Sunday, March 10, 2013

Microsoft Sub-Domain hacked by Pakistani Hacker

Subdomain Of Microsoft Cracked Jacked By Pakistani Hacker P4K-CoMManDeR



 


Microsoft Congo Website's Sub Domain of  Hacked by Pakistan Hacker P4K-CoMManDeR from Team Cyber Switch .

After few days ago Microsoft Congo Website's got hacked by some hackers, Today Pakistani hacker hacked there sub domain...

Hacker left msg on deface page...



Thanks To : Dark Snipper
Site Has Been Defaced

Please Wait . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Hacked Hacked Hacked . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
~$ Connected !
Server~ Checking Bug . . . . . . . . . . . . . . . . . . .
Server~~ Trying connect to Command . . . . . . . . . . .
Server~~$ Connected Command!
Server~~$ Hacked By P4K-CoMManDeR
Helo Admin . . . . . . . . . . . . . . . . . . .
This Is Just Show Off . . . . . . . . . . . . . . . . . . .

Ur Site Security Is Fucked . . . . . . . . . . . . . . . . . . .
Hacking is not a Game . . . . . . . . . . . . . . . . . . .
Hacking is Art . . . . . . . . . . . . . . . . . . .


Site:

Samsung Galaxy Note || Screen Lock Bypass Vulnerability


Samsung Galaxy Note II lock screen bypass flawiOS was in the news lately for a series of security mishaps, but this time android back in scene. A security flaw discovered by Terence Eden on the Galaxy Note II with Android 4.1.2 that allows hackers to briefly bypass the phone's lock screen without needing a password.

By hitting "emergency call" then "emergency contacts" then holding the home button, the main home screen becomes visible for around a second just 

Anonymous Member Barret Brown Arrested


Anonymous hacker Barrett Brown was arrested by the FBI last night, his apartment raided while he was in the middle of a live TinyChat session.

For those that may not be familiar with Brown, he came to some notoriety last year for allegedly mounting an operation against the Zeta drug cartel in Mexico after they had kidnapped a member of Anonymous. Brown claimed to hold the names of 75 Zeta collaborators, which he threatened to release to the press unless the Anon member was set free.

Brown is the founder of Project PM and has worked closely with the Anonymous hacker collective on several past operations. This is not the first time that Barrett Brown’s home has been raided. Six months ago the FBI came knocking on Brown’s door and confiscated his laptop, but no charges were filed against him. That incident followed the arrest of then-LulzSec leader Sabu, or rather Hector Xavier Monsegur, who then turned informant in exchange for leniency, although it’s also been suggested that Sabu was working for the FBI prior to his arrest, which then served as a cover.
Anonymous member Barrett Brown Arrested
The arrest came just hours after the activist published a video in which he threatened to destroy FBI agent Robert Smith. The video came in response of the fact that, apparently, his mother was accused of obstruction of justice and threatened.

Brown has often denied acting as a spokesperson for Anonymous in any officially capacity, as the amorphous group has no such official structure. Nonetheless, his knowledge of many of the group’s activities has often left many with such an impression.

You can see his details on Dallas County Online Jail Search website. According to those who follow Brown, his behavior had become erratic as of late, as evident in the last video he posted to his YouTube account.

Former LulzSec Hacker Pleads Guilty To Sony Attack


After last year's big PlayStation Network hack a lot of hacking groups such as Anonymous and LulzSec were intensely publicized. Back in June, a massive hack was conducted on the Sony Pictures Website. The attack led to the theft of details on over 1 million accounts and was linked to the hacker group Lulzsec.

At the time, the hacker group claimed to have used a “very simple SQL injection” attack. Samples of the compromised data were later posted online. Purported LulzSec member Raynaldo Rivera, 20, was charged in August with impairing a protected computer and conspiracy charges. In admitting his guilt, he joins Cody Kretsinger, who also pleaded guilty for the Sony Pictures hijack. Kretsinger is scheduled to be sentenced on 25th October.

lulzsec hacker arrested"Rivera used the HideMyAss anonymising proxy service in an attempt to disguise his IP address while he carried out reconnaissance work, probing Sony Pictures' website for security vulnerabilities. HideMyAss turned over his IP address after the authorities issued a court order, ultimately exposing Rivera's identity." John Leyden explained in Theregister.

Investigations were made in both the U.S. and Europe. Although not all culprits were caught, two ex-members of hacker group LulzSec admitted they are guilty in this case. Cody Kretsinger got a plea bargain with prosecutors in April this year.

The information that the hacker stole resulted in over $605,000 in financial losses. Part of the plea agreement will see Riviera paying restitution to the victims of the crime and facing prison time. The hacker is facing a maximum of five years in prison, and the fine will be at least $250,000.

Peru Domain Registrar Hacked

A huge hack carried out today ! One of the biggest Peru Domain registrar company (punto.pe) hacked by Lulzsecperu (declared by a tweet) and Complete database of 207116 websites has been leaked on internet. 

Leaked database include Domain panel username, encrypted password, Company descriptions. Hacked domains include all .PU domains ie. Banks , Institutes, computer security companies, corporates, colleges, government, personal websites.

"We clarify that we have no malicious purposes, only prove that the security of PERU is bad and should be corrected. Greetings to the computer crimes division of the National Police of Peru from March 2012 is nil activity and fail or be close to where we are now ASBANC for trying." Hacker said in an statement.

Password for file: lulzsecperu

2-3 Hours after Lulzsecperu hack,  another hacker "@passfile" come up with decrypted password file of all domains credentials.
passfile

Peru Domains Registrar Website is currently under maintenance !

LulzSec Hacker Could Face Life Prison Sentence


Lulzsec Hacker , Jeffrey Hammond faces a potential prison sentence of more than 30 years if found guilty of all charges filed against him. U.S. District Court chief judge Loretta Preska, who presided over a bail hearing for Hammond want last week.

Lulzsec hacker Jeffrey could face Life Imprisonment

Hammond was also charged with using some of the stolen credit card data to help make $700,000 in unauthorized charges, and accused of participating in a hack of the Arizona Department of Public Safety website.

"In early May 2012, a federal grand jury handed down a superseding indictment in the case against alleged LulzSec and Anonymous leaders, accusing Hammond of masterminding the LulzSec and Anonymous attacks against the website of Stratfor (a.k.a. Strategic Forecasting), beginning in December 2011." Informationweeksaid.

"At last week's hearing in a Southern District of New York federal courtroom, Hammond's defense attorney, Elizabeth Fink, suggested that the FBI may have used entrapment to catch her client, reported Courthouse News Service. That led Judge Preska to tell Fink that she should "feel free" to use entrapment as a defense, but that it had no bearing on Hammond's bail hearing. She ruled that with Hammond exhibiting a "lack of regard for legal authority" and facing a prison sentence of between 30 years and life imprisonment, the alleged hacktivist would be a flight risk. Accordingly, Preska denied Hammond's request for bail."

LulzSec Hacker Sabu Sentencing postponed Again

Lulzsec hacker Sabu
Remember Hector Xavier Monsegur a.k.a Lulzsec hacker Sabu ?  That undercover double agent working for the FBI. Once again Authorities abruptly postponed his sentencing due to his continued cooperation with the feds. All told, he faced a maximum time behind bars of 124 years associated with his guilty plea on ten counts of bank fraud and one count of identity theft. When he was a active member of LulzSec, the group hacked into sites belonging to the CIA, Serious Organised Crime Agency, Sony Pictures Europe and News International. "It's widely believed that Monsegur [...]


                                                       Techno-Pirate

Saturday, March 9, 2013

Chrome,Firefoc,Java,IE10 AT Pwn2Own Competiton


Chrome exploit demonstrates at Pwn2Own
Techno-Pirate.blogspot.com
During the first day of Pwn2Own competition at the CanSecWest conference in Vancouver , latest versions of all major browsers were exploited by hackers. 

Chrome, Firefox and Internet Explorer 10 on Windows 8 were successfully pwned by various competitors, bringing them tens of thousands of dollars in prizes. 
French vulnerability research and bug selling firm 'Vupen' brought down IE10 running on a Windows 8 powered Surface Pro tablet by exploiting a pair of flaws.

Researchers Jon Butler and Nils from MWR Labs managed to exploit Google Chrome on Windows 7 and also used a kernel bug to bypass the sandbox.

"By visiting a malicious webpage, it was possible to exploit a vulnerability which allowed us to gain code execution in the context of the sandboxed renderer process. We also used a kernel vulnerability in the underlying operating system in order to gain elevated privileges and to execute arbitrary commands outside of the sandbox with system privileges." they said. For this pwn they received $100,000 as reward.

The Java was also killed in Pwn2Own, Java cracked up to three times by three different hackers. Vupen also managed to exploit a vulnerability in Java, "Writing exploits in general is getting much harder. Java is really easy because there's no sandbox."

According to the participants, Chrome was the hardest target because of its sandbox and Java was the easiest target this year.

Phishers Hacking Facebook Pages By Facebook Apps

Hijacking Facebook pages

Another phishing campaign come in action recently targeting Facebook accounts and company pages with millions of followers. Phishers continue to devise new fake apps for the purpose of harvesting confidential information.



Not a new method, but very creative phishing example in Facebook hacking scene, where hacker host a phishing page on Facebook app sub domain itself. Designed very similar to Facebook Security team with title 'Facebook Page Verification' and using Facebook Security Logo as shown in the screenshot posted above.


Url Of Scam Page=https://apps.facebook.com/verify-pages/

Unofficial Pakistan Intelligence Website Hacked By Indian Hacker

Pakistan Intelligence agency









While the rest of the world engaged in cyber security conferences and Anonymous operations, an Indian patriotic hacker used the time to attack Unofficial Pakistan Intelligence agency ISI.

Hacker going by name "Godzilla" today claimed to hack into one of the server belongs to ISI website (http://isi.org.pk) and claimed steal possible information from website database.


                                                              -=Techno-Pirate-=