Google Search

Showing posts with label expose. Show all posts
Showing posts with label expose. Show all posts

Monday, November 12, 2012

TinKode sentenced after hacking Oracle, NASA and others to expose weak security

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

TinKodeThe infamous hacker known as TinKode has been sentenced by a Romanian court, according to media reports.

Cernaianu Manole Razvan was arrested in January 2012, after a series of high profile hacks of government and military websites, exposing their poor security and often publishing passwords and screenshots as evidence.

Past victims have included website belonging to the British Royal Navy, MySQL.com (which ironically fell foul of a SQL injection attack) and NASA servers.

Royal Navy website

To the relief of many, TinKode appeared to be inspired more by the desire to embarrass organisations into improving web security - rather than making money.

In an interview with Network World in 2011, TinKode compared his activities to a free security audit:

Until now, no. I don't do bad things. I only find and make public the info. Afterwards I send an email to them to fix the holes. It's like an security audit, but for free.

Nevertheless, his actions were illegal and led to his arrest by Romanian authorities earlier this year. Last month a Romanian court ordered Razvan to pay 93,000 Euros (approximately $120,000) to cover the costs suffered by his breached victims, and gave him a two year suspended prison sentence.

That's a lesson that others would be wise to learn from if engaged in similar activities.

Free TinKode petition

An online petition, started by TinKode's sympathisers, failed to receive significant support (a hoped-for 5000 signatures has only reached 187 at the time of writing). It remains to be seen whether they will help the young Romanian pay his substantial fine.

It's no excuse for TinKode's criminal hacks, but if the websites had been properly secured in the first place they would have never found themselves embarrassed by the Romanian hacker.

If you haven't already done so, check out our free technical paper about "Securing websites", which discusses common ways web servers are attacked and the various ways that they can be protected.

Follow @gcluley

View the original article here

Wednesday, July 13, 2011

Hackers hit Washington Post, expose 1.2 million accounts - Christian Science Monitor

An unknown group of hackers hit the jobs section of the Washington Post website last week, making away with the personal information of more than 1.2 million users. In a FAQ posted this afternoon, reps for the Post sought to play down the extent of the hack, assuring users that the worst that they will probably weather is a series of spam emails, which should obviously be ignored (the spam emails, not the FAQ).

Skip to next paragraph

"[Y]ou should be aware that you may receive some unsolicited e-mail (spam) as a result of this incident," Post exec Beth Diaz wrote in a letter to users. "As a general matter, you should always avoid opening suspicious or unsolicited e-mail, never respond to or click any links in spam, and avoid providing personal or financial information in an e-mail – especially credit card information, bank account information, passwords, and ID numbers."

Still, this isn't particularly great news for the Post, or for other newspapers, which typically require online readers to fork over a small amount of personal information – usually an email address and name, and sometimes more – before registering on the site. Readers like to trust that that personal information will be kept safe, not left exposed to marauding groups of hackers, whomever those marauding groups of hackers may be.

Speaking of which: Is it possible, as Kyle Wagner coyly hints over at Gizmodo, that the Washington Post attack could be the work of Anonymous or any of the other members of the AntiSec campaign? Horizons readers will remember that Anonymous has been very active in recent weeks, hitting the online home of the Arizona Police Department, among other targets.

Answer: Sure, it's possible that Anonymous is behind the attack. It fits the bill for AntiSec, which has typically targeted large governmental and media outposts. But then again, no one has yet claimed credit for the attack, and claiming credit is something that Anonymous likes to do. Stay tuned for more.


View the original article here

Tuesday, July 12, 2011

Hackers expose flaw in Apple iPad, iPhone software

BOSTON (Reuters) - Hackers have disclosed a bug in software from Apple Inc that security experts said could be exploited by criminals looking to gain remote control over iPhones, iPads and iPod Touch devices.

The security flaw in Apple's iOS operating system came to light on Wednesday as the website www.jailbreakme.com released code that Apple customers can use to modify the iOS operating system through a process known as "jail breaking."

Some Apple customers choose to jail break their devices so they can download and run applications that are not approved by Apple or use iPhone phones on networks of carriers that are not approved by Apple.

Security experts warned that criminal hackers could download that code, reverse engineer it to identify a hole in iOS security and build a piece of malicious software within a few days.

"If you are a malicious attacker, it is fairly doable," said Patrik Runald, a senior researcher with the Internet security firm Websense.

Apple has yet to release an update to iOS that protects customers against malicious software that exploits the flaw.

Apple spokeswoman Trudy Muller said the company was aware of the problem.

"We are developing a fix that will be available to customers in an upcoming software update," Muller said.

Apple has long been vocal against jail breaking, which if done voids the warranty on its devices.

Any security flaw in iOS software -- which runs Apple's iPhone, iPad tablet and iPod Touch -- has the potential to affect millions of devices that are at the core of Apple's business.

Apple has sold 25 million iPads since it launched last year. The company sold over 18 million of its popular iPhones in just the first three months of the year.

Hackers can exploit the iOS vulnerability by creating a malicious PDF document file. It would infect Apple devices when users attempt to open that document, according to Runald.

Once the device is infected, hackers could "do anything they want," Runald said. That includes stealing passwords, documents and emails.

Comex, a 19-year-old hacker from New York State who developed the jail-breaking tool, said that Apple might be able to patch the software before criminal hackers develop software that exploits the bug.

Last time he put out a version of his jailbreaking software, Apple was able to issue a patch before anybody exploited the bug for malicious purposes.

He said that Apple might not be able to move quickly enough this time.

"It's not that hard to reverse engineer," he said via telephone.

(Reporting by Jim Finkle, additional reporting by Poornima Gupta; Editing by Bernard Orr)


View the original article here

Monday, July 11, 2011

Hackers hit Washington Post, expose 1.2 million accounts

An unknown group of hackers hit the jobs section of the Washington Post website last week, making away with the personal information of more than 1.2 million users. In a FAQ posted this afternoon, reps for the Post sought to play down the extent of the hack, assuring users that the worst that they will probably weather is a series of spam emails, which should obviously be ignored (the spam emails, not the FAQ).

Skip to next paragraph

"[Y]ou should be aware that you may receive some unsolicited e-mail (spam) as a result of this incident," Post exec Beth Diaz wrote in a letter to users. "As a general matter, you should always avoid opening suspicious or unsolicited e-mail, never respond to or click any links in spam, and avoid providing personal or financial information in an e-mail – especially credit card information, bank account information, passwords, and ID numbers."

Still, this isn't particularly great news for the Post, or for other newspapers, which typically require online readers to fork over a small amount of personal information – usually an email address and name, and sometimes more – before registering on the site. Readers like to trust that that personal information will be kept safe, not left exposed to marauding groups of hackers, whomever those marauding groups of hackers may be.

Speaking of which: Is it possible, as Kyle Wagner coyly hints over at Gizmodo, that the Washington Post attack could be the work of Anonymous or any of the other members of the AntiSec campaign? Horizons readers will remember that Anonymous has been very active in recent weeks, hitting the online home of the Arizona Police Department, among other targets.

Answer: Sure, it's possible that Anonymous is behind the attack. It fits the bill for AntiSec, which has typically targeted large governmental and media outposts. But then again, no one has yet claimed credit for the attack, and claiming credit is something that Anonymous likes to do. Stay tuned for more.


View the original article here