Showing posts with label Vulnerability. Show all posts
Showing posts with label Vulnerability. Show all posts

2/12/12

United States Census Bureau Hacked and Vulnerability Exposed

United States Census Bureau Hacked and Vulnerability Exposed-Hunt Cafe News

























A Group of Hackers from r00tw0rm found SQL injection Vulnerability on United States Census Bureau and Hackers successfully exploit the Database and Leak it online today. The United States Census Bureau is the government agency that is responsible for the United States Census. It also gathers other national demographic and economic data. As part of the United States Department of Commerce, the Census Bureau serves as a leading source of data about America's people and economy.

The Pastebin Note include the complete Database Structure as shown:


















There is no reason mentioned for this attack yet by Hacker, But Hacker suggest United States Census Bureau to fix their loopholes as soon as possible. The Note include the Greets to other Hacking Groups like Inj3ct0r , TeaMp0isoN and Anonymous, seems that its a collective hack for #Antisec.

Thank You....Huntcafe.blogspot.com

2/9/12

XSS vulnerability reported in Yahoo subdomain website

XSS vulnerability reported in Yahoo subdomain website
Vansh Sharma & Vaibhuv Sharma from India Reported another important Cross site scripting XSS vulnerability in Yahoo subdomain as shown.

Vulnerable Link : http://au.tv.yahoo.com/plus7/royal-pains/
Cross-site scripting (XSS) is a type of computer security vulnerability typically found in Web applications that enables attackers to inject client-side script into Web pages viewed by other users.


Thank you...Huntcafe.blogspot.com

Smart Hacking For Privacy

Smart Hacking For Privacy 

White-hat hackers have exposed the privacy shortcomings of smart meter technology. At the Chaos Communication Congress in Germany, 28C3, researchers presented "Smart Hacking For Privacy" After analyzing data collected by a smart meter, these gentlemen were able to determine devices like how many PCs or LCD TVs in a home, what TV program was being watched, and if a DVD movie being played had copyright-protected material.

Dario Carluccio and Stephan Brinkhaus demonstrated the flaws. Advanced metering devices (aka smart meters) are nowadays being installed throughout electric networks in Germany, in other parts of Europe and in the United States. Due to a recent amendment especially in Germany they become more and more popular and are obligatory for new and refurbished buildings.
DarrellIssa
The researchers, also customers, learnt that energy consumption data was sent unencrypted because SSL was malfunctioning.They intercepted and manipulated the data using Fritzbox! and WireShark and returned to the company a negative energy consumption rate of -106610 kWh.Similar flaws also allowed Carluccio and Brinkhaus to demonstrate that a customer’s entire power consumption history was stored by Discovergy.

They signed up with a company called Discovergy to see what type of information these meters collect, whether they were as secure as the company promised and what they might be able to determine from consumption patterns. Because Discovergy's website's SSL certificate was misconfigured, the meters failed to send data over a secure, encrypted link contrary to claims Discovergy made at the time before the presentation. This meant that confidential electricity consumption data was sent in clear text. Because meter readings were sent in clear text, the researchers were able to intercept and send back forged (incorrect) meter readings back to Discovergy.

A capability that allowed power consumption to be monitored in two-second intervals was also exploited.The researchers said they could determine if a particular movie had been watched based on two-second relay data held by Discovergy and accessed through HTTP GET requests.

Researchers from Münster University of Applied Sciences were previously able analyze smart meter data to identify the power consumption activity for a refrigerator, stove, and television. They showed that the type of LCD TV set could be identified, what TV program was on, or if a movie was playing from a DVD or other source.


Thank You...Huntcafe.blogspot.com

FBI warning about Banking trojan "Gameover"

FBI warning about Banking trojan "Gameover"

Organized crooks have begun launching debilitating cyber attacks against banks and their customers as part of a smoke screen to prevent victims from noticing simultaneous high-dollar cyber heists. On Friday the FBI issued a warning about a banking trojan named Gameover. It’s a new variant of Zeus, a user credential stealing malware that targets online bank users. Zeus has been around for years, and every now and then a new version with a new twist pops up.

Gameover has also been implicated in Distributed-Denial-of-Service attacks that temporarily-disable bank websites to draw attention away from fraudulent transactions. Like another Zeus variant, Troj/BredoZp-GY, Gameover uses e-mail spam to propagate, and the safest way to keep Gameover away from your PC is to avoid links and file attachments that are contained in unfamiliar e-mail messages.
Experts warn that any interaction with this fake NACHA link can infect your PC with the Gameover banking Trojan, which will attempt to steal bank-related information while Gameover hides its own actions from site. Gameover Trojan it must be removed immediately to make your computer clean and safe.

How do you avoid bank trojans? - ( from Norman Blog )
  • Never, ever click on links (in email) that encourage you to “update your account information”, “check if your account has been compromised” or similar.
  • Always, always login to your bank by typing the address in the browser url bar.
  • Make sure your browser and operating system are always updated. Never, ever click “Later” when your browser or OS prompts you about a new security update.
  • Keep you antivirus up to date. An advanced security solution will detect any harmful sites and block any malicious files, so that you don’t have to.

Because Gameover and similar forms of banking Trojans are designed to conduct their attacks in a clandestine manner, you may not see much sign of Gameover on your PC, other than some anomalies in RAM usage or file processes. However, a successful Gameover infection can be the cause of :
  • Loss of account login data and other forms of information that are used in bank-related websites.
  • Loss of other forms of information that are gathered through keylogging (a broad form of spyware attack that monitors all types of keyboard input).
  • Fraudulent transactions from your bank account due to abuse of any information that was stolen in the above attacks.
  • DDoS (or Distributed-Denial-of-Service) attacks that crash your bank’s website to limit your access and conceal these transactions.
Read Here the Method to Remove "Gameover" from infected computers.