Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Saturday, November 20, 2010

BlackSheep: Way to Avoid FireSheep!

This is an intelligent tool in a sense that you get to know the IP address of the attacker who is running FireSheep. Suitably, BlackSheep is also a Firefox plugin, that is designed to combat FireSheep. It does so by dropping ‘fake’ session IDs on the wire and then monitoring traffic to see if it has been hijacked. BlackSheep identifies FireSheep via a request to a domain that it identifies session information. Using this hijacked session information, FireSheep contacts the targeted host in order to obtain the name of the hijacked user along with an image of the person, if available. When identified, the user will be receive the following warning message:





FireSheep and BlackSheep can not co-exist on the same Firefox profile as they share a lot of common code. If you need to use them on the same machine, use different Firefox profiles.

Download BlackSheep v1.0.0 (blacksheep-latest.xpi) here.

Tuesday, November 9, 2010

Computer Scientist, Student Design Software to Combat Hacking Using Keystroke Anti-Spoofing Technique

One of the serious threats to a user's computer is a software program that might cause unwanted keystroke sequences to occur in order to hack someone's identity. This form of an attack is increasing, infecting enterprise and personal computers, and caused by "organized malicious botnets," said Daphne Yao, assistant professor of computer science at Virginia Tech.

Friday, October 29, 2010

DNS Rebinding Attack Can Be Used to Hack Home Routers


A security researcher has devised a special attack that can be used to access the LAN-facing admin interfaces of many widely used home router models. The technique is a variation of DNS rebinding, but is able to bypass traditional protections against such attacks.

The attack method will be demonstrated at the upcoming Black Hat technical security conference in Las Vegas, by a ethical hacker named Craig Heffner, who currently works as a senior security engineer at Seismic. Heffner's presentation, called “How to Hack Millions of Routers” will be accompanied by the release of a tool which automates the attack.

Read More : Click Here

Researcher Forces Cash Out of Automated Teller Machines


Security researcher Barnaby Jack gave his long overdue presentation on ATM exploits in front of an audience at the Black Hat security conference in Las Vegas. The hacker managed to force two different ATM models to dispense cash using both remote and local attacks.

Automated Teller Machines (ATMs) are pretty much ubiquitous these days and most people are used to trusting them. Unfortunately, the sad reality is that these machines are far from safe and the rate of ATM crime is on a steep climb.

Attacks like ATM skimming have been around for a long time and several variants of ATM malware have also appeared in the past two years. However, Barnaby Jack's research, which involve remotely exploitable vulnerabilities, takes ATM security risks to a whole new level.

Researcher Releases Phone Call Eavesdropping Software

A security researcher has released open source software that can be used to record and decrypt communications passing over 2G GSM networks. Unlike other available solutions, that require very expensive set-ups, this free set of tools can work on off-the-shelf equipment.

The software was demoed at the Black Hat security conference in Las Vegas by Karsten Nohl, a security researcher who specializes in probing GSM security. His previous research focused on the A5/1 stream cipher used to encrypt GSM communications.

This cipher dates back to 1987 and is still widely used in Europe and the United States, despite being reverse-engineered in 1999. GSM operators have began adopting the more secure A5/3 cipher, which is used to encrypt traffic passing over 3G networks. However, when 3G coverage is not available, phones drop back to the insecure 2G standard.

Read More : Click Here

Monday, October 25, 2010

New Firefox add-on hijacks Facebook, Twitter sessions


A new Firefox add-on lets "pretty much anyone" scan a Wi-Fi network and hijack others' access to Facebook, Twitter and a host of other services, a security researcher warned today.

The add-on, dubbed "Firesheep," was released Sunday by Eric Butler, a Seattle-based freelance Web application developer, at the ToorCon security conference, which took place Oct. 22-24 in San Diego.

Butler said he created Firesheep to show the danger of accessing unencrypted Web sites from public Wi-Fi spots.

Read More : Click Here

Wednesday, October 20, 2010

'Unprecedented wave' of Java exploits hits users, says Microsoft

Microsoft said Monday that an "unprecedented wave" of attacks are exploiting vulnerabilities in Oracle's Java software.

According to a manager at Microsoft's Malware Protection Center (MMPC), attempts to exploit Java bugs have skyrocketed in the past nine months, climbing from less than half a million in the first quarter of 2010 to more than 6 million in the third quarter.

"Some of our exploit 'malware' families were telling a scary story ... an unprecedented wave of Java exploitation," said Holly Stewart, a senior program manager at the MMPC, in a post to the team's blog Monday.

Stewart went on to call the jump in Java attacks "scary" and added, "The spike in exploitation was surprising to say the least."

read more : http://www.computerworld.com

Hacker hits Kaspersky website

Scammers who try to trick victims into downloading fake antivirus software can strike almost anywhere. On Sunday they hit the website of Kaspersky Lab, a well-known antivirus vendor.

Someone took advantage of a bug in a Web program used by the Kasperskyusa.com website and reprogrammed it to try and trick visitors into downloading a fake product, Kaspersky confirmed Tuesday. Kaspersky didn't identify the flaw, but said it was in a "third-party application" used by the website.

"As a result of the attack, users trying to download Kaspersky Lab's consumer products were redirected to a malicious website," the antivirus vendor said. The website caused a pop-up window to appear that simulated a virus scan of the user's PC, and offered to install an antivirus program that was in fact bogus.

Georgia Tech Information Security Center Releases Cyber Threats Forecast for 2011

The Georgia Tech Information Security Center (GTISC), a national leader in information security research and education, has announced the release of the GTISC Emerging Cyber Threats Report for 2011, outlining the top three areas of security risk and concern for consumer and business Internet and computer users.

New Malware Could Steal Users Social Media Behavior and Info, Researchers Warn

A new study by Ben-Gurion University of the Negev (BGU) researchers predicts that a new generation of malware (software written for malicious purposes like identity theft) could steal data on human behavior patterns, which is more dangerous than traditional, detectable attacks.

SpamBot Wants to Be Your Friend

Social network sites such as Facebook, mySpace or Twitter are gaining popularity. But the 'Web 2.0' presents new dangers. At the Vienna University of Technology (VUT), security hazards of social network sites have been detected and studied. Researchers of the VUT now provide advice on how to increase your safety on the Web.

The last six months saw an increase in password stealing, as malware levels dropped

Predictions of an increase in attacks on social networks by password-stealing Trojans this year have been confirmed.

In McAfee’s 2010 Threat Predictions, it anticipated that attacks on social networks by password-stealing Trojans and other malware would increase in 2010, and during the current quarter it has seen several examples of that prediction in action. The most prominent of this is the Zeus family, which it usually observes as PWS-Zbot and Spy-Agent.bw, and is the pre-eminent password-stealing Trojan malware, according to its threat report for the first quarter of 2010.

The report said: “Zeus is just one of the key tools of cyber criminals, who often tie password stealers with other types of illegal online material. In this quarter we saw all kind of goodies being installed with Zeus. And whom do you imagine was the prime target for these attacks? Facebook users.”

Thursday, October 14, 2010

Beware of fake 'dislike' button on Facebook


Washington, Aug 17: A fake 'dislike' button, which is not offered by Facebook, is spreading like a virus across the social networking site Facebook.

If the user clicks the fake 'dislike' button followed by a link, instead of installing a dislike button, the application uses the person's network to continue spreading the fake programme.

Facebook officials told that they are trying hard to block the fake 'dislike' button. They also told that Facebook don't have any official dislike button and asked the users not to click on the suspicious links.

US focuses on technology to face cyber threats


Washington, Aug 26: United States defence official told that Pentagon trains it's network administrators 'ethical hacking' to understand the weaknesses before they are exploited by an enemy.

US Deputy Secretary of Defence William J Lynn told that the America must face the cyber defence challenge with a focus on superior technology and productivity. He also told that the US has to focus on technology and productivity as the countries like China and India will train more highly proficient computer scientists in coming years.

Wednesday, October 13, 2010

Google inserts 'extra protection' against hacking


San Francisco, Sep 21: The threats of online hacking and cyber crimes are increasing day by day. Internet users face hacking to their bank accounts, emails , social networking accounts and even to the personal websites. The security on web is the hottest issue faced by all big players in the web market. To face hacking threats, Google Inc has introduced a new security measure for Google account holders.