Showing posts with label COMPUTER. Show all posts
Showing posts with label COMPUTER. Show all posts
Tuesday, April 24, 2018
#include<iostream>
using namespace std;
float vol(float);
float vol(float, float);
float vol(float, float, float);
float vol(float a)
{
return(a*a*a);
}
float vol(float R, float H)
{
return(3.14*R*R*H);
}
float vol(float L, float B, float H1)
{
return(L*B*H1);
}
int main()
{
float x,y,z,o,p,q;
cout<<"\n Enter value A for cube:";
cin>>x;
cout<<"\n Ans:"<<vol(x);
cout<<"\n Enter value R for cylinder:";
cin>>y;
cout<<"H:";
cin>>z;
cout<<"Ans:"<<vol(y,z);
cout<<"\n Enter value L for Rectangle:";
cin>>0;
cout<<"B:";
cin>>p;
cout<<"H1:";
cin>>q;
cout<<"Ans:"<<vol(o,p,q);
return 0;
}
CODE:
#include<iostream>
using namespace std ;
inline int sum(int a,int b)
{
return(a+b);
}
inline int sub(int a,int b)
{
return(a-b);
}
inline int mul(int a,int b)
{
return(a*b);
}
inline float div(float a,float b)
{
return(a/b);
}
int main()
{
int x,y;
char n;
cout<<"Enter values to process \n X=";
cin>>x;
cout<<"\n Y=";
cin>>y ;
cout<<"Press '+' for Addition \nPress '-' for Substraction \nPress '*' for multiplication \nPress '/' for Division \n Choise Is :";
cin>>n ;
if(n=='+')
cout<<"Addition Is :"<<sum(x,y);
else if(n=='-')
cout<<"Substraction Is :"<<sub(x,y);
else if(n=='*')
cout<<"Multiplication Is :"<<mul(x,y);
else if(n=='/')
cout<<"Division Is :"<<div(x,y);
else
cout<<"Wrong Input";
return 0;
}
Monday, April 23, 2018
CODE:
#include<iostream>
using namespace std;
int display(int S,int N)
{
int i;
cout<<"Series ";
for(i=1;i<=N;i=i+2)
cout<<i<<"+";
cout<<"=" ;
cout<<S<<"\n" ;
return 0;
}
int main()
{
int i,n,sum=0,r;
cout<<"\t Sum Of 'N' Odd Numbers ";
cout<<"\n Enter the Value Of N : ";
cin>>n ;
a:
cout<<"\n Press '1' for SUM using 'for loop' \n Press '2' for SUM using 'while loop' \n Press '3' For Display";
cout<<"\n Your Choice :";
cin>>r ;
switch(r)
{
case 1 :
for(i=1;i<=n;i=i+2)
{
sum=sum+i;
}
goto a;
break;
case 2 :
i=1;
while(i<=n)
{
sum=sum+i;
i=i+2;
}
goto a;
break;
case 3 :
display(sum,n);
break;
default :
cout<<"You Entered Wrong choice";
}
return 0;
}
#include<iostream>
using namespace std;
int display(int S,int N)
{
int i;
cout<<"Series ";
for(i=1;i<=N;i=i+2)
cout<<i<<"+";
cout<<"=" ;
cout<<S<<"\n" ;
return 0;
}
int main()
{
int i,n,sum=0,r;
cout<<"\t Sum Of 'N' Odd Numbers ";
cout<<"\n Enter the Value Of N : ";
cin>>n ;
a:
cout<<"\n Press '1' for SUM using 'for loop' \n Press '2' for SUM using 'while loop' \n Press '3' For Display";
cout<<"\n Your Choice :";
cin>>r ;
switch(r)
{
case 1 :
for(i=1;i<=n;i=i+2)
{
sum=sum+i;
}
goto a;
break;
case 2 :
i=1;
while(i<=n)
{
sum=sum+i;
i=i+2;
}
goto a;
break;
case 3 :
display(sum,n);
break;
default :
cout<<"You Entered Wrong choice";
}
return 0;
}
Thursday, January 4, 2018
Now in these days Bitcoins are becoming very popular in the global marketing. Most of us still don’t know about what is bitcoins? And how we earn bitcoins very easily. For many of us, earning bitcoin is like a finding healthy food. We know the benefits of bitcoins very well but we can’t justify it real cost. It is not really simple to find interesting ways to earn bitcoins online. Mobile phones are becoming so popular in today’s life. Now everyone is using mobile phones in the world.
Do you know about that we can earn bitcoins very easily with the help of android mobile? Yes we can. There are lots of apps are available in Play store to earn bitcoin very easily and most of them are totally free. But beware of that most of them are scam or not real. But some of them are really effective and handily useful.
1) Bitcoin Farm:
Bitcoin Farm is also a very cool app to earn Satoshi for free. But It gives low amount of Satoshi. Bitcoin Farm is an easy to use Bitcoin Faucet for your phone and tablet. Within 60 Minutes your Bitcoin Flower will grow and you can harvest it to earn Satoshi.
2) Bitcoin Miner App- Earn Free Satoshis:
Bitcoin Miner App is a most popular new app for earn bitcoins free. It allows you to make free bitcoins, not by mining but by displaying add.It is paying very high amount of free Satoshi in interval of 1 hour.
3) BTC Safari:
BTC Safari is a free Bitcoin Faucet app for Android devices that will pay you every 15 minutes allowing you to earn up to 400 Satoshi per claim.
The app is simple to use and does not have too many features. It is a little clumsy looking, however it works as it should.
4) Free Bitcoin Miner:
Just launch our Free Bitcoin Miner and after a half of an hour close the advertisement and gain your own free BTC! This 30 minutes of your waiting, you are able to do what you like, for instance, play games, read news, watch films or anything you want.
5) BitMaker - Free Bitcoin:
Bitmaker is a quality Bitcoin faucet app that pays you every 30 minutes. This app has a nice interface with a lot of extra features compared to its rivals. Bitmaker has offers that reward you with Bitcoin and has a scoreboard where you can compare your earnings with your friends and other users of the app.
![]() |
| Best Bitcoin Miner App For Android |
Do you know about that we can earn bitcoins very easily with the help of android mobile? Yes we can. There are lots of apps are available in Play store to earn bitcoin very easily and most of them are totally free. But beware of that most of them are scam or not real. But some of them are really effective and handily useful.
1) Bitcoin Farm:
Bitcoin Farm is also a very cool app to earn Satoshi for free. But It gives low amount of Satoshi. Bitcoin Farm is an easy to use Bitcoin Faucet for your phone and tablet. Within 60 Minutes your Bitcoin Flower will grow and you can harvest it to earn Satoshi.
2) Bitcoin Miner App- Earn Free Satoshis:
| Bitcoin Miner App- Earn Free Satoshis |
Bitcoin Miner App is a most popular new app for earn bitcoins free. It allows you to make free bitcoins, not by mining but by displaying add.It is paying very high amount of free Satoshi in interval of 1 hour.
3) BTC Safari:
BTC Safari is a free Bitcoin Faucet app for Android devices that will pay you every 15 minutes allowing you to earn up to 400 Satoshi per claim.
The app is simple to use and does not have too many features. It is a little clumsy looking, however it works as it should.
4) Free Bitcoin Miner:
Just launch our Free Bitcoin Miner and after a half of an hour close the advertisement and gain your own free BTC! This 30 minutes of your waiting, you are able to do what you like, for instance, play games, read news, watch films or anything you want.
5) BitMaker - Free Bitcoin:
Bitmaker is a quality Bitcoin faucet app that pays you every 30 minutes. This app has a nice interface with a lot of extra features compared to its rivals. Bitmaker has offers that reward you with Bitcoin and has a scoreboard where you can compare your earnings with your friends and other users of the app.
Tuesday, December 26, 2017
Nowadays , WhatsApp has become the best interoperable Instant Messaging and VoIP (Voice over Internet Protocol) and Multimedia platform for the end users that provides them an well-serviced environment for Instant Messaging , Voice/Video Calling , File Transfer such as Documents , Videos and Images easily at the scale with high-end encryption encapsulated into it globally .
Read Full Artical click here <-- This Artical is easy to understand Decrypt Database. so i just suggest read this artical .
WhatsApp basically uses a standardised protocol for Instant Messaging called Extensible Messaging and Presence Protocol (XMPP). It basically uses one of it's most valuable service called Jabber for user account at the time of Installation using the phone no. as the username i.e. (Jabber ID: [phone number]@s.whatsapp.net) and then it estimates all smart phones from it's address book with the help of it's centralised database for adding contacts automatically to their contact list and then it also allows Multimedia Messaging to the end users with the help of HTTP server and generates a hyperlink to the content with Base64 encoded.
Before Demonstration , I'd like to write about the working principle of WhatsApp high-end Encryption
As you know that the Multimedia Messaging and other type of data are simply the decrypted data and need to be encapsulated in order to securely communicate with each other through a communication channel.
So Firstly , the Plain Text is encrypted using Private Key for the Data Encapsulation
i.e. PlainText + Secret Key == Data Encapsulation (Encrypted Data)
Once the data has been received by the receiver needs to be decrypted i.e. plain text using the same Secret Key for it
i.e. Data Encapsulation (Encrypted Data) + Secret Key == PlainText (Original Data)
Read Full Artical click here
The Main Problem with the Technique is the usage of Same Key for both encryption and decryption
So , if the sender sends the data to the receiver , the third party is likely to be able to eavesdrop and forge and sniff the conversation , data etc between sender and receiver which could create a massive problem to both of them
In order to overcome the problem , WhatsApp basically uses Two Keys for both encryption and decryption. These two keys are mathematically so related to each other that one key can encrypt the PlainText to Encrypted Data which can be later on decrypted by receiver
Both of your public and private keys are generated on your smartphone at the time of installation , So what does that mean by high-end encryption
As your private key is generated on your mobile , The third party Attacker cannot decrypt your messages due to the implementation of private key.
The 60 digit number shown above is shorter form of addition of your and your contact's public key. Remember, you use your contact's public key to encrypt outgoing message and your contact uses their private key to decrypt and vice versa.
Scanning QR code or comparing those 60 digit number is a way to verify and ensure that you are using correct public key of your contact and no one (whatsapp server or others) is spoofing you with wrong public key.
Now let me cut to the chase and write about the mechanism of both decryption and extraction of WhatsApp Database
You got to be thinking that it's impossible to just decrypt and extract the WhatsApp Database so easily with such high-end security attached to it
But let me tell you straight that it's possible and very easy to decrypt and extract the Database easily with the help of built-in tools available today in this technology
After all , Nothing is Impossible in today's technology
If there exists the technology then obviously there exists security tools too
Read Full Artical click here
There are following prerequisites software and tools need to be downloaded and installed before it
1. Crypt Key Extractor (https://codeload.github.com/EliteAndroidApps/WhatsApp-Key-DB-Extractor/zip/master)
2. Operating System (Windows , Linux , Mac OS X)
3. Java (https://www.java.com/en/download/)
4. ADB i.e. Android Debug Bridge (https://developer.android.com/studio/releases/platform-tools.html#download)
5. Android Device (with Android 4.0 or Higher than it)
6. USB Debugging must be enabled on the target device
7. Web Browser
8. Internet
9. USB (Universal Serial Bus)
In order to enable USB Debugging , Please navigate to Settings --> Developer Options --> Enable USB debugging. Please tap multiple times on Build Number under About Phone unless and until you become the developer if you find no developer option under the Settings option
Note :
01. I apologise Linux and Mac OS X users for the following below demonstration
02. Windows end users must have minimum knowledge about Windows OS for it
03. This is to be advised that it's for the education purpose , any illegal activity against any other unauthorised devices could lead to jail
Are you finally ready to decrypt and extract WhatsApp Database
So , Let's Get Started
04. Download prerequisites software and tools
05. Extract it to your preferred drive
06. Open up your Command Prompt
07. Navigate to the directory where WhatsApp Key DB Extractor installed
08. Connect your device via USB and change the mode from charging to media
09. Unlock your screen and wait for Full Backup option
10. Enter your backup password or leave the blank (if none set)
11. Tap on Back up my data.
Read Full Artical click here
Note : Please wait as It could take few minutes depending upon your size of data
12. Confirm backup password on your Command Prompt and check for extracted folder.
13. You'll find many files there such as axolotl.db , chatsettings.db , msgstore.db, wa.db.
14. As all these files are in SQL format visible through SQLite Software
15. Visit https://sqliteonline.com for Online Viewing
16. Click on Open DB and select them all in order to view the files online through the website
17. Done
I hope you can now easily decrypt and extract WhatsApp Database.
Read Full Artical click here <-- This Artical is easy to understand Decrypt Database. so i just suggest read this artical .
WhatsApp basically uses a standardised protocol for Instant Messaging called Extensible Messaging and Presence Protocol (XMPP). It basically uses one of it's most valuable service called Jabber for user account at the time of Installation using the phone no. as the username i.e. (Jabber ID: [phone number]@s.whatsapp.net) and then it estimates all smart phones from it's address book with the help of it's centralised database for adding contacts automatically to their contact list and then it also allows Multimedia Messaging to the end users with the help of HTTP server and generates a hyperlink to the content with Base64 encoded.
![]() |
| Whatsapp Database Decryption |
Before Demonstration , I'd like to write about the working principle of WhatsApp high-end Encryption
As you know that the Multimedia Messaging and other type of data are simply the decrypted data and need to be encapsulated in order to securely communicate with each other through a communication channel.
So Firstly , the Plain Text is encrypted using Private Key for the Data Encapsulation
i.e. PlainText + Secret Key == Data Encapsulation (Encrypted Data)
Once the data has been received by the receiver needs to be decrypted i.e. plain text using the same Secret Key for it
i.e. Data Encapsulation (Encrypted Data) + Secret Key == PlainText (Original Data)
Read Full Artical click here
The Main Problem with the Technique is the usage of Same Key for both encryption and decryption
So , if the sender sends the data to the receiver , the third party is likely to be able to eavesdrop and forge and sniff the conversation , data etc between sender and receiver which could create a massive problem to both of them
In order to overcome the problem , WhatsApp basically uses Two Keys for both encryption and decryption. These two keys are mathematically so related to each other that one key can encrypt the PlainText to Encrypted Data which can be later on decrypted by receiver
Both of your public and private keys are generated on your smartphone at the time of installation , So what does that mean by high-end encryption
As your private key is generated on your mobile , The third party Attacker cannot decrypt your messages due to the implementation of private key.
The 60 digit number shown above is shorter form of addition of your and your contact's public key. Remember, you use your contact's public key to encrypt outgoing message and your contact uses their private key to decrypt and vice versa.
Scanning QR code or comparing those 60 digit number is a way to verify and ensure that you are using correct public key of your contact and no one (whatsapp server or others) is spoofing you with wrong public key.
Now let me cut to the chase and write about the mechanism of both decryption and extraction of WhatsApp Database
You got to be thinking that it's impossible to just decrypt and extract the WhatsApp Database so easily with such high-end security attached to it
But let me tell you straight that it's possible and very easy to decrypt and extract the Database easily with the help of built-in tools available today in this technology
After all , Nothing is Impossible in today's technology
If there exists the technology then obviously there exists security tools too
Read Full Artical click here
There are following prerequisites software and tools need to be downloaded and installed before it
1. Crypt Key Extractor (https://codeload.github.com/EliteAndroidApps/WhatsApp-Key-DB-Extractor/zip/master)
2. Operating System (Windows , Linux , Mac OS X)
3. Java (https://www.java.com/en/download/)
4. ADB i.e. Android Debug Bridge (https://developer.android.com/studio/releases/platform-tools.html#download)
5. Android Device (with Android 4.0 or Higher than it)
6. USB Debugging must be enabled on the target device
7. Web Browser
8. Internet
9. USB (Universal Serial Bus)
In order to enable USB Debugging , Please navigate to Settings --> Developer Options --> Enable USB debugging. Please tap multiple times on Build Number under About Phone unless and until you become the developer if you find no developer option under the Settings option
Note :
01. I apologise Linux and Mac OS X users for the following below demonstration
02. Windows end users must have minimum knowledge about Windows OS for it
03. This is to be advised that it's for the education purpose , any illegal activity against any other unauthorised devices could lead to jail
Are you finally ready to decrypt and extract WhatsApp Database
So , Let's Get Started
04. Download prerequisites software and tools
05. Extract it to your preferred drive
06. Open up your Command Prompt
07. Navigate to the directory where WhatsApp Key DB Extractor installed
08. Connect your device via USB and change the mode from charging to media
09. Unlock your screen and wait for Full Backup option
10. Enter your backup password or leave the blank (if none set)
11. Tap on Back up my data.
Read Full Artical click here
Note : Please wait as It could take few minutes depending upon your size of data
12. Confirm backup password on your Command Prompt and check for extracted folder.
13. You'll find many files there such as axolotl.db , chatsettings.db , msgstore.db, wa.db.
14. As all these files are in SQL format visible through SQLite Software
15. Visit https://sqliteonline.com for Online Viewing
16. Click on Open DB and select them all in order to view the files online through the website
17. Done
I hope you can now easily decrypt and extract WhatsApp Database.
WhatsApp backup conversation files are now saved with the
.crypt12 extension. From crypt9, they seem to be using a modified version of Spongy Castle – a cryptography API library for Android.![]() |
| Decrypt Database |
All the findings below are based on reverse engineering work done on WhatCrypt and Omni-Crypt. I would like to highlight that IGLogger proved to be a very useful tool when it came to
smali code debugging.Extract Key File
To decrypt the
crypt12 files, you will first need the key file. The key file stores the encryption key, K. WhatsApp stores the key file in a secure location: /data/data/com.whatsapp/files/key.
If your phone is rooted, extracting this file is easy. If your phone is not rooted, refer to instructions from WhatCrypt and Omni-Crypt for details on extracting the
key file. The idea is to install an older version of WhatsApp, where Android ADB backup was still working and extract the key file from the backup.Extract crypt12 Backup File
Pull the encrypted WhatsApp messages file from your phone using ADB.
$ adb pull /sdcard/WhatsApp/Databases/msgstore.db.crypt12
Decryption Keys
This section is just for your information and you can skip this section.
The encryption method being used is AES with a key (
K) length of 256 bits and an initialisation vector (IV) size of 128 bits. The 256-bit AES key is saved from offset 0x7E till 0x9D in the file. Offsets start from 0x00. You can extract the AES key with hexdump and assign the value to variable $k.$ k=$(hexdump -ve '2/1 "%02x"' key | cut -b 253-316)
The
$k variable will hold a 64-digit hexadecimal value in ASCII that is actually 256 bits in length.
The IV or the initialisation vector is saved from offset 0x33 till 0x42 in the
crypt12 file. The IV value will be different for every crypt12 file.$ iv=$(hexdump -n 67 -ve '2/1 "%02x"' msgstore.db.crypt12 | cut -b 103-134)
The
K and IV extraction method is similar to what we have done for crypt8 files before.Strip Header / Footer in crypt12 File
Again, this section is just for your information and you can skip this section.
Before we start the decryption process, we will need to strip the 67 byte header and 20 byte footer from the
crypt12 file.$ dd if=msgstore.db.crypt12 of=msgstore.db.crypt12.enc ibs=67 skip=1 $ truncate -s -20 msgstore.db.crypt12.enc
The above
dd command will strip the the first 67 bytes from the crypt12 file and save it to a file with extension crypt12.enc. The truncate command will strip the last 20 bytes from the crypt12 file.Decrypt crypt12 File
As the WhatsApp AES cryptography API library seems to be a modified version, we will no longer be able to use
openssl to decrypt the crypt12 file. I have yet to determine what has been modified.
To decrypt
crypt12 files, I have written a simple Java program that will use the modified cryptography API library instead. For the cryptography API library, I have extracted the modified Spongy Castle cryptography class files from the Omni-Crypt APK file using dex2jar. You can find the Java program and crypto library over here at GitLab.
The Java program will create 3 output files:
msgstore.db.crypt12.enc– encrypted file with header and footer stripped.msgstore.db.zlib– decrypted file in zlib format.msgstore.db– decrypted sqlite3 database file.
Below is how you can compile and run the Java program.
$ git clone https://gitlab.com/stackpointer/whatsapp-crypt12.git $ cd whatsapp-crypt12/ $ javac -classpath "lib/whatsapp_spongycastle.jar:." crypt12.java $ cp ../whatsapp.data/key . $ cp ../whatsapp.data/msgstore.db.crypt12 . $ java -cp "lib/whatsapp_spongycastle.jar:." crypt12 K:XXXXXXXXXX IV:YYYY creating encrypted file with header/footer stripped: msgstore.db.crypt12.enc creating zlib output file: msgstore.db.zlib creating sqlite3 output file: msgstore.db $ ls -l total 136724 -rw-r--r-- 1 ibrahim staff 4339 Oct 9 16:05 crypt12.class -rw-r--r-- 1 ibrahim staff 5459 Oct 9 16:05 crypt12.java -rw-r--r-- 1 ibrahim staff 158 Oct 9 16:05 key drwxr-xr-x 2 ibrahim staff 4096 Oct 9 16:05 lib -rw-r--r-- 1 ibrahim staff 1089 Oct 9 16:05 LICENSE -rw-r--r-- 1 ibrahim staff 62692352 Oct 9 16:06 msgstore.db -rw-r--r-- 1 ibrahim staff 25757610 Oct 9 16:05 msgstore.db.crypt12 -rw-r--r-- 1 ibrahim staff 25757523 Oct 9 16:05 msgstore.db.crypt12.enc -rw-r--r-- 1 ibrahim staff 25757507 Oct 9 16:06 msgstore.db.zlib -rw-r--r-- 1 ibrahim staff 1376 Oct 9 16:05 README.md $ file * crypt12.class: compiled Java class data, version 52.0 (Java 1.8) crypt12.java: C source, ASCII text key: Java serialization data, version 5 lib: directory msgstore.db: SQLite 3.x database, user version 1 msgstore.db.crypt12: raw G3 data, byte-padded msgstore.db.crypt12.enc: data msgstore.db.zlib: zlib compressed data
Final Words
To use the Java decryption tool, you will need to use OpenJDK. Oracle require JCE Provider libraries to be signed. OpenJDK does not have this requirement. If you try running the Java program on Oracle JDK, you will most likely get the following exception.
Exception in thread "main" java.lang.SecurityException: JCE cannot authenticate the provider SC
Sunday, December 10, 2017
Aadhar Card database can easily be accessed by CIA Covert Operations via UIDAI certified company Cross Match. Today WikiLeaks published secret documents from the Express Lane Malware project of the CIA Spy operations. These documents show one of the cyber operations the CIA conducts against other govt. agencies. Let’s understand the process how can CIA hacks indias aadhar card database.
The OTS (Office of Technical Services), a branch of the CIA, has a biometric collection system that is provided to govt. agencies around the world — CIA’s ExpressLane is a covert information collection tool that is used exfiltrate data collections from such biometric systems provided to govt agencies around the world.
ExpressLane is installed and run with the cover of upgrading the biometric software by OTS agents that visit the Liaison sites. This procedure will remain unsuspicious, as the data exfiltration disguises behind a Windows installation splash screen.
The core components of the OTS system are based on products from Cross Match, a US company specializing in biometric software for law enforcement and the Intelligence Community.
Cross Match Is certified by UIDAI (India Govt’s Institute Responsible For Aadhar)
Cross Match was one of the first suppliers of biometric devices Aadhaar program. Cross Match received the Certificate of Approval for its Guardian fingerprint capture device and the iScan dual iris capture device on October 7, 2011. Both systems utilize Cross Match’s patented Auto Capture feature, which quickly captures high-quality images with minimal operator involvement.
Nearly all of the UIDAI certified enrollment agencies use Cross Match devices across India.
Components of India’s Aadhar Program:
The foundation of the Aadhaar program is based on biometric and demographic data that is unique to each citizen. This data can only be collected by leveraging biometric devices and compatible software – the second and third stages of the Aadhaar value chain.
All the devices and compatible software are provided by Cross Match [ExpressLane Data Collection Malware Has been developed exfiltrate databases from Cross Match Products]
Read the Manual Of Installing Aadhar Enrollment Software (You will see Cross Match products are used for it)
How CIA agents can access Aadhaar database in real-time
A number of the CIA’s electronic attack methods are designed for physical proximity. These attack methods are able to penetrate high-security networks that are disconnected from the internet. In these cases, a CIA agent or spy physically infiltrate the targeted workplace. The attacker is provided with a USB containing malware developed by CIA for this purpose(Express Lane), which is inserted into the targeted computer.
The attacker then infects and exfiltrates data to removable media. For example, the CIA attack a system. To witnesses, the spy appears to be running a program showing videos (e.g VLC), presenting slides (Prezi), playing a computer game (Breakout2, 2048) or even running a fake virus scanner (Kaspersky, McAfee, Sophos).
ExpressLane comes with a standardized questionnaire i.e menu containing questions that CIA spy fills out. The questionnaire is remotely used by the CIA’s OSB (Operational Support Branch) to transform the requests of spies into technical requirements for hacking attacks. The questionnaire allows the CIA to communicate with Express Lane Malware.
See Leaked Wikileaks Documents on CIA’s ExpressLane Malware
![]() |
| Aadhar & WiKi & CIA |
The OTS (Office of Technical Services), a branch of the CIA, has a biometric collection system that is provided to govt. agencies around the world — CIA’s ExpressLane is a covert information collection tool that is used exfiltrate data collections from such biometric systems provided to govt agencies around the world.
ExpressLane is installed and run with the cover of upgrading the biometric software by OTS agents that visit the Liaison sites. This procedure will remain unsuspicious, as the data exfiltration disguises behind a Windows installation splash screen.
The core components of the OTS system are based on products from Cross Match, a US company specializing in biometric software for law enforcement and the Intelligence Community.
Cross Match Is certified by UIDAI (India Govt’s Institute Responsible For Aadhar)
Cross Match was one of the first suppliers of biometric devices Aadhaar program. Cross Match received the Certificate of Approval for its Guardian fingerprint capture device and the iScan dual iris capture device on October 7, 2011. Both systems utilize Cross Match’s patented Auto Capture feature, which quickly captures high-quality images with minimal operator involvement.
Nearly all of the UIDAI certified enrollment agencies use Cross Match devices across India.
Components of India’s Aadhar Program:
The foundation of the Aadhaar program is based on biometric and demographic data that is unique to each citizen. This data can only be collected by leveraging biometric devices and compatible software – the second and third stages of the Aadhaar value chain.
All the devices and compatible software are provided by Cross Match [ExpressLane Data Collection Malware Has been developed exfiltrate databases from Cross Match Products]
Read the Manual Of Installing Aadhar Enrollment Software (You will see Cross Match products are used for it)
How CIA agents can access Aadhaar database in real-time
A number of the CIA’s electronic attack methods are designed for physical proximity. These attack methods are able to penetrate high-security networks that are disconnected from the internet. In these cases, a CIA agent or spy physically infiltrate the targeted workplace. The attacker is provided with a USB containing malware developed by CIA for this purpose(Express Lane), which is inserted into the targeted computer.
The attacker then infects and exfiltrates data to removable media. For example, the CIA attack a system. To witnesses, the spy appears to be running a program showing videos (e.g VLC), presenting slides (Prezi), playing a computer game (Breakout2, 2048) or even running a fake virus scanner (Kaspersky, McAfee, Sophos).
ExpressLane comes with a standardized questionnaire i.e menu containing questions that CIA spy fills out. The questionnaire is remotely used by the CIA’s OSB (Operational Support Branch) to transform the requests of spies into technical requirements for hacking attacks. The questionnaire allows the CIA to communicate with Express Lane Malware.
See Leaked Wikileaks Documents on CIA’s ExpressLane Malware
Denis Sinegubko (a security researcher from Sucuri) has discovered a new wave of the known malware wp-vcd that injects malicious WordPress admin users into vulnerable or hacked websites.
The researcher said that the wp-vcd malware is preinstalled inside pirated WordPress premium themes published for download for free on some websites, he noticed that the malicious code was loaded via the include function and injected malicious code into WordPress core files such as functions.php and class.wp.php.
According to Sucuri:
It was injecting its code on “wp-includes/class.wp.php”, this is an outdated strategy to avoid being detected by the unaware user; since nobody wants to delete WordPress core files and risk the site integrity. However, as security tools become more and more popular, this strategy fails. It’s now pretty easy for any tool to detect modifications on core files. And, since theme files are changed constantly, they found a better place to hide it.
The malware runs by adding a hidden admin user to the website’s database, with the username “100010010”. The hackers will use this secret account to access the affected websites so they can perform several malicious activities at later times.
The code is also straightforward and doesn’t cover its malicious intentions by encoding or obfuscation of functions…
Websites administrators are recommended to install themes and plugins only from trusted locations.
![]() |
| WordPress |
The researcher said that the wp-vcd malware is preinstalled inside pirated WordPress premium themes published for download for free on some websites, he noticed that the malicious code was loaded via the include function and injected malicious code into WordPress core files such as functions.php and class.wp.php.
According to Sucuri:
It was injecting its code on “wp-includes/class.wp.php”, this is an outdated strategy to avoid being detected by the unaware user; since nobody wants to delete WordPress core files and risk the site integrity. However, as security tools become more and more popular, this strategy fails. It’s now pretty easy for any tool to detect modifications on core files. And, since theme files are changed constantly, they found a better place to hide it.
The malware runs by adding a hidden admin user to the website’s database, with the username “100010010”. The hackers will use this secret account to access the affected websites so they can perform several malicious activities at later times.
The code is also straightforward and doesn’t cover its malicious intentions by encoding or obfuscation of functions…
Websites administrators are recommended to install themes and plugins only from trusted locations.
Friday, December 8, 2017
TEDx is an abbreviation for technology, entertainment, and design. A series of non-profit international conferences dedicated to the dissemination and sponsorship of ideas is the American Sapling Foundation, a non-profit, non-profit organization. TEDx Talks are usually short and strong (18 minutes or less). Ted began in 1984 and was covering technology, entertainment and design, but today it covers almost all subjects.
Which were posted on YouTube and the official website of Ted. Today, I offer you 15 videos from TEDx Talks about Cyber Security & Hacking.
1. Catherine Bracy: Why Good Hackers Make Good Citizens?
2. Ralph Langner: Cracking Stuxnet, A 21st century Cyberweapon
3. Glenn Greenwald: Why Privacy Matters?
4. Andy Yen: Think Your Email is Private? Think Again
5. Governments don't Understand Cyber warfare. We need Hackers!
6. Lorrie: What’s Wrong with your Pa$$w0rd?
7. Marc: A Vision of Crimes in the Future
8. Hackers: The Internet's Immune System
9. Chris Domas: The 1s and 0s Behind Cyber warfare
10. Misha Glenny: Hire the Hackers!
11. Avi Rubin: All Your Devices can be Hacked!
12. Caleb Barlow: Where is Cyber Crime Really Coming From?
13. Mikko Hypponen: Fighting Viruses, Defending the Net.
14. Guy-Philippe: How CyberAttacks Threaten World Peace
15. Everyday CyberCrime – And what you can do about it
![]() |
| TEDxTalks |
Which were posted on YouTube and the official website of Ted. Today, I offer you 15 videos from TEDx Talks about Cyber Security & Hacking.
1. Catherine Bracy: Why Good Hackers Make Good Citizens?
2. Ralph Langner: Cracking Stuxnet, A 21st century Cyberweapon
3. Glenn Greenwald: Why Privacy Matters?
4. Andy Yen: Think Your Email is Private? Think Again
5. Governments don't Understand Cyber warfare. We need Hackers!
6. Lorrie: What’s Wrong with your Pa$$w0rd?
7. Marc: A Vision of Crimes in the Future
8. Hackers: The Internet's Immune System
9. Chris Domas: The 1s and 0s Behind Cyber warfare
10. Misha Glenny: Hire the Hackers!
11. Avi Rubin: All Your Devices can be Hacked!
12. Caleb Barlow: Where is Cyber Crime Really Coming From?
13. Mikko Hypponen: Fighting Viruses, Defending the Net.
14. Guy-Philippe: How CyberAttacks Threaten World Peace
15. Everyday CyberCrime – And what you can do about it




