Showing posts sorted by relevance for query investigation. Sort by date Show all posts
Showing posts sorted by relevance for query investigation. Sort by date Show all posts

Facebook Law-Enforcement Tool


U.S. law-enforcement agencies are increasingly obtaining warrants to search Facebook, often gaining detailed access to users' accounts without their knowledge. A Reuters review of the Westlaw legal database shows that since 2008, federal judges have authorized at least two dozen warrants to search individuals' Facebook accounts. Many of the warrants requested a laundry list of personal data such as messages, status updates, links to videos and photographs, calendars of future and past events, "Wall postings" and "rejected Friend requests."
Federal agencies seeking the warrants include the FBI, DEA and ICE, and the investigations range from arson to rape to terrorism. The Facebook search warrants typically demand a user''s "Neoprint" and "Photoprint" -- terms that Facebook has used to describe a detailed package of profile and photo information that is not even available to users themselves. These terms appear in manuals for law enforcement agencies on how to request data from Facebook. The manuals, posted on various public-advocacy websites, appear to have been prepared by Facebook, although a spokesman for the company declined to confirm their authenticity.
The review of Westlaw data indicates that federal agencies were granted at least 11 warrants to search Facebook since the beginning of 2011, nearly double the number for all of 2010. The precise number of warrants served on Facebook is hard to determine, in part because some records are sealed, and warrant applications often involve unusual case names. (One example: "USA v. Facebook USER ID Associated with email address jimmie_white_trash@yahoo.com," a sealed case involving a drug sale.) In a telephone interview, Facebook's Chief Security Officer, Joe Sullivan, declined to say how many warrants had been served on the company. He said Facebook is sensitive to user privacy and that it regularly pushes back against law-enforcement "fishing expeditions."

NOT CHALLENGED:-

None of the warrants discovered in the review have been challenged on the grounds that it violated a person's Fourth Amendment protection against unlawful search and seizure, according to a review of the cases. Some constitutional-law experts said the Facebook searches may not have been challenged because the defendants - not to mention their "friends" or others whose pages might have been viewed as part of an investigation -- never knew about them.
By law, neither Facebook nor the government is obliged to inform a user when an account is subject to a search by law enforcement, though prosecutors are required to disclose material evidence to a defendant. Twitter and several other social-media sites have formally adopted a policy to notify users when law enforcement asks to search their profile. Last January, Twitter also successfully challenged a gag order imposed by a federal judge in Virginia that forbade the company from informing users that the government had demanded their data.
Twitter said in an email message that its policy was "to help users protect their rights." The Facebook spokesperson would not say whether the company had a similar policy to notify users or if it was considering adopting one.

THE CASE OF THE SATANISTS:-
In several recent cases, however, Facebook apparently did not inform account-holders or their lawyers about government snooping. Last year, several weeks after police apprehended four young Satanists who burned down a church in Pomeroy, Ohio, an FBI agent executed a search warrant on Facebook seeking data about two of the suspects. All four ultimately pleaded guilty and received sentences of eight to ten years in state prison (along with a message of forgiveness from a church official who called the sentence "God's time out," and presented them with a Bible). It is unclear if data obtained from the warrant was used in the investigation. Lawyers for the two defendants were unaware of the searches until they were contacted by Reuters.
In another case, the DEA searched the account of Nathan Kuemmerle, a Hollywood psychiatrist who pleaded guilty in Los Angeles federal court after a joint operation last year by the DEA and local police revealed he had run a "pill mill" for celebrity customers.
Westlaw records show that that the DEA executed a warrant to search Kuemmerle's Facebook account weeks after his arrest.
At Kuemmerle's bail hearing, a Redondo Beach police detective pointed to comments Kuemmerle made on Facebook and in the site's popular game "Mafia Wars" to argue that he should be denied bail.
According to Kuemmerle's lawyer, John Littrell, the detective testified on cross-examination that the information was from "an undercover source." Littrell told Reuters that neither he nor his client was ever informed about the warrant, and that he only learned of its existence from Reuters.
The detective said in an e-mail message that he did not recall being asked about how he obtained the Facebook information. The DEA did not reply to requests for comment.

POTENTIAL FOR NEW LEGAL CHALLENGES:-
The Facebook searches potentially open up new legal challenges in an area that at one time seemed relatively settled: How much protection an individual has against government searches of personal information held by third parties. In a 1976 case, United States v. Miller, a divided U.S. Supreme Court ruled that a bank did not have to inform its customer when it turned over his financial records to the Bureau of Alcohol, Tobacco and Firearms.
In doing so, the Supreme Court held that the customer could not invoke Fourth Amendment rights against illegal search and seizure because the records were bank property in which he had no legitimate "expectation of privacy."
Under this reasoning, a person would have no more expectation of privacy in Facebook content than in bank records. A key difference, however, is the scale of information that resides on social networking sites. "It is something new," said Thomas Clancy, a constitutional-law professor at the University of Mississippi. "It''s the amount of information and data being provided as a matter of course by third parties."
Eben Moglen, a cyberlaw professor at Columbia Law School, says the Facebook searches show that courts are ill-equipped to safeguard privacy rights in an age of digital media. In his view, "the solutions aren't legal, they''re technical."
Clancy, the Mississippi professor, said that courts are divided over whether the unprecedented volume of digital records in the possession of third parties should give rise to special rules governing the search of electronic data.
He added that the Supreme Court had an opportunity to clarify the issue in a case called Ontario v. Quon, but that it decided to "punt."
The Quon case concerned a California policeman who claimed his employer violated his Fourth Amendment rights when it read sexually explicit messages that he had sent from a work pager.
The Court found that that the employer's search was not unreasonable, but declined to rule on the degree to which people have a privacy interest in electronic data controlled by others.
Explaining the court's caution, Justice Anthony Kennedy wrote, "The judiciary risks error by elaborating too fully on the Fourth Amendment implications of emerging technology before its role in society has become clear."

To download the Facebook Law Enforcement Guidance click Here


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Three Secrets & Full Analysis of Flame's Command & Control Servers Unraveled

Three Secrets & Full Analysis of Flame's Command & Control Servers Unraveled

Flame the next generation cyber weapon which is also known as 'The Super Spy' has already fascinated the cyber-security industry with its sophistication and versatility as a Swiss-Army knife of cyber-spying. Recently security firm Kaspersky lab has published a new report on the sophisticated nation-state sponsored Flame cyber-espionage campaign. During the research, conducted by Kaspersky Lab in partnership with International Telecommunication Union’s cybersecurity executing arm - IMPACT, CERT-Bund/BSI and Symantec, a number of Command and Control (C&C) servers used by Flame’s creators were analyzed in detail. The analysis revealed new, groundbreaking facts about Flame. Particularly, traces of three yet undiscovered malicious programs were found, and it was discovered that the development of the Flame platform dates back to 2006.

Main findings:
  • The development of Flame’s Command and Control platform started as early as December 2006.
  • The C&C servers were disguised to look like a common Content Management System, to hide the true nature of the project from hosting providers or random investigations.
  • The servers were able to receive data from infected machines using four different protocols; only one of them servicing computers attacked with Flame.
  • The existence of three additional protocols not used by Flame provides proof that at least three other Flame-related malicious programs were created; their nature is currently unknown.
  • One of these Flame-related unknown malicious objects is currently operating in the wild.
  • There were signs that the C&C platform was still under development; one communication scheme named “Red Protocol” is mentioned but not yet implemented.
  • There is no sign that the Flame C&Cs were used to control other known malware such as Stuxnet or Gauss.
The Flame cyber-espionage campaign was originally discovered in May 2012 by Kaspersky Lab during an investigation initiated by the International Communication Union. Following this discovery, ITU-IMPACT acted swiftly to issue an alert to its 144 member nations accompanied with the appropriate remediation and cleaning procedures. The complexity of the code and confirmed links to developers of Stuxnet all point to the fact that Flame is yet another example of a sophisticated nation-state sponsored cyber operation. Originally it was estimated that Flame started operations in 2010, but the first analysis of its Command and Control infrastructure (covered by at least 80 known domains names) shifted this date two years earlier.
The findings in this particular investigation are based on the analysis of the content retrieved from several C&C servers used by Flame. This information was recovered despite the fact that Flame’s control infrastructure went offline immediately after Kaspersky Lab disclosed the existence of malware. All servers were running the 64-bit version of the Debian operating system, virtualized using OpenVZ containers. Most of the servers’ code was written in the PHP programming language. Flame’s creators used certain measures to make the C&C server look like an ordinary Content Management System, in order to avoid attention from the hosting provider.
Sophisticated encryption methods were utilized so that no one, but the attackers, could obtain the data uploaded from infected machines. The analysis of the scripts used to handle data transmissions to the victims revealed four communication protocols, and only one of them was compatible with Flame. It means that at least three other types of malware used these Command and Control servers. There is enough evidence to prove that at least one Flame-related malware is operating in the wild. These unknown malicious programs are yet to be discovered.
Another important result of the analysis is that the development of the Flame C&C platform started as early as December 2006. There are signs that the platform is still in the process of development, since a new, yet not implemented protocol called the “Red Protocol” was found on the servers. The latest modification of the servers’ code was made on May 18, 2012 by one of the programmers.
“It was problematic for us to estimate the amount of data stolen by Flame, even after the analysis of its Command and Control servers. Flame’s creators are good at covering their tracks. But one mistake of the attackers helped us to discover more data that one server was intended to keep. Based on this we can see that more than five gigabytes of data was uploaded to this particular server a week, from more than 5,000 infected machines. This is certainly an example of cyber espionage conducted on a massive scale,” commented Alexander Gostev, Chief Security Expert, Kaspersky Lab. 
Here we want to remind you that after the episode of 'Duqu'; In the middle of this year The Iranian Computer Emergency Response Team (MAHER) claims to have discovered a new targeted Stuxnet attacking the country's internal system. This newly found Stuxnet have been dubbed Flame (also known as Flamer or Skywiper). Later it was spotted in the wild when software giant Microsoft confirmed that its Windows Server Update Services (WSUS), Windows Update (WU) has been infected by Flame malware. Also in many fields, the name of 'Flame' was on the high node. 
For detailed analysis on Flame's command and control (C&C) servers click Here

-Source (Kaspersky)


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Anonymous Exposed The Private Information of The Special Agent, Officers, Cyber Crime Investigators Of Department Of Justice


The hacktivists claim to have hacked into Baclagan's Gmail account and to have accessed his voicemails and SMS message logs using unspecified techniques as part of their ongoing campaign against law enforcement officials and their "allies" in the computer security industry.
The email dump, released as a torrent last Friday in part of what has become the group's regular FuckFBIFriday release, is also said to contain personal information including Baclagan's home address and phone number. The cache of emails – which according to AntiSec are from the account of Fred Baclagan, a retired special agent supervisor of the Californian Department of Justice – includes 38,000 emails detailing various computer forensic techniques and cybercrime investigation protocols. 
Baclagan told that he was nobody special in the Justice Department ... which is what he would say, of course. He said that he had specialised in identity theft before he retired last year. "I'm really just a nobody," he told the Post, "just a local investigator, not involved in anything dynamic or dramatic

In the Press Release Anon Said:-

################################################################################
#        ANTISEC LEAKS DOJ SPECIAL AGENT SUPERVISOR'S PRIVATE EMAILS,         #
#               IACIS CYBERCRIME INVESTIGATOR COMMUNICATIONS                              #
#         care of the #OCCUPYWALLST CRACKDOWN RETALIATION TASK FORCE         #       
################################################################################

Greetings Pirates, and welcome to another exciting #FuckFBIFriday release.

As part of our ongoing effort to expose and humiliate our white hat enemies, we
targeted a Special Agent Supervisor of the CA Department of Justice in charge of
computer crime investigations. We are leaking over 38,000 private emails which
contain detailed computer forensics techniques, investigation protocols as well
as highly embarrassing personal information. We are confident these gifts will 
bring smiles to the faces of our black hat brothers and sisters (especially 
those who have been targeted by these scurvy dogs) while also making a mockery 
of "security professionals" who whore their "skills" to law enforcement to 
protect tyrannical corporativism and the status quo we aim to destroy.

We hijacked two gmail accounts belonging to Fred Baclagan, who has been a cop
for 20 years, dumping his private email correspondence as well as several dozen 
voicemails and SMS text message logs. While just yesterday Fred was having a 
private BBQ with his CATCHTEAM high computer crime task force friends, we were 
reviewing their detailed internal operation plans and procedure documents. We 
also couldn't overlook the boatloads of embarrassing personal information about 
our cop friend Fred. We lulzed as we listened to angry voicemails from his 
estranged wives and ex-girlfriends while also reading his conversations with 
girls who responded to his "man seeking woman" craigslist ads. We turned on his 
google web history and watched him look up linux command line basics, golfing 
tutorials, and terrible youtube music videos. We also abused his google 
voice account, making sure Fred's friends and family knew how hard he was owned.

Possibly the most interesting content in his emails are the IACIS.com internal
email list archives (2005-2011) which detail the methods and tactics cybercrime 
units use to gather electronic evidence, conduct investigations and make 
arrests. The information in these emails will prove essential to those who want 
to protect themselves from the techniques and procedures cyber crime 
investigators use to build cases. If you have ever been busted for computer 
crimes, you should check to see if your case is being discussed here. There are 
discussions about using EnCase forensic software, attempts to crack TrueCrypt 
encrypted drives, sniffing wireless traffic in mobile surveillance vehicles, how 
to best prepare search warrants and subpoenas, and a whole lot of clueless 
people asking questions on how to use basic software like FTP. In the end, we
rickrolled the entire IACIS list, causing the administrators to panic and shut
their list and websites down.

These cybercrime investigators are supposed to be the cream of the crop, but we
reveal the totality of their ignorance of all matters related to computer
security. For months, we have owned several dozen white hat and law enforcement
targets-- getting in and out of whichever high profile government and corporate
system we please and despite all the active FBI investigations and several
billion dollars of funding, they have not been able to stop us or get anywhere
near us. Even worse, they bust a few dozen people who are allegedly part of an
"anonymous computer hacking conspiracy" but who have only used 
kindergarten-level DDOS tools-- this isn't even hacking, but a form of
electronic civil disobedience. 

We often hear these "professionals" preach about "full-disclosure," but we are
sure these people are angrily sending out DMCA takedown notices and serving
subpoenas as we speak. They call us criminals, script kiddies, and terrorists, 
but their entire livelihood depends on us, trying desperately to study our 
techniques and failing miserably at preventing future attacks. See we're cut 
from an entirely different kind of cloth. Corporate security professionals like
Thomas Ryan and Aaron Barr think they're doing something noble by "leaking" the
public email discussion lists of Occupy Wall Street and profiling the "leaders"
of Anonymous. Wannabe player haters drop shitty dox and leak partial chat logs
about other hackers, doing free work for law enforcement. Then you got people 
like Peiter "Mudge" Zatko who back in the day used to be old school l0pht/cDc 
only now to sell out to DARPA going around to hacker conventions encouraging 
others to work for the feds. Let this be a warning to aspiring white hat 
"hacker" sellouts and police collaborators: stay out the game or get owned and 
exposed. You want to keep mass arresting and brutalizing the 99%? We'll have to 
keep owning your boxes and torrenting your mail spools, plastering your personal 
information all over teh internets.

Hackers, join us and rise up against our common oppressors - the white hats, the 
1%'s 'private' police, the corrupt banks and corporations and make 2011 the year 
of leaks and revolutions! 

We are Anti-Security,
We are the 99%
We do not forgive.
We do not forget.
Expect Us!

For More information Click Here


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Anonymous Releases More than 1 GB Restricted Document of NATO


The hacking collective Anonymous released a document on Thursday marked "restricted" from the North Atlantic Treaty Organization (NATO). The 36-page document, which is dated Aug. 27, 2007, appears to be budget and equipment outlays for what was termed a new "HQ ISAF JOINT CIS CONTROL CENTRE." NATO's press office could not be immediately reached.
Anonymous claimed on its "AnonymousIRC" Twitter handle that it has 1GB of material from NATO but said that most would not be published because it would be "irresponsible."
In another Tweet, Anonymous said that the data was harvested via "simple injection," which usually refers to inputting malformed data in Web-based forms and seeing if the back-end database responds with information.


The group prefaced its release of the NATO document with an earlier comment on Twitter about its alleged trove of e-mail from the British tabloid The Sun, part of Rupert Murdoch's News Corp. media group that is under investigation for voicemail interception and paying police officers for information.

"We think actually we may not release emails from The Sun, simply because it may compromise the court case," according to a Twitter post from Anonymous.
LulzSec, known as LulzSecurity, claimed credit on Twitter on Monday for that attack, but the two groups are somewhat aligned. Although LulzSec said it was going dormant after a string of highly successful attacks against the U.S. Central Intelligence Agency, PBS.org and Fox.com, among others, it appears to be back in action. LulzSec hit The Sun's website on Monday, posting a fake news story that Murdoch had died.

The two groups also posted a statement on Pastebin directed at Steven Chabinsky, a deputy assistant director in the U.S Federal Bureau of Investigation's cyberdivision.
"Your threats to arrest us are meaningless to us as you cannot arrest an idea," the statement said. "Any attempt to do so will make your citizens more angry until they will roar in one gigantic choir."

-News Source (PC World)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Three Hackers From Anonymous Arrested In Greece

Three Hackers From Anonymous Arrested In Greece 

Earlier this month Greece faced massive cyber attack from Anonymous and after investigation Greek police said they had arrested an 18-year-old suspected of hacking into the justice ministry's website. Also two other suspect aged 16 & 17 also being sought over the case.  In the February 2nd hackers from anonymous performed a cyber-attack on the Greek Ministry of Justice website, and warned of plans to target a further 300 ministry and media sites. The hack was apparently a protest against the Greek government's signing of the Anti-Counterfeiting Trade Agreement (ACTA), which is designed to reduce Internet piracy. After that Greek police confirmed via twitter that they have started investigation and all the countermeasures have been taken. Indeed the output is in-front of us, 3 teenagers from Greece are behind the bar. The authority also said- The three youths have been linked to dozens of cyber attacks against Greek websites, using the alias Greek Hacking Scene and the nicknames "delirium", "nikpa" and "extasy". Authority also confirmed that these teens may have to face 1 year of imprisonment.
This the second time of this year when hackers from Anonymous get busted by police. In January a 22 year aged student arrested in south-western Poland for allegedly hacking the prime minister's website and local authority said that he was a part of Hactivist Anonymous. 




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

TDL is Targeting Windows PC, Experts are saying that "it is almost indestructible"


More than four million PCs have been enrolled in a botnet security experts say is almost "indestructible". The botnet, known as TDL, targets Windows PCs and is difficult to detect and shut down. targeting
Code that hijacks a PC hides in places security software rarely looks and the botnet is controlled using custom-made encryption.
Security researchers said recent botnet shutdowns had made TDL's controllers harden it against investigation.
The 4.5 million PCs have become victims over the last three months following the appearance of the fourth version of the TDL virus. The changes introduced in TDL-4 made it the "most sophisticated threat today," wrote Kaspersky Labs security researchers Sergey Golovanov and Igor Soumenkov in a detailed analysis of the virus. "The owners of TDL are essentially trying to create an 'indestructible' botnet that is protected against attacks, competitors, and anti-virus companies," wrote the researchers.
Recent successes by security companies and law enforcement against botnets have led to spam levels dropping to about 75% of all e-mail sent, shows analysis by Symantec.
A botnet is a network of computers that have been infected by a virus that allows a hi-tech criminal to use them remotely. Often botnet controllers steal data from victims' PCs or use the machines to send out spam or carry out other attacks.
The TDL virus spreads via booby-trapped websites and infects a machine by exploiting unpatched vulnerabilities. The virus has been found lurking on sites offering porn and pirated movies as well as those that let people store video and image files. The virus installs itself in a system file known as the master boot record. This holds the list of instructions to get a computer started and is a good place to hide because it is rarely scanned by standard anti-virus programs.
The biggest proportion of victims, 28%, are in the US but significant numbers are in India (7%) and the UK (5%). Smaller numbers, 3%, are found in France, Germany and Canada.
However, wrote the researchers, it is the way the botnet operates that makes it so hard to tackle and shut down.
The makers of TDL-4 have cooked up their own encryption system to protect communication between those controlling the botnet. This makes it hard to do any significant analysis of traffic between hijacked PCs and the botnet's controllers.
In addition, TDL-4 sends out instructions to infected machines using a public peer-to-peer network rather than centralised command systems. This foils analysis because it removes the need for command servers that regularly communicate with infected machines.
"For all intents and purposes, [TDL-4] is very tough to remove," said Joe Stewart, director of malware research at Dell SecureWorks to Computerworld. "It's definitely one of the most sophisticated botnets out there."
However, the sophistication of TDL-4 might aid in its downfall, said the Kaspersky researchers who found bugs in the complex code. This let them pry on databases logging how many infections TDL-4 had racked up and was aiding their investigation into its creators.

-News Source (BBC)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Chinese Hackers Breached The NASA Jet Propulsion Lab

Chinese Hackers Breached The NASA Jet Propulsion Lab 

Chinese hackers gained illegal access NASA Jet Propulsion Laboratory (JPL). According to the investigation report of the Inspector General- hackers from China have breached the NASA JPL earlier in November and stolen sensitive data. Not only data stealing they have breached the security system of JPL which allowed them to delete sensitive files, add user accounts to mission-critical systems, upload malware and many more. That report revealed scant details of an ongoing investigation into the incident against the Pasadena, Calif., lab, noting only that cyberattacks against the JPL involved Chinese-based Internet Protocol (IP) addresses. Paul K. Martin, NASA's inspector general, put his conclusions bluntly."The attackers had full functional control over these networks," he wrote.
If you dig the history you will find that previously NASA was hit many times by the hackers from different part of the world. Such as Spamers targeted NASA, TeaMp0isoN hacked NASA official forum, Chinese Hackers hit NASA satellites, Indian hacker minhal stole secrete  information from NASA and so on. 



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Anonymous Member John Anthony Borell Charged For Hacking into Utah Police & Salt Lake City Police Dept

Anonymous Member John Anthony Borell Charged For Hacking into Utah Police & Salt Lake City Police Dept

FBI successfully tracked the #OpPiggyBank of Anonymous where two hackers from Anonymous named CabinCr3w & ItsKahuna took responsibility of hacking into the database of the Salt Lake City PD and exposed confidential information such as Full name of the Employ, Address, Phone Number, email-id, password hash and so on. According to a report of Huffington Post - An Ohio man linked to the hacker collective "Anonymous" pleaded not guilty Monday to charges of breaching the websites of the Utah Chiefs of Police Association and the Salt Lake City Police Department. John Anthony Borell III took credit for the attacks on Twitter, said FBI officials, who subpoenaed the direct messages the suspect traded with Salt Lake City reporters. The FBI traced Borell's Twitter account to a workplace computer.
"That didn't hurt the investigation, of course, when people make comments like that," FBI agent David Johnson said Monday. Borell appeared with a public defender at federal court in Salt Lake City after being released from a halfway house for the appearance. He faces 10 years in prison and a $250,000 fine if convicted on two counts of computer intrusion, prosecutors said. FBI agents say they don't know what motivated an Ohio man to tamper with the Utah police websites in January. Prosecutors say Borell intruded on the chiefs' website server Jan. 19, then broke into the police department's website Jan. 31. Salt Lake City police spent $33,000 to repair damage to their website and shore up security, and the hacker was able to access citizen's supposedly confidential crime tips and even some personal information on police officers, Johnson said. Borell was recently arrested after Federal Bureau of Investigations agents found him using Twitter and Internet Relay Chat logs. The investigation was spurred by two tips sent in to tips.fbi.gov and ic3.gov that stated Borell was a member of hacking collective Anonymous. It also provided a number of pseudonyms he was associated with including Kahuna, TehTiger, and anonJB.
The indictment states that Borell used the SQL Injection technique to access and take down the websites utahchiefs.org and slcpd.com (Salt Lake City Police Department). The FBI found Twitter direct messages and tweets in which Borell admitted to taking down the websites. Further proof of his identity was found when the FBI looked through chat logs in IRC. There, Borell explained that his father was an attorney and was advising him against talking to the FBI. Agents searched Ohio-based attorneys and found two local attorneys named “John Anthony Borell Esq.”
We would also like to give you reminder that another member of Anonymous affiliated CabinCr3w named Higinio O. Ochoa III, also get busted after he posted girlfriend's breast photo.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Crime Investigation Department (CID) West Bengal Hacked By XtReMiSt


Another big strike by Pakistani hackers. After the Mumbai Cyber Cell website hacking now they moved to West Bengal. The official website Crime Investigation Department CID West Bengal get hacked and defaced by XtReMiSt of Muslim Liberation Army (MLA). The hacker hijacked the CID server and all the three websites of CID get hacked. XtReMiSt said he has full control of teh server and also all the secrete information, Database get compromised. We must have to say that this is another big boom from the Pakistani Hackers. Now definitely one question arises and that is what the Indian Govt is thinking about the cyber security???

Hacked Sites:-
www.cidwestbengal.gov.in
www.cidwestbengal.com
www.cidwestbengal.org

Mirror Links:-
http://zone-h.org/mirror/id/15718411
http://zone-h.org/mirror/id/15718412
http://zone-h.org/mirror/id/15718413



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

2 Norwegian Teen Hackers of "TeaMp0isoN" Arrested By British Police

2 Norwegian Teen Hackers of "TeaMp0isoN" Arrested By British Police (PCeU)

Earlier in last month MI6 arrested the leader of TeaMp0isoN code named "TriCk" along with few other active members who ware directly involved behind the Denial of Service attack on MI6. Now two Norwegian teenagers, aged 18 and 19, have been arrested in connection with the distributed denial-of-service (DDoS) attack on the web site for the UK's Serious Organised Crime Agency (SOCA) and for swamping British intelligence agency (MI6) hotline with automated Skype calls. These two hackers ware the active members of hacker collective TeaMp0isoN and MLT. These two suspects are arrested in Newcastle on Wednesday evening, and is being questioned about offences under the Computer Misuse Act. Computer equipment has been seized for forensic analysis - and no doubt investigators are hoping that they may find digital clues which could help uncover other suspected hackers. Erik Moestue, a Norwegian prosecutor, said "We have arrested the two we think were most important in these attacks, but we still want to talk to more people". The offence that the two stand accused of carries a maximum jail sentence of six years. "The case is still under investigation," added Moestue, noting that "It is still too early to say anything about the motive for the actions"
The authorities, no doubt, will be hoping to confirm that they have arrested the correct man. Certainly, MLT's Twitter account has been silent since 6:27pm on Wednesday evening. According to the authorities these arrest is part of an ongoing investigation by the Police Central e-Crime Unit (PCeU) division of the Metropolitan Police into various hacking gangs who have made headlines in the last year or so. 
Earlier TeaMp0isoN was directly involved with Anonymous in #OpRobinHood #OpCensorThis. Also they have found SQL-i vulnerability on the Official NASA forum, and like this attack TeaMp0isoN also hacked English Defence League (EDL) ,T-Mobile USA, BlackBerry blog and many more





SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

FBI says it is "reviewing" PSN security breach


FBI says it is "reviewing" PSN security breach
The Federal Bureau of Investigation (FBI) is currently "reviewing" a recent security breach that compromised user data and downed the PlayStation Network (PSN) for over a week.
"The FBI is aware of the reports concerning the alleged intrusion into the Sony on line game server and we have been in contact with Sony concerning this matter," special agent Darrell Foxworth told Kotaku.
"We are presently reviewing the available information in an effort to determine the facts and circumstances concerning this alleged criminal activity."
Meanwhile, at least two dozen state AG's have kicked off their own investigation of the incident, with the FTC confirming it could theoretically claim jurisdiction in a case that involved loss of customer data via a securitybreach. 


"The fact that sensitive information was apparently accessed without authorization makes me especially concerned about the possibility of financial fraud and targeted phishing scams," Connecticut Attorney General George Jepsen wrote in an official letter to SCE CEO Jack Tretton.
"What is more troubling is Sony's apparent failure to promptly and adequately notify affected individuals of this large-scale breach."
As expected, a number of other countries aside from the United States have expressed concern over the embarrassing and damaging security lapse.
For example, the city of Taipei (Taiwan) is apparently demanding that Sony provide satisfactory details about the leak within 10 days or face heavy fines for alleged breaches of local consumer protection laws. 
"Manufacturers and service providers should take responsibility for their customers' reasonable expectations of security, including personal information security," Taiwan capital's Law and Regulation Commission said in a letter obtained by PC World.
"This incident [is said to] involve leaks of consumer names, e-mails, birth dates and even credit card information."


Indeed, security researchers say stolen credit card information may already be up for sale on various Internet forums.
"The hackers that hacked PSN are selling off the DB. They reportedly have 2.2 million credits cards with CVVs," Trend Micro security expert Kevin Stevens claimed in a tweet.
"Supposedly the hackers selling the DB says it has: fname, lnam, address, zip, country, phone, email, password, dob, ccnum, CVV2, exp date... It is not a rumor, it was a conversation on a criminal forum. [Still], I never saw the DB so I can't verify if it is real."

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Phone-hacking laws are 'very uneven and unclear'

Sir Christopher Graham
The information commissioner has told a powerful group of MPs that legislation outlawing phone hacking is "very uneven" and "very unclear" and the law should be clarified.
Christopher Graham told the home affairs select committee that existing legislation outlawing the practice "was drawn up for another age and other circumstances".
The committee is investigating the legal framework surrounding phone hacking following revelations that the News of the World commissioned a private investigator to illegally intercept voicemail messages belonging to dozens of public figures.
Since the committee began its inquiry the paper has apologised to eight victims who are suing its owner, News Group Newspapers, in the high court and offered to pay them compensation. The total bill is likely to run to many millions of pounds.
The information commissioner pointed out he is not responsible for enforcing the legislation which outlaws phone hacking, including the Regulation of Investigatory Powers Act, but told MPs it needs to be updated.
He said he was monitoring the dispute between the director of public prosecutions Keir Starmer and John Yates, the assistant commissioner of the Metropolitan police.
Starmer has contradicted Yates's claim that Starmer originally advised the Met that no offence was committed unless a voicemail message is intercepted before it has been listened to by its intended recipient. Yates told the home affairs committee earlier this month that advice "permeated the entire investigation".
Graham said on Tuesday: "We are a very interested bystander because there is a lack of clarity about where the law stands."
The information commissioner added: "At the moment you've got a regulatory vacuum because there's no equivalent of the information commissioner acting as a regulator giving advice and guidance."
Graham also said stiffer sentences should be imposed for illegally "blagging" information and revealed the Ministry of Justice is considering introducing measures that would allow judges to impose prison sentences of up to two years for the offence.
The maximum sentence for obtaining confidential information such as medical records or phone numbers by calling a company or public body posing as someone else is currently a £5,000 fine. Graham told MPs that blagging was a multimillion pound industry and that custodial sentences are needed to clamp down on "a very profitable business".
Graham said "tens" of public figures who are suing the News of the World for invasion of privacy have written to his office to discover if they were the victims of "blagging". He added that "less than a dozen" have obtained court orders requiring the commissioner to make available any information it has on whether they were victims of the practice.
The Information Commissioner's Office conducted an investigation called Operation Motorman in 2003 looking at Steve Whittamore, a private investigator who specialised in obtaining information from mobile phone companies, tax authorities and other public bodies, which resulted in his arrest and conviction. Some of the public figures suing the News of the World have asked it to provide relevant information from that inquiry.
Graham also criticised mobile phone operators for failing to advise their customers on the measures they should take to ensure their phones and other devices are secure.
He said he did not know whether mobile phone operators had written to their customers informing them they had been targeted by Glenn Mulcaire, the private investigator who was on the News of the World's books until August 2006, when he was arrested for illegally intercepting voicemail messages.
He said it was not his job to advise them on whether they should hand over that information and he hasn't given them guidance about whether to do so.
Yates claimed during evidence to MPs on the culture, media and sport select committee that the Met had asked mobile phone companies to warn customers who may have been targeted by Mulcaire.
All four leading mobile phone companies have since denied they received such a request.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...