Two students named Mathew Hewlett and Caleb Turon study in grade 9, they found an old ATM operators manual online that shows how to get into the ATM operator mode.
.:: INFORMATION SECURITY TO SECURE YOUR COMMUNICATION AND INFORMATION IN THIS CYBER AGE :::.
Showing posts with label Information. Show all posts
Showing posts with label Information. Show all posts
Monday, June 23, 2014
How 14-Years-Old coders hacked the ATM Machine | Hackers News Bulletin
Two students named Mathew Hewlett and Caleb Turon study in grade 9, they found an old ATM operators manual online that shows how to get into the ATM operator mode.
Wednesday, April 30, 2014
EC3: Darknet & cloud the barriers to prosecuting cyber-criminals | SC Magazine UK
He also said that cyber-crime investigations have been harder by the leaks from former CIA contractor Edward Snowden, perhaps on the basis that cyber-criminals have look to increase their anonymity.
“The Snowden revelations seemed to, one way or another, have made it more difficult law enforcement to clamp down on [internet] rules,” said Oerting.
Where’s the Next Heartbleed Bug Lurking? | MIT Technology Review
OpenSSL, which the Internet depends upon, has a single full-time employee dedicated to keeping the software secure. Other projects are similarly understaffed.
The Heartbleed bug was discovered earlier this month in a piece of software called OpenSSL that is widely used to establish a secure connection between Web browsers and servers by managing the cryptographic keys involved. OpenSSL is an “open source” project, meaning that the underlying code is published along with the software. Also, like many other open-source efforts, it is maintained by a small group of volunteer programmers (see “The Underfunded Project Keeping the Web Secure”).
RedHack Hackers Target Aktif Bank over Controversial e-Ticketing System | Softpedia
Members of the hacktivist collective RedHack claim to have breached into the systems of Aktif Bank (aktifbank.com.tr), Turkey’s largest privately owned investment bank. The attack comes just as the bank introduced a controversial e-ticketing system for soccer (football) fans.
The recently introduced system relies on special cards that are mandatory for all those who want to attend soccer games.
Sunday, July 14, 2013
Defcon to feds: 'We need some time apart' | cnet.com
In the wake of revelations about the NSA's PRISM program, Defcon's founder asks federal government employees to skip this year's hacker convention.
(Credit: Screenshot by Lance Whitney/CNET)
The federal government is persona non grata at this year's Defcon.
For the first time in the 21-year history of the famed hacker's convention, government employees are being asked to stay away, albeit in a polite fashion.
Defcon founder Jeff Moss, aka The Dark Tangent, posted the following request late Wednesday on the event's site:
Tuesday, June 25, 2013
Facebook Data-Leaking Bug Exposes 6 Million Users' Data | infosecurity-magazine.com
Facebook has admitted to a bug in its system that has given users of the Download Your Information (DYI) tool "additional email addresses or telephone numbers for their contacts or people with whom they have some connection."
Facebook apologized, stating that it has notified regulators in the US, Canada and Europe, and that it is contacting affected users by email. Security commentators, meanwhile, are trying to work out exactly what happened, and how.
Facebook has admitted that the bug caused the phone numbers and email addresses of six million users to be shared unintentionally. The number of UK users affected by the bug is believed to be around 200,000 according to the Telegraph.
Saturday, June 8, 2013
White-hat hacker fights cyber intrusions on NATO systems | NATO News
"I put myself in the mindset of a hacker and simulate cyber attacks so that I can identify potential weak points in our systems and then set up appropriate defences," explains Nuri Fattah, Senior Security Consultant, at the NATO Communications and Information Agency.
Microsoft, Feds Take Down Citadel Botnets | eSecurity
How did Microsoft shut down the notorious Citadel botnet ring, which stole more than $500 million from victims?
By Sean Michael Kerner
For over a year, Microsoft and its partners in the financial services community watched a big botnet operation siphon millions of dollars from victims. On Wednesday night, Microsoft announced that in coordination with the FBI, it had moved in to disrupt the massive botnet-based crime ring known as Citadel.
Richard Boscovich, assistant general counsel in the Microsoft Digital Crimes Unit, told eSecurity Planet that there were more than 1,400 botnets associated with this malware. As such, it took Microsoft and its partners a significant amount of time to locate all of the Citadel botnets operating around the world.
"This was a lengthy process and we relied heavily on our financial services and technology industry partners to ensure that we would be able to take aggressive action against this threat," Boscovich said.
The Citadel malware infected PCs with a keylogger that monitored user activity on financial websites. The malware infected more than five million people across 90 countries and stole more than $500 million in assets.
By Sean Michael Kerner
For over a year, Microsoft and its partners in the financial services community watched a big botnet operation siphon millions of dollars from victims. On Wednesday night, Microsoft announced that in coordination with the FBI, it had moved in to disrupt the massive botnet-based crime ring known as Citadel.
"This was a lengthy process and we relied heavily on our financial services and technology industry partners to ensure that we would be able to take aggressive action against this threat," Boscovich said.
The Citadel malware infected PCs with a keylogger that monitored user activity on financial websites. The malware infected more than five million people across 90 countries and stole more than $500 million in assets.
Black Hat security conference to include 110 talks | scmagazine.com
by Dan Kaplan, Executive Editor
When Black Hat's annual security conference rolls into Las Vegas at the end of July, event organizers promise one of the most "content-heavy" installments yet.
Last week, the conference, now in its 16th year, announced some of the planned presentations, most of which are known as "briefings" and which will span 11 tracks. In total, there will be 110 talks.
"Normally Black Hat accepts in the 80-90 range, but they expanded the number this year because there was so much incredible content – it was hard to fit it all in," a Black Hat spokeswoman told SCMagazine.com. "Not all of these talks have been announced on the website yet."
When Black Hat's annual security conference rolls into Las Vegas at the end of July, event organizers promise one of the most "content-heavy" installments yet.
Last week, the conference, now in its 16th year, announced some of the planned presentations, most of which are known as "briefings" and which will span 11 tracks. In total, there will be 110 talks.
"Normally Black Hat accepts in the 80-90 range, but they expanded the number this year because there was so much incredible content – it was hard to fit it all in," a Black Hat spokeswoman told SCMagazine.com. "Not all of these talks have been announced on the website yet."
Wednesday, May 8, 2013
Scammers Impersonate Bank Exec on LinkedIn to Target Corporate Bank Accounts | HOTforSecurity
Imagine you receive an e-mail from an unknown prince / political refugee – the classic Nigerian scam of the past 10 years. You wouldn’t fall for that, would you?
Imagine now a legit business proposal from a bank manager with all the credentials, work experience and peers. It’s not even disguised as a Nigerian operation – it’s a business proposition. And it’s on LinkedIn.
We got such a message from an individual impersonating Aziz Mohammad, a manager at a highly popular bank in Malaysia. A brief look at his profile revealed it was built using the visual identity and profile information of the real Aziz Mohammad, a third-degree connection.

The scam message is crafted generically, as it lays the ground for the con: a business proposal for people who have full control of the company, including the possibility to initiate money transfers. The contact information is, of course, an e-mail address that does not belong to the banking institution the impersonator claims to be affiliated with, but rather a disposable account set up with Yahoo.
Imagine now a legit business proposal from a bank manager with all the credentials, work experience and peers. It’s not even disguised as a Nigerian operation – it’s a business proposition. And it’s on LinkedIn.
We got such a message from an individual impersonating Aziz Mohammad, a manager at a highly popular bank in Malaysia. A brief look at his profile revealed it was built using the visual identity and profile information of the real Aziz Mohammad, a third-degree connection.
The scam message is crafted generically, as it lays the ground for the con: a business proposal for people who have full control of the company, including the possibility to initiate money transfers. The contact information is, of course, an e-mail address that does not belong to the banking institution the impersonator claims to be affiliated with, but rather a disposable account set up with Yahoo.
Hackers gain access to all .edu domains | H-Online
The hacker collective "Hack the Planet" (HTP) has claimed responsibility for an attack on MIT (Massachusetts Institute of Technology) computer systems in late January, in which it claims to have briefly taken control of the university's domain, redirected email traffic, and obtained administrator access to all .edu domains. HTP also claims to have compromised web servers for other sites, including security tool Nmap, network security service Sucuri, IT security company Trend Micro, and network analysis tool Wireshark.
Some of the hacks made use of a zero-day exploit, which the group has now taken the opportunity to disclose, against a vulnerability in the MoinMoin wiki system. Hack the Planet has also released information about an exploit against web servers running ColdFusion 9 or 10. The group claims to have used a variant of this exploit for their April attack on hosting company Linode.
Phishers target eBay customers via live chat support | Help Net Security
U.K.-based ISP Netcraft is warning users about phishers impersonating eBay's live chat support feature in the hopes of getting their hands on eBay users' login, personal and financial information.

The ISP blocked the bogus site offering the fraudulent service, but says that others might easily pop up.
In this particular case, the phishers were using a third-party live chat service provided by Volusion, and the fraudulent chat window was, at first, showing the eBay logo.
The eBay branding later disappeared from the site, and was replaced by a place-holder company logo, which means that the phishers can easily impersonate any of the other companies that outsource their live chat support. The fact that Volusion's services have a valid SSL certificate could also make many victims believe that they are dealing with a legitimate service.
The ISP blocked the bogus site offering the fraudulent service, but says that others might easily pop up.
In this particular case, the phishers were using a third-party live chat service provided by Volusion, and the fraudulent chat window was, at first, showing the eBay logo.
The eBay branding later disappeared from the site, and was replaced by a place-holder company logo, which means that the phishers can easily impersonate any of the other companies that outsource their live chat support. The fact that Volusion's services have a valid SSL certificate could also make many victims believe that they are dealing with a legitimate service.
Wednesday, March 20, 2013
BlackBerry BB10 fails government security test | SC Magazine
The UK government has rejected the BB10 software, calling it not secure enough for essential work.
According to a report by the Guardian, the operating system on the new Z10device has been rejected after BlackBerry version 7.1 was cleared by the UK's Communications Electronics Security Group (CESG) for classifications up to ‘Restricted' – two levels below ‘Secret'. A survey by Trend Micro deemed that the BlackBerry 7.0 was named most secure mobile OS for enterprises.
However tests on BB10 and the BlackBerry Balance software have failed the same security requirements and BlackBerry could not offer a date when revised software would be submitted.
A BlackBerry statement said: “We have a long-established relationship with CESG and we remain the only mobile solution approved for use at 'Restricted' when configured in accordance with CESG guidelines. This level of approval only comes following a process which is rigorous and absolutely necessary given the highly confidential nature of the communications being transmitted.
However tests on BB10 and the BlackBerry Balance software have failed the same security requirements and BlackBerry could not offer a date when revised software would be submitted.
A BlackBerry statement said: “We have a long-established relationship with CESG and we remain the only mobile solution approved for use at 'Restricted' when configured in accordance with CESG guidelines. This level of approval only comes following a process which is rigorous and absolutely necessary given the highly confidential nature of the communications being transmitted.
Tuesday, October 23, 2012
5 Ways to Make Your Browser More Secure | eSecurity Planet
While installing antivirus software is a good start to safe Internet browsing, it's only a start. There is much more you can do to help protect yourself when browsing the Web than merely installing antivirus.
Here I’ll share a couple ways. In this article you’ll discover extra security features in Firefox and Chrome, sandboxing to secure any browser, third-party DNS service for content filtering, and VPNs for securing your browsing while on Wi-Fi hotspots and other public networks.
Android apps 'leak' personal details | BBC News Technology
Better tools are needed to help developers secure data, say researchers |
Millions of people are using Android apps that can be tricked into revealing personal data, research indicates.
Scientists tested 13,500 Android apps and found almost 8% failed to protect bank account and social media logins.
These apps failed to implement standard scrambling systems, allowing "man-in-the-middle" attacks to reveal data that passes back and forth when devices communicate with websites.
Your Facebook Account Hacked? Protect it Now! | eHacking.net

Facebook has become a popular platform not only for social networking but also for business promotion. You will find many brand exposure on Facebook these days. But how will you feel when such an important account gets hacked? In the present scenario, hacking a Facebook account is quite alike hacking the email account or the bank account. It’s true that your life seems to get ruined when your Facebook account gets hacked.
Many users spend hours after hours staying online on these sites and hence, such a breach of act can affect them adversely. When your account gets hacked, all your personal details are hijacked and spam mails are sent to a number of high grade professionals. Want to safeguard yourself from getting hacked?
Follow these steps and protect yourself.
Tuesday, July 24, 2012
Mozilla Releases Multiple Updates | US-CERT
The Mozilla Foundation has released updates for the following products to address multiple vulnerabilities:
US-CERT encourages users and administrators to review the Mozilla Foundation Advisory for Firefox 14, Firefox ESR 10.0.6, Thunderbird 14, Thunderbird ESR 10.0.6, and SeaMonkey 2.11 and apply any necessary updates to help mitigate the risk.
Article source : https://www.us-cert.gov/current/#mozilla_releases_multiple_updates2
- Firefox 14
- Firefox ESR 10.0.6
- Thunderbird 14
- Thunderbird ESR 10.0.6
- Seamonkey 2.11
US-CERT encourages users and administrators to review the Mozilla Foundation Advisory for Firefox 14, Firefox ESR 10.0.6, Thunderbird 14, Thunderbird ESR 10.0.6, and SeaMonkey 2.11 and apply any necessary updates to help mitigate the risk.
Article source : https://www.us-cert.gov/current/#mozilla_releases_multiple_updates2
How to Prevent Social Engineering Attacks | ehacking.net

This post is about social engineering. It will cover some of the dangers of social engineering and focus more on what a corporation or a company can do to help better prepare their employees for those kinds of situations.
Security Awareness Training
The most important and something we don’t do enough is the basic security awareness training. Employees need to be aware of certain situations that look odd, keep them ingrained with understanding that even if they don’t want to admit it or don’t like the fact, they are part of the security team. Every employee no matter what their function is – they also have the duties of protecting the company and protecting the company’s assets. That’s part of their job. If the company goes out of business because of compromised info, they no longer have employment. It is in their best interest to make sure that the company is secured so that they can continue making money and keep paying people their salaries.
Sunday, July 22, 2012
Howto | Flush DNS | mYne-net
Most operating systems and DNS clients will automatically cache IP Addresses and other DNS results, this is done in order to speed up subsequent requests to the same hostname. Sometimes bad results will be cached and therefore need to be cleared from the cache in order for you to communicate with the host correctly. All major operating systems allow you to force this process, outlined below are the common steps you will need to follow in order to flush your DNS cache.
Thursday, July 19, 2012
Review | OWASP iGoat Project | mYne-net
Just to review this tools...found for iOS user..heheeh..
iGoat is a learning tool for iOS developers (iPhone, iPad, etc.). It was inspired by the WebGoat project, and has a similar conceptual flow to it.
As such, iGoat is a safe environment where iOS developers can learn about the major security pitfalls they face as well as how to avoid them. It is made up of a series of lessons that each teach a single (but vital) security lesson.
The lessons are laid out in the following steps:
1. Brief introduction to the problem.
2. Verify the problem by exploiting it.
3. Brief description of available remediations to the problem.
4. Fix the problem by correcting and rebuilding the iGoat program.
Step 4 is optional, but highly recommended for all iOS developers. Assistance is available within iGoat if you don't know how to fix a specific problem.
iGoat is free software, released under the GPLv3 license.
As such, iGoat is a safe environment where iOS developers can learn about the major security pitfalls they face as well as how to avoid them. It is made up of a series of lessons that each teach a single (but vital) security lesson.
The lessons are laid out in the following steps:
1. Brief introduction to the problem.
2. Verify the problem by exploiting it.
3. Brief description of available remediations to the problem.
4. Fix the problem by correcting and rebuilding the iGoat program.
Step 4 is optional, but highly recommended for all iOS developers. Assistance is available within iGoat if you don't know how to fix a specific problem.
iGoat is free software, released under the GPLv3 license.
Subscribe to:
Posts (Atom)
