Power By Dholu Production

Responsive Ads Here
Showing posts with label HACKING NEWS. Show all posts
Showing posts with label HACKING NEWS. Show all posts

Sunday, December 10, 2017

CIA SPIES INDIA’S BIOMETRIC AADHAAR DATABASE IN REAL TIME | News

Aadhar Card database can easily be accessed by CIA Covert Operations via UIDAI certified company Cross Match. Today WikiLeaks published secret documents from the Express Lane Malware project of the CIA Spy operations. These documents show one of the cyber operations the CIA conducts against other govt. agencies. Let’s understand the process how can CIA hacks indias aadhar card database.

Aadhar & WiKi & CIA
Aadhar & WiKi & CIA


The OTS (Office of Technical Services), a branch of the CIA, has a biometric collection system that is provided to govt. agencies around the world — CIA’s ExpressLane is a covert information collection tool that is used exfiltrate data collections from such biometric systems provided to govt agencies around the world.

ExpressLane is installed and run with the cover of upgrading the biometric software by OTS agents that visit the Liaison sites. This procedure will remain unsuspicious, as the data exfiltration disguises behind a Windows installation splash screen.

The core components of the OTS system are based on products from Cross Match, a US company specializing in biometric software for law enforcement and the Intelligence Community.

Cross Match Is certified by UIDAI (India Govt’s Institute Responsible For Aadhar)

Cross Match was one of the first suppliers of biometric devices Aadhaar program. Cross Match received the Certificate of Approval for its Guardian fingerprint capture device and the iScan dual iris capture device on October 7, 2011. Both systems utilize Cross Match’s patented Auto Capture feature, which quickly captures high-quality images with minimal operator involvement.
Nearly all of the UIDAI certified enrollment agencies use Cross Match devices across India.

 Components of India’s Aadhar Program:

The foundation of the Aadhaar program is based on biometric and demographic data that is unique to each citizen. This data can only be collected by leveraging biometric devices and compatible software – the second and third stages of the Aadhaar value chain.

All the devices and compatible software are provided by Cross Match [ExpressLane Data Collection Malware Has been developed exfiltrate databases from Cross Match Products]

Read the Manual Of Installing Aadhar Enrollment Software (You will see Cross Match products are used for it)

How CIA agents can access Aadhaar database in real-time

A number of the CIA’s electronic attack methods are designed for physical proximity. These attack methods are able to penetrate high-security networks that are disconnected from the internet. In these cases, a CIA agent or spy physically infiltrate the targeted workplace. The attacker is provided with a USB containing malware developed by CIA for this purpose(Express Lane), which is inserted into the targeted computer.
The attacker then infects and exfiltrates data to removable media. For example, the CIA attack a system. To witnesses, the spy appears to be running a program showing videos (e.g VLC), presenting slides (Prezi), playing a computer game (Breakout2, 2048) or even running a fake virus scanner (Kaspersky, McAfee, Sophos).
ExpressLane comes with a standardized questionnaire i.e menu containing questions that CIA spy fills out. The questionnaire is remotely used by the CIA’s OSB (Operational Support Branch) to transform the requests of spies into technical requirements for hacking attacks. The questionnaire allows the CIA to communicate with Express Lane Malware.

See Leaked Wikileaks Documents on CIA’s ExpressLane Malware

A New WordPress Malware Called “wp-vcd” Distributes Via Pirated Themes

Denis Sinegubko (a security researcher from Sucuri) has discovered a new wave of the known malware wp-vcd that injects malicious WordPress admin users into vulnerable or hacked websites.

WordPress
WordPress 


The researcher said that the wp-vcd malware is preinstalled inside pirated WordPress premium themes published for download for free on some websites, he noticed that the malicious code was loaded via the include function and injected malicious code into WordPress core files such as functions.php and class.wp.php.

According to Sucuri:
It was injecting its code on “wp-includes/class.wp.php”, this is an outdated strategy to avoid being detected by the unaware user; since nobody wants to delete WordPress core files and risk the site integrity. However, as security tools become more and more popular, this strategy fails. It’s now pretty easy for any tool to detect modifications on core files. And, since theme files are changed constantly, they found a better place to hide it.

The malware runs by adding a hidden admin user to the website’s database, with the username “100010010”. The hackers will use this secret account to access the affected websites so they can perform several malicious activities at later times.

The code is also straightforward and doesn’t cover its malicious intentions by encoding or obfuscation of functions…



Websites administrators are recommended to install themes and plugins only from trusted locations.

Friday, December 8, 2017

15 Video from TED Talks about Cyber Security & Hacking World You Should See | Computer

TEDx is an abbreviation for technology, entertainment, and design. A series of non-profit international conferences dedicated to the dissemination and sponsorship of ideas is the American Sapling Foundation, a non-profit, non-profit organization. TEDx Talks are usually short and strong (18 minutes or less). Ted began in 1984 and was covering technology, entertainment and design, but today it covers almost all subjects.

Hacking videos
TEDxTalks


Which were posted on YouTube and the official website of Ted. Today, I offer you 15 videos from TEDx Talks about Cyber Security & Hacking.

1. Catherine Bracy: Why Good Hackers Make Good Citizens?



2. Ralph Langner: Cracking Stuxnet, A 21st century Cyberweapon



3. Glenn Greenwald: Why Privacy Matters?



4. Andy Yen: Think Your Email is Private? Think Again



5. Governments don't Understand Cyber warfare. We need Hackers!



6. Lorrie: What’s Wrong with your Pa$$w0rd?



7.  Marc: A Vision of Crimes in the Future



8. Hackers: The Internet's Immune System



9. Chris Domas: The 1s and 0s Behind Cyber warfare



10. Misha Glenny: Hire the Hackers!



11. Avi Rubin: All Your Devices can be Hacked!



12. Caleb Barlow: Where is Cyber Crime Really Coming From?



13. Mikko Hypponen: Fighting Viruses, Defending the Net.



14. Guy-Philippe: How CyberAttacks Threaten World Peace



15. Everyday CyberCrime – And what you can do about it


Thursday, December 7, 2017

NiceHash (Popular Bitcoin Mining Service) Has Been Hacked: $62 Million Stolen! | News

A hacker successfully breached cryptocurrency mining marketplace NiceHash, resulting in the theft of up to $62 million worth of bitcoins.



The NiceHash website had gone offline earlier in the day, which the company had chalked up to maintenance. However, the team revealed the true nature of the outage through an announcement posted on the service’s social media channels, confirming users’ worst fears after hours frenzied speculation.

According to NiceHash:
“Dear NiceHash users!
Unfortunately, there has been a security breach involving NiceHash website. We are currently investigating the nature of the incident and, as a result, we are stopping all operations for the next 24 hours.
Importantly, our payment system was compromised and the contents of the NiceHash Bitcoin wallet have been stolen. We are working to verify the precise number of BTC taken.”

Although NiceHash has not confirmed the number of bitcoins stolen, NiceHash users have circulated a wallet address that suggests that 4,736.42 BTC — worth more than $62 million at the current exchange rate — was drained from the company’s hot wallet.



“While the full scope of what happened is not yet known, we recommend, as a precaution, that you change your online passwords.”


Wednesday, December 6, 2017

A New Technique Allows Website Owners To Use Your CPU To Mine Cryptocurrency Even After The Browser Window Is Closed | News

Security researchers from Malwarebytes have discovered a new technique that enables website owners or attackers that have hacked websites to keep mining for Cryptocurrency even if you close the browser window.



To prove their findings, the researchers have conducted many tests using the latest version of the Google Chrome browser. They noticed that once a user visits a website, the CPU activity rises but is not maxed out, however when the browser window is closed, the activity remains higher than normal as crypto mining continues.

""According to Malwarebytes:
The trick is that although the visible browser windows are closed, there is a hidden one that remains opened. This is due to a pop-under which is sized to fit right under the taskbar and hides behind the clock. The hidden window’s coordinates will vary based on each user’s screen resolution, but follow this rule:
-Horizontal position = ( current screen x resolution ) – 100
-Vertical position = ( current screen y resolution ) – 40





The new technique has been created to bypass adblockers and is a lot harder to recognize because of how cleverly it covers itself. Closing the browser window using the “X” button is not enough. Users are recommended to use Task Manager to ensure there is no remnant running browser processes and kill them.

Wednesday, September 20, 2017

BlueBorne: Critical Bluetooth Vulnerability Puts More Than 5 Billions of Devices at Risk of Hacking | Hacking News

If you are having Bluetooth enabled devices then you are vulnerable to BlueBorne attack. Be it a all the Bluetooth devices mobile, desktop, any IoT devices And OS including Android, iOS, Windows, and Linux are vulnerable.

BlueBorne Explained, Android Take Over Demo, Windows MiTM Demo, Linux Smartwatch Take Over Demo. All this term I am including videos at end of this post. you can watch the videos.

BlueBorne
BlueBorne


Using these vulnerabilities, security researchers at IoT security firm Armis have devised an attack, dubbed BlueBorne, which could allow attackers to completely take over Bluetooth-enabled devices, spread malware, or even establish a "man-in-the-middle" connection to gain access to devices critical data and networks without requiring any interaction from victime side.

Ben Seri, head of research team at Armis Labs, claims that during an experiment in the lab, his team was able to create a botnet network and install ransomware using the BlueBorne attack.

Security Experts from Armis Labs has identified 8 vulnerabilities. which can be the part of the attack vector and they published a Whitepaper.

1. Linux kernel RCE vulnerability – CVE-2017-1000251
2. Linux Bluetooth stack (BlueZ) information Leak vulnerability – CVE-2017-1000250
3. Android information Leak vulnerability – CVE-2017-0785
4. Android RCE vulnerability #1 – CVE-2017-0781
5. Android RCE vulnerability #2 – CVE-2017-0782
6. The Bluetooth Pineapple in Android – Logical Flaw CVE-2017-0783
7. The Bluetooth Pineapple in Windows – Logical Flaw CVE-2017-8628
8. Apple Low Energy Audio Protocol RCE vulnerability – CVE-2017-14315

Google and Microsoft have already made security patches available to their customers, while Apple iOS devices running the most recent version of its mobile operating system (that is 10.x) are safe.

What's worst? 

The worst part of the attacks is that user not required to be paired with attackers device and later not required to Authorize the connection means without any interaction from victime side.

All iOS devices with 9.3.5 or older versions and over 1.1 Billion active Android devices running older than Marshmallow (6.x) are vulnerable to the BlueBorne attack.

Android users need to wait for security patches for their devices, as it depends on your device manufacturers.

How To Check My Devices Under BlueBorne Attack? / How To Secure My Devices ? click here



Monday, September 11, 2017

Top 5 Hacking Books For Beginners in 2017 – You Must Read to be a Hacker | E-Books

Looking for best hacking books? We have short listed some of the highly recommended books for beginners and advanced hackers. The ethical hacking books may help you get the best security professional job you aspire.

With the increase in the use of internet, there is now a high demand for computer experts who can conduct ethical hacking operations. However, it is not an easy task to become an expert until you have basic knowledge about computers and network security. For beginners to start with, it is very important for them to know that there are two types of hacking: Ethical (White Hat) and Unethical (Black Hat).



According to us, given below are the 5 top books on ethical hacking for beginners that will provide the best knowledge about security :

1) Hacking: The Art of Exploitation, 2nd Edition: Download  or  Buy Now




This hacking book is a should learn for beginners. It is best amongst many Ethical Hacking Books. This book offers you knowledge about the obstacles beginners facing in the course of the starting of their moral hacking occupation. This book can help for beginners do their job more professionally.

Unlike others, this book spends more time explaining technical foundation of areas like programming, shell code and exploitation and how things work from inside. Instead of directly taking you through tutorials, this book will first make you understand underlying mechanism and architectures and then it teaches you how to outsmart security measures, corrupt system, wireless encryption cracking and network attacks etc. Programming languages that are covered includes C, Assembly Language and Shell Scripting.

2) Metasploit: The Penetration Tester’s Guide: Download  or  Buy Now




This book deals with Penetration Testing by making use of the open source Metasploit Framework. It is beneficial for the readers who do not have any prior knowledge about Metasploit. The Metasploit Framework makes discovering, exploiting, and sharing vulnerabilities quick and relatively painless.

At the end of the book, the reader will get sufficient knowledge of penetration test. It provides you with an actual penetration test’s simulated version so as to provide you with a realistic experience.

3) CEH Certified Ethical Hacker All-in-One Exam Guide: Download  or  Buy Now




It is a well written book in all Ethical Hacking Books. This comprehensive guide offers complete coverage of the EC-Council’s Certified Ethical Hacker exam.This is undoubtedly one of the well-written books of all times. It gives crisp and clear writing with relevant examples together with a humorous touch to enliven the dry and mundane subject. The contents of the book are properly organized in a neither too friendly nor too dry method. However, you require some theoretical networking background to derive full benefits from this book.

4) BackTrack 5 Wireless Penetration Testing Beginner’s Guide: Download  or  Buy Now




Right from the beginning, this book gives you what you need, without wasting time in unnecessary justifications. Instead of explaining only theoretical concepts, the book consists of finely tuned and crystal clear tutorials. It provides a good mix of basics and high level knowledge and works cohesively with the reader.

5) CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide: Download  or  Buy Now




This certification book is easy to read, straightforward and explains some of the complex topics in an excellent manner. All you need to do in order to pass the test is to read the book and do the practice exercises.

In addition to this, the “remember this sections” and the content headers highlight all the key topics that one must pay attention to. So, if you wish to straightaway get down to the study material without wasting time on esoteric gibberish, this is the book for you.

Although, hacking may sound like an interesting area of study, when it comes to the application of the various concepts of penetration testing, it is easier said than done. In addition to having an educational background in the field of computer science, the hackers must have an affinity to learning and acquiring new skills on an ongoing basis. Also, the ethical hackers must possess out-of-the box thinking so that they are able to come with maximum number of possible ways of designing and securing a computer system.

Monday, August 21, 2017

Vulnerability In SARAHAH App: Anyone can read your Messages |Tech News

Sarahah allows users to leave anonymous messages on other users' profiles.


Now a day Sarahah is trending application on iSO & Android for social media.Sarahah is an anonymous messaging app in which allows users to leave anonymous messages on other users’ profiles. Once a user registers for an account, they can share their profile link with friends (or post it publicly), and anyone with this link can share messages to their profile. The app doesn’t allow users to reply to messages, nor can they see who a message is from, unless the sender includes their name in the message. Users also have the option to only receive messages from other registered users.Sarahah was released on iOS and Android in June, and, as Android Authority reports, it blew up in popularity, in part, due to the ability for users to share their profile links in Snapchat snaps. Sarahah is currently the No. 1 free iPhone app on iTunes.

Vulnerability In Sarahah:


This vulnerability is mentioned by Defencely .comand they mentioned that this vulnerability is caused due to the insecure reflection of the message when new messages are loaded. They mentioned that the messages are not properly filtered out from the database.Recently Shawar Khan embedded a video in his website about XSS vulnerability in Sarahah.video is given blow.

The exploitation script can capture messages, change emails and delete accounts. Shawar Khan posted XSS exploit code on his GitHub account. Some users mentioned that now this vulnerability is removed but some are saying that code is still applicable. The whole video is present on Shawar Khan’s site. So, You can check it there.

This XSS vulnerability affects only browser user. If you are using it from the mobile app then you are safe. Before this, many ones were saying that this app is selling user data to advertisement company. This app has millions of download in just a few days.

Wednesday, August 16, 2017

India Arrest : Because 4 leaking ‘Game Of Thrones’ Episode 4 of Season 7 | Hacking News

Law enforcement authorities in India have arrested four people for leaking the unreleased episode of HBO’s (Home Box Office ) popular Games of Thrones (GOT) TV series.



GOT, since season one has been in the news for being one of the most pirated tv shows in the history. But season seven of the series made news for all the wrong reasons including data breach and having the personal phone numbers of its stars being leaked online.

The Deputy Commissioner of Police Mr. Akbar Khan told AFP (Agence France-Presse) that the department received a complaint from a Mumbai based firm stating that episode number four of Game of Throne’s season seven has been uploaded on the internet without the permission of its copyright holder.

“We investigated the case and had arrested four individuals for unauthorized publication of the fourth episode from season seven.”

Remember, in July hackers claimed to have stolen a massive trove of HBO data including the unreleased episodes of Game of Thrones. The hackers also claimed to leak the episodes online however it turned out that they have only leaked scripts of the episode.

It was on August 4th when out of nowhere a Reddit user uploaded episode four of GOT one day before it was supposed to be aired on HBO. Initially, the uploader claimed they are from Pakistan, but now it has been revealed that the four arrested are Indians and work for the firm which held the details allowing them to access the episodes legally.

All four have been accused of a criminal breach and detained until August 21st for investigations.



While it’s good news for HBO that the network has found the alleged culprits behind the leak of GOT episodes there are still questions about who is leaking other episodes online? Including the yesterday’s leak in which unaired episodes of  Curb Your Enthusiasm, Insecure, Ballers, Barry and The Deuce TV series were uploaded online?

Wednesday, August 2, 2017

HBO Hacked : Game Of Thrones Season 7 Scripts & Episodes Leaked Online | Hacking News

HBO Hacked : Hackers Leak The Entire Script of 'Game of Thrones' Season 7. Hackers say they have stolen 1.5TB Data From HBO including GoT Season 7 Episodes


Hacked
HBO confirmed that hackers were able to hack HBO’s online security systems and have leaked upcoming episodes and Additionally the hackers have also released a script that is upcoming fourth episode of "Game of Thrones" Season 7.

Reportedly, hackers have obtained 1.5 terabytes of data from the company and also posted the script for the upcoming fourth episode of “Game of Thrones” Season.