Advertisement
Home
Friday, 08 August 2008
 
 
Last week attacks
O.S.  Defs.  %
Linux  7420  78.14%
Win 2003  1429  15.05%
FreeBSD  368  3.88%
Win 2000  180  1.90%
Unknown  60  0.63%
Other  39  0.41%

Total attacks: 9496 of which 3246 single ip and 6250 mass defacements

Polls
Should Zone-H continue mirroring defacements? (floods will be purged)
 
Main Menu
Home
Digital Warfare
Geopolitics
ITsec News
ITsec Advisories
Test Drive
360°
Digital Attacks Archive
Zone-H events
Publications
Zone-H Friends/Partners
Contact Us
Search
Download Area
Zone-H forum
About this website
Login Form





Lost Password?
No account yet? Register
ZONE-H In Numbers
 News: 14545
 Advisories: 11
 Managers: 1
 Administrators: 1
 Super Administrators: 3
 Operators: 3
 Registered Users: 36618
 Downloadable Files: 3888
 Digital Attacks: 2786718
 Attacks On Hold: 483
 Online Users: 98
Syndicate
Visitors' Map
Highlight on most recent attacks
lodhranpolice.gov.pk/ibh.htm by Iran Black Hats Team       cics.go.ug/view.php by Swan       tpsudan.gov.sd/pdf by Iran Black Hats Team       seafordtowncouncil.gov.uk/pdf by Ktkoti       cheater.turkish.nmglj.gov.cn/fux0r.html by st@rext       personeriadeibague.gov.co by Very Secret       toshibatec-eu.cz/Snimace/snimace.asp by RedRolix       rapp.sr.gov.yu/home/index.php by Mi4night & Nuclear       hyundai.be/Delsearch.asp by RedRolix       hyundai-motors.be/Delsearch.asp by RedRolix       
Latest advisories
Latest on Digital Warfare
Latest on Geopolitics
Yet another Microsoft defacement
User Rating: / 17
ITsec News
Written by SyS64738   
Wednesday, 30 July 2008
winlogoOnce again Microsoft got defaced by means of SQL Injection. Few days ago a defacer known as Agd_Scorp defaced 6 Microsoft websites.
Few years ago, Microsoft was the target of the attacks mostly because defacers liked Linux more. Now it is just "for fame". Also in this case defacer didn't left any message.

The defacer also attacked many high profile companies and other interesting targets (for example, https://dol.hqda.pentagon.mil) by means of SQL Injection as to demonstrate that sometimes people are not checking the source code well enough... Write Comment (2 Comments)
Read more...
 
Hands-on Ethical Hacking - Upcoming seminars schedule
User Rating: / 9
Events
Written by Staff   
Thursday, 20 December 2007


July 3rd-4th Wireless Hacking Milano - IT
NPO
July 10th-11th HoH Unlimited Milano - IT
Sedoc
Sep. 22th-23th HoH Unlimited Johannesburg - ZA
Telspace
Oct. 15th-16th Wireless Hacking Milano - IT
Sedoc
Oct. 21st-22nd HoH Unlimited Bratislava - SK
S&T
Oct. 23rd-24th HoH Web Application Bratislava - SK
S&T
Nov. 19th-20th Wireless Hacking Bratislava - SK
S&T
 
HITB Security Conference 2008 in Malaysia
User Rating: / 3
ITsec News
Written by minor   
Friday, 25 July 2008

 If you still didn't have vacations, maybe it is worth to wait until the end of the October and visit the Hack In The Box conference in Malaysia. Let's take a look on some of the speakers and their topics.

Probably one of the most interesting topics will be introduced by Kris Kaspersky, he will talk about the Intel CPU bugs that lead to remote code execution regardless to the operating system used and show attacks based on JavaScript or just TCP/IP packets against Intel based machine.

 

Write Comment (0 Comments)
Read more...
 
Malaysian Kaspersky website and shop hacked. Users at risk?
User Rating: / 36
ITsec News
Written by Roberto Preatoni   
Sunday, 20 July 2008

kasperskyThe official Malaysian Kaspersky Antivirus's website has been hacked yesterday by a Turkish cracker going by the handle of "m0sted".

Along with it, the same cracker hacked also the official Kaspersky S.E.S. online shop and its several other subdomains. 

The attacker reported "patriotism" as the reason behind the attack and "SQL Injection" as the technical way the intrusion was performed.

Both websites  has been home page defaced as well as several other secondary pages.  The incident, though appearing a simple website defacement, might carry along big risks for end-users because from both the websites, evaluation copies of the Kaspersky Antivirus are distributed to the public. In theory, the attacker could have uploaded trojanized versions of the antivirus, infecting in this way the unaware users attempting a download from a trusted Kaspersky's file repository (remember the trojan in the Debian file repository?). 

Write Comment (11 Comments)
Read more...
 
Blogless blogs, Olympic blogs the Chinese way
User Rating: / 2
Geopolitics
Written by SyS64738 (Roberto Preatoni)   
Tuesday, 15 July 2008

beijing_olympic_08For all you folks, fan of the civil liberties as well as the Olympic games, here's the integral text of the International Olympic Committee Blogging Guidelines for the accredited persons. It's the perfect companion of the recent decision from the Olympic Chinese Committee to ban the flags from the stadiums.

As you will read, blogs are admitted but:

- should not contain information not related to strictly personal experience 
- should not contain sound or moving images from the Olympic Games
- should not contain still images containing any sporting action of the
Games or the Opening, Closing or Medal Ceremonies of the Games.
- should not contain the Olympic symbol
- should not contain commercial references (Blogspot, bye bye!) 
- should not contain the word "Olympic" within the blog URL 

But you are lucky, still you can use your plain white Olympic blog homepage to test the brightness of your screen.   

... enjoy and please comment the official text  

Write Comment (2 Comments)
Read more...
 
250 thousands emails at risk? It is a feature!
User Rating: / 4
ITsec News
Written by minor   
Thursday, 10 July 2008

 "It is not a bug, it is a feature. You invented the wheel."

If you get this kind of answer from a website operator in relation to a security bug found in his application, then you have only two choices: either you're paranoid or the operator doesn't care much about security. What are talking about? About leakage of 250.000 email addresses.

One of the most visited websites in Slovakia, the community website Azet.sk known thanks to his freemail and chat services has several sections, among which is also a dating section . The website is visited by surfers of various age that would like to find a partner for anything: chating, meeting, sex etc. You just put an announce and everybody can respond you through a web form. But few days ago, on one of the most visited security blogs in Slovakia blog.synopsi.com appeared the detailed description of how to get email addresses from the Azet dating service with a PoC script.

  

Write Comment (5 Comments)
Read more...
 
<< Start < Prev 1 2 3 4 5 6 7 8 9 10 Next > End >>

Results 1 - 21 of 411
Advertisement
 
Top! Top!