Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts
Tuesday, September 20, 2011
HACKERS CAN CHANGE YOUR PASSWORD IN LION OS X
Security blog Defense in Depth via CNET has found a glaring security flaw in OS X Lion that enables hackers to change the password of any user on a machine running Lion. “[While] non-root users are unable to access the shadow files directly, Lion actually provides non-root users the ability to still view password hash data,” Patrick Dunstan from Defense in Depth explained in a recent blog post. The result is that anyone could use a simple Python script, created by Dunstan himself, to discover a user’s password. It gets worse. Reportedly, OS X Lion does not require its users to enter a password to change the login credentials of the current user. That means typing the command: “dscl localhost -passwd /Search/Users/Roger” will actually prompt you to set a new password for Roger.
As CNET points out, a hacker could only take advantage of the known bug if he or she has local access to the computer and Directory Service access. CNET suggests disabling automatic log-in, enabling sleep and screensaver passwords and disabling guest accounts as some preventative measures to keep your Mac secure.
Wednesday, July 20, 2011
FBI RAIDS SUSPECTED 'ANONYMOUS' HACKERS HOMES
The FBI raided the homes of three hackers from the infamous hacking group ‘Anonymous’ in New York, Fox News reported on Tuesday. Reportedly, more than 10 FBI agents stormed the house of Giordani Jordan in Baldwin New York and took “at least one laptop from the premises.” Jordan is suspected to have been behind denial of service (DoS) attacks against a number of firms, including Mastercard and Visa. In addition, agents are also searching homes in Long Island and Brooklyn. The hackers are said to be in their late teens and early 20s. It’s unclear if the hackers were also part of the group LulzSec, which claimed responsibility for hacks against Sony, the U.S. Senate and the CIA.
Thursday, June 30, 2011
UNIVERSAL AND VIACOM HACKED LEAKING USERS PASSWORDS AND INFORMATION; ANTISEC CLAIMS RESPONSIBILITY
A hacking group named LulzSec made headlines recently for attacking high visibility targets, including Sony and the U.S. government. LulzSec announced earlier this week that it was stopping its operations, and rumor has it many of the members joined up with Anonymous’ “AntiSec” hacking group. Now that group is making its own headlines. On Tuesday AntiSec claimed responsibility for attacks against Universal and Viacom.
According to The Wall Street Journal, the hackers released personal data, including passwords, from the Universal Music Website. It also obtained and leaked information about Viacom’s network. It’s unclear how many users were affected by the security breach, although we hope to hear an official word from both firms in the near future.
Wednesday, June 29, 2011
LULZSEC LEAVES BEHIND ONE LAST PARTING SHOT WITH MALWARE, TROJANS AND VIRII
The small group of hackers known as Lulz Security, or simply “LulzSec,” would never disband without one final round of fun. BGR reported on Monday that the group’s reign of terror was coming to an end after 50 lul-filled days. During that period of time, LulzSec released data stolen in a series of online breaches with targets ranging from Sony to the U.S. Government.
In its coup de grĂ¢ce, LulzSec released a stash of stolen data from a variety of targets, including AT&T, Disney and the U.S. Navy. But data obtained through online breaches wasn’t the only thing LulzSec stuffed into the file; a directory named “BootableUSB” also contained a variety of malware including trojans and worms. While “LulzSec” is no more and its notorious Twitter account now sits dormant, members of the well-known hacktivism group “Anonymous Operations” have confirmed that LulzSec is gone in name only — the six LulzSec members have been absorbed by Anonymous, according to the group’s official Twitter feed.
Sunday, June 26, 2011
LULZSEC CALLS IT QUITS
After 50 days of wreaking cyber-caper havoc, Lulz Security says it's done and will sail into the horizon. The group has stolen mountains of personal data in a dozen different hacks, embarrassing law enforcement on both sides of the Atlantic while boasting about the stunts online.
The group's disbandment comes unexpectedly, and could be a sign of nerves in the face of law enforcement investigations. Rival hackers have also joined in the hunt, releasing information they say could point to the identities of the six-member group. One of the group's six members was interviewed by The Associated Press on Friday, and gave no indication that its work was ending.
LulzSec made its name by defacing the site of the U.S. Public Broadcasting Service, or PBS, with an article claiming that rapper Tupac Shakur was still alive. It has since claimed hacks on major entertainment companies, FBI partner organizations, a pornography website and the Arizona Department of Public Safety, whose documents were leaked to the Web late Thursday.
The hacking group stated "For the past 50 days we've been disrupting and exposing corporations, governments, often the general population itself, and quite possibly everything in between, just because we could," the LulzSec statement said. "All to selflessly entertain others — vanity, fame, recognition, all of these things are shadowed by our desire for that which we all love. The raw, uninterrupted, chaotic thrill of entertainment and anarchy. While we are responsible for everything that The Lulz Boat is, we are not tied to this identity permanently. The breeze is fresh and the sun is setting, so now we head for the horizon."
As a parting shot, LulzSec released a grab-bag of documents and login information apparently gleaned from gaming websites and corporate servers. The largest group of documents — 338 files — appears to be internal documents from AT&T Inc., detailing its buildout of a new wireless broadband network in the U.S. The network is set to go live this summer. An AT&T spokesman could not immediately confirm the authenticity of the documents.
Thursday, May 19, 2011
SONY'S PLAYSTATION NETWORK PASSWORD RESET PAGE HACKED
According to reports from numerous gaming sites, the password reset page for Sony’s PlayStation Network has been exploited. Sony built the page in an effort to allow users, whose accounts were already compromised during a major security breach last month, to reset their security credentials.
However, hackers who stole the information from Sony can reset users’ passwords by knowing an account holder’s email address and birthday — information they’ve already stolen. Forum members on Nyleveia have suggested that PSN users create a new email address specifically for use with PSN.
Sony has taken the website offline, and said: “Unfortunately this also means that those who are still trying to change their password via PlayStation.com or Qriocity.com will still be unable to do so for the time being.”
Labels:
compromised,
hackers,
passwords,
playstation network,
playstation 3,
ps3,
psn,
Sony,
vulnerability
Monday, February 7, 2011
ANONYMOUS GOES AFTER SECURITY FIRM FOR SELLING SUPPORTERS DETAILS TO FBI
If you thought Anonymous limited its cyber attacks to those who blocked WikiLeaks or suppressed free information, you’d be wrong. One software security firm is learning the hard way that it also targets anyone who acts to bring down the loosely-knit, global movement of young people who campaign through Web attacks.
On Sunday evening, just when the Super Bowl was kicking off in Dallas, Texas, five supporters of Anonymous’ elite arm AnonOps brought down the Web site for HBGary Federal, a small, Washington D.C.-based security services firm.
They then hacked into the Twitter account of CEO Aaron Barr, releasing a series of profane, self-denigrating Tweets that also provided links to the hacked Web site of one of his researchers.
An hour later, they released this screenshot, which reads: “Let us teach you a lesson you’ll never forget: you don’t mess with Anonymous,” which they hoped to use it as a new placeholder for HBGary’s site.
Why? Barr was recently quoted in the Financial Times as saying that he had identified two key members of Anonymous, including a co-founder in the U.S. along with senior members in Britain, Germany, Netherlands, Italy and Australia. He claimed to have picked up clues to their identities by monitoring emails, Facebook and IRC chat using fake online names.
The report followed news that police had arrested five suspected members of the group in the U.K. last month and carried out 40 court-authorized searches in the United States.
Though the FT report says that Barr did not plan to give his findings to the police, one person from within AnonOps who took part in Sunday night’s attack tells me that he had, in fact, been planning to sell his research to the FBI and hold a meeting with the authorities on Monday morning.
The five Anonymous supporters who participated in the hack also obtained more than 50,000 of Barr’s personal emails, financial details for HBGary and said they were planning to delete the company’s backups and support servers. The whole operation took just over 24 hours.
The hackers found that at Monday morning’s meeting with the FBI, Barr had been planning to offer a document showing names and addresses of dozens of Anonymous members, for a yet-to-be-negotiated fee.
Yet having obtained the alleged file, the Anonymous members didn’t destroy it–they made it public. The majority of the details in the 23-page document, they said, were incorrect and the names “random.” Nearly everyone actively involved in previous attacks has read the file and confirmed they were not it. The attackers thus released a link to the document through Barr’s own hacked Twitter account.
Barr did not respond to voicemails seeking comment at the time of writing.
Not long after this, Anonymous was Tweeting Barr’s cell number, a link to his 50,000 personal emails, social security number and home address.
Anonymous typically goes after big governments they accuse of corruption (think Tunisia, Egypt) and corporate players like MasterCard or eBay-owned PayPal. But in taking out HBGary the group has targeted a smaller player who, despite being a software security firm, isn’t very secure itself. (It took one of the hackers little over two minutes to get into the LinkedIn account of chief operating officer Ted Vera, another 10 to get his address and phone number.)
In their view this was all justified for serving a larger purpose: “It is harsh, but we’re harsh people,” said one of the attackers. “We felt Anon needed a break from seriousness for a while, we understood that Anon was getting paranoid about recent FBI raids and companies such as HBGary lurking our chats, so we’ve given all of Anonymous a message: we will fight back.”
Subscribe to:
Posts (Atom)






