Wednesday, 26 November 2014
Shellshock attacks against SMTP servers
Reports are emerging from various sources that many of the SMTP servers has been attacked by the Shellshock bug. Cyber hackers are taking advantage of the Shellshock bug and exploiting the vulnerabilities against certain SMTP servers.The campaign seeks to create an IRC botnet for DDOS attacks and other purposes.
Its going to be a month that Shellshock vulnerability was public and it is also being says that Shellshock is the worst then the Heartbleed vulnerability. After the public release of the Shellshock bug many of the firms and organisation have patch the vulnerabilities but there are still tonnes of the servers which are vulnerable to the Shellshock bug.
Shellshock bug was located in the Bash shell of the Linux operating system which was resides for 20 years. It was deployed on the configuration which makes the bug severity critical and was also easy to exploit.
Hackers are targetting SMTP server because the mail server are often left untouched (outdated or little concerns) for a long time.
CSO said on the post that they have found one the IRC servers used to host the bots, and they mentioned that it had 160 compromised servers connected to it on 24 October.
Enjoy Guys! and don't forget to post your comments. © Comrade Pyrate
A learning experience from Forbes hacking
A world’s best information sharing website Forbes.com is now in list of
successfully infiltrated website list Syrian Electronic Army – The #SEA.
They successfully able to get access of Forbes’ email and publishing
systems, download email addresses and hashed passwords of millions of
users, and post articles rights.
As we can see such a big name is now under the list of hacked website, then how small business can survive over on internet. It is very shocking for all of us how recently hackers have done very remarkable hacking of world’s well-known brands like Microsoft, Skype, Twitter account of Times Magazine, CNN. Below is main security ignorance, which played a main part in different cyber attacks.
Respond to Phishing mail: Phishing is a serious concern for the whole cyber world as it lures user to click on email links, which directs him/her on another page where attacker swipes the details of user. Sometimes such suspicious links ask users for private login details and after getting login details attacker can again attack on the server or system. It is sensible to avoid such spam links especially in organizations that seems ripe fruits for cyber culprits.
Respond to fake login page: When a user innocently enters his or her login details in fake login page, resulting in phishing attack. Attacker can take the user to another web page to make phishing attack in real. Attacker can perform an attack called cross-site request forgery to hack the browser. After hijacking the browser attacker can install malicious software to steal the information from the website. In this case, it is sensible to look for webpage security and authenticity before submitting the login credentials. Many website has SSL security on their login page to ensure users about website authenticity.
Lack of Security monitoring: It is very essential to monitor for any suspicious activity of the server or network system. Security monitoring
includes collection, analysis, and escalation of warning samples and
indications. It alerts organization immediately and organization can
avert
further potential destruction. Accomplish inspection about daily IT security risks.
Educate employees: The biggest concern is lack of security knowledge and its measures. Organization should provide enough security knowledge to its employees, which must cover organization’s security policy, immediate action against suspicious activity, policy about sharing details and web surfing guidelines, etc.
Other Recommendations: Besides the above security measures organization can take below security measures.
Cyber crime is evolving drastically around us. Whether you are a large organization or small business, security precautions can make a big difference. A single click in today’s world can welcome major cyber attack. It is better to take precaution rather to suffer.
As we can see such a big name is now under the list of hacked website, then how small business can survive over on internet. It is very shocking for all of us how recently hackers have done very remarkable hacking of world’s well-known brands like Microsoft, Skype, Twitter account of Times Magazine, CNN. Below is main security ignorance, which played a main part in different cyber attacks.
Respond to Phishing mail: Phishing is a serious concern for the whole cyber world as it lures user to click on email links, which directs him/her on another page where attacker swipes the details of user. Sometimes such suspicious links ask users for private login details and after getting login details attacker can again attack on the server or system. It is sensible to avoid such spam links especially in organizations that seems ripe fruits for cyber culprits.
Respond to fake login page: When a user innocently enters his or her login details in fake login page, resulting in phishing attack. Attacker can take the user to another web page to make phishing attack in real. Attacker can perform an attack called cross-site request forgery to hack the browser. After hijacking the browser attacker can install malicious software to steal the information from the website. In this case, it is sensible to look for webpage security and authenticity before submitting the login credentials. Many website has SSL security on their login page to ensure users about website authenticity.
Lack of Security monitoring: It is very essential to monitor for any suspicious activity of the server or network system. Security monitoring
includes collection, analysis, and escalation of warning samples and
indications. It alerts organization immediately and organization can
avert further potential destruction. Accomplish inspection about daily IT security risks.
Educate employees: The biggest concern is lack of security knowledge and its measures. Organization should provide enough security knowledge to its employees, which must cover organization’s security policy, immediate action against suspicious activity, policy about sharing details and web surfing guidelines, etc.
Other Recommendations: Besides the above security measures organization can take below security measures.
- Install essential tools to check the ability of your web server against DOS or DDOS attack.
- Install phishing detection tool on your server.
- Keep a data backup tool that regularly takes data backups.
- Secure your website with SSL protocol.
- Install anti-phishing and antivirus tool that regularly scans server for any vulnerability.
Cyber crime is evolving drastically around us. Whether you are a large organization or small business, security precautions can make a big difference. A single click in today’s world can welcome major cyber attack. It is better to take precaution rather to suffer.
Enjoy Guys! and don't forget to post your comments. © Comrade Pyrate
CryptoPHP: Thousands of CMS Themes and plugins have Backdoor
In today's world every small business house have their own websites and
also many users includes Politician, Journalist, high profiled person
and even there are many users who own their personal websites. There are
many few of them who use their own custom CMS (Content Management
System) for websites and majority of then uses the popular opensource
CMS - WordPress, Joomla and Durpal.
Many of the developer use the pirated version of the themes for the website but is this a good practice. Here, answer is simply NO.
A Netherlands based security firm Fox-IT have published a researcher paper
which reveals they have discovered a backdoor on the thousand of the
themes, plugins in the pirated version of the popular CMS themes. The
themes which is downloaded from the sites which offer Paid themes for
free (Pirated version) contains a backdoor dubbed as "CryptoPHP". The backdoor is present on themes as well as on many plugins also.
Features of CryptoPHP backdoor
The CryptoPHP backdoor has a few features that made it stand out for us. It lacked the usual attack vectors we normally see with web based backdoors, it social engineers website administrators to install itself through the use of popular free plug-ins, themes and extensions. CryptoPHP contains the following features:
Many of the developer use the pirated version of the themes for the website but is this a good practice. Here, answer is simply NO.
"By publishing pirated themes and plug-ins free for anyone to use instead of having to pay for them, the CryptoPHP actor is social-engineering site administrators into installing the included backdoor on their server," - Fox-IT researcher says on research paper.When this pirated theme is installed on the respective CMS server the backdoor (CryptoPHP) also gives the access to the particular site. Attacker (hacker) controlled backdoor with various technique like command and control server (C&C) communication, email communication and manual control as well.
Features of CryptoPHP backdoor
The CryptoPHP backdoor has a few features that made it stand out for us. It lacked the usual attack vectors we normally see with web based backdoors, it social engineers website administrators to install itself through the use of popular free plug-ins, themes and extensions. CryptoPHP contains the following features:
- It uses the framework of the CMS to function
- It uses the database of the CMS to store information
- It uses public key encryption for anything transferred from and to the C2 servers
- Utilizes a large amount of C2 servers (rather than a single one)
- Older versions contain a backup mechanism against takedowns, in the form of email communication
- Supports manual control (other than the automated C2 communication)
- Can update C2 servers remotely
- Ability to update itself
- Inject content into the webpages
- Code execution
Why They are Doing this?
For every attack or thing there is a reasons behind it, and same for
this also. Cyber Criminals or Miscreants uses CryptoPHP backdoor for
illegal Search Engine Optimization
(SEO), which is also known as Black Hat SEO. This also gives the
backlinks to the attacker site which is one of the important factor for
ranking results.
Black Hat SEO is a technique which helps the site to rank first on the
search engine results and this is done by violating search engine
guideline. Webmaster (attacker) can violates search engine guidelines by
hacking sites for backlinks, inserting iframe link attribute, inserting
unrelated keywords etc..
Fox-IT mention that they have found 16 variants of the CryptoPHP
backdoor and was first dicovered on 25th September 2013, and they claims
that there are thousands of affected sites or even more.
We also recommend our all users not to use the nulled or pirated version
of the themes and also asked to check all the plugins and theme source
code on a routinely. It is also a good practice to check all the
external going out from your sites.
Enjoy Guys! and don't forget to post your comments. © Comrade Pyrate
How to get Rs 100+ Free Talktime for downloading Android App - Mcent
YES Dear Friends,
You heard right after the old offer of Rs.10 recharge by watching video and downloading guitar app Mcent giving free Mobile Recharge with more activities where you just have to log in to
your account ( make a new if you don’t have one )
and visit here Offer page to Download list of mcent app and get talktime of Rs. 100.
To get 100/- Rs. Talk Time Please Follow Step by Step which is showing Below
Be Careful..
Important :Use Desktop chrome browser for sign up OR in mobile Opera browser, you must set websites view mobile to DESKTOP in opera mobile
Step - 1
Click Here
to Login to your account by mobile or PC browser/ make a new one if you don’t have one by CLICK HERE for sign up & use opera in mobile.
Step - 2
After Signup Verify your E-mail and download mcent app from the list [Android App to get your credit]
Step - 3
Come back to this page and install one by one app to get Talktime from bellow apps
Download RedBull to get Rs. 8/- (INSTANTLY)
Download DU Speed Buster to get Rs. 13/- (INSTANTLY)
Download GO Launcher EX to get Rs. 7/- (INSTANTLY)
Download Ixigo flights to get Rs. 11/- (INSTANTLY)
Download Chifro ABC to get Rs. 11/-
Note : Amount May be take maximum 30 minute to update in your a/c
Step - 4
Now Download Mcent App To Recharge Your Amount to Your Mobile No.
Click Here to Download Mcent App
Next Day you'll get more offer of more then 30 Rs.
Note:- First Signup using Mobile browser, and Visit this page to download application and Download Mcent App At last to recharge mobile otherwise you'll not get daily offer.
Enjoy Guys! and don't forget to post your comments. © Comrade Pyrate
You heard right after the old offer of Rs.10 recharge by watching video and downloading guitar app Mcent giving free Mobile Recharge with more activities where you just have to log in to
your account ( make a new if you don’t have one )
and visit here Offer page to Download list of mcent app and get talktime of Rs. 100.
To get 100/- Rs. Talk Time Please Follow Step by Step which is showing Below
Be Careful..
Important :Use Desktop chrome browser for sign up OR in mobile Opera browser, you must set websites view mobile to DESKTOP in opera mobile
Step - 1
Click Here
to Login to your account by mobile or PC browser/ make a new one if you don’t have one by CLICK HERE for sign up & use opera in mobile.
Step - 2
After Signup Verify your E-mail and download mcent app from the list [Android App to get your credit]
Step - 3
Come back to this page and install one by one app to get Talktime from bellow apps
Download RedBull to get Rs. 8/- (INSTANTLY)
Download DU Speed Buster to get Rs. 13/- (INSTANTLY)
Download GO Launcher EX to get Rs. 7/- (INSTANTLY)
Download Ixigo flights to get Rs. 11/- (INSTANTLY)
Download Chifro ABC to get Rs. 11/-
Note : Amount May be take maximum 30 minute to update in your a/c
Step - 4
Now Download Mcent App To Recharge Your Amount to Your Mobile No.
Click Here to Download Mcent App
Next Day you'll get more offer of more then 30 Rs.
Note:- First Signup using Mobile browser, and Visit this page to download application and Download Mcent App At last to recharge mobile otherwise you'll not get daily offer.
Enjoy Guys! and don't forget to post your comments. © Comrade Pyrate
Tuesday, 25 November 2014
How To Find Out Who Views Your Facebook Profile
The
biggest advantage for this trick to see who views you Facebook profile
is that you don’t require any kind of third party tool or software to
know it which sometimes seems complicated and even then do not display
the correct result.
In this method you just need to press some keys on your keyboard and the accurate result will be in front of you within a few minutes.
How to track Who Viewed My Facebook Profile ?
In this method you just need to press some keys on your keyboard and the accurate result will be in front of you within a few minutes.
So here we go with the method for “How to see who viewed your Facebook Profile ?”
You May Also Find This Useful –
- 13 Facebook Tricks You Probably Never Heard Of
- Facebook smiles with colourful heart
- Trick to Post Empty Status on Facebook
How to track Who Viewed My Facebook Profile ?
I.) First of all log in to your Facebook ID and then go to your timeline – facebook.com/xyz.
II.) Right click anywhere on your timeline and select ” VIEW PAGE SOURCE “.
II.) Right click anywhere on your timeline and select ” VIEW PAGE SOURCE “.
III.) Now you will be redirected to a new page where you will see lots of codes.
IV.) On this page just press ” CTRL +
F ” on your keyboard,after which a text box will appear on the screen,
in that box you have to type :- “InitialChatFriendsList” ( without
quotes ).
V.) Next to this word you will see a
list of numbers displayed, these numbers are actually the profile ID’s
of the people who visited your Facebook profile.
VI.) Now you juts have to go to
Facebook.com and paste the ID number you found in that list after
facebook.com with a ” / ” sign. For Example – Let us suppose 1234 is the
ID number you found, now write it like dis – facebook.com/1234 ( ID
number could be anything ).
VII.) Now leave the rest for Facebook, it will display the desired results.
Enjoy Guys! and don't forget to post your comments. © Comrade Pyrate
VII.) Now leave the rest for Facebook, it will display the desired results.
Subscribe to:
Posts (Atom)




