Friday, 10 January 2014

Hack or attempt to Hack, you may face 20 years in prison :-p


The Senate Judiciary Committee Chairman 'Patrick Leahy' reintroduced a revamped version of the "Personal Data Privacy and Security Act" for tough criminal penalties for hackers, that he originally authored in 2005.

During last Christmas Holidays, a massive data breach had occurred at the shopping giant Target, involving hack of 40 million credit & debit cards, used to pay for purchases at its 1500 stores nationwide in the U.S.

Reason: "Target Data Breach? Seriously"? In a statement, as published below, the Senator wrote: 

"The recent data breach at Target involving the debit and credit card data of as many as 40 million customers during the Christmas holidays is a reminder that developing a comprehensive national strategy to protect data privacy and cybersecurity remains one of the most challenging and important issues facing our Nation"
 




It seems that the TARGET Breach was scheduled, as the best opportunity to ramp up the cyber security laws against all kinds of Hackers.


Finally, on Wednesday he has re-introduced a stricter version of the "Personal Data Privacy and Security Act" bill that aims to protect Americans’ data from cyber criminals. He wrote in a statement,

"The Personal Data Privacy and Security Act will help to meet this challenge, by better protecting Americans from the growing threats of data breaches and identity theft."

In his proposal, the companies with databases containing sensitive customer information will have to adopt a 'nationwide standard' of internal policies to defend against cyber attacks. It will also provide an alert notice to all Americans users, when they have been victims of such data breach.  

No Doubt, I am also in favor to give strict sentences to the Cyber criminals who are involved in Malware related crimes, financial hacks, cyber bullying, espionage or spying, but this Bill now also covers strict sentencing for hactivists and hackers who have nothing to do with financial data. I have explained these facts about the bill as follow:


                                                  Obviously, I smell a Rat here!

New Penalty - 20 Years, rather than 10: Another most important modification is proposed to increase the maximum sentence for a first-time offender from 10 years to 20.

Cyber Criminal = Hacktivist = Anonymous = Cyber Fraud ≠ NSA: Unfortunately, this Bill will also apply to all types of hackers, who is involved in Data Breaches, Cyber Fraud activities, Identity theft, Malware developers as well as on the other hackers including Anonymous, Hacktivist etc. who is not hacking for financial benefits.

 “The bill also includes the Obama administration’s proposal to update the Computer Fraud and Abuse Act, so that attempted computer hacking and conspiracy to commit computer hacking offenses are subject to the same criminal penalties, as the underlying offenses."

 


If you haven’t forgotten the news of the Hactivist Jeremy Hammond, who was sentenced 10 years in prison under the same Computer Fraud and Abuse Act (CFAA) for hacking into private intelligence contractor Stratfor and attempting to highlight Stratfor’s work as a private intelligence firm.

He exposed Surveillance operation done by Stratfor on the political protesters at the behest of both private companies and the government. His attack was for political purpose, rather than financial.

Attempt to Hack = Successfully Hacked: If you are even planning to hack someone, then, according to this updated Bill, you are also considered as a Criminal. The Senator also proposed that the hackers who are unsuccessful in their actions are punished as severely as more accomplished ones regardless.

Considering the NSA's unethical Hacking operation? Now that’s interesting! Whistle-blowing comes under a massive crime, but spying on the whole world by the their own NSA comes under nothing from any above??






Recently, The Security researcher Jacob Appelbaum accused the NSA of illegally hacking the massive amounts of private data of users under the guise of counterterrorism. “NSA gets to do something like intercepting 7 billion people all day long with no problems. And the rest of us are not even allowed to experiment with improving the security of our own lives without being put in prison or under threat of serious indictment.” he said.

Making Laws more strict for hackers with criminal or Fraud activities is OKAY, but what about the team of hackers who are unethically hacking into world's telecommunication companies, devices or the database of Big Internet companies?

Now, this is something on what U.S Government won't give a damn look!

 


Monday, 6 January 2014

Cryptolocker Malware learned to replicate itself through removable USB drives





In the category of Ransomware Malware, a nasty piece of malware called CRYPTOLOCKER is on the top, that threatened most of the people around the world, effectively destroying important files of the victims. 

Cryptolocker, which strongly encrypts victims' hard drives until a ransom is paid, is now again back in action to haunt your digital life with an additional feature. 

Until now, CryptoLocker has been spread via spam email, with victims tempted to download an attachment or click on a link to a malicious website, but now it can spread itself as a worm through removable USB drives

Security Researchers at Trend Micro have recently reported a new variant of Cryptolocker which is capable of spreading through removable USB drives. 

Cryptolocker is a malware which locks your files and demand a ransom to release it. The files are encrypted so removing the malware from the system doesn’t unlock your files. The only way to get your files decrypted is to pay a demanded ransom amount to the criminals. 

This new cryptolocker’s version is detected as WORM_CRILOCK. A, and can infect the computers by posing as key generator or activators for paid software like Adobe Photoshop, Microsoft Office on Torrent websites. 

If CryptoLocker has already encrypted your files, then it will display a message demanding payment. Once installed on a system, it can replicate itself onto a USB drive and spread further and also if that infected system is connected to a network, the Cryptolocker work can look for other connected drives to infect them as well. 

Other malware has employed similar tactics in the past, but CryptoLocker's encryption is much more secure and is currently not possible to crack. But the new Cryptolocker didn’t use DGA (domain generation algorithm), but instead relied on hardcoded command & control center details. 

  “Further analysis of WORM_CRILOCK reveals that it has a stark difference compared to previous variants. The malware has foregone domain generation algorithm (DGA). Instead, its command-and-control (C&C) servers are hardcoded into the malware. Hardcoding the URLs makes it easier to detect and block the related malicious URLs. DGA, on the other hand, may allow cybercriminals to evade detection as it uses a large number of potential domains. This could mean that the malware is still in the process of being refined and improved upon. Thus, we can expect latter variants to have the DGA capability.”

Recommendations for users to defend against such threats:
  Users should avoid using P2P i.e. Torrent sites to get pirated copies of software and stick with official or reputable sites. Users should also be extremely careful about plugging USB drives into their computers. If you found one lying around, don't plug it in to see what may be on it.

Monday, 23 December 2013

iOS 7 Untethered Jailbreak released for iPhone, iPad, and iPod devices :)



If you love iPhone you are surely going to love this news. iOS 7 was released in 3 months before and today finally the evad3rs team has released untethered jailbreak for iPhone, iPad, and iPod devices running iOS 7.0 through iOS 7.0.4.

The evasi0n installer is compatible with Windows, Mac OS X and Linux so no matter what operating system you’re on, you should be able to jailbreak your device.

"Jailbreaking is the procedure of modifying the iOS of your iPhone to remove the limitations imposed by Apple. This allows a user to access and install a lot of new applications, software and other similar content which otherwise are not made available to iPhone users through the Apple Store."

The process is very simple, and within five minutes you can jailbreak your device. According to the instructions, iTunes must be installed if you’re running Windows and the only prerequisite is that the device should be running iOS 7.0.4.

Team advice user to backup device data before using evasi0n tool. If something breaks, you'll always be able to recover your data.

FAQ :- "Jailbreak is legal or not ?", - Yes is legal, at least in the US, a rule was passed in July 2010 by the US government made it legal so whatever you are doing with your iPhone is completely legal.

Once the installation will complete, the Cydia will appear on the home screen.

 Download Evasi0n forWindows 
 Download Evasi0n for Mac 


 


Monday, 16 December 2013

Hacker demonstrated 'Remote Code Execution' vulnerability on EBay website



According to David Vieira-Kurz discovered Remote code execution flaw "due to a type-cast issue in combination with complex curly syntax", that allows an attacker to execute arbitrary code on the EBay's web server. In a demo video, he exploited this RCE flaw on EBay website, and managed to display output of phpinfo() PHP function on the web page, just by modifying the URL and injecting code in that.

According to an explanation on his blog, he noticed a legitimate URL on EBay:

"https://sea.ebay.com/search/?q=david&catidd=1" 

..and modified the URL to pass any array values including a payload:

"https://sea.ebay.com/search/?q[0]=david&q[1]=sec{${phpinfo()}}&catidd=1"

But it is not clear at this moment that where the flaw resides on Ebay server, because how a static GET parameter can be converted to accept like an array values?





According to me, it is possible only if the 'search' page is receiving "q" parameter value using some LOOP function like "foreach()". Most probably code at the server end should be something like:

"foreach($_GET['q'] as $data)
{
        If $data is successfully able to bypass some input filter functions
    {
        eval("execute thing here with $data");
    }
 }

David has already reported the flaw responsibly to the Ebay Security Team and they have patched it early this week.