Showing posts with label News. Show all posts
Showing posts with label News. Show all posts

Apr 22, 2016

Panama Papers – How Hackers Breached the Mossack Fonseca Firm

Introduction

The Panama Papers are a huge trove of high confidential documents stolen from the computer systems of the Panamanian law firm Mossack Fonseca that was leaked online during recently.
It is considered the largest data leaks ever, the entire archive contains more than 11.5 Million files including 2.6 Terabytes of data related the activities of offshore shell companies used by the most powerful people around the world, including 72 current and former heads of state.
Figure 1 – Data Leaked (Source: Süddeutsche Zeitung)
To better scale the dimension of the data leaks, let’s compare the dimension of the stolen data to the size of archives disclosed after other

Mar 23, 2016

Android Forensic Logical Acquisition

Introduction

The following is a demonstration of how we will create an Android Emulator; then we will go through needed steps to acquire a logical image of the system and how we can start forensically analyzing it.
In mobile forensic world (depending on the OS, the OS version, and the device) there are in general three main acquisition techniques:
  • Direct acquisition
  • Logical acquisition
  • Physical acquisition
The direct acquisition technique can be performed if the seized device is either not locked or the PIN/Password/Pattern lock is known by the investigator, this way every data available to the user is available to the examiner via the usual user interface(UI). The only “disturbing” point is that if relying on only this method, system files, systems logs or system partition is not accessible.
The logical acquisition is a bit-by-bit copy of a given logical storage, (the storage may refer to user data partition as well as system data partition), and this acquisition method produces

Feb 13, 2016

How Malware Detects Virtualized Environment (and its Countermeasures)

Virtual Machines are usually considered a good way to analyze malware as they can provide an isolated environment for the malware to trigger but their actions can be controlled and intercepted. However, modern age malware detects their environment in which they

Jan 28, 2016

Cellphone Surveillance: The Secret Arsenal

StingRay and the cellphone surveillance

In a previous post, I detailed the technologies used to track mobile devices, with a specific reference to the StingRay IMSI-catcher (International Mobile Subscriber Identity).
An IMSI-catcher is a surveillance solution used by law enforcement, military and intelligence agencies for telephony eavesdropping, it is the technology used for intercepting mobile phone traffic and tracking movements of mobile phone users.
An IMSI catcher runs a Man in the Middle (MITM) attack acting as a bogus mobile cell tower that sits between the target mobile phone and the service provider’s real towers.
The only way to prevent being tracked by an IMSI catcher is using specific

Nov 26, 2014

'Regin' - 'State-Sponsored' Spying Tool Targeted Govts, Infrastructures for Years


CryptoPHP Backdoor Hijacks Servers with Malicious Plugins & Themes

Nov 16, 2014

Spy Planes Equipped with Dirtbox Devices Collecting Smartphone Data

Nov 12, 2014

European Space Agency’s Spacecraft Lands on Comet’s Surface

The Philae has landed.
 
 
The European Space Agency’s ambitious attempt to place a spacecraft on the surface of a comet succeeded when a signal arrived at the mission control center at Darmstadt, Germany, just after 5 p.m . local time (11 a.m. Eastern time).
Cheers erupted.
“We’re there and Philae is talking to us,” said Stephan Ulamec, the manager for the lander. “We are on the comet.”
The lander, Philae, and its 10 instruments have now begun 64 hours

Nov 4, 2014

Sony Xperia Devices Secretly Sending User Data to Servers in China



AirHopper — Hacking Into an Isolated Computer Using FM Radio Signals

BlackEnergy Malware Targets Linux Systems and Cisco Routers

blackenergy-malware
BlackEnergy Malware Targets Linux Systems and Cisco Routers

 
Cyberespionage Group, generally known for using the malware BlackEnergy for their cyber-crime activities has been compromising routers and Linux system based on ARM and MIPS architectures in addition to Windows Computers.
BlackEnergy was mainly developed by cybercriminals to

Vulnerability in e-Commerce Wordpress Plugin: Buy Anything Without Paying

wordpress-ecommerce-plugin
Vulnerability in e-Commerce Wordpress Plugin: Buy Anything Without Paying

Alongside Drupal, one of the most popular CMS Wordpress seems also to be vulnerable to serious flaws. Researchers at Sucuri have found an information leak and access control bypass vulnerability in popular WP eCommerce Plugin.

WP eCommerce Plugin is mainly used for selling products, downloads as well as memberships online. The number of downloads of this plugin clearly says how much popular it is- 2.9 Million.

According to the researchers, the vulnerability can be exploited by

Rootpipe — Critical Mac OS X Yosemite Vulnerability Allows Root Access Without Password


Mar 22, 2013

Apple blocks ad-injecting Mac trojan, Yontoo

Yontoo trojan throws extra ads into Web pagesA day after Russian anti-virus firm Doctor Web highlighted an adware Mac trojan called "Yontoo," Apple has moved to block it. Confirmed by Intego, Apple has updated the definitions included in OS X's Xprotect.plist in order to detect the adware, meaning users don't need to run anything special in order to be protected.
"In testing, it appears this detection is very specific and potentially location-dependent," wrote Intego. "This extra specificity is likely there so as to catch only the surreptitious installations of this file."

As we wrote on Thursday, the Yontoo adware socially engineers users into installing it as a browser plugin. Once it's installed into Safari, Firefox, and Chrome, the plugin injects advertising into the websites you're visiting—including those that don't even normally show ads.
The plugin poses a risk not just because it's annoying to see third-party ads where they don't belong, but because those behind the trojan could inject other malicious code. (The same trojan exists for PC users as well.) But now that Apple has added Yontoo to the built-in malware protections in OS X, it's a lot less likely that Mac users will end up accidentally installing it.

Source:http://www.arstechnica.com

Feb 6, 2013

Bicololo malware spreading via 404 Error targeting Russians

Bicololo virus spreading via 404 Error
A Trojan that attacks Russian Internet users using a new trick to spread itself. Known as "Bicololo" was first discovered in October 2012 and specially designed to steal login credentials from users. 
For this, the malware modify the system Hosts file (i.e etc/hosts) to host perfect phishing sites via DNS poisoning to

Feb 5, 2013

Wine On Android For Running Windows Apps

Wine On Android For Running Windows Apps
As you know, many enthusiasts Android mobile users wishing for alternate of WINE software for Android mobiles or tablet as well, that allow applications designed for Microsoft Windows to run on Unix-like operating systems. Sounds Interesting ?
Alexandre Julliard, the original developer behind the Wine software project working on upcoming WINE version that will allow you to run windows apps on Android platform. Wine development talks being held during FOSDEM 2013.
In a Demo Julliard showed lite version of Wine running on Android, was quite slow. Anyway, this Wine port for Android is an active work-in-progress and hasn't received much attention yet.
Before this

Android malware with ability to install Backdoor on Computers

Kaspersky Lab has revealed a new type of malware that can infect your computer when connected smartphone or tablet. Two such application, Super Clean and DroidCleaner found in Google Play android market. These two are actually same application, just released with two different names.
Android hacked
These applications apparently disguised as a tool to clean memory for the Android operating system but after installing and running it displays a list of all running some processes and then restart the device. Later, in background, the app downloads three files autorun.inf, folder.ico, and svchosts.exe in phone.


When user connect infected android mobile phone to any Windows computer with active Autorun or Autoplay functionality for USB devices, the svchosts.exe file (Backdoor.MSIL.Ssucl.a) is automatically executed on computer. A similar situation may arise in case of SD card.
Android malware with ability to install Backdoor on Computers
Before apps were removed by Google, they may together have been downloaded up to 6000 times. Malicious code then starts capturing the sound instantly from systems microphone and all recorded data is sent to remote servers after encrypting files.
Other than this, the malware is capable of Sending SMS messages, Enabling Wi-Fi, Gathering information about the device, Opening arbitrary links in a browser, Uploading the SD card’s entire contents, Uploading an arbitrary file to the master’s server, Uploading all SMS messages, Deleting all SMS messages, Uploading all the contacts/photos/coordinates from the device to the master.
The attacks are becoming more sophisticated and users, especially those with low knowledge of technology come easily to the hook of cyber criminals.

Android malware with ability to install Backdoor on Computers

Kaspersky Lab has revealed a new type of malware that can infect your computer when connected smartphone or tablet. Two such application, Super Clean and DroidCleaner found in Google Play android market. These two are actually same application, just released with two different names.
Android hacked
These applications apparently disguised as a tool to clean memory for the Android operating system but after installing and running it displays a list of all running some processes and then restart the device. Later, in background, the app downloads three files autorun.inf, folder.ico, and svchosts.exe in phone.


When user connect infected android mobile phone to any Windows computer with active Autorun or Autoplay functionality for USB devices, the svchosts.exe file (Backdoor.MSIL.Ssucl.a) is automatically executed on computer. A similar situation may arise in case of SD card.
Android malware with ability to install Backdoor on Computers
Before apps were removed by Google, they may together have been downloaded up to 6000 times. Malicious code then starts capturing the sound instantly from systems microphone and all recorded data is sent to remote servers after encrypting files.
Other than this, the malware is capable of Sending SMS messages, Enabling Wi-Fi, Gathering information about the device, Opening arbitrary links in a browser, Uploading the SD card’s entire contents, Uploading an arbitrary file to the master’s server, Uploading all SMS messages, Deleting all SMS messages, Uploading all the contacts/photos/coordinates from the device to the master.
The attacks are becoming more sophisticated and users, especially those with low knowledge of technology come easily to the hook of cyber criminals.

Jul 20, 2012

App Store bypassed without jailbreaking (how to install payed apps from apple store for free)



in_app_purchase_hack_confirm
Apple is investigating yet another security breach in its iTunes app store . A Russian hacker worked out a way that allows people to bypass payment in the App Store and download products for free.

The hacker, dubbed ZonD80, posted a video of the crack on YouTube (Deleted by Youtube now) and claims that the technique makes it possible to beat Apple's payment systems by installing a couple of certificates and assigning a specific IP address to the device.

The new service, which has already been subject to attempts at shutting it down, requires no jailbreaking and only minimal configuration changes. It works by funneling purchase requests through a server operated by the hacker, rather than the legitimate one offered by Apple. As a result, charges that normally would be applied to a user's account are bypassed.
Below are the steps to the hack:
  • Install two certificates: CA and in-appstore.com.
  • Connect via Wi-Fi network and change the DNS to 62.76.189.117.
  • Press the Like button and enter your Apple ID & password.
  • Using the above hack, you are actually stealing in-app purchase content from developers, which is kind of disturbing and is of course against developer’s terms of service.
ZonD80 is now asking for donations to set up a website to promote the hack."Why you must to pay for content, already included in purchased app? I think, you must not," he said.


Apple has responded with the following statement:“The security of the App Store is incredibly important to us and the developer community,” Apple representative Natalie Harrison. “We take reports of fraudulent activity very seriously and we are investigating.”



Obama will control internet, signs Emergency Internet Control

Emergency+Internet+Control
Barack Obama has signed an executive order that could hand control of the internet to the U.S. Government, in the event of a natural disaster or terrorist attack. "The federal government must have the ability to communicate at all times and under all circumstances to carry out its most critical and time sensitive missions," Obama said.

President Obama adds that it is necessary for the government to be able to reach anyone in the country during situations it considers critical, writing, “Such communications must be possible under all circumstances to ensure national security, effectively manage emergencies and improve national resilience.” Later the president explains that such could be done by establishing a “joint industry-Government center that is capable of assisting in the initiation, coordination, restoration and reconstitution of NS/EP [national security and emergency preparedness] communications services or facilities under all conditions of emerging threats, crisis or emergency.”
 
But Section 5.2 has raised alarm among those who fear the government will have too much control over the Web. The section explained how the secretary of homeland security - currently Janet Napolitano - will 'satisfy priority communications requirements through the use of commercial, Government, and privately owned communications resources, when appropriate.'

White House officials have acted quickly to ease concern, insisting the order is just an update of an existing authority dating back to 1984 . The claim the government has been granted no extra powers.