More

Pages

Thursday, 12 July 2012

200+ Indian Sites defaced by "hcrack2"

A Pakistani hacker name as "hcrack2" from "Sharp-cyber Group" hacked and deface 200 plus Indian sites including xooomhosting and BJPMP . According to hacker, this hack is also part of cyber attack in payback response of Indians hacking activities toward Pakistani cyber space.





The list of impacted sites was published on Pastebin yesterday, but at press time, most of them still weren’t restored.

 While these mass defacements may not seem to have devastating effects, many website owners complain that it takes quite an effort to fully recover after such a hack.

Mirror :

450+ Indian Sites Defaced by Pakistani VOBHH


Hacker name as "h4x0r HuSsY", who is part of pakistani hacking Group "Voice of Black Hat Hackers (VOBHH)", has defaced 450+ Indian sites. According to hacker, this cyber attack was in response of Indins hacking activities toward Pakistani cyber space.


“This is a war against terror, [expletive] European Union, America, Israel & Indian Force. A special [expletive] to those who try to enter Paki Cyber Space!!!” he wrote on the webpages added to each of the affected domains.

“We are not afraid to die because whenever death may surprise us, let it be welcome if our battle cry has reached even one receptive ear and another hand reaches out to cake up our cause.”

The list of impacted sites was published on Pastebin yesterday, but at press time, most of them still weren’t restored.

While these mass defacements may not seem to have devastating effects, many website owners complain that it takes quite an effort to fully recover after such a hack.

Here are the hacked sites mirror

Mirror :
http://www.zone-hack.com/iparchive/184.172.58.141/1

Reference: Link1

Yahoo Voice hack leaks 450,000 passwords by "The D33Ds Company"

Username and unencrypted passwords posted online after hack attack on Yahoo Voice network. The most interesting thing in this hack is that hacker use simple SQL union all queries to get dump of yahoo database.
"We recommend you to change your yahoo password as soon as possible"

More than 450,000 usernames and unencrypted passwords appear to have been stolen from Yahoo Voice, a user-contribution services on Yahoo's network, and posted online.

Similar attacks have been reported separately against other online services, including Android Forums and Formspring, where users are being encouraged to change their passwords immediately, and to check whether they used the same password on other services.


It is not known whether the attacks are linked. Both Formspring and Android Forums encrypted the passwords that they stored, although that is not a guarantee that they cannot be cracked.

However the Yahoo attack is potentially the most serious. Yahoo bought Associated Content for $100m (£64.5m) in May 2010, and then set it up as Yahoo Voices, allowing user-generated content to be posted online.

Yahoo claims to have more than 600,000 contributors – which would include many of the data dump if it is verified. The Guardian could not verify whether any of the accounts were still active.

The last entries in the data dump appear to be linked to IDs which were created in 2006 – which could mean that the listing discovered by the hacker, or hackers, is an old one that is no longer in use.

Security experts said that the most worrying aspect of the attack was that the passwords for the accounts were not encrypted – meaning that any hacker could scoop up the emails and immediately start using them against other services, including Yahoo Mail.

That potentially puts far more at risk than just the Yahoo Voices accounts if they are still active.

Writing at the Trusted Security site, David Kennedy noted that: "The passwords [were linked to] a wide variety of email addresses including those from yahoo.com, gmail.com, [and] aol.com," and that they seem to have been extracted using an SQL injection attack – an increasingly common form of hacking attack in which flaws in the database and web software are exploited to get administrator-level access to the contents and structure of a database.

The page containing the Yahoo Voice addresses has all the details of the structure of the database that holds the details, as well as the usernames and passwords.



The Yahoo Voice hack has been claimed by a group or individual calling themselves "the D33Ds Company"

That's all for this news now.