vineri, 3 februarie 2012

Company Security Staffers Warned About MSUpdater Trojan

Two of the leading companies in the security industry, Zscaler and Seculert, released a joint report as a result of a thorough investigation targeting a series of attacks that attempt to stay under the radar by sending fake Microsoft Windows Update HTTP requests.

The researchers reveal that another malware, identified as MSUpdater Trojan, is participating in these targeted attacks designed to hit organizations, including government-related ones.


Disguised as a file called msupdater.exe, the Trojan takes place in these malicious operations since 2010, but experts found occurrences of similar attacks since early 2009.

Most of the attacks that drop the above mentioned malware start with a simple email that invites company employees to conferences related to their field of activity, bearing a so-called invitation file that comes in the form of a PDF attachment.

By exploiting vulnerabilities that at the time were considered to be 0-day in Adobe Reader, the msupdater.exe file is dropped on the victim system along with other malevolent elements in a highly sophisticated manner.

Once it’s dropped on a system, the Trojan communicates with a command and control server with the purpose of downloading, uploading and executing files.

Since these attacks are designed to target only firms, staffers, especially the ones that handle company security, are advised to be on the lookout for such threats and take the appropriate measures.

Currently, the emails have been identified as coming in the form of an invitation to conferences such as the IEEE Aerospace Conference, Iraq Peace Conference, Intelligent Sensors, Sensor Networks and Information Processing (ISSNIP), and others depending on the organization’s profile.

Experts warn that these types of threats are usually persistent and they’re bound to exist undetected for long periods of time.

Security solutions providers offer products that mitigate advanced persistent threats (APTs), but sound security policies are also needed to make sure the malicious elements don’t infiltrate company networks.


news.softpedia.com

Organizers: This Super Bowl Is the Most Technologically Secure in History

Night-vision cameras, mobile gamma-ray scanners, explosion-proof manhole covers and an $18 million (12.5 million EUR) regional operations center. No, we’re not talking about the latest James Bond movie, instead we’re referring to this year’s Super Bowl, considered by the organizers “the most technologically secure Super Bowl in the history of the Super Bowl.”

WISH and Public Intelligence provide the details for the most important game of the year, programmed to take place on February 5 at the Lucas Oil Stadium in Indianapolis.


Besides the massive deployment of local and federal law enforcement representatives, the technological means that power this year’s security measures are extraordinary.

The Department of Homeland Security (DHS) is sending an unspecified number of gamma-ray cargo and vehicle scanners to secure the location of the event. The Mobile Vehicle and Cargo Inspection Systems (VACIS) are supposedly designed to reveal even the secrets that may hide behind six inches of steel.

Authorities give a friendly warning to attendees, advising them not to try to smuggle any illegal objects inside the stadium since they’re keeping a close eye on anything that enters and the chances to get by them are pretty slim.

The mobile gamma-ray command center will be housed in a 51-foot Featherlite trailer, provided to the DHS by Verizon, its total price being estimated at around $1 million (700,000 EUR).

At this event, nothing is left to chance. Even the manhole covers are being secured to make sure that a potential underground explosion won’t cause them to fly around, injuring people and damaging vehicles.

Special covers that cost some $150,000 (105,000 EUR) were installed. These Swiveloc locking manhole covers are designed to lift a couple of inches off the ground, allowing potentially dangerous gases to come out, but not enough to feed in oxygen which would make the explosion even bigger.

A number of 75 night vision cameras were installed by the DHS and the FBI in the city and around the stadium, allowing authorities to access them from anywhere, including cars and helicopters.

The cherry on top of this magnificent cake is represented by the Regional Operations Center (ROC) which will serve as a fusion center for coordinating the various agencies responsible with making sure that incidents will be avoided.

All we can say now is: let the games begin!



news.softpedia.com

Counterclank Stays on Android Market, Symantec Gives More Explanations

After mobile security firm Lookout argued that Android.Counterclank is not a piece of malware as Symantec labeled it, the latter came forward with some new arguments to sustain their initial decision of informing users on the potential dangers.

Symantec’s update on the matter reveals that even Google decided that the apps met their Terms and Service conditions and their removal from the Android Market was unnecessary. Even the developers accused of serving malicious apps came forward to deny that their products represent malware.


“WE ARE NOT MALWARE!! Symantec, the company that wrongly labeled this app as malware the other day, have contacted us and are in the process of un-doing the mistake they did and whitelabling our product,” the developers write on Android Market.

On the other hand, Symantec explains that they maintain their initial arguments, claiming that they want to keep users informed on the behaviors of some applications that may pose a threat to regular users.

“The situation we find ourselves in is similar to when Adware, Spyware, and Potentially Unwanted Applications first made appearances on Windows. Many security vendors did not initially detect these applications, but eventually, and with the universal approval of computer users, security companies chose to notify users of these types of applications,” they said.

Now, they bring further details to support their initial arguments around the dangers presented by the applications in question.

They reveal that Tonclank and Counterclank apps come from the same vendor, a company that distributes an SDK to third parties with the purpose of helping them monetize their applications, mainly through search.

So exactly what do these apps do if installed on an Android phone?

First, they connect to a remote server and send information such as the device’s IMEI, data to identify the application that uses the SDK, device information, including OS version, display metrics, language preferences, and browser user agent.

After receiving this information, the application waits for commands from the remote server. These commands can cause the application to display a certain webpage, set the browser’s homepage to an arbitrary page, create or request bookmarks, and place shortcuts on the home screen.

Some users provided negative feedback regarding these apps and since the vendors didn’t inform their customers on the privacy implications, Symantec decided to notify people of Counterclank.

While the parties involved resolve the issue, users are advised to take the behaviors detailed by Symantec into consideration before installing the following apps: Counter Elite Force, Counter Strike Ground Force, CounterStrike Hit Enemy, Heart Live Wallpaper , Hit Counter Terrorist, Balloon Game, Deal & Be Millionaire, and Wild Man.

The complete list of names and vendors is available here.


news.softpedia.com

A Cyber Arms Race Is Currently Taking Place, 57% of Experts Say

A recent study commissioned by McAfee and produced by the Security & Defence Agenda (SDA), a Brussels-based defense and security think-tank, reveals the opinions of policy-makers and cyber-security experts in government, business and academia from 35 countries on the currently existent cyber threats and the measures that can be taken to mitigate them.

The figures from the report entitled Cyber-security: The Vexed Question of Global Rules show that 57% of experts believe that an arms race is taking place as we speak in cyberspace.


Some 36% say that cyber security is more important than missile defense and 45% even claim that it’s just as important as border security. Around 42% think that a potential attack on critical infrastructures is a major threat that could have wide economic consequences.

Interestingly enough, the report reveals that countries such as Finland, Israel, Sweden are far better prepared in case they’re targeted by a cyberattack, compared to China, Russia, Australia, the US, Italy, the UK and Poland.

“The core problem is that the cyber criminal has greater agility, given large funding streams and no legal boundaries to sharing information, and can thus choreograph well-orchestrated attacks into systems,” says Phyllis Schneck, vice president and chief technology officer, Global Public Sector at McAfee.

“Until we can pool our data and equip our people and machines with intelligence, we are playing chess with only half the pieces.”

While most experts agree that smartphones and cloud computing raise a completely new set of issues regarding security, more than half of them also reveal that in their opinion there is a shortage of cyber workforce.

When it comes to cyber security exercises, only 20% of the respondents have taken part in such drills, even though they’re considered highly important by most.

Finally, many consider that global treaties are an essential factor in the development of efficient policies, but some believe that they’re impractical because treaties are hard to verify and enforce.


news.softpedia.com

The Truth About ACTA and the Inaccurate Protest Arguments

The Anti-Counterfeiting Trade Agreement, or ACTA as many of us know it, is highly debated and protested against these days, but few know that a lot of the anti-ACTA arguments are highly inaccurate.

Since the Stop Online Piracy Act (SOPA) was abandoned, Internet users from all over the world turned their attention to the latest controversial agreement that was already signed by a large number of countries worldwide, including European Union member states.


Ars Technica reveals the most common inaccurate arguments used by the highly determined protestors. As they inform us, few people know that most of the outrageous motives used by anti-ACTA protestors are actually part of some older drafts that are no longer present in the final form of the agreement.

One of the most common inaccurate claims is that ACTA will allow Internet Service Providers (ISPs) to monitor all our internet traffic.

Many readers will probably argue that this is nothing new, many ISPs already monitoring much of our traffic, but the fact of the matter is that in reality ACTA will not empower them more to follow such practices.

Some earlier variants did propose measures similar to the French “three strike” law, which would require traffic monitoring, but the final version only requires participating nations to “promote cooperative efforts within the business community to effectively address trademark and copyright or related rights infringement while preserving legitimate competition and, consistent with that Party's law, preserving fundamental principles such as freedom of expression, fair process, and privacy.”

States could choose to monitor all the traffic of Internet users, such as in France, but they could implement other measures that would not be so draconic, especially considering the fact that they have to preserve the fundamental principles.

Another exaggerated argument is that generic drugs and seeds could be seized in the name of patents while they’re being transported from one country to the other, thus endangering the lives of ill people and leaving thousands without food.

This is partly true, but most protestors say that ACTA will actually completely ban generic drugs and seeds, which is highly untrue.

ACTA will not totally ban generic drugs and seeds, but it does increase “the risks and consequences of wrongful searches, seizures, lawsuits and other enforcement actions against legitimate suppliers of generic medicines.”

This means that generic drug suppliers will have to modify the appearance of their products so they can’t be confused with corresponding name-brand drugs.

The third argument is that ACTA is very similar to SOPA and PIPA when it comes to blacklisting sites from DNS, search engines, payment methods and ad networks, but in reality, the agreement doesn’t contain these proposals.

“ACTA's Internet provisions are plainly not as bad as those contemplated by SOPA. Over the course of several years of public protest and pressure, the Internet provisions were gradually watered down with the removal of three strikes and you're out language,” said Michael Geist, a Canadian copyright scholar and ACTA critic.

“Other controversial provisions on statutory damages and anti-camcording rules were made optional rather than mandatory.”

Finally, one erroneous argument claims that ISPs are forced to constantly check for copyright infringing materials on their servers and even parts of sentences could be protected and “made prescript by copyright,” but in reality, there is nothing in ACTA to say that user-generated materials need to be monitored for infringing material.

Unfortunately, after the 22 countries signed the agreement in Tokyo last week, a lot of state representatives proved that they had no idea what so ever what ACTA was all about. A perfect example is Romania, where politicians haven’t got the slightest clue about the controversial agreement, most of them voting for it just to vote differently than the ruling party.

Protests aren’t a bad thing. They’re a good way of showing world leaders that they can’t take decisions without consulting the masses. They’re also a good way of making sure that decisions can’t be made only to favor certain companies with certain interests, but it’s just as important to know precisely what we protest against.

The bottom line is that ACTA is certainly a bad thing, an agreement secretly made by wealthy countries with the purpose of watching out for their personal interests.

It has many downsides for the everyday Internet users and for the citizens of certain countries, but let’s not make people panic without legitimate reasons, because then it would be like sending spam messages such as the ones that say Facebook is about to start charging members.


news.softpedia.com

Code 2600: A Hacking Documentary

Following the success of his debut documentary feature, Land of Confusion, award winning Pittsburgh filmmaker Jeremy Zerechak is already garnering early accolades for his newest project, CODE 2600. The film—a no-holds-barred look at the ramifications of the Information Technology era—has been selected from to have its world premiere at the 2012 CINEQUEST FILM FESTIVAL (February 28th – March 11th) in San Jose, CA. Appropriately located in the heart of silicon valley, CINEQUEST is one of the country's top film festivals—a 13-day event of 200 international films with over 600+ film artists, technologists, and professionals from 44 countries in attendance.

CODE 2600 documents the rise of the Information Technology Age as told through the events and people who helped build and manipulate it. The film explores the impact this new connectivity has on our ability to remain human while maintaining our personal privacy and security. As we struggle to comprehend the wide-spanning socio-technical fallout caused by data collection and social networks, our modern culture is caught in an undercurrent of cyber-attacks, identity theft and privacy invasion. Both enlightening and disturbing, CODE 2600 is a provocative wake-up call for a society caught in the grips of a global IT takeover. 
 
 
 
Born out of curiosity and compulsion, CODE 2600 wasn’t about making a film that simply told the story of the computer revolution,” said Zerechak. “It is a journey that explores the eras and events that led up to modern society’s current love affair with technology and all the dangers that come with being wildly in love.

It seemed that although most of the modern world now rested on a digital platform, few people understood how it all worked or, more importantly, about the perils that lurked behind their addictive personal tech devices and the implications of their ignorance. Moreover, the history of hacking and the Internet was, by cinema standards, an untold epic tale full of great characters, events, and David-Goliath-battles.

CODE 2600 will be screened at the Camera 12 Theatre, located at 201 South Second Street, San Jose, CA 95113. For tickets and information, please visit http://www.cinequest.org
 
 
thehackernews.com

HBGary Federal One Year Later !

Doug Vitale sharing and interesting read with our Readers from his Blog About HBGary Federal.

In February 2011, the loosely knit collective of hacktivists known as Anonymous successfully compromised the corporate network of HBGary Federal (HBG Fed), a company that provided information security services to the federal government of the United States. This attack brought down the HBGary Federal website, compromised the Twitter and LinkedIn accounts of HBGary Federal CEO Aaron Barr, and resulted in the public release of thousands of internal documents and emails.

Aaron Barr believed he had penetrated Anonymous. The loose hacker collective had been responsible for everything from anti-Scientology protests to pro-Wikileaks attacks on MasterCard and Visa, and the FBI was now after them. But matching their online identities to real-world names and locations proved daunting. Barr found a way to crack the code.In a private e-mail to a colleague at his security firm HBGary Federal, which sells digital tools to the US government, the CEO bragged about his research project.

They think I have nothing but a heirarchy based on IRC [Internet Relay Chat] aliases!” he wrote. “As 1337 as these guys are suppsed to be they don’t get it. I have pwned them! : )”  But had he?

On February 6, 2011, the HBG Fed website was wiped out and replaced with a message from Anonymous .Barr’s Twitter and LinkedIn accounts were taken over and used to disseminate messages that were derogatory against him, and which also included his cell phone number, his home address, and his Social Security number. Not surprisingly, Barr began receiving threats and prank calls.As if these breaches weren’t enough, a treasure trove of HBG Fed’s internal emails over 60,000 of them was released for public download. In fact, the very document that HBG Fed had been planning to sell to the FBI as some sort of intelligence report was also made available and criticized by Anonymous for being inaccurate. Additionally, Anonymous hackers acquired data backups and deleted HBG Fed’s copies.
 
thehackernews.com

Syrian president’s e-mail hacked by Saudi hackers

According to report received to THN editorial, A hacker based out of Saudi Arabia, identified as Salman Al Anzi, claims to have hacked the private email account of Syrian president Bashar Al Assad. He also hack a number of Syrian ministries, the Al-Arabiya TV Channel. The hacker threatened to reveal Assad's personal correspondence containing scandalous facts if the president doesn't meet his requirements.

According to the city Saudi Arabia, the hacker threatened to Bashar al-Assad download scandals and scandals of his aides and Iran's support for him, and copies of e-Bashar by secret ballot, with said hacker to the size of these scandals, 4 GB, gave the hacker the Saudi ultimatum to President Bashar al-Assad for the implementation of conditions, and only carried out what threatened him.

The wave of threats from the hacker, Israeli sources said that a Saudi, and announced several thwarted attempts to penetrate the sites belonging to the Ministries of sovereign Israel, where he succeeded hacker Saudi Arabia's alleged access to a page, Deputy Israeli Foreign Minister Danny Ayalon and wrote down: "I apologize to you Danny, I'm not a man You can not and Stand ".

The Syrian government said more than 2,000 army and security personnel were killed during the months-long unrest, while the UN puts the death toll at more than 5,400.

According to Al Madina newspaper , the hacker submitted some demands to the Syrian regime, most importantly to stop the killings of Syrians immediately and give up power.The hacker threatened Bashar Al Assad that he would publishing top secret information accessed from the email - such as the Iran's support for him.The hacker is alleged to have given a deadline to President Bashar Al Assad which he has not made public.


thehackernews.com

miercuri, 1 februarie 2012

Gov.uk service portal opens for public testing



A website which aims to bring government services together under a single web address has been launched as a public trial.

The gov.uk project, which is expected to launch in full later this year, has a budget of £1.7m.

Currently, online government services are spread across multiple domains and managed by different teams.

The government claimed that bringing services together in this way could save up to £50m per year.

This saving is said to come from making operational savings by "removing the costs associated with software licences and infrastructure investment".

However, when contacted by the BBC, the Cabinet Office could not give specific details over where those savings would be made.

The site uses a simple search engine-like interface to tie the government's vast portfolio of websites together.

Users have been invited to test the new website and report any bugs or usability issues.

The website advises that while gov.uk is fully-functional, some aspects may be "inaccurate or misleading" while still in the beta stage.

'Simple to use'

The Cabinet Office told the BBC that the full public release of gov.uk was planned for some time later this year once extensive user testing and feedback had been gathered.

A decision over what will happen to the government's existing portal -directgov - has not yet been made.

"Digital public services should be easy to find and simple to use," said Francis Maude, Minister for the Cabinet Office, in a press release.

"The beta release of a single domain takes us one step closer to this goal.

"Our approach is changing. IT needs to be commissioned or rented, rather than procured in huge, expensive contracts of long duration.

"We are embracing new, cloud-based start-ups and enterprise companies - this will bring benefits for small- and medium-sized enterprises here in the UK and so contribute to growth."'Pretty looking icon'

The UK's "digital champion", Martha Lane Fox - who has been asked to find ways to get more people online - welcomed the revamp.

"The beta release of gov.uk is a fantastic milestone in this government's ambition to become a digital world leader and dramatically change the focus of public service delivery onto the end user," she said.

However, Geoff McCormick, director of the UK-based design company TheAlloy, said the revamp did little to solve existing problems.

"The new gov.uk site is an improvement on the direct.gov site, but the bar wasn't set too high in the first place," he told the BBC.

"Once you have navigated away from the front page, it is back to business as usual - the same information architecture, but with a 'pretty looking icon' next to it.

"They do not make it easier to navigate in any way."

Apple petitioners tell firm to protect Chinese workers


An online petition, signed by 154,000 people, has called on Apple to do more to ensure its Chinese factory workers are treated better.

The campaign, on Change.org, follows reports of poor working conditions in factories that make Apple products.

A separate SumOfUs petition, with more than 43,000 signatories, calls for the iPhone 5 to be made "ethically".

Apple acknowledged the demands. Its chief executive earlier said it cared about every worker in its supply chain.

The Change petition was organised by Washington-based communications worker Mark Shields.

It calls on Apple to "release a worker protection strategy for new product releases", saying that injuries tend to spike at times when staff are under the most pressure.'Moral responsibility'

It also praises Apple's commitment to allow the non-profit Fair Labor Association to monitor the suppliers, but urges the company to publish the results with details of where each identified violation occurred.

The SumOfUs movement focuses its efforts on the firm's next major smartphone update.

"Every time a Foxconn worker is killed or disabled making an Apple product, Mr Cook bears personal moral responsibility," wrote Taren Stinebrickner-Kauffman, the campaign's executive director.

"Apple is going to have much bigger longer-term problems than paying a few extra dollars for its products if it loses its lustre with ethical consumers," she added.

The petitions follow a New York Times investigation into working conditions in Chinese factories used by Apple.

An anonymous Apple executive told the paper that the firm just had to say the word to bring about change.

"Suppliers would change everything tomorrow if Apple told them they didn't have another choice," he is quoted as saying.

It prompted a company-wide email response from Apple's chief executive, defending the firm's position.

"Any accident is deeply troubling, and any issue with working conditions is cause for concern," Tim Cook wrote.

"Every year we inspect more factories, raising the bar for our partners and going deeper into the supply chain. As we reported earlier this month, we've made a great deal of progress and improved conditions for hundreds of thousands of workers," he added.

The company also referred the BBC to its most recent Supplier Responsibility Progress Report.

The document says that Apple conducted 229 audits throughout its supply chain in 2011. It says that is an 80% increase on 2010, including more than 100 first-time audits.Suicide attempts

The issue about overseas working conditions hit the headlines two years ago when 137 workers at Apple supplier Wintek in eastern China were injured after they used a poisonous chemical - n-hexane - to clean iPhone screens.

Last year four workers were killed in two separate explosions at factories manufacturing iPads.

Taiwanese factory owner Foxconn, which employs an estimated 1.2 million workers in China, has come in for some of the closest scrutiny, amid claims that at least 18 of its workers have attempted suicide over the past two years.

The New York Times recently reported workers' accounts of 20 people being "stuffed" in a three-room apartment and a riot set off by "a dispute over paychecks".

It also noted that Apple's previous audits had turned up cases of under-age workers and staff being paid less than the minimum wage at unspecified locations.

The paper said that Foxconn disputed the accounts of crowded living accommodations and the causes of the riot, and said that it had "never been cited by a customer or government for under-age or overworked employees or toxic exposures".

Apple tends to be singled out because of the huge profits it makes - and many of the other big tech firms outsource manufacturing to Foxconn and other Chinese suppliers.

Despite recent reports, workers in China do not appear to have been dissuaded from applying for jobs at the firms.

China's CUTV station recently reported that Foxconn's efforts to recruit an additional 100,000 workers to its Zhengzhou campus attracted long queues of young jobseekers, including staff from one of its Shenzhen plants.

TripAdvisor rebuked over 'trust' claims on review site



TripAdvisor has been ordered to rewrite some of its marketing claims by the UK's Advertising Standards Authority.

The ruling follows complaints by hotels that the site had said that its holiday reviews could be "trusted".

The ASA said it was concerned that consumers might be fooled by fraudulent posts since the entries could be made "without any form of verification".

TripAdvisor described the ruling as a "highly technical view" of "copy that was used in a limited capacity".

However, the watchdog said that the ruling served as a warning to all UK-focused sites with user-generated material.Fraud systems

The ASA said that the US-based firm's site originally carried statements saying that it contained "reviews that you can trust" and that it had "more than 50 million honest travel reviews".






It said that two hotels and the online reputation firm Kwikchex, which represented others, had complained that the claims were misleading since they could not be substantiated.

The advertising body said it acknowledged that reviewers were asked to sign a declaration that their reviews were real and that they had no incentive or competitive interest with the places commented on.



It also recognised that the site said that it used "advanced and highly effective fraud systems" to identify and remove fake content.

However, the ASA said it was still possible that "non-genuine" reviews could appear on the site undetected and that users might not be able to spot them.

It warned that this was particularly a problem in cases where an establishment only had a small number of reviews. It added that offering hoteliers a right to reply did not fully address the problem.

The ASA ordered the site to avoid running adverts in the same form again and said it must not claim or imply that all its reviews were from real travellers, or were honest, real or trusted.

"This should be regarded as a benchmark ruling which applies to all web sites which make claims about the reliability of their user-created content," the ASA's spokesman Matthew Wilson told the BBC.

Chief executive Guy Parker said that advertising rules policed by the authority applied to companies' claims on their own websites.

"This is a classic example of the sort of thing that members of public are complaining to us about," he said.

"Advertisers must apply the same scrutiny to their websites, as they do to their campaigns in paid-for space. And don't major on trustworthiness if fake reviews can appear."





The pros and cons of having your business reviewed on TripAdvisor: Published January 2012

The ASA's ruling was based on a survey of the site carried out in July 2011 when it was still owned by the travel booking service Expedia.

It has since been spun off as a separate entity. The current management downplayed the risk of customers being misled.

"We have confidence that the 50 million users who come to our site every month trust the reviews they read on TripAdvisor, which is why they keep coming back to us in increasingly larger numbers to plan and have the perfect trip," it said in a statement.

The tripadvisor.co.uk homepage now contains no reference to the word "trust" and simply describes itself as "the world's largest travel site".

However, its international tripadvisor.com address - which is accessible in the UK - continues to describe its content as the "world's most trusted travel advice" in the corresponding part of the page. It adds elsewhere that "you'll find real hotel reviews you can trust".

When asked about this the ASA said that its remit only extended to claims targeted at a UK audience, so it would not be pursuing changes at the .com site.

Βρήκατε το site σας hacked; ... Πιστεύετε ότι αυτό είναι όλο;

Βρήκατε το site σας hacked;
Πιστεύετε ότι αυτό είναι όλο;
Αυτό που δεν ξέρετε είναι ότι αυτός που έχει εισέλθει στην ιστοσελίδα σας μπορεί να άφησε περισσότερο από ένα index!



Insider θέλει να προειδοποιήσει τους ιδιοκτήτες ότι υπάρχει κίνδυνος και κανείς δεν μιλάει

Όταν κάποιος έχει πρόσβαση στα αρχεία της ιστοσελίδας σας μπορεί να κάνει ό, τι θέλει και αυτό περιλαμβάνει ανέβασμα / κατέβασμα αρχείων
Θα παρουσιάσω μερικές από τις πιθανές ενέργειες που μπορεί να κάνει ένας χάκερ στο τερματικό σας:



  •      Η πιο απλή και ορατή δράση την αλλαγή ή αντικατάσταση του index ώστε να αποδείξουν ότι είχαν πρόσβαση
  •      Μια άλλη επιλογή είναι για τους εισβολείς να αντιγράψουν τα πάντα  ή να κλέψουν τα σημαντικά πράγματα και η ζημία είναι μεγαλύτερη από μια απλή ... You are hacked by ... ...
  •      Αυτό που πολλοί αγνοούν και είναι πολύ σοβαρό είναι ότι ο εισβολέας μπορεί να χρησιμοποιήσει το χώρο για  δράση ενάντια σε άλλους δικτυακούς τόπους ή ανθρώπους. Μπορεί να φορτώσει στον host  μεθόδους για να κλέψουν τα προσωπικά δεδομένα των ατόμων που επισκέπτονται το site, ή να χρησιμοποιεί το χώρο υποδοχής για:
                                                            Stealer / Keyloger / Phishing / Rat
                                                          / Botnet / DDosser /  Shell

 
Τα παραπάνω είναι αρκετά επικίνδυν
α, γιατί αν βρεθούν ... Είστε ένοχοι επειδή είναι στο χορό σας και για να ξεφύγετε θα πρέπει να το αποδείξετε μπροστά στο νομο

Για την καλύτερη κατανόηση έχω ένα πολύ ενδιαφέρον παράδειγμα


http://www.voiceofnigerians.com/







Εάν το index δεν θα είχε αλλαχτεί θα ήταν μια απλή ιστοσελίδα ... και τώρα όταν βλέπετε μπορείτε να πείτε ότι είναι μια απλή hacked ιστοσελίδα

Αλλά ... κοιτάξτε εδώ


 http://www.voiceofnigerians.com/Main/



Αυτά είναι όλα τα αρχεία ενός ιού που ονομάζεται SpyEye ... virus με το οποιο o χάκερ μπορεί να κλέψει  προσωπικά δεδομένα, όπως πιστωτικές κάρτες, προσωπικούς λογαριασμούς, ... αλλά επίσης χρησιμοποιείται για επιθέσεις εναντίον άλλων sites/forums

Γι 'αυτό δεν είναι αρκετό για να δείτε αν το site σας είναι online .... επιθεωρήστε τα αρχεία σας όσο συχνά μπορείτε και αν δεν ξέρετε ... ζητήστε βοήθεια για να έχετε ένα ασφαλή site/forum για να μην μπείτε σε μπελάδες



 Stay close and you wiil see more



Prodefence.org

Found your site hacked ? ... Do you think that's all?


Found your site hacked ?
Do you think that's all?
What you do not know is that he who has entered in your site can leave little more than an index!



Insider  wants to warn site/forum owners that there's danger and no one speaks

When someone has access to site files can do whatever he wants and that includes uploading / downloading files
I will present some of the possible actions that can be a hacker in your host:



  • The simplest and visible action is changing or replacing index show that's all he had access
  • Another option is for intruders to copy everything found or steal important things and such damage is greater than a simple ... You are hacked by ...
  • What many ignore and is very serious is that the intruder can use the site for action against other websites or people. He can load on the host diferent hacking methods to steal personal data of those who visit the site, or use the host site for:
                                                         Stealer / Keyloger / Phishing / Rat
                                                         Botnet's / DDosser's/ Shell's

The above are quite dangerous because if they are found ... you are guilty because it's your host and to escape the trouble you have to fight with the law

To better understand i have a very interesting example

http://www.voiceofnigerians.com/




if the index would have changed would be a simple site ... and now when you see you can tell it's a simple hack

But ... look here

http://www.voiceofnigerians.com/Main/




These are all files of a virus called SpyEye ... virus that hackers steal personal data such as credit cards, personal accounts, ... but also is used for attacks against other sites



So it is not enough to see if your site is online .... inspect your files as often as you have and if you do not know ... ask for help to have a secure site not to get into trouble

Stay close and you wiil see more




Prodefence.org