Showing posts with label News. Show all posts
Showing posts with label News. Show all posts

Sunday, 5 August 2012

Alleged Anonymous hacker arrested for Facebook threat

| |
0 comments

Hong Kong police said Sunday they had arrested a 21-year-old man believed to be a member of the international hacker group Anonymous, after he reportedly said on social networking site Facebook that he would hack several government websites.

“The Internet is not a virtual world of lawlessness,” a police spokesman said, adding that the man was required to report back to the police in October.

He faces up to five years imprisonment if found guilty.The man is a member of the global hacker group Anonymous, the South China Morning Post said. The group is said to have 20 members in the semi-autonomous Chinese territory, which guarantees civil liberties not seen on the mainland, including freedom of speech.

The police spokesman declined to confirm his link to Anonymous. The last posting on the “Anonymous HK” Facebook page on July 22 urged authorities to show “respect” to citizens.
Read More

Friday, 20 July 2012

Kevin Mitnick joins the Zimperium team

| |
0 comments

Security firm Zimperium developer of Android app zANTI (Android application Toolkit) now have World Best Hacker "Kevin Mitnick" in their Team.

In a Press Release ,Itzhak “Zuk” Avraham said "Zimperium is honored and excited to announce our newest member of the advisory board, world renowned hacker Kevin Mitnick.We are thrilled to have Kevin on board and feel that his leadership and consultancy will help Zimperium to get to the next level,through corporate efficiency, brand recognition and better quality solutions for our clients!"

Zimperium Ltd. is a privately owned start-up located in Tel Aviv, Israel; whichdesigns and develops cutting edge Intellectual Property in the field ofinformation security and mobile technology. The company was founded in 2010.

"Mobile devices are the new target-rich environment. Based on lessons learned in the early days of the personal computer,businesses should adopt a proactive approach to mobile security so they don't repeat the same mistakes that resulted in billions of dollars in economic loss.” Mitnick said.

Mitnick joined Zimperium team to support the effort of providing advanced security protections for enterprises facing modern mobile threats,those threats were mismanaged and exposed enterprises to cyber-espionage, Mitnick also added: "It's an honor and privilege to join Zimperium to help innovate solutions in the mobile security space. It will be a new exciting and challenging pursuit ahead."

Zimperium will introduce its smartphone security solution, zCore IPS, for enterprises and mobile carriers at the Blackhat event next week.Between Blackhat & DEFCON conferences, Zimperium will host a private event named "Compile n' Crash Bash" featuring Kevin Mitnick, Zuk and the rest of Zimperium's team together with the latest Pentester's Worldcup Winner.
Read More

Sunday, 15 July 2012

App Store bypassed by Russian hacker without jailbreaking

| |
0 comments

Apple is investigating yet another security breach in its iTunes app store . A Russian hacker worked out a way that allows people to bypass payment in the App Store and download products for free.

The hacker, dubbed ZonD80, posted a video of the crack on YouTube (Deleted by Youtube now) and claims that the technique makes it possible to beat Apple's payment systems by installing a couple of certificates and assigning a specific IP address to the device.

The new service, which has already been subject to attempts at shutting it down, requires no jailbreaking and only minimal configuration changes. It works by funneling purchase requests through a server operated by the hacker, rather than the legitimate one offered by Apple. As a result, charges that normally would be applied to a user's account are bypassed.

Below are the steps to the hack:

1.  Install two certificates: CA and in-appstore.com.
 

2.  Connect via Wi-Fi network and change the DNS to 62.76.189.117.
 

3. Press the Like button and enter your Apple ID & password.

4. Using the above hack, you are actually stealing in-app purchase content from developers, which is kind of disturbing and is of course against developer’s terms of service.

ZonD80 is now asking for donations to set up a website to promote the hack."Why you must to pay for content, already included in purchased app? I think, you must not," he said.


Apple has responded with the following statement:“The security of the App Store is incredibly important to us and the developer community,” Apple representative Natalie Harrison. “We take reports of fraudulent activity very seriously and we are investigating.”
Read More

NVIDIA Developer Forums Hacked, 400000 user accounts at Risk

| |
0 comments

Nvidia shut down its Developer Zone online forum today after hackers gained access to members' account details.A statement Nvidia posted on the forum reads, "Nvidia suspended operations today of the Nvidia Developer Zone. We did this in response to attacks on the site by unauthorised third parties who may have gained access to hashed passwords."

Users are also warned not to provide any personal, financial or sensitive information in response to any email purporting to be sent by an NVIDIA employee or representative. All user passwords will be reset when the system comes back online, though it wasn’t mentioned when that was going to be. NVIDIA insists it is “continuing to investigate this matter.

Nvidia forum hack follows the recent LinkedIn and Yahoo! hacks. Earlier 6.5 million LinkedIn hashed passwords were stolen and subsequently published on unauthorized websites.
Read More

Hacker wanted by FBI held in India For Carding Crimes

| |
0 comments
Nikhil Kolbekar, aka HellsAngel, was arrested on July 11 in Mumbai, India. Eric Bogle, known as Swat Runs Train, and Justin Mills, or xTGxKAKAROT, were taken into custody in Canada, respectively Colorado, US. HellsAngel and Bogle is suspected of selling complete credit card details, including names, addresses, social security numbers, birth dates, and bank account information. He also sold remote desktop protocol (RDP) access data that could be utilized to breach computers in countries such as Turkey, India, Czech Republic, Brazil, Germany, France, Italy, Spain, Sweden, and others.

The suspect, Nikhil Kolbekar, was produced before the Esplanade Court on Thursday and has been remanded in judicial custody. He will be produced before the Patiala House court in Delhi on July 25, with the US pressing for his extradition through the Interpol.

Carding refers to various criminal activities associated with stealing personal identification information and financial information belonging to other individuals including the account information associated with credit cards, bank cards, debit cards, or other access devices and using that information to obtain money, goods, or services without the victims’ authorization or consent.

Janice K. Fedarcyk, the assistant director in charge of the New York FBI, said the cross-border law-enforcement operation is targeting "highly organized cyber criminals" and is designed to "root out criminal behavior on the Internet."

FBI Assistant Director in- Charge Janice K Fedarcyk said, “These arrests in India, Canada, and the United States as part of Operation Card Shop are just another example that cyber criminals will be stopped even if they cross borders. Operation Card Shop is an international operation aimed at sophisticated, highly organized cyber criminals involved in buying and selling stolen identities, exploited credit cards, counterfeit documents, and sophisticated hacking tools. The FBI and all our law enforcement partners, here and abroad, will continue to root out criminal behavior on the Internet.”

The police have seized a computer, hard-disk, CPU, CDs and pen-drives from Kolbekar, which will be used as evidence against him.
Read More

Saturday, 14 July 2012

Android Forums hacked, User Credentials Stolen

| |
0 comments

Phandroid's Android Forums Web site is hacked and user account details stolen, according to a notice posted online. The data includes the user names, e-mail addresses, hashed passwords, and registration IP addresses of the forums' more than 1 million users.

If you are one of them, you should change your password: go to your UserCP or use the Forgot your password?. Furthermore, if you use the same e-mail address and password combination elsewhere, you should change it there as well.

"I have some unfortunate news to pass along," the post reads. "Yesterday I was informed by our sever/developer team that the server hosting Androidforums.com was compromised and the website's database was accessed. While the breach is most likely harmless, there are important and potential pitfalls, and we want to provide as much helpful information to our users as possible (without getting too technical)."

Phandroid will continue to investigate what happened. The exploit used has been identified and resolved. All code that resides in the database and the file system has been thoroughly reviewed for malicious edits and uploads.

Recently, the social Q&A Web site Formspring said that it was the victim of a hack that yielded hashed passwords for around 420,000 of its users. Yahoo warned users of its Yahoo Voice service of a breach in which 400,000 plaintext passwords were stolen from the company and posted online.


Read More

Saturday, 7 July 2012

Bulgarian Hackers Group Arrested

| |
0 comments

Bulgarian authorities say that after months of investigation they have busted the “most powerful hacker group” in the country, the Cyber Warrior Invasion. The operation was conducted by Bulgaria’s Sector for Computer Crimes, Intellectual Property and Gambling and the territorial units of the Chief Directorate for Fight with Organized Crime in the municipalities of Pleven, Shumen, Plovdiv, Burgas, Haskovo, Stara Zagora and Kyustendil.

Using cyber “terrorist” methods, the group had attacked more than 500 websites worldwide, including those of financial institutions, web-based companies, and governmental and non-governmental organizations. On the confiscated computers, police discovered databases with large amounts of stolen emails, social network profiles and associated passwords, as well as stolen credit card data.


The site www.cwi-group.org was used by the members of the group to coordinate their activities. Constantly changing its location and using a complex system of "zombie" proxy servers they disguised its true location, and that of the administrators. Despite the attempts to wipe out their tracks, hackers were detected.The investigation unveiled that hacker group members followed a strict hierarchical order, evidencing the high degree of organization and coordination between them. They were structured into different groups according to their access and power: "Administrators", "Moderator", "Scanning team," "Donors / Sponsors", "Sectional moderators", "Friends," "VIP Members" and group "members."

Four laptops, five desktop computers, seven portable digital information devices, three hard discs and over 200 CDs were seized.

Read More

Thursday, 5 July 2012

Android Clickjacking Rootkit Demonstrated

| |
0 comments

Mobile security researchers have identified an aspect of Android 4.0.4 (Ice Cream Sandwich) and earlier models that clickjacking rootkits could exploit. Researchers at NC State in the US have developed a proof-of-concept prototype rootkit that attacks the Android framework and could be used to steal personal information.

What is clickjacking? It is a malicious technique that tricks users and is often used to take over computers, web cams, or snag confidential info that is revealed by users who thinks they are on an innocent webpage.



Like most Android malware, the rootkit can be distributed as a malicious app, opening up a host of potential vulnerabilities on any device on which it is installed. However, it functions in a different way.

The rootkit, which could be bundled with an app and is said to be undetectable by anti-virus packages, would allow an attacker to replace a smartphone's browser with a version that logs key strokes to capture bank card data and uploads them to a hacker-controlled website.

Jiang explained in a video in which he demonstrates the rootkit in action:
In a demonstration video, the rootkit is shown manipulating the apps on a smartphone. Such a program could be used by cybercriminals to replace an app with a malicious data stealing version that appears legitimate to the user.
“This would be a more sophisticated type of attack than we’ve seen before,” says Jiang, “But there is good news. Now that we’ve identified the problem, we can begin working on ways to protect against attacks like these.”
Read More

Sunday, 24 June 2012

Anonymous Hackers shut down website of Colombia Justice Ministry

| |
0 comments


Anonymous hackers shut down the websites of Colombia's Justice Ministry website on Friday evening. The website was back online Saturday morning.


Also, The website of Cambio Radical, the political party of Interior Minister German Vargas Lleras, was hacked later Friday evening and was still showing a message saying "You have been hacked".

Anonymous said on its facebook page the Ministry's website was shut down to protest "impunity" granted to corrupt politicians by a justice reform that had been approved by Congress but was sent back to the legislative branch by President Juan Manuel Santos on Thursday because of its unconstitutionality and inconsistencies that “do not favor justice and transparency.”
Read More

Saturday, 23 June 2012

Department of Homeland Security and U.S Navy hacked

| |
0 comments


Department of Homeland Security and U.S Navy websites once again at Major Risk. This time hacking group called "Digital-corruption" hacked into subdomains of both sites and leak database info on pastebin.

In its announcement on the pastebin.com website, the group said it has leaked database  from https://www.smartwebmove.navsup.navy.mil/ and twicinformation.tsa.dhs.gov using Blind SQL-Injection method.

The Database include Usernames, Passwords, Email ID's, Security Questions - Answers of all users.

Hackers shout:
say("#FreeTriCk #FreeMLT #FreePhantom");
say("Knowledge is power!");
say("NAVY.MIL, care to share some of your staff information?");

Department of Homeland Security and U.S Navy websites are hacked lots of times in past one year by Different hackers from all over world.
Read More

Russian Botnet Hacker arrested for hacking into six million computers

| |
0 comments

Police have detained a 22-year-old hacker who created a system of networked computers that was used to steal more than 150 million rubles ($4.47 million) from people's bank accounts and already one of the most wanted hacker in the world. But now, "Hermes" is, has been tapped over six million computers and earns around 5 million francs, was caught in Russia.



The network infected around six million computers with a Trojan virus, which helped get access to users' bank accounts. About the Trojans secretly installed, he had arranged illegal money transfers, said the interior ministry in Moscow on Friday.


Police from Division K, the cybercrime branch of the Interior Ministry, searched the hacker's place of residence, confiscating computers and arresting the suspect. The statement did not specify when the arrest was made.The botnet built by the hacker included around 6 million computers from regions that included Krasnodar, Samara, and Ivanovo, as well as from the cities of Moscow and St. Petersburg, where the majority of the infected computers were located.


The hacker faces a lengthy jail term if convicted on fraud charges.
Read More

20-year-old Anonymous Hacker arrested by Bulgarian Police

| |
0 comments


Bulgarian police authorities have arrested an alleged member of the loosely associated Anonymous hacktivist group. The 20-year-old suspect has allegedly attacked the website of Prophon, a Bulgarian music licensing company.

The reason - Mitko was against paying for music and movies, like to draw at will from the network. The attack he made on February 5, 2012 as able to penetrate into account the site administrator. Following the intervention of Mitko, entering the address www.prophon.org is appeared a message that "Anonymous" seize the site.

"PROPHON Hello, We are Anonymous. We learned that you are greedy and another 12 organizations have signed an open letter in support of the so-called. Agreement ACTA. This is unacceptable and this angered us. You are first, not last. This should be a lesson to all who support ACTA. We are Anonymous. We are legion. We do not forgive. We will not forget. Expect us, "the message of hackers.


Police have seized four PCs, eleven servers, three laptops, a large amount of hard discs, flach memory cards, CDs and DVDs, according to the Bulgarian Interior Ministry.The suspected hacker is said to have admitted his guilt.

Mitko has completed secondary education right in the field of high technologies in the future dreams is your hosting company and continue their education. Ministry of Interior does hope Mitko to harness their skills for good and constructive things. For this offense the law provides for up to 1 year in prison, but because the young man has a criminal record and admitted his guilt, probably Themis will judge "probation" for his offense.

Read More

Windows 8 will be challenge for Malware writers

| |
0 comments

Microsoft™s security researcher believe that upcoming operating system, Windows 8 is a step forward in security and Windows 8 will be far better at protecting against malware than it’s predecessors.

Chris Valasek, a senior security research scientist at development testing firm Coverity, began examining the security features of Windows 8 last autumn, before the consumer previews of the upcoming revamp of the new Microsoft OS came out.

"There are always going to be vulnerabilities but you can make it difficult to leverage vulnerabilities to write exploits." One major change between Windows 7 and 8 is the addition of more exploit-mitigation technologies, however. Windows Memory Managers (specifically the Windows Heap Manager and Windows Kernel Pool Allocator) are designed to make it far harder for attackers to exploit buffer-overflow vulnerabilities and the like to push malware onto vulnerable systems.


The "security sandbox" for applications for Windows 8 will also be a great step forward. "These new Windows 8 Apps will be contained by a much more restrictive security sandbox, which is a mechanism to prevent programs from performing certain actions," Valasek explains


"This new App Container provides the operating system with a way to make more fine-grained decisions on what actions certain applications can perform, instead of relying on the more broad ‘Integrity Levels’ that debuted in Windows Vista/7.

Windows 8 also comes with a new version of Internet Explorer, Microsoft's browser software. Internet Explorer 10 will come with a mode that disables support for third-party plug-ins such as Flash and Java.

Read More

Wednesday, 20 June 2012

Indian ISPs get court relief, Torrent Sites Unblocked

| |
0 comments


After weeks of confusion and frustration with blocked websites, the mess finally looks to be clearing. Indians are all heaving a sigh of relief because their ISPs have unblocked the access to the file-sharing, video-streaming BitTorrent sites that include The Pirate Bay, Torrentz.eu, Vimeo among others.


It was in news last month that following Reliance, Airtel had also blocked torrent services and video sites after they received the ‘John Doe’ court order. Thousands of users from various states of India found the access to torrents blocked.

India's Medianama is reporting today that the Madras High Court recently limited a badly drafted April ruling on the subject. The court said in its updated ruling, according to Medianama, which obtained a copy of it, that "the interim injunction is granted only in respect of a particular URL where the infringing movie is kept and not in respect of the entire website. Further, the applicant is directed to inform about the particulars of URL where the interim movie is kept within 48 hours."

MediaNama reports that the Madras High Court, on an appeal filed by a conglomerate of Internet Service Providers (ISPs), has passed an order saying that entire websites cannot be blocked on the basis of "John Doe" orders.

Starting with the movie Singham, for which Reliance Entertainment had taken a John Doe order last year, movie studios have been consistently getting John Doe orders blocking access to file sharing, video sharing and torrenting websites.
Read More

Hacker charged for hacking into U.S. Energy Department

| |
0 comments

Andrew James Miller, a 23-year-old resident of Devon, Pennsylvania, was arrested on Thursday and charged with one count of conspiracy, two counts of computer fraud, and one count of access device fraud, according to a statement issued by the Justice Department's Criminal Division.


According to the indictment, between 2008 and 2011, Miller and others allegedly remotely hacked into computer networks belonging to RNK Telecommunications Inc., a Massachusetts company; Crispin Porter and Bogusky Inc., a Colorado advertising agency; the University of Massachusetts; the U.S. Department of Energy; and other institutions and companies.

The indictment alleges that when Miller hacked into the computers, he obtained other users’ access credentials to the compromised computers. He and his co-conspirators then allegedly sold access to these computer networks as well as other access credentials.

After gaining unauthorized access to these systems, Miller is alleged to have installed Trojan horse programs that gave him access to the networks which he and his co-conspitrators sold online.Miller and his co-conspirators were discovered after they attempted to sell access to the victim networks to an undercover FBI agent.

The indictment details an IRC conversation between Miller and an undercover agent in which Miller exchanges access to RNK’s servers and a list of hundreds of user names and passwords for two payments of $500.00. Payment was to be made to Andrew Miller of Lancaster, PA, via Western Union.

Miller later requested two payments of $600 via Western Union in exchange for a U-Mass database dump and $1,000.00 for access to CPB Group. At one point, Miller attempted to sell the FBI access to a supercomputer belonging to the DoE’s National Energy Research Scientific Computing Center for $50,000.

Miller faces up to five years in prison for the conspiracy count and one of the computer fraud counts, and up to 10 years in prison on one of the computer fraud counts and the access device fraud count, to be followed by three years of supervised release, a $250,000 fine and restitution, if convicted.
Read More

Friday, 15 June 2012

LulzSec hacker - Brit Ryan Cleary charged for Sony and Fox hacks

| |
0 comments


A 20-year-old Briton suspected of links to the hacking group Lulz Security is accused of cracking into websites for a Fox reality TV show, a venerable news show and other sites to deface them or steal personal information, federal prosecutors said Wednesday.

Ryan Cleary, 20, reportedly had ties to the well-known branch of Anonymous called LulzSec before he was arrested in London last June (although the hacktivist group denies his involvement with it). U.S. federal prosecutors said today that he worked to take down, deface, and steal personal information from Web sites.

In a separate and similar case filed against Cleary in the United Kingdom in 2011, he faces allegations that he and others hacked a law enforcement agency, the Serious Organized Crime Agency, and various British music sites - all while he was still a teenager.

Commenting on Tuesday’s indictment, FBI spokesperson Laura Eimiller said, “Cleary is a skilled hacker. He controlled his own botnet, employed sophisticated methods and his broad geographic scope affected a large number of businesses and individuals.”Those businesses included Sony Pictures Entertainment, Fox Entertainment and the Public Broadcasting Service.


The attacks, carried out between April and June last year, made international headlines as global companies began to wonder if they would be next to suffer at the hands of LulzSec, an off-shoot of the larger Anonymous hacking group.

Cleary is charged with one count of conspiracy and two counts of unauthorized impairment of a protected computer. He faces a maximum sentence of 25 years in prison if convicted.

In September 2011, the FBI arrested LulzSec member Cody Kretsinger, a 24-year-old Phoenix citizen. He pleaded guilty to participating in an attack on Sony Pictures’ website, stealing personal information from registered users of the site and, according to Sony, causing over $500,000 of damage in the process.

Read More

Sunday, 10 June 2012

FBI to hunt down hackers behind Linkedin password leak

| |
1 comments



Social networking site Linkedin is working with FBI to track down those stole password of its around 6.5 million members.

“We take this criminal activity very seriously so we are working closely with the FBI as they aggressively pursue the perpetrators of this crime,” Director at LinkedIn, Mr Vicente Silveira said in his blog post.

India is second largest market for LinkedIn after the US. It has over 15 million members and has seen 300 per cent growth its member base since start of its operation.

The company, on June 6, learnt that approximately 6.5 million hashed (secured) LinkedIn passwords were posted on a hacker site.

“Most of the passwords on the list appear to remain hashed and hard to decode, but unfortunately a small subset of the hashed passwords was decoded and published,” Mr Silveira said.

He further clarified that company is not aware of any member information being published and only information published was the passwords themselves.

LinkedIn Director said that company has disabled passwords of members that company believes were at risk.

“Based on our investigation, those members whom we believed were at risk, and whose decoded passwords already had been published, had their passwords quickly disabled and were sent an email by the Customer Service team,” he said.

He said that LinkedIn has not disabled password of members who were not at risk as per its investigation.
Read More

Sqli Vulnerability in channel [V] Website

| |
0 comments


A 16 years old White Hat Hacker "Arjun Siyag" from India discover a Critical Sqli Vulnerability in channel [V] Website (http://www.channelv.in). Proof of the hack is as shown in above image. Hacker disclose only the admin username and password, which will not effect the admin panel directly,because for login Email ID is required.


SQL Injection is one of the many web attack mechanisms used by hackers to steal data from organisations. It is perhaps one of the most common application layer attack techniques used today. Through SQL Injection, the hacker may input specifically crafted SQL commands with the intent of bypassing the login form barrier and seeing what lies behind it.

This is only possible if the inputs are not properly sanitised (i.e., made invulnerable) and sent directly with the SQL query to the database. SQL Injection vulnerabilities provide the means for a hacker to communicate directly to the database.
Read More

Friday, 8 June 2012

Anonymous India takes down MTNL website

| |
0 comments
The hacker-group Anonymous has struck again in India. This time the victim is the MTNL website. The group posted on their website, saying, ”We are against Internet Cencorship. Instead of blocking few URLs the ISP blocked the whole domain of various file sharing websites. The HC Madras, DoT didn’t isssue any list of websites to be blocked still ISP supported internet censorship.”



MTNL's corporate website could not be accessed, following the attack since afternoon and officials said efforts were underway to restore it. MTNL Delhi, Deputy - GM (Internet), Deepak Sharma said it was not hacking but 'denial of service attack' under which the server is unable to provide services to the customers.

Anonymous has called for non-violent protests across several cities in India on June 9 to protest against what it alleges as ‘censorship’ of the internet. It accused the department of telecom of instructing the Internet Service Providers (ISPs) to block file-sharing websites unilaterally, while the courts had ordered blocking of certain websites.


f the protests, Anonymous has also asked all citizens to wear Anonymous’ (Fawkes) mask, dress completely in black and step out on the streets to protests.

This is the latest in a series of such attacks in the over the past month by the group, which has targeted the websites of the Internet Service Providers Association of India, the Trinamool Congress and Reliance Communications.

The government has so far refrained from making any comments on the concerted campaign by Anonymous over the last 15 days.


Read More

Thursday, 7 June 2012

LinkedIn Confirms Millions of Account Passwords Hacked

| |
0 comments



LinkedIn Wednesday confirmed that at least some passwords compromised in a major security breach correspond to LinkedIn accounts.

Norweigan IT website Dagens IT first reported the breach, noting that “Two days ago a package on the 6.5 million encrypted passwords posted on a Russian hacker site.

Vicente Silveira, Director at LinkedIn, confirmed the hack on the company's blog Wednesday afternoon and outlined steps that LinkedIn is taking to deal with the situation. He wrote that those with compromised passwords will notice that their LinkedIn account password is no longer valid.


“It is worth noting that the affected members who update their passwords and members whose passwords have not been compromised benefit from the enhanced security we just recently put in place, which includes hashing and salting of our current password databases,” Linkedn director Vicente Silveira said in the blog post.

The file only contains passwords hashed using the SHA-1 algorithm and does not include user names or any other data, security researchers say. However, the breach is so serious that security professionals advise people to change their LinkedIn passwords immediately. An SHA-1 hash is an algorithm that converts your password into a unique set of numbers and letters. If your password is “LinkedIn1234,” for example, the SHA-1 hex output should always be “abf26a4849e5d97882fcdce5757ae6028281192a.” As you can see that is problematic since if you know the password is hashed with SHA-1, you can quickly uncover some of the more basic passwords that people commonly use.

Here’s what Imperva found: The most common password used was “123456,” followed by “12345″ and “123456789.” All in all, more than half a million people chose passwords composed of only consecutive numbers. So, if a hacker tried to log in to all RockYou accounts with just one password attempt–123456–every hundred or so attempts would yield a compromised account. Dozens of attempts can be scripted every second, so Imperva estimates that using this technique would only take around 15 minutes to hack 1,000 accounts.

Read More

Receive all updates via Facebook. Just Click the Like Button Below

?

You can also receive Free Email Updates:

Powered By IndiCyborg