Articles by "Hacking News"
Showing posts with label Hacking News. Show all posts
Tech Touchz is a Network about Hacker News, Tech News &Tech Hacks - Latest &Tech News, Hacker News and Hacking Tricks About Technology

Sadly! Pokémon Go Servers Went Offline After A Massive DDoS Attack

Servers Goes Offline After A Massive DDoS Attack
Servers Goes Offline After A Massive DDoS Attack


Pokémon Go Players who are looking to spend their weekend playing the game were left disappointed. On 16th July a significant interruption striked the game servers. However, PoodleCorp claims this time about the interruption and had mentioned that they had used a DDos attack to take down Niantic servers.

In a DDoS attack, the incoming traffic flooding the victim begins from many unusual sources – potentially hundreds of thousands or further. This completely makes it difficult to stop the attack simply by blocking a single IP address. Moreover, it is very difficult to recognize genuine user traffic from attack traffic when spread across so many points of entrance.

According to the sources, this attack took place just after the Game Pokemon Go launched in 26 more countries in Europe which include Ireland, Greece, Poland and Sweden.


“Our servers are humbled by your incredible response. We are working to resolve the issue. Please try again soon!” It was the message that was shown to Pokémon Go users when they tried to play the game.



Servers Goes Offline After A Massive DDoS Attack
Servers Goes Offline After A Massive DDoS Attack

Pokemon Go’s soon recognized the attack and then tweeted from its official twitter account “Trainers! We have been working to fix the #PokemonGO server issues. Thank you for your patience. We’ll post an update soon.”

Trainers! We have been working to fix the #PokemonGO server issues. Thank you for your patience. We'll post an update soon.

— Pokémon GO (@PokemonGoApp) July 16, 2016

As we already mentioned that the hacker group Poodle Corp claims the responsibility of all the happenings. Poodle Corp tweeted about the responsibility for the latest interruption “PokemonGo #Offline #PoodleCorp”

PokemonGo #Offline #PoodleCorp

— PoodleCorp (@PoodleCorp) July 16, 2016

Poodle Corp twitter account also retweeted one of the posts of a user whose name was “XO” that reads “Just was a lil test, we will do something on a larger scale soon.”

Just was a lil test, we will do something on a larger scale soon .

— XO (@xotehpoodle) July 16, 2016

As soon as Pokémon Go servers went down fans preferred social media to voice their rage and disappointment. Some of them also came out with some funny tweets.

When pokemon go goes down and you don't know how to cope pic.twitter.com/UuuvZddL8i

— TechnicallyRon (@TechnicallyRon) July 16, 2016

I'm really pissed off that Pokémon Go is down because a group of killjoys decided it would be fun to hack the servers and take them offline.

— Meg Bethany Read (@triforcemeg) July 16, 2016

Why would someone hack the #PokemonGO servers and make the game go down? I don't get it and I really want to catch them all! #😫 #whyyy

— Rachel A (@RachelAnders66) July 16, 2016

Servers down. Guess I will chase the real thing. #PokemonGO pic.twitter.com/3DIbI2jOZN

— Me, Myself and I (@HolmesRia) July 16, 2016



For your information let me tell you PoodleCorp was the same group who hacked some popular Youtube Accounts which includes the accounts of WatchMojo, Lilly Singh, Redmercy, and Leafyishere. This time, they have taken down one of the world’s most famous game Pokemon Go servers.
Tech Touchz is a Network about Hacker News, Tech News &Tech Hacks - Latest &Tech News, Hacker News and Hacking Tricks About Technology

Linux OS Ubuntu’s Forums Hacked, 2 Million Users’ Data Stolen

Linux OS Ubuntu’s Forums Hacked
Linux OS Ubuntu’s Forums Hacked

Canonical has announced that the official Ubuntu forum has been hacked and is now known that two million accounts have been compromised as announced by the Canonical, the company behind the development of the most popular Linux distribution Ubuntu. Hence, the committed data contains the IP addresses, usernames, and email addresses.

The hackers managed to enter into the Forum through a security breach, which consisted of insufficient protection of the site against SQL injection type attacks. SQL injection is to introduce SQL commands at the site in order to access the same database. Hence, the attackers gained access to the site’s user table, which contains all the information from the forum users.


Jane Silber, CEO of Canonical, has had to face for the company and apologize by saying the following:

“There has been a security breach on the website of the Ubuntu forums. We take very seriously the information security and privacy of users, following a strict set of security practices and this incident has started a thorough investigation. Corrective measures have already been taken and service forums and has been fully restored. In the interest of transparency, we will share all the details of the security breach and the measures taken. We apologize for the security breach and for any inconvenience caused”.

Later, Jane Silber explained that “After an initial investigation, we can confirm that there has been exposure data and have closed the forums as a precaution. On further investigation, we have found that there was a known SQL injection vulnerability in the Forumrunner supplement that had not been patched yet”.

Continuing its intention to offer full transparency has also published what attackers has managed to access and what not.


Attackers managed to access:-


  • Attackers have been able to inject SQL code formatting to a database of forums on the database server. This gave the people ability to read any table, but Canonical believe only been able to read the “user” table.

  • Attackers have used this access to download portions of the user table containing usernames, email addresses and IP addresses of 2 million users. No detected access to the passwords, which are stored in this table as strings of random characters because the Ubuntu forums rely on access via Ubuntu Single Sign On, so attackers have only been able to have access to the chains on which has been applied hash and salt.



Attackers failed to access:-


  • Canonical knows that the attackers were unable to access any of the major repositories of Ubuntu or update mechanism.
  • Canonical knows that the attackers have not been accessed through valid user passwords.
  • Canonical believes that the attackers were not able to climb a remote read access to SQL database on the server forums database.
  • Canonical believes that the attackers were unable to gain remote access to write SQL Server database.
  • Canonical believes that the attackers were not able to gain access to the shell on any of the applications of the forum or the server database.
  • Canonical believes that the attackers were not able to access servers at all frontend the forum.
  • Canonical believes that the attackers were not able to access any other service Canonical or Ubuntu through this attack.


According to the information provided by Canonical so far, the users’ passwords have not been committed. But, it would be advisable to change the password used for the Ubuntu forums and all websites where it is used.

Not the first time that the Ubuntu forums are hacked since in 2013 they were also victims of another attack in which a similar number of accounts were pledged, but with more serious consequences because the passwords were not insured as they should.
Tech Touchz is a Network about Hacker News, Tech News &Tech Hacks - Latest &Tech News, Hacker News and Hacking Tricks About Technology

Based on Linux, Android is compared to iOS Mobile and Windows 10. Microsoft and Apple each of operating systems, which is based on open source. Exactly, for this reason, users of Android can easily ‘root’ their devices, get privileges as an administrator on the operating system and thus control even how the software controls power to the processor, RAM or GPU.

Beware Android users, “GODLESS” Malware affected 90% of Android devices

However, rooting Android is also exploited by hackers and recently discovered a malware that is used against the user which usually targets devices running Android Lollipop or earlier. Recently Trend Micro security labs find out a family of mobile Malware which is known as “Godless” detected as (ANDROIDOS_GODLESS.HRX)

According to Trend micro labs, almost 90% of Android devices run on affected versions, malicious apps related to this threat can be found in prominent app stores, including Google Play, and has affected over 850,000 devices worldwide.


According to Trend Micro Labs, Godless uses a framework called “android-rooting-tools” to gain the root access to Android-based devices “Godless is reminiscent of an exploit kit, in that it uses an open-source rooting framework called android-rooting-tools. The said framework has various exploits in its arsenal that can be used to root various Android-based devices. The two most prominent vulnerabilities targeted by this kit are CVE-2015-3636 (used by the PingPongRoot exploit) and CVE-2014-3153 (used by the Towelroot exploit). The remaining exploits are deprecated and relatively unknown even in the security community.”

Apart from this, Godless malware can receive remote instructions that let apps to automatically download and silently install on Android devices which in results users are affected with unwanted spam apps that contain ads. This can even use to install backdoors and spy on the users.

Trend Micro recommends downloading apps from trusted stores such as Google Play and Amazon. Users must have secure mobile security that can mitigate mobile malware
Tech Touchz is a Network about Hacker News, Tech News &Tech Hacks - Latest &Tech News, Hacker News and Hacking Tricks About Technology


Here Are The 10 Best Penetration Testing Linux Distributions 2016 For Ethical Hackers.

Penetration means to penetrate any security system and this is mainly used to check the vulnerability of the bug in the network security. And mainly these testing is done with some pro security tools. But today there are many tools that have been developed which can be used as the pen-testing tool. These tools will be really helpful and can be used by a limited knowledge about security and its vulnerability.


1. BackTrack 5r3

Linux Pentesting Distro 1

BackTrack is one of the best known Linux pentesting distros. It gives you a “The quieter you become, the more you are able to hear.” BackTrack is usually based on the ever-popular Ubuntu. It is used to be only available within a KDE environment but to the added version Gnome was added with BackTrack v5. Its too popular pentesting distros that can run on any live CD or flash drive. The distribution is absolute for wireless cracking, exploiting, web application assessment, learning.



2. BackBox Linux

Linux Pentesting Distro 2


Now-a-days, Backbox is getting more popular. Similar to BackTrack, BackBox Linux is an Ubuntu-based distribution designed basically to perform penetration tests and security assessments. It was designed by developers with an idea to create a penetration test as fast and easy to use. It includes a very pretty short looking desktop environment and is updated to the latest versions of most used and best known tools through repositories.
BackBox provides all suspects for Forensic Analysis,Documentation and Reporting and Reverse Engineering with john, nmap, Social Engineering Tool etc.


3. Blackbuntu


Linux Pentesting Distro 3

The name clearly defines that it is yet another distro that is based on Ubuntu. It comes wit many pentesting distros as Information Gathering, Network Mapping, Vulnerability Identification, Penetration, Maintaining Access, radio Network Analysis, Reverse Engineering. The list is heavy too but the tools defined are different to the other distros.



4. Samurai Web Testing Framework

Linux Pentesting Distro 4


This is one of a live distro that is pre-configured with some open-source tools that aims only on testing and attacking websites. The main purpose of Samurai Web Testing Framework is it is based on attacking websites. The four steps are outlined by developers to carry out a web pen-test. These steps are incorporated within the distro and includes tools to complete up the task:


  1. Reconnaissance – Tools include Fierce domain scanner and Maltego.
  2. Mapping – Tools include WebScarab and ratproxy.
  3. Discovery – Tools include w3af and burp.
  4. Exploitation – Tools include BeEF, AJAXShell and much more.



5. Knoppix STD

Linux Pentesting Distro 5

Knoppix STD is based on Debian and was originated in Germany. The architecture of Knoppix StD is i486 and it runs on platforms like GNOME, KDE, LXDE. It was introduced from the long time. Basically, It was designed to be used as a live CD and can be installed on a hard disk. The STD stands for Security Tools Distribution. Knoppix provides you full scenario for cryptography.


6. Pentoo

Linux Pentesting Distro 6

Pentoo is based totally on security live CD on Gentoo. “Pentoo is Gentoo with the pentoo overlay“. The best distro to use is Pentoo. The homepage lists some of their customized tools and Kernel that includes a Hardened Kernel with aufs patches, Back ported Wifi Stack and even Cuda/OPENCL cracking support with all the development tools.



7. WEAKERTH4N



This distro is built from Debian Squeeze and uses Fluxbox for its desktop environment. This penetrating distro is adjusted for Wifi hacking as it contains many wireless tools. Categories of WEAKERTH4N are SQL Hacking, Cisco Expoitation, Password Cracking, Web Hacking,Networking ans Shells.



8. Kali Linux


Kali Linux is an Advanced Penetration Testing Linux distribution used for Penetration Testing, Ethical Hacking and network security assessments. This is one the best pentesting distros that you will surely love to use. Must try this out as this is the tool packed with lots of hacking tools.



9. Bugtraq



Bugtraq is one another reader penetration distro. This distro offers you a widerange of penetration and forensic tools. Bugtraq is harder to install but runs as a live DVD or from a USB Drive. It claims to be updated for kernel’s better performance and is configured too but importantly it can recognize more hardware. The team of Bugtraq seems to be solid as they have put full effort to get the kernel work best with more hardware.



10. NodeZero



Similar to BackTrack, NodeZero is also an Ubuntu based distro for pentesting using repositories. Following the way, Ubuntu releases a patch for its bugs, notifications for the system updates or upgrades are always present. It has become famous due to its inclusion of THC IPV6 Attack toolkit that includes tools like alive6, dnsdict6 etc.

Tech Touchz is a Network about Hacker News, Tech News &Tech Hacks - Latest &Tech News, Hacker News and Hacking Tricks About Technology

Reset Windows 10 Login PasswordHow To Hack and Reset  Your Forgotten Windows 10 Login Password

The process is simple but little time-consuming but it will definitely work for you. Moreover, with this method you can set your desired password to login into your windows account. this window 10 hack is only for emergency hour when you need to login to your PC. Follow some simple steps below to proceed.



Step 1. First of all, you need to boot your computer with Windows 10 installation drive. Once the setup process starts Press “Shift+F10 this will bring up the command prompt.




Step 2. Now you need to enter the following commands in the command prompt:



move d:\windows\system32\utilman.exe d:\windows\system32\utilman.exe.bak 
copy d:\windows\system32\cmd.exe d:\windows\system32\utilman.exe
Step 3. Now you need to restart your system, Enter the command “wpeutil reboot” to restart your computer.

Step 4. Now when you are back to your login screen, you need to click on Utility Manager, and you will see a command prompt appears.

Step 5. Now you need to add another user account to access your files, for that simply enter the following command:


net user <username> /add 
net local group administrators <username> /add

you need to replace <Username> with your desired name.

Step 6. Now reboot the computer by entering “wpeutil reboot” on your command prompt. And use your newly created account to enter your desktop. Browse to Start menu> Computer Management


Step 7. Now navigate to Local Users and Groups, select your local account and select the option of “Set Password” and enter your new password there.


That’s it you can now access the old account with your new password.


 Thanks For Reading.......
Tech Touchz is a Network about Hacker News, Tech News &Tech Hacks - Latest &Tech News, Hacker News and Hacking Tricks About Technology

#LifeHacks Here is how you can make your own cheap and effective infrared camera

How to make your own infrared camera cheaply and affordableWith 1080p cameras available at extremely affordable prices, it is extremely simple to produce your very own infrared camera. If you a look at the video given below, you will know that all cameras are capable of ‘seeing’ infrared light, but for standard photography and video, you don’t want to see the infrared light. Majority of camera sensors have an infrared filter in front of the sensor, in order to block out any excess to infrared light.

If you end up removing the filter, then voila, you have a fully converted infrared camera in the palm of your hands. The following video shows exactly how to modify a camera. However, a true infrared camera is similar to the visibility of a FLIR or Seek Thermal. This little camera hack will allow you to see a mixture of visible and near infrared light.


As a result, you will be able to see hot things glowing through the camera, but not to the same degree as a real thermal imaging device. Regardless, it is still a pretty cool trick if you want to add something extra to your home camera.
Tech Touchz is a Network about Hacker News, Tech News &Tech Hacks - Latest &Tech News, Hacker News and Hacking Tricks About Technology

Here are the top 8 websites to learn and train has an ethical hacker

 Top 2016 8 Websites To Learn Ethical Hacking

Everybody wants to learn hacking in today’s age. However, this is not an easy task until you have basic knowledge about computers and network security. For beginners to know, there are two types of Hacking Ethical (White Hat) and Unethical (Black Hat). Unethical hacking is considered illegal while ethical hacking may be regarded as legal.
We provide you with a list of websites that offers you white hat content. However, it is important to note that as a beginner to not perform any hacking & cracking tactics that breach any cyber law.



Hackaday



Hackaday is one of the top ranked sites that provide hacking news and all kinds of tutorials for hacking and networks. It also publishes several latest articles each day with detailed description about hardware and software hacks so that beginners and hackers are aware about it. Hackaday also has a YouTube channel where it posts projects and how-to videos. It provides users mixed content like hardware hacking, signals, computer networks and etc. This site is helpful not only for hackers but also for people who are in the field of Digital Forensics and Security Research.


Evilzone Forum



This hacking forum allows you see the discussion on hacking and cracking. However, you need to be a member on this site to check out queries and answers regarding ethical hacking. All you need to do is register to get your ID to get an answer for your queries there. The solution to your queries will be answered by professional hackers. The Remember not to ask simple hacking tricks, the community people here are very serious.


HackThisSite



HackThisSite.org, commonly referred to as HTS, is an online hacking and security website that gives you hacking news as well as hacking tutorials. It aims to provide users with a way to learn and practice basic and advanced “hacking” skills through a series of challenges, in a safe and legal environment.


Break The Security



The motive of the site is explained in its name. Break The Security provides all kind of hacking stuff such as hacking news, hacking attacks and hacking tutorials. It also has different kind of useful courses that can make you a certified hacker. This site is very helpful if you are looking to choose the security and field of hacking and cracking.


EC-Council – CEH Ethical Hacking Course



The International Council of Electronic Commerce Consultants (EC-Council) is a member-supported professional organization. The EC-Council is known primarily as a professional certification body. Its best-known certification is the Certified Ethical Hacker. CEH, which stands for Comprehensive Ethical Hacker provides complete ethical hacking and network security training courses to learn white hat hacking. You just have to select the hacking course package and join to get trained to become a professional ethical hacker. This site helps you to get all kinds of courses that make you a certified ethical hacker.


Hack In The Box



This is a popular website that provides security news and activities from the hacker underground. You can get huge hacking articles about Microsoft, Apple, Linux, Programming and much more. This site also has a forum community that allows users to discuss hacking tips.


SecTools



As the name suggests, SecTools means security tools. This site is devoted to provide significant tricks regarding network security that you could learn to fight against the network security threats. It also offers security tools with detailed description about it.
Tech Touchz is a Network about Hacker News, Tech News &Tech Hacks - Latest &Tech News, Hacker News and Hacking Tricks About Technology

Here is how a ethical hacker works at IBM

Get to know the life of an ethical hacker at IBM

As an ethical hacker for IBM, Charles Henderson gets paid to think like a bad guy. His job is to break into networks, applications, or physical locations to find out how a real attacker would carry out their work, uncovering errors and the effect those errors might have on an organization’s security.

IBM says that there has been a continuous change in corporations appointing their own hackers to “pen-test” (penetration test) online systems, networks, and physical locations, considering the increase in cyber-attacks and the need to strengthen cyber security.

In fact, Henderson is just one of the 1,000 security specialists the tech giant hired in 2015.

In a candid conversation with Business Insider, Henderson, 40, described what is like to be a hacker for IBM.

He said he has always been curious as a kid. He grew up in Austin, Texas where he still resides has now become a haven for young technologists with its lively computer security scene. Henderson attended the University of Texas and studied Computer Science.

“When I was 11, my father brought home our first computer. Within a week, I had become an active participant on the Bulletin Board Systems (BBS). Using these bulletin boards introduced me to other like-minded individuals and hackers across the world. All of a sudden the world became more accessible to me.”

“I quickly decided that I was more interested in taking things apart than putting them together.”

By the age of 12, Henderson started taking interest in networks, which at that saw the emergence of phone system. After legally getting a phone booth in his room, he took it apart. Today, we have websites and videos that tell us how things work and how to take them apart and put them back together. However, while Henderson was growing up, none of it existed, which is what thrilled him. With inquisitiveness triggered by the unknown, he decided to take things apart so that he could learn how they operated. He says that he would have probably never done it, had there been a book on how these things worked.

“I’ve always been bound by ethics,” he says. “That is not to say that kids don’t do stupid things.”

“For example, when I was in elementary school, I discovered that I could use my parent’s cordless phone as a scanner to listen in on our neighbor’s conversations. Did my parents love when I’d take apart their expensive electronics within just a few days of purchase? Probably not. But being a hacker, I had to know how everything worked.”

Henderson says that his curiosity led him into security research and penetration testing over the last 20 years, which has helped him make his career.

About seven months ago, when he was looking to switch jobs, IBM offered him a very interesting and challenging position that he couldn’t resist. He was fascinated to the wealth of information and resources available here.

For him, it has been really exciting working for IBM from the time he joined the company in October of 2015, as he gets to work with some of the largest brands in the world.

“Coming from smaller security teams, we just didn’t have access to the kinds of tools we have at IBM. We often had to create adhoc tools, which took time. At IBM, we have more firepower, thanks to tools like BlueMix and Watson, among other resources. I have access to basically anything I could ever imagine — which is really exciting for a researcher. The sky is really the limit here.”

“The first thing I do every morning is catch up on what happened when I was sleeping”

“The cool thing is, since I run a global team, when I’m sleeping there are teams conducting research and working engagements with customers.

“So in the morning I start by asking, ‘Did we find any critical flaws?’ ‘Do I need to tell a client we found a vulnerability and begin working to fix it?’ From there, I am working with my team to plan penetration tests and make sure we have the resources we need to address the issues we have found. There isn’t an hour that goes by that I don’t find a cool, new way of doing something, which means my days are both unpredictable and exciting.

While Henderson does a lot of research himself, he does like to look at consumer electronic devices that range from planes to trains to automobiles to mobile devices. He always find methods to break into or break apart these devices, to find new errors and susceptibilities. Also, he is always interested in knowing how devices connect to one another and what vulnerabilities might surface as a result. Thanks, to the growth of the Internet of Things (IoT).

Henderson travels the world to meet with clients when not in Texas, in order to help him better understand their security issues and the security landscape. During these meetings, he gets to work with some of the world’s biggest and most exciting companies that help him find out how their company handles security concerns. While the companies share their needs, requirements, and the trials they face, they work together to come up with solutions to fix them.

Sharing some examples of what Henderson and his team does, he says:

“One time, with the authorization of a previous client, I was hired to conduct a physical penetration test, which resulted in a stolen corporate vehicle filled with confidential information.

“The goal of the engagement was to have my team see how much damage we could do by using tools such as social engineering to infiltrate the client’s building and see how much confidential information we could get our hands on. Turns out, we could take it a few steps further, and stole the data and then drove away with it in a company car — but of course, we had permission.

“When it comes to hacking physical locations, we typically execute what I call ‘tiger teams’ (think ninja style/secret ops) to break into buildings on behalf of clients, to test their physical front-door security.

“We don’t use bars to get in the door — rather, we organise highly orchestrated attacks to get into client buildings by any means necessary, which often includes hacking into unsecured systems, copying employee badges, etc., with the client’s prior approval.”

Henderson says that the best part of his job is to find and fix key security susceptibility before attackers get a chance to abuse it.

Explaining the excitement of the chase, it is one less possibility for a criminal to abuse every time they help a client fix major security vulnerability, which also extends to the customers’ customers, the people they do business with.

He says, “Every day I’m faced with a new brain teaser, a new challenge, and that’s really exciting. The worst part about my job is telling a client they have a major vulnerability.

“Often, their initial reaction is fear, but the good news is, no matter how bad the vulnerability is, there is something we can do to fix it to protect the customer. But often, that initial delivery of bad news is difficult.”

Whenever Henderson tells people what he does for a living, he is often faced with one question which is “Can you hack into my bank account?”

To which his reply to the question would be, “It depends on what bank you use.”

He is also asked by people if he has ever done any ‘spy stuff”.

Henderson says that the biggest misconception that people have about hackers is that they are all criminals. Ironically, the word ‘hacker’ has been regarded as malicious computer hacking, which is why it very necessary to understand that the word is not a synonym for criminal.

“To me, being a hacker means you have an unbridled curiosity about how things work. Whereas many people look at a new technology and think about the possibility for creation, hackers look at a new technology and want to understand how to deconstruct that technology. We have an insatiable appetite for understanding how the world works — and we take it as a personal challenge to find flaws in technology before criminals have a chance to.

“Television shows and movies depict hackers as simply knowing how to do something. In reality, hacking is about taking something apart physically or virtually and understanding the inner workings.”

Explaining the difference between good hackers and bad hackers, he says that a criminal hacker is someone who abuses susceptibility for monetary gain or hidden motives, and is not interested in helping to fix the flaw they used to gain access. Criminals take the path of least resistance, while non-criminal hackers choose their targets based on a challenge or the learning process.

“As an ethical hacker, we are driven to understand how things work. When we find a vulnerability, we share that information and we work to responsibly disclose it and help fix the problem we found. Ethical hackers have a moral compass guiding them to help protect people from the flaws they find.”

“There is also a preconceived notion of hackers that we are people who choose to hack because we are maladjusted or full of angst and anger.

“Most people assume if you’re hacker, you had no friends growing up. But honestly, hacking has nothing to do with that. There are perfectly well-adjusted hackers in the world, we’re just curious people, looking for a deeper understanding of how the world works. I’m a father of two and I’m happily married.

“Also, my expertise in hacking has lead me to become a world-class practical joker within my team. I think that practical jokes foster critical thinking.”

Giving his piece of advice for aspiring hackers, Henderson says that the one thing they should always do is to question everything, be curious and never take anything at face value.

He further adds on to say that you should always keep sight of your ethical compass and practice responsible disclosure. It is easy to upset a promising career by doing something stupid. Ensure that you are guided by your values while you research vulnerabilities. Always keep in mind that a company cannot protect their users from a flaw found by a hacker unless they responsibly reveal it to the company, as a flaw cannot be fixed if the affected company has no knowledge about it.
Tech Touchz is a Network about Hacker News, Tech News &Tech Hacks - Latest &Tech News, Hacker News and Hacking Tricks About Technology


LG has released a whole bunch of 360-degree spherical wallpapers for you to enjoy on your brand new G5 smartphones. "Spherical wallpapers?" you exclaim in confusion, with a firm belief in your head that walls do generally tend to be flat.

360-degree spherical wallpapers now available for your LG G5Well, these are meant for your phone and your phone can be oriented in any arbitrary direction plus it has a gyroscope. Depending on its orientation you'd be served the respective portion of the spherical image and it will keep panning around as you move.

At this point there are 12 such wallpapers available, shot at exotic locations throughout the world by pro photographers. 4 new ones will be added each month until November. You can download them for free from the LG SmartWorld app.

We can see how it may be distracting in day to day use, more so than the parallax effect some makers apply. It's still pretty cool, though, and gives you an idea for another use of that 360CAM you got with the G5.
Tech Touchz is a Network about Hacker News, Tech News &Tech Hacks - Latest &Tech News, Hacker News and Hacking Tricks About Technology

White Hat, Black Hat, and Grey Hat Hackers : Finding which hacker is what made easy

What Are White Hat, Grey Hat, and Black Hat Hackers?

The long-fought battle between Apple and the FBI over unlocking of San Bernardino’s terrorist iPhone 5C finally saw a resolution. The Washington Post reported this week that the FBI broke into the San Bernardino shooter’s iPhone using the services of paid professional hackers, called as “grey hat” hackers.

The federal government paid hackers a one-time fee to find a “previously unknown software flaw” or a zero-day flaw in the iOS 9 software in the San Bernardino iPhone 5C that would allow them to access the data on the terrorist’s phone.

The new information was then used to create a piece of hardware that helped the FBI to crack the iPhone’s four-digit personal identification number without triggering a security feature.

There are basically three types of hackers: white hats, black hats and grey hats.

To understand these, let’s first know what a hacker is. A hacker is someone who seeks and exploits weaknesses in a computer system or computer network. Hackers may be motivated by a multitude of reasons, such as profit, protest, challenge, enjoyment, or to evaluate those weaknesses to assist in removing them.

White Hat hackers aka ethical hackers

White hats are security researchers or hackers who breaks security for non-malicious reasons, either to test their own security system, perform penetration tests or vulnerability assessments for a client or while working for a security company which makes security software. They normally notify the vendor once they discover a vulnerability in software so that the flaw can be fixed. For identifying any flaws in software, companies that have bug bounty programs these days pay white hats anywhere between $500 to more than $100,000 by selling that information. White hats are also considered as ethical hackers.

Black Hats aka cyber criminals


Considered as criminals, a “black hat” hacker is a hacker who “violates computer security for little reason beyond maliciousness or for personal gain”. Black hat hackers use their expertise to find or develop software holes and break into secure networks to destroy, modify, or steal data; or to make the network unusable for those who are authorized to use the network. They also sell information about the security holes, zero day vulnerabilities and exploits to other criminals for them to use. Obviously, black hats are considered the bad guys, as they are the epitome of all that the public fears in a computer criminal.

Grey Hats aka bit of both


A grey hat hacker lies between a black hat and a white hat hacker. A grey hat hacker can be individual hackers or researchers who surf the Internet and hack into a computer system for the sole purpose of notifying the administrator that their system has a security defect, for example. They may then offer to correct the defect for a fee. Grey hats normally sell or disclose their zero-day vulnerabilities not to criminals, but to governments—law enforcement agencies, intelligence agencies or militaries presuming that they use the vulnerabilities responsibly for the public good. The government’s use those security holes to hack into the systems of adversaries or criminal suspects.
Tech Touchz is a Network about Hacker News, Tech News &Tech Hacks - Latest &Tech News, Hacker News and Hacking Tricks About Technology



Cyber criminals hacked Swedish military computers and used them to attack major US Banks in 2013

Swedish military computers were hacked and used in an attack targeting major US banks in 2013, the armed forces said on Monday.
Sweden military servers hacked and used in attacks on US banks in 2013

The attack knocked out the web pages of as many as 20 major US banks and financial institutions, sometimes for several days.

Speaking to AFP, military spokesman Mikael Abramsson said that a server in the Swedish defence system had a flaw which was exploited by hackers to carry out the attacks, confirming a report in the Swedish daily DN.

“The hacking attack was a kind of wake-up call for us and forced us to take very specific security steps to prevent such a thing from happening again,” he said.

“We cannot be more specific about the new security measures we put in place, but such an attack could not happen again.”

The servers were used in a so-called DDoS attack (distributed denial of service) which pounded the websites of US financial institutions — among them Citigroup, Capital One and HSBC — with overwhelming requests for information.

At the time, the attack, which began in 2012 and continued for months, was one of the biggest ever reported.

US officials blamed Iran, suggesting it was in retaliation for political sanctions and several earlier cyber attacks on its own systems.

Many other vulnerable servers in locations throughout the world were used in the attack, and together they created an Internet traffic jam so powerful that it knocked out the banks’ websites.

“We normally have a good eye on our stuff. This mistake is about the human factor,” Dan Eriksson, IT security expert with the Swedish armed forces, told DN.

DDoS attacks have long been a basic hacker weapon but they have typically involved the use of armies of personal computers tainted with viruses and coordinated to make simultaneous requests at targeted websites.

In 2013, attackers infected datacentres used to host services in the Internet “cloud” and commandeered massive computing power around the world to back the DDoS attacks, security experts said.

US-based Neustar, which protects companies from such attacks, said they can cost financial institutions as much as $100,000 (about 88,000 euros) an hour.
Tech Touchz is a Network about Hacker News, Tech News &Tech Hacks - Latest &Tech News, Hacker News and Hacking Tricks About Technology

Hackers can hack into your Facebook, Gmail or Yahoo account for just $129


Hackers can break into your Facebook, Gmail, Hotmail or Yahoo account for just $129, says Dell

According to an annual report from Dell SecureWorks on underground hacker marketplaces, hiring a hacker to compromise an account with a popular email or social networking account will cost you just $129.

Hackers are increasingly operating as regular businesses with many advertising themselves as “honest, trustworthy and professional,” and providing a variety of illicit goods and services on the cheap, says the cybersecurity company’s third annual Underground Hacker Markets Report.

According to the Dell report, released on 5 April, the information was gathered by two intelligence analysts from the company’s CISO INTEL Team, who tracked hackers on a number of underground hacker forums and marketplaces scattered across the globe.

The report focuses on markets in the Russian underground as well as English-based markets, and covers the third quarter of 2015 to the first quarter of 2016 time frame.

To enlist the help of a team of “trustworthy, professional” hackers to gain access to your Facebook, Gmail, or Outlook account, all that someone has to pay is $129. It appears like quite the illicit bargain considering the kind of harm someone could inflict once they have gained access. These hackers stand by their work promising fast results, total confidentiality, and even offer after-sales support.

Stolen bank account credentials, passports, social media hacking and other services tend to get higher prices and prices are steadily rising.

“Like any other market in a capitalist system, the business of cybercrime is guided by the supply and demand for various goods and services,” the report’s authors wrote. “Unfortunately for the law abiding public, both sides of that equation remain strong, with everything from credit cards to hacker-for-hire services being sold online.”

Security analysts found that those interested in hiring a hacker to compromise a Gmail, Hotmail, or Yahoo account only have to pay $129 for the service. Popular U.S. social media and Ukrainian email accounts are priced the same, popular Russian email accounts range between $65 and $103, while Russian social media accounts are priced higher, at $194. If someone is looking to hack the IP address of a computer user, it will cost them another $90. On the other hand, hacking into someone’s corporate email account will cost $500 per business mailbox.

Over the past three years, prices for a Remote Access Trojan (RAT) — a malware program that allows cybercriminals to secretly control your computer remotely — have reduced from $50-$250 in 2013, to only $5-$10 in 2015. On the other hand, the Angler Exploit Kit is available for $100-$135, and that the price for “Crypters” went up significantly, reaching $80-$440, compared to 2014, when this type of malware went for only $50-$150.

Hacking tutorials are available for purchase online between $20-$40 for multiple tutorials, whereas doxing services cost only $19.99 (down from up to $100 a year ago). While hacking a website (stealing data) costs $350, distributed denial of service (DDoS) attacks can be hired for as low as $5 per hour, $200 per week, or $1,000 per month, with the price being higher if the website has anti-DDoS protection installed.

The upgraded ATM “skimmer” – hidden electronics that steal personal data stored on your debit or credit card’s magnetic stripe – is one of the most popular items on the underground market this year. These devices are priced at $1,775 with new 3D printed versions coming out as well.

Airline and hotel points can also be purchased in these underground black markets. Based on the number of points in account, large U.S. airline points accounts priced as high as $450 for 1,500,000 points, and large Middle East airline points accounts priced at $150 for 500,000 points. A large international hotel chain points account with 1,000,000 points cost just $200, the report reveals.

Another interesting item available for purchase on the Russian underground is “full business dossiers” on companies situated within the country and include credentials linked with the company’s bank accounts including account numbers, logins, passwords and more.

“Our security experts had never seen a full business dossier being sold for any companies, much less for Russian organizations. What could one do with this type information besides potentially siphon off all the money in the company’s bank accounts? Well, the possibilities are extensive. If the company has good credit, there is certainly the potential for those possessing this data to apply for hefty bank loans, high-limit credit cards, car loans and other lines of credit,” Dell says.

Hackers are concentrating even more on salesmanship to please customers in order to compete and guarantee “customer satisfaction.” Dell says one ad offered “free-trial attacks” and “abilities” while other hackers are increasing their work hours to include weekends and even claim of 24/7 customer service.

“Prices and goods are not the only way sellers are distinguishing themselves. There also continues to be a focus on salesmanship,” Dell reports. “Compared to the report last year, our security experts noted this time around that many hackers were expanding their working hours to include weekends and even promising to be available 24 hours a day.”
Tech Touchz is a Network about Hacker News, Tech News &Tech Hacks - Latest &Tech News, Hacker News and Hacking Tricks About Technology

New iPhone hack will free up at least 1-2GB of your valuable memory

This New iPhone Hack Will Free 1 to 2GB of Your Much Needed Storage — And It’s Easy

iPhone is very popular but it has one genuine problem. Fixed memory! A 16GB or 32GB iPhone can hold only so much albums, videos and images. Most users have to often delete their favourite videos/photos to make space for new images/videos. Not anymore! This new hack that can help you free up that valuable extra GBs of storage on your iPhone — and it’s effortless.
The hack was first pointed by a Redditor eavesdropping you who discovered that if you try and rent a movie with a large file size, your phone will automatically erase some unnecessary files you don’t need. eavesdroppingyou, who owns a 16GB iPhone says that repeating the process a few times could free up anywhere from 1GB to 2GB of your valuable storage space in an iPhone.
This New iPhone Hack Will Free 1 to 2GB of Your Much Needed Storage — And It's Easy
Remember, the larger the size of the movie, the more easy it is to free up the space. eavesdroppingyou chose Lord of the Rings film, The Two Towers to demonstrate the hack. I tried the hack with The Hobbit: The Desolation of Smaug and was able to free up 1.2GB in the first attempt on my iPhone 32GB
Tech Touchz is a Network about Hacker News, Tech News &Tech Hacks - Latest &Tech News, Hacker News and Hacking Tricks About Technology

Expert Palestinian Hacker Indicted for Hacking Israeli Drones and CCTV Systems

Palestinian Hacker Indicted For Hacking Israeli Drones And CCTV Systems
An Israeli judge has indicted the Palestinian Islamic Jihad (PIJ) movement’s main, expert hacker from the Gaza Strip for breaking into Israeli military drone camera systems for Islamic militants and collecting details of civilian aircraft movements.
The Palestinian hacker, Maaged Ben Juwad Oydeh, was formally charged by the judge at the Beersheba District Court after he was arrested by Israeli forces earlier this year. The indictment filed by the Southern District Attorney’s Office also charged Oydeh with hacking into video cameras of the IDF, the police and the Road Safety Authority, allowing the terrorist group to study the location of civilians and IDF personnel in real-time as it was firing rockets into Israel from the Gaza Strip. He was also charged with spying, conspiracy, membership in an illegal organization, and contact with enemy agents.
Oydeh’s hacking also allowed Islamic Jihad to keep track of the movement of airplanes at Ben-Gurion Airport, to view the passenger lists on incoming and outgoing flights, the type of airplane and its weight and landing and departure times, the indictment said.
As the Jerusalem Post reports based on court documents, Oydeh was recruited by PIJ as a teenager and was first tasked with managing PIJ’s radio station, where he first started receiving a monthly salary from the group.
Eventually, his technical skills got polished and he learned to hack CCTV cameras that were installed on roads in Israel. After witnessing his talent in hacking, PIJ’s leadership first asked Oydeh to hack into Israel’s Road Safety Authority, so the group leader could see video feeds from road cameras on his laptop.
Seeing that the new guy has talent, the group then asked Oydeh to hack IDF (Israel Defense Forces) UAVs (drones), which means drones. His first two attempts yield no success, which he managed to achieve after the third try in 2011.
The objective of targeting IDF’s UAVs was to pinpoint the position of IDF drones and even see their video feeds. However, when IDF updated their UAVs by the IDF in 2014, Oydeh’s hacking technique could no longer obtain video feeds.
Later on, in 2013, Oydeh was given the task of hacking into cell phones operating on the Palestinian Jawwal mobile network as well as Israel’s Orange Mobile and Cellcom networks so that PIJ could find out Israeli spies who were hiding in Gaza. However, Oydeh only managed to hack Jawwal’s network.
In the same year, the Ben-Gurion Airport was also hacked by Oydeh in 2013, as the group wanted to view video feeds, access information on flights, and even plan rocket strikes against certain airplanes. At one point in 2013, PIJ also secured a training session in Iran so that Oydeh could improve his skills, but the deal fell apart right at the end.
In 2015, Oydeh hacked into the Israel Interior Ministry’s records to help Islamic Jihad learn details about potential recruits and to better check the commitment of Islamic Jihad agents to the organization.
Oydeh continued to repair and upgrade Islamic Jihad’s computers, video cameras and other technologies until his arrest by Israel in 2016.