Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

DEF-CON Bangalore September 2012 Meet-Call for Papers


September 2012, DEF-CON Meet (Bangalore Chapter) is the platform for the presentation of new advances and research results in the fields of theoretical, experimental, and applied Computer Technology and Science. The paper presentation held as part of The Meet attracts some of the best minds from all over the country. Participants are invited to present papers spanning various research topics pertaining to the different branches of engineering.

Topics of interest for submission include, but are not limited to:

  • New Vulnerabilities and Exploits/0-days
  • Open Source Security&Hacking Tools
  • Antivirus/Firewall/UTM Evasion Techniques
  • Software Testing/Fuzzing
  • Network and Router Hacking
  • Malware analysis & Reverse Engineering
  • Mobile Application Security-Threats and Exploits
  • Advanced Penetration testing techniques
  • Web Application Security & Hacking
  • Browser Security
  • Hacking virtualized environment
  • WLAN and Bluetooth Security
  • Lockpicking & physical security
  • Honeypots/Honeynets
  • Exploiting Layer 8/Social Engineering
  • Cloud Security
  • Critical Infrastructure & SCADA networks Security
  • National Security & Cyber Warfare
  • Cyber Forensics, Cyber Crime & Law Enforcement

PS: This is just a sample, the topics can be anything and everything related to computer science and security engineering.

Procedure for submitting your papers:-

Your submissions should follow the following format.

1. Author name
2. Title of the Paper
3. Email Address
4. Mobile Number
5. Provide Supporting Materials for your paper in form of PDF or Links
6. Presentation Format must be in PDF for submission.

Send your submissions to: defconbangalore@gmail.com

Important Dates

Date for Abstract Submission : 29th June 2012

Date for Notification of Selection : 8th July 2012

Date for Final submission of full paper : 15th August 2012
DEF-CON Bangalore Meet Scheduled on: 9th September 2012

Harvard &North Philippines University website Hacked, Accounts Leaked

Indian Hackers have managed to hack into a sub-domain of Harvard (http://steele.mgh.harvard.edu/). According to the Hackers "The website was vulnerable to Sql Injection" .

Hackers leaked the compromised database in pastebin(http://pastebin.com/3dU8nTGY), contains all the users login & the admin Details of the website


They also breached a North Philippines University and leaked the compromised data. The leaked information comes from Panpacific University(http://www.punp.edu.ph/) and has been dumped in three parts.

The first part that was dumped contains the injected url along with two other pastes that contain a total of just over 400 accounts.

http://ozdc.net/archives.php?aid=1618 - part 1
http://ozdc.net/archives.php?aid=1619 – part 2 - 224 emails
http://ozdc.net/archives.php?aid=1620 – part 3 - 183 emails

In the past they have also leaked many users database of Stanford University .

5 Pakistan websites Hacked by NYRO Hacker and Indian Cyber Pirates

5 Pakistan websites Hacked by NYRO Hacker and Indian Cyber Pirates.


http://darultajweed.com/
http://www.gtspakistan.com/
http://www.akinternational.com.pk/
http://ama.org.pk/
http://cafehits.com/

#Mirrors
http://arab-zone.net/mirror/89082/akinternational.com.pk/
arab-zone.net/mirror/89081/gtspakistan.com/
http://arab-zone.net/mirror/89080/darultajweed.com/
http://arab-zone.net/mirror/89086/cafehits.com/
http://arab-zone.net/mirror/89085/ama.org.pk/

Notepad++ site hacked ,hackers trick users into handing their Facebook data


Hackers group "Kha &Mix" have break into the website of the popular open source text editor Notepad++ and tried to trick users into handing over the credentials to their Facebook accounts.

Hackers defaced the website and post a message "Kha &Mix is back".  Along with defacement, hackers managed to display a pop-up window that dupe user into entering facebook account details.
 
It is currently believed that the software downloads were not affected. The rest of the web site now appears to have been fixed.


Users who actually entered their Facebook credentials could potentially have provided the attackers with persistant access to all functions on their account such as personal information and the ability to post status messages. In this case, users would have to visit their Facebook account settings to revoke these permissions.

"Simply changing the account password is not sufficient in this case. The site MyPermissions.org provides direct links to all relevant permission pages for services such as Facebook." The H security Report says.

Hackers attack on Voyager Mobile site postponed the Launch



Voyager Mobile’s planned roll-out of a new discount mobile plan on Tuesday was stopped after Voyager’s website was allegedly hacked.

"During its Tuesday, May 15 launch, Voyager Mobile experienced a malicious network attack to its primary website: voyagermobile.com," reads a notification posted on the official site.

"Due to the network outage, Voyager Mobile is postponing its launch to a time and date in the very near future."

"Our goal of low cost wireless service for all will not be undermined and we strive to continue the voyage for a better wireless world"

Running on Sprint‘s (NYSE:S) wireless network, the new plan is expected to feature unlimited calling, text messages and 3G/4G data. The low price had attracted considerable attention.

Under its deal with Sprint, Voyager was to retail smartphones from Motorola (NYSE:MMI) and Samsung that use Google‘s (NASDAQ:GOOG) Android operating system.

50+ sites hacked by Silent Hacker and Nyro Hacker

Silent Hacker and Nyro Hacker have hacked into more than 50 websites and defaced them.

The list of hacked sites:
http://asyrafmarketer.com/
http://auly.co.cc/
http://azreen.com/
http://c-onweb.com/
http://dynamicconceptjb.com/
http://ekursus-affiliate.com/
http://emelmatik.com/
http://galerikahwin.com/
http://gedungsihat.com/
http://gempakcyber.com/
http://geriknet.co.cc/
http://iklanextra.co.cc/
http://www.impianrealiti.com/
http://jayen.com.my/
http://josephbiz.com/
http://jponlinestore.com/
http://www.kedaiemas2u.com/
http://kelasblogger.com/
http://kepoweraninternet.com/
http://kerunai.com/
http://latestnewsengine.info/
http://www.1suara.com.my//cgi-sys/suspendedpage.cgi
http://vemmazing.co.cc//cgi-sys/suspendedpage.cgi
http://www.wimexbeauty.co.cc/wb/
http://weegoo.co.cc/
http://xlimberry.com/cgi-sys/suspendedpage.cgi
http://mangosteen2u.com/
http://www.matjiwang.com/
http://monavieteamwork.com/
http://www.mudahjual.com/
http://myphyto.com/
http://myslimberry.co.cc/
http://www.nazimlaguna.com/
http://wanzulhamli.com/
http://pakartuisyenonline.com/
http://botolsusu.pakartuisyenonline.com/
http://kangarookeeper.pakartuisyenonline.com/
http://www.kedaionline.pakartuisyenonline.com/
http://pier-four.com/
http://rahsiacharkueyteow.com/
http://kerjasambilandarirumah.com/
http://rahsiamaklumat.co.cc/
http://rezekimasyuk.com/
http://digital-niaga.co.cc/
http://kursus-affiliate.co.cc/
http://rahsiapakarsoftware.co.cc/
http://rahsiacharkueyteow.com/
http://sanetwork.com.my/
http://satuminda.co.cc/
http://spheraresources.com.my/
http://superslideup.com/
http://v1ezlife.com/
http://www.vemmachinese.com/

Mirrors :-
http://arab-zone.net/mirror/88124/emelmatik.com/
http://arab-zone.net/mirror/88123/ekursus-affiliate.com/
http://arab-zone.net/mirror/88122/dynamicconceptjb.com/
http://arab-zone.net/mirror/88121/azreen.com/
http://arab-zone.net/mirror/88119/asyrafmarketer.com/
http://arab-zone.net/mirror/88270/josephbiz.com/
http://arab-zone.net/mirror/88269/jayen.com.my/
http://arab-zone.net/mirror/88268/impianrealiti.com/
http://arab-zone.net/mirror/88267/iklanextra.co.cc/
http://arab-zone.net/mirror/88266/geriknet.co.cc/
http://arab-zone.net/mirror/88265/gempakcyber.com/
http://arab-zone.net/mirror/88263/galerikahwin.com/
http://arab-zone.net/mirror/88264/gedungsihat.com/
http://arab-zone.net/mirror/88335/vemmachinese.com/
http://arab-zone.net/mirror/88334/v1ezlife.com/
http://arab-zone.net/mirror/88333/superslideup.com/
http://arab-zone.net/mirror/88332/sanetwork.com.my/
http://arab-zone.net/mirror/88331/rahsiacharkueyteow.com/
http://arab-zone.net/mirror/88330/kursus-affiliate.co.cc/
http://arab-zone.net/mirror/88329/rezekimasyuk.com/
http://arab-zone.net/mirror/88328/kerjasambilandarirumah.com/
http://arab-zone.net/mirror/88327/rahsiacharkueyteow.com/
http://arab-zone.net/mirror/88326/pier-four.com/
http://arab-zone.net/mirror/88325/kedaionline.pakartuisyenonline.com/
http://arab-zone.net/mirror/88324/kangarookeeper.pakartuisyenonline.com/
http://arab-zone.net/mirror/88321/nazimlaguna.com/
http://arab-zone.net/mirror/88320/myslimberry.co.cc/
http://arab-zone.net/mirror/88319/myphyto.com/
http://arab-zone.net/mirror/88318/mudahjual.com/
http://arab-zone.net/mirror/88317/monavieteamwork.com/
http://arab-zone.net/mirror/88315/mangosteen2u.com/
http://arab-zone.net/mirror/88314/latestnewsengine.info/
http://arab-zone.net/mirror/88313/kerunai.com/
http://arab-zone.net/mirror/88312/kepoweraninternet.com/
http://arab-zone.net/mirror/88311/kelasblogger.com/
http://arab-zone.net/mirror/88310/kedaiemas2u.com/
http://arab-zone.net/mirror/88309/josephbiz.com/
http://arab-zone.net/mirror/88308/vemmachinese.com/
http://arab-zone.net/mirror/88307/v1ezlife.com/
http://arab-zone.net/mirror/88306/superslideup.com/
http://arab-zone.net/mirror/88305/sanetwork.com.my/
http://www.arab-zone.net/mirror/88304/rahsiacharkueyteow.com/
http://www.arab-zone.net/mirror/88303/kursus-affiliate.co.cc/
http://arab-zone.net/mirror/88302/rezekimasyuk.com/
http://arab-zone.net/mirror/88301/kerjasambilandarirumah.com/
http://www.arab-zone.net/mirror/88299/pier-four.com/
http://www.arab-zone.net/mirror/88300/rahsiacharkueyteow.com/
http://arab-zone.net/mirror/88298/kedaionline.pakartuisyenonline.com/
http://www.arab-zone.net/mirror/88296/botolsusu.pakartuisyenonline.com/
http://arab-zone.net/mirror/88295/pakartuisyenonline.com/
http://www.arab-zone.net/mirror/88294/wanzulhamli.com/
http://www.arab-zone.net/mirror/88293/nazimlaguna.com/
http://arab-zone.net/mirror/88292/myslimberry.co.cc/
http://www.arab-zone.net/mirror/88291/myphyto.com/
http://www.arab-zone.net/mirror/88289/matjiwang.com/
http://arab-zone.net/mirror/88287/latestnewsengine.info/
http://www.arab-zone.net/mirror/88285/kepoweraninternet.com/
http://www.arab-zone.net/mirror/88286/kerunai.com/
http://arab-zone.net/mirror/88283/kedaiemas2u.com/
http://www.arab-zone.net/mirror/88282/josephbiz.com/

k7 antivirus got hacked by Ion, Team Openfire

A Hacker called as "The Ion", from TeamOpenFire, hacked into website belong to K7 Computing, one of the antivirus company.
  
Hacker compromised the database by exploiting the SQL injection vulnerability.  He found lot of bugs in that website.


"Hack on challenge they said they are secured" Hacker claimed as the reason of the attack.

In order to prove the unauthorized acces, he provide a screenshot that contains details about the database.

Peugeot Argentina hacked and defaced by UR0B0R0X


A Hacker called as 'UR0B0R0X' hacked into the website belong to Peugeot, the world renowned car manufacturer. The Hacker defaced a number of Argentina based websites and all domains appear to belong to the main Argentinian Peugoet website (http://www.peugeot.com.ar

According to the Cyber war news report , the following sites become victim of this attack:
  • - comunicacionpeugeot.com.ar
  • - grandprixpeugeot.com.ar
  • - laboutiquepeugeot.com.ar
  • - elearningpeugeot.com.ar
  • - peugeot3008.com.ar
  • - peugeotmagazine.com.ar.

The hacker didn’t alter the index page of these sites; instead, he added his own HTML file that contained the defacement image.

P2P Zeus Variant targets Facebook,Google & Yahoo users

Trusteer researchers have discovered a peer-to-peer (P2P) variant of the Zeus platform that targets users of Google, Yahoo, Hotmail, Facebook in order to steal their credit card data.


The scams exploit the trust relationship between users and these well-known service providers, as well as the Visa and MasterCard brands.

When targeting the facebook users, the attackers use a web inject to present the victim with a fraudulent 20% cash back offer by linking their Visa or MasterCard debit card to their Facebook account. The scam claims that after registering their card information, the victim will earn cash back when they purchase Facebook points. The fake web form prompts the victim to enter their debit card number, expiration date, security code, and PIN.



The attacks against Google Mail, Hotmail and Yahoo users, Zeus offers an allegedly new way of authenticating to the 3D Secure service offered by the Verified by Visa and MasterCard SecureCode programs.

The scam that targets Google Mail and Yahoo users claims that by linking their debit card to their web mail accounts all future 3D Secure authentication will be performed through Google Checkout and Yahoo Checkout respectively. The fraudsters allege that by participating in the program the victim’s debit card account will be protected from fraud in the future. The victim is prompted to enter their debit card number, expiration date, security code, and PIN.

The Hotmail scheme is somewhat similar, the potential victims being informed of the fact that “Windows Live Inc” is concerned about their security, offering a “100% secure, fast and easy” method of preventing fraud by linking the account to the debit card.


This attack is a clever example of how fraudsters are using trusted brands – social network/email service providers and debit card providers – to get victim’s to put down their guard and surrender their debit card information.

These webinjects are well crafted both from a visual and content perspective, making it difficult to identify them as a fraud. It’s also ironic how in the Google Mail, Hotmail and Yahoo scams, the fraudsters are using the fear of the very cybercrime they are committing to prey on their victims.

Spam tweets target Pc and Android users & serves Rogue Antivirus


Bogus Twitter accounts spam random users with attractive tweets that contains links to websites hosted on dot TK(.tk) domains. The spam targets not only PC users but also smartphone users.

Once user click the link in the tweet, they will be redirected to some Russian web page that host Fake AV. Depending on the Device from the website is being accessed, the site serves different files.

If you are computer user, it will serve VirusScanner.jar. If you are Android user, it will serve VirusScanner.apk. The rogue AntiVirus uses logo of Kaspersky.


GFI VIPRE Mobile Security detects it as Trojan.Android.Generic.a.

DHL spam mails strikes again ,serves malware

Once again, we are seeing a widespread malware campaign spammed out - this time pretending to be regarding an aborted attempt to send a parcel via DHL to the recipient's address.

The mail has an attachment "DHL report.zip",which contains malware designed to infect Windows computers.


A typical spam mail:

Dear [name derived from email address], with this message we notify you that delivery at your destination, tracking ID #[number], has FAILED due to an address discrepancy. To obtain your delivery please print out the attached document and contact DHL US support

Feel free to contact us with further questions.

Sophos security solutions detect the attack as Mal/BredoZp-B and Troj/Zbot-BWI.