Saturday, June 16, 2012

United States Department of Defense data leaked by Anonymous hackers


dod-coin-on-american-flag

 
A group called the "Wikiboat" belongs to Anonymous hackers have attacked the Defense.gov website and leaked data from the website. They have published the leaked data to the pastebin note. Also, today the Wikiboat targeted the GEMA.de website and took it offline.

The leaked data includes some officials name, Emails ID's and Phone numbers as shown below:
dod_data

Hackers claim that, they have not collect this data from any SQLi vulnerability, even this data is collected form other sources. Three weeks before they was threatening to take down the websites of companies like Apple, Bank of America and Toyota and leak sensitive data.
 
As part of its "Operation New Son ' they announced to attacks on a number of international companies.

Tuesday, June 12, 2012

OpenVPN Defaced by Hackers


OpenVPN+Defaced+by+Hackers

OpenVPN is a robust and highly flexible tunneling application that uses all of the encryption, authentication, and certification features Got Hacked Yesterday by Hacker called "HcJ".Hacked deface the page as shown in above picture. Words form Page:
OPENVPN Hacked
No News Is a Good News
HcJ & Cyb3R-1sT & Egyptian.H4x0rZ & Sas-TerrOrisT & H311 c0d3 &ISM H4CK
Quote of the Day
Don’t be lammer, Leave your computer and enjoy your summer ./ HcJ

During the writing of post, OpenVPN officials restore the site back to original state. If you like to see the deface page, can visit Zone-H for mirror.

VPN Hacks May Leak Information: Such hacks can also be carried out by investigation agencies to collect evidences against various hackers. Always use double VPN or Tor with VPN for better Security.

10000 Twitter User oauth token hacked and Exposed by Anonymous


data

Anonymous Hackers, with Twitter account "LulzsecReborn" Hack into TweetGif (http://tweetgif.com) and Hack complete Database, Later they publish that on Internet also. TweetGif is a website which allow you to use animated GIF image as your twitter picture.
 
LulzSec Reborn, a 3.0 version of the earlier LulzSec, has leaked 10,000 Twitter profiles’ passwords,  Usernames, real names, locations, bios, avatars and secret tokens used to authenticate their accounts.
Pastebin message posted: The leaked data was uploaded to embed upload and contains a 4 MB SQL file with all the users details.
Users table from http://tweetgif.com/ nothing serious like 10.000 twitters…
http://www.embedupload.com/?d=9ZMOMGIIQA


How Hackers and Spammer can use this?
OAuth is an authentication protocol that allows users to approve application to act on their behalf without sharing their password. If your Twitter oauth Secret Key and Token get compromised , then application or Hacker can user your Twitter account on Behalf of Your access. You can get sample script here. These accounts can be used to spam over 10000 of compromised twitter accounts.

Also if hackers are able to compromise the keys of popular applications like TweetGif and use those keys to evade Twitter's abuse controls. By using the consumer key and consumer secret key from a popular third-party Twitter application, a spammer can make it harder for Twitter to lock out all of his spam accounts at once without also locking out a large number of legitimate users of the compromised application.

How you can Protect your Twitter Account: If you are also TweetGif  User, you need to go to settings > apps > deauthorize app. #TweetGif. "Revoke Access".

Flame spy virus going to Suicide


Flame+spy+virus+going+to+Suicide

The creators of the world's most complicated espionage virus Flame have sent a 'suicide' command that removes it from some infected computers. U.S. computer security researchers said on Sunday that the Flame computer virus, which struck at least 600 specific computer systems in Iran, Syria, Lebanon, Egypt, Sudan, Saudi Arabia and the Palestinian Authority, has gotten orders to vanish, leaving no trace.
 
The 20-megabyte piece of malware already had a self-destruct module known as SUICIDE that removed all files and folders associated with Flame, but the purging command observed by Symantec researchers instead relied on a file called browse23.ocx that did much the same thing. According to Symantec, the ‘suicide' command was “designed to completely remove Flame from the compromised computer,” the BBC reports.

Computers infected with Flame, including honeypots, have been routinely contacting its C&C servers to check for new commands. When the C&C servers still owned by Flame’s authors recently sent out a self-destruct code, Symantec detected the command immediately.

Flame was designed to suck information from computer networks and relay what it learned back to those controlling the virus. It can record keystrokes, capture screen images, and eavesdrop using microphones built into computers.

Bots have long contained such self-destruct mechanisms, so it's not surprising that malware as complex and comprehensive as Flame would, too.

CVE-2012-2122 : Serious Mysql Authentication Bypass Vulnerability


mysql_logoA serious security bug in MariaDB and MySQL Disclosed, According to Advisory All MariaDB and MySQL versions up to 5.1.61, 5.2.11, 5.3.5, 5.5.22 are vulnerable. This issue got assigned an id CVE-2012-2122.
 
"When a user connects to MariaDB/MySQL, a token (SHAover a password and a random scramble string) is calculated and comparedwith the expected value. Because of incorrect casting, it might'vehappened that the token and the expected value were considered equal,even if the memcmp() returned a non-zero value. In this caseMySQL/MariaDB would think that the password is correct, even while it isnot. Because the protocol uses random strings, the probability ofhitting this bug is about 1/256."

"Which means, if one knows a user name to connect (and "root" almostalways exists), she can connect using *any* password by repeatingconnection attempts. ~300 attempts takes only a fraction of second, sobasically account password protection is as good as nonexistent.Any client will do, there's no need for a special libmysqlclient library."

The following one-liner in bash will provide access to an affected MySQL server as the root user account, without actually knowing the password.

$ for i in `seq 1 1000`; do mysql -u root --password=bad -h 127.0.0.1 2>/dev/null; done
mysql>

Defense: The first rule of securing MySQL is to not expose to the network at large in the first place. Most Linux distributions bind the MySQL daemon to localhost, preventing remote access to the service. In cases where network access must be provided, MySQL also provides host-based access controls. There are few use cases where the MySQL daemon should be intentionally exposed to the wider network and without any form of host-based access control.

the easiest thing to do is to modify the my.cnf file in order to restrict access to the local system. Open my.cnf with the editor of your choice, find the section labeled [mysqld] and change (or add a new line to set) the "bind-address" parameter to "127.0.0.1". Restart the MySQL service to apply this setting.

Note: Download The Latest Exploits for CVE-2012-2122 From our TOOLS YARD section.

Online game 'League of Legends' Compromised


Online+game+%27League+of+Legends%27+Compromised





A recent slew of security failures have left countless accounts hacked at sites like Linkedin and eHarmoney. Now League of Legends is the latest database to suffer from hackers this week.
 
Riot has sent out a mail to registered League of Legends players in Europe, asking them to change their passwords due to a hackers accessing some player account information. Full details are below, but know that according to Riot,” absolutely no payment or billing information of any kind was included in the breach.” but email addresses, encrypted account password, summoner name, date of birth, and for a small number of players – first and last name and encrypted security question and answer.

Obviously, this information could be used in phishing scams. Riot Games does encrypt passwords through it warns “our security investigation determined that more than half of the passwords were simple enough to be at risk of easy cracking”. Marc Merrill and Brandon Beck posted an update on the situation, as well as a formal apology which you can read below.

As these things go, Riot appears to be handling this embarrassing situation relatively well. There's no info yet on exactly when the breach took place.

Finally, Riot's Marc Merrill Brandon Beck have apologised to players for the breach, saying "We take your privacy and security seriously, and we're working diligently to improve it for the better."


Anonymous did Protest and IT ministry says 'Anonymous' is lying


anonymous-group-wear-fawkes

The call for demonstrations by the Indian arm of the group follows a March 29 court order issued in the southern city of Chennai demanding 15 Indian Internet providers block access to file-sharing websites such as PirateBay.
The order has resulted in access being denied to a host of websites that carry pirated films and music among other legal content, including www.isohunt.com and www.pastebin.com.On Wednesday, the Anonymous forum fired an opening shot by attacking the website of state-run telecom provider MTNL, pasting the logo of the group the mask of 17th century revolutionary Guy Fawkes on www.mtnl.net.in.

Computer Emergency Response Team (CERT-IN), the country's premier agency dealing with cyber security contingencies, said that its website was neither attacked nor brought down on Saturday. Hackers allegedly belonging to the group called Anonymous had earlier claimed they had attacked CERT-IN website with Distributed Denial of Service (DDoS) attack.

A spokesperson from ministry of communications & IT told TOI, "The claim that CERT-IN website was attacked and brought down by hackers is without any basis and at complete variance with the facts. The fact is that the website has been running continuously & uninterruptedly  including the whole of today."

"We don't want anything to be censored online because now-a-days the web is an effective tool to express thoughts and share things with others - be it through social networking or emails," said a volunteer from the group. "Without Internet, people cannot be liberated," added another participant.
group-anonymous-wear-masks


The minister was said to have shown Internet executives examples of obscene images found online that risked offending Muslims or defamed politicians, including his boss, the head of the ruling Congress party, Sonia Gandhi.

Earlier Anonymous, which protested against what it perceives web censorship in several Indian cities today evening, had claimed that it attacked and took down CERT-IN website. "This is your response team #india! They can't even protect themselves. How will they protect others," read a tweet from @opindia_revenge, the group's Twitter handle.

"We will keep attacking http://cert-in.org.in and http://india.gov.in ! #GOI, ready to face ups and downs?" said the hackers.

Image Credit: Rt.com

Critical SQL Vulnerability in channel [V] Website


v

A 16 years old White Hat Hacker "Arjun Siyag" from India discover a Critical Sqli Vulnerability in channel [V] Website (http://www.channelv.in). Proof of the hack is as shown in above image. Hacker disclose only the admin username and password, which will not effect the admin panel directly,because for login Email ID is required. 
SQL Injection is one of the many web attack mechanisms used by hackers to steal data from organisations. It is perhaps one of the most common application layer attack techniques used today. Through SQL Injection, the hacker may input specifically crafted SQL commands with the intent of bypassing the login form barrier and seeing what lies behind it.

This is only possible if the inputs are not properly sanitised (i.e., made invulnerable) and sent directly with the SQL query to the database. SQL Injection vulnerabilities provide the means for a hacker to communicate directly to the database.

Serious Tumblr Cross Site Scripting Vulnerability can be used to Spread Worms


Screen+Shot+2012-06-09+at+4.51.35+PMTwo Indian Security Researchers Aditya Gupta (@adi1391) and Subho Halder (@sunnyrockzzs) have found a serious Cross Site Scripting vulnerability in one of the most famous social networking websites Tumblr.
 
This could be used to steal the cookies of the authenticated user, as well as could be used to make a worm, like the one seen in MySpace (Samy Worm) and Orkut (Bom Sabado) earlier.

"We have also tried to contact them via Twitter and mail earlier, but no response from their side. So we have decided to release it. Well, not exactly, where the vulnerability is, but just to let them know that it is vulnerable."

Tumblr is the one of the most popular social networking websites worldwide, and is ranked 37th by Alexa.

Saturday, June 9, 2012

Last.fm Confirms They Were Hacked, Change Your Passwords Now !!!


Last.fm+Confirms+They+Were+Hacked

After this week’s LinkedIn fiasco, it appears the latest tech giant to fall to bored hackers is Last.fm. Music-streaming website Last.fm is the latest organisation to urge its users to change their passwords immediately.

The London-based site, owned by CBS, said in an advisory that it was currently investigating a possible leak of passwords but did not provide any further details.
 
The dating site said it is "continuing to investigate" but "as a precaution" has reset affected members passwords.Affected members will receive an email with instructions on how to reset their passwords.eHarmoney, which brands itself as "#1 Trusted Online Dating Site for Singles" has around 20 million registered online users.
The breach was confirmed by Last.fm on their official Twitter account overnight, and comes amidst a backdrop of similar breaches, including at LinkedIn where up to 8 million passwords may have been compromised, and at dating site eHarmony where 1.5 million passwords were harvested.

Here are some tips to keep your passwords safe:
  • If you get an email from any services asking your to update your information, DO NOT CLICK on the link the in the email. Odds are pretty high it’s spoofed.
  • Do not use the same password for everything. I have one password for throwaway accounts, one for sites that don’t have much information on me, one for those that have a bit of info, and unique passwords for each account that has a high level of information, like my bank account.
  • Do not use “password,” “12345,” or any other easily guessable words. If you have to use one word so you can remember it, choose a word that does not mean anything to anyone except you. Try misspelling it and adding numbers. For example, I have passwords that are from other languages but spelled incorrectly (as well as a few other memes).
  • If you’re feeling advanced, you can try this trick: Think of the first line of a song you like, take the first letter of each word in that line, then put them together. Swap out some of the letters for numbers if you can and maybe add a symbol or two.
  • DO it now. I know it’s a pain, but better safe then sorry. And again DO NOT CLICK on anything from an email. Only go to the site directly in a new tab or window.
  • To make your life easier in the future, keep a list of every site you create a login for. That way, when it’s time to do a clean sweep, you know exactly where to go.
Recommended Post Slide Out For Blogger