Showing posts with label Hacking stories. Show all posts
Showing posts with label Hacking stories. Show all posts

Saturday, August 24, 2013

Windows 8 vulnerable to hacking: Germany


A German government technology agency has warned that new security technology in computers running Microsoft'sWindows 8 operating system may actually make PCs more vulnerable to cyberthreats, including sabotage. 

Germany's Federal Office for Information Security, or BSI, said in a statement posted on its website on Wednesday that federal government agencies and critical infrastructure operators should pay particular attention to the risk. 

The warning comes after weeks of public indignation in Germany over leaks related to US surveillance programmes. The spying scandal has become a headache for Chancellor Angela Merkel ahead of a September 22 election. 

The problem, according to the BSI, is with the use of a computer chip known as the Trusted Platform Module, or TPM 2.0, which is built into Windows 8 computers. TPM 2.0 is designed to better protect PCs by interacting with a variety of security applications. 

But the BSI, which provides advice on technology and security to the government as well as the public, said the joint implementation of Windows 8 and TPM 2.0 chips could lead to "a loss of control" over both the operating system and hardware, without specifying exactly how that could occur. 

"As a result, new risks occur for users, especially for federal and critical infrastructure," it said. 

The statement concluded: "The new mechanisms in use can also be used for sabotage by third parties. These risks need to be addressed." 

Microsoft declined comment on the BSI statement. 

The company provided Reuters with a statement saying that PC makers have the option to turn off TPM technology, so that customers can buy PCs with it disabled. 

TPM was developed by the Trusted Computing Group, a non-profit organization backed by technology firms including IBM, Intel, Hewlett-Packard and Microsoft. 

The BSI said it was working with the Trusted Computing Group and operating systems producers to find a solution. 

A spokeswoman for that group declined to comment on the specific claims raised by the BSI. She said the group has provided PC makers and users with plenty of advice on best security practices to avoid any threats that they may face.

Friday, August 23, 2013

Hacker who exposed Facebook bug to get reward

A man who hacked into Mark Zuckerberg's Facebook page to expose a software bug is getting donations from hackers around the world after the company declined to pay him under a program that normally rewards people who report flaws.

Khalil Shreateh discovered and reported the flaw but was initially dismissed by the company's security team. He then posted a message on the billionaire's wall to prove the bug's existence.

Now, Marc Maiffret, chief technology officer of cybersecurity firm BeyondTrust, is trying to mobilize fellow hackers to raise a $10,000 reward for Shreateh after Facebook refused to compensate him.

Maiffret, a high school dropout and self-taught hacker, said on Tuesday he has raised about $9,000 so far, including the $2,000 he initially contributed.

He and other hackers say Facebook unfairly denied Shreateh, a Palestinian, a payment under its "Bug Bounty" program. It doles out at least $500 to individuals who bring software bugs to the company's attention.

"He is sitting there in Palestine doing this research on a five-year-old laptop that looks like it is half broken," Maiffret said. "It's something that might help him out in a big way."

Shreateh uncovered the flaw on the company's website that allows members to post messages on the wall of any other user, including Zuckerberg's. He tried to submit the bug for review but the website's security team did not accept his report.

He then posted a message to Zuckerberg himself on the chief executive officer's private account, saying he was having trouble getting his team's attention.

"Sorry for breaking your privacy," Shreateh said in the post.

The bug was quickly fixed and Facebook issued an apology on Monday for having been "too hasty and dismissive" with Shreateh's report. But it has not paid him a bounty.

"We will not change our practice of refusing to pay rewards to researchers who have tested vulnerabilities against real users," chief security officer Joe Sullivan said in a blogpost.

He said Facebook has paid out more than $1 million under that program to researchers who followed its rules.

Wednesday, August 21, 2013

No reward for hacking Zuckerberg‘s Facebook page

A researcher who hacked into Facebook chief Mark Zuckerberg's profile to expose a security flaw won't get the customary reward payment from the social network.

While Facebook offers rewards for those who find security holes, it seems that Palestinian researcher Khalil Shreateh went too far by posting the information on Zuckerberg's own profile page.

Shreateh said on his blog he found a way for Facebook users to circumvent security and modify a user's timeline.

He said he took the unusual step of hacking into Zuckerberg's profile after being ignored by the Facebook security team.

"So i did post to Mark Zuckerberg's timeline, as those pictures shows," he said, including screen shots of the posting.

"Dear Mark Zuckerberg," he wrote."First sorry for breaking your privacy and post to your wall, i had no other choice to make after all the reports i sent to Facebook team. My name is KHALIL from Palestine."

His reward for exposing the flaw was having his Facebook account disabled.

He later got a message saying, "We are unfortunately not able to pay you for this vulnerability because your actions violated our Terms of Service. We do hope, however, that you continue to work with us to find vulnerabilities in the site."

Facebook said it appreciates help with security but not by hacking into user accounts.

Facebook security engineer Matt Jones posted a comment Sunday on a security forum saying "we fixed this bug on Thursday," and admitted that "we should have asked for additional... instructions after his initial report."

"We get hundreds of reports every day," Jones said. "We have paid out over $1 million to hundreds of reporters. However, many of the reports we get are nonsense or misguided."

Jones added that "the more important issue here is with how the bug was demonstrated using the accounts of real people without their permission."

"We welcome and will pay out for future reports from him (and anyone else!) if they're found and demonstrated within these guidelines," Jones said on the YCombinator hacker news forum.

Independent security researcher Graham Cluley said he had "some sympathy" with Facebook on the issue.

"Although he was frustrated by the response from Facebook's security team, Shreateh did the wrong thing by using the flaw to post a message on Mark Zuckerberg's wall," Cluley said on his blog.

Wednesday, July 24, 2013

Apple developer site remains shut 4 days after hacking

A website that Apple uses to communicate with its community of some 6 million software developers remained shuttered on Monday, four days after a cyberattack that prompted a harried upgrade to prevent future breaches. 

It was not immediately clear what data, if any, was been compromised by the attack. 

Apple said in a notice released late on Sunday that names, mailing addresses and emails may have been accessed by unknown attackers. It added that "sensitive personal information" was encrypted and could not be accessed. 

Security experts said Apple's brief statement made it difficult to assess the severity of the breach. 

"I am not exactly sure what happened. I do not know what to make of this," said Charlie Miller, author of the iOS Hacker's Handbook. 

Miller said he received an email from Apple on Monday warning him about the breach, adding that he hoped none of his personal information had been compromised in an attack. 

Still, he said he had not seen any indications that suggest other attacks on Apple could soon follow. 

"I don't think this indicates any system problems in their security," he said. 

Data breaches are relatively common because hackers are constantly identifying new ways to attack by exploiting software bugs and leveraging mistakes in the way companies configure websites and computer systems. Hackers are also relentless in sending emails with malicious links and attachments to targeted companies. 

Security experts speculated that the site may have been attacked using one of several widely known security bugs in web technology, but there seemed to be no consensus. 

A man claiming to be a Turkish security researcher posted a video on YouTube and sent out comments on Twitter saying that he was responsible for the attack on Apple's developer site and had done so in a bid to publicize a security bug. 

Apple declined comment on his claim, which could not be independently verified. The man could not be reached for comment. 

Other corporate victims of recent security breaches include: Evernote, LinkedIn Corp, LivingSocial and Sony. 

Apple said in its statement to developers that it was completely overhauling the technology on the shutdown site, which it hoped would soon be back online. 

It may be in hot demand as developers are writing and testing apps to run on iOS 7, the next-generation operating system for iPhones and iPads that Apple is planning to release in the fall. 

It was the second security breach that the company has disclosed in five months. In February, the maker of Macs and iPhones said that some Mac computers had been infected by hackers who had also attacked Facebook and other technology companies.