Showing posts with label hacker. Show all posts
Showing posts with label hacker. Show all posts
Monday, May 1, 2017
Hacker Publishes Personal Info of 20 000 FBI Agents
Hacker Publishes Personal Info of 20 000 FBI Agents
While America was getting ready to watch the Super Bowl on Sunday, a hackerpromised he would dump online a list of more than 20,000 agents of the Federal Bureau of Investigation and 9,000 Department of Homeland Security officers.
Right after the big games kickoff, the cybercriminal carried out part of his promise,publishing a list of 9,000 DHS employees. On Monday, less than 24 hours later, the hacker, who wishes to remain anonymous, has fulfilled the remaining part of his promise.
Long Live Palestine, Long Live Gaza, reads a message at the top of the dump, which also included the hashtag #FreePalestine.
The hacker provided Motherboard with a copy of the data on Sunday. The list includes names, email addresses (many of which are non-public) and job descriptions, such as task force deputy director, security specialist, special agent, and many more. The list also includes roughly 1,000 FBI employees in an intelligence analysis role.
Motherboard reached out to some random numbers on the list, and most corresponded to the names listed, while a small number went through generic FBI operator desks. The FBI did not respond to a request for comment, deferring to the Department of Justice.
A spokesperson for the DOJ told Motherboard on Monday that the department is looking into the unauthorized access of a system operated by one of its components containing employee contact information.
This unauthorized access is still under investigation; however, there is no indication at this time that there is any breach of sensitive personally identifiable information, DOJ spokesperson Peter Carr said in a statement.
Carrs statement seems to confirm what the hacker told Motherboard. The cybercriminal reached out to Motherboard through an apparently compromised DOJ email account earlier last week, and claimed to have obtained the stolen data by compromising that account and then using it to access a DOJ portal.
After tricking a department representative into giving him a token code to access the portal, the hacker claimed he used the compromised credentials to log into the portal, where he gained access to an online virtual machine. From here, the cybercriminal was presented with three different computers to access, he said, one of which belonged to the person behind the compromised email account. The databases of DHS and FBI details were on the DOJ intranet, the hacker said.
This is not one hack. This is an ongoing hack against the United States government.
Some of the data from the DHS list appears to be outdated, according to The Guardian. In any case, a DHS spokesperson said the agency is looking into the reports, though there is no indication at this time that there is any breach of sensitive or personally identifiable information.
Michael Adams, an information security expert who served more than two decades in the US Special Operations Command, criticized the US government for its failure to protect data, especially in the aftermath of the embarrassing and damaging hack on OPM, the government agency that handles employee information.
What has anybody in the United States government learned? Adams told Motherboard in a phone interview. Theyre not doing information security fundamentals, obviously. Its just fucking unacceptable.
This latest data dump comes on the heels of a long series of attacks on US government employees. In October, a group of hackers calling itself Crackas With Attitude (CWA) broke into the AOL email of CIA director John Brennan. The hacktivists then targeted several other high-profile government employees, including the US spy chief James Clapper, a White House official, and others.
Last year the hacktivists were also able to break into a US law enforcement portal,gaining access to a series of information sharing tools. This hack allegedly allowed them to download one or more databases of US government employees. In November, the CWA hackers released two lists of law enforcement agents from several departments, one containing around 2,300 names, and another containing almost 1,500 names. Both lists seemed incomplete, given that they were in alphabetical order and only included names starting with the first letters of the alphabet.
The CWA hackers appear to have shared the databases stolen last year with others. In January, another group of cybercriminals released a list of 80 police officers from Miami, Florida.
Its unclear if this new dump was carried out by the same hackers behind these past exploits. The person or people behind the Twitter account that first tweeted the DHS list on Sunday told Motherboard that this data doesnt come from last years portal hack, and said that they were not Cracka, the leader of the hacking group CWA.
The account, however, used the hashtag #FreePalestine in several of his tweets. This is the same hashtag Cracka and his associates have used since the beginning to show support to Palestine, which they claimed is the motivation behind their hacks.
The data dump on Sunday opened with a quote from the rap song Long Live Palestine: This is for Palestine, Ramallah, West Bank, Gaza, this is for the child that is searching for an answer.
In one of its first tweets, which has since been deleted, the Twitter account that shared the stolen data also mentioned @Fruityhax as their leader. Last year, after the Brennan hack, the Twitter account Fruityhax was linked to a hacker only known as Cubed, who claimed to be one of the leaders of CWA, along with Cracka.
This is not one hack, Adams said. This is an ongoing hack against the United States government, whether its from one or more actors is unknown.
Go to link Download
Friday, April 28, 2017
Hacker Defending Active Directory Against Cyberattacks
Hacker Defending Active Directory Against Cyberattacks
Here is a very interesting Microsoft Virtual Academy about Active directory Security.
https://mva.microsoft.com/en-US/training-courses/defending-active-directory-against-cyberattacks-16327?l=Gj8k5XsSC_2004300474
Interested in the why, how, and what of Active Directory (AD) and enterprise protection? This course has the answers you need to help you defend AD against cyberattacks. Learn from the experts, as they look at Active Directory from an enterprise risk perspective. The key to success is knowing what your high-value assets are, securing them, and securing their dependencies.
Whether your digital assets are on-premises or in the cloud, join us to explore the AD environment, todays adversaries, relationship dynamics, and strategic prioritization, along with adoption of least privilege. Take a look at the different aspects of Active Directory security, based on findings from the Microsoft Cybersecurity Services team, learn strategies to protect privileged identities in your environment, and finish the course with a roadmap for hardening your AD environment. Defenders should be as extremely adaptive as adversaries are these days, and this course is a great place to start.
1 | Active Directory Security: First Things First
Take a look at the sophisticated threats that target Active Directory. Examine the anatomy of a cyberattack, and review the basics of Active Directory security.
2 | Adopt Least Privilege
Learn about the centricity of Active Directory, further explore Tier 0, and understand the importance of assigning least privilege, including its role in your organizations cyberdefense strategy.
3 | Protect Privileged Identities
Adversaries leverage privileged identities, the primary attack vector, to persist and expand the scope of compromise. Learn strategies to protect privileged identities in your environment.
4 | Defend Your Directory
Do you know who your admins are? Learn why maintaining solid access control to sensitive directory objects is important for mitigating stealthy means of persistence and escalation of privilege.
5 | Defend Your Domain Controllers
Protecting Domain Controller hosts is fundamental to maintain the integrity of the overall access model and security boundary provided by Active Directory. Learn how to mitigate the risks.
6 | Beware of Security Dependencies
Security dependencies are one of the more sophisticated means of compromising Active Directory. Learn how to minimize and protect the security dependencies in your organizations environment.
7 | Monitoring
Collection is not the same as detection. Learn what to collect and how to analyze and respond to your collected data. Start making more informed decisions in response to security events.
Go to link Download
Monday, March 13, 2017
HACKER PENCURI DATA PAJAK SBY DIAMANKAN
HACKER PENCURI DATA PAJAK SBY DIAMANKAN
Akhirnya terungkap pencuri data pajak sby. Yang hmembuat sby gerah. Kenapa bisa kecolongan begitu. Kita harus meningkatkan sistem keamanan di direktorat jendral pajak. Dengan meningkatkan kualitas SDM yang sudah ada. Mengingat dilembaga tersebut tersimpad data data rahasia yang sangat pribadi dan dilindungi undang undang.
http://feeds2.feedburner.com/blogspot/gEZc
Go to link Download
Friday, March 10, 2017
Hacker Bukanlah Penjahat
Hacker Bukanlah Penjahat

Banyak orang berpendapat bahwa "HACKER" itu adalah penjahat di dunia maya. sebenarnya kalau di telisik dengan seksama, arti dari sebuah hacker bukanlah seseorang yang melakukan kejahatan di dunia maya.
kenapa kok hacker bsa saya katakan bukan penjahat ?
1. Hacker hanyalah seseorang yang ingin mencari pengetahuan saja. misalnya, mempelajari sistem keamanan website lain, tapi tidak merugikan website tersebut dan tidak merubah 1 bit data apapun. itulah hacker.
2. Hacker tidak menerima keuntungan dari kegiatan yang dijalaninya, kecuali jika suatu perusahaan menginginkan situsnya di otak-atik oleh seorang hacker atas persetujuan dari perusahaan untuk memperbaiki sistem keamanannya.
3. Jika tidak ada hacker, dunia maya tidak akan pernah semaju seperti ini dan tidak akan pernah aman.
lalu.... ????? apa sebutan bagi orang yang merusak,menjebol,mencuri dari sebuah sistem???? ya sebutannya adalah "CRACKER". cracker adalah seseorang yang dengan sengaja merusak,menjebol, dan mencuri suatu sistem milik orang lain demi keuntungan pribadi. nah, uda tahu kan secara singkat arti cracker, jadi jangan pernah sebut HACKER penjahat. HACKER hanyalah orang biasa yang memiliki kemampuan luar biasa. Bingung???? saya menjuluki hacker adalah orang yang tidak diketahui keberadaannya, tapi kemampuannya diketahui oleh orang banyak. itulah mengapa HACKER ADALAH ORANG BIASA YANG MEMILIKI KEMAMPUAN BIASA. Saya membuat postingan ini terinspirasi dari Manifesto Hacker yang dikirimkan oleh seseorang dengan nickname "The Mentor" pada 8 Januari 1986.
Go to link Download
Wednesday, March 8, 2017
Hacker How to verify if your user has been hackered credential stolen
Hacker How to verify if your user has been hackered credential stolen
On internet, during these years there are lot of websites where user credential and password was stolen.
Here is an interesting website that, utilizing a database, advise you about your account weakness on some websites where you are registered on.
https://haveibeenpwned.com/
Go to link Download
Tuesday, January 24, 2017
Hacker How to disable history in Chrome without using hidden browsing mode
Hacker How to disable history in Chrome without using hidden browsing mode
I was searching about settings in google chrome to disable history saving.
I was surprised that is not implemented. (only manual deletion)
So, i searched on internet and I found that, to avoid hidden browsing mode but having cookies saved the only solution is to search for history file here:
C:UsersusernameAppDataLocalGoogleChromeUser DataDefaulthistory putting it in read only mode
http://www.geekissimo.com/2011/02/06/chrome-come-disabilitare-salvataggio-siti-cronologia-senza-modalita-incognito/
Go to link Download
Monday, October 10, 2016
Hacker Reset Windows local user password free tool
Hacker Reset Windows local user password free tool
About O.S. local user password recovery/reset I usually utilize Pc Login 2.0 that is free and work fine as Live CD/DVD/USB drive
Pc Login Download:
http://www.download3k.com/Install-PCLoginNow-2.0.5.html
You can review blog USB live section to learn about how to create USB
http://www.alessandromazzanti.com/search/label/CD%20Live
http://www.alessandromazzanti.com/search/label/USB
Go to link Download
Subscribe to:
Posts (Atom)