Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Sunday, November 27, 2011

Apps : Siri hacks control your car and media center

via img.skitch.com
The Siri proxy hack allows developers to catch custom phrases and act on them, expanding the functionality of Apple's voice-controlled personal assistant. This work is being employed by other developers, and a few exciting uses for the hack have already started to appear.
First up, Brandon Fiquett has written code that allows him to start, stop, open the trunk, and activate the alarm in his Acura using the kind of voice controls we've come to expect from Siri. The hack works alongside his Viper car automation and security system, with Siri communicating with his proxy server, which forwards commands on to the cellular-connected car.
Second, an Icelandic developer named Hjalti Jakobsson has created a plugin for Plex, allowing you to ask for "Seinfeld season five, episode one" — and returning either the episode title or an apology if it can't find the show you're after. The system is impressively fast, with no lag between sending the command and playback beginning.
While the source code for the car control is available for download now, the Plex controller still requires some work before it's ready for primetime. You'll still need to set up your own proxy server though, and we know that for some of you the thought of adding a modified root certificate to your iPhone is out of the question.






Saturday, November 5, 2011

Tech : iSpy software can read texts and steal passwords

We spy, with our bleary eye, a new piece of software that could make it dramatically easier to steal personal data. The program, known as iSpy, allows devious voyeurs to remotely identify and read text typed on touchscreen displays. That, in and of itself, isn't exactly new, but iSpy takes shoulder surfing to slightly terrifying new areas -- namely, those beyond the "shoulder." Developed by Jan-Michael Frahm and Fabian Monrose of the UNC-Chapel Hill, this program, like those before it, takes advantage of the magnified keys found on most touchscreens. All you'd have to do is point a camera at someone else's screen and iSpy will automatically record whatever he or she types by stabilizing the video footage and identifying the enlarged keys. If you're using a smartphone camera, you'll be able to eavesdrop from up to three meters away, but if you opt for a more heavy duty DSLR device, you could steal passwords from up to 60 meters away. The software can also recognize any words typed into a device, and, according to its architects, can identify letters with greater than 90 percent accuracy. When used with a DSLR camera, iSpy can even pick up on reflections of touchscreens in sunglasses or window panes from up to 12 meters away. To avoid this, Frahm and Monrose recommend disabling the magnified key function on your smartphone, or using some sort of screen shield.

Monday, August 8, 2011

Rides : Hackers show that they can unlock a Subaru Outback and start engine via text message

Hackers show that they can unlock a Subaru Outback and start engine via text message 2011 Subaru Outback
At the Black Hat security conference that took place recently in Las Vegas, there was a demonstration of the Subaru Outback being unlocked and its engine being started remotely. The event was conducted by two security researchers from iSec Partners named Don Bailey and Matthew Solnik. They got an Android phone and used a technique they referred to as 'war texting' wherein they used two unnamed remote control products that are for locking and unlocking.
After setting up their own GSM network, it took them just two hours to intercept the password authentication messages between the server and the car. They said that this technique could be used to hit other systems that receive firmware updates through text messages, according to TGDaily. These include traffic control systems and security cameras. It’s worrisome that this technique could be used on SCADA sensors, which are employed in industrial systems like the power grid and water supply.
Bailey said that the “real threat” would be if this technique controls power, phone, or traffic systems. They declined to provide details about how the hacking is accomplished or to say what cars are at risk until the manufacturers get the chance to fix the vulnerabilities. Notably, similar remote-control apps are used by General Motors, BMW and Mercedes. In May 2010, other security researchers have successfully attempted to remotely control cars. A group from the University of Washington used a diagnostic computer system named the Controller Area Network to control the locks and the brakes of the cars remotely.

Saturday, July 16, 2011

Hotmail adds 'My friend's been hacked!' feature to finger phishers

Hotmail adds Hotmail's spent the past few years playing catch up with the competition, but for the most part, it hasn't done anything particularly groundbreaking with its services. Earth shattering might not be the appropriate descriptor for its latest addition, but Hotmail's added a helpful new feature to distinguish plain old spam from the kind that comes form a trusted source. Now, when you get an email from a friend that smells of something sea dwelling -- say a plea for some extra scratch from abroad -- you can select "My friend's been hacked!" from the "Mark as" menu, alerting the powers that be that your friend's account has been hacked. When you mark a missive as junk, you can likewise click a box that reads: "I think this person was hacked!" Once that's done, the spammers are kicked to the curb, and your friend is put through an "account recovery flow" the next time they attempt to log in. On the prevention front, Hotmail will soon roll out a new service that blocks users from selecting common passwords. It might not be enough to coax us over, but maybe this time the other guys could learn a few lessons.

Monday, June 20, 2011

Gaming : Sega's online Pass hacked, 1.3 million user passwords stolen

Let's bid a bitter welcome to Sega, the latest entrant to the newly founded club of hacked online communities. Sega Pass, the company's web portal, suffered a breach of its defenses on Thursday, which has now been identified to have affected a whopping 1.29 million users. Usernames, real names, birth dates, passwords, email addresses, pretty much everything has been snatched up by the malicious data thieves, with the important exception of credit / debit card numbers. We'd still advise anyone affected to keep a watchful eye on his or her banking transactions -- immediately after changing that compromised password, of course. In the meantime, Sega's keeping the Pass service offline while it rectifies the vulnerability; it'll be able to call on an unexpected ally in its search for the perpetrators in the form of LulzSec, a hacker group that boasted proudly about infiltrating Sony's network, but which has much more benevolent intentions with respect to Sega.

Friday, February 4, 2011

Check Where You're Logged Into Gmail


Gmail Account
Gmail has a neat little feature that lets you check where your account is logged in and see all of its recent activity. All the way at the bottom of the screen (in very tiny text) you'll find a notification of where your account is currently logged in. Click on the 'Details' link and you'll get a full list of where your account is being accessed from, whether it's via a browser or mobile device, the country of origin and an IP address. You can even check a recent history of when, where and how the account was accessed. And, of course, you can sign out of other sessions. This is handy in case you forget to sign out from a public PC or a friend's computer, and serves as a good alert if someone hacks your account.

Tuesday, January 18, 2011

Rides - tech : How Hackers Can Use Smart Keys To Steal Cars

How Hackers Can Use Smart Keys To Steal CarsModern smart keys use radio frequencies to let drivers unlock and start a vehicle without fumbling with a key fob. Now European researchers have found such systems can be hacked, letting thieves easily steal your car.

We've written before about hackers testing the increasingly complex electronics inside vehicles, which typically lack basic security measures. While many of the hacks require access to the car's diagnostic port, one team was able to wirelessly set off faults through tire pressure sensors.

The research by the team from the Swiss Federal Institute of Technology targeted a new weakness; the smart key fobs common on luxury vehicles and spreading to mainstream models that allow a driver to unlock doors and start a vehicle without touching the fob. Using radio signals, the fob and vehicle send encrypted signals to each other over short distances, and while other researchers had suggested the fobs could be vulnerable, no one had put the idea to a test.

Using ten different borrowed models from eight manufacturers (without the automakers' input), the Swiss team was able to unlock and start all of their test vehicles, showing that hacking the smart fobs is "feasible and practical." Their system simply used two antennas; one carried by the hacker trying to get in and start the vehicle, the other in the vicinity of the fob, to amplify the signals between the transmitters and break in.

How Hackers Can Use Smart Keys To Steal CarsWith both wired and wireless connections between their antennas, the team was able to unlock and start vehicles even when up to eight meters away from the key fob holder. They didn't have to touch or alert the owner; just getting their antenna within a few meters of the fob was enough to pick up the signals that were then sent to the vehicle for unlocking and starting the car. Once the vehicles started, they stayed running despite the fob not being present, a feature automakers use to keep dead fob batteries from causing stalled vehicles.

The team noted that their hack could be done fairly cheaply; even the most expensive version cost only $1,000. It also left no trace; since the car isn't getting any false signals, there's no alarms or other evidence that the vehicle has been broken into. And since all keyless entry systems use the same basic design, the hack likely works on millions of vehicles.

In their paper (PDF link) to be presented later this month at a computer security forum in San Diego, the researchers say the best way to fix the security hole would be smarter software that attempts to verify how close the key fob is to the vehicle. Otherwise, the only secure solution would be the same one that's been in use for decades: an old-fashioned metal key.

Monday, January 17, 2011

Lil Wayne's Twitter Account Hacked and Reclaimed


Lil Wayne has been Twitter hacked. The Young Money leader, who typically keeps his presence on the social networking site to a minimum, suddenly started posting dozens of bizarre and uncharacteristic messages Sunday afternoon (Jan. 16) to more than a million followers. It quickly became clear that Weezy wasn't behind the errant tweets, but that didn't stop the hacker from doing some damage.

After his Twitter handle changed from "LilTunechi" to "LilChineTu," the perpetrator poked some fun at Wayne's peers, replying to Soulja Boy and making reference to the poor sales of his latest album 'The DeAndre Way.' "I sent a donations to your paypal, check it, I heard you got 13,000 sales lil homie, i feel bad for you! #DamnSoulja," wrote the hacker.

He also set his sights on other rappers including 50 Cent, Fat Joe and Game, sending comedic messages about past collaborations. "@thegame you still owe me money for that My Life joint, how your family crip but you blood," he wrote, then moving on to Fat Joe. "@JOEYCRACKTS you fat ass nigga it on when i see you Why."

The tweets got a little too serious, going so far as to claim that Wayne was sexually abused in prison. "The real reason I made 6'7 is cuz that's how tall the nigga in rikers was that raped me," tweeted the impersonator, also making reference to a romantic relationship between him and Cash Money kingpin Baby. "I went an entire year with kissing baby #withdrawls."

After hours of Twitter hijinks, Lil Wayne finally reclaimed the account, canceling the old profile and launching a new one under the handle "LilTunechi_YM."