Showing posts with label SECURITY. Show all posts
Showing posts with label SECURITY. Show all posts

Wednesday, 5 November 2014

Search Your Inbox To Unsubscribe From Unwanted Mails

Search Your Inbox To Unsubscribe From Unwanted Mails

 If you are not intelligent enough to uncheck the boxes that seek your permission to mail you newsletter, chances are that your mailbox is stuffed with unwanted marketing e-mails and reminders about anything and everything on this earth.

Well, for one, be smart enough to uncheck the boxes the next time you sign-up for anything; for the mails that you are already reporting, well here is how you can save some time.

Search the word Unsubscribe in your mailbox and every mail that has the option, just use the option and stop receiving the mails.

Sure this will take some time but we all like clean inboxes, don't we?

 Picture by Mahesh.

Friday, 31 October 2014

Chase Bank Hacked,Stolen for 83 Million Accounts

Chase Bank Hacked, Info Stolen for 83 Million Accounts

 

Last night, JPMorgan Chase & Co revealed the scope of a data breach that affects 83 million households and small business accounts. There's good news and there's bad news.
The bad news is hackers have stolen the contact information for 76 million households-that's nearly 65% of all US households!-and 7 million small businesses: names, addresses, phone numbers, and email addresses. This makes this latest data breach one of the biggest in history. The information may also include former account holders, Reuters says, not just current ones.
The good news, however, is that Chase has no evidence that passwords, account numbers, user IDs, birthdates, or Social Security numbers had been stolen. And it hasn't seen any "unusual customer fraud" since the cyber-attack happened in mid-August.
In a customer notice on its site, Chase says:
Your money at JPMorgan Chase is safe:
  • Unlike recent attacks on retailers, we have seen no unusual fraud activity related to this incident.
  • Importantly, you are not liable for any unauthorized transaction on your account that you promptly alert us to.

We are very sorry that this happened and for any uncertainty this may cause you. We don't believe that you need to change your password or account information. Click here for answers to questions you might have. As always, we recommend you use care with your accounts and information, as we describe in our Security Center.
We're here to help
Attacks like these are frustrating. There are always lessons to be learned, and we will learn from this one and use that knowledge to make our defenses even stronger.
Chase customers-current and former-should be on the lookout for any fraudulent activity on their accounts and report it as soon as possible.
Also be extra vigilant about possible phishing schemes, since the hackers will likely try to use the personal information they stole to get you to reveal your other account info. And although Chase doesn't think you have to change your password, it's probably a good idea to do so-just make sure you choose a really secure one.

Reboot Your iPhone Before Being Detained by Police to Disable Touch ID

Reboot Your iPhone Before Being Detained by Police to Disable Touch ID

 

The Virginia Circuit Court ruled this week that you don't have to give up your passcode to police if you're detained. That's great news, but apparently fingerprints are a different story, so if you have Touch ID enabled, you could still be forced to unlock your phone.
Basically, fingerprints don't fall under the 5th Amendment like a passcode does, so a police officer who can't force you to unlock your iOS device with your passcode could make you do it with your fingerprint. The solution? If you're detained, reset your iOS device (hold the Home and Power button for a few seconds) before you have to hand it over. Touch ID doesn't work on the first boot. 

Mahesh

Hacking Computers and Networks


Six Great DIY Projects for Hacking Computers and Networks

 

If you're testing your hacking skills or trying to learn more about security, your toolkit shouldn't end with your computer. If you're willing to pick up a screwdriver, a soldering iron, or a few other tools, there are several great DIY hacking projects that'll test your mettle and teach you a few things about networking at the same time. Let's take a look at some of them.
This post is part of our Evil Week series at Lifehacker, where we look at the dark side of getting things done. Knowing evil means knowing how to beat it, so you can use your sinister powers for good. Want more? Check out our evil week tag page.
As with all hacking and network sniffing and monitoring projects, keep in mind that these are the kinds of things you should use ethically, on your own network or networks you have permission to probe. Your company's IT department wouldn't like it much if you started sniffing around their network, and neither would everyone else at the coffee shop trying to get work done. With that out of the way, let's take a look.

Build a DIY Wi-Fi Hacking, Password Cracking, Cell Tower Spoofing Drone



Who wouldn't want their very own high-flying, Wi-Fi cracking, password stealing unmanned aerial vehicle? I certainly do, and it's easier to build than you may think. Back in 2010, a former Air Force cyber security contractor and a former Air Force engineering systems consultant trotted out the WASP, or Wireless Aerial Surveillance Platform, and proved that the government isn't the only entity that can build a drone capable of sucking down information from every network or wireless radio it's in range of. Both Forbes took a look at the drone a few years back, as did Popular Science, not to mention a ton of other outlets. The video above is the first in a two-parter with the folks at Hak5, where they chat with Mike Tassey and Richard Perkins, the creators of the WASP, and take it for a test run. From the Forbes article linked above:
The WASP, built from a retired Army target drone converted from a gasoline engine to electric batteries, is equipped with an HD camera, a cigarette-pack sized on-board Linux computer packed with network-hacking tools including the BackTrack testing toolset and a custom-built 340 million word dictionary for brute-force guessing of passwords, and eleven antennae.
... On top of cracking wifi networks, the upgraded WASP now also performs a new trick: impersonating the GSM cell phone towers used by AT&T and T-Mobile to trick phones into connecting to the plane's antenna rather than their carrier, allowing the drone to record conversations and text messages on a32 gigabytes of storage. A 4G T-mobile card routes the communications through voice-over-Internet or traditional phone connections to avoid dropping the call. "Ideally, the target won't even know he's being spied on," says Tassey.
The WASP may be a retired Army target drone, but these days you can make your own with a step-by-step guide or DIY kit from DIY Drones. From there, it's just a matter of packing on the right radios to mount on it, and how to connect to them once the drone is in the air. Luckily, the team behind the WASP have a blog at Rabbit-Hole.org, and while it hasn't been updated in a while, they do go into detail on their build process, the equipment they used, and how to to perfect your own hacker-drone if you choose to build one.

Transform a Safety Flare Gun Into a Wireless Camera Launcher

Six Great DIY Projects for Hacking Computers and Networks
If you've ever been sailing or camping, you probably have a flare gun somewhere in your gear. In worst case scenarios, it's designed to signal for help when you're lost or somewhere you can't get away from, or just to let others know your position if you know people are looking for you. Well, if you're not in the wilderness (and you don't feel like building a drone), why not turn it into a wireless camera launcher that can fire a camera 250 feet into the air and record everything as it parachutes down to the ground?
This is, of course, another project that originated from the Def Con security conference in Las Vegas. The original project was designed by an Israeli defense contractor to use a 40mm grenade launcher, but Vlad Gostom and Joshua Marpet, a pair of enterprising hardware hackers, decided to build their own using a 40mm flare gun that civilians could easily buy. The duo documented their experiences, although the first attempt didn't turn out terribly well. They've been working on it ever since (off and on), but ideally the next iteration will be a bigger success. If you're interested in DIY-ing it, they rundown all the parts you'll need (and you'll need a lot of parts and enough specific firearm-related equipment you may draw attention from your local authorities). Still, it may be worth it to build a flare gun that can map your neighborhood or be used for other cool outdoorsy projects.

Turn a Raspberry Pi Into a Pentesting Drop Box (and Disguise It In a Power Strip)


It's no secret that we love the Raspberry Pi, and it's a great platform for all sorts of things, including some awesome network hacking. In a previous Evil Week, we showed you how to turn a humble power strip into a Pi-powered packet sniffer that would look at home underneath someone's desk. That works well for stealthy purposes, like if you want to try it out and see if anyone notices that there's a network monitoring device under their desks, but if stealth isn't totally important, the Rogue Pi is a network monitor that, unlike the Pi-powered power strip, doesn't require you return periodically to pick up the data you've collected. Like we mentioned in our post, the Rogue Pi packs the radios required for you to connect to it wirelessly whenever you need to.
Even better, the Rogue Pi conducts a test when you turn it on to make sure it's connected to the network you want to probe, then creates an SSH tunnel that you can use to get to it when you need to, along with a hidden SSID and a Wi-Fi radio that lets you connect to it directly whenever you're in range. It has a laundry list of pentesting and Wi-Fi cracking tools onboard too, so once it's embedded in your target network, it can do whatever you need it to. It even has an tiny external LCD so you can power it on and configure it without whipping out a laptop. Nefarious? Absolutely-but it's also a blast to make and perfect for surreptitious surveillance of your own networks or use as a hidden access point. All the code and gear you'll need for it are listed over at the project site. If you're really enterprising, you could combine this hack with the power strip hack, and take your show on the road to Def Con.

Build an Arduino TV Annoyer

Six Great DIY Projects for Hacking Computers and Networks
Most of these projects are aimed at network hacking and information gathering, like any good hacking project, but this one, the DIY Arduino-based TV annoyer, is strictly for fun and laughs. Put simply, this little device will turn on TVs when you want them off, and turn TVs off when you want them on. Think of it as a simple April Fool's gag, or something a little more innocuous and less aggravating than the always-classic annoy-a-tron from ThinkGeek.
Our guide (originally from Instructables) walks you through the entire build process, as well as the parts you'll need to make the whole thing happen.

Turn an Airsoft Rifle Into a 2.4Ghz Wi-Fi Sniffer with a Raspberry Pi

Six Great DIY Projects for Hacking Computers and Networks
From the "hacking projects I probably wouldn't want to be seen carrying on the street but are still cool" department comes the Hack Rifle, an Airsoft rifle with a Raspberry Pi at its heart that's capable of picking Wi-Fi signals out of the air at long distances. It sports a high-gain directional antenna attached to the barrel, a fold-out screen to monitor the information it's capturing, and a button connected to the trigger to fire up the Wi-Fi antenna, scan for targets, select a target, and crack the target device or network.
The Hack Rifle is running Raspberry Pwn (like the Rogue Pi above), a pentesting Linux distro designed for the Pi. It's designed to be collapsable into five pieces, and has an orange tip so people don't think it's a real rifle-although even its creator acknowledges it's not that simple:
This isn't a real gun, it's an airsoft rifle. And yes, pointing anything that looks like a gun at a person or building is a terrible idea, and yes this thing will freak people out and probably get you arrested. That's why it's never been outside my apartment, has never been aimed out my windows, and has an orange tip.
Follow his example if you opt to make something like this. In fact, there's little about the build that requires the rifle, although there's some allure to the idea of point, pull the trigger, and hack. Even so, there's a reason this thing hasn't seen the light of day outside of its creator's apartment, and if you want to do something similar, it should stay in yours where it's safe as well. If you opt for a diferent form factor though, you may be able to take the thing around with you-everything you need to know is over at the project site. The commentariat at Hack a Day have some thoughts on the build too (like disguising it as a hedge trimmer instead of a rifle!), and call back to an even older version that could pull Bluetooth as well as Wi-Fi out of the air-and looked significantly less menacing, what with the Pringles cans on the barrel.

Turn a Nexus 7 Into a Portable Network Probing Tablet


If you're looking to build a pentesting or scanning tool that's a little less conspicuous than a huge rifle or a PC attached to some Pringles cans, the Pwn Pad may be perfect for you. The Pwn Pad is a portable pentesting tablet based on the Nexus 7 and designed by the folks at Pwnie Express, a security firm and online store packed with products for the discerning hacker. The Pwn Pad will set you back close to $1100 if you want the tablet and the rest of the gear right off the shelf (complete with support for the gear and training in how to use it all), but if you have the Nexus 7 yourself and just want the code and the radios, you can buy the accessories for less and build your own Pwn Pad at home.
Hack a Day explains you'll ned a few other components of course, including a USB OTG cable with USB Ethernet, Bluetooth, and WiFi adapters, and of course the array of open source pentesting tools included on the Pwn Pad. Rolling your own isn't too difficult if you have the right gear, or just don't want to drop the cash directly for the whole package.

Dont Trust a Website's Seal

Don't Trust a Website's Seal of Approval

 

Chances are you've come across "seals of approval" on web sites at some point in your web browsing life. Whether it's a Better Business Bureau seal, a Norton Secured Seal, or the TRUSTe Certified seal, they seem like a good thing to watch out for. How-To Geek points out how wrong that is.
Pretty much any seal you see on a site is just a JPG and doesn't require any work to put it there:
These badges - technically called "trust seals" - are just images. Anyone could copy and paste these images and put them on any software download page. Really, we can't stress this enough. Although a seal of approval might look fancy and official, it's no different from a statement written out in text. If you saw a scammy-looking software download page that said, "This software was certified virus-free by Symantec!", would you blindly trust it? Of course not! Of course they'd say that - anyone can write that.
If you want to actually verify the claim in a seal, you'll have to head over to the seal's web site and research the company in question. Otherwise, those claims mean absolutely nothing. If you've been using a computer for a long time you've probably already figured this out, but it's a good tip to add to you tech support kit. Head over to How-To Geek for some more tips on reading through those seals of approval.

Norbert Finds and Verifies People's Email Addresses

Norbert Finds and Verifies People's Email Addresses







Norbert Finds and Verifies People's Email Addresses 
With Norbert, you can find someone's email address by simply typing in their first name, last name, and the domain name where you think they work.

There are dozens of ways to find someone's email address, but they all have drawbacks. For example, sometimes Rapportive doesn't work because someone's current business email address isn't connected to their LinkedIn or Twitter profile. 

Norbert offers a simple interface, and you don't need to install a plugin to use it. The second you search for someone and turn up an address, Norbert checks the mail host to confirm that the address exists. Norbert is also compatible with Gmail addresses, but I'd suggest pairing it with Rapportive to confirm an identity before reaching out.

Despite its strengths, Norbert also has its own drawbacks. Although Norbert tests and pings mail hosts, it doesn't yet check for catchall addresses. Some domains will return false positives. Also, Norbert limits users' queries because the creators fear some SMTP servers may block the service if Norbert pings them too frequently. These quotas are reset every day.
If you're not performing dozens of searches daily, Norbert helps you quickly discover email addresses. Check it out at the link below.