Entradas

SIRIA - UTILIZANDO TÉCNICAS HACKER .. PARA QUE?.. dedicado a MAY

  Electronic Frontier Foundation ha descubierto que el Ejecutivo de Siria está utilizando técnicas propias de los ciberdelincuentes para intentar detener a los activistas que se promulgan en la Red en contra del régimen de Bashar Asad.  Han creado una página falsa e idéntica a YouTube que supuestamente pertenecía a una persona contraria al Gobierno. La página ya ha sido clausurada. Cuando los usuarios accedían a la misma y trataban de comentar el vídeo alojado en esta página, les robaban las contraseñas. Además, el sistema solicitaba a los internautas que ejecutasen una actualización de Adobe Flash Player... como es lógico si no tienes "parcheado" el Flash, "entramos" por Adobe .. es lo que tiene. Para ello, les proporcionaban un código que contenía malware y de esta manera dejaba al descubierto todos los archivos que el usuario tenía en su equipo.... código embebido en JavaScritp reventando con ActiveX y Applets "a saco" ... "n...

IE 10 ATTACKS -Enhanced Memory Protections in IE10-

Imagen
Internet Explorer 10 introduces significant improvements in memory protections to help make vulnerabilities harder to exploit, helping to keep users safe on the sometimes-hostile Web. These improvements will increase the difficulty and development cost of exploits, making life harder for the bad guys. While socially-engineered malware is the primary way that bad guys get their code onto victims’ computers, that is largely because browser vulnerabilities have become less common and harder to exploit over the last few years. However, as more and more users upgrade to IE9 and benefit from the protection provided by SmartScreen Filter , bad guys have a renewed interest in attacking the browser and its add-ons directly. In today’s post, I explain the threat environment, survey the existing protections available in IE9, and explain how IE10’s new memory protections provide even more security. Attacking Web Browsers The goal of an attacker exploiting a memory-related vulnerab...

Reverse Engineering Hostile Code

Imagen
                                   Reverse Engineering Hostile Code Computer criminals are always ready and waiting to compromise a weakness in a system. When they do, they usually leave programs on the system to maintain their control. We refer to these programs as "Trojans" after the story of the ancient Greek Trojan horse. Often these programs are custom compiled and not widely distributed. Because of this, anti-virus software will not often detect their presence. It also means information about what any particular custom Trojan does is also not generally available, so a custom analysis of the code is necessary to determine the extent of the threat and to pinpoint the origin of the attack if possible. This article outlines the process of reverse engineering hostile code. By "hostile code", we mean any process running on a system that is not authorized by the system administrator, s...

Reverse Engineering Hostile Code - INGENIERÍA INVERSA -

RESPUETA TEMPRANA A INCIDENTES CERT´s -Incident Recovery-

INCIDENT RECOVERY ******************** An intrusion is not the end of the world. Recovering from an intrusion can be a chore, but is not impossible, if you know what to do. This article will look over intrusion recovery and take a brief look at computer forensics -- i.e., what to do if you want to try to get the law involved in the incident. Much like any other part of intrusion response, recovery from attack starts before you've been attacked. It can be very difficult to recover if you don't have recent backups of your system -- back things up regularly; nightly if possible. If you've got important information on your system, a nightly backup just makes sense. I prefer backing up to tape if you can afford a tape drive, but it's not a requirement. What you do need is some form of backup that holds your important system files and binaries, so you can restore if something happens, or a rescue disk that contains clean versions of important system binaries. Also (prefer...

NORTON HACKED BY ANONYMOUS ... HAHA!!! CONGRATULATIONS

Imagen
Security firm Symantec confirmed Friday that the hacker group Anonymous has just posted some of its product source code, but strongly downplays any risk, because it's old code from a 2006 version of Norton security software. Anonymous claimed to have the information for a while but they finally published it on The website Pirate Bay . The information is a source code for the Symantec Norton Antivirus 2006 edition,which includes files that serve as a source code for software products like the corporate edition, the consumer version, and files for NetWare, Windows and Unix. The download file is 1.07GB. The file has a note that asks for the liberation of the LulzSec members that were arrested. Symantec the anti-virus and Security Company previously stated that the breach will “ not affect any current Norton product ”. Then added: “ The current version of Norton Utilities has been completely rebuilt and shares no common code with Norton Utilities 2006. The code that ha...

LulzSec- FBI asegura que ha descabezado a los hackers de LulzSec gracias a un 'topo'

El FBI ha anunciado la detención de cinco personas acusadas de pertenecer al grupo de hackers LulzSec, que además formarían la cúpula del mismo. La operación se habría llevado a cabo gracias a que uno de estos supuestos líderes, Hector Xavier Monsegur, alias 'Sabu' -fundador del grupo-, habría actuado como 'topo' de las autoridades y habría revelado información sobre sus compañeros. Dos de los cinco presuntos hackers, los británicos Ryan Ackroyd, 'Kayla' y Jake Davis, 'Topiary', han sido arrestados en Londres. Darren Martyn, 'pwnsaucey' y Donncha O'Cearrbhail, 'palladium', irlandeses, en Irlanda. Y Jeremy Hammond, 'Anarchaos', estadounidense, en Chicago. "Es devastador para la organización (...) estamos cortando la cabeza de LulzSec", ha asegurado a FOXNews un portavoz del FBI. Todos ellos se enfrentarán ahora a cargos de conspiración para cometer accesos no autorizados a ordenadores -hacking- y todos ha...

Las primeras webs denunciadas por la ley Sinde: está SeriesPepito; no está SeriesYonkis

La industria cultural ha comenzado ya a presentar denuncias contra webs con contenidos protegidos con derechos de autor ante la Sección Segunda de la Comisión de la Propiedad intelectual, en funcionamiento desde el pasado 1 de marzo, y ya hay una lista de 25 páginas webs denunciadas. Según ha podido saber RTVE.es, en esta lista de 'las primeras 25' se encuentran Seriespepito.com, elitetorrent.net, pordescargadirecta.com, foroxd y gratisjuegos. Fuentes cercanas al sector explican que las denuncias se han presentado desde diferentes entidades de gestión como Egeda o Promusicae y que el resto de webs ya demandadas van desde páginas que albergan videojuegos a webs de películas y series o libros. Las denuncias no llegarán sin embargo de mano de la SGAE, que ha explicado que "no tiene previsto" denunciar a páginas webs ante la Comisión. ¿Por qué SeriesYonkis no está en esta lista? Entre las primeras webs denunciadas no se encuentra de momento SeriesYonkis. Es...

WINDOWS 8 E INTERNET EXPLORER 10 .. BOOM !!!!

Bueno, cada vez está más cerca ( he tenido el privilegio de andar trasteando con Windows 8 cliente entre otras cositas ... táctil, junto con tablet ... un puto Boom !!! garantizado) el tan ansiado y experado Internet Explorer 10 que junto con Windows 8 cliente y el nuevo sistemas de ficheros en la parte servidor ( Adios NTFS ..) (Joder que viejo me siento .. adios FAT, adios FAT32, adios NTFS .. Pufff ) van a suponer la gran revolución.  La gran Manzana  jamás se imagino que los de Redmon iban a superar y con creces a Mac ... si señores y señoras, se van a encontrar ante un sistema operativo totalmente innovador, cambiante y cuanto menos sorprendente. De hecho es el primer sistema operativo de estas características ... si nombrar las mejoras de seguridad en el Kernel , que por cierto es el 6.2 .. Es la continuación del Kernel de Vista , NT 6.1 , por lo tanto y desde mi punto de vista no se ha reconstruido un kernel nuevo ... si no, estaríamos hablando de un kernel v 7.x ......