PayPal denies to pay Bug Bounty reward to teenager.
A 17-year-old German student contends PayPal has denied him a reward for finding a vulnerability in its website.Robert Kugler said he notified PayPal of the vulnerability on May 19. He said he was informed by email that because he is under 18 years old, he did not qualify for its Bug Bounty Program.
Many companies such as Google and Facebook have reward programs. The programs are intended to create an incentive for website users to report problems and create fixes before hackers can take advantage.
Google pays from $100 up to $20,000 depending on the severity of the issue and Facebook pays a minimum of $500 for qualifying bugs. Neither company has age restrictions listed on their websites.
Labels:
Security News,
Security News.,
vulnerability
Australia's top spy agency headquarters blueprints stolen by Chinese hackers.
Australian Broadcasting Corp. television reported that the plans for the 630 million Australian dollar ($608 million) Australian Security Intelligence Organization building in Canberra had been stolen through a cyberattack on a building contractor.
Australian officials refused to confirm or deny whether Chinese hackers had stolen the blueprints of a new spy agency headquarters as a news report claims.
According to ABC's Four corners the blueprints setting out the building's cable layouts and security systems had been illegally accessed by a server in China.
Under this hacking operations the Prime Minster's Office, the Defence Ministry and the Department of Foreign Affairs had been breached.
Labels:
hackers News,
news,
Security News,
Security News.
iPhone has most vulnerabilities, so why is Android the most attacked?
The biggest story in malware right now is mobile malware. The shift from traditional mobile phones that simply made phone calls to smartphones containing gigabytes of data has made the
pocket-sized computers a prime target for attackers.
There was a 32 percent increase in the number of documented vulnerabilities for mobile operating systems and, not surprisingly, a 58 percent increase in mobile malware and
Android smartphones and tablets are the hottest targets.
Virtually all mobile malware samples detected are intended for Android, ranging from malware that sends out SMS messages, or fraudulent SMS payments, mobile botnets, spyware, and Trojans that can capture or destroy data from Android devices.
There has been biggest spike in malware samples detected in four years, and the growing threat faced by mobile devices—particularly Android mobile devices.
Labels:
android,
Security News,
Security News.,
vulnerability
Nmap ("Network Mapper")
Nmap ("Network Mapper") is a free and open source utility for network exploration or security auditing. Many systems and network administrators also find it useful for tasks such as network inventory, managing service upgrade schedules, and monitoring host or service uptime. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services (application name and version) those hosts are offering, what operating systems (and OS versions) they are running, what type of packet filters/firewalls are in use, and dozens of other characteristics.
Features
- Host discovery - Identify hosts on a network.
- Port scanning - Enumerate the open ports on one or more target hosts.
- Version detection - Interrogate network services listening on remote devices to determine the application name and version number.
- OS detection - Remotely determine the operating system and some hardware characteristics of network devices.
- Scriptable interaction with the target - Using Nmap Scripting Engine and the Lua language, customized queries can be made.
- Reverse DNS lookup.
- Find device type information.
- Retrieve MAC addresses and many more.
Download:-Nmap download
Labels:
Monitoring,
Networking,
Security.
Topera- The IPv6 port scanner invisible to Snort IDS.
Topera is a brand new TCP port scanner under IPv6, with the particularity that these scans are not detected by Snort. Snort is the most known IDS/IPS and is widely used in many different critical environments. Some commercial tools (Juniper or Checkpoint ones) use it as detection engine also. Mocking snort detection capabilities could suppose a high risk in some cases.
Fixed some bugs: - Get local IPv6 address - Get local ethernet interface - sniffer packet counter - Some minor fixes.
You can see an example of execution of Topera in link below demo video.
Download Topera IPv6 port scanner.
Labels:
hacking tools.,
port scanner.
Android app SwiftKey Keyboard turned into a Keylogger app.
One of the best 3rd party Android Mobile Keyboard called 'SwiftKey' turned into a Keylogger Trojan by an Android developer to show the possible security threat of downloading pirated cracked apps from non-official App Stores and websites , "anyone pirating Swiftkey is taking a serious risk" developer said.
He demonstrated
how to inject a Keylogger snippets of code into a legitimate Android
Keyboard application that infected a mobile device with Trojan,
connected with a remote server and transmitted data from the
device inducing your all key logs.
Android apps are coded in Java and compiled to byte code that is
run on the Dalvik VM and this byte code is not that hard to edit and
insert back into an APK." he explained.
He developed a keylogger from SwiftKey(APK Download), a malicious Java program designed to collect and send all key logs to a remote server (Check Keylogs) Along with the host IP address. He explained the complete code also on his blog.
Android malware is growing at a far more rapid pace than for other
mobile platforms. For a Cyber Criminals, it is not important to develop
their own malware program from scratch, Reversing ready-mate apps
and inserting malware code can easily make their job more easy.
Be careful from where you are downloading apps and think about the permissions and consider what the app is asking to do, and
Labels:
APK Download,
cracked apps,
malware,
mobile keylogger,
Security News.,
SwiftKey,
Trojan
Skype Malware that turns computers into Bitcoin miners.
Increasingly desperate to cash in on the sky-rocketing price of Bitcoin these days, gangs of cybercriminals have designed a new malware that’s infecting computers via Skype in an attempt to build a botnet massive enough to start mining the virtual currency.
Researchers from Kaspersky Lab have discovered a new spam message campaign being transmitted via Skype contains malware capable of using an infected computer to mine for Bitcoins. The malware, identified as Trojan.Win32.Jorik.IRCbot.xkt.
According to Kaspersky Lab, the average click rate for the rogue URL is high, at over 2,000 clicks per hour, and the creators of this malware had used it to seize control of hundreds of computers in Russia, Germany, Ukraine, Poland, Spain and other countries.
The malware spreads itself by infecting the Skype VoIP program, using the age old
Labels:
bitcoin miner,
malware,
Security News,
skype,
spam.
Subscribe to:
Posts (Atom)






