오늘 우린 창의적인 천재를 잃었다. 그를 추모하며..

 


"I'm convinced that the only thing that kept me going was
that I loved what I did.
You've got to find what you love.
And that is as true for your work as it is for your lovers."
내가 계속할 수 있었던 유일한 이유는 내가 하는 일을
사랑했기 때문이라 확신합니다.
여러분도 사랑하는 일을 찾으셔야 합니다.
당신이 사랑하는 사람을 찾아야 하듯 일 또한 마찬가지입니다.
[스티브 잡스]





 Apple's passionate pitchman (10초 후 동영상 재생)

CNN|Added on August 24, 2011
Steve Jobs' enthusiasm and sense of humor were on full display at the launch of some of Apple's greatest hits.

[Source] CNN

Posted by bitfox
l
정말 신통방통한 마술쇼입니다.
얼마나 연습한 것일까요?

 Marco Tempest: The magic of truth and lies (and iPods)





Amazing~ :-D


[출처] TED http://www.ted.com/talks/marco_tempest_the_magic_of_truth_and_lies_on_ipods.html
Posted by bitfox
l
2011년 해외 굵직한 해킹 사고만을 정리한 뉴스가 있어 올려봅니다.

RSA Hack (3/17/2011) :

Motive - Unknown attacker, although China believed to be suspect. Motive is probably espionage
Method - Advanced Persistent Threat (APT) targeted at individuals within an organization using social engineering. Malware hidden in an Excel spreadsheet exploited a zero-day (unpatched) Flash hole.
Harm - SecurID token deployments at financial, government and other sites were at risk.

Comodo Hack and several of its digital certificate resellers (3/23/2011) :
Motive - 21-year-old Iranian patriot took credit saying he was protesting US policy and retaliating against the US for its alleged involvement with last year’s Stuxnet, which experts say was designed to target Iran’s nuclear program.
Method - Compromise of digital certificate registry authorities led to the theft of digital certificates that are used by sites to prove they are who they are legitimate.
Harm - If they had not been revoked the faked certificates could have been used to spoof sites like Google, Yahoo,Microsoft and Skype.

Sony (Indonesia, Japan , Thailand, Greece , Canada, Netherlands, Europe, Russia, Portugal) & Sony PlayStation Network Hacked (4/6/2011-6/8/2011) :
Motive - Lulzsec ,Anonymous, Lebanese hacker Idahc and various other hackers organized the attack in retaliation for Sony attempting to identify visitors to PlayStation 3 hacker George Hotz' blog site, as well as seeking data from his Twitter and YouTube accounts as part of a lawsuit. The case was later settled out of court.
Method - Distributed Denial-of-Service (DDoS), Sql injection
Harm - Defacement of various domains of Sony and Personal information of 77 million people, including customer names, addresses, e-mail addresses, birthdays, PlayStation Network and Qriocity passwords, user names, online handles and possibly credit cards were exposed.

Fox Network's X Factor (5/7/2011) :
Attacker - Lulzsec
Harm - X factor contestants personal information exposed and internal Fox data exposed.

PBS.org - Public Broadcasting Service Hacked (5/30/2011) :
Attacker - LulzSec in retaliation over Frontline Wikileaks program they considered biased
Method - zero-day exploit in Movable Type 4
Harm - Passwords were leaked and a fake news article was published on the page.


100's of Gmail users (6/1/2011) :
Motive - Google says attack originated in China and appeared designed to monitor communications of journalists, political activists and military personnel.
Method - After stealing passwords with a phishing attack, perpetrators apparently used the passwords to change Gmail users' forwarding and delegation settings.
Harm - Attack was "disrupted" but it's unknown if any snooping was accomplished.

Acer Europe Hacked (6/3/2011) :
Attacker - Pakistan Cyber Army
Method - Stupidity of Server admin
Harm - Source code and user data of 40,000 people reportedly compromised.

FBI partner Infragard Atlanta Hacked (6/3/2011) :
Motive - LulzSec, in an attempt to embarrass the FBI and security firm government contractors
Harm - Site was hacked, defaced and 180 Infragard usernames and passwords were leaked.

Citigroup Hacked (6/8/2011) :
Motive and Attacker - unknown
Harm - Names, account numbers, and contact information, including e-mail addresses, were accessed during the breach, which affected about 360,000 customers.

Turkish government (6/9/2011) :
Motive - Anonymous, in opposition to Internet filtering plan
Harm - site inaccessible temporarily

U.S. Senate hacked (6/13/2011) :
Motive - LulzSec, saying it doesn't like the U.S. government
Harm - published on the Web server's directory and file structure of the Senate site

Spanish National Police (6/13/2011) :
Motive - Anonymous, in retaliation for the arrest of three people in Spain
Harm - site was inaccessible temporarily

CIA Hacked (6/15/2011) :
Attacker - Lulzsec
Harm - site temporarily down

Electronic Arts hack (6/16/2011) :
Harm - System hosting BioWare Neverwinter Nights forum is breached and user names, encrypted passwords, e-mail addresses, mailing addresses, names, phone numbers, CD keys and birth dates may have been compromised. Some unencrypted passwords believed stolen.

Sega Hack (6/18/2011) :
some Sega Pass member e-mail addresses, dates of birth, and encrypted passwords compromised.

NATO Hack (6/23/2011) :
Motive - After NATO released a report singling out Anonymous' hacktivism as a cyber threat, the group warned NATO not to challenge it.
Harm - subscribers to NATO's e-Bookshop service were urged to change their passwords after a possible compromise of usernames, passwords, addresses and e-mail addresses.

Arizona Department of Public Safety (6/23/2011) :
Motive - LulzSec said it is leaking the data to protest "racial profiling anti-immigrant" policies of Arizona law enforcement, specifically SB1070, which makes it a crime to be in Arizona without documentation proving United States residency. Releases another batch of data on June 29.
Harm - publicly released hundreds of private intelligence bulletins, training manuals, personal e-mail correspondence, names, phone numbers, addresses and passwords belonging to Arizona law enforcement.

Former British Prime Minister Tony Blair Hack (6/24/2011) :
Motive - TeaMp0isoN says it targeted Blair over his support for the Iraq War
Harm - contents of his electronic address book, including contact data for members of Parliament

Arizona Department of Public Safety Hack (6/29/2011) :
Attacker - Antisec
Harm - hackers release second dump of data, including more personal data on specific officers

Al-Qaeda Hack (6/29/2011) :
Harm - hackers shut down al-Qaeda's Internet communications, halting the flow of videos and statements online

Arizona Fraternal Order of Police, Fraternal Order of Police in Mesa, Tucson Hack (6/30/2011):
Attacker - Antisec
Harm - 8 Web sites defaced, documents released including passwords and e-mail addresses of 1,200 officers, some financial data of specific officers and personal e-mails

Apple Hack (7/4/2011) :
Attacker - Antisec
Method - exploited security flaw in the software Apple used
Harm - 26 admin usernames and passwords for an Apple server exposed

Fox News Twitter account Hack (7/4/2011) :
Harm - The Fox News Twitter feed was used to publish false reports that President Obama had been killed.

German Federal Police Hack (German Federal Police) :
Attacker - n0-N4m3 Cr3w
Harm - The hackers compromised a server used by the country's customs service and posted location coordinates, license plate and telephone numbers, police usernames and passwords, and a GPS application in response to government communications interception.

News Corp. sites, The Sun and News International Hack (7/18/2011) :
Attacker - Lulzsec
Harm - Hackers redirected The Sun home page to fake story about death of News Corp. owner Rupert Murdoch, and then later to LulzSec's Twitter feed, as well as redirected a News International's page with a statement on the hack to the LulzSec Twitter feed. They also released phone numbers of News Corp. employees and an e-mail address and password for former Sun editor Rebekah Brooks, who is embroiled in the mobile phone voice mail hacking scandal at News of the World.

Italian Police's National Center for Computer Crime and the Protection of Critical Infrastructure (7/22/2011) :
Attacker - Antisec
Harm - Hackers claim to have stolen more than 8 GB of internal data that was allegedly seized during police investigations, including information on the Ministry of Transport in Egypt, Ministry of Defense in Australia, Russian companies and U.S. Justice Department. They threatened to publish it online.

72 public and private organizations in 14 countries Hack (8/2/2011) :
Motive - McAfee report does not speculate, but there's a pattern in the targets which do not include China but do include political non-profits, a pro-democracy organization, the World Anti-doping Agency, and the International Olympic Committee and Olympic committees in three countries, which were targeted right before and after the 2008 Olympic Games in Beijing.
Method - targeted phishing attacks with e-mail exploit that installed a back door
Harm - National secrets, classified government data, source code, bug databases, email archives, details for new oil and gas field auctions, legal contracts, SCADA configurations and more.

Citigroup Japan hack (8/5/2011) :
Method - A source said the scheme was perpetrated by a third-party vendor that had been given access to Citi's internal systems.
Harm - Personal information of 92,408 Citigroup credit card customers in Japan was stolen and sold to third parties, the bank said.

70 U.S. law enforcement agencies and police association in Italy Hacked (8/6/2011):
Attacker - Antisec
Harm - 10GB of personal information, private e-mails, passwords, training files, data from informants, Social Security numbers and stolen credit card information


Government of Syria (8/8/2011) :
Attacker - Anonymous
Harm - Home page of the Syrian Ministry of Defense site defaced with Anonymous logo and a call for the downfall of President Bashar al-Assad.

BlackBerry maker Research In Motion (RIM) Defacement (8/9/2011) :
Attacker - Team Poison
Harm - RIM's BlackBerry blog was hacked in retaliation for RIM offering to assist London police in combating rioters, many of whom are using BlackBerrys to organize.

Hong Kong stock exchange Hack (8/10/2011) :
Harm - Hackers broke into news site of Hong Kong stock exchange, where corporate filings are published, forcing the suspension of trading for seven companies.


[출처]http://thehackernews.com/2011/09/its-fail-2011-year-of-hacks.html
Posted by bitfox
l

요즘 TED를 보면서 참신한 아이디어를 많이 얻는다.
왜 이렇게 좋은 사이트를 몰랐을까..-0-;;
2008년 재미교포로 보여지는 Johnny Lee 씨는 Wii를 해킹하여 다양한 디바이스를 보여주고 있다.



[출처] http://www.ted.com/talks/johnny_lee_demos_wii_remote_hacks.html
Posted by bitfox
l

Jeff Han demos his breakthrough touchscreen

5년전에 이렇게 시연하다니..지금의 아이패드보다 더 멋지다.
진정한 카피캣은 애플인가? ㅎ

[출처] http://www.ted.com/talks/jeff_han_demos_his_breakthrough_touchscreen.html

Posted by bitfox
l
u토렌트와 비트토렌트 사이트가 해킹당했다. 기사를 보면 어제(화요일) 태평양 표준(11:20)시 1시간 정도(4:20 a.m. ~ 6:10 a.m.) 해킹당하였으며 "Security Shield"란 프로그램을 다운 받으면 바이러스에 감염되었을 수 있다.

uTorrent & BitTorrent Sites Hacked, Spread Security Shield Malware


Attackers hijacked two popular Torrent websites "bittorrent.com and utorrent.com" and tampered with their download mechanisms, causing visitors trying to obtain file-sharing software to instead receive malware. The site reported on its blog that the attack had occurred at around 04:20 Pacific Daylight Time (11:20 GMT) on Tuesday. Initially, the incursion was also thought to have affected the servers of the main BitTorrent site, but further investigation revealed this site had been unaffected by the attack.

Once installed, Security Shield delivers false reports that a computer is infected with multiple pieces of malware and prompts the user for payment before claiming to disinfect the machine. The attack affected only users who downloaded and installed software from bittorrent.com and utorrent.com during the hour-and-fifty-minute window that the sites were compromised. Those who installed software previously are unaffected.

"We have completed preliminary testing of the malware. Upon installation, a program called ‘Security Shield" launches and pops up warnings that a virus has been detected. It then prompts a user for payment to remove the virus. " experts write on the blog.

It is very important to once more note that infected are only users who have downloaded the software between 4:20 a.m. and 6:10 a.m. Pacific time. If you have previously downloaded it - you can rest assured your software is clean.

[출처] http://thehackernews.com/2011/09/utorrent-bittorrent-sites-hacked-spread.html
Posted by bitfox
l
지난 9월 10일.
미국 NBC News 트위터 계정이 해킹되어 9/11 테러에 대한 허위 기사가 나갔었습니다.
스크립키드로 추정되고 있으며 그라운드 제로에 다시 한번 테러가 났다는 브레킹 뉴스를 보내고 있습니다.
흠..장난 치고는 좀 그렇죠;;

관련기사
NBC News Twitter account hacked & post fake news of 9/11


Hackers have broken into the Twitter account of NBC News and posted messages claiming that there has been a terrorist attack at Ground Zero in New York. Coming two days before the tenth anniversary of the 9/11 attacks, the prank by a group calling themselves the 'script kiddies' was greeted with widespread opprobrium from other twitter users."Breaking News! Ground Zero has just been attacked. Flight 5736 has crashed into the site, suspected hijacking. More as the story develops," was the first tweet this afternoon. It was followed by two others, including one that started "This is not a joke." The fourth tweet said "NBCNEWS hacked by The Script Kiddies."
Luke Russert, who covers politics for NBC News, also tweeted: "Please ignore NOT TRUE tweets coming from @NBCNews. We got hacked by tasteless despicable attention seeking criminals." Some experts suspect that script kiddies, who are thought to have hacked a Fox News account two weeks ago, are British although this had not been confirmed.


출처 : http://thehackernews.com/2011/09/nbc-news-twitter-account-hacked-post.html
Posted by bitfox
l
9월 11일 PANDA Security 파키스탄 도메인 계정 해킹되었군요. zohn-h에 올라와 있다는데..
보안 업체들도 수난 시대입니다.

관련기사..........

Panda Security (Pakistan domain) hacked by X-NerD


Panda Security, One of the famous Computer software company website got hacked. Pakistan domain of Panda Security hacked by Pakistani hacker "X-NerD". Hacker is from Pakistan Cyber Army team of hackers. Taunt by hacker on deface page "OoooOOPss...I am ShockeD At YouR SecuritY..S3cuR!tY L3vEL Z3r0...YOu Dont KnoW HOw To SecurRe Your AsS n Pr0vidinG SEcurity to 0therS...Big LauGh...". Yesterday X-Nerd was in news for hacking Hundreds of other domains. Mirror of hack on Zone-H.


출처: http://thehackernews.com/2011/09/panda-security-pakistan-domain-hacked.html
Posted by bitfox
l
이스라엘과 터키간의 사이버 전쟁이 다시 시작되었다. 워낙 역사적으로 앙숙관계이고 이 친구들은 한번 붙으면 피해가 수백만 달러에 이른다고 한다.
요즘 DNS 업체에 공격이 많이 들어오는데.. 그 만큼 보안상 중요한 업체이기 때문이다.
얼마전 국내 G모 DNS 업체가 공격당해 피해 정보는 공개적으로 알려지지 않았으나 외국 보도에 따르면 100,000 건의 도메인과 350,000명의 개인정보가 유출 되었다고 한다.
이 뉴스를 보면 우리나라도 사이버 전에 대한 대비방안을 견고히 구축해야 할 것 같다.


[관련기사]

Israeli-Turkish Cyberwar Begins

Turkish hackers launched a DNS attack on 350 Israeli websites in what experts believe was a test run for attacks on Israeli domains.
Cyberwarfare
Amid the current diplomatic impasse between Ankara and Jerusalem, Turkish hackers hijacked some 350 Israeli websites on Sunday evening, launching a Domain Name System (DNS) attack on dozens of other websites as well.

Israeli IT analysts said Tuesday the DNS hijacking is likely to be, in fact, a "test-run" ahead of a major attack on Israeli domains.

Visitors to some of the sites were diverted to a page declaring it was “World Hackers Day."

At least seven high-profile websites outside Israel were also hijacked, including those of The Telegraph, Acer, National Geographic, UPS and Vodafone.

Hackers calling themselves the "TurkGuvenligi group" claimed they had done the cyber-attack. TurkGuvenligi translates as "Turkish security."
.....

[출처 및 더 보기] http://www.israelnationalnews.com/News/News.aspx/147603

Posted by bitfox
l
1년만에 나의 PC에 먼지를 털어냈다. 키보드와 마우스는 항상 청결(?)을 유지하지만..
본체를 열고 청소한다는게 여간 귀찮은 일이 아니다.

하지만 인터넷에 올라온 사진을 보면.. 여러분도 청소할 수 밖에... >_<;; ㅋ

제목:

Filthy PCs: The X-rated circus of horrors


 


ㅋ 맨 마지막 사진이 압권이다.
청결한 PC를 만듭시다.

[사진 출처] http://www.theregister.co.uk/2010/11/26/ventblockers_2/page11.html
Posted by bitfox
l