Hackers are hacking cars !

Posted on:
tags: , , , , , ,

Cars which lock without using keys can be hacked into as easily as any other computerised device. Just as you lock it with your remote control, the thief blocks the signal and the car remains unlocked. Now the contents can be stolen without attracting attention by breaking a window. 
 
It has already happened in Switzerland, and the piece of equipment thieves use can be bought via the internet – a radio frequency scrambler. 
 
But having your car hacked can also result in it being stolen, pure and simple – and modern cars have multiple vulnerabilities: from the plug for the car’s diagnostic computer to the multimedia functions. The CD and radio,GPS, Bluetooth, WIFI, USB port - they are all doors to hackers.
 
The hack is always based on the same thing which is making your car believe the thief has the key. Once this has been done using a laptop, the rest is easy.
 
Professor Jean-Pierrre Hubaux, from the Faculte Informatique and Communications at l’EPFL told euronews: “A hacker could suddenly interfere with the brakes, so that when a driver puts their foot on the pedal it no longer works. In theory a hacker could turn the ignition off by remote control so that the vehicle is immobilised and vulnerable to attack. You could even use it to open bullet-proof glass windows. You could imagine a whole series of scenarios.”
 
The police have already recorded various car hacking crimes across Europe involving vehicles without traditional keys and the owners have been hard pushed to prove to their insurance companies that they did not leave their cars unlocked.
 
So IT security for cars is becoming a new specialist field. Computer Security Consultant Paul Such was, in the name of research, able to get hold of the software to operate all the multimedia facilities of a massive limousine.
 
He explained: “I can really modify the computer system on this car, I can change the icons it uses for example, like the icon warning me that fuel is running low, or the icon for telephoning or changing the sound of the car. The different beeps it makes when there is no more petrol, or to remind me to put my seat belt on, etc. There’s no technical reason to stop me doing all that. So if I can modify all that, it means that I could apply other codes to the car. You could easily imagine a virus, for example, which targets cars.”
 
A modern car is in fact a computer on four wheels. Dozens of interconnected processors and millions of lines of source code are hidden under the bonnet. The more the car communicates with the outside world, the more vulnerable it is. The equation is logical. But for one specialist, car manufacturers have overlooked security in their enthusiasm for innovation. 
 
Paul Such added: “With mechanical keys, like we had in the past, the risk of theft also existed. The aim is to make the bar high enough so that a car can’t be stolen at all easily. Manufacturers ought to be doing the same things as software companies have done over the past 10 years - making their code secure. Quite simply, this in-car systems need to be tested and improved.”
 
Today, some large car manufacturers are responding to the hackers. They are starting to react but the most important task is to firewall all the computer information linked to controlling a vehicle and the computer equipment installed in it. 


Source


---------------------------------------------------------------------------------
Posted By Sundeep aka SunTechie

Sundeep is a Founder of Youth Talent Auzzar, a passionate blogger, a programmer, a developer, CISE and these days he is pursuing his graduation in Engineering with Computer Science dept.
Add Sundeep as a Friend on 

270 government websites hacked in this year till July

Posted on:
tags: , , , , , , , ,



Over 270 government websites were reported to have been hacked till July this year.
“A total number of 201, 303, 308 and 273 government websites were hacked during the year 2009, 2010, 2011 and 2012 (till July) respectively,” Minister of State for Communications and IT Sachin Pilot said in a written reply to the Lok Sabha this week.
When asked if computer security analysts have issued alerts for internet users, Pilot said the Indian Computer Emergency Response Team (CERT-In) regularly issues alerts for users and operators on vulnerabilities.
It also published advisory providing countermeasures to safeguard the websites and network infrastructure against such attacks.

---------------------------------------------------------------------------------
Posted By Sundeep aka SunTechie

Sundeep is a Founder of Youth Talent Auzzar, a passionate blogger, a programmer, a developer, CISE and these days he is pursuing his graduation in Engineering with Computer Science dept.
Add Sundeep as a Friend on 

Anonymous may hack Mars rover 'Curiosity'

Posted on:
tags: , , , , , , , ,



NASA's Mars rover 'Curiosity' might be facing a hacking threat from the notorious hacker group, Anonymous, a US security firm has claimed.

Anonymous had reportedly brought down websites including Visa and several US government sites as a protest against WikiLeaks founder Julian Assange's arrest, and 'Curiosity' could be their next target, the Daily Mail reported.

A New York security firm claimed to have spotted a message on an Internet Relay Chat (IRC) asking for help to hack into the signals NASA uses to communicate with the Curiosity rover.

Flashpoint Partners spotted a message by user 'MarsCuriosity' in one of the Anonymous-related IRC channels that it monitors known as the AnonOps IRC channel.



"Anyone in Madrid, Spain or Canbarra who can help isolate the huge control signal used for the Mars Odyssey / Curiosity system please?" the message read.

"The cypher and hopping is a standard mode, just need base frequency and recordings/feed of the huge signal going out. (yes we can spoof it both directions!)," it added.

There is speculation by online discussion groups that the message could be a fake, or even an attempt by law enforcement agencies to trap hackers, the report said.

'Curiosity' had made a spectacular landing in Gale Crater at 05:30 GMT (11:00 IST) on August 6 in a two-year search to find out if the red planet once hosted conditions suitable for life.

Source

Other news of Anonymous Group

---------------------------------------------------------------------------------
Posted By Sundeep aka SunTechie

Sundeep is a Founder of Youth Talent Auzzar, a passionate blogger, a programmer, a developer, CISE and these days he is pursuing his graduation in Engineering with Computer Science dept.
Add Sundeep as a Friend on 

Hackers build their own mobile phone network at conference

Posted on:
tags: , , , , , , , ,




A custom mobile phone network came to life in the middle of Def Con as hackers showed off their technology skills in tribute to the infamous gathering's elite "ninjas."


A Def Con team bought a telecom company van and configured a "Ninja Tel" cellular phone network to pay homage to longtime hackers who have kept the spirit of the event alive and, admittedly, just to do something "over the top."
"People don't realize how much hacking has changed," said Def Con veteran Dan Kaminsky, known for discovering a perilous Internet bug that bears his name.

"This used to be a sub-culture of people who bonded over their fascination with technology," he continued. "Now, hacking has gone mainstream.
"A mom hacks her kid's grade at school and Rupert Murdoch gets called out for hacking."

The Ninja Tel team built 650 handsets powered by Google-backed Android software tailored to synch with the exclusive Ninja Tel network.

The smartphones were handed out as "badges" to members of the Def Con community whose hacker accomplishments or whose legacies in the 20-year-old annual gathering have earned them "ninja" status.

"The ninjas represent a group of phenomenally intelligent people who share a common interest and passion," said John Hering, head of Lookout Mobile security startup and part of the team behind Ninja Tel.
"They are a center point for the community at Def Con; it is a very special thing."
Ninja Tel mobile phones only work within range of the van, which is parked in the middle of the Def Con event that continues through Sunday in the Rio Hotel and Casino in Las Vegas.

Contact numbers for anyone with a Ninja Tel phone are automatically listed in handsets, which also allow callers to playfully battle one another with virtual karate moves in a spin on the child's game Rock, Paper, Scissor.

Ninja Tel has a geek "Easter egg" -- the woman who was the original voice for recorded AT&T information messages during landline days of decades gone by did the voice-overs for the hacker network.

"It really is a throwback to a more simplistic era of telephony," Hering said. "It looks like the Yellow Pages, but it is a really sophisticated Android operating system."
Ninja Tel phones could also be used to signal vending machines scattered about Def Con to pop out free beer or soda using wireless technology at close range.

"We've made it hackable from the ground up," Hering said of the handsets.
"You can build your own apps and customize the device to do some more interesting things."

The team at Ninja Tel declined to reveal how much was spent on the project, which was pulled off with the backing of Facebook, Zynga, Qualcomm, and Lookout.

"It's a pretty ambitious project to build your own Telco, effectively, and your own device from scratch," Hering said.

The hacker mobile network came as the sun set on a Def Con tradition, the exclusive annual party hosted by Ninja Networks.

Ninja Networks is rooted in the original hackers whose time at Def Con dates back decades to when it was an intimate assembly of technology renegades.

Kaminsky smiled at the notion of Ninja Tel, seeing it as hackers "social engineering" major companies into buying them a mobile phone network.

"There are many definitions of the word 'hacking,' " Kaminsky said. "This is hacking on a corporate scale."


---------------------------------------------------------------------------------
Posted By Sundeep aka SunTechie

Sundeep is a Founder of Youth Talent Auzzar, a passionate blogger, a programmer, a developer, CISE and these days he is pursuing his graduation in Engineering with Computer Science dept.
Add Sundeep as a Friend on 

Using Reconnaissance to Gain Physical Access

Posted on:
tags: , , ,


Every weekday at 3 p.m. the Federal Express driver stops at the loading dock of a building where the offices of Medical Associates, Inc. are located. When the driver backs the truck up to the rear door of the building, he presses the buzzer and lets the security guard know he is at the door. Because the building’s security personnel recognize the driver—as he comes to the door every day around the same time for pickup and drop-off—they remotely unlock the door and allow the driver to enter. A hacker is watching this process from a car in the parking lot and takes note of the procedure to gain physical entry into the building.


The next day, the hacker carries a large cardboard box toward the door just as the Federal Express driver has been given entry to the building. The driver naturally holds the door for the hacker because he is carrying what appears to be a heavy, large box. They exchange pleasantries and the hacker heads for the elevator up to Medical Associates’ offices. The hacker leaves the box in the hallway of the building as he heads to his target office.


Once he reaches the front desk of the Medical Associates office, he asks to speak with the office manager whose name he previously looked up on the company website. The receptionist leaves her desk to go get the office manager, and the hacker reaches over the desk
and plugs a USB drive containing hacking tools into the back of her computer. Because the computer is not locked with a password, he double-clicks on the USB drive icon and it silently installs the hacking software on the receptionist’s computer. He removes the USB drive and quickly exits the office suite and building undetected.

This is an example of how reconnaissance and understanding the pattern of people’s behavior can enable a hacker to gain physical access to a target—in this case the Medical Associates network via a Trojaned system—and circumvent security checkpoints.


Reconnaissance
The term reconnaissance comes from the military and means to actively seek an enemy’s intentions by collecting and gathering information about an enemy’s composition and capabilities via direct observation, usually by scouts or military intelligence personnel trained in surveillance. In the world of ethical hacking, reconnaissance applies to the process of information gathering. Reconnaissance is a catchall term for watching the hacking target and gathering information about how, when, and where they do things. By identifying patterns of behavior, of people or systems, an enemy could find and exploit a loophole.



Fraudsters Now Using 3D Printers To Make Authentic Looking ATM Skimmers

Posted on:
tags: ,

What looks like the card slot from a Chase Bank ATM is actually a sophisticated card skimmer removed from a branch in West Hills, California. And police believe a 3D printer may have been used to create it.
Those green bulbous card slots that were supposed to make it very difficult for a card skimmer to be attached to an ATM have turned out to be just a minor inconvenience for sophisticated thieves. Investigators believe this skimmer—which perfectly fits over the ATM's regular slot— was created from a mould that came from a 3D printer. Which means those behind this particular ATM scheme had some very expensive tools at their disposal.
Fraudsters Now Using 3D Printers To Make Authentic Looking ATM SkimmersIn addition to being a perfect replica of the ATM's standard card slot, this skimmer incorporates a small pinhole camera that starts recording the PIN pad whenever a card is inserted. On the underside is a series of holes that investigators believe allowed the thieves to download data and footage, but the complex electronics on the inside may have been salvaged from a cellphone, giving this skimmer wireless connectivity. So in the future, like in many situations, make sure you take a good look at the hardware before you stick your thing in the slot.

Anonymous and Team Poison Join Forces For OpRobinHood to Target Banks and Give to Charities

Posted on:
tags: , , , ,


Two hacking groups, Anonymous and Team Poison, have joined forces to take on the banks, steal money and donate it to charities and protests. Reclaiming the "99 per cent's money back".
Apparently the plan is to swipe money from stolen credit card and bank details and donate it to charities and protest movements:
"Operation Robin Hood is going to return the money to those who have been cheated by our system and most importantly to those hurt by our banks. Operation Robin Hood will take credit cards and donate to the 99 per cent as well as various charities around the globe."
PoisAnon is relying on the fact that the banks will reimburse stolen cash from victim's credit cards, which is probably a safe bet, but would backfire horribly if that doesn't actually happen. Both hacker teams have had success in the past hacking into banks and are confident they can do it again. The thought of internet Robin Hoods running around helping out the poor is a noble proposition, but I can't see this not impacting your average Joe on the street. The money they intend to steal has to come from somewhere and almost everything ends up landing with the customer. 

TeamPoison Busts Into the UN and Leaks Passwords

Posted on:
tags: , , , ,


The tech security gurus at the United Nations just got quite a startle: A team of hackers posted about 1000 login credentials for United Nations staff members on PasteBin. Apparently a large number of the passwords were simply blank. Seriously, guys? After LulzSec?
The hackers at TeamPoison reportedly exploited a security vulnerability on the UN Development Program website to obtain the usernames and passwords of UN Staff. The group's post on PasteBin accuses the UN of a long list of crimes ranging from mundane corruption to more existential transgressions like trying "to facilitate the introduction of a New World Order and a One World Government" which would necessitate crushing human individuality. Sheesh.
TeamPoison previously hacked RIM's blog to and leaked Tony Blair's private address book. In a separate story this morning, Team Poison has publicly teamed up with Anonymous to launch a hacking operation against banks.

For Remembering Our 26/11 Heros -- UnicornGold A pakistani Website Hacked By Indishell Group

Posted on:
tags: , , ,



www.unicorngold.pk a pakistani website hacked by Indian Hackers Group Indishell. Website hacked due to dedication for our heros of 26/11.

but they deserve more !!!
Defacement written on the website is :
“This mass deface cyber attack is done by team ICA of www.indishell.in . We are the only real and first ever INDIA CYBER ARMY [ICA] made and existing !! Rest in the of 26/11 Mumbai Attacks !
26/11 Never Forgot your sacrifice and we never will let porkis and this this world foget it too !”
Anyhow, Congrats to every Indian…
JAI HIND!!!!!!!!

Hacking Book From A Great Indian Hacker

Posted on:
tags: , , , , , , ,

Manthan Desai is a sovereign Computer Security Consultant and has state-of-the-art familiarity in the field of computer.

An ethical hacker and a freelance web designer is famous for his website Hacking Tech (www.hackingtech.co.tv) which is 
ranked 2nd in the ucoz.com web hosting servers for security field.



Manthan is indeed a writer on the internet through his website. Over 10,000 visits have been incurred on his website and 
on the increase day by day.



Manthan is currently perusing his bachelor’s degree in computer science engineering and is working as and information 
security consultant and web designer.



He is providing the services like Ethical hacking training and workshops, website Development and maintenance, security 
consultant, graphic designing for website.



The one and the only quote that Manthan uses while his ethical hacking is “Hack it and Have it.”




Hacking For Beginners - a beginners guide for learning ethical hacking Download it from here.

INTERESTING FACTS ABOUT ETHICAL HACKING

Posted on:
tags: , , , ,

INTERESTING FACTS ABOUT ETHICAL HACKING




Ethical hacking enjoys great popularity in the world these days. The notion ethical hacking refers to the usage of programming skills in order to determine vulnerabilities of computer system. Ethical hacking is essentially different from non-ethical hacking in the causes for this penetration. The reasons for non-ethical hacking is mischief, personal gain etc. Meanwhile, the reasons of ethical hacking are evaluation of security system, introduction of changes to the available system with the objective to make computer system less likely to be attacked by non-ethical hackers.
So actually, ethical hacking represents an attack to the security system by a computer and network professional on behalf of its owner. High-Tech Bridge SA is the major Ethical Hacking organization that is founded in the city of Geneva, Switzerland. During short time High-Tech Bridge SA has reached impressive results on the market of IT technologies. Nowadays the company increases equity capital to CHF 2m and announces expansion both on Swiss and International IT Security markets. The target of the High-Tech Bridge SA is explained by Chief Executive Officer Mr. Ilia Kolochenko. According to him, the company's current plan is to accomplish acquisitions during the nearest three years so as to increase the organization's market share, as well as to invest CHF 1m in the company's Security Research laboratory with the objective to create a unique in-house knowledge base.
The Head of Ethical Hacking Department Mr. Frederic Bourla emphasized that the year of 2010 was a significant step in the technological development of the organization. During this year the personnel of Security Research lab was significantly increased, and new penetrating technologies and suitable ways of protection were created. The most popular service of High-Tech Bridge company is now different kinds of penetration tests with application of a unique know-how of the company. The organization also contributes to the social sphere by publishing some secutity advisories for software sellers. The peculiarity of High-Tech Bridge company is that they don't have reselling partnerships and remain absolutely neutral, in this way becoming an ideal security auditor.

Facebook Rumor Warns of Photo Tagging 'Virus'

Posted on:
tags: , , , , ,

A "new" viral message warns Facebook users of a virus supposedly transmitted when you receive a notification that you've been tagged in a picture and click on a link to see it. This is the text of the rumor:

NEW VIRUS ON FB using YOUR pictures. It says you've been tagged in a picture, wants you to click on a link to see it. Then hacks into YOUR computer & ALL YOUR ACCOUNTS including BANKING & other secure accounts. It DESTROYS YOUR COMPUTER. Once hacked into your comp; it sends e-mails to your friends telling them they have been TAGGED in pics & starts the process again. PLEASE RE-POST URGENT !!!!!!!!!!

This warning isn't really new — it's been circulating since last year, when it was debunked by Hoax-Slayer.com — nor is it entirely true. Facebook automatically notifies users when they've been tagged, and there's typically no harm in clicking through to tagged images. I've found no confirmation on Internet security sites of a related virus that "hacks into your secure accounts" or "destroys your computer."


Photo tagging spam
I have seen reports of an annoying phenomenon called "photo tagging spam" wherein marketers tag images with the names of people who don't actually appear in said images to advertise products or drive traffic to storefront websites. If you receive such a notification you can delete your name by viewing the image and clicking the "Remove My Tag" link (which should appear next to your name), and you can report the spammer by clicking the "Report this Photo" link below the picture.


◘ >