Learn Hacking And Get Hacking tools
Across the United States, law enforcement officers have arrested 14 people the FBI claims are connected to the group Anonymous. The arrests follow raids on the suspects’ homes. It looks like these suspects aren’t directly connected to LulzSec, the anti-security hacker group that seemed to split off — and later rejoin — Anonymous. Instead, these members may have used their computers to participate in direct denial of service (DDoS) attacks against targets like credit card companies during various Anonymous operations.
“They [the Storm gang] don’t need a ‘supercomputer’,” said Ducklin. “They just need a wide range of different computers to do their dirty work. It’s not so much about CPU, and RAM, and disk space. It’s about being able to operate from a widely distributed and ever-moving target. Slim down the target and it becomes much easier to hit.”
Others who left comments on Petkov’s post, however, made a wide range of claims. Some, for instance, reported that the proof-of-concept samples that Petkov offered up failed on Windows XP SP2 when running Opera, while others said Firefox on Mac OS X is also invulnerable to the hacks.Some people just have no idea what they are doing. Here we go again â this is another case of overzealous security that can seriously end up in hurting the ones who should be protected!
General Motors is going to come up with a system to make car thefts history⌠at least in their opinion! The technology is called Stolen Vehicle Slowdown and itâs used, as you might have imagined, to slow down cars. So, basically, should the Police be chasing a stolen vehicle, or a speeding one, they could call GM and ask for them to remotely shut down the engine. Now, surely this would help the Police a lot, but letâs think what else could happen.
Over the time, weâve learned that hackers can do just about anything if they have the right skills and the right tools. So, if they bypass GM security systems and gain access to the control panel for this technology, things could end up in a disaster! Also, malicious insiders could wreak havoc on the streets, by abusing this system.
And imagine what could happen if a hacker accesses the system and, instead of slowing down the engine, would actually reverse the process and increase velocity â now that would cause a lot of problems, probably death! Also, these systems are going to be controlled remotely, fact which means jamming stations could be put in place to avoid control. I donât even want to think what could happen if a terrorist gained access to this system!
These are just a few possible things, and when GM releases this new technology, they need to think things through and be pay even more attention to aspects of security! But do not worry, this system isnât something compulsory. You have to choose if you want it or not; furthermore, itâs not out yet â itâs going to be available in 2009. I hope that by then, they will have the time to improve security too. And I certainly hope that nothing of what I have predicted in this article is going to come true!
We’re not looking at general availability yet, but those happy hacking cats unravelling the iPod touch have decrypted the ramdisk and are now busy installing applications. Already, Mail, Maps, and other 3rd party apps are up and running on their jailbreaked touches. The race is on between the cat and the mouse to see who will release their wares first. Maps screenshot after the break.
YOU’VE got ten minutes until you need to leave for the airport, but you just have to send out that e-mail containing this month’s sales figures. Dashing up the street in search of a taxi, you spot the magic words “wireless hotspot” in a cafĂŠ window. The figures are sensitive, but the cafĂŠ is almost empty. You sit down, facing your laptop screen away from the few others in the room and log on.
Safe as houses. Or not? Richard Rushing, chief security officer for US firm AirDefense, says people are leaving themselves open to fraudsters every day through insecure public wireless networks, which have transformed working practices.
Rushing, in Edinburgh to speak to Scottish business leaders about how to secure company data, believes groups of “bad guys” are targeting areas they know business people are likely to frequent, such as airports, or a cafĂŠ near financial institution headquarters.
He says most open networks, such as those offered for free in many public places, such as airports, coffee houses and even telephone booths, are insecure – and anyone with access to the same network could steal information just by logging on.
A former consultant for the CIA and the FBI, Rushing knows how important it is for companies – and individuals – to keep their data protected. “With more and more companies going to wireless now, it is a growing problem,” he says.
“If they supply laptops to their employees, they are at risk.
The people who are doing this are looking for company data, they’re looking for anything that is valuable, credit card details, even just knowing that people are there.”
Rushing’s firm, based in Georgia but with an operation in Basingstoke, can advise on how firms can make their computers more secure – by supplying software to encrypt data sent over the internet and also a package that can alert a PC user to someone trying to access information.
“A cafĂŠ owner doesn’t know what the situation is with his Wi-Fi – it’s not his responsibility,” says Rushing.
“He doesn’t think about the wireless network unless a customer tells him it doesn’t work, then he unplugs it, plugs it back in and asks ‘Does it work now?’ That’s it. A lot of them, especially those which are cheap to use, or even free, are unlikely to have encrypting technology.”
With plans for Edinburgh to become a city-wide Wi-Fi hotspot underway and many Scottish cities already covered by BT’s service, businesses were keen to listen to his message, with representatives from Standard Life, ScottishPower and Royal Bank of Scotland signing up to Rushing’s seminar.
Rushing, who has worked as a computer security adviser for the likes of Siemens and General Electric, and most recently held the role of chief technical officer of VeriSign’s network security services division, adds: “People get excited by wireless networks, at home as well. They say ‘great – I can log on to my next door neighbour’s wireless!’ But that means their neighbour could possibly log on to theirs too – and potentially see all of their personal information.”
Hackers do not need special software to check on what their network co-users are up to. “It’s not like they can see your screen shot for shot,” says Rushing. “But they can see any data that is sent via the internet, on an e-mail, over a website form and so on.
“You wouldn’t put your bank details on a postcard and send it through the mail for everyone to see, so why would you send them through an insecure network?”
In addition to protecting sensitive business information, Rushing is also keen to educate workers on keeping personal data close to their chests.
“If you’re out, you have your laptop and find you’re in a Wi-Fi zone, it is fine to use the internet to do certain things like check the football scores,” he says. “But if you’re not sure the network is safe, leave checking your internet bank, or using your credit card for when you are somewhere where you know no-one can access what you are doing.”
Anna Steven, senior press officer at BT, says wireless security was a hot issue for both broadband providers and companies.
The firm, which already uses AirDefense’s systems for wireless intrusion detection in around a dozen BT buildings UK-wide, recently launched a high-security way of sharing wireless broadband with other people – by providing separate channels for different users.
Steven said: “Users need to assess what is at risk and then implement the appropriate technology to protect it.”
We like to imagine that hackers are smart, but it is their collective incompetence that has allowed the IT industry to survive their attacks as long as they have. Viruses may be unleashed, worms may spread, but usually the McAfees and Symantecs of the world are quick enough to help isolate and deal with such malware in a manner of weeks, if not days. This was the case with Sasser, Nimda, and even Code Red. Rare is the malware that acts with the consistent, determined approach of a stealth marketing campaign. This, however, has been the hallmark of Storm, a quietly professional example of online organised crime at its best. And scariest.
You know something’s different when Storm starts cropping up in the pages of mainstream newspapers, as it did in the Toronto Star here in Canada last week. In a story which described Storm as the “syphilis of computers”, the Star explained in very basic, accessible terms what the threat is and how it is growing. It’s the kind of story you would have expected to find written about head lice in elementary schools or, before SARS hit Toronto, the nature of pandemics. A problem historically of concern to specialists such as doctors (or in Storm’s case, IT managers) is translated for a mass audience, because the specialists are proving incapable of stopping the worst of its effects.
The most recent reports about Storm, particularly a blog post from Secure Works researcher Joe Stewart, suggest that the hackers behind it are splitting up access to the compromised computers for sale to spammers. It doesn’t matter whether you believe there are millions of such zombie machines or, as some experts say, a quarter of a million. We’re potentially talking about an army of infected machines the size of several corporate enterprises. Selling them to those who send unsolicited commercial email is the least of the dangers such a “market” of botnets poses.
We’ve become so used to the identify-contain-forget cycle of security that Storm may require a completely different mind set, both for IT managers and their users. Storm has already hung on for the better part of a year. There’s little to indicate it will be on the wane anytime soon. Instead of seeing such malware as a short-term event which we combat and vanquish, we may have to think of coping strategies that extend to several years. This would, of course, have major implications for enterprise IT security policies, which typically focus on user behaviour in exceptional circumstances (illegal downloads, connecting an unknown device to the network) rather than guidelines for ongoing vigilance.
Storm got its name because of an email message that warned of a disastrous weather event that was taking place in Europe, but the metaphor may not really apply anymore. When a real storm ends, people can usually walk around the way they did before. With the Storm malware, the rain might keep falling. IT managers will have to decide whether to permanently carry an umbrella, or get used to being wet.
TIRUCHI: The Chinthamani Cooperative Supermarket at Puthur here has fixed a cracker sales target of Rs. 1 crore for Deepavali festival. The authorities have planned to establish 10 special sales outlets in the Chinthamani branches at Puthur and Teppakulam in the city and Manapparai and Kulithalai towns to sell popular brands of fireworks.
Transport Minister K.N. Nehru inaugurated the sale at a function held at the Chinthamani supermarket on Sunday.
The cracker outlets will function from 9 a.m. to 9 p.m. on all days till Deepavali and adequate stock of crackers have already been procured.
A sales target of Rs. 35 crore has been fixed for the supermarket during the current financial year through its six branches at Kailasapuram, Subramaniapuram, Puthur and Teppakulam in the city and Mapparai and Kulithalai towns. The business done during the half-year stood at Rs. 19 crore.
Special arrangements have been made for the sale of essential commodities such as sugar, dhal, rava, maida, dalda and edible oil at the supermarket in connection with Deepavali. The supermarketâs annual turnover through the sale of controlled and non-controlled commodities was Rs. 45 crore, according to its Special Officer
A. Palanivel. MLAs Anbil Periasamy and K. N. Sekaran, Deputy Mayor M. Anbalagan, deputy registrar of Public Distribution System Sirajudeen were present.
eBay has begun an audit of its IT systems after a hacker managed to access and disable user accounts. The company said last week that the hacker exploited public application programming interfaces (APIs) that enable merchants to build e-commerce sites on top of eBay. “This fraudster found very old administrative interfaces into the eBay system that had not been deactivated when we changed the security of our internal systems several years ago,” a member of the company’s trust and safety division said in a posting on an eBay blog.
The Chinese state is behind almost daily internet espionage attacks on German companies and government bodies, a top German intelligence official said on Monday. “In our view, state Chinese interests stand behind these digital attacks,” said Hans Elmar Remberg, vice president of the Federal Office for the Protection of the Constitution, the country’s domestic intelligence agency.
“Supporting this view is the intensity, structure and scope of the attacks, and above all the targets, which include [German] authorities and companies,” Remberg told a conference on industrial espionage in Berlin.
In August, German media reported that computer hackers believed to be linked to the Chinese army had infected German government ministries with spying programs. Beijing denied the allegation and said all “hacking” behaviour was prohibited.
“Some people call this the Chinese cyberwar,” Remberg said, adding that a new concept for protection against such cyberattacks was needed.
Remberg added it was important to differentiate between legitimate attempts to gather information on competitors by Chinese companies and state-led industrial espionage.
Driving China’s interest in industrial and government secrets is its desire to become a top global economic power, Remberg said. To catch up with the West, China needed “a massive transfer of high technology”.
“Across the world the People’s Republic of China is intensively gathering political, military, corporate-strategic and scientific information in order to bridge their technological gaps as quickly as possible,” Remberg said.
The attacks often rely on “Trojan horse” email programs or the hacking of websites, Remberg said.
“Astonishing intensity”
The attacks on German ministries and authorities had an “astonishing intensity” and the perpetrators appeared unconcerned that the attacks were being discovered.
“Every one or two days new attacks are detected,” Remberg said.
China is also using classic espionage methods.
“The diplomatic representative offices and Chinese media agencies in Germany enable the hidden deployment of intelligence agents,” Remberg said.
Firms in joint ventures with Chinese firms were also at risk, Remberg added.
China is not the only country engaged in such espionage, according to Remberg.
“Russian intelligence agencies are making great efforts in Germany to get important information in the military fields, politics, economy and science, using both open and conspiratorial methods,” Remberg said.
Remberg added that other countries had sent intelligence agents to Germany to procure “dual-use” machinery and know-how for illegal weapons technology, including nuclear technology.
Remberg named Iran, North Korea, Pakistan and Syria as countries seeking to procure technology with dual civilian and military uses.
UK IT professionals are more concerned about internal system failures than hacker attacks, according to new research. The study by training company Firebrand Training asked 601 UK IT workers to rank their greatest concerns. System failure ranked the highest with 63 per cent of those questioned more concerned about interrupted IT services than the 24 per cent who ranked external threats as their key worry.
Technology issues rate far higher than human error or breaches in security from employees.
Almost half of those questioned said they did not worry about security threats from their companyâs staff.
The research indicates a trend towards external security issues taking a back seat to day-to-day operational concerns, said Firebrand Training chief executive Robert Chapman.
“The fact that IT staff are pushing protection against external threats to the bottom of the pile is concerning,” he said.
âSecurity must be higher up the priority list for IT because a security breach, whether by a hacker or a disgruntled employee could be far more damaging in the long run than a few hoursâ downtime.”
Hacker bust for virtual theft. Dutch police arrested a 17-year-old who stole ÂŁ2 500 worth of virtual furniture from an online hotel. The teenager was arrested after playing Habbo Hotel, an international online community with an estimated seven million members and an annual turnover of ÂŁ3 million, states The Times. The game allows players to create virtual characters, or Habbos. These characters can take their own rooms in the hotel, which they can then decorate with their own furniture. The furniture is purchased with special Habbo credits, but the credits are paid for with real money.
The teenager hacked into the accounts of other Habbo community members, took their furniture and put it in his own room. The 17-year-old has been charged with hacking and burglary.
Dell unveils all-in-one PC
Dell has introduced an all-in-one computer that combines the monitor and CPU in one box, says PC World.
The XPS One will be available as a system with only a widescreen display, a mouse and keyboard. Processing capabilities and other components will be fixed inside the display.
The systems will be available in four designs with the monikers indicating the target audience: the Essential One, the Music One, the Performance One and the Entertainment One.
eBay bot hops to other sites
Yet another sophisticated Web-based attack against eBay and its users is being investigated by a Tel Aviv-based security vendor that discovered a similar attack two months ago involving a custom-made bot designed to steal accounts, states Network World.
Ofer Elzam, Aladdin Knowledge Systems’ director of product management, says his firm has determined in the last few days that at least two Web sites, Save Our Planet and Nova Radio, appear to have been compromised with malicious code that combines to launch an attack against a site visitor.
The goal of the attack is to combine code to break in through the browser to the victim’s desktop and install a Trojan to collect eBay user account information, if it’s found, and connect to eBay to use that account information to commit fraud.