Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

China Coal Bank website hacked by Japan hackers

The official website of newly created Chinese coal bank has been hacked and defaced by Japanese based hackers.

"www.MeitanBank.com", It is reportedly the first bank in the world with coal as the core focus, founded by JinBen Investment Group co and 15 coal firms.

The website has been defaced since February(29th November) with the defacement message written in Japanese.


"Warning Ben Gold Investment Group! ! ! You engage in the voting trust, offend a lot of people! ! ! You engage in coal bank, offend more people! ! ! ! Mainland stock market you can not play! ! ! We short, you can do much more! ! ! " The defacement message reads(translated).

"You have to let us do more thermal difficult subject, and dared short squeeze, do not blame us rude! ! ! Your uncle, 8.16, you crazy son of a bitch to pull these heavyweights, almost blow us tens of billions of short positions! ! ! Today you also colluded agencies mad pull coal colored, futures and harm our financial group on short loss of hundreds of millions!!! Lord Black of your station has been very kind to you, next time do not speak the arena rules do not blame us! ! ! Last warning! ! ! Go back to coal mines to bring the coal bosses, how far roll far! ! !"

The firm told local news paper that their website attacked by Japanese based IP addresses.  The firm also said they won't approach police and going to action on its own.

It's been more than three days, the site is still defaced.  

State Bank of Patiala hacked and defaced by Pakistani Hacker

A Pakistani hacker with the online handle " Kai-H4xOrR" from PAKISTAN HAXORS CREW(PHC), has hacked into the State Bank of Patiala(SBP) sub-domain and managed to deface the website.

In the defacement page, hacker stated that the security breach is payback "For Hacking Sui Gas Site".

"And Dont mess with Pakistan else you will lose both your Name and this Game   Backoff Lamers from our cyber space. Everybody Knows whose cyber space is more vulnerable" The defacement message reads.



"You will hack 1, we will hack thousands" hacker sent a warning message to Indian Hackers who deface Pakistani websites.  

The hacker has uploaded his defacement here: "https://hindi.sbp.co.in/index.html".  The main page and other pages are not affected by this defacement.  At the time of writing, the website still displays the defacement.

Used memory sticks being sold online contains sensitive Government data


Selling an used memory sticks often pose an information security risk-  We might be thinking that we completely erased the data from it, but it is possible to recover the files that are not properly deleted with the help of some tools.

A recent study found that "old memory sticks" being sold online contain sensitive Australian Government data.

The research paper which is to be presented at a cyber security conference in Perth reveals how researchers discovered the confidential Government data while they are researching the used memory sticks, The Australian news reports.

The study found that sellers are sending memory cards without properly erasing the data. The recovered data not only contains a personal info but also appears to be information belong to Australian government.

"It is evident that actions must be taken by second hand auction sites, and the media to raise awareness and educate end-users on how to dispose of data in an appropriate manner," the study says.

UW Medicine's Computer infected with Malware, 90k patients data accessed

The University of Washington School of Medicine reports that their computer which had patient stored in it is infected with malware.

The malware made it's way into the infected-system when an employee opened the email attachment that contained malicious software.

After an internal investigation, they found that the patients' data are not targeted. However, the malware managed to access the files containing data of approximately 90k UW Medicine and Harborview Medical Center patients.

The accessed-data includes names, Social Security Numbers,phone number, address, medical record number and few other details, According to their press release.

UW Medicine officials started to notifying patients about the incident. The incident has also been reported to FBI.

It is always good to create cyber security awareness among employees who are taking care of system that has both internet and sensitive data.

Venezuela Government websites defaced by @LIberoamericaMu

A hacker with twitter handle "LIberoamericaMu" from Hack Argentino team, has gained access to multiple Venezuela Government websites and defaced them.

The hacker in tweet said the hack is for Anonymous Venezuela and said that it will be continued.

"This post is dedicated to all venezonalos, we will not allow this corrupt government dominates our way of thinking we are prepared to face them MATURE F*** YOU!! Cuba will not allow our country to dominate." The defacement message reads(translated).


List of hacked websites:
pgmerida.gob.ve
www.fundaciteportuguesa.gob.ve/
zonfipca.gob.ve
www.iamdr.gob.ve
alcaldiabrion.gob.ve
www.alcaldetorbes.org.ve
www.cortudelta.gob.ve
casabello.gob.ve
polimaturin.gob.ve

The group also hacked the sub-domain of the Venezuela Military website "http://esguarnacpuntademata.mil.ve".  At the time of writing, all of the affected sites still defaced.  

Larry Clinton addresses at an event held by CSPF and Anna University


Mr. Larry Clinton, President & CEO Internet Security Alliance gave an informative speech at the recent event held by the Cyber Security Privacy Foundation(CSPF) and Anna University.

The event was inaugurated by Mr. Ramamurthy, Chairman, Cyber Security and Privacy Foundation and followed by Dr. Chellappan, Dean Anna University.


Speaking on "The Evolving Cyber Threats, and How to Address Them", Larry Clinton said that Chief Financial Officier(CFO) in 95% of companies are not directly involved in information security.

He suggested CFOs to "appoint an enterprise wide cyber risk team and Develop an enterprise wide cyber risk management plan" in order to improve information security of an organization.


Clinton also appreciates CSPF's Tech Core which is headed by J Prasanna for pre-empting cyber threats.


"First of all, let me thank the Cyber Security and Privacy Foundation for all your efforts in putting together the interactive session with Mr. Larry Clinton at Anna University on November 21." In an email sent to CSPF, US Consulate said. "My colleagues and I were very pleased with the level of participation and engagement"


"Mr. Clinton was particularly happy to have had such a well-informed audience and their enthusiastic participation in the discussions."

Union of Reserve Officers of the Armed Forces Argentina website hacked

Team Hacking Argentino has hacked into Sub-domain of Argentina Military "unor.mil.ar", a webpage used by Union of Reserve Officers of the Armed Forces Argentina.

The hacker group defaced the webpage with the following message(translated):

"Hacked By @ LiberoamericaMu And @ HackearArgentino Union Reserve Officers of the Armed Forces <-! Owned! Again, "


"we continue to demonstrate that security in Argentina no excite! A greeting to all the corrupt government of shit SYSTEM YOU PWNED! ;) Just modify the index does not remove any important file :)!"

At the time of writing, admin has managed to remove the defacement page.  The mirror of the defaced page is available at zone-h : http://zone-h.com/mirror/id/21288785


CVE-2013-5065: Windows XP Kernel Privilege escalation vulnerability exploited in the wild


Microsoft has issued a warning about new zero-day vulnerability affecting the Windows XP and 2003 Server operating systems.

The bug referred with CVE id "CVE-2013-5065" is a local privilege escalation vulnerability, is reportedly being exploited in the wild.

A successful exploitation allows attackers to run the arbitrary code in Kernel mode(User mode --> kernel mode).  It will get access to install software, modify data or creating accounts with admin privilege.

However, the vulnerability is not exploitable by a remote attacker.

"It does not affect customers who are using operating systems newer than Windows XP and Windows Server 2003." Microsoft security advisory reads.

Though the Microsoft is issued a workarounds for this vulnerability, it is better to switch to the latest version of Windows (7 or 8), as we aware that Microsoft is going to stop supporting Windows xp by April 2014. 

Lashkar-e-Taiba website hacked by Indian Hacker "Godzilla"

An Indian hacker with online handle "Godzilla" who is popularly known for hacking Pakistan government websites has once again come with up an interesting hack.

This time, the hacker has hacked into the official websites of Lashkar-e-Taiba and left them defaced on 26/11.


"Hafiz Muhammad Saeed, its a promise from our side you will not stay in Pakistan for a longer time." The defacement message reads.

"To stupid ISI and Pakistan Army stop supporting such poeple, Sher kabhi chupkar shikar nahi karte, Buzdil kabhi khulkar war nahi karte Its upto you to decide on which side you are.."

"Greetz: To all those people who want peace in the world. Proud to be a Muslim, Proud to be an Indian." end of the defacement message reads.

Hacked site:
  • http://www.jamatdawa.org/ 
  • http://www.jamatdawa.net/ 
Mirrors:
  •  http://zone-hc.com/archive/mirror/45a0f4a_jamatdawa.org_mirror_.html
  • http://zone-hc.com/archive/mirror/cf990df_jamatdawa.net_mirror_.html

Albania, Bulgaria government website hacked by TeslaTeam

TeslaTeam, one of the infamous hacker group from Serbia, has hacked into the Government websites belong to Albania and Bulgaria.


Bashkia Librazhd website of Albania( www.bashkialibrazhd.gov.al) has been defaced the group with a simple text saying "Hacked by teslateam".


Hackers discovered a SQL Injection vulnerability in the government.bg, a website that provides biographical information about the Prime Minister and Ministers, programs, priorities, Press and links to various ministries.

The group has managed to exploit the vulnerability and extracted login credentials from the database server belong to government.bg.

The leak(pastebin.com/GA8ivuV9) contains user IDs and hashed passwords that includes the credentials of admin account.

The group also discovered a SQL Injection vulnerability in the "University of Cambridge" subdomain(buffalo.niees.group.cam.ac.uk) .

Central Bank Of India Hacked by Pakistan Cyber Army and Team MaDLeeTs

The official site of "Central Bank Of India" has been defaced by Pakistan Cyber Army and Team MaDLeeTs .

The deface seems to be a retaliation to defaces this morning by "Indian Cyber Army" on many Pakistani Sites.

The reasons for the Indian attack was that today is the 5th anniversary of the 26/11 terrorists attacks on Mumbai.



 Mirror:http://www.zone-hack.com/134702.html

Deface Link:https://www.centralbankofindia.co.in/site/