Monday, 25 April 2011

India's Railway Email System hacked by Pakistan Cyber Army !


India's Railway Email System hacked by Pakistan Cyber Army !
The Indian Railway Email System is Hacked by Pakistan Cyber Army (pca), They have taken complete backup of all important mails and user-pass of all email id's . Have a look to the images below as HACK PROOF and thier statement on this Hack attack.


Statement By Pakistan Cyber Army :
Dear All, Answer to Indian hackers for hacking the server of Pakistan Air Force


We are Pakistan Cyber Army (Real PCA is Reality). Many times we told Indian hackers out there from various groups that don’t mess with any Pakistani site or server especially systems from government organizations. We observe another attack on 22nd April 2011 at Pakistan Air Force Server backup server and other 8 machines on the same network. We would like to tell you that Pakistan Cyber Army is looking at each and every move you do on the cyber front of Pakistan. Indian hackers were unable to do anything accept taking screenshot of the server. We told you before that we will smoke your door off but we think you more like to be burned in fire then accept some. Go read some course books else you will lose both your name and this game.


We hacked Indian railway's email system and download all of the confidential emails as well as email addresses and their passwords. Next time we will attack your more sensitive areas where it will hurt you more. We did not delete anything on the mail system although we thought about it for a while but we are not out to destroy. Never under estimate capabilities of Pakistan and the sons of the land. Your Central bureau of investigation still looking for our clues keep on Looking CBI and use all of your investigation Agencies, keep on searching us in USA, Latvia, China, India and all of the countries listed on the MAP. We are for peace as long as no offensive attacks from your side. We are Nationalist and we are on our mission and that is the retaliation. We can’t stop Indian hackers to hack servers on our side but we can give you the best of answers possible. Your National Informatics Centre team is useless you guys can’t stop us.


We don’t accept your supremacy in Information Technology as well as in any other field. We have the minds to answer your every move. We are for Pakistan and Pakistan Cyber Army Knows its responsibility and we will never shatter the hopes of our Pakistanis. We are sleeping but not dead.


Pakistan Zindabad


Pakistan Cyber Army (Real PCA is Reality) Peace

Sunday, 24 April 2011

Facebook hacker posts stolen pics on porn site !


Facebook hacker posts stolen pics on porn site !
A 26-year-old man faces 13 felony charges after being accused of hacking into Facebook accounts, stealing photos of young women and posting them on porn sites, reports the Kansas City Star.
Along with content belonging to the 13 young women (ages 17 to 25), Timothy P. Noirjean is accused of victimizing, investigators found 92 folders on his computer containing names or photos of women, as well as 235 email addresses with security information. Noirjean confessed to accessing more than 100 Facebook accounts, and told police he was unaware that it's a crime.
The shocking thing here isn't that there are predators on the Internet, that Noirjean claims ignorance of the law, that police arrested Noirjean in his parents' basement (which, according to the report, they totally did) or that young ladies of today have porn-worthy photos of themselves in unencrypted files on their computers. It's that Noirjean carried out his crimes largely with the unwitting help of his victims:

According to the complaint, a 20-year-old woman from Oakdale told police in February 2010 that someone had accessed her personal information after pretending to be a friend through Facebook. The woman said she was exchanging instant messages with somebody she thought was her friend. The woman was logged off her Facebook account while messaging, but when she tried to log in, she was told her password had been changed.
The next day, the woman was able to access her Facebook page. But in a link to a website on a message from the woman she thought was her friend, she discovered a sexually explicit website, the complaint said.
There, she found three photos of herself that had been stored in her e-mail account. Her first and last names and city of residence also were listed.


Noirjean told police he initiated contact with the victims after obtaining their email addresses from their Facebook accounts. (Note: Facebook privacy settings allow users to hide their email addresses from some or all Facebook users, but it is not the default setting.) He then friended the women on Facebook, where he persuaded the victims to share answers to the security questions used for changing a password.

Any security expert will tell you we are a people largely given to ignoring (but still complaining about) our privacy settings, friending anyone on Facebook who asks, and we are notoriously unimaginative with our passwords.

While the report doesn't specify how Noirjean got the women to spill the answers to their security questions, one might speculate he found ways to work mom's maiden name, first pet and the street the victim grew up on into the conversation.

Once Noirjean used the security answers to get a new password to the account, his grift got easier. He could log on as the victim and IM her friends. The woman who filed the original report told police "she unwittingly disclosed the information while exchanging messages with the person she thought was her friend," reports the Star. "When investigators questioned the friend, she said that passwords to her Facebook and e-mail accounts had been changed without her knowledge the previous day."

If this sounds familiar, it's because Noirjean's M.O. has a lot in common with that of George Samuel Bronk, 23, of Citrus Heights, Calif. who faces six years in prison after he was arrested for hacking hundreds of women's e-mail accounts, using their personal information to commit identity theft and obtaining nude photos of the victims. He is also required to register as a sex offender.

So what did we learn?
If the lesson you come away with here is "Dang! It sure is easy to get into someone's computer," hopefully you won't use this new-found knowledge for your own nefarious purpose.

If you're basically good, take this as a big fat example why Internet privacy is such a hot-button issue. It's not the only reason, but it's a big one. The more a scammer knows about you, the easier it is to rip you off. If you think you're smarter than the victims here, consider that scammers can use your personal information to figure out your passwords and other info without even contacting you.

At the very least, lock down your Facebook account, and double check to make sure you did it right. And if your IMing bestie starts querying about what name your mom went by when she met her first husband, for cryin' out loud, be at least a little suspicious.

FBI tracking hackers who targeting vanessa Hudgens and other celebs !


The Federal Bureau of Investigation (FBI) is reportedly investigating a hacker ring that is targeting phones and computers of celebrities and stealing nude photos and other personal items.


The probe stems from nude photos of Vanessa Hudgens that were recently leaked online, reports the New York Daily News. 

According to TMZ.com, the federal investigators met Hudgens Wednesday to discuss her latest nude photo scandal and believe she might be the latest victim of a notorious hacker crew that has targeted scores of celebrities, including Scarlett Johansson, Ali Larter, Busy Philipps and Miley Cyrus.

A source told the website that one ringleader had fingerprints on every job and the primary motivation appeared to be the thrill and challenge - not money.

The new round of Hudgens' photos surfaced on the Internet Monday after similar full-frontal nudes appeared online in 2007 and 2009.

Hudgens, 22, is seen kissing 'Zoey 101' actress Alexa Nikolas in one of the new photos.

"Vanessa is deeply upset and angered that these old photos, which were taken years ago, continue to resurface," Hudgens' lawyer Christopher Wong said in a statement.

"It is particularly disturbing that whoever got hold of these private photos seems to be intent on illegally leaking them out over a long period of time," he said. 

"We are actively working with law enforcement to determine who is responsible and hold them accountable for their actions," he added.

The alleged raiding of her gmail account comes as the 'High School Musical' star prepares her return to the big screen in her new film 'Sucker Punch'.

Tor 0.2.1.30 is released, Download Now



Tor 0.2.1.30 fixes a variety of less critical bugs. The main other change is a slight tweak to Tor's TLS handshake that makes relays and bridges that run this new version reachable from Iran again. We don't expect this tweak will win the arms race long-term, but it buys us time until we roll out a better solution.


Complete Release description : Click Here

Infondlinux - Security tools install script for Ubuntu !


Infondlinux - Security tools install script for Ubuntu !

infondlinux is a post configuration script for Ubuntu Linux. It installs useful security tools and firefox addons. Tools installed by script are listed at the beginning of source code.

# download:
$ wget

# install:
$ sudo infondlinux.sh

Pakages :

# debian packages
# - imagemagick
# - vim 
# - less 
# - gimp
# - build-essential 
# - wipe 
# - xchat 
# - pidgin 
# - vlc 
# - nautilus-open-terminal
# - nmap
# - zenmap
# - sun-java6-plugin et jre et jdk
# - bluefish
# - flash-plugin-nonfree
# - aircrack-ng
# - wireshark
# - ruby
# - ascii
# - webhttrack
# - socat
# - nasm
# - w3af
# - subversion
# - wireshark
# - mercurial
# - libopenssl-ruby
# - ruby-gnome2
# - traceroute
# - filezilla
# - gnupg
# - rubygems
# - php5
# - libapache2-mod-php5
# - mysql-server 
# - php5-mysql
# - phpmyadmin
# - extract
# - p0f
# - spikeproxy
# - ettercap
# - dsniff :
# * arpspoof - Send out unrequested (and possibly forged) arp replies.
# * dnsspoof - forge replies to arbitrary DNS address / pointer queries on the Local Area Network.
# * dsniff - password sniffer for several protocols.
# * filesnarf - saves selected files sniffed from NFS traffic.
# * macof - flood the local network with random MAC addresses.
# * mailsnarf - sniffs mail on the LAN and stores it in mbox format.
# * msgsnarf - record selected messages from different Instant Messengers.
# * sshmitm - SSH monkey-in-the-middle. proxies and sniffs SSH traffic.
# * sshow - SSH traffic analyser.
# * tcpkill - kills specified in-progress TCP connections.
# * tcpnice - slow down specified TCP connections via â€Å“active” traffic shaping.
# * urlsnarf - output selected URLs sniffed from HTTP traffic in CLF.
# * webmitm - HTTP / HTTPS monkey-in-the-middle. transparently proxies.
# * webspy - sends URLs sniffed from a client to your local browser
# - unrar
# - torsocks
# - secure-delete
# - nautilus-gksu
# - sqlmap
# - john the ripper

# third party packages
# - tor
# - tor-geoipdb
# - virtualbox 4.0
# - google-chrome-stable

# manually downloaded softwares and version
# - DirBuster (1.0RC1)
# - truecrypt (7.0a)
# - metasploit framework (3.6)
# - webscarab (latest)
# - burp suite (1.3.03)
# - parosproxy (3.2.13)
# - jmeter (2.4)
# - rips (0.35)
# - origami-pdf (latest)
# - pdfid.py (0.0.11)
# - pdf-parser.pym (0.3.7)
# - fierce (latest)
# - wifite (latest)
# - pyloris (3.2)
# - skipfish (1.86 beta)
# - hydra (6.2)
# - Maltego (3.0)
# - set
# - volatilty (1.3 beta)

# home made scripts
# - hextoasm
# - md5crack.py (written by Corbiero)
# - chartoascii.py
# - asciitochar.py
# - rsa.py

# firefox extensions
# - livehttpheaders 
# - firebug 
# - tamperdata 
# - noscript 
# - flashblock 
# - flashgot 
# - foxyproxy
# - certificatepatrol
# - chickenfoot 1.0.7

Saturday, 23 April 2011

The World Largest Touch Screen Hacked !


It's gigantic ! It can handle over 100 simultaneous touch points! It has a curvature of 135 degrees! And best of all, it is NOT the newest, insanely expensive gadget to hit the market. Instead, this touchscreen was hacked together with a bunch of PCs, video cameras, projectors and cheap infrared illuminators at the University of Groningen, in the Netherlands.
It works like this: "The cameras, illuminators and projectors are all placed behind a large, cylindrical screen (formally used as a 3D theater). Due to the diffuse layer on the front side of the screen, the cameras cannot see clearly through the screen, however whenever someone touches the screen, enough of the infrared light is reflected back to see the tip of the finger. The difference is very small (on a scale of 0-255 the difference is only 2 or 3), but still big enough to be seen by the computers that analyze the images from the cameras."
The display is used to teach mathematics and computer science students the elusive concept of interactivity.

PlayStation Network Hacked, Information leaked !


PlayStation Network Hacked, Information leaked !

While the PlayStation Network is down, a lot of gamers are curious as to what have been the reasons to this outrageous downtime. Today, Media Molecule said that the PSN is once again, hacked.

According to the post that Media Molecule posted today, the PSN is hacked and it warned users not to enter any personal information including credit card, etc until the PSN website says it’s okay.
Here’s what Media Molecule posted:

The PSN is still down because of a hack and will remain out of service for another while yet (worst-case scenario would be 1 or 2 more days). DO NOT enter ANY personal information (credit card information etc.) until the PSN website says its OK. Even once the PSN website says it’s OK, please wait at least 2 hours to make sure it’s a legitimate announcement. But for the moment, you should be patient and don’t worry about it.

As what Patrick Seybold of Sony Computer Entertainment America said yesterday, the downtime may last up to two days depending on how successful they get in getting the server back up online.

The-HYDRA v6.1 brute force tool released!

One of the most famous network logon cracker - THC-HYDRA, has been updated! We now have THC-HYDRA version 6.1 in less than a fortnight!

“THC-HYDRA is a very fast network logon cracker which support many different services. This tool is a proof of concept code, to give researchers and security consultants the possibility to show how easy it would be to gain unauthorized access from remote to a system. It was tested to compile cleanly on Linux, Windows/Cygwin, Solaris, FreeBSD and OSX.”

This is the change log:
More license updates for the files for the debian guys
Fix for the configure script to correctly detect postgresql
Add checks for libssh v0.4 and support for ssh v1
Merge all latest crypto code in sasl files
Fix SVN compilation issue on openSUSE (tested with v11.3)




Hacker Pleads After Busted With 675K Stolen Cards


A Georgia man has pleaded guilty to fraud and identity theft after authorities found him in possession of more than 675,000 credit card numbers, some of which he obtained by hacking into business networks

Rogelio Hackett Jr., 26, pleaded guilty on Thursday to one count each of access device fraud and aggravated identity theft after authorities executed a search warrant at his home and discovered the card numbers, used to conduct fraudulent transactions totaling more than $36 million, on his computers and storage devices.

According to the indictment, authorities hunted Hackett down after monitoring his activity in internet relay chat (IRC) rooms and on underground forums, where he sold stolen card numbers, usually at $20 to $25 each to buyers around the world. He used the proceeds to make high-end purchases, such as a 2001 BMW X5 and a pair of $450 Louis Vuitton shoes.

In addition, Hackett was charged with obtaining devices used to create counterfeit credit cards.

According to prosecutors, Hackett started hacking in the late 1990s when he was a teenager and eventually was recruited to hack for profit.

He leveraged SQL injection vulnerabilities to access the networks of a number of businesses, including an unnamed online ticket provider in 2007 to steal 360,000 credit card numbers. He also purchased card data over the internet from individuals he believed lived in the United States, Russia and Ukraine.

The net began to close in on Hackett in 2009, after he sold 40 bogus credit cards for $1,180 to U.S. Secret Service agents.

He faces 12 years in prison when he is sentenced, scheduled for July 22. He also faces fines of $500,000 for the two charges.

Additionally he agreed to the judge's restitution order of $36 million. Sentencing is scheduled for July 22.

Friday, 22 April 2011

Pakistan Air Force Server Hacked by Code Breaker/Lucky (Indishell)

Pakistan Air Force Server Hacked by Code Breaker/Lucky (Indishell)

Indishell, group of some Indian Hackers hacked PAF (Pakistan Air Force) server with 8 more server in LAN. They claimed that all those 8 more servers were in LAN with that PAF server. Here’s a screenshot of RDP. 'Code Breaker' claims to have backed up all the data using remote desktop protocols.

Wednesday, 20 April 2011

The World Now,"Third Age" Cyber Crime

The year 2010 was a crime of great team and could prove to mark the beginning of a "third age" of computer crimes, security expert Graham Cluley of Sophos, said before the review of the latest threats Company year.


The first period was marked by amateur hackers and virus creation on the PC, the second by the merger of organized crime with new Internet technologies, and as expected 2010 has seen a lot on both fronts in ways each increasingly sophisticated and varied.

That the points during the year, the criminals seem to be moving some of the old-fashioned junk mail and use their websites to incorporate crime e-mail, Battlefront, social networks.

"The scale subversive activities, Facebook seems out of control," said report co-author, Graham Cluley. "Social media sites, however, unable or unwilling to invest the resources necessary to stamp out," he writes, the last line of stinging comments made in recent months is evident satisfaction of security.

Verizon 2011 Data Breach Investigations Report Released !


Verizon 2011 Data Breach Investigations Report Released !
Data loss through cyber attacks decreased sharply in 2010, but the total number of breaches was higher than ever, according to the " Verizon 2011 Data Breach Investigations Report ." These findings continue to demonstrate that businesses and consumers must remain vigilant in implementing and maintaining security practices.

The number of compromised records involved in data breaches investigated by Verizon and the U.S. Secret Service dropped from 144 million in 2009 to only 4 million in 2010, representing the lowest volume of data loss since the report's launch in 2008. Yet this year's report covers approximately 760 data breaches, the largest caseload to date.

According to the report, the seeming contradiction between the low data loss and the high number of breaches likely stems from a significant decline in large-scale breaches, caused by a change in tactics by cybercriminals. They are engaging in small, opportunistic attacks rather than large-scale, difficult attacks and are using relatively unsophisticated methods to successfully penetrate organizations. For example, only 3 percent of breaches were considered unavoidable without extremely difficult or expensive corrective action.

The report also found that outsiders are responsible for 92 percent of breaches, a significant increase from the 2010 findings. Although the percentage of insider attacks decreased significantly over the previous year
(16 percent versus 49 percent), this is largely due to the huge increase in smaller external attacks. As a result, the total number of insider attacks actually remained relatively constant.

Hacking (50 percent) and malware (49 percent) were the most prominent types of attack, with many of those attacks involving weak or stolen credentials and passwords. For the first time, physical attacks -- such as compromising ATMs -- appeared as one of the three most common ways to steal information, and
constituted 29 percent of all cases investigated.

For the second year in a row, the U.S. Secret Service collaborated with Verizon in preparing the report. In addition, the National High Tech Crime Unit of the Netherlands Policy Agency (KLPD) joined the team this year, allowing Verizon to provide more insight into cases originating in Europe. Approximately one-third of Verizon's cases originated in either Europe or the Asia-Pacific region, reflecting the global nature of data breaches.

A complete copy of the "2011 Data Breach Investigations Report" is available for download.

Tuesday, 19 April 2011

Cybersecutity Expert Creat Program That Steals Text Messages !

Two cybersecurity researchers have just taught smartphones a lesson by developing a program that can eavesdrop and steal text messages from any phone on a GSM network – all in about 20 seconds.


The Guardian reported that Karsten Nohl and Sylvain Munaut spent a year honing their technology, which starts by sending a text message to a target phone; called a “ghost” message, the text doesn’t show up on the recipient’s phone, but enables the hackers to obtain the handset’s unique identification number.

Once that identification number is stolen, Nohl and Munaut were able to record phone conversations and texts from the hijacked phone. Their proof-of-concept hack can be deployed on any phone running on a GSM (Global System for Mobile Communications) network.

That’s a pretty big focus group – about 80 percent of the world’s phones run on a GSM network.

“Any GSM call is fair game,” Nohl told the BBC. He and his partner in cybercrime demonstrated their data-grabbing technology at last week’s Chaos Computer Club Congress (a gathering of the hacker organization) in Berlin.

Despite its mischievous nature, there is no devious design behind their hacking technology.

Nohl said he and Munaut do not plan to make the eavesdropping kit available for others to use. He said they developed it in the hopes it would serve as a wake-up call to the mobile security industry.

“This is all a 20-year-old infrastructure, with lots of private data and not a lot of security,” Nohl said of the GSM network. “We want you to help phones go through the same kind of evolutionary steps that computers did in the 1990s.”

Stolen data may be sold on cyber black market !

Hackers behind what computer security experts believe could be the biggest data theft in US history may be planning to sell the information to cyber criminals for targeted scams.

And while the tens of millions of names and email addresses swiped from online marketing firm Epsilon do not appear to have been used yet for cyber crime, the experts said it may just be a matter of time.

Major US banks, hotels, retail outlets and other companies have been warning customers to be wary of fraudulent emails after Epsilon acknowledged last week that hackers had gained access to the Texas-based company's email system.

Epsilon, which provides email services for some 2,500 companies around the world, has said that customer data for about two per cent of its total clients was exposed in what it called an "unauthorized entry."

Epsilon, which sends out over 40 billion emails a year, did not identify the firms whose customers' names and email addresses were taken but dozens of US companies have come forward over the past few days.

"It's basically a who's who from the retail and banking space," said Nicholas Percoco, head of Trustwave's SpiderLabs. "Some of the top brands in the world."

They include Hilton and Marriott hotels, telecom giant Verizon, drugstore chain Walgreens, the Home Shopping Network and retailers Best Buy, Kroger, New York & Co. and Target.

Among the banking and financial firms that have notified customers of the breach are Citigroup, JPMorgan Chase, Capital One, US Bank, Barclays Bank of Delaware and Ameriprise Financial.

Security experts said the data theft at Epsilon could be the largest ever in terms of sheer volume, comparable to the exploits of Albert Gonzalez, one of the most prolific US commercial hackers ever.

Gonzalez is serving 20 years in prison for stealing tens of millions of debit and credit card numbers from firms supporting major US retailers and financial institutions.

Percoco said the Epsilon data theft may involve as many as 100 million unique email addresses and "could end up being the largest breach ever of raw personal data, consumer data."

Marian Merritt, Internet Safety Advocate at Symantec, the maker of Norton anti-virus software, said data breaches occur frequently but "all indications are this could be the biggest one in history."

It is unlikely to prove as damaging, however, as the Gonzalez scams.

"The good news is it's just the names and the email addresses and the affiliation of the company that you did business with," said Joris Evers, a security expert at McAfee.

"It's not your credit card number or your social security card number or your home address... information that could be more personal and used in more nefarious ways immediately," Evers said. "There's a lot of work to do before you can convert this into cash."

The Epsilon data does not appear to have been used yet for any cyber crime.

"We have been looking around since this news broke for spam and scams and scammy websites that potentially take advantage of this breach and we haven't seen anything just yet," Evers said.

That may be because the hackers who carried out the Epsilon attack intend to sell the information to other cyber criminals, the experts said.

"They may be people who are buying and selling stolen data bases of user names and email addresses," said Symantec's Merritt.

"There are marketplaces on the Internet, underground markets, where people sell bulk bunches of email addresses and names," Evers added. "You can buy a million email addresses for 20 dollars or something like that.

"But that's just email addresses, mailing lists that you can then start spamming."

The information stolen from Epsilon is more valuable because it links names and email addresses with particular companies that an individual already has a trusted relationship with.

"They've got your name, not your user name, but your actual name, your email address and brands that you regularly do business with and trust in an email relationship," Merritt said.

"You've already identified yourself as willing to receive communications from those brands," she said. "So the cybercriminals have pretty good information to use against you."

Evers said such information can be a "treasure trove" for cyber attackers because now they can start personally targeting individuals, a tactic known as "spear phishing."

For example, "you might have bought something from LL Bean recently," he said. "You receive an email that says 'We want to confirm your order, please click here.'

"And you end up on a website that infects your computer with something. Or you're asked to type in your credit card number again to make sure the order goes through," he said. "And now, boom, I have your credit card information." Whatever form the attacks take, experts are certain they're coming.

"They didn't go get these email addresses and names just to get them," Percoco said. "They're going to use them."

Source : http://www.asiaone.com

China's Cyber Hackers Target Western Firms !

China's Cyber Hackers Target Western Firms !














Sky News has learnt of the growing threat Western governments and corporations are under from hackers based in China.

Cyber crime costs the UK tens of billions of pounds every year.
The attacks cannot be traced but I have gained access to some of the country's growing number of hackers to discover just how big a risk they pose:
The man I meet is 21, he has no technical training and has moved to Beijing from a small town in southern China.
But within minutes of our meeting, he's shown me how he can hack into my email account.
A few more clicks of his mouse, and he's stolen my credit card details as I make an online purchase.
He says he's a "cyber security expert" - not a hacker - but we can't use his name and he refuses to show his face.
I ask him whether he could successfully hack into more carefully guarded computer systems: those of government officials and top companies in the West.
"Even the strongest security systems have holes," he tells me. "Everyone knows that those people haven't realised that there are hackers who can attack them. They probably think they have the best security possible."
Last year, cyber attacks cost Britain £27bn. The global hub for targeted attacks is China. An estimated 1.6 billion attacks are launched from the country each month.
The Chinese government says it is cracking down on hackers. Last year authorities reportedly made several hundred arrests and closed one online hacking school that was said to have 180,000 members.
But other websites that offer the same service are still operating.
Sky News recently gained access to a conference organised by a well-known hacking group in a four-star hotel in Beijing.
The event was sponsored by a security firm with alleged connections to the Chinese military. Speakers covered topics such as Defeat Windows 7 and Virtual Viruses Infection.
The conference also highlighted the murky connections between hackers and the Chinese government.
One man who identified himself as a policeman said: "We're here to see if they have anything we can use. If there is, then we'll get in touch with them, and take the next step."
Chinese hackers are accused of breaching the computer systems of the Pentagon in the US and the French and German governments, as well as several Whitehall departments.
In 2009, investigators discovered that Ghostnet, the largest ever network of cyber attacks, could be traced back to China.
The operation's command and control had gained real time control over 1,200 computers belonging to foreign embassies, international organisations, and media groups in more than 100 countries.
However, according to experts, the biggest threat posed by attacks traced to China is the loss of industrial secrets.
Last year several attacks targeted some of the world's biggest oil and gas companies - an area of enormous strategic importance to China's economy.
It was also recently revealed that investment bank Morgan Stanley was hit by a six-month attack emanating from China.
Experts say Britain's high-tech industries are particularly vulnerable.
"Britain spends £25bn a year in these areas," says British cyber security expert Will Gilpin.
"It has a lot of specialist knowledge, abilities and plans available in its computers which are tremendously appealing to a country like China that wants to short circuit and leapfrog the Western countries in developing their economy."
But the young "cyber security expert" says there may be an even bigger threat. If the West ever came into conflict with China, he says the country's hackers would be able to inflict untold damage.
"They may be able to shut down the electrical grid," he says. "Lots of things don't function without electricity. You could stop a whole area or the entire country from working."

Saturday, 16 April 2011

Emergency Adobe Flash Player patch coming today !

Emergency Adobe Flash Player patch coming today !

Less than a week after warning that hackers were embedding malicious Flash Player files (.swf) into Microsoft Word documents to launch targeted malware attacks, Adobe plans to release an emergency Flash Player patch today to fix the underlying problem.

The patch will fix a “critical” vulnerability in Flash Player 10.2.153.1 and earlier versions for Windows, Mac OS X Linux and Solaris.


According to this Secunia advisory, the flaw allows a hacker to completely hijack a vulnerable Windows computer:
A vulnerability has been reported in Adobe Flash Player, which can be exploited by malicious people to compromise a user’s system.


The vulnerability is caused due to an error when parsing ActionScript that adds a custom function to the prototype of a predefined class. This results in incorrect interpretation of an object (i.e. object type confusion) when calling the custom function, which causes an invalid pointer to be dereferenced.

Secunia has posted a technical analysis of the flaw as well.

Adobe has confirmed that the vulnerability (CVE-2011-0611) could cause a crash and potentially allow an attacker to take control of the affected system.

There are reports that this vulnerability is being exploited in the wild in targeted attacks via a malicious Web page or a Flash (.swf) file embedded in a Microsoft Word (.doc) or Microsoft Excel (.xls) file delivered as an email attachment, targeting the Windows platform. At this time, Adobe is not aware of any attacks via PDF targeting Adobe Reader and Acrobat. Adobe Reader X Protected Mode mitigations would prevent an exploit of this kind from executing.

A patch for Google Chrome users is already available in Chrome version 10.0.648.205.

Adobe plans to fix the vulnerability in Adobe Acrobat and Adobe Reader at a later date.

Friday, 8 April 2011

Google Fixing the little things !


Google Fixing the little things !
Ever since I joined the Gmail team, my friends have been eager to tell me, "I love Gmail ! Except for this one thing..." And every day, Gmail users share their "one thing" that would make Gmail better for them through our suggestions page. While we enjoy creating new solutions to old problems with features like Priority Inbox, those little annoyances and missing pieces are important, too. Recently, we've rolled out several small tweaks to Gmail to show it a little extra love. 


Here’s a rundown:
  • Auto-save contacts setting: Most people like that Gmail automatically saves every email address you send messages to; it can help recover forgotten addresses of former teachers, bosses, and people you contacted once but never thought you'd need to contact again. For some people, though, this feature can cause too much contacts clutter. Today, we're rolling out a new setting to let you turn off the auto-save option. You’ll see it on the General tab of Gmail Settings.
  • Better warnings for typos in email addresses: We all make typos, even when addressing email. In the old days, when you accidentally left out the "." in your ".com", Gmail would tell you there was an error but not point it out. Now, it’ll let you know which address has the problem -- much easier when sorting through a long “To:” list.
  • Fewer annoying error pop-ups: Gmail's filters are really useful for organizing your messages automatically, but sometimes those filters can have unintended consequences, like sending mail you'd like to keep to the trash. When you replied to a message in the Trash, Gmail would show an error message you'd have to click through to continue working. Now, you’ll still see the error, but it's no longer a pop up and it gives you an easy way to move the conversation out of Trash right from there.
  • Easier transitions between certain actions: You can create filters quickly from the "Filter messages like this" option that shows up on some messages. Now, after you've saved your filter, Gmail will send you right back to the message you were reading so you can go right back to what you were doing before.
  • Keyboard shortcut guide for everyone: Keyboard shortcuts can be a huge productivity boosters. If you've never tried them, try hitting Shift+? -- that's one keyboard shortcut that's now automatically turned on and gives you a peek into the rest of them and a quick link to enable from there.
  • Refresh button: For a long time, people have pointed out the inconsistency of having "Refresh" as a link in the menu bar, next to all of the buttons. We changed it to a button to match.

If any of these small fixes were your "one thing," we hope you've noticed the changes as they rolled out. When you find the next little tweak that would make you love Gmail even more, let us know.

Thursday, 7 April 2011

Hackers steal Dell 1000's customer information !


Hackers steal Dell 1000's customer information !

































The personal information of thousands of Australians has been stolen by hackers who raided a US-based database company, in what some experts are calling the biggest data theft in US history.

Dell Australia says customer data was "exposed" by an unauthorised entry into the computer system of email service provider Epsilon.

The information includes the names and email addresses of Dell Australia's customers.

In a statement, Dell assured its customers that credit card, banking and other personally-identifiable information was not at risk and remained secure.

Australian Privacy Commissioner Timothy Pilgrim says Dell has informed him of the data breach.

"Dell Australia have also advised all of its customers affected by the data breach and have set up an advice service that those customers can use to obtain further information if needed," he said in a statement.

Mr Pilgrim has launched an investigation into the incident.

"I have also been advised that Epsilon has commenced an investigation into this matter and is keeping Dell Australia informed," he said.

Dell is warning affected customers to be aware of unusual or suspicious emails requesting personal information.

The crime is being described by experts as the biggest data theft in US history, and it is believed the hackers may be planning to sell the information to cyber criminals for targeted scams.

And while the tens of millions of names and email addresses swiped do not appear to have been used yet for cyber crime, experts said it may just be a matter of time.

Ed Heffernan, chief executive of Alliance Data Systems Corp, Epsilon's parent company, apologised for the breach and says it is being investigated by federal authorities and outside computer forensics experts.

"We will leave no stone unturned and are dealing with this malicious act by highly sophisticated cyber thieves with the greatest sense of urgency," he said.

Experts says the data theft could be the largest ever in terms of volume, comparable to the exploits of Albert Gonzalez, a hacker serving 20 years in prison for stealing tens of millions of debit and credit card numbers.

"All indications are this could be the biggest one in history," says Marian Merritt, internet safety advocate at Symantec, the maker of Norton anti-virus software.

It is unlikely, however, to prove as damaging as the Gonzalez scams.

"The good news is it's just the names and the email addresses and the affiliation of the company that you did business with," said Joris Evers, a security expert at McAfee.

"It's not your credit card number or your social security card number or your home address... information that could be more personal and used in more nefarious ways immediately," he said.

"There's a lot of work to do before you can convert this into cash.