Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Thursday, October 13, 2011

National Academy For Medical Education : NAME DEFACED !

Hacker Group Called "Revolutionar" Hacked National Academy For Medical Education site Today.

The Group Post the Message "Don't Turn Education into Business" on the Header banner of the NAME site.

Visit NAME for more Details.

Screenshot of the HACKED
Defaced Page of  Name.edu.np


Monday, September 19, 2011

Bank of Melbourne Twitter account hacked


The Twitter account of Bank of Melbourne was compromised last Wednesday, and was used to spread phishing links as direct messages to the account followers, according to reports coming in from affected users.

Followers of the bank's Twitter page were sent direct messages encouraging them to click on a link designed to fraudulently acquire their Twitter user name and password.

BusinessDay understands that the messages were sent to only a small proportion of its nearly 800 Twitter followers, but the exact number was unknown.

At around 6.30pm yesterday Bank of Melbourne tweeted “ATTN: Unauthorised DMs sent bw 4-5pm today, do not click link. No customer/personal data compromised. Apologies for the inconvenience. ^TT”, in response to several complaints from its followers.

After apologising to customers, the bank assured them: 'Thanks for all your support. We take security very seriously & will be strengthening our policies to further protect our social channels 

The Westpac-owned Melbourne bank said no customer accounts were compromised.

Thursday, July 28, 2011

International Journalists GMail Account Hacked in China, China Against Human Right !


The independent Chinese magazine Caixin has said that unidentified hackers broke into the private Gmail account of one of its investigative reporters following the publication of articles that accused local government officials of taking part in child-trafficking.


The Foreign Correspondents' Club of China sent an e-mail Monday to its members warning that reporters in at least two news bureaus in Beijing said their Gmail accounts had been broken into, with their e-mails surreptitiously forwarded to unfamiliar accounts.

The Caixin reporter, Zhao Hejuan, recently contributed to a series of investigative reports on child-trafficking, and the apparent complicity of officials in Hunan Province’s Longhui County. Last week, she began to suspect that someone was accessing her e-mail.
As the magazine explained in a statement on Friday:

Zhao learned of the attacks July 21 after receiving a Gmail security alert. Caixin’s I.T. department later uncovered evidence that the hacks into Zhao’s account went as far back as July 19. Based on Gmail’s I.P. history, the hackers had logged on to Zhao’s Gmail account every day since July 19. Zhao and Caixin’s legal affairs consultant reported the incident to district police in Beijing on July 22.

The news comes just one week after Google said it had been targeted by recent cyberattacks aimed at accessing the Gmail accounts of Chinese human rights activists. The U.S. search giant cited the attacks as one reason it has decided to stop censoring its Chinese search engine and may ultimately close its China offices, a threat China has dismissed.

Google spokesperson Kay Oberbeck said :


“These highly sophisticated attacks and the surveillance they have uncovered — as well as attempts over the past year to limit free speech on the web even further - have led us to conclude that we are no longer comfortable censoring results in China and that we must take a new approach in China,”



Google Also Said that:

 "hackers were only able to view account information and subject headers of emails, and that only two email accounts were compromised, the company has nevertheless increased security for all Gmail users."  


However, A final report on the investigation has yet to be released, and the magazine appears to be standing by its reporting, although it has not published any reply to Mr. Zeng’s statement.

The first reported incident of e-mail hacking against Caixin occurred several days after Mr. Zeng’s comments.

Wednesday, July 27, 2011

Stop Using Paypal : Anonymous and LulzSec says, Ebay Stock Price Drops !


Anonymous and LulzSec have declared war on eBay’s PayPal with a boycott of the payment service and the fallout could have some real financial implications.

Anonymous, together with LulzSec, issued a press release  urging PayPal users to close their accounts immediately and consider an alternative. They pointed to PayPal's willingness to "fold to legislation" as proof that it doesn't deserve its customers and the business they give to the payments providers.

Not surprisingly, Anonymous and LulzSec are urging a legal boycott of PayPal. The groups said:
In recent weeks, we’ve found ourselves outraged at the FBI’s willingness to arrest and threaten those who are involved in ethical, modern cyber operations. Law enforcement continues to push its ridiculous rules upon us - Anonymous “suspects” may face a fine of up to 500,000 USD with the addition of 15 years’ jail time, all for taking part in a historical activist movement. Many of the already-apprehended Anons are being charged with taking part in DDoS attacks against corrupt and greedy organizations, such as PayPal.


According to a Tuesday report by U.S.-based alternative news site, The Raw Story, 20-year-old University of Nevada journalism student Mercedes Haefer faces a jail term of up to 15 years and $500,000 in fines if convicted of hacking charges.

Cnet Reports,Shortly after the new post hit the Web today, Anonymous claimed through its Twitter account that PayPal had lost more than 9,000 accounts in just a couple of hours. The group also claimed that PayPal had taken down its Web page where people can cancel their accounts, though the site seemed to be up and running normally.



ZDNet reports, the Federal Bureau of Investigation (FBI) arrested her last week for allegedly participating in distributed denial-of-service (DDoS) attacks against PayPal last year as part of the "Operation Payback" campaign.

Operation Payback was an organized launch of DDoS attacks against entertainment websites like the Recording Industry Association of America and Motion Picture Association of America. The attack was sparked by members of the image board website 4chan.

Wikileaks is showing support by tweeting: "We support the work of #Anonymous in drawing attention to the economic blockade of #Wikileaks by corrupt financial institutions. #OpPayPal"

EBAY STOCK PRICE DROP!!

EBay's share price dropped over 2.5 percent at the beginning of Nasdaq trading on Wednesday.

WikiLeaks was quick to crow drop of price on Ebay's stock. Anonymous' campaign dealt a "$933M stock crash" this morning for PayPal parent eBay. Shares in eBay did drop over 2.5 percent at the market open, but have since recovered somewhat.
Evercore financial analyst Ken Sena told ZDNet UK  that the Anonymous action was unlikely to have had much of an effect on investors. Sena instead attributed the fall to strong results posted by Amazon on Tuesday.

"eBay shares are suffering from Amazon posting really strong results," said Sena. "I don't see this [Anonymous action] as a big driver."

Already, people are responding to Anonymous' call. One user, Pantha85, tweeted:
"Account Closed. Mmake you bleed from the only place you care.. your wallet. thanks @YourAnonNews #oppaypal #anonymous".

Another follower, Pacific_Justice, pointed out: 


"Next reason to join #OpPaypal and cancel your account: they created an illegal financial blockade of #WikiLeaks - a publishing organization".


There is no information on how long the boycott would last, although a tweet at 3.32 p.m. on Wednesday revealed an estimated "few hundred" PayPal accounts have been closed so far.
This is not the first time hacking groups like Anonymous have targeted financial institutions. Visa and MasterCard were also attacked for their role in blocking donations to Wikileaks.

Scotland Yard: LulzSec spokesman arrested


(AP)  
Scotland Yard says officers from its specialist cybercrime unit have arrested the suspected spokesman of the Lulz Security hacking group.

Metropolitan Police Central eCrime Unit (PCeU) statement said that:

"The man arrested is believed to be linked to an ongoing international investigation in to the criminal activity of the so-called 'hacktivist' groups Anonymous and LulzSec, and uses the online nickname 'Topiary',"

In a statement Wednesday the police force says that the 19-year-old was arrested at an address in Scotland's Shetland Islands on Wednesday. They say he is the name behind the hacker known as "Topiary," who has given several interviews in recent weeks.



LulzSec, an offshoot of the amorphous hacking collective known as Anonymous, has claimed responsibility for a series of hacking attacks on both sides of the Atlantic.



More details soon ...

Sunday, July 24, 2011

Hacker Caught With 675k Stolen Credit Cards Gets Maximum Prison


Rogelio Hackett of Lithonia, Georgia who had been found with more than 675000 stolen credit card numbers that reportedly led to loses totaling more than $36 million, was sentenced on Friday to 120 months in prison.
 more on

Friday, July 22, 2011

"Anonymous" hacker: We can close your website

In a videotaped interview with CBS News on Tuesday, Commander X, who asked that his identity be hidden, said, "The power of Anonymous is that we have the ability to effect change on the Internet. You have a site online -- all of a sudden, we snap our fingers and that site is gone."

The statement came after Anonymous have D-DOS NATO website and breached NATO security and accessed a trove of restricted material Thursday Afternoon.




On Twitter, Anonymous said that it would be "irresponsible" to post most of the data. However, Commander X told CBS News that Anonymous plans to release every NATO document it has in its possession.
"Anonymous ALWAYS releases EVERYTHING we take...eventually. But with these big classified dumps we like to take our time analyzing exactly what it is we have. That way we can do the disclosures in such a way as to maximize the political impact of the release."

Anonymous posted a PDF file on its Twitter page showing what appeared to be a document headed "NATO Restricted" and dated Aug. 27, 2007.
"Hi NATO," the group teased on Twitter. "Yes, we haz more of your delicious data," hinting that more would be released in the next few days.

A NATO spokesman said "NATO is aware that a hackers' group has released what it claims to be NATO classified documents on the Internet," NATO spokesman Damien Arnaud told Postmedia News in an e-mail. "NATO security experts are investigating these claims. We strongly condemn any leak of classified documents, which can potentially endanger the security of NATO allies, armed forces and citizens."

On Tuesday, the FBI conducted multiple raids and arrested 14 suspects in connection with December attacks claimed by Anonymous on PayPal, the Internet payment service that had stopped processing donations for Wikileaks.

Read More 




Thursday, July 21, 2011

Anonymous: We Owned NATO ! [Image added]




NATO (Atlantic North Treaty Organization), e-Bookshop, had suffered a data breach. A hacker group called Team Inj3ct0r claimed responsible for targeting a NATO server with a private zero day exploit.

"Yes, #NATO was breached. And we have lots of restricted material. With some simple injection. In the next days, wait for interesting data," the group tweeted via the @Anonymous IRC feed.

According to the report by The Hacker News, their reasons for hacking is the development and financing of nuclear weapons. The documents contain budget information for a new Joint Communications Control Center (JCCC) within the International Security Assistance Force (ISAF), a NATO-led mission in Afghanistan. Various other Anonymous-affiliated accounts claimed to have lifted a gigabyte worth of data from NATO servers, so presumably more document releases are on the way.


By way of evidence of the hack , AnonymousIRC has released two PDF documents,also posted links to two documents.

1.The first, dated 2007 and marked “Nato Restricted”, purports to be a working paper on communication systems at the Joint Communications Control Centre for ISAF forces in Afganistan. It includes detailed procurement estimates and technical information.

2.The second document, dated 2008 and also marked “Nato Restricted”, covers proposals for outsourcing communications systems for Nato forces in Kosovo.

Below are the image of the files leaked by AnonymousIRC/




Source of the IMage

Anonymous also warned NATO not to "make the mistake of challenging Anonymous.


According to theregister.co.uk 
"NATO members were warned last month of increasing threats from hackivist group Anonymous. Looks like their advice was right."

The hackers have attacked websites including those of the CIA and SOCA, and infiltrated networks belonging to Sony, security companies and the broadcaster Fox. Earlier this week LulzSec hacked into The Sun newspaper website and published a fake news story claiming Rupert Murdoch had died of metal poisoning.

Sunday, March 22, 2009

Hack mobile even its locked with security code

The most common European emergency number 112 and also standard on GSM mobile phones. 112 is used in Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Republic of Macedonia, Malta, Netherlands, Norway, Poland, Portugal, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Ukraine and the United Kingdom in addition to their other emergency numbers.We can use emergency number (112) to hack mobile even its locked: Send messages, see contacts ...






Step 1: Press 112

Step 2: Press Call button






(Green button on keypad)





Step 3: When that mobile calling, press down button







Contacts will enable.
Step 4: Do anything if you want !If you know that code, you can Exit with these steps:

Step 1: Options

Step 2: Press security code

Step 3: OK (Not need to clear 112)

source:Warez Community

Wednesday, November 26, 2008

Firefox integrated NTLM authentication

Firefox, Mozilla, and friends CAN now do integrated NTLM Authentication. You need to set the following 4 preferences:

network.automatic-ntlm-auth.allow-proxies true

network.automatic-ntlm-auth.trusted-uris proxy1 (where proxy1 = the name of your proxy), proxy2, domain FQDN, etc

network.negotiate-auth.trusted-uris proxy1, proxy2, domain FQDN, etc

network.negotiate-auth.delegation-uris proxy1, proxy2, domain FQDN, etc

Here is how:
1. Type about:config in URL bar
2. In search bar type any part of the item you are looking for (ntlm or Negotiate)
3. Click on the item you want to change. (Or double click if it is a boolean, to change it)
4. Change the value in the pop up.
5. Click OK
6. Presto!

Wednesday, November 5, 2008

A browser as web hacking platform

A list of Firefox plugins to turn your browser in an hacking platform. This is an improved list based on "Turning Firefox to an ethical hacking platform" from Security-Database.com

Information gathering

  • Whois and geo-location
    • ShowIP
      : Show the IP address of the current page in the status bar. It also
      allows querying custom services by IP (right mouse button) and Hostname
      (left mouse button), like whois, netcraft.
    • Shazou
      : The product called Shazou (pronounced Shazoo it is Japanese for
      mapping) enables the user with one-click to map and geo-locate any
      website they are currently viewing.
    • HostIP.info Geolocation : Displays Geolocation information for a website using hostip.info data. Works with all versions of Firefox.
    • Active Whois : Starting Active Whois to get details about any Web site owner and its host server.
    • Bibirmer Toolbar
      : An all-in-one extension. But auditors need to play with the toolbox.
      It includes ( WhoIs, DNS Report, Geolocation , Traceroute , Ping ).
      Very useful for information gathering phase
  • Enumeration / fingerprinting
    • Header Spy: Shows HTTP headers on statusbar
    • Header Monitor
      : This is Firefox extension for display on statusbar panel any HTTP
      response header of top level document returned by a web server.
      Example: Server (by default), Content-Encoding, Content-Type,
      X-Powered-By and others.
  • Social engineering
    • People Search and Public Record:
      This Firefox extension is a handy menu tool for investigators,
      reporters, legal professionals, real estate agents, online researchers
      and anyone interested in doing their own basic people searches and
      public record lookups as well as background research.
  • Googling and spidering
    • Advanced dork
      : Gives quick access to Google’s Advanced Operators directly from the
      context menu. This could be used to scan for hidden files or narrow
      in a target anonymously (via the scroogle.org option)
    • SpiderZilla : Spiderzilla is an easy-to-use website mirror utility, based on Httrack from www.httrack.com.
    • View Dependencies
      : View Dependencies adds a tab to the "page info" window, in which it
      lists all the files which were loaded to show the current page. (useful
      for a spidering technique)

Security Assessment / Code auditing

  • Editors
    • JSView
      : The ’view page source’ menu item now opens files based on the
      behavior you choose in the jsview options. This allows you to open the
      source code of any web page in a new tab or in an external editor.
    • Cert Viewer Plus
      : Adds two options to the certificate viewer in Firefox or Thunderbird:
      an X.509 certificate can either be displayed in PEM format (Base64/RFC
      1421, opens in a new window) or saved to a file (in PEM or DER format -
      and PKCS#7 provided that the respective patch has been applied - cf.
    • Firebug
      : Firebug integrates with Firefox to put a wealth of development tools
      at your fingertips while you browse. You can edit, debug, and monitor
      CSS, HTML, and JavaScript live in any web page
    • XML Developer Toolbar:allows XML Developer’s use of standard tools all from your browser.
    • Web developer : Adds a menu and a toolbar with various web developer tools.
  • Headers manipulation
    • HeaderMonitor
      : This is Firefox extension for display on statusbar panel any HTTP
      response header of top level document returned by a web server.
      Example: Server (by default), Content-Encoding, Content-Type,
      X-Powered-By and others.
    • RefControl : Control what gets sent as the HTTP Referer on a per-site basis.
    • User Agent Switcher :Adds a menu and a toolbar button to switch the user agent of the browser
  • Cookies manipulation
    • Add N Edit Cookies : Cookie Editor that allows you add and edit "session" and saved cookies.
    • CookieSwap
      : CookieSwap is an extension that enables you to maintain numerous sets
      or "profiles" of cookies that you can quickly swap between while
      browsing
    • httpOnly : Adds httpOnly cookie support to Firefox by encrypting cookies marked as httpOnly on the browser side
    • Allcookies : Dumps ALL cookies (including session cookies) to Firefox standard cookies.txt file
  • Security auditing
    • HackBar
      : This toolbar will help you in testing sql injections, XSS holes and
      site security. It is NOT a tool for executing standard exploits and it
      will NOT learn you how to hack a site. Its main purpose is to help a
      developer do security audits on his code.
    • Tamper Data : Use tamperdata to view and modify HTTP/HTTPS headers and post
      parameters.
    • Chickenfoot
      : Chickenfoot is a Firefox extension that puts a programming
      environment in the browser’s sidebar so you can write scripts to
      manipulate web pages and automate web browsing. In Chickenfoot, scripts
      are written in a superset of Javascript that includes special functions
      specific to web tasks.

Proxy/web utilities

  • FoxyProxy
    : FoxyProxy is an advanced proxy management tool that completely
    replaces Firefox’s proxy configuration. It offers more features than
    SwitchProxy, ProxyButton, QuickProxy, xyzproxy, ProxyTex, etc
  • SwitchProxy:
    SwitchProxy lets you manage and switch between multiple proxy
    configurations quickly and easily. You can also use it as an anonymizer
    to protect your computer from prying eyes
  • POW (Plain Old WebServer)
    : The Plain Old Webserver uses Server-side Javascript (SJS) to run a
    server inside your browser. Use it to distribute files from your
    browser. It supports Server-side JS, GET, POST, uploads, Cookies,
    SQLite and AJAX. It has security features to password-protect your
    site. Users have created a wiki, chat room and search engine using SJS.
  • Torbutton : Torbutton provides a button to securely and easily enable or disable
    the browser’s use of Tor. It is currently the only addon that will
    safely manage your Tor browsing to prevent IP address leakage, cookie
    leakage, and general privacy attacks.

Misc

  • Hacks for fun
    • Greasemonkey : Allows you to customize the way a webpage displays using small bits of JavaScript (scripts could be download here)
  • Encryption
    • Fire Encrypter
      : FireEncrypter is an Firefox extension which gives you
      encryption/decryption and hashing functionalities right from your
      Firefox browser, mostly useful for developers or for education &
      fun.
  • Anti Spoof
    • refspoof
      : Easy to pretend to origin from a site by overriding the url referrer
      (in a http request). — it incorporates this feature by using the
      pseudo-protocol spoof:// .. thus it’s possible to store the information
      in a "hyperlink" - that can be used in any context .. like html pages
      or bookmarks

Thursday, July 10, 2008

Speed up your Torrents

First go to Options>Preferences>Network
1. Under ‘Port used for incomming connections‘ enter any port number. It is best to use a port number above 10000. I use 45682.
2. Randomize port each time µtorrent starts: UNCHECKED
I leave this unchecked because I have a router. If you do not have a router or a firewall, and want extra security,check this option.
3. Enable UPnP port mapping (Windows Xp or later only): UNCHECKED
I leave this unchecked because I have experienced it slowing down speeds. It is not needed if you manually port forward.
4. Add µtorrent to Windows Firewall exceptions (Windows XP SP2 or later only): UNCHECKED (do this only if you have windows firewall disabled)
5. Global Maximum upload rate (kb/s): [0: unlimited]: 22 (for 256k connection)
6. Protocol Encryption: ENABLED
I would recommend everyone to enable this. This can help increase speeds with many ISPs.
7. Allow incoming Legacy Connections: CHECKED

Options>Preferences>Torrents
1. Global Maximum Number of Connections: 130 (for 256k connection)
This number should not be set too low or the number of connections made to your torrents will be limited. Setting it too high may cause too much bandwidth to be used and can cause slowdowns.
2. Maximum Number of connected peers per torrent: 70 (for 256k connection)
If you see that the peers connected to a specific torrent are exactly this number, or very close, increase this number to improve speeds.
3. Number of upload slots per torrent: 3 (for 256k connection)
This depends on how much you want to upload to other users. Do not set too low or it may affect download speeds.
4. Use additional upload slots if upload speed <90%: CHECKED
5. Maximum number of active torrents: 2 (for 256k connection)
6. Maximum number of active downloads: 1 (for 256k connection)