Showing posts with label Cyber Crime. Show all posts
Showing posts with label Cyber Crime. Show all posts

Sunday, 30 June 2013

Pakistani Hacker Sentenced 18 months in Prison due to Mutimillion Dollar ATM heists

Pakistani man "Imran Elahi" who was involve in two Multimillion-dollar ATM heists targeting debit card processors was sentenced in Brooklyn federal court on Friday to 18 months in prison.

Imran Elahi pleaded guilty last year to access device fraud and conspiracy, largely for his involvement in two precision strikes: a $9 million heist in 2008 involving RBS WorldPay and a $14 million hack in 2011 against Fidelity Information Services.


Investigators said these two incidents were similar to another massive heist for which 8 individuals were charged in May, 2013.

Elahi has helped investigators, so he might be released soon and sent back to Pakistan.

References: Softpedia, Reuters

Tuesday, 11 September 2012

Pirate Bay Founder Held In New Hacking Probe

Pirate Bay Founder Held In New Hacking Probe

Pirate Bay founder held in new hacking probe

Pirate Bay founder Gottfrid Svartholm Warg, who faces a year-long prison sentence for promoting copyright infringement, was detained on new computer hacking suspicions when he landed in Sweden on Tuesday morning.
Cambodia deports Pirate Bay founder to Sweden (11 Sep 12)
Cambodia to deport Pirate Bay co-founder (4 Sep 12)
Pirate Bay founder arrested in Cambodia (1 Sep 12)


According to a statement issued on Tuesday by the Swedish Prosecution Authority (Åklagarmyndigheten), Warg is suspected of having hacked into the Swedish Tax Agency (Skatteverket) as well as Swedish IT firm Logica, which supplies services to the agency.

"During a preliminary investigation concerning computer hacking at the company Logica and the Swedish Tax Agency during the spring, suspicions were directed at one person, Gottfrid Svartholm Warg," the Prosecution Authority wrote.

The agency added, however, that Warg's August 30th arrest in Cambodia and subsequent deportation from the country on Monday were due to an arrest warrant issued for him in relation to his conviction in the Pirate Bay trial.

Shortly after Warg's arrest, reports emerged that he was wanted in an investigation into a hacker attack against Logica and the tax agency.

According to a September 6th report in the Dagens Nyheter (DN) newspaper, the attacks gave the hackers access to a sizeable amount of protected personal information.

The attack is believed to have started in 2010 and continued until April of this year.

Warg, and his fellow co-founders Fredrik Neij and Peter Sunde, as well as financier Carl Lundström, were all convicted in 2009 of facilitating copyright infringement and ordered to pay 46 million kronor ($6.9 million) in damages to the music and movie industry.

While Neij, Sunde, and Lundström all had their 12-month sentences reduced to between four and 10 months on appeal in late 2010, Warg did not attend his appeal hearing and his one-year sentence was upheld.

Prosecutors now have until Friday to issue a remand order for Warg related to the new computer hacking suspicions.

Domino's India Web Site Hacked | Customer Data Leaked



Domino's India Web Site Hacked | Customer Data Leaked
The Indian Web site of pizza retailer Domino was hacked by a Turkish group, which leaked information from about 37,000 accounts online. The data included names, phone numbers, email addresses, and passwords.
In a report Tuesday by the Business Standard, the culprits behind the breach called themselves the Turkish Ajan Hacker Group.

The hack was done via SQL injection method and remote file inclusion, one of the most common methods for stealing private data from web databases, according to the news agency. The news daily explained that through this, the site's database is tricked into revealing data that should be hidden by ‘injecting’ certain commands.
The news follows a recent spate of hacking of company Web sites in India. In May, electricity company AP Power Generation had its site hacked by hacktivist group Anonymous. In March, the government revealed that 112 of its sites had been breached in the first three months of the year.

Sunday, 9 September 2012

Al Jazeera Says News Service Hacked Again

Al Jazeera Says News Service Hacked Again



Qatar-based Al Jazeera news network’s mobile service was hacked on Sunday, four days after a number of its Internet websites came under cyber attack, it reported on its website Al jazeera.net.
‘The story claiming that the Prime Minister (Sheikh Hamad bin Jassem) has been the target of an assassination attempt in the royal palace is completely false and was a result of hacking of the service,’ the channel said in breaking news.
The main Arab satellite news channel said the claim was among three false texts sent via its mobile service ‘which has been hacked.’
Social networks, including Twitter, quoted Al Jazeera’s mobile service on Sunday as saying that Shaikh Hamad was targeted in an attack on the palace in Doha and that the wife of the emir, Sheikha Moza bint Nasser, was lightly wounded.
On Wednesday, the network said that a number of its websites had been hacked, and Internet users reported that pro-Syrian regime slogans were posted on the broadcaster’s pages.
Internet reports had said that the websites of the Qatar-owned network appeared with a Syrian flag along with the word ‘Hack’ and a message saying the piracy was in ‘response to the hostile position of the channel towards Syria, its people and government.’
The message also cited Al Jazeera’s ‘spread of false news.’
Qatar has repeatedly voiced support for the Syrian opposition against President Bashar Al Assad’s regime and has openly called for arming rebels there, drawing strong criticism from Damascus which accuses Al Jazeera of pro-rebel bias.

Tuesday, 4 September 2012

Madisonville Police Officer Arrested for Breach of Security


Madisonville Police Officer Arrested for Breach of Security

A Madisonville Police Officer -- recently accused of hacking into a department computer -- has turned himself in for breach of security; a state jail felony.
Holding criminals accountable for their actions is a standard that's always upheld at the Madisonville Police Department -- even if it involves -- one of their own.
The tables were turned Friday after eight-year Madisonville Police veteran David Aaron Sims turned himself in to a Texas Ranger for the crime he's accused of committing in July.
The 46-year old peace officer allegedly hacked into a Madisonville Police sergeant's desktop computer where he allegedly removed confidential electronic files from the system. While the department cannot comment on the open investigation -- after learning of the alleged crime, the Madisonville Police Chief tells News 3 aTexas Ranger was called in to assist.
Sims has since been terminated pending the outcome of the investigation.
We spoke to Texas Ranger Steve Jeter who tells News 3 Sims was indicted Thursday; he then turned himself in Friday. He was booked inside the Madison County Jail on $1,500 bond. Furthermore, Jeter says the investigation has been turned over to the Madison County District Attorney's Office.

Sunday, 2 September 2012

Rita Ora's Twitter Page Hacked‎


Rita Ora’s twitter page hacked

British pop star posted that she has a crush on One Direction singer Harry Styles
British pop star Rita Ora has apologised to fans after a prankster hacked her Twitter account and posted that she has a crush on One Direction singer Harry Styles.
The 21-year-old got to know about the news on Saturday when she discovered a tweet on her page: “I wanna be with Harry Styles.”
She quickly deleted the message and told her 1.1 million followers she had contacted bosses at the social networking site about temporarily closing her account while resolving the problem, reports contactmusic.com.
“My Twitter has been hacked! Trying to get it frozen for a bit! Sorry guys,” she said.

Saturday, 1 September 2012

2 Indishell Members Arrested For Hacking Cell Recharge Site

2 Indishell Members Arrested For Hacking Cell Recharge Site



NOIDA: Two members of the hacker group, "Indishell", and its offshoots were arrested on Saturday after an extensive investigation by the Gautam Budh Nagar cyber crime cell. The accused, who did BTech in computer science, were charged with hacking into an e-commerce website that specializes in mobile recharge. Cops said four members of the gang with pan-India operations were at large. 

The hackers have cheated a Delhi-based company of more than Rs 50 lakh, police said. The accused, Sumit Gupta (24) and Ankit Singh(22), are from Moradabad in UP, and are considered one of the "most sophisticated hackers in the country". They were arrested from Noida and booked under Sections 420 of the IPC and 66C of the IT Act, 2008. 

"We received a complaint from the head of recharge of Memory Electronics Pvt Ltd about the website being hacked," said Triveni Singh, DSP (cyber crime cell) GB Nagar. 

The IP address used by the hackers was located in Sector 62 of Noida. Cops then zeroed in on the duo, allegedly involved in scores of hacking cases. To siphon off the money, the hackers would bypass the cc avenue payment gateway, cops said. "After hacking into the server, the accused obtained administrative rights of the website. when users asked for recharge of their cellphones, DTH cards, net cards, etc, the hackers would just key in the cell number and the amount to be topped up. However, no bill would be generated as the hackers had bypassed the payment page," Triveni said. 

"This way the recharge company would be debited every time without a bill, leading to losses worth several lakhs," the DSP said. 

The other accused who are yet to be arrested are also BTech graduates from across India. "Shrinivas, facebook name 'neo', is from Kohlapur in Maharashtra; Ajay Dhaka, alias dark look, is from Jaipur; Raman Kumar Rana, facebook name 'google warrior', is a resident of Pathankot; and Manmohan, alias 'mack', is from Muradabad," Triveni said. 

"We have found that Shrinivas is the founder and president of a cyber security and anti-hacking organization. But now he is involved in hacking himself and has made a business out of it," Triveni said.

Friday, 31 August 2012

Local UK Police Site Hacked, Personal Details Dumped Online

Local UK Police Site Hacked, Personal Details Dumped Online

herts-police-hack

Part of a Hertfordshire Police web site has been hacked, with the attacker uploading his stupid treasure trove of IP addresses and phone numbers of officers online.
Hertfordshire Police says the stolen data was hosted externally on a database associated with some sort of Neighbourhood Watch scheme, so the hacker wasn’t exactly setting his sights particularly high. The police site has been taken offline while staff investigate what was accessed and what actually turned up online as a result.
The hacker added the banner “OpFreeAssange” to the data he published along with quotes from the famous Ecuadorian immigrant, so it looks like this is some sort of weird revenge attack against authorities for pestering poor Julian — although the person responsible also said he wasn’t part of the notorious Anonymous collective

Thursday, 30 August 2012

Cyber attack takes Qatar's RasGas offline

RasGas, the second largest producer of Qatari LNG after Qatar Petroleum, has been hit with an "unknown virus" which has taken the company offline.

A RasGas spokesperson confirmed that “an unknown virus has affected its office systems" since Monday 27 August.

RasGas confirmed the situation by fax yesterday. “RasGas is presently experiencing technical issues with its office computer systems,” said the RasGas fax seen by Oil & Gas Middle East, dated 28 August. “We will inform you when our system is back up and running.”




Emails to verified addresses at RasGas bounced back with a permanent delivery failure error message. and the RasGas website (www.rasgas.com) is down.

The RasGas spokesman said the virus has “no impact whatsoever on operations in Ras Laffan Industrial City and there are no issues with cargo deliveries.”

“Everyone is reporting to work as normal,” the spokesman said. “We are working with ICT Qatar to resolve the situation as soon as possible.”

The news follows a malware attack against Saudi Aramco on 15 August which forced the world's largest oil company to take down its company-wide office systems for 12 days.

RasGas, a joint venture between QP and ExxonMobil, comprises seven giant LNG process trains in Ras Laffan, Qatar. The company exports 36.3m tonnes a year of LNG, most of which under long-term contracts with customers in Korea, India, Italy, Spain, Belgium, Taiwan, and the Americas. The company us also responsible for around 10% of global helium production.

Times reporter arrested over police blogger hacking


Times reporter arrested over police blogger hacking

Senior executives at The Times newspaper could be questioned by police investigating allegations of computer hacking after a former reporter was arrested on suspicion of conspiracy to pervert the course of justice.


A former Times reporter has been arrested for allegedly hacking into an anonymous police blogger’s email account in an attempt to expose his identity.


Patrick Foster, 28, a former media reporter at Rupert Murdoch’s paper, was arrested at his North London home this morning for allegedly hacking into the email account of an anonymous police blogger named Nightjack in 2009.
The Times subsequently went to the High Court and successfully overturned an injunction banning them from naming Nightjack as Lancashire Police detective Richard Horton.
At the hearing before Mr Justice Eady in June 2009, lawyers for the newspaper argued that Mr Foster had used legitimate journalistic methods to identify Mr Horton.
But the paper’s editor James Harding was later forced to apologise to Mr Justice Eady and Mr Horton, after admitting senior figures had failed to disclose that they knew about the computer hacking when the hearing took place.
In March this year the newspaper’s former legal chief, Alastair Brett, came under fire when he gave evidence to the Leveson Inquiry into press standards admitting he had made a “mistake” by failing to divulge that he knew about the hacking before the Times went to court.
Scotland Yard today confirmed that a 28-year-old journalist had been arrested over the alleged computer hacking, but stating that he was also being questioned over conspiracy to pervert the course of justice, related to the alleged cover up.
Mr Foster’s arrest is the 11th as part of Operation Tuleta, a Metropolitan Police Investigation into alleged computer hacking by journalists, but the first related to the Nightjack incident.
News International, publisher of Times, declined to comment on Mr Foster’s arrest.
The Metropolitan Police said in a statement on Wednesday: “Officers from Operation Tuleta, the investigation into criminal breaches of privacy including computer hacking which is being carried out in conjunction with MPS phone-hacking inquiries, arrested a man in North London this morning, 29 August.
“The 28-year-old man, a journalist (Tuleta arrest 11) was arrested at his home address at approximately 07.00 hrs for suspected offences under the Computer Misuse Act 1990 and suspected conspiracy to pervert the course of justice, contrary to the Criminal Law Act 1977
“He is being questioned at a North London police station about alleged computer hacking relating to the identification of a previously anonymous blogger in 2009.”
News International, publisher of Times, declined to comment on Mr Foster’s arrest.

Wednesday, 29 August 2012

Hackers release one million bank, web account details


Hackers release one million bank, web account details


Hackers release one million bank, web account details

A hacking group has released one million records and accounts from banks, government agencies and other sources.
The group, calling itself Team GhostShell posted compromised databases from a Chinese mainframe, a US stock exchange mainframe and access points to three or four Department of Homeland Security servers among other sources.
Security analysts have confirmed that the data released includes at least 30,000 records, with data including credit histories from banks, administrator login information, usernames and passwords and files from content management systems.
Security company Imperva said that a lot of the data appeared to have been taken using SQL injection attacks.
In a statement accompanying the records, Team GhostShell said that the ‘Project HellFire' release was its "final form of protest this summer against the banks, politicians and for all the fallen hackers this year".

Hackers allegedly breached Saudi Aramco again

Hackers allegedly breached Saudi Aramco again



Saudi Aramco, the national oil company of Saudi Arabia and the biggest oil company in the world, has issued a statement announcing that it has restored all its main internal network services that were impacted in a recent cyber attack which affected about 30,000 workstations - a number that corresponds with that shared by the Cutting Sword of Justice, the hacker group that took credit for the breach.

The company's primary enterprise systems of hydrocarbon exploration and production were unaffected as they operate on isolated network systems, the statement confirmed. The production plants were also fully operational.

“We addressed the threat immediately, and our precautionary procedures, which have been in place to counter such threats, and our multiple protective systems, have helped to mitigate these deplorable cyber threats from spiraling,” said Khalid A. Al-Falih, president and CEO of Saudi Aramco.

Published on Sunday, the statement doesn't contain any mention about further attacks by the hacker collective, despite one being announced and scheduled for the day before.

But the group didn't remain silent.

"We think it's funny and weird that there are no news coming out from Saudi Aramco regarding Saturday's night, they said in a new Pastebin post. "Well, we expect that but just to make it more clear and prove that we're done with we promised, just read the following facts -valuable ones- about the company's systems."

The post included the email and password of Khalid A. Al-Falih; information and access credentials of the company's core, backup and middle routers; and the security appliances used by the company and the fact that they all still have default passwords.

If the leaked information is legitimate, the situation doesn't bode well for the company, as the hackers announced one last paste, and who knows what information will be revealed in it.

Second accused LulzSec hacker arrested in Sony Pictures breach


Second accused LulzSec hacker arrested in Sony Pictures breach


(Reuters) - A second suspected member of the clandestine hacking group LulzSec was arrested on Tuesday on charges he took part in an extensive computer breach of Sony Pictures Entertainment, the FBI said.
Raynaldo Rivera, 20, of Tempe, Arizona, surrendered to U.S. authorities in Phoenix six days after a federal grand jury in Los Angeles returned an indictment charging him with conspiracy and unauthorized impairment of a protected computer.
If convicted, Rivera faces up to 15 years in prison.
The indictment, unsealed on Tuesday, accuses Rivera and co-conspirators of stealing information from Sony Corp's Sony Pictures' computer systems in May and June 2011 using an "SQL injection" attack against the studio's website, a technique commonly employed by hackers.
The indictment said Rivera then helped to post the confidential information onto LulzSec's website and announced the intrusion via the hacking group's Twitter account.
While Rivera was the only person named in the indictment, the FBI said his co-conspirators included Cody Kretsinger, 24, a confessed LulzSec member who pleaded guilty in April to federal charges stemming from his role in the Sony attack.
Following the breach, LulzSec published the names, birth dates, addresses, emails, phone numbers and passwords of thousands of people who had entered contests promoted by Sony, and publicly boasted of its exploits.
"From a single injection we accessed EVERYTHING," the hackers said in a statement at the time. "Why do you put such faith in a company that allows itself to become open to these simple attacks?"
Authorities have said the Sony breach ultimately cost the company more than $600,000.
LulzSec, an underground group also known as Lulz Security, is an offshoot of the international hacking collective Anonymous and has taken credit for such cyber incursions on a number of government and private sector websites.
The latest indictment says Rivera, who went by the online nicknames of "neuron," "royal" and "wildicv," is suspected of using a proxy server in a bid to conceal his Internet Protocol, or IP, address, and avoid detection.
Court documents revealed in March that an Anonymous leader known as Sabu, whose real name is Hector Monsegur, had pleaded guilty to hacking-related charges and provided information on his cohorts to the FBI.
That same month, five other suspected leaders of Anonymous, all them alleged to be LulzSec members as well, were charged by federal authorities with computer hacking and other offenses.
An accused British hacker, Ryan Cleary, 20, was indicted by a federal grand jury in June on charges related to LulzSec attacks on several media companies, including Sony Pictures.
Kretsinger, who pleaded guilty to the same two charges now facing Rivera, is slated to be sentenced on October 25. A federal prosecutor said he would likely receive substantially less than the 15-year maximum prison term carried by those offenses.
Anonymous and its offshoots focused initially on fighting attempts at Internet regulation and the blocking of free illegal downloads but have since taken aim at the Church of Scientology, global banking and other targets.
Anonymous, and LulzSec in particular, became notorious in late 2010 when they launched what they called the "first cyber war" in retaliation for attempts to shut down Wikileaks.
(Editing by Cynthia Johnston and Lisa Shumaker)

Hack on Saudi Aramco hit 30,000 workstations, oil firm admits


Hack on Saudi Aramco hit 30,000 workstations, oil firm admits 

Analysis Saudi Aramco said that it had put its network back online on Saturday, 10 days after a malware attack floored 30,000 workstations at the oil giant.
In a statement, Saudi Arabia's national oil firm said that it had "restored all its main internal network services" hit by a malware outbreak that struck on 15 August. The firm said its core business of oil production and exploration was not affected by the attack, which resulted in a decision to suspend Saudi Aramco's website for a period of a few days, presumably as a precaution. Corporate remote access services were also suspended as a result of the attack.
Oil and production systems were run off "isolated network systems unaffected by the attack, which the firm has pledged to investigate. In the meantime, Saudi Aramco promised to improve the security of its network to guard against fresh assaults.
Saudi Aramco has restored all its main internal network services that were impacted on August 15, 2012, by a malicious virus that originated from external sources and affected about 30,000 workstations. The workstations have since been cleaned and restored to service. As a precaution, remote Internet access to online resources was restricted. Saudi Aramco employees returned to work August 25, 2012, following the Eid holidays, resuming normal business.The company confirmed that its primary enterprise systems of hydrocarbon exploration and production were unaffected as they operate on isolated network systems. Production plants were also fully operational as these control systems are also isolated.
A previously unknown group called Cutting Sword of Justice claimed responsibility for the attack, which affected three in four of the estimated 40,000 workstations used by the oil giant. The group said that it had hacked Saudi Aramco in retaliation against the Al-Saud regime for the "crimes and atrocities taking place in various countries around the world, especially in the neighboring countries such as Syria, Bahrain, Yemen, Lebanon [and] Egypt".
The group said it hacked Aramco after compromising systems in "several countries" before implanting malware to "destroy 30,000 computers" within Aramco's network. The infected machines claim was made days before Saudi Aramco confirmed the same number of machines had been hit, lending credibility to the hacker group's claims.
Neither victim nor perpetrator named the malware that featured in the attack but security researchers implicated the Shamoon malware in the security breach (analysis by Seculert here). Shamoon, which emerged days before the assault, has both the capability to over-write data on infected machines and to destroy Master Boot Record files, thus making infected Windows machines impossible to boot.
Over-written files were reportedly replaced by an image of a burning US flag.
According to researchers, the malware also has the capacity to extract information from compromised before uploading it to the internet.
Core router names and admin passwords along with email address and supposed password of Saudi Aramco chief exec, Khalid A Al-Falih, were uploaded to Pastebin on Monday. The latest leak may be a result of the threatened follow-up attack, due to take place last weekend, rather than the fruits of the original malware-fuelled assault.
Rob Rachwald, director of security strategy at Imperva, described that Saudi Aramco attack as the first hacktivist-style assault to use malware.
"In the past, hacktivists have typically used application or distributed denial of service (DDoS) attacks - in which they clog a website with traffic until it goes offline. However, the attack on Saudi Aramco is the first significant use of malware in a hacktivist attack. Hacktivists rarely use malware, if other hacktivists jump on this trend it could become very dangerous," he said.
A blog post by Imperva on the attack can be found here.
Similar data-wiping malware disrupted systems at Iranian oil exploration facilities in May in an attack that led researchers at Kaspersky Lab to the discovery of the Flame cyber-espionage tool. US gas prospecting firms have been hit by previous attacks, most of which are suspected to have been state-sponsored.
It seems wise to view claims that the Saudi Aramco assault was a case of politically motivated hacktivism with some skepticism, at least until a clearer picture of the previously unknown Cutting Sword of Justice group emerges. It could be the group is solely motivated at hitting back at Saudi's ruling royal family for the country's support in putting down Arab Spring-style revolts in other nations, such as Bahrain, but other motives are also possible.
More commentary on the information security aspects of the attack can be found in a post on Sophos' Naked Security blog here. ®

Customers still 'in the dark' on cyber crime, warns EU agency


Cyber crime worth billions of euros is going unreported because companies are failing to admit to security breaches, according to a paper released Tuesday (28 August) by the EU's internet security agency.
  • Cyber-crime worth billions is going unreported, says the EU's internet agency 
In "Cyber incident reporting in the EU" the European Network and Information Security Agency (ENISA) highlighted a series of regulatory gaps in EU cyber laws. In its conclusions, ENISA admitted that although "large outages and large data breaches receive extensive media coverage.... many breaches, however, remain undetected and if detected, are not reported to authorities and not known to the public."
The report highlighted five major cyber incidents which all went unreported, including an 'IP hijacking' case in April 2010 where China Telecom fed incorrect routing information instructing US and other international Internet traffic to feed through Chinese servers, swallowing 15% of global Internet use in less than 20 minutes.
In a press statement accompanying the report, co-authors Dr Marnix Dekker and Chris Karsberg admitted that “cyber incidents are most commonly kept secret when discovered, leaving customers and policymakers in the dark about frequency, impact and root causes.”
Commenting that the "lack of transparency and lack of information about incidents makes it difficult for policy makers to understand the overall impact", the report added that this, in turn, "complicates the effort in the industry to understand and address cyber security incidents."
Under the EU Telecoms directive adopted in 2009, service providers are required to report "all significant security breaches" to ENISA and national data supervisors. Meanwhile, provisions of the recently adopted e-privacy directive requires service providers to report all security lapses compromising personal data.
ENISA revealed that it had received 51 incident reports for 2011-2012, the first year of mandatory reporting requirements, saying that it would publish an overview of cyber-security breaches in September and annual reports from spring 2013 onwards.
However, the data was incomplete, with a number of member states yet to implement the directive in to national law, it said. ENISA executive director, Professor Udo Helmbrecht insisted that EU cyber policy should extend the reporting provisions for companies describing it as "essential to obtain a true cyber security picture."
A Eurobarometer in July revealed that one in ten Europeans had been victims of data theft, while online security firm McAfee estimated that cyber-crime cost businesses $750bn (€600bn) in lost income across the world in 2011.
EU Digital Agenda Commissioner Neelie Kroes has repeatedly promised plans for a detailed cyber security strategy, including a European Cyber-Crime Centre based in Europol's Dutch headquarters which will start work in 2013. Speaking in January at the World Economic Forum, Kroes called for concerted action on cyber-crime claiming that there was a 10% chance of a major break-down of the worldwide computer network.

Hackers Claim to Have Breached Saudi Aramco Again on August 25


Hackers Claim to Have Breached Saudi Aramco Again on August 25



Hackers claim to have breached Saudi Aramco once again

Right after they attacked the systems of oil giant Saudi Aramco, the hackers promised to breach the company’s networks once again on August 25 and, according to a statement published on Pastebin, they succeeded.
While initially the company insisted that the damage was contained, in a recent statement they admitted that 30,000 workstations were affected by a malicious virus (just as the hackers said).

The firm’s representatives claimed that everything was restored to normal and that operations were resumed on August 25.

“We addressed the threat immediately, and our precautionary procedures, which have been in place to counter such threats, and our multiple protective systems, have helped to mitigate these deplorable cyber threats from spiraling,” explained Khalid A. Al-Falih, president and CEO of Saudi Aramco.

“Saudi Aramco is not the only company that became a target for such attempts, and this was not the first nor will it be the last illegal attempt to intrude into our systems, and we will ensure that we will further reinforce our systems with all available means to protect against a recurrence of this type of cyber-attack,” Al-Falih added.

There’s no mention of another attack on August 25, but according to a group of hackers, they did penetrate the organization’s networks once again.

“We think it's funny and weird that there are no news coming out from Saudi Aramco regarding Saturday's night. Well, we expect that but just to make it more clear and prove that we're done with we promised, just read the following facts -valuable ones- about the company's systems,” they wrote.

They published the details of core routers, backup routers, and middle routers, along with their access credentials which included clear text passwords.

They also made available Khalid Al-Falih’s email address and associated password (in clear text), and the security appliances utilized by the company to protect its infrastructures. 

“We think and truly believe that our mission is done and we need no more time to waste. I guess it's time for SA to yell and release something to the public. However, silence is no solution,” the hackers concluded.

It’s uncertain at this point if this hacker collective – which signed the file with “angry internet lovers #SH” – is connected in any way to “Cutting Sword of Justice,” the group which has taken credit for the previous attack.

Tuesday, 28 August 2012

Hackers Can Read Your Thoughts Inside Your Mind

Hackers Can Read Your Thoughts. It’s like phishing, only it happens inside of your skull.

 It’s hard to imagine something more futuristic than a helmet that lets you control machines with your mind. As if out of an X-Men comic, this technology became a reality about five years ago when not one but two devices, the NeuroSky MindWave and the Emotiv EPOC, that used brainwaves as an input hit the market. At first, the headsets were more or less novelties, a fun new way to play video games, but as the technology improved, all kinds of industries — from medicine to education, security to government — are looking for ways to take advantage of brain-controlled interfaces. We may never have to push a button again.



 Turns out there’s a downside to hooking your brain up to a computer. If you’re not careful, hackers could manipulate the game you’re playing or program you’re using and literally read your mind. (Sidenote: I’m pretty sure this was actually the horrifying premise of one of the latest X-Men movies and at least two Arnold Schwarzenegger flicks from the ‘90s.) A new study by a team of researchers from the University of California at Berkeley, Oxford and the University of Geneva shows how these devices can give unwarranted access to your private thoughts. By taking some backdoor approaches to reading the electronic signals the brain machines pick up, the team gained access to subconscious thoughts, including the location of the subjects’ homes and their banking PIN numbers.

 Hacking into someone’s brain isn’t exactly a straight-forward task. To find these private thoughts, By matching the EEG data of reactions from the first set with reactions from the second set, the researchers were able to when the subject recognized an image of something, say the location of their house on a map. It’s very basic mind-reading but mind-reading nevertheless.

 This doesn’t mean that thought thieves can come at your in the middle of the night, hook you up to a machine and download the contents of your brain. It is an indication that these brain-control devices pick up more information than what it needs to accomplish the task at hand.

 And, the researchers warned, the technology will improve over time and make it easier to identify and translate those signals. So you could look forward to hackers developing fake applications aimed at getting your brainwaves going.

 “In this threat model, the attacker doesn’t need to compromise anything,” says Dawn Song, a Berkeley computer science professor who helped lead the study. “He simply embeds the attack in an app, such as a game using [brain-machine interface] that the user downloads and plays. In this case, the malicious game designs and knows the visual stimuli the user is looking at and also gets the brain signal reading at the same time.” It’s like phishing, only it happens inside of your skull.

Oil giant Saudi Aramco workstations hit by malware Restored

Oil giant Saudi Aramco back online after workstations hit by malware.

 Aramco, Saudi Arabia’s national oil company, said on Sunday that the company was back in operation ten days after a massive malware outbreak hobbled 30,000 workstations at the company.

 In a statement on the company’s Facebook page (content alert: Facebook page contains images of extremely phallic architecture), Aramco said that it had “restored all its main internal network services” that were affected by a malware outbreak on August 15.


 The attack was attributed to “external sources.” It is just the latest against a national oil company, following reports of malware attacks on Iran’s oil infrastructure linked to the “Flame” malware in May.

 The malicious Trojan horse, which Sophos named Troj/MDrop-ELD, attempts to overwrite the master boot record on infected systems, which would make it impossible to boot the machine.

 Responsibility for the attack from a previously unknown group calling itself the “Cutting Sword of Justice.”

 The group posted details of the hack on Pastebin, and said that Aramco was attacked in retaliation against the Al-Saud regime for the “crimes and atrocities taking place in various countries around the world, especially in the neighboring countries such as Syria, Bahrain, Yemen, Lebanon (and) Egypt.

 Pastie bin link:
http://pastebin.com/HqAgaQRj

 We, behalf of an anti-oppression hacker group that have been fed up of crimes and atrocities taking place in various countries around the world, especially in the neighboring countries such as Syria, Bahrain, Yemen, Lebanon, Egypt and ..., and also of dual approach of the world community to these nations, want to hit the main supporters of these disasters by this action.

 One of the main supporters of this disasters is Al-Saud corrupt regime that sponsors such oppressive measures by using Muslims oil resources. Al-Saud is a partner in committing these crimes. It's hands are infected with the blood of innocent children and people.

 In the first step, an action was performed against Aramco company, as the largest financial source for Al-Saud regime. In this step, we penetrated a system of Aramco company by using the hacked systems in several countries and then sended a malicious virus to destroy thirty thousand computers networked in this company. The destruction operations began on Wednesday, Aug 15, 2012 at 11:08 AM (Local time in Saudi Arabia) and will be completed within a few hours.

 This is a warning to the tyrants of this country and other countries that support such criminal disasters with injustice and oppression. We invite all anti-tyranny hacker groups all over the world to join this movement. We want them to support this movement by designing and performing such operations, if they are against tyranny and oppression.



 Cutting Sword of Justice

 Attacks against private and public energy-producing firms are nothing new. In addition to the “Flame” malware attacks against Iran’s oil refineries, the US Department of Homeland Security warned in May about ongoing cyber attacks aimed at firms operating natural gas pipelines within the United States.

 In its Pastebin manifesto, Cutting Sword of Justice said its attack on Aramco was “a warning to the tyrants of this country and other countries that support such criminal disasters with injustice and oppression.” The group invited other “anti-tyranny hacker groups” to join the movement.

Saturday, 25 August 2012

Indian Hacker Playing with Pakistani Cyber Space

India Hacker Playing with Pakistani Cyber Space and Pakistani hacker watching silently. We have confirm that hackers attack on Pakistani cyber space increase 80% more in month of August. According to Indians IRC channels they are willing to attack more.


In the world of technology, it's not a war of drones and manual army between India and Pakistan but a war between the Cyber Army of both the nations since the eve of Independence that is still continued on Internet. Indian Hackers are united first time ever on Facebook claiming themselves as 'United Hackers of India' and are constantly preventing the Pakistani hackers to hack Indian websites. Indian hackers had jumped recently to a void Pakistani hackers to fuel the communal fire in India by defacing Indian websites.

On August 13, Indian hacker Coded32 appears with an idea to retaliate against Pakistani hackers - who were busy defacing Indian websites. Coded32 gathered all strong Indian hackers labeled as greyhats and whitehats.

Major hacker teams named Team OpenFire, Indian Cyber Force, IndiaShell, Indian Cyber Pirates many other teams got united and everyone attacked Pakistan telecom departments, educational centers, Railway centers and vowed to put down the NIC (National Informatics Center), PKNIC, of Pakistan on same day.

The United Indian hackers on their page uploads as, "We are Indian Hackers, it was not supposed to happen all the sudden this way, but hey who knew? We belong to India. We are one blood! We have one cause. STOP breaching Indian servers, you we bet, the whole Pakistan, Bangladesh, or whosoever breaches Indian Security will have to pay a big time that will be permanent, and irreversible."

Hackers named as coded32, 64, Xhunthacker, and code injector revealed HT: "At this, Pakistani hackers forces discussed among themselves and called for a peace deal between India-Pakistan and the cyber war on both the sides got over on 16th August.

But that was not the only end, Bangladesh, provoked up, and Indian hackers already knew most of the data were supplied by Pakistan Internally supporting them, to this current date Indian hackers are fighting with Bangladesh as cold war, attacking each other but with no direct terms and with negotiation."

One more new Group appear name as H2O, They hacked some Pakistani facebook pages contain huge fan clubs, They also leak some data about about admins of those pages.

Today Offical Shahi Afridi sites was also hacked by Indian Hacker http://www.shahidafridi.com.pk/ . This was also a huge security flaw.

In the End we try to find out the right number of hacked sites and came to result that yeah it is true that india hacked pakistani sites and it was about to 1,000 to 1500 and those server was already hacked by Indian hackers and only few mirror are made in zone-h. And the real reason of this artical is to increase the awareness of Security in Pakistani Cyber Space.

US general: We hacked the enemy in Afghanistan

The U.S. military has been launching cyber attacks against its opponents in Afghanistan, a senior officer said last week, making an unusually explicit acknowledgment of the oft-hidden world o
f electronic warfare.


Marine Lt. Gen. Richard P. Mills' comments came at a conference in Baltimore during which he explained how U.S. commanders considered cyber weapons an important part of their arsenal.

"I can tell you that as a commander in Afghanistan in the year 2010, I was able to use my cyber operations against my adversary with great impact," Mills said. "I was able to get inside his nets, infect his command-and-control, and in fact defend myself against his almost constant incursions to get inside my wire, to affect my operations."