الثلاثاء، 31 يناير 2017

Facebook Unveils 'Delegated Recovery' to Replace Traditional Password Recovery Methods




How do you reset the password for your Facebook account if your primary email account also gets hacked?

Using SMS-based security code or maybe answering the security questions?

Well, it's 2017, and we are still forced to depend on insecure and unreliable password reset schemes like email-based or SMS code verification process.

But these traditional access recovery mechanisms aren't safe

Check If Your Netgear Router is also Vulnerable to this Password Bypass Flaw




Again bad news for consumers with Netgear routers: Netgear routers hit by another serious security vulnerability, but this time more than two dozens router models are affected.

Security researchers from Trustwave are warning of a new authentication vulnerability in at least 31 models of Netgear models that potentially affects over one million Netgear customers.

The new vulnerability,

الاثنين، 30 يناير 2017

Over 70% of Washington DC's CCTV Were Hacked Before Trump Inauguration




Just days before the inauguration of President Donald Trump, cyber criminals infected 70 percent of storage devices that record data from feds surveillance cameras in Washington D.C. in a cyber attack.

Any guess, What kind of virus could have hit the storage devices?

Once again, the culprit is Ransomware, which has become a noxious game of Hackers to get paid effortlessly.

Ransomware is an

WWE Social Media Accounts Hacked Before Royal Rumble


WWE Social Media Accounts Hacked Before Royal Rumble Match


Hacker Group OurMine tweeted from verified twitter accounts of World Wrestling Entertainment (WWE). As we all know this group has already hacked so many verfied twitter accounts in the past.

Hacker group took control of @WWENXT twitter account and posted,

Hey, it's OurMine we are jus testing your security, please contact us for more information, Thanks.

According to Mashable, the compromised accounts, which included WWE Universe, WWE NXT, WrestleMania, WWE Network,  Summer Slam, and John Cena, were all linked to the profile of WWE’s head of social media, which is what allowed OurMine to break into all of them at once. Perhaps the most notable revelation from this is the fact that John Cena’s personal social media accounts are apparently controlled in some fashion by WWE, possibly as a safeguard against rogue tweeting or, ironically, hacking, as are all of the accounts of WWE superstars,

According to a statement from the Hackers group.

We just hacked it using the head of WWE social media account. It is linked to all of WWE Superstars accounts — Twitter and Facebook.

In a statement, WWE confirmed the hacks.

"WWE can confirm that several official WWE Twitter accounts were hacked for a brief period on Saturday evening," a spokesperson said. "WWE subsequently re-secured the accounts.

الأحد، 29 يناير 2017

3D Bioprinter Which Can Print Functional Human Skin

3D Bioprinter
Aging is a natural process; as we are aware that every living animal, plant etc. is not immortal, whatever born has to die or destroyed, according to the law of nature. The human race is not an exception and some aging signs use to take place with the growing age, which is quite annoying for the person concerned, as nobody wants to admit the decaying of age and its symptoms.

To get rid of the aging problems, such as; wrinkles, fine lines, sagging, dark circles around the eye region are some of the most annoying signs, which have the potential of destroying the youthful look to a great extent and people use to try lots of means of various natures, including surgery.

The massive growth in the science and technology have paved the way for some of the most interesting and innovative solutions for arresting these disturbing symptoms, with an intention to get back the younger look.

Recently some scientists in Spain have invented a magical solution, by developing one of the most promising prototypes for the 3D bioprinter, which has the capability of producing some human skin with entire functionality.

Issues to be noted

It can be noted that the decayed skin texture can soon be rectified by replacing the affected area with the printed skins, which have all the functional characters and elements to provide maximum support for the user. The patching up of this mechanically printed skin can be of great support in reducing the aging signs on visible areas and helps the concerned person to get the comparatively younger appearance.

Skin is considered as the biggest organ of the human body and it is almost entirely exposed to the environment and sunlight, which potentially damage the skin texture and aggravate the untimely aging symptoms to be occurred in different regions, especially on the facial area. This unique and innovative scientific development has opened up the scopes of various uses of this artificially created skin, which can be used for various research purposes, testing of cosmetics and most importantly transplanting onto the human or other species.

It is the first of this kind of development that produces artificial, printed skin, by using the bioprinter, which will be introduced to the marketplace very soon for commercial and medical uses.

Conclusion

This innovative bio-printed skin is the result of the collaboration between extremely experienced scientists at the Universidad Carlos III de Madrid (UC3M) and the BioDan Group, a famous bioengineering company, who have the long history and specialization in the field of regenerative medicine, especially focused on the skin texture.

The most important part of this printed skin is; the material of this skin is having the qualities of the skin structure, wherein the inner part is having the fibroblast, which produces collagen; the most crucial protein element that provides the elasticity, as well as, enhances the mechanical strength of the skin. This mechanically bio-printed skin is being processed and generated in the automated and standardized way, which is less expensive than the manual process.

Google Announces Root Certificate Authority To Secure Websites

Google Announces Root Certificate Authority To Secure Websites


Google Announces Root Certificate Authority To Secure Websites


Google launches own Certificate Authority (GIAG2), issued by a third-party. This has been a key element enabling us to more rapidly handle the SSL/TLS certificate needs of Google products.

The newly established Google Trust Services will operate these Certificate Authorities on behalf of Google and parent company Alphabet.

The Google Public Key Infrastructure (“Google PKI”), has been established by Google Trust Services, LLC (“Google”), to enable reliable and secure identity authentication, and to facilitate the preservation of confidentiality and integrity of data in electronic transactions.

Google Trust Services now operates the following Root Certificates:


Due to timing issues involved in establishing an independently trusted Root Certificate Authority, Google also have secured the option to cross sign our CAs using:


Ransomware Hijacks Hotel Smart Keys to Lock Guests Out of their Rooms




What's the worst that could happen when a Ransomware hits a Hotel?

Recently, hundreds of guests of a luxurious hotel in Austria were locked in or out of their rooms when ransomware hit the hotel's IT system, and the hotel had no choice left except paying the attackers.

Today, we are living in a digital age that is creating a digital headache for people and organizations around the world with

السبت، 28 يناير 2017

Police Arrest 5 Cyber Thieves Who Stole 3.2 Million From ATMs Using Malware




Law enforcement authorities from Europe and Russia have arrested five members of an international cyber criminal gang for stealing $3.2 million cash from ATMs using malware.

Three of the suspects, Andrejs Peregudovs (41), of Latvia, Niklae Penkov (34) of Moldova, and Mihail Colibaba (30) of Romania, were arrested in Taiwan by the Taiwanese Criminal Investigation Bureau last summer, have

Google becomes its own Root Certificate Authority




In an effort to expand its certificate authority capabilities and build the "foundation of a more secure web," Google has finally launched its root certificate authority.

In past few years, we have seen Google taking many steps to show its strong support for sites using HTTPS, like:

Giving more preference to HTTPS websites in its search rankings than others.


Warning users that all HTTP

الجمعة، 27 يناير 2017

Dump Database Website LeakedSource Gets Shut Down

Dump Database Website Leaked Source Gets Shut Down

Dump Database Website Leaked Source Gets Shut Down


Breach Aggregator Leaked source website goes offline. Multiple data breaches had been collected by website. Also its Social Media accounts have suspended.

This website Search hundreds of leaked databases like LinkedIn, MySpace, Dropbox and Twitter by name, email, IP address, and more personal details.

LeakedSource has always maintained that the information in its database was already publicly accessible. "All we do is combine it in one easy to use location," a spokesperson told Wired recently. Some suspect the team was encouraging the community to come forward with new data dumps, however. Troy Hunt, a security researcher that runs a similar service called Have I Been Pwned, writes on his blog

"There was a constant flow of data that wasn't appearing anywhere else in the usual trading circles before first coming to air via their service. Speculation was rife that there was incentivisation occurring not just to provide data that had already been obtained, but to actively seek out new targets."

"Yeah you heard it here first. Sorry for all you kids who don't have all your own Databases.

LTD Pastebin source said,

Leakedsource is down forever and won't be coming back. Owner raided early this morning. Wasn't arrested, but all SSD's got taken, and Leakedsource servers got subpoena'd and placed under federal investigation. If somehow he recovers from this and launches LS again, then I'll be wrong. But I am not wrong.
Also, this is not a troll thread.
EDIT: Don't forget that LTD was the first person to make this news public.

But still, we don't know the reality behind to shutdown the Leakedsource.

Facebook Adds FIDO U2F Security Keys Feature For Secure Logins




Hacking password for a Facebook account is not easy, but also not impossible.

We have always been advising you to enable two-factor authentication — or 2FA — to secure your online accounts, a process that requires users to manually enter, typically a six-digit secret code generated by an authenticator app or received via SMS or email.

So even if somehow hackers steal your login credentials,

Google Is Making AI That Can Make More AI

Google
It is extremely touch to get a good artificial intelligence going on across the devices or on a single device. The tier tech companies from the Silicon Valley namely Google, Microsoft and Apple have spent millions of dollars and years of research to develop their own proprietary AI for their range of devices. Within a short time their distinct AI has become an integral part of their overall device user experience. This has been result of continuous monitoring, tweaking and further development of the AI to enhance its potential and to work at their best. Now Google AI research lab has stated that it is currently building a new AI software which possess the ability to develop more of its kin i.e. AI. In short AI is set to make more AI in future will be much cheaper and easier affair than today.

A smart enough AI to develop more AI

Google has stated that for AI to become capable of developing AI is a extremely delicate and complex process which does require higher level of human intervention. Google has hired a number of experts of experts to develop or discover such tools which has the potential of developing more AI in future. Secondly Google is trying to reduce cost incurred at the development of the AI by building a smart enough Ai to do the job. In future educational institutions and corporation will be able to hire AI builder to develop their own Ai for exclusive purposes.

Is science fiction turning into reality? 

We already have a rich science fiction literature and movie galore which showcases how AI will eventually take over the world and decides to kill the humanity. This scenario is more commonly own as the Skynet catastrophe based on the Terminator series evil AI. When machines are allowed to develop their offspring that are smarter than the earlier iteration then it is certainly a major reason to worry. In similar fashion AI will work on its own to develop Ai and it will keep learning things related to development on its own without any human assistance. This will bring up a situation where in humans wouldn’t be able to understand the minute working details of the AI by looking at its performance and this will create a trouble for the AI trainers. Eventually AI will overcome as a powerful entity which wouldn’t require human at all to discover new territories.

This might appear to be too dark to digest given the fact that Google wouldn’t let the AI run rogue at any given time. Google has built it contingency plans to avoid any such miserable situations by ensuring that Ai doesn’t get the chance to disable its own killswitches at any given point of time. Furthermore Google has clarified that its AI charged with the task of developing more AI isn’t capable of competing against the human engineers which ensure that dark futuristic Skynet isn’t in making at all.

Ref:

Fast Reinforcement Learning via Slow Reinforcement Learning

Learning to Optimize

Breach Database Site 'LeakedSource' Goes Offline After Alleged Police Raid




The biggest mistake companies make with data security is leaving all their secrets unprotected at one place, which if attacked, they are all gone in one shot.

An unnamed law enforcement agency has reportedly accessed billions of compromised usernames, email IDs, and their passwords, collected by LeakedSource, a popular breach notification service.

LeakedSource, launched in late 2015, that

Facebook Improve Its Security With New Login Approvals

Facebook Improve Its Security With New Login Approvals


Facebook added Security Keys function to more secure your account. According to Facebook these options can protect users account. If you use a security Key then you can protect from attacks like Phishing and Man in the Middle attacks, its support Universal second Factor (U2F) to login to your Facebook account for confirm your identity.

It works like your Fingerprint option to unlock your Mobile. As compared to other form security settings, security keys are more relevant option to choose. Security Keys for Facebook logins work with Mobile devices and web browsers. You need to be updated your Web browser like Chrome to add security Key from your Computer.

What is Security Key?

It is a USB based Hardware key, once you log into a service that supports they key, all you need to do is insert the key into a port and tap it to complete your login — no SMS or Google Authenticator codes required. Keys typically support several security features and standards, like one-time passwords, public key encryption and authentication, and the Universal 2nd Factor (U2F)

Universal 2nd Factor (U2F) is an open authentication standard that strengthens and simplifies two-factor authentication using specialized USB or NFC devices based on similar security technology found in smart cards.While initially developed by Google and Yubico, with contribution from NXP Semiconductors.

Using security keys for two-factor authentication provides a number of important benefits:

  • Phishing protection: Your login is practically immune to phishing because you don't have to enter a code yourself and the hardware provides cryptographic proof that it's in your machine.
  • Interoperable: Security keys that support U2F don't just work for Facebook accounts. You can use the same key for any supported online account (e.g. Google, Dropbox, GitHub, Salesforce), and those accounts can stay safe because the key doesn't retain any records of where it is used.
  • Fast login: If you use a security key with your desktop computer, logging in is as simple as a tap on the key after your enter your password.

Currently, this will not work with Facebook App. but if you have an NFC-capable Android device with the latest version of Chrome and Google Authenticator installed, you can use an NFC-capable key to log in from our mobile website. In Firefox can currently be enabled through an addon support.

How do I turn on login approvals?

Login approvals are a security feature similar to login alerts, but with an extra security step. If you turn on login approvals, you'll be asked to enter a special security code each time you try to access your Facebook account from a new computer, mobile device or browser.

To turn on login approvals:

  • Go to your Security Settings
  • Click on the Login Approvals section
  • Check the box and click Save Changes

After adding U2F option, Facebook accounts become more secure. Other companies are also using security keys include Google, Github, Dropbox.

الخميس، 26 يناير 2017

President Trump's @POTUS Twitter Linked To A Private Gmail Account




It seems like the new American President's Twitter account could easily be hacked due to security blunders he made with the most powerful Twitter account in the world, experts warned.

Days after we got to know that the newly inaugurated President Donald Trump was still using his old, insecure Android smartphone, it has now been revealed that the official @POTUS Twitter account was linked to a

NCIIPC: It's Time to Step Forward And Protect Our Critical Infrastructures from Cyber Attacks




The IT threat landscape has changed dramatically over the last three-four years.

With no shortage of threat actors, from hacktivists to nation-states, criminals to terrorists, all of them are now after something new.

It's no more just about stealing your money, credit cards and defacing websites, as now they are after the intellectual property, mass attacks and most importantly, our critical

Google Placed Its Own Ads First, Study Claims

Google
Google search engine is the most widely favored search option for millions of users across the varied devices and platforms. With its immense success over the years Google started offering paid advertisements to the individuals and businesses to rank better in the search engine results and gain more business and clients through diverting users to their websites. It might seem a noble thing to do but Google has been found to plunder top ad slots for its own products. A study conducted by the Wall Street Journal showcases that Google’s own products accounts for 91% of the top results on the search results page.

Google advertisement scheme is fabricated

One of the popular advertising data firms named SemRush has conducted a thorough analysis of Google advertising scheme by carefully analyzing over 25000 pages. It undertook the research in the popular search terms like speakers, laptops, smoke detectors and watches on Google and analyzed 1000 results. It was found that Google own products across the categories found themselves in the top of the results. Google already has a dedicated marketing policies ensures that its products doesn’t interfere with the carefully design online system and this was stated by one of the official spokesperson.

Google does away with the studies

Google has clarified that the studies is baseless as it has a auction system for determining how much price will be paid by the advertisers for featuring in the Google search page results. This system not just governs other advertisers on its platform but it also work on Google’s ads as well. In short Google has tried to away with all the allegations on its popular search engine by ensuring that its ads are on the same page as other advertisers ads but sadly that isn’t the case.

A report as stated earlier released by the Wall Street Journal carefully points out the for the search term ‘laptop’ in more than 1000 searches on its platform has resulted in offering Google ChromeBook as the top choice. In similar fashion Google favored the Android smartwatch as much as 98% in the searches for the search term ‘watches’ thereby fail to mention the popular and expensive Apple Watch. Thirdly searches conducted on the search term ‘smoke detector’ positioned Nest as numerouno as it is a Google’s own alarm product.

Google is wading through rough waters

This isn’t the first time Google has been accused of placing its own ads above the competitors and other advertisers. Last year Google had to deal with an unwanted controversy with its search platform when European Commission accused it of abusing its dominant position in the internet shopping arenas.

It also mentioned that Google was proactively being using its platform for restricted competition by placing its own ads in the top tier. Google has always maintained that the advertising auctions done on its search platform is run by the algorithm which doesn’t indulge in making decision on any particular advertiser or Google’s behalf at all.

700bike Galaxy Smart Folding Bike: Mono-live Review

700bike Galaxy
If you are crazy about folding bikes then this one will make you crazier and pumped up again. Folding bikes are popular for its extreme portability factor which helps in saving space as it can be placed right in the back of the trunk without much hassle. You can place folding bikes in any corner of your home, office or garage and it can zoom past vehicles and narrow passage ways with ease and they are lifesaver in traffic jams. Currently the folding bike segment is filled with innumerable styles at varied price points. 700Bike latest offering Galaxy is set to bring a storm in the market and the most valuable factor this bike going in the market is that it is the winner of the Red Dot Design Award.

The Design

The best about 700bike Galaxy design is that it looks stunning and beautiful from every angle which isn’t s small feat to achieve. The designers of this 700bike Galaxy bicycle has certainly inspiration from the automobile sector as very angle of its bears the smart finish and attention to the details. Like any other foldable bike this one also folds right from the middle of its frame. User can easily fold the handles and pedals to make it a compact version of itself which can be placed in any corner of the room, office or car with ease and grace. Manufacturers have used the latest 3D welding technique which is utilized in building headtube and top tube right from a single mold. 700bike Galaxy has a sleek look and weighs just 12.5 kgs which makes it extremely light to carry around.

Features

It features the CST Kevlar-protected anti-puncture tires and has a Selle Royal Comfort saddle. The aluminum rims are of 20 niches and it has brake from Tektro with 140mm disc along with the SRAM X5 9 speed shifter for enhanced agility. To render a comfortable biking experience on the city roads Galaxy comes with the PG950 cassette which makes driving down the road, cobblestone or any other terrain within the city a splendid experience.

Users can adjust the seat as per their comfort level by adjusting the height. Another great thing about its design is that when this bike is folded up the bottom of the seat post acts as the stand for the bike itself. Being a futuristic bike it doesn’t lag behind on the tech front and it comes with a black & white LCD white placed in the handle post. It showcases the time along with the speed and distance covered by the user. The Chinese edition boasts of a special feature wherein SIM cards can be paired with the integrated GPS and can easily show the location right on the screen but this feature is severely missed on the international retail units of this 700bike Galaxy bike. The best thing about this 700bike Galaxy is that user can easily connect and sync it with their Android or IOs device to track their performance.

ReverseMap - To Analyse SQL Injection Attempts in Web Server Logs

ReverseMap - To Analyse SQL Injection Attempts in Web Server Logs

ReverseMap - To Analyse SQL Injection Attempts in Web Server Logs


The program can either be run in batch mode or interactive mode. In batch mode the program will accept Apache web server logs and will deobfuscate requested URLs from the logs. In interactive mode the program will prompt for user input and will print the deobfuscated results.

The program can deobfuscate the following obfuscation techniques:

  • SQL CHAR encoding
  • SQL CAST encoding
  • Case encoding of SQL keywords
  • Substring(Experimental - Disabled by default as it will fail with nested queries)
Pull requests, patches and feedback is welcome.

Download ReverseMap

الأربعاء، 25 يناير 2017

New Trojan Turns Thousands Of Linux Devices Into Proxy Servers




"Linux doesn't get viruses" — It's a Myth.

A new Trojan has been discovered in the wild that turns Linux-based devices into proxy servers, which attackers use to protect their identity while launching cyber attacks from the hijacked systems.

Dubbed Linux.Proxy.10, the Trojan was first spotted at the end of last year by the researchers from Russian security firm Doctor Web, who later