Showing posts with label Hack. Show all posts
Showing posts with label Hack. Show all posts

Monday, 10 August 2015

Facebook Hacked : Software Engineer Discovers Flaw, Harvests Public User Data With Algorithm

Facebook has been urged to tighten its privacy settings after a software engineer was able to harvest data about thousands of users – simply by guessing their mobile numbers.

“Hacked” is a word that nobody wants to hear associated with Facebook, and it’s maybe a bit of an overstatement here. Software engineer Reza Moaiandin, technical director of Leeds-based Salt.agency, took note of a relatively unused Facebook feature which allows users to search for other Facebook users, using only their phone number.
 
All of the data is publicly available, but as there is no limit to the number of searches an individual user can make, the loophole could be used by cyber crooks to extract information about “millions” of users, according to the engineer Reza Moaiandin (Moaiandin), technical director of Leeds-based company Salt.agency. Writing on the company blog, he said the loophole was discovered “by mistake”:
"By using a script, an entire country’s (I tested with the US, the UK and Canada) possible number combinations can be run through these URLs, and if a number is associated with a Facebook account, it can then be associated with a name and further details"
Moaiandin has alerted Facebook to the security flaw, and a spokesperson told him “We do not consider it a security vulnerability, but we do have controls in place to monitor and mitigate abuse.”
 
The “Who can search for me?” setting is set to public by default, meaning that even if your mobile number is withheld on the site, it can still be used to find you using this loophole.A Facebook spokesperson told City A.M. that this is set to public so that they can more easily be found by friends, and that users' privacy was "extremely important" to the company:
"We have industry leading proprietary network monitoring tools constantly running in order to ensure data security and have strict rules that govern how developers are able to use our APIs to build their products. Developers are only able to access information that people have chosen to make public."

Thursday, 18 June 2015

Samsung Galaxy hack: SwiftKey vulnerability lets hackers easily take control of phones

  • Software flaw lets hackers read text messages and install apps
  • It was discovered by NowSecure mobile security researcher Ryan Welton and could affect 600 million handsets, including the new Galaxy S6
  • Owners have to wait for a fix from Samsung but are advised to avoid  unsecured Wi-Fi networks until it's rolled out

  • Hackers can easily break into Samsung Galaxy phones and spy on the entire life of their users.

    A vulnerability in software on the phones lets hackers look through the phones’ camera, listen to the microphone, read incoming and outgoing texts and install apps, according to researchers. Until Samsung fixes the problem, there is little that owners of the phone can do beyond staying off unsecured wifi networks.

    The hack works by exploiting a problem with the Samsung IME keyboard, a re-packaged version of SwiftKey that the company puts in Samsung Galaxy keyboards. That software periodically asks a server whether it needs updating — but hackers can easily get in the way of that request, pretend to be the server, and send malicious code to the phone.

     

    It doesn’t matter if Samsung users are using the keyboard or not, because it is still making the requests. But users of SwiftKey on other Android phones seem to be safe, because the problem appears to be isolated to Samsung’s version of the software.

    There are usually protections in place that stop hackers from performing what is called a “man in the middle attack”, by encrypting communication with the server, as well as ones to stop any malicious code from getting too deep into the phone. But Samsung has given its version of the software special permissions, which means that hackers can get through the protections in Android that stop third-party apps from tampering with other bits of the device.

    Though staying away from unsecured wifi networks will make users less likely to be hit by the problem, it doesn’t mean that they’re safe. Hackers could still get in the way of the messages during the course of normal browsing.

    Researchers have confirmed that the exploit works on versions of the Samsung Galaxy S6, the S6 and Galaxy S4 Mini. But it may also be active on other Samsung Galaxy phones, since the keyboard software is installed on more devices.

    Samsung is reported to have provided a patch to mobile network operators, who must push Android updates out themselves. But it’s unclear whether any networks have done so yet, and they are often slow to push out both incremental Android updates as well as security fixes.

    SwiftKey has confirmed that the problem doesn’t affect the version of SwiftKey that’s available to download for any Android or iOS device from their app stores.

    Monday, 15 June 2015

    Emoji Passwords: Harder to Hack Easier to Remember

    A company in the UK has developed a way for emoji to be used as characters in passwords, reflecting its growing use as an online language throughout the world. It sounds a bit crazy, and you would have to imagine that this is an idea that will take a long time to manifest itself into widespread adoption, but hey, the internet is full of crazy ideas.

    This is all coming from Intelligent Environments, which says its emoji PIN system is ready to go right now. The small print explains the maths behind the claim of enhanced security, calculating: “Traditional PIN = 7,290 unique permutations of four non-repeating numbers vs Emoji Passcode = 3,498,308 million unique permutations of non-repeating emojis, based on a selection size of 44 emoji.”

    If that doesn’t get you all hot for internet security matters, it quotes “Memory expert Tony Buzan” as saying: “The Emoji Passcode plays to humans’ extraordinary ability to remember pictures, which is anchored in our evolutionary history. We remember more information when it’s in pictorial form, that’s why the Emoji Passcode is better than traditional PINs.” 
     
    This does make some sense, and not just merely in a numerical sense. By committing to emoji stories that only you know, rather than relying on a phone number or date of birth that can be easily hacked.

    Friday, 12 June 2015

    None of us is safe: Major cybersecurity company hacked

    Guess what: Even the best security companies can be hacked.

    Security firms are supposed to keep us safe from threats like malware and hacker attacks, but occasionally they fall foul of the bad guys too. A year ago Avast was hacked, and some 400,000 user details were stolen. Two years ago, AVG and Avira had their websites taken over by pro-Palestinian hackers. The latest security firm to be hacked is Russian anti-virus software maker Kaspersky Lab.

    In a post on the company's blog, Chairman and CEO Eugene Kaspersky says the attack on its own internal networks was "complex, stealthy, [and] it exploited several zero-day vulnerabilities". The firm is also very confident that there was a "nation state" behind it all. Antivirus firms like to name threats, and Kaspersky Lab has labeled this particular attack Duqu 2.0, after the Duqu Trojan which was used in attacks on Iran, India, France and Ukraine back in 2011.

    Kaspersky Lab believes the purpose of the hack was to steal the company’s secrets, and says the attack was "a generation ahead of anything we’d seen earlier -- it uses a number of tricks that make it really difficult to detect and neutralize. It looks like the people behind Duqu 2.0 were fully confident it would be impossible to have their clandestine activity exposed".

    The firm views the hack as being mostly a good thing because despite its sophistication, Kaspersky Lab was able to detect it, and now has everything it needs to protect customers against future attacks. No products or services were compromised in the hack, and customers remain perfectly safe.

    Duqu 2.0 wasn’t only used to spy on Kaspersky Lab but, according to the firm, also used to spy "on several prominent targets, including participants in the international negotiations on Iran’s nuclear program and in the 70th anniversary event of the liberation of Auschwitz".

    Tuesday, 9 June 2015

    OlaCabs denies security breach, hackers claim access to vital customer information

    One of India’s popular online taxi booking service providers, OlaCabs is claimed to be accessed illegally by an alleged group of hackers called TeamUnknown. According to the post appeared on Reddit, OlaCabs’ development server has been hacked which then resulted into compromising the credit card information, history, vouchers and behavior of all its users.

    However, according to the company, no sensitive information has been compromised due to this hack attempt that was performed on a staging environment when exposed for one of OlaCabs’ test runs.

    The post found on Reddit includes the company information that is directly been copied from OlaCabs Wikipedia page. It further claims that OlaCabs’ application design is very poor and their development server is weakly configured.
    “The hack was a little tricky and involved many steps to get into the database. Once we got into the database, it was like winning a lottery,” says TeamUnknown.

    TeamUnknown has also claimed to be having the credit card details and voucher codes from OlaCabs users. However, a list containing voucher codes has not been leaked anywhere. TeamUnknown has additionally promised that it will not be misusing the users’ credit card details and voucher codes.

    On the other hand, OlaCabs said the hackers got into the server that the company uses to experiment with new features. As per a message circulated over email by the company, the server contains “dummy user” data.

    Thursday, 4 June 2015

    Ten Most Dangerous Things Users Do Online

    1. Clicking on email attachments from unknown senders
    2. Installing unauthorized applications
    3. Turning off or disabling automated security tools
    4. Opening HTML or plain-text messages from unknown senders
    5. Surfing gambling, porn, or other legally-risky Websites
    6. Giving out passwords, tokens, or smart cards
    7. Random surfing of unknown, untrusted Websites
    8. Attaching to an unknown, untrustworthy WiFi network
    9. Filling out Web scripts, forms, or registration pages
    10. Participating in chat rooms or social networking sites
    Securing your PC is in your hand. If you like to secure your PC from getting infected or getting hacked, stop being bait to hackers by doing the above things...