Showing posts with label Hacking Team. Show all posts
Showing posts with label Hacking Team. Show all posts

Wednesday, 4 November 2015

Google Hacks Samsung Galaxy S6 During Internal Competition


During an internal competition at the offices of Google are employees of the Internet giant has managed to hack a Samsung Galaxy S6 Edge, which ultimately resulted in 11 serious vulnerabilities. Google has a team of hackers called Project Zero.

The team looks for vulnerabilities in popular software. This time, the hackers also decided to look at a handset from Samsung. Most Android devices are namely not created by Google, but by external parties, known as Original Equipment Manufacturers (OEMs). These manufacturers use the Android Open Source Project (AOSP) as the basis for their devices.According to Google, OEMs are an important area for Android screening.

Namely manufacturers add all kinds of code and applications increasing, which can introduce new vulnerabilities. The manufacturers decide if and when they deploy updates. After previously having been created by a Google Nexus device examined Project Zero now decided to look at the safety of an OEM device. In addition to finding vulnerabilities, the researchers were also curious to see how quickly they were resolved. It was ultimately for the Samsung Galaxy S6 Edge chosen because a high-end device with many users.

Competition

It was then decided to organize a match between the North American members of Project Zero and the European section. The teams were given a week's time for the challenge. Eventually there were 11 vulnerabilities discovered and reported to Samsung. Eight of the leaks were patched by Samsung during patch cycle of October. The remaining three will be resolved this month. Who the match between the two teams eventually won, Google has not disclosed.

Sunday, 30 August 2015

Director Ashley Madison Departs After Massive Hack


The director of Ashley Madison has resigned after attackers managed to steal confidential data of 32 million users, including names, addresses, email addresses and hashed passwords. Also all kinds of confidential business information were stolen, including e-mails.

It was gigabytes of data that have been published in part last week. In a statement enables Avid Life Media, the company behind Ashley Madison CEO Noel Biderman which has resigned and no longer works for the company. Until a new director was appointed the existing management team will lead the company. The company also states that it is still working on the settlement of the attack and actively with international investigative agencies work together to identify the perpetrators.

Tuesday, 11 August 2015

Espionage Group Uses Rtlo-Trick In Windows


A group of cyber spies who in the last year, news came as the guests through the WiFi network of their hotel with malware infected, now uses other methods to attack targets, including the rtlo-trick in Windows and a vulnerability that by Italian Hacking Team was discovered.

The group, according to the Russian anti-virus firm Kaspersky Lab since 2007 active and has conducted several attacks this year. The attacks took place among others in Germany, Mozambique, Bangladesh, Thailand, Russia and North Korea. To attack the targets the group makes use of physical access as well as a flaw in Adobe Flash Player that was familiar to Hacking Team. Kaspersky discovered that there are several e-mails were sent with links, pointing to a page on which the Flash Player leak was attacked.

Rtlo

The group also sent emails with RAR attachments that recipients via the rtlo-trick in Windows attempted to mislead. This RAR attachments contain an executable .scr file. By using rtlo seems like a jpg image. Rtlo stands for Right-to-Left Override and ensures that the sequence of characters of a file name can be reversed through a special unicode character. This will SexyPictureGirlAl [rtlo] gpj.exe appear in Windows as SexyPictureGirlAlexe.jpg.

In this case, the .scr file resembled a jpg image. As soon as the recipient opened the file is a real image was shown, while a backdoor was installed in the background. The used backdoors are signed with a valid, stolen certificates, which might help to bypass certain security mechanisms of the operating system and anti-virus software. Windows users who want to protect themselves against rtlo to the detail switch. In this case, Windows will display the jpg image is actually an application.

Saturday, 18 July 2015

Zero-Day Vulnerability In Microsoft Office Used For Cyber-Espionage


Last Tuesday, Microsoft patched a zero-day vulnerability in Office, which recently has been actively used by a group engaged in cyber espionage. The group sent at least one RTF document on the nuclear negotiations with Iran. The document, which was discovered in Georgia, contained an exploit for a critical vulnerability in Microsoft Office 2013 Service Pack 1 and earlier versions of Office.

Once users opened the paper exploits document was replaced by a genuine document with information on the nuclear negotiations. In the background, however, was installed a backdoor that attackers had full control over the computer, says security firm iSIGHT Partners . According to the company, the group behind the attacks also associated with a recently patched zero-day vulnerability in Java that was also used in targeted attacks.

The group would in April two zero-day vulnerabilities in Flash Player and Windows have used and the recently unveiled Flash exploits which was available to the Italian Hacking Team. The group would have to cater for the collection of military and diplomatic intelligence, although telecoms and defense companies have been targeted. The Office leak that the group is used patched by MS15-070 .

Adobe Flash Player Arming Against New Attacks


Adobe has security measures in collaboration with Google added to Flash Player that should arm the video plug-in against new attacks. In recent months, several different zero-day vulnerabilities found in Flash Player that allows Internet users were attacked.

In this case there was no update available before the attacks took place. In addition, there were dozens of other vulnerabilities discovered in the software that could give an attacker access to computers. A number of these leaks, after the appearance of the update also be used for users of attacks. In this case it was users who did not install the update. A large proportion of the vulnerabilities in Adobe fixes Flash Player detected by Google. The reason is that Google Chrome has an embedded Flash Player. Vulnerabilities in Flash Player can consequently affect Chrome users. In addition, Google has a separate team of hackers that focuses on researching and safer popular software, such as Flash Player.

In addition to reporting new vulnerabilities Google therefore contributes to security. Measures to make it more difficult for attackers to attack vulnerabilities. Along with these measures now from Adobe Adobe Flash Player version 18.0.0.209 implemented. Thus, for example, the memory locations of Flash Player made ​​more random. Because these locations were previously predictable, an attacker could easily use it here. "We think we have put a great step forward when it comes to the security of Flash, but we're not done yet," said Chris Evans of Google.

He stressed that will find a way for every defensive measure attackers to bypass it. "It's a cat-and-mouse game." Evans stressed that the new security measures are effective in 64-bit versions of Flash Player. Users also are advised to upgrade to a 64-bit version of both their browser and Flash Player.

Thursday, 16 July 2015

Manufacturer Stops Installing Flash Player On Computers



The American computer manufacturer System76 has stopped the default install Adobe Flash Player on new computers. It includes both desktops and laptops now come without the video plug-in. System76 delivers desktops, laptops and servers, which all run on Ubuntu.

In 2007, the manufacturer of a license to install Adobe Flash Player advance new systems. Something the company did until now standard. Starting today, there came a change in systems and be delivered without Flash Player. According to the manufacturer's decision is based on two reasons. First, Flash Player no longer required to have a "full web experience", whereas previously it was often the case. In addition, the safety of users of the other reason.

In recent weeks, several zero-day vulnerabilities discovered in the video plug-in, which were then used by cyber criminals to infect computers silently by malware. Besides the decision to henceforth avoid Flash Player System76 also advises to remove the browser plug-in already purchased systems. "Even if you think you need Flash, you might have to experiment further by not using a time. You will be surprised how little your Internet experience is changing," the company said.

In case customers but not without Flash Player is advised to Google Chrome, which uses a proprietary Flash Player located in a sandbox. Still, this offers no guarantee, as one of the Flash Player vulnerabilities that an attacker had discovered had to break out here the Italian Hacking Team, and then take on the underlying system. Therefore, it is according to the manufacturer still more sensible to avoid flash at all.

Wednesday, 15 July 2015

Microsoft Patches 59 Vulnerabilities, Of Which 7 Zero Days



Microsoft Patch Tuesday during the July 59 vulnerabilities in Windows, Internet Explorer, Office and SQL Server patched, 7 of zero days. It is in this case for vulnerabilities that were already known or were attacked before the relevant Microsoft security update was available.

Three of the zero-day vulnerabilities in Internet Explorer, Office and Windows were actively attacked, Microsoft said. Two of these vulnerabilities in IE and Windows, were coming from the Italian company hacked Hacking Team. This means that Hacking Team possessed far as is known about five zero-day vulnerabilities. In addition to IE and Windows, the company had also provided with three unknown vulnerabilities in Adobe Flash Player. The remaining four zero-day vulnerabilities that Microsoft patched this month found in IE and were already made ​​public, but according to the software giant does not actively attacked.

Updates

In total there are 14 security updates. Thus it belongs patch round both the number patches as corrected vulnerabilities into one of the toughest rounds patch from Microsoft ever. Four updates, MS15-065 , MS15-066 , MS15-067 and MS15-068 , have the highest priority and are labeled by Microsoft as critical. Through these vulnerabilities, an attacker can take over the underlying system. These include a vulnerability in the Remote Desktop Protocol (RDP). RDP is not enabled by default, but if that is the case an attacker by sending a few packets take over the system.

Three other updates are not labeled as critical, but let an attacker or run arbitrary code on a computer. It is MS15-058 for SQL Server MS15-069 for Windows and MS15-070 for Office. Microsoft regards this update as "important" because an attacker needs to do more effort before code execution is possible. The other security bulletins this month fix vulnerabilities that an attacker can increase his privileges on the computer. These include to the zero-day flaw in Windows which was discovered by Hacking Team. In these vulnerabilities, an attacker must already have access to the system before use can be made.

The updates can be downloaded via Windows Update and will be automatically installed on most computers. An overview of all bulletins on this page to find.

Anti-Virus Company: Adobe Flash Player Is Just Like Smoking



The use of Adobe Flash Player is similar to smoking, people know that it is bad for them, but can not always stop, according to the Japanese anti-virus company Trend Micro. Last week, three vulnerabilities in the browser plug-in discovered, two of which are used by cyber criminals to infect computers with malware. The vulnerabilities were discovered by the Italian Hacking Team.

A company with forty employees. "As a relatively small company like Hacking Team can find these types of vulnerabilities, consider the tools that other parties, including countries dispose of. Previously, we only had suspicions about the extent of this problem. Now we have a better idea of the risk, "said analyst Martin Roesler . He notes that disappears in an ideal world Flash in its current form. Whether it is replaced by a technology such as HTML5, or Adobe finds a way to protect the software. According Roesler it is unlikely that this will happen.

"Despite the risks, people continue to use it as security alone is not sufficient reason not to do it." Makers of Web sites still use Flash, allowing users need the plug-in. Roesler calls therefore on end users to remove Flash Player if it is not needed, or click to set to play in. In this case, an extra mouse click required to activate the plug-in. In addition, companies are advised not to use Flash when developing new websites. Also Alex Stamos , the new head of security at Facebook, made ​​a call earlier that Adobe Flash has to stop so that there can be switched to HTML5.

Tuesday, 14 July 2015

Hacking Team Has BIOS Rootkit For Permanent Infection



The Italian Hacking Team has an UEFI BIOS rootkit to infect computers with spyware permanently from the company. This enables the Japanese anti-virus company Trend Micro on the basis of the data that was recently at the Italian company captured.

Hacking Team offers government agencies a "Remote Control System" (RCS) allows investigators to remotely access the computers, for example, suspects can get. To ensure that the software remains on computers even if the hard drive is formatted or replaced by a new one, Hacking Team has an UEFI BIOS rootkit developed.

The BIOS (Basic Input / Output System) and the Unified Extensible Firmware Interface (UEFI), the successor to the BIOS is a set of basic instructions for communication between the operating system and hardware. It is essential for the operation of the computer, and also the first major software that is loaded. In the case of Hacking Team involves a rootkit for UEFI BIOS, Insyde Software. The company makes BIOS software for laptops.

Physical Access

To install the rootkit do have to have physical access to the system can be obtained. According to analyst Philippe Lin Trend Micro can not be ruled out that it is also possible to remotely install the rootkit. The Italian company also developed a tool to help users of the rootkit and provides support in the event the BIOS image is not compatible. According to Lin, the rootkit can be modified so that it also works with other BIOS software, such as the well-known software vendor AMI.

To protect themselves against the attacks, users of Lin's advice to enable UEFI Secure Flash BIOS, update the BIOS if updates are available and set a password to access the BIOS or UEFI. However, it is in many computers as possible to reset the password, but in this case, a user can see that something is wrong because he forgot no longer have to specify whether his original password no longer works.

Monday, 13 July 2015

Ads Malware Via Flash Player Flaw


Vulnerability in Adobe Flash Player last Wednesday by Adobe was patched is now attacked by infected ads. It is the first flaw in Flash Player that were found in the stolen data of the Italian Hacking Team.

According to anti-virus firm Malwarebytes there since the discovery of this vulnerability an increase in attacks on Internet users through so-called drive-by downloads. In this case, Internet users become infected through unpatched software, which only visiting a malicious or hacked website or see getting an infected ad is sufficient. One reason for the increase in the number of attacks is that many users their Flash Player version have not yet patched, said analyst Jerome Segura.

Ads

Meanwhile, the leak will also be attacked by infected ads. The way this is done is remarkable, says Segura. This primarily concerns a Flash ad that loads another Flash file containing the exploit for the Flash Player leak. The use of contaminated advertentes is much more common, but in most cases advertisements pointing to another website that the user attempts to attack.

The infected ad came from the DirectRev ad network and offered directly from the ad network server. In case the attack is successful, the Kovter malware is installed. Kovter can use computers to commit fraud ad (click fraud) or install ransomware.The malware was recently still in the news because the vulnerable versions of Flash Player on infected computers patches, to keep other malware on the computer outdoors.

Sunday, 12 July 2015

New Flash Player Flaw Hacking Team Actively Attacked


The Italian Hacking Team appears to have over many more unknown vulnerabilities in Adobe Flash Player than the one that was unveiled earlier this week and one of these leaks is now actively attacked by cyber criminals and an update from Adobe is not yet available.

Thereby running millions of Internet users risk. The situation looks like a repeat of the scenario that played out earlier this week. An attacker managed to break into Hacking Team and made ​​as 400GB of data booty. The data has a zero-day vulnerability for Flash Player encountered. After the discovery added to all kinds of so-called criminals who exploit kits with Internet attack . Adobe then came up with a patch to fix it.

Two new zero days

In the archives of Hacking Team researchers have now two new "zero-day vulnerabilities" found and made ​​public. The vulnerabilities in Adobe Flash Player version 18.0.0.204 and earlier are designated by the CVE numbers CVE-2015-5122 and CVE-2015-5123. One of these vulnerabilities, CVE-2015-5122, cyber criminals have been added to the Angler Exploitkit, reports researcher JuK of the blog Malware Do not Need Coffee. The code has also been added to Metasploit, a program for security professionals and penetration testers can test the security of networks and systems.

Thereby running Internet with Flash Player when visiting a hacked or malicious Web site, see getting infected ads or open a Word document with an embedded Flash file the risk of becoming infected with malware. As this week will come with Adobe emergency patch. However, to be published next week, as the software company in the late notice know, although the advisory refers to the week of 12 July. In the meantime, Internet users can protect themselves by temporarily disabling Flash Player.

Update

The CERT Coordination Center (CERT / CC) at Carnegie Mellon University warns also of vulnerability and allows users to protect themselves from the free Microsoft EMET to install or not to implement Flash content from unreliable.

Flash Player Leak Attacked Via Email With "Flash Update"


Besides cyber criminals now also create different groups that engage in cyber espionage using the vulnerability in Adobe Flash Player which this week released a patch appeared. It is about the vulnerability where the Italian Hacking Team had.

A hacker who managed to break into the company made 400 GB of data captured and put it online. In the files the Flash Player flaw was found and an exploit that allows its use. The exploit was quickly added to cyber criminals exploit kits and has been included in the Metasploit program. Now reporting anti-virus company ESET and security Volexity which called APT groups use the exploit in targeted attacks. It mainly involves attacks via e-mail.


The attack where Volexity warns consists of an e-mail masquerading as a message from Adobe. In the message, users are encouraged to update Flash Player using the attached link. The link does not point to the Adobe website, but to a page this week patched Flash vulnerability is trying to attack. Is the attack successful, malware is installed on the computer with which the attackers have full access and control over the computer.

Second attack

Also in the case of the attack that ESET is reported using email made ​​to lure victims to a malicious website. The link in the email points to a landing page that collects all sorts of data on the computer. In the event that your computer meets certain requirements, such as language and time zone, the exploit is loaded. Again, concerns the exploits based on the code of the Italian Hacking Team.

If the attack succeeds, then a backdoor installed. The backdoor also uses a different exploit where Hacking Team on disposal and that it is possible for an attacker to increase his rights to Windows. This Windows vulnerability, which can only be attacked if the attacker already has access to the system, no update is available.

Friday, 10 July 2015

Hacking Team Warns Leaked Software



The Italian developer of government spyware Hacking Team, which was recently the victim of a major burglary, has issued a warning for the software that was stolen at the company and has appeared online.According to the Italian company has sufficient code captured by which malicious attack other Internet users.

"For Hacking Team could determine the attack who had access to the technology, which was only sold to governments and government agencies." Through the work of criminals were now "terrorists, extortionists and others" to use the technology, according to the warning from the company. It is the first reaction to the incident Hacking Team via the website has brought out. According to the Italian company, the resulting situation is very dangerous. Hacking Team would also check whether it is possible to reduce the risk.

In addition, the company expects that will take anti-virus companies measures. Hacking Team develops software that allows investigators computers of suspects can control remotely. Because of the incident investigation services were requested to make temporary use of the software. Meanwhile, we are working on an update so that investigators can monitor the systems that have been infected with software Hacking Team again.

Furthermore, the Italian company has denied the reports that backdoors are present in the software that can control it. "That's just not true. Our customers use the technology on their own computer, and are therefore customers need to take action to cease operations," the statement said.

Flash Player Leak Of Hacking Team Previously Attacked


The critical vulnerability in Flash Player, which the Italian Hacking Team disposal and this week was discovered and published, has already been used to attack in Korea and Japan. These are limited attacks that took place on July 1, reports the Japanese anti-virus company Trend Micro.

Hacking Team had developed an exploit that made ​​abuse of the then unknown Flash Player flaw. However, operating would have been used on 1 July, before the hacker to Hacking Team did in breaking the corporate data put online, says Trend Micro . The exploit that discovered the virus fighter is very similar to that of Hacking Team. "We think this attack was carried out by someone who has access to the tools and code of Hacking Team," said analyst Wu Weimin. The only difference was that the leaked operates Hacking Team did not contain malware, whereas in the attack which it was held on July 1 the case.

Victims used by the leak to attack his likely spear phishing emails. These emails contain a Word document with a link. This link pointing back to a website with the Flash Player exploit. Further investigation revealed that the website from June 22 already had been visited by other users from Korea, as well as a user from Japan. Whether these users through the same or other exploits are attacked Trend Micro can not confirm, but according to this virus fighter is quite probable. Meanwhile, Adobe has released an update released to fix the leak.

Hacking Team Had Conceived Attack On Tor Users


The Italian developer of government spyware Hacking Team had thought an attack on users of the Tor network, according to a presentation that was captured at the company and analyzed by the Tor Project. The Italian company said recently that it had an exploit for Tor Browser, the browser used to connect to the Tor network can be made.

Based on a preliminary analysis of the data by Hacking Team were stolen this turns out not to be the case. This week published an attacker about 400GB of files were from Hacking Teams network. Including a presentation on attacking encrypted connections and Tor users were found. The attack Hacking Team had thought comes down to that first briefly a target had to be chosen.

Next to be determined is how users connect to the internet. After this, the hardware would Hacking Team on the local network, such as the ISP, be put down. Next, wait until the user was using it with a different browser. By adding an exploit on the pages visited by the user, for example via the Adobe Flash Player flaw which Hacking Team disposal, the computer might be infected with malware.

If the control was obtained over the computer users of the Tor Browser could be set to use a socks proxy on a remote server that is owned by Hacking Team. This way, the user would not use the Tor client that is part of the Tor Browser, but the Tor client Hacking Team. Thus Hacking Team can view traffic before it goes to the Tor network.

Scalable

According to Tor Project, the organization that maintains the Tor network, the attack of the Italian company is not very scalable. In addition, attackers who control over a user's computer also have many other ways have to fall further users. At issue in this case mass surveillance but targeted surveillance. As a solution, the Tor Project recommends Tails, an operating system focused on privacy that does not use local "resources".

"Ultimately, security down here on having secure browsers. That's why we work hard to Tor Browser to create more resistant to attacks, but the lesson in this case is that they attack the weakest link in your system, and in the case of Hacking Team Tor Browser is not the weakest link, " says Tor developer Roger Dingledine.

Wednesday, 8 July 2015

Zero-Day Vulnerability In Flash Player Active Attacked - Update


The vulnerability in Adobe Flash Player which the Italian developer of government spyware Hacking Team disposal is now actively used to infect internet users with malware. Recently, an attacker managed to break in Hacking Team in there and made some 400GB of data booty.

Among the files an exploit was discovered a vulnerability in Flash Player for which no security exists a so-called 'zero-day'.Anti-virus firm Malwarebytes and researcher JuK of the blog Malware Do not Need Coffee now now report that several exploit kits about the exploit to have discovered by Hacking Team Flash Player flaw.

Exploit kits are programs that cyber criminals can infect Internet users through unpatched vulnerabilities in popular software.Thereby running Internet using Adobe Flash Player now a high risk of becoming infected with malware. Visiting a hacked or malicious Web site or see getting an infected ad is sufficient to run an infection.

Emergency Patch

Adobe yesterday evening let know that there are expected today to emergency patch will appear. The notice is still no reports that the vulnerability is also actively attacked. Google Chrome users seem to be already protected against the vulnerability. Yesterday, Google published because a new version of Google Chrome. Details on changes Google is not announced, but discovered that the embedded Flash Player in the browser but was upgraded to a version that is not vulnerable according to Adobe.

Update 12:38

Adobe has released the emergency patch already released . This is version 18.0.0.203 for Windows and Mac users, while version 18.0.0.204 for the Linux version of Chrome is available. For the Linux version of Firefox, version 11.2.202.481 appeared. The update will be rolled out in most cases via the automatic update function, but can also be downloaded manually from Adobe.com .

Tuesday, 7 July 2015

Hacking Team Had Zero Day Vulnerabilities For Windows And Flash



The Italian developer of government spyware Hacking Team had zero day vulnerabilities for Windows and Adobe Flash Player, according to the files that were stolen from the company. Yesterday published attackers a file of about 400GB with all sorts of information that was captured by Hacking Team.

The files have now discovered two vulnerabilities for which no security update available yet, says security researcher The Grugq . It is a vulnerability in Windows that allows an attacker can increase his rights on the system. In this case, the attacker must already have access to the computer in order to use the leak. The second vulnerability is in Adobe Flash Player. Through this vulnerability, an attacker computers or completely take over, for example, when users visit a hacked or malicious website.

The embedded Flash Player in Google Chrome is vulnerable. According to security researcher Kevin Beaumont makes the leak is possible to escape from the sandbox of Chrome. Researcher Rik van Duijn of security Dear Bytes however, leaves know that a sandbox escape "through the published code is not possible and therefore a second exploit is required. Hacking Team, which develops spyware for government agencies, has in statement confirming that it has been hacked. "We think there are documents of the company have been stolen. We have launched an investigation to determine the extent of the attack and to determine what exactly is captured," said a spokesman. The company's website has been offline since yesterday.

Update

The National Cyber ​​Security Center (NCSC) government has a warning issued for the flaw in Flash Player. Through the leak, an attacker execute arbitrary code on the computer with the rights of the logged in user. The NCSC states that there is no update available for the leak yet.

Update 13:48

The attack on Hacking Team is claimed by the hacker who last year by spyware developer Gamma International managed to break in and there gigabytes of data was captured, says Vice Magazine . The hacker says soon come up with the details of how he managed to break into Hacking Team.

Update 15:09

Anti-virus company Symantec confirms that this is a zero-day vulnerability in the latest version of Flash Player. The virus firefighter expects that attackers will probably make use of the vulnerability.

Update 15:19

The CERT Coordination Center (CERT / CC) at Carnegie Mellon University warns also the vulnerability and says that users can protect themselves by installing Microsoft EMET unreliable or not Flash content to perform.

Hacking Team Gets Control Back Hacked Twitter Account


The Italian company Hacking Team spyware for governments to develop and victim of a very large hack became possible where all data was captured, has regained control over its own Twitter account after about 10 hours.

A group of attackers who "HackedTeam" named used the hijacked Twitter account to spread links to a torrent file containing the data that was captured at the break. It would go together to such a 400GB 500GB of data. How the attackers were able to gain access to the network is still unknown. The leaked documents would prove, however, that surveillance company weak passwords like "Passw0rd" used. In addition, should the software company SQL Injection vulnerabilities contain.

The burglary was also the source of all kinds of programs, as well as the software itself stolen. A number of the programs has now been on GitHub placed. Furthermore, it seems that the attackers hacked not only the company but also at least one employee of the company. The Gmail account of this employee would be hacked and his Twitter account. Meanwhile, the Gmail password changed and raised the Twitter account, so says a security engineer with the alias "bcrypt" via Twitter.Hacking Team's website is now also no longer accessible.

Monday, 6 July 2015

Italian Spyware Developer Hacked Hacking Team



Attackers have managed the controversial Italian surveillance operation and spyware developer Hacking Team to hack and thereby some have 400GB to 500GB of data captured, including financial data, software source code, e-mail and much more sensitive matters.

Hacking Team is a company that develops spyware for governments in recent years and was regularly in the news . The company's spyware would include being deployed by totalitarian regimes against activists. As Amnesty International showed a tool developed to detect the spyware Hacking Team. How the attackers, calling themselves Team Hacked call, access the data received is unknown. The stolen data is now distributed via .torrent files.

Evidenced by the now leaked information that the company customers in countries like Ethiopia, Sudan, Azerbaijan, Bahrain, Oman, Saudi Arabia has and the United Arab Emirates, but also Switzerland, Spain, Poland, Luxembourg, Germany and the United States found in the customer base, as on Hacker News reported, and would from a post on Pastebin appear. An anonymous source leaves in front of Vice Magazine that the attackers have managed to steal all company.

Last year was the German-British Gamma International, developer of the FinFisher spyware same. The website was hacked and then published attackers database, ultimately to parliamentary questions resulted in Netherlands. In an e-mail now to Hacking Team was captured late CEO and founder of the Italian surveillance company David Vincenzetti, bending over his rival hacked off. "A wannabe competitor of ours is severely compromised," he writes. Hacking Team has not yet responded to the burglary, which about nine days ago was announced.

Update

By now appear more and more details about the stolen data. There is an overview of the contents of the torrent file online appeared. Privacy activist Christopher Soghoian reports that the Italian company used illegal software, as there was a cracked version of a popular analysis tool found in the download. Another Twitter announced that the software Hacking Team vulnerable for SQL Injection.