Read more: http://thehackernews.com/2013/10/malware-infected-international-atomic.html#ixzz2iiH4NNRx
Follow us: @TheHackersNews on Twitter | TheHackerNews on Facebook
Tag: Hacker News
Chinese Hackers Caught by US water control system Honeypots

http://thehackernews.com/2013/08/Chinese-hackers-APT1-honeypot-water-control-system.html
Massive Brute-force attack Targets WordPress sites worldwide
A large distributed brute force attack against WordPress sites is understood to be occurring. A large botnet with more than 90,000 servers is attempting to log in by cycling through different usernames and passwords.
WordPress Pingback Vulnerability Serves DDoS attack feature
Accunetix a web application security company reported vulnerabilities found in the WordPress Pingback feature. According to report, Pingback vulnerability exists in the WordPress blogging platform that could leak information and lead to distributed denial of service (DDoS) attacks.
“WordPress has an XMLRPC API that can be accessed through the xmlrpc.php file. When WordPress is processing pingbacks, it’s trying to resolve the source URL, and if successful, will make a request to that URL and inspect the response for a link to a certain WordPress blog post. If it finds such a link, it will post a comment on this blog post announcing that somebody mentioned this blog post in their blog.” Bogdan Calin explained.
Tool description – “WordPress exposes a so called Pingback API to link to other blogposts. Using this feature you can scan other hosts on the intra- or internet via this server. You can also use this feature for some kind of distributed port scanning: You can scan a single host using multiple WordPress Blogs exposing this API.“
The bug is already reported on WordPress community, but Softpedia notice that the ticket was closed at the time after someone argued that “there are so many ways to orchestrate a DDOS attack.”
All the wordpress blogs are at risk,can be heavily abused by attackers. Since the WordPress also supports URL credentials , the attacker can use a link like http://admin:admin@192.168.0.1/changeDNS.asp?newDNS=aaaa to reconfigure internal routers.
He also says that disabling the Pingback feature won’t fix the solution ,the ultimate solution is a patch.
About Author:
Mohit Kumar aka ‘Unix Root’ is Founder and Editor-in-chief of ‘The Hacker News’. He is a Security Researcher and Analyst, with experience in various aspects of Information Security. His editorials always get people thinking and participating in the new and exciting world of cyber security. Other than this : He is an Internet Activist, Strong supporter of Anonymous & Wikileaks. His all efforts are to make internet more Secure.
http://thehackernews.com/2012/12/wordpress-pingback-vulnerability-serves.html
Hackers Hit Former U.S. Military Chief
About Author:
Mohit Kumar aka ‘Unix Root’ is Founder and Editor-in-chief of ‘The Hacker News’. He is a Security Researcher and Analyst, with experience in various aspects of Information Security. His editorials always get people thinking and participating in the new and exciting world of cyber security. Other than this : He is an Internet Activist, Strong supporter of Anonymous & Wikileaks. His all efforts are to make internet more Secure.
Sensitive information of 1 Million people breached at Nationwide Insurance
About Author:
Mohit Kumar aka ‘Unix Root’ is Founder and Editor-in-chief of ‘The Hacker News’. He is a Security Researcher and Analyst, with experience in various aspects of Information Security. His editorials always get people thinking and participating in the new and exciting world of cyber security. Other than this : He is an Internet Activist, Strong supporter of Anonymous & Wikileaks. His all efforts are to make internet more Secure.
Read more at http://thehackernews.com/2012/12/sensitive-information-of-1-million.html#bGEqKbfr5O1mtMXg.99
XSS vulnerability in 4shared and NATO Multimedia Library Exposed
These three servers are available online without authorization, but its not confirm that servers got hacked or not.
.jpg)
Hackers break into International Atomic Energy Agency servers
.jpg)
Israeli Hackers Leak Credit Card Data from Palestine ISP
!!EEV: Again, always proceed with caution when clicking unknown links!!
About Author:
Mohit Kumar aka ‘Unix Root’ is Founder and Editor-in-chief of ‘The Hacker News’. He is a Security Researcher and Analyst, with experience in various aspects of Information Security. His editorials always get people thinking and participating in the new and exciting world of cyber security. Other than this : He is an Internet Activist, Strong supporter of Anonymous & Wikileaks. His all efforts are to make internet more Secure.
http://thehackernews.com/2012/11/israeli-hackers-leak-credit-card-data.html
Anonymous Hackers may have hacked Former CIA Director David Petraeus
About Author:
Mohit Kumar aka ‘Unix Root’ is Founder and Editor-in-chief of ‘The Hacker News’. He is a Security Researcher and Analyst, with experience in various aspects of Information Security. His editorials always get people thinking and participating in the new and exciting world of cyber security. Other than this : He is an Internet Activist, Strong supporter of Anonymous & Wikileaks. His all efforts are to make internet more Secure. Follow him @ Twitter | LinkedIn | Google | Email
http://thehackernews.com/2012/11/anonymous-hackers-may-have-hacked.html
Guy Fawkes Day start with Hack of 28,000 Paypal Accounts
– See more at: http://thehackernews.com/2012/11/guy-fawkes-day-ends-with-hack-of-28000.html#sthash.8Gjujh22.dpuf
Mohit Kumar aka ‘Unix Root’ is Founder and Editor-in-chief of ‘The Hacker News’. He is a Security Researcher and Analyst, with experience in various aspects of Information Security. His editorials always get people thinking and participating in the new and exciting world of cyber security. Other than this : He is an Internet Activist, Strong supporter of Anonymous & Wikileaks. His all efforts are to make internet more Secure
GhostShell leaks 2.5 million Russian government accounts as #ProjectBlackstar
This set of hacks is spread out across 301 links, many of which simply contain raw dump files uploaded to GitHub and mirrored on paste sites like Slexy.org and PasteSite.com. The files include IP addresses, names, logins, email addresses, passwords, phone numbers, and even addresses.
.
“The average citizen is forced to live an isolated life from the rest of the world imposed by it’s politicians and leaders. A way of thinking outdated for well over 100 years now,” Team GhostShell member DeadMellox wrote. Project BlackStar is the second alleged hack from Team GhostShell in the last month.
.
“The still present communism feeling has fused with todays capitalism and bred together a level of corruption and lack of decency of which we’ve never seen before.”
GhostShell’s latest operation was announced just one day after Russia’s new “Internet blacklist bill,” Bill 89417-6, took effect. The controversial legislation allows the Russian government to censor any site accused of illegally hosting copyrighted material by ordering the country’s Internet service providers to block access.
.
About Author:
Mohit Kumar aka ‘Unix Root’ is Founder and Editor-in-chief of ‘The Hacker News’. He is a Security Researcher and Analyst, with experience in various aspects of Information Security. His editorials always get people thinking and participating in the new and exciting world of cyber security. Other than this : He is an Internet Activist, Strong supporter of Anonymous & Wikileaks. His all efforts are to make internet more Secure
– See more at: http://thehackernews.com/2012/11/ghostshell-leaks-25-million-russian.html#sthash.wEsyIYLd.dpuf – See more at: http://thehackernews.com/2012/11/ghostshell-leaks-25-million-russian.html#sthash.wEsyIYLd.dpuf
1 Million dollar hacked in 60 Seconds from Citibank
FBI agents assisted by the Glendale Police Department and the Los Angeles Police Department arrested 13 of the defendants in the Los Angeles area Wednesday and Thursday.
About Author:
Mohit Kumar aka ‘Unix Root’ is Founder and Editor-in-chief of ‘The Hacker News’. He is a Security Researcher and Analyst, with experience in various aspects of Information Security. His editorials always get people thinking and participating in the new and exciting world of cyber security. Other than this : He is an Internet Activist, Strong supporter of Anonymous & Wikileaks. His all efforts are to make internet more Secure. Follow him @ Twitter | LinkedIn | Google | Email
– See more at: http://thehackernews.com/2012/10/1-million-dollar-hacked-in-60-seconds.html#sthash.kZR6LnC6.dpuf
Researchers caught espionage malware mastermind on webcam: linked Russian Official Security Agencies
In march 2011 CERT-Georgia has Discovered Cyber Espionage Attack Incident on country of Georgia. Advanced Malicious Software was Collecting Sensitive, Confidential Information about Georgian and American Security Documents and then uploading it to some of Command and Control Servers.
.
“We have obtained Russian Document, from e-mail, where he was giving someone instructions how to use this malicious software and how to infect targets. We have linked him with some of German and Russian hackers. Then we have obtained information about his destination city, Internet service provider, e-mail, and etc.” Researchers said.
Most Georgian Infected computers were from our Governmental Agencies and Critical Information Infrastructures . Main targets of hacker was classified information from Georgia Ministries ,Parliament ,Critical Information Ifrastructures, Banks , NGO’s.
During investigation they got the origin of hacker, which was Russian Ministry of Internal Affairs, Department of Logistics , according to google map its just next to “Federal Security Service of the Russian Federation (FSB)”
About Author:
Mohit Kumar aka ‘Unix Root’ is Founder and Editor-in-chief of ‘The Hacker News’. He is a Security Researcher and Analyst, with experience in various aspects of Information Security. His editorials always get people thinking and participating in the new and exciting world of cyber security. Other than this : He is an Internet Activist, Strong supporter of Anonymous & Wikileaks. His all efforts are to make internet more Secure. Follow him @ Twitter | LinkedIn | Google | Email
– See more at: http://thehackernews.com/2012/10/researchers-caught-espionage-malware.html#sthash.yRm90N2B.dpuf – See more at: http://thehackernews.com/2012/10/researchers-caught-espionage-malware.html#sthash.yRm90N2B.dpuf
Anonymous going to lauch wikileaks like project called TYLER
About Author:
Mohit Kumar aka ‘Unix Root’ is Founder and Editor-in-chief of ‘The Hacker News’. He is a Security Researcher and Analyst, with experience in various aspects of Information Security. His editorials always get people thinking and participating in the new and exciting world of cyber security. Other than this : He is an Internet Activist, Strong supporter of Anonymous & Wikileaks. His all efforts are to make internet more Secure. Follow him @ Twitter | LinkedIn | Google | Email
– See more at: http://thehackernews.com/2012/10/anonymous-going-to-lauch-wikileaks-like.html#sthash.4vk647F9.dpuf – See more at: http://thehackernews.com/2012/10/anonymous-going-to-lauch-wikileaks-like.html#sthash.4vk647F9.dpuf
Hacker catches Facebook registering private links as ‘likes’
If you’ve sent Facebook friends a link to something out on the wilds of the World Wide Web, the social network knows and they’re telling others about it.
A video published online this week by a poster on Hacker News reveals that Facebook scans private messages and registers links in them as “likes.” That means if you’ve ever privately sent your friends a link to something you’d rather not publicize, well, too bad.
The “likes” problem could better be described as an exploit of Facebook’s code that can be used to fraudulently inflate the number of “likes” an external page gets.
For instance, if a company wanted a product to appear popular, they could set up dozens of fake Facebook accounts and begin trading messages back and forth, adding “likes” just as fast as they can click “send” — up to 1,800 an hour, according to the anonymous person behind the video.
“[It] won’t drive any traffic to your website,” a commenter on Hacker News noted. “But if your visiting an online store and you see a lot of likes under the product then this might cloud your judgement.”
For a publicly-traded company, the potential for “like” fraud is a serious threat to their credibility — perhaps even moreso than the obvious concerns over collecting metrics data from ostensibly private communications.
Facebook didn’t commented on the exploit, but Raw Story‘s own tests showed that the “likes” were no longer appearing on public-facing profiles. The “likes” were instead only visible in Facebook Insights for domain owners.
Facebook founder Mark Zuckerberg said Thursday that the social network has over 1 billion monthly active users, making the site by far the largest of its kind in the world.
This video was published to YouTube on October 3, 2012
http://www.rawstory.com/rs/2012/10/04/hacker-catches-facebook-registering-private-links-as-likes/
‘Anonymous’ retaliates after member arrested by FBI

WASHINGTON — The hacker group known as Anonymous on Thursday posted credit card numbers in retaliation for what it claimed was an FBI raid arresting one of its members.
The group said Barrett Brown was arrested in an FBI raid while participating in an online chat Wednesday.
Contacted by AFP, the FBI declined to comment.
But a video posted by the group, a loosely knit collective with no clearly defined leadership structure, showed the chat interrupted by what appeared to be a raid.
In retaliation, the group posted “these 13 credit cards details as teaser,” saying they were “potentially belonging” to government officials.
A Twitter posting said the offshoot of the group, called Antisec, “retaliates on Barrett Brown arrestation.”
According to a report on the website The Hacker News, Brown came to notoriety when he threatened to release the names of 75 collaborators of the Mexican Zetas cartel for kidnapping an Anonymous member.
The report also said he founded Project PM, which collects information about the intelligence industry and what it claims are threats to privacy and democratic institutions