Subscribe For Free Updates!

We'll not spam mate! We promise.

Showing posts with label Hacking news. Show all posts
Showing posts with label Hacking news. Show all posts

Sunday, August 24, 2014

Technical Description of Latest Facebook Virus- Sorpampa

Beware of a new Facebook virus called 'Sorpampa', spreading through Facebook Messages."This video is yours?", tries to disable/bypass the anti-virus software, then spreads itself by different chat sessions of the infected user/system.

How to remove it? Read a clear description at http://cyb3rgeeks.blogspot.com/2014/08/facebook-malware-this-video-belong-to-you-thatis-funny.html
 

What the virus does, well it redirects you to a*m*k-m*t*2[dot]com , example:-
<script> location.href="http://www.a*m*k-m*t*2[dot]com/?bencegomik"; </script> (without *'s)

Then when reading the source code on that page, it's clear enough to me they try to infect you.

After checking the domain info of http://www.a*m*k-m*t*2[dot]com, it seems this is the owner:-
(note: i do not say/blame this is the person that spreads the virus, but this is the person that hosts the virus/script)(Regards Ray bro)

Registrant Name: BAYRAM ACAN
Registrant Organization: BAYRAM ACAN
Registrant Street: bbbbbbbbbb
Registrant City: ISTANBUL
Registrant State/Province:
Registrant Postal Code: 34100
Registrant Country: TR
Registrant Phone: +90.5442396707

Registrant Email: saner.3@hotmail.com

Saturday, August 23, 2014

Gmail Android app hacked by researchers

US Researchers have found a weakness in Google’s popular Android operating system.Your most trustworthy apps may be at risk. Researchers say they have found a way to hack Gmail apps with a 92 percent success rate.

The vulnerability extends to a number of other apps including H&R Block, Newegg, WebMD, Chase Bank, Hotels.com and Amazon, according to their study. In most cases, their technique succeeded 80-90% of the time. Amazon’s app was the most difficult to crack at 48%.

gmail hack

Although the paper only covers these seven Android apps, the researchers said their hacks exploit a vulnerability that apps on other operating systems likely share.
"I certainly think the report is credible," cyber-security analyst Michela Menting said in an email. "If a researcher or a hacker looks hard enough, there will be ways to exploit any number of vectors within an application."

Technical Section(How did they do it?)

The hack begins when a user downloads malicious software disguised as a seemingly harmless app like background wallpaper app. Next, the masquerading app exploits a common feature of operating systems—shared memory —to figure out what users are doing on their smartphones.

When timed properly—say, just as a user is entering a username and password, or snapping a picture of a personal check—a hacker can launch a phishing attack. Users think they’re punching their passwords into an app like Gmail, Amazon or Chase, but they’re actually typing it into a sham-screen generated by the malicious app.“At this point, the information is stolen and the attack succeeds,” the authors said in the study. Two of the researchers hail from University of Michigan and another from University of California at Riverside.

Demo videos show how a hacker could use another phone to monitor the activity on the sensitive apps and grab personal information when entered by the victim.





The hack exploits the same design principle that allows alarm and apps that serve as reminder to pop up on a smartphone. Zhiyun Qian, assistant professor at UC Riverside and one of the study’s authors, said in a statement that “by design, Android allows apps to be preempted or hijacked.” 

The hacker would gain access by causing a user to install a seemingly harmless app such as phone wallpaper and expose a newly discovered public side channel that doesn't require privileges. This feature allows processes to share data efficiently and is quite common, since all a phone's downloaded apps interact with one operating system.

"The assumption has always been that these apps can't interfere with each other easily," researcher Zhiyun Qian said in a statement. "We show that assumption is not correct and one app can in fact significantly impact another and result in harmful consequences for the user."

Why Amazon is less vulnerable?

The researchers said they had only a 48 percent success with the Amazon app because it allows transition from one activity to almost any other, increasing the difficulty of guessing what the user is doing and finding the exact moment to steal data.


How to secure your smartphone from it?
  • Users should be cautious and only download apps from trusted sources—big, popular apps are hacker magnets.
  • Do a routine check of your smartphone and tablet, especially if you have little ones using the device, to ensure only apps that can be trusted are the only ones installed. Immediately uninstall apps that appear to be from unknown sources or are not necessary.

 The researchers suspect their method will work just as well on other mobile OS, such as Apple iOS and Microsoft Windows, although they have yet to attempt the hack on those systems. They were scheduled to present their findings today at the USENIX Security Symposium in San Diego.
Google did not immediately respond to a request for comment.
I hope you enjoyed it.... Give us feedback that next we can serve more better.....

Sunday, August 17, 2014

Facebook Malware - "This video belong to you? That's funny." - How to Remove it


Now a days a facebook worm is infecting millions of people. So i decided to write an article on it to aware people.  So i am going to describe you that how you can secure yourself from this or if are infected then how can you remove it.

How it is being spread ?

 Koobface sends malicious codes in forms of messages such as "You look funny in this new video" and "You look just awesome in this new movie" leads straight to the virus

I assure you there is nothing funny about it. The Albanian malware can cause a lot of damage to your PC. The way it works is rather simple. You see that your friend has shared a video link on Facebook, you click on it and get redirected to a fake YouTube site which then requires you to download an Adobe Flash Player update. The video features a woman starting to undress and beneath it you see that it has more than a million views. That, of course, is not true. The fake video may play for a second or two so that the you  would be even more tempted to download the supposed update and finish watching the clip. Instead of this update, however, you get infected with a malicious Trojan.

 

Funny Facebook video scam Funny Facebook video scam 

 

How it works ?
The Trojan that is spread via this scam is called Trojan.Agent.BDYV and once it enters the system it starts collecting user’s personal data. It may also function as a browser hijacker. Needless to say, whoever gets infected with this malware is very likely to suffer financial consequences. Moreover, the Trojan also uses the victim’s Facebook account in order to continue on with its distribution. The user may not even be able to delete these fake posts from his own timeline and activity log. As you can see, the program is truly intrusive.
Unfortunately, Funny Facebook video scam is not the only one of its kind. Earlier this year a scam called “Rest in Peace” first appeared online. The name of the scam refers to its content: a video link posted appears to be about a famous person’s death. If one were to click on it, he or she would be redirected to a corrupted page harboring malware. A slightly different scam was also reported in May 2013: Dorkbot malware was being distributed via Facebook chats.
How to prevent yourself from it?

  • DON'T CLICK ON THE MESSAGE
  •  Be cautious of individuals who represent themselves as officials soliciting personal information via e-mail
  • Be cautious of emails that contain pictures in attached files,  as many of the files may contain a virus. Only open attachments from known senders
  • Be cautious of emails that contain pictures in attached files, as many of the files may contain a virus. Only open attachments from known senders.
  •   Do not provide personal information to anyone who solicits information. Also beware on the social network sites that include messages and comments such as Paris Hilton Tosses Dwarf On The Street; Examiners Caught Downloading Grades From The Internet; Hello; You must see it!!! LOL. My friend catched you on hidden cam; Is it really celebrity? Funny Moments and many others. 
  •   When you're on a social networking site, pay close attention to executables downloaded to Windows machines, keep your machine fully patched and run updated anti-malware software.

     How to remove if you are already infected
    1.Clear ‎Cookies‬ and ‎Cache‬(you can use cc cleaner for it )

    2.Open task manager and if you see any egs fbv6 (dont know the name exactly ) kill it if you seen any with that name  (not sure)
    if you done the above things after that download "malwarebytes" software and install.
    3.After that click "Account" on the top right, then "Privacy Settings." Then, click "Edit your settings" under "Apps and Websites" at the bottom left. Click "Remove Unwanted or Spammy Apps," then click the blue X next to the apps you want to get rid of.
    4.If it is koobface worm check out this link Remove Koobface Worm (Remove Koobface, Koobface Remover) http://www.softpedia.com/hubs/Remove-Koobface-Worm  .
    5.See is there any plugins have been installed in your browser without your knowledge then uninstall it.(regards Sri bro)
    I hope it works for you............


 

 

 

 

Monday, July 14, 2014

Nokia Asha Series Lock Screen Cracked

There have been a lot of lock screen bypasses lately in almost every mobile deice such as iPhone, Samsung galaxy, HTC etc and if you observe carefully most of them rely upon abusing the "Emergency Calling" option some how. Hammad Shamsi a Security researcher from RHAinfoSec has found a lockscreen bypass which resides in all the latest versions of Nokia Asha series. The bypass occurred due to mishandling of SOS button (Emergency Panic Button) which is present in all Nokia Asha Series and is used to perform the emergency calls.

                                

How to Reproduce? Here are the steps to reproduce, in case you are curious:
 i) First, set up the lock code to lock the screen.

 ii) Next, type any number on the unlock screen. 

iii) Next, press the SOS button followed the green button and you are sent to recent call lists. This could be furthur abused into gaining complete phonebook access, add/delete a number, turning bluetooth on/off etc. Hammad, has created a series of three video which demonstrates how you could go about accomplishing it.

Nokia Asha Lock Screen Bypass - Video #1



Nokia Asha Lock Screen Bypass - Video #2



Nokia Asha Lock Screen Bypass - Video #3




 

Wednesday, April 2, 2014

An Interview with a Hacker - Spider64

Hi guys ... Life of a hacker is itself a salted hash :-P , Which can't be easily cracked.So I decided to post an interview of a  hacker, because there are lot of wrong myths about hackers. These wrong perceptions are created by some james bond type movies :P
Rajib Acharyya mostly known as Spider64 is a  Black hat-turned-White hat famous Indian hacker in Black world of Hacking.There were thousands of hacks done by him but his major targets were  Pakistani government sites. Once he hacked all the Pakistani government sites in one day including pakistan.gov . Long list, containing some of the top most university . Now a days he is busy in development projects.
 

     




Satya - Welcome Spider! Can you tell us a little bit about your background? 

Spider64 - Hello , this is Spider64(Rajib Acharyya) from Kolkata, i am currently a student of BCA from  IGNOU . My background is very much different from others but quite natural in terms of my thirst for knowledge and you might say, with many  unusual surprises things in terms of boring reality..   ;-)

 

Satya - When did you find your interest in Computer? and when this interest change in to Hacking?
 

Spider64-When my father first bought me a Desktop with P4 after passing my class 10 . People usually find the CPU as a Big Basket in my age, but my innocence had driven me to find Miracles in that Square chip within that Big, Heavy Weight, Black Box. That's how I must describe in short.  :-)
well, Actually this question is a bit controversial, because, Interest never changes, what is Change, it becomes the Interest. So Hacking is the "Change" in the way of my discovering 'How' and 'Why'. That's all.


 

Satya- Can you describe the first time you remember deliberately breaking a computer-related law? Why did you do it and how did you justify it?

Spider64- I don't remember anything like that.Well I do hacks because I remember everything.. From the Kashmir War to 26/11.And I love my country. That's enough justification.

 

Satya - In which category of hackers you belong? 

Spider64- You know it very well  :p .Actually I love black color, but its too dark so I made it a bit light these days.


Satya - Which one is your biggest hacking target?

Spider64- It's a "Mission" and strictly censored under (A) i.e. Adults only. So in terms of that devotion, I did a joint operation with people like me with a team name as, BROTHER OF 64 and Leaked or you might describe as ‘made privacy public’ of a leading Pakistani Hacker Group and its Leader named Chromos IP, for Kashmir issue.
    Else, due the love for my country (India), I thought Pakistan Govt. should get some surprise. So I send some gift for them and for which all of the main stream Govt. websites were down for one day, including, www.pakistan.gov.pk. And also defaced the website of, High Commission of India, in Pakistan, and do you remember It was looking fabulous than the original.  :-P  



Satya- What is your favorite kind of website to compromise? Or are your hack attempts entirely randomly?
 

Spider64- I find all website interesting that doesn't belong to India. No they are not randomly .

 

Satya- Did you ever hack any bank account?

Spider64- Well I think I don't remind anything like that.. But... I love when a Joker falls in between Spades. Let me ask you something... Can you verify a person by asking if he/she works for RAW or ISI?

 

Satya- How do you think the rest of the world views hackers?

Spider64-See Hacking is technology, it is philosophy, it is uncovering the truth, it is an way of revolution.So a deepest feeling of many thousand people is engaged with HACKING. Rest of the World, though understand What Real Hackers want, but they are afraid of their Governments.
But actually a maximum percentage after enormous study and degree and even research finds a Hacker as Criminal. They are everywhere from common people to ruling Govt. It’s because they are bound in Knowledge, but "Knowledge is Free", even the great TAGORE said that. And I think the day is not too far,
when People along with Govt. will understand the Philosophy of Hacks. Because if they don't understand our mind, do you think it is possible to trace back?  :-P


 

Satya- Now what is your future plans? and what advise you want to give to young folks interested in Hacking?

Spider64-Actually, future plan always starts from the present. And to be more specific, I want to be a part of revolution, to bring down Corruption, outdated and garbage educational system in our country. Because it’s the young generation, who will take our country ahead.
   Hacking is not a game, if you are interested in this field than you have to work hard sometimes more than other fields because here law changes everyday. Remember it is not a timepass. The hard work and dedication will become a kind of intense play rather than drudgery. That attitude is vital to becoming a hacker.
   Never say anyone that you even heard of it untill you make sure what is your position now.Never study for marks and try to escape (only) Boring Lectures  :-P. Because Boring Lectures makes your mind Dull. Else, use an AntiVirus as many people do, though I haven't used it so far.  And if you find your days boring use precaution first, i think you understand what i mean to be say :v.   

 Finally, the quieter you become, the more you'll be able to hear.

 Thanks Spider64 for providing your precious time from your busy schedule.


Comment your views.....