Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

23.1.08

Call-jacking VOIP / More Worms for Cellphones

New VOIP 'Call-Jacking' Hack Unleashed


JANUARY 22, 2008 Dark Reading

Now there's a way for attackers to hijack a user's voice-over-IP service: "call-jacking" could let the bad guys launch sophisticated phishing attacks as well as perpetrate lucrative toll fraud.

Researchers from the hacker group GNUCitizen have released a proof-of-concept for call-jacking via a BT Home Hub user's router. The attack exploits cross-site request forgery (CSRF) and authentication bypass vulnerabilities in the router that were previously discovered by the researchers. The attack works even if the default password in the router has been changed.

"We believe that this technique, which we coined as 'call jacking,' is completely new. There is nothing like this in the public domain as far as we know," says Adrian Pastor, a senior IT security consultant for an unnamed penetrating testing firm in London. "The beauty of the attack is that the victim user thinks he/she is receiving a phone call, but in fact he/she is making the phone call and paying for it. We find this quite innovative and unique, hence the need for coining a new term."

The exploit could be used in a phishing attack, where the victim would get a phone call from his "bank" after clicking a link in a phishing email. Phishers typically don't know their victims' phone numbers, he says, so the phone call would help the attacker appear legitimate and gain the victim's trust.

Another attack scenario involves toll fraud, where the victim's router would be forced to dial a toll number. "Premium numbers are very expensive, and allow the identity who registered them -- in this case, the attackers -- make money every time someone dials them," Pastor says.

+++++++++++++++++++++++++++++++++++++++++

Malicious MMS worm hits Nokia handsets


January 22, 2008 (TechWorld.com)

-- Security vendor Fortinet has uncovered a malicious SymbianOS Worm that is actively spreading on mobile phone networks.

Fortinet's threat response team warned on Monday that the worm, identified as SymbOS/Beselo.A!worm, is able to run on several Symbian S60 enabled devices. These include the Nokia 6600, 6630, 6680, 7610, N70 and N72 handsets.

The malware is disguised as a multimedia file (MMS) with an evocative name: either Beauty.jpg, Sex.mp3 or Love.rm. Fortinet warned this is deceiving users into unknowingly installing the malicious software onto their phones.

Unlike Microsoft Windows, SymbianOS types files based on their contents and not their extensions, so it is worth noting that recipients of infected MMS would still be presented with an installation dialogue upon "clicking" on the attachment. "Therefore, users could easily be deceived by the extension and unknowingly install the malicious piece of software," warned Fortinet.

After installation, the worm harvests all the phone numbers located in the phone's contact lists and targets them with a viral MMS carrying a SIS-packed (Symbian Installation Source) version of the worm. In addition to harvesting these numbers, the malware also sends itself to generated numbers as well.

6.1.08

Hackers from China force Pennsylvania to shut down state government's Web site

Could all the recent hacks from China just be a way of covering up domestic hacking? I say this because if you the General American Public knew this was happening from within your own country, you would 5hit even more.

"Administration spokeswoman Mia DeVane said there was no reason to think anyone's personal data had been compromised."

Would they really tell you if it was?

I also wonder if this is another attempt to sway the Vote in the upcoming election. Pennsylvania with 21 electoral votes is a large state and could be in the running again this year as the swing state.

http://thestar.com.my/news/story.asp?file=/2008/1/5/apworld/20080105085041&sec=apworld

HARRISBURG, Pennsylvania (AP) - Hackers from China infiltrated the Web site of the Pennsylvania state government, but officials said they found no evidence of damage.

Four state departments had security problems with their Web pages, leading to a decision to take down nearly all of the state's Internet site on Friday morning.

Office of Administration spokeswoman Mia DeVane said there was no reason to think anyone's personal data had been compromised or that any damage occurred when a hacker "got into what we would say is a back door.''

By late afternoon, nearly all of the state's site had been put back online. "It was more that we needed to take down those sites to make sure a virus couldn't spread,'' she said.

The problems arose at pages of the departments of Labor and Industry, Education, and Military and Veterans Affairs, as well as the Pennsylvania Lottery's page.

Investigators tracked the source to a domain registered in China, she said.
Wow, they traced it to China. There are many different ways I could make you think I hacked you from another place than from where I am actually at.

It is not unusual for the state's computer system to be the target of hackers, but having problems at four separate branches of state government prompted the decision to take down nearly the entire system, she said.

DeVane said Pennsylvania's information technology officers learned during a conference call held by the Multi-State Information Sharing and Analysis Center that four other states and one state university had been attacked in a similar manner.

2.1.08

Military Issues Warning on Chinese Hackers

I have known about China hacking various nations for awhile. They[meaning you know who] try and keep things like this from making the snooze in the USA. Hell, I'll go as far to say that 85% of all hacks come from China. At least thats what my Smoothie tells me.

Military Issues Warning on Chinese Hackers

By Jung Sung-ki
Staff Reporter
01-01-2008
http://www.koreatimes.co.kr/www/news/nation/2008/01/205_16537.html


The South Korean military has issued a warning that computer systems of soldiers and defense institutes have become the victims of presumed Chinese hacking activities, a military source said Tuesday.

The source said hackers, believed to be Chinese nationals, penetrated computers of soldiers by sending e-mail involving hacking programs falsely titled ``the situation on North Korea's arms power.''

``We are now investigating several cyber hacking cases believed to be conducted by Chinese nationals based on evidence that the hackers stole information stored in soldiers' computers,'' the source said, asking not to be named.

The hackers appeared to have penetrated Web sites of military units and retired soldiers to steal e-mail adresses of individuals registered to the sites, he said.

The Defense Security Command recently distributed up-to-date vaccine programs to service members as a precautionary measure, he added.

Cyber attacks from China have become frequent and aggressive in recent years, according to reports.

The Chinese military created a cyber-hacking unit named ``NET Force'' in 2000 operated by about 1 million hackers, the reports said.

In 2004, the state-funded Korea Institute for Defense Analyses was hacked by a Chinese person.

Reports said last year Chinese military hackers were preparing a detailed plan to disable America's aircraft carrier fleet as part of an aggressive push by Beijing to achieve ``electronic dominance'' over each of its global rivals by 2050, particularly the United States, Britain, Russia and South Korea.

The U.S. Department of Defense said China's military regards offensive computer operations as ``critical to seize the initiative'' in the first stages of a war.

gallantjung@koreatimes.co.kr
Of course you do know who pretty much controls the South Korean government;.........don't you? Of course you do.......