Apple Crash Reports Help Hackers to create a jailbreak exploit


iPhone "jailbreaking" has been a hot topic since Apple released its smartphone more than two years ago. According to the Latest report posted by BBC that Thousands of iPhone owners have joined forces with a team of hackers to help them find new ways to jailbreak Apple's phone software & Jailbreakers use Apple crash reports to unlock iPhones.

You may be wondering and hearing alot on “What Is Jailbreaking an Iphone? How do you do that?” Jailbreaking is basically modifying the iPhone’s firmware so that you can get access to the internals of its operating system and install a whole slew of third-party applications on your iPhone that are not otherwise available through official channels.Jailbreaking your iPhone in and of itself doesn’t normally make much difference in your operation of it, but it does allow you to install other third-party applications that are not blessed by Apple.

A collective of hackers known as the iPhone Dev-Team publishes easy-to-use, cross-platform tools that allow you to install third-party apps on your iPhone that Apple won't admit into its App Store. The latest version of the iPhone's operating system is proving to be extremely hard to jailbreak fully, according to Joshua Hill, a member of the Chronic Dev hacker team."Apple is really making it tough for us. The iPhone is now better protected than most nuclear missile facilities," he says.

Jailbreaking your iOS device also enables you to change your phone’s behavior and even add some nifty extra features. One such feature that Apple prohibited was FaceTime or any demanding data tasks over 3G.


How Hackers Develop a Jailbreak application ? Well, Hackers like Mr Hill hunt for programming errors, or bugs, in Apple's software. Bugs may result in a program crashing or shutting down, and they are like gold dust to hackers because sometimes they can be exploited to create a jailbreak. Hackers may have to crash a particular program thousands of times as they work out how to exploit a bug successfully, but this alerts Apple that the bug exists and that hackers may be investigating it.

Phone manufacturers don’t want you to do it because of the small number of cases in which it can make the phone unstable or open it up to security breaches. It then makes them look bad because it’s their phone that’s crashing or introducing malware to your network. 

But Users Hate hate it even more because it can cost them money. They even go so far as to cripple features that the phone makers build in, so they can charge you an extra fee for the same service. One example is Wi-Fi hotspot capability, for which carriers charge up to $30 per month when you can do the same thing on a rooted phone with no extra fees using a free or low, one-time-cost app. Some carriers also don’t want you running apps like Skype to make phone calls instead of using expensive cellular voice minutes.

Chronic Dev is ready to turn this little information battle into an all-out, no-holds-barred information WAR. A program called CDevreporter that iPhone users can download to their PC or Mac. The program intercepts crash reports from their phones destined for Apple and sends them to the Chronic Dev team. "In the first couple of days after we released CDevreporter we received about twelve million crash reports," he says. "I can open up a crash report and pretty much tell if it will be useful or not for developing a jailbreak, but we have so many that I am working on an automated system to help me analyse them."

Is Jailbreaking Legal ? In July,2010 The United States government announced that jailbreaking and unlocking iPhones, rooting of Android phones and ripping DVDs (for educational purposes) is completely legal as long as they are not violating copyright law.  It is also apparently not illegal to jailbreak devices in the UK, although it does invalidate product warranties, according to Simon Halberstam, technology law expert and partner at Kingsley Napley.

Apple tries to prevent jailbreaking for security reasons  once a phone has been jailbroken users could unwittingly install malware that might not get past Apple's approval process. Mr Hill rejects this argument: "I am trying to make sure that my phone is safe and your phone is safe. Apple cares about money, not your safety."

As yet the Chronic Dev team has not announced that it has found any bugs that it can exploit, but a member of the team called pod2g claims to have found a way to create an untethered jailbreak anyway. Even if Apple fixes the bug that makes this jailbreak possible, Mr Hill is confident that the hackers will find more ways.

Facebook Ticker partially Removed Due To Various Bugs


According to a Post on Facebook Known Issues Page, Facebook has removed the ticker apparently motivated the social network to call the phenomenon a bug that’s undergoing a fix.

Facebook says that "Some people are seeing their ticker disappear. We are aware of this issue and are working to resolve it.". Comments explaining that people with less active accounts won’t see the feature, Because when your friends aren’t doing anything on the site, the ticker would only duplicate the news feed and not scroll, so there’s no point in the feature taking up part of your screen.

Not even this, Last month a Brazilian (independent) Security and Behavior Research had analyzed a privacy issue in Facebook Ticker that allows any person chasing you without your knowledge or consent .How Facebook Ticker exposing your information and behavior without your knowledge. Meanwhile, the Known Issues on Facebook page posted that some people aren’t seeing the ticker who should be, and that the site is working to fix this glitch and developers continues to refine the ticker, alternately testing labels for the feature along with shifting its location and size.

Facebook privacy flaw exposes Mark Zuckerberg private photos


Facebook privacy flaw exposes Mark Zuckerberg private photos

A flaw in Facebook has granted prying users access to supposedly private photographs, including those of the website’s chief executive, Mark Zuckerberg. In total 14 pictures of Mr Zuckerberg were posted to image site Imgur under the headline: "It's time to fix those security flaws Facebook".The bug in the website’s photo reporting tool - which Facebook says was only temporary and has now been fixed - meant that users could access others’ pictures even if they were private.
The flaw was first reported on the forums of BodyBuilding.com, presumably because the users of that website like taking photos of themselves and putting them online. The bug exploits the way the offensive photograph reporting tool works. Facebook has been heavily criticised in the last few years for matters of privacy and so there are people who will leap on this story as yet another example of how the company simply doesn’t take its users privacy seriously. Such problems have included a change to the terms and conditions that made all your photographs and statuses Facebook’s property and a settings change that made everything on everybody’s profile accessible to search engines by default.
The exploit has since been patched, and Facebook has officially responded:
“Earlier today, we discovered a bug in one of our reporting flows that allows people to report multiple instances of inappropriate content simultaneously. The bug allowed anyone to view a limited number of another user’s most recently uploaded photos irrespective of the privacy settings for these photos. This was the result of one of our recent code pushes and was live for a limited period of time."
In a blog post, Mr Zuckerberg said that “even if our record on privacy were perfect, I think many people would still rightfully question how their information was protected”.

“It's important for people to think about this, and not one day goes by when I don't think about what it means for us to be the stewards of this community and their trust,” he added. Facebook was forced to agree to external inspections of its privacy systems and agree to fines of $16,000 per day for new violations. Mr Zuckerberg also pledged to protect users' information "better than any other company in the world".

Indian Cyber Force Hacked By KhantastiC HaXor & Shadow008



The 2 Pakistani hackers called KhantastiC HaXor & Shadow008 has hacked the Official Site of Indian Cyber Force. The hacker had left a message to Indian Hackers that stop hacking Pakistani sites.

Site Hacked:
http://www.indiancyberforce.com/

Mirror:
http://www.zone-h.com/mirror/id/16004128

MySQL.com Once again Compromised using Sql Flaw



A hacker with name "D35M0ND142" claim to hack MySql.com website using Sql Injection Flaws. In September, Mysql.com was hacked and it was serving BlackHole exploit malware on the site. In apastebin dump Hacker Exposes various Admin user credentials and Database info. The Compromised Usernames and Passwords are from Blog site of MySql.

MySql website is pretty embarrassed for not securing its own database’s properly, Even hacker share that "Robin Schumacher is MySQL's Director of Product Management andhas over 20 years of database experience in DB2, MySQL, Oracle, SQLServer and other database engines. Before joining MySQL, Robin wasVice President of Product Management at Embarcadero Technologies."

Besides the hack on MySQL.com, D35M0ND142 also managed to breach the systems of the Urbino University in Italy and the Universal Language & Computer Institute in Nepal and Stream Database.

Hacker attack Google, Gmail, YouTube, Yahoo, Apple, Microsoft, Hotmail…



The biggest are down!!! Hacker with nickname AlpHaNiX attack Google, Gmail, Youtube, Yahoo, Apple etc. All websites are hacked on domain .cd wich belongs to Democratic Republic of Congo. Hacker use strategy so-called DNS cache poisoning.
Hacked websites:
http://apple.cd/
http://yahoo.cd/
http://gmail.cd/
http://google.cd/
http://youtube.cd/
http://linux.cd/
http://samsung.cd/
http://hotmail.cd/
http://microsoft.cd/




DNS cache poisoning is a method through which hackers are able to insert malicious and fake records into the cache of DNS servers. As a result, the hackers can then spoof a response to a DNS query, forcing users to go to a phony Web site instead of the real one.

Picture show you how hacker insert fake records into the cache of DNS servers.



Biggest Independent Russian Election site Hacked on election day


Popular Russian media websites, the major LiveJournal social network and the website of the country’s biggest independent election watchdog, were inaccessible in hacking attacks for several hours on Sunday in what their employees said was an attempt to jam information on parliamentary elections.“The attack on the website on election day is apparently tied to an attempt to publish information about violations,” chief editor of the independent-minded Ekho Moskvy radio Aleksei Venediktov wrote in his Twitter blog.Websites of Forbes Russia, Bolshoi Gorod and New Times magazines, Slon.ru news portal, Golos election watchdog and its Kartanarusheniy.ru website that was supposed to map vote fraud were down throughout most of Sunday.These media organizations and the watchdog have pledged to report voting violations from all over Russia live.Independent and opposition media, as well as the LiveJournal social network that has become the main political discussion venue in Russia, are often subjected to hacking attacks, though the Sunday assault was the most concerted and broad. Law enforcement officials had not commented on it as of late Sunday afternoon.[Source]

Related Posts Plugin for WordPress, Blogger...