Showing posts with label hack. Show all posts
Showing posts with label hack. Show all posts

Monday, January 9, 2017

Ransomware: Over 27,000 databases managed by MongoDB held to ransom; 99,000 still vulnerable

Ransomware: Over 27,000 databases managed by MongoDB held to ransom; 99,000 still vulnerable

Image: Reuters
By 
Tens of thousands of online databases have been breached by what appears to be a single hacker or group of hackers. The databases in question appear to be managed by MongoDB, a database application.
A hacker or hackers going by the handle Harak1r1 has spent the last week or more gaining access to MongoDB-based databases and then threatening to either delete or encrypt the entire database. In exchange, Harak1r1 has demanded money in the form of BitCoin (0.2 BTC to be exact).
Latest reports suggest that over 27,000 databases (up from around 10,000 just a few hours ago) have so far been breached and, as ArsTechnica points out, 99,000 are vulnerable. The number of hackers/groups has gone up to at least 15, reports The Register. The ransom for the databases has also gone up to 1BTC (around Rs 61,000).
The problem appears to be restricted to MongoDB-based databases, but doesn’t seem to be a vulnerability in the application itself. The application needs to be configured properly for maximum security and it looks like misconfigured databases are the reason for this sudden spurt in breaches.
MongoDB has published a blog post explaining the situation, how you can prevent it and steps to check the integrity of your data.
If you remember the recent hacks in India by hacker group calling itself Legion, the group claimed to have compromised databases belonging to banking institutions, government email servers and the databases of Apollo hospitals.
Databases are the ledgers of the internet. If they’re compromised, a great deal of personal information will be at risk.

Friday, January 6, 2017

CyberZeist, a hacker breaches FBI website and posts information on Pastebin

CyberZeist, a hacker breaches FBI website and posts information on Pastebin

Representational image
A hacker has claimed to have breached the US Federal Bureau of Investigation’s website and leaked personal account information to a public site, media reported. The hacker, known as CyberZeist, exploited a zero-day vulnerability in the highly-secured Plone Content Management System (CMS) of the FBI’s website and leaked some of the information to Pastebin, an open source site that is often used by hackers to post stolen information and bits of code, RT.com reported on Thursday.
A zero-day fault is a vulnerability in the code that has not been detected, listed, or patched yet. Therefore, the FBI had zero days to respond to the attack. This is not the first time the hacker claimed breaching the FBI site. In 2011, CyberZeist is believed to have hacked the FBI site as a member of a group known as Anonymous.
Authorities in the US have not yet responded to the recent hacking incident that was claimed to have occurred last month. “fbi.gov CMS Exploited, files in view – PasswordResetTool.py, product permissions, setup file. More coming soon #FBI #PWNED,” the hacker had tweeted on December 22.
“Don’t blame the #hacker, blame the faulty #code!,” CyberZeist had said in another tweet on December 27. CyberZeist warned other agencies that are currently using the Plone CMS that they too are vulnerable to a similar attack. “Amnesty acknowledges to patch the Plone #vulnerability in their CMS, just in time!,” CyberZeist said in a recent tweet.
IANS

Saturday, December 3, 2016

Hackers can hack any Visa credit card or debit card in six seconds

Visa credit hacked
Visa credit hacked

02 Dec 2016 , 14:50


It can take hackers just six seconds, a laptop and an internet connection to hack any Visa credit or debit card, new research has revealed. The research, published in the journal “IEEE Security and Privacy”, said that the “distributed guessing attack” circumvents all the security features put in place to protect online payments from fraud. Neither the network, nor the banks are able to detect attackers making multiple, invalid attempts to get payment card data.
The current online payment system does not detect multiple invalid payment requests from different websites. This allows unlimited guesses on each card data field, using up to the allowed number of attempts – typically 10 or 20 guesses – on each website, explained Mohammed Ali, a PhD student in Newcastle University.
“Different websites ask for different variations in the card data fields to validate an online purchase. “This means it’s quite easy to build up the information and piece it together like a jigsaw,” Ali added. The combination of these two factors — unlimited guesses and variation in the payment data fields — makes it easy for attackers to hack all the card details.
Each generated card field can be used in succession to generate the next field and so on. “If the hits are spread across enough websites then a positive response to each question can be received within two seconds – just like any online payment,” Ali warned.
The researchers explained that even starting with no details at all other than the first six digits — which tell you the bank and card type — a hacker can obtain essential pieces of information. These are — card number, expiry date and security code — to make an online purchase within as little as six seconds. Researchers believe this ‘guessing attack’ method could have been used in the recent Tesco cyber attack where the hackers defrauded customers of 2.5 million pounds.
The risk is higher at this time of the year as many people are making online purchases ahead of Christmas. However, researchers found that unlike Visa cards, MasterCard’s centralised network was able to detect the guessing attack after less than 10 attempts – even when those payments were distributed across multiple networks.
The researchers suggested that to minimise the chances of hacking, card-holders should use just one card for online payments and keep the spending limit on that account as low as possible. “If it’s a bank card then keep ready funds to a minimum and transfer over money as you need it,” said Martin Emms, co-author of the research.
IANS

Thursday, December 1, 2016

Congress Party and Rahul Gandhi’s Twitter account hack come as no surprise for cyber experts

Rahul Gandhi’s Twitter account
Rahul Gandhi

01 Dec 2016 , 17:02


As the news of Congress Party and its Vice President Rahul Gandhi’s Twitter accounts being hacked spread like wildfire on Thursday, cyber experts were not surprised as the phenomenon is quite common across the globe where hackers are always a step ahead when it comes to data breach — be it a social media platform or your financial information. When it comes to celebrities, Facebook CEO Mark Zuckerberg, Twitter CEO Jack Dorsey, Google CEO Sundar Pichai, Twitter co-founder and former CEO Evan Williams, US actor-singer Jack Black — even the deceased Beatle George Harrison — have seen their social media accounts being hacked in recent times.
Even social networking websites with two-step verification procedures are not secure any more as hackers have evolved various strategies to steal personal information from computers, laptops or smartphones. “There may be a possibility that Rahul Gandhi’s Twitter account was logged into from an unsecured computer or a device that did not have next-generation firewall, an updated anti-virus software or from a compromised IP address. This situation is a boon for hackers who are constantly searching for security flaws and hack into the social media accounts of celebrities and political leaders,” Anoop Mishra, one of the nation’s leading social media experts, told IANS.
According to Saket Modi, Co-founder and CEO of IT risk assessment and digital security services provider Lucideus, the social media hack of both Congress Party and its Vice President’s Twitter accounts can be a result of any one of two possibilities. “It can either be a potential backdoor (malware) being present on a computer system on which both the accounts might have been simultaneously accessed, or this can be a long, persistent and targeted attack (spear phishing in most cases) on the political party. In either case, I am certain there is more data in the hands of the hackers than just account access that might be released in due course of time,” Modi told IANS.
“The only two parties responsible for the security of a social media account are the social media provider (in this case Twitter) and the owner of the account. As these are just two accounts that have been compromised and misused, it is safe to assume that the exploited vulnerability was not present on the side of Twitter,” Modi added. There are several infamous groups busy working day and night to hack into social media accounts — be it Legion, that claimed to have hacked into Rahul Gandhi’s Twitter account, or OurMine, that compromised the Twitter accounts of Zuckerberg, Dorsey, Pichai and others.
The most popular website among hackers is LeakedSource.com which compiles the databases for publicly available hacks of usernames, passwords and email addresses from every major website security breach over the last few years, say media reports. For a country like India that is transitioning to a digital era, experts feel there is a need for stronger cyber laws to minimise such cyber-bullying risks.
“India still does not have a dedicated legislation on cyber security or bullying when it comes to social media platforms. The country, given its vision of becoming an IT super-power, needs to have a dedicated cyber security law on this at the earliest,” Pavan Duggal, one of the nation’s top cyber law experts and a senior Supreme Court advocate, told IANS. The Information Technology Act, 2000, was amended in 2008. By virtue of the 2008 amendments, certain cosmetic changes concerning cyber security were made to the Information Technology Act, 2000.
“These amendments are not sufficient and adequate in today’s scenario. Further, the cyber security breach ecosystem ground realities are distinctly different in 2016 as compared to 2008. As such, there is a distinct need for India to beef up its legal frameworks on cyber security and cyber bullying,” Duggal added. People need to adopt various cyber hygiene methodologies in order to avoid online data stealing.
“Having in place an updated anti-virus software on your computer system is a critical component. There are several encrypted data services available which can be used abroad. Company executives should only access HTTPs sites — being secure sites,” Duggal suggested. “If you’re accessing something sensitive on public Wi-Fi, try to do it on an SSL (Secure Socket Layer) encrypted websites. The HTTPs browser extension can reduce the risk by redirecting you to an encrypted page when available,” Mishra explained.
Turn off file/computer/network sharing and avoid using specific websites where there’s a chance that cyber criminals could capture your identity, passwords or personal information. “Make all new PIN and account passwords different and difficult to guess. Include upper and lower case letters, numbers and symbols to make passwords harder to crack online,” suggested Sunil Sharma, Vice President-Sales and Operations (India & SAARC), Sophos, a global leader in network and endpoint security.
IANS

Monday, October 24, 2016

Comedian Leslie Jones lashes back at hackers in “Saturday Night Live” over recent celeb hacks

Comedian Leslie Jones lashes back at hackers in “Saturday Night Live” over recent celeb hacks

A day after hackers unleashed an attack on some of the world’s best-known websites, comedian Leslie Jones weighed in on cyber-security in a commentary on “Saturday Night Live,” saying cyber criminals could put their talents to far better use than hacking celebrities. Jones, whose own website was hacked in August resulting in nude photos and personal information including her passport and driver’s license being posted, offered her perspective during her recurring gig as an impassioned contributor to the weekly comedy show’s “Weekend Update” news segment.
“I am very comfortable with who I am. I am an open book,” Jones declared, noting “I keep my porn in a folder labeled porn.” “If you wanna see Leslie Jones naked, just ask,” the comedian added, in what one Twitter user, an entertainment website editor, said may have been Jones’ “finest SNL moment.” After starring in the “Ghostbusters” film this summer, Jones briefly quit Twitter because she was bombarded by racist and abusive comments.
“If I was good at computers, I wouldn’t waste it trolling on people,” Jones said. Instead, “I would do something useful, like renew my driver’s license from home. I would hack into Tinder and delete all those other girls’ profiles, so no matter where you swipe, you get me.”
Adopting a seemingly more serious tenor, Jones scolded hackers by saying “If you want to hurt anybody these days, you’re going to have to do way more than leak their news or call them names. You can’t embarrass me more than I have embarrassed myself.”
“At a certain point you got to stop being embarrassed and just start being you, and I have been me for 49 years. Because the only person who can hack me is me,” she vowed, adding: “My firewall is a crazy-ass bitch with a shovel.”
Reuters

Friday, September 30, 2016

US Securities and Exchange Commission may make Yahoo the test case of data breach disclosure rules

#YAHOO

US Securities and Exchange Commission may make Yahoo the test case of data breach disclosure rules
Yahoo’s disclosure that hackers stole user data from at least 500 million accounts in 2014 has highlighted shortcomings in U.S. rules on when cyber attacks must be revealed and their enforcement. Democratic Senator Mark Warner this week asked the U.S. Securities and Exchange Commission to investigate whether Yahoo and its senior executives properly disclosed the attack, which Yahoo blamed on Sept. 22 on a “state-sponsored actor.”
The Yahoo hack could become a test case of the SEC’s guidelines, said Jacob Olcott, former Senate Commerce Committee counsel who helped develop them, due to the size of the breach, intense public scrutiny and uncertainty over the timing of Yahoo’s discovery. Yahoo has not specifically addressed when it learned of the 2014 attack. And the vagueness of SEC’s 2011 rules on disclosure and its failure to enforce them are drawing equal attention, privacy lawyers and cyber security experts said.
The agency has “been looking for the right case to bring forward,” said Olcott. The agency in 2011 told publicly traded companies to report hacking incidents that could have a “material adverse effect on the business” but did not define that. SEC has never acted against a company for failing to disclose a cyber security incident or threat, and it has brought just two enforcement actions against companies for insufficient data protection, an agency spokesman said. Lawyers said this reflected difficulty in determining if breaches were material and many companies’ belief that reporting on cyber threats generally satisfies the disclosure requirement.
Yahoo has not offered a precise timeline about when it was made aware of the breach. On Sept. 9, it said in an SEC filing it did not know of “any incidents of, or third party claims alleging … unauthorized access” of customers’ personal data that could have a material adverse effect on Verizon Communication Inc’s planned $4.8 billion acquisition of Yahoo’s core business. Since then, Yahoo has not clarified if it knew of the attack before that SEC filing. “Our investigation into this matter is ongoing and the issues are complex,” a Yahoo spokesman said last week.
In his letter, Warner asked the SEC to evaluate whether the current disclosure regime was adequate. He cited reports that fewer than 100 of 9,000 public companies disclosed a material data breach since 2010. “I don’t know that we need new rules. But in certain situations, you may need more aggressive enforcement,” said Roberta Karmel, a Brooklyn Law School professor. The SEC in 2014 examined whether cyber disclosure rules needed to be strengthened and imposed new requirements for broker-dealers and investment advisers but not public companies.
‘Punish the victim’
Some policymakers worry rules compelling prompt disclosure of cyber attacks could deter companies from cooperating with authorities.“We cannot blame executives for worrying that what starts today as an honest conversation about a cyber attack could end tomorrow in a ‘punish the victim’ regulatory enforcement action,” Commerce Secretary Penny Pritzker said this week. Congress last year expanded liability protections for companies that share cyber information with the government, and Pritzker urged granting companies temporary immunity during the response to a hack.
Amid SEC inaction, the Federal Trade Commission has brought 60 successful data security cases since 2001 in part, lawyers said, because its authority is clearer than the SEC’s. Those cases have dealt with deceptive statements by companies and security lapses. The FTC is hampered by the lack of a national requirement for companies to notify the public about data breaches. That idea got widespread support after the 2013 hacking of shoppers’ credit card information from Target Corp. But legislation proposed by President Barack Obama in 2015 fizzled.
Reuters

Related Posts Plugin for WordPress, Blogger...