Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Thursday, March 10, 2011

Hackers unleash fake Google Android update

Symantec says the malware, which purports to be Google's latest security update for Android, sends SMS messages to a command-and-control server

Google's latest update for its Android mobile OS appears to already have been subverted by hackers, according to the security vendor Symantec.


Symantec found an application called the "Android Market Security Tool" that is a repackaged version of the legitimate update by the same name that removed the DroidDream malware from infected devices.

The fake security tool sends SMSes to a command-and-control server, wrote Mario Ballano of Symantec.

The company is still analyzing the code, which it found on a third-party application market targeted at Chinese users.

"What is shocking is that the threat's code seems to be based on a project hosted on Google Code and licensed under the Apache License," Ballano wrote.

The fake security tool shows that hackers are taking an interest in Android, which is the fastest growing mobile OS according to analyst Gartner. More than 67 million Android devices were sold last year.

Google took the rare step last week of forcing the "Android Market Security Tool March 2011" onto devices to remove DroidDream. Typically, phone manufacturers and operators are responsible for issuing updates to devices, not Google.

The move came after more than 50 applications within Google's official Android Market were found to be contaminated with DroidDream, which stole information such as the phone's International Mobile Equipment Identity (IMEI) number and the SIM card's International Mobile Subscriber Identity (IMSI) number, and sent it to a server located in Fremont, California.

DroidDream could also download other code to a person's mobile phone. It used two exploits called "exploid" and "rageagainstthecage" to infect the phone. Google has patched the vulnerabilities in Android versions above 2.2.2, but many Android users do not have the latest version of the software.

The "Android Market Security Tool March 2011" does not actually fix the vulnerability that allowed DroidDream to infect phones but merely removes the malware, wrote Timothy Armstrong, a junior malware analyst with Kaspersky Lab, in a blog post.

The intervention by Google also underscores problems with how Android is updated, he wrote.

"Due to the nature of Android in its current state, it's very difficult and expensive to push security updates as you would on a desktop operating system like Linux or Windows," Armstrong wrote. "Unlike iPhone, which installs patches via iTunes, or Windows Mobile which uses ActiveSync, Android works almost entirely via over-the-air communication."

Google officials contacted in London did not have an immediate comment.

Saturday, January 15, 2011

HackCenter to Hack Games on Game Center

Well, here's a great hack for all Game Center players, this hack will allow you to send any score you want to any game in Game Center, this hack called "Hack Center", it will be available at Cydia soon, in the below embedded video you will see how to use HackCenter to submit a fake score for "Fruit Ninja".
[via 9to5mac]

Wednesday, September 29, 2010

An Interview With the Vincent About GreenPois0n Jailbreak [EXCLUSIVE]

Ok, we are very close to see the new jailbreak tool GreenPois0n so I'm receiving a huge number of questions (i.e. Facebook page, and Twitter) about release date, untethered status of the new jailbreak tool. Also, we received questions about the new Cydia update, so we asked Vincent (known as @veeence) for a quick interview to answer all questions that being asked about Greenpois0n, Cydia and Ultrasn0w unlock, here's the full interview below.
Q1: At first, identify yourself? some people think you are the administrator of iPhone Wiki? Right?
No, I'm not the admin of the iPhone wiki. The guys over at Redmond Pie misinterpeted that. I follow the jailbreak scene very closely and read a lot about the exploits, vulnerabilities and payloads on the iPhone Wiki. On my twitter I tweet (and answer questions) about jailbreak related things. I did some minor things like porting the blacksn0w unlock to 4.0 beta's (with help of msft.guy).
Q2: What's SHAtter and how it works?
SHAtter is a bootrom exploit. It's very likely that it has something to do with the signchecking of the SHA-1 in the IMG3 files, but nothing is sure right now. Whether it's tethered or untethered is unknown yet. (my honest *guess* (!!) is that it will be untethered. see Q7)
Q3: What about Greenpois0n? Will it be the name of the new Jailbreak?
Originally greenpois0n is a set of tools that is designed to help hackers in their search for vulnerabilities and exploits. I'm not sure whether they are going to give the new jailbreak that uses the SHAtter exploit the name "greenpois0n". Would be kinda lame, though, greenpois0n is now widely known as "THE new jailbreak" so it might be good (to prevent confusion) to name it greenspois0n.
Q4: What are the compatible devices with this jailbreak?
All that are available right now. Though, users of the old bootrom units should use the 24kpwn and Pwnage 2.0 already as it is probably superior to SHAtter.
Q5: Who are the developers of the new jailbreak tool?
The Chronic Devteam (posixninja, chronic etc.) and I think guys from the iPhone Dev-Team (MuscleNerd) help them developing the jailbreak.
Q6: Will the new jailbreak really act on the bootrom and jailbreak devices forever?
Yes, a bootrom exploit means Pwnt for life (pwnt4life). The device will always be vulnerable to this SHAtter exploit, which will make it possible to jailbreak. The bootrom cannot softwarematically be updated by Apple. They will have to do a hardware revision (like they did with the 3GS after September 09). What the conditions of SHAtter are, are again unknown. I believe that this exploit is different from others in this way, so I don't want to speculate on that.
Q7: The most interesting question, Will it be Untethered or Tethered? (please give me a different answer from "don't know")
My source (which I can't reveal) says, untethered. I don't want to shout it out all over the web and my twitter because 1. I can't reveal my source and 2. It's not 100% sure yet. We'll have to see.
Q8: There's a tweet from MuscleNerd saying that @comex is working on userland exploit, any ideas what does this mean?
Comex has exploits in private for another usrland jailbreak. But since Chronic Dev came up with SHAtter, he probably put his exploits in his fridge (you know what I mean ;-) )
Q9: What about unlocking baseband 05.14 and 2.10? is it difficult of be unlocked?
Whether an unlock will be released for 05.14 and 2.10 is unknown yet. If there will be an unlock, it'll come from the iPhone Dev-Team (MuscleNerd). They just need another command that creates the right baseband crash to inject the ultrasn0w payload. I don't know if they have one in private.
Q10: Any info about the release date of new jailbreak tool? (any any info)
No, sorry. I could say a lot of things, but what would you be with that if it isn't the truth?
Q11: People are reporting crashes and errors in Cydia, will this be fixed in the new Cydia update?
Send your crashlogs to @chpwn and he will very likely take a look at it and, if possible, fix it :)
Q12: What are the new features that will be added to Cydia in the next update?
I read things like a rate/comment system and I really hope speeds improvements by hiding the themes or something like that. If you have suggestions, send them to @chpwn.
Q13: Will the new update be released with the jailbreak? before? after?
Maybe together, but I think those project are separate projects and will both see daylight when they're ready for release.
Q14: Will the new jailbreak tool be different from Spirit and Blackra1n?
Different in a way of exploits, yes. Different in a way of applying the jailbreak to your device, no. The SHAtter exploit will make use of a USB connection, so you will need a computer to jailbreak your device. I won't be as easy as JailbreakMe this time ;-)
You may notice in Q10 about release date, there was no answer yet! But now, we have got an answer about the release date from pod2g which confirms that it's coming in the next few days (may be less than a week). We would thank Vincent for accepting to answer all questions and giving all information about the new jailbreak, Cydia updates and the unlock.

You may also like:

Thursday, August 19, 2010

PS 3 ModChip is Here, Pre-Order now [PS Jailbreak]

Early this morning, we already reported you that PS3 is finally hacked successfully using a piece of ModCip, and watch out! it's here, the PS 3 ModChip is finally available to pre-order and will be shipped by August 27th to jailbreak PS 3 and you will be able to run games without original disks.
I think that the problem of most of you would be the price as it's available on OzmodChips for $169 and this is not a cheap price for hacking a PS3! Whatever, I think it works as guys on Elotrolado an Redboxmodds has already tested the delivered chips and it works perfect!

To get your PS3 hacked, you have to pre-order this modchip from OzmodoChips from here and it will be arrived by August 27th, after that you will need to follow instructions over at PS Jailbreak to install the backup manager which will allow you to dump games into the PlayStation! Stay tuned for any updates and results after receiving the modchip!

You have to check out this:
How to: Jailbreak PlayStation 3 (PS3) With PS Jailbreak.

Wednesday, July 7, 2010

Apple Says Only 400 iTunes Accounts Compromised

Apple has informed Clayton Morris that Only 400 iTunes Accounts Compromised and this is a very small percentage -- 0.0003% of iTunes accounts, Also Apple has banned that Vietnamese hacker, Thuat Nguyen
Apple told me that an extremely small percentage of users, about 400 of the 150 million iTunes users - that is less than 0.0003% of iTunes users, were impacted.
Read More

Tuesday, July 6, 2010

Apple Responses to iTunes Accounts Hacking Issue?

Two days ago, I told you that most of iTunes accounts got hacked by a Vietnamese Hacker and Apple should do something about that! Now Engadget is reporting the Official Apple's press release, check it after the break..
The developer Thuat Nguyen and his apps were removed from the App Store for violating the developer Program License Agreement, including fraudulent purchase patterns.

Developers do not receive any iTunes confidential customer data when an app is downloaded.

If your credit card or iTunes password is stolen and used on iTunes we recommend that you contact your financial institution and inquire about canceling the card and issuing a chargeback for any unauthorized transactions. We also recommend that you change your iTunes account password immediately. For more information on best practices for password security visit http://www.apple.com/support/itunes.

Sunday, July 4, 2010

iTunes Accounts got Hacked by Vietnamese Guy!

Did you get your iTunes account hacked? Yes I think so, Go ahead and Check for it Now because a Vietnamese Developer, If you navigate to Books category of iPhone App Store and Check top paid apps, You will notice that there's a Developer who owns 40 apps. (WTF)
Also guys on The Next Web reporting that they got their iTunes accounts Hacked and they found themselves owners of the 40 apps.

Here's another iPhone Developer reporting that a Vietnamese Developer is hacking iTunes Accounts, he was the first who find that:
I’m the developer of the QuickReader iPhone application. I’ve been noticing over the past few days that my app along with yours has been slipping down in the rankings. On trying to figure out why, I discovered what appears to be a concerted and criminal effort to game the Books category rankings.

It looks like the Books category has been hijacked by an app publisher named mycompany/Thuat Nguyen. His apps now occupy 40 of the top 50 ranks in the Books category on the app store. These are apps that typically wouldn’t rank in the Books category and most of them don’t have any ratings or reviews. However if you look at the reviews for the Conan 3 app, you can see that 2 reviewers complain (as early as Monday the 28th) that their iTunes accounts were hacked and the apps were purchased by the hacker. It would appear that this publisher is hacking accounts and buying his own apps in order to drive up his rankings in the Books category.

This is having a negative impact on our apps, which are being pushed down in the rankings and losing visibility, plus it makes for a bad user experience.
[via MacStories]
Got your iTunes Account Hacked? Hope you report us here and We will help you when we get Support for this ... Vitenamese!

Update 1: Also some members of Mac Rumors got their iTunes accounts hacked, What the hell is going up there!
I had a similar issue around christmas time - i tried to buy a song using my account (as I have done many times). iTunes rejected my password - i definatley typed it in right! I reset it to what it was before and then it was ok.

I was worried someone had got into my account but i dont see anything being bought that I didnt so i assume was just a glitch.....
Update 2: Some tips you may follow:
  1. At first, you should Change your password Immediately, then continue reading!
  2. Check for your recent purchases history, if you found something wrong with it, REPORT Apple.
  3. Remove your credit card details by setting the “Payment Method” to “None”
  4. If you really still serving or hacked, Report us by commenting down here, and I may solve it for you! 
Update 3: Apple has successfully removed the apps by the developer, check here.