Posts

Showing posts with the label hacking

The US Military Plans to Hack the Human Brain to Teach a Second Language Faster

It is not easy being a spy or a soldier: you have to be completely foucsed in dangerous situations, assess information in the field, speak many foreign languages, and also handle all kinds of technical weaponry and equipment. Learning how to do all of this needs a lot of training, which is why the US Department of Defence research wing wants to figure out other ways to make their workers learn the vital skills faster – even if they have to zap them to get the job done. To explore all the possibilities, Defence Advanced Research Projects Agency or DARPA has awarded more than US$50 million in their funding to eight teams which are researching on how electrical stimulation of the nervous system can help them facilitate learning. The four-year program is called TNT(Targeted Neuroplasticity Training), aims to be the identity safe and also optimal neurostimulation methods which can activate what is called synaptic plasticity, the ability of synapses to weaken or strengthen, and by doing so, ...

South Korean Bitcoin Exchange Hacked and $5 Million Stolen

Yapizon the Bitcoin exchange of South Korea suffered from a massive data breach earlier this week. Hackers stole about 3816.2028 Bitcoin (about US$5 million) which is nearly 37% of total user funds. According to official statement from exchange in Korean language, this attack took place on the Saturday, April 22, 2017, a hacker has compromised four of the total exchange’s hot wallets. A hot wallet means a Bitcoin wallet that is online and is connected to the Internet in some way. As if this data breach was not enough to annoy the users, exchange has decided to make use of 37 percent of the user balances to accommodate the loss of 37 percent in the incident. But to compensate all this loss, the exchange is planning to issue the ‘Fei’ tokens to the “priority members.” Fei is the service product which exchange has been trading eversince 2014. “After so many discussions, the legal and accounting consultations and reviews, has come to the conclusion that this losses incurred in this case sh...

Hackers can Steal Keyless BMW Remotely within Seconds [Video]

As recently as April 4, a security camera recorded two people simply walking around a car and one of them was holding some type of bag close to the front door of a house. Next thing you know; they managed to steal a BMW. This has happened only days after a Mercedes was taken in a very similar way in the United Kingdom. The car in question, the £60,000 BMW X5, seemed to have disappeared from the driveway while its owners slept. Upon investigating the CCTV footage, it was revealed that two thieves stole it by using some transmitting device that was apparently hidden inside the bag which extended the signal coming from the car keys inside the house. This model uses a keyless start system, which means that the car can be unlocked only by having the fob relatively close, or in this case, transmitting its signal so that the car would assume that you have the keys with you. Since both of the vehicles were stolen in Essex, it’s believed that they are being stolen by a gang that’s targeting val...

Someone scraped 40,000 Tinder selfies to make a facial dataset for AI experiments

Image
 Tinder users have many motives for uploading their likeness to the dating app. But contributing a facial biometric to a downloadable data set for training convolutional neural networks probably wasn’t top of their list when they signed up to swipe. Read More

Twitter’s surveillance API crackdown Irritates UK government

The UK government has complained to the Twitter over a block on the access to data from the social network, they are reportedly using this to track potential terror attacks, said the officials on Wednesday. “The government has protested against the decision and is in an ongoing discussion with the Twitter and trying to get access to this data,” said a Home Office spokesman. The Prime Minister Theresa May’s spokesman have declined to specify exactly what that data was and why it is important, saying just “we wish to have access to that information”. But he told the reporters that: “This fight against terrorism is not just one for the security services and the police.Tech companies and social media have a role to play.” A Daily Telegraph newspaper has reported that the government is tracking terms related to the potential terror attacks using a third-party firm, but this is now blocked. In a blog post in November, the Twitter executive Chris Moody has said their firm encouraged the devel...

Nearly 9,000 servers infected with malware across Asean

  In an operation targeting cybercrime across Asean, the Interpol says it has identified thousands of compromised systems that included command-and-control (C2) servers infected with malware and websites run by governments. Some 8,800 of the servers across eight countries were found to be infected with various malware codes including those targeting financial institutions and used to launch DDoS (distributed denial-of-service) attacks. Investigations involving these systems were still ongoing, according to a statement released by Interpol, which ran the Asean operation out of its Global Complex for Innovation in Singapore. It added that some 270 websites were found to have been infected with a malware code that exploited a vulnerability in the website design software. These compromised sites included those run by governments, which might contain personal data of their citizens, it said. “A number of phishing website operators were also identified, including one with links to Nigeri...

MARA FRAMEWORK V0.2(BETA) – MOBILE APPLICATION REVERSE ENGINEERING & ANALYSIS FRAMEWORK.

Image
Ken-Pachi / August 12, 2016 / Comments Off on Mara framework v0.2(beta) – Mobile Application Reverse Engineering & Analysis Framework. / Android Tools, Anti Malware/Virus – Malware Analysis, Encryption, Framework, Registry Analysis, Security Tools Changelog v0.2(beta): * Adding Preliminary Analysis (*new Features) * Adding APK Manifest Analysis (*new Features) * Tools Update tools/editors/com.maskyn.fileeditor-59.apk tools/editors/sublime-text_build-3114_amd64.deb * setup.sh * mara.sh Mara Framework v0.2 MARA is a Mobile Application Reverse engineering and Analysis Framework. It is a tool that puts together commonly used mobile application reverse engineering toolsets, in order to make the task or reverse engineering and analysis easier and friendly to mobile application developers and security professionals. Mara Features supported: * APK Reverse engineering Disassembling Dalvik bytecode to smali bytecode via baksmali and apktool Disassembling Dalvik bytecode to java b...

U.S. launches ‘Hack the Air Force’ bug bounty program

The U.S. Air Force launched a new bug bounty program dubbed “Hack the Air Force” on Wednesday, continuing a trend within the U.S. military that began last year with Hack the Pentagon and Hack the Army. Before the Pentagon’s bug bounty programs launched, it was illegal to search for vulnerabilities on Defense Department networks. The trend has extended overseas, as well, with the U.K. government’s announcement of its own bug bounty program last month. The Air Force program is directed by HackerOne, the bug bounty platform behind Hack the Pentagon that just raised a $40 million investment in February, and Luta Security, the security consulting firm driving the U.K. program. HackerOne and Luta Security are partnering to deliver up to 20 bug bounty challenges over three years to the Defense Department. “This outside approach — drawing on the talent and expertise of our citizens and partner-nation citizens — in identifying our security vulnerabilities will help bolster our  cybersecurity,”...

Kali Linux 2017.1 Released With New Features | Download ISO Files And Torrents Here

Kali Linux is the favorite operating system of ethical hackers. Last year, the developers of this ethical hacking toolset decided to switch to the rolling release model. This means that instead of being based on the standard Debian releases, Kali Linux rolling distro ensures that it’s regularly being updated with latest features and patches. But, in the rolling model, the release of updated images isn’t much important. But, the latest release, i.e., Kali Rolling 2017.1, brings in a bunch of exciting features and updates. So, let’s take a look at the major highlights: Kali Linux 2017.1 new features RTL8812AU Wireless Card Injection support This release brings wireless injection support to 802.11ac standard. This has happened due to the implementation of drivers for RTL8812AU chipsets. For installing the driver, you simply need to run the following command: 1 2 apt – get update apt install realtek – rtl88xxau – dkms CUDA GPU Cracking support Thanks to the improvements in packaging, the u...

Aadhaar Details Of 1.4 Millions People Leaked Due To Programming Error On Govt Website

While the Indian government is trying hard push its Digital India initiative via its new policies, it’s finding it difficult to maintain top-notch security practices. Last month, we told you about an Indian bank’s loss of 25 crores (~ $4 million) due to a flaw in UPI system. Now, an incident in Jharkhand has raised doubts regarding Aadhaar. For those who don’t know, Aadhaar is a 12-digit unique identification number issued by the Indian government to Indian citizens. Due to a programming error in the website maintained by the Jharkhand Directorate of Social Security, Aadhaar data of more than 1.4 million citizens has leaked. The leaked details include names, Aadhaar numbers, addresses, and bank account details of the beneficiaries of the Jharkhand’s old-age pension scheme. The state has 1.6 million pensioners; out of the total, 1.4 million seeded their Aadhaar cards for direct transfer of pensions into their accounts. “We got a call from the UID cell telling us that the Aadhaar numbers...

IT Engineer Hacked His Own Wall Street Company And Stole Source Code, Arrested By FBI

Image
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh  | Cyber Suraksha Abhiyan I t was known last Friday that an American trading firm KCG Holdings was a victim of an internal data breach, it was brought to fruition by a senior employee named Zhengquan Zhang. Employed since March 2010, the DevOps engineer Zhang was working as a supervisor at the firm when the news about the internal hacking came to light. He was arrested by the FBI on Friday, April 7, and charged with one count of theft of trade secrets. Between the months of December 2016 and March 2017, Zhang had accessed the accounts of various employees to gather the maximum amount of information. He also stole the proprietary source code of KCG’s trading system and transferred to a remote server, all of this totaling to around 3 million files. Zhang’s actions were traced on March 25 when he tried to access the home computer of a quantitive analyst who was trying to acces...

Longest-ever US Hacking Sentence — Russian Lawmaker’s Son Gets 27 Years In Prison

Image
The Russian hacker, Roman Seleznev aka Track2, was arrested in Maldives in 2014. He was caught with more than 1.7 million credit card numbers and large stacks of cash. He was accused of hacking into the computers of businesses. Seleznev was convicted on 38 counts, according to Ars Technica, including the likes of wire fraud, widespread identity theft, damage to protected computers, etc. Recently, Seleznev was sentenced to 27 years in prison and convicted of hacking into point-of-sale PCs and causing more than $169 million in damages. According to the prosecutors, the hacking campaign of Seleznev hit more than 3,700 businesses. The government law enforcement authorities asked for 30 years of prison time, so the awarded sentence is pretty close to that. According to the New York Times, it is the “longest sentence handed down for hacking-related charges in the United States.” It should be noted that Seleznev is the son of Valery Seleznev, a Russian Parliament member and an ally to Russian...

Beware of ‘BrickerBot’, the Destroyer of Unsecure Internet Devices – Homeland Security

Image
A new kind of attack is targeting unsecured Internet of Things devices by scrambling their code and rendering them useless. Security firm Radware first spotted the newly found “BrickerBot” malware last month after it started hitting its own honeypots, logging hundreds of infection attempts over a few days. When the malware connects to a device with their default usernames and passwords — often easily found on the internet — the malware corrupts the device’s storage, leading to a state of permanent denial-of-service (PDoS) attack, also known as “bricking.” In other words, this attack “damages a system so badly that it requires replacement or reinstallation of hardware,” said Radware. It’s a novel take on an ongoing security problem with Internet of Things devices: Botnets controlled by hackers, like the Mirai malware, typically infect unsecured devices that are enlisted as part of wider bandwidth-stealing attacks to bring down websites and services by overwhelming them with internet tra...

Indian Train Station Screen Hacked and Replaced with Hardcore Porn

Image
A recent incident in Indian Railways left the officials in shock. One of the busiest metro stations in India started streaming hardcore pornography videos in the middle of the day. The video about the above incident went viral and the company which is handling the network promised that a thorough investigation will be done, as stated on Sunday. This pornographic footage was broadcasted on a TV screen which is usually reserved for different commercials and advertisements. All these advertisements mostly include luxury property or credit card schemes and nothing like this ever been happened before. That is why the whole event immediately stopped every passer there in the Delhi’s central business district of Connaught Place. Among all, one of the spectators started filming this broadcast on his phone and after uploading the clip on the internet, the video has gone viral rapidly and forcing all the local authorities to act. A spokesperson for the DMRC (Delhi Metro Rail Corporation), Mohind...

Here is Why Everyone Should Be Thankful For Hackers

Hackers are an interesting subculture and, as such, they get a fair bit of attention from the media. The idea of a teenager breaking into high security databases is fascinating and more than a little terrifying. However, hackers aren’t all teenagers, nor are they all focused on breaking into places they shouldn’t be. In this article, we’ll look at some reasons why the general public can actually be thankful for hackers. The White Hat Hackers The first reason people should be thankful for hackers is that not all hackers are fixated on breaking into your computer and stealing your data. In fact, hackers see themselves as a group with several subgroups. The black hat hackers are the ones who break into systems for material gain. Gray hat hackers, on the other hand, are in it for personal recognition mostly, but they still break important rules. It’s the white hat hackers that really do good work, however, by hacking into sites in order to help those sites test and improve their security...

Millions Of Smartphones Using Broadcom Wi-Fi Chip Can Be Hacked Over-the-Air

Image
Millions of smartphones and smart gadgets, including Apple iOS and many Android handsets from various manufacturers, equipped with Broadcom Wifi chips are vulnerable to over-the-air hijacking without any user interaction. Just yesterday, Apple rushed out an emergency iOS 10.3.1 patch update to address a serious bug that could allow an attacker within same Wifi network to remotely execute malicious code on the Broadcom WiFi SoC (Software-on-Chip) used in iPhones, iPads, and iPods. The vulnerability was described as the stack buffer overflow issue and was discovered by Google's Project Zero staffer Gal Beniamini, who today detailed his research on a lengthy blog post , saying the flaw affects not only Apple but all those devices using Broadcom's Wi-Fi stack. Beniamini says this stack buffer overflow issue in the Broadcom firmware code could lead to remote code execution vulnerability, allowing an attacker in the smartphone's WiFi range to send and execute code on the device. ...

Google achieves first ever SHA-1 collision attack

Image
Researcher unveiled on Thursday the first practical collision attack for cryptographic hash function SHA-1. SHA-1,Secure Hash Algorithm 1,is popular hashing function used in many websites. Google researchers and academics have today demonstrated it is possible – albeit with a lot of computing power – to produce two different documents that have the same SHA-1 hash signature. How is SHA-1 Used? One real-world example where SHA-1 may be used is when you're entering your password into a website's login page. Though it happens in the background without your knowledge, it may be the method a website uses to securely verify that your password is authentic. In this example, imagine you're trying to login to a website you often visit. Each time you request to log on, you're required to enter in your username and password. If the website uses the SHA-1 cryptographic hash function, it means your password is turned into a checksum after you enter it in. That checksum is then compa...

Facebook Will Soon Pay You Money For Your Videos, Trying To Become “Next YouTube”

Facebook is all set to ditch the cloak of a social media company and turn itself fully into a media company. Its investments in videos will be further pushed in near future. During Facebook’s Q4 earning announcement, Zuckerberg told that Facebook is planning to start sharing its ad revenue with content creators. This strategy will attract more content creators to Facebook.   Facebook has defied the predictions made by economists and revealed that its growth isn’t going to stop anytime soon. On Wednesday, the company said that its revenue grew 51% in 2016’s fourth quarter. Zuckerberg’s company was also able to convert 52 cent of every dollar into operating profit. But, before Facebook’s growth stumbles, what’s next? Last year, Facebook made big bets on video by pushing live videos like crazy. This year things won’t slow down. Instead, the company is expected to invest more money to create its new moneymaking machine. Zuckerberg himself considers video a mega trend. “That’s why we’re...

Pentagon Servers are Flawed and Easy to Hack

The U.S. Department of Defense can be at a huge risk of being attacked by hackers very easily, a security researcher warns. According to the  ZDNet , who cites the Dan Tentler, the founder of cybersecurity firm Phobos Group, there are several misconfigured servers run by Department of defence could allow attackers an easy access to the internal government systems. This includes eagerness of foreign actors to find a way to get into U.S. systems, especially since they can easily make it look as if the attacks are from within the United States. Dan said that he’s probably not the first to discover these flaws since they are particularly easy to discover. He added that they are probably already being exploited now. “There were hosts which were discovered having serious technical misconfiguration problems that can be easily abused by an attacker outside or inside of the country, they could implicate the US as culprits in hacking attacks if they desire so,” Tentler told ZDNet. They have info...

Check If Your Netgear Router is also Vulnerable to this Password Bypass Flaw

Image
Again bad news for consumers with Netgear routers: Netgear routers hit by another serious security vulnerability, but this time more than two dozens router models are affected. Security researchers from Trustwave are warning of a new authentication vulnerability in at least 31 models of Netgear models that potentially affects over one million Netgear customers. The new vulnerability, discovered by Trustwave's SpiderLabs researcher Simon Kenin, can allow remote hackers to obtain the admin password for the Netgear router through a flaw in the password recovery process.  Kenin discovered the flaw ( CVE-2017-5521 ) when he was trying to access the management page of his Netgear router but had forgotten its password. Exploiting the Bug to Take Full Access on Affected Routers So, the researcher started looking for ways to hack his own router and found a couple of exploits from 2014 that he leveraged to discover this flaw which allowed him to query routers and retrieve their login creden...