Tuesday, October 30, 2012

Thai Official Police Government site Hacked by Sizzling Soul (PCA)

Thai Official Police Government site Hacked by Sizzling Soul from Pakistan Cyber Army. According to hacker Thai Gov Police Can't Secure Itself How They Will Secure The Citizens. 2012 is really consider really worst for government sites.



Hacked Site:

http://www.finance.police.go.th/pic/

Mirror:
http://z-z0ne.net/mirror/id/55890

Monday, October 29, 2012

80+ Israeli sites including Ministry of National Infrastructures (MNI) Hacked By Hitcher (MLA)

A couple of domains owned by Israel’s Ministry of National Infrastructures (MNI) have been breached and defaced by Hitcher, a hacker part of the Muslim Liberation Army collective. Mass Attack on Israeli webs also get 80 Pulse domains are Hacked along two government sites Two and Message is Delivered.


Deface Page say's:
We are outraged at the Palestine present condition and the Illegal occupation of Palestanaian Land By the zionist Israelis
This attack is in response to the Injustice against the Palestinian people
terrorist.
w Israel is a serious threat to Palestinian
Occupied Palestinian land under the guise of residential settlements are being increased
Palestinians are deprived of their basic human rights
International Aid workers are stopped from providing any humanitarian assistance to the people.
The International community and media is not allowed to bring facts to world as due to strict restrictions

WE ARE :

XtReMiSt, KillerMind Haxor, Jerry Hassan, Syed Zaadaa, HyP3r-Boy 
Zarb-E-Momin, fAchO, Radical Assassin,Spartan, Hitcher

-.- UNITED WE STAND..DIVIDED WE FALL -.-

Ministry of National Infrastructures Hacked Domains:
http://mine-rec.mni.gov.il/images/
http://www.kasham.mni.gov.il/images/
________________________________

Other Hacked Sites Links:
http://www.wn-school.co.il/
http://www.abu-shakra.com/index.html
http://studioyael.com/
http://abckid.co.il/
http://www.swiftstake.com/index.htm
http://summit-il.com/index.html
http://swiftstake.biz/index.htm
http://swiftstake.com/index.htm
http://mashov.kela.co.il/mla.html
http://www.summit-il.com/index.html
http://www.ihaklai.org.il/index.htm
http://swiftstake.info/index.htm
http://swiftstake.net/index.htm
http://swiftstake.org/index.htm
http://fwaz.net/images/
http://blog.kuchi.co.il/mla.html
http://cube.co.il/mla.html
http://www.5-nagarim.kuchi.co.il/mla.html
http://abbott.kuchi.co.il/mla.html
http://adin.kuchi.co.il/mla.html
http://admin.ramir.kuchi.co.il/mla.html
http://affiliates.kuchi.co.il/mla.html
http://amr.kuchi.co.il/mla.html
http://anatevka.kuchi.co.il/mla.html
http://amutabj.kuchi.co.il/mla.html
http://api.kuchi.co.il/mla.html
http://www.b-fresh.kuchi.co.il/mla.html
http://banner.kuchi.co.il/mla.html
http://bellhotel.kuchi.co.il/mla.html
http://bigusa.kuchi.co.il/mla.html
http://briza.kuchi.co.il/mla.html
http://careervibes.kuchi.co.il/mla.html
http://www.cms.kuchi.co.il/mla.html
http://crm.kuchi.co.il/mla.html
http://dque.kuchi.co.il/mla.html
http://eim.kuchi.co.il/mla.html
http://einstein.kuchi.co.il/mla.html
http://elal.kuchi.co.il/mla.html
http://exclusive.kuchi.co.il/mla.html
http://fattalexp.kuchi.co.il/mla.html
http://www.founders.kuchi.co.il/mla.html
http://friendlyurl.kuchi.co.il/mla.html
http://fxlider.kuchi.co.il/mla.html
http://generalbar.kuchi.co.il/mla.html
http://gmul.kuchi.co.il/mla.html
http://gmed.kuchi.co.il/mla.html
http://hammernutrition.kuchi.co.il/mla.html
http://hmg.kuchi.co.il/mla.html
http://jetro.kuchi.co.il/mla.html
http://juniversity.kuchi.co.il/mla.html
http://liderforex.kuchi.co.il/mla.html
http://leverate.kuchi.co.il/mla.html
http://mailer.kuchi.co.il/mla.html
http://www.maritayin.kuchi.co.il/mla.html
http://mintz.kuchi.co.il/mla.html
http://pediasure.kuchi.co.il/mla.html
http://pelecom.kuchi.co.il/mla.html
http://www.royal.kuchi.co.il/mla.html
http://similac.kuchi.co.il/mla.html
http://sandbox.kuchi.co.il/mla.html
http://portfolio.kuchi.co.il/mla.html
http://simzol.kuchi.co.il/mla.html
http://www.snew.kuchi.co.il/mla.html
http://soflex.kuchi.co.il/mla.html
http://stc.kuchi.co.il/mla.html
http://the7species.kuchi.co.il/mla.html
http://tzorfati.kuchi.co.il/mla.html
http://ultima.kuchi.co.il/mla.html
http://zhg.kuchi.co.il/mla.html
http://zinuk.kuchi.co.il/mla.html
http://abbott.kuchi.co.il/mla.html
http://kuchi.kuchi.co.il/mla.html
http://einstein.kuchi.co.il/mla.html
http://zhg.kuchi.co.il/mla.html
http://blog.kuchi.co.il/mla.html
http://admin.ramir.kuchi.co.il/mla.html
http://adin.kuchi.co.il/mla.html
http://www.5-nagarim.kuchi.co.il/mla.html

Mirror
http://www.legend-h.org/deface.php?id=817398
http://www.legend-h.org/deface.php?id=817397
http://www.legend-h.org/deface.php?id=817340
http://www.legend-h.org/deface.php?id=817339
http://www.legend-h.org/deface.php?id=817338
http://www.legend-h.org/deface.php?id=817336
http://www.legend-h.org/deface.php?id=817335
http://www.legend-h.org/deface.php?id=817334
http://www.legend-h.org/deface.php?id=817333
http://www.legend-h.org/deface.php?id=817332
http://www.legend-h.org/deface.php?id=817396
http://www.legend-h.org/deface.php?id=817395
http://www.legend-h.org/deface.php?id=817394
http://www.legend-h.org/deface.php?id=817393
http://www.legend-h.org/deface.php?id=817392
http://www.legend-h.org/deface.php?id=817391
http://www.legend-h.org/deface.php?id=817389
http://www.legend-h.org/deface.php?id=817389
http://www.legend-h.org/deface.php?id=817387
http://www.legend-h.org/deface.php?id=817386
http://www.legend-h.org/deface.php?id=817385
http://www.legend-h.org/deface.php?id=817384
http://www.legend-h.org/deface.php?id=817383
http://www.legend-h.org/deface.php?id=817382
http://www.legend-h.org/deface.php?id=817382
http://www.legend-h.org/deface.php?id=817381
http://www.legend-h.org/deface.php?id=817380
http://www.legend-h.org/deface.php?id=817379
http://www.legend-h.org/deface.php?id=817378
http://www.legend-h.org/deface.php?id=817377
http://www.legend-h.org/deface.php?id=817376
http://www.legend-h.org/deface.php?id=817375
http://www.legend-h.org/deface.php?id=817374
http://www.legend-h.org/deface.php?id=817373
http://www.legend-h.org/deface.php?id=817371
http://www.legend-h.org/deface.php?id=817370
http://www.legend-h.org/deface.php?id=817369
http://www.legend-h.org/deface.php?id=817368
http://www.legend-h.org/deface.php?id=817367
http://www.legend-h.org/deface.php?id=817366
http://www.legend-h.org/deface.php?id=817364
http://www.legend-h.org/deface.php?id=817364
http://www.legend-h.org/deface.php?id=817363
http://www.legend-h.org/deface.php?id=817362
http://www.legend-h.org/deface.php?id=817361
http://www.legend-h.org/deface.php?id=817360
http://www.legend-h.org/deface.php?id=817359
http://www.legend-h.org/deface.php?id=817358
http://www.legend-h.org/deface.php?id=817357
http://www.legend-h.org/deface.php?id=817356
http://www.legend-h.org/deface.php?id=817354
http://www.legend-h.org/deface.php?id=817353
http://www.legend-h.org/deface.php?id=817352
http://www.legend-h.org/deface.php?id=817351
http://www.legend-h.org/deface.php?id=817350
http://www.legend-h.org/deface.php?id=817349
http://www.legend-h.org/deface.php?id=817348
http://www.legend-h.org/deface.php?id=817347
http://www.legend-h.org/deface.php?id=817346
http://www.legend-h.org/deface.php?id=817345
http://www.legend-h.org/deface.php?id=817344
http://www.legend-h.org/deface.php?id=817343
http://www.legend-h.org/deface.php?id=817342
http://www.legend-h.org/deface.php?id=817341


Wednesday, October 3, 2012

TN, Kerala govt. websites hacked

TN, Kerala govt. websites hacked




Hacker groups from Indonesia and Pakistan have defaced several websites of state governments of Tamil Nadu and Kerala in the last two days, raising concern over the security of servers hosting these websites. Interestingly, an Indian group also has hacked a Bihar government website.
The latest in the string of attack is the defacement of ‘www.tnvkpmis.gov.in’ belonging to Tamil Nadu Vazhndhu Kaathuvom Project on Wedneday. The site administrators were quick in pulling off the defaced page and re-hosting the original pages.
On Tuesday, an Indian group ‘Anon.India’ defaced the website of Bihar State Development Corporation (www.bstdc.gov.in) to protest the blocking of some websites by the Bihar government. The group posted a detailed message on the defaced page along with the audio of a popular Hindi movie running in the background. In this instance also, the web administrators immediately hosted the original page.
On nine websites of the Kerala Government, a Pakistani hacker group, “h4xOr HuSsY” posted abusive messages against India. The websites included that of the Directorate of Medical Education, land records, biotech commission, stores purchase department, the state land board, Neyyar Wildlife Sanctuary, State Rural Roads Development Corporation, Department of Environment and Climate change. While some of the websites are up and running, a couple of them have been taken off the servers.
Screenshots of the defaced web pages are hosted on zone-h.org, a website that keeps track of defacement of websites.
Source: Click To View

Monday, October 1, 2012

Chinese Computer Hackers Break Into White House Military Network

Chinese Computer Hackers Break Into White House Military Network






Bill Gertz has the grim news in the Washington Free Beacon:
Hackers linked to China's government broke into one of the U.S. government's most sensitive computer networks, breaching a system used by the White House Military Office for nuclear commands, according to defense and intelligence officials familiar with the incident.
One official said the cyber breach was one of Beijing's most brazen cyber attack against the United States and highlights a failure of the Obama administration to press China on its persistent cyber attacks.
Disclosure of the cyber attack also comes amid heightened tensions in Asia, as the Pentagon moved two U.S. aircraft carrier strike groups and Marine amphibious units near waters by Japan's Senkaku islands.
China and Japan-the United States' closest ally in Asia and a defense treaty partner-are locked in a heated maritime dispute over the Senkakus, which China claims as its territory.
U.S. officials familiar with reports of the White House hacking incident said it took place earlier this month and involved unidentified hackers, believed to have used computer servers in China, who accessed the computer network used by the White House Military Office (WHMO), the president's military office in charge of some of the government's most sensitive communications, including strategic nuclear commands. The office also arranges presidential communications and travel, and inter-government teleconferences involving senior policy and intelligence officials.
An Obama administration national security official said: "This was a spear phishing attack against an unclassified network."
Spear phishing is a cyber attack that uses disguised emails that seek to convince recipients of a specific organization to provide  confidential information. Spear phishing in the past has been linked to China and other states with sophisticated cyber warfare capabilities.
The official described the type of attack as "not infrequent" and said there were unspecified "mitigation measures in place."
"In this instance the attack was identified, the system was isolated, and there is no indication whatsoever that any exfiltration of data took place," the official said.
The official said there was no impact or attempted breach of a classified system within the office.
Teenagers? Or Chinese government sponsored criminals? It sounds like the hacking job was unremarkable - the attack was on an unclassified network - so amatuers looking for a thrill might have been responsible.
But it also may have been a test by professionals. Government hackers may have accessed the network to gauge our response to an attack. They also may have been looking for an "in" to more sensitive parts of the system.
Let's hope this was a wake up call to our cyber security people.


Saturday, September 29, 2012

Indian Air Force issues strict orders to tackle hacking

Indian Air Force issues strict orders to tackle hacking

Indian Air Force issues strict orders to tackle hacking

New Delhi: Every officer of the Indian Air Force (IAF) will now have to sign a declaration that they will not save or view any official document on personal computers. Failure to adhere to this directive will lead to a court marshal and prosecution.

The recent directive from the IAF headquarters to all its formations across the country comes after repeated leaks of sensitive documents - some of which are of operational and sensitive in nature - from personal computers of officers and men.

In a recent case, operational documents were found on the personal computer of a young pilot posted at an airbase in Tamil Nadu. A court of inquiry has been initiated.

In another incident this July, it was found that classified data regarding Indian Naval operations were transmitted to IP addresses in China. Later, inquiries revealed that a few naval officers had, against the rules, taken copies of the plans in pen drives from a naval computer, to study. The Chinese-made pen drives allegedly had malwares which transmitted the data back to IP addresses in China once they were used on computers connected to the internet.

Earlier last year, a major with the Indian Army posted in the crucial Andaman and Nicobar Command was investigated by the Intelligence Bureau (IB) and the National Investigative Agency (NIA) when classified Army plans and other sensitive operational data stored in his personal computer reached Pakistan's Inter-Services Intelligence Agency (ISI). The inquiry revealed that the Major was preparing for a course, and had taken copies of presentations and plans in his personal computer, which was subsequently hacked by malware originating from Pakistan.

In almost every case of cyber leak, subsequent inquiries have revealed that officers wanting to study the documents at leisure copied the data from the official systems into their personal computers, and the data later found its way into the cyberspace.

Over the years, cyberspace has emerged as a critical frontier for espionage as the use of computers and dependence on the internet has grown. Thus, document security has emerged as one of critical areas of concern for the government. It is perhaps alluding to these increasing instances of the cyberspace being used by foreign agencies to collect critical information. Prime Minister Manmohan Singh, while addressing top cops of the country at the annual security conference hosted by the Intelligence Bureau earlier this month, said, "Our country's vulnerability to cybercrime is escalating... Large-scale computer attacks on our critical infrastructure and economy can have potentially devastating results. The government is working on a robust cyber security structure."

The Indian armed forces are considering a joint cyber command to deal with document security and hackers, many of whom are funded and used by foreign governments searching for sensitive and strategic information. The Indian Navy has come up with an exclusive Information Technology brigade to be deployed on warships and various sensitive establishments on shore to manage and secure the network and data.

As a general rule, computers in which sensitive information are stored or prepared are never connected to the internet. "The IAF internal communication network, for instance, is not only a stand-alone network with no connection to the net, but also has the system configured in such a way that it doesn't allow external storage devices like pen drives or CDs," a senior MoD official told NDTV. Nonetheless, some officers have been found "keeping copies or preparing documents using critical information in their personal computers, which have subsequently passed out by malwares in the system or hacked," the officer added.

Thursday, September 27, 2012

Banks Fail To Repel Cyber Threat

Banks Fail To Repel Cyber Threat

Attacks that have tied up bank websites show U.S. financial institutions' vulnerability to electronic terrorism.

U.S. Bank branch


A shadowy but well organized hacker group in the Middle East has disrupted the electronic banking operations of America's largest financial institutions in recent days, underscoring U.S. vulnerability to online terrorism.
A group identifying itself as Izz ad-Din al-Qassam Cyber Fighters attacked the websites of Wells Fargo, U.S. Bancorpand Bank of America. The strikes left customers temporarily unable to access their checking accounts, mortgages and other services.
The banks said account and personal information for their tens of millions of online and mobile customers were not compromised. Still, experts said the size and ferociousness of the attacks highlight the broader threat posed by electronic crime and the susceptibility of financial targets.
Of particular concern, experts said, is that the attackers used the Internet to warn the institutions ahead of time — but the banks still couldn't repel the assaults.
"The banks put a lot of effort into cyber security. But they're so desirable as a target, even with all that effort they still have problems," said James Lewis, an expert at the Center for Strategic and International Studies in Washington. "If you can pull together enough resources, you can overwhelm any defense temporarily."
The attacks on banks began last week on the largest institutions in the country: JPMorgan Chase, Citigroup and Bank of America. They spread to Wells Fargo on Tuesday and U.S. Bank on Wednesday. Another attack has been threatened against PNC Financial Services on Thursday.
The U.S. government and banks have been working feverishly to learn more about the attackers. A financial executive not authorized to speak publicly described a "war room" where bankers were coordinating efforts with the Department of Homeland Security
Izz ad-Din al-Qassam is the name of the military wing of Hamas, the political party that governs theGaza Strip. Experts say the attacks appear to have originated from the Middle East, thought it isn't clear who is behind them or the motivation.
However, on Tuesday the group posted a manifesto on the Internet saying attacks would continue until a video insulting the Islamic prophet Muhammad was removed from the Internet. That video, "Innocence of Muslims," has caused violent clashes in the Middle East, and led to the attack of the U.S. embassy in Libya.
Dmitri Alperovitch, a computer security expert investigating the recent attacks, said they are the latest in a series of cyber assaults by the group. The attacks were not only on financial firms, he said, although he declined to identify other industries. Alperovitch said Izz ad-Din al-Qassam has demonstrated "advanced capabilities."
He said it was unlikely that the anti-Islamic video alone had triggered the attacks. He said his firm, CrowdStrike Inc., has linked the group to attacks on other targets since January, long before the trailer for the anti-Islamic film was posted on YouTube.
Wells Fargo, based in San Francisco, had intermittent service interruptions all day Tuesday, distressing many of its 21 million online customers.
Similar problems occurred Wednesday at U.S. Bank. The Minneapolis-based bank said it was experiencing unusually high Web traffic and that the coordinated attacks were "very similar" to those at other major banks. "We are working very closely with federal law enforcement," spokesmanTom Joyce said.
Pittsburgh-based PNC, facing the threatened attack on Thursday, was preparing for the worst. "We've seen the posting" on the Internet, PNC spokesman Fred Solomon said. "We're taking appropriate measures."
Security consultant Alperovitch said the volume of phony demands on bank sites was two to three times heavier than previous records for denial of service attacks, and 10 to 20 times higher than the average such attack. Still, the onslaught so far has had a "very limited impact," resulting in only brief shutdowns of websites.
"The attacks, while very, very large and historic in that sense, are not super sophisticated," he said. Although evidence points to a group "certainly of Middle Eastern origin," his company could not tell whether a state or private group was behind the attacks.
Some speculation centered on whether Iran might be retaliating for economic sanctions placed on the country because of its nuclear program and enforced by U.S. banks.
"I don't believe these were just hackers," Senate Homeland Security Committee Chairman Joe Lieberman (I-Conn.) said last week in an interview on C-SPAN's "Newsmakers" program. "I think this was done by Iran and the Quds Force," a secretive Iran military unit blamed for terrorist activity.
Lieberman was observing Yom Kippur and could not be reached Wednesday. The FBI and Justice Department declined to comment on the origin of the attacks.
Two bankers, who spoke on condition of anonymity, said their banks were also on the alert for cyber thieves who might use the attacks as a diversion.


Google patches 24 Chrome bugs, pays out $29K to bounty hunters

Google patches 24 Chrome bugs, pays out $29K to bounty hunters





Google yesterday patched 24 vulnerabilities in Chrome, and paid out $29,500 in bounties to nine researchers, more than half of that to one of the company's most prolific bug finders.

Chrome 22, which Google started pushing to current users on Tuesday, also debuted improvements in how the browser renders 3-D web apps, including games.

The 24 vulnerabilities include one rated "critical," Google's highest threat ranking, 15 tagged "high," five pegged "medium," and three labeled "low."

[ Get the latest IT news on the Australian government and businesses in Computerworld's Business & Government newsletter ]
Critical bugs are rare in Chrome: Yesterday's, in fact, was not in the browser itself but rather in Windows. In Tuesday's update notification, Google called it a "Windows kernel memory corruption" and attributed the report to a pair of researchers at a Finnish company, Documill, that specializes in creating software for accessing Microsoft Office and Adobe Reader documents through a browser.

For their work, Google awarded the pair $5,000.

The company also paid $15,000 to long-time bug contributor Sergey Glazunov for reporting a pair of critical universal cross site scripting (UXSS) vulnerabilities, one in the browser's frame handling, the other in how it interacts with Google's V8 JavaScript engine.

Glazunov was one of two security researchers who hacked Chrome at Google's inaugural "Pwnium" contest last March. That feat earned him $60,000.

With Tuesday's $15,000 check, Glazunov has taken home nearly $80,000 for his research efforts this year.

So far in 2012, Google has paid over $290,000 in bounties, a number sure to climb. Last month, Google raised the bonuses it pays, saying the change was triggered by a decline in submitted reports.

Several of the researchers who received bounties for the bugs patched in Chrome 22 benefited from the increase, including Glazunov, the two from Documill, and others who received $1,000, the new bonus basement.

Chrome 22 includes few if any visible changes, but yesterday Google touted some behind-the-scenes improvements, notably support for the Pointer Lock JavaScript API, or "Mouse Lock."

The feature should improve play of first-person, 3-D games within Chrome, said Google engineer Vincent Scheib in a Tuesday blog post.

Google also called out some unspecified enhancements to Chrome in preparation for the Oct. 26 launch of Windows 8 by Microsoft.

Although Google announced a Windows 8 version of Chrome -- one that will include not just a desktop browser for that traditional UI, but also one for what was formerly called the "Metro" environment -- in mid-June, it has not shifted the latter from the rough-around-the-edges "Dev" channel since then.

Chrome 22 can be downloaded for Windows, Mac OS X and Linux from Google's website. The browser is updated automatically through its silent service.