Showing posts with label Hack. Show all posts
Showing posts with label Hack. Show all posts

Thursday, May 26, 2011

IT Hackers

What is IT Hackers?

IT Hackers is a free, safe and legal security community which want to help hackers to expand and test their hacking and security skills. This is more than just a normally hacking related forum as we have a lot of missions where you can legally test your technically knowledge in hacking.
We have many active projects in development and we will release many tools that can help you by passing our missions.

Also people with no knowledge on security and hacking at all are welcome, we can easily turn you into the hacking underground. So please join, learn and share your knowledge with our community as we share everything with you.

- IT Hackers Team

Read more: IT Hackers

Tuesday, May 24, 2011

Anatomy of a Domain Hijacking, part 1

Two weeks ago I'd never heard the term 'Domain Hijacking'. Right now, I'm in the middle of a fight to regain control of my hijacked domain, secretGeek.net. It's not an easy fight, I haven't yet won, and I may never win.
If you have any information that could help me get control of my domain again please leave a comment, or tweet me (@secretgeek), or get in touch via my (now re-secured) email address, leonbambrick@gmail.com
From Russia with Love
On Monday 9th May, I checked my gmail account at around 3:40 in the afternoon, and I was confronted with a dark red message at the top of the screen (in the area where you normally see messages like 'Your email has been sent'). The message said:

Warning: we believe your account was recently accessed from: Russia. Show details and preferences | 
Ignore

I clicked on 'show details and preferences', and a new window opened with this message:


This was definitely not me. At 4:19 AM, and 5:40am I had been far too busy being fast asleep, preparing for a big week, to get to Russia and back for some casual email reading. So someone had infiltrated my email. The freaking out sensation began immediately. I couldn't move. I was frozen completely still.
I followed google's advice and immediately changed my password, then notified my wife. My mind was racing as to what the implications could be.
A little voice told me to check the trash. I was really hesitant, I think I knew the trash would contain something I didn't want to see.

Read more: secretGeek

Wednesday, March 23, 2011

Hacker Spies Hit Security Firm RSA

RSA-Token.jpg


Top security firm RSA Security revealed on Thursday that it’s been the victim of an “extremely sophisticated” hack.
The company said in a note posted on its website that the intruders succeeded in stealing information related to the company’s SecurID two-factor authentication products. SecurID adds an extra layer of protection to a login process by requiring users to enter a secret code number displayed on a keyfob, or in software, in addition to their password. The number is cryptographically generated and changes every 30 seconds.

“While at this time we are confident that the information extracted does not enable a successful direct attack on any of our RSA SecurID customers,” RSA wrote on its blog, “this information could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack. We are very actively communicating this situation to RSA customers and providing immediate steps for them to take to strengthen their SecurID implementations.”
As of 2009, RSA counted 40 million customers carrying SecurID hardware tokens, and another 250 million using software. Its customers include government agencies.

RSA CEO Art Coviello wrote in the blog post that the company was “confident that no other … products were impacted by this attack. It is important to note that we do not believe that either customer or employee personally identifiable information was compromised as a result of this incident.”
The company also provided the information in a document filed with the Securities and Exchange Commission on Thursday, which includes a list of recommendations for customers who might be affected. See below for a list of the recommendations.

Read more: Wired

Sunday, January 30, 2011

mac2wepkey Huawei Home Gateway default WEP

Huawei HG520 and HG530 routers are vulnerable to weak cipher attacks. It is possible to generate the default WEP/WPA key of Huawei HG520 routers. The purpose of this document is to explain the process of developing a key generator for these devices.

Huawei router models HG520b and HG520c contain a key generator command (mac2wepkey) in their TELNET interface. They also contain a command to change the MAC address (fakemac).
It is possible to change our MAC to generate the default WEP key of a MAC of our choosing.
This was published by adiaz last August in Comunidad Underground de México. Over the past few months we have been working on obtaining the algorithm to create our own key generator and we finally made it!

The first step was generating some lists containing MAC, SSID and WEP keys of about 200 entries and trying to identify patterns. The first thing we noticed was that the WEP key had values from 30 to 39 and from 61 to 66. These values correspond to the numbers 1 to 9 and letters a-f in ASCII.

Read more: websec

Wednesday, January 26, 2011

Cyber-crime black market undercovered

The first time I performed a somehow deep research on the black market was back in 2007. At that time, most of it was about selling-buying Trojans, infection kits, and of course stolen data, such as bank and credit card details stolen from users around the world.

A few years later I thought it was time to find out how this market had evolved, and today we have released a report with all our findings.

Credit card details can be purchased for as little as $2 per card, but this level does not provide additional information or verification of the account balance available. If the buyer wants a guarantee for the available credit line or bank balance, the price increases to $80 for smaller bank balances and upwards of $700 to access accounts with a guaranteed balance of $82,000.

Prices are higher if the accounts have a history of online shopping or use payment platforms such as PayPal. For a simple account without a guaranteed balance, we found prices starting at $10 and increasing to $1,500 depending on the platform and the guarantee of available funds. Similarly, these cyber-criminals also offer cloned credit/debit cards (from $180), card cloning machines ($200-1,000), and even fake ATM machines (from $3,500 depending on the model). Additional products such as money laundering services (bank transfers or cashing checks) are available for a commission ranging from 10 to 40 percent of the operation. If buyers want to use stolen bank details to buy products online, but are wary of being traced through the delivery address, the cyber-criminals will make the purchase and forward the goods for a fee of between $30 and $300 (depending on the chosen product).
For more sophisticated cyber-criminals who want to set up their own fake online stores and use rogueware techniques to obtain both user details and also reap the money these unsuspecting victims pay for fake antivirus products, there are also teams available to deliver turnkey projects, design, develop and publish the complete store, even positioning it in search engines. In this case, the price depends on the project.

Prices for botnet rental for sending spam (using bot-infected zombie computers, for example) vary depending on the number of computers used and the frequency of the spam, or the rental period. Prices start at $15 and rise to $20 for the rental of a SMTP server or VPN to guarantee anonymity.
Following is a summary of the products available and their prices:


Products Price

Credit card details
Physical credit cards
Card cloners
Fake ATMs
Bank credentials
Money laundering
Online stores and pay platforms
Design and publishing of fake online stores
From $2-90
From $180 + cost of details
From $200-1000
From $3,500
From $80-700 (with guaranteed balance)
From 10 to 40 percent of the total
$10 for simple accounts without guaranteed balance
From $80-1500 with guaranteed balance
According to the project (not specified)

Read more: PandaLabs Blog

Sunday, January 23, 2011

Compromised Government and Military Sites For Sale

Imperva blogged today about the sale of compromised .gov, .mil, and .edu sites, illustrating that cyber-criminals are getting bolder. Krebs on Security has an unredacted view of the site list. Perhaps the biggest threat is yet to come; if an industrious criminal can break into top government and military sites, so too can government-backed teams, proving that GhostNet and Stuxnet are just the beginning

Read more: Slashdot

Wednesday, January 19, 2011

Hakin9

hakin9_EN.png?1253693799

Hackers :) security magazine

Read more: Hakin9

Some Metasploit video tutorials

Metasploit is probably one of the most useful tools to a hacker. Contains tons of well tested exploits which can be used with multiple payloads to break into systems. In this video series, I have tried to cover all the essential things one needs to know about Metasploit. I start from the very basics and slowly more towards covering intermediate and advanced functionality. I have already created over 300 mins of video.

Read more: Ethicalhacker.net

Read more: Armitage

Monday, January 17, 2011

Research shocker! Keyless car entry systems can be hacked easily, elegantly

know you are vigilant enough not to trust your car's security to a wireless system, but plenty of other folks like the convenience of putting away the metallic keys and getting into their vehicles with a bit of Bond-like swagger. Professor Srdjan Capkun of ETH Zurich found himself perched on the fence between these two groups when he recently purchased a vehicle with a keyless entry system, so he did what any good researcher would: he tried to bypass its security measures. In total, he and his team tested 10 models from eight car makers and their results were pretty conclusive: each of the tested vehicles was broken into and driven away using a very simple and elegant method. Keyless entry systems typically work by sending a low-powered signal from the car to your key fob, with the two working only when they're near each other, but the wily Zurich profs were able to intercept and extend that signal via antennas acting as repeaters, resulting in your key activating your car even when it's nowhere near it.

Read more: Engadget

Sunday, January 09, 2011

Eavesdropping on GSM Calls

It's easy and cheap:
Speaking at the Chaos Computer Club (CCC) Congress in Berlin on Tuesday, a pair of researchers demonstrated a start-to-finish means of eavesdropping on encrypted GSM cellphone calls and text messages, using only four sub-$15 telephones as network "sniffers," a laptop computer, and a variety of open source software.
The encryption is lousy:
Several of the individual pieces of this GSM hack have been displayed before. The ability to decrypt GSM's 64-bit A5/1 encryption was demonstrated last year at this same event, for instance. However, network operators then responded that the difficulty of finding a specific phone, and of picking the correct encrypted radio signal out of the air, made the theoretical decryption danger minimal at best.
But:
As part of this background communication, GSM networks send out strings of identifying information, as well as essentially empty "Are you there?" messages. Empty space in these messages is filled with buffer bytes. Although a new GSM standard was put in place several years ago to turn these buffers into random bytes, they in fact remain largely identical today, under a much older standard.
This allows the researchers to predict with a high degree of probability the plain-text content of these encrypted system messages. This, combined with a two-terabyte table of precomputed encryption keys (a so-called rainbow table), allows a cracking program to discover the secret key to the session's encryption in about 20 seconds.

Read more: Bruce Schneier

Thursday, December 30, 2010

Hackers claim discovery of PS3 'private key,' enabling unauthorized code [Update]

During the ongoing Chaos Communication Conference 27C3, the hackers responsible for the Wii's Homebrew Channel, calling themselves fail0verflow, gave a presentation in which they claimed to have figured out the "private key" used by Sony to authorize code to run on retail PS3 systems. This means, as a PSX-Scene forum post puts it, giving a hacker "full control of the PS3 system," without the use of a USB device.
The group will explain more when its website launches, and also plans to show a demo tomorrow at the conference. This hack is designed not to enable PS3 game piracy (though it might have that effect) but, according to a tweet by fail0verview, to enable Linux to run on all PS3s, "whatever their firmware versions."

Read more: joystiq

Monday, December 27, 2010

AMD Radeon HD 6950 can be turned into an HD 6970 using a BIOS hack

10x1227bu3stk.jpg


Ah, the joy of getting something for nothing -- that's what this time of year is all about, right? The techPowerUp! guys seem to think so, and they've got the perfect gift for all you thrifty PC gaming enthusiasts: a BIOS flash for the Radeon HD 6950 that unlocks the full potential of its hardware (in other words, it turns it into an HD 6970). We already knew the two retail SKUs were built on the same Cayman core, but this hack confirms that all the 6950's performance handicaps have been enacted in software rather than hardware, leaving you all to flip a switch, click a few confirmatory dialogs, and get your game on.

Read more: Engadget

Thursday, December 23, 2010

Nexus S has been rooted, let the madness commence!

Our good friends at xda-developers haven't kept us waiting long. Root access on the Nexus S has been achieved on the phone's day of release, and full instructions for replicating it are available at the link below. The Nexus S is the proud and so far only carrier of Google's latest and greatest Android software, so you're basically getting unrestricted access to the very best Mountain View can offer. Hit that source link. Do it.

Read more: engadget

Tuesday, December 14, 2010

Gawker Media Websites Hacked, Staff and User Passwords Leaked

Gawker Media, the blog powerhouse built by Nick Denton, has been hacked.

After bringing the company’s websites to a standstill Sunday, one or more hackers operating under the name Gnosis released a 500-MB file apparently containing Gawker’s source code, commenter and staff passwords, and internal conversations between the company’s employees.

The e-mail addresses and passwords of hundreds of thousands of Gawker users have been compromised, the hackers said.

It’s the worst security breach in New York-based Gawker’s eight-year history, and a wake-up call to all web publishers. (Click here to access your Wired.com profile if you feel the need to change your password for this website.)

“We’re deeply embarrassed by this breach,” Gawker said in a blog post Sunday afternoon.

The attack included Gawker’s eponymous flagship property, as well as gadget site Gizmodo and the culture site Jezebel. The successful Gawker hack followed a week of escalating attacks in the wake of Wikileaks’s continued release of U.S. State Dept. documents and counter-attacks by hackers associated with a group known as Anonymous, which has staged a pro-Wikileaks campaign called Operation Payback.

Read more: Wired

Posted via email from .NET Info

Thursday, December 09, 2010

FFsniFF (FireFox sniFFer)

FFsniFF is a simple Firefox extension, which transforms your browser into the html form sniffer. Every time the user click on 'Submit' button, FFsniFF will try to find a non-blank password field in the form. If it's found, entire form (also with URL) is sent to the specified e-mail address. It also has the ability to hide itself in the 'Extensions manager'. This extension is meant to be as an example of the 'evil side of Firefox extensions'.

Configuration

FFsniFF has no GUI (so the only way how to find it is looking into Extensions window*) and it cannot be configured after installation. You have to edit it by hand to change the settings (e-mail address, SMTP server..). Please look into the file chrome/content/ffsniff/ffsniffOverlay.js .
* as from version 0.2, the FFsniFF has the ability to hide itself from 'Extensions manager'

From version 0.2 there's a package creator script (written in Python) which will ask you some questions and create 'xpi' package for you, so there's no need of manual configuration any more (just run the file 'pkg_creator.py').

Read more: FFsniFF

Posted via email from .NET Info

Wednesday, December 08, 2010

Gov2.0 and Facebook ‘Like’ Buttons

I am all for Gov2.0.  I think that it can genuinely make a difference and help bring public sector organisations and people closer together and give them new ways of working.  However, with it comes responsibility, the public sector needs to understand what it is signing its users up for.
In my post Insurers use social networking sites to identify risky clients last week I mentioned that NHS Choices was using a Facebook ‘Like’ button on its pages and this potentially allows Facebook to track what its users were doing on the site.  I have been reading a couple of posts on ‘Mischa’s ramblings on the interweb’ who unearthed this issue here and here and digging into this a bit further to see for myself, and to be honest I really did not realise how invasive these social widgets can be.
Many services that government and public sector organisations offer are sensitive and personal. When browsing through public sector web portals I do not expect that other organisations are going to be able to track my visit – especially organisations such as Facebook which I use to interact with friends, family and colleagues.

This issue has now been raised by Tom Watson MP, and the response from the Department of Health on this issue of Facebook is:
“Facebook capturing data from sites like NHS Choices is a result of Facebook’s own system. When users sign up to Facebook they agree Facebook can gather information on their web use. NHS Choices privacy policy, which is on the homepage of the site, makes this clear.”
"We advise that people log out of Facebook properly, not just close the window, to ensure no inadvertent data transfer.”

I think this response is wrong on a number of different levels.  Firstly at a personal level, when I browse the UK National Health Service web portal to read about health conditions I do not expect them to allow other companies to track that visit; I don't really care what anybody's privacy policy states, I don't expect the NHS to allow Facebook to track my browsing habits on the NHS web site.

Secondly, I would suggest that the statement “Facebook capturing data from sites like NHS Choices is a result of Facebook’s own system” is wrong.  Facebook being able to capture data from sites like NHS Choices is a result of NHS Choices adding Facebook's functionality to their site.

Finally, I don't believe that the "We advise that people log out of Facebook properly, not just close the window, to ensure no inadvertent data transfer.” is technically correct.
(Sorry to non-technical users but it is about to a bit techy…)

Read more: The Other James Brown

Friday, December 03, 2010

Flaw in Microsoft Windows SAM Processing Allows Continued Administrative Access Using Hidden Regular User Masquerading After Compromise

TITLE:
Flaw in Microsoft Windows SAM Processing Allows Continued Administrative Access Using Hidden Regular User Masquerading After Compromise

SUMMARY AND IMPACT:
All versions of Microsoft Windows allow real-time modifications to the Security Accounts Manager (SAM) that enable an attacker to create a hidden administrative backdoor account for continued access once a system has been compromised. Once an attacker has compromised a Microsoft Windows computer system using any method, they can either leave behind a regular user or hijack a known user account (Such as ASPNET). This user account will now have all of the rights of the built-in local administrator account from local or remote connections. The user will also share the Administrator's desktop and profile. When inspected by system administrators, the regular user always looks like it is just part of the built-in user's group. The attacker can also make the regular user account hard to detect by creating a user with the username of "ALT-0160", for blank space. Events in the audit log pertaining to the hidden account will be created if the system administrator has enabled auditing, but the user name fields are all blank. Once a system has been compromised, the attacker would need to ensure the Task Scheduler service is enabled only when starting the method. This method can be used to masquerade as any user account on the computer system.

DETAILS:
Use the following steps to exploit this vulnerability.

Read more: ExploitDevelopment.com

Thursday, December 02, 2010

Death from the mailroom – iPhone hacks your company from the inside

Las Vegas (NV) – The Apple iPhone is great for phone calls and viewing YouTube videos, but it can also be turned into one heck of a wireless hacking tool capable of wrecking havoc on almost any company or government organization from the inside.  In a talk at the Defcon security convention, Robert Graham and David Maynor of Errata Security explained how they could defeat firewalls, intrusion detection systems and even armed security guards by Fedexing a modified iPhone to a fictitious employee.   The phone calls home every hour and can then be instructed to sniff network traffic, discover nearby wireless devices and even download information.

Read more: TG Daily

ProFTPD.org Compromised, Backdoor Distributed

A warning has been issued by the developers of ProFTPD, the popular FTP server software, about a compromise of the main distribution server of the software project that resulted in attackers exchanging the offered source files for ProFTPD 1.3.3c with a version containing a backdoor. It is thought that the attackers took advantage of an unpatched security flaw in the FTP daemon in order to gain access to the server.

Read more: Slashdot
Read more: Sourceforge ProFTPD

Tuesday, November 30, 2010

SQL injection with raw MD5 hashes (Leet More CTF 2010 injection 300)

The University of Florida Student Infosec Team competed in the Leet More CTF 2010 yesterday. It was a 24-hour challenge-based event sort of like DEFCON quals. Ian and I made the team some ridiculous Team Kernel Sanders shirts at our hackerspace just before the competition started. The good colonel vs. Lenin: FIGHT!
Here’s a walkthrough/writeup of one of the challenges.

Injection 300: SQL injection with raw MD5 hashes

One challenge at yesterday’s CTF was a seemingly-impossible SQL injection worth 300 points. The point of the challenge was to submit a password to a PHP script that would be hashed with MD5 before being used in a query. At first glance, the challenge looked impossible. Here’s the code that was running on the game server:

<?php
require "inc/mysql.inc.php";
?>
<html>
<head><title>Oh, Those Admins!</title></head>
<body><center><h1>Oh, hi!</h1>
<?php
if (isset($_GET['password'])) {
$r = mysql_query("SELECT login FROM admins WHERE password = '" . md5($_GET['password'], true) . "'");
if (mysql_num_rows($r) < 1)
 echo "Oh, you shall not pass with that password, Stranger!";
else {
 $row = mysql_fetch_assoc($r);
 $login = $row['login'];
...

The only injection point was the first mysql_query(). Without the complication of MD5, the vulnerable line of code would have looked like this:

$r = mysql_query("SELECT login FROM admins WHERE password = '" . $_GET['password'] . "'");

If the password foobar were submitted to the script, this SQL statement would be executed on the server:

SELECT login FROM admins WHERE password = 'foobar'

That would have been trivial to exploit. I could have submitted the password ' OR 1 = 1; -- instead:

SELECT login FROM admins WHERE password = '' OR 1 = 1; -- '

…which would have returned all the rows from the admins table and tricked the script into granting me access to the page.
However, this challenge was much more difficult than that. Since PHP’s md5() function was encrypting the password first, this was what was being sent to the server :

SELECT login FROM admins WHERE password = '[output of md5 function]'

So how could I possibly inject SQL when MD5 would destroy whatever I supplied?

The trick: Raw MD5 hashes are dangerous in SQL
The trick in this challenge was that PHP’s md5() function can return its output in either hex or raw form. Here’s md5()’s method signature:

string md5( string $str [, bool $raw_output = false] )

If the second argument to MD5 is true, it will return ugly raw bits instead of a nice hex string. Raw MD5 hashes are dangerous in SQL statements because they can contain characters with special meaning to MySQL. The raw data could, for example, contain quotes (' or ") that would allow SQL injection.

Read more: cvk | nc -l -p 80