Tuesday, 20 August 2013

Hacker who exposed Facebook bug to get reward from unexpected source moretan $50000

A man who hacked into Mark Zuckerberg's Facebook page to expose a software bug is getting donations from hackers around the world after the company declined to pay him under a programme that normally rewards people who report flaws.

Khalil Shreateh discovered and reported the flaw but was initially dismissed by the company's security team. He then posted a message on the billionaire's wall to prove the bug's existence.

Now, Marc Maiffret, chief technology officer of cybersecurity firm BeyondTrust, is trying to mobilize fellow hackers to raise a $10,000 reward for Shreateh after Facebook refused to compensate him.

Maiffret, a high school dropout and self-taught hacker, said on Tuesday he has raised about $9,000 so far, including the $2,000 he initially contributed.

He and other hackers say Facebook unfairly denied Shreateh, a Palestinian, a payment under its "Bug Bounty" program. It doles out at least $500 to individuals who bring software bugs to the company's attention.

"He is sitting there in Palestine doing this research on a five-year-old laptop that looks like it is half broken," Maiffret said. "It's something that might help him out in a big way."

Shreateh uncovered the flaw on the company's website that allows members to post messages on the wall of any other user, including Zuckerberg's. He tried to submit the bug for review but the website's security team did not accept his report.

He then posted a message to Zuckerberg himself on the chief executive officer's private account, saying he was having trouble getting his team's attention.

"Sorry for breaking your privacy," Shreateh said in the post.

The bug was quickly fixed and Facebook issued an apology on Monday for having been "too hasty and dismissive" with Shreateh's report. But it has not paid him a bounty.

"We will not change our practice of refusing to pay rewards to researchers who have tested vulnerabilities against real users," Chief Security Officer Joe Sullivan said in a blogpost.

He said Facebook has paid out more than $1 million under that program to researchers who followed its rules.

Google raises bug reporting rewards to $5000

Google had recently announced that it is considering offering as much as $5000 to those people who report bugs under the Chromium and Google Web Vulnerability Reward Programs. And less than two weeks later, the company has gone on record to confirm this bit of news.
According to a report on PTI, Google has already implemented the new rewards which are as much as 5 times more than the previous ones. Basically, the search engine giant’s big bounty program encourages people across the world to detect bugs and other problems with the Chrome browser or the operating system. And those who manage to spot these are rewarded with money based on how harmful the bug is.
Google Logo
The company based in Mountain View has received 2000 security reports ever since it started the initiative about three years ago. And Google had disclosed the amount of cash that it has given out in this time period to all the people who sent those reports in, through a blog post on the official Online Security blog. The total stands at a whopping $2,000,000. Over a million is for Chromium VRP, while the rest of the money has been offered as rewards to those who detected vulnerabilities in Google Web VRP.
The Search engine will give $5000 to those who notice problems that pose a significant threat and provide a detailed analysis of the severity of these bugs. And the already-implemented bonuses, will continue to be given to those who spot errors.
And people who have found bugs can head over to the official website for more information.

Philips Light Bulb Vulnerability Could Leave Some In the Dark

 philips-hue-ha779_av1
Watch This Video ---> http://www.youtube.com/watch?v=5iEJSQSTfTM
According to research unveiled this week some types of web-enabled light bulbs are vulnerable to a flaw wherein an attacker could literally leave users of the bulbs in the dark.
Philips’ Hue brand lighting systems can be exploited, according to independent researcher Nitesh Dhanjani who published a paper, Hacking Lightbulbs (.PDF) to accompany his research on Tuesday.
Hue received scattered acclaim last year after it popped up at the Apple store and was later called the best new product of 2012 by Forbes. Essentially it’s a wireless system that can manage an infrastructure of LED light bulbs via iOS and Android devices.
The main problem here lies in the fact that Hue’s bridge uses a whitelist of associated tokens to authenticate its requests. Anyone else who can get on its network and glean at least one of the whitelisted tokens can issue HTTP commands to the system and in turn control the lightbulbs.
Dhanjani notes that in testing, determining one of the whitelist tokens was not difficult, it was simply the MD5 hash of the MAC address of the users’ iOS or Android device.
“This leaves open a vulnerability whereby malware on the internal network can capture the MAC address active on the wire (using the ARP cache of the infected machine). Once the malware has computer the MD5 of the captured MAC addresses, it can cycle through each hash and issue ‘all lights off’ instructions to the bridge via HTTP.”

Attackers can repeatedly insert code to trigger a “sustained blackout,” and rig the victim’s system so they can remotely change people’s light bulbs.
In one – perhaps farfetched situation – an attacker could even cause a blackout in a person’s home or office just by tagging a completely black image of them on Facebook. This stems from functionality in the app that lets social media dictate users’ lighting. Hue can change lights to reflect the color of an Instagram or Facebook photo and blink a certain number of times if they receive an email.
Dhanjani contacted the makers of the system, Philips, several times via Twitter in June to address the issues with Hue but the company never responded with an email to Dhanjani to further explain the vulnerability.
When reached this week Philips claimed it was aware of Dhanjani’s whitepaper but insists the vulnerability is only possible on local area networks, adding that if users secure their internet, “traffic passing between your devices and across the internet will remain fully secure.”
The news that an internet-connected lighting system is vulnerable shouldn’t come as too big of a surprise. In this day in age – as we’ve learned with cars, pacemakers, washing machines and even coffee makers – practically everything that can connect to the internet can be compromised.
While Dhanjani warns “lighting is critical to physical security,” and that if anyone were to exploit this vulnerability in a hospital or public venue, it could cause trouble, it’s not likely many of these vulnerabilities will really affect the general public.  In advertising, the product is catered more towards the home and in most situations it’s hard to comprehend being left in the dark as anything more than just a nuisance.

Monday, 19 August 2013

Palestinian apologizes for yesterday hacking Zuckerberg’s Facebook page

Khalil Shreateh contacted Zuckerberg in an attempt to claim reward Facebook pays users who find holes in its security.

   

Palestinian hacker Khalil Shreateh has apologized to Facebook CEO Mark Zuckerberg for gaining access to his wall in an attempt to prove a glitch, Al Arabiya reported on Monday.

Shreateh accessed the page of the social media website’s founder by taking advantage of a glitch that would allow any Facebook user to post on a stranger’s wall, despite security settings designed to help users keep their pages private.

Facebook has a reward for hackers who manage to bypass their security system, hoping this will act as an incentive to report glitches rather than exploit them.

The hacker first contacted the Facebook security team after proving a glitch was real by writing on the wall of a friend of the Facebook founder.

Shreateh – whose first language is Arabic – wrote to Facebook saying: “My name is Khalil Shreateh. I finished school with BA degree in Information Systems. I would like to report a bug in your main site (www.facebook.com) which i discovered it...The bug allow Facebook users to share links to other facebook users, I tested it on Sarah.Goodin wall and I got success post [sic].”

Shreateh went on to recount his attempts to notify the social media site, and posted a grab of the message on his blog. He says he hoped his ability to post to Sarah Goodwin’s page would help prove his case to the Facebook security team. There is also a video on YouTube showing how he accessed the various pages.

After Facebook responded by denying that the glitch was a bug, Shreateh used the same glitch to hack his way onto Zuckerberg’s Facebook page. And, in a message to Zuckerberg, he wrote: “Sorry for breaking your privacy.... I had no other choice… after all the reports I sent to Facebook team.”

He also posted an image grab of this message on his blog.

Facebook responded immediately, asking him why he had hacked the page when they had fixed the bug, according to a post by Matt Jones from Facebook’s security team on Hacker News.

According to Hacker News, Shreateh had violated the terms of service by posting to Zuckerberg and Goodin’s accounts and would not be rewarded for his find.

“In order to qualify for a payout, you must make a good-faith effort to avoid privacy violations” and “use a test account instead of a real account when investigating bugs,” the Daily Mail quoted Jones as writing.

“[We] will pay out for future reports from him,” the Mail quoted Jones as saying, “if they’re found and demonstrated within these guidelines.” 

Demand for IT security experts outstrips supply

Demand for information security experts in the United States is outstripping the available supply by a widening margin, according to a pair of recently released reports.
A report from Burning Glass Technologies, which develops technologies designed to match people with jobs, shows that demand for cybersecurity professionals over the past five years grew 3.5 times faster than demand for other IT jobs and about 12 times faster than for all other jobs.
Burning Glass said its report is based on a study of job postings for cybersecurity professionals placed by U.S. businesses and government agencies over the past five years.
In 2012, there were more than 67,400 separate postings for cybersecurity-related jobs in a range of industries, including defense, financial services, retail, healthcare and professional services. The 2012 total is 73% higher than the number of security jobs posted in 2007, Burning Glass said.
By comparison, the number of job postings for all computer jobs grew by about 20% between 2007 and 2012. Postings for all jobs grew by only 6% during the period.
The two most sought-after jobs by employers were information security engineers and security analysts. Close to one in three of all computer security jobs advertised last year were for information security engineers. Nearly 25% of the job postings were for security analysts.
Demand for cybersecurity professionals was especially strong in Baltimore, Dallas, Atlanta, Denver, San Diego and Richmond, Va., Burning Glass noted.
The number of cybersecurity jobs in each of those cities increased by more than 100% between 2007 and 2012. Large defense contractors and IT firms appear to have driven the demand increases in all of the cities except Atlanta.
Matt Sigelman, CEO of Burning Glass Technologies, said the soaring demand for information security professionals suggests that enterprises and government agencies are putting a lot more money and effort into protecting their data against attacks and compromise.
"The other thing that jumps out at me is the question of whether there is sufficient supply in the market to meet this demand," Sigelman said.
For instance, over the past two years the number of jobs requiring a Certified Information Systems Security Professional (CISSP) certification has jumped from 19,000 to more than 29,000. "When you see 10,000 new job postings in a two-year period in a field that has just over 50,000 CISSPs, there is a question of availability," he said.
Another indication of the increasing difficulty U.S. employers face in finding qualified information security professionals comes from their job posting behavior. Employers typically have to repost or duplicate security job posts almost 35% more often than other IT jobs to find someone qualified, according to Burning Glass.
"Posting behavior suggests the possibility of a particular shortage of managers and analysts with cybersecurity expertise," Burning Glass noted in its report.
Julie Peeler, director of ISC2 Foundation, the developer of the CISSP program, said there is no doubt that soaring demand is exacerbating an already difficult demand and supply situation for security experts.
Ove the next year, Peeler estimated that there will be a need for 330,000 more IT security professionals worldwide. It's not clear that close to that many new professionals are graduating each year, she said.
A recent ISC2 Foundation survey of some 12,000 information security professionals worldwide found that a shortage of talent has had a dramatic impact on the ability of organizations to defend against or recover from a cyberattack.
"[The shortage] is causing a strain on the existing workforce," Peeler said. "They are having to work harder and longer hours."
More than half of the respondents to the ISC2 survey said the shortage is the ability of their organizations to defend against cyberthreats, she said.
The growing shortage has meant better salaries for information security professionals compared to many other IT jobs.
According to Burning Glass, cybersecurity jobs on average offer a premium of about $12,000 over the the average for all computer jobs -- the advertised salary for cybersecurity jobs in 2012 was $100,733 versus $89,205 for all computer jobs.
People with security certifications appeared to be getting a modestly higher salary, the Burning Glass report found. In many cases, companies appear to require security certification as a way to filter experienced candidates from the non-experienced ones, Sigelman noted.
"Demand is high, but demand in and of itself does not create opportunity" for everyone, cautioned Roger Cressey, senior vice president at Booz Allen Hamilton.
While it is true that employers are looking for more information security professionals than ever, they only want workers with long experience in areas like network security governance, policies and procedures. "You got to have the right skills set" Cressey said.
He noted that U.S. universities today are not training enough people to deal with the explosive growth in demand for IT security specialists.
Pete Lindstrom, an analyst with Spire Security, cautioned against "irrational exuberance" on the IT security job market. "The need for security professionals should not be a cause for celebration. I worry that it is more emotional reaction than warranted pragmatism