Showing posts with label Gmail. Show all posts
Showing posts with label Gmail. Show all posts

Tuesday, 24 October 2017

Man Charged For Hacking 550 Gmail And iCloud Accounts


In the United States, a 32-year-old man is charged with hacking over 550 Gmail and iCloud accounts, including Hollywood star and other celebrity accounts. According to the charge, the man sent phishing emails from April 2013 until the end of August 2014 in which recipients were asked to return their username and password.

If the recipient responded and returned the credentials, the man used to log in to the victim's iCloud and Gmail account. As soon as the man logged in, he searched for sensitive personal information, including photos and videos. The case against the man arises from the search for 'Celebgate' or 'The Fappening', which loads all kinds of nude photos of celebrities. However, the FBI has not found evidence that the accused man is responsible for leakage of the naked photos or that he has shared or uploaded the information obtained.

The man has now signed a "plea" agreement with Justice and is expected to acknowledge debt, as soon as the US Department of Justice knows. Earlier this year, a 29-year-old American was sentenced to a nine-month imprisonment for hacking the iCloud and Gmail accounts of more than 300 people, including at least thirty Hollywood stars. According to the FBI, this man was not responsible for Celebgate.

Wednesday, 10 February 2016

Gmail Notifies Users Of Unencrypted Messages



Google Gmail users will now warn if they receive unencrypted messages, as the Internet giant has on Safer Internet Day 2016 announced . Google itself uses TLS encryption for encrypting messages. Gmail users can send encrypted messages to each other in this way. TLS is not yet used by all email providers.

This allows messages that Gmail users received via this e-mail providers, or send to this, be read. Gmail will therefore present a warning showing that the email provider of the addressee no encryption support, or if a message is received that is not encrypted via TLS. There will also be a warning if the sender's domain could not be authenticated. Gmail recently did not know that more and more support major email providers tls and domain authentication.


From investigation of Google, the University of Michigan and the University of Illinois show that from December 2013 to October 2015 the number of encrypted emails rose Gmail non-Gmail users received from 33% to 61%. In the same period, the number of emails were encrypted using TLS and Gmail to non-Gmail users was sent from 60% to 80%. Further uses 94% of the incoming email for Gmail, a form of authentication to protect against phishing and spoofing.

John Rae-Grant Google argues that not all e-mails which warned is dangerous. "But we advise you to be extra careful when answering or opening links in messages that you have doubts about. And by this update, you have the resources to make that decision."

Thursday, 19 November 2015

Botnet Tool Uses Twitter Direct Messages



Cyber criminals can control their botnet recently via Direct Messages on Twitter. The Python program Twittor called, was designed by the idea of GCAT, a similar program cyber criminals command & control servers to be managed via Gmail. Twittor made ​​by self-appointed security researcher Paul Amar and available from September, but is now observed by Sophos.

The tool uses direct messages on Twitter. The "advantage" of them, as compared to the conventional way of managing command & control servers, which the Direct Messages on Twitter are private. And the traffic is not stopped with IP filtering because Twittor use the Twitter API.

In addition, Twitter announced earlier this year that the limit of 140 characters is widened in private messages. This will therefore also more malicious traffic. The limitation is that there is a maximum of 1 000 direct messages per day can be sent.A botmaster can therefore no more than approximately 100 bots manage per account.

Many security tools such as Nmap and Metasploit, are not only useful for cyber criminals also useful for security researchers. Publishing a free tool that makes it possible to create a botnet via Twitter Direct Message operate seems an odd way of security research, says John Zorabedian Sophos.

Friday, 23 October 2015

Google Will Implement Stricter DMARC Policies For Gmail


Google next year, the emails that Gmail users receive stringent filtering, as the Internet giant announced. Emails that do not meet the requirements will be refused DMARC from June 2016.DMARC (Domain-based Message Authentication, Reporting and Conformance) is a standard developed by fifteen leading Internet companies, including Microsoft, Facebook, LinkedIn and Google.


Through the new policy change, Google will soon emails from Gmail.com refuse which addresses claiming to be from Google's servers, but do not originate in reality. This should for instance prevent spoofing or phishing attacks. The stricter DMARC standard was already through AOL set and Yahoo. Yahoo will DMARC next month also ymail.com and rocketmail.com's set.

Google also announced to support the new ARC protocol. The Authenticated Received Chain (ARC) protocol is designed to prevent problems with DMARC. It is in this case added to a cryptographically signed header to the message. At present, many legitimate emails from forwarding services and mailing lists rejected because they do not meet the DMARC requirements. The ARC-protocol must ensure that such services the forwarded e-mails still can authenticate that they are accepted.

Wednesday, 23 September 2015

Gmail Lets Users Email Addresses Block


A new feature in Gmail makes it now possible for users to block mail from specific email addresses. According to Sri Harsha Somanchi Google must give the new feature users more control over their inbox, for example if they are harassed by e-mail .

In case a user specific email address block the e-mail sender will be automatically placed in the spam folder. The option is now available to Gmail users and will appear next week for Android. In addition, Android users will soon have the option to unsubscribe simply from the Gmail app for newsletters.

Thursday, 9 April 2015

Experts Divided On Risk Of Trackers On Porn Sites



In February warned a software engineer for the risk of trackers and other ways in which it can be followed online porn surfing habits of viewers, but experts are divided over how big the risk is real. Software engineer Brett Thomas suggested two months ago that the viewing habits on porn sites the next "big privacy scandal" can be. Many ways to websites and advertisers identify Internet users today and that is no different on porn sites.

This data could, for example end up using a hacked advertising company, tracker or porn site on the Internet. It does not matter if people such as "private browsing" to use to protect their browsing habits, so let experts opposite Vice Magazine know. Even if this option is enabled the user's IP address is on the website visited, and the trackers that are active thereon passed.

88% of the 500 most visited porn sites are active trackers. "If you look at porn on the Internet in 2015, even in incognito mode, you must assume that at some point your viewing habits public and will be linked to your name," said Thomas. In addition to the IP address has almost every computer to identify a unique fingerprint browser so that users are. "It is certainly cause for concern," said Justin Brookman, privacy expert of? Center for Democracy & Technology.

Alarmism

According to Cooper Quintin of the American civil rights movement EFF is possible that the viewing habits of one's membership in a porn site is known, but he calls the remark of Thomas later someone can easily put it online porn viewing habits of viewers on the Internet scaremongering. Vice Magazine porn sites also asked for a response, but received only sent a statement of PornHub. The site is on the 75th place of most visited websites on the Internet, just for Gmail.com , which stands on a 78th place.

The statement PornHub calls the assertion of Thomas not only utterly wrong but also dangerously misleading. According to the porn store the viewing habits of daily users would cost 3,600 terabytes. The searches of these data would be almost impossible and very time consuming. "The server logs PornHub contain only for a limited time the IP address and user agent, never a browser fingerprint," said a spokesman.

Monday, 6 April 2015

Google Allows Gmail SMTP SSL Certificate Expired Again


Google has the SSL certificate used for the domain smtp.gmail.com leave again expired , allowing Gmail users to send email through an email client all kinds of warnings received. It seems to be a human error, because the SSL certificate for imap.gmail.com it had been updated, so let users on the Google forum know.

In 2008, it happened even though that Google SSL certificate had expired . At the time, it took several hours before the problems were solved and advised Google users to email through the webmail interface. Again, it took a few hours before the domain had a renewed SSL certificate. This certificate expires on December 31, 2016, which some Internet users fear a repetition, as it lies on an American holiday, as this weekend.

Thursday, 19 March 2015

Qakbot Botnet: "Infects Systems US Police"


Police in the US city of Baltimore has been hit by a computer virus which systems worked slower than normal. IT staff of the police was doing a research on what the inertia of the police systems caused the last few months, when they discovered the virus.

It was a variant of the Qakbot. This malware can data for online banking login credentials for social networks, Hotmail, Gmail, Yahoo !, credit card information, FTP, POP and IMAP logins, certificates and even steal the browsing history. Also can install additional malware Qakbot. Last year there was still a Qakbot botnet discovered from 500,000 computers existed.

How many computers have been infected with the police of Baltimore by the malware is unknown, but according to officials it could involve hundreds of machines, reports the Baltimore Sun . Police believe that the lack of security updates and other security has ensured that the virus could spread. The police do not think that information has been compromised or stolen.Meanwhile, outside help is enabled and started an investigation into the infection.

Wednesday, 30 April 2014

Russian Internet giant offers email service without a password

The Russian Internet giant Mail.Ru has a new e-mail service launched where users have no password.
My.com such as the e-mail service is called, is in fact only accessible via an app on the smartphone.Once users register they will receive a unique SMS code.
This registration code is used once, after which users never have to enter a password. The phone is namely as authentication."And you always have with you", so let the developers know. Our own research would show that often their email on their smartphone then check users on their desktop.
Furthermore, all sent and received e-mails should be encrypted, but specific details are not given. In addition, users of the free e-mail service to get 150 gigabytes of data storage, ten times as much as in the case of Gmail. 
My.com is only available for iOS and Android users. The developers say that they keep an eye on Windows Phone, but due to limited resources and expertise will now focus on iOS and Android.

Monday, 14 April 2014

Top 5 of imaginary viruses that would make the world more fun



Why bugs should always be evil? What if they would like you to reconcile with your ex fun and useful things, or that awful Tumblr account before you delete?
Stuart Heritage describes in The Guardian five imaginary viruses that would make the world. enjoyable. He calls virus creators to show another side of himself, and actively improve to helping people instead of harassing. Positive viruses the world

1. Facebook privacy virus

The privacy settings on Facebook are all an eyesore. Every few months, Facebook decision or something which leads to a sudden anyone 5 years old photo, where you say the least not too flattering on state, can be seen. Then you have to login again and again confirm what you want to share and what not. What if a virus would be that would ensure that all of your pictures remain private forever? Would not that be nice?

2. Spotify playlist virus

No one will just have to play Spotify playlists at a party. Sane Indeed, there is a high probability that a track is played where you actually die ashamed of you and so you end up with your tail between your legs to leave the party. But think of a virus scan on playlists of songs you could possibly embarrass and removes them for you before anyone else can hear? That way you'll never laughed!

3. Tumblr itself destroyer

The world is full of teenagers who cram their Tumblr account with hand-drawn Justin Bieber fan art or other bad things. There will come a day when these teens will apply. Their potential employer will google their name and find the Tumblr account, with all its consequences. Rising unemployment is the result. Why does no one a virus that all traces of your Tumblr account automatically deleted on the day of your 18th birthday? That would be the best for everyone!

4. Reconcile virus

Gmail still read all all emails. Why is there no peaceful virus maker who does something here? What if somehow the phrase "How could you cheat on me" pops up. Reconcile the virus would see this and immediately, of course with a stolen credit card, buy a huge bouquet and have it delivered. Indignant at the partner Bingo! Everyone is happy again because everyone loves flowers, regardless of the sender.

5. Reminder Flickr

Just a virus that sends emails to you to remind that the Flickr account that you created in 2004 still exists ...

Sunday, 16 March 2014

Phishing Attack on Google users hosted by Google

In a recent phishing attack on users of Google Docs and Google Drive cybercriminals have the phishing page where victims had to introduce hosted on the servers of Google. Their credentials Something the phishing attack is both refined and remarkable, says Symantec.

Google Docs phishing login page

The anti-virus company discovered the attack, which starts with an email subject "Documents" has. The email prompts the recipient to view an important document. The link does not point to Google Docs, but after a fake Google login page. The neppagina however hosted on Google's servers and then ran over an SSL-secured connection, which makes the attack seem more convincing.
In this case, the scammers a folder in a Google Drive account is created, placed it in a file and then put the public folder. The preview feature of Google Drive they got this way a publicly accessible URL that was added. To the phishing emails When users their information on the phishing page fill go directly to the criminals behind the attack, while the victim to the real Google Docs page is redirected and possibly nothing by it.