Saturday, December 31, 2011

Anonymous targets military-gear site in latest holiday hack.

On Christmas Day the target was security think tank Strategic Forecasting, or Stratfor. This time it was SpecialForces.com, a Web site that sells military gear. 

Specialforces.com
"Continuing the week long celebration of wreaking utter havoc on global financial systems, militaries, and governments, we are announcing our next target: the online piggie supply store SpecialForces.com," the group wrote in a Pastebin posting today. 

The hackers said they breached the SpecialForces.com site months ago, but only just got around to posting the customer data. Even though the site's data was encrypted, they claim to have 14,000 passwords and details for 8,000 credit cards belonging to Special Forces Gear customers. 

Special Forces Gear founder Dave Thomas confirmed that his company's Web servers were compromised by Anonymous in late August, resulting in a security breach that allowed the hackers to obtain customer usernames, passwords, and possibly encrypted credit card information in some cases. "We have no evidence of any further security breaches, and we believe that the recent Stratfor incident is being used to bring this old news back into the spotlight," he noted.


Thomas added that the compromised passwords were from a backup of a previous version of the Web site that is more than a year old. "Most of the credit card numbers are expired, and we don't have evidence of any credit card misuse at this time," he wrote. "The current Web site does not store customer passwords or credit card information."

After the security breach, "we completely rebuilt our Web site and hired third-party consultants to help us shore up Web site security," he said, adding that the vast majority of the sites' sales are custom t-shirts and related gifts, and that the company donates a portion of its profits to charity.


Identity Finder, a New York-based data loss and identity theft prevention service, determined that files posted to date by Anonymous and its AntiSec offshoot related to this breach include 7,277 unique credit card numbers; 68,830 e-mail addresses (of which 40,854 are unique); and 36,368 plain-text usernames and passwords, some of which might be duplicates.
In the statement issued today, the hackers also took another shot at Stratfor for its alleged confusion over whether its data had been encrypted or not.

How Mark Zuckerberg Hacked Into Rival ConnectU In 2004.

ConnectU Founder's
This is the story of how, in the summer of 2004, Mark Zuckerberg hacked into a Facebook rival called ConnectU, whose founders had accused him of stealing their idea to build Facebook.  The details of this story were developed from a broader investigation of the origins of Facebook.  The investigation included interviews with more than a dozen sources over two years, as well as what we believe to be relevant IMs and emails from the period.

During the summer of 2004, Mark Zuckerberg's new social network theFacebook.com was already wildly popular.

After Mark launched it in February, the site dominated the conversation at Harvard all spring.  It reached 250,000 users by the end of August and a million users that fall.

TheFacebook.com was so popular that one thing Mark probably never needed to worry about was competition from the other social network launched at Harvard in 2004, ConnectU, whose founders had accused him of stealing their idea.

ConnectU's founders -- Cameron Winklevoss, Tyler Winklevoss, and Divya Narendra -- had launched the site that spring at 15 schools. But it never gained anywhere close to the critical mass of user adoption that Facebook did. Today, 400 million people visit Facebook each month while ConnectU exists only in the Internet archives.

Nevertheless, during 2004, Mark Zuckerberg still appeared to be obsessed with ConnectU. Specifically, he appears to have hacked into ConnectU's site and made changes to multiple user profiles, including Cameron Winklevoss's.

At one point, Mark appears to have exploited a flaw in ConnectU's account verification process to create a fake Cameron Winklevoss account with a fake Harvard.edu email address.

In this new, fake profile, he listed Cameron's height as 7'4", his hair color as "Ayran Blond," and his eye color as "Sky Blue." He listed Cameron's "language" as "WASP-y."

Next, Mark appears to have logged into the accounts of some ConnectU users and changed their privacy settings to invisible.  The idea here was apparently to make it harder for people to find friends on ConnectU, thus reducing its utility.   Eventually, Mark appears to have gone a step further, deactivating about 20 ConnectU accounts entirely.

Mark appeared to be worried about the risk of his actions, but reasoned that ConnectU's developers wouldn't notice a succession of account deactivations coming from the same IP address. He took comfort that Apache logs didn't reveal that type of activity either. Mark also figured that if ConnectU developers did notice anything, their most natural conclusion would be to think that someone had emailed people convincing them to deactivate their accounts.

It is not clear how Mark accessed these accounts. (In an earlier hack of the email accounts of two Harvard Crimson editors, he used login information stored in Facebook's servers.)  It does appear that he retained access to ConnectU's servers for quite some time.

Hacker who bypassed Facebook security pleads guilty.

A British student has pleaded guilty to charges that he breached security at Facebook earlier his year, despite arguing that his intentions were not malicious.


York computer science student Glenn Steven Mangham, 26, attempted to bypass security on the company's internal systems, raising alarm amongst the FBI that industrial espionage was occurring, according to media reports.

Mangham, who had previously been rewarded by Yahoo for finding vulnerabilities in its systems, discovered that Facebook was far from amused by his activities.

The social networking giant discovered evidence that pointed back to Mangham and he was arrested by the Metropolitan Police Central e-Crime Unit (PCeU) in June.

Specifically, Mangham was accused of using a computer program to secure unauthorized access to Facebook, of attempting to hack into Facebook's Mailman server (used to run internal and external email lists), and attempting to secure access to the Facebook Phabricator server used by internal developers.

Southwark Crown Court was told Mangham produced software scripts that could hack into Facebook's Phabricator server to download "highly sensitive intellectual property".

In addition, the student was said to have breached a webserver used by Facebook to set software development puzzles to programmers who might be interested in working for the company.
Mangham's defence team has argued that he was an "ethical" or "white-hat" hacker, whose intentions - rather than being malicious - were to uncover security vulnerabilities at Facebook with the intention of getting them fixed.


Facebook users will be relieved to hear that the social network told BBC News that the attack "did not involve an attempt to compromise or access user data."

Monday, May 23, 2011

Sony takes sites down after log-in exploit found

The sign-in for PlayStation Network on the Web was out of service this morning.
Just days after most services for PlayStation Network were brought back online, it appears a new exploit has been discovered that allows hackers to change users' passwords with the data stolen during the break-in to the service last month.
The Web sites that allow PSN users to sign in and reset their passwords have since been taken offline, as the graphic above from PlayStation.com shows. This problem reportedly does not affect the ability to sign in via a PlayStation 3 or PlayStation Portable, just some Sony Web sites.
The report comes from gaming blog Nyleveia, which posted a warning to PSN users that their passwords might not be safe and contacted Sony about it.
Another blog, Eurogamer, says it confirmed the exploit, which allows someone to reset your password by knowing your e-mail address used for the account and date of birth. That information is known to be among the data belonging to 100 million users of Sony's gaming services that was exposed between April 17 and 19 in the second-largest security breach in U.S. history.
Eurogamer says users that changed the e-mail address connected to the PSN account after PSN was restored this weekend should not be at risk.
Yesterday, speaking to a handful of reporters, Sony CEO Howard Stringer admitted that while the company had rebuilt the security for PSN during the three weeks it was unavailable, no system could be guaranteed "100 percent secure."
Update 11:12 a.m. PT: Sony spokesman Patrick Seybold wrote today in a blog post that Sony "temporarily took down the PSN and Qriocity password and reset page." There was "no hack," he emphasized, but a "URL exploit that we have subsequently fixed."
At the time of this update, PlayStation.com and Qriocity.com log-in pages were still inaccessible.

Friday, May 20, 2011

Relive the Early Days of the Internet at Telehack



Once upon at time before the age of HTML, the internet looked like a command prompt and a world of text. Telehack is a simulation site that recreates the early internet experience.
How exactly does it recreate the experience? From the Telehack FAQ file:
Telehack is a simulation of a stylized arpanet/usenet, circa 1985-1990. It is a full multi-user simulation, including 25,000 hosts and BBS’s the early net, thousands of files from the era, a collection of adventure and IF games, a working BASIC interpreter with a library of programs to run, simulated historical users, and more.
It’s a well fleshed out project that allows you to use commands, load games, navigate the network, interact with real users (currently logged in) and see significant historical users (simulated for posterity). You can access the project either via web interface or by firing up an actual telnet client and connecting in the old fashioned way. Hit up the link below to access the web portal and type telehack.txt at the prompt to read more about the project.

Sunday, May 15, 2011

Add Copy To / Move To to the Windows Explorer Right Click Menu

A hidden functionality in Windows allows you to right click on a file, select Copy To Folder or Move To Folder, and the move to box will pop up and let you choose a location to either copy or move the file or folder to.

Here’s the quick registry hack to get this working. As usual, back up your registry just in case. You will want to browse down to this key:
HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\ContextMenuHandlers
Once you are at that key, right click and choose the New Key option:

Now you will double-click on the (Default) value and enter the following:
{C2FBB630-2971-11D1-A18C-00C04FD75D13}
Click OK and continue.

If you want to enable Move To, you will repeat the same steps, except creating a new key named Move To, and using this value:
{C2FBB631-2971-11D1-A18C-00C04FD75D13}
Now when you right click on a file or folder, you should see the following options:

Let’s click Copy To Folder just to see what happens….

And that’s it. Useful!

Play Angry Birds in Your Favorite Browser (Web App, Website, and a Game Hack)

Are you ready to indulge in all of that Angry Birds goodness with your favorite browser? Then we have just what you need with information about the web app for Chromium-based browsers, accessing the game via website using your favorite browser, and a quick hack to unlock all of the levels.
First we will start off with the app for Chromium-based browsers. While this is little more than a link to the official website it can be nice to have if you like keeping everything neat and organized in your Apps Tab.

Decided that you want to play Angry Birds in Firefox, Opera, or another browser? Then you can visit the website directly and play the game there! You can choose between the Standardand HD versions as desired…


Want to unlock (or relock) all of the levels when playing Angry Birds in your favorite browser? Then use the following bits of code by pasting them into the Address Bar while the game is open and hit Enter.
Unlock the Levels
javascript: var i = 0; while (i<=69) { localStorage.setItem(‘level_star_’+i,’3′); i++; } window.location.reload();
Lock the Levels
javascript: var i = 0; while (i<=69) { localStorage.setItem(‘level_star_’+i,’-1′); i++; } window.location.reload();



Thursday, May 12, 2011

Don't fall for 'First Exposure: iPhone 5' Facebook scam

Facebook users are being duped into unwittingly spreading spam by clicking on what looks like a link to news entitled "First Exposure: iPhone 5."
A version of the scam, exploiting peoples' interest in the next-generation iPhone, went around Facebook earlier this month, and it's back today with minor changes.
The scam starts when you see someone in your social network comment on a link in a post that looks like it leads to a news story about the iPhone 5 at a Web address of "greatlakesnews.info." Clicking on the link takes you to a different Web page, which provides a captcha window where you're asked to verify a word, ostensibly to prove that you are not an automated bot.
If you see this post on Facebook, don't click on it.
Once you click to verify, a message is posted to your Facebook stream notifying all your friends that you commented on the item and providing them with the bogus iPhone 5 link, in a type of attack known as "clickjacking." Then you're asked to choose from a list of items that then lead to a survey which is really marketing, according to this M86 post.
Clickjacking can be a problem on any Web site, but social networks are particularly susceptible because people share so many links. Facebook's advice to not click on strange links even if they are from friends would cut out many of the legitimate links people share on Facebook.
It's good idea to try to avoid getting news from sources that aren't known news sites. But a big red flag is the captcha window--legitimate sites don't typically make you prove you're human to read a news item.