.
4shared.com - Free file sharing and storage

Tampilkan postingan dengan label Hacker.. Tampilkan semua postingan
Tampilkan postingan dengan label Hacker.. Tampilkan semua postingan

Selasa, 16 Maret 2010

Hacker Iran Deface Situs Spionase AS

0 comments
TEHERAN - Sekelompok hacker asal Iran berhasil mengacak-acak 29 situs internet yang diduga berafiliasi dengan jaringan spionase asal Amerika Serikat. Di duga para peretas tersebut merupakan kelompok yang mendukung pemerintahan.

"Hacker yang merusak situs tersebut bertindak melawan sekelompok orang yang menggangu keamanan nasional Iran yang mengatasnamakan kegiatan hak asasi manusia."

Internet sendiri telah digunakan oleh kelompok-kelompok oposisi Iran yang ikut hasil pemilu tahun lalu untuk mengatur demonstrasi dan berbagi informasi tentang protes dan penangkapan terhadap aktivis oposisi. Pengawal Revolusi adalah kelompok militer yang didirikan tahun 1979 setelah revolusi Iran. Grup yang konvensional termasuk tentara, angkatan laut, angkatan udara, dan unit-unit intelijen.

Beberapa nama domain yang terdaftar hacked menunjuk ke sebuah situs Web, seperti hra-iran.org, yang menampilkan pernyataan singkat pada halaman utama: "Situs ini sementara tidak tersedia, silakan coba lagi nanti."

Baru-baru ini versi lain dari hra-iran.org menunjukkan situs ini dioperasikan oleh sebuah kelompok yang menamakan dirinya aktivis HAM di Iran (HRAI). Informasi yang sebelumnya tersedia di situs termasuk laporan 400 pengunjuk rasa oposisi Iran yang ditangkap pada 4 November 2009.

Tidak jelas apakah HRAI mempunyai kaitan organisasi intelijen AS atau murni sebagai kelompok yang menggawani HAM di negara tersebut.

(Choi)

Sumber : Okezone.Com
Read full story

Sabtu, 19 Desember 2009

Hacker Iran Bobol Twitter

0 comments
CALIFORNIA - Sejumlah pengguna Twitter sempat mengeluhkan sulitnya mengakses situs mikroblogging, twitter beberapa waktu lalu. Pasalnya, hacker asal Iran sempat mengacak-acak halaman depan Twitter.

Tapi, pengelola Twitter berhasil memulihkan situs dari serangan hacker sehingga Twitter dapat kembali diakses. Down-nya situs yang didirikan pada Maret 2006 tersebut kini menjadi trending topic.

Hacker Iran sempat menuliskan pesan yang berbunyi:

Iranian Cyber Army THIS SITE HAS BEEN HACKED BY IRANIAN CYBER ARMY iRANiAN.CYBER.ARMY@GMAIL.COM U.S.A. Think They Controlling And Managing Internet By Their Access, But THey Don't, We Control And Manage Internet By Our Power, So Do Not Try To Stimulation Iranian Peoples To.... NOW WHICH COUNTRY IN EMBARGO LIST? IRAN? USA? WE PUSH THEM IN EMBARGO LIST Take Care.

Masalah keamanan memang menjadi perhatian Twitter. Pengguna-pengguna Twitter kerap menjadi target utama penjahat dunia maya untuk mencuri informasi. Selain itu, Twitter juga kerap menjadi target Phishing melalui pesan dengan link di dalamnya yang mengarah ke halaman login Twitter, di mana halaman tersebut sebetulnya palsu dan dapat mencuri password user.

(Choi)

Sumber : Okezone.com
Read full story

Senin, 30 November 2009

10 Hacker Ternama Dunia

0 comments
LONDON - Keahlian seorang hacker seringkali dianggap 'merepotkan' sejumlah korbannya. Padahal belum tentu semua hacker bisa dicap negatif, banyak diantara mereka yang menggunakan keahliannya untuk tujuan-tujuan melihat atau memperbaiki kelemahan perangkat lunak di komputer.

Tapi akibat, ulah sejumlah hacker yang menggunakan keahliannya untuk tujuan jahat seringkali hacker mendapat pandangan negatif dari masyarakat.

Perjalanan untuk menjadi seorang hacker sendiri dilalui melalui perjalanan yang panjang. Untuk menjadi seorang hacker terkenal, tak jarang harus berhadapan dengan penjara. Tengok saja perjalanan 10 hacker ternama dunia berikut seperti dilansir Telegraph, Minggu (29/11/2009).

1. Kevin Mitnick
Pria kelahiran 6 Agustus 1963 ini adalah salah satu hacker komputer yang paling kontroversial di akhir abad ke-20. Pengadilan Amerika Serikat bahkan menjulukinya sebagai buronan kriminal komputer yang paling dicari di Amerika. Kevin diketahui pernah membobol jaringan komputer milik perusahaan telekomunikasi besar seperti Nokia, Fujitsu and Motorola.

Kevin Mitnick ditangkap FBI pada Januari 1995 di apartemennya di kota Raleigh, North Carolina atas tuduhan penyerangan terhadap pemerintahan. Saat ini, ia berprofesi sebagai seorang konsultan keamanan sistem jaringan komputer.

2. Kevin Poulson
Jauh sebelum menjadi senior editor di Wired News, Pria bernama lengkap Kevin Lee Poulsen ini dikenal sebagai seorang hacker jempolan. Pria kelahiran Pasadena Amerika Serikat, 1965 ini pernah membobol jaringan telepon tetap milik stasiun radio Los Angeles KIIS-FM, sehingga ia seringkali memenangkan kuis-kuis radio. Bahkan lewat kuis telepon via radio ia bisa memenangkan sebuah hadiah utama, mobil Porsche.

3. Adrian Lamo
Nama Adrian Lamo sering dijuluki sebagai 'the homeless hacker' pasalnya ia sering melakukan aksi-aksinya di kedai-kedai kopi, perpustakaan atau intenetcafe. Aksinya yang paling mendapatkan perhatian adalah ketika ia membobol jaringan milik perusahaan Media, New York Times dan Microsoft, MCI WorldCom, Ameritech, Cingular. Tak hanya itu, ia juga berhasil menyusupi sistem milik AOL Time Warner, Bank of America, Citigroup, McDonald's and Sun Microsystems. Kini pria tersebut berprofesi sebagai seorang jurnalis.

4. Stephen Wozniak
'Woz' begitu ia biasa disapa. Saat ini mungkin lebih dikenal sebagai seorang pendiri Apple. Tapi saat menjadi mahasiswa, Wozniak pernah menjadi seorang hacker yang cukup mumpuni. Pria berusia 59 tahun itu diketahui pernah membobol jaringan telepon yang memungkinkannya menelepon jarak jauh tanpa membayar sedikit pun dan tanpa batas waktu. Alat yang dibuat semasa menjadi mahasiswa itu dikenal dengan nama 'blue boxes'

5. Loyd Blankenship
Pria berjuluk The Mentor ini pernah menjadi anggota grup hacker kenamaan tahun 1980 Legion Of Doom. Blakenship adalah penulis buku The Conscience of a Hacker (Hacker Manifesto). Buku yang ditulis setelah ia ditangkap dan diumumkan dalam ezine hacker bawah tanah Phrack.

6. Michael Calce
Sejak usia muda Calce memang dikenal sebagai seorang Hacker. Aksinya membobol situs-situs komersial dunia dilakukannya ketika ia berusia 15 tahun. Pria yang menggunakan nama MafiaBoy dalam setiap aksinya itu, ditangkap ketika membobol pada tahun 2000 mengacak-acak eBay, Amazon and Yahoo.

7. Robert Tappan Morris
Nama Morris dikenal sebagai seorang pembuat virus internet pada tahun 1988, atau dikenal sebagai 'Morris Worm' yang diketahui merusak sekira 6.000 komputer. Akibat ulahnya ia dikenai sanksi untuk bekerja sosial selama 4000 jam. Kini ia bekerja sebagai pendidik di Massachusetts Institute of Technology.

8. The Masters Of Deception
The Masters Of Deception (MoD) merupakan kelompok hacker yang berbasis di New York. Kelompok ini sering mengganggu jaringan telepon milik perusahaan telekomunikasi seperti AT&T. Sejumlah anggota kelompok ini ditangkap pada tahun 1992 dan dijebloskan ke penjara.

9. David L. Smith
Smith dikenal sebagai penemu Mellisa worm, yang pertama kali ditemukan pada 26 Maret 1999. Mellisa sering juga dikenal sebagai "Mailissa", "Simpsons", "Kwyjibo", atau "Kwejeebo". Virus ini didistribusikan lewat email. Smith sendiri akhirnya diseret ke penjara karena virusnya telah menyebabkan kerugian sekira USD80 juta

10. Sven Jaschan
Jaschan menorehkan namanya sebagai seorang penjahat dunia maya pada tahun 2004 saat membuat program jahat Netsky dan Sasser worm. Saat ini ia bekerja di sebuah perusahaan keamanan jaringan.

Choi

Sumber : Okezone.com
Read full story

Kamis, 26 November 2009

Yahoo Open Hack Day Pertama di Asia Tenggara Sukses

0 comments
JAKARTA - Yahoo sukses menghadirkan acara khusus bagi web developer, yang bertajuk Open Hack Day, di Pusat Konferensi Balai Kartini, Jakarta. Acara yang berlangsung selama dua hari penuh ini memberikan kesempatan bagi para developer berbakat serta para partisipan yang inovatif untuk bertemu satu sama lain dan saling bertukar pengalaman sambil mengembangkan aplikasi bagi sebuah platform global.

Melalui Open Hack Day, web developer akan dapat berpartisipasi dalam acara bincang-bincang teknologi dan diskusi panel bersama para ahli teknologi terkemuka dan para inovator untuk membahas beragam teknologi dari Yahoo dan lebih banyak lagi. Dalam sesi ini, para developer akan mempunyai banyak kesempatan untuk belajar, berbagi dan berpartisipasi serta berkesempatan untuk mengakses secara langsung berbagai peralatan dan layanan untuk menjangkau khalayak yang tepat bagi aplikasi yang mereka ciptakan serta meraih sukses baik di dalam maupun di luar jaringan Yahoo.

Sesi-sesi tersebut akan diikuti dengan kesempatan untuk melakukan hack terhadap penawaran developer paling menarik sepanjang malam dan juga sepanjang hari. Acara ini akan ditutup dengan pameran hasil karya dari aplikasi yang telah dikembangkan selama acara berlangsung dan juga pemberian penghargaan bagi pemenang.

"Yahoo! berkomitmen untuk memacu pertumbuhan ICT dan industri Internet di Indonesia dengan berbagi lebih banyak lagi praktek-praktek terbaik serta mendukung ekosistem yang telah ada."

"Open Hack Day merupakan bagian dari strategi Yahoo! untuk memberikan kesempatan pertama bagi para pengembang, penerbit dan pengiklan di Indonesia untuk menciptakan sebuah pengalaman situs yang inovatif, relevan, bersifat pribadi serta membangun bisnis di antara para pengguna Yahoo!," tambahnya.

Dalam acara tersebut, Yahoo menyediakan koneksi bagi para developer ke jutaan pengguna dalam jaringan Yahoo!, menyediakan kesempatan untuk memanfaatkan aplikasi mereka di dalam platform Yahoo! dengan menggunakan data dari Yahoo! homepage, Yahoo! Mail, fasilitas Yahoo! Messenger, situs untuk berbagi foto Flickr dan penanda situs-situs penting Delicious, sebagai beberapa contoh diantaranya. Dengan menggunakan konten dan data dari jaringan Yahoo! akan memberikan nilai lebih kepada aplikasi pihak ketiga.

"Lebih dari 300 hacker yang telah terdaftar di Open Hack Day pertama di Asia Tenggara dengan sebagian partisipan berasal dari beberapa negara di ASEAN," ujar Michael Smith Jr., Head of Yahoo! Developer Network, Yahoo! Southeast Asia.

"Partisipan Open Hack Day akan berkesempatan merasakan pengalaman yang dialami oleh sekelumit orang elit di seluruh dunia, yaitu persahabatan, kerjasama, dan kompetisi dalam menciptakan aplikasi-aplikasi terbaik yang mereka miliki. Acara ini merupakan acara yang sangat unik dalam komunitas developer," tandasnya.

(Choi)

Sumber : Okezone.com
Read full story

Senin, 23 November 2009

Hacked Climate Change E-mails Highlight Security Concerns.

0 comments
In the heat of the climate change debate sparked by hacked e-mail messages, there has been little discussion of how the e-mails were leaked. In a connected world, security and privacy are both more important, and harder to come. The debate over climate change--and what is fact versus what fits the agenda of one side or the other--is raging in the wake of hacked e-mails alleging that facts were covered up. I'll let the climate change rivals battle that out, but let's take a closer look at the security aspects of e-mail and how attackers were able to acquire these messages.

A server at the Hadley Climate Research Center in the United Kingdom was breached and the attacker was able to acquire thousands of e-mail messages and sensitive documents which were subsequently uploaded to an FTP server in Russia and have since been publicly shared and analyzed around the world.

Officials have not commented on the authenticity of the data, although at least portions of it have been confirmed as legitimate. In a statement, officials did confirm the breach, though: "We are aware that information from a server in one area of the university has been made available on public Web sites."

Of course, this isn't the first time that potentially damaging information has been leaked due to an e-mail hack. You might recall Sarah Palin's personal Yahoo e-mail account getting hacked during the Presidential campaign last year.

Twitter has been victimized twice this year. First, in January some prominent Twitter accounts were compromised, leading to fake messages like the one allegedly from CNN anchor Rick Sanchez that said "i am high on crack right now might not be coming into work today." Then in May an attacker was able to compromise internal documents and employee salary information and post it to the Web.

These attacks are unfortunately not all that isolated or unique. In the case of the Palin hack, and at least one of the Twitter breaches, the weak link can be traced back to security controls on Web-based e-mail services. Attackers were able to exploit the system in place for users to recover lost usernames and passwords, and instead use it to gain unauthorized access.

The Hadley climate change breach, and the compromise of sensitive documents at Twitter, though, demonstrate why it is important to encrypt data--even data at rest on internal servers that are not intended to be exposed to the public Internet. Improved security controls to prevent unauthorized access in the first place would be nice as well, but encrypting the data trumps all else and virtually ensures it won't be compromised.

Ben Rothke, senior security consultant at BT Global Services notes that these types of attacks are simply a perfect storm, where hacktivists, broadband, poor security and cheap storage meet.

All of the breaches, hacks, compromises, and attacks highlight another point as well-if you write it, record it, photograph it, or in any way document or archive something, assume that it will be seen by the general public someday. With virtually endless amounts of digital storage, and social nature of online communications, its not possible to guarantee the data will never be disclosed.

I am not saying the ‘sky is falling' or declaring that security is dead. With strong passwords, solid security practices, and sufficient encryption, most data will never see the light of day. I am saying, though, that it is possible that the information could be disclosed despite your best efforts, and that you should think twice about what you write in an e-mail or post in a Facebook status update, lest it become a smoking gun skeleton in your closet.

Rothke says "The message is that every organization needs to take security seriously. But contentious organizations or those that store controversial data, be it a bank, embassy, developer of an operating system, or political organization, need to be extra diligent in securing their infrastructure."

Make sure you have security controls in place to prevent unauthorized access. Encrypt the data so that it can't be compromised even if the security controls fail. And, ultimately, don't write things in e-mails that you wouldn't want broadcast on the big screen in New York's Times Square.

Hope for the best, but plan for the worst. As Rothke puts it "Until they do that, the University of East Anglia will be just one of many such attacks. Get used to it."

(Choi)

Cumber : PCworld.com
Read full story

300 Hacker Asia Tenggara 'Serbu' Jakarta

0 comments
Jakarta - Jakarta akan jadi sorotan bagi para peretas jaringan komputer alias hacker, khususnya 300 hacker yang berasal dari negara-negara di Asia Tenggara. Mau apa mereka?

Jangan salah sangka dulu. Hacker-hacker ini datang ke Jakarta bukan untuk membongkar sistim jaringan komputer di Indonesia, namun untuk menghadiri ajang Open Hack Day yang digelar Yahoo!.

Indonesia menjadi negara pertama di Asia Tenggara yang jadi dipilih Yahoo! untuk menggelar ajang bergengsi bagi para hacker mancanegara tersebut.

"Ada lebih dari 300 hacker yang telah terdaftar di Open Hack Day, dengan sebagian partisipan berasal dari beberapa negara di ASEAN."

Open Hack Day sendiri akan berlangsung selama dua hari terhitung mulai hari Sabtu ini hingga Minggu (22/11/2009) di tempat konperensi berlangsung, ballroom Balai Kartini, Jakarta.

Perlu diketahui, Open Hack Day merupakan acara rutin yang diselenggarakan oleh Yahoo! untuk meningkatkan performa layanan mereka.

Dalam acara ini, Yahoo! berupaya mengumpulkan beberapa programmer terutama web developer agar dapat mengembangkan beragam aplikasi berdasarkan platform Yahoo!.

(Choi)

Cumber : Detikinet.com
Read full story

Urusan Hacker, Indonesia Juaranya

0 comments
Jakarta - Dari beberapa negara di Asia Tenggara, Indonesia telah dipilih sebagai tuan rumah Yahoo! Open Hack Day ASEAN. Bukan kebetulan belaka Indonesia menjadi tuan rumah acara digelar selama 21-22 November 2009 tersebut.

Pontus Sonnerstedt, Senior Director Business Development and Indonesia Country Lead, Yahoo! Southeast Asia, mengakui bakat hebat para hacker muda di Indonesia.

"Kami telah bekerja di Indonesia selama beberapa tahun, dan kami percaya akan kemampuan para web developer di Indonesia. Untuk itulah kami memilih Indonesia sebagai tempat diadakannya Open Hack Day."

Open Hack Day ASEAN diikuti oleh peserta dari beberapa negara tetangga seperti, Malaysia, Filipina, Singapura dan Vietnam. Dan pada akhirnya, Indonesialah yang terpilih sebagai tuan rumah ketimbang negara lain tersebut.

(Choi)

Cumber : Detikinet.com
Read full story

Hacker se-ASEAN Kumpul, Indonesia Dominan

0 comments
Jakarta - Ajang kompetisi multinasional Open Hack Day untuk wilayah ASEAN ternyata lebih banyak disesaki para peserta yang berasal dari Indonesia.

Dari total 300 orang yang telah terdaftar dalam ajang Open Hack Day yang diselenggarakan di Balai Kartini, 21-22 November 2009, terlihat bahwa Indonesia masih mendominasi jumlah peserta.

Open Hack Day untuk wilayah ASEAN memang diiukuti banyak peserta dari berbagai negara, meski belum ada data pasti, namun terlihat jelas bahwa Open Hack Day kali ini didominasi para peserta dari Tanah Air.

"Open Hack Day kali ini memang diikuti oleh peserta dari berbagai negara, namun kami belum memiliki angka pasti berapa total peserta yang berasal dari Indonesia" ujar Pontus Sonnerstedt selaku Senior Director Business Development and Indonesia Country Lead, Yahoo! Southeast Asia.

Diperkirakan 90% dari sekitar hampir 200 orang partisipan yang ada adalah para web developer yang berasal dari Indonesia.

(Choi)

Cumber : Detikinet.com
Read full story

Senin, 26 Oktober 2009

Hackers Hitting AV Infrastructure

0 comments
It's become an all-too-common scam: A legitimate Web site pops up a window that looks just like a real security warning. It says there's something wrong with the computer, and click here to fix it. A few clicks later, the victim is paying out US$40 for some bogus software, called rogue antivirus.

Rogue AV scams have become a big problem in recent months, but according to Trend Micro CEO Eva Chen, it's part of a more sinister, strategic attack on the antivirus industry in general. Criminals "can fake any other application. Why do they fake AV?" she asks.

According to her, a lot of today's security problems are designed not only to steal information from victims, but to undermine the credibility of companies like Trend Micro itself.

One way hackers have done this is by changing the way their software is put together each time they attack, forcing the AV vendors to bloat up their products with hundreds of thousands of new detection signatures.

In response, Trend was one of the first companies to push reputation-based technology into its antivirus products, developing its Smart Protection Network to identify and block not just viruses themselves, but also the malicious Web sites that are used to distribute malware.

Since 2004 Chen has served as CEO of the company she co-founded in 1988. She dropped by IDG News Service offices in San Francisco this week to answer a few questions. The following is an edited transcript of her interview.

IDG News Service: Microsoft has done a good job of making Windows more secure, but are Windows users better off today than they were five years ago?

Eva Chen: If Microsoft thinks it's secure enough, why do they bother to come up with MS Security Essentials for a free download on the side? With so much social engineered malware it actually has nothing to do with whether Windows itself is secure or not. It's the user's behavior. Plus there are so many applications -- either the browser or other applications' vulnerability, not just Windows.

IDGNS: It almost sounds like you're saying that things are worse?

Chen: Yes I would say so. …It has nothing to do with whether Windows is secure or not. It's just that the whole environment is much more unsafe. Hackers are making more money. And with the economic downturn, the criminal rate is going up, and therefore [there is] more cybercrime.

IDGNS: People say that conventional antivirus has not been up to the task and maybe even takes the wrong approach.

Chen: Actually I was the first one to say that. Last year I said the antivirus industry sucks. We were all competing on something that was irrelevant: our detection rates. You're at 100 percent detection rate this minute, the next minute it's down to 70 percent. What's the point of that competition?

There are really two industries fighting. The hackers, they are attacking the antivirus industry's infrastructure. How? First, they created all these variants and all these downloaders. They knew that the whole industry was competing against each other for detection rate. So when they came out with all these variants, it forced all the antivirus companies to add lots of pattern files. Those pattern files got so bloated because of the competition, [that] one it [created] lots of false alarms. So people hated antivirus for so many popups and false alarms. Second, the performance got really bad, so users tended to disable it. Two years ago there was a survey, called "The Most Hated Application," and antivirus -- not ours, but antivirus -- was on the top. So they attacked the whole antivirus industry in this way and therefore if we continue to compete with the detection rate thing, it just plays into their hands.

The second way they attacked antivirus infrastructure is the fake AV. If you look at this, they can fake any other application. Why do they fake AV? They make money and also they ruin antivirus companies' reputations and confidence in the whole antivirus industry.

Can you imagine our support engineers getting phone calls, "Hey your antivirus did not detect these viruses. This other antivirus detected all these viruses for me." And we have to explain to them, "No no no, that antivirus is actually a virus." It's a large burden for the antivirus [industry] to defend ourselves and to defend against that kind of bad reputation. (Choi)

Sumber : Yahoo.com
Read full story

Jumat, 16 Oktober 2009

Hacker Susupi Aplikasi Facebook

0 comments
SAN FRANSISCO - Hacker punya berbagai macam cara untuk membobol sistem komputer dan menyebarkan virus. Salah satunya adalah dengan menyusup melalui beberapa game dan aplikasi lain yang terdapat pada Facebook.

Dengan demikian, saat pengguna mengakses aplikasi yang telah disusupi hacker tersebut maka secara langsung mereka menginstal virus atau program lain yang dapat mengancam keamanan komputer.

Hal ini dikatakan oleh Chief Research Officer perusahaan keamanan komputer AVG Roger Thompson. Dia menemukan ada sekira setengah lusin game dan aplikasi Facebook yang disusupi program jahat.

"Saya justru berterimakasih dengan adanya serangan virus Koobface yang kemarin sempat mengenai Facebook dan situs jejaring sosial lainnya beberapa waktu lalu."

"Saat itu pertamakalinya saya baru benar-benar melihat bagaimana aplikasi Facebook terkena hack dan dari peristiwa itu kemudian kita mempelajarinya," tambah Thomson.

Menurutnya, beberapa aplikasi yang tersusupi hacker tersebut kini sudah tidak lagi ditampilkan di Facebook. Dia pun menyebutkan, program jahat tak hanya bisa menjalar melalui aplikasi di Facebook namun dapat juga menginfeksi melalui beberapa jenis peranti lunak yang digunakan pada PC. (Choi)

Sumber : Okezone.com
Read full story

Minggu, 13 September 2009

Rencana Hacker Bobol Situs PM Australia Terbongkar

0 comments
SIDNEY - Pemerintah Australia membongkar perbincangan hacker yang berencana menjebol situs milik Perdana Menteri Australia Kevin Rudd. Perbincangan sejumlah orang di forum chatting itu juga mengungkapkan jika sebelumnya hacker pernah membobol situs yang beralamat di pm.gov.au tersebut. Namun rencana tersebut gagal.

Dalam perbincangan dalam forum itu, terungkap bahwa keinginan hacker untuk membobol situs perdana menteri dilatarbelakangi kebijakkan Rudd yang mencoba untuk melakukan filterisasi internet.

Read More . . .
Read full story

Jumat, 07 Agustus 2009

Hacker Sempat Ganyang Facebook, Twitter dan Google

0 comments
SAN FRANSISCO - Serangan cyber berhasil melumpuhkan situs-situs ternama di dunia maya. Tidak hanya mesin pencarian Google, Facebook dan Twitter pun berhasil dilumpuhkan.

Twitter sempat tidak beroperasi selama lebih dari satu jam pada saat serangan berlangsung, Kamis (6/8/2009) malam.

Hal yang sama pun terjadi pada situs milik Mark Zuckerberg.Hanya saja, Facebook langsung menyadari serangan tersebut setelah sebagian besar penggemarnya melaporkan 'lemotnya' akses Facebook. Facebook menyadari adanya serangan distributed-denial-of-service (DDoS) yang menjadikan situsnya sulit diakses tadi malam.

Google masih lebih beruntung dibanding Twitter dan Facebook. Menurut Google, sistem jaringan keamanan Google telah lebih dahulu mengantisipasi serangan ini sehingga tidak ada kendala berarti di jaringan akses Google.

Menurut Google, hacker berhasil membuat serangan DDoS dan berupaya untuk menginfeksi komputer pengguna sehingga dapat berfungsi sebagai komputer 'zombie'. Komputer yang terinfeksi virus tersebut akan diperintahkan untuk secara simultan mengunjungi situs tertentu.

"Sepuluh tahun yang lalu kami pernah menyaksikan sebuah situs besar berhasil dilumpuhkan oleh serangan DDoS ini," ujar peneliti keamanan jaringan dari Cisco Patrick Peterson.

Namun bedanya, lanjut Peterson, saat ini botnet yang mereka ciptakan akan menginfeksi PC pengguna secara otomatis.

Facebook dan Google sudah bisa diakses dengan baik. Berbeda dengan Twitter, yang masih sulit diakses. Bahkan saat okezone mencoba membuka akun twitter terdapat notifikasi, (Choi)

Sumber : Okezone.com
Read full story

Hackers attack Twitter, Facebook also slows down

0 comments
NEW YORK - Hackers on Thursday shut down the fast-growing messaging service Twitter for hours, while Facebook experienced intermittent access problems.

Twitter said it suffered a denial-of-service attack, in which hackers command scores of computers toward a single site at the same time, preventing legitimate traffic from getting through.

The attacks may have been related to the ongoing political conflict between Russia and Georgia. They started with hackers using a botnet to send a flurry of spam e-mail messages that contained links to pages on Twitter, Facebook and other sites written by a single pro-Abkhazia activist, according to Bill Woodcock, research director of the San Francisco-based Packet Clearing House, a nonprofit that tracks Internet traffic.

Russia recognized as independent the breakaway regions of South Ossetia and Abkhazia after a brief war with Georgia a year ago.

When people clicked on the links, they were taken to the activist's legitimate Web pages, but the process of loading the pages at such volumes overwhelmed some servers and disrupted service, Woodcock said. He said it's hard to immediately tell whether it was a case of hackers trying to punish the sites for publishing views they disagree with, or if they were directing traffic to the sites out of sympathy for the activist's message.

"There's very little way of distinguishing which side was taking this action, because either side could hypothetically benefit from it," Woodcock said.

The fact that a relatively common attack could disable such a well-known Web site shows just how young and vulnerable Twitter still is, even as it quickly becomes a household name used by celebrities, large corporations, small businesses and even protesters in Iran.

"Clearly they need a stronger infrastructure to be able to fight this kind of attack," said Graham Cluley, senior technology consultant at computer security firm Sophos. Twitter's tech support teams, he added, "must be frankly out of breath" trying to keep up with the site's enormous growth.

According to comScore, Twitter had 20.1 million unique visitors in the United States in June, some 34 times the 593,000 a year earlier.

For Twitter users, the outage meant no tweeting about lunch plans, the weather or the fact that Twitter is down.

"I had to Google search Twitter to find out what was going on, when normally my Twitter feed gives me all the breaking news I need," said Alison Koski, a New York public-relations manager. She added she felt "completely lost" without Twitter.

The Twitter outage began at about 9 a.m. EDT and lasted a few hours.

Facebook, whose users encountered intermittent problems Thursday morning, was also the subject of a denial-of-service attack, though it was not known whether the same hackers were involved. Unlike Twitter, Facebook never became completely inaccessible. Facebook said no user information was at risk.

LiveJournal, a 10-year-old online diary and blogging site that has waned in popularity in recent years, was also the subject of a denial-of-service attack that lasted about an hour Thursday morning, the company said.

By early afternoon both Twitter and Facebook seemed to be functioning, giving cubicle-bound social media addicts a collective sigh of relief. Twitter warned, though, that as it recovers, "users will experience some longer load times and slowness."

Technology business analyst Shelly Palmer told AP Radio that denial-of-service attacks are a reality of the information age.

"People tend to want to take sites that are very public and go after them," said Palmer, managing director of Advanced Media Ventures Group. "In fact you'd be surprised how many sites for major companies are really attacked on a daily basis. This is a crime, it's a real crime and it should be treated that way."

Earlier this week, Gawker Media, which owns the eponymous media commentary blog and other sites, was also attacked. In a blog post, Gawker said Tuesday it was attacked by "dastardly hackers," leading to server problems that caused network-wide outages Sunday and Monday. It was not immediately clear whether those attacks were related to Twitter's.

Thursday's was not the first — and likely not the last — outage for Twitter.

Besides planned maintenance outages, overcapacity can cripple Web sites, especially such fast-growing ones as Twitter and Facebook.

In fact, service outages on Twitter once were so common that management began posting a "Fail Whale" logo on the Web site to signal when the service was down. The logo featured a whale being hoisted above the water by a flock of birds.

Millions of Twitter users aren't familiar with the 3-year-old service's history of frequent outages because they began tweeting in the past six months, around the same time that the San Francisco-based company had was spending more money to increase its computing power and reduce the disruptions. With the added capacity, the Fail Whale rarely surfaces any more.

Even so, the entire site being down means Twitter hasn't put enough measures in place to prevent such an attack, Cluley said. That could include working with Internet service providers to filter potentially malicious requests from legitimate ones, as well as having servers spread out around the world.

Denial-of-service attacks are typically carried out by "botnets" — armies of infected computers formed by spreading a computer virus that orders compromised machines to phone home for further instructions. They are generally used to send out spam or steal passwords, though some can be commanded to overwhelm Web sites.

Successful attacks on popular Web sites were common earlier this decade. Sites such as eBay, Amazon.com and CNN were overwhelmed by such attacks, sometimes for days, in 2000.

But Thursday's attack underscores the fact that no one is immune.

"With these attacks, if you get enough infected machines ... you can take down anyone," said Dmitri Alperovitch, vice president of threat research at security vendor McAfee Inc.

Last month, dozens of U.S. and South Korean sites, including those of the White House and South Korea's presidential Blue House, were targeted in denial-of-service attacks.

For Lev Ekster, who runs a mobile cupcake truck called CupCakeStop in New York, Thursday's Twitter hiccup meant no tweets to customers and fans on the truck's location and the day's flavors.

But it wasn't the end of the world.

"As soon as I saw the Twitter outage, I went on to our Facebook fan page," said Ekster, who also uses Twitter to get reviews of his cupcakes, find employees and let people know about giveaways. (Choi)

Sumber : Yahoo.com
Read full story

Minggu, 02 Agustus 2009

Hackers expose weakness in visiting trusted sites

0 comments
LAS VEGAS - A powerful new type of Internet attack works like a telephone tap, except operates between computers and Web sites they trust.

Hackers at the Black Hat and DefCon security conferences have revealed a serious flaw in the way Web browsers weed out untrustworthy sites and block anybody from seeing them. If a criminal infiltrates a network, he can set up a secret eavesdropping post and capture credit card numbers, passwords and other sensitive data flowing between computers on that network and sites their browsers have deemed safe.

In an even more nefarious plot, an attacker could hijack the auto-update feature on a victim's computer, and trick it into automatically installing malware pulled in from a hacker's Web site. The computer would think it's an update coming from the software manufacturer.

The attack was demonstrated by three hackers. Independent security researcher Moxie Marlinspike presented alone, while Dan Kaminsky, with Seattle-based security consultancy IOActive Inc., and security and privacy researcher Len Sassaman presented together.

They reached essentially the same conclusion: There are major problems in the way browsers interact with Secure Sockets Layer (SSL) certificates, which is a common technology used on banking, e-commerce and other sites handling sensitive data.

Browser makers and the companies that sell SSL certificates are working on a fix.

Microsoft Corp., whose Internet Explorer browser is the world's most popular, said it was investigating the issue. Mozilla Corp., which makes the No. 2 Firefox browser, said most of the problems being addressed were fixed in the latest version of its browser, and that the rest will be fixed in an update coming this week.

VeriSign Inc., one of the biggest SSL certificate companies, maintains that its certificates aren't vulnerable.

Tim Callan, a product marketing executive in VeriSign's SSL business unit, added that the "tap" won't work against so-called Extended Validation SSL certificates, which cost more and involve a deeper inspection of a company's application for a certificate.

The attack falls into a class of hacks known as "man-in-the-middle," in which a criminal plants himself between a victim's computer and a legitimate Web site and steals data as it moves back and forth.

Jeff Moss, founder of the Black Hat and Defcon conferences who this summer was appointed to the Homeland Security Department's advisory council, said the fact a hacker has to actually break into a victim's network for the attack to work can limit its usefulness.

"That's the nice mitigating thing," he said.

But he warned that "for targeted attacks it's absolutely deadly. This is the way you can get everything. If you can get in the middle, you can get everything. It's a big, giant wake-up call for the industry."

SSL certificates are a critical technology in assigning trust on the Web.

Sites buy them to encrypt traffic and assure visitors it's OK to enter confidential information. Companies that sell SSL certificates verify that someone trying to buy a certificate actually owns the site that certificate will be attached to.

The presence of an SSL certificate on a site is designated by a padlock in the address bar. But many people don't pay attention to whether a padlock is present or not.

Browsers do care, though, which is why this week's talks were significant.

Browsers are programmed to block sites that don't have a valid SSL certificate, or have a certificate displaying a Web address that doesn't match the address a Web surfer was trying to reach (which can indicate someone has hijacked a person's Internet session). If the sites aren't blocked, users are warned about potential danger, and have the option to click through.

The problems outlined by researchers center on a quirk in the way browsers read SSL certificates.

Many SSL certificate companies will allow people to attach a programming symbol called a "null character" into the Web address onto the certificates they receive. Web browsers generally ignore that symbol. They stop reading at that symbol when they're checking the Web address on a certificate.

The trick in the latest type of attack is that all a criminal would need to do is put the name of a legitimate Web site before that character, and the browser will believe that the site it's visiting — which is under the criminal's control — is legitimate.

The criminal could then forward the traffic onto the legitimate site and spy on everything the victim does on that site. It's a complicated attack, but it highlights a significant weakness in the very technology widely used to assure people it's safe to navigate sensitive sites.

Jon Miller, an SSL expert and director of Accuvant Labs, said he expects significant attacks against corporations using this technique in the coming months. Criminals who run "phishing" scams, in which people are tricked into visiting phony sites, will also likely latch on.

"What kind of makes this earth-shattering is these aren't the most sophisticated attacks in the world," he said. "This is going to become a huge problem."

There are signs it's already starting.

VeriSign's Callan said within hours of the talks, his company got a number of applications for SSL certificates featuring null characters, but they were denied. (Choi)

Sumber : yahoo.com
Read full story

Minggu, 26 Juli 2009

Film Uighur Tayang, Hacker China Rusak Situs Australia

0 comments
MELBOURNE - Hacker China kembali melancarkan serangannya. Kali ini yang menjadi sasaran adalah sebuah situs tentang festival film terbesar di Australia.

Para peretas sengaja melakukan aksi ilegal itu karena mereka tersinggung dengan pihak panitia penyelenggara festival. Pasalnya, dalam salah satu agenda akan menampilkan sebuah film dokumenter mengenai tokoh etnis Muslim Uighur, Rebiya Kadeer.

Situs itu telah diubah tampilan dan diganti dengan bendera China. Selain menyusup dan memasang bendera, hacker juga mengkritik keinginan festival itu dalam menyajikan film yang berjudul l The 10 Conditions of Love tersebut.

Sebelumnya, Konsulat China telah mengontak penyelenggaran Melbourne International Film Festival dan mendesak mereka membuang sebuah film yang bercerita tentang perempuan pengusaha Uighur, Rebiya Kadeer, yang diasingkan ke luar negeri, serta hubungannya dengan suaminya yang juga seorang aktivis, Sidik Rouzi, serta 11 anaknya. 3 anak Kadeer kini telah ditahan Pemerintah China. Selama ini Kadeer dikenal atas perjuangannya mendesak otonomi bagi Uighur yang dihuni 10 juta warga Muslim.

Pemerintah China belum lama ini menuduh Kadeer sebagai otak di balik kerusuhan etnis di Provinsi Xinjiang, antara etnis Muslim Uighur dan etnis mayoritas Han.

Akan tetapi, direktur festival Richard Moore menegaskan tidak akan menarik film yang rencananya akan tayang pada 8 Agustus mendatang. "Saya tidak akan tunduk pada keinginan penguasa China," jelas Moore.

Saat ini Moore telah menyerahkan kasus ini kepada kepolisian Australia. Pihak berwajib pun tengah menelusuri aksi yang diyakini dilakukan China tersebut, terlihat dari alamat internet yang teridentifikasi. (Choi)

Sumber : Okezone.com
Read full story

Jumat, 24 Juli 2009

Hacker Group L0pht Makes a Comeback, of Sorts

0 comments
The news report begins with shots of a tense space shuttle launch. Engineers hunch over computer banks and techno music pounds in the background. There is a countdown, a lift-off, and then you see a young man in a black T-shirt and sunglasses, apparently reporting from space.

This is the Hacker News Network, and after a decade offline it is lifting off again, this time with a quirky brand of video reports about security.

Hacker News Network is one of the side projects of the Boston-based hacker collective known as L0pht Heavy Industries. They're the guys who famously told the U.S. Congress that they could take down the Internet in about 30 minutes, and who helped invent the way that security bugs are reported to computer companies.

The L0pht's eight members were hacker gods back in the '90s, but most of them have faded from the limelight, even as they've watched a cottage industry of security research firms sprout up based on many of the disclosure techniques they pioneered. The L0pht disbanded after it sold out to consultancy @stake in 2000, and its members gradually watched their dream of being paid to do cutting-edge hacking and security research wither and die.

But over the past few months, the L0pht has been getting back together, kind of.

Six of the eight members reunited last year at a Boston security conference, and in May 2009, members of the group released the first update to their L0phtCrack password audit tool since 2005. They say it took a few years of negotiations with Symantec -- which bought @stake in 2004 -- to get back control of L0phtCrack and several other L0pht properties.

Last month the L0pht Web site went back online, and the demo version of Hacker News Network is set for an official launch on Jan. 11, 2010. (Chosen because the date 01-11-10 works as a binary number.)

The L0pht Web site will give members a single place to link to their current projects. Peiter Zatko, aka Mudge, says he'd like to use it as an archive of the group's historic security advisories.

More projects may evolve. The group acquired the rights to its AntiSniff network monitoring tool from Symantec and is toying with the idea of reviving that as well.

"We're still trying to figure out what the ultimate goals are," said Joe Grand, aka Kingpin. "But I'm just happy that we can be in touch on a personal level and not have to deal with business, not have to deal with politics, and just have a place to do stuff."

Business and company politics pretty much killed the L0pht, according to some members. The core members sold their business to @stake in the hopes that with a deep-pocketed corporate sponsor, they would be free to do hacking projects that really interested them, such as drawing attention to important security problems that were being ignored by software vendors.

Mudge describes the L0pht's early security advisories as "very much a Rachel Carson-meets-Consumer Reports sort of attempt." (Carson was a biologist who advanced the environmentalist movement in the '60s.) Initially, the group tried to apply that neutral Consumer Reports model to its @stake work, refusing to take money or free products from vendors. "It drove the venture capitalists nuts because we'd be turning down the money," he said.

But in the end, corporate pressures trumped idealism. Within six months, Space Rogue, the only member who remains anonymous, was fired from his job in the company's PR department ("I didn't fit in at all; they were a bunch of clueless idiots," Space Rogue remembers), and gradually other members drifted away, often in disillusionment.

"We went there to become researchers," said Christien Rioux, aka DilDog. "Unfortunately the research part didn't generate enough money to fund the consulting part."

"It stopped being fun," said Joe Grand, who said he left after being pressured to do consulting work instead of the research he loved. Today Grand runs his own electronics design company, Grand Idea Studio.

Some members stopped talking to each other, angry with the way things had gone. The only L0phter with Symantec today is Paul Nash (aka Silicosis).

But bad feelings between the members have softened with time. Though many of them live in different cities now, they still get together whenever they can, at conferences or when they happen to be passing through the same city.

"I don't think we could ever recapture the magic of what the L0pht was," said Space Rogue, who is now an IT staffer in Massachusetts. "But I think we're at the point now where we can rekindle the friendship."

"It's L0pht again, but different," he said.
(Choi)

Sumber : Yahoo.com
Read full story

Rabu, 22 Juli 2009

Situs Jejaring Jadi Target Hacker

0 comments
SAN FRANSISCO - Penjahat cyber kini semakin gencar memanfaatkan jejaring sosial untuk menyasar calon korban yang potensial untuk kemudian menyerang mereka.

Salah satu firma keamanan internet, Sophos mengatakan perusahaan situs dua arah saat ini berkonsentrasi pada upaya meningkatkan jumlah pengguna mereka, namun kurang ketat dalam melindungi para pengguna mereka dari serangan cyber.

Faktanya, jejaring sosial cenderung tidak menyediakan pedoman privasi yang jelas dan mudah diakses untuk menghindari serangan cyber yang membidik mereka.

"Kami khawatir, pegawai perusahaan yang mencantumkan terlalu banyak informasi personal mereka melalui situs jejaring sosial akan berisiko menjadi sasaran serangan cyber. Terutama jika mereka menaruh data tentang infrastruktur perusahaan maupun data sensitif lainnya."

Survei yang diadakan oleh Sophos juga mengindikasikan bahwa lebih dari seperempat perusahaan rata-rata menjadi sasaran empuk serangan spam, phising, ataupun virus jahat yang disebarkan melalui situs jejaring seperti Twitter, Facebook, LinkedIn dan MySpace.(Choi)

Sumber : Okezone.com.com
Read full story

Jumat, 17 Juli 2009

Twitter Sempat Kena Hack

0 comments
LONDON - Situs-situs yang tengah populer memang menjadi sasaran empuk bagi para hacker. Setelah sebelumnya Facebook sempat dihajar oleh hacker kini giliran situs mikroblogging Twitter yang menjadi sasaran.

Pendiri Twitter, Biz Stone mengaku terkejut mengetahui situsnya dihack melalui salah seorang pegawai yang ditugasi untuk mengatur akses informasi perusahaan. Hacker tidak masuk kedalam akun pengguna, melainkan dengan mengambil screenshot halaman Twitter milik salah satu pengguna.

"Ini bukanlah serangan terhadap layanan Twitter, melainkan serangan personal yang diikuti oleh pencurian dokumen pribadi perusahaan," kata Stone.

Hacker bisa mengakses informasi perusahaan Twitter melalui akun Google Apps salah satu pegawai Twitter yang memiliki spreadsheet dan detail informasi keuangan yang tersimpan di dalamnya. Stone pun menambahkan hal ini terjadi bukan karena kelemahan pada peranti lunak yang digunakan Twitter.

Hacker itu kemudian menyebarkan detil informasi perusahaan Twitter di berbagai blog dan publikasi lainnya. Beberapa dokumen diantaranya bahkan dipublikasikan dalam blog yang memuat beragam informasi teknologi, TechCrunch. (Choi)

Sumber : Okezone.com
Read full story

Jumat, 10 Juli 2009

16 Negara Serang Jaringan Komputer Korsel - AS

0 comments
SEOUL - Gelombang serangan hacker ke sejumlah situs di dua negara Amerika Serikat (AS) dan Korea Selatan (Korsel) diketahui berasal dari 86 alamat IP di 16 negara.

Hal itu diungkapkan anggota parlemen Korea Selatan, Chung Chin-Sup kepada wartawan. Pernyataan itu dilontarkan Chin setelah memberikan pengarahan kepada National Intelegence Service (NIS), Korsel untuk menyelidiki lebih lanjut alamat IP penyerang.

Chin mengatakan, 16 negara tersebut antara lain, Korea Selatan, Amerika Serikat, Jepang, dan Guatemala.

"Sejauh ini Korea Utara memang tidak termasuk ke dalam 16 negara asal 86 alamat IP tersebut," kata seorang anggota parlemen lainnya, Park Young-sun.

Kendati demikian, NIS tetap menduga bahwa Korea Utara tetap dapat dituding berada di belakang penyerangan tersebut. Sebelumnya, Korsel telah 'keukeuh' mencurigai dalang dari penyerangan tersebut adalah Korea Utara.

Tak hanya Korsel, pemerintah AS juga menuding Korea Utara sebagai biang keladi dari penyerangan. Tapi untuk membuktikan penyerangan itu, AS mengaku sangat kesulitan.

Tudingan ke arah Korea Utara, cukup beralasan, karena Korea Utara sedang di sorot dunia internasional terkait ujicoba rudal nuklir dan roket yang dilakukan negara di bawah kepemimpinan Kim Jong Ill tersebut. (Choi)

Sumber :okezone.com.com
Read full story
Twitter Delicious Facebook Digg Stumbleupon Linkedin Yahoo! Bookmarks Google Buzz Google Reddit Mixx Technorati RSS Favorites
 

Blog Archive

News Technology Computer © 2008 Business Ads Ready is Designed by Choi Rozs Supported by Blogger