Report

YouPorn passwords available for download, thousands of users exposed [Updated]

Published: February 23, 2012 Reading time: 2 min

SophosLabs: Want a free password for one of the world’s most popular adult websites? YouPorn, one of the world’s most popular porn video websites and one of the top 100 websites of any kind in the world, appears to have been caught with its pants down – after a list of many of its users’ email addresses, passwords and dates of birth were left exposed on a public-facing server. ...

Continue Reading

Chinese hackers had free rein at Nortel

Published: February 15, 2012 Reading time: 2 min

The H-Online: According to a report, hackers, allegedly from China, had access to telecoms equipment manufacturer Nortel‘s IT systems over a period of several years – access that they took full advantage of. Citing an internal investigation, the Wall Street Journal reported on Tuesday that, using seven passwords stolen from senior managers, intruders had access to almost all confidential information within Nortel from 2000 onwards. Brian Shields, the manager who led the Nortel investigation, is quoted as saying that the hackers “had access to everything”. Huge volumes of technical documents, research and development (R&D) reports, business plans and emails were downloaded over the course of several years. “They had plenty of time,” said Shields, “All they had to do was figure out what they wanted.” The seven stolen passwords included the password belonging to the company’s then CEO. The attackers have not been identified, but the WSJ notes that they appear to have been working from China. ...

Continue Reading

350,000 users exposed by hacking porn mavens Brazzers

Published: February 13, 2012 Reading time: 2 min

SophosLabs: A hacker, identified as a 17-year-old based in Morocco, claims to have stolen the personal information of 350,000 users from hardcore porn mavens Brazzers. The point, claims the hacker, was to highlight a security vulnerability on the adult site. According to reports, the teen uploaded a small small of the stolen data to the internet, displaying customer emails, usernames and passwords. Presumably to offer up proof that he was behind the breach. ...

Continue Reading

Beware of spam this Valentine's Day

Published: February 13, 2012 Reading time: 2 min

SophosLabs: It’s Valentine’s Day tomorrow and the spammers are out in force to make the most of unwitting shoppers on the international day of love. Looking to buy a present for someone this Valentine’s Day? Ooh look what popped into my inbox, an email inviting me to buy my Valentine an *ahem* “romantic” gift. Valentine's Day, the 14th February, is the day we celebrate our feelings of affection for our boyfriends, girlfriends, husbands and wives. It is traditional to do this with a special romantic gift. Looking for a Valentine's Day Gift for him or the perfect token of love for her? Look no further than here! ...

Continue Reading

"NASA Own3d Again" – NASA Database Leaked by r00tw0rm

Published: February 12, 2012 Reading time: 1 min

The Hacker News: Hackers from Team r00tw0rm again hit NASA. According to Latest tweet by Hackers, They claim to hack the one of the Sudomain of Nasa (Link is not exposed by hackers and claimed to be reported for Fix). Hackers claim to hack GB’s of database and they Leaked sample of database include Users names, emails and Passwords , Contact as shown: ...

Continue Reading

Microsoft Store India got hacked in India!

Published: February 12, 2012 Reading time: 1 min

The Hacker News: Today, Hackers from group EvilShadow successfully hack and deface the website of Microsoft Store India (http://www.microsoftstore.co.in) . But Hacker upload his deface page at location http://www.microsoftstore.co.in/evil.html . Hacker revealed that user passwords were saved in plain text as shown below:

Continue Reading

Microsoft to send users 4 critical patches on Valentine's Day

Published: February 12, 2012 Reading time: 2 min

The Register: Microsoft plans to publish nine updates next Tuesday – four of which are critical – as part of a Valentine’s Day edition of its Patch Tuesday update cycle. Highlights of the batch, which collectively address 21 vulnerabilities, include a critical update for Internet Explorer. There are also two critical fixes for Windows itself, plus one for Microsoft’s .NET framework. Three the five remaining “important” fixes grapple with remote code execution-type vulnerabilities, one of which involves Office. Flaws of this type are best addressed sooner rather than later because they might easily be exploited by malware slingers. ...

Continue Reading

Hacker claims to have compromised Intel

Published: February 12, 2012 Reading time: 2 min

The Inquirer: A Hacker using the pseudonyms ‘Weedgrower’ or ‘X-pOSed’ claims that he has compromised Intel and obtained sensitive data. The solo hacker claims to have found a flaw in the subscriber segment of Intel’s web site, according to The Hacker News. He said that he has access to sensitive data that includes credit card numbers, email addresses and passwords. Weedgrower said, “I’ve got to give some applause to all these pseudo-security technicians out there. I cut Intel a break, I have access to a database and another vulnerability which enables the right to read user data. I’ll be gracious here and NOT spill the data, but I will provide screenshots to prove that I have access to Credit Card data and such.” ...

Continue Reading

CIA website brought down – were Anonymous attackers responsible?

Published: February 11, 2012 Reading time: 3 min

SophosLabs: The CIA’s website was brought down for some hours last night by what appears to have been an internet distributed denial-of-service (DDoS) attack. A post made from an Anonymous-affiliated Twitter account announced that the site was doing using the phrase “CIA Tango Down”, although a later tweet left ambiguity as to whether the hacktivists were claiming responsibility for the attack. Of course, this is one of the challenges when trying to get a sense of what actions can be attributed to Anonymous or not. ...

Continue Reading

Dutch ISP KPN hacked, credentials and personal information leaked

Published: February 11, 2012 Reading time: 2 min

SophosLabs: One of the largest ISPs in The Netherlands has shut down its email services after hackers posted usernames, passwords, phone numbers, addresses and more of more than 500 customers on the internet. KPN discovered the attackers on its network January 27th, but decided not to disclose the information immediately after consulting with the Dutch government and law enforcement agencies. Presumably this was intended to allow them to monitor the attacker and gather evidence that might be used to apprehend and prosecute them. ...

Continue Reading

No further updates for Debian 5.0 Lenny

Published: February 10, 2012 Reading time: 1 min

The H-Online: The Debian developers have pointed out, in an announcement on the debian-announce mailing list, that – three years after it was released –Debian GNU/Linux 5.0 (Lenny) has reached its “End of Life”. Debian GNU/Linux 5.0 was originally released in February 2009 and on 6 February 2012, the developers stopped providing security updates for that version of the distribution. Users have now had a year to update their systems to Lenny’s successor, Squeeze, which was released on 6 February 2011. The Debian developers recommend that any installations that are still using Debian 5.0 should be updated to version 6 of the distribution immediately. The Debian community recently released version 6.0.4 of Debian Squeeze which includes all the updates that have been released for Squeeze since its release.

Continue Reading

63 Vulnerabilities on United Nation Website Exposed Online

Published: February 10, 2012 Reading time: 2 min

The Hacker News: Latest Notification in The Hacker News Vault by a Hacker named “Xenu (Casi)” from r00tw0rm Team that There are 63 Blind SQL injection Vulnerabilities exist on United Nation’s Website (www.un.org). Blind SQL injection is identical to normal SQL Injection except that when an attacker attempts to exploit an application rather then getting a useful error message they get a generic page specified by the developer instead. This makes exploiting a potential SQL Injection attack more difficult but not impossible. An attacker can still steal data by asking a series of True and False questions through sql statements. ...

Continue Reading

LinkedIn Hits 150 Million Members

Published: February 10, 2012 Reading time: 1 min

Mashable: LinkedIn on Thursday announced it has 150 million members in its network, a 20 million increase over November. The figure was disclosed in a press release the company issued Thursday announcing its fourth quarter and full-year 2011 results. The company posted revenues of $167.7 million, beating the analysts’ consensus of $160 million for Q4. Adjusted profit was $0.12 cents per share, which beat analysts’ projections of 7 cents a share. LinkedIn’s stock was up more than 5% in after-hours trading. ...

Continue Reading

Is Digital Pearl Harbor THE most tasteless term in IT security?

Published: February 10, 2012 Reading time: 3 min

SophosLabs: Can hackers really cause as much bloodshed as 353 Imperial Japanese Navy fighters, bombers and torpedo planes launched from six aircraft carriers? Can hackers really kill 2,402 U.S. citizens, leave 1,282 wounded, lose 65 of their own attackers in the process, and plunge the United States into a World War? Heaven only knows. Maybe they can. The lack of security around Supervisory Control And Data Acquisition (SCADA) systems is scary. ...

Continue Reading

Foxconn hacked by Swagg Security

Published: February 9, 2012 Reading time: 2 min

The H-Online: Hackers operating under the name Swagg Security have said they were responsible for breaching the security of Chinese electronics manufacturer Foxconn. In a posting on Pastebin, the group took credit for penetrating the systems, noting that “Foxconn did have an appropriate firewall, but fortunately to our intent, we were able to bypass it almost flawlessly”. The posting pointed to a 6.5 MB torrent on The Pirate Bay which contained what appears to be CSV file dumps of database tables and other text files. The files included lists of what look like customer names, accounts and plain text passwords though many of those passwords are “foxconn” or “foxconn2”. ...

Continue Reading