Showing posts with label Hacking News. Show all posts
Showing posts with label Hacking News. Show all posts

Hackers come up with new modus operandi for internet banking frauds

Written By ization shop on Tuesday, January 7, 2014 | Tuesday, January 07, 2014


Hacking News New Delhi

Delhi police have stumbled upon a new modus operandi of e-banking fraudsters in which they first hack the internet banking account of the target and then get mobile number blocked to prevent the bank customer from receiving SMS alerts about illegal transactions made by them.

In a recent case, two Nigerians were arrested by the staff of South Delhi police for allegedly swindling Rs 70 lakh from the bank account of an NRI based in Japan.

Police seized three laptops from them containing banking data of around 1.5 crore people.

During interrogation, the duo told police about the new modus operandi in which hackers first hack data of bank customers from its website which contains the internet banking Id, passwords, other basic details and the mobile number on which SMS alerts are sent in case of a transaction from the account.

“Armed with this information, fraudsters reach retail outlet of the mobile service provider and get the number blocked on the pretext that the SIM along with the mobile handset has been stolen or was lost.

“As they already know the name and address of the owner of the mobile number through hacking, they even get a duplicate SIM issued of the same number,” said a senior police official.

As per police, there have been a number of such cases in the recent past in which transactions worth lakhs were made after getting the number blocked.

On August 13, Basanta Kumar, Country Head of Bangladesh of Global Alliance for Improved Nutrition (GAIN) had filed an FIR with the Economic Offences Wing of the Delhi police saying that some fraudsters swindled Rs 19,31,000 from his bank account through internet banking after getting his phone number blocked.

Criminals have gone a step further after banks started sending SMS alerts to their customers about every transaction and the need of the hour is to devise new methods to counter it, the official said.

“Firstly, people should regularly change their internet banking passwords. We have observed that most of such dubious transactions are made at night and more than one at a time.

Banks should change their policy and take note of transactions which take place at odd hours and are dubious in nature,” he said.

“Banks should ask for alternate mobile number on which a customer can be informed if they detect some suspicious activity from an account such as multiple transactions involving big money or in which money is transferred to foreign accounts,” he said.
Tuesday, January 07, 2014 | 3 komentar | Read More

Could online hackers steal your cash?


When you access your bank account online you probably don't think that at that exact moment there may be a hacker, somewhere in the world, trying to steal your bank information and your money.

Your bank offers secure online banking, so why should you worry, right?

Despite banks' efforts to protect accounts from the online crooks, hacker attacks remain a serious threat that cost Americans millions of dollars each year. The Internet Crime Complaint Center reported that Americans lost about $559 million to Internet thieves in 2009. That is more than twice the 2008 figure, when $268 million was stolen on the Internet, according to the center.

"Last year there were more online bank robberies than there were actual on-site bank robberies," says Sean Sullivan, a security adviser at F-Secure, an Internet security firm. "Banks have become very proactive in protecting accounts from hackers, but it's still quite a large problem. We see all types of new attempts every day."

Biggest threat
Banking Trojans -- malicious code specifically designed for banking fraud -- are one of the biggest threats to consumers who bank online, Sullivan says. They are invisible and can steal multiple types of data, including passwords. Some more advanced types of Trojans can make fraudulent transfers and drain your account while you are logged on to the account online, he says.
Is your bank safe?
The more questions and passwords you are asked to enter in order to log in to your account, the safer is your bank's website.
If your bank only asks you to enter a username and password to log in its website is not as secure as it should be, Sullivan says.

Some banks require customers to create a username, a site key name and use personalized pictures or symbols that appear during the login process. In addition, banks should ask customers to answer a security question before gaining access to their account.

"The more layers you have before you get to your account, the safer you are," Sullivan says.

Who's liable?
In the event you become a victim of online theft, act quickly and know your rights. The general rule for consumer checking and savings accounts is the bank is liable for most of the damage, as long as you report the illicit transfer in a timely manner. But if you have a line of credit account or a business account, you need to be extra careful, because the bank will not always be obligated to pay for your loss.

Consumer accounts
Consumer checking and savings accounts are protected by the Electronic Funds Transfer Act, which limits consumer losses for online theft to $50, as long as the consumer reports the loss within 60 days after the fraudulent transfer appears on the statement.
The act does not apply to line of credit accounts, says David Johnson, an Internet law attorney at Epstein Becker and Green in San Francisco. Line of credit accounts are covered by "negligence law," Johnson says.

Tuesday, January 07, 2014 | 3 komentar | Read More

Bank of America Hacked By Anonymous: Hackers Leak ‘Secrets’ About Executives, Salaries, And Spy Activities

Written By ization shop on Saturday, October 19, 2013 | Saturday, October 19, 2013

Anonymous has done it again. The loosely associated hacking collective, which has hacked everything from GoDaddy to religious organizations to government websites, the Pentagon and more, has released 16 gigabytes of data, code and software related to Bank of America, Bloomberg, Thomson Reuters and others, claiming that Bank of America had employed security firms to “spy and collect information on private citizens.”

One Anonymous subgroup, identifying itself as Par:AnoIA (aka Anonymous Intelligence Agency), issued a press release on Wednesday to discuss some of the details of the release.

“The source of this release has confirmed that the data was not acquired by a hack but because it was stored on a misconfigured server and basically open for grabs,” Par:AnoIA said. “Looking at the data it becomes clear that Bank of America, TEKSystems and others (see origins of reports) gathered information on Anonymous and other activists' movement on various social media platforms and public Internet Relay Chat (IRC) channels.”

The Anonymous collective said the data was actually retrieved from an open, insecure server in Tel Aviv, Israel, but also managed to obtain a full version of ClearForest’s text analyzing software called “OneCalais,” which was stored and openly accessible on the same server.

Among the leaked documents, Anonymous discovered that TEKSystems had compiled reports last year about hackers and so-called “cyber threats,” as well as online activity surrounding the Occupy Wall Street movement. Anonymous dismissed all of this research as “sloppy, random and valueless.”

“Apparently a keyword list was used to match for items of interest on IRC, Twitter and other social media,” Par:AnoIA said. “While the list has over 10.000 [sic] entries only 1,125 keywords seem to be genuine, the rest are simply Wikipedia references.”

In addition to the overwhelming amount of “research” about Bank of America’s antagonists, the Anonymous group also discovered an extra 4.8 gigabytes of “detailed career and salary information of hundreds of thousands of executives and employees from various corporations all around the world.” Anonymous noted that the folder was named “Bloomberg,” while the entries were tagged with “reuterscompanycontent,” which could mean Bloomberg LP and/or Thomson Reuters could have been involved or targeted as well.

“What it was doing on the Israeli server is up to anyone’s guess,” Anonymous added.

But above all, Anonymous hopes to use this data dump to spotlight these misguided efforts to hamper online activism, but also show how corporations like Bank of America are paying for these operations to take place.

“We release the received files in full to raise awareness to this issue and to send a signal to corporations and Governments that this is unacceptable,” the Anonymous press release concluded.

Anonymous recently hacked the Federal Reserve on Feb. 6, and threatened to publish private personal information about a number of Goldman Sachs employees on Valentine’s Day, but did not.
Saturday, October 19, 2013 | 2 komentar | Read More

Pakistan army website hacked by Human mind cracker

Written By ization shop on Sunday, January 13, 2013 | Sunday, January 13, 2013

The Tunisian hacker 'Human Mind Cracker' who discover critical vulnerability in high profile website.Again,this time he hacked into Pakistan Army website  and he get into their Database. He discovered SQL Injection vulnerability in their website 'www.pakistanarmy.gov.pk' .

In an email sent to EHN,the hacker provided us the vunerable link as a proof for his hacking.And he also provided a link to the dump (www.heypasteit.com/clip/0N5T).

" The reason of the hack is just to break the security of that website...I was thinking that Pakistan has a good cyber army but lool also they have a lot of vulnerable websites" hacker said in the email.

The dump contains database details, password, email address, admin id and password.

The hacker always try to hack into governments and banks website to improve his skills and want to know if government mind about security in their website.And the hacker said that more governments websites will be hacked by him soon.
Sunday, January 13, 2013 | 2 komentar | Read More

Hacking Satellite Communications

Written By ization shop on Friday, January 11, 2013 | Friday, January 11, 2013

One more to worry about is the real security of satellite infrastructures.
In a technological civilization, satellites play a vital role in the management and transmission of information of all kinds. Satellites in fact do the work in silent that we enjoy every day, but we often forget this crucial aspect of communications.

Are these powerful systems of communication actually safe? Is it sufficient just to be in orbit thousands of miles above our heads  in order to ward off the danger of an attack? In using satellites, are we sure that nobody could listen in on our communications?
Of course not! The main concern is the possibility of compromising satellite those communications in the context of warfare.

Consider that satellite communication are widely used in military applications, particularly in those regions where other communication infrastructures are insufficient or absent, like the Middle East and Africa.

Security researchers have demonstrated that satellite phones can be easily intercepted and deciphered.
It is already of enough concern any common computer can be used to hack the two encryption systems used to protect satellite phone signals, so anyone with a computer and a radio could conceivable eavesdrop on calls, and a multitude of satellite phones are vulnerable.

With a few thousand dollars it is possible, according a researchers' announcement, to buy the equipment and software needed to intercept and decrypt satellite phone calls from hundreds of thousands of users.

The academics have summarized the threat in a single sentence: "Do not Trust Satellite Phones".
The two main standard encryption algorithms that have been compromised are known as GMR-1 and GMR-2, which are implemented by the satellite phone operators. The problem really affects only those companies that use the ETSI GMR-1 and GMR-2 encryption algorithms.

The speed with which it is possible to decipher a call is linked to the computing power applied, but keep in mind that it is possible with suitable equipment decipher the communications in real time.

The researchers are convinced that the main problem is related to the encryption algorithms and the "security through obscurity" approach applied by attempting to use secrecy of design and implementation to provide security, and preventing the security community from testing them.

In publishing the hacking procedure proof-of-concept, the researchers hoped to prompt the ETSI organization to set new standards based on stronger encryption algorithms.
It was revealed in the past that GSM communications, an approach used to hide the algorithms for encrypting communications is certainly wrong, and represents a risk to the integrity of the overall infrastructure.

Due to this incorrect approach in the management of the algorithms, many organizations have implemented extra layers of cipher software in their satellite phones with the unintended result of increasing its vulnerability.
A consequence of the announcement is that satellite handsets with built in encryption mechanisms based on the hacked algorithms are no longer secure, which could pose a considerable threat to the business and military sectors. Hostile governments and criminals are actually able to monitor satellite phone networks on a large scale.

If the situation regarding satellite encryption algorithms is worrying, certainly the security of the satellites themselves is not any better.

A report released in 2011 named titled the "2011 Report to Congress of the U.S.-China Economic and Security Review Commission" revealed that some US operated satellites were vulnerable to attacks, and on more than one occasion attackers had taken control of the systems.

Sensitive satellite systems have been successfully breached, according to the report:
"Satellites from several U.S. government space programs utilize commercially operated satellite ground stations outside the United States, some of which rely on the public Internet for 'data access and file transfers,' according to a 2008 National Aeronautics and Space Administration quarterly report.† The use of the Internet to perform certain communications functions presents potential opportunities for malicious actors to gain access to restricted networks." 

Information regarding several attacks to satellite control systems are in the public domain, and these events have been confirmed also by The National Aeronautics and Space Administration (NASA).
Below is a brief list of events:
  • On October 20, 2007, Landsat-7, a U.S. earth observation satellite jointly managed by the National Aeronautics and Space Administration and the U.S. Geological Survey, experienced 12 or more minutes of interference.
  • On June 20, 2008, Terra EOS [earth observation system] AM–1, a National Aeronautics and Space Administration- managed program for earth observation, experienced two or more minutes of interference.The responsible party achieved all steps required to command the satellite but did not issue commands.
  • On July 23, 2008, Landsat-7 experienced 12 or more minutes of interference. The responsible party did not achieve all steps required to command the satellite.
  • On October 22, 2008, Terra EOS AM–1 experienced nine or more minutes of interference. The responsible party achieved all steps required to command the satellite but did not issue commands.
In the report, the responsibility for the attacks was assigned to China, but similar hacks can be conducted by every hostile foreign government. We must consider that compromised satellites are a serious risk, the exposure could affect communications in the business and military sectors, and also can cause the loss of sensitive and strategic technological information.

My last consideration is related to threats to satellite systems. In our imagination we make the mistake of considering only as possible sources of attacks as being foreign governments.
The proof that this view is wrong arrived in recent weeks when the group Anonymous announced that it had successfully hacked a NASA satellite The group has also published on Pastebin evidence of knowledge on NASA project.

Clearly the situation merits a high level of attention given the looming threat.
Friday, January 11, 2013 | 2 komentar | Read More

Hacker satellite grid to counter Internet censorship



The Hackerspace Global Grid is hoping to build its own satellite network in an effort to counter various Internet censorship initiatives such as the controversial Stop Online Piracy Act (SOPA) act.
In addition to launching communications satellites into space, the group plans to develop a grid of ground stations to track and communicate with the satellites.


Hacker satellite grid to counter Internet censorship

"The first goal is an uncensorable internet in space. Let's take the internet out of the control of terrestrial entities. [We] can put humanity back in space in a meaningful way," hacktivist Nick Farr told the BBC on the sidelines of the Chaos Communication Congress in Berlin.

"The goal is to get back to where we were in the 1970s. Hackers find it offensive that we've had the technology since before many of us were born and we haven't gone back. We believe communication is a human right."

Hackerspace Global Grid participant Armin Bauer expressed similar sentiments, but acknowledged that hobbyists have thus far only managed to put a few small satellites in orbit due to budgetary constraints.
"Professionals can track satellites from ground stations, but usually they don't have to because, if you pay a large sum [to send the satellite up on a rocket], they put it in an exact place."



However, Bauer plans to create a network of low-cost ground stations that can be purchased (at 100 euros each) or built by individuals that could be in place during the first half of 2012. Operating together in a global network, the stations would be capable of pinpoint satellites, helping them to send data back to Earth.
"It's kind of a reverse GPS. GPS uses satellites to calculate where we are, and this tells us where the satellites are. We would use GPS co-ordinates but also improve on them by using fixed sites in precisely-known locations," he added.

Aside from budgetary constraints and technical difficulties, the Hackerspace Global Grid also faces potential legal threats from various countries opposed to the anti-censorship plan.

"There is an interesting legal dimension in that outer space is not governed by the countries over which it floats," explained Prof Alan Woodward from the computing department at the University of Surrey.
"So, theoretically it could be a place for illegal communication to thrive. However, the corollary is that any country could take the law into their own hands and disable the satellites.

Friday, January 11, 2013 | 2 komentar | Read More

Hackers plan to circumvent SOPA by launching their own satellite



The term “hacker” carries with it several connotations, with meanings that are both positive and negative. Among the positive descriptors, the word “resourceful” comes to mind. So, when faced with the possible reality of SOPA being written into law, a group in Germany has decided to take action instead of throwing up their hands and giving up. If the United States is going to lock down the current version of the internet, they plan to make their own by launching a satellite into orbit.

An ambitious undertaking, but one that is actually feasible with the lowering of costs associated with putting a payload into space. Introduced at the Chaos Communication Congress in Berlin, the plan calls for the launching of a single satellite into low orbit that would communicate with a series of ground stations to create an independent network.

 Called the Hackerspace Global Grid (HGG), the network would operate like a GPS system, only in reverse. In theory, the plan would give users continuous access to the network by using the ground stations as a global relaying system. When one base station is in range of of the satellite, it would take the signals received and re-broadcast them to the rest of the network it was a part of. In theory this plan can work experts have said, but there are hurdles — chief among them being financial.

While not nearly as expensive as in decades past, space travel and payload delivery is still costly. The price tag on building a satellite with equipment that can handle the rigors of space can still run in the millions of dollars, making it an expensive enterprise indeed. Couple that with the fact that no single country can govern space itself, there are no laws to protect the HGG orbital device. Any country could come along and try to disable it with no ramifications.

As far as logistical hurdles, unless the HGG satellite is in geosynchronous orbit, it’s going to be very difficult to track. Instead of having a known point in space where the device travels at the same speed as the Earth so appears to not move, a low orbit satellite would be moving very quickly. Even if the team behind the HGG could put it out far enough for geosync to be accomplished, the distance might be too great to get a good signal on the ground.

Nevertheless, the group is moving ahead with plans to develop the ground stations and communications protocol they are going to use. They plan to have two ground stations deployed by the next Chaos Communication Conference, as well as having a stock available for purchase by private individuals. If you’re as fascinated with the project as we are, you can get involved by checking out Constellation, a project that the HGG has joined for collaboration.
Friday, January 11, 2013 | 2 komentar | Read More

New bank hacking program hits three continents

Written By ization shop on Thursday, January 10, 2013 | Thursday, January 10, 2013

A new wave of automated hacking of online bank accounts might have stolen $78 million in the past year from customers in Europe, Latin America and the United States.

This is according to researchers who peered into the computers of the hacking gangs.
The groups used recent improvements to two families of existing malicious software, known as Zeus and SpyEye, which lodged on the computers of clients at 60 banks.

While previous versions of the software have proved adept at stealing logon information, the latest variants automate the subsequent transfer of funds to accounts controlled by accomplices.

The findings, to be released on Tuesday by security firms McAfee and Guardian Analytics, confirmed and expanded on research from Japan-based Trend Micro Inc that was first reported last week by Reuters.
“This looks like the beginning of a new technique,” said Guardian’s Vice President Craig Priess, whose firm specializes in protecting banks.

The software is sophisticated enough to defeat “chip and PIN” and other two-factor authentication and to avoid transferring the entire contents of an account at one time, which can trigger review, according to the study.

Trend Micro said it had seen the automated versions in action in Germany, the United Kingdom and Italy.
Guardian and Intel Corp-owned McAfee said the same technology, while still emerging, had been used by a dozen gangs against consumers and business clients of financial institutions in those countries and Colombia, the Netherlands, and the United States.

“Someone designing this system has insider knowledge as to what the banks are looking for,” said Dave Marcus, research director at Mcafee Labs.

Server logs viewed by the researchers saw commands from the fraud rings to transfer a total of $78 million, including $130000 from one account. The banks may have been able to block some of those transactions, the researchers acknowledged.

Money mules
Though written and controlled by different groups, SpyEye and Zeus share the ability to be installed on computers that visit malicious websites or legitimate pages that have been compromised by hackers, as well as through tainted links in emails.

The programs already have used a technique called “web injection” to generate new entry fields when victims log on to any number of banks or other sensitive websites. Instead of seeing a bank ask for an account number and password, for example, a victimized user sees requests for both of those and an ATM card number. All that information is sent to the hacker, who signs in and transfers money to an accomplice’s account.

Those transfers can be time-consuming, and the hacker has to consider how much can be sent at once without drawing attention.
Multiple, smaller transfers are preferable but take more time.

For the past year or more, some variants have also captured one-time passwords, such as those sent from the banks by text messages to client cell phones as an added security measure. But a hacker had to be online within 30 or 60 seconds in order to use the one-time password.

The new software allows the criminal to siphon money out at all hours, potentially increasing the number of hacked accounts and the speed with which they are drained.

Brett Stone-Gross, a senior security researcher with Dell Inc unit Dell SecureWorks, said previously that the main limiting factor for crime groups is the number of accomplices, known as money mules, that they can hire to accept transfers from victim accounts. Automation will not lessen the need for mules, Stone-Gross said.

Trend Micro spoke online with sellers of the automated transfer modules who were based in Russia, Ukraine and Romania, where arrests and prosecutions are rare. It said the new software costs between $300 and $4000.

Banks generally compensate individuals in full for such losses if they are detected quickly. But recent versions of SpyEye and Zeus can present fake account balances to individual bank customers, so they might not realize their savings are being drained until too late.
Thursday, January 10, 2013 | 2 komentar | Read More

Mideast hackers disrupt websites of U.S. banks over anti-Islam film, says more shutdowns to come

Written By ization shop on Friday, December 28, 2012 | Friday, December 28, 2012

A hacker group based in the Middle East has flaunted its online muscle against several of America’s largest financial firms, temporarily keeping customers from accessing their information on banking websites and promising similar shut downs again next week.

But while cyberattacks are routinely done to glean private account information, this threat appears different — it’s political.

The group — identifying itself as the Izz ad-Din al-Qassam Cyber Fighters — claimed responsibility in a post on Pastebin, a site used by hackers, according to The New York Times.

The group said the attacks are linked to the anti-Islam film that sparked deadly protests this month across the Muslim world.
“Insult to a prophet is not acceptable especially when it is the Last prophet Muhammad,” the post said. “So as we promised before, the attack will be continued until the removal of that sacrilegious movie from the Internet.”

Websites of JPMorgan Chase, Citigroup and Bank of America were affected last week, while Wells Fargo’s website was hit Tuesday, U.S. Bank was affected Wednesday and PNC Financial Services was disrupted Thursday.

A PNC spokesman told The Times it was taking “appropriate measures.”
But ABC News said it was shut out of the PNC site for about three hours Thursday, leaving some customers to gripe on social media.
“Hopefully it can be up soon,” posted Facebook user Stacy Briggs-Gerlach. “Never realized how dependent I am on it!!! ”

The hackers in their post even wrote a timetable for their attacks and implored other “cyberspace workers to join us.”
Security experts told the Daily News that the group’s boasting beforehand indicates just how certain they are of being able to shake up the banks’ business.
But these hackers haven’t exactly brought the firms to their knees, said Rob Rachwald, director of security strategy for Imperva, a data security company.

“[Officials] know that if the bank is breached and that suddenly everyone’s account number is publicized, that will really kill their business, whereas going offline for a little while is just embarrassing,” Rachwald said. “In this case, this shows data security practice at the banks is still really solid.”
It’s unclear the exact origin of the attacks, although Connecticut Sen. Joseph Lieberman told C-Span last week they appear to be coming out of Iran. Some observers speculate the Iranian government at least knew of the attacks, if not actually orchestrated them.

The fact that the hackers are trying to recruit more people to join them — and want to hit banks in other countries — is alarming, said Atif Mushtaq, a senior staff scientist for online security company FireEye.
“You can’t really prevent this type of attack [on your website]. You can mitigate it a little,” he said. “But the real question is, when is this going to end?
Friday, December 28, 2012 | 2 komentar | Read More

DOS hackers take HSBC websites down

Written By ization shop on Monday, December 3, 2012 | Monday, December 03, 2012

Some HSBC customers are still unable to access some of HSBC's online portals and services following a denial-of-service attack, resulting in customers being unable to log on for several hours.
HSBC
Some HSBC web services went down on Thursday due to a DDoS attack.
Twitter users began reporting the problems accessing the sites at around 17:45BST.
"Anyone else having problems with HSBC Internet Banking not working? Site seems to be down," wrote a user with the name of 'Mrs_Spartacus'.

According to Mark Denne, a partner at West Avenue Capital, the sites us.hsbc.com, hsbc.co.uk and offshore.hsbc.com were all still offline still at around 20:00BST.
"HSBC down. http://www.us.hsbc.com , http://www.hsbc.co.uk & http://www.offshore.hsbc.com all offline. Looks serious. Anyone else seeing this?" he said on Twitter.

At around 20:15BST HSBC provided details of the problem, blaming hackers for the downtime.

"On 18 October 2012 HSBC servers came under a denial of service attack which affected a number of HSBC websites around the world. This denial of service attack did not affect any customer data, but did prevent customers using HSBC online services, including internet banking," the company said in a statement.
"We are taking appropriate action, working hard to restore service.

 We are pleased to say that some sites are now back up and running," it added.
Monday, December 03, 2012 | 2 komentar | Read More

Paul Graham Publicly Releases Nodejitsu From Hacker News Jail

Written By ization shop on Tuesday, October 30, 2012 | Tuesday, October 30, 2012


Notorious Nodejitsu just got a big fat "get out of jail free" card from Paul Graham. The New York-based startup has been persona non grata on the forum Hacker News Influential geek since. . . well, we first heard about the drama, oh, back in December?

Mr. Graham, who runs Y Combinator and Hacker News, says Nodejitsu was banned for spamming; Nodejitsu's founders Because they suspected it was Y Combinator alum Compete with Heroku. But as of Sunday night, Nodejitsu's back in the game.


Heroku and Nodejitsu both host apps for developers, although Nodejitsu does it only for apps written in node.js, while Heroku has a wider range of offerings, Including Java and Ruby. Heroku Launched "experimental support" for node.js in April 2010, as Nodejitsu was just getting started. The race was on.


Yesterday, a Hacker News user posted an alternative to the forum called Lamer News, inspired by all the kvetching and conspiracy theory surrounding the moderator opaque policies of Hacker News. Some users say the site is "a shill for Y Combinator companies;" "why did Hacker News remove my blog post," and so on. Foursquare's Eric Friedman's personal domain, marketing.fm, was mysteriously banned after a post about VC breakfast etiquette; others have been mystified as to why their submissions did or did not show up.


The site provoked a discussion about Hacker News policies in general. "We do not ban sites of competitors of companies we fund," Mr. Graham said in the thread. "Even if we wanted to do something like that, how could we ever get away with it?" Then he leapt to a conclusion: "I'm guessing you're referring to Nodejitsu.com. They're banned Because they created an army of sockpuppets to vote up their posts. "


The accusation brought a fiery rebuttal from Nodejitsu's clear-eyed CEO Charlie Robbins, a coder who was recruited out of college to work at Microsoft, did his time coding in the finance sector, and also serves served until recently as the CTO of the General Assembly. "Your claim that Nodejitsu 'created an army of sockpuppets to vote up their posts' is outrageous. Let me enumerate the issue here, "he wrote, and proceeded to pick apart Mr. Graham's statement and attack Hacker News for its lack of transparency in four arguments.


Mr. Explained that banning Nodejitsu Robbins meant that not only was the company's blog blocked, any developer using Nodejitsu would run into trouble if he or she tried to put an app on Hacker News-something that is commonly done to get users or feedback."The problem with that is you are also penalizing Nodejitsu customers (like myself) that host their projects on their platform," Frank Denbow, a local founder and coder, wrote in the thread. "I support the Nodejitsu guys but I'm not an employee and do not share all their Viewpoints; I was just working on my first project for NodeKnockout Nodejs and wanted to get some feedback from the HN community, but my site was blocked also . "


"I did not Realize users' stuff was hosted on subdomains. Ok, I'll unban nodejitsu.com, "Mr. Graham RESPONDED. "We do not ban lightly sites. We only do it when people make-repeated, deliberate efforts to bypass protections lighter weight ... I'm happy to unban nodejitsu.com if you promise to stop trying to game HN. In your case I recommend the following standards for what counts as gaming HN: if you're not sure, do not. "
Tuesday, October 30, 2012 | 1 komentar | Read More

Hackers may catch Indian banks napping

Written By ization shop on Saturday, October 20, 2012 | Saturday, October 20, 2012

With the rising incidence of cyber crime, how safe is Internet banking in India? Samir Kelekar finds out....

About two months ago, there was a major phishing attack on one of India's largest public sector banks.I too received a phishing mail even though I did not even have an account in that bank then. When I checked with the bank if the account holders had lost money, they were not sure.
  
Users, who enter their credentials in a phishing site and subsequently lose money, do not always admit what they have done. Instead, they blame the banks for losing money.

The increasing incidents of online fraud and hacking have put banks in a difficult position. Phishers are Becoming more and more sophisticated and phishing mails have begun to Appear in Hindi too, targeting the growing numbers of regional language Internet users. Also, it seems that the law applying to the loss of money in an Internet banking transaction is tilted against the banks.


A well-known legal expert says the liability of cyber crime, in roomates the customer is not a co-conspirator, is always on the banks. In other words, if a user loses her money, RBI may ask the concerned bank to compensate the user unless it can show that the user herself is INVOLVED in a conspiracy to steal the money.


So, even if there is no anti-virus on the user's computer or a key-logger is installed by a malicious hacker on the user's machine, banks would still be held responsible for the loss of money. To avoid these risks, experts say banks should come up with automated methods to Ensure that the user's machine is secure before allowing her access to Internet banking.


But not many banks have realized the gravity of the situation and life goes on as usual for them. But surely it will not be long before banks start to Realise how vulnerable they are. A chief information security officer (CISO) of a well known bank retorted when confronted with a blatant security hole in the bank's procedure: "Has a fraud happened? If not, why worry? "


This means that he will wake up only when the bank is swindled of significant money, and it may be too late then to plug the hole. Usually the PSU banks do not adequately reward performance and hence, you can expect the bank's managing security personnel to be not very highly motivated. Further, with their present salary structure, PSU banks fail to attract top security professionals.


Fortunately, in India the major frauds in banks are still not the ones involving hacking. In most circumstances, it is an acquaintance, who defrauds the victim. Recently, in the U.S., large companies such as Sony and Citibank have been hacked and passwords of millions of users stolen. Why has not such an incident happened in India? My take is that the hacker-criminals in India are not sophisticated enough as yet. And international criminals have not turned their gaze towards India as yet. But the situation could change anytime.To be frank, not all security holes of Internet banking can be blamed on the banks. Today's Internet infrastructure is full of holes, and still, banks are moving at high speed introducing newer and newer services, without closing the holes that are found.


To give a few examples, most of the home routers come with default passwords, roomates few users change. As a result, it is not difficult for a hacker to log into them. Wireless networks are vulnerable to using WEP WEP cracking, and software to do so is freely available on the net. And many of Indian payment gateways have security holes.Banks have to also worry about mobile transactions, roomates are Becoming Common.Vulnerabilities have been found in iphones and other mobiles. Mobiles are increasingly also used on wireless hotspots, and they are particularly vulnerable there. Along with banks, the government also needs to wake up to online security needs.


Recently, Indian Institute of Science, Bangalore tied up with a major Chinese company Huawei Technologies, roomates has funded its center for security testing in telecom systems. It is inconceivable that our government exposes such a critical national security area to a foreign company. The UIDAI, another critical project for national security, is associated with the U.S. companies with dubious credentials.


The government has also failed to act on cyber crime. Until a year ago, Bangalore had not had a single conviction in cyber crime. Having interacted with the cyber crime police, I can vouch for the good job the Investigators are doing. However, if the grapevine is to be believed, the reason for the zero rate of conviction seems to be that the powers-that-be have a tough time Distinguishing between the IT Act as in the Income Tax Act and the IT Act as in the Information Technology Act.


There are also some bright sides. The two-factor authentication --- requiring a one-time password that is sent on a mobile --- is a much needed improvement that the RBI has Mandated for banking transactions. The hacker's task has got more difficult as he now has to hack the mobile of the victim too along with the desktop computer. However, two-factor authentication is not Followed in case of transactions involving share purchase as the time factor is crucial there and one can not wait for an SMS, roomates might take minutes or sometimes hours before making the transaction.


What can a lay person do to protect his interest online? While the law Favours the user as of now, it is an open question if banks would compensate users in case of a major breach. Thus, it would be surely a good idea for high-value depositors to spread their funds across different banks. ICICI Bank has Introduced an insurance policy, roomates provides a cover of Rs one lakh if ​​money is lost due to fraudulent use of an ATM card. This is a good start.


Secondly, consumer forums should tie up with banks and security companies in educating the users about the security of internet banking. After all, however difficult it may look, there is nothing better than taking the bull by the horns.
Saturday, October 20, 2012 | 0 komentar | Read More

Islamic hackers threaten Bank of America and NY Stock Exchange


The Bank of America's online banking site suffered occasional problems Tuesday after threats on the internet that a cyber-attack would be Launched on the banks and other U.S. targets in protest at a movie mocking Islam.

A message on pastebin.com claiming to be from 'cyber fighters of Izz ad-din al qassam'-a reference to the military wing of Hamas declared that it would attack the Bank of America and the New York Stock Exchange as a first step in a campaign against "American Zionist capitalists".


The posting promised to continue aggressive actions until the "Erasing of the nasty movie", although YouTube has blocked roomates in volatile regions, remains available in other parts of the world.


The movie in question, a privately funded short-movie, mocking the Prophet Mohammad, has ignited days of demonstrations.The Uproar has left many dead across the Arab world, Including Africa, Asia and some Western countries.


A Bank of America spokesman told Reuters that the website had suffered some problems but was available to customers.But customers contacted by Reuters in Michigan, Ohio, Georgia and New York said they could not access the site.


The threat to the New York Stock Exchange has seemingly not materialized as trading continued as normal.Bill Pennington, chief strategy officer at WhiteHat Security, told the weekly magazine InformationWeek that the problems on the Bank of America website do not necessarily mean they've been hacked.


"It's reasonable to suppose it could be a coincidence," he said, citing the recent outage GoDaddy, which was an internal technical error for roomates hackers claimed responsibility.But he did concede that the website's problems could also be the result of hackers, saying that hacking was "pretty easy".


He said that only the perpetrators and possibly the victims [of the Bank of America] will ever really know what happened.


Pennington warned that businesses should expect more attacks, "It's probably going to get worse before it gets better," he said.
Saturday, October 20, 2012 | 0 komentar | Read More

Hackers attack US banking In Los Angeles

LOS ANGELES: A shadowy but well-organised hacker group in the Middle East has disrupted the electronic banking operations of America's largest financial institutions in recent days, underscoring US vulnerability to online terrorism.

A group identifying itself as Izz ad-Din al-Qassam Cyber Fighters attacked the websites of Wells Fargo, US Bancorp and Bank of America. The strikes left customers temporarily unable to see their accounts, mortgages and other services.

The banks said account and personal information for their tens of millions of online and mobile customers were not compromised. Still, experts said the size and ferociousness of the attacks highlight the broader threat posed by electronic crime and the susceptibility of financial targets.

Of particular concern is that the attackers used the internet to warn the institutions ahead of time - but the banks still could not repel the assaults.
Advertisement

''The banks put a lot of effort into cyber security. But they're so desirable as a target, even with all that effort they still have problems,'' said James Lewis, an expert at the Centre for Strategic and International Studies in Washington. ''If you can pull together enough resources, you can overwhelm any defence temporarily.''

The attacks on banks began last week on the largest institutions in the country: JPMorgan Chase, Citigroup and Bank of America. They spread to Wells Fargo on Tuesday and US Bank on Wednesday. Another attack has been threatened against PNC Financial Services.

The US government and banks have been working feverishly to learn more about the attackers before they strike again.

Izz ad-Din al-Qassam is the name of the military wing of Hamas, the political party that governs the Gaza Strip.

On Tuesday the group posted a manifesto on the internet saying attacks would continue until a video insulting the prophet Muhammad was removed from the internet.
Saturday, October 20, 2012 | 0 komentar | Read More

Cyber criminals actively targeting financial institutions, warns FBI

Written By ization shop on Thursday, September 20, 2012 | Thursday, September 20, 2012

Cyber criminals have been and are actively targeting employees of financial institutions with spam and phishing e-mails, warns the FBI-backed Internet Crime Complaint Center (IC3).



Their aim is to compromise the employees' computers via information-stealing Trojans, keyloggers and Remote Access Tools (RATs) and then use the gleaned information to access the institutions' internal networks and third party systems.

The attackers' ultimate goal is to circumvent authentication methods used by the financial institutions to deter fraudulent activity, so that they can handle all aspects of a wire transaction, including the approval.

"The unauthorized transactions were preceded by unauthorized logins that occurred outside of normal business hours using the stolen financial institution employees’ credentials. These logins allowed the actors to obtain account transaction history, modify or learn institution specific
wire transfer settings, and read manuals providing information and training on the use of US payments systems," says in the advisory. "In at least one instance, actors browsed through multiple accounts, apparently selecting the accounts with the largest balance."

The attackers seem to prefer targeting small-to-medium sized banks and credit unions, although some of larger banks have been hit, as well.

The stolen information and the unauthorized access is misused to approve and cover fraudulent wire transfers, and the attackers have also been known to launch DDoS attacks against the institutions' Internet Banking websites in order to distract the personnel and prevent them noticing and blocking in time these money transfers.

The advisory also contains a number of helpful recommendations for preventing the attacks or minimizing their effects.
Thursday, September 20, 2012 | 0 komentar | Read More

New bank theft software hits three continents: researchers


(Reuters) - A new wave of automated hacking of online bank accounts might have stolen $ 78 million in the past year from customers in Europe, Latin America and the United States, According to Researchers who peered into the computers of the hacking gangs.
 The groups used recent improvements to two existing families of malicious software, known as Zeus and SpyEye, roomates lodged on the computers of clients at 60 banks.

While previous versions of the software have proved Adept at stealing logon information, the latest variants Automate the subsequent transfer of funds to accounts controlled by accomplices.The findings, to be released on Tuesday by security firms McAfee and Guardian Analytics, confirmed and expanded on research from Japan-based Trend Micro Inc. that was first reported last week by Reuters."This looks like the beginning of a new technique," said the Guardian's Vice President Craig Priess, Whose Firm Specializes in protecting banks.


The software is sophisticated enough to defeat "chip and PIN" and other two-factor authentication and to avoid transferring the entire contents of an account at one time, roomates can trigger review, According to the study.


Trend Micro said it had seen the automated versions in action in Germany, the United Kingdom and Italy.Guardian and Intel Corp.-owned McAfee said the same technology, while still emerging, had been used by a dozen gangs against consumers and business clients of financial institutions in those countries and Colombia, the Netherlands, and the United States.


"Someone designing this system has insider knowledge as to what the banks are looking for," said Dave Marcus, director of research at Mcafee Labs.Server logs Viewed by the commands of Allah Researchers from the fraud rings to transfer a total of $ 78 million, Including $ 130,000 from one account. The banks may have been Able to block some of those transactions, the Researchers acknowledged.


MONEY Mules


Though written and controlled by different groups, SpyEye and Zeus share the ability to be installed on computers that visit malicious websites or legitimate pages that have been compromised by hackers, as well as through tainted links in emails.


The programs have already used a technique called "injection site" to generate a new entry fields when victims log on to any number of banks or other sensitive websites. Instead of seeing a bank ask for an account number and password, for example, a user sees victimized requests for both of those and an ATM card number. All that information is sent to the hacker, who signs in and transfers money to an Accomplice's account.


Those transfers can be time-consuming, and the hacker has to consider how much can be sent at once without drawing attention. Multiple, smaller transfers are preferable but take more time.


For the past year or more, some variants have also captured a one-time passwords, such as those sent from the banks by text messages to cell phones client as an added security measure. But a hacker had to be online within 30 or 60 seconds in order to use the one-time password.


The new software Allows the criminals to siphon money out at all hours, Potentially increasing the number of hacked accounts and the speed with roomates they are drained.


Brett Stone-Gross, a senior security researcher with Dell SecureWorks Dell Inc. unit, said previously that the main limiting factor for crime groups is the number of accomplices, known as money mules, that they can hire to accept transfers from victim accounts. Automation will not lessen the need for mules, Stone-Gross said.Trend Micro Online spoke with sellers of the automated transfer modules who were based in Russia, Ukraine and Romania, where arrests and prosecutions are rare. It said the new software costs between $ 300 and $ 4,000.


Banks generally individuals compensate in full for such losses, if they are detected Quickly. But recent versions of SpyEye and Zeus can present fake bank account balances to individual customers, so they might not Realize their savings are being drained until too late.
Thursday, September 20, 2012 | 0 komentar | Read More

Chase, Bank of America credit cards too hacker-friendly?

Written By ization shop on Saturday, September 15, 2012 | Saturday, September 15, 2012

SEATTLE -- There's a warning for anyone with a credit card from two of the nation's largest banks.

A security loophole could make your information vulnerable to criminals.

This has to do with those automated telephone account information systems all the banks have. They sure are convenient. At Chase and Bank of America, they could be a little too easy to use.

"I was shocked at how easy it was to get into the accounts of other people. I had their permission, so I didn't do anything illegal," said Edgar Dworsky, consumer advocate and founder of website ConsumerWorld.org.

But he proved his point.

Here's the flaw he uncovered. When you call a bank's automated credit card account information system, the computer uses caller ID to compare the number you're calling from with the one on the account,usually your home phone.

At Bank of America and Chase, if the phone number is a match, the verification process is streamlined. You don't have to enter the entire 16 digits of the credit card; in most cases, all you need is the last four numbers -- something that can be found on any credit card receipt.

"This is people's personal information," Dworsky said. "No one has a right but me or someone I authorize to go into my account and hear what my credit line is, where I've been shopping, what I bought. to allow hackers in because of this security loophole is really pretty bad."

In order for someone to take advantage of this security loophole, the hacker would have to trick the bank's computer to make it appear the call is coming from your home phone.

Internet spoofing sites make this incredibly easy to do, as I discovered when I did a test and broke into Dworsky's account with his permission. Hackers know all about these sites.

I asked Chase and Bank of America to comment on this. Both said they take customer security very seriously, have procedures in place to detect fraud. And they do not think Dworsky's scenario is a significant security threat.

So how can this hurt you? Security experts tell me identity thieves can use these details they get from that automated credit card phone system to trick you into giving up valuable information, such as your security number or full account number. believe me, they have ways to do it.

The security protocol is stricter at Capital One, Citi and American Express. They all require the entire card number to be entered every time, no matter where the call is placed from, Dworsky would like to see Chase and Bank of America do the same thing.
Saturday, September 15, 2012 | 0 komentar | Read More

New bank hacking program hits three continents

A new wave of automated hacking of online bank accounts might have stolen $78 million in the past year from customers in Europe, Latin America and the United States.

This is according to researchers who peered into the computers of the hacking gangs.
The groups used recent improvements to two families of existing malicious software, known as Zeus and SpyEye, which lodged on the computers of clients at 60 banks.

While previous versions of the software have proved adept at stealing logon information, the latest variants automate the subsequent transfer of funds to accounts controlled by accomplices.

The findings, to be released on Tuesday by security firms McAfee and Guardian Analytics, confirmed and expanded on research from Japan-based Trend Micro Inc that was first reported last week by Reuters.
“This looks like the beginning of a new technique,” said Guardian’s Vice President Craig Priess, whose firm specializes in protecting banks.

The software is sophisticated enough to defeat “chip and PIN” and other two-factor authentication and to avoid transferring the entire contents of an account at one time, which can trigger review, according to the study.

Trend Micro said it had seen the automated versions in action in Germany, the United Kingdom and Italy.
Guardian and Intel Corp-owned McAfee said the same technology, while still emerging, had been used by a dozen gangs against consumers and business clients of financial institutions in those countries and Colombia, the Netherlands, and the United States.
 
“Someone designing this system has insider knowledge as to what the banks are looking for,” said Dave Marcus, research director at Mcafee Labs.

Server logs viewed by the researchers saw commands from the fraud rings to transfer a total of $78 million, including $130000 from one account. The banks may have been able to block some of those transactions, the researchers acknowledged.

Money mules

Though written and controlled by different groups, SpyEye and Zeus share the ability to be installed on computers that visit malicious websites or legitimate pages that have been compromised by hackers, as well as through tainted links in emails.

The programs already have used a technique called “web injection” to generate new entry fields when victims log on to any number of banks or other sensitive websites. Instead of seeing a bank ask for an account number and password, for example, a victimized user sees requests for both of those and an ATM card number. All that information is sent to the hacker, who signs in and transfers money to an accomplice’s account.

Those transfers can be time-consuming, and the hacker has to consider how much can be sent at once without drawing attention.

Multiple, smaller transfers are preferable but take more time.
For the past year or more, some variants have also captured one-time passwords, such as those sent from the banks by text messages to client cell phones as an added security measure. But a hacker had to be online within 30 or 60 seconds in order to use the one-time password.

The new software allows the criminal to siphon money out at all hours, potentially increasing the number of hacked accounts and the speed with which they are drained.

Brett Stone-Gross, a senior security researcher with Dell Inc unit Dell SecureWorks, said previously that the main limiting factor for crime groups is the number of accomplices, known as money mules, that they can hire to accept transfers from victim accounts. Automation will not lessen the need for mules, Stone-Gross said.
Trend Micro spoke online with sellers of the automated transfer modules who were based in Russia, Ukraine and Romania, where arrests and prosecutions are rare. It said the new software costs between $300 and $4000.

Banks generally compensate individuals in full for such losses if they are detected quickly. But recent versions of SpyEye and Zeus can present fake account balances to individual bank customers, so they might not realize their savings are being drained until too late.
Saturday, September 15, 2012 | 0 komentar | Read More

Popular Posts Today