Showing posts sorted by relevance for query Sony. Sort by date Show all posts
Showing posts sorted by relevance for query Sony. Sort by date Show all posts

BackTrack 5 ‘Revolution’ release ups the penetration testing ante


BackTrack,  the GNU/Linux distribution focused on digital forensics and penetration testing, has a new version out, with the public release (on May 10) of BackTrack 5, code-named Revolution, by the BackTrack development team. BackTrack focuses primarily on providing a native environment purely dedicated to hacking. This latest distro was eight months in the making, and boasts of significant improvements over its predecessor.
BackTrack 5 features a comprehensive arsenal of over 350 security-related tools to test everything from Web applications to RFID systems. The new version of BackTrack lives up to its “Revolution”  moniker in that it has been completely overhauled and rewritten from the ground up, providing  users with an optimized platform for penetration testing and digital forensics exercises. For the first time in its development road map, BackTrack now includes support for ARM-based systems — a significantly upgrade.

BackTrack 5 features

A major addition in the new version of BackTrack is the 64-bit offering. BackTrack 5 is based on Ubuntu Lucid Lynx v10.04, the latest long term support (LTS) release using Linux kernel v2.6.38. BackTrack 5 is the first version to be released with the complete source code in its repositories. This addition is expected to clear up licensing issues that existed in the previous Backtrack distros. BackTrack 4 is no longer available for download at the developer’s Website, and support for it has officially been discontinued.
Here is a more detailed look at important features of BackTrack 5.
  • Support for KDE and Gnome
BackTrack 5 boasts of support for KDE Plasma (4.6), Gnome (2.6) and Fluxbox. This makes it much simpler to migrate from Gnome-based distributions. Unifying the desktop environment has the added advantage of an easier learning curve for new users. Streamlined images for each desktop environment (DE) are available on the backtrack website. Tool integration with supported environments is seamless with DE-specific menu structures. However, while Gnome has a smaller memory footprint and is less resource hungry, the Gnome versions lack default package managers, which need to be added separately.
KDE plasma desktop used in BackTrack 5

  • 32-bit and 64-bit support
The addition of 64-bit support in BackTrack 5 makes it possible to tap additional power for processor-intensive tasks such as brute force password cracking. The 32-bit and 64-bit images support various boot modes, including a “Stealth” mode that boots without generating network traffic and a “Forensics” mode for forensic purposes.
  •  ARM architecture support
 An ARM image of BackTrack 5 is available, having officially been tested on the Motorola Xoom tablet and the Motorola Atrix 4G smart phone by the developers. Custom chroot scripts are already available to run BackTrack 5 on Android systems with ARM processors.
Users have successfully deployed BackTrack 5 on Samsung Galaxy S and Sony Xperia smart phones. However, there are still some issues with these systems and not all features are available. There are known issues with wireless drivers on ARM-based systems including lack of support, for  WiFi packet injection.

BackTrack 5 on a Motorola Atrix 4G
Anant Srivastava, a Mumbai-based software developer and member of the null community, was one of the first to successfully run BackTrack 5 on a Sony Xperia X10. Srivastava used a rooted Xperia x10 running Android 2.2 (Froyo) with an Android terminal application and an Android VNC viewer.


  • Packaged tools
BackTrack 5’s arsenal of tools have been upgraded to the latest versions. BackTrack 5 comes preloaded with tools for LAN and WLAN sniffing, vulnerability scanning, digital forensics and password cracking. The Metasploit exploit framework v3.7.0 has been packaged into BackTrack 5. The tools are organized into a comprehensive menu structure, streamlined to comply with the PTES and OSSTMM standards.

Conclusion

BackTrack 5 promises to surpass previous versions in terms of functionality and stability. However, users have raised concerns over the discontinued support for Ubuntu repositories. BackTrack 5 instead uses its own repositories, which have been benchmarked to work with its tools. The BackTrack 5 team justified this move by highlighting performance concerns when the custom features of BackTrack’s tools are used with other repositories, including corruption of the installation. There is no official support for any repository other than that which is provided by the developers.



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Obama Proposes Anti-Hacking Laws



Hackers will face tougher penalties in the U.S. if the Obama administration's proposed cyber-security measures become law, in an attempt to deter attacks on critical online infrastructure.Under the new law, hackers would face 20 years in prison for endangering national security, 10 years for stealing data and three years for accessing a government computer.
The proposal doubles the penalties from current laws in nearly every category, responding with force to the spate of hacks that have made headlines this last month.The Obama administration first suggested the law last month, before the hacking group LulzSec broke into FBI, CIA and U.S. Senate websites. If prosecuted under the new law, its members could face hefty prison terms for flaunting national security.Compared to the anonymous hacks against Lockheed Martin and the International Monetary Fund, however, LulzSec's distributed denials-of-service, or DDoS, attacks against government websites were merely an annoyance.
Groups like LulzSec, who hack for the fun of it, may face the same sentences as serious data thieves under the cyber-security plan.
Either way, the trouble lies in catching computer hackers who use botnets and server mis-location to cover their tracks. Months after Sony's disastrous data breach left 100 million users' information exposed, Sony and the FBI still haven't found those responsible for the attack.
Tracking down "smoking keyboards" is not impossible, however, as Spain and Turkey proved by arresting members of the Anonymous hacking group. Spain's authorities captured three men accused of intending to publish "sensitive data" about Spanish politicians and policemen. Turkey nabbed 32 Anonymous hackers that had coordinated DDoS attacks against the Turkish government after the country announced plans to restrict Internet services starting this August.
Arresting hackers may deter some from attempting further exploits, but in Anonymous' case the group's loose-knit organization means hundreds of new hackers can rise to fill one member's shoes.
Furthermore, some hackers may have government backing, as IMF officials believe was the case in their hack and as Google alleges happened to them in China.If governments are indeed involved in some of the major recent hacks, things could get sticky, as the Pentagon is set to publish a policy to use physical force against online crime. As one official warned, "If you shut down our power grid, maybe we will put a missile down one of your smokestacks."
The difficulties of catching and prosecuting hackers seem nearly insurmountable. But the new law in the U.S. could encourage a reduction in cybercrimes if it makes an example of even a few.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

IU experts find flaws in US web protection plan


The White House proposed new cybersecurity legislation Thursday that aimed to protect the country against threats to the national infrastructure and the economy, but it was too small a step, according to IU cybersecurity experts.
Fred Cate, a professor in the Maurer School of Law and the director of the Center for Applied Cybersecurity Research, said cybersecurity attacks are a huge problem in today’s society.
“We live in a data-driven society — almost everything we do generates or uses digital data,” Cate said. “Yet as the president and most everyone else recognizes, those data and the systems that transmit and store them are not secure.”
The proposal focuses on the protection of American citizens, critical infrastructure, government systems and privacy and civil liberties. The legislation includes harsher penalties for cybercriminals and requires the Department of Homeland Security to work with companies in the private sector to identify and address vulnerabilities.
Von Welch, the deputy director of the CACR, thinks the new legislation was a positive step, but not a big enough one.
“My concern is that it isn’t keeping up with advances we’re seeing in cybercrime,” he said.
The administration’s cybersecurity efforts have been focused on new technologies, rather than on creating legal and economic incentives for the private sector to invest in better security, Cate said. This approach hasn’t worked, he said.
“During the past two years we have witnessed massive security breaches involving hundreds of millions of Americans, involving Sony PlayStation, the online marketing firm Epsilon, even the security powerhouse RSA,” Cate said. “According to one study, more than 2,500 companies were victims of one sophisticated cyberattack that exfiltrated proprietary corporate data, and there are thousands of other successful attacks against companies and agencies.”
Cate said that U.S. counterintelligence officials report that 140 foreign intelligence organizations are actively engaged in trying to hack into U.S. government and business networks.
“Without appropriate incentives, industry won’t invest sufficiently in good security,” he said. “It is that simple.”
Welch agrees. Much of what the legislation does is formalize practices already happening, he said.
“For example, federalizing breach notification laws have already been put in place by many states, and explicitly allowing collaboration and information exchange that is already taking place by cybersecurity practitioners.”
Cate and Welch agree that there are some positive parts to the plan. Its focus on critical infrastructure, by mandating core critical infrastructure operators, creates a plan for addressing threats. Having those plans evaluated by third parties is a good step given the importance of critical infrastructure to national security, Welch said.
What’s missing from the plan, Welch said, is a similar push for other parts of the Internet.
“As recent high-profile cases such as Sony and Epsilon have shown, and what seem to be constant problems with privacy on social networking sites, there are other companies operating on the Internet that while perhaps not critical to our national security, still impact millions of people,” he said. “There is nothing in the proposed legislation to really incentivize these companies to improve their cybersecurity and, in turn, our privacy as their users.”
Cate explained how the plan could be improved.
“The plan could include legal requirements for good information security, tax incentives, safe harbor provisions for businesses that try to enhance security even if they fail, liability provisions to allow injured consumers to recover from harms caused by bad security and new enforcement powers and resources for the Federal Trade Commission,” he said.
In addition to calling for new privacy protections, he said the President should appoint the members of the Privacy and Civil Liberties Oversight Board, which Congress created, but the administration has yet to fill.
Cate also said the administration’s plan includes no effort to curtail risky behaviors by businesses themselves.
“The recent discoveries that Google and Apple are both collecting location data on smart phone users and storing that data, unencrypted, in unsecured files suggests that some regulation may be appropriate to protect individuals as well as industry,” he said.
The bottom line? Technology is very important in security, but the administration’s focus on it is only one step towards enhancing information security.
“Technologies are like magic bullets for the government — no matter what the problem, we want to believe that technology can solve it,” Cate said. “Technology alone just isn’t enough — for security or anything else.”

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Sony Hackers LulzSec Strike FBI Affiliate InfraGard


LulzSec, the hacking group that has been identified as being behind the latest attack on Sony, has struck again—this time targeting a private-sector FBI affiliate called InfraGard.
InfraGard is a non-profit organization that connects the business community with law enforcement. It has about 42,000 members, including FBI agents, according to its website, and has an FBI special agent coordinator at each the bureau's field offices who recruits interested civilians nearby to form local InfraGard chapters. The InfraGard hack was part of a LulzSec action it called "Fuck FBI Friday" and culminated in the anonymous hacking group's publication of InfraGard e-mails, passwords and personal contact information for about 180 members on Friday. One LulzSec tweet late Friday promised "700MB in emails" via a link to a torrent file. LulzSec also defaced the InfraGard Atlanta website with a YouTube video challenging its target to "LET IT FLOW YOU STUPID FBI BATTLESHIPS," according to reports.
The hack of InfraGard that netted all the data published Friday seems to have occurred about a week or more ago. One InfraGard member told CNET Friday that he was contacted by a hacker group via email on May 26.
Karim Hijazi, CEO of botnet-tracking company Unveillance, said the hackers threatened to publish information about him found on InfraGard if he didn't give them sensitive security information about botnets. Botnets are networks of personal computers used by hackers and spammers who have slaved those PCs to the botnet either from volunteers, as is the case with the Anonymous hacking group's botnet, or from unsuspected PC users through a computer virus. Hijazi said that about a week before the first email came from "unveillance.owned@husmail.com," his company had detected attempts to crack the Unveillance corporate network with iPredator, a VPN tunneling tool. He also told CNET that he believed an unknown person had listened in on a company conference call. In a later IRC chat with his tormenters, the LulzSec hackers threatened to post a recording of a company call they said they had listened in on. "They had me under the gun for a little over a week with threats and extortion," Hijazi told CNET. "The very nature of having to contend with someone who is holding something ransom is not pleasant."


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

LulzSec Spokesman Busted By Scotland Yard


Scotland Yard's cybercrime unit has arrested a teenager it suspects of working as the spokesman for the Lulz Security hacking collective, officials said Wednesday.
The Metropolitan Police's Central e-Crime Unit arrested a 18-year-old at an address in Scotland's remote Shetland Islands, the force said in a statement. His name wasn't released, but police said he was believed to be "Topiary," one of LulzSec's most prominent members.
Police originally gave his age as 19 but later issued a correction. 
LulzSec shot to prominence in May with attacks on the US Public Broadcasting Service - whose website it defaced by posting a bogus story claiming that the late rapper Tupac Shakur had been discovered alive in New Zealand.
The group is a spin-off of Anonymous, an amorphous collection of Internet enthusiasts, pranksters and activists whose targets have included the Church of Scientology, the music industry, and financial companies including Visa and MasterCard.
Topiary was linked to both groups, serving as the on-again, off-again media liaison for the publicity-hungry hackers.
In his only known television interview, on the "David Pakman Show" earlier this year, Topiary phoned in via Skype to feud with Shirley Phelps-Roper of the Westboro Baptist Church, a Kansas-based group notorious for picketing the funerals of slain American soldiers.
Anonymous vandalised the church's website live over the course of the interview.
In conversations with The Associated Press, Topiary said he controlled LulzSec's Twitter feed, which garnered some 300,000 followers over the course of its six-week-long Internet rampage.
LulzSec has claimed responsibility for breaches at pornography websites, gaming companies, and law enforcement organisations. It's also claimed credit for harassing seemingly random targets including an obscure New Jersey-based magnet manufacturer.
One its most spectacular hacks was against Sony Pictures Entertainment. The group posted the usernames, passwords, email addresses and phone numbers of tens of thousands of people, many of whom had given Sony their information for sweepstakes draws. Another stinging series of breaches last month targeted Arizona's police force in protest against its contentious immigration law. Officers had to scramble to change their numbers because their phones were being jammed with calls.
Shortly thereafter the group abruptly announced it was disbanding, although Topiary said at the time that the group wasn't bowing to police pressure.
"We're not quitting because we're afraid of law enforcement," he said in a Skype call. "The press are getting bored of us, and we're getting bored of us."
Attempts to reach Topiary since then have been unsuccessful, although his group recently re-emerged from retirement, defacing The Sun newspaper's website with a fake story claiming that media tycoon Rupert Murdoch had died. In one of its last messages, LulzSec said it was working with unnamed media outlets on a WikiLeaks-style release of emails it claimed to have stolen from the tabloid.
Topiary's once-plentiful Twitter feed was practically wiped clean Wednesday. The only remaining post, from nearly a week ago, read: "You cannot arrest an idea."
The latest arrest is one of an increasing number claimed by law enforcement in Britain and the United States in connection to their investigations into Anonymous and its offshoots. Last week, the FBI, British and Dutch officials carried out 21 arrests, many of them related to the group's attacks on Internet payment provider PayPal Inc., which has been targeted over its refusal to process donations to WikiLeaks.
Last month another 19-year-old, Ryan Cleary, was charged with attacks on Britain's Serious Organized Crime Agency and various UK-based music sites. Although at least one of the attacks he was charged with seemed linked to LulzSec, Topiary claimed at the time that Cleary was at most only tangentially involved with the group.
Scotland Yard said Wednesday it was also searching a residential address in Lincolnshire, in central England, and interviewing an unnamed 17-year-old in connection with the investigation. The second teen has not been arrested.

-News Source (IBN)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Google Pakistan Hacked & Defaced By Turkish Hacker

Google Pakistan Along With Microsoft  HP, HSBC, Apple, PayPal, Blogspot Hacked & Defaced By Turkish Hacker

Today was most probably the worst day in the history of Pakistan cyber space. Ten big domains of Pakistan has been stroked very badly. Many of you are guessing that it was Indian hackers who cost this damage. But in reality the attack was not generated from India, Bangladesh or such any other native countries,  but it was a Turkish hacker who have reportedly taken down the home and search page of Google Pakistan while leaving an image of two penguins walking across a bridge for million of users. I think now you got that, yes it was Google Pakistan which has been hacked and defaced by a Turkey hacker code named "KriptekS". In the deface page the hacker left several messages in Turkish language, the translation of the text, written on the website, is: "eboz. My homies in a friend always there for me. Have not shot by me with every breath." Also the hacker left a message saying "Pakistan Downed" which is indicating that the home page of Google Pakistan is indeed take down. According to deface mirror on Zone-H, the attack took place around 02:17 in the afternoon, but still, when I am writing this article, the home page of Google Pakistan is still offline. 
May be you are thinking that the story is over, but no; as I told earlier it was the worst day for Pakistani cyber fence, trust me indeed it was. As along with Google, KriptekS, the Turkish hacker also targeted Pakistani domain of Blogger, HSBC, Coca-Cola, Fanta, Paypal, Microsoft, HP & Apple. Also it has been reported that Pakistani domain of Sony, Yahoo & Windows has also been allegedly hacked. And all those hacked domains are still offline. 

List of Hacked Sites:-

http://www.google.com.pk
http://www.google.pk
http://www.hp.com.pk
http://www.apple.pk
http://www.hsbc.pk
http://www.blogspot.pk
http://www.coca-cola.pk
http://www.fanta.pk
http://www.paypal.pk
http://www.microsoft.pk
www.visa.com.pk
www.ebay.pk
www.msn.org.pk
www.sony.pk
www.windows.com.pk
www.yahoo.pk


Deface Mirrors:-

http://zone-h.com/mirror/id/18639529
http://zone-h.com/mirror/id/18639530
http://zone-h.com/mirror/id/18639528
http://zone-h.com/mirror/id/18639527
http://zone-h.com/mirror/id/18638930
http://zone-h.com/mirror/id/18638890
http://zone-h.com/mirror/id/18638879
http://zone-h.com/mirror/id/18638866
http://zone-h.com/mirror/id/18638824
http://zone-h.com/mirror/id/18638825
http://zone-h.com/mirror/id/18638826
http://zone-h.com/mirror/id/18638827
http://zone-h.com/mirror/id/18638828
http://zone-h.com/mirror/id/18638820
http://zone-h.com/mirror/id/18638822
http://zone-h.com/mirror/id/18638823


While talking about this dangerous cyber attack, we would like to remind you that few days ago couple of Pakistani hackers defaced several big Israeli domains including MSN, Bing, Live, Skype, Microsoft Store, BBC, CNN, Coca-Colla, XBOX, Windows, Intel, Philips, Israeli Parliament, Citi Bank and so on. Whether it is not clear that this attack on Pakistan has nay relation with that attack on Israel. But what we can say is that "KriptekS" exactly followed the same path, which Pak hackers shown the world few days ago. 




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

VOGH Exclusive: Xbox Live Outage Caused For Networking Misconfiguration, Not Hacker Attack

Microsoft Said Xbox Live Outage Caused For Networking Misconfiguration During Routine Maintenance, Not Hacker Attack 

Xbox Live -one of the world's most popular and usually very reliable gaming network which rarely has unexpected outages, nor does Microsoft ever take it down for any extended period of time. But accident occurs, and it happened in last Sunday. The software giant and the developer of Xbox - Microsoft has reported a significant Xbox Live outage, rendering the service unavailable since earlier last 13th afternoon, smack in the middle of the peak weekend usage period. The outage is preventing users from signing in to Xbox Live, blocking access to the online services normally available through the console. While acknowledging the issue, on their official Xbox Live Status page Microsoft said “There is still an issue members are having signing in to Xbox LIVE, we greatly appreciate you sticking it out with us while we work as hard as we can to get this problem fixed. Keep checking back here every 30 minutes for another update on our progress.” This update came from Microsoft at 3:30 Pacific time on 13th of April. As soon as this story get spotted, several hikes rises. Among this buzz, it was a few unnamed hacker who took credit of the Xbox outage, while declaring that a cyber attack. Another buzz which just got spread so quickly, was that the outage of Xbox Live network has been caused by hacker collective Anonymous.  Here we must have to say that those buzz have some solid reasons as couple of months ago Windows Azure faced an organized cyber attack which effected the service of Azure storage, Xbox Live and 52 other. And that outage or in other word service interruption stays for 12 long hours. But unlike earlier, this time the issue get resolved immediately. Within one hour all the service get restored and came back to its normal order. On the same Xbox Live Status page Microsoft said “If you were one of the members who was having issues signing in to Xbox LIVE, good news! This issue has been fixed! Thank you so much for your patience during this time, feel free to go enjoy your favorite games and content!”
So far we have discussed about the story of the outage and it's restoration. Now we will talk about the cause of this interruption. As I have said earlier that the rumor of hacker's attack was there which was claiming responsibility of the Xbox Live outage. But in reality it was not due to cyber attack but some internal network problems. In their official respond of the situation and those buzz Microsoft completely dines all those rumors and said  "The Xbox Live service outage on 13 April resulted from networking misconfiguration during routine maintenance and was in no way related to false claims of hacking the service." 
While talking about Xbox outage, we would like to remind you that - another world famous gaming console 'PlayStation' had fallen victim to cyber attacks. It was Anonymous who hit Sony PSN and caused massive outage, data leak and many other devastating damages







SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

FBI is ramping Up Cyber-Attack Defense



The FBI has been called to investigate cyber attacks at Google and Sony in the past week, incidents that shed light on "the ever-present danger from sophisticated Internet attack," FBI Director Robert Mueller said intestimony Wednesday before the Senate Judiciary Committee."Along with countless other cyber incidents, these attacks threaten to undermine the integrity of the Internet and to victimize the businesses and people who rely on it," he said.The hearing, a video of which is available online, was focused on President Obama's request to extend Mueller's term as director until 2013. The director gave an opening statement on threats facing the intelligence organization and how it's working to combat them, and then fielded questions from the committee.
Mueller cited cyber attacks as one of the FBI's top challenges in the next 10 years, and said the agency needs to step up efforts to combat them, something it's currently working on."The increase of cyber as a mechanism for conducting all sorts of crimes--and also it being a highway to extracting our most sensitive secrets or extracting IP from our commerce" is a key concern, he said. "We as an organization need to continue to grow the capability of addressing that arena in the future."In addition to addressing growing cybersecurity needs, Mueller cited other technology-focused priorities of the organization during his testimony. One is the use of the Internet for terrorist cells to communicate, organize, and radicalize new terrorists, something the FBI is aimed at stifling, he said."In the age of the Internet, these radicalizing figures no longer need to meet or speak personally with those they seek to influence," Mueller said. "Instead, they conduct their media campaigns from remote regions of the world, intent on fostering terrorism by lone actors here in the United States."Another concern Mueller said he will continue to work on is his quest for the intelligence agency to expand its wiretapping capability to avoid a problem known as "going dark." The term refers to situations in which the agency has legal authorization to obtain Internet communications but cannot do so in a timely fashion due to a company's lack of technology to get the information quickly and efficiently.
An increase in high-profile and sophisticated cyber attacks in the United States is pushing the FBI to bolster its ability to fight cybercrime and foster stronger cybersecurity, its director told Congress this week.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Apple Working On TV With Integrated Voice/Motion Controller & Gaming Console

Apple Working On TV With Integrated Voice/Motion Controller & Gaming Console

Apple is planning an assault on the living room with a TV that will come equipped with an Apple-branded, Kinect-like video game console. According to sources Apple is working on a television set with an iTunes-integrated touch screen remote and Siri-like voice command technology. The TV set will be coming before the end of 2012. Rumors and patents have said as much for the past year, so that’s nothing new. But that’s not all we’ve heard. Also it has come to light that Apple’s television set will come with an Apple-branded, Kinect-like video game console. The interface will rely heavily on motion and touch controls. The rumor gained more traction following claim made by Walter Isaccson in Steve Jobs’ biography that the late Apple CEO would ‘like to create an integrated television set that is completely easy to use’ that would ‘ seamlessly synced with all of your devices and with iCloud. ‘Jobs also claimed to have ‘finally cracked’ the user interface problem to make the whole package easy to use.
Here comes few Doubts:-
  • Outside of the iOS platform (iPhone and iPad), Apple isn’t known as a gaming company.
  • A TV with a built-in voice and motion controller and a games console? How much is this thing going to retail for exactly?
  • The games console market is tightly stitched up by Microsoft, Sony and Nintendo. Breaking into this new market would be extremely difficult.
  • Valve does have a portfolio of Mac games, but not enough to create a new ecosystem for a games console.
  • Apart from branding, what differentiates an Apple games experience from PC/Mac/Xbox 360/PS3?
  • Wouldn’t it make more sense for Apple to bring iOS games into the living room through an updated Apple TV set top box? There’s a massive ecosystem of games here ready to exploit, along with a healthy developer base.
  • That said, folks who own an iPhone/iPad and an Apple TV device can use AirPlay to put games on any HDMI-enabled TV without the need for an Apple-branded TV or an Apple-branded games console. Where does a console fit into the picture?

-Source (Cut of Mac, Forbes, Rumor) 





SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Thousands of E-Mails, Résumés at Risk After Eidos Hacking


Hackers might have accessed up to 25,000 e-mail addresses and 350 résumés during an attack on game developer Eidos Interactive’s websites, parent company Square Enix said Friday.
The security breach, which Square Enix said occurred Wednesday, could have given hackers access to user data for the Deus Ex: Human Revolution website, as well as résumés submitted by job applicants to Eidos.
“Square Enix can confirm a group of hackers gained access to parts of our Eidosmontreal.com websiteas well as two of our product sites,” the company told Joystiq. “We immediately took the sites offline to assess how this had happened and what had been accessed, then took further measures to increase the security of these and all of our websites, before allowing the sites to go live again.”
Square Enix added that it would be contacting all parties that might have been affected by the breach, emphasizing that no credit card information was compromised.
According to a report by former Washington Post writer Brian Krebs, the official Deus Ex: Human Revolution and Eidos websites were inaccessible Thursday morning. During this period, hackers reportedly put up a banner that read “Owned by Chippy1337.”
The hackers, Krebs wrote, said they plan to distribute the stolen information on file sharing networks. His report pegs the volume of information stolen, according to the hackers, to be the personal information of more than 80,000 users and 9,000 ésumés.
A recent Ars Technica report suggests there might be discord among members of hacking collective Anonymous, centering on a 17-year-old British hacker named Ryan. According to a chat log uncovered by Krebs, the Eidos hackers attempted to frame Ryan for the attack.
It’s unclear whether this is related to the crippling hack on Sony’s PlayStation Network several weeks ago that left millions of users’ personal information at risk. Anonymous has disavowed responsibility for that attack.
Neither Square Enix nor Eidos Interactive responded to Wired.com’s requests for comment Friday.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Square Enix Server Hacked, More Than 1.8 Million Gamers Accounts Compromised


Square Enix the famous franchise for the Final Fantasy and Dragon Quest compromised. The Square Enix Authority reported that a hacker gained unauthorized access to one of their servers thus the attacker managed to access the personal information of 1.8 million gamers in the US and Japan. Though the company spokes man claimed that no credit card information was compromised in this attack. The video game industry has been the target of several hacker attacks this year. Few days ago 13 million MapleStory players personal data was also stolen. It was one of the largest cyber attack happened in South Korea. Earlier such phenomena took place in Sony PSN breaching case, there more than 93K user details ware compromised
In an exclusive report it is demonstrated that  the target of the attack was a free fan site called Square Enix Members. Officials at Square Enix noticed the unauthorized access on December 12 and subsequently shut the site down to investigate. Members of the site register using their email addresses but some enter additional information like names, addresses and phone numbers. A spokesperson for Square Enix said no credit card information is stored on the server.
Those affected include 1 million users from Japan and 800,000 gamers in the US. As of writing, the Square Enix Members site remains offline, instead redirecting visitors to a page explaining the breach and actions the company is taking moving forward. The message indicates that the suspension will continue for a few days until the security team completes their investigation and counter-measures are in place.



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Four LulzSec Hackers Appeared In Court Together For The First Time


Four LulzSec Hackers Appeared In Court Together For The First Time

For the first time the four men, Ryan Ackroyd, 25, Ryan Cleary, 20, Jake Davis, 19 and a 17-year-old male who could not be named appeared in Court together. They are charged with taking part in cyber attacks under hacking group LulzSec, an offshoot of Anonymous, appeared in court Friday afternoon, appearing side-by-side for first time before a judge.  British prosecutors allege that the quartet last engaged with one another under the guises of online pseudonyms to wreak havoc on the web. These LulzSec key members are accused of accessing computers operated by News Corp. (NWSA) (NWSA)’s Twentieth Century Fox, Sony Corp. (6758), the U.K.’s National Health Service, the Arizona State Police, and technology-security company HBGary Inc.
Four of the eight counts listed in the updated British indictment today, were levelled solely on 20-year-old Cleary. He is accused of supplying a botnet — or a network of thousands of infected computers that can be used to paralyze websites — to others, and operating one himself to attack the website of DreamHost, a web hosting company. He is also accused of “installing and/or altering computer programs” on computers at the Pentagon controlled by the U.S. Air Force, between May 1 and June 22, 2011.
Cleary was the only one of the four defendants who was still in police custody. He was arrested on March 6 of this year — the same day Hector “Sabu” Monsegur was unveiled as an informant — for breaching his bail conditions. 
According to the new indictment, the four men also targeted denial of service attacks against: Westboro Baptist Church, which has staged anti-homosexual demonstrations at military funerals; the online role-playing game Eve Online; the U.S. Central Intelligence Agency; and Britain’s Serious Organised Crime Agency.





-Source (Forbes) 






SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Internet Criminals Targeting Smaller Companies


Last week Sony announced that its PlayStation Network fell victim to hackers. This was embarrassing for the company, worrisome for gamers and just proved that big companies remain targets. But last week Verizon also released its annual Data Breach Investigation and there was good news and bad news.
The good was that cyber criminals were far less successful in 2010, with the amount of data that was obtained or compromised falling dramatically last year. One reason cited is that law enforcement has begun to crack down on cyber crime, with one individual receiving a 20-year prison sentence last year. In total the Secret Service arrested more than 1,200 suspects last year for cyber crime violations.
So what’s the bad news? Instead of targeting large companies, it seems the new breed of cyber criminals is going after smaller companies that tend to be less well-guarded. According to reports, about 40 percent of the breaches were in the hospitality industry, 25 percent in retail and 22 percent in financial services.
Attacks against small business have been on the rise since 2008, and in according to a recent report from KnowBe4 in 2009 cyber criminals extracted nearly $400,000 from a Florida dentist’s account! Talk about a painful extraction.
But it was also a savvy style of attack, where Robert Thousand Jr. received thousands of calls to his business, home and mobile phones. These calls consisted of 30-second long recorded messages from a sex hotline – and these were done to keep Thousand’s phone lines tied up while cyber criminals made five transfers totaling $399,000 from a TD Ameritrade retirement account.
Cyber criminals also targeted lawyer Kimberly Graus, bypassing her anti-virus software to initiate $35,000 in wire transfers from a trust fund she managed. She was likely the victim of a phishing attempt, which installed malware that allowed hackers to capture her account passwords.
Both Graus and Thousand had virus protection in place, but today’s savvy hackers are finding inventive ways around it.
Part of the issue for small business is that identity theft is often a large component of the cyber crime. When fraud strikes it reportedly costs the average consumer $631 and take on average 130 hours to recover from identity theft
The good news is that help may be on the way. Last month President Barack Obama stated that he is looking to create an “identity ecosystem” that could include unique software that creates one-time digital passwords. This is part of the National Strategy for Trusted Identities in Cyberspace (NSTIC).
The most important thing to do is to always be on guard, and not to be the low hanging fruit for cyber crimina

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

After #opTurky, 32 Anonymous get busted by Turky Police



After hacker group Anonymous' apparently successful Operation Turkey to protest Internet censorship, the country's authorities have detained 32 people in connection with the attack on Turkish government Web sites.
After Friday's attack, Turkey's telecommunications authorities investigated and took the people into custody, according to a report today by Turkey's state news agency. Eight of those detained were under 18 years old, the report said.
The arrests come just days after Spain said Friday it arrested three Anonymous hackers in connection with attacks on Sony's PlayStation Network, governments, banks, and others. Retribution followed quickly, with an Anonymous attack that reportedly took a Spanish police off the Net.
The attacks take the form of a distributed denial of service (DDoS), which involves a coordinated flooding of a Web site with traffic with specially crafted network tools.
Security firm Sophos, though, said the Turkish attackers apparently used an attack tool called LOIC (Low Orbit Ion Cannon) that isn't terribly anonymous.
"LOIC...doesn't do a very good job of covering your tracks--making it potentially easy for computer crime authorities to track those behind the attacks," said Sophos' Graham Cluley.
A loose group of angry hacktivists is only one force spotlighting the Net's vulnerabilities today. The International Monetary Fund suffered what was reported over the weekend to be a major network breach. Google said it disrupted a plan the company said originated from China to break into Gmail accounts. It's open season for hackers.
One person's illicit hacker might be another person's sanctioned military authority, though. The United States and United Kingdom increasingly talk of cyberwar as just a facet of ordinary war.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Executives underestimate cybercrime danger


collage: data stream and eye

These are boom times for stolen data. Be it the publication of secret diplomatic cables on Wikileaks, foreign intelligence services mining data from German government computers, or the case of Sony, which had to admit that information on millions of customers had been hacked, the incidence of sensitive data being stolen from protected networks is on the rise.
German business leaders are well aware of this phenomenon, according to consulting firm Ernst & Young, which surveyed 400 executives on the topic of economic espionage and data theft. Almost all the respondents said they were convinced that the problem would become even more serious in the future, especially in countries and regions such as Asia, China, eastern Europe, Russia and the US.
However, Ernst & Young found a remarkable contradiction in its poll. While 94 percent of those leaders surveyed talked about the growing danger of cybercrime, 38 percent said they thought the threat to their own firm was rather small.



Digital denial
One-half of those polled said the danger posed to their companies was only moderate, and only one in ten admitted that their firms had been victims of corporate espionage or data theft in the past three years.
"This is far removed from reality," said Stefan Heissner, a security expert at Ernst & Young. "Our experience tells us that every company faces this risk, not just large corporations."
He added that many executives do not take the risk seriously enough.
"All information today can be accessed in some way and those who don't accept that live with a sense of false security," he said.


In-house problem
Sometimes simple online searches and the collection of data from different sources, available to anyone with an Internet connection, can lead to the assembly of amazingly complete troves of sensitive information.
Getting hold of important information doesn't always involve a talented hacker or direct access to a data-rich computer and a USB stick. Sometimes human vanity is enough, according to Heissner.
"Just think of the amounts of know-how some people reveal in speeches at conferences or trade fairs," he said. "It's sometimes really dramatic."

However, the most dangerous risk for companies is not hackers from another continent - experience bears out – but disgruntled in-house workers. In two-thirds of data theft cases, companies say their own employees were the guilty parties.
In about half of those instances, monetary gain was the motive, although one-third involved taking revenge for some kind of slight, perceived or otherwise.
"A good defense against data theft is satisfied employees," said Heissner.


Antitrust issues
Computers in a company's administration department are most frequently targeted, even more often than those in research and development sections. According to Heissner, that is because a company's administration usually has to have an immense amount of information on its computer drives just to be able market its own products.
That means data theft from these machines often becomes an antitrust issue if the material taken is related to product launches or pricing.
"Some cases where antitrust authorities suspect price collusion among companies are in fact instances of data theft by competitors," Heisser said.



Lax security
Many firms struggle to establish effective countermeasures to prevent data theft. While most companies do have a basic system of firewalls and passwords in place, big holes often remain.
Only one in five companies forbid CD burners or USB ports on its computers, which are often used by data thieves absconding with precious data. Only about 18 percent of companies prohibit employees from accessing the Internet. And just 6 percent have installed so-called intrusion detection systems, which can alert system administrators when outside parties try to breach computer security walls.
In addition, only one in ten firms is certified according to standards set out by the Federal Office of Information Security (BSI), which investigates IT security risks and develops preventive security measures.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

3 Anonymous suspects get busted in Spain


Police in Spain have arrested three cyber criminals who are suspected to be members of the online ‘hactivist’ group, Anonymous. The group has been in the news recently with their attack on the Sony PlayStation Network, the Indian army website as well as the Indian government website - NIC.According to the Spanish police Twitter feed, the hackers were arrested in Spanish cities of Barcelona, Alicante and Almeria and a server hosted in Gijon was seized, as well. They also claim that they have dismantled the Anonymous hacker group in Spain who were responsible for attacking the PlayStation Store. The police said that these individuals have the capacity to make decisions and direct attacks. They also claim that the group has the ability to coordinate DDoS attacks to collapse Web sites around the world and are considered a threat by NATO.
According to a report, these arrests were made after investigation which began in October 2010. The Spanish police say that the arrests were made after going through millions of lines of chat logs to discover who was behind the group’s activity. The report goes on to say that some of the attacks made by the group’s members used a web based tool called Loic to fill the targeted sites with the required data.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Plugs Internet Explorer Security Hole (Which was Exposed in A Contest)


Microsoft last week patched the last vulnerability in Internet Explorer (IE) used by a researcher in March to win $15,000 at the
The company had patched IE twice before to quash bugs exploited by Stephen Fewer of Harmony Security to bring down IE8 on Windows 7 at Pwn2Own. For his efforts, Fewer was awarded a cash prize of $15,000 and a Sony notebook.

Microsoft internet explorer Fewer chained three exploits , each for a different vulnerability, to bypass IE's sandbox, called "Protected Mode," and compromise IE8. Pwn2Own sponsor HP Tipping Point called the feat "impressive" at the time.
Microsoft patched the third IE bug in a multiple-flaw update to its browser, part of a 13-bulletin collection .
Although Microsoft credited Fewer in the MS11-057 bulletin for reporting the third vulnerability, it said the bug wasn't a security flaw. "Yes, this update addresses a Protected Mode bypass issue, publicly referenced as CVE-2011-1347," Microsoft said in response to an FAQ query, "Does this update contain any non-security related changes to functionality?"
At Pwn2Own, Fewer used the bypass bug to escape Protected Mode so he could circumvent the browser's sandbox, which allowed him to add a file to the machine, a task that mimicked a hacker's insertion of malware.

Fewer confirmed that last week's IE update fixed the final flaw he used at Pwn2Own.
"Yes MS11-057 patches the final bug, the protected mode bypass, that I used in my Pwn2Own exploit, the other two being a use-after-free which was patched in MS11-018 and an information leak patched in MS11-050," Fewer said today in an email reply to questions.

Earlier Flaws Addressed

MS11-018 and MS11-050 were the designations of the April and June bulletins, respectively, that patched the two other vulnerabilities he reported to Microsoft via Tipping Point's bug bounty program.
According to Aaron Portnoy, manager of TippingPoint security research team and the company's Pwn2Own organizer, Tuesday's IE update wraps up patching for the 2011 contest.
During Pwn2Own, Microsoft said that IE9, the browser that launched shortly after Fewer's hack, did not contain the bugs he exploited.
Including Tuesday's update, IE9 has been patched twice since its March launch. Of the August bugs Microsoft acknowledged as security issues, one was reported by Fewer.
"Yes, I have been doing some research into IE9 and actually my first IE9 vulnerability was also patched this Tuesday as part of MS11-057," Fewer said, referring to a separate bug he was credited with this week.
That flaw, dubbed "CVE-2011-1964," was reported via TippingPoint to Microsoft in May, and was ranked critical for IE9 when run on Vista or Windows 7.
Fewer wouldn't commit to taking on IE9 at next year's Pwn2Own, but he left the door open to a repeat performance. "I don't have any plans as of yet for next year's competition, but if I have a few new bugs handy closer to the time, who knows?"
August's security updates, including MS11-057 for IE, can be downloaded and installed via the Microsoft Update and Windows Update services, as well as through Windows Server Update Services.

-News Source (PC-World)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

SEGA Hacked



SEGA took the SEGA Pass system offline Thursday. Friday morning, it sent an email to Pass members alerting them that an unauthorized and unidentified third party had gained access to the SEGA Pass database. SEGA Pass, the gaming company’s member database and online network, has been hacked. Members’ email addresses, birth dates and encrypted passwords were obtained in the attack, according to the company. SEGA is also telling members that it has reset their passwords, that all access to SEGA Pass has been temporarily suspended and that Pass users should consider changing their passwords on other sites. No party has stepped up to claim responsibility as of yet, though hacker group LulzSec tweeted at SEGA Friday morning:


 “We want to help you destroy the hackers that attacked you. We love the Dreamcast, these people are going down.” Meanwhile, LulzSec recently claimed responsibility for hacking Sony’s and Nintendo’s servers, taking down the CIA’s website and hacking the U.S. Senate.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Samsung TV & BD Systems are Vulnerable to DoS & Remote Administration

Samsung TV & BD Systems are Vulnerable to DoS & Remote Administration 

The most recent bug, found in a wide range of high-definition TVs from Samsung, was disclosed on Thursday. Luigi Auriemma an Italy-based researcher who regularly finds security flaws in Microsoft Windows, video games, and so on. While poking around a Samsung D6000 model belonging to his brother, he inadvertently discovered a way to remotely send the TV into an endless restart mode that persists even after unplugging the device and turning it back on.
Vulnerability Description:-
All the current Samsung TV and BD systems can be controlled remotely via iPad, Android and other software/devices supporting the protocol used on TCP port 55000
The vulnerabilities require only the Ethernet/wi-fi network connected to be exploited so anyone with access to that network can do it. I have not tested if there are limitations on Internet or in big WANs. The remote controller feature is enabled by default like all the other services (over 40 TCP ports opened on the TV).
Bugs
When the controller packet is received on the device it displays a message on the screen for telling the user that a new "remote" device has been found and he must select "allow" or "deny" to continue. The message includes also the name and MAC address specified in the received packet, they are just normal strings (there is even a field containing the IP address for unknown reasons). For additional information click here
"It wasn't even planned," Auriemma told Ars, referring to the most damaging of his two attacks, which rendered the device useless for three days, until he finally found a way to restore it to normal operation. "I wanted only to show a message on the TV when my brother was watching it. He selected the 'deny' choice and boom."

The TV was connected by ethernet cable to a home network, so Auriemma thought it would be funny to use a computer connected to the same network to send it a message that contained a series of custom headers. Without warning, the TV spiraled into an endless loop of restarts. For about five seconds, the device would appear to work correctly, but then would stop responding to commands entered by remote control or through the panel. A few seconds later, the TV would restart and repeat the process. Unplugging the power cord or ethernet cable did nothing. Auriemma had just stumbled upon a crippling denial-of-service attack.

Auriemma said he sees no reason the attack couldn't be carried out over the Internet if the TV had a public IP address and used no filters. His discovery came two weeks after a separate researcher reported a DoS vulnerability in Sony Bravia TVs. Using the publicly available hping networking tool, Gabriel Menezes Nunes said he was able to seriously disrupt its operation.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Motorola’s Latest Phone will no loger be Friendly With Hackers


For phone modification junkies, the Android software platform comes with a host of mod-friendly features. It’s too bad, then, that Motorola’s latest Android phone lacks all of them.
Motorola’s Droid 3 features a locked boot loader, which is a program that loads the operating system software on every smart phone when it’s turned on. The company said it planned to change the policy this year.

The news first came from a Motorola support forums representative.

“As we’ve communicated, we plan to enable the unlock-able/re-lockable bootloader in future software releases, starting in late 2011, where channel and operator partners will allow it,” said a Motorola spokesperson in a statement provided to Wired.com. “DROID 3 is not built on a software version that includes this feature.”

Locking down the bootloader is a big pain for those who want to modify their Android phone operating systems. Essentially, it drastically limits the extent of modification and customization you can accomplish on your phone. If you wanted to install a particularly popular piece of modding software like, say, CyanogenMod — a very popular custom Android build that optimizes a phone’s hardware performance and adds a number of nifty flourishes — with a locked bootloader, you’re out of luck.

In today’s smart-phone landscape, handset manufacturers face pressure from wireless carriers like Verizon and AT&T to lock down phone boot-loaders. This is done especially to prohibit the potential installation of software used to do things that carriers don’t want you doing, like, say, capture licensed streaming content. There’s also software available that lets you tether your phone to your computer (providing it with an internet connection) for free, a feature for which wireless companies normally charge users. Bypassing that charge means cutting into a carrier’s bottom line.

Motorola doesn’t want to deal with the tech support nightmare that widespread phone hacks entail. “If you brick your phone messing with it” — which basically means rendering the device useless (like an electronic “brick,” as it were) — “we don’t want to have to fix it under warranty,” a Motorola representative wrote in a message board post.

Because of all this, hacker-unfriendly phones aren’t uncommon. Motorola’s Atrix debuted with a locked boot-loader, as have many of the company’s phones since the release of the Droid 2. Motorola’s upcoming Photon 4G smart-phone will also be locked down.

Android modification junkies aren’t happy about Motorola’s decisions. In March, one Motorola smartphone owner started an online petition, asking others who don’t agree with the company’s locked bootloader decisions to sign and bring up the issue on Moto’s Facebook page. As of this post’s publishing time, the petition has over 10,000 signatures.

Given the hardware specs on the Droid 3, it’s especially disappointing for hackers to see the phone debut as mod-unfriendly. The Droid 3 has a beefy dual-core 1GHz processor under the hood, which when used in conjunction with modding software, can be overclocked to faster speeds.

The future isn’t entirely grim for phone hackers. Motorola continually promises a change in locked bootloader policy come late-2011, and other companies like Sony Ericsson have even begun to court the modding community, providing a detailed list of instructions on how to unlock the company’s phones.

It seems as if the predominant feeling is: We’ll believe it when we see it.

“There’s not a single reason to believe that Motorola has truly changed their views,” wrote an angry Motorola message board user in a post. “We’re not saying you have to unlock all our devices now, but a little sign of good faith would be much appreciated.”

-News Source (Gadget Lab)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...