Showing posts with label Account Hack. Show all posts
Showing posts with label Account Hack. Show all posts

Tuesday, 19 April 2016

Police Asked Apple To About 341 Units


The Dutch police Apple has in the second half of last year asked for information on 341 Apple devices, according to a new Transparency Report of the tech company ( pdf ). It went to a total of 39 requests related to 341 devices.

Sixteen requests were granted by Apple. According to Apple will most requests for lost or stolen devices. In the first half of 2015 were still 25 requests filed with about 85 aircraft was searched. During that period twelve requests were honored.

In addition to information about devices, the police also sought information about Apple accounts. In the second half of 2015 was about thirteen data requests related to 13 Apple accounts. In five cases, data were presented. three more requests came in the first half of 2015 within the information requested on three accounts. In one case, when Apple decided to hand over information.

In addition, Apple also received three emergency requests from the police in the second half of last year. This relates to data requests made in an emergency, for example, to save a life or prevent injury. In the first half of 2015, it went to one emergency request.

Friday, 9 October 2015

Serious Leak Showed Hacker Outlook.com Account-Hijacking



Microsoft has a vulnerability in the login mechanism for Outlook.com poem allow an attacker accounts of the webmail service, and possibly other Microsoft services could hijack. Just visiting a malicious website or see getting a malicious ad with a login account for this was sufficient, says researcher Wesley Wineberg of security SYNACK.



He discovered on August 23, the vulnerability in the login mechanism of Live.com and now has his research made ​​public.Login.live.com the authentication system that Microsoft uses to allow users to Outlook.com to log in and let other Microsoft services. The problem Wineberg encountered is called cross-site request forgery (CSRF). These are performed in a user's name unauthorized actions.

Owners of a Microsoft account, that Outlook.com is used, apps give access to certain things, such as the address book or profile information. The user must confirm this entry itself and also get to see exactly clear what the app will access it. Wine Berg developed an attack in which CSRF is used to carry out this operation in the user's name.

In this case, the user would grant permission to an app that was given full access to the account. The CSRF code would thereby be executed automatically when a user visits a malicious website logged by Microsoft or view a malicious ad got.After being informed three weeks, the vulnerability was later closed by Microsoft and Wineberg received a reward of $ 24,000.