Skip to main content

Posts

Showing posts with the label hack

Microsoft Wireless Desktop 2000 protects that sensitive area between your peripherals

Microsoft's new wireless keyboard-and-mouse duo aims to thwart keystroke spies with full AES 128-bit encryption on over-the-air data -- an improvement on older wireless models that have proven to be easy pickings for hacker-types. You can pick up the Wireless Desktop 2000 now for $40, but that won't buy you protection from more common threats like Shandong phishmongers, nor will it make up for security loopholes in your other peripherals. Speaking of which, are you still using that seemingly innocent USB coffee-cup warmer? Microsoft

Kinect hack turns your living room into a crazy one-man laser techno dance party (video)

We've seen it aid surgery, help make smarter robots, and even do some gaming stuff, but honestly, what good is a controller if it can't fuel your crazy techno dance parties? Vimeo user Matt "Namethemachine" Davis posted a video showing a new hack for the peripheral, using its camera-based motion detection, combined with Ableton Live, DMX protocol, and more clever hackery to create a one-man electro-laser light show. It's easy to see this getting a bit out of control real fast in a room packed with overexcited club goers, but if you're looking to recreate the communal experience for you and your cat in your one bedroom apartment, this may be just the ticket. Create Digital Music Vimeo

FaceNiff makes Facebook hacking a portable, one-tap affair (video)

Remember Firesheep? Well, the cookie snatching Firefox extension now has a more portable cousin called FaceNiff. This Android app listens in on WiFi networks (even ones encrypted with WEP, WPA, or WPA2) and lets you hop on to the accounts of anyone sharing the wireless connection with you. Right now it works with Facebook, Twitter, YouTube, and Nasza-Klasa (a Polish Facebook clone), but developer Bartosz Ponurkiewicz promises more are coming. You'll need to be rooted to run FaceNiff -- luckily, we had such a device laying around and gave the tap-to-hack app a try. Within 30 seconds it identified the Facebook account we had open on our laptop and had us posting updates from the phone. At least with Firesheep you had to sit down and open up a laptop, now you can hijack Twitter profiles as you stroll by Starbucks and it'll just look like you're sending a text message (but you wouldn't do that... would you?). One more image and a video are after the break. FaceNiff

Google admits sensitive email accounts have been hacked, some users knew months ago (update: US says no government accounts compromised)

The  Contagio  security blog posted evidence back in February of targeted attacks against government and military officials on Gmail. Today, nearly four months later, Google has finally admitted this is true: hundreds of personal accounts have been compromised by hackers it believes to be working out of Jinan, the capital of China's Shandong province. The accounts include those of "senior U.S. government officials, Chinese political activists, officials in several Asian countries (predominantly South Korea), military personnel and journalists." The hijackers' aim appears to have been to spy on their targets using Google's automatic forwarding function. But unlike the PSN fiasco, Google insists its internal systems "have not been affected." Instead it seems the hackers used a phishing scam, possibly directing users to a spoof Gmail website before requesting their credentials. Google says its own "abuse detection systems" disrupted the campaign ...

Sony Pictures hacked by Lulz Security, 1,000,000 passwords claimed stolen

Oh, Sony -- not again. We've just received numerous tips that Lulz Security has broken into SonyPictures.com, where it claims to have stolen the personal information of over 1,000,000 users -- all stored (disgracefully) in plain text format. Lulz claims the heist was performed with a simple SQL injection -- just like we saw the last time around. A portion of the group's exploit is posted online in a RAR file, which contains over 50,000 email / password combos of unfortunate users. We've downloaded this file (at our own risk, mind you) and can verify these sensitive bits are now in the wild, though it remains unclear if what's published matches reality. In addition to user information, the group has blurted out over 20,000 Sony music coupons, and the admin database (including email addresses and passwords) for BMG Belgium employees. Fresh off the heels of the PlayStation Network restoration, we're guessing the fine folks in Sony's IT department are now surviving...

Researchers hack Kinect for glasses-free 3D teleconferencing (video)

Since the dawn of Kinect hacking, we've seen cameras strung together (or rotated) to create 3D, video game-like environments, while others have tweaked it for headtracking. Others, still, have used it for teleconferencing (albeit, the flat, two-dimensional variety). Now, a team of researchers have gone and thrown it all together to achieve 3D video chats, and if we do say so, the result is greater than a sum of its parts. The group, based out of UNC-Chapel Hill, uses 3D mapping (and at least four Kinects) to render the video, and then employs headtracking on the receiving end so that people tuning in will actually see the live video in 3D, even without wearing 3D glasses. The result: a tableau that follows you as you move your head and spin around restlessly in your desk chair waiting for the meeting to end. That's mighty impressive, but we can't help but wonder: do you really want to see your colleagues in such lifelike detail? Have a gand...

Pentagon says cyber attacks are acts of war: send us a worm, get a missle in return?

Well, the Pentagon is finally fed up with hackers picking on its buddies and foreign intelligence taking shots at its computer systems, and has decided that such cyber attacks can constitute an act of war. Of course, the powers that be won't be bombing you for simply sending them some spyware, but attempts to sabotage US infrastructure (power grids, public transit, and the like) may be met with heavy artillery. It's unclear how our government will identify the origin of an attack or decide when it's serious enough to start shooting, but Uncle Sam is looking to its allies to help create a consensus answer for those questions. The retaliatory revelation is a part of the Pentagon's new cyber strategy that'll be made public in June -- so saboteurs beware, your next internet incursion might get you an ICBM in your backyard. Wall Street Journal

CNC mill and Sixaxis controller make beautiful DIY music together (video)

Have you ever thought to yourself, "my CNC mill is pretty cool, but I really want to make it more awesomer"? Well, first, "awesomer"  totally  isn't word, and second, have we got a hack for you! A reader wrote in to the DIY hub Adafruit to show off his CNC being operated by a PS3 Sixaxis controller -- mimicking features found on high-end machines that allow you to trigger jobs from a distance and manually control the mill. Best of all, it's a pretty simple mod that uses a program called QtsixA to map the gamepad as a keyboard and mouse, allowing you to interact with a Linux box running EMC2, which is used for controlling the mill, lathe, plasma torch, or a number of other fun and dangerous tools. Check out the video after the break. Adafruit dammitdarrell (YouTube)

Modder turns candy canisters into gaming console, retro Pong paddles (video)

This is the second time this week we've covered a modder getting an old-school game to run with the help of some unexpected hardware. And arguably, it's the simpler of the two tales. A fellow named John Graham-Cumming fashioned a game console out of little more than a pair of metal canisters, an Arduino Pro board, and a potentiometer -- all so he could play Pong on his TV. The rig (cutely dubbed the Cansole) actually consists of two controllers, with the secondary one housing just a potentiometer. The first has one, too, but also houses the Arduino Pro, along with a battery, A/V controls, and a button for selecting and firing in the game.  Et voilà ! 1970s arcade-style tennis for two. For a 90-second nostalgia break, head on past the break to see these vintage-looking paddles in action. CrunchGear John Graham-Cumming

Water-cooled, luggable PS3 offers semi-convenient gaming for your on-the-go lifestyle

We've seen plenty of handheld console mods, but only a few laptops -- most impressively, Ben Heck'ssleek PlayStation 3 -- and  PSHax  member Pirate recently finished his water-cooled take on the notebook PS3. The cooling system replaces the stock heatsinks, allowing for a slimmer design, and one much more polished than the last water-cooled version we saw. Weighing in at 15 pounds, it's also got a built-in keyboard and speakers, a 500GB hard drive, and a 720p / 1080i screen. If this sounds like your type of machine, Pirate's put it on eBay, where it's currently heading north of $1,500. He's not looking to make a profit, promising that after costs a portion of the selling price will go to server expenses at  PSHax , with another portion dedicated to tornado relief efforts in Joplin, Missouri. Check out the video after the break to see this beast in action.  PS3Hax ,  eBay

RSA SecureID hackers may have accessed Lockheed Martin trade secrets, cafeteria menus

RSA SecureID dongles add a layer of protection to everything from office pilates class schedules to corporate email accounts, with banks, tech companies, and even U.S. defense contractors using hardware security tokens to protect their networks. Following a breach at RSA in March, however, the company urged clients to boost other security methods, such as passwords and PIN codes, theoretically protecting networks from hackers that may have gained the ability to duplicate those critical SecureIDs. Now, Lockheed Martin is claiming that its network has come under attack, prompting RSA to issue 90,000 replacement tokens to Lockheed employees. The DoD contractor isn't detailing what data hackers may have accessed, but a SecureID bypass should clearly be taken very seriously, especially when that little keychain dongle is helping to protect our national security. If last month's Sony breachdidn't already convince you to beef up your own computer security, ...

Telecommunications device for the deaf gets hitched to a rotary phone, hacked to run Zork

In today's episode of "But will it run Zork?" a chap named Ulysses got the vintage game to run on a TDD (telecommunications device for the deaf) -- a project he built to show off at the Bay Area Maker Fairelast weekend. In a move we truly respect, he hunted down a rotary phone lifted straight out of the era when Zork was conceived (that would be the late '70s / early '80s). Then, he modified a modem so that the acoustically coupled TDD could be interfaced -- transmitting at a slow 45.5 baud to make it easy for even ponderous readers to keep up, one line at a time on the TDD's narrow display. Once this was sorted, things weren't exactly smooth sailing when Ulysses started fitting the compressed Zork story file into the system. At first, he tried using an Arduino Pro and an Arduino Mega, but found that neither had enough memory to accommodate the compressed Zork story file. Ultimately, he took a different tack and settled on an embeddable FitPC. We'd lo...

Arduino, magnet wire, and Android combine to create poor man's NFC (video)

Jealous of your Nexus S-owning friends and their fancy NFC chips after yesterday's Google Walletannouncement? Well tech tinkerer Joe Desbonnet has whipped up what he dubs "poor man's NFC" using an Arduino, some magnet wire, and any compass-equipped Android smartphone (which is almost all of them). By placing a coil of wire on the phone and connecting it to the DIYer's favorite microcontroller, Desbonnet was able to send data, albeit very slowly, to his HTC Desire running a special app to decode the signals. Granted, you're probably not going to see American Eagle mod their point of sale systems to talk to your phone's magnetometer, but it's still a neat trick. In fact, we'd break out our Arduino right now to give it a try, but our secret lair is strangely devoid of enameled copper wire. Check out the source link for instructions, and don't miss the video after the break. Random Tech Stuff

Sony says PlayStation Network will return to Asia, starting tomorrow

Good news, Asia -- the PlayStation Network is finally coming back. Today, Sony announced that it will restore its gaming network across the continent, more than a month after falling prey to a crippling data breach. The company's PSN services are already up and running across other parts of the world and, beginning tomorrow, will light up once again in Taiwan, Singapore, Malaysia, Indonesia, Thailand and even Japan, which had been harboring serious reservations about the network's security. Gamers in South Korea and Hong Kong, meanwhile, will have to wait a little longer before returning to normalcy, though Sony is hoping to completely resolve the issue by the end of the month. The company certainly seems eager to put this saga to bed, and for understandable reasons. The incident has already cost Sony an estimated $171 million in revenue -- not to mention the untold numbers of suddenly wary consumers. Bloomberg

StreakDroid 2.0.0 gives the gift of Gingerbread to Streak hackers

If you've been following along, you know that a phone enthusiast named DJ_Steve has kept the Dell Streak fresh, thanks to a series of hacked ROMs, dubbed StreakDroid. The latest version, 2.0.0 (or GingerStreak, if you're feeling cute) brings Gingerbread to the 5-inch smartphone -- expanding on the last ROM, which gave hackers the option of selecting Gingerbread's app launcher. As always, though, dear Steve has noted a handful of bugs in the ROM's early stages, including issues with the Superuser app, less-than-stellar graphics performance, and the fact that both GPS and 720p video recording require an engineering baseband and DSP to be flashed. As of this writing, all of the comments are from Streak owners eager to download this for themselves. We assume you are, too, so let us know how the new ROM works out for ya. MoDaCo

Sony Ericsson's Canadian online store hacked, more than 2,000 customers' data taken

The hackers just won't give poor Sony a break, will they? Following the infamous PSN breach last month and an attack on the company's Greek online music service earlier this week, Sony Ericsson has now seen another intrusion that extracted personal data of more than 2,000 Canadian Eshop customers. Fortunately, the company claims that passwords taken were encrypted and no credit card details were lost, but this is still worrisome nevertheless. Right now, the Eshop service has been taken off line -- for the sake of Sir Howard and his Japanese chums, let's just hope that this will be the last Sony breach we hear about.   The Star ,  BBC

Add GPS to your Viewsonic G-Tablet and test your soldering skills

If you picked up one of those G-Tablets, but are now suffering from buyer's remorse after realizing how much you miss GPS, there's a solution -- provided you have a strong DIY streak. It turns out Viewsonic set space aside on the Froyo-powered slate's motherboard to place a GPS receiver. Of course, if you even have to ask what flux is or what SMD stands for this is not the hack for you. And while apps that rely on 3G, such as Google Maps, won't work properly, offline navigators like Navigon and CoPilot should be just fine. If you're comfortable tearing open your device and poking at it with a hot iron, hit up the source link for a complete list of parts and some very detailed instructions... or, you could just buy a tablet that already has GPS.   XDA Developers Forum

New CyanogenMod lets you rule Android app permissions with an iron fist

We've recently seen Google crack down on rogue apps and patch some server-side security issues, but let's not forget Android does have a small measure of built-in security: app permissions. But as with those pesky EULAs, many users tend to breeze through the permissions screen. And Android forces even the most attentive readers to accept or deny  all  permissions requested by an app. But the newest nightly builds of the CyanogenMod custom ROM include a clever patch allowing users to grant and revoke permissions individually -- something like the TISSA security manager we're still awaiting. Obviously playing God with permissions can crash your applications: with great power comes great responsibility. But we figure if you're running aftermarket firmware on a rooted phone, you're comfortable experimenting. See how it works in the video after the break, then hit the source link to download. Androinica CyanogenMod

Visualized: Androidify avatar dance party (video)

Have your YouTube dance videos been lacking something? Can't quite put your finger on it? How 'bout another, more Android-y you to add some diversity to your  One, Two Step ? The folks who brought you the Androidify app have apparently enlisted a friend, his Android avatar, and a Kinect to bring you the above video. Not too shabby, but we'd be even more intrigued if he was rocking a black leotard and busting out  Mexican Breakfast , Beyonce-style. Check out the not-so-Fosse video after the break.   Less, But Better

Eee Pad Transformer gets overclocked to 1.4GHz, deemed less than stable

While many of you continue your quest for an Eee Pad Transformer, some folks, predictably, have already figured out how to overclock it. Netarchy over at the XDA forum posted a custom kernel allowing hackers to crank the tablet's clock speed to 1.4GHz, the same peak reached by the ViewSonic G Tablet. Beware, though, that performance at that speed has proven unreliable, so for now the dev recommends a more modest 1.2GHz to avoid data loss, a meltdown, and "injury of assorted puppies."Par for the course, really. Lilliputing xda-developers