EFIXPC.COM WORLDWIDE HOME HOME EFIXPC.COM Worldwide SOLUTIONS PRODUCTS & SERVICES SUPPORT About EFIXPC.COM

 

Cyber Security Threats in 2008

 

Top Web Hacking and extremely clever hacking techniques of 2008.

Cross-Site Printing (2007 issue)
CUPS Detection
CSRFing the uTorrent plugin
Clickjacking / Videojacking
Bypassing URL Authentication and Authorization with HTTP Verb Tampering
I used to know what you watched, on YouTube (CSRF + Crossdomain.xml)
Safari Carpet Bomb
Flash clipboard Hijack
Flash Internet Explorer security model bug
Frame Injection Fun
Free MacWorld Platinum Pass? Yes in 2008!
Diminutive Worm, 161 byte Web Worm
SNMP XSS Attack (1)
Res Timing File Enumeration Without JavaScript in IE7.0
Stealing Basic Auth with Persistent XSS
Smuggling SMTP through open HTTP proxies
Collecting Lots of Free 'Micro-Deposits'
Using your browser URL history to estimate gender
Cross-site File Upload Attacks
Same Origin Bypassing Using Image Dimensions
HTTP Proxies Bypass Firewalls
Join a Religion Via CSRF
Cross-domain leaks of site logins via Authenticated CSS
JavaScript Global Namespace Pollution
GIFAR
HTML/CSS Injections - Primitive Malicious Code
Hacking Intranets Through Web Interfaces
Cookie Path Traversal
Racing to downgrade users to cookie-less authentication
MySQL and SQL Column Truncation Vulnerabilities
Building Subversive File Sharing With Client Side Applications
Firefox XML injection into parse of remote XML
Firefox cross-domain information theft (simple text strings, some CSV)
Firefox 2 and WebKit nightly cross-domain image theft
Browser's Ghost Busters
Exploiting XSS vulnerabilities on cookies
Breaking Google Gears' Cross-Origin Communication Model
Flash Parameter Injection
Cross Environment Hopping
Exploiting Logged Out XSS Vulnerabilities
Exploiting CSRF Protected XSS
ActiveX Repurposing, (1, 2)
Tunneling tcp over http over sql-injection
Arbitrary TCP over uploaded pages
Local DoS on CUPS to a remote exploit via specially-crafted webpage (1)
JavaScript Code Flow Manipulation
Common myflhome.webhost4lifemysql.com dns misconfiguration can lead to "same site" scripting
Pulling system32 out over blind SQL Injection
Dialog Spoofing - Firefox Basic Authentication
Skype cross-zone scripting vulnerability
Safari pwns Internet Explorer
IE "Print Table of Links" Cross-Zone Scripting Vulnerability
A different Opera
Abusing HTML 5 Structured Client-side Storage
SSID Script Injection
DHCP Script Injection
File Download Injection
Navigation Hijacking (Frame/Tab Injection Attacks)
UPnP Hacking via Flash
Total surveillance made easy with VoIP phone
Social Networks Evil Twin Attacks
Recursive File Include DoS
Multi-pass filters bypass
Session Extending
Code Execution via XSS (1)
Redirector’s hell
Persistent SQL Injection
JSON Hijacking with UTF-7
SQL Smuggling
Abusing PHP Sockets (1, 2)
CSRF on Novell GroupWise WebAccess

Read more from Blogspot


 

-12/22/2008 BOSTON, U.S. Three Massachusetts Institute of Technology students who were sued earlier this year by the Massachusetts Bay Transit Authority (MBTA) said Monday that they are now working to make the Boston transit system more secure. Read more from PCworld


-12/19/2008 WASHINGTON, U.S. Congressional Budget Office had been hit with a computer virus. Hackers had been trying for years to break into government computers in Congress and the executive branch, and some had succeeded. Read more from Nextgov


-12/12/2008 NY, US. A 28-year-old man caught in the act of using hacked ATM codes to loot Citibank accounts last May pleaded guilty this week to a single count of access device fraud, bringing to five the number of defendants who've entered guilty pleas in connection with an intrusion into an ATM processing server that led to at least $2 million in fraudulent withdrawals this year. Read more from Wired.


-12/09/2008 DUBLIN, IRELAND. Surfers attempting to visit Microsoft's Irish website via Microsoft.ie on Tuesday morning were greeted with a defaced page instead. Hackers sprayed digital graffiti bragging that Microsoft Ireland had been hacked by the previously unknown "Terrorist crew". Read more from TR


-12/09/2008 HILLSBOROUGH. U.S. Computer hackers gained access to the town's telephone system and made hundreds of hours of calls to countries on six continents, including Libya, Cuba, Egypt, Pakistan, Syria and Saudi Arabia. Intelligence agencies have known for years that telecommunication systems are vulnerable, especially as those systems grow more complex and rely more on wireless signals, which are easier to intercept. Read more from UL


-12/08/2008 ATLANTA, U.S. It was revealed earlier in the week that hackers had taken command and control of a free e-bill Web site called CheckFree.com. CheckFree offers their customers the ability to collect all their bills and pay them with a few clicks of a mouse. Read more from BC


-12/03/2008 BERLIN, GERMANY. German police will get sweeping new powers to hack into people's home computers with 'Trojan' viruses sent through the internet. New laws, some of the toughest in Europe, will also allow police to bug and photograph suspect's homes, tap their phones and track the location of their mobile calls. Read more from Telegraph


-12/03/2008 LONDON, UK. A judicial review of the Gary McKinnon extradition case is being scheduled for 20 January, the same day Barack Obama assumes the US presidency. McKinnon's hopes of avoiding extradition to the US on hacking charges. Read more from TR


-12/02/2008 LONDON, UK. Data hack makes cyber-shoplifting easy. Fraudsters could skim millions of pounds from retail websites this Christmas because retailers do not have adequate security. Security tester NTA Monitor found that, manipulating form variables on a website or back-end payment gateway, hackers can change the amount debited from their account or change the purchase currency, resulting in paying less for the items in their shopping basket. Read more from CW


-12/01/2008 NEW YORK. U.S. CBS website bitten by iFrame hack. TV network CBS has become the latest big name to have it website used to host malware, a security company has reported. It appears that Russian malware distributors were able to launch another iFrame attack on a sub-domain of the cbs.com site. Read more from TW


-11/25/2008 KARACHI, PAKISTAN. Pakistani hackers hack Indian website. In what seems to be an intensifying cyber war between hackers of Pakistan and India, Pakistani hackers managed to hack website of ONGC (Oil and Natural Gas Corporation) of India on Tuesday. Read more from TN


-11/24/2008 MI, USA. Verizon Employees Fired Over Obama Cell Hack. Verizon employees hack Obama records. Some Verizon Wireless employees accessed billing records from a cell phone President-elect Barack Obama had used, the Obama transition and Verizon Wireless said Thursday. Read more from PCmag


-11/22/2008 WASHINGTON, U.S. China has stepped up computer espionage against the US government and American businesses, according to an influential Washington congressional panel. Read more from BBC


-11/20/2008 GLASGOW, SCOTLAND, UK. Alleged computer hacker Gary McKinnon could serve sentence in UK jail. A SCOT accused of hacking into US military and NASA computers could serve any prison sentence in Britain, it emerged yesterday. Glasgow-born Gary McKinnon is due to be extradited to the US, where he faces up to 70 years in jail if convicted. Read more from DR


-11/17/2008 MAINE, U.S. As many as 1,000 University of Maine FirstClass accounts were hacked into with a Trojan horse virus, resulting in the arrest of former UMaine student James Wieland on Wednesday, Nov. 12. Police arrested Wieland for Aggravated Criminal Invasion of Computer Privacy - a Class C felony. Wieland attended UMaine from the fall of 2000 until the spring of 2008 as a business student. Read more from MC


-11/14/2008 WASHINGTON, U.S. Palin Email Hack Trial Delayed Until 2009. Kernell, a student at the University of Tennessee and the son of Tennessee state Rep. Mike Kernell, a Democrat, turned himself in to authorities on October 8. He is accused of hacking into Palin's "gov.palin@yahoo.com" e-mail account on September 16 by successfully navigating Yahoo's password recovery system. Read more from PCmag



-11/12/2008 SAN JOSE U.S. A former San Jose network administrator is facing 12 years in prison after pleading guilty to hacking, ID theft, burglary and drug charges. According to the Santa Clara District Attorney's office, Andrew Madrid, 34, used his IT experience to pull off a variety of crimes between September 2006 and March 2008. Read more from CW


- 11/08/2008 WASHINGTON, U.S. Chinese hackers have penetrated the White House computer network on multiple occasions, and obtained e-mails between government officials, a senior US official told the Financial Times. US government cyber intelligence experts suspect the attacks were sponsored by the Chinese government because of their targeted nature. Read more from FT


- 11/06/2008 TOKYO, JAPAN. WPA encryption hack to be shown. Two security researchers claim to have broken WPA (Wi-Fi Protected Access) encryption techniques, though they have not yet released further information. Erik Tews and Martin Beck have said they will demonstrate the hack at the PacSec conference in Tokyo next week. Read more from WU


- 11/06/2008 DENMARK. Cyber Criminals Hack Code, Raising Global Spam Levels. Two scientists at Newcastle University had discovered flaws in Yahoo and Microsoft's spam filters, which were considered to be strong enough to check any abuse. News reports stated that Newcastle University's PhD student, Ahmad Salah El Ahmad along with Dr Jeff Yan rendered their research discoveries directly to Microsoft and Yahoo for enhancing their systems security. Read more from SF


- 11/02/2008 LONDON, UK. Tax website shut down as memory stick with secret personal data of 12million is found in a pub car park. An urgent investigation is now under way into how the stick, belonging to the company which runs the flagship system, came to be lost. Read more from DM


- 10/31/2008 WORLDWIDE. Trojan virus steals banking info. The details of about 500,000 online bank accounts and credit and debit cards have been stolen by a virus described as "one of the most advanced pieces of crimeware ever created". Read more from BBC


-10/28/2008 RALEIGH, U.S. Government computer security reviews an issue. Two state agencies - one of them State Auditor Les Merritt's office - are at odds over how Merritt has handled government computer security reviews. Read more from WRAL


-10/24/2008 NEW JERSEY, U.S. Sequoia e-voting machines disturbingly easy to hack. The Princeton University Center for Information Technology Policy has published a report disclosing security vulnerabilities that researchers have detected in Sequoia's AVC Advantage voting machine. According to the researchers, the machine can be completely compromised by replacing a single ROM chip - a task that they were able to complete in only seven minutes. Read more from AT


-10/23/2008 NEW YORK, U.S. The Shenendehowa school district is investigating a electronic hacking incident that involved two students, they hacked into the grade system recently when they discovered a file they were not looking for, hacking incident happened when the district was in the process of moving files from one server to another. Read more from CBS6


-10/22/2008 WASHINGTON, U.S. FBI raids Miley Cyrus email hacker. He posed as a MySpace.com administrator to steal Cyrus” password, and hack her Gmail account. The teen hacker, who allegedly posted Miley Cyrus saucy photos online, has been raided by the FBI. Read more from EO


-10/21/2008 COLUMBUS, U.S. Ohio Secretary of State Jennifer Brunner announced on Monday afternoon that the state website has been set in a static mode with limited functionality as a precaution. The Ohio State Highway Patrol will assist with an investigation of one or more security breaches detected by the Secretary of State. Read more from BB


-10/20/2008 LAUSANNE, SWITZERLAND. Researchers hack wired keyboards, hijack keystrokes, team of Swiss researchers say there are several ways to recover keystrokes from wired keyboards by simply measuring the electromagnetic radiations emitted when keys are pressed. Read more from ZDNET


-10/20/2008 BACOLOD CITY, PHILIPPINES. Beware of e-mails purportedly from friends “desperately asking” for money. Con artists hack doc’s e-mail. A hacker nearly victimized the friends of a Negrense doctor who gained access to the doctor’s e-mail address after sending messages saying the doctor was mugged in London and needed money right away. Read more from Inquirer



-10/19/2008 PARIS, FRANCE. The French Cabinet's spokesman says "swindlers" have broken into the personal bank account of President Nicolas Sarkozy. Sarkozy's bank account hacked by thieves. Read more for CNN or JDD


-10/18/2008 TRENTON, U.S. Some 10,000 voting machines throughout New Jersey could be hacked into in less than 10 minutes to manipulate vote tallies, which critics say puts the integrity of elections in New Jersey into question, according to a once-suppressed report by a Princeton University computer scientist released to the public Friday. Read more from MCJ


-10/17/2008 GENEVA, SWITZERLAND. Hack attacks become more sophisticated. The danger of infections by simply visiting websites is on the rise, the Federal Police Office has warned. Read more from SI


-10/15/2008. ENCINO, U.S. New generation of hackers. How did "hacker" become a dirty word? Columnist Jeremiah Gray looks at the evolving definition of the term, offers his own and suggests that what this country needs now more than ever is a resurgence of hacker society. Read more from ECT


-10/14/2008 MANHATTAN, U.S.The high end American Thompson hotel chain suffered an embarrassing and thought provoking hack-attack over the weekend. The hacker apparently managed to obtain emails sent to and from guests at the hotel, both personal and business. Read more from SW


-10/13/2008 WASHINGTON, U.S. Hackers are conning Windows users into installing a Trojan Horse disguised as a Microsoft security patch, according to security firm Sophos. Read more from PCpro.


-10/13/2008 DELHI, INDIA. According to an Indian security official, the co-founder of the IM media cell sent 32 emails to a number of cyber experts, including those residing United States, Europe, and Asia, he worked as a Yahoo software engineer and allegedly disseminated warning e-mails a short time before a series of bomb blasts occured. Read more from ITE.


-10/10/2008 WASHINGTON, U.S. At least six major intrusions, two of them using the same group of IP addresses originating from China have been detected at the World Bank since the summer of 2007, with the most recent breach occurring just last month. Read more from FOX


-10/10/2008 ASTRAHAN, RUSSIA. Head of networking technology and computing technology "Astrahanprombanka" Alexander Krylov sentenced to 5.5 years in prison for 20 million rubles fraud. Read more from Lenta.


-10/09/2008 U.S. David C. Kernell, the 20-year-old son of Tennessee state representative Mike Kernell, plead not guilty on Wednesday, October 9, 2008 to a single count of unauthorized access to an e-mail account. Read more from SF


-10/06/2008. U.S. The FBI is seeking two Europeans alleged to have been involved in attacks on web retailers. Briton Lee Graham Walker and Axel Gembe of Germany are being sought in connection with attacks on two sellers of satellite TV equipment. The attacks targeted two shops that sell digital video recorders and TV satellite equipment: Miami-based Rapid Satellite and Los Angeles-based Weaknees. Read more from BBC


-10/04/2008 MUNICH, GERMANY. Bitmaps stored inside encrypted backup files could be vulnerable to a sophisticated 'comparison' attack, Bernd Roellgen of Munich-based German security researcher has discovered. Read more from TW


-10/03/2008 U.S. A security researcher warns that criminal gangs have obtained administrative log-in credentials for more than 200,000 Web sites, including the one used by the U.S. Postal Service. Read more from ITBE.


-10/03/2008 A US COURT has indicted two Europeans for allegedly launching Internet attacks against a number of retail sites. Losses ranging from $200,000 to over $1 million. Wanted by the FBI. Read more from Inquirer.


-10/02/2008 LONDON, UK. The researcher who claims to have created code that can emulate and clone Dutch e-passports has given details of the purported hack. Read more from ZDNET.


-10/02/08 U.S. The country's most notorious hacker, Mafiaboy, has written a tell-all book about his Internet attack of 2000 when he paralyzed the Web sites of CNN, Yahoo, eBay and other businesses for several hours. Read more form NP


-10/01/2008 LONDON, UK. A Dutch researcher has published code that purports to emulate and clone e-passports, and has released a video to prove it works. Read more from ZDNET.


- 10/01/2008. SUNNYVALE, U.S. Atenean hacks Yahoo! Another Filipino has made Web history by hacking into Internet search granddaddy Yahoo! Read more from ABS.


- 09/30/2008 PRINCETON, U.S. A banking website has been hacked by researchers - allowing them to transfer funds from users' accounts - and similar threats appear in three other extremely popular sites. The Princeton University team found cross-site request forger (CSRF) vulnerabilities on direct savings bank ING, YouTube, the New York Times and MetaFilter. Read more from BCS.


- 09/29/2009 SUNNYVALE, U.S. Yahoo's Zimbra e-mail program exposes passwords. Passwords used to access Yahoo mail through the Zimbra client are sent over the Internet in clear text, a Canadian programmer says. Read more from CNET.


- 09/29/2008 OTTAWA, CANADA. The 20-year-old student that allegedly hacked Carleton University's e-mail system refused last week to agree to penalties and, instead, quit school and now awaits his trial on computer-intrusion charges.Read more from SF.


- 09/28/08 KUWAIT CITY, KUWAIT: The Criminal Investigations Department has finally arrested a Bedoun youth, who had been stealing cash from several bank accounts of Kuwaiti citizens and residents via the Internet. Read more from AT .


- 09/26/08 CALGARY, CANADA. An Israeli national who hacked into a U.S. Defence Department computer and $1.8-million theft from a Calgary financial company. Read more from CNS .


- 09/24/2008 WASHINGTON, U.S. United States were responsible for more than 20.6 million attempted attacks, while China came in second place with 7.7 million attacks. Computer systems located in other countries placed distantly behind the two top nations, with Brazil accounting for 166,987 attempted attacks, South Korea for 162,289, Poland for 153,205, Japan for 142,346, and Russia for 130,572. Read more from SF


- 09/23/2008 WASHINGTON, U.S. Federal grand jury meets on Sarah Palin hacking case. Read more from CW or BBC


- 09/22/2008 WASHINGTON, U.S. The Department of Justice released data from its 2005 National Computer Security Survey last week, finding that two-thirds of firms detected at least one cybercrime during that year. Read more from SF


- 09/17/2008 LONDON, UK. The British government has admitted another data loss blunder: Its bankruptcy agency has lost a laptop carrying personal information on more than 100 former company directors. Read more from AP


- 09/13/2008 GENEVE, SWITZERLAND. Hackers have mounted an attack on the Large Hadron Collider, raising concerns about the security of the biggest experiment in the world. Read more from Telegraph


- 08/28/2008 LONDON, UK. McKinnon hacked into more than 90 computer systems belonging to the U.S. Army, Navy, Air Force, Department of Defense and NASA, $900,000 worth of damage. Read more from BBC or CNN


- 08/18/2008 WASHINGTON, U.S. at risk of cyberattacks, experts say: An assault may be carried out in cyberspace by shadowy hackers half a world a way. Read more from CNN  or watch  video


- 08/05/2008 WASHINGTON, U.S. The eleven suspects, including three U.S. citizens, allegedly took part in stealing more than 40 million credit- and debit-card accounts from nine major retailers and restaurants, including TJX Companies, BJ’s Wholesale Club, OfficeMax, Barnes & Noble, Sports Authority, Forever 21 and DSW. Read more from SF


- 05/21/2008 WASHINGTON, U.S. Study finds The Tennessee Valley Authority vulnerable to hacking. Read more from CNN

 

 

     

 
  ©2008 EFIXPC.COM. Patent Pending. All trademarks used are properties of their respective owners. All rights reserved.   Contact Us