english-inmind.com Hacked by aK47 and D4RK CRYST4L

Website english.inmind.com is hacked by Indian Hackers :- aK47 and D4RK

On Page SEO Optimization Techniques for Blogs/Beginners/Blogger

On Page SEO optimization is a technique to bring your site on to the top pages of search engines so If you want to do SEO for blogs then you can't be ignore on page seo optimization.

What is Denial of Service (DoS) Attacks

Denial Of Service (DoS) Attacks :- A denial of service (DoS) attack is an attack that clogs up so much memory on the target system that it can not serve it’s users, or it causes the target system to crash, reboot, or otherwise deny services to legitimate users.

26 Books on Hacking by Ankit Fadia: Free Downloads

Download various books on Hacking by Ankit Fadia for free Collection

Showing posts with label News. Show all posts
Showing posts with label News. Show all posts

Monday, November 7

Israeli Government and Security Services Websites attacked by 'Anonymous Hackers'



Several Israeli government websites crashed on Sunday in what appeared to be a cyber-attack by Anonymous hackers. The websites of the IDF, Mossad and the Shin Bet security services were among the sites that went down, as well as several government portals and ministries.The Israeli army and intelligence agencies' websites were offline.
In a video that was uploaded to YouTube, Anonymous warns that if the siege on Gaza is maintained, it will have no choice but to go on the attack.. "Your actions are illegal, against democracy, human rights, international, and maritime laws," the statement addressed to the government of Israel and posted on Youtube and Anonymous-affiliated sites said. "Justifying war, murder, illegal interception, and pirate-like activities under an illegal cover of defense will not go unnoticed by us or the people of the world."





"If you continue blocking humanitarian vessels to Gaza or repeat the dreadful actions of May 31st, 2010 against any Gaza Freedom Flotillas then you will leave us no choice but to strike back. Again and again, until you stop," the statement said.

Anonymous said that if the siege continues and Israeli forces intercept additional flotillas, or if they conduct additional operations such as the commandeering of the Mavi Marmara, it will have no alternative but to launch repeated cyber-attacks on Israeli computer systems until the siege ends.

Saturday, October 1

english-inmind.com Hacked by aK47 & D4RK CRYST4L







 
Website english.inmind.com is hacked by Indian Hackers :- aK47  & D4RK CRYST4L
So here is the Deface Page !

Saturday, September 17

2nd largest Database of jobseekers in pakistan hacked by H@ck3r h!t3sh

H@ck3r h!t3sh Member of Hindustan Cyber Force hacked the website containing 2nd largest database of jobseekers in pakistan and revealed user info and passwords. You can see the exposed database of jobseekers Here . 

4 Indian Government Railway websites defaced by KhantastiC HaXor!

SSHtrix - Fastest Multithreaded SSHv1 and SSH1v2 login cracker




sshtrix is a very fast multithreaded SSH login cracker. It supports SSHv1 and SSHv2.sshtrix was designed to automate rapid bruteforce attacks against SSH authentification screens. Unlike other public tools, the aim is to keep it simple, stable, fast and modular. With its clean code design, it is easy to extend the code to a framework or to fork it against protocols of your choice. In fact, sshtrix is a fork of my own generic login cracker framework.
Download SSHtrix here

Droidsheep : Android Application for Session Hijacking




Droidsheep is free alternate of faceniff which is available on download droidsheep website for free. Its one click hijacking tool which supports
  • Amazon.de
  • facebook.com
  • flickr.com
  • twitter.com
  • linkdein.com
  • yahoo.com
  • live.com
  • google.de (only the non-encrypted services like "maps")
What do you need to run DroidSheep.?

  • You need an android-powered device, running at least version 2.1 of Android
  • You need Root-Access on your phone (link)
  • You need DroidShep (You can get it in the "GET IT" section)

Download Droidsheep

Operation OpIndependencia : Anonymous Hit Mexican Government Official websites



The websites of several Mexican government ministries, including Defense and Public Security, went offline on Thursday, and a hacker group claimed responsibility. Yesterday’s date was significant because it was the symbolic beginning of Mexico’s independence from Spain.

According to Anonymous, blocking Mexican government sites is part of the operation OpIndependencia, but its essence is not disclosed and could not explain their actions.“We are anonymous, we are legion, we don’t forgive, we don’t forget. Wait for us,” said a statement on a blog linked to a Twitter account for Anonymous Hispano.

Meanwhile, X-Ploit's three members say they are tracking senators' Web surfing habits, including visits to porn sites, in addition to initiating hacks against Mexico's Health Ministry, National Water Commission and National Statistics Institute sites."We're only looking to show that we don't agree [with the government]. In other places, these protests are not heard, but a hacked website is read by millions," said LoTek, a member of the X-Ploit group.Both groups are well acquainted with online protests. X-Ploint in February wrote, "We're watching you, Big Brother," on the Mexican Finance Ministry's home page, next to a picture of revolutionary leader Emilio Zapata.

Anonymous, a loosely knit group that has attacked financial and government websites around the world, said it orchestrated the shutdowns as part of what it termed OpIndependencia, but did not give a reason for its actions.

Hackers from the group Anonymous, as a rule, carry out the so-called DDoS-attacks, in which the company’s server simultaneously receives tens of thousands of requests from users. The site can’t withstand such a flood of virtual clients and breaks down. Recent list of group’s victims includes Sony, IMF, several U.S. banks, U.S. Senate, and even the CIA website.The hacker group has launched cyber attacks in several countries before, including the United States, the United Kingdom, Colombia and the Dominican Republic.

ClickIndia Classifieds network hacked by Sec Indi



Sec Indi Security Team have found Multiple major flaws on Clickindia.com - One of the biggest Classifieds network. There is a highly possible chance to damage ClickIndia system or to steal the Database. Hackers Exploit it via SQL Injection Vulnerability.

Linux.com down again due to Security Breach



Linux Foundation infrastructure including LinuxFoundation.org, Linux.com, and their subdomains are again down for maintenance due to a security breach that was discovered on September 8, 2011. Investigators yet can't elaborate the source of attack. Regarding coming back online , Linux.com says "Our team is working around the clock to restore these important services. We are working with authorities and exercising both extreme caution and diligence. Services will begin coming back online in the coming days and will keep you informed every step of the way." The added "We are in the process of restoring services in a secure manner as quickly as possible. As with any intrusion and as a matter of caution, you should consider the passwords and SSH keys that you have used on these sites compromised. If you have reused these passwords on other sites, please change them immediately. We are currently auditing all systems and will update this statement when we have more information."

Linux Foundation make sure that they does not store passwords in plaintext,So its hard for attacker to decrypt all hashes (its depends upon password strength).

Friday, September 16

WAVSEP 1.0.3 – Web Application Vulnerability Scanner Evaluation Project

A vulnerable web application designed to help assessing the features, quality and accuracy of web application vulnerability scanners. This evaluation platform contains a collection of unique vulnerable web pages that can be used to test the various properties of web application scanners. Additional information can be found in the developer's blog.

Project WAVSEP currently includes the following test cases:
Vulnerabilities:


  • Reflected XSS: 66 test cases, implemented in 64 jsp pages (GET & POST)
  • Error Based SQL Injection: 80 test cases, implemented in 76 jsp pages (GET & POST )
  • Blind SQL Injection: 46 test cases, implemented in 44 jsp pages (GET & POST )
  • Time Based SQL Injection: 10 test cases, implemented in 10 jsp pages (GET & POST )

False Positives:

  • 7 different categories of false positive Reflected XSS vulnerabilities (GET & POST )
  • 10 different categories of false positive SQL Injection vulnerabilities (GET & POST)

Additional Features:

  • A simple web interface for accessing the vulnerable pages
  • Sample detection & exploitation payloads for each and every test case
  • Database connection pool support, ensuring the consistency of scanning results
Although some of the test cases are vulnerable to additional exposures, the purpose of each test case is to evaluate the detection accuracy of one type of exposure, and thus, “out of scope” exposures should be ignored when evaluating the accuracy of vulnerability scanners.

Thursday, September 15

THC-HYDRA v7.0 new version released for Download




THC-HYDRA is a very fast network logon cracker which support many different services. This tool is a proof of concept code, to give researchers and security consultants the possibility to show how easy it would be to gain unauthorized access from remote to a system. It was tested to compile cleanly on Linux, Windows/Cygwin, Solaris, FreeBSD and OSX.

Official change log:

  • New main engine for hydra: better performance, flexibility and stability
  • New option -u – loop around users, not passwords
  • Option -e now also works with -x and -C
  • Added RDP module, domain can be passed as argument
  • Added other_domain option to smb module to test trusted domains
  • Small enhancement for http and http-proxy module for standard ignoring servers
  • Lots of bugfixes, especially with many tasks, multiple targets and restore file
  • Fixes for a few http-form issues
  • Fix smb module NTLM hash use
  • Fixed Firebird module deprecated API call
  • Fixed for dpl4hydra to work on old sed implementations (OS/X …)
  • Fixed makefile to install dpl4hydra (thx @sitecrea)
  • Fixed local buffer overflow in debug output function (required -d to be used)
  • Fixed xhydra running warnings and correct quit action event

Download THC-HYDRA v7.0

uTorrent & BitTorrent Sites Hacked, Spread Security Shield Malware




Attackers hijacked two popular Torrent websites "bittorrent.com and utorrent.com" and tampered with their download mechanisms, causing visitors trying to obtain file-sharing software to instead receive malware. The site reported on its blog that the attack had occurred at around 04:20 Pacific Daylight Time (11:20 GMT) on Tuesday. Initially, the incursion was also thought to have affected the servers of the main BitTorrent site, but further investigation revealed this site had been unaffected by the attack.

Once installed, Security Shield delivers false reports that a computer is infected with multiple pieces of malware and prompts the user for payment before claiming to disinfect the machine. The attack affected only users who downloaded and installed software from bittorrent.com and utorrent.com during the hour-and-fifty-minute window that the sites were compromised. Those who installed software previously are unaffected.

"We have completed preliminary testing of the malware. Upon installation, a program called ‘Security Shield" launches and pops up warnings that a virus has been detected. It then prompts a user for payment to remove the virus. " experts write on the blog.

It is very important to once more note that infected are only users who have downloaded the software between 4:20 a.m. and 6:10 a.m. Pacific time. If you have previously downloaded it - you can rest assured your software is clean.

Backtrack 5 Wireless Penetration Testing by BOOK Vivek Ramachandran




This book will provide a highly technical and in-depth treatment of Wi-Fi security. The emphasis will be to provide the readers with a deep understanding of the principles behind various attacks and not just a quick how-to guide on publicly available tools. We will start our journey with the very basics by dissecting WLAN packet headers with Wireshark, then graduate to the next level by cracking WEP, WPA/WPA2 and then move on to real life challenges like orchestrating Man-in-the-Middle attacks, creating Wi-Fi Honeypots and compromise networks running WPA-Enterprise mechanisms such as PEAP and EAP-TTLS.

Even though touted as a Beginner's Guide, this book has something for everyone - from the kiddies to the Ninjas. You can purchase the book from:
Global:  http://www.amazon.com/BackTrack-Wireless-Penetration-Testing-Beginners/dp/1849515581/
India: http://www.packtpub.com/backtrack-5-wireless-penetration-testing-beginners-guide/book

Sample Chapter can be downloaded here: 
http://www.packtpub.com/sites/default/files/5580OS-Chapter-6-Attacking-the-Client_0.pdf

Author Bio:
Vivek Ramachandran, the author of the book has been into Wireless security research since 2003. He has spoken at conferences such as Blackhat, Defcon and Toorcon on Wireless Security and is the discoverer of the Caffe Latte attack. He also broke WEP Cloaking, a WEP protection schema in 2007 publically at Defcon. He was one of the programmers of the 802.1x protocol and Port Security in Cisco's 6500 Catalyst series of switches. He was one of the winners of Microsoft Security Shootout contest held in India among a reported 65,000 participants. He is best known in the hacker community as the founder of SecurityTube.net where he routinely posts videos on Wi-Fi Security, Assembly Language, Exploitation Techniques etc. Vivek's work on wireless security has been quoted in BBC online, InfoWorld, MacWorld, The Register, IT World Canada etc. places. This year he is either speaking or training at Blackhat, Defcon, Hacktivity, HITB-ML, Brucon, Derbycon, HashDays, SecurityByte etc.
For those who cannot afford to purchase the book, Vivek's Wireless Megaprimer Video series (12+ hours of HD videos on Wi-Fi Hacking) is the next best thing to it.
You can download the DVD here: http://www.securitytube.net/downloads

McAfee DeepSAFE - Anti-rootkit Security Solution



McAfee previewed its DeepSAFE hardware-assisted security technology for proactively detecting and preventing stealthy advanced persistent threats (APTs) and malware. The technology, which was co-developed with Intel, sits below the OS, providing the ability to fundamentally change the security game, according to the companies.

According to McAfee Labs, more than 1,200 new rootkits per day are detected - equating to 50 per hour every single day. The DeepSAFE technology, which was demonstrated at the Intel Developer Forum in San Francisco, was able to detect and stop a zero-day Agony rootkit from infecting a system in real time. This technology is expected to launch in products later in 2011.

Key attributes of McAfee DeepSAFE:
  • Builds the foundation for next-generation hardware-assisted security operating beyond the operating system
  • Provides a trusted view of system events below the operating system
  • Exposes many attacks that are undetectable today
  • New vantage point to block sophisticated stealth techniques and APTs
  • Provides real time CPU event monitoring with minimal performance impact
  • Combines the power of hardware and flexibility of software to deliver a new foundation for security.
"Intel and McAfee are working on joint technologies to better protect every segment across the compute continuum from PCs to devices," said Renée James, senior vice president and general manager of the Software and Services Group at Intel and the Chairman of McAfee. "By combining the features of existing Intel hardware and innovations in security software, Intel and McAfee are driving innovation in the security industry by providing a new way to protect computing devices. We are truly excited to introduce this technology upon which we will deliver new solutions."

Presidential website president of Bolivia hacked



The presidential website of Bolivia presidencia.gob.bo has been hacked. The hack has been carried out by twitter id: @SwichSmoke. The website data has been breached and has been data leaked.Hacker upload the dumps on Pastebin.

Wednesday, September 14

BarackObama Website Service - Persistent Web Vulnerability

A persistent high priority Input Validation vulnerability is detected on BaraObamas official website service. Attacker can form malicious requests which pass through the backend (not parsed!) & can be displayed as outgoing info@barakobama.com mail. Attackers can steal backend sessions of the portal users/admins & can send malicious mails by the original postbox.
Vulnerability-Lab Team discovered persistent Web Vulnerability on BaraObamas official website service.
Disclaimer:
=======
The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss of business profits or special damages, even if Vulnerability-Lab or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. Any modified copy or reproduction, including partially usages, of this file requires authorization from Vulnerability- Lab. Permission to electronically redistribute this alert in its unmodified form is granted. All other rights, including the use of other media, are reserved by Vulnerability-Lab or its suppliers.
Status :fixed 

XSS Vulnerability On KASKUS.US | Indonesian Largest Community

Indonesian Largest Community website kaskus.us Xss Vulnerability found by Cyber4rt . 416,238,482 posts and 3,422,101 Members in this website . You can see the vulnerable link Here .  
Status: Unfixed

Top100 Arena Gaming Sites Network hacked By ACA [Albanian Cyber Army]



Albania hackers have exploited one of the biggest Game Arena site  "Top100" database using SQL injection attack. They leak the database on mediafire. Hackers belongs from group ACA [Albanian Cyber Army].

The Security Onion LiveDVD - Download



The Security Onion LiveDVD is a bootable DVD that contains software used for installing, configuring, and testing Intrusion Detection Systems. It is based on Xubuntu 10.04 and contains Snort, Suricata, Sguil, Squert, Xplico, nmap, metasploit, Armitage, scapy, hping, netcat, tcpreplay, and many other security tools.Official change log for Security Onion 20110919:

  • The “IDS Rules” menu now has a new entry called “Add Local Rules” which will open /etc/nsm/rules/local.rules for editing using the “mousepad” GUI editor. You can then add any rules that you want to maintain locally (outside of the downloaded VRT or Emerging Threats rulesets).
  • A new menu called “IDS Config” was added with a new menu entry called “Configure IDS engine(s)”. This will list all of the IDS engines on your system and allow you to choose one to configure. It will then open the proper config file for whatever IDS engine you’re running. After you save and close the config file, it will offer to restart the IDS engine for you.

#Opiran new press release for 23 September by Anonymous Hackers






[Salutation]
To the Noble and Brave People of Iran and Syria,
[Acknowledge plight]
The people of Iran and Syria are still being caged, tortured and murdered. They are ruled by vile leaders, who seek not to protect, but to harm. Leaders who will stop at nothing to keep their power.
[Statement of Facts and Outcomes]
Iran deserves modern affortable energy and fair elections. The entire world speaks of the treachery of Iran's fraudulous regime. Newly secret US ambassadorial letters, released by WikiLeaks, confirm what you already know. [irc.iranserv.com #opiran port 6697 ssl]
[Outline Client Condition]
The people of Syria are beaten by regime police from Iran. The People of Syria are kept down by the regime of Iran, which backs the will of Assad to remain in power. No matter how many innocent victims fighting for freedom and social justice, this may cost.
[Support]
Ahmadinejad, Khamenei and Assad know their time has come. The world waits, the people act. Know that Anonymous actively supports the Syrian and Iranian people in their battle for a democratic and secular governmental rule, respecting their culture, peoples and future.

We are Anonymous
We are legion
We do not forgive
We do not forget
Expect us

Related Posts Plugin for WordPress, Blogger...