Google Search

Showing posts with label group. Show all posts
Showing posts with label group. Show all posts

Wednesday, January 9, 2013

Albania Pirate Group thrown off Facebook for second time in a month

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

APGHackers who have been sharing information publicly on Facebook about how to break into computer systems have had their pages shut down for the second time in a month.

The Albania Pirate Group (APG) was first thrown off the social network earlier this month, after Sophos researchers contacted Facebook's Security Team.

Smarting slightly, the group appears to have attempted to regroup on Facebook - creating a new page and - again - openly sharing passwords of breached systems.

In the Facebook page we discovered yesterday, we found that the Albania Pirate Group had been posting details of Twitter accounts they had hacked, and usernames and passwords for RDP (Remote Desktop Protocol) servers - making it simple for hackers to get unauthorised remote access to computer systems.

APG Facebook page

The RDP usernames and passwords which were posted on the Facebook page make for depressing reading - demonstrating that many people are using very poorly chosen passwords.

Usernames and passwords posted on the Albania Pirate Group Facebook page

Sophos has contacted Facebook Security, which has promptly shut down the page.

Our thanks go to the Facebook security team for shutting down the page so promptly. Of course, this is something like a game of whack-a-mole for Facebook's security team, and it wouldn't be a surprise if the hacking group reared its head again.

Stay informed about the latest security and privacy issues related to Facebook. Join the Naked Security page on Facebook, where over 200,000 people regularly share information on threats and discuss the latest security news.

http://twitter.com/gcluley

View the original article here

Monday, December 24, 2012

Facebook shuts down Albania Pirate Group, after stolen passwords shared

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Facebook and APGIt's easy to understand how hacking groups, involved in undercover cybercrime, might want to keep their activities hidden from the-powers-that-be and law enforcement agencies, and conduct their crimes in secrecy.

Which makes it all the more surprising when you stumble across a group apparently engaged in stealing and sharing login passwords for third party systems, doing so not just on a public-facing website, but on a page hosted by the world's biggest social network.

A reader of Naked Security, who works at a Yorkshire-based security company, contacted us last week to tell us about a particular Facebook page they had stumbled across belonging to the Albania Pirate Group.

Albania Pirate Group on Facebook

On its Facebook page, 600+ fans and members of the Albania Pirate Group were sharing RDP (Windows Remote Desktop) logins, giving hackers unauthorised access to computer systems, and what appeared to be compromised banking details.

The potentially sensitive information was free for anyone to view, even if you hadn't "Liked" the page.

Curiously, the Albania Pirate Group has a similar logo to the Kosova Hacker's Group, who breached servers belonging to the US National Weather Service last month.

Albania Pirate Group on Facebook

Sophos contacted Facebook, and within the hour the social network's security team had closed down the page.

Remember that pages and groups on Facebook are not pre-vetted, and anyone can create a page with ease and use it for illegal purposes. If you stumble across a Facebook page that you believe is involved in law-breaking or breaches the terms and conditions of the site, you should report it to Facebook.

Our thanks go to the Facebook security team for shutting down the page so promptly.

Stay informed about the latest security and privacy issues related to Facebook. Join the Naked Security page on Facebook, where over 190,000 people regularly share information on threats and discuss the latest security news.

Follow @gcluley

View the original article here

Tuesday, July 31, 2012

Facebook users can now see if and when you have read their group posts. Privacy anyone?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Facebook quietly introduced new functionality onto its site last week that could have some worried about their online privacy.

The social network is rolling out the ability to see if and when someone has seen a post on a Facebook group.

Less privacy on Facebook groups

For now you can still snoop on the profiles and pictures of your ex-partners (their privacy settings permitting) to keep a track - without them knowing - of how miserable their life has become since they split up with you.

But if you are in the same Facebook group (perhaps related to a school, club or joint interest), you can see both whether someone has seen a particular post and at what time they saw it.

So, although you can configure Facebook to not tell your online friends when you are online (effectively hiding from their instant messaging chats, and maintaining a pretence that you have a social life rather than being plugged into the internet constantly) they can still keep some track on what you are up to, and when, on Facebook.

I don't want to come across as a complete privacy zealot here. I can understand that there are justifiable explanations of why knowing if someone has read a group announcement could be very useful... but is there anyone else who agrees that Facebook just became a little less private?

Similar functionality already exists in the Facebook Messenger app, telling you if and when your contacts have read a message.

Facebook Messenger

One wonders if this is a slippery slope, and whether Facebook will consider introducing the (desired by many, and dreaded by the privacy conscious and anonymous snoopers) ability to tell who has been checking out your Facebook profile?

When TechCrunch asked Facebook if the "Seen by" functionality would be ported over to the news feed, the site said it was "not going to discuss what we might (or might not) do in the future."

Hmm.

In the meantime, I've been unable to find any way to prevent Facebook from sharing whether I had read a group post, or share to users with the Messenger app if I had seen a message. I would, at least, have liked the option.

Once again, Facebook has become a little less private.

If you want to learn more about privacy and security threats on the social network and elsewhere on the internet, join the Naked Security from Sophos Facebook page.

Follow @gcluley

View the original article here

Thursday, September 29, 2011

Austrian Hacker Group Publishes Police Data - RTT News

(RTTNews) - A group of Austrian hackers has published the names and home addresses of nearly 25,000 police officials, triggering fears that the move might compromise the personal security of the officers.

According to Austrian officials, the data published as a searchable database on Twitter contained private information of more than 24,938 law enforcement officials ranging from beat officers to senior commanders.

Police union official Walter Scharinger said Monday that the hackers' move poses risks to officers as they might now become targets of revenge attacks by criminals they have encountered earlier.

Austrian authorities said the police data was published by a domestic hacker group known as 'AnonAustria', the Austrian branch of the global hacker collective 'Anonymous.'

The group said in a statement posted on its Twitter account that the move was to protest against a proposed law that would force telecommunications companies to save the details of all their telephone and internet traffic for a period of six months and provide them to the police, if required.

Austria's State Office of Criminal Investigation has launched an investigation into the leak of the police data.

Anonymous had come into prominence late last year after breaching websites belonging to several Internet services and online payment providers who cut their ties with whistle-blower WikiLeaks, including MasterCard and PayPal.

WikiLeaks, a website that publishes leaked classified information online, had earlier published thousands of confidential cables sent by U.S. embassies across the world as well as secret documents relating to wars in Iraq and Afghanistan.

Many members of Anonymous as well as allied hacker groups have already been arrested on both sides of the Atlantic in a crackdown involving European and US enforcement agencies. In response to those arrests, Anonymous called on its supporters to stop using PayPal accounts for making online payments

by RTT Staff Writer

For comments and feedback: editorial@rttnews.com


View the original article here

Sunday, July 3, 2011

LulzSec hacker group inspires copycats - Washington Times

The anarchistic hacker group LulzSec formed, attacked websites around the world and announced its breakup all within two months — demonstrating the speed with which cybersecurity threats develop in the Internet age.

Since emerging in May, LulzSec has:

• Decrypted and published the login names, passwords and other personal information of members of the FBI’s private sector partnership organization Infraguard.

• Broken into NATO’s online electronic bookstore.

• Posted confidential documents from a half-dozen foreign governments.

• Briefly taken offline the websites of the CIA and of Britain’s Serious Organized Crime Agency.

This week, the group — apparently less than a dozen strong — posted hundreds of internal documents stolen from the Arizona State Police computer network, including the home addresses of several officers and their families.

Cybersecurity experts tell The Washington Times that copycat groups already are emerging all over the world, that the hacker tools they use are widely available and that LulzSec’s nihilistic mindset will continue spreading.

“It’s the idea behind it that will be picked up,” said David Marcus, director of security research for McAfee Labs, noting that LulzSec lookalikes already had been founded in Brazil and Spain. “It’s hard to fight an idea.”

The group has used the slogan, “Laughing at your security since 2011,” and derives its name from “security” and the Internet term “lulz,” which means “loads of laughs.” LulzSec also has 280,000 followers on Twitter.

The group’s objective has been “basically to laugh at you and embarrass you about your poor security,” Mr. Marcus said. “They’re very hard to categorize.”

“We like crushing things; we like inside info,” wrote a member using the name Espeon about the group’s philosophy during an Internet chat with a security executive whose firm LulzSec had hacked. The group later published a purported transcript of the exchange.

Over the weekend, LulzSec issued a statement saying it was disbanding out of “boredom.”

Mr. Marcus said the group “crossed a line” in posting the home addresses and phone numbers of Arizona Department of Public Safety officers and their families. “That’s not funny, that’s not ‘lulzy,’ ” he said. “If you want to protest, protest. But that is putting people in danger.”

Many of the group’s attacks have used relatively simple methods, including SQL injection, in which hackers exploit very widespread and easily discoverable software security flaws to take control of websites’ databases.

Story Continues ?

View Entire Story © Copyright 2011 The Washington Times, LLC. Click here for reprint permission.


View the original article here