HACKER NEWS




Indonesian president website defaced
Hackers crew Jember Hacker terrorists (JHT) deface the official website of Indonesian president (http://www.presidensby.info) with a message reads, “This is a PayBack From Jember Hacker Team”. Hackers deface website of president Susilo Bambang Yudhoyono (SBY) apparently in protest at growing corruption and wealth inequality in the country and because of increasing anger at the current administration. Deface page mention hacker code name as "MJL007" who performed the hack and government is working with law enforcement teams to examine log files in a bid to trace the origin of the attack. "Corruption is rampant, the poor are...

Warm up your keyboard for Facebook Hacker Cup 2013


Facebook Hacker Cup 2013
Dear Hackers, Warm up your keyboards! Because Facebook open Registration for third Hacker Cup 2013, an annual worldwide programming competition where hackers compete against each other for fame, fortune, glory and a shot at the title of world champion, with $5,000 top prize. The qualification round begins on January 25th. So Participate and enhance your programming competency. The dates have been set for Facebook Hacker Cup 2013Jan 7 — Jan 27 — Registration Jan 25 — Jan 27 — Online Qualification Round Feb 2 — Online Elimination Round 1 Feb 9 — Online Elimination Round 2 Feb 16 — Online Elimination Round 3 March 22 -23 — Onsite Finals at...

NASA 'Space your Face' domain hacked


nasa hacked
Another basic security loop-hole in NASA website lead to a Hack. This time hacker going by name "p0ison-r00t" deface a sub domain of NASA (http://spaceyourface.nasa.gov/). The hacked sub domain running a web application using flash, that allow visitors to create some funny videos of Space using Faces. Hacker able to upload his text on the website, as shown in screenshot taken by 'The Hacker News'. We contact hacker to know more about the hack, on asking How ? Hacker said,"I found a form on website, accepting file upload but without validating the extension, that allow me to upload a php shell on server". Hacker also said...

Israel preparing Cyber Iron Dome Shield


Israel preparing Cyber Iron Dome Shield
Israel's Prime Minister officially opened a new national program to train teenagers in the art of cyberwarfare. The program named "Magshimim Le'umit", is to prepare them for their future role in the military and intelligence community. Israel Prime Minister Binyamin Netanyahu said the country's computer systems are facing attacks from Iran and other countries, and such attacks are set to increase in the digital age. The new program will accept outstanding pupils aged between 16 and 18 and train them to intercept malicious attacks through a three-year course. Cyber security has become a national priority in Israel, with significant...

Chinese Hackers exploiting Internet Explorer Zero Day vulnerability for Cyber Espionage


Chinese Hackers exploiting Internet Explorer Zero Day vulnerability for Cyber Espionage
Web site for the Council on Foreign Relations was compromised and recently hit by a drive-by attack that was detected earlier this week. Hacker are suspected to be from China , who are exploiting a zero day  Internet Explorer vulnerability for Cyber Espionage attack against one of American most elite foreign policy web groups. According to Fireeye researchers, a malicious content on the website was hosted by hackers, that is exploiting Internet Explorer version 8.0 (fully patched version) to hack windows systems of visitors. "We have chosen not to release the technical details of this exploit, as Microsoft...

Team Ghostshell leaks 1.6 million accounts under #ProjectWhiteFox


team ghostshell
Team Ghostshell a Hacktivists group of hackers, who before was in news for hacking Major Universities Around The Globe and leaked 120,000 records, are once again hit major organisations and expose around 1.6 million accounts  Hacker name the project as #ProjectWhiteFox , means "Freedom of Information" . These leaked 1.6 millions user accounts belongs to aerospace, nanotechnology, banking, law, education, government, military, all kinds of wacky companies & corporations working for the department of defense, airlines and more. In a Pastebin Note hackers mention, "How we went from 'cyber-criminals' to 'hacktivists'...

Ministry of Justice of Qatar vulnerable to hackers


Ministry of Justice of Qatar
Hacker Going by name "human mind cracker" discovered SQL injection vulnerability in official website of Ministry of Justice of Qatar. He has successfully breached the database and dump it on internet. Exploited Domain : http://www.justice.gov.qa Hacker Mentioned no reason to hack this website in his note, neither any user information published. According to the note, he just expose the bug and exploit it using Boolean based blind injection to show Database structure including table names. There are about 10 Database available on server of Ministry of Justice of Qatar, that can have sensitive information...

#OpSyria : Teamr00t Hack Syrian Government Sites


Teamr00t Hack Syrian Government Sites
The Syrian government is almost certainly responsible for a blackout Thursday that shut down virtually all Internet service in the country. However, The Syrian government blamed the outage in internet service and mobile coverage in some areas on the armed groups' sabotage acts against cellular broadcast centers.Hacker with name Teamr00t has hacked and defaced Syrian government and showed their support for the people of Syria against President Bashaar Al-Assad's latest actions in shutting down the internet. Deface messagePresident Bashaar Al-Assad You have taken a step too far in shutting down the internet so the outside world cannot...

Lulzsec hacker Jeffrey could face Life Imprisonment


Lulzsec hacker Jeffrey could face Life Imprisonment
Lulzsec Hacker , Jeffrey Hammond faces a potential prison sentence of more than 30 years if found guilty of all charges filed against him. U.S. District Court chief judge Loretta Preska, who presided over a bail hearing for Hammond want last week. Hammond was also charged with using some of the stolen credit card data to help make $700,000 in unauthorized charges, and accused of participating in a hack of the Arizona Department of Public Safety website. "In early May 2012, a federal grand jury handed down a superseding indictment in the case against alleged LulzSec and Anonymous leaders, accusing Hammond of masterminding the LulzSec and...

Hackers break into International Atomic Energy Agency servers


Hackers break into International Atomic Energy Agency servers
The UN nuclear watchdog has acknowledged one of its former computer servers had been hacked. The stolen information was contained in a statement by a group with an Iranian-sounding name calling for an inquiry into Israel's nuclear activities. The International Atomic Energy Agency (IAEA) is investigating Iran's nuclear program. A group called Parastoo Farsi for the swallow bird and a common Iranian girl’s name claimed responsibility for posting the names on its website two days ago. The group had been known to be critical of Israel's undeclared nuclear weapons program. “The IAEA deeply regrets this publication of information stolen...

Java zero-day exploit sold in underground Market


Java zero day exploit sold in underground Market
Once again a zero day vulnerability exploit is sold by cyber criminals in the underground, once again a the flaw is related to Oracle’s Java software that could allow to gain remote control over victim's machine. The news has been reported by KrebsOnSecurity blog that announced that the exploit being sold on an Underweb forum. The vulnerability is related to the most recent version of Java JRE 7 Update 9, it isn't present in previous versions of the framework, in particular the bug resides within the Java class “MidiDevice according the info provided by the seller that describes it with following statements: “Code execution is very reliable,...

Anonymous Leak Emails from Syrian Ministry of Foreign Affairs


Anonymous Leak Emails from Syrian Ministry of Foreign Affairs
Anonymous Hacker managing Operation Syria (OpSyria) have released 1 GB of emails dump from Syrian Ministry of Foreign Affairs. Files are in files are in Arabic language. Documents includes scanned copies of Syrian ministers passports, details about an arms transport from Ukraine, report which shows that 200 tons of Syrian bank notes have been shipped from Russia. "Within the stash you will find details about cargo flights from Russia, each containing 30 tons of fresh Syrian Cash" Hackers said. "Furthermore you will find lulzy documents such as scanned passports from Syrian ministers (PDF) and details about arms transportation...

Anonymous Takes Down NISD Over Student Tracking


Anonymous Takes Down NISD Over Student Tracking
Hacker group Anonymous claims he took down North-side Independent School District's website (www.NISD.net) on Saturday to protest the district's use of tracking badges. On Sunday, Nov. 25, the same hacktivist released a statement via Pastebin giving the school district “1-3 days” to meet with parents and explain the student tracking program in detail. If the district fails to comply with the request, hacktivist promise to “simply shut down” the school district website once again. The hacker group also sent a Twitter message to the NISD account on Thursday, teasingly notifying them that their site was down....

TripAdvisor travel website infected with Gamarue malware, infect 2% Indian Internet Users


TripAdvisor travel website infected with Gamarue malware, infect 2%25 Indian Internet Users
TripAdvisor Inc., a hotel-review website, recently became a victim of the bug, said Trend Micro Inc., an Internet security solutions provider. Many of TripAdvisor’s users received spam mail with booking confirmations for hotels they had checked out on the website, 1.89% of Indian Internet Users have already been affected. The email purporting to be in the name of one of the Hotels has a similar theme to its English counterpart as it contains confirmation and details on an alleged booking reservation. TripAdvisor, which is among India’s top five travel brands as per digital market research firm ComScore Inc., globally has 60 million...

Go Daddy Sites Serve Up Ransomware Malware


PCEU malware
Domain name registrar and website hosting provider Go Daddy is responding to a DNS attack targeting a "small number" of its hosted websites that one security firm said is enabling cyber criminals to spread ransomware.  The DNS (Domain Name System) is what transfers host-names into IP addresses, meaning computers can talk to each other and users can access them online. Godaddy said, "We suspect that the affected customers have been phished or their home machines have been affected by Cool Exploit as we have confirmed that this is not a vulnerability in the My Account or DNS management systems." The Cool...

Narilam malware target Iran Financial SQL Databases


208193958
Symantec recently identified a database-corrupting piece of malware targeting systems mostly in Iran, but despite early speculation that it could be related to the likes of Stuxnet and Flame, it appears to be targeting small businesses rather than the country’s infrastructure. Malware Dubbed W32.Narilam, is predominantly active in the Middle East, and it has also been detected in the USA and UK. The worm looks for particular words in Microsoft SQL databases and overwrites them. The worm specifically targets SQL databases with three distinct names, alim, maliran, and shahd. Once the targeted databases are found, Narilam looks for...

XSS Vulnerability in Apple website


apple xss
A 16 years old Spanish Whitehat hacker going by name "The Pr0ph3t" found XSS Vulnerability on Apple website. The Vulnerability reported in Apple subdomain - https://locate.apple.com, where users can choose a service center location. About Cross site scripting : Cross-Site Scripting attacks are a type of injection problem, in which malicious scripts are injected into the otherwise benign and trusted web sites. The malicious script can access any cookies, session tokens, or other sensitive information retained by your browser. This vulnerability may be used by attackers to bypass access controls such as the same origin policy. After capturing HTTP...

Tunisians Voice - Nawaat Portal hacked


Nawaat hacked
Kosova Warriors Group deface a subdomain (http://events.nawaat.org/) of Nawaat Portal.. Its an independent collective blog hosted by Tunisians. It gives a voice to all those who, through their civic engagement, take the cover and spread. Our editorial decisions are guided by among other concerns that affect the lives of our countrymen and our fellow man. It seems that hacker is able to hack into the server and have control over two subdomains. After talking with hacker, we came to know that there is one more panel open for hackers at http://facebook.nawaat.org/ , where by default anyone is logging as admin user id. Zone-h...

Guadeloupe National Domain registrar hacked, Twitter & Google domain credentials leaked


domains
Guadeloupe is a Caribbean island located in the Leeward Islands, in the Lesser Antilles. Today a hacker going by name "UR0B0R0X" claimed to hack into the "Network Information Center Guadeloupe" (nic.gp), which is Guadeloupe National Domain registrar having control over domains of big companies like Google.gp, Paypal.gp, twitter.gp, Yahoo.gp,  and many more. Hacker claimed to hack server of nic.gp and leak credentials (encrypted) of 1271 Guadeloupe domains and user accounts including usernames, email addresses and phone numbers from server as shown via a paste-bin note. and complete database...

Pizza Hut defaced, Authorities denies theft of 240000 Credit Cards


Pizza Hut defaced
Yesterday Australian Pizza Hut website was compromised by a hacking group going by the name of 0-Day and Pyknic. Hackers defaced the website and claim that they made off with 260,000 Australian credit card numbers. Hack was 1st noticed by Whirlpool Forum users. But a Pizza Hut spokeswoman said the company did not store such information on its website. "Pizza Hut can confirm that a layer of its website, pizzahut.com.au, was breached with access gained to names and contact information, including email addresses". "We are working with our website providers to conduct a thorough investigation of the matter and have also reported the incident...