Tampilkan postingan dengan label Anti Hacking. Tampilkan semua postingan
Tampilkan postingan dengan label Anti Hacking. Tampilkan semua postingan

Kamis, 30 Juni 2016

How To Hack WhatsApp Using SS7 Flaw


Researchers are easily able to hack WhatsApp and Telegram using the known telecom flaw


We continuously receive queries from readers about how to hack WhatsApp. The world’s most popular cross platform messaging App is seen to be ultimate hack by many because it has recently enabled 256-bit encryption.

For ordinary souls this encryption would take days and months to decode a sentence or a complete message. Ditto with another secure messaging service called Telegram. Though Telegram is not as popular as WhatsApp, it has its ardent group of followers who use it for its encryption as well as snooping free service.

Though both of these Apps are end-to-end encrypted both of them suffer from hardware side vulnerability which can be exploited to hack and hijack both WhatsApp and Telegram.

The vulnerability lies in Signalling System 7, or SS7, the technology used by telecom operators, on which the highly secure messaging system and telephone calls rely. SS7 is a set of telephony signalling protocols developed in 1975, which is used to set up and tear down most of the world’s public switched telephone network (PSTN) telephone calls. It also performs number translation, local number portability, prepaid billing, Short Message Service (SMS), and other mass market services.

SS7 is vulnerable to hacking and this has been known since 2008. In 2014, the media reported a protocol vulnerability of SS7 by which both government agencies and non-state actors can track the movements of cell phone users from virtually anywhere in the world with a success rate of approximately 70%. In addition, eavesdropping is possible by using the protocol to forward calls and also facilitate decryption by requesting that each caller’s carrier release a temporary encryption key to unlock the communication after it has been recorded. Researchers created a tool (SnoopSnitch) which can warn when certain SS7 attacks occur against a phone and detect IMSI-catchers.

You can view how researchers managed to hack WhatsApp and Telegram using the SS7 flaw below:

WhatsApp Hack



Telegram Hack



Both the hacks exploit the SS7 vulnerability by tricking the telecom network into believing the attacker’s phone has the same number as the victim’s phone. Once the network has been fooled, anybody, even a newbie can spy on the legitimate WhatsApp and Telegram user by creating a new WhatsApp or Telegram account using the secret code.

Once complete, the attacker now controls the account, including the ability to send and receive messages. Even more horrific is the fact that the hacker can also send messages on behalf of the victim, and read confidential messages intended for the victim without ever having to try to break strong encryption protocols.

See how easily you can hack WhatsApp and Telegram by fooling the network into believing your are the victim.
Source: http://www.techworm.net/2016/06/how-to-hack-whatsapp-using-ss7-flaw.html

Selasa, 31 Mei 2016

How to Bypass Android Lollipop 5.0 Lock Screen


he vulnerability is the thing – that each and every system currently have, whether we found that now or later on but sooner or later we will. Why we need to bypass our Android password protected lock screen? there is only two reason either you have forgotten your password (After the maximum limit of incorrect password you will be prompt to click on Forget Password and you will be required to provide your Gmail password) or else you are trying to hack into your Android Lollipop smartphone!

This is a security bug on your Android smartphone, but Google updated this via OTA still some of the devices can be used to perform this so-called hack, follow the below steps to bypass password protected lock screen.


So start following the below steps:


Step1: Your Android is already locked so you need to click on Emergency button (if you can’t find that then you need to use maximum limit of the incorrect password which will lead you to Emergency call.)
click on Emergency button

Step2: Now on the Emergency dialer you need to click random numbers continuously until it crossed its limit.

Step3: After that you need to copy that whole number by long pressing and select “Select All” and then select “Copy“.
Select All and copy it

Step4: After that you need to open your camera, Camera can be accessible if you have not locked your camera too, After opening camera – you need to slide down the notification bar and it will ask you to provide your lock screen password then paste the copied numbers.

Step5:
Soon after you provide the copied number you will see your camera is crashed or if not then you need to paste the password again which may be 3 – 5 times along with pressing the volume up-down key to make your system lag.
Unfortunately, Camera has stopped

Step6: And if you followed the process correctly then your camera will get crash suddenly and from there your device is unlocked with a pop-up window showing “Unfortunately, Camera has stopped“.

Note: This security vulnerability still works on some of the outdated devices, if your Android device is not being updated with the recent update patch then it will work on that device.
Source: https://codingsec.net/2016/05/bypass-android-lollipop-5-0-lock-screen/

Minggu, 29 Mei 2016

Tips From A Hacker: Trick To Come Up With A Strong Password



Short: A security consultant from the RedTeam talks about the easiest way to come up with a strong password. You just need to memorize a sentence and play around with the first letter of the each of the words of the sentence. And then you can further tweak those letters to make an even stronger password.

Kurt Muhl works as a security consultant with RedTeam and he has recently come up with a video which talks about the easiest ways to come up with a strong password which could be easily remembered as well.

In the video, he explains about some tricks using which password could be remembered very easily.

So, here are some prescribed steps by Kurt Muhl which can be used to generate a strong password as well as memorize that:

How to make a super-strong password?

  • Try to come up with a sentence which is closely related to you.
That sentence could be “I and family booked a tour to Hawai for $5000”.
  • Once you have come up with that sentence, take out the first alphabet from each of the words. So, here it is how it would look for the above sentence.
“IafbattHf$5”
  • Then, you can map those characters with easily remembered alphabets or letters from your keyboard.

Here is an example to replace some of the alphabets:
A: @
I: 1
L: !
o: 0 (zero)
S: $
Z: 2 etc.

You can come up with your own combinations as well if you think those combinations are easy for to remember.

How NOT to put a password?

  • Do not put passwords after the name of your girlfriend, your date of birth, your city, your postal code, your vehicle number etc.
  • A hacker can make an exhaustive list of these passwords and by using brute force attack, your password might be tried out extensively.

Example of a weak password:

Let’s say, my favourite player is Sachin Tendulkar, I keep telling this to everybody, and his jersey number is 10. In this case, I might come up with a password such as “tendulkar10” which is a bad way of practicing a password.

Here is the complete video article on how to make a strong password.
Source: http://fossbytes.com/trick-to-come-up-with-a-strong-password/

A Hacker Reveals The Easiest Way To Come Up With A Strong Password That's Easy To Remember

Sabtu, 28 Mei 2016

Google’s VirusTotal Can Now Scan Your Firmware For Infection

Short: Google is in the process of adding a new anti-malware detection program in its online malware detection tool VirusTotal. It will be used for scanning BIOS for the legitimate programs installed on it. VirusTotal will also use machine learning to learn from the program behavior and hence finding out the malware.

Latest National Security Agency revelations by Snowden involves many secrets regarding the projects involving infecting BIOS firmware. Apart from the NSA, there are more examples of attempts to inject malware into the firmware of the computer.

Until now, the Antivirus industry has not made anything to detect the malware in the BIOS. BIOS is loaded into memory at the beginning of the boot process. That’s why the main operating system code resides on a memory chip soldered onto the mainboard. Thus, BIOS becomes one of the most targeted virus attacks as the code is loaded into the machine before the startup of the operating system.

This makes a malware residing on the firmware almost impregnable and virtually impossible to detect. They can survive system reboots, system wiping and reinstallations of the operating systems. Until now the firmware malware has been ignored a lot in the Antivirus industry but, Google’s VirusTotal may well change this.

VirusTotal will categorize the BIOS into either a legitimate or a malicious BIOS image. VirusTotal can scan all the operating systems including Windows and Apple Mac BIOS to obtain relevant information about the code on the Flash tool. It uses heuristic detection which is based on machine learning to identify the suspect code as well as looking up for the legitimate executable applications built into the BIOS.

Sometimes, the BIOS manufacturers put a computer legitimate program like computer trace programs. These programs help an owner of the machine to trace the computer in case of lost. VirusTotal will extract these executable files and submits them to the service. It will also enable a user to look into the details of the legitimate executable programs.
VirusTotal Blog
Source: http://fossbytes.com/googles-virustotal-can-now-scan-firmware-infection/

Senin, 09 Mei 2016

Your Facebook account's been hijacked. Here's how to recover it and keep it safe





If a crook succeeds in stealing your Facebook account, they can masquerade as you, find out a good deal about you, and get access to your friends.

If the email address and/or password on your account has changed--and you didn't change it, your account has been hacked. Other possible symptoms that should worry you include new "friends" that you never approved, and status updates and messages allegedly going out from "you" even though you didn't send them.

The following instructions assume that you're accessing Facebook from a full, desktop-oriented browser rather than a mobile browser or app.

First, try to change your Facebook password:
  1. Click the little white triangle near the upper-right corner or the Facebook webpage and select Settings.
  2. This brings you to the Settings page's General tab. Click Password.
  3. Enter your current password in the Current field.
  4. Type a strong password in the New and 'Re-type new' fields. This should be a password you've never used before. I strongly suggest you use a password manager.

When you click Save Changes, Facebook may reject your current password. If it does, whoever hacked your account has already changed it.

Go to Facebook's Report Compromised Account page, click the My Account in Compromised button, and follow the wizard.



But if Facebook accepts the old password (and the new one, of course), you can sigh with relief. You've recovered your account. Facebook will ask if you want it to log off of other devices; take them up on that offer.



Once you've got your Facebook account pages, take some steps to make sure this never happens again:

Back on the Settings page, click the Security tab on the left, then click Login Approvals (also known as 2-step verification). Check Require a security code to access my account from unknown browsers. If you haven't given Facebook your cell number, you'll have to enter it here.

Once you've setup Login Approvals, enable Login Alerts. That way, Facebook will notify you via email if your account is accessed by a browser, app, or device that has never accessed your account before. If you didn't do the logging in, you'll know you have a problem.

Minggu, 29 November 2015

How To Recover Data From An SD Card Or Hard Drive


Are you worried about the files which are deleted ? If yes then don’t worry since there are lot of softwares and tools to recover deleted files from your disk but few works and few might not. Here is the best software that we suggest you to recover your deleted files from your disk. This software have free version and paid version too, its better you go with free version. Using free version we can recover almost all the files which have been deleted or corrupted or formated accidentally.



File Name :- Recuva
File Size :- 4.5 MB
System Requirements :- Windows 8.1, 8, 7, Vista and XP.
Download Link :- Click Here (Link will open in a new tab)