<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ClubHack &#187; Attacks</title>
	<atom:link href="http://www.clubhack.com/category/news/attacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.clubhack.com</link>
	<description></description>
	<lastBuildDate>Mon, 02 Apr 2012 11:23:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Hacks in last few days</title>
		<link>http://www.clubhack.com/hacks-in-last-few-days/</link>
		<comments>http://www.clubhack.com/hacks-in-last-few-days/#comments</comments>
		<pubDate>Sun, 02 Oct 2011 02:28:35 +0000</pubDate>
		<dc:creator>VishalK™</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1454</guid>
		<description><![CDATA[It seems that hacking activity is on continuous rise. It appears that the guys in the wild do not take any break or rather there is no specific season for hacking; its 24&#215;7 on all 365 days&#8230;.. Amongst others, following are some of the recent hacking activities: Harvard University website hacked by Syria protesters 75 [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>It seems that hacking activity is on continuous rise. It appears that the guys in the wild do not take any break or rather there is no specific season for hacking; its 24&#215;7 on all 365 days&#8230;..</p>
<p>Amongst others, following are some of the recent hacking activities:</p>
<ul>
<li><a class="zem_slink" title="Harvard University" href="http://www.harvard.edu/" rel="homepage">Harvard University</a> website hacked by Syria protesters</li>
<li>75 Indian Govt and University Sites hacked including Patiala Police</li>
<li>The Council on Governmental Ethics Laws (COGEL) hacked and complete database dumped</li>
<li>Anonymous Austria post via the official Twitter account about 25,000 records <a class="zem_slink" title="Federal Police (Austria)" href="http://www.bundespolizei.gv.at/" rel="homepage">Austrian police</a> officers</li>
<li>Mysql.com website hacked</li>
<li><a class="zem_slink" title="USA Today" href="http://www.usatoday.com/" rel="homepage">USA Today</a> Twitter account hacked</li>
<li>700,000 sites on Inmotion Hosting Server hacked</li>
<li><a class="zem_slink" title="Core Security Technologies" href="http://www.coresecurity.com" rel="homepage">Core Security Technologies</a> website defaced</li>
</ul>
<p>Phew&#8230; there are many more and still counting</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://geeks.thedailywh.at/2011/09/26/usa-today-twitter-hack-of-the-day/">USA Today Twitter Hack of the Day</a> (geeks.thedailywh.at)</li>
<li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-1009_3-20111923-83/harvard-web-site-hacked-with-pro-syria-message/?part=rss&amp;subj=news">Harvard Web site hacked with pro-Syria message</a> (news.cnet.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=a719a2c2-6168-41ce-9495-ea11b03bc531" alt="Enhanced by Zemanta" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/hacks-in-last-few-days/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IGI airport shutdown was due to cyber attack</title>
		<link>http://www.clubhack.com/igi-airport-shutdown-was-due-to-cyber-attack/</link>
		<comments>http://www.clubhack.com/igi-airport-shutdown-was-due-to-cyber-attack/#comments</comments>
		<pubDate>Mon, 26 Sep 2011 06:05:33 +0000</pubDate>
		<dc:creator>ClubHack</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Airline]]></category>
		<category><![CDATA[ARINC]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[Cyberwarfare]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1432</guid>
		<description><![CDATA[Around 3 months back we heard a news of &#8220;technical snag&#8221; which caused chaos in T3 of IGI airpot delhi. The internal team was doing invetigation since then and now they have concluded that the &#8220;technical snag&#8221; was a cyber attack. Its is believed that its was a malicous script sent from remote As per Indian Express, CBI [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Around 3 months back we heard a news of <a href="http://articles.economictimes.indiatimes.com/2011-06-29/news/29717105_1_check-in-counters-check-in-system-technical-problem">&#8220;technical snag&#8221; which caused chaos in T3 of IGI airpot delhi</a>. The internal team was doing invetigation since then and now they have concluded that the &#8220;technical snag&#8221; was a <a class="zem_slink" title="Cyberwarfare" href="http://en.wikipedia.org/wiki/Cyberwarfare" rel="wikipedia">cyber attack</a>. Its is believed that its was a malicous script sent from remote</p>
<p>As per <a href="http://www.indianexpress.com/story-print/851365/">Indian Express</a>, CBI registering a case under the IT Act in June and started investigation. Investigators of CBI says that “<a class="zem_slink" title="Malware" href="http://en.wikipedia.org/wiki/Malware" rel="wikipedia">malicious code</a>” was in the form of “attack scripts”, which means a programme was written by an expert to exploit the system’s security weakness.</p>
<p>The check-in counters, transfers counters and boarding gates at the IGI are operated using the Common Use Passengers Processing System (CUPPS), maintained by Aeronautical Radio Incorporated (<a class="zem_slink" title="ARINC" href="http://www.arinc.com/" rel="homepage">ARINC</a>). The CUPPS operates on a common software-and-hardware platform that integrates all information such as an airline’s reservation system, the expected time of departure and the capacity at waiting lounges. The problem in CUPPS started at 2.30 am on June 29 due to which check-in counters of all airlines at T3 became non-operational.</p>
<p>“This forced the airlines to opt for manual check-in and as a result passengers had to wait. There are around 172 CUPPS counters and only a third were functioning online,” said an official. The investigation revealed that someone had hacked into the main server of the CUPPS and introduced a virus.</p>
<p>It took nearly 12 hours for the experts — from ARINC, <a class="zem_slink" title="Wipro Technologies" href="http://www.wipro.com/index.htm" rel="homepage">Wipro</a> and DIAL — to restore the system. The CBI was also called in as officials suspected it was a security breach. “We found that there were serious security lapses,” said a CBI official.</p>
<p>&nbsp;</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=fdcdd7e1-c556-49aa-aa28-1d2ad5ddad9a" alt="Enhanced by Zemanta" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/igi-airport-shutdown-was-due-to-cyber-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Oracle released out of cycle patch for Apache &#8220;HTTP Killer&#8221; bug</title>
		<link>http://www.clubhack.com/oracle-released-out-of-cycle-patch/</link>
		<comments>http://www.clubhack.com/oracle-released-out-of-cycle-patch/#comments</comments>
		<pubDate>Sun, 18 Sep 2011 08:37:32 +0000</pubDate>
		<dc:creator>Sorabh Kalra</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Apache HTTP Server]]></category>
		<category><![CDATA[National Vulnerability Database]]></category>
		<category><![CDATA[Oracle HTTP Server]]></category>
		<category><![CDATA[Patch]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1411</guid>
		<description><![CDATA[Oracle issued an emergency patch to fix a denial of service(DoS) vulnerability in Oracle HTTP server products that are based on the Apache Web server 2.0 and 2.2. Attack Details &#8212;&#8212;&#8212;&#8212;&#8212;&#8211; With this attack any exploiter can remotely send large chunk of data in the header without any authentication or requiring  any username and password. [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="zemanta-img" style="margin: 1em">
<div class="wp-caption alignright" style="width: 240px">
	<a href="http://www.flickr.com/photos/43394187@N00/125245043"><img src="http://farm1.static.flickr.com/45/125245043_0080575160_m.jpg" alt="Denial of Service Attack" width="240" height="160" /></a>
	<p class="wp-caption-text">Image by kryptyk via Flickr</p>
</div>
</div>
<p>Oracle issued an <a href="http://www.oracle.com/technetwork/topics/security/alert-cve-2011-3192-485304.html">emergency patch</a> to fix a denial of service(DoS) vulnerability in Oracle HTTP server products that are based on the <a class="zem_slink" title="Apache HTTP Server" href="http://en.wikipedia.org/wiki/Apache_HTTP_Server" rel="wikipedia">Apache Web server</a> 2.0 and 2.2.</p>
<p>Attack Details<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
With this attack any exploiter can remotely send large chunk of data in the header without any authentication or requiring  any username and password. When the server tries to process the data, memory and CPU resources are exhausted, resulting in a <a class="zem_slink" title="Denial-of-service attack" href="http://en.wikipedia.org/wiki/Denial-of-service_attack" rel="wikipedia">DoS attack</a>. This bug is known since long but a  security researcher [kingscope] posted an &#8220;<a href="http://seclists.org/fulldisclosure/2011/Aug/175">Apache Killer</a>&#8221; Perl script on <a class="zem_slink" title="Full disclosure" href="http://en.wikipedia.org/wiki/Full_disclosure" rel="wikipedia">Full Disclosure mailing list</a> in August; which made it easier to launch such attacks.</p>
<p>National Vulnerability Database (NVD) has assigned a <a class="zem_slink" title="CVSS" href="http://en.wikipedia.org/wiki/CVSS" rel="wikipedia">Common Vulnerability Scoring System</a> (CVSS) score of 7.8 to this vulnerability &#8211; <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3192">Common Vulnerability and Exposures -2011-3192</a>.</p>
<p>Oracle strongly recommended customers to apply Security patch as soon as possible since this patch is released out of the regular quarterly cycle of updates.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/oracle-released-out-of-cycle-patch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Goof up in Chinese Military show exposes &#8220;cyberwar&#8221; activities</title>
		<link>http://www.clubhack.com/goof-up-in-chinese-military-show-exposes-cyberwar-activities/</link>
		<comments>http://www.clubhack.com/goof-up-in-chinese-military-show-exposes-cyberwar-activities/#comments</comments>
		<pubDate>Tue, 23 Aug 2011 02:31:30 +0000</pubDate>
		<dc:creator>ClubHack</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Cyberwarfare]]></category>
		<category><![CDATA[Falun Gong]]></category>
		<category><![CDATA[Government of the People's Republic of China]]></category>
		<category><![CDATA[United States]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1390</guid>
		<description><![CDATA[A chinese documentary on military activities by mistake exposed a lot which was not intended. Check out the video at 36s onwards. You&#8217;ll notice a nice UI (probably written in delphi) being used to launch attack against an IP. The large writing at the top says &#8220;Select Attack Target.&#8221; Next, the demonstrator choose an IP address to attack [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>A chinese documentary on military activities by mistake exposed a lot which was not intended.</p>
<p><iframe src="http://www.youtube.com/embed/L_Wu1HlZbBk" frameborder="0" width="560" height="345"></iframe></p>
<p>Check out the video at 36s onwards. You&#8217;ll notice a nice UI (probably written in delphi) being used to launch attack</p>
<p><a href="http://clubhack.com/wp-content/uploads/2011/08/US-IP-in-attack-from-china.jpg"><img class="aligncenter size-medium wp-image-1391" title="IP used in the text box belongs to an American university." src="http://clubhack.com/wp-content/uploads/2011/08/US-IP-in-attack-from-china-300x210.jpg" alt="China exposed" width="300" height="210" /></a></p>
<p>against an IP. The large writing at the top says &#8220;Select Attack Target.&#8221; Next, the demonstrator choose an IP address to attack from (it belongs to an American university). If you dig more online, you&#8217;ll find that the compromised IP 138.26.72.17 belongs to the <a class="zem_slink" title="University of Alabama at Birmingham" href="http://www.UAB.edu/" rel="homepage">University of Alabama in Birmingham</a> (UAB).</p>
<p>The documentary was intended to praise the wisdom Chinese military strategists, and a typical condemnation of the United States, but accidentally it exposed the intent and activities Chinese Military University do.</p>
<p>As per  Jason Ma, a commentator for New Tang Dynasty Television: &#8220;This is the first time we see clearly that one of the top Chinese military universities is doing this research and developing software for cyber-attacks. There&#8217;s solid proof of it in this video&#8221;</p>
<p>Check out the full report by <a href="http://www.theepochtimes.com/n2/china-news/slip-up-in-chinese-military-tv-show-reveals-more-than-intended-60619.html" target="_blank">TheEpochTimes</a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=660b690b-b390-4912-9689-afcb96b5696b" alt="Enhanced by Zemanta" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/goof-up-in-chinese-military-show-exposes-cyberwar-activities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>China suffered half a million cyber attacks last year</title>
		<link>http://www.clubhack.com/china-suffered-half-a-million-cyber-attacks-last-year/</link>
		<comments>http://www.clubhack.com/china-suffered-half-a-million-cyber-attacks-last-year/#comments</comments>
		<pubDate>Thu, 11 Aug 2011 16:59:45 +0000</pubDate>
		<dc:creator>ClubHack</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[Cyberwarfare]]></category>
		<category><![CDATA[India]]></category>
		<category><![CDATA[United States]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1374</guid>
		<description><![CDATA[As per china daily, last year china has suffered nothing less than 493000 cyber attacks. This was claimed  in a report by the country&#8217;s National Computer Network Emergency Response Technical Team/Coordination Center (CNCERT/CC) According to the report, 14.7% of the attacks came from US where as 8% came from Indian IPs. Hackers tampered with nearly [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>As per <a href="http://www.chinadaily.com.cn/usa/china/2011-08/09/content_13082671.htm" target="_blank">china daily</a>, last year china has suffered nothing less than 493000 cyber attacks. This was claimed  in a report by the country&#8217;s National Computer Network Emergency Response Technical Team/Coordination Center (CNCERT/CC)</p>
<p>According to the report, 14.7% of the attacks came from US where as 8% came from Indian IPs.</p>
<blockquote><p>Hackers tampered with nearly 35,000 web pages &#8212; including 4,635 government websites &#8212; in the past year, the report said, up 67.6 percent from a year earlier. It said 60 percent of websites of ministry-level government departments are at risk of being hacked.</p></blockquote>
<p>Personally not sure how much to trust this news.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=82047ea8-c16c-4944-9424-e4e62dc3ba7e" alt="Enhanced by Zemanta" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/china-suffered-half-a-million-cyber-attacks-last-year/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>U.N. hit by biggest ever cyber attacks uncovered</title>
		<link>http://www.clubhack.com/u-n-hit-by-biggest-ever-cyber-attacks-uncovered/</link>
		<comments>http://www.clubhack.com/u-n-hit-by-biggest-ever-cyber-attacks-uncovered/#comments</comments>
		<pubDate>Wed, 03 Aug 2011 09:48:15 +0000</pubDate>
		<dc:creator>ClubHack</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Cyberwarfare]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[United Nations]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1355</guid>
		<description><![CDATA[Security experts from McAfee have discovered the biggest series of cyber attacks to date. This one involves the infiltration of the networks of 72 organizations including the United Nations, governments and companies around the world. McAfee reported a five year long attack which affects # Govt of 1.  US 2. India 3. Taiwan 4. South [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Security experts from McAfee have discovered the biggest series of <a class="zem_slink" title="Cyberwarfare" href="http://en.wikipedia.org/wiki/Cyberwarfare" rel="wikipedia">cyber attacks</a> to date. This one involves the infiltration of the networks of 72 organizations including the <a class="zem_slink" title="United Nations" href="http://en.wikipedia.org/wiki/United_Nations" rel="wikipedia">United Nations</a>, governments and companies around the world.</p>
<p>McAfee reported a five year long attack which affects</p>
<p># Govt of</p>
<p>1.  US<br />
2. India<br />
3. Taiwan<br />
4. South Korea<br />
5. Canada</p>
<p>etc</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Full report @ <a href="http://in.reuters.com/article/2011/08/03/idINIndia-58594520110803">http://in.reuters.com/article/2011/08/03/idINIndia-58594520110803</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://gizmodo.com/5827187/operation-rat-is-the-largest-cyber-attack-ever-uncovered">Operation Shady Rat Is The Largest Cyber Attack Ever Uncovered [Hacking]</a> (gizmodo.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.guardian.co.uk/technology/2011/aug/03/biggest-series-cyber-attacks-uncovered&amp;a=50587562&amp;rid=a28177a4-c2aa-4e0a-8c31-4ea899ce549e&amp;e=e727418211f6af9fcfa661f498ad6dcc">Biggest series of cyber-attacks in history uncovered</a> (guardian.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.telegraph.co.uk/technology/8678492/Hackers-target-72-organisations-in-biggest-cyber-attack-in-history.html&amp;a=50586717&amp;rid=a28177a4-c2aa-4e0a-8c31-4ea899ce549e&amp;e=aa4af40ae5e6b4d833000ed46123101f">Hackers target 72 organisations in &#8216;biggest cyber attack in history&#8217;</a> (telegraph.co.uk)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=a28177a4-c2aa-4e0a-8c31-4ea899ce549e" alt="Enhanced by Zemanta" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/u-n-hit-by-biggest-ever-cyber-attacks-uncovered/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TDL-4 botnet traps 4.5 million PC&#8217;s</title>
		<link>http://www.clubhack.com/tdl-4-botnet-traps-4-5-million-pcs/</link>
		<comments>http://www.clubhack.com/tdl-4-botnet-traps-4-5-million-pcs/#comments</comments>
		<pubDate>Fri, 01 Jul 2011 13:32:46 +0000</pubDate>
		<dc:creator>Sorabh Kalra</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[tdl-4]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1326</guid>
		<description><![CDATA[Security researchers [Sergey Golovnoav &#38; Igor Soumenkov] at Kaspersky Lab have posted a detailed analysis of new botnet called TDL-4 and calling it as &#8211;&#62;  the one that might just be &#8220;indestructible&#8221;. TDL-4 compared to previous versions is an updated algorithm encrypting the protocol used for communication between infected computers and botnet command and control [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="zemanta-img" style="margin: 1em">
<div class="wp-caption alignright" style="width: 128px">
	<a href="http://commons.wikipedia.org/wiki/File:Malware_logo.png"><img src="http://upload.wikimedia.org/wikipedia/commons/7/7a/Malware_logo.png" alt="I constructed this image using :image:Computer..." width="128" height="128" /></a>
	<p class="wp-caption-text">Image via Wikipedia</p>
</div>
</div>
<p><a href="http://www.securelist.com/en/analysis/204792180/TDL4_Top_Bot">Security researchers [Sergey Golovnoav &amp; Igor Soumenkov] at Kaspersky Lab</a> have posted a detailed analysis of new <a class="zem_slink" title="Botnet" rel="wikipedia" href="http://en.wikipedia.org/wiki/Botnet">botnet</a> called  TDL-4 and calling it as &#8211;&gt;  the one that might just be &#8220;indestructible&#8221;. TDL-4 compared to previous versions is an  updated algorithm encrypting the protocol used for communication between  infected computers and botnet command and control servers.</p>
<p>TDL-4 is distributed via adult sites, bootleg websites, and video and file storage  services where affiliates receive between $20 to $200 for every 1,000 installations of  TDL. The [TDL-4] botnet have already infected  more than 4.5 million computers and is    used by hackers to manipulate adware, search engines, to provide    anonymous internet access and acts as a launch pad for other malware&#8217;s.</p>
<p>TDL loads into the MBR and messes with Windows memory even before the OS loads, injecting malware right into Windows right from the start when there is no security at place. [MBR: <a class="zem_slink" title="Master boot record" rel="wikipedia" href="http://en.wikipedia.org/wiki/Master_boot_record">Master Boot Record</a> is responsible for bootstrapping/loading  the OS].</p>
<p>As per Kaspersky Labs &#8220;key threat&#8221; from TDL-4 type botnet is that even if the    control servers are seized and shut down, botnet owners will not loose complete control because    of its <a class="zem_slink" title="Peer-to-peer" rel="wikipedia" href="http://en.wikipedia.org/wiki/Peer-to-peer">peer to peer networking</a> capabilities.</p>
<p>TDL seems to be dodgy, well planned and smartly implemented and can be a tough analysis problem for security researchers. But History tells us its the ethical guys or investigators/security researchers have taken down all malware&#8217;s sooner or later and the challenge is open again for them.</p>
<p>Note:</p>
<ul>
<li> <a class="zem_slink" title="Conficker" rel="wikipedia" href="http://en.wikipedia.org/wiki/Conficker">Conficker</a> was taken down  last year.</li>
<li><a href="http://clubhack.com/rustock-botnet-goes-silent-2/">Rustock botnet</a> [world's biggest source  of <a class="zem_slink" title="E-mail spam" rel="wikipedia" href="http://en.wikipedia.org/wiki/E-mail_spam">SPAM</a>] was    shut down after <a class="zem_slink" title="Microsoft" rel="geolocation" href="http://maps.google.com/maps?ll=47.6395972222,-122.12845&amp;spn=1.0,1.0&amp;q=47.6395972222,-122.12845%20%28Microsoft%29&amp;t=h">Microsoft</a> and US authorities  located and seized its control    servers.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/tdl-4-botnet-traps-4-5-million-pcs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sosasta attacked in a &#8220;sasta&#8221; way</title>
		<link>http://www.clubhack.com/sosasta-attacked-in-a-sasta-way/</link>
		<comments>http://www.clubhack.com/sosasta-attacked-in-a-sasta-way/#comments</comments>
		<pubDate>Wed, 29 Jun 2011 02:33:24 +0000</pubDate>
		<dc:creator>ClubHack</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Groupon]]></category>
		<category><![CDATA[password]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1310</guid>
		<description><![CDATA[Sosasta (Indian subsidiary of GrounOn) got compromised in a very easy &#38; sasta(cheap) way. A simple Google query exposed there database of  3,00,000 usernames and password. God knows when people will understand basic security of hashing the password. This si being covered in OWASP TOP 10 from many years (See https://www.owasp.org/index.php/Top_10_2010-Insecure_Cryptographic_Storage) &#160; Discovered by: Australian security [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Sosasta (Indian subsidiary of GrounOn) got compromised in a very easy &amp; sasta(cheap) way.</p>
<p><a href="http://clubhack.com/wp-content/uploads/2011/06/sosasta2.png"><img class="alignleft size-full wp-image-1311" title="sosasta2" src="http://clubhack.com/wp-content/uploads/2011/06/sosasta2.png" alt="" width="600" height="107" /></a></p>
<p>A simple Google query exposed there database of  3,00,000 usernames and password. God knows when people will understand basic security of hashing the password. This si being covered in <a class="zem_slink" title="OWASP" rel="wikipedia" href="http://en.wikipedia.org/wiki/OWASP">OWASP</a> TOP 10 from many years (See <a href="https://www.owasp.org/index.php/Top_10_2010-Insecure_Cryptographic_Storage">https://www.owasp.org/index.php/Top_10_2010-Insecure_Cryptographic_Storage</a>)</p>
<p>&nbsp;</p>
<p><strong>Discovered by:</strong> Australian security consultant Daniel Grzelak</p>
<p><strong>First reporte to: </strong><a href="http://risky.biz/sosasta" target="_blank">http://risky.biz/sosasta</a></p>
<p><strong>Company&#8217;s response:</strong> Groupon sent an advisory mail to all customers requesting passwod change</p>
<p>&nbsp;</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://techie-buzz.com/tech-news/groupon-india-sosasta-com-suffers-security-issue-user-account-information-possibly-compromised.html">Groupon India (SoSasta.com) Suffers Security Issue, User Account Information Possibly Compromised</a> (techie-buzz.com)</li>
<li class="zemanta-article-ul-li"><a href="http://go.theregister.com/feed/www.theregister.co.uk/2011/06/28/groupon_india_privacy_breach/">Groupon India publishes 300,000 user passwords</a> (go.theregister.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=e8f36e5e-4b9a-4edc-9184-3f285524d3f2" alt="Enhanced by Zemanta" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/sosasta-attacked-in-a-sasta-way/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sega Database Pwned, Account Information Compromised</title>
		<link>http://www.clubhack.com/sega-database-pwned-account-information-compromised/</link>
		<comments>http://www.clubhack.com/sega-database-pwned-account-information-compromised/#comments</comments>
		<pubDate>Tue, 21 Jun 2011 05:48:28 +0000</pubDate>
		<dc:creator>ClubHack</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Bethesda Maryland]]></category>
		<category><![CDATA[Codemasters]]></category>
		<category><![CDATA[Information sensitivity]]></category>
		<category><![CDATA[Nintendo]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[Plain text]]></category>
		<category><![CDATA[Sega]]></category>
		<category><![CDATA[Sony]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1305</guid>
		<description><![CDATA[Seems like all the attackers have started targeting games industry. After breaking into Sony(multiple times), Nintendo, Bethesda, Codemasters and Epic,  this time they have infiltrated into SEGA. As per the mail sent out to sega customers Dear ___, As you may be aware, the SEGA Pass system has been offline since yesterday, Thursday 16 June. Over the last 24 hours [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="zemanta-img" style="margin: 1em; display: block;">
<div class="wp-caption alignright" style="width: 126px">
	<a href="http://www.last.fm/music/SEGA"><img title="SEGA" src="http://userserve-ak.last.fm/serve/126/48547407.jpg" alt="SEGA" width="126" height="126" /></a>
	<p class="wp-caption-text">Cover of SEGA</p>
</div>
</div>
<p>Seems like all the attackers have started targeting games industry. After breaking into <a class="zem_slink" title="Sony" rel="homepage" href="http://www.sony.com">Sony</a>(multiple times), <a class="zem_slink" title="Nintendo" rel="geolocation" href="http://maps.google.com/maps?ll=34.9699694444,135.756202778&amp;spn=1.0,1.0&amp;q=34.9699694444,135.756202778 (Nintendo)&amp;t=h">Nintendo</a>, <a class="zem_slink" title="Bethesda, Maryland" rel="geolocation" href="http://maps.google.com/maps?ll=38.9847222222,-77.1130555556&amp;spn=0.1,0.1&amp;q=38.9847222222,-77.1130555556 (Bethesda%2C%20Maryland)&amp;t=h">Bethesda</a>, <a title="Epic Games, Codemasters Sites Hacked" href="http://playstationlifestyle.net/2011/06/10/epic-games-codemasters-sites-hacked/">Codemasters</a> and <a title="Epic Games, Codemasters Sites Hacked" href="http://playstationlifestyle.net/2011/06/10/epic-games-codemasters-sites-hacked/">Epic</a>,  this time they have infiltrated into <a class="zem_slink" title="Sega" rel="homepage" href="http://www.sega.co.jp/">SEGA</a>.</p>
<p>As per the mail sent out to sega customers</p>
<blockquote><p><em>Dear ___,</em></p>
<p><em>As you may be aware, the SEGA Pass system has been offline since yesterday, Thursday 16 June.</em></p>
<p><em>Over the last 24 hours we have identified that unauthorised entry was gained to our SEGA Pass database.</em></p>
<p><em>We immediately took the appropriate action to protect our consumers’ data and isolate the location of the breach. We have launched an investigation into the extent of the breach of our public systems.</em></p>
<p><em>We have identified that a subset of SEGA Pass members emails addresses, dates of birth and encrypted passwords were obtained. To stress, none of the passwords obtained were stored in plain text.</em></p>
<p><em>Please note that no personal payment information was stored by SEGA as we use external payment providers, meaning your payment details were not at risk from this intrusion.</em></p>
<p><em>If you use the same login information for other websites and/or services as you do for SEGA Pass, you should change that information immediately.</em></p>
<p><em>We have also reset your password and all access to SEGA Pass has been temporarily suspended.</em></p>
<p><em>Additionally we recommend you please take extra caution if you should receive suspicious emails that ask for personal or sensitive information.</em></p>
<p><em>Therefore please do not attempt to login to SEGA Pass at present, we will communicate when the service becomes available.</em></p>
<p><em>We sincerely apologise for this incident and regret any inconvenience caused.</em></p>
<p><em>We are contacting all our members with these recommendations.</em></p>
<p><em>If you have any further questions please contact SEGA customer support on csescalations@sega.com</em></p></blockquote>
<p>&nbsp;</p>
<p>As soon as this attack surfaced at <a href="http://playstationlifestyle.net/2011/06/17/sega-pass-database-hacked/">playstationlifestyle.net</a> it was thought to be yet another attack by LulzSec but seems like they haven&#8217;t claimed any responsibility yet (sounds so much like terrorist attack, and taking responsibility)</p>
<p>&nbsp;</p>
<blockquote><p>&nbsp;</p></blockquote>
<p>&nbsp;</p>
<p>&nbsp;</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://kotaku.com/5813075/sega-hacked-says-payment-info-not-compromised">Sega Hacked, Says Payment Info Not Compromised [The Neverending Story]</a> (kotaku.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.inquisitr.com/114286/segas-sega-pass-service-hacked/">Sega&#8217;s &#8220;Sega Pass&#8221; Service Hacked</a> (inquisitr.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.pcworld.com/article/230701/reports_sega_customer_database_hacked.html">Reports: Sega Customer Database Hacked</a> (pcworld.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=8f64fefb-ba1a-47f2-95d0-dceef005f1a3" alt="Enhanced by Zemanta" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/sega-database-pwned-account-information-compromised/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>After PSN, hackers attack codemasters</title>
		<link>http://www.clubhack.com/after-psn-hackers-attack-codemasters/</link>
		<comments>http://www.clubhack.com/after-psn-hackers-attack-codemasters/#comments</comments>
		<pubDate>Sat, 11 Jun 2011 09:30:37 +0000</pubDate>
		<dc:creator>Sorabh Kalra</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[Codemasters]]></category>

		<guid isPermaLink="false">http://clubhack.com/?p=1237</guid>
		<description><![CDATA[Attack after attacks and this time its UK game developer Codemasters whose customer database has  been compromised. As posted on company&#8217;s forum: Codemasters said  hackers gained unauthorized entry to Codemasters.com on Friday, June 3. &#8220;As soon as the intrusion was detected, we immediately took codemasters.com and associated web services offline in order to prevent any [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Attack after attacks and this time its UK game developer <a class="zem_slink" title="Codemasters" rel="wikipedia" href="http://en.wikipedia.org/wiki/Codemasters">Codemasters</a> whose customer database has  been compromised.</p>
<div class="wp-caption alignright" style="width: 312px">
	<a href="http://en.wikipedia.org/wiki/File:Codemasters-logo.png"><img src="http://upload.wikimedia.org/wikipedia/en/7/78/Codemasters-logo.png" alt="" width="312" height="72" /></a>
	<p class="wp-caption-text">Image Source: Wikipedia</p>
</div>
<p>As posted on <a href="http://community.codemasters.com/forum/codemasters-news-announcements-neues-und-ankuendigungen-nouvelles-et-annonces-1299/announcements.html">company&#8217;s forum</a>: Codemasters said  hackers gained  unauthorized entry to Codemasters.com on Friday, June 3. &#8220;As soon as the  intrusion was detected, we immediately took codemasters.com and  associated web services offline in order to prevent any further  intrusion,&#8221;  Director, Community Relations @ Codemasters.</p>
<p>Investigation conducted by Codemasters after the hack revealed that the intruders accessed:</p>
<ul>
<li>Codemasters.com;</li>
<li>DiRT 3 VIP code redemption page;</li>
<li>the Codemasters estore;</li>
<li>and the  Codemasters CodeM database.</li>
</ul>
<p>and the intrusion means hackers gained access to customers</p>
<ul>
<li>names and addresses,</li>
<li>email addresses,</li>
<li>telephone numbers,</li>
<li>encrypted  passwords</li>
<li>member names/usernames or screen names,</li>
<li>newsletter preferences,</li>
<li>any biographical  information entered by the user,</li>
<li>details of last site activity,</li>
<li><a class="zem_slink" title="IP address" rel="wikipedia" href="http://en.wikipedia.org/wiki/IP_address">IP  address</a>,</li>
<li>and <a class="zem_slink" title="Xbox Live" rel="wikipedia" href="http://en.wikipedia.org/wiki/Xbox_Live">Xbox Live</a> gamertags.</li>
</ul>
<p><strong>Good Part</strong>: Since no personal payment information is stored with  Codemasters as they use external payment providers, assuring payment  details were not at risk from this intrusion.</p>
<p><em>As mentioned in forum post</em>: Codemasters.com will remain offline and all  traffic  will be redirected to the company&#8217;s <a class="zem_slink" title="Facebook features" rel="wikipedia" href="http://en.wikipedia.org/wiki/Facebook_features">Facebook page</a> [redirection is not working for me though?]. A new Web  site will  launch later in the year.</p>
<p>Codemasters suggested that  users change their passwords immediately,  especially if that password  or login is used for other accounts.</p>
<p><span style="text-decoration: underline">Some thoughts/ideas:</span><br />
&#8211; Does all this info really needed by these gaming portals? Isn&#8217;t a net-identity linked with e-mail is not enough?<br />
&#8211; Always keep a separate password on different portals, so that if one is compromised you don&#8217;t have to change all your passwords.<br />
&#8211; If your data got hacked in PSN attack and you also happen to have an account at codemasters, hackers might have some redundant data problems now <img src='http://www.clubhack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/after-psn-hackers-attack-codemasters/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

