إظهار الرسائل ذات التسميات hacking news. إظهار كافة الرسائل
إظهار الرسائل ذات التسميات hacking news. إظهار كافة الرسائل
الثلاثاء، 21 أكتوبر 2014
Chinese Government Executes MITM Attack against iCloud
Apple iCloud users in China are not safe from the hackers — believed to be working for Chinese government — who are trying to wiretap Apple customers in the country.
Great Fire, a reputed non-profit organization that monitors Internet censorship in China, claimed that the Chinese authorities have launched a nationwide Man in the Middle (MITM) campaign against users of Apple’s iCloud
الجمعة، 17 أكتوبر 2014
Reflection DDoS Attacks Using Millions of UPnP Devices on the Rise
After successful in launching reflection and amplification Distributed Denial-of-Service (DDoS) attacks by abusing various protocols such as DNS, NTP and SMTP, hackers are now abusing Simple Service Discovery Protocol (SSDP) – part of the UPnP protocol standard – to target home and office devices, researchers warned.
SSDP is a network protocol based on the Internet Protocol Suite that
Hacking Smart Electricity Meters To Cut Power Bills
Smart devices are growing at an exponential pace with the increase in connecting devices embedded in cars, retail systems, refrigerators, televisions and countless other things people use in their everyday life, but security and privacy are the key issues for such applications, which still face some enormous number of challenges.
Millions of Network-connected electricity meters or Smart
الأربعاء، 15 أكتوبر 2014
POODLE SSL 3.0 Attack Exploits Widely-used Web Encryption Standard
Another Heartbleed-like vulnerability has been discovered in the decade old but still widely used Secure Sockets Layer (SSL) 3.0 cryptographic protocol that could allow an attacker to decrypt contents of encrypted connections to websites.
Google's Security Team revealed on Tuesday that the most widely used web encryption standard SSL 3.0 has a major security vulnerability that could be exploited
Google's Security Team revealed on Tuesday that the most widely used web encryption standard SSL 3.0 has a major security vulnerability that could be exploited
التسميات:
digital Certificate,
encryption,
hacking news,
Heartbleed bug,
man-in-the-middle attack,
POODLE,
Shellshock,
ssl security,
SSL vulnerability,
Vulnerability,
web browser,
website security
الثلاثاء، 14 أكتوبر 2014
Microsoft Windows Zero-Day Vulnerability "CVE-2014-4114" Used to Hack NATO
Once again a Russian cyber espionage group has gained media attention by exploiting a Zero-day vulnerability in Microsoft’s Windows operating system to spy on the North Atlantic Treaty Organization (NATO), Ukrainian and Polish government agencies, and a variety of sensitive European industries over the last year.
ZERO-DAY VULNERABILITY IN MICROSOFT WINDOWS
Researchers at cyber
التسميات:
CVE-2014-4114,
cyber espionage,
hacking news,
Russian hackers,
Sandworm Team,
Spear Phishing,
Vulnerability,
Windows zero-day vulnerability
الأربعاء، 8 أكتوبر 2014
"Pakistan People's Party" Website Hacked — Message for Bilawal Bhutto
On Tuesday, Indian and Pakistani army forces continued to exchange fire along the Line of Control (LoC) in Jammu and Kashmir, which was started when Pakistan’s military fired machine guns and mortars at about 60 Indian army posts during last week.
Tensions between the two countries have intensified since Bilawal Bhutto Zardari, the only son of former Pakistani President Asif Ali Zardari
التسميات:
Defacement,
hacking news,
hacking website,
Indian Army,
Indian Hackers,
Pakistan Army,
Pakistan People Party (PPP),
website Defaced
Tyupkin Malware Hacking ATM Machines Worldwide
Money is always a perfect motivation for cyber criminals who tries different tricks to solely target users with card skimmers that steal debit card numbers, but now the criminals are using specialized malware that targets ATM (Automated Teller Machine) systems to withdraw cash even without the need of a card.
The new backdoor program, dubbed as “Tyupkin,” requires physical access to the
الثلاثاء، 7 أكتوبر 2014
Zero-Day in Bugzilla Exposes Zero-Day Vulnerabilities to Hackers
A critical zero-day vulnerability discovered in Mozilla’s popular Bugzilla bug-tracking software used by hundreds of prominent software organizations, both private and open-source, could expose sensitive information and vulnerabilities of the software projects to the hackers.
The critical flaw allows an attacker to bypass email verification part when registering a new Bugzilla account,
الأحد، 28 سبتمبر 2014
Privacy-focused Tails 1.1.2 Operating System Released
Tails, a Linux-based highly secure Operating System specially designed and optimized to preserve users' anonymity and privacy, has launched its new release, Tails version 1.1.2.
Tails, also known as 'Amnesiac Incognito Live System', is a free security-focused Debian-based Linux distribution, which has a suite of applications that can be installed on a USB stick, an SD card or a DVD. It keeps
Tails, also known as 'Amnesiac Incognito Live System', is a free security-focused Debian-based Linux distribution, which has a suite of applications that can be installed on a USB stick, an SD card or a DVD. It keeps
التسميات:
Anonymous,
Firefox,
hacking news,
hacking tool,
Live Operating System,
man-in-the-middle attack,
Network Security Services,
Privacy,
Tails,
tails Operating System,
Tails Os,
Vulnerability
السبت، 27 سبتمبر 2014
Apple — Most Mac OS X Users Not Vulnerable to 'Shellshock' Bash Bug
On one hand where more than half of the Internet is considering the Bash vulnerability to be severe, Apple says the vast majority of Mac computer users are not at risk from the recently discovered vulnerability in the Bash command-line interpreter – aka the "Shellshock" bug that could allow hackers to take over an operating system completely.
Apple has issued a public statement in response
Hackers Using 'Shellshock' Bash Vulnerability to Launch Botnet Attacks
Researchers on Thursday discovered a critical remotely exploitable vulnerability in the widely used command-line shell GNU Bourne Again Shell (Bash), dubbed "Shellshock" which affects most of the Linux distributions and servers worldwide, and may already have been exploited in the wild to take over Web servers as part of a botnet that is currently trying to infect other servers as well.
الأربعاء، 24 سبتمبر 2014
TripAdvisor's Viator Hit by Massive Data Breach Affecting 1.4 Customers
TripAdvisor's Online travel booking and review website Viator has reportedly been hit by a massive data breach at its that may have exposed payment card details and account credentials of its customers, affecting an estimated 1.4 million of its customers.
The San Francisco-based Viator, acquired by TripAdvisor – the world's largest travel site – for £122 million (US$ 200 million) back in
التسميات:
book hotel,
credit card hacking,
data breach,
encrypted password,
hacking news,
hotel reservations,
travel booking,
travel inn,
TripAdvisor,
viator tour guide
الثلاثاء، 23 سبتمبر 2014
The Pirate Bay Runs on 21 "Raid-Proof" Virtual Machines To Avoids Detection
The Pirate Bay is the world's largest torrent tracker site which handles requests from millions of users everyday and is in the top 100 most visited websites on the Internet. Generally, The Pirate Bay is famous for potentially hosting illegal contents on its website.
Despite years of persecution, it continues to disobey copyright laws worldwide. Even both the founders of The Pirate Bay (
Limitless Keylogger Optimized with AutoIT Infected thousands of Computers
A new surge of malware has been discovered which goes on to infect hundreds of thousands of computers worldwide and allegedly steals users’ social and banking site credentials.
Few days back, a list of 5 million combinations of Gmail addresses and passwords were leaked online. The search engine giant, Google said that Gmail credentials didn’t come from the security breaches of its system,
الاثنين، 22 سبتمبر 2014
Hacking any eBay Account in Just 1 Minute
Four month ago, a massive data breach on the eBay website affected 145 million registered users worldwide after its database was compromised. Meanwhile, another critical vulnerability on the eBay website was reported, allowing an attacker to hijack millions of user accounts in bulk.
An Egyptian security researcher ‘Yasser H. Ali’ informed The Hacker News about this vulnerability 4 months ago,
An Egyptian security researcher ‘Yasser H. Ali’ informed The Hacker News about this vulnerability 4 months ago,
السبت، 20 سبتمبر 2014
Avira Vulnerability Puts Users' Online Backup Data At Risk
A popular Anti-virus software Avira that provides free security software to its customers with Secure Backup service is vulnerable to a critical web application vulnerability that could allow an attacker to take over users’ account, putting millions of its users’ account at risk.
Avira is very popular for their free security software that comes with its own real-time protection module
التسميات:
Avira Antivirus,
cloud backup,
cloud storage,
Cross site scripting,
Cross-site request forgery,
CSRF,
hacking news,
Vulnerability,
Web Application Security
الجمعة، 19 سبتمبر 2014
How to Detect SQL Injection Attacks
SQL Injection (SQLi) attacks have been around for over a decade. You might wonder why they are still so prevalent. The main reason is that they still work on quite a few web application targets. In fact, according to Veracode’s 2014 State of Security Software Report , SQL injection vulnerabilities still plague 32% of all web applications. One of the big reasons is the attractiveness of the
التسميات:
AlienVault,
AlienVault Unified Security Management,
AlienVault USM,
hacking news,
sql injection,
SQLi vulnerable sites,
Web Application Security
الأربعاء، 17 سبتمبر 2014
Malicious Kindle Ebook Let Hackers Take Over Your Amazon Account
If you came across a Kindle e-book download link from any suspicious sources or somewhere other than Amazon itself, check twice before you proceed download. As downloading an eBook could put your personal information at risk.
A security researcher has uncovered a security hole in Amazon's Kindle Library that could lead to cross-site scripting (XSS) attacks and account compromises when you
الثلاثاء، 16 سبتمبر 2014
Twitter Vulnerability Allows Hacker to Delete Credit Cards from Any Twitter Account
At the beginning of this month, just like other social networks, Twitter also started paying individuals for any flaws they uncover on its service with a fee of $140 or more offered per flaw under its new Bug Bounty program, and here comes the claimant.
An Egyptian Security Researcher, Ahmed Mohamed Hassan Aboul-Ela, who have been rewarded by many reputed and popular technology giants
Google Public DNS Server Spoofed for SNMP based DDoS Attack
The Distributed Denial of Service (DDoS) attack is becoming more sophisticated and complex, and, according to security experts, the next DDoS vector to be concerned about is SNMP (Simple Network Management Protocol) amplification attacks.
Yesterday afternoon, the SANS Internet Storm Center reported SNMP scans spoofed from Google’s public recursive DNS server searching for vulnerable
الاشتراك في:
الرسائل (Atom)
