Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, April 2, 2012

Microsoft India Web Store Hacked in Plain Text Document

Breaking News: Microsoft India’s web store being hacked by a group calling itself Chinese Evil Shadow Team. The hacker team is seems a two-man team, who also managed to upload a page to deface the site and put a new face on Windows products, revealed that user passwords were saved in plain text.

The store is now offline, and site is not run by Microsoft, but Quasar Media, an Indian company responsible for its maintenance and operation. The company has confirmed the attack, and sent out defensive emails to members. That credit card details and payment information databases were not affected, however, other data may have been exposed, such as order details, and shipping addresses, apart from usernames, e-mail addresses, and passwords.

The hackers appear to have uploaded a file called evil. In Html, which says “Unsafe system will be baptized”. Things got bad when Hacker posted screenshots of the user database see below its screen shot:

msft db 01 Microsoft India Web Store Hacked in Plain Text Document

Microsoft will be sending an email with a temporary password and a prompt to create a new password. Users who receive the e-mail are requested to immediately create a new password.



msft db 01 Microsoft India Web Store Hacked in Plain Text Document



Microsoft will be sending an email with a temporary password and a prompt to create a new password. Users who receive the e-mail are requested to immediately create a new password.

Saturday, March 31, 2012

Do Insecure Open Source Components Threaten Your Apps?

Open Source components are a boon to developers, allowing them to efficiently write code without reinventing the wheel. But since open source lacks the notification infrastructure of commercial software, organizations must maintain a running inventory of open source components and their dependencies in production applications or risk deploying apps with known vulnerabilities.
Since Apache Maven, the brainchild of Sonatype founder Jason van Zyl, emerged as a top-level Apache Software Foundation project in 2003, the Central Repository has become a primary source of open source components. Jackson says the Central Repository receives four billion requests per year for its 300,000 components.

But after crunching the data on how the Central Repository's components are used--with the help of application security specialist Aspect Security--Jackson says he believes organizations need to be much more diligent in their practices around open source components because many are exposing themselves to risk by deploying older, vulnerable versions of components.

Global 500 Firms Downloaded 2.8 Million Insecure Components

Aspect Security's study of Sonatype's data found that more than 80 percent of typical software applications are open source components and frameworks consumed in binary form, and that Global 500 organizations, collectively, downloaded more than 2.8 million insecure components in one year. The average enterprise downloads more than 1,000 unique components from the Central Repository each month, and large banks and independent software vendors (ISVs) download even more. And many of the most popular components displayed flaws.

Known open source vulnerabilities.

Source: Aspect Security's Study of Sonatype data.

The study found there were more than 46 million downloads of insecure versions of the 31 most popular open source security libraries and frameworks. For instance, Google Web Toolkit (GWT) was downloaded 17.7 million times with known vulnerabilities. Other popular vulnerable libraries downloaded included Xerces, Spring MVC and Struts 1.x.

In many cases, newer, patched versions of the components or frameworks were available, but users downloaded insecure versions anyway. The study found one in three of the most popular components had older, vulnerable versions that were still commonly downloaded, even when a newer version with a security fix was available.

"The rates of consumption of flawed components were shocking to us," Jackson says. "I think the root reason for that behavior must be a lack of awareness driven by a lack of notification infrastructure."

The Issue Is Notification, Not Open Source

Jackson's issue is not with the open source model itself. "I have been for years and remain a huge advocate for open source," he says. "I think the pace of innovation, the ability to leverage other people's innovation and the transparency and many-eyeballs theory makes open source much more secure over time. What we are trying to point out is not whether open source is better or worse than commercial software or whether open source is fundamentally flawed."

Instead, he says, the issue is that the open source ecosystem lacks the ongoing relationship between vendor and customer that has evolved in the commercial software space. The commercial software world has become used to patch management, update management and even events like Microsoft's Patch Tuesday, when the Redmond-based software behemoth regularly releases security patches for its software. In the open source world, the onus remains largely on the consumers of open source components to track the status of the releases, patches and fixes issued for the components they use.

"The data clearly show that organizations consume huge numbers of vulnerable libraries," says Jeff Williams, CEO of Aspect Security. "While the numbers from this report are alarming, the take-away is clear--open source software is critical to forward-thinking development organizations, but there must be education and control to accompany its usage."

Best Practices for Remediation

The troublesome nature of the situation becomes even clearer when you consider the viral nature of the open source component ecosystem. A single open source component can be reused in dozens or even hundreds of other components, meaning that a flaw in that component will then be inherited by every component that depends on it. For instance, a security vulnerability in Spring-beans 2.5.6 affected 1,447 dependent components and untold thousands of applications. Even when Spring-beans was updated to fix the vulnerability, there was no process in place for updating the ecosystem, meaning hundreds of components remain flawed.

The first step to getting this situation under control is to put together an inventory of open source components used in production applications. And the inventory needs to contain information about component dependencies as well. You need to track component downloads and usage to understand consumption and inventory internal component repositories to determine what is being distributed to development teams. And you need to monitor application bills of materials for updates and newly discovered vulnerabilities. As it stands, 48 percent of organizations don't maintain such an inventory at all, and another 20 percent maintain an inventory but don't keep track of component dependencies.

Once you've taken that step, you need to analyze your component repositories for vulnerable components and your key applications for known security vulnerabilities.

Finally, you must establish controls throughout the development cycle. Jackson suggests establishing policies regarding security, the use of viral licenses and out-of-date or out-of-version components. He also suggests eliminating or blacklisting known vulnerable components in internal repositories and establishing mechanisms to prevent known flawed components from entering the organization.

Thank You : computerworld.co.nz

Internet around the world may shut down Saturday

New Delhi, March 30 (IANS) Come Saturday and there is a strong possibility that you won't be able to indulge in your favourite internet activities like shopping and surfing due to a hacking group - Anonymous - which has threatened to shut down the net.
"Operation Global Blackout 2012 looks to shut down the internet for a whole day tomorrow (Saturday) by disabling its core DNS servers, making websites inaccessible," said Interpol's Secretary General, Ronald K. Noble.
Noble was speaking at the thirteenth D.P. Kohli memorial lecture on "Multijurisdictional Investigation: Operation Unmask" in the capital.
According to Noble, "Anonymous" is protesting against several reasons including the crash of Wall Street and irresponsible leaders.
"Investigations have already been launched by Colombia, Chile and Spain as their private and public websites have been attacked by the group," he added.
Meanwhile, Interpol has launched Operation Unmask to deal with the group and arrested 31 alleged members in two different phases in February and March, 2012.
However, Anonymous vowed vengeance and retaliated through a global wave of cyber-attacks on Interpol Feb 28.
"At its peak, the wave reached 400,000 attacks per minute. My parents' home address and phone number were published on websites," said Noble.
According to Noble, there are around 2.3 billion internet users in the world and more than one million of them are affected by cybercrime every year while $388 billion dollars is the global cost of such crimes.

Thank You : Yahoo

Friday, March 23, 2012

EBay CISO receiving security industry lifetime achievement award

Dave Cullinane, chief information security officer at eBay, will be honored on March 28 in Boston with the SecureWorld Lifetime Achievement Award "for his outstanding contributions to the advancement of the information security community."
Cullinane is being recognized for, among other things, his work on industry standards and associations such as the security information sharing outfit IT-ISAC, by SecureWorld, which is hosting a conference in Boston next week
TURING AWARD: Judea Pearl, big brain behind AI, wins 2011 Turing Award
RECOGNITION: Whirlwind tour of computing and telecom's top honors, awards and prizes
Cullinane is chairman of the board for the Cloud Security Alliance, which has established a Security Trust and Assurance Registry (STAR) to help cloud customers gain better insight into cloud security processes. 
He has also been active with the Security for Business Innovation Council, which last year issued a report on advanced persistent threats and spoke to Network World about APTs being a major concern. 
Bob Brown tracks network research in his Alpha Doggs blog and Facebook page, as well on Twitter and Google +.

Thank You : computerworld.co.nz

Tuesday, March 20, 2012

Developer interest in Android slowly eroding, survey finds

While Google doesn’t have to worry about app developers fleeing Android en masse, they might be concerned that developer interest appears headed in the wrong direction.

A new survey of more than 2,100 app developers released jointly by IDC and mobile development platform vendor Appcelerator Tuesday found that 78.6% of developers were interested in creating apps for Android smartphones during the first quarter of 2012, down from the 83.3% in Q4 of 2011 and down from around 87% in Q1 of 2011.

“Massive platform fragmentation is a big reason that we’re seeing this decline in interest,” says Mike King, a former Gartner analyst who now works as Appcelerator’s principal mobile strategist.  “If you look at all the other numbers such as Android smartphone market share it’s on the upswing, but for app developers it’s a real challenge.”

MORE SURVEYS: Survey finds Android users more likely to be app freeloaders

SLIDESHOW: 10 terrific apps for the new iPad

Even so, Android still easily generates the second-greatest level of interest among mobile developers, as only Apple generated more with 89% of developers saying they wanted to make apps for iOS.  And Android is nowhere near seeing the dramatic free fall in developer interest currently plaguing Research in Motion’s BlackBerry OS, which saw its developer interest plunge to 15.5% in the first quarter of 2012, down from 20.7% in the fourth quarter of 2011 and down from around 37% in the first quarter of 2011.

The key for Android shoring up developer interest will be whether it’s successful in unifying Android smartphones and tablets under the same version of its mobile operating system, thus creating far fewer uncertainties for developers.  Android 4.0 (“Ice Cream Sandwich”) was an important step in this direction as it was the first version of Android to be optimized for both tablets and smartphones.  All the same, King says that app developers aren’t yet embracing Ice Cream Sandwich with open arms.

“They’re somewhat lukewarm to Ice Cream Sandwich, they’re taking a wait-and-see approach,” he says.  “Whereas with Apple, they’re saying, ‘We know iOS and it’s relatively easy for us to build an application and deploy it.”

IDC and Appcelerator also found that Microsoft has been making progress in attracting mobile developers as 37% said they were interested in developing apps for Windows Phone 7 and Windows 8 tablets.

In addition to its findings on developer interest in mobile operating systems, the IDC/Appcelerator survey found that HTML5, the programming langue pushed by Apple as an alternative to Adobe Flash for online video, has been making major inroads with app developers.  IDC and Appcelerator report that 78% of app developers surveyed say they “will integrate HTML5 in their apps” this year.  The firms say that this number is “much higher than industry observers had anticipated” even late last year.  The migration to HTML5 may have been accelerated by Adobe’s announcementlate last year that it planned to start using HTML5 for mobile going forward, relegating Flash to being a desktop video platform.

“HTML 5 is now universally supported on major mobile devices, in some cases exclusively,” Adobe said last year when it made its decision to adopt the standard.  “This makes HTML 5 the best solution for creating and deploying content in the browser across mobile platforms.”

Thank you : /computerworld.co.nz/

Saturday, March 17, 2012

Hack/Close any Facebook account in 24 Hours ! Hacking Tips



WARNING: FOR EDUCATIONAL PURPOSES ONLY. DO NOT SPREAD OR MISUSE THIS GUIDE

Everyone want to become an hacker. but this not possible without having some knowledge of computer. there are lot of guide around web but believe me this guide is freakish awesome icon smile Hack/Close any Facebook account in 24 hours | Hacking Tips please comment here …

Facebook Virus war Hack/Close any Facebook account in 24 hours | Hacking Tips

Just Follow the steps:
Step 1 – Go to this url:
http://www.facebook.com/help/contact.php?show_form=deceased
So this is the Url we will use to Report our slave. This Form allows you to report a deceased person (someone who is dead).
Step 2 – Complete the Fields:
Explain:
Full Name: Your Victims Full name(Name last name)
Date of birth: Go at his profile and click at Info tab and get his date of birth.
Account Email Addresses: Do the same thing, go to his profile and click on info tab and get his email addresses.
Networks: Again,go to his profile and click on Info tab and get his networks, copy them and paste in the form.
Web address of profile you would like to report: Just go to his profile and copy the link in the address bar.
Relationship to this person: To make more believable select Immediate Family.
Requested Action: Remove Profile
Proof Of Death: This is the hardest part of this form. Now to make a proof of a death just Google in your language a “Death Certificate” or “Certificate of a Death”. It doesn’t matters from what country you are, just use this Italian certificate and open up photoshop or whatever Image
Editor and just write in a blank field:
Annunciamo il morte di [name goes here]. Save your image to desktop and upload it in one of the Image
Free Hosting like: http://imageshack.us/
And it’s done blank Hack/Close any Facebook account in 24 hours | Hacking Tips… Italian Death Certificate:
Additional Information: Write what you want, just write that you are in his/her family and you would like to close his/her Facebook account because you won’t like that when he is dead, his Facebook is opened.
Step 3 – Click on Submit and then a message will appear:
Your injury was submitted at Facebook Team .. So the meaning is that one of the mod’s of Facebook will review your report and will do the right decision. It works in most of the times. I closed a few ones.

WARNING: FOR EDUCATIONAL PURPOSES ONLY. DO NOT SPREAD OR MISUSE THIS GUIDE
 
Thank you Ankit Ningtech