Thursday, 19 April 2012

Google Sent Hacked Notification Messages to Millions of Webmasters


Google Sent Hacked Notification Messages to Millions of Webmasters
GoogleNotice2010

Google’s head of the webspam team, Matt Cutts, announced on Twitter that they have sent out new message notifications to 20,000 web sites that are hacked. Specifically, Google sent these messages to sites doing “weird redirects.”

Weird redirects means the hack is where the hacker gains access to your HTACCESS and only redirects users who click from Google to your web site. Otherwise, if they type in the domain name directly, there will be no redirect.

A year ago, Google began labeling hacked sites and sites with malware as sites that may compromised in the search results snippets.


If a site has been hacked, it typically means that a third party has taken control of the site without the owner's permission, Hackers may change the content of a page, add new links on a page, or add new pages to the site. The intent can include Phishing to tricking users into sharing personal and credit card information or spamming. 

Well for Webmasters, we also shared a script few months back "Irongeek's Shared hosting MD5 Change Detection Script". Another great option for web admins that will monitor the files on a website, and report any changed via email.

Have you ever had your site hacked into ? What precautions had you taken to get your site back up and running as quickly as possible ? Let us know in the comments below.

Nikjju Mass injection campaign target more than 2 Millions Urls

Nikjju Mass injection campaign target more than 2 Millions Urls
Nikjju+mass+SQL+injection


Daniel Cid an open source developer and information security professional reported on Sucuri blog that their team tracked a new mass SQL injection campaign that started early this month and till now more than 180,000 URLs have been compromised. Nikjju is a mass SQL injection campaign targeting ASP/ASP.net sites.




At the time of writing Google has identified 361,000 pages infected with that javascript call, but the number is growing really fast.

In this case it adds the following javascript to the compromised sites.
script
One more interesting fact that researchers have noticed that Nikjju.com domain was registered on April 1st 2012 and in 18 days more than 180,000 urls get infected.

This mass Sql Injection also compromise some Government sites also , as listed below :
jnd.xmchengdu.gov.cn
study.dyny.gov.cn
www.cnll.gov.cn
www.bj.hzjcy.gov.cn
www.mirpurkhas.gov.pk
www.tdnyw.gov.cn
gcjs.kaifeng.gov.cn


Few hours we have also reported that, Google Sent Hacked Notification Messages to Millions of Webmasters of sites doing “weird redirects.”

winAUTOPWN v3.0 Released - System vulnerability exploitation Framework


winAUTOPWN v3.0 Released - System vulnerability exploitation Framework
winAUTOPWN+v3.0+Released

The improved GUI extension - WINAUTOPWN ACTIVE SYSTEMS TRANSGRESSOR GUI [ C4 - WAST ]is a Systems and Network Exploitation Framework built on the famous winAUTOPWN as a backend.  C4 - WAST gives users the freedom to select individual exploits and use them.
BSDAUTOPWN has been compiled, like always for various flavours and has been upgraded to version 1.8 alongwith all applicable exploits which have been added in this release. Included this time is the bsd_install.sh, which will set chmod on all applicable BSD compiled binaries.

WINAUTOPWN requires PERL,PHP,PYTHON,RUBY and its dependencies alongwith a few others' too for smooth working of exploits included in it.

winAUTOPWN and bsdAUTOPWN are available at http://winautopwn.co.nr

Rootdabitch version 0.1 - Multithreaded Linux root password Bruteforcer

Rootdabitch version 0.1 - Multithreaded Linux root password Bruteforcer
Screenshot

r00tw0rm hacker "th3breacher!" release Rootdabitch v0.1 ,which is a Multithreaded Linux/UNIX tool to brute-force cracking local root through su using sucrack.


sucrack is a multithreaded Linux/UNIX tool for brute-force cracking local user accounts via su. The main feature of the Rootdabitch is that It's local brute forcer, using 10 passwords in 3 seconds. and works in background so you can leave it , when root is cracked it will email the user using /bin/mail .

All for this, you need to have a php shell/reverse shell/ssh access to the target to run thistool and run it as a normal user, Upload this script into it and give it the execution permission and execute the script like:

 ~ ./rootdabitch youremail@address.com

If the password is cracked you will have a mail with the root password and the password will be stored into password.txt . Try it !

Tuesday, 17 April 2012

Banking System Vulnerability - 3 million bank accounts hacked in Iran


Banking System Vulnerability - 3 million bank accounts hacked in Iran
iran_atm_hacked


Iran's Central Bank has announced that the electronic information of 3 million customers of 10 Iranian banks have been compromised. These banks now require their customers to change their ATM pin numbers before they can access their account. This has caused a rush to the ATM machines by the worried customers.

The hacker was identified as Khosro Zare', a former bank-system specialist in Iran who recently left the country.Zare' claimed in a blog that he hacked the PIN codes to highlight the vulnerability of Iran's banking system.
According to the report, the hacker had provided the managing directors of the targeted banks with information about the bank accounts of 1000 customers in the previous Iranian calendar year (ended on March 19) to warn them about the susceptibility of their computer systems and networks to cyber threats.

But Central bank officials had earlier downplayed the reports, saying that "the threat to Iran's banking system is not serious."
Finally to proof the Vulnerability he dumped the account details of around 3 million individuals, including card numbers and PINs, on his blogircard.blogspot.ca.

At least three Iranian banks (Saderat, Eghtesad Novin, and Saman) have already sent text messages to their clients, warning them to change their debit card PINs. The warning was repeated on state TV channels.

Lebanese Government sites hacked by ‘Raise Your Voice’

Lebanese Government sites hacked by ‘Raise Your Voice’
Lebanese+Government+sites+hacked
















A group calling itself ‘Raise Your Voice’ hacked on Tuesday around 15 Lebanese government websites to ask for an improvement in living standards, the day the parliament launches a three-day session to assess the cabinet’s performance.



“To our dear “beloved” Lebanese Government,We are RYV, short for Raise Your Voice, and we are simply a group of people who could not bare sitting in silence, watching all the crimes and injustice going on in Lebanon. We will not be silenced and brainwashed by your media. We will not stop until the Lebanese people mobilize, demand their rights, and earn them. We will not stop until the standards of living are raised to where they should be in Lebanon. We will not stop until this government’s self-made problems are solved, like the power shortage, water shortage, rise in gas prices and rise in food product prices. We are RYV, expect us to break the silence, whether in the streets or on the Internet. Silence is a crime.“

Hacked Sites List:
http://www.presidencyinfo.gov.lb
http://www.isc.gov.lb
http://www.nna-leb.gov.lb
http://www.omspa.gov.lb
http://www.customs.gov.lb
http://www.justice.gov.lb
http://www.transportation.gov.lb
http://www.moew.gov.lb
http://www.foreign.gov.lb
http://www.ebml.gov.lb
http://www.bccl.gov.lb
http://www.isf.gov.lb
http://www.interior.gov.lb
http://www.southernlebanon.gov.lb
http://www.state-security.gov.lb
http://www.pcm.gov.lb

Among the sites that were hacked are the National News Agency, the Presidency and the Energy, Water, Justice and Foreign Ministries.The hacking comes as the opposition is gearing up to grill the government for what it calls a bad performance and procrastination in the implementation of major decisions.

Only the Energy and Water Ministry websites had messages written on them that “Electricity is Cut” and “Water is Cut.” The group previously hacked several government sites in early March.

MI6, CIA and Department of Justice Tango Down !



MI6,+CIA+and+Department+of+Justice+Sites+Tango+Down+!

Hacker group Anonymous claimed it took down the CIA website for the second time in two months following a new DDoS attack on the U.S. secret service which lasted 45 minutes. 

Anonymous is reportedly on a DDoS rampage today, downing the CIA, Department of Justice, and two Mi6 websites. Members of the group claimed responsibility throughout Facebook and Twitter.

Brazilian hacktivist Havittaja reportedly launched the initial offensive on the DoJ and CIA for “lulz” while other members jumped on board a short time later.

The technique also known as a DDoS (distributed denial-of-service) attack, is a concentrated effort by multiple individuals to make a network busy to its intended users. The end result is server overload. Anonymous makes a freeware tool available to its members to carry out these attacks, which it calls the Low Orbit Ion Cannon.
Havittaja
The collective targeted the department of justice in January as part of Operation Megaupload, in a retaliatory attack against the US government's decision to close the popular file-sharing site.