Mostrar mensagens com a etiqueta security. Mostrar todas as mensagens
Mostrar mensagens com a etiqueta security. Mostrar todas as mensagens

domingo, 27 de novembro de 2011

‘Black Friday’ iTunes credit scam


In The Telegraph

An email claiming to be from Apple’s iTunes store contains a compressed ZIP file, which security experts say could allow hackers to gain access to computers.

The German Eleven security blog suggests that the attack is timed to coincide with the start of the American holiday shopping season, called Black Friday.

The email offers credit for iTunes music, games and video, and is just one of a huge number of scams that try to lure people in with offers that seem plausible in the context of other Black Friday discounts.

The email apparently offers recipients $50 (£32) and claims they need to open an attached file to access their certificate code. In fact the attachment is a file called Mal/BredoZp-B. It opens a security loophole on Windows PCs and allows hackers to remotely capture passwords and other information. It also slows down the computer and hides some files.

Although such malware can be removed with the use of widely available anti-malware tools, damage can be done in the meantime.

segunda-feira, 24 de outubro de 2011

Microsoft Youtube Channel Hacked


In Cnet

The background on the channel has been changed to one that includes the title "Predator Cinema," and a message has been posted that says: "I DID NOTHING WRONG I SIMPLY SIGNED INTO MY ACCOUNT THAT I MADE IN 2006 :/"

The channel's archived videos have been removed and replaced with short clips titled "We are sponsoring!" and "Make us a background to get a Subbox!!!"

Microsoft confirmed the hacking of the channel this afternoon.

"We have regained control of the Microsoft channel on YouTube, and we are working to restore all of the original content," a Microsoft representative told CNET. " We will continue to work with YouTube to ensure safeguards are in place for the future."

This is the second high-profile YouTube channel to be hacked in the past week. Sesame Street's YouTube channel was hacked last weekend, leaving its normally family-friendly content replaced with pornographic content.

segunda-feira, 26 de setembro de 2011

Bulletproof vest gets GPS


In Cnet


If you already bought a bulletproof Mercedes and a bulletproof watch, then you might want to complete the look with a bulletproof vest.

The S-911 Vest from Laipac Technology is chest armor with brains. Just as phones have evolved to handle a gazillion different functions, this bulletproof vest has sprouted a GPS system.

Law enforcement, military, security personnel, and VIPs are the target market for the high-tech vest. Built-in GPS provides real-time tracking with location, heading, and speed.

The vest's most important function is to stop bullets, of course. Kevlar and optional armor plates handle that task. The basic Kevlar model has enough stopping power to protect against most handguns, including a shot from a .44 Magnum.

The vest works over a GSM/GPRS network and will record waypoints when out of GSM range. Set up a virtual geo-fence and get alerts when the vest moves in or out of a certain area.

You could do all that with a regular GPS tracking system, but the S-911 also has a built-in G sensor that sends alerts when it registers an impact or a man down. All this extra equipment means the vest comes with its own battery charger. You might want to pick up acar charger adapter for your bulletproof Mercedes.


Read more: http://news.cnet.com/8301-17938_105-20108423-1/bulletproof-vest-gets-gps-man-down-alerts/#ixzz1Z4lNK2ew

terça-feira, 20 de setembro de 2011

Missile maker sees network hacked


In Cnet

Mitsubishi Heavy Industries factories that build guided missiles and rocket engines; submarines; and nuclear-power equipment have had their computer networks hacked, according to a report.

The Reuters news agency said Japanese newspaper Yomiuri reported that information from Mitsubishi's computer system was stolen in the attack. A representative of the company confirmed the attack, Reuters reported, but said the company was still looking into whether any data had been taken.

The Yomiuri report said about 80 infected computers were found at Mitsubishi headquarters in Tokyo and various facilities in other areas of Japan, according to Reuters.

segunda-feira, 19 de setembro de 2011

Google’s Malware Infection Warnings

In techbusy

Google has started a service to warn its users about malware infection on their system. But this warning will be only for that system which is already infected by a malwares. I am adding this line because many malware writers have been using google’s malware infection warnings as a beneficial to share more viruses over the net.

If you have warning on google’s homepage with yellow background (as shown below) then only you can trust “Learn how to fix this” link otherwise dont ever think of clicking on it as it may be from any malware writers.

Air traffic system vulnerable to cyber attack


In NewScientist

A next-generation global air traffic control system is vulnerable to malicious hacks that could cause catastrophe

AN ALARM blares in the cockpit mid flight, warning the pilot of an imminent collision. The pilot checks his tracking display, sees an incoming aircraft and sends the plane into a dive. That only takes it into another crowded air lane, however, where it collides with a different plane. Investigators later discover that the pilot was running from a "ghost" - a phantom aircraft created by a hacker intent on wreaking havoc in the skies.

It's a fictional scenario, but US air force analysts warn that it could be played out if hackers exploit security holes in an increasingly common air traffic control technology.

At issue is a technology called Automatic Dependent Surveillance - Broadcast (ADS-B), which the International Civil Aviation Organisation certified for use in 2002. Gradually being deployed worldwide, ADS-B improves upon the radar-based systems that air traffic controllers and pilots rely on to find out the location and velocity of aircraft in their vicinity.

Conventional ground-based radar systems are expensive to run, become less accurate at determining position the further away a plane is, and are slow to calculate an aircraft's speed. Perhaps worst of all, their limited range means they cannot track planes over the ocean.

So instead of bouncing radar signals off aircraft, ADS-B uses GPS signals to continuously broadcast a plane's identity, ground position, altitude and velocity to networks of ground stations and other nearby aircraft. This way, everyone knows where everyone else is.

ADS-B transmits information in unencrypted 112-bit bursts - a measure intended to make the system simple and cheap to implement. It's this that researchers from the US air force's Institute of Technology at Wright-Patterson Air Force Base in Ohio are unhappy with. Donald McCallie, Jonathan Butts and Robert Mills warn that the unencrypted signals could be intercepted and spoofed by hackers, or simply jammed.

The team says the vulnerabilities it has identified "could have disastrous consequences including confusion, aircraft groundings, even plane crashes if exploited by adversaries" (International Journal of Critical Infrastructure Protection, DOI: 10.1016/j.ijcip.2011.06.001).

One attack they label "low difficulty" is a "ground station flood denial": jamming an ADS-B ground receiver mast (like a cellphone mast) by placing a low-power radio transmitter near it. That effectively blinds controllers to where planes are.

Tougher to carry out is a "ghost aircraft injection". This attack mimics the format of ADS-B data packets to create fake aircraft signals, either on the ground controller's screen or on the pilot's tracking display.

"We're aware of the research undertaken by the US air force and have been working for some time with UK and European authorities and agencies to understand and mitigate the issues," says Brendan Kelly, policy chief at National Air Traffic Services in the UK.

But the Federal Aviation Administration, which wants ADS-B fully operational across the US by 2020, says tests it completed in 2009 show ADS-B has no risks over and above those presented by existing radar systems. "The FAA has a thorough risk management process for all possible risks to ADS-B, including intentional jamming," says a spokesman.

McCallie's team is not convinced, and has asked to see the FAA's test data - which the agency has so far refused to make public, citing security concerns. The team accepts that such concerns are warranted, but insist that additional safeguards must be introduced into ADS-B. Specifically, they say ways to authenticate messages between planes and ground control ought to be explored. "Security as an afterthought will not suffice," they write.

quarta-feira, 24 de agosto de 2011

Beware of New Fake PayPal Email Scam


In Techbusy

If you too get this kind of message from any email then just ignore or trash it and never click on any other link of that mail. Clicking on links on scam mail will result in you account to be hacked. It’s very serious and after hacking your all balanced money can be transferred to hacker’s a/c without any prior notice to you.

This email has ben sentto many paypal users of US/UK to disturb their safety and security. So just permanently delete this kind of scam mails from any mailing service as soon as possible to be clean.

sábado, 13 de agosto de 2011

Hackers can attack android


In Reuters

Riley Hassell, who caused a stir when he called off an appearance at a hacker's conference last week, told Reuters he and colleague Shane Macaulay decided not to lay out their research at the gathering for fear criminals would use it attack Android phones.

He said in an interview he identified more than a dozen widely used Android applications that make the phones vulnerable to attack.

"App developers frequently fail to follow security guidelines and write applications properly," he said.

"Some apps expose themselves to outside contact. If these apps are vulnerable, then an attacker can remotely compromise that app and potentially the phone using something as simple as a text message."

He declined to identify those apps, saying he fears hackers might exploit the vulnerabilities.

"When you release a threat and there's no patch ready, then there is mayhem," said Hassell, founder of boutique security firm Privateer Labs.

Hassell said he and Macaulay alerted Google to the software shortcomings they unearthed.

Google spokesman Jay Nancarrow said Android security experts discussed the research with Hassell and did not believe he had uncovered problems with Android.

"The identified bugs are not present in Android," he said, declining to elaborate.

It was the first public explanation for the failure of Hassell and Macaulay to make a scheduled presentation at the annual Black Hat hacking conference in Las Vegas, the hacking community's largest annual gathering.

They had been scheduled to talk about "Hacking Androids for Profit." Hundreds of people waited for them to show up at a crowded conference room.

Hassell said in an interview late on Thursday the pair also learned -- at the last minute -- that some of their work may have replicated previously published research and they wanted to make sure they properly acknowledged that work.

"This was a choice we made, to prevent an unacceptable window of risk to consumers worldwide and to guarantee credit where it was due," he said.

A mobile security researcher familiar with the work of Hassell and Macaulay said he understood why the pair decided not to disclose their findings.

"When something can be used for exploitation and there is no way to fix it, it is very dangerous to go out publicly with that information," the researcher said. "When there is not a lot that people can do to protect themselves, disclosure is sometimes not the best policy."

Hassell said he plans to give his talk at the Hack in The Box security conference in Kuala Lumpur in October.

(Reporting by Jim Finkle; editing by John Wallace and Andre Grenon)

terça-feira, 9 de agosto de 2011

Facebook Becomes A Favorite Target Of Phishers


The Securelist division of Kaspersky Labs issued a report yesterday, and the identities of the top three organizations that have been targeted by phishers may not come as a surprise to anyone; they're PayPal (with 52.2 percent of all attacks aimed at it), eBay (with 13.3 percent), and HSBC (with 7.8 percent).

The report, which covered the period between January and March of this year, next stated, though, "Facebook popped up unexpectedly in fourth place. This was the first time since we started monitoring that attacks on a social networking site have been so prolific."

By way of explanation, the report then continued, "Having stolen users' accounts, the fraudsters can then use them to distribute spam, sending bulk emails to the account owners and their friends in the network. This method of distributing spam allows huge audiences to be reached. Additionally, it lets the fraudsters take advantage of the social networking sites' additional options, like being able to send different requests, links to photo's and invitations, all with the advertisement attached, both within the network and to users' inboxes."

Obviously, this isn't good news for Facebook's users or the security community as a whole. Facebook acts as a sort of point of entry to information about a whole lot of people (the social network had 400 million users in early February).

This isn't good news for Facebook, either, though - nothing that makes its users uncomfortable or unhappy, and therefore likely to leave, is - so perhaps we'll at least see the company make some attempt(s) to address this problem.

Anyway, if you're curious, the list of phishers' targets picked up after Facebook with Google, the IRS, Rapidshare, Bank of America, UBI, and Bradesco.


About the Author:
Doug is a staff writer for SecurityProNews, InternetFinancialNews, SearchNewz, and WebProNews.