31 Dec 2012

Security flaw In facebook may let anyone see your private new year messages


Security flaw In facebook exposes Your Message


To usher in the New Year, Facebook recently launched Midnight Deliveries, a feature that allows users to send private messages to their contacts that will be delivered to them at the stroke of midnight. But in a reported security slip-up, it was discovered that with simple manipulation of the URL, private messages could be viewed by anyone on the web.

In a blog post, IT student Jack Jenkins revealed how anyone logged on to Facebook could use simple manipulation techniques to view other users' messages and photos and even delete them. Jenkins wrote that if one changed the numbers in the URL generated after your message is sent out, you can view private messages sent by others with your profile picture next to it, as if you’ve sent it.


GET OUR TOP STORIES

FOLLOW THEHACKERSBLOG


Some of these private ‘Midnight Deliveries’ messages even had photographs attached to them. “It is you may say a pretty harmless flaw, as they tend to be generic messages and you can’t see who sent them (it shows your profile pic next to the message, as if you’ve sent it). However you can see the names of the recipients of the message,” writes Jenkins in his blog.


What's worse, Jenkins realised that if you're able to see messages sent by others, you can delete them too. The IT student experimented by deleting a ‘1-1 message, to minimise disruption’ and documenting it with screenshots.

While it is practically impossible to find a message by a specific user in order to view or manipulate it thanks to the randomly generated string of numbers at the end of the URL, it is still possible to view messages by strangers. The Midnight Deliveries service will in all probability carry only generic wishes and even festive season photographs, but it is a serious slip up on Facebook’s part that allows private messages to become public. Facebook has not  commented on the issue but the Midnight Deliveries site seems to be under maintenance now.

Facebook’s privacy flaws have been in the news since the past week after founder Mark Zuckerberg’s sister Randi found herself embroiled in controversy. The older Zuckerberg sibling was in for a surprise when she found a private picture of hers leaked on Twitter by a subscriber.

Zuckerberg chastised Callie Schweitzer, Vox Media’s Marketing Manager, for invading her privacy. The former marketing head of Facebook soon regained her control and graciously accepted Schweitzer’s apology saying, “I think you saw it [because] you're friends [with] my sister (tagged).Thanks for the apology.” The tweet has since been deleted, but Zuckerberg was clearly sore about the entire incident as she added, “I’m just sensitive to private photos becoming ‘news.’”

Zuckerberg signed off by blaming social networking users for lack of digital etiquette instead of obviously contemplating on what is wrong with the privacy settings of the website younger sibling Mark heads. A Twitter user named Anna (@girlvanized) pointedly told Zuckerberg, “ Instead of vilifying a subscriber for not reading your mind, maybe you should talk to your brother about recent FB changes.”


Facebook have implemented a new service to wish friends and family a Happy New Year, offering to deliver your message to them on the strike of midnight.
StoriesFacebook however have not been very security consious when setting this up. By simple manipulation of the ID at the end of the URL of a sent message on the FacebookStories site, you are able to view other peoples Happy New Year messages. At least I was when I edited the ID for myself.
For example. I made this test one which you should be able to see saying “TEST TEST TEST TEST”:
Story2If you manipulate the ID (http://www.facebookstories.com/midnightdelivery/confirmation?id=76188), you can view other people’s messages, just change the ID number up or down a few.
It is you may say a pretty harmless flaw, as they tend to be generic messages and you can’t see who sent them (it shows your profile pic next to the message, as if you’ve sent it). However you can see the names of the recipients of the message.
Some messages do contain a photo, one such message I saw contained a photo of a father and their child, another a family photo, another was a personally written message with a photo such as this:
FBStory5I don’t know who these people are, but you can see it puts my profile pic next to it, as if I have sent the message. It shouldn’t be possible to do this, as these are not generic and are people’s personal images.
A very bad part of it all is I think that you can actually DELETE other people’s messages, which I have tested for myself on a single message as I thought that it would say access denied
Screenshot 1: FBStory3
Screenshot 2:
FBStory4
After I action the deletion, this URL is no longer reachable. Which may mean that I have deleted their message
Screenshot 3:
FBStory2Just an example of a mass message  that I saw
I just wanted to share this. I don’t know how a site like Facebook can continue to take these kinds of risks. PLEASE Don’t go deleting random messages, but try and delete one of mine that I set up especially if you want :) . And share this message with someone else who may be interested:
http://www.facebookstories.com/midnightdelivery/confirmation?id=76746
http://www.facebookstories.com/midnightdelivery/confirmation?id=76742
Jack. https://twitter.com/Jackthewelshman
UPDATE 31/12/2012 05:25GMT – the site is currently down for maintenance, I sent it to Facebook too so I think they are working on it
UPDATE 31/12/2012 14:00GMT – Facebook still haven’t got back to me personally with  any response. This is the reason that I contacted The Verge, to actually get some action taken
UPDATE 31/12/2012 14:35GMT – I have just checked, the bug / oversight has now been fixed. You can no longer access other people’s messages, by changing the confirmation message ID





   Stay Connect with Us:- Facebook  §   Twitter   §   Google+   §   LinkedIn   §   YouTube  §   Email Us    
NiRaj KashYaP
Article written by Niraj kashyap [ Admin ]
I am a Certified Information Security Expert [C.I.S.E], Web-Designer, PHP programmer. Blogger and a friendly guy.
▲Want to SUBMIT you News ◙ Click Me↓ ( its Totally Free ) ◙ 
|||  Or Want to Write For Us ◙ Click Me ◙ ▲
THE ARTICLE IN THIS POST IS FOR INFORMATIVE AND EDUCATIONAL PURPOSE ONLY..WE ARE NOT RESPONSIBLE FOR ANY TYPE OF USE BY YOU..FOR MORE INFORMATION OR FOR ANY QUERIES CONTACT US.
source:-network18

Website Of Government Of Ghana Hacked and Database Leaked by JokerCracker

Sawla.ghanadistricts.gov.gh Hacked by JokerCracker

Website Of Government Of Ghana Hacked

Sawla.ghanadistricts.gov.gh Hacked by JokerCracker

The website of government of ghana has been hacked by JokerCracker, Also STANFORD EDUCATION'S SUBDOMAIN WAS HACKED by him yesterday on 22:57.

GET OUR TOP STORIES

FOLLOW THEHACKERSBLOG



JokerCracker stated the reason for hacking is just a personal challenge. Also he had leaked the database of http://Sawla.ghanadistricts.gov.gh/

The leaked  database contains data like :-
Daily Revenue:
Website Worth:
IP Address:
Server Location:
name Constituency
yearsinoffice
DOF
uname passwd fullname role
name intro rank yearsinoffice
email districtID RegionID



Links to the leaked database:-
or 



   Stay Connect with Us:- Facebook  §   Twitter   §   Google+   §   LinkedIn   §   YouTube  §   Email Us    
NiRaj KashYaP
Article written by Niraj kashyap [ Admin ]
I am a Certified Information Security Expert [C.I.S.E], Web-Designer, PHP programmer. Blogger and a friendly guy.
▲Want to SUBMIT you News ◙ Click Me↓ ( its Totally Free ) ◙ 
|||  Or Want to Write For Us ◙ Click Me ◙ ▲
THE ARTICLE IN THIS POST IS FOR INFORMATIVE AND EDUCATIONAL PURPOSE ONLY..WE ARE NOT RESPONSIBLE FOR ANY TYPE OF USE BY YOU..FOR MORE INFORMATION OR FOR ANY QUERIES CONTACT US.

30 Dec 2012

Stanford Education's Subdomain Hacked by JokerCracker

Stanford Education's Subdomain Hacked by JokerCracker

http://english.stanford.edu Suffers XSS Attack

JokerCracker has hacked stanford.edu

JokerCracker has hacked 7 websites of stanford.edu and also has leaked the database from the website of Stanford Education. The database contains :- first_name, email, last_name current_job, grad_year, Website Worth and daily income.

The database can be found on our database:- http://database.thehackersblog.com/2012/12/englishstanfordedu-database-leaked-by_30.html

GET OUR TOP STORIES

FOLLOW THEHACKERSBLOG


The preview of the defaced website :-
is Pasted on our Database = LINK 

The Leaked database are as.

 Hacked by JokerCracker
                                                                              
Taget: http://english.stanford.edu
Panel: http://english.stanford.edu/admin/login.php
Reason of Hacking: It's just a personal challenge

XSS:

-http://goo.gl/YlfqC
-http://goo.gl/Rzn9N
-http://goo.gl/vjuqm
-http://goo.gl/Rxee2
-http://goo.gl/kNTht
-http://goo.gl/PcPMh
-http://goo.gl/h3EbE


Daily Revenue: $ 5,424 USD
Website Worth: $ 18,134,028 * USD
Primary Country: United States (Alexa Rank #833 in United States)






   Stay Connect with Us:- Facebook  §   Twitter   §   Google+   §   LinkedIn   §   YouTube  §   Email Us    
NiRaj KashYaP
Article written by Niraj kashyap [ Admin ]
I am a Certified Information Security Expert [C.I.S.E], Web-Designer, PHP programmer. Blogger and a friendly guy.
▲Want to SUBMIT you News ◙ Click Me↓ ( its Totally Free ) ◙ 
|||  Or Want to Write For Us ◙ Click Me ◙ ▲
THE ARTICLE IN THIS POST IS FOR INFORMATIVE AND EDUCATIONAL PURPOSE ONLY..WE ARE NOT RESPONSIBLE FOR ANY TYPE OF USE BY YOU..FOR MORE INFORMATION OR FOR ANY QUERIES CONTACT US.

Database Of Hackers - Each And Every Hacks And Defaces

database.TheHackersBlog.com is LIVE!

Database Of Hackers - Each And Every Hacks And Defaces

The database.TheHackersBlog.com is LIVE!

Link to The Database - DATABASE.

THe website database.TheHackersBlog.com which contains each and every Hacks And Defaced sites and its defaced codes running live just as the cached sites.. is now active.

Also More than 20 Submission has been accepted today by the hackers to add the defaced websites to our database.


GET OUR TOP STORIES

FOLLOW THEHACKERSBLOG



Do you think that you are Up-To-Date with the hackers..Then you must have a glance at our database and see the hackers activity.



the database

We tried our best to add as much defaced and hacked websites to our database.

You can also add your hacked and defaced websites directly to our database.
Then be a Author | Writer For Our Database



   Stay Connect with Us:- Facebook  §   Twitter   §   Google+   §   LinkedIn   §   YouTube  §   Email Us    
NiRaj KashYaP
Article written by Niraj kashyap [ Admin ]
I am a Certified Information Security Expert [C.I.S.E], Web-Designer, PHP programmer. Blogger and a friendly guy.
▲Want to SUBMIT you News ◙ Click Me↓ ( its Totally Free ) ◙ 
|||  Or Want to Write For Us ◙ Click Me ◙ ▲
THE ARTICLE IN THIS POST IS FOR INFORMATIVE AND EDUCATIONAL PURPOSE ONLY..WE ARE NOT RESPONSIBLE FOR ANY TYPE OF USE BY YOU..FOR MORE INFORMATION OR FOR ANY QUERIES CONTACT US.

28 Dec 2012

Indonesian Maritime Council's Website Hacked And Database Breached

Indonesian Maritime Council's Website Hacked database leaked
Indonesian Maritime Council's Website Hacked And Database Breached

Hacked Brazilian Cyber Army

GET OUR TOP STORIES

FOLLOW THEHACKERSBLOG


The Website www.dekin.kkp.go.id has been compromised by Brazilian Cyber Army on 27th dec, also they have all other hackers stating that " No more website hacks and No war  " 

The BCA has dumped all the database that of Indonesian Maritime Council's on Pastebin which contains the sql query's also table and columns.
The link to the dumped database in pastebin

They also leaked details of users- Id and Password and leaked mysql username, password and host.

They also hosted a image in picasa that shows XSS Vulnerability - 



   Stay Connect with Us:- Facebook  §   Twitter   §   Google+   §   LinkedIn   §   YouTube  §   Email Us    
NiRaj KashYaP
Article written by Niraj kashyap [ Admin ]
I am a Certified Information Security Expert [C.I.S.E], Web-Designer, PHP programmer. Blogger and a friendly guy.
▲Want to SUBMIT you News ◙ Click Me↓ ( its Totally Free ) ◙ 
|||  Or Want to Write For Us ◙ Click Me ◙ ▲
THE ARTICLE IN THIS POST IS FOR INFORMATIVE AND EDUCATIONAL PURPOSE ONLY..WE ARE NOT RESPONSIBLE FOR ANY TYPE OF USE BY YOU..FOR MORE INFORMATION OR FOR ANY QUERIES CONTACT US.

25 Dec 2012

Anonymous takes down website of Delhi Police in revenge of the Delhi's GangRape Case

Anonymous hacks website of Delhi Police

Anonymous takes down the website of Delhi Police  in revenge of the Delhi's GangRape Case and for Violence against the protestor/Public

We all Know about the Shameful incident that happened in Delhi, And we all want the same result i.e- Punish the rapist. And also we thank the greatful public who came down protesting in the freezing streets of Delhi. But the police doesn't seemed to be operating with the protestors, instead finding the culprits the police started firing water Cannon and Tear Gas shells which caused a lot of running around and police hitting the protestors with Sticks [lathi Charge] etc.


GET OUR TOP STORIES

FOLLOW THEHACKERSBLOG


But the police can suppress the voice of local public by closing/blocking the roads leading to India Gate, but can they stop Anonymous Hackers. 

And So Anonymous Hackers have done it, They have hacked the website of Delhi Police [http://delhipolice.gov.in] and the website of the Police is #Down. And as it is said By us " Who can stand in the way of Freedom, If Anonymous is There to fightback ".
The hack was announced on the twitter handle of Anonymous.
Anonymous takes down the website of Delhi Police


You can get more info about the shameful Incident happened in Delhi .

Please Dont Ignore - We TheHackersBlog Request you to Support the protest, so that it could never happen with any other woman.
To support please Comment below  with the most appropriate punishment for criminals  and share this post to everyone..




   Stay Connect with Us:- Facebook  §   Twitter   §   Google+   §   LinkedIn   §   YouTube  §   Email Us    
NiRaj KashYaP
Article written by Niraj kashyap [ Admin ]
I am a Certified Information Security Expert [C.I.S.E], Web-Designer, PHP programmer. Blogger and a friendly guy.
▲Want to SUBMIT you News ◙ Click Me↓ ( its Totally Free ) ◙ 
|||  Or Want to Write For Us ◙ Click Me ◙ ▲
THE ARTICLE IN THIS POST IS FOR INFORMATIVE AND EDUCATIONAL PURPOSE ONLY..WE ARE NOT RESPONSIBLE FOR ANY TYPE OF USE BY YOU..FOR MORE INFORMATION OR FOR ANY QUERIES CONTACT US.