Author Topic: Internet Vulnerability & Exploits  (Read 1889 times)

reDEEMed

  • Subordinate Wasp
  • ***
  • Posts: 202
Re: Internet Security & Exploits.
« Reply #60 on: August 21, 2011, 03:18:06 AM »
Nice one here: US court test for rights not to hand over encryption keys. http://www.theregister.co.uk/2011/07/13/eff_piles_in_against_forced_decryption/

I was wondering, how hard would it be to natively support encrypted private messages here the way they do at the shroomery? Is that even a possibility, or would one need to share a key and do it all manually? That would be nice considering there are some security concerns around our private messages.
"Ego is a structure that is erected by a neurotic individual who is a member of a neurotic culture against the facts of the matter. And culture, which we put on like an overcoat, is the collectivized consensus about what sort of neurotic behaviors are acceptable."
— Terence McKenna

Wizard X

  • Lord of the Realms
  • Foundress Queen
  • *****
  • Posts: 1,224
Re: Internet Security & Exploits.
« Reply #61 on: August 27, 2011, 03:29:31 AM »
Browsing and Privacy: How to Not Get Tracked. http://www.cio.com/article/688362/Browsing_and_Privacy_How_to_Not_Get_Tracked?source=cwartsnip

A researcher at Stanford University recently found that Microsoft (MSFT) has been using an online tracking technology that allowed the company to sneakily track users on MSN.com even though it had used some of the standard techniques developed to avoid tracking.

Yale warns 43,000 about 10-month-long data breach. http://www.computerworld.com/s/article/9219369/Yale_warns_43_000_about_10_month_long_data_breach?taxonomyId=17

China yanks video that leaked hacking tool. http://www.computerworld.com/s/article/9219538/China_yanks_video_that_leaked_hacking_tool?taxonomyId=17
The video appeared to show a Chinese DDOS tool: http://www.youtube.com/watch?v=L_Wu1HlZbBk
Albert Einstein - "Great ideas often receive violent opposition from mediocre minds."

Wizard X

  • Lord of the Realms
  • Foundress Queen
  • *****
  • Posts: 1,224
Re: Internet Security & Exploits.
« Reply #62 on: September 12, 2011, 12:43:17 AM »
Albert Einstein - "Great ideas often receive violent opposition from mediocre minds."

Wizard X

  • Lord of the Realms
  • Foundress Queen
  • *****
  • Posts: 1,224
Re: Internet Security & Exploits.
« Reply #63 on: September 17, 2011, 11:02:27 PM »
Malware burrows deep into computer BIOS to escape AV. http://www.theregister.co.uk/2011/09/14/bios_rootkit_discovered/

Known as Trojan.Mebromi, the rootkit reflashes the BIOS of computers it attacks to add malicious instructions that are executed early in a computer's boot-up sequence. The instructions, in turn, alter a computer's MBR, or master boot record, another system component that gets executed prior to the loading of the operating system of an infected machine. By corrupting the processes that run immediately after a PC starts, the malware stands a better chance of surviving attempts by antivirus programs to remove it.

PCI point-to-point encryption guidelines raise new questions. http://www.computerworld.com/s/article/9220039/PCI_point_to_point_encryption_guidelines_raise_new_questions?taxonomyId=17

DHS seeks to share top-secret info with banking and finance cybersecurity pros. http://www.networkworld.com/news/2011/091511-homeland-security-banking-250924.html

Researcher discloses zero-day flaws in SCADA systems. http://www.computerworld.com/s/article/9220099/Researcher_discloses_zero_day_flaws_in_SCADA_systems?taxonomyId=17

Man stole data from US service members via P2P. http://www.networkworld.com/news/2011/091611-man-stole-data-from-us-250967.html
Albert Einstein - "Great ideas often receive violent opposition from mediocre minds."

Wizard X

  • Lord of the Realms
  • Foundress Queen
  • *****
  • Posts: 1,224
Albert Einstein - "Great ideas often receive violent opposition from mediocre minds."

Wizard X

  • Lord of the Realms
  • Foundress Queen
  • *****
  • Posts: 1,224
Re: Internet Security & Exploits.
« Reply #65 on: September 27, 2011, 02:30:37 AM »
Facebook has denied that it tracks its users' web surfing even when they are logged out, saying it only uses tracking cookies to personalise content and to make the site more secure.

Australian technologist Nik Cubrilovic this week accused Facebook of using cookies to track users when they are logged off from the service.

http://www.smh.com.au/technology/technology-news/facebook-euthanising-privacy-but-denies-tracking-users-20110927-1kucc.html


The problem is that Facebook already has privacy issues, not least of which is the face identification software recently installed, which has some real security implications for users, particularly those who don’t want to be that easy to find.

http://digitaljournal.com/article/311960
Albert Einstein - "Great ideas often receive violent opposition from mediocre minds."

Wizard X

  • Lord of the Realms
  • Foundress Queen
  • *****
  • Posts: 1,224
Albert Einstein - "Great ideas often receive violent opposition from mediocre minds."

Wizard X

  • Lord of the Realms
  • Foundress Queen
  • *****
  • Posts: 1,224
Re: Internet Security & Exploits.
« Reply #67 on: October 08, 2011, 11:30:39 PM »
Albert Einstein - "Great ideas often receive violent opposition from mediocre minds."

Wizard X

  • Lord of the Realms
  • Foundress Queen
  • *****
  • Posts: 1,224
Re: Internet Security & Exploits.
« Reply #68 on: October 15, 2011, 09:14:01 PM »
Albert Einstein - "Great ideas often receive violent opposition from mediocre minds."

Wizard X

  • Lord of the Realms
  • Foundress Queen
  • *****
  • Posts: 1,224
Re: Internet Security & Exploits.
« Reply #69 on: October 23, 2011, 12:00:17 AM »
Breach reporting: Now companies have to do it. http://www.networkworld.com/columnists/2011/101711-bradner.html

U.S. lawmakers push to limit gov't mobile tracking. http://www.computerworld.com/s/article/9220960/U.S._lawmakers_push_to_limit_gov_t_mobile_tracking?taxonomyId=17

DDoS and SQL injection are main topics on hacking forums. http://www.computerworld.com/s/article/9220954/DDoS_and_SQL_injection_are_main_topics_on_hacking_forums?taxonomyId=17

Researchers discover keyboard keylogger attack via iPhone. http://www.networkworld.com/news/2011/101811-keylogger-iphone-252123.html

Massive SQL injection attack has compromised nearly 200,000 ASP.Net sites. http://www.networkworld.com/news/2011/101911-sql-injection-attack-252188.html

German federal Trojan eavesdrops on 15 applications, experts find. http://www.networkworld.com/news/2011/101911-german-federal-trojan-eavesdrops-on-252153.html
A Trojan used by German law enforcement authorities to intercept Internet phone calls is capable of monitoring traffic from 15 programs, including browsers and instant messaging applications.
http://www.securelist.com/en/blog/208193167/Federal_Trojan_s_got_a_Big_Brother

Google adds default end-to-end encryption to search. http://www.theregister.co.uk/2011/10/19/google_default_ssl/

Despite Stuxnet, Duqu, control system flaws still overlooked. http://www.computerworld.com/s/article/9221065/Despite_Stuxnet_Duqu_control_system_flaws_still_overlooked_?taxonomyId=17
Albert Einstein - "Great ideas often receive violent opposition from mediocre minds."

fresh1

  • conspirator
  • Dominant Queen
  • ****
  • Posts: 339
Re: Internet Security & Exploits.
« Reply #70 on: October 29, 2011, 07:52:16 AM »
  A f(r)iend was recently running a hacked and patched win 7 OS, and had non operational AVG, on his computer,(other anti virus software was running) BUT......

  When he went online, LUCKILY, he was watching his task manager, as well as his wireless modems speed, and noticed a huge amount (120mb) of data coming in, at a rapid rate, as well as about 20kb of data was 'sent'!!!

  Freaking out, he shut down his computa and had a look at what had come in.....WHOA!!! 15 pages of NASTY code had come from MS via an AVG 'backdoor' as Updates!!!

  Fortunately he saw it coming, UNfortunately, that computa is now unable to be used for ANYTHING but a "library",, NO WAY can he safely go online with it, requiring the purchase of a NEW computa!!!

  It was  a trojan/worm which turned Half of his music and film files into "rar" files which are now unreadable, as well as sending his IP, email addys and god knows what else, to Microshit!!!

  There was no way to stop it other than going offline AND deleting the code BEFORE it could 'update & DESTROY' much of his data.

  I suppose the lesson learned is that MS are more than happy to use open source 'backdoors' to punish those they feel have stolen from them,,the WORST part was, that they compressed music and video files that were completely legit,
having been bought from genuine sources, e.g. Genuine CD/DVD's!!!

 After seeing the code, all I can say it was very sophisticated, and VERY NASTY!!!

 This guy loves to 'play' and his hacking days are effectively long past, he was just dicking with win7 for a bit of fun!!
although I doubt he will do so again!!!

 Anyone else have similar probs?

 Regars  F1 ;)
"Curiosity is a gift"

Vesp

  • Administrator
  • Foundress Queen
  • *****
  • Posts: 3,130
Re: Internet Security & Exploits.
« Reply #71 on: October 29, 2011, 08:00:33 AM »
"  Fortunately he saw it coming, UNfortunately, that computa is now unable to be used for ANYTHING but a "library",, NO WAY can he safely go online with it, requiring the purchase of a NEW computa!!!"

Neither of you know very much about computers, I suspect?
Why not just re-install the operating system? Or better yet if he hacks, actually use an OS that is built for hacking; Backtrack 5, for instance. Or just use Ubuntu 10.04 TLS if he wants it as a useful desktop.
Bitcoin address: 1FVrHdXJBr6Z9uhtiQKy4g7c7yHtGKjyLy

fresh1

  • conspirator
  • Dominant Queen
  • ****
  • Posts: 339
Re: Internet Security & Exploits.
« Reply #72 on: October 29, 2011, 08:47:28 AM »
  You are right about a reinstall, but as i said, considering it was a patched 32bit win7 there IS no disc to "re install" it from, for the disc it WAS installed from, has now been cracked by MS.
 The reason for NOT using the same computa is a little more involved than that, but from what he told me, he was unable to stop the data from entering, and IMO he's not stupid, just a little careless!

   Its pretty clear if you saw the code, I cannot remember much of the specifics, it was about a month ago, but if Kaspersky have been finding similar, I dont think you could fairly say,"its "basic"!!!

  And I am no hacker, as I have far too many other things to interest me, no offence intended at all, and I have NO doubt your skills vesp, in this area ARE much better than his, and light years beyond mine!!!
  Also it seems MS want to force people into Buying software to open said rar. files, yes there is "free" software to do the job, but do you REALLy think MS is going to go about countering "software piracy" in a 'Nice' way?
  I do appreciate Wizard X's numerous posts, but it really is a full time job,to try and stay up to date with cyberland :P


 
"Curiosity is a gift"

lugh

  • Global Moderator
  • Foundress Queen
  • *****
  • Posts: 876
Re: Internet Security & Exploits.
« Reply #73 on: October 29, 2011, 09:09:57 PM »
You can boot the computer with a Linux boot disk and recover the data as was said in:

http://127.0.0.1/talk/index.php/topic,2450.msg24866.html#msg24866

some useful links:

h**p://www.hiren.info/pages/bootcd

h**p://www.tux.org/pub/people/kent-robotti/looplinux/rip/

h**p://wiki.centos.org/Manuals/ReleaseNotes/CentOSLiveCD5.6

h**p://ubcd.sourceforge.net/

h**p://www.backtrack-linux.org/

h**p://www.archlinux.org/

h**p://www.linuxfromscratch.org/livecd/

as was already mentioned, open source software can help solve your friend's problems  8)



« Last Edit: October 30, 2011, 12:33:55 AM by lugh »
Chemistry is our Covalent Bond

Wizard X

  • Lord of the Realms
  • Foundress Queen
  • *****
  • Posts: 1,224
Re: Internet Security & Exploits.
« Reply #74 on: October 30, 2011, 04:28:41 AM »
Albert Einstein - "Great ideas often receive violent opposition from mediocre minds."

fresh1

  • conspirator
  • Dominant Queen
  • ****
  • Posts: 339
Re: Internet Security & Exploits.
« Reply #75 on: October 31, 2011, 11:06:25 AM »
  thanx lugh, I've never used linux but maybe its time to learn! I definitely like open source software 8)

 wixard x I wish I had your skills.....sigh ??? maybe in a decade or so!

 F1 ;)
"Curiosity is a gift"

Wizard X

  • Lord of the Realms
  • Foundress Queen
  • *****
  • Posts: 1,224
Re: Internet Security & Exploits.
« Reply #76 on: November 06, 2011, 11:14:30 PM »
Albert Einstein - "Great ideas often receive violent opposition from mediocre minds."

Wizard X

  • Lord of the Realms
  • Foundress Queen
  • *****
  • Posts: 1,224
Re: Internet Security & Exploits.
« Reply #77 on: November 12, 2011, 04:23:39 AM »
Albert Einstein - "Great ideas often receive violent opposition from mediocre minds."

Sedit

  • Global Moderator
  • Foundress Queen
  • *****
  • Posts: 2,099
Re: Internet Security & Exploits.
« Reply #78 on: November 13, 2011, 03:01:07 PM »
Sound like the Botnets that participated in the freeze up of the Estonian government a while back. Just one more member of Lulzsec down. There tactics are to week for them, they seem to have way to little understanding of security to be laughing at it the way they do. There track record of covering there ass has been rather poor to date.

Have they not heard of TOR for fuck sake? Why would you route your traffic through Hidemyass.com WTF where they thinking?
There once were some bees and you took all there stuff!
You pissed off the wasp now enough is enough!!!

Wizard X

  • Lord of the Realms
  • Foundress Queen
  • *****
  • Posts: 1,224
Re: Internet Security & Exploits.
« Reply #79 on: December 08, 2011, 11:04:04 PM »
Albert Einstein - "Great ideas often receive violent opposition from mediocre minds."