Sunday, January 22, 2012

Wikipedia Released Their Official Application For Android



Today Wikipedia announced the availability of their official Wikipedia Application for Google's open source Android mobile operating system also known as Android 4.0, Ice Cream Sandwich (ICS). With the new app for the online encyclopedia users can search the entire Wikipedia site as well as find articles for nearby points of interest. Articles can be saved to a user's device for offline viewing or shared using the Android "Share" function, allowing users to send an article via, for example, email or text message. Previously Wikipedia released their official application "Wikipedia Mobile" for iTunes App Store, iOS devices like the iPhone. 
The official Wikipedia app for Android is available to download from the Android Market and requires Android 2.2 "Froyo" or later.  



Koobface Malware Gang Exposed & Comamnd and Control (C&C) Servers Stopped



We are quite sure that Facebook user will never forget the dangerous malware named "Koobface". According to facebook security team it was the most dangerous malware ever made to infiltrate Facebook made by few Russian hacker. The hackers, known as the Koobface gang, sent Facebook users attractive invitations to watch a funny or sexy video. When the unsuspecting users clicked the link, the message appeared saying that their computer’s Flash software needed updating. The “update” was in fact malware that hijacked the user’s clicks and delivered them to advertisers, making the hackers money -to the tune of over $2 million annually. According to Kaspersky Labs the network of infected computers included between 400,000 and 800,000 PC
Now facebook take decision to expose the five men alleged to be behind the malware told Ryan McGeehan, Facebook security official. "The thing that we are most excited about is that the botnet is down." said McGeehan. Yesterday, Facebook decided to publish the names of alleged gang members based on details of research carried out in 2009-2010 by two German researchers. One of the researchers works for Security company Sophos

To know who was behind the koobface malware or in short to know the exposed Koobface malware gang click Here


Hackers Have Stolen Data From Japan Aerospace Exploration Agency (JAXA)



In 2011 Japan was targeted by several cyber attacks. Japan's biggest defense contractor Mitsubishi network was comprised, after that hackers stolen user-names & passwords from Japan Parliament  & many more. Then earlier in 2012 Japanese technology firm named Fujitsu developed a virus named ‘seek and destroy’ virus for the Japanese government and hopes that it will identify and prevent and combat cyber attacks. But now it seems that heavy weight ‘seek and destroy’ does not able to stop cyber criminals. 
Japanese space engineers have discovered a Trojan on an employee's computer and confirmed that hackers may have smuggled out login information to gain access to a cargo shuttle that carries food and equipment to the International Space Station (ISS). The compromised information may have included up to 1,000 email addresses, login details for the Japanese space agency's intranet, and NASA documents covering operation of the ISS and so on. The Japan Aerospace Exploration Agency(JAXAhas confirmed that sensitive data has been stolen from a staff computer. The agency said that a virus infection was detected on an employee's terminal on 6th January. The employee is involved with theH-II transfer vehicle that carries cargo to the International Space Station. The agency added that, apart from the email addresses stored on the computer, data related to the transfer vehicle and its schedule, as well as system login data, is potentially at risk because of the intrusion. 

JAXA Press Release:-
On January 6, 2012, the Japan Aerospace Exploration Agency (JAXA) found that a computer terminal used by one of our employees was infected with a computer virus, and information stored in the computer as well as system information that is accessible by the employee have been leaking outside.
We are now confirming the leaked information and investigating the cause.
1. Possible leaked information
As the computer was used by an employee who is involved in the H-II Transfer Vehicle (HTV, a cargo transporter to the International Space Station,) the following information was potentially compromised.
  • Stored mail addresses
  • Specification and operation information of the HTV
  • System log-in information accessed from the computer

2. Currently confirmed background
On August 11, 2011, some anomaly was detected in the said computer, thus it was detached from the network for checking. As a result, on August 17, we found that the computer was infected with a virus. The virus was removed, but the computer has continuously been monitored and investigated since then because it was still unstable and displayed abnormalities. On January 6, 2012, we found a trace that a different virus had gathered information from the computer. In addition, it was also discovered that the computer sent out some information sometime between July 6 and August 11.
With the above backdrop, passwords for all accessible systems from the computer have been immediately changed in order to prevent any abuse of possibly leaked information, and we are currently investigating the scale of damage and the impact. Also, all other computer terminals are being checked for virus infections.

3. Further steps to take

We sincerely apologize over such trouble, and we will promptly address the following measures while strengthening our information security in order to prevent any recurrence, as we gravely regret this incident.
  • Specify leaked information and investigate the cause.
  • Take measures to prevent a recurrence according to the investigation.
  • Call attention and caution the person if his or her personal information is found to have been leaked.


Symantec Network Was Breached On 2006 & At That Attack The Code Was Stolen


Few days ago a hacker group named The Lords of Dharmaraja has managed to steal the source code of Norton anti-virus. Symantec, the anti-virus maker, has confirmed that hackers have stolen a “segment” of its flagship product. They have also said that some of its code had been lifted from the server of a third party. But after investigation the security firm has found that its network had indeed been compromised. Symantec spokesman Cris Paden said on Tuesday that unknown hackers breached its network back in 2006 and obtained the source code to Norton Antivirus Corporate Edition, Norton Internet Security, Norton Utilities, Norton GoBack and pcAnywhere. 
The only real threat at this time resides with customers using pcAnywhere, Symantec's software that facilitates remote access of PCs. "Symantec is currently in the process of reaching out to our pcAnywhere customers to make them aware of the situation and to provide remediation steps to maintain the protection of their devices and information," the company reports.
Symatec admitted that it previously offered up the source code of its products in compliance with the Indian government so that officials could make sure the software didn't contain spyware or other malicious programs. Save for the firm's current caution with pcAnywhere as revealed on Tuesday, Symantec wasn't too worried about a possible code leak given the stolen software is six years old.

Netzob- Network Protocol Reverse Engineering Tool



Today we will discuss you about another reverse engineering tool. The name of the tool is Netzob, and it's is an open source tool which supports the expert in its operations of reverse engineering, evaluation and simulation of communication protocols. It has been developed by security auditors of Amossys and the CIDre research team of SUPELEC to address the reverse engineering of communication protocols. Additionally, it supports security auditors and evaluators in their activities of modeling and fuzzing unknown protocol. In short Netzob is mainly a protocol reverse engineering tool. To be precise, Netzob helps security evaluators to:
  1. Assess the robustness of proprietary or unknown protocols implementation.
  2. Analyze the traffic for potential information leakage.
  3. Simulate realistic communications to test third-party products (IDS, firewalls, etc.).
  4. Create an open source implementation of a proprietary or unknown protocol.
This open source tool is provided with is GPLv3 license and is programmed in Python. You can capture files/data from the network, IPC interface, USB devices, etc. and save them in PCAP, hex, raw binary flows, etc. file formats. Fuzzing of API calls, IPC’s is still in progress though. To know more about Netzob click Here

To Download NETZOB Click Here

Resilient File System (ReFS) - Next Generation File System For Windows Server 8



We have one question to all the Microsoft users & that is did you feel bored while using NTFS file system for a long time? If the answer is yes, then we would love to share that in upcoming Windows Server 8 Microsoft is going to introduce a new file system named Resilient File System, or ReFS., as a "next generation file system" built on the foundations of the NTFS. By reusing NTFS' API / semantics engine, ReFS hopes to retain a high level of compatibility with NTFS features. Underneath the existing semantics engine, the new file system introduces a new storage engine that hopes to protect against latent disk errors, resist data corruption, uphold metadata integrity, grant large volume, file and directory size -- and well, just build a better storage system in general. 

To Know In Details Click Here

Oracle Issued Critical Patch Update (CPU) For 78 Security Holes



As expected Oracle today officially released their January security update. In this critical patch update they have closed 78 security holes.  The company says that these patch day updates address vulnerabilities in "hundreds of Oracle products". 16 of the vulnerabilities patched are remotely exploitable without authentication. Affected products include Oracle Database 10g and 11g, Fusion Middleware 11g, Application Server 10g, Outside In Technology, WebLogic Server, versions 11i and 12 of its E-Business Suite, Oracle Transportation Management, JD Edwards, Sun Ray, VM Virtualbox, Virtual Desktop Infrastructure, MySQL Server, and PeopleSoft Enterprise CRM, HCM and PeopleTools,. A vulnerability in Solaris 9, 10 and 11 Express's TCP/IP is the highest rated of these with a CVSS score of 7.8 out of 10.0.

According to Oracle:- 

Affected Products & Components:-

Security vulnerabilities addressed by this Critical Patch Update affect the products listed in the categories below.  The product area of the patches for the listed versions is shown in the Patch Availability column corresponding to the specified Products and Versions column.   Please click on the link in the Patch Availability column below or in the Patch Availability Table to access the documentation for those patches.
The list of affected product releases and versions that are in Premier Support or Extended Support, under the Oracle Lifetime Support Policyis as follows:
AFFECTED PRODUCTS AND VERSIONSPATCH AVAILABILITY
Oracle Database 11g Release 2, versions 11.2.0.2, 11.2.0.3Database
Oracle Database 11g Release 1, version 11.1.0.7Database
Oracle Database 10g Release 2, versions 10.2.0.3, 10.2.0.4, 10.2.0.5Database
Oracle Database 10g Release 1, version 10.1.0.5Database
Oracle Fusion Middleware 11g Release 1, versions 11.1.1.3.0, 11.1.1.4.0, 11.1.1.5.0Fusion Middleware
Oracle Application Server 10g Release 3, version 10.1.3.5.0Fusion Middleware
Oracle Outside In Technology, versions 8.3.5, 8.3.7Fusion Middleware
Oracle WebLogic Server, versions 9.2.4, 10.0.2, 11gR1 (10.3.3, 10.3.4, 10.3.5)Fusion Middleware
Oracle E-Business Suite Release 12, versions 12.1.2, 12.1.3E-Business Suite
Oracle E-Business Suite Release 11i, version 11.5.10.2E-Business Suite
Oracle Transportation Management, versions 5.5, 6.0, 6.1, 6.2Oracle Supply Chain
Oracle PeopleSoft Enterprise CRM, version 8.9PeopleSoft
Oracle PeopleSoft Enterprise HCM, versions 8.9, 9.0, 9.1PeopleSoft
Oracle PeopleSoft Enterprise PeopleTools, version 8.52PeopleSoft
Oracle JDEdwards, version 8.98JDEdwards
Oracle Sun Product SuiteOracle Sun Product Suite
Oracle VM VirtualBox, version 4.1Oracle Virtualization Product Suite
Oracle Virtual Desktop Infrastructure, version 3.2Oracle Virtualization Product Suite
Oracle MySQL Server, versions 5.0, 5.1, 5.5Oracle MySQL Product Suite


For More Information Click Here