Showing posts sorted by relevance for query social networking. Sort by date Show all posts
Showing posts sorted by relevance for query social networking. Sort by date Show all posts

Facebook Started Enabling HTTPS by Default for North American Users

Facebook Started Enabling HTTPS by Default for North American Users

The social networking giant Facebook has started securing all data traffic to the social networking site using HTTPS by default. The change started rolling out to all North American users last week, while users in the rest of the world should see HTTPS enabled by default soon. This change will make HTTPS the default connection option for all Facebook sessions for those users, a shift that gives them a good baseline level of security and will help prevent some common attacks. Switching to HTTPS by default will mean that all connections and data, including cookies, will be transmitted over SSL in encrypted form and should no longer be able to be easily read and used for fraudulent purposes by attackers. While Facebook has used HTTPS connections to protect users' login credentials for some time, it only started offering an HTTPS option for the entire site in January 2011. The feature was not turned on by default and instead required users to manually enable the HTTPS option in their Facebook account settings.
Facebook users have had the option of turning on HTTPS since early 2011 when the company reacted to attention surrounding the Firesheep attacks. However, the technology was not enabled by default and users have had to in and manually make the change in order to get the better protection of HTTPS. 
Now, users will have to manually turn HTTPS off if they don't want it, a distinction that is a major change, especially for Facebook's massive user base, which has become a major target for attackers





SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Wisconsin University Hacked (75,000 social security numbers, Student Credentials Exposed)


The University of Wisconsin’s Milwaukee campus has been subject to a malware attack, which has exposed names and social security numbers of students — past and present — and staff alike.
Malware was discovered on a database server, which contained 75,000 social security numbers, and was shut down immediately after the malware was found.
While law enforcement and school investigators have yet to find evidence that data was stolen, the university sent out a letter to those who may have been affected by the breach.
In a statement, the vice-chancellor — the university boss — believes that the motive was theft of research project data; data and research programmes the university itself excels in. Staff found back-door malware, which can scan and view documents on a server, which is used by many of the university’s departments to store crucial research.
One of the concerns is that the malware could have had access to other servers, indicating the likelihood of a wider hack.
The malware is thought to have been installed on May 25th, and local and federal law enforcement were called in to investigate. On June 30th, however, it was discovered that the database containing social security numbers was compromised, also.
University officials, via a notice on their website, warn students to monitor their financial information and credit card statements to be on the safe side.
This news comes only days after it was discovered that users’ data, including social security numbers — predictable in nature — can be taken from sites like Facebook and other publicly government sites.
While data in this case may not have been downloaded — only exposed to hackers by malware — it once again calls questions on the data that universities have on its students.
It is, however, another reminder to users of Facebook and other social networking sites not to make birthday and date of birth data available on the web. While though it may be benign on in singular form, hacks like these, which include your full name, make you even more vulnerable to identity theft and bank account hacks more likely.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

APAC lax on data breach, theft

SINGAPORE--Lack of data privacy regulations, as well as lenient law enforcement in the Asia-Pacific region, have not helped the fight against cybercrime, according to a security expert.
Touching on the recent Epsilon incident, Paul Ducklin, Sophos' head of technology for the Asia-Pacific region, told ZDNet Asia the lack of legislation in this region had given affected companies opportunities to "sweep it under the carpet".
The e-mail marketing service provider, which sends some 40 billion e-mail messages annually, revealed in early April that its system was breached and about 2 percent of its customers' client names and e-mail had been leaked. Among the organizations affected were Citi, JPMorgan Chase, Marriot International and McKinsey & Company.
Of the affected companies, only U.S. companies have revealed that they were customers of Epsilon, and sent out e-mail messages to customers informing them of the data breach, Ducklin noted in an interview during a recent visit to Singapore.
He blamed this on the lack of mandatory disclosure laws in the region, adding that companies have no obligations to go public, as the information stolen are mainly e-mail addresses and not personal identifiable information.
The United States, for instance, has legislation requiring companies, which handle and "do things" with consumer data, to disclose any data breach and implement encryption.
Aside from the absence of laws, judiciary powers do not appear to be taking cybercrime seriously, judging by the punitive measures, lamented Ducklin.
According to him, a criminal who tried to sell 60, 000 stolen credit card numbers to undercover police in Perth last year, was let off on a "good behavior bond" and payment of A$150 (US$161) for court costs. The sentencing was similar to a fine of not paying toll on the Sydney Harbour Bridge, he pointed out.
"The magistrates don't seem to accept the severity of cybercrime, where lots of people's identities are stolen at a time," said Ducklin. "You're not actually punching someone or committing [a] violent crime, so these hackers can expect quite light sentences in some cases."
Users more savvy, but Facebook must up security 
Ducklin added that cybercriminals are also finding Facebook an effective channel to lure victims, as seen from the security vendor's frequent blog updates of alerts of scams targeting the social media site. The popular social networking platform, he noted, is a good way to popularize dodgy sites as cyberciminals can typically reach tens of millions of users effortlessly, with many of the unsuspecting users falling prey to malicious apps and javascript injection.
Sophos published an open letter to Facebook last week, asking Facebook to take on three security issues to improve privacy and safety for its over 500 million users.
In the letter, Sophos' senior technology consultant Graham Cluley urged Facebook to--instead of being required to do so by regulators--implement opt-in functions for new features on information sharing, publish only vetted and approved third-party developer apps and enforce a "secure connection" at all times.
The HTTPS function currently requires users to turn it on in their account settings but Facebook noted that it is looking to enable HTTPS by default "sometime in the future". The social network also announced on Apr. 19 that it would automatically switch users back to the more secured connection after they have used a non-HTTPS application.
Ducklin said he is puzzled as to why Facebook users willingly allow apps from unknown or suspicious companies, access to their personal information. "Do you really want to allow someone you do not know to post articles as if it were you? It seems crazy but we're trying to bring the [preventive] message across," he pointed out.
Rogue apps are not only the ones making their rounds in the social media site now, he said. Another recently introduced 'feature' claiming to allow users to view stalkers or frequent visitors to their page, is actually a javascript attack that injects malicious codes when users try to access it through browsers.
Many URLs these days are shortened, making it very difficult "to see where you're going", he added.
Bogus surveys are also contributing to the underground economy, where users, lured by bogus iPhone and iPad prizes, are willing divulge information online to dodgy Web sites, said Ducklin. Not only are such information obtained by cybercriminals, users' computer systems may also be infected as these sites may trigger some form of exploit via browsers, he shared.
However, Ducklin acknowledged that an increasing number of people are now more aware of online scams. Citing an impromptu video survey in Singapore he conducted last year, where 20 locals and tourists were quizzed on whether they would divulge information for a free iPad, at least half stood firm against giving in to such "temptation".
"I was quite pleased that the results were 50-50, they were either willing or not willing to divulge any information," he said.
"If we did the same thing three years ago, when Facebook was still quite new, people either wouldn't be on it yet, or would be more than willing to partake in the 'fun'."

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

EPIC Sues DHS Is Monitoring Suspicious Words on Social Networks



The Electronic Privacy Information Center (EPIC), has filed suit in US District Court against the Department of Homeland Security. The grounds for the suit is a refusal by DHS to reply to a Freedom of Information Act request filed by EPIC in April of this year.
According to EPIC’s Press Release the center of the issue is a plan by DHS to create fake accounts on social networking sites and use those accounts to monitor the networks for certain key words – such as “drill,” “infection,” “strain,” “virus,” “trojan,” and others. The complaint was filed in the District of Columbia, and asks the court to compel DHS to process EPIC’s FOIA request, as well as to order DHS to produce the records EPIC has requested, to acknowledge EPIC as news media, and to pay EPIC’s legal bills for the suit.
The impetus for EPIC’s request was an announcement by DHS that it planned to implement a Social Media Monitoring and Situation Awareness Initiative, whereby it would monitor social media sites in order to gain realtime information on events. The DHS announcement states that the goal of the initiative is not to collect personally identifiable information except in extreme cases – e.g., a person trapped in rubble with their mobile phone who is posting their status (as happened during the Japanese tsunami).







SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Security Breach in Ning (Largest Platform for Creating Social Websites) 100 Million Users Affected

Security Breach in Ning (Largest Platform for Creating Social Websites) 100 Million Users Affected 

Social networking company Ning is reportedly suffering from security problem that could affect 100 million users. Three students from the junior college Media College Amsterdam (MA) together discovered five security holes in Ning. They found those security vulnerabity immediately   after the social network platform launched at their school. In a report Dutch security firm - Angelo Geels and Alex Brouwer have exploited cookies to gain login control over Ning user accounts. They used a proof of concept that showed they could access 90,000 accounts and 100 million users, but had no intention of exploiting it for malicious purposes.
The first problem was that the boys were not so serious but annoying. People who can put a blog which is to deface the site through the HTML section on the website the html element 'div' with content sites. Thus, for example, an overlay on the website come with in the case of the website of the Media College a cat Nyan. Then became the administrator of the website is still unknown hackers through the community called for pie for dinner. The boys did, admitted that they had hacked the code, but then decided to go further to look for any other problems on Ning, so said the hackers in an extensive interview with Webwereld.
Soon they discovered that Ning sites very susceptible to cross site scripting (XSS). The MBO students of 17 and 18 were four non-persistent or reflective cross-site scripting vulnerabilities in the site. Which run over several pages on the website. For example, via a link to a specific comment, so with code, or a cancel link containing a standard URL to the previous page. For detail information about the story click here.



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Facebook Outage in Many European Countries Not Caused By Anonymous But DNS Problem

Facebook Outage in Many European Countries Not Caused By Anonymous But DNS Problem 

World's most popular and largest social network Facebook faced another downtime. This time the outage effected millions of users in European countries including Denmark, France, NorwayGermany and Italy. After June this is the second outage which effected large number of Facebook users. Last time Facebook users faced disturbance while using their favorite social network. Facebook users across the globe experienced log-in difficulties for several hour. But this time, the social networking giant remain down for a decent time. The outage may have caused Facebook’s share price to go down. For a site with 900 million users worldwide, even a minor outage has a huge effect. Like the June issue, here also hacker collective came first and took credit of the outage. According to a twitter account of the hacktivist group named  Anonymous Own3r, took responsibility of the outage, In his tweet he claimed to figure out several vulnerabilities in Facebook, which causes the outage. In a pastebin note, the hacker publishes those so called vulnerabilities. Also in his tweet the hacker claimed to have control in many servers owned by Facebook. 

But Facebook completely denies the hacker attack & said the cause of the outage was nothing but DNS issue, neither hacker attack nor DDoS.  Here we want yo give you reminder that i2011 Anonymous openly declared to take down Facebook. The operation was dubbed #Op-Facebook and Anonymous told that they will hit FB on the 5th of November last year. But in reality it was just a threat and as expected Anonymous failed to execute Operation Facebook. Later in June this year, Anonymous took credit for a couple of hours outage of Facebook, and here again Anonymous affiliated member repeated the same story, which again proves completely baseless, and in short it was nothing but a publicity stunt. 

In case of large social network like Facebook, such kind of DNS issues can be happened. Whatever immediately after this outage Facebook released a statement saying -
"There has not been a hack of Facebook. We have investigated these claims, and they are not valid. The evidence cited was produced by an automated vulnerability scanner that alerts developers of potential vulnerability, and we have found these all to be false alerts.
We expect Anonymous just like we expect any other attack on any other day. Due to our size, we face the same threats as seen everywhere else on the Web, but we have developed partnerships, back-end systems, and protocols to confront the full range of security challenges we face. Facebook has always been committed to protecting our users’ information, and we will continue to innovate and work tirelessly to defend this data.
Earlier (Thursday), we made a change to DNS as part of a traffic-optimization test, and that change resulted in some users being temporarily misrouted. We detected and resolved the issue immediately, but a small number of users located primarily in Western Europe experienced issues accessing the site while the DNS addresses repopulated. We are now back to 100 percent, and we apologize for any inconvenience..."



-Source (All Facebook)




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Anonplus Hacked by Akincilar (Turkish Hacker Group)


AnonPlus, a social network created by the hacker group Anonymous has been hacked by a Turkish hacker group called Akincilar, who replaced the Anonymous logo of men in suits, with one of a dog wearing a suit on the social networking site, according to The Register.
Anonymous began setting up its own social network after profiles set up by its members on Google+ were removed last week. Several days later, the rival hacker group from Turkey defaced the pre-beta site's front page with the joke version of the standard Anonymous logo and a message mocking the group in Turkish and English.

"We Are TURKIYE We Are Akincilar. This logo suits you more ... How dare you rise against to the World ... Do you really think that you are Ottoman Empire? We thought you before that you cannot challenge with the world and we teach you cannot be social Now all of you go to your doghouse ..." read the message.
Details of how the hack was perpetrated are unknown, but are likely to have involved either easily exploited site vulnerabilities or sloppy password security: the same vulnerabilities that Anonymous has been criticising big business for, through its AntiSec campaign.

Developers behind AnonPlus had a few choice words for Turkish hackers dismissing them, among other things, as "snobby, arrogant, IGNORANT little fucking children" in a counter-rant.
Anonymous attacked government websites in Turkey in protest against controversial internet filtering plans back in June. Turkish police arrested 32 suspects days later.

-News Source (ITP)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

IBM Unveils Breakthrough Software and New Services to Exploit Big Data




As companies seek to gain real-time insight from diverse types of data, IBM (NYSE: IBM) today unveiled new software and services to help clients more effectively gain competitive insight, optimize infrastructure and better manage resources to address Internet-scale data. For the first time, organizations can integrate and analyze tens-of-petabytes of data in its native format and gain critical intelligence in sub-second response times.
(Logo: http://photos.prnewswire.com/prnh/20090416/IBMLOGO)
IBM also announced a $100 million investment for continued research on technologies and services that will enable clients to manage and exploit data as it continues to grow in diversity, speed and volume. The initiative will focus on research to drive the future of massive scale analytics, through advancing software, systems and services capabilities.
The news comes on the heels of the 2011 IBM Global CIO Study where 83 percent of 3,000 CIOs surveyed said applying analytics and business intelligence to their IT operations is the most important element of their strategic growth plans over the next three to five years.
Today's news further enables Smarter Computing innovations realized by designing systems that incorporate Big Data for better decision making, and optimized systems tuned to the task and managed in a cloud.
According to recent IT industry analyst reports, enterprise data growth over the next five years is estimated to increase by more than 650 percent. Eighty percent of this data is expected to be unstructured.  
The new analytics capabilities pioneered by IBM Research will enable chief information officers (CIOs) to construct specific, fact-based financial and business models for their IT operations. Traditionally, CIOs have had to make decisions about their IT operations without the benefit of tools that can help interpret and model data.
With today's news, IBM is expanding its portfolio and furthering its investments in analytics with:
  • New, patented software capabilities to analyze massive volumes of streaming data with sub-millisecond response times and Hadoop-based analytics software to offer scalable storage to handle tens-of-petabytes level data.  These capabilities complement and leverage existing IT infrastructure to support a variety of both structured and unstructured data types.
  • 20 new services offerings, featuring patented analytical tools for business and IT professionals to infuse predictive analytics throughout their IT operations. The services enable IT organizations to assess, design and configure their operations to address and take advantage of petabytes of data.

"The volume and velocity of information is generated at a record pace. This is magnified by new forms of data coming from social networking and the explosion of mobile devices," said Steve Mills, Senior Vice President and Group Executive, IBM Software & Systems.  "Through our extensive capabilities in business and technology expertise, IBM is best positioned to help clients not only extract meaningful insight, but enable them respond at the same rate at which the data arrives."


New Services Address Analytics for IT Infrastructure
Leveraging years of intellectual capital in managing data centers and IT departments, as well as over 30 patented technologies from IBM Research, the new IT services feature dozens of analytical tools to help IT professionals use server, storage and networking technologies more efficiently, improving security and insight into planning major IT investments.  Examples of services that help clients with analytics include:
  • Cloud Workload Analysis -- The new analysis tool maps your IT workload characteristics and current capabilities to prioritize cloud deployment and migrations plans. This allows IT managers to identify cloud opportunities 90 percent faster to reduce costs.  
  • Server and Storage -- New server optimization and analysis tools achieve up to 50 percent reduced transformation costs and up to 80 percent faster implementation time.  New storage services help create self-service to provision explosive growth while reducing architects time by 50 percent.
  • Data Center Lifecycle Cost Analysis Tool -- Identifies how to reduce total data center costs by up to 30 percent by assessing total cost plus including environmental impact over a 10 to 20 year life.
  • Security Analytic services -- Analytic systems identify known events and automatically handle them; This results in handling of more than 99 percent of critical events without human intervention.

IBM Big Data Software Taps into Hadoop
IBM is making available new InfoSphere BigInsights and Streams software that allows clients to gain fast insight into information flowing in and around their businesses.  The software, which incorporates more than 50 patents, analyzes traditional structured data found in databases along with unstructured data -- such as text, video, audio, images, social media, click streams -- allowing decision makers to act on it at unprecedented speeds.  
BigInsights software is the result of a four-year effort of more than 200 IBM Research scientists and is powered by the open source technology, Apache Hadoop. The software provides a framework for large scale parallel processing and scalable storage for terabyte to petabytes-level data. It incorporates Watson-like technologies, including unstructured text analytics and indexing that allows users to analyze rapidly changing data formats and types on the fly.  
Additional new features include data governance and security, developer tools, and enterprise integration to make it easier for clients to build a new class of Big Data analytics applications. IBM also offers a free downloadable BigInsights Basic Edition for clients to help them explore Big Data integration capabilities.  
Also born at IBM Research, InfoSphere Streams software analyzes data coming into an organization and monitors it for any changes that may signify a new pattern or trend in real time. This capability helps organizations to capture insights and make decisions with more precision, providing an opportunity to respond to events as they happen.
New advancements to Streams software makes it possible to analyze Big Data such as Tweets, blog posts, video frames, EKGs, GPS, and sensor and stock market data up to 350 percent faster than before.  BigInsights complements Streams by applying analytics to the organization's historical data as well as data flowing through Streams. This is an ongoing analytics cycle that becomes increasingly powerful as more data and real-time analytic results are available to be modeled for improvement.
As a long time proponent of open source technology, IBM has chosen the Hadoop project as the cornerstone of its Big Data Strategy. With a continued focus on building advanced analytics solutions for the enterprise, IBM is building upon the power of these open source technologies while adding improved management and security functions, and reliability that businesses demand. Hadoop's ability to process a broad set of information across multiple computing platforms, combined with IBM's analytics capabilities, now makes it possible for clients to tackle today's growing Big Data challenges. IBM's portfolio of Hadoop-based offerings also include IBM Cognos Consumer Insight which integrates social media content with traditional business analytics, and IBM Coremetrics Explore which segments consumer buying patterns and drills down into mobile data. Additionally, Hadoop is the software framework the IBM Watson computing system uses for distributing the workload for processing information, which supports the systems breakthrough ability to understand natural language and provide specific answers to questions at rapid speeds.
University of Ontario Institute of Technology Expands Neo-Natal Research to China
Dr. Carolyn McGregor, Research Chair in Health Informatics at the University of Ontario Institute of Technology has been exploring new approaches for the last 12 years to provide specialists in neonatal intensive care units better ways to spot potentially fatal infections in premature babies.  
Changes in streams of real-time data such as respiration, heart rate and blood pressure are closely monitored in her work and now she is expanding her research to China. "Building upon our work in Canada and Australia, we will apply our research to premature babies at hospitals in China.  With this new additional data, we can compare the differences and similarities of diverse populations of premature babies across continents," said Dr. McGregor. "In comparing populations, we can set the rules to optimize the system to alert us when symptoms occur in real time, which is why having the streaming capability that the IBM platform offers is critical. The types of complexities that we're looking for in patient populations would not be accessible with traditional relational database or analytical approaches."
IBM's Big Data software and services reinforces IBM's analytics initiatives to deliver Watson-like technologies that help clients address industry specific issues. On the heels of The IBM Jeopardy! Challenge, in which the IBM Watson system demonstrated a breakthrough capability to understand natural language, advanced analytical capabilities can now be applied on real client challenges ranging from identifying fraud in tax or healthcare systems, to predicting consumer buying behaviors for retail clients.
Over the past five years, IBM has invested more than $14 billion in 24 analytics acquisitions. Today, more than 8,000 IBM business consultants are dedicated to analytics and over 200 mathematicians are developing breakthrough algorithms inside IBM Research. IBM holds more than 22,000 active U.S. patents related to data and information management.
To hear how IBM clients are using analytics to transform their business visit: http://www.youtube.com/user/ibmbusinessanalytics.
For more information on IBM Big Data initiatives, visit: www.ibm.com/bigdata.
For more information on IBM's full set of new analytics services, visit: www.ibm.com/services/it-insight.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

6.5 Million of LinkedIn Passwords Stolen By Cyber Criminals

6.5 Million of LinkedIn Passwords Stolen By Cyber Criminals

Very popular social networking site LinkedIn are currently running through a massive cyber attacks. It has been allegedly reported that more than six million passwords belonging to LinkedIn users have been compromised among them more than 300,000 passwords has already been cracked and published as plain text. A file containing 6,458,020 SHA-1 unsalted password hashes has been posted on the internet, and hackers are working together to crack them.  
LinkedIn has confirmed that it is investigating the incident. In the meantime, several reputable sources have said that they have found their LinkedIn passwords in that list; it can therefore be assumed that the social network's operator actually does have a problem.
Pages are already appearing on the internet that prompt you to enter your password to verify whether you are affected; these are phishing sites. It is also expected that there will be waves of spam email soon which will call for you to change your password with a link to a LinkedIn-impersonating phishing site. Instead of following these links, either enter the LinkedIn URL yourself (linkedin.com) or use a stored bookmark to visit the social network and change your password.





SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Hacker Are Invited To Attack Facebook's Corporate Network


Hackers Are Invited To Attack Facebook's Corporate Network

Last year the social networking giant, Facebook introduced its bug bounty program, inviting security researchers to poke around the site, discover vulnerabilities that could compromise the integrity or privacy of Facebook user data, and then responsibly disclose them to the company. The minimal reward amount was of $500. White hats were urged to search for Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF/XSRF) and Remote Code Injection bugs. In Facebook's White Hat program the company strictly announced that they should not be bothered with spam or social engineering techniques, DoS vulnerabilities, bugs in Facebook's corporate infrastructure and vulnerabilities in third-party websites or apps. Now they changed their mind. When the social network's security team randomly receiving tips from a researcher about a vulnerability in the company's own network which would allow attackers to eavesdrop on internal communications, they made an unprecedented choice by broadened the scope of the bug bounty program and inviting researchers to search for other holes in the Corporate Network. There are quite a few bug bounty programs instituted by tech companies such as Google, Paypal but Facebook has become the first firm that gave formal permission to white hats to target its networks. Ryan McGeehan, the manager of Facebook's security-incident response unit, stated that if there’s a million-dollar bug, they will pay it out.
Given that Facebook has a strong incentive to protect the data belonging to its 900 million users, and the fact that data breaches have become a disturbingly common occurrence in the last two years or so, the step seems like a logical one. 


-Source (Net-Security)





SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Facebook Forces 900 Million Users To Put Phone Details To Prevent Hacking

Facebook Forces 900 Million Users To Put Phone Details To Prevent Hacking

After the security breach in LinkedIn and eHarmony now the world's largest social network Facebook is asking each of its over 900 Million active users to provide their original mobile numbers as a part of a drive to improve security on the social networking site. Millions of Facebook users have already seen a link at the top of their profile requesting them to follow ''simple security tips''. Clicking on the link opens the site''s security page where users are asked to pick a unique password and given a tutorial on how to spot an online scam. Users are then requested to provide their phone number for secure account recovery. Facebook claims that when a user confirms their phone number it allows the site to automatically wipe their password in case their account is being hacked. The social network would then send a text message to the user informing that their password has been changed. According to the paper, Facebook, however, claimed that the security update has nothing to do with the recent LinkedIn hack.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Spammers are Exploiting Google+


Scammers have begun exploiting the launch of Google’s new Google+ social network, with a growing raft of spam emails that imitate Google+ invitations. Google+ is currently still in the testing phase following its launch last week, and users need to be invited by another Google+ member before they can sign up.

Fake invitations:-

However, some of those Google+ invitations are fake, and their links direct traffic to an online business called Canadian Family Pharmacy, which sells Viagra, according to Sophos. Sophos said the emails, distributed by a Canadian hacking group called Partnerka, look authentic.
“The spammers are no doubt hoping that the email will be hard to resist, as many people are eager to see what is being billed as Google’s answer to Facebook,” said Graham Cluley, senior technology consultant at Sophos, in a statement. “Research shows that last year alone, 36 million Americans bought drugs from online pharmacies, so this is a technique that is clearly continuing to work for spammers.”
Overall the scam is “amateur” in that it makes no attempt to use a site that looks like Google+ to harvest users’ personal information, Sophos said. While Facebook doesn’t allow friends lists to be exported to Google+, an extension is now available for Google’s Chrome browser that allows users to export friends data in a format that can be imported into Google+. Facebook has, however, begun modifying accounts to prevent the tool from working, according to Mohamed Mansour, who developed the Facebook Friend Exporter tool.

Google’s answer to Facebook:-

Google unveiled Google+ last week as its answer to Facebook, which has racked up some 700 million users in six-plus years. Seizing on the market leader’s seemingly cavalier attitude toward user privacy, Google envisions Google+ as a more nuanced approach to social networking that tries to give users complete control over what content they share online and with whom they share it. Available to users by invitation only for now, Google+ comprises four major components: Circles, Sparks, Hangouts and mobile, which includes instant photo and video uploads and group messaging.
Social Circles has been rumoured since March, and was at the centre of a clumsy smear campaign by Facebook which attempted to brand Google’s privacy as poor. Circles is a sharing service that lets users add circles, or groups of users united by common interests by dragging and dropping their profiles into a circle. Circles could include family, friends and colleagues.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Google+ Now has 20 Million+ Users


Google has another hit on its hands. According to a study released Friday by web-tracking firm comScore, the web search giant’s new social networking tool, Google Plus, has amassed 20 million users in just three weeks since its launch on June 28.
While that figure is still far from the 750 million registered users of Facebook, it is still enough to make Google Plus the fastest growing social network in history. The spectacular early success indicates that Google Plus may well challenge Facebook once it comes out of a trial mode in which Google has strictly restricted the number of users, Comscore said.

“It would be difficult to think of many sites that reached such a large number in such a short period of time,” said study author Andrew Lipsman.
“That said, Google does have a built-in visitor base of more than 1 billion to work with, so there is clearly potential to convert a high number of users to its new social tool — even if it is still invite-only.” According to Comscore, the latest figures represent an 82 per cent surge from the previous week and a 561 per cent increase over the usage figures two weeks prior.
While the U.S. is the biggest market with 5.3 million users, India is a strong second with 2.8 million users, followed by Britain (866,000), Canada (858,000), and Germany (706,000)


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

XSS Worm on Chinese Twitter

Users of Sina Weibo, the Chinese Twitter alternative, were targeted by a cross-site scripting (XSS) worm spreading through a vulnerability on the micro blogging site.
With over 140 million users, Sina Weibo is the most popular social networking site in China, a country where both Twitter and Facebook are banned. The site's administrators announced that an worm exploiting an XSS weakness hit the platform on Tuesday evening. The worm propagated through messages that lured users with videos, pictures and software. For example some advertised bloopers from a new film, while others nude pictures of Chinese actress Fan Bingbing. Clicking on the included links forced users to re-post the spam messages from their own accounts, therefore helping the worm spread.
The attack was apparently launched from an account called @hellosamy, a name possibly chosen as a tribute to the Samy (Spacehero) worm released on MySpace back in 2005.
The work of security enthusiast Samy Kamkar, Spacehero was the first large-scale worm to spread on a social network by exploiting a cross-site scripting vulnerability and paved the way for many similar attacks that have occurred since then.
There is barely any social network left that hasn't been affected by such a worm. Some of them have had to deal with such problems multiple times and on some occasions the attacks distributed malware or spam.

There doesn't seem to have been any malicious component behind the Weibo worm, though, except for its spreading mechanism.

When such attacks happen if webmasters are not quick enough there is a high risk that the worms will mutate as other users modify the code and launch their own versions. In this case, the Weibo staff plugged the hole in around one hour, which is a rather long time for such an attack.

-News Source (Softpedia)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Anonplus the Social Networking site of Anonymous


Renowned hacker group Anonymous revealed yesterday that its Google+ profile has been removed and that their Gmail account has been blocked as well. Google claims that the profile and account go against "Community Standards" and has shut down most, if not all, profiles related to Anonymous.
As a result of being blocked, Anonymous says that they have organized against Google+ and will be developing their own social network, dubbed "AnonPlus."
Welcome to AnonPlus. This will be your future. This will be our future. Today, we welcome you to begin anew…to watch this glorious incipience happen – one upon which you will never turn your back on. Welcome to the Revolution – a new social network where there is no fear…of censorship…of blackout…nor of holding back. Life is what you make of it – and we are making it. As you step through into the coming weeks, months, and years with us…they will know that we've arrived. There will be no more oppression. There will be no more tyranny. We are the people and we are Anonymous. We have arrived.
The site currently has the Anonymous logo, the text that is above, a link to the dev forums, and a version number (0.1). From what we can tell, Anonymous is taking this pretty seriously.
 
What do you think? Was Google right in blocking Anonymous' profiles? What do you think about AnonPlus?

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Twitter Traffic Hits 6,049 Tweets per Second As News of Jobs' Death Spread



Traffic hit near-record levels on Twitter Wednesday after news spread of Apple co-founder Steve Jobs' death. Leaders in the high-tech industry, as well as Apple fans and average people, took to social networking sites Wednesday night and Thursday to spread the word about Jobs and to share memories and tributes to the man behind the iMac, iPod, iPhone and iPad. Around 8 p.m. EDT Wednesday, shortly after news of Jobs' passing was made public, Twitter was handling 6,049 tweets per second, according to Twitter spokeswoman Rachael Horwitz.
"I'm surprised at the number of tweets it got, but I guess I shouldn't be," said Zeus Kerravala, principal analyst with ZK Research. "Social networks are increasingly the de facto place for people to go to when they want to share information. Twitter is perfect for this type of thing."
While Wednesday night didn't set a record for Twitter traffic, it was one of the site's highest number of tweets per second ever recorded.
Horwitz noted that early last May, the death of al-Qaeda leader Osama Bin Laden set a record at that time with a peak of 5,106 tweets per second.
When Brazil was eliminated from the international soccer tournament Copa America in July, Twitter saw 7,166 tweets per second. The current record is 8,868 tweets per second, which was set during the 2011 MTV Video Music Awards in August, Horwitz noted.

Shawn White, vice president of operations at Keynote Systems, an Internet and mobile monitoring company, told Computerworld that the surge in Twitter traffic after Job's death was staggering.
"We saw it with the death of Michael Jackson and the inauguration of President Obama. Sometimes sites just get overwhelmed," White said. "The pattern we saw [with Twitter] was that things hummed a long pretty normally and then right after the announcement of Steve Jobs' passing, the site slowed." He noted that the time to access Twitter's homepage for many users went from 3 seconds to 20 or 30 seconds. The site increasingly struggled under the load, with the first error hitting at 8:10 p.m. ET.
Then the availability of Twitter's homepage dropped nearly 40% between 8:50 and 9:05, according to Keynote.
"During that 15-minute period, roughly 60% of Twitter users would have gotten some kind of error trying to get to the home page. And if they got there, it was probably really slow," White said. "But Twitter recovered pretty quickly."


-News Source (Computer World, BBC, twitter) 




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Apple Hacked By The Same Group Who Attacked Facebook

Apple Hacked, Macintosh Computers Infected  By The Same Group Who Attacked Facebook 

The month of February is not going good for cyber space, specially for giant organization. Last week the social networking giant Facebook fallen victim of a devastating cyber attack which did effected a number of  systems. Facebook admitted that it faced a "sophisticated attack" on computers where it has been found the attackers used a zero-day Java exploit to initiate the attack, but that no user data was compromised. The same thing happened to micro blogging site Twitter and New York Times. And now it was the turn for Apple. The California based multinational company acknowledged that recently their systems has been attacked by hackers who infected Macintosh computers of some employees. Like Facebook here also no data has been effected, "there was no evidence that any data left Apple." -said Apple. 
According to an exclusive report of Reuters -some unknown hackers infected the computers of some Apple workers when they visited a website for software developers that had been infected with malicious software. The malware had been designed to attack Mac computers. The same software, which infected Macs by exploiting a flaw in a version of Oracle Corp's Java software used as a plug-in on Web browsers, was used to launch attacks against Facebook, which the social network disclosed on Friday. The malware was also employed in attacks against Mac computers used by "other companies," Apple said, without elaborating on the scale of the assault. Experts are presuming that all these cyber attacks of February, that is Twitter, New York Times, Facebook & Lastly Apple Inc was originated from China, and executed by the same hacker group. On the other side few experts are also saying that the group responsible for the hack, has been identified as "Unit 61398" of the People's Liberation Army. But so far there is no proof. 
Apple also revealed that it plans to release a software tool later Tuesday that will protect customers against the same type of software that was used against its employees. 

Apple also provided a statement as follows:-
"Apple has identified malware which infected a limited number of Mac systems through a vulnerability in the Java plug-in for browsers. The malware was employed in an attack against Apple and other companies, and was spread through a website for software developers. We identified a small number of systems within Apple that were infected and isolated them from our network. There is no evidence that any data left Apple. We are working closely with law enforcement to find the source of the malware.
Since OS X Lion, Macs have shipped without Java installed, and as an added security measure OS X automatically disables Java if it has been unused for 35 days. To protect Mac users that have installed Java, today we are releasing an updated Java malware removal tool that will check Mac systems and remove this malware if found..."




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

"Facebook Exploit" Violating Privacy Settings Found By London Computer Scientists

"Facebook Exploit" Violating Privacy Settings Found By London Computer Scientists

London computer scientists Shah Mahmood and Yvo Desmedt has found serious security flaws in the world's largest social network, Facebook. They have discovered that Facebook suffers from a crucial exploit that allows users to view full profiles they normally would not have access to. The news comes as the social networking site faces increasing scrutiny over its privacy procedures including a lawsuit over the misuse of users contact information by its mobile App. The exploit was discovered by London computer scientists Shah Mahmood and Yvo Desmedt. The analysts, working at University College London, used a couple of Facebook’s system properties to allow them to view profiles they otherwise may not have access to and stalk unwitting users.
The hack centers on two basic aspects of Facebook’s system. Users are allowed to deactivate and reactivate their accounts at will, and while accounts are deactivated the user has no control over their privacy settings in relation to that account. This means that if you are registered as a friend of another user who then deactivates their profile they will be able to reactivate their account for short periods of time in order to watch your profile. You cannot restrict the behavior of deactivated profiles. The ability to allow this kind of behavior has birthed worries of stalking. Personal relationships in real life can change but this change cannot be reflected in Facebook’s virtual privacy settings.

-Source (Value Walk)



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft supports PPP model to generate awareness about cyber attacks



The social networking community, which has seen a skyrocketing growth in recent times, has promoted technology giant Microsoft to support a public-private partnership (PPP)-based model for creating awareness among people in India about cyber attacks.


A recent Security Intelligence Report from Microsoft, which highlighted cyber attacks and the trend of attacks revealed phishing attack through social networks increased from a low of 8.3 per cent of all phishing in January to a high of 84.5 per cent in December 2010. Microsoft releases this report every six months.


The report, which took into account the six-month period from June to December 30, 2010, indicates that in India, the most common category of cyber attacks was worms, which affected 42.5 per cent of all infected computers, down from 45.4 per cent in the last quarter.


The second-most common category in India was Miscellaneous Trojans, which affected 33.9 per cent of all infected computers, down from 34.5 per cent last quarter.


The third most common category in India was Miscellaneous Potentially Unwanted Software, which affected 33.7 per cent of all infected computers, up from 31.9 per cent in the last quarter.


Microsoft further opined the Indian government should come out with a PPP model, which includes government, private organizations and NGOs to make people more aware of the cyber attacks and increase the level of security.


With the increasing online presence of consumers and devices, it becomes easy for hackers to take charge with many intrusion methods such as adware, phishing and rogue security software. To prevent such inadvertent practices, greater collaboration across the security industry is required.


Through collective efforts – such as the sharing of threat intelligence and guidance, software providers making advancements in security protections and customers keeping their systems up to date, will surely help in minimizing cyber crime while delivering a more safer and reliable computing experience.


Although cyber-security awareness among the people in India is on the rise, there is ample scope to expand awareness, which is only possible through the PPP model.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...