Showing posts with label Ethical World. Show all posts
Showing posts with label Ethical World. Show all posts

Thursday, July 28, 2011



After 7 days of speculation-ridden downtime, Sony has finally announced that the PlayStation Network (PSN) outage was due to a massive hack that exposed the names, birthdays, email addresses, passwords, security questions, and maybe credit card details, of all PSN users.

At first, the most likely explanation for the PSN’s downtime was a continuation of Anonymous’s DDoS reprisal for Sony’s persecution of PlayStation 3 jailbreaker, George Hotz (geohot). Then, as the outage extended past a few days, and Sony announced that it was “rebuilding” its network due to an “external intrusion,” it became apparent that this was much more than a simple, brute force denial of service attack. Today’s announcement by Sony confirms that the PlayStation Network’s security mechanisms were fully circumvented, and that at least one of its most sensitive databases was breached and accessed sometime between April 17 and 19.

How was the PlayStation Network hacked, though? Ironically, for security reasons, and because Sony is historically very tight-lipped on such matters, we will probably never know the exact attack vector — but we can certainly make some well-educated guesses about how the PlayStation Network was hacked. First, given its proximity to Anonymous’s recent attacks, it’s likely that the database breach is somehow related. It’s safe to assume that Anonymous could have learned about a weakness in the PSN’s security mechanisms, and then passed that data on to another group of hackers — and from there, if the hole was big enough, the attackers might have been able to simply step right in with an SQL injection attack.

Moving forward, there’s no indication of when the PlayStation Network will return. Sony has warned its users to look out for mail or telephone scams, and to lodge a “fraud alert” with credit bureaus like Experian and and Equifax, which should prevent your credit card from being used by the hackers. If you’re a PlayStation Network user, check the PlayStation Blog for more information.

As we move towards a lifestyle that is dominated by cloud-based services like Gmail, Steam, Xbox Live, and Netflix, these attacks will become more and more commonplace. It’s infinitely convenient to have your data all in one place and accessible from any net-connected computer — but likewise, these services represent the juiciest imaginable hacking target. A large database of email addresses is worth millions if sold to a spam baron!

SoSasta Logo



The entire user database of Groupon’s Indian subsidiary Sosasta.com was accidentally published to the Internet and indexed by Google.

The database includes the e-mail addresses and clear-text passwords of the site’s 300,000 users. It was discovered by Australian security consultant Daniel Grzelak as he searched for publicly accessible databases containing e-mail address and password pairs.

Grzelak used Google to search for SQL database files that were web accessible and contained keywords like “password” and “gmail”.

“A few hours and tweaks later, this database came up,” he said. “I started scrolling, and scrolling and I couldn’t get to the bottom of the file. Then I realised how big it actually was.”

Grzelak contacted Risky.Biz after the Sosasta discovery to seek advice on disclosure. This website contacted the CEO of Groupon, Andrew Mason, who called back personally within 24 hours of initial contact.

The database was removed immediately and the company has launched an internal investigation to find out how it wound up publicly accessible in the first place.

Groupon is notifying all its Sosasta users of the incident and is advising them that the passwords they used on the website are now compromised and cannot be relied upon to secure other accounts.


The Hacker’s Choice announced a security problem with Vodafone’s Mobile Phone Network.
An attacker can listen to UK Vodafone mobile phone calls.
An attacker can exploit a vulnerability in 3G/UMTS/WCDMA – the latest and most secure mobile phone standard in use today.
The technical details are available at http://wiki.thc.org/vodafone.
The problem lies within Vodafone’s Sure Signal / Femto equipment.
A Femto Cell is a tiny little home router which boosts the 3G Phone signal. It’s available from the Vodafone Store to any customer for 160 GBP.
THC managed to reverse engineer – a process of revealing the secrets – of the equipment. THC is now able to turn this Femto Cell into a full blown 3G/UMTC/WCDMA interception device.
A Femto is linked to the Vodafone core network via your home Internet connection. The Femto uses this access to retrieve the secret key material of a Vodafone customer who wants to use the Femto.
THC found a way to circumvent this and to allow any subscriber – even those not registered with the Femto – to use the Femto. They turned it into an IMSI grabber. The attacker has to be within 50m range of the UK Vodafone customer to make the customer’s phone use the attacker’s femto.
The second vulnerability is that Vodafone grants the femto to the Vodafone Core Network HLR /AuC which store the secret subscriber information. This means an attacker with administrator access to the Femto can request the secret key material of a UK Vodafone Mobile Phone User.
This is exactly what happened. The group gained administrator access to the Femto. An attacker can now retrieve the secret key material of other Vodafone customers.
This secret key material enables an attacker to listen to other people’s phone calls and to impersonate the victim’s phone, to make phone calls on the victim’s cost and access the victim’s voice mail.
This is clearly a design flaw by Vodafone. It is disgusting to see that a major player like Vodafone chooses ‘newsys’ as the administrator password, thus allowing anyone to retrieve secret data of other people.

Monday, May 9, 2011


It’s bad news piled on top of bad news for Sony.


Hackers may have stolen the personal information of 24.6 million Sony Online Entertainment users, the company said on Monday. More than 20,000 credit card and bank account numbers were also put at risk. This is in addition to the recent leak of over 70 million accounts from Sony’s PlayStation Network and Qriocity services.


“We are today advising you that the personal information you provided us in connection with your SOE account may have been stolen in a cyberattack,” Sony wrote in a statement on its website.


Sony Online Entertainment is a division of the company that publishes online multiplayer games like the recently released DC Universe Online. Sony turned off all SOE game services Monday after it learned of the intrusion.


Sony said that the compromised personal information includes customers’ names, addresses, e-mail addresses, birth dates, gender, phone numbers, logins and hashed passwords.
Also at risk are the credit card numbers and expiration dates of 12,700 non-U.S. customers, plus 10,700 direct debit records from customers in Austria, Germany, Netherlands and Spain, containing bank-account numbers, customers’ names and addresses. This information was stored in what Sony said was an “outdated database from 2007.”
Hackers may have had this information for more than two weeks now. The intrusion occurred April 16 and 17, Sony said.


Customers first noticed that Sony’s PlayStation Network service was down April 20. After a week of downtime, the company said that hackers had attacked its services and that the personal and credit card information associated with more than 70 million accounts were at risk.


At the time, Sony said that the Online Entertainment division had not been affected by the hack and would remain in operation, telling customers that their data was safe to the best of its knowledge.


Though both Visa and American Express told Wired.com last week that they had no reason to believe their credit cards had been compromised, several dozen Ars Technica readers reported what they believed to be PSN-connected fraud.


The PlayStation Network is still offline, but Sony says it will restore some services later this week, including online multiplayer gaming for PlayStation 3 and PSP. As a goodwill gesture, Sony says it will offer all customers a selection of downloadable content and 30 free days of its premium PlayStation Plus service.


As compensation for the Sony Online Entertainment leak, Sony said that it will give all of its customers 30 days of additional subscription time, plus an extra day for each day the servers remain down.


Sony did not say when its SOE services would be back online.

Wednesday, May 4, 2011


                         Screenshot of SMS message sent to botnet administrator


BlackBerry smartphones have come under a new attack targeting their SMS feature according to security firm Trend Micro.

Just like its desktop counterpart, the ZeuS Trojan, identified as BBOS_ZITMO.B, removes itself from the list of applications to be able to stay undetected, rather than displaying any graphical user interface (GUI). Once it is installed, ZeuS sends a confirmation message "App Installed OK", to the administrator number, which is a U.K. number, to signal that it can now receive commands.

The administrator/attacker can remotely change the number to which it forwards SMS sent to the affected phone. Thus, in case the original administrator/attacker number is tracked and taken down, the attacker can send a command to update the attacker number to continue receiving forwarded messages.

According to the analysis carried out by Trend Micro, ZeuS Trojan is capable of carrying out the following commands:

1.Display SMS: Unmonitored SMS will be treated as a normal SMS and will be displayed on the phone.
2.Delete/Drop SMS: SMS from hacker will not be seen by the user.
3.Forward SMS: Send SMS to hacker without the user's knowledge.
4.Block Calls
5.Remove Block Calls
6.Set Administrator: Register a new administrator.
7.On/Off
8.Add Sender
9.Remove Sender
10.Set Sender
11.Block/Unblock Phone Numbers

Trend Micro country manager for India and SAARC, Amit Nath said, "As more users access internet from expanding pool of devices, web based threats will continue in size. The Growth of Smartphones and faster data speeds will also increase the possibilities of infection. As criminals devise ways to make money out of exploiting mobile technologies, mobile users will grow extremely vulnerable. With the growing diversity of operating systems among companies, as well as the growing use of mobile devices, cybercriminals should have a very profitable 2011. Their tactic will be to put a new spin on social engineering by way of malware campaigns, by bombarding recipients with emails that drop downloaders containing malware. All this will largely be made possible because of the Internet."

Trend Micro asserts that this threat affects not just BlackBerry phones, but has also been spotted in smartphones based on Symbian (SYMBOS_ZBOT.B) and Windows Mobile (WINCE_ZBOT.B). People using mobile banking need to be extra cautious while installing applications and clicking links sent by unknown users or they risk downloading this malicious application and compromising their security.



Web Applications relay on dynamic content to achieve the appeal of traditional desktop windowing programss. This dynamism is typically achieved by retrieving updated data from a database. One of the more popular platforms for web datastores is SQL, and many web applications are based entirely on front-end scripts that simply query an SQL database, either on the web server itself or a spearate back-end system. One of the most insidious attacks on a web application involves hijacking the queries used by the front-end scripts themselves to attain control of the application or its data. One of the most efficient mechanisms for achieving this is a technique called SQL-Injection.

SQL-Injection refers to inputting raw Transact SQL queries into an application to perform an unexpected action. Often, existing queries are simply edited to achieve the same results-- Transact SQL is easily mnipulated by the placement of even a single character in a judiciously chosen spot, causing the entire query to behave in quite malicious ways. Some of the characters commonly used for such input validation attacks include the backtick ( ` ), the double dash ( -- ). and the semicolon ( ; ), all of which have special meaning in transact SQL.

Sunday, May 1, 2011



Anti Keylogger Shield is a powerful, easy to use anti-spy software tool that prohibits operation of keyloggers, known or unknown, professional or custom made. Once installed, Anti Keylogger Shield will run silently in your System Tray, it will block the system mechanisms that are exploited by keyloggers, and will immediately start protecting your privacy. With Anti Key logger shield you can hide and protect your keystrokes from prying eyes.


Keep your Keystrokes PRIVATE!


Keyloggers are small spy programs, that record everything you type on the computer, including documents, emails, user names and passwords, and then either stores this information in a hidden place on your computer or sends it over the Internet to the person who infiltrated it.
Keyloggers can come in many forms, as emails, viruses, Trojan horses; from people who might try to invade your privacy and see what you are typing, or remote hackers, who might want to steel user names and passwords as you type them.



download here



Google talk is under suspicion of malware spreading..Some of the best viruses of ‘yahoo messenger’ have started attacking the online chat service of Google which is popularly known as g-talk

This new virus which duplicates the link of your friend in g talk and sends you various links……When you click that link the page will divert into another with a malware content..The moment you reaches this page the virus content in the page will freeze your anti virus software , does certain problems and even makes your computer a machine for future virus downloads.

You will get this virus , like your friend sent it. but, do remember to always think twice before clicking it , g-talk is no longer safe.

First a link of an image file will reach your chat box in the name of a friend, thinking that he actually sent it , we’ll click it.Then that virus will be automatically downloaded into your computer and will start sending the same virus to all your online friends in the name of you (we will not notice it!).

Actually in our chat window in the name of an image file,a link to a ‘zip’ extension or an E.X.E file is appearing.

(eg:-http://srv057.imageshares.info:88/displayphoto009.jpg.zip)

If this virus strike your computer then there will be a festival of messages. a number of messages will appear in your chat box in the name of your friends(eg:- hurrrrey,r u dre,look at my new my space photo etc)

Some of these messages or viruses in this case will frequently “open and close” and makes your system hank.

We can escape from these “fake message malwares through filtering the link using your anti virus program, but even the latest anti-virus soft wares are not noticing these viruses.There is also a chance for your anti-virus to freeze.

So, think twice before clicking a link sent to you by a friend , always make sure they are not ending with ‘.zip’ or ‘.axe’

AND STAY OUT OF TROUBLE……O.K