'글로벌_Gossip/2011'에 해당되는 글 24건

  1. 2011.12.26 [뉴스] 안드로이드용 프리 백신 avast mobile by bitfox
  2. 2011.10.21 다시 위협되고 있는 Mass-Sql injection by bitfox
  3. 2011.10.18 0day Full disclosure: American Express by bitfox
  4. 2011.10.18 BlueStacks: App player tool for windows by bitfox
  5. 2011.10.13 HTML5 Security by bitfox 2
  6. 2011.10.11 Exclusive: Computer Virus Hits U.S. Drone Fleet by bitfox
  7. 2011.10.06 Steve Jobs, Apple founder, dies by bitfox
  8. 2011.09.20 진실과 거짓의 마술(그리고 아이팟) by bitfox
  9. 2011.09.19 2011년 해외 해킹사례 정리 by bitfox
  10. 2011.09.18 Johnny Lee demos Wii Remote hacks by bitfox

안드로이드용 프리 백신이 공개되었네요. 아직 전 옴니아 유저라 사용해 보진 못했지만 ㅡ_-+
항상 바이러스때문에 안드로이드 폰에 대해 우려하셨던 분들은 사용해 보시길 바랍니다.
현재 적용되는 버젼은 Android 2.1.x, 2.2.x, or 2.3.x 이며 안드로이드 마켓을 이용하시면 됩니다.

Android Market

[사진 출처] thehackernews.com






Posted by bitfox
l

어제 해커 뉴스에 나온 내용을 바탕으로 국내 감염 실태를 확인해 봤습니다.
여러 패턴이 있지만 그 중에 이슈가 되는 IIS/ASP.net만 노리는 "hxxp://jjghui.com/urchin.js"를
대상으로 확인해보니..


무려 백오십만건이 발견되었습니다. 간단한 구글링만으로.. 물론 중복된 링크도 있겠지만 더 많을
것으로 파악하고 있습니다. 필자가 뉴스를 접했을 때 백만건 정도 였으나 뉴스에 나온것보다 30%증가한 수치네요..-0-;;

문제는 백오십만건 중 국내 사이트는...

 

거의 6십만건에 이르고 있습니다. 그 중에 공공기관도 몇 군대 발견되었는데..
1차 피해보다는 2차, 3차 감염 피해가 우려되는 상황입니다.

[경고 : 검색된 위에 사이트에 접근시 바이러스 감염 및 침해 당할 수 있으니 안전한 조치가 
없을시 촉수 불가 합니다.]


이 지능적인 Mass-Sql 인젝션에 대해 공격에 대한 정보 및 대응 방안은 링크로 첨부하겠습니다.

[Mass SQL Injection Attack Hits Sites Running IIS] Link
[Mass infection of IIS/ASP sites] Link
[SQL/JavaScript Hybrid Worms] Link



오늘도 지뢰밭을 피해 안전한 검색 하시길.. -0-;; 

Posted by bitfox
l
지난 10월 6일 American Express(이하 AMEX)가 어처구니 없는 보안 사고를 일으켰었군요.;
관리자 페이지가 노출되고 있었고 그 안에 정보가..ㄷㄷㄷ

 


자세한 건 링크...
LINK



고객의 가장 중요한 고급 정보를 지니고 있는 AMEX가 이렇게 웹사이트를 운용하다니 일반인이나 IT인들에게 조롱거리가 되는건 시간 문제겠군요.
트윗을 통해 담당자의 연락처를 알아보고 전달했다는..씁쓸한 얘기였습니다. 그리고
Max Niederhofer의 정보에 의하면..이런 취약점이..-0-;;

 


빨리 조치되길 바랄뿐 입니다.


[주의] 본 자료는 연구용 및 학습 자료로 사용하길 바라며, 악의적인 사용시 사용자 본인에게 책임이 있음을 명시합니다.
Posted by bitfox
l
이젠 앱게임을 윈도우에서도 즐길수 있게 되었네요. ㅎㅎ
전세가 역전되는 건가봅니다. 고사양의 스마트폰을 무기로 각종 게임이 나오고 있으니.. 단순하지만 중독성있는 겜을 즐겨봅시다. (보안쪽으로 보면 이제 앱을 PC로 다운받아 실행시켜 개인정보노출 및 코드 결함을 알아볼수 있겠네요..^^;)

We all know about android and big and growing applications market. most of us must be using windows and their operating system. And many of us also must be thing of using this apps on windows machine. BlueStacks will make android run on windows machine.


BlueStacks 관련 데모 영상


BlueStacks 기능

Features of BlueStacks

  • Play Android apps fast and full-screen
  • Push your favorite apps from your Android phone to your PC using BlueStacks Cloud Connect
  • Run 10 pre-loaded apps “out of the box”
  • Install up to 26 more of your favorite apps
  • May not work fast on older netbooks and tablets
  • Available now for Win7, and it’s Free


[다운로드 링크] 

Download BlueStacks Click 

[출처] pentestit.com
Posted by bitfox
l
HTML5의 보안 취약점에 대해 미리 알아보자




[출처]slideshare.net
Posted by bitfox
l

 미군의 무인 항공기 프레데터와 랩터 드론이 전쟁지역인 아프칸에서 키로깅 바이러스에 감염되었다는 군요~ ;( 전술 및 전략이 다 노출되었을 가능성이 있네요.


A computer virus has infected the cockpits of America’s Predator and Reaper drones, logging pilots’ every keystroke as they remotely fly missions over Afghanistan and other warzones.

The virus, first detected nearly two weeks ago by the military’s Host-Based Security System, has not prevented pilots at Creech Air Force Base in Nevada from flying their missions overseas. Nor have there been any confirmed incidents of classified information being lost or sent to an outside source. But the virus has resisted multiple efforts to remove it from Creech’s computers, network security specialists say. And the infection underscores the ongoing security risks in what has become the U.S. military’s most important weapons system.

자세히


Photo courtesy of Bryan William Jones

[출처]
wired.com

'글로벌_Gossip > 2011' 카테고리의 다른 글

BlueStacks: App player tool for windows  (0) 2011.10.18
HTML5 Security  (2) 2011.10.13
Steve Jobs, Apple founder, dies  (0) 2011.10.06
진실과 거짓의 마술(그리고 아이팟)  (0) 2011.09.20
2011년 해외 해킹사례 정리  (0) 2011.09.19
Posted by bitfox
l
오늘 우린 창의적인 천재를 잃었다. 그를 추모하며..

 


"I'm convinced that the only thing that kept me going was
that I loved what I did.
You've got to find what you love.
And that is as true for your work as it is for your lovers."
내가 계속할 수 있었던 유일한 이유는 내가 하는 일을
사랑했기 때문이라 확신합니다.
여러분도 사랑하는 일을 찾으셔야 합니다.
당신이 사랑하는 사람을 찾아야 하듯 일 또한 마찬가지입니다.
[스티브 잡스]





 Apple's passionate pitchman (10초 후 동영상 재생)

CNN|Added on August 24, 2011
Steve Jobs' enthusiasm and sense of humor were on full display at the launch of some of Apple's greatest hits.

[Source] CNN

Posted by bitfox
l
정말 신통방통한 마술쇼입니다.
얼마나 연습한 것일까요?

 Marco Tempest: The magic of truth and lies (and iPods)





Amazing~ :-D


[출처] TED http://www.ted.com/talks/marco_tempest_the_magic_of_truth_and_lies_on_ipods.html
Posted by bitfox
l
2011년 해외 굵직한 해킹 사고만을 정리한 뉴스가 있어 올려봅니다.

RSA Hack (3/17/2011) :

Motive - Unknown attacker, although China believed to be suspect. Motive is probably espionage
Method - Advanced Persistent Threat (APT) targeted at individuals within an organization using social engineering. Malware hidden in an Excel spreadsheet exploited a zero-day (unpatched) Flash hole.
Harm - SecurID token deployments at financial, government and other sites were at risk.

Comodo Hack and several of its digital certificate resellers (3/23/2011) :
Motive - 21-year-old Iranian patriot took credit saying he was protesting US policy and retaliating against the US for its alleged involvement with last year’s Stuxnet, which experts say was designed to target Iran’s nuclear program.
Method - Compromise of digital certificate registry authorities led to the theft of digital certificates that are used by sites to prove they are who they are legitimate.
Harm - If they had not been revoked the faked certificates could have been used to spoof sites like Google, Yahoo,Microsoft and Skype.

Sony (Indonesia, Japan , Thailand, Greece , Canada, Netherlands, Europe, Russia, Portugal) & Sony PlayStation Network Hacked (4/6/2011-6/8/2011) :
Motive - Lulzsec ,Anonymous, Lebanese hacker Idahc and various other hackers organized the attack in retaliation for Sony attempting to identify visitors to PlayStation 3 hacker George Hotz' blog site, as well as seeking data from his Twitter and YouTube accounts as part of a lawsuit. The case was later settled out of court.
Method - Distributed Denial-of-Service (DDoS), Sql injection
Harm - Defacement of various domains of Sony and Personal information of 77 million people, including customer names, addresses, e-mail addresses, birthdays, PlayStation Network and Qriocity passwords, user names, online handles and possibly credit cards were exposed.

Fox Network's X Factor (5/7/2011) :
Attacker - Lulzsec
Harm - X factor contestants personal information exposed and internal Fox data exposed.

PBS.org - Public Broadcasting Service Hacked (5/30/2011) :
Attacker - LulzSec in retaliation over Frontline Wikileaks program they considered biased
Method - zero-day exploit in Movable Type 4
Harm - Passwords were leaked and a fake news article was published on the page.


100's of Gmail users (6/1/2011) :
Motive - Google says attack originated in China and appeared designed to monitor communications of journalists, political activists and military personnel.
Method - After stealing passwords with a phishing attack, perpetrators apparently used the passwords to change Gmail users' forwarding and delegation settings.
Harm - Attack was "disrupted" but it's unknown if any snooping was accomplished.

Acer Europe Hacked (6/3/2011) :
Attacker - Pakistan Cyber Army
Method - Stupidity of Server admin
Harm - Source code and user data of 40,000 people reportedly compromised.

FBI partner Infragard Atlanta Hacked (6/3/2011) :
Motive - LulzSec, in an attempt to embarrass the FBI and security firm government contractors
Harm - Site was hacked, defaced and 180 Infragard usernames and passwords were leaked.

Citigroup Hacked (6/8/2011) :
Motive and Attacker - unknown
Harm - Names, account numbers, and contact information, including e-mail addresses, were accessed during the breach, which affected about 360,000 customers.

Turkish government (6/9/2011) :
Motive - Anonymous, in opposition to Internet filtering plan
Harm - site inaccessible temporarily

U.S. Senate hacked (6/13/2011) :
Motive - LulzSec, saying it doesn't like the U.S. government
Harm - published on the Web server's directory and file structure of the Senate site

Spanish National Police (6/13/2011) :
Motive - Anonymous, in retaliation for the arrest of three people in Spain
Harm - site was inaccessible temporarily

CIA Hacked (6/15/2011) :
Attacker - Lulzsec
Harm - site temporarily down

Electronic Arts hack (6/16/2011) :
Harm - System hosting BioWare Neverwinter Nights forum is breached and user names, encrypted passwords, e-mail addresses, mailing addresses, names, phone numbers, CD keys and birth dates may have been compromised. Some unencrypted passwords believed stolen.

Sega Hack (6/18/2011) :
some Sega Pass member e-mail addresses, dates of birth, and encrypted passwords compromised.

NATO Hack (6/23/2011) :
Motive - After NATO released a report singling out Anonymous' hacktivism as a cyber threat, the group warned NATO not to challenge it.
Harm - subscribers to NATO's e-Bookshop service were urged to change their passwords after a possible compromise of usernames, passwords, addresses and e-mail addresses.

Arizona Department of Public Safety (6/23/2011) :
Motive - LulzSec said it is leaking the data to protest "racial profiling anti-immigrant" policies of Arizona law enforcement, specifically SB1070, which makes it a crime to be in Arizona without documentation proving United States residency. Releases another batch of data on June 29.
Harm - publicly released hundreds of private intelligence bulletins, training manuals, personal e-mail correspondence, names, phone numbers, addresses and passwords belonging to Arizona law enforcement.

Former British Prime Minister Tony Blair Hack (6/24/2011) :
Motive - TeaMp0isoN says it targeted Blair over his support for the Iraq War
Harm - contents of his electronic address book, including contact data for members of Parliament

Arizona Department of Public Safety Hack (6/29/2011) :
Attacker - Antisec
Harm - hackers release second dump of data, including more personal data on specific officers

Al-Qaeda Hack (6/29/2011) :
Harm - hackers shut down al-Qaeda's Internet communications, halting the flow of videos and statements online

Arizona Fraternal Order of Police, Fraternal Order of Police in Mesa, Tucson Hack (6/30/2011):
Attacker - Antisec
Harm - 8 Web sites defaced, documents released including passwords and e-mail addresses of 1,200 officers, some financial data of specific officers and personal e-mails

Apple Hack (7/4/2011) :
Attacker - Antisec
Method - exploited security flaw in the software Apple used
Harm - 26 admin usernames and passwords for an Apple server exposed

Fox News Twitter account Hack (7/4/2011) :
Harm - The Fox News Twitter feed was used to publish false reports that President Obama had been killed.

German Federal Police Hack (German Federal Police) :
Attacker - n0-N4m3 Cr3w
Harm - The hackers compromised a server used by the country's customs service and posted location coordinates, license plate and telephone numbers, police usernames and passwords, and a GPS application in response to government communications interception.

News Corp. sites, The Sun and News International Hack (7/18/2011) :
Attacker - Lulzsec
Harm - Hackers redirected The Sun home page to fake story about death of News Corp. owner Rupert Murdoch, and then later to LulzSec's Twitter feed, as well as redirected a News International's page with a statement on the hack to the LulzSec Twitter feed. They also released phone numbers of News Corp. employees and an e-mail address and password for former Sun editor Rebekah Brooks, who is embroiled in the mobile phone voice mail hacking scandal at News of the World.

Italian Police's National Center for Computer Crime and the Protection of Critical Infrastructure (7/22/2011) :
Attacker - Antisec
Harm - Hackers claim to have stolen more than 8 GB of internal data that was allegedly seized during police investigations, including information on the Ministry of Transport in Egypt, Ministry of Defense in Australia, Russian companies and U.S. Justice Department. They threatened to publish it online.

72 public and private organizations in 14 countries Hack (8/2/2011) :
Motive - McAfee report does not speculate, but there's a pattern in the targets which do not include China but do include political non-profits, a pro-democracy organization, the World Anti-doping Agency, and the International Olympic Committee and Olympic committees in three countries, which were targeted right before and after the 2008 Olympic Games in Beijing.
Method - targeted phishing attacks with e-mail exploit that installed a back door
Harm - National secrets, classified government data, source code, bug databases, email archives, details for new oil and gas field auctions, legal contracts, SCADA configurations and more.

Citigroup Japan hack (8/5/2011) :
Method - A source said the scheme was perpetrated by a third-party vendor that had been given access to Citi's internal systems.
Harm - Personal information of 92,408 Citigroup credit card customers in Japan was stolen and sold to third parties, the bank said.

70 U.S. law enforcement agencies and police association in Italy Hacked (8/6/2011):
Attacker - Antisec
Harm - 10GB of personal information, private e-mails, passwords, training files, data from informants, Social Security numbers and stolen credit card information


Government of Syria (8/8/2011) :
Attacker - Anonymous
Harm - Home page of the Syrian Ministry of Defense site defaced with Anonymous logo and a call for the downfall of President Bashar al-Assad.

BlackBerry maker Research In Motion (RIM) Defacement (8/9/2011) :
Attacker - Team Poison
Harm - RIM's BlackBerry blog was hacked in retaliation for RIM offering to assist London police in combating rioters, many of whom are using BlackBerrys to organize.

Hong Kong stock exchange Hack (8/10/2011) :
Harm - Hackers broke into news site of Hong Kong stock exchange, where corporate filings are published, forcing the suspension of trading for seven companies.


[출처]http://thehackernews.com/2011/09/its-fail-2011-year-of-hacks.html
Posted by bitfox
l

요즘 TED를 보면서 참신한 아이디어를 많이 얻는다.
왜 이렇게 좋은 사이트를 몰랐을까..-0-;;
2008년 재미교포로 보여지는 Johnny Lee 씨는 Wii를 해킹하여 다양한 디바이스를 보여주고 있다.



[출처] http://www.ted.com/talks/johnny_lee_demos_wii_remote_hacks.html
Posted by bitfox
l