Nathan Power from SecurityPentest has discovered new Facebook Vulnerability



Nathan Power from SecurityPentest has discovered new Facebook Vulnerability, that can easily attach EXE files in messages,cause possible User Credentials to be Compromised .


When using the Facebook 'Messages' tab, there is a feature to attach a file. Using this feature normally, the site won't allow a user to attach an executable file. A bug was discovered to subvert this security mechanisms. Note, you do NOT have to be friends with the user to send them a message with an attachment.


But Nathan Power Find the way to upload EXE . When uploading a file attachment to Facebook we captured the web browsers POST request being sent to the web server. Inside this POST request reads the line:
Content-Disposition: form-data; name="attachment"; filename="cmd.exe"
It was discovered the variable 'filename' was being parsed to determine if the file type is allowed or not. To subvert the security mechanisms to allow an .exe file type, we modified the POST request by appending a space to our filename variable like so:
filename="cmd.exe "

Anonymous DDOS Oakland police site after violence


Cyber activists associated with Anonymous have targeted the Oakland Police Department (OPD) and other law enforcement agencies that participated in a controversial crackdown against OccupyOakland protestors. A DDOS (distributed denial-of-service) attack against the department's websitewww.oaklandpolice.com is underway, and the website currently is unreachable.

AnonyOps tweet "I'm amazed and proud of #occupyOakland protesters who stood defiant, peaceful in the face of lethal force by Oakland PD."

Police fired a number of tear gas canisters, concussion grenades, rubber bullets and non-lethal rounds at demonstrators on Tuesday night, drawing widespread condemnation for the use of heavy-handed tactics against unarmed civilians.Cyber activists associated with Anonymous have targeted the Oakland Police Department (OPD) and other law enforcement agencies that participated in a controversial crackdown against OccupyOakland protestors. A DDOS (distributed denial-of-service) attack against the department's websitewww.oaklandpolice.com is underway, and the website currently is unreachable.

AnonyOps tweet "I'm amazed and proud of #occupyOakland protesters who stood defiant, peaceful in the face of lethal force by Oakland PD."

Police fired a number of tear gas canisters, concussion grenades, rubber bullets and non-lethal rounds at demonstrators on Tuesday night, drawing widespread condemnation for the use of heavy-handed tactics against unarmed civilians.


US satellites was victim by Chinese Hackers


Computer hackers, possibly from the Chinese military, interfered with two U.S. government satellites four times in 2007 and 2008 through a ground station in Norway, according to a congressional commission. According toBloomberg, the Chinese military is suspected of executing the digital intrusions which targeted satellites used for earth climate and terrain observation.

Indeed, a Landsat-7 earth observation satellite system experienced 12 or more minutes of interference in October 2007 and July 2008, while hackers tapped into a Terra AM-1 earth observation satellite twice, for two minutes in June 2008 and nine minutes in October that year. Interestingly enough, the report doesn't actually accuse the Chinese government of sponsoring or executing the four attacks. 



However, it clearly states that the breaches are "consistent" with Beijing's military doctrine which advocates disabling an enemy's space systems, and particularly "ground-based infrastructure, such as satellite control facilities."
[Source]

TeaMp0isoN releases list of vulnerable police web sites


TeaMp0isoN group of hackers published a list of vulnerable law enforcement authorities websites that can be hacked using MSAccess SQL injection attacks. Member from TeaMp0isoN with codename "_f0rsaken" create a pastebin note with following message for Police and People of World :
I do not like the Police. You beat on innocent and peaceful protestors for no reason other than that you want to protect your friends at the banks and yourselves to make money. It's all about money and the Police aiming to keep their job. Why did I decide on not releasing the databases? I want you to see for yourself how vulnerable these people really are and for you all to get an understanding on why I didn't release.


In this release I present you vulnerable websites that are open to MSAccess SQL injection. Below are official city websites that also the Police of that said area uses for their updates. Of course with all the money they make they couldn't spend a dime to invest into their security to make sure no breaches are bound to happen, they let petty vulnerabilities that still exist on their websites stay there with no fix.


Whatever you are storing fellow below cities, which I've seen from table names it isn't good, you better hope the rest of the Community who is smart doesn't find out what's to see ;-) You should of expected me a long time ago, now the realness is setting free the cage.
The SIX vulnerable sites as listed below
  • http://www.ci.vallejo.ca.us/GovSite/default.asp?serviceID1=79' (City of Vallejo, California Website)
  • http://holmesbeachfl.org/Cities/COHB/default.asp?section=3'(City of Holmes Beach, Florida Website)
  • http://www.cityofkaukauna.com/announcements/announcementdetail.asp?DeptID=1' (City of Kaukauna, Wisconsin Website)
  • http://www.ci.kaukauna.wi.us/departments/depthome.asp?DeptID=12'(City of Kaukauna, Wisconsin Website)
  • http://www.romenewyork.com/organization.asp?orgid=63' (City of Rome, New York Website)
  • http://www.eastgreenwichri.com/matriarch/MultiPiecePage.asp?PageID=84' (Town of East Greenwich, Rhode Island Website)
TeaMp0isoN Invites hackers to Use these vulnerabilities for destroying Police sites.

3 Indian Govt Websites Hacked by KhantastiC Haxor

A Pakistani Hacker called KhantastiC Haxor Hacked 3 Indian  Govt Websites .Hacker putting the following message on defaced sites

"g0t R00t3d ? -[220.156.188.72]- 

Hacked =P ??

[!] By KhantastiC HaXor!!
FREEBSD l0v3r Rap3d y0 *Winks*
# Khan@bsd ~ HellO GayHind PeoPle , Where is Security Now ?!
Are U Hacked ? Yesh ! U have been Hacked !!! not because of your stupidity thats because some Indian Gays hacked our Paki sites !
so just here to warn you, that you have been pwnd by Pakistani hacker This is not a joke or dream, this is fucking reality, kids.
This is now just a warning !!
Deleted Every Database !! Muwah <3 .... Backup in my P0cket =p ohh i means in ma Flash Drive =D ...
 


Hate me - Fear me - Despise me 

rm -rf /planet/world/earth/india
echo "The world is a better place now!"
Hey Admin: sorry, nothing harmed, just logs deleted
 
 
L0v3 tO :- all Muslims
h4ck3r@live.com.pk 
Defaced sites and Mirror http://pastebin.com/Lns502nN

World Call Telecommunication forum hacked by Indian Hacker

Today Indian Hacker Ro0t_d3vil Hacked World Call Telecommunication  forum.Hacker Hacked Website to take revenge from KhantastiC Haxor (who recently hacked Indian Telecommunication site BSNL)

BSNL Hacked by KhantastiC


A Pakistani hacker called KhantastiC HaXor has hacked into Bharat Sanchar Nigam Ltd.- India's No. 1 Telecommunications Company. The hacker had added a message to them saying:


Hax3d By KhantastiC haX0r
-[ Bharat Sanchar Nigam Ltd.- India's No. 1 Telecommunications Company ]-
Hacked =P ??
[!] By KhantastiC HaXor!!
# Khan@bt ~ HellO GayHind PeoPle , Where is Security Now ?!
Are U Hacked ? Yesh ! U have been Hacked !!! not because of your stupidity thats because some Indian Gays hacked our Paki sites !
so just here to warn you, that you have been pwnd by Pakistani hacker This is not a joke or dream, this is fucking reality, kids.
This is now just a warning !!
Deleted Every Database !! Muwah <3 .... Backup in my P0cket =p ohh i means in ma Flash Drive =D ...

Hate me - Fear me - Despise me
rm -rf /planet/world/earth/india
echo "The world is a better place now!"
Hey Admin: sorry, just logs and database deleted


L0v3 tO :- all Muslims
h4ck3r@live.com.pk



Site Hacked :
http://bsnl.co.in/tender1/

Mirror:
http://www.zone-h.com/mirror/id/15699580

Related Posts Plugin for WordPress, Blogger...