Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts
Monday, August 12, 2013
0
Monday, August 12, 2013
Nauman Ashraf
Read More..
FinSpy surveillance software by Gamma Group that surveil activitists
FinSpy surveillance software, marketed worldwide to law enforcement agencies as a way to monitor criminals, is widely used by repressive governments to spy on human rights groups. It is currently used in around 25 countries including US.
The report by researchers at the Citizen Lab at the University of Toronto found the software is "regularly sold to countries where dissenting political activity and speech is criminalized."
What FinSpy Does?
FinSpy, is a surveillance tool that infects computers to capture screenshots, log keystrokes, record Skype conversations and activate cameras and microphones. Gamma Group, a British company, makes the software and markets it to law enforcement agencies as a lawful way to monitor criminals.
How it Infect Internet Users:
The surveillance suite is installed after the target accepts installation of a fake update to commonly used software. Code which will install the malware has also been detected in emails. The software, which is designed to evade detection by anti-virus software, has versions which work on mobile phones of all major brands.
A security flaw in Apple's iTunes allowed unauthorized third parties to use iTunes online update procedures to install unauthorized programs. Gamma International offered presentations to government security officials at security software trade shows where they described how to covertly install the FinFisher spy software on suspect's computers using iTunes' update procedures.
Firefox Masquerading
FinFisher is capable of masquerading as other more legitimate programs, such as Mozilla Firefox. On April 30, 2013, Mozilla announced that they had sent Gamma a cease-and-desist letter for trademark infringement. Gamma had created an espionage program that was entitled firefox.exe and even provided a version number and trademark claims to appear to be legitimate Firefox software.
Martin J. Muench, a Gamma Group managing director, told The New York Times that FinSpy was used mostly “against pedophiles, terrorists, organized crime, kidnapping and human trafficking." He declined to disclose which countries had bought the software.
But security researchers say FinSpy is used by governments around the world for broader purposes. Last year, Citizen Lab researchers found that the government in Bahrain had used FinSpy to target activists in that country.
"Our findings highlight the increasing dissonance between Gamma’s public claims that FinSpy is used exclusively to track 'bad guys' and the growing body of evidence suggesting that the tool has and continues to be used against opposition groups and human rights activists," the researchers wrote.
The report by researchers at the Citizen Lab at the University of Toronto found the software is "regularly sold to countries where dissenting political activity and speech is criminalized."
What FinSpy Does?
FinSpy, is a surveillance tool that infects computers to capture screenshots, log keystrokes, record Skype conversations and activate cameras and microphones. Gamma Group, a British company, makes the software and markets it to law enforcement agencies as a lawful way to monitor criminals.
How it Infect Internet Users:
The surveillance suite is installed after the target accepts installation of a fake update to commonly used software. Code which will install the malware has also been detected in emails. The software, which is designed to evade detection by anti-virus software, has versions which work on mobile phones of all major brands.
A security flaw in Apple's iTunes allowed unauthorized third parties to use iTunes online update procedures to install unauthorized programs. Gamma International offered presentations to government security officials at security software trade shows where they described how to covertly install the FinFisher spy software on suspect's computers using iTunes' update procedures.
Firefox Masquerading
FinFisher is capable of masquerading as other more legitimate programs, such as Mozilla Firefox. On April 30, 2013, Mozilla announced that they had sent Gamma a cease-and-desist letter for trademark infringement. Gamma had created an espionage program that was entitled firefox.exe and even provided a version number and trademark claims to appear to be legitimate Firefox software.
Martin J. Muench, a Gamma Group managing director, told The New York Times that FinSpy was used mostly “against pedophiles, terrorists, organized crime, kidnapping and human trafficking." He declined to disclose which countries had bought the software.
But security researchers say FinSpy is used by governments around the world for broader purposes. Last year, Citizen Lab researchers found that the government in Bahrain had used FinSpy to target activists in that country.
"Our findings highlight the increasing dissonance between Gamma’s public claims that FinSpy is used exclusively to track 'bad guys' and the growing body of evidence suggesting that the tool has and continues to be used against opposition groups and human rights activists," the researchers wrote.
0
Nauman Ashraf
Read More..
TorrentFreak blocked by UK ISP SKY for Privacy
TorrentFreak - a latest news reporting and file sharing site is blocked by British ISP Sky. The four million customers of the popular British ISP Sky are reporting trouble accessing TorrentFreak.
Sky has not blocked the site deliberately. Instead, TorrentFreak has really been made inaccessible by EZTV.it, the popular torrent site that’s being blocked by six UK ISPs in response to a High Court ruling.
EZTV utilized Geo DNS to redirect its UK visitors to TorrentFreak.com. Nonetheless, a fault in Sky’s filtering scheme makes any site that’s added to EZTV’s DNS inaccessible to customers.
For research purposes, EZTV even attempted to add some of Facebook’s IP addresses to their DNS. However, it didn’t work, possibly because of the wide range of IPs.
Unfortunately, Sky isn’t in a hurry to amend the problem, TorrentFreak says. Even so, EZTV will get rid of the sites IPs from its DNS to allow users to access it.
Sky has not blocked the site deliberately. Instead, TorrentFreak has really been made inaccessible by EZTV.it, the popular torrent site that’s being blocked by six UK ISPs in response to a High Court ruling.
EZTV utilized Geo DNS to redirect its UK visitors to TorrentFreak.com. Nonetheless, a fault in Sky’s filtering scheme makes any site that’s added to EZTV’s DNS inaccessible to customers.
For research purposes, EZTV even attempted to add some of Facebook’s IP addresses to their DNS. However, it didn’t work, possibly because of the wide range of IPs.
“It appears that Sky’s filtering system blocks any and all IP-addresses that EZTV adds to their DNS. This essentially means that EZTV, or any other blocked site, has the power to render entire websites inaccessible to Sky subscribers. Luckily we were the target and not Google,” TorrentFreak noted.It seems only Sky is using this filtering system, since the news website can be accessed by the customers of other ISPs around the world.
Unfortunately, Sky isn’t in a hurry to amend the problem, TorrentFreak says. Even so, EZTV will get rid of the sites IPs from its DNS to allow users to access it.
Saturday, July 27, 2013
0
Saturday, July 27, 2013
Nauman Ashraf
Read More..
List of Free VPN to Protect Privacy
Virtual Private Networks, or VPNs for short, is necessary for privacy these days. If you want to open blocked sites in US, UK, India, China etc. or if you want to browse the web anonymously, then using a good VPN service is what you need. Some websites like pandora.com, hulu.com, ABC.com, BB.co.uk etc. are restricted to be available only in certain countries. The trick to open any such website is to use a VPN service or a proxy based in that country.
There are lots of VPNs to choose from, some of which are free, some of which are not — We will talk about free VPNs. The List below is some of the top free VPN services around for circumventing censorship at home and at the workplace and for protecting your identity and data from prying eyes; especially useful for public Wi-Fi connections.
List of Free VPN:
Super Free VPN
http://www.superfreevpn.com/
Anchor Free
http://www.anchorfree.com/
Free VPN Access
http://www.freevpnaccess.com/
Just Free VPN
http://www.justfreevpn.com/
VPN Book
http://www.vpnbook.com/
ProXPN
http://proxpn.com/
Free Cloud VPN
http://www.freecloudvpn.com/
A Free VPN
http://www.afreevpn.com/
PPTP VPN
http://www.pptpvpn.org/
Best VPN USA
http://www.bestvpnusa.com/
US IP VPN
http://www.usipvpn.com/
USA Free VPN
http://usafreevpn.com/
Free Canada VPN
http://www.freecanadavpn.com/
USA New Free VPN
http://us.newfreevpn.com/
Security Kiss
http://www.securitykiss.com/pricing/
Comodo VPN
http://www.comodo.com/home/download/download.php?prod=comodounite
There are lots of VPNs to choose from, some of which are free, some of which are not — We will talk about free VPNs. The List below is some of the top free VPN services around for circumventing censorship at home and at the workplace and for protecting your identity and data from prying eyes; especially useful for public Wi-Fi connections.
List of Free VPN:
Super Free VPN
http://www.superfreevpn.com/
Anchor Free
http://www.anchorfree.com/
Free VPN Access
http://www.freevpnaccess.com/
Just Free VPN
http://www.justfreevpn.com/
VPN Book
http://www.vpnbook.com/
ProXPN
http://proxpn.com/
Free Cloud VPN
http://www.freecloudvpn.com/
A Free VPN
http://www.afreevpn.com/
PPTP VPN
http://www.pptpvpn.org/
Best VPN USA
http://www.bestvpnusa.com/
US IP VPN
http://www.usipvpn.com/
USA Free VPN
http://usafreevpn.com/
Free Canada VPN
http://www.freecanadavpn.com/
USA New Free VPN
http://us.newfreevpn.com/
Security Kiss
http://www.securitykiss.com/pricing/
Comodo VPN
http://www.comodo.com/home/download/download.php?prod=comodounite
Thursday, July 18, 2013
0
Thursday, July 18, 2013
Nauman Ashraf
Read More..
Blackberry 10 Sends Full Email Account Credentials To RIM
Anyone who has ever used his email account with a current BlackBerry, should think seriously to change his password: When setting up an email account on the BlackBerry 10, It sends the entered credentials to the server in Canada without the consent of the User.
When you enter your POP / IMAP e-mail credentials into a Blackberry 10 phone they will be sent to Blackberry without your consent or knowledge. A server with the IP 68.171.232.33 which is in the Research In Motion (RIM) netblock in Canada will instantly connect to your mailserver and log in with your credentials, a German based security researcher Frank Rieger writes.
If you have not forced SSL/TLS configured on your mail server, your credentials will be sent in the clear by the Blackberrys server for the connection. Blackberry thus has not only your e-mail credentials stored in its database, it makes them available to anyone sniffing in-between – namely the NSA and GCHQ as documented by the recent Edward Snowden leaks.
You should delete your e-mail accounts from any Blackberry 10 device immediately, change the e-mail password and resort to use an alternative mail program like K9Mail, Researcher writers.
Clarification: this issue is not about PIN-messaging, BBM, push-messaging or any other Blackberry service where you expect that your credentials are sent to RIM. This happens if you only enter your own private IMAP / POP credentials into the standard Blackberry 10 email client without having any kind BER, special configuration or any explicit service relationship or contract with Blackberry. The client should only connect directly to your mail server and nowhere else. A phone hardware vendor has no right to for whatever reason harvest account credentials back to his server without explicit user consent and then on top of that connect back to the mail server with them.
Recipe for own experiment:
1. set up your own mail server with full logging
2. create throw-away IMAP account
3. enter IMAP account credentials into Blackberry 10 device, note time
4. check mail with Blackberry
5. look in logfiles for IP 68.171.232.33 (or others from RIM netblock)
Update:
Since some diehard Blackberry friends doubted the veracity of this discovery here are example logfiles from dovecot and smtpd. The original domain has been replaced with “mymailserver.org” and the IP with “217.xxx.xxx.xxx”.
I started configuring the mail account 13:46. As can be clearly seen, long before there is a successful connect from my mobile operator E-Plus (46.115.99.217) that should have happened in the very first place, the Blackberry server 68.171.232.33 connected back to my mailserver apparently trying to figure out the correct configuration for the account, as soon as I had entered user, password and mailserver name. And it logged in sucessfully with my e-mail credentials after figuring out the correct SSL / TLS configuration, Reiger writers.
smtpd log:
Jul 17 13:47:12 mymailserver vpopmail[98463]: vchkpw-submission: (PLAIN) login success frank@mymailserver.org:68.171.232.33
Jul 17 13:47:12 mymailserver vpopmail[98464]: vchkpw-submission: (PLAIN) login success frank@mymailserver.org:68.171.232.33
Jul 17 13:47:13 mymailserver vpopmail[98465]: vchkpw-smtp: (PLAIN) login success frank@mymailserver.org:68.171.232.33
Jul 17 13:47:13 mymailserver vpopmail[98466]: vchkpw-smtp: (PLAIN) login success frank@mymailserver.org:68.171.232.33
Jul 17 13:48:59 mymailserver vpopmail[98580]: vchkpw-smtp: (PLAIN) login success frank@mymailserver.org:46.115.99.217
dovceot log:
Jul 17 13:47:11 auth(default): Info: vpopmail(frank@mymailserver.org,68.171.232.33): lookup user=frank domain=mymailserver.org
Jul 17 13:47:11 auth(default): Info: client out: OK 1 user=frank@mymailserver.org
Jul 17 13:47:11 auth(default): Info: vpopmail(frank@mymailserver.org,68.171.232.33): lookup user=frank domain=mymailserver.org
Jul 17 13:47:11 auth(default): Info: master out: USER 96457 frank@mymailserver.org uid=89 gid=89 home=/usr/local/vpopmail/domains/mymailserver.org/frank
Jul 17 13:47:11 imap-login: Info: Login: user=<frank@mymailserver.org>, method=PLAIN, rip=68.171.232.33, lip=217.xxx.xxx.xxx, TLS
Jul 17 13:47:11 auth(default): Info: vpopmail(frank@mymailserver.org,68.171.232.33): lookup user=frank domain=mymailserver.org
Jul 17 13:47:11 auth(default): Info: client out: OK 1 user=frank@mymailserver.org
When you enter your POP / IMAP e-mail credentials into a Blackberry 10 phone they will be sent to Blackberry without your consent or knowledge. A server with the IP 68.171.232.33 which is in the Research In Motion (RIM) netblock in Canada will instantly connect to your mailserver and log in with your credentials, a German based security researcher Frank Rieger writes.
If you have not forced SSL/TLS configured on your mail server, your credentials will be sent in the clear by the Blackberrys server for the connection. Blackberry thus has not only your e-mail credentials stored in its database, it makes them available to anyone sniffing in-between – namely the NSA and GCHQ as documented by the recent Edward Snowden leaks.
You should delete your e-mail accounts from any Blackberry 10 device immediately, change the e-mail password and resort to use an alternative mail program like K9Mail, Researcher writers.
![]() |
| Source: www.heise.de |
Recipe for own experiment:
1. set up your own mail server with full logging
2. create throw-away IMAP account
3. enter IMAP account credentials into Blackberry 10 device, note time
4. check mail with Blackberry
5. look in logfiles for IP 68.171.232.33 (or others from RIM netblock)
Update:
Since some diehard Blackberry friends doubted the veracity of this discovery here are example logfiles from dovecot and smtpd. The original domain has been replaced with “mymailserver.org” and the IP with “217.xxx.xxx.xxx”.
I started configuring the mail account 13:46. As can be clearly seen, long before there is a successful connect from my mobile operator E-Plus (46.115.99.217) that should have happened in the very first place, the Blackberry server 68.171.232.33 connected back to my mailserver apparently trying to figure out the correct configuration for the account, as soon as I had entered user, password and mailserver name. And it logged in sucessfully with my e-mail credentials after figuring out the correct SSL / TLS configuration, Reiger writers.
smtpd log:
Jul 17 13:47:12 mymailserver vpopmail[98463]: vchkpw-submission: (PLAIN) login success frank@mymailserver.org:68.171.232.33
Jul 17 13:47:12 mymailserver vpopmail[98464]: vchkpw-submission: (PLAIN) login success frank@mymailserver.org:68.171.232.33
Jul 17 13:47:13 mymailserver vpopmail[98465]: vchkpw-smtp: (PLAIN) login success frank@mymailserver.org:68.171.232.33
Jul 17 13:47:13 mymailserver vpopmail[98466]: vchkpw-smtp: (PLAIN) login success frank@mymailserver.org:68.171.232.33
Jul 17 13:48:59 mymailserver vpopmail[98580]: vchkpw-smtp: (PLAIN) login success frank@mymailserver.org:46.115.99.217
dovceot log:
Jul 17 13:47:11 auth(default): Info: vpopmail(frank@mymailserver.org,68.171.232.33): lookup user=frank domain=mymailserver.org
Jul 17 13:47:11 auth(default): Info: client out: OK 1 user=frank@mymailserver.org
Jul 17 13:47:11 auth(default): Info: vpopmail(frank@mymailserver.org,68.171.232.33): lookup user=frank domain=mymailserver.org
Jul 17 13:47:11 auth(default): Info: master out: USER 96457 frank@mymailserver.org uid=89 gid=89 home=/usr/local/vpopmail/domains/mymailserver.org/frank
Jul 17 13:47:11 imap-login: Info: Login: user=<frank@mymailserver.org>, method=PLAIN, rip=68.171.232.33, lip=217.xxx.xxx.xxx, TLS
Jul 17 13:47:11 auth(default): Info: vpopmail(frank@mymailserver.org,68.171.232.33): lookup user=frank domain=mymailserver.org
Jul 17 13:47:11 auth(default): Info: client out: OK 1 user=frank@mymailserver.org
Thursday, April 18, 2013
0
Thursday, April 18, 2013
Nauman Ashraf
Svartholm Warg charged with “three counts of computer hacking, one case of serious fraud, and a case of attempted aggravated fraud.”
First hack charges involves allegedly hacking and using a username and password of a person to search Infotorg, a well-known massive privately held commercial database of “private individuals, companies, properties and vehicles.”
The second hack charges include an alleged hack of Logica in 2010. On March 2012, Logica was hit by an online attack that resulted in around 9,000 Swedes (Google Translate) having their personal identity numbers and names released to the public.
The third hacking charge, accuses Svartholm Warg of unauthorized access to major Nordic region bank Nordea’s computers. The fraud charges accuse Svartholm Warg of allegedly transferring and attempting to transfer money from Nordea to other unauthorized bank accounts. Svartholm Warg allegedly tried to transfer 5.7 million Swedish kronor ($900,000) to various accounts. However, only 27,000 kronor (roughly $4,200) belonging to a Danish trade union was actually transferred out.
According to the indictment, evidence includes a confiscated computer as well as transcripts of online chats between Svartholm Warg and the three other suspects charged in the case. Since December, Svartholm Warg has been held in a prison in Mariefred in central Sweden where he is serving out a prison sentence related to his activities with The Pirate Bay. Svartholm Warg and his fellow Pirate Bay co-founders Fredrik Neij and Peter Sunde, as well as financier Carl Lundström, were all convicted in 2009 of facilitating copyright infringement and ordered to pay 46 million kronor ($6.9 million) in damages to the music and movie industry.
Read More..
The Pirate Bay co-founder charged for hacking attacks
The Pirate Bay founder Gottfrid Svartholm Warg charged in Sweden on suspicions for hacking into several Swedish agencies and companies and money transfer from the Nordea bank. Svartholm Warg was arrested in Cambodia and deported to Sweden in September last year due to an arrest warrant issued for him in relation to his conviction in the Pirate Bay trial.
"A large amount of data from companies and agencies was taken during the hack, including a large amount of personal data, such as personal identity numbers (personnummer) of people with protected identities," prosecutor Henrik Olin said in a statement.
-->
"A large amount of data from companies and agencies was taken during the hack, including a large amount of personal data, such as personal identity numbers (personnummer) of people with protected identities," prosecutor Henrik Olin said in a statement.
Svartholm Warg charged with “three counts of computer hacking, one case of serious fraud, and a case of attempted aggravated fraud.”
First hack charges involves allegedly hacking and using a username and password of a person to search Infotorg, a well-known massive privately held commercial database of “private individuals, companies, properties and vehicles.”
The second hack charges include an alleged hack of Logica in 2010. On March 2012, Logica was hit by an online attack that resulted in around 9,000 Swedes (Google Translate) having their personal identity numbers and names released to the public.
The third hacking charge, accuses Svartholm Warg of unauthorized access to major Nordic region bank Nordea’s computers. The fraud charges accuse Svartholm Warg of allegedly transferring and attempting to transfer money from Nordea to other unauthorized bank accounts. Svartholm Warg allegedly tried to transfer 5.7 million Swedish kronor ($900,000) to various accounts. However, only 27,000 kronor (roughly $4,200) belonging to a Danish trade union was actually transferred out.
According to the indictment, evidence includes a confiscated computer as well as transcripts of online chats between Svartholm Warg and the three other suspects charged in the case. Since December, Svartholm Warg has been held in a prison in Mariefred in central Sweden where he is serving out a prison sentence related to his activities with The Pirate Bay. Svartholm Warg and his fellow Pirate Bay co-founders Fredrik Neij and Peter Sunde, as well as financier Carl Lundström, were all convicted in 2009 of facilitating copyright infringement and ordered to pay 46 million kronor ($6.9 million) in damages to the music and movie industry.
Wednesday, April 17, 2013
0
Wednesday, April 17, 2013
Nauman Ashraf
Read More..
How Strangers Can Read Your Private Facebook Messages
If your private message is flagged by Facebook automated tools, then Facebook team/employees are going to your message and contact law enforcement if its regarding child exploitation.
Facebook has a team of employees who read your private messages if they have been flagged by an automated tool. The tool searches for content that appears to violate their terms of service, namely malicious (infected) URLs or child pornography. It's imperfect, of course — that's where humans come in, According to BuzzFeed.
If a private message is flagged, actual people will jump in and read it. If there is something that could be illegal — particularly regarding child exploitation — those people contact law enforcement. The intent here is clear and defensible, yet the fact remains: All that stands between your "private" messages and the eyes of a stranger is the snap judgment of an algorithm, BuzzFeed adds.
It's not just Facebook. Dating site OkCupid has humans read private messages that have been flagged by its users.Twitter doesn't monitor direct messages either through automated tools or humans.
Facebook has a team of employees who read your private messages if they have been flagged by an automated tool. The tool searches for content that appears to violate their terms of service, namely malicious (infected) URLs or child pornography. It's imperfect, of course — that's where humans come in, According to BuzzFeed.
If a private message is flagged, actual people will jump in and read it. If there is something that could be illegal — particularly regarding child exploitation — those people contact law enforcement. The intent here is clear and defensible, yet the fact remains: All that stands between your "private" messages and the eyes of a stranger is the snap judgment of an algorithm, BuzzFeed adds.
It's not just Facebook. Dating site OkCupid has humans read private messages that have been flagged by its users.Twitter doesn't monitor direct messages either through automated tools or humans.
Subscribe to:
Posts
(
Atom
)






