Showing posts sorted by date for query Apache. Sort by relevance Show all posts
Showing posts sorted by date for query Apache. Sort by relevance Show all posts

DSH is Taking Anonymous More Seriously & Issued A Security Bulletin To Warn About The Upcoming Cyber Threats



The Department of Homeland Security is beginning to take Anonymous and other non-professional cyber-attackers more seriously as it issues a warning about potential attacks.
The United States Department of Homeland Security warned the security community about potential attacks from hacking collective Anonymous over the next few months. The Sept. 2 security bulletin from the DHS National Cyber-Security and Communications Integration Center warned financial services companies to be on the lookout for attackers operating under the Anonymous umbrella to "solicit ideologically dissatisfied, sympathetic employees" to the cause. The collective recently took to Twitter to persuade employees within the financial sector to hand over information and access to enterprise networks. Though such attempts may have been unsuccessful so far, "unwilling coercion through embarrassment or blackmail may be a risk to personnel," the DHS bulletin warned.
DHS issued the bulletin primarily for cyber-security professionals and staff in charge of protecting critical infrastructure. The bulletin also refer to new tools that Anonymous may be using in launching future attacks. Anonymous has been primarily using the Low Orbit Ion Cannon, a fairly simple testing software that can ping a server repeatedly, to launch its distributed denial of service attacks. Some of the members have been working on a new DDoS tool, based on JavaScript,  dubbed #RefRef.

The new attack tool is said to be capable of using the server's own resources and processing power to launch a denial of service attack against itself, but "so far it's unclear what the true capabilities of #RefRef are," the DHS said in the bulletin. The tool is slated to be released Sept. 17.
DHS also referenced the "Apache Killer" Perl script that can be used to launch denial of service attacks against Web servers running the popular Apache software. Apache developers released a patch earlier this week to fix the vulnerability in Apache 2.2. Administrators have been urged to patch their servers immediately.

The DHS also mentioned three cyber-attacks and civil protests Anonymous has already announced. "Occupy Wall Street" is the first scheduled one, for Sept. 17. Announced by a group Adbusters in July and actively supported by Anonymous, the goal is to get 20,000 individuals to gather on Wall Street to protest various U.S. government policies. Similar rallies targeting financial districts are being planned in Madrid, Milan, London, Paris and San Francisco.
Another protest in October, also led by Adbusters, is scheduled to be held at the Washington, D.C. National Mall to mark the 10th anniversary of the war in Afghanistan. There is also the supposed Nov. 11 attack against Facebook and Project Mayhem, scheduled for Dec. 21, 2012, DHS warned. There are indications that Project Mayhem would be a combination of physical disruption and targeting of information systems.

The bulletin itself is unusual in that DHS hasn't commented on the activities of Anonymous ever since the group stepped up its efforts over the past few months, attacking federal agencies and private corporations to protest a wide range of issues. As anyone following the security space undoubtedly knows, there have been at least one or two attacks by Anonymous, even more, each week for the past few months, so the bulletin may be just stating the obvious when warning of future potential attacks.
"Anonymous has shown through recently reported incidents that it has members who have relatively more advanced technical capabilities who can also marshal large numbers of willing, but less technical, participants for DDOS activities," the DHS said.

-News Source (e-Week)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Database of Stanford University's Hacked By An0nym0us sn3Ak3r


The official website of Stanford University's Nanoelectronics Group is Vulnerable to SQL-i and its DB Hacked By An0nym0us sn3Ak3r. The hacker exposed many information like Db name, Tables, Column, user credentials, admin details and so on. 



Vulnerable Site:-  http://nano.stanford.edu/

Host IP: 171.67.216.22
Web Server: Apache
DB Server: MySQL
Column Count is 10
String Column is 2


User Credentials:-

User Name=superadmin
Password=93a76158cafcd6bd9227607a5f5bd8eaf36ac7d8
User Name=addcontent
Password=fd9b61ca989759ecb0cd0ae5298e2c61f8e0add7
User Name=hspwong
Password=4ba878ab4d1d19d3
User Name=mrlinPassword=f87f8271afa4e5c2380822d33d37f132c4c6675b

To See The hacked DB Click Here

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Ministry of Civil Aviation & Tourism, Bangladesh Hacked By TEAM T!g3R

Ministry  of Civil Aviation & Tourism, Bangladesh is Vulnerable to SQL-i and the entire Database get hacked by TEAM T!g3R. They exposed sensitive  information like DB name, server details, admin credentials and lots of other things.

Vulnerable Site:-
http://www.mocat.gov.bd/

Vulnerable Link:-

Server Details:-

Target:         http://www.mocat.gov.bd/personnel.php?id=1
Host IP:        75.125.91.162
Web Server:  Apache/2.2.19 (Unix) mod_ssl/2.2.19 OpenSSL/0.9.8e-fips-rhel5        mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
                        mod_perl/2.0.5 Perl/v5.8.8

Powered-by:         PHP/5.2.17
DB Server:          MySQL >=5
Resp. Time(avg):    4767 ms
Current User:       mocatgo_mocatdb@localhost
Sql Version:        5.1.56-log
Current DB:         mocatgo_mocatdb
System User:        mocatgo_mocatdb@localhost
Host Name:         dhaka-bd2.number1shop.com
Installation dir:         /
DB User:         ' mocatgo_mocatdb'@'localhost'


User Credentials:-
admin          QQmoca3tad
jabed           QQrrtre
rubel           QQinfo@bdt
rumu           QQinfo
sdnp            QQqrr
tina             QQadmin


To see the hacked DB click Here

Here are Some screen Shots Submitted by The hacker:-

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Ministry Of Home Affairs, Bangladesh is SQL-I Vulnerable (DB Hacked By Team T!g3R)


The official Website of Ministry Of Home Affairs Of Bangladesh is Vulnerable to SQL-i said Team T!g3R. w3bd3f4c3r, n3ll@!s@mur4!, r00t, burn3r 3 members of (Team T!g3R) hacked into the DB of that site and exposed DB info including DB name, tables, online user details, admin credentials

Server Info:-

Target    :     http://www.mha.gov.bd/index5.php?category=105
Host IP   :    202.79.16.14
Web Server:     Apache/2.2.3 (CentOS)
Powered-by:     PHP/5.1.6
DB Server :     MySQL >=5
Resp. Time(avg):7161 ms
Current User:     mha@localhost
Sql Version:     5.0.77
Current DB :     mha
System User:     mha@localhost
Host Name  :     webstar
Installation dir:/usr/
DB User    :     'mha'@'localhost'

Admin Details:- 

USERNAME : behari
PASSWORD : bbn19741

For More Information and see the hacked DB Click Here

Here are some screen shots Submitted By the Hacker:-



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Apache 2.2.20 Released (DDoS Vulnerability Fixed)


This afternoon the Apache Foundation released an awaited fix to the denial of service (DoS) vulnerability reported a few days ago. The fixes in version 2.2.20 of the Apache httpd server reduce the amount of memory that is used by range requests. If the total bytes of a file requested exceed the total file size, httpd will return the entire file. This follows closely on the heels of a tool released to the Full Disclosure mailing list this week that exploits the flaw. Apache web administrators are encouraged to apply this fix immediately. Unfortunately, as we see all too frequently, many Linux and Unix administrators "set and forget" their installations and never bother to look after their servers.
The Apache team should be applauded for testing and releasing an important security fix so quickly. Now it is up to you, the IT administrators who are using Apache, to follow through and apply these fixes.

For More information, to see the official release of Apache notes and patches of that vulnerability click Here

-News Source (NS & Apache)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

killapache (DDOS Tool For Apache Web Server)

A unknown flaw in the code for processing byte range headers allows versions 2.2.x of the Apache Web Server to be crippled from a single PC. A suitable “Apache Killer” Perl script that impressively demonstrates the problem. This has been assigned CVE-2011-3192 as its CVE identifier.

How killapache Works:-

killapache sends GET requests with multiple “byte ranges” that will claim large portions of the system’s memory space. A “byte range” statement allows a browser to only load certain parts of a document, for example bytes 500 to 1000. It is normally used while downloading large files. This method is used by programs such as download clients to resume downloads that have been interrupted; it is designed to reduce bandwidth requirements. However, it appears that stating multiple unsorted components in the header can cause an Apache server to malfunction.

To download the Killapache Perl file Click Here

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Kathmandu Metropolitan City (Gov Of Nepal) Database Hacked By T34mT!g3R


SQL-i Vulnerability found by w3bd3f4c3r & n3ll4!h4ck3r (T34mT!g3R) on the official website of Kathmandu Metropolitan City (Govt. Of Nepal). The hackers also hacked the DB and sensitive credentials like server information and admin credentials and so on.

Vulnerable Website:-

Vulnerable Link:-
http://www.kathmandu.gov.np/index.php?cid=153&pr_id=183


Server Details:-
 
Host IP: 205.234.235.248
Web Server: Apache
Powered-by: PHP/5.2.13
Keyword Found: 07:07:18
Injection type is Integer
Keyword corrected: 07:07:26
DB Server: MySQL

Admin Details:-

username : admin
password : 00186efe593f6a75fe43a2a9187a2fcf
email    : info@kathmandu.gov.np
phone no.: +977984111111 


To See The Hacked Database Click Here 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

National Telecommunication Authority of Nepal Hacked By w3bdf4c3r & n3ll4!h4ck3r


National Telecommunication Authority of Nepal hacked by w3bdf4c3r & n3ll4!h4ck3r. According to the hacker there was SQL-i vulnerability on their site, using that they hacked the entire Database exposed including admin details 

Website:- 

Vulnerable Link:-  
www.nta.gov.np/en/aboutus/index.php?id=7

 



Exposed DB & Admin Credentials:-

##############ADMIN DETAILS#####################
USERNAME : Administrator
PASSWORD : cWccBbcbcLPCAYtMBA+c9jz6Q/Gvgn5FEPWxuwewFwY


##############SERVER DETAILS####################
web server operating system: Linux Debian or Ubuntu 6.0 (unstable sid or testing squeeze)
web application technology: Apache 2.2.16
back-end DBMS: MySQL 5.0

available databases [2]:
[*] dbase_nta
[*] information_schema

#########DATABASE NAMES############
Database: dbase_nta
[29 tables]
+----------------------+
| ajaxim_chats         |
| ajaxim_users         |
| poll_answers         |
| poll_options         |
| poll_questions       |
| tblaboutus           |
| tbladmin             |
| tblarticles          |
| tblemailtemplate     |
| tblemployee          |
| tblflashnews         |
| tblgroup             |
| tblindustry          |
| tbllicenselist       |
| tbllink              |
| tbllinktype          |
| tblmenu              |
| tblmisreport         |
| tblnewsnevents       |
| tblperformanceform   |
| tblperformancereport |
| tblpublicnotice      |
| tblsettings          |
| tblsitecontent       |
| tblsitedefinition    |
| tblsubscriber        |
| tblsuccessstory      |
| tbltestimonials      |
| tblwhatsnew          |
+----------------------+

Database: dbase_nta
Table: tbladmin
[8 columns]
+--------------------+-------------+
| Column             | Type        |
+--------------------+-------------+
| account_created_on | datetime    |
| admin_id           | int(11)     |
| fullname           | varchar(90) |
| last_logged_on     | datetime    |
| logged_times       | int(11)     |
| password           | varchar(90) |
| user_type          | int(11)     |
| username           | varchar(90) |
+--------------------+-------------+

Database: dbase_nta
Table: tbladmin
[7 entries]
+---------------+
| username      |
+---------------+
| Administrator |
| newadmin      |
| License       |
| skhatiwada    |
| employee      |
| shiva         |
| hiranya       |
+---------------+

Database: dbase_nta                                                                                                                                                                             
Table: tbladmin
[7 entries]
+-----------------------------------------------------+
| password                                            |
+-----------------------------------------------------+
| cWccBbcbcLPCAYtMBA+c9jz6Q/Gvgn5FEPWxuwewFwY=        |
| kDe+yWtg8ig1c7u/xUFGUNW346lxji9dULxj0zEgDpo=        |
| dbeHX/VJnZX/k1WWX1/PgNtQ9J3vOAH4wRbOknMZpmM=        |
| Cgvlz3lhqdQjnJme8mPyPbIz4aAcNrbcBrbG+qng10I=        |
| ktvKe8xBnYQSdYdCXXqsUe1NPdyxubXuDiZqZhOc8U8=        |
| b12d9c7d622fbf7c4d1ed40a3b13ada1ab342c5a (newworld) |
| tR2rHWvfuW1jUXZmetwRs+ggUx4D5ROXqBwOqG87Mos=        |
+-----------------------------------------------------+

Database: dbase_nta
Table: tbladmin
[7 entries]
+-------------------+
| fullname          |
+-------------------+
| Udaya Raj Regmi   |
| new admin         |
| License Section   |
| Sunil Khatiwada   |
| employee          |
| shiva ram         |
| HIiranya Bastkoti |
+-------------------+
Database: dbase_nta
Table: ajaxim_users
[7 columns]
+-----------+---------------------+
| Column    | Type                |
+-----------+---------------------+
| buddylist | text                |
| email     | text                |
| id        | bigint(20) unsigned |
| is_online | int(11)             |
| last_ping | text                |
| password  | text                |
| username  | text                |
+-----------+---------------------+

Database: dbase_nta
Table: ajaxim_users
[3 entries]
+-------------+
| username    |
+-------------+
| sumanshakya |
| testuser    |
| admin       |
+-------------+

Database: dbase_nta
Table: ajaxim_users
[3 entries]
+-----------------------+
| email                 |
+-----------------------+
| nqholder@hotmail.com  |
| test@test.com         |
| nqholdesr@hotmail.com |
+-----------------------+

Database: dbase_nta                                                                                                                                                                             
Table: ajaxim_users
[3 entries]
+-------------------------------------------+
| password                                  |
+-------------------------------------------+
| 0e02d54612f4e7e959aea25c5a43a2ea          |
| 098f6bcd4621d373cade4e832627b4f6 (test)   |
| 21218cca77804d2ba1922c33e0151105 (888888) |
+-------------------------------------------+



Database: dbase_nta
Table: tblemployee
[9 columns]
+----------------+---------------+
| Column         | Type          |
+----------------+---------------+
| department     | tinytext      |
| dt_appointment | date          |
| email          | varchar(200)  |
| emp_id         | int(11)       |
| fullname       | varchar(300)  |
| grp_id         | int(11)       |
| isenable       | enum('Y','N') |
| post           | text          |
| qualification  | text          |
+----------------+---------------+

Database: dbase_nta
Table: tblemployee
[5 entries]
+------------------+
| fullname         |
+------------------+
| Shakya

Suman |
| ss               |
| Suman Shakya     |
| Sam Shrestha     |
| Suresh Shrestha  |
+------------------+


Database: dbase_nta
Table: tblemployee
[5 entries]
+-------------------------+
| email                   |
+-------------------------+
| nqholder@hotmail.com    |
| suman.nta.com.np        |
| nqholder@hotmail.com    |
| sam@nta.com.np          |
| sureshthedude@gmail.com |
+-------------------------+

For More Info Click Here

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Netsparker 2.0 Released (Web Application Security Scanner)

Mavituna Security has released V2.0 of its web application security scanner Netsparker. The new version includes 16 new security checks, 15 new features and a variety of minor improvements.
New in V2.0 is a Vulnerability Database with a list of known vulnerabilities for Apache, Tomcat, MSSQL and MySQL. When Netsparker identifies one of these systems, it’ll reference the database and report all known vulnerabilities for that particular version with severity, exploit details and CVE references.

The new security checks performed by Netsparker 2.0 include: SSL checks (Netsparker will report weak ciphers, self-signed SSLs and similar SSL / Certificate related issues), Tomcat default files checks, ASP.NET MVC version disclosure checks and  Mongrel / Nginx version disclosure checks.

The vulnerability engine has also been enhanced:

    * Improved Signature based SQL Injection detection
    * LFI checks improved and coverage increased
    * Attribute-based XSS checks improved
    * PHP source code disclosure checks improved
    * Protocol-based XSS attacks significantly improved
    * ASP.NET / .NET Framework 4 Viewstate support added. MAC Enabled and Encryption issues will also be reported correctly in .NET Framework 4 systems
    * ORACLE SQL Injection checks improved

On a lighter note, Mavituna Security are also proud of the new dramatic splash screen. You can’t beat that!

For more Information About Netsparker 2.0 click Here

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

indiancyberforce.in Hacked By Shadow008

Official website of Indian cyber Force (indiancyberforce.in) Hacked By Shadow008. He also Exposed the DB, which is available for download.

Hacked Sites:-


Mirror Link:-

&

More Details:- 
Method :- KhantastiC meth0d

Team Members:- KhantastiC haXor - InnOcent Hacker - ReXor HaXor -

LOV3 tO : All Muslims and Pakistanis -Dr.tr0Jan -SqL_MaSt3r - Dr.Viru$ - PretoriaN - ErmaL - bh - Shad0w008 -Killermind - Mkhan - Jerry - Rafay - IPv6 Aka Faruk - SyedZada-- PakCyberArmy (Shak) nd all Paki L33tS

################################################## ###########################################

server IP : 64.37.52.2

Host Name : aspire.nsjet.com

Uname -a : Linux aspire.nsjet.com 2.6.18-238.12.1.el5.centos.plus #1 SMP Wed Jun 1 11:12:25 EDT 2011 x86_64 x86_64 x86_64 GNU/Linux

Server : Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_fcgid/2.3.5

safe_mode: OFF

id : uid=1237(mfriendz) gid=1237(mfriendz) groups=1237(mfriendz)


MySQL DETAILS :-

$config['MasterServer']['username'] = 'mfriendz_Forum';
$config['MasterServer']['password'] = 'ICF@ForumPass';
$config['Database']['dbname'] = 'mfriendz_ICFforum';

http://indiancyberforce.in/admincp

USer : ICFAdminUser
pass : **********

Email admin@indiancyberforce.in


Database Link : http://www.mediafire.com/?b5spav2xca9ghqi

Archive Password:- pakistan

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Web hosting, Reseller, Vps & Dedicated services Provider Hosterbox is Vulnerable to SQL-i said Shadman Tanjim (BCA)



Web hosting, Reseller, Vps & Dedicated services Provider Hosterbox Hacked by Shadman Tanjim , Admin Bangladesh Cyber Army

According to the Hacker:- 

Website: www. hosterbox.com
Hacking Method: SQL Injection
Vulnerability risk: high
Host IP: 184.82.153.150
Web Server: Apache
Powered-by: PHP/5.2.16
Injected Link:


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Kerala state social welfare dept & Advocate General Rajastan is Vulnerable to SQL-i


The official website of Kerala state social welfare dept & Advocate General Rajastan  is Vulnerable to SQL-i. Those two are the Govt. site of India. This vulnerability has been found by Moofster

Kerala state social welfare dept:
Vulnerable Website:-  http://www.keralawomen.gov.in/
Host IP: 74.220.207.96
Web Server: Apache
Powered-by: PHP/5.2.17


Advocate General Rajastan:
Host IP: 210.212.105.51
Web Server: Apache/2.2.3 (Red Hat)
Powered-by: PHP/5.1.6

Admin details:
Data Found: password=0192023a7bbd73250516f069df18b500 (admin123 in plaintext)
Data Found: user_name=administrator

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Another DoS fix for Apache HTTP server


The update of the Apache HTTP Server (httpd) to version 2.2.18 earlier this month to close a denial of service (DoS) problem appears to have exposed a related DoS vulnerability. The developers have nowreleased httpd 2.2.19 to fix this new problem which has been rated as moderately critical; however, as with the previous DoS vulnerability, it requires that mod_autoindex is enabled in the web server.
It appears that the updated Apache Portable Runtime (APR) 1.4.4 – which was bundled with the server to correct the denial of service vulnerability – could cause httpd workers to enter a 100% CPU utilising hung state when calling apr_fnmatch. An update to APR, version 1.4.5, which resolves the issue has been released by the APR developers and is bundled with Apache HTTP Server 2.2.19. Users can upgrade to httpd 2.2.19 or, if running httpd 2.2.17 or earlier, work around the denial of service problem by using the "IgnoreClient" option of the "IndexOptions". The problem was first noted and tracked on Debian mailing lists.
The developers also took the opportunity to fix an inadvertently changed function signature for ap_unescape_url_keep2f which had broken binary compatibility with some third party modules. The 2.2.19 update to httpd is available to download from the project's download page. The updated APR 1.4.5 is also available for download for developers who use the library in other projects.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

IBM Unveils Breakthrough Software and New Services to Exploit Big Data




As companies seek to gain real-time insight from diverse types of data, IBM (NYSE: IBM) today unveiled new software and services to help clients more effectively gain competitive insight, optimize infrastructure and better manage resources to address Internet-scale data. For the first time, organizations can integrate and analyze tens-of-petabytes of data in its native format and gain critical intelligence in sub-second response times.
(Logo: http://photos.prnewswire.com/prnh/20090416/IBMLOGO)
IBM also announced a $100 million investment for continued research on technologies and services that will enable clients to manage and exploit data as it continues to grow in diversity, speed and volume. The initiative will focus on research to drive the future of massive scale analytics, through advancing software, systems and services capabilities.
The news comes on the heels of the 2011 IBM Global CIO Study where 83 percent of 3,000 CIOs surveyed said applying analytics and business intelligence to their IT operations is the most important element of their strategic growth plans over the next three to five years.
Today's news further enables Smarter Computing innovations realized by designing systems that incorporate Big Data for better decision making, and optimized systems tuned to the task and managed in a cloud.
According to recent IT industry analyst reports, enterprise data growth over the next five years is estimated to increase by more than 650 percent. Eighty percent of this data is expected to be unstructured.  
The new analytics capabilities pioneered by IBM Research will enable chief information officers (CIOs) to construct specific, fact-based financial and business models for their IT operations. Traditionally, CIOs have had to make decisions about their IT operations without the benefit of tools that can help interpret and model data.
With today's news, IBM is expanding its portfolio and furthering its investments in analytics with:
  • New, patented software capabilities to analyze massive volumes of streaming data with sub-millisecond response times and Hadoop-based analytics software to offer scalable storage to handle tens-of-petabytes level data.  These capabilities complement and leverage existing IT infrastructure to support a variety of both structured and unstructured data types.
  • 20 new services offerings, featuring patented analytical tools for business and IT professionals to infuse predictive analytics throughout their IT operations. The services enable IT organizations to assess, design and configure their operations to address and take advantage of petabytes of data.

"The volume and velocity of information is generated at a record pace. This is magnified by new forms of data coming from social networking and the explosion of mobile devices," said Steve Mills, Senior Vice President and Group Executive, IBM Software & Systems.  "Through our extensive capabilities in business and technology expertise, IBM is best positioned to help clients not only extract meaningful insight, but enable them respond at the same rate at which the data arrives."


New Services Address Analytics for IT Infrastructure
Leveraging years of intellectual capital in managing data centers and IT departments, as well as over 30 patented technologies from IBM Research, the new IT services feature dozens of analytical tools to help IT professionals use server, storage and networking technologies more efficiently, improving security and insight into planning major IT investments.  Examples of services that help clients with analytics include:
  • Cloud Workload Analysis -- The new analysis tool maps your IT workload characteristics and current capabilities to prioritize cloud deployment and migrations plans. This allows IT managers to identify cloud opportunities 90 percent faster to reduce costs.  
  • Server and Storage -- New server optimization and analysis tools achieve up to 50 percent reduced transformation costs and up to 80 percent faster implementation time.  New storage services help create self-service to provision explosive growth while reducing architects time by 50 percent.
  • Data Center Lifecycle Cost Analysis Tool -- Identifies how to reduce total data center costs by up to 30 percent by assessing total cost plus including environmental impact over a 10 to 20 year life.
  • Security Analytic services -- Analytic systems identify known events and automatically handle them; This results in handling of more than 99 percent of critical events without human intervention.

IBM Big Data Software Taps into Hadoop
IBM is making available new InfoSphere BigInsights and Streams software that allows clients to gain fast insight into information flowing in and around their businesses.  The software, which incorporates more than 50 patents, analyzes traditional structured data found in databases along with unstructured data -- such as text, video, audio, images, social media, click streams -- allowing decision makers to act on it at unprecedented speeds.  
BigInsights software is the result of a four-year effort of more than 200 IBM Research scientists and is powered by the open source technology, Apache Hadoop. The software provides a framework for large scale parallel processing and scalable storage for terabyte to petabytes-level data. It incorporates Watson-like technologies, including unstructured text analytics and indexing that allows users to analyze rapidly changing data formats and types on the fly.  
Additional new features include data governance and security, developer tools, and enterprise integration to make it easier for clients to build a new class of Big Data analytics applications. IBM also offers a free downloadable BigInsights Basic Edition for clients to help them explore Big Data integration capabilities.  
Also born at IBM Research, InfoSphere Streams software analyzes data coming into an organization and monitors it for any changes that may signify a new pattern or trend in real time. This capability helps organizations to capture insights and make decisions with more precision, providing an opportunity to respond to events as they happen.
New advancements to Streams software makes it possible to analyze Big Data such as Tweets, blog posts, video frames, EKGs, GPS, and sensor and stock market data up to 350 percent faster than before.  BigInsights complements Streams by applying analytics to the organization's historical data as well as data flowing through Streams. This is an ongoing analytics cycle that becomes increasingly powerful as more data and real-time analytic results are available to be modeled for improvement.
As a long time proponent of open source technology, IBM has chosen the Hadoop project as the cornerstone of its Big Data Strategy. With a continued focus on building advanced analytics solutions for the enterprise, IBM is building upon the power of these open source technologies while adding improved management and security functions, and reliability that businesses demand. Hadoop's ability to process a broad set of information across multiple computing platforms, combined with IBM's analytics capabilities, now makes it possible for clients to tackle today's growing Big Data challenges. IBM's portfolio of Hadoop-based offerings also include IBM Cognos Consumer Insight which integrates social media content with traditional business analytics, and IBM Coremetrics Explore which segments consumer buying patterns and drills down into mobile data. Additionally, Hadoop is the software framework the IBM Watson computing system uses for distributing the workload for processing information, which supports the systems breakthrough ability to understand natural language and provide specific answers to questions at rapid speeds.
University of Ontario Institute of Technology Expands Neo-Natal Research to China
Dr. Carolyn McGregor, Research Chair in Health Informatics at the University of Ontario Institute of Technology has been exploring new approaches for the last 12 years to provide specialists in neonatal intensive care units better ways to spot potentially fatal infections in premature babies.  
Changes in streams of real-time data such as respiration, heart rate and blood pressure are closely monitored in her work and now she is expanding her research to China. "Building upon our work in Canada and Australia, we will apply our research to premature babies at hospitals in China.  With this new additional data, we can compare the differences and similarities of diverse populations of premature babies across continents," said Dr. McGregor. "In comparing populations, we can set the rules to optimize the system to alert us when symptoms occur in real time, which is why having the streaming capability that the IBM platform offers is critical. The types of complexities that we're looking for in patient populations would not be accessible with traditional relational database or analytical approaches."
IBM's Big Data software and services reinforces IBM's analytics initiatives to deliver Watson-like technologies that help clients address industry specific issues. On the heels of The IBM Jeopardy! Challenge, in which the IBM Watson system demonstrated a breakthrough capability to understand natural language, advanced analytical capabilities can now be applied on real client challenges ranging from identifying fraud in tax or healthcare systems, to predicting consumer buying behaviors for retail clients.
Over the past five years, IBM has invested more than $14 billion in 24 analytics acquisitions. Today, more than 8,000 IBM business consultants are dedicated to analytics and over 200 mathematicians are developing breakthrough algorithms inside IBM Research. IBM holds more than 22,000 active U.S. patents related to data and information management.
To hear how IBM clients are using analytics to transform their business visit: http://www.youtube.com/user/ibmbusinessanalytics.
For more information on IBM Big Data initiatives, visit: www.ibm.com/bigdata.
For more information on IBM's full set of new analytics services, visit: www.ibm.com/services/it-insight.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

CCAvenue denies hacking attack



Online commerce service provider, CCAvenue, has denied that its portal has been hacked.
Vishwas Patel, CEO,  CCAvenue told NDTVGadgets, "I confirm that the image posted by a hacker is a spoofed, self-created one and not that of our database and it has been created just to create panic and defame our company. We are in the process of filing a criminal complaint against the unknown hacker for the slander and malicious campaign run against our company."
Earlier today, we reported that a hacker claimed to have broken into CCAvenue by exploiting "SQL injection vulnerability".  The hacker, identifying himself as d3hydr8, submitted what he called a full disclosure of his attack on HackerRegiment.com. The "report" included what the hacker said were all the admin usernames and passwords of the CCAvenue portal.
In what was his first reaction on this,  Vishwas Patel said, "First and most [we] would like to say that this a slanderous campaign that is targeting CCAvenue. Based on our initial investigations by our security officials, we confirm that no hack has happened of our servers at 1515 hours on 04th May 2011 by the following person, as claimed in his article. We also confirm that  that the screenshot is not of our live database as the Apache version on live server is 2.2.17 (Updated more than 5 months ago) and not 2.2.14 (as claimed by the hacker). We also confirm that all the passwords of our merchants and all login credentials in our live database are encrypted and stored in our database and not in text format as claimed by the hacker."
He also assured that, "We don't store credit card details or Netbanking account details on our servers."
HackerRegiment has published the details submitted by the hacker but has maintained discretion by blurring the "passwords". The information published includes a list of databases, some information on tables within the databases, and screenshots of the administrator usernames and passwords.
HackerRegiment.com also claims to have reported the issue to CERT (Computer Emergency Response Team) India to help CCAvenue take corrective action before any information is released through any other media.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Apache Web Server Under Stealth Attack

 
Online attackers seem to love to exploit Web servers, because they can add scripts that quickly and automatically add malicious links to static HTML pages via an iFrame tag, or code that attempts to exploit website visitors' PCs via drive-by downloads. But an attack discovered on Friday, dubbed Apmod, pushes this attack technique one step further by not just infecting static Web pages. "The attack was unusual in that the Web server itself was the infection target," said Cathal Mullaney, a security response engineer at Symantec, in a blog post. "When a Web server is infected like this, every user that requests any Web page from that Web server is a potential victim. This is opposed to cases where static Web pages are infected with malicious code--only those specific pages put a user at risk of infection."
This new attack, which has been seen in the wild but doesn't currently appear to be widespread, targets the popular Apache Web Server, which runs on Windows and Linux. According to Netcraft, Apache Web Server is now used to host about 204 million websites.
The attack is innovative in that it uses Apache's built-in filter capabilities. A filter, as defined by Apache, "is a process that is applied to data that is sent or received by the server," and can be used to add functionality without rewriting the code base. Many websites use this capability to add advertisements to Web pages on the fly, while also tracking that advertising delivery to generate revenue via ad agencies.
"We have discovered a malicious module that performs identical steps in order to include links to malicious websites," said Mullaney. "All of the actions performed by the rogue module are done using legitimate code provided by the Apache API, specifically for this type of on-the-fly content generation. This is not an exploit or a hack of Apache's code base; the module uses Apache's inherent functionality to infect users and attempts to redirect them to a malicious Web page."
Interestingly, the module doesn't attempt to infect every Web page it serves. In fact, it includes a number of anti-detection capabilities, including watching for signs of administrator access or processes and avoids serving malware to search engines. Furthermore, when it does serve a Web page infected with links to malicious websites, the module then temporarily blacklists the user's IP address to avoid delivering multiple, infected Web pages, which might make its activities easier to detect. It then queries a command and control server to provide a new iFrame tag, further hampering detection.
As a result, "this is a complex and potentially difficult threat to detect accurately," said Mullaney. "As the rogue module contains a number of evasion techniques, it is possible that a system administrator would not notice the infection for some time. A further difficulty in detecting the threat is the on-the-fly nature of the infection. Since no Web pages are infected on the disk, no detections on stored HTML pages are possible."

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

SAMHAIN v2.8.4 is now available




The samhain open source host-based intrusion detection system (HIDS) provides file integritychecking and logfile monitoring/analysis, as well as rootkit detection, port monitoring, detection of rogue SUID executables, and hidden processes.
It has been designed to monitor multiple hosts with potentially different operating systems, providing centralized logging and maintenance, although it can also be used as standalone application on a single host.



Difference between the previous version and the new one:-



  • Some bugs have been fixed that under certain circumstances would cause samhain to hang or crash when reloading the configuration file.
  • A compile error in the samhain_hide.ko kernel module has been fixed. However, it has been found that this module will not work anymore with recent kernels because of protection measures introduced in newer kernel.
  • A contributed patch for samhainadmin.pl has been included (allows to specify the location of the secret keyring).
  • The (l)stat timeout has been increased to fix spurious timeouts under heavy load.
  • The Apache logfile parser has been enhanced to allow the insertion of arbitrary regexes into the format definition.
  • New options PortcheckMinPortPortcheckMaxPort allow to define the port range for the openports check (requested feature).
Download SAMHAIN v2.8.4 (samhain-current.tar.gzhere

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...