Apr 10, 2008

=== Announcement ===

0 comments
Posted in

Sorry that you all could not comment, I have fixed it now so comment. Enjoy



=== Irey  ===

Breaking into a power station in three easy steps

0 comments
Posted in ,
"I will tell (you) how to break into a nuclear reactor," Ira Winkler, president of security firm ISAG said as he launched into his presentation on "How to Take Down the Power Grid" at RSA 2008 on Tuesday night.

"Frankly, it's really easy to break into the power grid," he said. "It happens all the time."

First, you set up a Web server that downloads spyware onto the computers that visit.

Second, you send an e-mail to people who work inside a power station that entices them to click on a hyperlink to the Web server with the spyware. Warning them that their human resources benefits are going to be cut and sending them to a Web site with "hr.com" in the domain would work, according to Winkler, who said he has done this several times in company-approved penetration tests.

Third, you wait as the recipients--and everyone else they forwarded the e-mail to--visit the server and get infected.

"Then we had full system control," he said. "Once the malware was downloaded onto their systems...we could see the screens and manipulate the cursors."

It took about a day to set up the attack and was effective within minutes, according to Winkler.

"It had to be shut down after a couple of hours because it was working too well," he said.

This is akin to social engineering attacks that happen all the time, but this attack has more far-reaching consequences than most such attacks.

Power stations running special SCADA control software have the perception that they are more secure than other networked systems. However, they are just as vulnerable because they are connected to the Internet and run on computers that also run Windows NT, he said.

"Things are really this bad," Winkler said. "I'm not exaggerating.

Face book with chat feature

1 comments
Posted in
Facebook fans are getting a new toy this week. With the launch of Facebook Chat, users will be able to communicate in real time with friends on the site.

The new Facebook Chat interface allows users to see which friends are online. The social networking giant, which boasts more than 69 million active users, has always had a built-in message system that resembles e-mail.

But for the first time, the site will release a chat system so friends can type back and forth instantly.

Because Facebook users already have lists of friends, they won't need to build buddy lists. At the bottom right of any Facebook page, users can click an "Online Friends" button that will indicate which friends are available to chat.

Facebook Chat only allows for one-to-one conversations. Users will be able to view recent conversations, but the chats won't be logged permanently, and users will be able to clear that chat history any time.

Facebook users will also have the option of keeping the conversation on the bottom of the screen or creating a pop-up window they can move. A chat window will also display Mini-Feed stories, which are notices concerning other friends' Facebook activities. Kool dhoo

Mar 28, 2008

Facebook got Hacked!!

2 comments
Posted in
facebook12.jpgYap you heard it right. Facebook has been hacked, with a technician managing to exploit a recent security update and view private pictures of people such as Paris Hilton and Mark Zuckerberg.

After Facebook introduced new options and a new privacy interface on 19 March, Canadian technician Byron Ng managed to exploit security holes and access private details.
Normally it is not possible for users to view photos and details which the owner does not give permission for them to access. With his computer expertise, Ng managed to breach security barriers to do this until Facebook installed a bug fix to prevent it from happening.

"The recent Facebook breach highlights how the social networking world is still evolving and continues to harbour a host of potential threats to personal and sensitive information,"
"And it's not new - this exploit mirrored MySpace's breach in January. Users accessing social networking sites from work leave their organization vulnerable to hackers."

So Facebook users beware of your personal stuff. Nothing is safe on the internet.

My Blog is Still Up and Running

0 comments
Posted in
I thought my blog will be hacked now ey guess not hehehe?????!!!!!. Ya someone told he/she is going to hack it if I don’t do what he/she tell me. For that person I really sorry. I’m not going to do it. heheh.

== Irey ==

MacBook Air HACKED.

0 comments
Posted in

Most of the people say Mac can’t be hacked. Guess again???apple.gif



A team of security researchers has won $10,000 for hacking a MacBook Air in two minutes using an undisclosed Safari vulnerability.
IDG News Service is camped out at CanSecWest in lovely Vancouver, Canada, and has chronicled the exploits (gotta love security puns) of Charlie Miller, Jake Honoroff, and Mark Daniel of Independent Security Evaluators during the Pwn to Own contest sponsored by TippingPoint. The team was able to gain control of a MacBook Air on the second day of the hacking competition, which pitted the Air against Windows Vista and Ubuntu machines.

No one was able to execute code on any of the systems on Wednesday, the first day of the contest, when hacks were limited to over-the-network techniques on the operating systems themselves. But on the second day, the rules changed to allow attacks delivered by tricking someone to visit a maliciously crafted Web site, or open an e-mail. Hackers were also allowed to target "default installed client-side applications," such as browsers.
The team had attack code already set up on a Web site, and was able to gain access to the MacBook Air and retrieve a file after judges were "tricked" into visiting the site. According to the TippingPoint DVLabs blog, a newly discovered vulnerability in Safari was used to gain control of the Air.

The contest rules stipulated that winners immediately sign a nondisclosure agreement relating to their technique, so that the vulnerability could be disclosed to the vendor, and TippingPoint said Apple has been informed of the vulnerability.

Last year's contest was won by exploiting a QuickTime vulnerability, which was patched by Apple in less than two weeks. As of the time I posted this, no one had gained control of the Vista or Ubuntu machines, but I'll update later as the results come in over the rest of the afternoon

Photoshop Online version

0 comments
Posted in ,
46009.jpgOky this is kool. Adobe maker of the popular photo-editing software Photoshop "Free" on Thursday launched a basic version available for free online.

San Jose, Calif.-based Adobe Systems Inc. says it hopes to boost its name recognition among a new generation of consumers who edit, store and share photos online.

While Photoshop is designed for trained professionals, Adobe says Photoshop Express, which it launched in a "beta" test version, is easier to learn.
User comments will be taken into account for future upgrades. Photoshop Express will be completely Web-based so consumers can use it with any type of computer, operating system and browser. And, once they register, users can get to their accounts from different computers. Web-based software is increasingly popular.
Many kinds of software are available for use online in a trend known as "software as a service," or "cloud computing." The earliest were e-mail programs, but they now include services to create and manage content and even whole operating systems.
And they don't require time-consuming upgrades because they're maintained by the service provider.
Photoshop enters the online photo-management arena many years after such services first appeared. Some companies have already made a big name for themselves, like 9-year-old storage solution Shutterfly Inc., photo-editing service Picnik or image-sharing site Photobucket Inc.
Adobe says providing Photoshop Express for free is part marketing and part a strategy to create up-sell opportunities. It hopes some customers will move from it to boxed software like its $99 Photoshop Elements or to a subscription-based version of Express that's in the works.

http://www.photoshop.com/express