Skip to main content

Posts

Showing posts with the label hacked

FaceNiff makes Facebook hacking a portable, one-tap affair (video)

Remember Firesheep? Well, the cookie snatching Firefox extension now has a more portable cousin called FaceNiff. This Android app listens in on WiFi networks (even ones encrypted with WEP, WPA, or WPA2) and lets you hop on to the accounts of anyone sharing the wireless connection with you. Right now it works with Facebook, Twitter, YouTube, and Nasza-Klasa (a Polish Facebook clone), but developer Bartosz Ponurkiewicz promises more are coming. You'll need to be rooted to run FaceNiff -- luckily, we had such a device laying around and gave the tap-to-hack app a try. Within 30 seconds it identified the Facebook account we had open on our laptop and had us posting updates from the phone. At least with Firesheep you had to sit down and open up a laptop, now you can hijack Twitter profiles as you stroll by Starbucks and it'll just look like you're sending a text message (but you wouldn't do that... would you?). One more image and a video are after the break. FaceNiff

Sony Pictures hacked by Lulz Security, 1,000,000 passwords claimed stolen

Oh, Sony -- not again. We've just received numerous tips that Lulz Security has broken into SonyPictures.com, where it claims to have stolen the personal information of over 1,000,000 users -- all stored (disgracefully) in plain text format. Lulz claims the heist was performed with a simple SQL injection -- just like we saw the last time around. A portion of the group's exploit is posted online in a RAR file, which contains over 50,000 email / password combos of unfortunate users. We've downloaded this file (at our own risk, mind you) and can verify these sensitive bits are now in the wild, though it remains unclear if what's published matches reality. In addition to user information, the group has blurted out over 20,000 Sony music coupons, and the admin database (including email addresses and passwords) for BMG Belgium employees. Fresh off the heels of the PlayStation Network restoration, we're guessing the fine folks in Sony's IT department are now surviving...

Pentagon says cyber attacks are acts of war: send us a worm, get a missle in return?

Well, the Pentagon is finally fed up with hackers picking on its buddies and foreign intelligence taking shots at its computer systems, and has decided that such cyber attacks can constitute an act of war. Of course, the powers that be won't be bombing you for simply sending them some spyware, but attempts to sabotage US infrastructure (power grids, public transit, and the like) may be met with heavy artillery. It's unclear how our government will identify the origin of an attack or decide when it's serious enough to start shooting, but Uncle Sam is looking to its allies to help create a consensus answer for those questions. The retaliatory revelation is a part of the Pentagon's new cyber strategy that'll be made public in June -- so saboteurs beware, your next internet incursion might get you an ICBM in your backyard. Wall Street Journal

RSA SecureID hackers may have accessed Lockheed Martin trade secrets, cafeteria menus

RSA SecureID dongles add a layer of protection to everything from office pilates class schedules to corporate email accounts, with banks, tech companies, and even U.S. defense contractors using hardware security tokens to protect their networks. Following a breach at RSA in March, however, the company urged clients to boost other security methods, such as passwords and PIN codes, theoretically protecting networks from hackers that may have gained the ability to duplicate those critical SecureIDs. Now, Lockheed Martin is claiming that its network has come under attack, prompting RSA to issue 90,000 replacement tokens to Lockheed employees. The DoD contractor isn't detailing what data hackers may have accessed, but a SecureID bypass should clearly be taken very seriously, especially when that little keychain dongle is helping to protect our national security. If last month's Sony breachdidn't already convince you to beef up your own computer security, ...

StreakDroid 2.0.0 gives the gift of Gingerbread to Streak hackers

If you've been following along, you know that a phone enthusiast named DJ_Steve has kept the Dell Streak fresh, thanks to a series of hacked ROMs, dubbed StreakDroid. The latest version, 2.0.0 (or GingerStreak, if you're feeling cute) brings Gingerbread to the 5-inch smartphone -- expanding on the last ROM, which gave hackers the option of selecting Gingerbread's app launcher. As always, though, dear Steve has noted a handful of bugs in the ROM's early stages, including issues with the Superuser app, less-than-stellar graphics performance, and the fact that both GPS and 720p video recording require an engineering baseband and DSP to be flashed. As of this writing, all of the comments are from Streak owners eager to download this for themselves. We assume you are, too, so let us know how the new ROM works out for ya. MoDaCo

Sony BMG Greece hacked, company's security woes continue

It's the  security  nightmare that just won't end, and right now there's got to be plenty of Sony executives beginning to wish someone would pinch them already. After taking quite a PR and financial beating over the PSN breach, now the Greek site of Sony BMG has been hacked and the account info of thousands of users has been posted online. According to the Sophos blog  Naked Security , the attack does not appear to have been particularly sophisticated and was carried out using an automated SQL injection tool that demands more patience than skill. While the data dump reveals the usernames, real names, and email addresses of registered SonyMusic.gr customers, other fields (including passwords and telephone numbers) are either empty or contain fake data -- suggesting the hack was not entirely successful. Here's hoping Sony takes this as an opportunity to seriously baton down those security hatches. Naked Security

HTC Sensation looks to have signed bootloader, custom ROMs look to be bummed

Did you think maybe HTC would change its ways after locking down the bootloader on the Thunderboltand Incredible S? Sorry, no. The upcoming Sensation looks to have been similarly afflicted, with Android Police  bringing the bad news that its internals are protected by HTC's private key. This will definitely prove to be an issue for those looking to run custom ROMs that are clean as a whistle, but something tells us the hackers shall overcome. They usually do.   Android Police

GameCube Fusion portable brings Wii aesthetics, GBA design to Nintendo's boxiest console (video)

It seems like there was a time, not that long ago, where we saw another new hand-crafted portable console every week, each one smaller and more impressive than those before. Those days are, sadly, gone and, whether you want to blame the short attention span of today's youth or simply conclude that everyone's too busy playing  Angry Birds , it's a sad fact. Modder Ashen is bucking the trend, creating what he calls the GameCube Fusion. It's a hand-built portable GameCube that plays (hopefully legally acquired) titles from SD card via both WiiKey and Gecko, offering full controls on-board plus an external controller port, all kept cool by a laptop-sourced fan that sounds powerful enough to make the thing hover,  F-Zero -style. It's far smaller than 2009's NCube, but the omission of a battery pack means it won't be traveling far. For those who want to know more, every detail will be revealed in the 12 minute video embedded just below -- if you can keep focused ...

Sony misses promised PlayStation Network and Qriocity restoration date, begs for more patience

Whoops. If you'll recall, Sony held what can only be described as an emergency press event in Japan a week ago in order to issue a number of assurances about the resumption of service as it relates to the PlayStation Network and Qriocity. Seven days later, things are still as dead as they were pre-Cinco de Mayo. This evening, the company's Senior Director of Corporate Communications Patrick Seybold punched out a quick update to let the world know that they could actually leave the house and find something else to entertain 'em -- like it or not, PSN isn't coming back online today. The reason? On May 1st, Sony was apparently "unaware of the extent of the attack on Sony Online Entertainment servers," and now, it's spinning its wheels in order to restore security on the network and "ensure" that user data is safe. Mr. Seybold seems to understand that you're overly anxious about getting back into the swing of things, and he's even going so f...

Modder miniaturizes 5.25-inch disk drive, brings microSD support to Atari 400

You aren't looking at a retro microSD card reader, you're looking at an Atari-compatible serial disk drive that just  happens  to use microSD in lieu of 5.25-inch floppies. In a Zork inspired fit of nostalgia (we've all been there), hardware modder Rossum paired up an Atari connector with a LPC1114 microcontroller, capable of emulating up to eight Atari drives, managed by a custom, auto-booting app. The whole package is neatly packed in to a tiny 3D printed replica of the original Atari 810 disk drive, and is available for sale never -- but don't let that stop you: Rossum's schematics are free for the taking. The word's biggest little Atari drive is just a DIY away. Rossum

Sony offers free Debix identify theft protection for PSN and Qriocity hack victims in US

Sony's "Welcome Back" package of free software and PlayStation Plus subscriptions was a nice gesture, but it won't help you if your credit card gets fraudulently charged in the aftermath of the PlayStation Network debacle. That, however, is exactly what Debix is for. Sony's announced that it will provide a complimentary one-year subscription to Debix's "AllClear ID Plus" identity theft protection service to all PlayStation Network and Qriocity account holders in the United States, which will attempt to protect your personal data from harm, by both monitoring known criminal activity for your private digits and providing up to $1 million in ID theft insurance coverage. We've never used Debix, so we can't vouch for its reliability, and this particular plan admittedly doesn't look  quite  as comprehensive as the one Debix offers regular customers for $10 a month. Still, some peace of mind is a heck of a lot better than none, so we think we m...

Sony's Kaz Hirai addresses PlayStation Network hack, we're liveblogging

Sony's PlayStation Network has been down for over a week, and it's a royal mess for all involved -- as you've no doubt heard, an external intrusion by unknown hackers compromised the personal information (supposedly including everything but credit card numbers) of potentially millions of users. This morning, Sony VP Kaz Hirai (formerly of the PlayStation division) will address the world from the company's headquarters in Japan, and our friends at Engadget Japanese are on the scene to bring us first-hand details in just a few minutes. Additionally, there appears to be an official livestream that will begin at 1AM ET, so keep it locked right here and potentially find some video at our source link. Update:  We're hearing that Sony's "goodwill gesture" may not be an incredibly significant one -- affected users can expect a free 30-day subscription to PlayStation Plus and a free software download of some sort, while Qriocity customers will get ...

Skype for Android vulnerable to hack that compromises personal info

If you didn't already have enough potential app privacy leaks to worry about, here's one more --  Android Police  discovered that Skype's Android client leaves your personal data wide open to assault. The publication reports that the app has SQLite3 databases where all your info and chat logs are stored, and that Skype forgot to encrypt the files or enforce permissions, which seems to be a decision akin to leaving keys hanging out of the door. Basically, that means a rogue app could grab all your data and phone home -- an app much like Skypwned. That's a test program  Android Police  built to prove the vulnerability exists, and boy, oh boy does it work -- despite only asking for basic Android storage and phone permissions, it instantly displayed our full name, phone number, email addresses and a list of all our contacts without requiring so much as a username to figure it out.  Android Police  says Skype is investigating the issue now...

SparkFun intros IOIO for Android, a hack-free breakout box to get your mind spinning

Meet any seasoned techie, and they'll likely spin whimsical tales of computing's early days, and the challenge of finding a practical use for a device with seemingly limitless potential (you know, like feeding your cat while you sleep). A new product from SparkFun promises to bring this old-school awesomeness into the smartphone age: introducing IOIO (pronounced yo-yo), a breakout box that enables any Android 1.5+ device to control electronic circuits from within Android's applications. Designed in collaboration with Google, Spark's PCB connects to your phone over USB, working its magic through a Java library that hooks into your apps. This DIY paradise will begin shipping in a few weeks, and can be yours for $49.95 on pre-order. We've already witnessed some clever mods with IOIO, and when it sent a real alarm clock ringing, we couldn't help but smile. Crack one yourself after the break. ...