Showing posts with label Steal Information. Show all posts
Showing posts with label Steal Information. Show all posts

Wednesday, 25 November 2015

Hilton Hotel Chain Discovered Malware On POS Systems


Hilton hotel chain has customers warned that possibly their credit card information stolen after it different POS systems malware has been detected. The malware was designed to steal the name of cardholder, credit card numbers, security codes and expiry dates.

Address details and PINs would not be captured. The malware was active from November 18 to December 5 last year and from April 21 to July 27 of this year. Customers in this period at a Hilton Worldwide hotel have used their credit cards are advised to check their statements. The chain does not know how many credit cards may be compromised and how the POS systems became infected. The malware was eventually discovered through its own systems.

Hilton further states that customers generally not for fraudulent activity on their debit are responsible and should notify their bank if they find irregularities. Furthermore, the chain offers customers a year of free credit monitoring. The malware would by now have been removed and the security of the hotel systems have been tightened.

Monday, 23 November 2015

FBI Warns Officials For Attacks By Hacktivists


The FBI has a warning issued in which the police and other government staff warns of cyber attacks by hacktivists. In addition to attacks in which there is information about agents and officials is gathered and published, there have also been attacks observed attempting to hack into the email accounts of agents and officials.

Recently, there was still an old private mail account CIA director cracked. According to the FBI's use of social media can increase the chance of being attacked. The attacks are not directly aimed at the person but are carried out via eg the ISP or email provider. Thus, the attackers use social engineering to steal information from these parties, which they eventually gain access to email accounts.

Actions

To limit such attacks advises the FBI's use of two-factor authentication, turn on privacy settings, limiting the social media footprint, no post information about work or function online, be careful with online responses, secret questions and answers unanswerable simply, regularly changing passwords is also more than 15 characters and should also advise families to secure their accounts properly. The FBI provides advice to government personnel to periodically check what information about themselves online to find.

Saturday, 21 November 2015

PayPal Phishing Site On World Bank Group Website



A website run by the World Bank Group, has this week been compromised. The site climatesmartplanning.org, which was provided with a valid Extended Validation SSL Certificate, appeared for a short time one hardly be distinguished from real phishing site with a PayPal login page.

Visitors were asked to sign in with their own PayPal information. The entries were processed and sent to the criminals.

After this gave the site gave a message that the account data is temporarily not available, and it required an additional verification. Visitors were invited to give their name, date of birth, address, telephone number and finally to give up your credit card number plus the CSV code, writes Netcraft. Those who had completed everything, was eventually transferred to real website of PayPal.

According to Netcraft, the criminals can take advantage of the smart Extended Validation SSL certificate that has the site climatesmartplanning.org. Made it seem as if the site was to be trusted. The EV certificate has been revoked.

The Climate Smart Planning Platform is an initiative led by the World Bank, to develop employees with tools, data and knowledge to be busy in developing countries with climate change.

Friday, 20 November 2015

"Apple's Siri Personal Reveals"


Users with an iPhone or iPad who appreciate their privacy, the voice assistant Siri better off if they do not use it. Experts Trend Micro maintain that someone on an iPhone or iPad when Siri is activated within 30 seconds after the full name, email, phone number and profile picture may come. It does not matter whether the device is locked.

Data

Who has a phone in hand, with his voice can retrieve all kinds of information, such as name, contact information and even calendar appointments. By the command 'what is my name' to speak of, for example, Siri intones the full name of the owner.And so there are a number of assignments which Siri, even if the smartphone or tablet is blocked.

Privacy

It is, according to Trend Micro a weakness of Siri where users already longer complain on Internet forums. According to Trend Micro not only the privacy of the owner of the iPhone or iPad at stake, but also the contacts of that person.

Apple late in a response to the security company that Siri users can disable it on a locked screen. This can be done via the Settings menu and then using the "Touch ID & password 'option and then' Siri '. As the personal assistant can be switched off.

Sunday, 27 September 2015

Apple Will Protect Mac Computers From malware XcodeGhost


 In addition, also put a new variant of the Genieo-adware on the black list, let developer of Mac software Intego know.

XcodeGhost came a few days regularly in the news. Chinese developers had downloaded an infected websites through unofficial version of Xcode for OS X, Apple's tool for developing apps. The infected Xcode ensured that the developed apps became infected. Apple yesterday published a list of the 25 most downloaded apps infected. Besides XcodeGhost is now also detected a new version of the Genieo-adware. This adware creates problems for years to Mac users, according to the questions and comments on the official Apple forum.

Friday, 25 September 2015

Apple Publishes List Of Top 25 Infected Apps


Apple has as indicated previously published the list of the 25 infected apps were downloaded the most. The apps infected with malware XcodeGhost, which can send information about the device and apps. According to Apple the malware is not in a position to steal personal information.

We deliberately for a Top 25 chosen because in addition to these 25 applications, the number of affected users is very small. Users who have downloaded an infected app are advised to update the app, which addresses the issue. If the app is no longer available in the App Store, the update will appear soon. In the Top 25 apps are of WeChat, DiDi Taxi, Railroad 12 306, China Unicom, Baidu music, Himalay FM and various games. The apps have been downloaded by millions of people, mainly in China. Furthermore, Apple users will also be separate warn.

Sunday, 16 August 2015

Hacker Can Now Access Remote BMW And Mercedes



The famous hacker Samy Kamkar recently a tool presented that he cars from General Motors could open remote start and has expanded its device, which also cars from BMW, Mercedes-Benz and Chrysler are no longer safe. This has Kamkar via Twitter announced.

Like General Motoros other manufacturers offer a smartphone app to locate car, open and start. It involves BMW RemoteMercedes-Benz mbrace and Uconnect Chrysler. Kamkar developed for 100 dollars a small device, the OwnStar that a car or truck should be placed and the communication of the smartphone to the app to intercept.

The Ownstar consists of a Raspberry Pi and three radios and can occur as a friendly network. Once the user starts the app and the phone within range of the device is a man-in-the-middle attack is carried out to steal the user's credentials. Then this data via a 2G GSM connection is sent to the attacker. With the login information, an attacker then follow the car, open the doors, start the engine or to sound the horn or alarm.

The problem is that with the apps who do use SSL to exchange encrypted data, but the certificate not control well to ensure that there are also communicates with the real servers of the mobile service. General Motors fixed it the problem but Kamkar discovered that the problem with BMW, Mercedes-Benz and Chrysler plays. According to the hacker, the cars thus easy to fall into. Manufacturers are now working on an update, but that is not yet available. Kamkar advises car owners not to use temporarily the corresponding apps.

Saturday, 25 July 2015

No New Data Ashley Madison Users Put Online


Several media reports that the attackers behind the hack of Ashley Madison information of users have put online, but it is the same data that Sunday had already been made ​​public. Attackers then made ​​known to the data of over 37 million users had captured, as well as all kinds of business data of a site for cheaters.

The attackers threatened to remove all data online as Ashley Madison has not been taken off the air. The website is still online. Still, the threat has not yet been implemented and there are no new data made public. In announcing the hack data from two users were mentioned. It is the real name, username, registration date, complete address, email address, sexual fantasies, desires and password hash of an American man.

In the case of the second user it comes to someone from the "full delete" function had used. This option allows users of the website for $ 19 it removed their profile. However, the purchase details have been preserved, said the attackers. In this case it is the user's name, address and sexual fantasies. His username, password hash and email address are not mentioned.Ashley Madison is a website for people who want to cheat. Because of the incident, the website decided users free of charge to raise their profile.

Monday, 6 July 2015

Clinton Gets Hard Out To Chinese Cyber Espionage


During an election event in New Hampshire, the Democratic presidential candidate Hillary Clinton lashed out hard at China, which they accused of widespread hacking systems and steal information. China hacks according to Clinton, "everything in America that does not move," notes CNN .

In addition, companies as well as government agencies are the target. "They steal trade secrets, blueprints of defense companies, large volumes of government information. All to gain an advantage," said Clinton. She went on to say that she hopes that China's growth will take place peacefully, but also called for vigilance, now the size of the Chinese army is growing strongly.

Sunday, 14 June 2015

Hack US Government Possibly Worse Than Thought


The US government agency that attackers late last year for a second time managed to break in and possibly the data of millions of officials spoils were very likely also sensitive private data stolen by which officials could be extorted.

The Office of Personnel Management runs a system called e-QIP, where federal officials can apply for security clearances. It should be introduced all sorts of very personal information ( pdf ), including financial data. Research now shows that these sensitive data may be stolen. It would be forms that officials must fill highly personal information, such as mental health problems, drug and alcohol use, arrests by police and bankruptcies. Also have names of acquaintances and contacts are being completed, and the social security number.

In a statement allows the White House that researchers have found that with a "very high degree of certainty" the systems for the background checks of current, former and future officers used are compromised and data is stolen, reports the Associated Press . As with the first report of the burglary researchers have no hard evidence that the data are actually captured.

Tuesday, 12 May 2015

Trojan Hides In Microsoft SQL Database


Researchers have discovered a Trojan horse that is not downloaded from a URL, but through a Microsoft SQL database. That leaves Intel Security know. The infection begins with an infected e-mail attachment that contains a downloader. Once the attachment is opened will download the final malware.

Normally this is done via a URL, but does in the case of the now discovered downloader that connects to a Microsoft SQL database. That makes it difficult for administrators to find out where the malware comes from. To download the Trojan horse downloader makes the connection to the database, check the correct table and downloads the malware via the response from the database.

VB.Net code showing the SQL query to download the payload.
In this case, it is a banking Trojan that steals money from Brazilian bank accounts. The malware can also steal login details for Facebook, email services and other websites where a password field is used. The Trojan also disables the G-Buster plug-in from. This plug-in should properly protect users during online banking. Furthermore, the malware screenshots of the online banking session. All information stealing malware is then stored in the Microsoft SQL database.

Saturday, 17 January 2015

Phishing Attack On LinkedIn Users With HTML Attachment


LinkedIn users have become the target of a phishing attack that through html files attempting to steal credentials. The email has the subject "LinkedIn Alert" and argues that there is a mandatory security update is necessary due to unusual activity.

LinkedIn phishing email

For this check is sent an html file. When users open the file, they get to see a copy of the real LinkedIn site. However, the code has been modified so that users via the HTML page to try to log their data forwarding to the attackers, warns anti-virus company Symantec. The IT security advises users to turn on two-factor authentication. Even if the credentials are stolen an attacker can therefore not on the account login.