Affichage des articles dont le libellé est email spoofing. Afficher tous les articles
Affichage des articles dont le libellé est email spoofing. Afficher tous les articles

Italian Surveillance Company "HackingTeam" Gets Hacked, 400GBs Data Leaked Online




Italian Surveillance Company "HackingTeam" Gets Hacked, 400GBs Data Leaked Online!

An Italian company which sells spying tools to government and law enforcement agencies has been hacked with 400GB data of internal documents, source code and emails.

Hacking Team is one of the most private companies in the world which sells powerful surveillance tools across the world to the Law Enforcement and Government Intelligence Agencies.

Yesterday their internal network had been breached with 400GBs of data have been compromised and distributed publically on torrents and file sharing sites.

Despite their previous denials of exposing this precious data to companies, they sold their data and tools to countries like Egypt, Ethiopia, Morocco, Nigeria, Sudan, Chile, Colombia, Ecuador, Honduras, Mexico, Panama, United States, Azerbaijan, Kazakhstan, Malaysia, Mongolia, Singapore, South Korea, Thailand, Uzbekistan, Vietnam, Australia, Cyprus, Czech Republic, Germany, Hungary.

This attack was performed by some unknown hackers who exposed their internal private documents on various file sharing sites as well as they replaced the logo of Hacking Team’s twitter account to “Hacked Team” and currently tweeted with images of compromised data.





Regarding this breach, one of the employees of Hacking Team, Christian Pozzi has responded on twitter :

#Update now: 
1. @HackingTeam account restored & @christian_pozzi account deleted.


2. Hacking Team Website Offline:
"503 Service Temporarily Unavailable"



~ lundi 6 juillet 2015 0 commentaires

How To Bypass Two Step Verification Code



How To Bypass Two Step Verification Code? 

Now 2 step authentication are not safe, you guys will shock but its true. The attacker types ../sms in the SMS token field.

Sakurity researchers found the way to bypass the Authy 2 factor Authentication.

Here the details: 

>> The client app encodes it as ..%2fsms and makes an API call to Authy - https://api.authy.com/protected/json/verify/..%2fsms/authy_id

>> Path_traversal middleware decodes path to https://api.authy.com/protected/json/verify/../sms/authy_id,
splits by slashes and removes the directory in front of /...

>> Actual Authy API sees modified path https://api.authy.com/protected/json/sms/authy_id,
simply sends another SMS to authy_id (the victim) and responds with 200 status and {"success":true,"message":"SMS token was sent","cellphone":"+1-XXX-XXX-XX85"}

>> All Authy SDK libraries consider 200 status as a successful response and let the attacker in. Even a custom integration most likely will look for "success":true in the JSON body, and our /sms response body has it. So the only secure way to verify the response is to search for "token":"is valid" substring (which is what Authy libraries do now).

Yes, the attacker was able to bypass 2 factor authentication on any website using Authy with something as simple as "../sms" in the token field!

Source: Sakurati

~ mercredi 18 mars 2015 0 commentaires