Friday, 10 January 2014

Hack or attempt to Hack, you may face 20 years in prison :-p


The Senate Judiciary Committee Chairman 'Patrick Leahy' reintroduced a revamped version of the "Personal Data Privacy and Security Act" for tough criminal penalties for hackers, that he originally authored in 2005.

During last Christmas Holidays, a massive data breach had occurred at the shopping giant Target, involving hack of 40 million credit & debit cards, used to pay for purchases at its 1500 stores nationwide in the U.S.

Reason: "Target Data Breach? Seriously"? In a statement, as published below, the Senator wrote: 

"The recent data breach at Target involving the debit and credit card data of as many as 40 million customers during the Christmas holidays is a reminder that developing a comprehensive national strategy to protect data privacy and cybersecurity remains one of the most challenging and important issues facing our Nation"
 




It seems that the TARGET Breach was scheduled, as the best opportunity to ramp up the cyber security laws against all kinds of Hackers.


Finally, on Wednesday he has re-introduced a stricter version of the "Personal Data Privacy and Security Act" bill that aims to protect Americans’ data from cyber criminals. He wrote in a statement,

"The Personal Data Privacy and Security Act will help to meet this challenge, by better protecting Americans from the growing threats of data breaches and identity theft."

In his proposal, the companies with databases containing sensitive customer information will have to adopt a 'nationwide standard' of internal policies to defend against cyber attacks. It will also provide an alert notice to all Americans users, when they have been victims of such data breach.  

No Doubt, I am also in favor to give strict sentences to the Cyber criminals who are involved in Malware related crimes, financial hacks, cyber bullying, espionage or spying, but this Bill now also covers strict sentencing for hactivists and hackers who have nothing to do with financial data. I have explained these facts about the bill as follow:


                                                  Obviously, I smell a Rat here!

New Penalty - 20 Years, rather than 10: Another most important modification is proposed to increase the maximum sentence for a first-time offender from 10 years to 20.

Cyber Criminal = Hacktivist = Anonymous = Cyber Fraud ≠ NSA: Unfortunately, this Bill will also apply to all types of hackers, who is involved in Data Breaches, Cyber Fraud activities, Identity theft, Malware developers as well as on the other hackers including Anonymous, Hacktivist etc. who is not hacking for financial benefits.

 “The bill also includes the Obama administration’s proposal to update the Computer Fraud and Abuse Act, so that attempted computer hacking and conspiracy to commit computer hacking offenses are subject to the same criminal penalties, as the underlying offenses."

 


If you haven’t forgotten the news of the Hactivist Jeremy Hammond, who was sentenced 10 years in prison under the same Computer Fraud and Abuse Act (CFAA) for hacking into private intelligence contractor Stratfor and attempting to highlight Stratfor’s work as a private intelligence firm.

He exposed Surveillance operation done by Stratfor on the political protesters at the behest of both private companies and the government. His attack was for political purpose, rather than financial.

Attempt to Hack = Successfully Hacked: If you are even planning to hack someone, then, according to this updated Bill, you are also considered as a Criminal. The Senator also proposed that the hackers who are unsuccessful in their actions are punished as severely as more accomplished ones regardless.

Considering the NSA's unethical Hacking operation? Now that’s interesting! Whistle-blowing comes under a massive crime, but spying on the whole world by the their own NSA comes under nothing from any above??






Recently, The Security researcher Jacob Appelbaum accused the NSA of illegally hacking the massive amounts of private data of users under the guise of counterterrorism. “NSA gets to do something like intercepting 7 billion people all day long with no problems. And the rest of us are not even allowed to experiment with improving the security of our own lives without being put in prison or under threat of serious indictment.” he said.

Making Laws more strict for hackers with criminal or Fraud activities is OKAY, but what about the team of hackers who are unethically hacking into world's telecommunication companies, devices or the database of Big Internet companies?

Now, this is something on what U.S Government won't give a damn look!

 


Monday, 6 January 2014

Cryptolocker Malware learned to replicate itself through removable USB drives





In the category of Ransomware Malware, a nasty piece of malware called CRYPTOLOCKER is on the top, that threatened most of the people around the world, effectively destroying important files of the victims. 

Cryptolocker, which strongly encrypts victims' hard drives until a ransom is paid, is now again back in action to haunt your digital life with an additional feature. 

Until now, CryptoLocker has been spread via spam email, with victims tempted to download an attachment or click on a link to a malicious website, but now it can spread itself as a worm through removable USB drives

Security Researchers at Trend Micro have recently reported a new variant of Cryptolocker which is capable of spreading through removable USB drives. 

Cryptolocker is a malware which locks your files and demand a ransom to release it. The files are encrypted so removing the malware from the system doesn’t unlock your files. The only way to get your files decrypted is to pay a demanded ransom amount to the criminals. 

This new cryptolocker’s version is detected as WORM_CRILOCK. A, and can infect the computers by posing as key generator or activators for paid software like Adobe Photoshop, Microsoft Office on Torrent websites. 

If CryptoLocker has already encrypted your files, then it will display a message demanding payment. Once installed on a system, it can replicate itself onto a USB drive and spread further and also if that infected system is connected to a network, the Cryptolocker work can look for other connected drives to infect them as well. 

Other malware has employed similar tactics in the past, but CryptoLocker's encryption is much more secure and is currently not possible to crack. But the new Cryptolocker didn’t use DGA (domain generation algorithm), but instead relied on hardcoded command & control center details. 

  “Further analysis of WORM_CRILOCK reveals that it has a stark difference compared to previous variants. The malware has foregone domain generation algorithm (DGA). Instead, its command-and-control (C&C) servers are hardcoded into the malware. Hardcoding the URLs makes it easier to detect and block the related malicious URLs. DGA, on the other hand, may allow cybercriminals to evade detection as it uses a large number of potential domains. This could mean that the malware is still in the process of being refined and improved upon. Thus, we can expect latter variants to have the DGA capability.”

Recommendations for users to defend against such threats:
  Users should avoid using P2P i.e. Torrent sites to get pirated copies of software and stick with official or reputable sites. Users should also be extremely careful about plugging USB drives into their computers. If you found one lying around, don't plug it in to see what may be on it.

Monday, 23 December 2013

iOS 7 Untethered Jailbreak released for iPhone, iPad, and iPod devices :)



If you love iPhone you are surely going to love this news. iOS 7 was released in 3 months before and today finally the evad3rs team has released untethered jailbreak for iPhone, iPad, and iPod devices running iOS 7.0 through iOS 7.0.4.

The evasi0n installer is compatible with Windows, Mac OS X and Linux so no matter what operating system you’re on, you should be able to jailbreak your device.

"Jailbreaking is the procedure of modifying the iOS of your iPhone to remove the limitations imposed by Apple. This allows a user to access and install a lot of new applications, software and other similar content which otherwise are not made available to iPhone users through the Apple Store."

The process is very simple, and within five minutes you can jailbreak your device. According to the instructions, iTunes must be installed if you’re running Windows and the only prerequisite is that the device should be running iOS 7.0.4.

Team advice user to backup device data before using evasi0n tool. If something breaks, you'll always be able to recover your data.

FAQ :- "Jailbreak is legal or not ?", - Yes is legal, at least in the US, a rule was passed in July 2010 by the US government made it legal so whatever you are doing with your iPhone is completely legal.

Once the installation will complete, the Cydia will appear on the home screen.

 Download Evasi0n forWindows 
 Download Evasi0n for Mac 


 


Monday, 16 December 2013

Hacker demonstrated 'Remote Code Execution' vulnerability on EBay website



According to David Vieira-Kurz discovered Remote code execution flaw "due to a type-cast issue in combination with complex curly syntax", that allows an attacker to execute arbitrary code on the EBay's web server. In a demo video, he exploited this RCE flaw on EBay website, and managed to display output of phpinfo() PHP function on the web page, just by modifying the URL and injecting code in that.

According to an explanation on his blog, he noticed a legitimate URL on EBay:

"https://sea.ebay.com/search/?q=david&catidd=1" 

..and modified the URL to pass any array values including a payload:

"https://sea.ebay.com/search/?q[0]=david&q[1]=sec{${phpinfo()}}&catidd=1"

But it is not clear at this moment that where the flaw resides on Ebay server, because how a static GET parameter can be converted to accept like an array values?





According to me, it is possible only if the 'search' page is receiving "q" parameter value using some LOOP function like "foreach()". Most probably code at the server end should be something like:

"foreach($_GET['q'] as $data)
{
        If $data is successfully able to bypass some input filter functions
    {
        eval("execute thing here with $data");
    }
 }

David has already reported the flaw responsibly to the Ebay Security Team and they have patched it early this week.

Tuesday, 10 December 2013

Rogue Android Gaming app that steals WhatsApp conversations


Google has recently removed a Rogue Android gaming app called "Balloon Pop 2" from its official Play store that was actually stealing user's private Whatsapp app conversations.

Every day numerous friends ask me if it is possible to steal WhatsApp chat messages and how, of course a malware represents an excellent solution to the request.

In the past I already posted an article on the implementation of encryption mechanisms for WhatsApp application explaining that improper design could allow attackers to snoop on the conversation. Spreading the malware through an official channel the attacker could improve the efficiency of the attack, and it is exactly what is happening, an Android game has been published on the official Google Play store to stealthy steal users’ WhatsApp conversation databases and to resell the collection of messages on an internet website.

The games titled “Balloon Pop 2” has been fortunately identified and removed from the official Google Play store, it was able to spy on conversations made via WhatsApp and upload them to the WhatsAppCopy website.

On the WhatsAppCopy website is advertised the Android game BalloonPop2 as a way of “backing up” a device’s WhatsApp conversation, it's very curious, what do think about?

The website managers sustain that their app is a legitimate game that could be used to back up WhatsApp messages, they aren't responsible for its abuse for spying purposes. The attacker paying a fee could view the stolen WhatsApp conversations from the WhatsAppCopy website, it is necessary to provide the phone number of the targeted Android device to read the private messages exchanged by the victims.

The message posted on the website states: 
"Execute our game on a mobile, whatsapp conversations are sent to this website, an hour later looking for the phone, and you can read the conversations ."

Despite the application has been immediately removed from the Google Play store there is the concrete risk that ill-intentioned will continue to distribute it through unofficial stores.

The rapid diffusion of mobile platforms and lack of defense mechanisms on almost every device make them a privileged target, the number of malicious code designed for Android and iOS is literally exploded in the next years.

Cyber criminals have also exploited official channel to spread malicious code, it is happening to the mobile version of the popular Carberp banking trojan.

The fact that an app has been published on official store it isn't sufficient to consider it reliable and secure, same consideration is valid for other mobile platforms.



Take care of your privacy, be smart!