Monday, July 23, 2012

Hollowood Hacker to be sentenced


The Jacksonville man who hacked into the emails of Hollywood celebrities could face up to six years in prison for his crimes and pay more thousands of dollars to his victims.

The victims who were hacked include Scarlett Johanson and Christina Aguilera, just to name a few.

His nickname has become The Hollywood Hacker. 35-year-old Christopher Chaney admitted to being sorry for hacking into the online accounts of stars like Christina Aguilera and Scarlett Johanson.



But despite the fact that Chaney has shown remorse for his online crimes, the Jacksonville man may have to pay $150,000 in fines and spend 71 months behind bars.

In court Chaney was asked, “What do you want to tell your family. Do you really think that’s right?” After this question, Chaney apologized.

“It’s not that we’re retreating from this. but we can’t wholly embrace it either, because the case is becoming more convoluted and more convoluted,” Chaney’s lawyer Mark Chestnutt said.

Chaney’s lawyers said it was an adrenaline rush that fueled his online criminal behavior. He even sent nude photos of the stars to celebrity websites and other hackers.

Prosecutors want Chaney to compensate his victims.

They said Scarlett Johanson is owed more than $66,000, Christina Aguilera $7,500, Renee Olstead $76,000 and an undisclosed amount to Mila Kunis.

In addition to the hollywood starlets, a search warrant of Chaney’s hard drive revealed that it was used to conduct Internet searches for an underage Connecticut woman. She complained to police that Chaney had been chatting with her online since she was 13. She alleged the hacker stole private transmissions as well, but his lawyer claims the opposite.

“He says man, I”ve never heard of her,” Chestnutt said. “Listen, this guy’s never been on a plane! Never been to Connecticut. Never met this young lady. Hedoesn’t know her, doesn’t recall talking with her on the Internet.”

Chaney is scheduled to be sentenced Monday morning in Los Angeles federal court on his guilty plea to nine felony counts of hacking into the email accounts of several actresses. Prosecutors have recommended 6 years in prison.

Hacker Will Expose Potential Security Flaw In Four Million Hotel Room Keycard Locks

The next time you stay in a hotel room, run your fingers under the keycard lock outside your door. If you find a DC power port there, take note: With a few hacker tricks and a handful of cheap hardware, that tiny round hole might offer access to your room just as completely as your keycard.



At the Black Hat security conference Tuesday evening, a Mozilla software developer and 24-year old security researcher named Cody Brocious plans to present a pair of vulnerabilities he’s discovered in hotel room locks from the manufacturer Onity, whose devices are installed on the doors of between four and five million hotel rooms around the world according to the company’s figures. Using an open-source hardware gadget Brocious built for less than $50, he can insert a plug into that DC port and sometimes, albeit unreliably, open the lock in a matter of seconds. “I plug it in, power it up, and the lock opens,” he says simply.

In fact, Brocious’s break-in trick isn’t quite so straightforward. Testing a standard Onity lock he ordered online, he’s able to easily bypass the card reader and trigger the opening mechanism every time. But on three Onity locks installed on real hotel doors he and I tested at well-known independent and franchise hotels in New York, results were much more mixed: Only one of the three opened, and even that one only worked on the second try, with Brocious taking a break to tweak his software between tests.

Even with an unreliable method, however, Brocious’s work–and his ability to open one out of the three doors we tested without a key–suggests real flaws in Onity’s security architecture. And Brocious says he plans to release all his research in a paper as well as source code through his website following his talk, potentially enabling others to perfect his methods.

Brocious’s exploit works by spoofing a portable programming device that hotel staff use to control a facility’s locks and set which master keys open which doors. The portable programmer, which plugs into the DC port under the locks, can also open any door, even providing power through that port to trigger the mechanism of a door lock in which the battery has run out.

The system’s vulnerability arises, Brocious says, from the fact that every lock’s memory is entirely exposed to whatever device attempts to read it through that port. Though each lock has a cryptographic key that’s required to trigger its “open” mechanism, that string of data is also stored in the lock’s memory, like a spare key hidden under the welcome mat. So it can be immediately accessed by Brocious’s own spoofed portable device and used to open the door a fraction of a second later.

Brocious believes that the unreliability of his method stems from timing issues in how his hacked-together unlocking device communicates with Onity’s locks. He doesn’t plan to complete the development and debugging of the technique himself, due to what he says are time constraints and concerns about what a universally effective exploit would mean for the security of millions of hotel guests. But he believes that with more experimentation and tweaking, someone could easily access a significant fraction of hotel rooms around the country without leaving a trace.

In fact, Brocious isn’t the only one who knows his tricks. His former employer, a startup that sought to reverse engineer Onity’s hotel front desk system and offer a cheaper and more interoperable product, sold the intellectual property behind Brocious’s hack to the locksmith training company the Locksmith Institute (LSI) for $20,000 last year. LSI students, who often include law enforcement, may already have the ability to open Onity doors at will.

“With how stupidly simple this is, it wouldn’t surprise me if a thousand other people have found this same vulnerability and sold it to other governments,” says Brocious. “An intern at the NSA could find this in five minutes.”

The ability to access the devices’ memory is just one of the two vulnerabilities Brocious says he found in Onity’s locks. He says the company also uses a weak encryption scheme that allows him to derive the “site code”–a unique numerical key for every facility–from two cards encoded one after another for the same room. By reading the encrypted data off of two cards and testing thousands of potential site codes against both cards until the decoded data displays a predictable interval between the two, he can find the site code and use it to create more card keys with a magnetizing device. But given that he can only create more cards for the same room as the two keys he’s been issued, that security flaw represents a fairly low risk compared with the ability to open any door arbitrarily.

Brocious says he stumbled upon the the flaws in Onity’s locks while working as the chief technology officer for a startup called Unified Platform Management Corporation, which sought to compete with bigger players in the hotel lock industry by creating a universal front end system for hotels that used common lock technologies. Brocious was hired to reverse engineer hotel locks, and Onity was his first target. The discovery of Onity’s security vulnerabilities was entirely unintentional, he says.

UPM failed to find customers or investment and soon folded. With the exception of the sale of his exploit methods to LSI–the biggest sale the startup ever achieved–Brocious kept quiet about his discovery, until now.

“This wasn’t the way we wanted to disrupt the business, exactly,” says Brian Thomason, one of UPM’s founders. “But hey, stuff happens, right?”

In a move that may dismay security practitioners, Brocious never contacted Onity or its parent company United Technologies Corporation to tell the firm about its security flaws, and doesn’t plan to ahead of his talk. But he says that’s because there’s little the company could do: the locks can’t be simply upgraded with new firmware to fix the problem. New circuitboards will have to be installed in every affected lock, a logistical nightmare if millions of locks prove to be vulnerable. “I didn’t want to delay putting this out there any further than I had to. I see no path to mitigate this from Onity’s side,” he says. “The best way to help hotels at this point is educate them about this, not to go through Onity and delay getting the information out longer than I had to.”

When I contacted Onity and provided a detailed description of Brocious’s work, the company responded with this statement: “We have not seen Mr. Brocious’ presentation and cannot comment on the content. Onity places the highest priority on the safety and security provided by its products and works every day to develop and supply the latest security technologies to the marketplace.”

And if Onity’s locks are in fact as insecure and unsecurable as Brocious says, how does he suggest hotels and their guests protect themselves? “Hotels need to come up with a plan to move to more secure locks,” he says.

Eight Million Email Addresses And Passwords Leaked From Gaming Site Gamigo

Call it a slow leak. Four months after the gaming site Gamigo warned users about a hacker intrusion that accessed some portions of its users’ credentials, more than 8 million usernames, emails and and encrypted passwords from the site have been published on the Web, according to the data breach alert service PwnedList. The half-gigabyte collection of stolen user data was posted to the password-cracking forum Inside Pro earlier this month, where it remained online until late last week.
   
                             

PwnedList founder Steve Thomas downloaded the file prior to its removal from the Web and has shared it with me, and I can confirm that it appears to be an enormous list of user emails with passwords obscured by cryptographic hashes.

“It’s the largest leak I’ve ever actually seen,” says Thomas, whose startup seeks to track data breaches and alert users when their information is published. “When this breach originally happened, the data wasn’t released, so it wasn’t a big concern. Now eight million email addresses and passwords have been online, live data for any hacker to see.”

Gamigo users can check on PwnedList’s site whether their email address is included in the leak.

Though the passwords weren’t posted in a readable form initially, they may still be compromised. Within a half hour, another user in the Inside Pro forum thread responded to the post of the file with a message reading “found 94%,” implying that the passwords may have been easily derived from their hashed form.

Gamigo, a free gaming site owned by German publishing firm Axel Springer AG, forced all users to change their passwords after it announced it had been hacked in March of this year, so the exposed passwords likely won’t give anyone access to user accounts on Gamigo.com itself. But given that users very often re-use passwords between sites, the breached passwords could offer access to more sensitive accounts on email or banking sites. Anyone who has had an account with Gamigo prior to its March breach should be sure to change their passwords on any accounts where they used the same credentials as on Gamigo.com.

According to PwnedList’s analysis, the spilled data includes 3 million American accounts including Hotmail, Gmail, and Yahoo! mail addresses, 2.4 million German accounts, and 1.3 million French accounts. The company found dozens of email addresses from corporations including IBM, Allianz, Siemens, Deutsche Bank, and ExxonMobil.

Though the user who posted the file to Inside Pro counted 11 million hashed passwords, PwnedList’s Thomas says he found only 8,244,o00 unique email addresses in the file. More than five thousand of the email addresses included the word “gamigo,” a sign that they were created specifically to register for Gamigo and strong evidence that the stolen database was in fact taken from Gamigo’s servers.


In early March, Gamigo warned users that its “database was subject to an attack in the last few days,” and that “the intruder(s) managed to acquire (alias) user names and encrypted gamigo user passwords.” A few hundred of those credentials were posted in Gamigo forums.

“We cannot rule out that the intruder(s) is/are still in possession of additional personal data, although to date we have received no report of any fraudulent use,” read the message. “To prevent any unauthorized access to your account, we have reset all passwords for the gamigo Account System and for all gamigo games!”

I’ve contacted Gamigo for comment, and will add any update from the company when I hear back.

PwnedList’s Steve Thomas says he believes Gamigo hasn’t acted irresponsibly in responding to the breach, despite not warning users to change any passwords they reused across other accounts. But he emphasizes that users who do reuse passwords should act now to change them immediately. “Now that these full details are out there, we can expect more attempts for accounts to be taken over or used maliciously,” he says.

40+ Pakistani sites Hacked and Defaced by "venki"


40+ Pakistani sites Hacked and defaced by "venki" form "Indian Cyber Pirates". There is no specific reason mention in hacked site but this is clearly told Pakistani admin that how much they need to work on security. This kind of attack become a regular on Pakistani cyber space and need lot of work to patch them.


Deface page info:


"Hacked bY venki

Hey Lmao Admin Shocked 4 HaCked!!!!
U Have Bad Security lolx u Realy Need to Patch Your ASs Cya Again

INDIAN CYBER PIRATES

We Are : | Pr3d4t0r 34gl3 Haxor | D34DM4N | ICP MEMBERS | "

Hacked Site List and Mirrors:
Pastbin

Sunday, July 22, 2012

Samsung Galaxy Tab Stays Banned in the US in Increasingly Bizarre Apple Case


Samsung tried to get it overturned, but the preliminary injunction against its Galaxy Tab tablet in the US will be enforced after all, despite different rulings in other parts of the world.

District Judge Lucy Koh issued an injunction, back in late June, against the Samsung Galaxy Tab tablet, which essentially forbids its sale in the United States.

Naturally, the company wasn't about to take it lying down, so it turned to the US appeals court, hoping it wouldn't have to change the looks.


Unfortunately, its attempts to overturn the ruling was denied. Also, the court refused to speed up the appeal process, which means that Samsung has to wait until July 30 at the very earliest before it can be heard again.

"Samsung may of course significantly self-expedite the case by filing its own brief early. Samsung, however, has not shown that the time for Apple to file its brief should be shortened," the court said in its ruling, according to The Register.

Apple is no doubt ecstatic about the outcome, bizarre as it is. We call it bizarre because of the grounds on which the ban was granted in the first place.

The patent which Apple managed to use in the banning of the Samsung Galaxy Tab is "the ornamental design for an electronic device," which describes what a tablet looks like.

We won't say (again) how strange it is that someone is allowed to claim ownership of what is essentially an aesthetic concept that was used, by others, before Apple's iPad even came out. That's for the USPTO to sort out.

Instead, we'll draw attention to the fact that the very same patent was ruled to not have been infringed by Samsung's Galaxy Tab in a different part of the world: The United Kingdom.

Remarks of Tab not being as “cool” as iPad aside, there is another matter: the same court has ordered Apple to publicly admit, advertise even, that the Galaxy Tab is not a copy, and keep doing so for at least six months. It's the closest thing to a public apology we can think of.

Apple might still get out of it but, if it does not, this patent war will reach new levels of ridiculous. Apple will basically declare, in official capacity, that Galaxy Tab does not infringe its IP, while declaring, in official capacity, that Galaxy Tab does infringe its IP, only in a different part of the world.

We'll give this mess this much: it gave the term “cognitive dissonance” a whole new meaning.

Reference:  http://news.softpedia.com/news/Samsung-Galaxy-Tab-Stays-Banned-in-the-US-Apple-Can-Rejoice-282495.shtml

Russian hacker arrested for cyber attacks on Amazon.com


A Russian man who is indicted in the Western District of Washington for cyber attacks on Seattle-based Amazon.com was arrested in Cyprus this week on an international warrant, announced U.S. Attorney Jenny A. Durkan. Dmitry Olegovich Zubakha, 25, of Moscow, was indicted in May 2011, for two denial of service attacks on the Amazon website.

The indictment, unsealed today following his arrest on July 18, 2012, also details denial of service attacks on Priceline.com and eBay.  The illegal hacking and denial of service attacks outlined in the indictment occurred in June 2008.  Zubakha is charged in relation to the attacks with conspiracy to intentionally cause damage without authorization to a protected computer, and two counts of intentionally causing damage to a protected computer resulting in a loss of more than $5,000.


Zubakha is also charged with possession of 15 or more unauthorized access devices, and aggravated identity theft for a separate incident involving the possession of stolen credit card numbers in October 2009.  The United States is seeking to extradite Zubakha from Cyprus.  He remains in custody pending extradition.

“These cyber bandits do serious harm to our businesses and their customers.  But the old adage is true: the arm of the law is long,” said U.S. Attorney Jenny A. Durkan who leads the Justice Department’s Cybercrime and Intellectual Property Enforcement Committee.  “This defendant could not hide in cyberspace, and I congratulate the international law enforcement agencies who tracked him down and made this arrest.

According to the indictment, Zubakha is alleged to have mounted a denial of service attack against Amazon on June 6, 2008 and again on June 9, 2008.  In both instances, the attacks disrupted the ability of customers to access the Amazon site for hours while the company attempted to deal with the attacks from a ‘botnet’ or web of connected computers.  Zubakha, and another Russian hacker, allegedly launched the attacks against the Amazon servers by having the botnet computers request large and resource intensive web pages. The attacks made it difficult for Amazon customers to complete their business on line. Zubakha and his coconspirator claimed credit for the attacks in hacker forums.  In one instance a co-conspirator called a victim company, Priceline.com and offered his services as a consultant to stop the denial of service attack.   In October 2009, law enforcement traced the possession of more than 28,000 stolen credit card numbers to Zubakha and his co-conspirator.  Zubakha is charged with aggravated identity theft for illegally using the credit card of a Lake Stevens resident.

“The investigation culminating in the arrest of Dmitry Zubakha by authorities in Cyprus was extremely complex. The apprehension of Zubakha is the result of a concerted effort by the Secret Service, the U.S. Attorney’s Office for the Western District of Washington and the Seattle Police Department. I would also like to commend Amazon.com for its forthrightness and assistance in dealing with this series of computer network attacks which had the potential to adversely impact the company’s ability to serve its customers,” said James Helminski, Special Agent in Charge of the U.S. Secret Service in Seattle.

The charges contained in the indictment are only allegations.  A person is presumed innocent unless and until he or she is proven guilty beyond a reasonable doubt in a court of law.

Conspiracy is punishable by up to five years in prison. Intentionally causing damage to a protected computer resulting with a loss of more than $5,000 is punishable by up to ten years in prison and a $250,000 fine.  Possession of more than 15 unauthorized access devices is punishable by up to ten years in prison and a $250,000 fine.  Aggravated identity theft is punishable by an additional two years in prison on top of any sentence for the underlying crimes.

The case is being investigated by the U.S. Secret Service Electronic Crimes Task Force which includes detectives from the Seattle Police Department.  The Office of International Affairs in the Justice Department’s Criminal Division provided substantial assistance. Assistant United States Attorney Kathryn Warma is prosecuting the case in the Western District of Washington.

Saturday, July 21, 2012

Two LulzSec hackers plead guilty to hacking charges

Two LulzSec hackers may soon learn that it’s easier to break into government databases than it is to break out of jail. Ryan Cleary, 19, and Jake Davis, 18, on Monday both pleaded guilty in a London court to charges that they attacked both government websites and major commercial websites, the BBC reports. The two men, both citizens of the United Kingdom, admitted to hacking into the Pentagon, the CIA, the U.K.’s National Health Service, News International, PBS, Sony, Nintendo and the 20th Century Fox film studio. Both men, however, pleaded not guilty to more serious charges that they “unlawfully obtained confidential computer data” and posted it on popular hacker hubs such as LulzSec.com and Pirate Bay. A trial for those charges has been set for April 2013, the BBC reports.