Four Hong Kong Pro-Democracy websites compromised

The protests which started in September 2014 lost steam midway only to gather momentum again since 10th October. These attempts at exploitation, compromise, and digital surveillance are detailed throughout this post. ATD is an alliance of people and organizations dedicated to democracy and universal suffrage in Hong Kong. Volexity refers to this shell as the Angel Webshell, named after its default password of angel. The shell will simply display the text Password:, a text input box, and a Login button....

October 13, 2014 · 1 min · 150 words · Debra Park

Reflected File Download (RFD) attack method with malware

This attack technique has been discovered by Oren Hafif, a Trustwave SpiderLabs security researcher. Worse news is that he has also developed a worm to take advantage of RFD technique. Current security measures like firewalls and anti-viruses are futile against this worm. The sad news is that Anti-virus engines wont even detect the hack. And once the file has been executed, there is no security mechanism as of yet to stop it....

October 13, 2014 · 1 min · 124 words · David Garcia

Booking.com vulnerable to CSRF Attack leading to account hijack and stealing of customer details

A potential hacker can also view the email ids or credit cards/debit card information of all booking.com customers. The CSRF attack can also be mounted through by adding review /comment on Booking.Com website. Booking.com offers online accommodation booking. It has over 540,000 properties globally under contract and deals with more than 650,000 room nights reservations per day. Booking.com is available in more than 41 languages. Priceline, the holding company has reported 2013 fourth quarter revenue of $1....

October 12, 2014 · 1 min · 129 words · Jessica Gonzalez

Part 5 of iCloud hacks celebs leaks, Matt Smith with Daisy Lowe, KeKe Palmer, Kelly Brook and many others feature in new leaks

The iCloud Hacks leakers were back with new leaks for this weekend. Broadway Cinderella star KeKe Palmer is another celebrity targeted in the iCloud Hacks photo scandal. The leaks contain half-dozen photos of the 21-year-old surfaced online Friday morning, however only 3 images are NSFW. It is a sex crime. It is a sexual violation. Its disgusting.The law needs to be changed, and we need to change. Thats why these websites are responsible....

October 12, 2014 · 1 min · 165 words · Robert Huang

Twitter, the new battleground for Jehadis, ISIS threatens Twitter employees, TTP threatens Malala

? ? ?????? ? ? ????? ? ? ??? He referenced the term kuffars in his tweet, a provocative Islamic slur meaning non-believers and infidels. Malala speaks so much against guns and armed conflicts. source: www.techworm.net

October 12, 2014 · 1 min · 36 words · Danielle Klein

Kmart Hacked, Customer Credit/Debit Card Numbers Compromised

Also Read:Dairy Queen admits that nearly 400 of its restaurants around the U.S was hacked Read More source: www.techworm.net

October 11, 2014 · 1 min · 19 words · William Simpson

SnapChat Hacks, the aftermath of the leak

Table Of Contents Theleakwhich took the world yesterday by storm is bound to leave maximum impact. SnapChat, the self destructive messaging service provided on its part struct the blame squarely on third party clients. In two tweets released yesterday, it expressly said that the fault was with the third party client Apps. We can confirm that Snapchats servers were never breached and were not the source of these leaks. Whatever ToU was signed by SnapChat with its 3rd party clients should have included this facts....

October 11, 2014 · 2 min · 373 words · Amanda Harris

After iCloud Hacks now come the SnapChat Hacks, 13GB of SnapChat images leaked

The users of 4Chan have named this hack as The Snappening, while we will call it SnapChat Hacks. The database is said to contain 200,000 images of SnapChat users. SnapChat is a online messaging and image sending service with a unique quality of self destroying messages. Image taken during a review of SnapSave on www.comboupdates.com The leak finally arrived yesterday. SnapSave Preliminary reports indicate that not one but two SnapChat clients servers were hacked....

October 10, 2014 · 2 min · 243 words · Dawn Quinn

Dairy Queen suffers Data breach, Releases list of affected Restaurants

Dairy Queen is providing free identity repair services of upto one years to its affected Customers. List of effected Dairy Queen Stores can be seen fromhere Read More source: www.techworm.net

October 10, 2014 · 1 min · 30 words · Mr. Robert Rodriguez

Authentication Flaw in PayPal mobile API lets users access blocked accounts

What is the flaw? What is wrong with that? PayPal often blocks users for variety of reasons like preventing a fraudster from reaching illicitly obtained funds. The most famous user blocked by PayPal. The vulnerability was discovered byBenjamin Kunz Mejri from Vulnerability Laboratoryin 2013. In the report of the glitch, Mejri says that version 4.6.0 of the PayPal iOS App is affected. After several attempts, the service requests the answer to a security question to validate the user....

October 9, 2014 · 1 min · 97 words · Amanda Stout

Is iOS encryption going to really keep NSA snooping at bay?

Table Of Contents Is iOS encryption going to really keep NSA snooping at bay? A few days back, the all mighty iPhone 6 was revealed to the world. In between all the razzle dazzle launch, one feature of Iphone 6 caught my attention. The question that came into my mind is, is Apple wasting its time? Encrypted data on your phone cannot solve either of the two problems faced by a typical user....

October 9, 2014 · 2 min · 230 words · Jeffrey White

Take privacy seriously? destroy your data via SMS text on SecureDrives Autothysis SSD

Once the Autothysis receives a SMS text message, it wipe data via what SecureDrives calls crypto sanitization. SecureDrives claims that these are the first SSDs available that offer such remote physical fragmentation. Any attempt to crack fire up the drive will also set off the self-destruct mechanism. While security is at a premium with these SSDs, performance is not. The privacy wont come cheap. The Autothysis128s will sell for 967....

October 9, 2014 · 1 min · 96 words · Kelly Smith

Tyupkin Malware Infects ATMs Worldwide, lets cyber criminals take ‘wads of cash’

Aresearch published by Kaspersky Labsaid that they have discovered a new malware named Tyupkin solely developed for this purpose. Fraudsters do not require a credit or debit card to carry out the scam. All this allows the gang to control the cash being withdrawn by their henchmen across the world. The malware only accepts commands to dispense cash at specific times on Sunday and Monday nights. source: www.techworm.net

October 9, 2014 · 1 min · 68 words · Erica Moore