Showing posts with label hack. Show all posts
Showing posts with label hack. Show all posts
Tuesday, November 15, 2011
HACKERS GET SIRI WORKING ON ANY DEVICE
A group of developers from Applidium posted a story recently that explains how the group was able to crack Siri so that they could run the virtual assistant on any device. Basically, the group was able to get Siri to analyze voice inputs that were never spoken through an iPhone. It turns out Siri uses TCP to speak to a server at 17.174.4.4 using port 443. Applidium then logged on to a desktop computer, entered in that IP address, and realized that Apple was returning a server named “guzzoni.apple.com” and that Siri was using HTTPS as its protocol. Putting it simply, the group then created a fake guzzoni.apple.com address and tricked Siri into sending commands there instead of to Apple’s own server. Applidium discovered that Siri sends Apple a time stamp for each word spoken, as well as a reply confidence score, and described the software as “very, very chatty.” It is possible to get the software working on an Android device, or any similar gadget, but you’ll need at least one iPhone 4S identifier and some coding know-how. The hackers published a set of tools that it says can be used by anyone to create Siri-enabled applications and is encouraging fellow hackers to try the tools out and see what they can develop. “And let’s see how long it’ll take Apple to change their security scheme,” the group jested.
Friday, November 11, 2011
STEAM HACKED, USER DATABASE ACCESSED
Valve has taken the Steam Forums offline and Gabe Newell has posted a message explaining that Steam has been hacked.
On Sunday, the Steam Forums were defaced, but remained online. However, further investigation found the hack was more than just for the forum software, the intruder had also gained access to a Steam user database. On that database is the following information for customers of the digital gaming service:
Valve is going to force everyone to change their Steam Forum password when they decide to bring them back online as a security measure. Gabe has also apologized for what has happened and the inconvenience it is causing.
If you are one of the millions of Steam account holders out there, then be cautious and watch your credit card activity. If you shared your Steam Forum password with other services you use, then go change the password on those services immediately.
On Sunday, the Steam Forums were defaced, but remained online. However, further investigation found the hack was more than just for the forum software, the intruder had also gained access to a Steam user database. On that database is the following information for customers of the digital gaming service:
- Usernames
- Hashed and salted passwords
- List of game purchases per user
- E-mail addresses
- Billing addresses
- Encrypted credit card details
Valve is going to force everyone to change their Steam Forum password when they decide to bring them back online as a security measure. Gabe has also apologized for what has happened and the inconvenience it is causing.
If you are one of the millions of Steam account holders out there, then be cautious and watch your credit card activity. If you shared your Steam Forum password with other services you use, then go change the password on those services immediately.
Monday, October 17, 2011
SESAME STREET YOUTUBE CHANNEL HACKED
Children hoping to watch Sesame Street on YouTube on Sunday were greeted with quite the opposite. The channel was hacked, all videos deleted, design modified and graphic porn uploaded. It took Google around 22 minutes to pull the content down and close the channel but even now, search results for Sesame Street on YouTube reveals the occasional graphic thumbnail. It was believed that a hacker using the name Mr. Edxwx on Reddit was behind this, since the name on the YouTube channel was changed to Mr Edxwx, however that person has stated he had nothing to do with this hack.
Labels:
channel,
Google,
hack,
pornography,
sesame street,
youtube
Friday, August 5, 2011
RESEARCHERS WORRIED ABOUT HACKERS ATTACKING WIRELESS INSULIN PUMPS
If the recent news of hackers hitting Apple's new line of Macbook batteries with the potential to make them explode, or the Subaru unlock and start hack with a text message wasn't enough to scare you, now researchers are worrying about medical devices.
At the recent Blackhat security conference researcher and diabetic Jay Radcliffe pondered about the ability of hackers to gain access to wireless glucose meters attached to insulin pumps and deliver a lethal dose.
Radcliffe hasn't figured out how to this...yet, but in theory a hacker with a big enough antenna could be up to half a mile away when the hack occurs.
Labels:
blackhat,
devices,
hack,
insulin pump,
jay radcliffe,
medical
Thursday, June 30, 2011
UNIVERSAL AND VIACOM HACKED LEAKING USERS PASSWORDS AND INFORMATION; ANTISEC CLAIMS RESPONSIBILITY
A hacking group named LulzSec made headlines recently for attacking high visibility targets, including Sony and the U.S. government. LulzSec announced earlier this week that it was stopping its operations, and rumor has it many of the members joined up with Anonymous’ “AntiSec” hacking group. Now that group is making its own headlines. On Tuesday AntiSec claimed responsibility for attacks against Universal and Viacom.
According to The Wall Street Journal, the hackers released personal data, including passwords, from the Universal Music Website. It also obtained and leaked information about Viacom’s network. It’s unclear how many users were affected by the security breach, although we hope to hear an official word from both firms in the near future.
Sunday, June 26, 2011
LULZSEC CALLS IT QUITS
After 50 days of wreaking cyber-caper havoc, Lulz Security says it's done and will sail into the horizon. The group has stolen mountains of personal data in a dozen different hacks, embarrassing law enforcement on both sides of the Atlantic while boasting about the stunts online.
The group's disbandment comes unexpectedly, and could be a sign of nerves in the face of law enforcement investigations. Rival hackers have also joined in the hunt, releasing information they say could point to the identities of the six-member group. One of the group's six members was interviewed by The Associated Press on Friday, and gave no indication that its work was ending.
LulzSec made its name by defacing the site of the U.S. Public Broadcasting Service, or PBS, with an article claiming that rapper Tupac Shakur was still alive. It has since claimed hacks on major entertainment companies, FBI partner organizations, a pornography website and the Arizona Department of Public Safety, whose documents were leaked to the Web late Thursday.
The hacking group stated "For the past 50 days we've been disrupting and exposing corporations, governments, often the general population itself, and quite possibly everything in between, just because we could," the LulzSec statement said. "All to selflessly entertain others — vanity, fame, recognition, all of these things are shadowed by our desire for that which we all love. The raw, uninterrupted, chaotic thrill of entertainment and anarchy. While we are responsible for everything that The Lulz Boat is, we are not tied to this identity permanently. The breeze is fresh and the sun is setting, so now we head for the horizon."
As a parting shot, LulzSec released a grab-bag of documents and login information apparently gleaned from gaming websites and corporate servers. The largest group of documents — 338 files — appears to be internal documents from AT&T Inc., detailing its buildout of a new wireless broadband network in the U.S. The network is set to go live this summer. An AT&T spokesman could not immediately confirm the authenticity of the documents.
Friday, June 24, 2011
HACKER PLEADS GUILTY IN AT&T iPAD BREACH
Nearly six months after his arrest, one hacker pleaded guilty to charges that he exposed the email addresses of over 100,000 AT&T iPad 3G users. It's been a year since Daniel Spitler and his compatriot, Andrew Auernheimer, coaxed Ma-Bell servers into delivering the goods, with a brute force script they lovingly named the iPad 3G Account Slurper. The hacker's plea agreement suggests a 12 to 18-month sentence, which is a lot more lenient than the 10-year maximum we hear he could face. Spitler's collaborator is apparently still in plea negotiations with the prosecutor. Both men initially claimed they were just trying to draw attention to a security hole, but maybe next time they'll think twice before embarking on such altruistic endeavors.
Wednesday, June 22, 2011
LULZSEC DENIES LEADER ARRESTED
There are numerous reports claiming that the leader of the now infamous hacking group LulzSec has been arrested in the United Kingdom. According to London’s Metropolitan Police, the shadowy leader was a 19-year old responsible for hacking “a number of international businesses and intelligence agencies.” The group took responsibility for Sony’s recent massive security breach and has also targeted a number of high-visibility websites, including that of the Central Intelligence Agency, and has waged war on the U.S. government with another group dubbed Anonymous.
Despite the reports, however, LulzSec has denied that any of its members have been arrested. Early Tuesday morning the group tweeted: “Seems the glorious leader of LulzSec got arrested, it’s all over now… wait… we’re all still here! Which poor bastard did they take down?”
Labels:
anonymous,
arrest,
battle computer,
cia,
hack,
hacker,
hacking,
infiltrate,
london,
lulzsec,
metropolitan police,
Sony
Monday, June 20, 2011
SEGA'S ONLINE PASS HACKED, PASSWORDS STOLEN
Sega Pass suffered a breach of its defenses on Thursday, which has now been identified to have affected a whopping 1.29 million users. Usernames, real names, birth dates, passwords, email addresses, pretty much everything has been snatched up by the malicious data thieves, with the important exception of credit / debit card numbers. We'd still advise anyone affected to keep a watchful eye on his or her banking transactions -- immediately after changing that compromised password, of course. In the meantime, Sega's keeping the Pass service offline while it rectifies the vulnerability; it'll be able to call on an unexpected ally in its search for the perpetrators in the form of LulzSec, a hacker group that boasted proudly about infiltrating Sony's network, but which has much more benevolent intentions with respect to Sega.
Labels:
hack,
lulzsec,
offline,
online gaming,
sega pass
Friday, June 10, 2011
CITIGROUP HACKED, ACCOUNTS COMPROMISED
On Thursday Citigroup announced that hackers had breached its systems in May and accessed personal data from 200,000 accounts — about 1% of its customers. The hackers managed to steal customer email addresses, contact information and account numbers, but Reuters reported that other information such as birth dates, Social Security Numbers and credit card expiration dates were not accessed. “We are contacting customers whose information was impacted. Citi has implemented enhanced procedures to prevent a recurrence of this type of event,” Citigroup spokesperson Sean Kevelighan, said. “For the security of these customers, we are not disclosing further details.”
Tuesday, June 7, 2011
SONY BRAZIL SITE HACKED
The list of hacked Sony properties continues to grow as Sony Music Brazil finds its website the latest victim in a long line of breaches. The company’s website was the target of a cyberattack on Saturday night and nearly 36 hours later, the site is still offline. Initially, the hackers defaced the site with a single page titled “Hacked The UnderTaker,” which apparently contained nicknames of several people responsible for the attack. More than 12 hours later, the website was finally taken offline. Sony Music Brazil has not commented on the breach and it is unclear if any private data was exposed.
Friday, June 3, 2011
SONY PICTURES WEBSITE HACKED; 1 MILLION ACCOUNTS COMPROMISED
Hackers from a group called LulzSec announced on Thursday that they had breached sonypictures.com, the website belonging to Sony-owned studio Sony Pictures. The group claims to have compromised personal information belonging to over 1 million users, including user names, passwords, home addresses, dates of birth and other sensitive data.
The group also claims to have accessed 75,000 “music codes” and 3.5 million “music coupons.” LulzSec says it employed a simple SQL injection technique to access the data, and that Sony Pictures’ site was not secure and was therefore easy to breach.
The hackers did not have the resources to download all of the exposed data, but they say they did obtain samples in order to prove the authenticity of the attack.
This is the fourth breach of a Sony owned property in the last two months. The most famous being the Sony Playstation Network. Sony was forced to bring the site down while additional security measures were put in place.
Labels:
breach,
compromised,
hack,
lulzsec,
Sony,
sony pictures
Thursday, June 2, 2011
GOOGLE ADMITS SOME SENSITIVE EMAILS HACKED; BLAMES CHINA
The Contagio security blog posted evidence back in February of targeted attacks against government and military officials on Gmail. Today, nearly four months later, Google has finally admitted this is true: hundreds of personal accounts have been compromised by hackers it believes to be working out of Jinan, the capital of China's Shandong province.
The accounts include those of "senior U.S. government officials, Chinese political activists, officials in several Asian countries (predominantly South Korea), military personnel and journalists." The hijackers' aim appears to have been to spy on their targets using Google's automatic forwarding function. But unlike the PSN fiasco, Google insists its internal systems "have not been affected." Instead it seems the hackers used a phishing scam, possibly directing users to a spoof Gmail website before requesting their credentials.
Google says its own "abuse detection systems" disrupted the campaign -- but in a footnote right down at the bottom of their official blog page they also credit Contagio and user reports.
China's Foreign Minister, Hong Lei responded with a statement saying "Allegations that the Chinese government supports hacking activities are completely unfounded and made with ulterior motives."
Saturday, May 28, 2011
DEFENSE CONTRACTOR LOCKHEED MARTIN INVESTIGATING SECURITY BREACH
Lockheed Martin is one of the US Department of Defense‘s largest contractors, and the biggest provider of technology services to the government overall. Now, word is trickling out from unnamed sources close to the company that Lockheed Martin’s internal technology team is working overtime to combat major network issues that could be related to a security breach.
It’s important to note that the issues haven’t been confirmed as a hack or security issue as of yet, but if the issues do turn out to be security related, it could be a very serious problem for the Pentagon and the US government as a whole. Lockheed Martin is the company behind a number of high-tech, classified government progrmas, like the F-22 Raptor fighter/bomber: the US Air Force’s next generation air superiority fighter. (Lockheed Martin is also the company behind the famous-but-now-decommissioned SR-71 Blackbird spy jet, which once held the record for fastest manned jet aircraft.)
Lockheed Martin is also the parts and technology manufacturer behind a number of other weapons systems already deployed in conflicts around the globe and at sea, and a major technology partner in a number of NASA’s space exploration projects, like the Phoenix Mars Lander and the Mars Global Surveyor. Reuters reports that Lockheed Martin has notified the Pentagon of its network issues, and has already advised Pentagon officials with access to information shared with Lockheed Martin to take steps like changing their passwords. Lockheed Martin employees have already been advised to take the same steps to protect their own security.
Labels:
department of defense,
f-22,
fighter,
hack,
lockheed martin,
security breach,
us,
weapons
Friday, May 27, 2011
PLAYSTATION NETWORK RETURNING TO ASIA TOMORROW SAYS SONY
Good news, Asia -- the PlayStation Network is finally coming back. Today, Sony announced that it will restore its gaming network across the continent, more than a month after falling prey to a crippling data breach. The company's PSN services are already up and running across other parts of the world and, beginning tomorrow, will light up once again in Taiwan, Singapore, Malaysia, Indonesia, Thailand and even Japan, which had been harboring serious reservations about the network's security. Gamers in South Korea and Hong Kong, meanwhile, will have to wait a little longer before returning to normalcy, though Sony is hoping to completely resolve the issue by the end of the month. The company certainly seems eager to put this saga to bed, and for understandable reasons. The incident has already cost Sony an estimated $171 million in revenue -- not to mention the untold numbers of suddenly wary consumers.
Thursday, May 26, 2011
SONY'S HACKING NIGHTMARE CONTINUES
Sony continues to be targeted in a series of cyberattacks that have resulted in the theft of personal information belonging to over 100 million Sony customers. Following breaches of the company’s PlayStation Network, Sony Online Entertainment, So-net Entertainment and most recently, the Sony’s Greek website, hackers have breached a database associated with Sony Ericsson’s Canadian online shop.
Personal data including names, email addresses and passwords belonging to more than 2,000 customers was compromised, but Sony said no credit card numbers were stolen. A Lebanese hacking group called Idahca claimed responsibility for the attack, and it said the information obtained has been leaked on Facebook and Twitter.
It is unclear if this latest attack is tied in any way to previous attacks on Sony’s various digital properties.
Labels:
breach,
hack,
personal data,
Sony,
Sony Ericsson
Tuesday, May 24, 2011
SONY BMG GREECE HACKED
It's the security nightmare that just won't end, and right now there's got to be plenty of Sony executives beginning to wish someone would pinch them already. After taking quite a PR and financial beating over the PSN breach, now the Greek site of Sony BMG has been hacked and the account info of thousands of users has been posted online.
According to the Sophos blog Naked Security, the attack does not appear to have been particularly sophisticated and was carried out using an automated SQL injection tool that demands more patience than skill. While the data dump reveals the usernames, real names, and email addresses of registered SonyMusic.gr customers, other fields (including passwords and telephone numbers) are either empty or contain fake data, suggesting the hack was not entirely successful.
Sunday, May 15, 2011
SONY BEGINS PHASED RESTORATION OF PLAYSTATION NETWORK
After three weeks of waiting, and to many PSN users’ delight, Sony’s PlayStation Network is finally coming back. Sony Computer Entertainment CEO Kazuo Hirai announced on Saturday via video that Sony will begin a phased restoration process of its PSN services. Hirai said the company has been working “around the clock” to bring he services back online.
A mandatory firmware update on PS3 consoles is required to restore PSN service. This update, v3.6.1, will require that users change their passwords, which is understandable seeing as Sony confirmed earlier this month that over 23,000 credit card numbers and bank information had been stolen. Your new password can only be changed on the same PS3 in which your account was activated, or through a validated e-mail confirmation.
Patrick Seybold, Sony’s Senior Director of Corporate Communications and Social Media, said in a blog post that the restoration process has started and some states already have access. He asked users to be patient as the restoration reaches more cities and states. You can visit Sony’s blog to see an updated map with locations in which service has been restored. It will take “several hours” to get the service back online throughout the entire U.S.
Labels:
hack,
Kazuo Hirai,
online,
playstation,
playstation network,
ps3,
psn,
Sony
Saturday, May 7, 2011
PLAYSTATION NETWORK AND QRIOCITY RESTORATION DATE MISSED, SONY BEGS FOR MORE TIME
If you'll recall, Sony held what can only be described as an emergency press event in Japan a week ago in order to issue a number of assurances about the resumption of service as it relates to the PlayStation Network and Qriocity. Seven days later, things are still as dead as they were pre-Cinco de Mayo.
This evening, the company's Senior Director of Corporate Communications Patrick Seybold punched out a quick update to let the world know that they could actually leave the house and find something else to entertain 'em, like it or not, PSN isn't coming back online today. The reason? On May 1st, Sony was apparently "unaware of the extent of the attack on Sony Online Entertainment servers," and now, it's spinning its wheels in order to restore security on the network and "ensure" that user data is safe.
Mr. Seybold seems to understand that you're overly anxious about getting back into the swing of things, and he's even going so far as to ask your trust that Sony's doing "everything [it] can" to get the lights blinking once more. Oh, and if you were planning on visiting that source link just to find the new ETA... don't. Sony's planning to update you "as soon as it can."
Labels:
hack,
playstation network,
psn,
Qriocity,
Sony,
sony online entertainment
Friday, May 6, 2011
SONY OFFERS FREE IDENTITY THEFT PROTECTIONS FOR PSN AND QRIOCITY USERS
Sony's announced that it will provide a complimentary one-year subscription to Debix's "AllClear ID Plus" identity theft protection service to all PlayStation Network and Qriocity account holders in the United States, which will attempt to protect your personal data from harm, by both monitoring known criminal activity for your private digits and providing up to $1 million in ID theft insurance coverage. We've never used Debix, so we can't vouch for its reliability, and this particular plan admittedly doesn't look quite as comprehensive as the one Debix offers regular customers for $10 a month. Still, some peace of mind is a heck of a lot better than none, so we think we might take Sony up on its offer and sign up by the June 18th deadline.
Labels:
all clear id plus,
debix,
hack,
identity theft,
playstation network,
protection,
psn,
Qriocity
Subscribe to:
Posts (Atom)



















