Miley Cyrus, Taylor Swift and Britney Spears websites hacked by Ethical Spectrum
By : Unknown
Update :
The latest tweet from the hacker shows he compromised the
database containing username and password details belong to these websites
"The database of #MileyCyrus, #SelenaGomez......etc with 2,5 million users
and pass is for sell, anyone interested email me at my mail"
Exclusive Information:
The hacker told E Hacking News that he found multiple
vulnerabilities in the Groundctrl website and gained access to the database
server.
He also gained access to the CMS panel which manages the
celebrities' websites.
GroundCtrl CMS Panel
Original Article:
A hacker going by online handle "Ethical Spectrum"
has hacked into websites belong to several celebrities and defaced the sites.
The affected websites include Miley Cyrus official
site(mileycyrus.com), Selena Gomez(selenagomez.com), Taylor Swift
site(taylorswift.com), Britney Spears site(britneyspears.com).
Sponsored Links
We are able to confirm that these are official websites of
the celebrities, as it is being linked from their twitter account.
According to hackers twitter account(@Eth_Spectrum), he
hacked into the above mentioned websites on March 8th. The website was restored after the
breach. However, hacker mentioned he once
again managed to deface them. ]
Other websites attacked by the hacker are Ground
Ctrl(groundctrl.com), mypinkfriday.com, Chelsea Handler site
(chelseahandler.com), Aaron Lewis(aaronlewismusic.com/), therealcocojones.com,
christinagrimmieofficial.com, Kacey Musgraves(kaceymusgraves.com).
The defacement just reads "Why i hacked this site, you
can ask this person greg.patterson@groundctrl.com".
Greg Patterson is the co-founder of the Groundctrl, an
organization that build websites for artists.
It appears the security breach started from Groundctrl.
Other affected sites:
Pat Green(patgreen.com),
Rob Thomas(robthomasmusic.com),
Rock Mafia(rockmafia.com
),
ritawilson.com ,
sum41.com
nickcarter.net
jordanknight.com
If you are not able to see the defacement, you can find the
mirror here:
http://www.zone-h.org/archive/notifier=Ethical%20Spectrum
All of the affected websites are currently showing the
maintenance error message except groundctrl official website.
Hacker didn't provide much information about the breach, so
we are not sure how exactly he hacked into all of these websites, whether he
found a zero-day exploit on the cms developed by groundctrl or all of the
affected sites managed in a central place.
Bug in Twitter could allow anyone to read tweets from protected accounts
By : Unknown
Twitter has fixed a bug in their website that could allow
non-approved followers to read the tweets made by protected twitter accounts.
Normally, Tweets from protected accounts can't be seen by
public user; One should get approval from
the account holder to view the protected tweets.
This bug could allow anyone to view hidden tweets by getting
SMS or push notification from the accounts.
The microblogging firm said a member of white hat security
community helped them to discover and diagnose the bug. According to its blog post, the bug is there
since November 2013.
"As part of the bug fix, we’ve removed all of these
unapproved follows, and taken steps to protect against this kind of bug in the
future."
The bug affects around 93,788 protected accounts. Twitter has sent mail to all affected users
to inform about the bug and apologize.
Hacker breaches Johns Hopkins University website
By : Unknown
The database server contains information of current and
former biomedical engineering students.
The stolen information includes name, phone number and email id of
students.
The University says no information such as Social Security
numbers and credit card numbers that would make identity theft a concert, is
not involved in the breach.
According to the Baltimore Sun, the so-called anonymous
hacker attempted to extort the university for further access to its database
server, threatening to leak the stolen data unless university handed over the
server password.
The breach reportedly occurred in last November, the
vulnerability responsible for the breach has been patched. The University is currently working with FBI
and trying to remove the leaked data from online.
Apple’s iPhone 5S tracks your every physical movement even after the battery dies
By : Unknown
Something serious about your privacy revealed in public by
an user of Apple iPhone 5S, right now you just know-Apple has a motion
co-processor called M7 Chip that tracks of your motion related data derived
from the integrated accelerometer, gyroscope and compass sensors but you know
if your ever died then-still all of your data collected by the M7 Chip.
The fact is when iPhone’s battery shuts down due to low
battery, actually the battery isn’t completely drained. M7 designed to work in
very tiny power also. So M7 analyzes your every physical activity even if the
your battery dies.
M7 processor works
independently , so it doesn’t need any other components on the iPhone to
be powered on.
This Privacy stuff revealed by a Reddit user, who wrote:
While traveling abroad, my iPhone cable stopped working so
my 5s died completely.
I frequently use Argus to track my steps (highly recommended
if you have any health bands or accessories) since it takes advantage of the M7
chip built into the phone.
Once I got back from my vacation and charged the phone, I
was surprised to see that Argus displayed a number of steps for the 4 days that
my phone was dead.
I’m both incredibly impressed and slightly terrified.
M7 only analyze physical activity, not your actual location.
Share and Enjoy
European Apple users targeted with phishing emails
By : Unknown
A new phishing campaign targeting European users of Apple
store which promises to offer a discount.
Security researchers at Kaspersky have spotted a new spam
mail targeting Apple users, tricks users into thinking that they can get
discounts of 150 euros by just paying 9 euros.
"Apple is rewarding its long-term customers. Your loyalty for our products made you
eligible for buying an Apple discount card" The spam mail reads.
The spam mail asks users to download an attached HTML file
and fill the form, where users are being asked to enter personal information as
well as credit card information.
The scammers spoofed the email address such that it makes
the email pretending to be from informs@apple.com. They also promised to send the discount card
within 24 hours, after filling the form.
If a recipient follows the instructions and fill the form,
the phishing file will send the data to the attacker server. The attacker will use the given financial data.
World’s Biggest Cyber Attack-360 Million email accounts credentials, 1.25 billion email addresses
By : Unknown
Do you know?-More than 360 Million accounts credentials and
around 1.25 billion email addresses are put up on sale on the online Black
Market by Hackers worldwide.
This is the world’s biggest cyber attack ever.
A company in London named ‘Hold Security’ researched and
found this huge size of data .
Only one of the hacker attack stole more than 105 million
records, which is a single largest data breach in the history.
“These credentials can be stolen directly from your company
but also from services in which you and your employees entrust data. In October
2013, Hold Security identified the biggest ever public disclosure of 153
million stolen credentials from Adobe Systems. One month later we identified
another large breach of 42 million credentials from Cupid Media,” the firm
said.
The firm took three weeks to collect the data. Firm tracked
over 300 million abused credentials that were not disclosed publicly (that is
over 450 million credentials if one counts the Adobe find).
“But this month we exceeded all expectations. In the first
three weeks of February we identified nearly 360 million stolen and abused
credentials and 1.25 billion records containing only email addresses. These
mind boggling numbers are not meant to scare you and they are a product of
multiple breaches which we are independently investigating. This is a call to
action,” it added.
“The sheer volume is overwhelming,” said Alix Holden, chief
information security officer of Hold Security.
Email addresses include all the major providers like Google,
Microsoft and Yahoo. Many non-profit organizations and all Fortune companies
had been affected.
This is the biggest data breach after the Adobe one.
Share and Enjoy
YouTube ads serve Banking Trojan Caphaw
By : Unknown
Number of Malvertising attacks are appeared to be increasing
day by day, even top websites fall victim to such kind of attacks - YouTube is
to be the latest popular organization affected by malicious ads.
Security experts from Bromium have discovered that the cyber
criminals were distributing a malware via YouTube ads.
According to researchers,
malicious ads attempt to exploit vulnerabilities in outdated Java. It loads different malicious jar file, to
ensure the exploit is compatible with the installed java version.
The Exploit kit used in this attack "Styx Exploit
Kit" which was the same one used by cybercriminals to infect users of toy
maker Hasbro.com.
If the user's machine is having vulnerable plugins, it will
exploit the vulnerability and drops a Banking Trojan known as
"Caphaw". Researchers say they
are working with Google Security team.
Why Use A Firewall? IP Tables In A Simple Way
By : Unknown
ABSTRACT
Readers, there are numerous reasons... It is well known that
the Internet is an unmanaged a decentralized network, running under a set of
protocols, which are not designed to ensure the integrity and confidentiality
of information and access controls.
There are several ways to breach a network, but these ways
do nothing more than take advantage of flaws within network protocols and
services.
CONCEPTS
IPTABLES is an editing tool for packet filtering, with it
you can analyze the header and make decisions about the destinations of these
packets, it is not the only existing solution to control this filtering. We
still have the old ipfwadm and ipchains, etc.
It is important to note that in Gnu / Linux, packet
filtering is built into the kernel. Why not configure your installation in
accordance with this article, since most distributions come with it enabled as
a module or compiled directly into the kernel.
STEP BY STEP
case "$1" in
start)
Clearing Rules
iptables -t filter -F
iptables -t filter -X
Tips [ICMP ECHO-REQUEST] messages sent to broadcast or
multicast
echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_broadcasts
Protection against ICMP redirect request
echo 0 > /proc/sys/net/ipv4/conf/all/accept_redirects
Do not send messages, ICMP redirected.
echo 0 > /proc/sys/net/ipv4/conf/all/send_redirects
(Ping) ICMP
iptables -t filter -A INPUT -p icmp -j ACCEPT
iptables -t filter -A OUTPUT -p icmp -j ACCEPT
Packages logs with nonexistent addresses (due to wrong
routes) on your network
echo 1 > /proc/sys/net/ipv4/conf/all/log_martians
Enabling forwarding packets (required for NAT)
echo "1" >/proc/sys/net/ipv4/ip_forward
SSH accepted
iptables -t filter -A INPUT -p tcp --dport 22 -j ACCEPT
Do not break established connections
iptables -A INPUT -m state --state RELATED,ESTABLISHED -j
ACCEPT
iptables -A OUTPUT -m state --state RELATED,ESTABLISHED -j
ACCEPT
Block all connections by default
iptables -t filter -P INPUT DROP
iptables -t filter -P FORWARD DROP
iptables -t filter -P OUTPUT DROP
IP spoofing protection
echo "1" > /proc/sys/net/ipv4/conf/default/rp_filter
echo - Subindo proteção contra ip spoofing : [OK]
Disable sending the IPV4
echo 0 > /proc/sys/net/ipv4/ip_forward
SYN-Flood Protection
iptables -N syn-flood
iptables -A syn-flood -m limit --limit 10/second
--limit-burst 50 -j RETURN
iptables -A syn-flood -j LOG --log-prefix "SYN FLOOD:
"
iptables -A syn-flood -j DROP
# Loopback
iptables -t filter -A INPUT -i lo -j ACCEPT
iptables -t filter -A OUTPUT -o lo -j ACCEPT
Tips connections scans
iptables -A INPUT -m recent --name scan --update --seconds
600 --rttl --hitcount 3 -j DROP
iptables -A INPUT -m recent --name scan --update --seconds
600 --rttl --hitcount 3 -j LOG --log-level info --log-prefix "Scan
recent"
Tips SYN packets invalid
iptables -A INPUT -p tcp --tcp-flags ALL ACK,RST,SYN,FIN -j
DROP
iptables -A INPUT -p tcp --tcp-flags SYN,FIN SYN,FIN -j DROP
iptables -A INPUT -p tcp --tcp-flags SYN,RST SYN,RST -j DROP
iptables -A INPUT -p tcp --tcp-flags ALL ACK,RST,SYN,FIN -j
LOG --log-level info --log-prefix "Packages SYN Detected"
iptables -A INPUT -p tcp --tcp-flags SYN,FIN SYN,FIN -j LOG
--log-level info --log-prefix "Packages SYN Detected"
iptables -A INPUT -p tcp --tcp-flags SYN,RST SYN,RST -j LOG
--log-level info --log-prefix "Packages SYN Detected"
# Tips SYN packets invalid
iptables -A OUTPUT -p tcp --tcp-flags ALL ACK,RST,SYN,FIN -j
DROP
iptables -A OUTPUT -p tcp --tcp-flags SYN,FIN SYN,FIN -j
DROP
iptables -A OUTPUT -p tcp --tcp-flags SYN,RST SYN,RST -j
DROP
iptables -A INPUT -p tcp --tcp-flags ALL ACK,RST,SYN,FIN -j
LOG --log-level info --log-prefix "Packages SYN Detected"
iptables -A INPUT -p tcp --tcp-flags SYN,FIN SYN,FIN -j LOG
--log-level info --log-prefix "Packages SYN Detected"
iptables -A INPUT -p tcp --tcp-flags SYN,RST SYN,RST -j LOG
--log-level info --log-prefix "Packages SYN Detected"
Certifies that new packets are SYN, otherwise they Tips
iptables -A INPUT -p tcp ! --syn -m state --state NEW -j
DROP
Discard packets with fragments of entry. Attack that can
cause data loss
iptables -A INPUT -f -j DROP
iptables -A INPUT -f -j LOG --log-level info --log-prefix
"Packages fragmented entries"
Tips malformed XMAS packets
iptables -A INPUT -p tcp --tcp-flags ALL ALL -j DROP
iptables -A INPUT -p tcp --tcp-flags ALL ALL -j LOG
--log-level info --log-prefix "malformed XMAS packets"
DNS In/Out
iptables -t filter -A OUTPUT -p tcp --dport 53 -j ACCEPT
iptables -t filter -A OUTPUT -p udp --dport 53 -j ACCEPT
iptables -t filter -A INPUT -p tcp --dport 53 -j ACCEPT
iptables -t filter -A INPUT -p udp --dport 53 -j ACCEPT
NTP Out
iptables -t filter -A OUTPUT -p udp --dport 123 -j ACCEPT
WHOIS Out
iptables -t filter -A OUTPUT -p tcp --dport 43 -j ACCEPT
FTP Out
iptables -t filter -A OUTPUT -p tcp --dport 20:21 -j ACCEPT
iptables -t filter -A OUTPUT -p tcp --dport 30000:50000 -j
ACCEPT
FTP In
iptables -t filter -A INPUT -p tcp --dport 20:21 -j ACCEPT
iptables -t filter -A INPUT -p tcp --dport 30000:50000 -j
ACCEPT
iptables -t filter -A INPUT -m state --state ESTABLISHED,RELATED
-j ACCEPT
HTTP + HTTPS Out
iptables -t filter -A OUTPUT -p tcp --dport 80 -j ACCEPT
iptables -t filter -A OUTPUT -p tcp --dport 443 -j ACCEPT
HTTP + HTTPS In
iptables -t filter -A INPUT -p tcp --dport 80 -j ACCEPT
iptables -t filter -A INPUT -p tcp --dport 443 -j ACCEPT
Mail SMTP:25
iptables -t filter -A INPUT -p tcp --dport 25 -j ACCEPT
iptables -t filter -A OUTPUT -p tcp --dport 25 -j ACCEPT
Mail POP3:110
iptables -t filter -A INPUT -p tcp --dport 110 -j ACCEPT
iptables -t filter -A OUTPUT -p tcp --dport 110 -j ACCEPT
Mail IMAP:143
iptables -t filter -A INPUT -p tcp --dport 143 -j ACCEPT
iptables -t filter -A OUTPUT -p tcp --dport 143 -j ACCEPT
# Reverse
iptables -t filter -A INPUT -p tcp --dport 77 -j ACCEPT
iptables -t filter -A OUTPUT -p tcp --dport 77 -j ACCEPT
MSF
iptables -t filter -A INPUT -p tcp --dport 7337 -j ACCEPT
iptables -t filter -A OUTPUT -p tcp --dport 7337 -j ACCEPT
WEB Management Firewall
touch /var/log/firewall
chmod +x /var/log/firewall
/var/log/firewall -A INPUT -p icmp -m limit --limit 1/s -j
LOG --log-level info --log-prefix "ICMP Dropped "
/var/log/firewall -A INPUT -p tcp -m limit --limit 1/s -j
LOG --log-level info --log-prefix "TCP Dropped "
/var/log/firewall -A INPUT -p udp -m limit --limit 1/s -j
LOG --log-level info --log-prefix "UDP Dropped "
/var/log/firewall -A INPUT -f -m limit --limit 1/s -j LOG
--log-level warning --log-prefix "FRAGMENT Dropped "
/var/log/firewall -A INPUT -m limit --limit 1/minute
--limit-burst 3 -j LOG --log-level DEBUG --log-prefix "IPT INPUT packet
died: "
/var/log/firewall -A INPUT -m limit --limit 3/minute
--limit-burst 3 -j LOG --log-level DEBUG --log-prefix "IPT INPUT packet
died: "
exit 0
;;
stop)
echo "turning off the firewall "
iptables -P INPUT ACCEPT
iptables -P OUTPUT ACCEPT
iptables -t filter -F
exit 0
;;
restart)
/etc/init.d/firewall stop
/etc/init.d/firewall start
;;
echo "Use: /etc/init.d/firewall
{start|stop|restart}"
exit 1
;;
esac
Logs available: /var/log/firewall
COMMANDS TO MONITOR LOGS: tail -f /var/log/messages
Save: /etc/init.d/firewall
CONCLUSION
I hope to help you in configuring your network security and
remind you to choose only the best options available.
Allow me to add a few Advantages of using your firewall. Be
sure to Block unknown and unauthorized connections. You can specify what types
of network protocols and services to be provided and you may control the
packets from any untrusted services... Your firewall also allows blocking
websites with URL filters, access control, access logs for reports by user,
protecting the corporate network through proxies, and Network Address
Translation (NAT). Control services that can either be executed or not, on the
network allowing for high performance in their duties with easy administration
and reliability.
EC Council official website hacked
By : Unknown
A hacker who calls himself "Eugene Belford" (A
character from the movie "Hackers" )has hacked the EC-Council website
- an organization that offers Certified Ethical Hacker(CEH)
"Owned by certified unethical software security
professional" The defacement message reads.
He has also put in the deface page documents proving that
"Edward Snowden" attended the CEH classes in India.
A spokesman from CSPF (Cyber Security and Privacy
Foundation) says, it appears to be hackers used DNS hijacking attack to deface
the website and possible gain access to their email.
Another CEH certified professional says he was not satisfied
with EC Coucil Training. He says though
the course material is good and certification is recognised worldwide, the
trainers from francisees of EC Coucil do not know hacking and they are not
competent to take CEH classes.
Update: Sometime after this news was posted the hacker
edited the deface page with this extra text.
"Defaced again? Yep, good job reusing your passwords
morons jack67834#
Obligatory link:
http://attrition.org/errata/charlatan/ec-council/
-Eugene Belford
P.S It seems like lots of you are missing the point here,
I'm sitting on thousands of passports belonging to LE (and .mil) officials
"
It might be that the attacker has gotten access to the
emails of EC Council and hence all the email correspondence of the Law
Enforcements and Military officials might be compromised also.
Anonymous hacker sentenced for DDoS Attack, will pay $110,932 for the damage
By : Unknown
Anonymous hacker “Jacob Wilkens” responsible for the
denial-of-service attack against Koch Industries was sent on 24 months of
probation through the decision of The U.S. District Court, Eastern District of
Wisconsin, in addition court ordered him to pay
$110,932.71 for the damage caused in DDoS attack.
Jacob pled guilty to take down the servers of Angel Soft
bathroom tissue (which is based in Green Bay) with other members of the
hacktivist collective Anonymous, the attack took place in February and March of
2011.
As a result of the DDoS Attack, Koch Industries servers was
down for three days which caused losses of hundred-thousand dollars.
For the same attack, Christopher Sudlik was ordered to pay
and he also sentenced to 36 Months of probation.
Share and Enjoy
SIM Cards can be Hacked; Give me any phone number i will clone that researcher says
By : Unknown
In this Modern Era everyone knows that his/her latest mobile
can be hacked by hackers but now The sim card hacking flaw was discovered by
German programmer Karsten Nohl, who has informed mobile operators of the
potential danger.
After that all the Mobile phone users have been put on an
alert that their sim cards can be hacked anytime which leads to fraud and
soaring premium rate bills.
On the other hands, if we talk about the mobile operators
then they says that they already aware about this flaw and taking steps to
patch the flaw before customers are hit.
Worldwide Mobile Phones are Major source to be used in
accessing online banking and other sensitive personal information and if the
discovered flaw will be used by Hackers can make a privacy disaster, this flaw
also makes some noise for the mobile customers who use their smartphones to pay
bills and transfer money.
The security flaw is due to aging sim card security
technology, which has struggled to keep up with high-tech smartphones such as
the iPhone and Samsung’s Galaxy S4.
Flaw Researcher (Karsten Nohl) says something about his
Flaw:
“Give me any phone number and there is some chance I will, a
few minutes later, be able to remotely control this SIM card and even make a
copy of it,”
The hack works by manipulating a coding technology used by
operators to update sim cards. Properly equipped, a hacker can send a code to a
sim card to gain access to a phone’s systems, from where fraudulent activity
can be perpetrated.
Nohl said that a quarter of all sim cards he tested could be
hacked.
However, the international umbrella mobile operator
organisation, the GSMA, said that the flaw was limited to a minority of sim
cards and that newer sim cards may not be affected.. It said that it had
advised operators of the security risks involved.
Share and Enjoy
Lightbeam for Firefox (Shows the First and Third Party Interaction on the Web)
By : Unknown
Lightbeam is a Firefox add-on that enables you to see the
first and third party sites you interact with on the Web. Using interactive
visualizations, Lightbeam shows you the relationships between these third
parties and the sites you visit.
Using interactive visualizations, Lightbeam enables you to
see the first and third party sites you interact with on the Web. As you
browse, Lightbeam reveals the full depth of the Web today, including parts that
are not transparent to the average user. Using three distinct interactive
graphic representations — Graph, Clock and List — Lightbeam enables you to
examine individual third parties over time and space, identify where they
connect to your online activity and provides ways for you to engage with this
unique view of the Web.
How Lightbeam Works ::
When you activate Lightbeam and visit a website, sometimes
called the first party, the add-on creates a real time visualization of all the
third parties that are active on that page. The default visualization is called
the Graph view. As you then browse to a second site, the add-on highlights the
third parties that are also active there and shows which third parties have
seen you at both sites. The visualization grows with every site you visit and
every request made from your browser. In addition to the Graph view, you can
also see your data in a Clock view to examine connections over a 24-hour period
or in a List view to drill down into individual sites.
How You Can Use Lightbeam to Help Us Illuminate the Inner
Workings of the Web ::
As a part of Lightbeam, we're creating a big-picture view of
how tracking works on the Internet, and how third-party sites are connected to
multiple other sites. You may contribute your data to our crowdsourced directory
by simply turning on the share switch within the add-on. To disable
crowdsourcing, you can turn it off at any time. You can view your local data
stored within Lightbeam at any time, or save your data by clicking the
"Save" button under the data section on the left side of the add-on.
How is my information stored? ::
As a default, all info generated and used for Lightbeam’s
visualizations and features are only stored locally on your computer. You can
save a copy of your connection history at any time, which is also where you can
see the specific data collected by the add-on. You may also reset Lightbeam to
erase your locally stored connection history, disable it to stop data
collection or uninstall it to instantly remove all locally stored data related to
Lightbeam.








