj

Anonymous & the other cyber liberation groups around the world
together with all the freedom loving people in the USA will NOT
stand for this. We will peacefully yet forcefully resist the abuses
of the NYC Police Department. And so Anonymous announces a
nationwide “Day Of Vengence” to take place in dozens of cities
across the USA on Saturday – September 24, 2011 at High Noon.

Poster – http://t.co/BSuXCdRR

Video – http://youtu.be/2svRa-VSaOU

In coordination with these protests across the USA on September
24th, Anonymous and other cyber liberation groups will launch a
series of cyber attacks against various targets including Wall
Street, Corrupt Banking Institutions – and the NYC Police
Department. We encourage the media to follow the Twitter feed
@PLF2012 for ongoing reports throughout the day.

We Are Anonymous – We Are Everywhere – We Are Legion – We Never
Forget – We Never Forgive

EXPECT US — Anonymous

Author: dfgdfg,

Categories: , ,

September 19, 2011

Japan's biggest defence contractor hit by hackers


mitsubishi_logo
Mitsubishi Heavy Industries factories that build guided missiles and rocket engines; submarines; and nuclear-power equipment have had their computer networks hacked.

The firm said that the attack resulted in the infection of 10 of its sites across Japan, including its submarine manufacturing plant in Kobe and a facility in Nagoya which makes engine parts for missiles. In total 45 network servers and 38 PCs became infected with eight strains of malware, including Trojan horse programs.

News of the security breaches emerged over the weekend. Mitsubishi said the circumstances of the intrusions – first detected in mid-August – are under investigation, with a report due by the end of the month. In the mean time the firm is playing down suggestions that the malware may have been used to successfully extract industrial secrets via compromised systems.

A Mitsubishi spokesperson said "We've found out that some system information such as IP addresses has been leaked and that's creepy enough.

"We can't rule out small possibilities of further information leakage but so far crucial data about our products or technologies has been kept safe," he added.
Attacks against defence contractors have appeared frequently in the news of late. Earlier this year Lockheed Martin and L-3 Communications said they had each come under attack via an assault that relied on data stolen during the earlier RSA megahack.

Presumed industrial espionage attacks against defence contractors and energy firms are often blamed on China, an accusation that the country strongly denies. Evidence that China is involved tends to come in the form of the origin of the attack (easily faked using a compromised system in China) or regional quirks and the languages used in hostile code (harder to spoof but still inconclusive).

Author: dfgdfg,