CGISecurity Logo
  • Swedish Bank Stops Attempt to Take Control of Computer and Transfer Millions

    "The would be bank robbers had placed "advanced technical equipment" under the employee's desk that allowed them to take control of his computer remotely, prosecutor Thomas Balter Nordenman said in a statement. The employee discovered the device shortly after he realized his computer had started an operation to transfer "millions" from the bank into another…

  • SEO + Hacked Hosts Rig Google to Deliver Malware

    "If last November you googled one of thousands of innocuous and common search terms, such as "Microsoft excel to access" or "how to teach your dogs to fetch," you were in line for an Internet attack that infects PCs with spam senders, password stealers, and other kinds of nasty malware. Beginning on November 24 and…

  • RIAA SQL Injected, website deleted

    The RIAA website was apparently vulnerable to a SQL Injection vulnerability and had it's website deleted. "It’s a weekend, and a holiday weekend to boot, so the site might stay this way for some time. Someone apparently used SQL injection to wipe, and we do mean wipe, the website of the Recording Industry Association of…

  • Mystery web infection grows, but cause remains elusive

    "Five days ago, we wrote about the infection of several hundred websites that was unlike anything seasoned researchers had seen before. Mary Landesman, a cyber gumshoe who first brought it to public attention, asked for help from other security pros in figuring out how the unusual new technique worked. And help is what many of…

  • Italian Bank XSS utilized by fraudsters

    "An extremely convincing phishing attack is using a cross-site scripting vulnerability on an Italian Bank's own website to attempt to steal customers' bank account details. Fraudsters are currently sending phishing mails which use a specially-crafted URL to inject a modified login form onto the bank's login page. The vulnerable page is served over SSL with…

  • Calling all Web Hacks of 2007

    Jeremiah Grossman, Rsnakez0r, and myself put together a top web hacks of 2006 last year and this year we're soliciting public participation to submit what you think made the list for 2007. From Jeremiah's blog "As RSnake, Robert Auger, and I released in 2006, we’ll be putting together a Top 10 Web Hacks for 2007.…

  • Six charged over Czech TV nuclear hoax stunt

    "Six Czechs were charged Wednesday over an incident in June 2007 when a TV channel was hacked into, transforming scenes of a mountain beauty spot into a nuclear mushroom cloud, Czech TV reported. The six, all from the capital Prague, were charged with propagating false information and scaremongering after the stunt and could face jail…

  • Blackhat SEO: Servers Hacked to Boost Google Rank

    "Attackers have hacked the servers of Australian Web hosting provider MD Web Hosting (mdwebhosting.com.au), embedding malicious code to spawn "link farms" on its customers' sites, according to news site, Australian IT (australianit.news.com.au)." "The hackers gained access to about five servers which failed to have the correct security profiles. To make matters worse, the company's IP…

  • Orkut XSS worm in the wild

    According to ISC orkut has been striken with a persistant XSS worm via the user profiles. Will be updating this as new information breaks so stay tuned! So far no news at the orkut blog UPDATE A few news articles have started to pop up regarding this. "Google's Orkut social networking site appeared to have…

  • F-Secure Forum Defaced

    Security vendor F-Secure was defaced a few days ago by a turkish defacement crew. "So how did this happen? The server itself is quite well hardened, but the web forum software had an unannounced security patch silently released by the vendor nine days ago. The defacement gang learned of the vulnerability and went through the…

  • Facebook Tracks Down Hackers

    "Most recently, Facebook has chased down three hackers who attempted to break into its site to access personal information back in June, according to InformationWeek. Although Facebook filed charges immediately following the attacks, up until now all the defendants have been John Does. The company managed to unmask three of them by taking a list…

  • SquirrelMail Server Compromised, Sourcecode Modified

    According to the Squirrelmail website some of the packages available for download on their site had been modified by an outside intruder. If you are running 1.4.11 or 1.4.12 you are urged to upgrade immediately. From their site "Due to the package compromise of 1.4.11, and 1.4.12, we are forced to release 1.4.13 to ensure…

  • Facebook Sues Canadian Porn Company Over Screen Scraping

    "Facebook alleges that in June servers controlled by the defendants used automated scripts to make more than 200,000 requests for personal information stored on Facebook's site. The allegations are contained in an amended lawsuit filed earlier this month in U.S. District Court in San Jose, California. The company first filed suit back in June, but…

  • Did Iceland Teen Call Secret White House Phone?

    "Introducing himself as Ólafur Ragnar Grímsson, the actual president of Iceland, Atlason found President George W. Bush's allegedly secret telephone number and phoned, requesting a private meeting with him. "I just wanted to talk to him, have a chat, invite him to Iceland and see what he'd say," Vífill told ABC News. A White House…

  • Hackers Launch Major Attack on US Military Labs

    "Hackers have succeeded in breaking into the computer systems of two of the U.S.' most important science labs, the Oak Ridge National Laboratory (ORNL) in Tennessee and Los Alamos National Laboratory in New Mexico. In what a spokesperson for the Oak Ridge facility described as a "sophisticated cyber attack," it appears that intruders accessed a…

  • Chinese Hackers Accused of Attacking Shell, Rolls Royce

    " Britain's domestic intelligence agency is warning that cybercrime perpetrated by China is on the rise following hacking attacks against Rolls-Royce and Royal Dutch Shell. The agency, known as MI5, recently sent letters to some 300 banks, accounting and legal firms warning that "state organizations" of China were plying their networks for information, according to…

  • WabiSabiLabi founder arrested, in custody of Italian authorities

    "Italian authorities are holding the founder of WabiSabiLabi, an eBay-like online marketplace for buying and selling zero-day vulnerabilities. However, the arrest of Roberto Preatoni, reportedly on charges related to a well publicized Italian spying scandal, has not affected the organization's day-to-day operations, according to a statement released by the Switzerland-based group. WabiSabiLabi confirmed in the…

  • Hacked grades = 20 years in jail?

    "It's the stuff of movies such as War Games but two California men accused of hacking into a University database system to change their grades face up to 20 years imprisonment. John Escalera, 29, and Gustavo Razo, 28, are charged (PDF) with conspiring together to increase their marks by manipulating California State University at Fresno's…

  • Man Hacks 911 System, Sends SWAT on Bogus Raid

    "SWAT officers expected to find a victim shot to death, drugs and a belligerent armed suspect when they surrounded the home of an unsuspecting couple, but found they were only a part of a false emergency call caused by a teenager who hacked into the county’s emergency response system, authorities said. As officers swarmed the…

  • Russian Business Network Is Haven For Online Crime

    The Russian Business Network is an ISP in St. Petersburg allowing for hosting of 'anything'. "The Russian Business Network sells Web site hosting to people engaged in criminal activity, the security experts say. Groups operating through the company's computers are thought to be responsible for about half of last year's incidents of "phishing" — ID-theft…

  • Websites with adsense being hacked, having codes replaced

    Not that this is surprising but it appears rather then defacing sites outright attackers are now starting to target sites with adsense on them and replacing the codes in order to steal earnings. For those of you unfamiliar with adsense you stick a piece of javascript on your site with your code so if someone…

  • Isreal Pwns Syria before Pwning them with bombs

    "Instead of jamming radar signals, Suter uses a more sophisticated approach of "hacking" into enemy defences. "The technology allows users to invade communications networks, see what enemy sensors see, and even take over as systems administrator so sensors can be manipulated into positions so that approaching aircraft can't be seen," Aviation Week explains. "The process…

  • Hacked Marin County website prompts shutdown of all California state sites

    "A hacked county website in California that redirected users to a pornographic site triggered the federal government late Tuesday to initiate a system-wide shutdown of all government sites in the Golden State. The process was never completed, after state officials urged the feds to reverse their decision to take offline all state websites bearing the…

  • Google Fixes Gmail Cross-site Request Forgery Vulnerability

    "Google has fixed a vulnerability in their Gmail web based email service which would have allowed internet attackers to steal mail messages from users without being noticed. The attack works by forcing a logged-in user to add a mail filter to their Gmail account, thereby allowing their mail to be forwarded to an external mail…

  • Gmail cookie vulnerability exposes user’s privacy

    "Petko Petkov of "ethical hacking" group GNUCitizen has developed a proof-of-concept program to steal contacts and incoming e-mails from Google Gmail users. "This can be used to forward all your incoming e-mail," Pure Hacking security researcher Chris Gatford said. "It's just a proof of concept at the moment, but what they're demonstrating is the potential…