Sabtu, 02 Juni 2012

Security Short : Flame, WHMCS and Controversy


From an information security standpoint, this previous week ( May possibly 28 &ndash June three ) has been really an intriguing a single. Three key subjects stand out: the new Flame malware, the WHMCS breach, and the controversy that surrounds the UGNazi hacker collective.

When the globe initially learned of the Flame threat, many rushed to conclude that it may possibly be the up coming Stuxnet, particularly since its key targets were a amount of Middle Eastern nations, which includes Iran. However, after further evaluation, authorities have admitted that the 20 MB malicious element doesn&rsquot pose a big danger as initial believed, at least not still.

Besides the now-infamous Flame, we also discovered of the begin of the Holy Lulz Crusade of Canada, an operation initiated by Team Dig7tal that targets Canadian government and other major internet sites.

One particular of the most significant victims of this campaign was the website of the Toronto Police Division from which the hackers leaked the total database, totaling a 32 MB file.

The WHMCS saga, which started last week, continued with the arrest of Cosmo, a single of the hackers actively involved in the breach. Then, the firm discovered from &ldquoan ethical hacker&rdquo of an SQL Injection vulnerability in the billing software program which could have permitted an attacker to get access to their techniques.

WHMCS has rushed to release a security update to deal with the issue, but we have a hunch that this incident is far from currently being over.

As far as UGNazi is concerned, the crew has brought about a lot of controversy, several individuals condemning their apparently unjustified actions. The hackers also produced public their personalized vendetta plans against the well-known Jester (th3j3st3r) by launching a distributed denial-of- service (DDOS) attack on the website of the Wounded Warrior Venture.

In the hacktivist category we find a couple of interesting operations. One of them is aimed at the Formula one Grand Prix that&rsquos about to take location in Montreal. Anonymous promised to initiate each physical and virtual protests, claiming that sporting occasions shouldn&rsquot consider place in nations in which human rights are violated.

We also had the chance to talk to a somewhat new group of hacktivists called k0detec, which highlighted the security holes that exist in the United Kingdom&rsquos Nationwide Well being Service (NHS).

AlienVault issued an intriguing report in which it detailed how information breaches could result not only in intellectual home loss, but also in the loss of human lives.

Lastly, we discovered that the White House has taken initiative in fighting botnets.

Tidak ada komentar:

Posting Komentar