Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts
Monday, February 27, 2012

WikiLeaks publishes Stratfor emails linked to Anonymous attack

0 comments
WikiLeaks on Monday began publishing more than five million confidential emails from US-based intelligence firm Stratfor, the anti-secrecy group said.

The messages, which date from between July 2004 and December 2011, will reveal Stratfor's "web of informers, pay-off structure, payment-laundering techniques and psychological methods," claimed a WikiLeaks press release.

"The material shows how a private intelligence agency works, and how they target individuals for their corporate and government clients," added the press release.

The online organisation claims to have proof of the firm's confidential links to large corporations, such as Bhopal's Dow Chemical Co. and Lockheed Martin and government agencies, including the US Department of Homeland Security, the US Marines and the US Defense Intelligence Agency.

WikiLeaks founder Julian Assange is currently in Britain fighting extradition to Sweden where he is wanted for questioning on rape and sexual assault allegations, and WikiLeaks has long expressed concern that if he is sent to Sweden, Stockholm would quickly send him on to the United States.

Washington is eager to lay hands on the founder after the organisation's publication of hundreds of thousands of classified US diplomatic files.

WikiLeaks promises that the latest leak will highlight Stratfor's attempts to "subvert" the website and expose the US's attempts to "attack" Assange.

Stratfor, which was founded by George Friedman in 1996, describes itself as "a subscription-based provider of geopolitical analysis."

"Unlike traditional news outlets, Stratfor uses a unique, intelligence-based approach to gathering information via rigorous open-source monitoring and a global network of human sources," according to the Texas-based firm's website.

The company promises subscribers will "gain a thorough understanding of international affairs, including what's happening, why it's happening, and what will happen next."

WikiLeaks predicts that the significance of the emails will only become clear over the next few weeks as its 25 media partners and the public sift through the raft of messages.

Its media partners include Rolling Stone magazine, The Hindu newspaper and Italy's La Repubblica.

The group claims to have found evidence that Stratfor gave a complimentary membership to Pakistan general Hamid Gul, former head of Pakistan's ISI intelligence service, who, according to US diplomatic cables, planned an IED attack against international forces in Afghanistan in 2006.

The group also alleges it has proof that Stratfor monitored and analysed the online activities of activists seeking redress for the 1984 Dow Chemical/Union Carbide gas disaster in Bhopal, India.

Bradley Manning, the man suspected of turning over a massive cache of classified US documents to the secret-spilling site, on Thursday declined to enter a plea at his arraignment.

Manning, a 24-year-old US Army private, is charged with 22 counts in connection with one of the biggest intelligence breaches in US history.
Continue reading →
Saturday, February 25, 2012

Bug in Android allows smartphones to be controlled outside : Reports

0 comments
Cybersecurity experts have uncovered a flaw in a component of the operating system of Google Inc's widely used Android smartphone that they say hackers can exploit to gain control of the devices.

Researchers at startup cybersecurity firm CrowdStrike said they have figured out how to use that bug to launch attacks and take control of some Android devices.

CrowdStrike, which will demonstrate its findings next week at a major computer security conference in San Francisco, said an attacker sends an email or text message that appears to be from a trusted source, like the user's phone carrier. The message urges the recipient to click on a link, which if done infects the device.

At that point, the hacker gains complete control of the phone, enabling him or her to eavesdrop on phone calls and monitor the location of the device, said Dmitri Alperovitch, chief technology officer and co-founder of CrowdStrike.

Google spokesman Jay Nancarrow declined comment on Crowdstrike's claim.

Alperovitch said the firm conducted the research to highlight how mobile devices are increasingly vulnerable to a type of attack widely carried out against PCs. In such instances, hackers find previously unknown vulnerabilities in software, then exploit those flaws with malicious software that is delivered via tainted links or attached documents.

He said smartphone users need to prepare for this type of attack, which typically cannot be identified or thwarted by mobile device security software.

"With modifications and perhaps use of different exploits, this attack will work on every smartphone device and represents the biggest security threat on those devices," said Alperovitch, who was vice president of threat research at McAfee Inc before he co-founded CrowdStrike.

Researchers at CrowdStrike were not the first to identify such a threat, though such warnings are less common than reports of malicious applications that make their way to online websites, such as Apple's App Store or the Android Market.

In July 2009, researchers Charlie Miller and Collin Mulliner figured out a way to attack Apple's iPhone by sending malicious code embedded in text messages that was invisible to the phone's user. Apple repaired the bug in the software a few weeks after the pair warned it of the problem.

The method devised by CrowdStrike currently works on devices running Android 2.2, also known as Froyo. That version is installed on about 28 per cent of all Android devices, according to a Google survey conducted over two weeks ending February 1.

Alperovitch said he expects to have a second version of the software finished by next week that can attack phones running Android 2.3. That version, widely known as Gingerbread, is installed on another 59 per cent of all Android devices, according to Google.

CrowdStrike's method of attack makes use of a previously unpublicized security flaw in a piece of software known as webkit, which is built into the Android operating system's Web browser.

Webkit is also incorporated into other software programs, including Google's Chrome browser and the Apple iOS operating system for the iPhone and iPad.

CrowdStrike said it had not attempted to create software to attack iOS devices or the Chrome browser.

Manufacturers of Android devices include HTC Corp, LG Electronics Inc, Motorola Mobility Holdings Inc and Samsung Electronics Co.
Continue reading →
Wednesday, February 22, 2012

The Pirate Bay could be blocked in UK; Could it be the next victim of Copyright violation?

0 comments
Popular filesharing website The Pirate Bay could end up being blocked in the United Kingdom following a High Court ruling that found that TPB and users of the service breach copyright on a major scale. British music companies are pushing for ISPs to block their customers from accessing The Pirate Bay on the grounds of copyright infringement. Justice Arnold of the British High Court yesterday ruled that TPB goes "far beyond merely enabling or assisting" copyright infringement and says that the case is similar, if not stronger, than last year's bid to have ISPs block access to Newzbin2. Arnold said that though TPB's operators can prevent copyright infringement by removing the offending torrents, they choose not to. What's more, they take no steps to prevent infringement.

"TPB would be able to prevent infringement of copyright, should its operators so wish. As the website makes clear, torrents can be removed. They will be removed if "the name isn't in accordance with the content" or if they are "child porn, fakes, malware, spam and miscategorised torrents". As a matter of policy, however, the rights of copyright owners are excluded from the criteria by which the operators of TPB choose to exercise this power," Mr Justice Arnold said in the ruling.

"Despite their ability to do so and despite the judicial findings that have been made against them, the operators of TPB take no steps to prevent infringement," he continued. "On the contrary, as already explained, they actively encourage it and treat any attempts to prevent it (judicial or otherwise) with contempt."

Mr Justice Arnold goes on to highlight the site's recent decision to switch to Magnet links as its default.

"Indeed, according to a statement on the website, the reason for its recent adoption of Magnet links as the default option is that "it's not as easy to block as .torrent files". This confirms the operators' determination to do whatever they can to provide users with unrestricted access to torrent files and thereby enable the users to continue to infringe. As noted above, [The British Phonographic Industry] has asked TPB to cease infringing its members' and PPL's members' copyrights, but this request has been ignored."

Arnold concluded that the operators of TBP do authorise users' infringements and go far beyond enabling or assisting.

"In my judgment, the operators of TPB do authorise its users' infringing acts of copying and communication to the public," he said. "They go far beyond merely enabling or assisting. On any view, they "sanction, approve and countenance" the infringements of copyright committed by its users. But in my view they also purport to grant users the right to do the acts complained of. It is no defense that they openly defy the rights of the copyright owners," Arnold finished, adding that the case is indistinguishable from, if not stronger than, last year's landmark case that saw several ISPs forced to block file-sharing site Newzbin2.

According to the Guardian, the high court is expected to rule whether the ISPs should block TPB in June.
Continue reading →
Tuesday, February 21, 2012

Yahoo, Gmail should route all mails through Indian servers

0 comments
Internet content providers Yahoo, Gmail and others would be asked to route all emails accessed in India through the country even if the mail account is registered outside the country.

The move comes in the wake of instances where security agencies could not have a real-time access to some emails as they were registered outside the country but were opened in India.

During a recent high-level meeting held in the office of Union Home Secretary RK Singh, the Department of Information Technology (DIT) was asked to take up the matter at the earliest with the content providers.

During the meeting, director general from CERT-in informed that content provider Yahoo automatically locates all email accounts registered in India to the server in India, minutes of the meeting said.

However, Yahoo accounts registered outside India and subsequently accessed from India are routed through servers outside India, it said.

"It was decided to advice Yahoo, Gmail etc that all emails accessed from India should be routed through servers in India," it said, adding that the DIT would take up the matter with the content providers.

When the content provider was approached, the sleuths were told that in order to see the mails, which had been accessed from India, a request to a European nation where the server was based, was required, official sources said.
Continue reading →

Microsoft slams Google bypassed Internet Explorer Privacy Policies

0 comments
In the wake of reports that Google had bypassed privacy settings in Safari, Microsoft announced today it had discovered the Web giant had done the same with Internet Explorer.

"When the IE team heard that Google had bypassed user privacy settings on Safari, we asked ourselves a simple question: Is Google circumventing the privacy preferences of Internet Explorer users too?" IE executive Dean Hachamovitch wrote in a blog post this morning. "We've discovered the answer is yes: Google is employing similar methods to get around the default privacy protections in IE and track IE users with cookies."

The blog post, which details Microsoft's findings and offers privacy protection tips, said it has contacted Google about its concerns and asked it to "commit to honoring P3P privacy settings for users of all browsers".

Google representatives did not immediately respond to CNET's request for comment.

In the blog post, Hachamovitch explained how the bypass occurs:

Technically, Google utilizes a nuance in the P3P specification that has the effect of bypassing user preferences about cookies. The P3P specification (in an attempt to leave room for future advances in privacy policies) states that browsers should ignore any undefined policies they encounter. Google sends a P3P policy that fails to inform the browser about Google's use of cookies and user information. Google's P3P policy is actually a statement that it is not a P3P policy.


P3P, or Platform for Privacy Preferences, is an official recommendation of the World Wide Web Consortium that sites use to summarize their privacy policies. However, the recommendation has been largely ignored in the past decade since introduction a decade ago with many major Web sites such as Google.com, Apple.com, CNN.com, and Twitter.com opting not to use it to describe their policies.

Hachamovitch also took the opportunity to point out at IE users have access to a Tracking Protection List that it says prevents the P3P bypass. Additionally, he said Microsoft is "investigating what additional changes to make to our products. The P3P specification says that browsers should ignore unknown tokens. Privacy advocates involved in the original specification have recently suggested that IE ignore the specification and block cookies with unrecognized tokens."

Microsoft slammed Google earlier this week after The Wall Street Journal reported that Google had sidestepped Safari user privacy settings to track Internet users. The search giant and other ad companies reportedly used special code to get around Safari's privacy controls in order to track users on computers and mobile devices.
Continue reading →
Monday, February 20, 2012

UK's new spy plan to store Phone and email records

0 comments

For the first time, Britain plans to store details of all phone calls, text messages, emails and websites visited online as part of the government's new anti-terror plans, says a media report.

Landline and mobile phone companies and broadband providers will be ordered to store the data for a year and make it available to the security services under the scheme.

The databases would not record the contents of calls, texts or emails but the numbers or email addresses of who they are sent and received by, the 'Daily Telegraph' reported.

UK's security services will have widespread access to information about who has been communicating with each other on social networking sites such as Facebook. Direct messages between subscribers to websites like Twitter would also be stored, as well as communications between players in online video games, the report said.

It is certain to cause controversy over civil liberties - but also raise concerns over security of records.

The plan has been drawn up on the advice of MI5, the home security,the home security service, MI6, which operates abroad, and GCHQ, the government's 'listening post' to monitor communications.
Continue reading →
Saturday, February 18, 2012

Adobe confirms new zero-day Flash bug

0 comments
Adobe on Wednesday patched seven critical vulnerabilities in Flash Player, including one reported by Google researchers that hackers are using in "active targeted attacks." The bug attackers have been exploiting is a cross-site scripting (XSS) flaw in the Flash Player plug-in used by Microsoft's Internet Explorer (IE).

"This update resolves a universal cross-site scripting vulnerability that could be used to take actions on a user's behalf on any website or Web mail provider, if the user visits a malicious website," read the Adobe security advisory that accompanied yesterday's Flash update. "There are reports that this vulnerability is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message."

The attack only works against IE.

Adobe said the other six vulnerabilities, all rated critical like the XSS bug, were memory corruption flaws or security bypass bugs that "could cause a crash and potentially allow an attacker to take control of the affected system."

Google was credited with notifying Adobe of the XSS vulnerability, but Adobe did not note when Google filed the bug report or how long attackers have been exploiting the bug.

To patch the vulnerabilities, Adobe updated Flash Player 11 and Flash Player 10 on Windows, Mac OS X, Linux and Solaris, and Flash Player on Android.

Also on Wednesday, Google updated Chrome to offer the newly-patched Flash to its users. Google has packaged Flash Player with Chrome since April 2010, and remains the only browser that contains its own copy of Flash Player.

Last week, Adobe confirmed that its next target for a "sandboxed" Flash Player would be the plug-in for Internet Explorer. But Adobe confirmed that even if the defense had been in place, the active attacks exploiting the just-patched XSS vulnerability would still have succeeded.

"The universal [XSS] vulnerability breaks the same-origin security model in the browser and allows the attacker to 'make clicks' on behalf of the user in a way that is normally not allowed," said Adobe spokeswoman Wiebke Lips in an email reply to questions. "All of this activity occurs within the browser context, so running the browser in a low-rights sandbox would not change the behavior of the attack. Even if we had a rock-solid sandbox in place for Flash Player on Internet Explorer, this vulnerability could have been exploited the same way."

Adobe finished a sandboxed Flash for Chrome in 2010, and has just launched a beta of sandboxed Flash for Mozilla's Firefox on Windows Vista and Windows 7.

Wednesday's Flash update was the first this year for the media player, but the software has required aggressive patching: In 2011, Adobe fixed Flash flaws nine different times.

The patched versions of Flash Player for Windows, Mac, Linux and Solaris can be downloaded from Adobe's website. Alternately, users can run Flash's update tool or wait for the software to prompt them that a new version is available.

Android users can retrieve the new version from the Android Market.
Continue reading →
Monday, February 13, 2012

Microsoft India Store gets hacked by Evil Shadow Team, passwords and usernames exposed (updated)

0 comments


Hackers, allegedly belonging to a Chinese group called Evil Shadow Team, struck at www.microsoftstore.co.in on Sunday night, stealing login ids and passwords of people who had used the website for shopping Microsoft products.

While it is troublesome that hackers were able to breach security at a website owned by one of the biggest IT companies in the world, it is more alarming that user details - login ids and passwords - were reportedly stored in plain text file, without any encryption.

Following the hack, the members of Evil Shadow Team, posted a message on the Microsoft website saying "unsafe system will be baptized". The story was first reported by www.wpsauce.com.

Later, the website seemed to have been taken offline by Microsoft. We advise the users at Microsoft India Store to change the password as soon the website comes online. Also, if they have used the same password or login id on any other web service, they should change it immediately.

Last year, hacker groups like Lulzsec had carried out several-profile high profile break-ins, putting focus on the security measures companies put in place. Sony allegedly suffered several security breaches and hackers stole user ids and passwords of customers from its network.

In a message posted on a website called Pastebin, Lulzsec claimed the group was bringing attention to the web security. "Do you think every hacker announces everything they've hacked? We certainly haven't, and we're damn sure others are playing the silent game. Do you feel safe with your Facebook accounts, your Google Mail accounts, your Skype accounts? What makes you think a hacker isn't silently sitting inside all of these right now," the group wrote.

But the incident at Microsoft Store on Sunday hints that lessons have not been learnt. Just like Sony, which later revealed that user ids and passwords were not encrypted at the time of security breach, Microsoft too seemed to have been casual about handling the user details by storing them in a plain text file. We have contacted Microsoft but company has so far not acknowledged or commented on the security breach.


Microsoft now working on securing their site with message in their Home Page indicating.
The Microsoft Store India is currently unavailable. Microsoft is working to restore access as quickly as possible. We apologize for any inconvenience this may have caused.

Check here the complete screenshots of the exposed username and passwords database.

http://hi.baidu.com/hackteach/blog/item/b4a85ec3deee224ab219a8fa.htmlexploited
Continue reading →
Wednesday, February 8, 2012

Indian Hacker leaks Symantec source code after failed $50,000 Demand

0 comments

A hacker suspected to be from India released the source code for antivirus firm Symantec's pcAnywhere utility on Tuesday, raising fears that others could find security holes in the product and attempt takeovers of customer computers.

The release followed failed email negotiations over a $50,000 payout to the hacker calling himself YamaTough to destroy the code.

The email thread was published on Monday, but the hacker and the company said their participation had been a ruse. YamaTough said he was always going to publish the code, while Symantec said law enforcement had been directing its side of the talks.

The negotiations also might have bought Symantec time while it issued fixes to the pcAnywhere program, which allows customers to access their desktop machines from another location.

"Symantec was prepared for the code to be posted at some point and has developed and distributed a series of patches since January 23rd to protect our users against known vulnerabilities," said company spokesman Cris Paden.

Symantec had taken the extraordinary step of asking customers to stop using the software temporarily until it readied the patches. It issued fixes for "known vulnerabilities" in version 12.5 of the software on January 23 and fixes for versions 12.0 and 12.1 on Friday January 27.

Paden said that Symantec had contacted its customers and that it had not lost any customers. He said that if they were running up-to-date, patched versions they should not face increased risk.

Symantec also expects hackers to release other source code in their possession, 2006 versions of Norton Antivirus Corporate Edition and Norton Internet Security. "As we have already stated publicly, this is old code, and Symantec and Norton customers will not be at an increased risk as a result of any disclosure," Paden said.

The emails over the $50,000 payoff was widely circulated, with some mocking the world's largest standalone security company for its apparent attempt to buy protection.

But the company said the emails were in fact between the hacker and law enforcement officials posing as a Symantec employee.

"The communications with the person(s) attempting to extort the payment from Symantec were part of the law enforcement investigation," Paden said, adding that no money was paid.

Paden declined to name the law enforcement agency, saying it could compromise the investigation.

Symantec had previously confirmed the hacker, part of a group called Lords of Dharmaraja and affiliated with Anonymous, was in possession of source code for its products, obtained in a 2006 breach of the company's networks.

The email exchange released by the hacker, who claims to be based in Mumbai, India, shows drawn-out negotiations with a purported Symantec employee starting on January 18.

The email negotiations echoed conversations in past years, viewed by Reuters, in which police agencies directed talks between victims and hackers.

"We can't pay you $50,000 at once for the reasons we discussed previously," said one email from a purported Symantec employee Sam Thomas, who offered to pay the full amount at a later date.

"In exchange, you will make a public statement on behalf of your group that you lied about the hack."

A common tactic of the FBI and others investigating extortionists and kidnappers is to seek to break down the amount of money sought by the suspects into multiple smaller payments.

This stretches out the negotiation, giving authorities more insight into the suspect and more time in which to make an arrest. It also lessens the risk to any victim inclined to pay the entire amount demanded.

Most important, it creates more transactions, each one of which provides a trail of records and human beings that can be traced as the police seek their quarry.

The hacker said he never intended to take the money.

"We tricked them into offering us a bribe so we could humiliate them," YamaTough told Reuters.

In recent weeks, the hacker has posted segments of code for Norton Utilities and other programs. A software maker's intellectual property, specifically its source code, is its most precious asset.

Symantec's Norton Internet Security is among the most popular software available to stop viruses, spyware, and online identity theft.
Continue reading →
Sunday, February 5, 2012

Hackers Intercept FBI Call With UK

0 comments
FBI Scotland Yard call Hackers eavesdropping
The FBI has admitted that hackers intercepted a conference call it held with Scotland Yard to discuss an ongoing investigation into Anonymous and LulzSec attacks.

Hackers claiming to be from Anonymous said they were behind the interception on 17 January. A recording of the call posted on YouTube on Friday is bona fide, the FBI confirmed on Friday.

"The information was intended for law enforcement officers only and was illegally obtained," said an FBI spokeswoman. "A criminal investigation is under way to identify and hold accountable those responsible."

Details about the conference call, including the names of participants, were posted in an email on Pastebin on Friday. The email has been acknowledged by the FBI as authentic. It lists addresses for officers from the Met's Police Central eCrime Unit (PCeU), the FBI, the Irish Garda and Europol, as well as cybercrime police agencies from Holland, France, Germany and Sweden.

"We are aware of the video which relates to an FBI conference call involving a PCeU representative," the Metropolitan Police said in a statement. "At this stage no operational risks to the [Metropolitan Police Service] have been identified; however we continue to carry out a full assessment."

During the call, a PCeU representative called 'Stewart' recounts how the international police investigation is progressing. He mentions suspected Anonymous hackers Ryan Cleary and Jake Davis, who are being held in the UK on charges of involvement in distributed denial-of-service attacks. In addition, he reveals that a cyber-team from the US Air Force examined Cleary's hard drive and discusses a hacker known as 'TehWongZ'.

Cleary's solicitor Karen Todner said there may be implications for his case, which will aired next at a plea hearing on 11 May, postponed from 27 January.

"I think it's astonishing that the FBI and the e-Crime unit don't have secure email," Todner told ZDNet UK. "In terms of the implications for the case, I don't know at this stage, but I will be looking at it carefully."

Sophos security expert Graham Cluley suggested the hack could have arisen from the email being forwarded to an officer's compromised personal account, rather than the police email system being breached.

"It's deeply embarrassing that the very hackers that are being investigated are listening into the call as they are being discussed," Cluley said. "They also published an email — clearly, someone's email has been compromised."
Continue reading →
Friday, February 3, 2012

Google enables 'Per Country' Blocking on Blogger

0 comments
Google's Blogger Censorship Blocking
Google says its Blogger sites can now be blocked on a “per country” basis, following a recent similar Censorship announcement by Twitter.

Google says it will now be able to block access in individual countries following a legal removal request by a country’s government.

The new system, under which blocking will not require restricting world-wide access to a blog, has been implemented in Australia, New Zealand and India, but Google has plans to roll it out globally, the BBC reported Thursday.

Google’s action comes after Twitter’s announcement it could selectively block tweets on a country-by-country basis, a decision roundly criticized by free-speech advocates.

However, Joss Wright at the Oxford Internet Institute said he saw the changes to Blogger as being positive.

“Google’s new approach to supporting country-level takedown requests in Blogger strikes a good balance between free speech, legality and practical issues for end users,” he said.

“By allowing per-country takedown requests, Google can meet local laws without blocking content at a global level.”

A change to the Web address system makes “per country” blocking possible, Google said.

“If you visit a blog that does not correspond to your current location as determined by your IP address, the blogspot servers will redirect you to the domain associated with your country,” Google said in a statement about the changes.
Continue reading →
Monday, January 30, 2012

Google joins Facebook and Microsoft to fight Phishing

0 comments
Microsoft+Google+Facebook fights Phishing

On Monday, Google, Facebook, Microsoft, Yahoo!, and eleven others outfits announced they had formed a new alliance to combat phishing — a way of fooling email and web users into providing sensitive information, including credit card numbers. The alliance is known as Domain-based Message Authentication, Reporting and Conformance, DMARC for short, and the aim of this sprawling alliance is to lay down new email standards that help stop the nefarious practice.

“One of the worst experiences for a user is being phished,” Adam Dawes, a Google product manager and DMARC representative, tells Wired. “The best way to protect them is to make sure the email never reaches the spam folder at all.”

Phishing is a relatively simple trick. Often, the spammer spoofs the data in the email message so it really looks like it came from a legitimate sender. There’s usually a way to figure out where the message really came from, but it can be hard for the average Joe to spot.

Today, as Dawes points out, phishing messages are often caught by an email client’s spam filters. But even as they check out their spam folders, many users can’t help but open on a message than says its from PayPal. Before they know it, someone has phished their credit card number. With DMARC, the idea is to get the email companies working behind the scenes to prevent phishing emails from ever hitting your inbox or spam folder.
About eighteen months ago, PayPal began working directly with Google and Yahoo to set standards for Gmail and Yahoo! Mail that would prevent fake PayPal messages from hitting a user’s inbox. According to Brett McDowell, one of PayPal’s security managers and now chairman of DMARC, the three companies were blocking over 200,000 fake PayPal messages each day.
Eventually, PayPal, Google, and Yahoo! started asking other outfits to get involved. Behind the scenes, new names began using what would become the DMARC protocols, and as more and more companies used the protocols, engineers noticed new flaws — and fixed them. Mike Adkins, a Facebook messaging engineer, says that Monday’s news isn’t a “Coming soon” announcement. “You’ve been protected by DMARC for a while,” he says.
The DMARC protocols are based on existing technologies, including the Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM). Both are common mail security protocols. SPF verifies the IP address of the email’s sender, while DKIM vets the structure of the email’s content, comparing it to encoded information coming from the sender.
DMARC is hardly the only cross-industry effort to battle phishing. A global non-profit called The Anti-Phishing Working Group encourages businesses to share the latest information about phishing tactics and techniques. Paul Ferguson, a senior threat researcher at anti-virus developer Trend Micro, tells Wired he supports any collaboration that fight malicious software and phishing — up to a point. “The only caution that I would have is that there are too many of these kinds of these of efforts, they start working against each other,” he says. Even inside a single company, he continues, you might have the marketing department backing one anti-phishing group, while the research department backs another.
PayPal’s McDowell reiterates that the goal of DMARC — at least for the moment — is to defend legitimate domains, not to address what’s sometimes called “typo-phishing,” where scammers use something that looks like a common domain but is actually a slightly different spelling.
“Domain-based phishing cannot happen when both parties deploy DMARC,” he says.

Other companies involved in the group include American Greetings Corp, LinkedIn Corp and Yahoo as well as privately held Agari, Cloudmark, eCert, Return Path and the Trusted Domain Project.

IDC security analyst Michael Versace said that the approach recommended by the group appeared to be effective and inexpensive to implement.

Yet he said that the industry should keep developing new technologies to fight spammers because he expects that cyber criminals will eventually figure out how to circumvent the DMARC protections.
Continue reading →
Saturday, January 14, 2012

Indian hackers published Symantec Source Code

0 comments
A group of Indian hackers has offered support to an American man who filed a lawsuit against Symantec Corp by publishing source code from a 2006 version of Norton Utilities, a software program at the heart of the legal dispute.

A spokesman for the group, which is known as "Lords of Dharmaraja," released more than 13,000 files that were part of the product's source code late on Friday. "Pass it on to forensics and win the lawsuit," YamaTough said via Twitter.

The proposed class-action lawsuit claims that Symantec seeks to convince consumers to buy Norton Utilities and PC Tools software programs by scaring them with misleading information about the health of their computers. Symantec has said those claims are without merit.

It was not immediately clear how the source code might help the case. And one of the attorneys working with plaintiff James Gross said that he did not welcome assistance from the Indian hackers.

"This is not something we think is necessary to support our case and we don't support hacking," said Jay Edelson, an attorney with Edelson McGuire LLC. "We are not a rogue nation where the only hope is for people to take matters in their own hands."

Symantec spokesman Cris Paden said that his company no longer sells or supports Norton Utilities 2006. "The current version of Norton Utilities has been completely rebuilt and shares no common code with Norton Utilities 2006," he said. "

Symantec previously confirmed that the same group of hackers had accessed the source code to some of its anti-virus software.
Continue reading →
Thursday, December 29, 2011

India ranks top in source of spam in 3rd quarter of 2011 with 14.8 percentage

0 comments
More than 50 per cent of all spam messages in the world during the third quarter of 2011 originated from just six countries, with India accounting for the highest 14.8 percent of such messages.

According to Kaspersky Lab's spam report, India was ahead of countries like Indonesia (10.6 per cent), Brazil (9.65 per cent), Peru (6.65 per cent), South Korea (5.85 per cent) and Ukraine (3.7 per cent).

All of the countries that make up the top 10 sources of spam are situated in South America, Asia and Eastern Europe, the report said.

"This is due to the fact that there are numerous users in these countries and they are, for the most part, not very experienced when it comes to IT security. This makes them a soft target for cybercriminals spreading spam-bots," it said.

The report said that all GCC countries together accounted for only 1.33 per cent of all global spam, with Saudi Arabia leading the pack. This was attributed to the low number of users and more vigilance in protecting computers in these countries.

GCC countries are Bahrain, Kuwait, Oman, Qatar, Saudi Arabia, and United Arab Emirates.
Continue reading →
Tuesday, November 22, 2011

How Facebook tracks its 800 Million Users Online and Offline ?

0 comments
Facebook has for the first time revealed details about how it tracks users across the Web.

According to USA Today, the complete picture how the social network keeps tabs on its 800 million users was revealed through series of interviews with the social networking site's engineering director, spokesman, corporate spokesman and engineering manager.

Facebook does not track everybody the same way, as it uses different methods for members who have signed in and are using their accounts, members who are logged-off and non-members.

To do this, the company relies on tracking cookie technologies similar to the controversial systems used by Google, Adobe, Microsoft, Yahoo and others in the online advertising industry, Arturo Bejar, Facebook's Engineering Director, was quoted as saying.

Here's how it works: 

Every time one logs onto Facebook it inserts a "session cookie" and a "browser cookie" into one's browser. If one simply visits the site without signing up on the browser, cookie is inserted.

From that point on, each time one visits a site which uses Facebook technology, the cookie works in conjunction with the plug-in to alert Facebook to the date, time and URL of the page you are viewing.

The unique characteristics such as one's IP address, screen resolution, operating system and browser version, are also recorded by the social networking site, the report said.

Facebook spokesman Andrew Noyes said that the company's tracking systems are used to personalise content and help boost security, adding the tracking practices are spelt out in its 'Privacy Policy' and 'Help Center' web pages.

However, industry critics have expressed serious concern about the practice. "Tracking data can be used to figure out your political bent, religious beliefs, sexuality preferences, health issues or the fact that you're looking for a new job," Peter Eckersley of Electronic Frontier Foundation, a digital rights organisation, told the newspaper.

Continue reading →
Wednesday, November 2, 2011

Duqu, a new variant of Deadly worm Stuxnet

0 comments
Recent Chaos in Cyber World : 

Recently several Antivirus companies have reported that they've found that Several Computers across the Globe has been affected by a Deadly Worm called Duqu.

Etymology of Duqu :

It is named "Duqu" because this worm creates files with a Prefix ~DQ in all the infected Computers.

Father of Duqu : 

Scientists strongly believe that the Code of Duqu has some similarity with Stuxnet Code.Eventhough the actual objective of Duqu is unknown, Since it is a variant of Stuxnet, it is widely discussed that Duqu is being launched for another Corporate Attack and Data Stealing.

A byte of Information about Stuxnet : 

Stuxnet was designed to disrupt operations at a specific Iranian nuclear-weapons facility, and the general consensus among security and intelligence experts is that it was hatched by the United States and Israel for Cyberwar as an alternative to a military strike.

Primary victims of Stuxnet : 


Eventhough  Stuxnet was primarily designed to attack Iranian Nuclear Facility Center, It also affected Indonesia,India and some parts of US.


Reason for Spreading :

A Bug in Microsoft operating system is the primary reason for the Spread of Duqu.
Continue reading →
Sunday, October 30, 2011

RIM Facility Center in India to spy on Blackberry Users

0 comments
Research In Motion Ltd. has set up a facility in Mumbai to help the Indian government carry out lawful surveillance of its BlackBerry services, according to people familiar with the matter, but the move hasn't fully satisfied India's appetite for access to messages on the popular smartphones.

Last year, India threatened to shut down BlackBerry encrypted email and instant messaging services because it couldn't wiretap them. The government put the onus on Waterloo, Canada-based RIM to come up with solutions. Several government-set deadlines have passed and, though India still isn't happy with its surveillance capabilities, it is no longer threatening to shut down the service.

RIM partly assuaged India by setting up the small Mumbai facility earlier this year to handle surveillance requests from India. India can submit the name of a suspect its investigators want to wiretap, and RIM will return decoded messages for that individual, as long as it is satisfied the request has legal authorization, according to the people familiar with the matter.

The Mumbai facility handles lawful intercept requests for consumer services including the BlackBerry Messenger chat service, these people say. India saw the move as a positive step, but would prefer an arrangement where it has the ability to decode messages itself, so that it can conduct surveillance without disclosing the names of suspects to RIM.

India still has no method to intercept and decode BlackBerry enterprise email, which is used by corporate customers and features a higher level of encryption than consumer email and instant messaging. BlackBerry has repeatedly said it doesn't have the keys to unlock enterprise email messages—security is one of the service's key selling points.
Continue reading →
Thursday, October 27, 2011

New 'Socialbot' threat steals private info from Facebook - Do you know all your FB Friends?

0 comments

Do you really know all your Facebook "friends"? Beware, if your answer is 'No', as researchers say you could be putting your private details at risk every time you say 'Yes' to an unknown friend request.

A team at the University of British Columbia in Canada found a worrying way to evade Facebook's security measures entirely and harvest information from the popular social networking site.

They created a team of "fake" Facebook users who were able to harvest tens of thousands of email addresses and private information from unsuspecting users, without human input, the Daily Mail reported.

Such basic information is often sufficient to launch an identity theft attack or launch a "phishing" attack to pilfer somebody's bank details, said lead researcher Yazan Boshmaf.

"An attacker could do many things with this data." According to the researchers, the fake Facebook users, known as Socialbots, were software agents that function almost like a social computer virus and can manipulate a Facebook account, pretending to be a human being.

The 'Socialbots' created by the team began sending friend requests to random users. Each was armed with a profile picture and name -- but were totally unknown to their new "friends".

The team found that one in five users accepted the friend requests, even without knowing them. The figure rose when the 'Bots' attempted to befriend the friends of the "friends" they already had on the network.

Because the 'Bots' seemed to be friends of friends, 60 per cent of people accepted the requests.


The team unleashed 102 Socialbots on the network. Within weeks, they had made 3,000 friends, they reported in New Scientist.

According to the researchers, many people's privacy settings 'shield' private data such as email addresses or their physical address from the public -- but leave the data open to friends.

The team of Socialbots were able to harvest 46,500 email addresses and 14,500 physical addresses from users' profiles.

The attack launched by Boshmaf's team was small scale -- and Facebook's defences could pick up on large numbers of socialbots.

But if the software were "cleverer" than the basic models used by Boshmaf, then Facebook's protection would be rendered useless, the researchers added.
Continue reading →
Friday, October 21, 2011

SIRI - She brings in a security loophole in IPhone 4S

0 comments
There must be nobody who never talked about SIRI the awesome voice recognizing feature in the new IPhone 4S.

Some interesting stuffs that she is capable of doing.

1. You tell her, remind me to call my dad. She will.
2. You ask who is the Prime Minister of India, She will answer you.
3. You ask her about the weather she will show you.
4. Tell her to send a message,make a call,write a mail to your friend. She will help you.

So, while driving, if you wanna text somebody, you need not take your phone out. Just tell SIRI, she will do it. :P

Check out live SIRI here.


Alright Siri, you help me a lot (With all smiles!). But did you hear ? She can help you even when your phone is locked with a passcode. Yes, so whoever gets your phone can make use of SIRI, and blow off your call balance or even blow of your business by dealing with your clients :P So, How can you securely use SIRI?
Watch out:

So, thank Steve that there atleast is an option to disable siri when pass locked the IPhone is! :) ;)

Continue reading →

Followers

Aco

Related Posts Plugin for WordPress, Blogger...