Tuesday, March 18, 2014

THE UROBUROS MALWARE: HOW RUSSIA MIGHT BE THE ONES HACKING COMPUTERS IN UKRAINE USING CYBER WARFARE

If you think russia wont join their counterparts in other countries in privacy and hack expliots this year, then uroburos is questionable

RTX11PGR
An electronic-mechanical typewriter with a Cyrillic keyboard is pictured at the headquarter of the German firm Olympia Business Systems in Hattingen near the western German city of Wuppertal July 17, 2013. REUTERS/Wolfgang Rattay
Dozens of Ukrainian computer networks, including government systems, have reportedly been infected by an “aggressive cyberweapon” called Snake or Uroburos, supposedly created in Russia.
The British-based security firm BAE Systems has identified 14 instances of Uroburos in Ukraine in 2014, the earliest instances of which were before the Euromaidan protests even heated up. Experts haven't identified specific victims of Uroburos attacks, but its sophisticated nature suggests it was designed to attack high-value targets like government networks and telecom systems.
The malware expertly bypasses sophisticated Windows security measures and can steal data and capture network traffic, according to Hacker News. Experts say Uroburos could have been active up to three years ago and gone undetected since then, which would be a testament to how sophisticated it is.
More specifically, Uroburos is a rootkit, a type of software whose primary function is to hide functions and processes in a system. It acts like a stealth cloak that allows someone to basically do whatever they please on a system without being detected.
G Data Software, a German-American cybersecurity firm that has researched Uroburos extensively, coined the named Uroburos after finding several instances of the world embedded in the malware’s code. There’s even a line of code that reads “Uroburos got you,” stylized to suggest the programmers got the name from a webcomic called Homestuck, of all places.
There’s also several references to snakes found in the rootkit’s code, prompting the name Snake for the larger toolkit software Uroburos is a part of.
Can Uroburos Be Tracked To The Russian Government?
It’s incredibly sophisticated nature suggest to experts that it was developed not by cybercriminals, but by a state agency.
It’s likened in complexity to the Stuxnet malware used to sabotage a number of Iranian nuclear centrifuges, which is saying a lot. G Data calls it “one of the most advanced rootkits (G Data) has ever analyzed.”
G Data “believes that highly trained developers must have been involved,” and that “a secret service is behind Uroburos.”
Just which secret service? G Data believes it's Russia’s. They found indications that suggest the developers of Uroburos speak Russian. They suspect the people behind Uroburos are the same who attacked U.S. systems with a malware called Agent.BTZ. The programming language is similar and Uroburos even checks to see if Agent.BTZ is already on a system, in which case it remains inactive.
Evidence also suggests the code was developed in a UTC+4:00 time zone, otherwise known as Moscow Time, which encompasses most of western Russia.
That would explain why Uroburos is either being rolled out or activated in Ukraine. Ukraine targets make up 57 percent of all instances of Uroburos infections identified by BAE Systems.
Granted, most occurred before former President Viktor Yanukovych was tossed out of power, but if we’ve learned anything about international security efforts since the NSA scandal broke, it’s that state governments are not afraid to stick their noses in their neighbors’ (and friends’) business.
See G Data's full Red Paper report on Uroburos here.

HOW TO CONTROL A COMPUTER USING AN ANDROID DEVICE

Welcome, here i will show you how to control your PC or any PC using an android device. 
To begin we will require
ANDROID REMOTE PC SERVER: download here
ANDROID PC CLIENT FOR ANDROID DEVICE: download from playstore
YOU CAN DOWNLOAD THE PREMIUM VERSION here







With this device you can control the mouse pad of your computer and remotely control some default applications, like music, video and word documents. 

check for documentation at ADREMOTEPC

Thursday, March 6, 2014

APPLE BORROWING FROM BLACKBERRY

The fact that Apple's in-car software is running atop a QNX platform would be less than newsworthy except for the fact that BlackBerry bought QNX back in 2010.

Apple has managed to rouse those of us in the tech press from the early-March doldrums by taking the wraps off CarPlay, the company’s in-vehicle iPhone interface that was revealed nine months or so earlier and simply named iOS in the Car.
BlackBerry news site N4BB managed to confirm with the spokesperson of a company called QNX that the CarPlay interface rests atop QNX’s widely-used “infotainment platform” – a fancy term for the thing with the screen in between you and your passenger that you poke at with your finger — the screen, not the passenger — to change the radio station. I suppose poking at your passenger might ultimately achieve the same result.
The fact that Apple’s in-car software is running atop a QNX platform would be less than newsworthy except for the fact that BlackBerry bought QNX back in 2010, and has used QNX technology as the basis for its ill-fated PlayBook tablet and the most recent version of its smartphone software, BlackBerry 10.
So, yes: Apple software is being powered by BlackBerry, in a sense. QNX has been the glue holding together many an in-car entertainment – sorry, infotainment – system for years and years now, so it’s likely this CarPlay interface would have been running atop it whether BlackBerry was in the picture or not. It could almost certainly run atop non-QNX systems as well for all we know.
In other scandalous news, the camera sensor in the iPhone is widely believed to be made by Sony, and the iPad, iPhone and MacBook Pro displays have come from the likes of Samsung and LG over the years. I know, right? It’s like learning that Santa Claus doesn’t… you know what? On second thought, I’m not going to spoil that one.

HOW YOUR ANTI-VIRUS SOFTWARE MIGHT BE USELESS

Some computer consultants say the global malware threat has gotten so bad that conventional security measures, such as anti-virus software, are no longer adequate to fight them.
Anti-virus programs are “totally useless,” says Mohammad Mannan, an assistant professor at the Concordia Institute for Information Systems Engineering in Montreal.
“If you use them, you might even be vulnerable [to malware] to some extent,” he says.
A recent Visa survey showing that 92 per cent of respondents under the age of 35 had been the target of phishing scams demonstrates the tenacity of the hackers who are trying to seize personal financial information.
Anti-virus software works on the principle of identifying malevolent files and infected sites. But because of the sheer volume of malware online nowadays, rather than blacklisting bad sites we should be “whitelisting” the good ones, says Stu Sjouwerman, founder and CEO of U.S.-based computer security consultancy KnowBe4.com.
The amount of malicious software — better known as “malware”— circulating on the web has grown significantly in the past decade.
According to figures from virus detection sites, in 2002 there were an estimated 17 million known “good” executable files from various existing applications on the commercial internet, while antivirus engines detected two million nefarious ones.
By 2012, there were 40 million known good files and 80 million bad ones.

Malware threat growing

The main driver of this shift is cybercrime, says Fabrice Jaubert, a software developer who works with Google’s malware detection team in Montreal.
In the past, malware was often the work of malicious individuals or pranksters looking for recognition of their coding prowess. But according to Jaubert, computer attacks nowadays are perpetrated almost entirely by organized crime.
Malware graphic
“It’s 100 per cent criminal – or 99.99999 per cent,” says Jaubert. “The end goal here is money — big money.”
Criminal hackers look for ways to install malware on your computer for the purpose of stealing your passwords, credit card numbers and banking information — which they can sell to other criminals — or commandeering your computer to distribute illicit material such as porn.
Cybercrime is estimated to be a $3 billion US industry, and its perpetrators are largely based in eastern European countries such as Romania, Russia and Ukraine, says Sjouwerman, author of Cyberheist: The Biggest Financial Threat Facing American Businesses Since the Meltdown of 2008.
One of the reasons malware is such a widespread problem is that it has become harder for consumers to detect, says Tony Anscombe, senior security evangelist for anti-virus firm AVG.
“Malware viruses used to be disruptive — if you got one, you knew you had it. Now, they’re deceptive and hide in the background,” Anscombe says.
There are a number of ways hackers can get into your computer, but nowadays, a lot of it is accomplished by “social engineering.” For example, you may get an email or even a phone call that appears to be from a bank or a tech support representative asking you to open an email attachment or to click through to an infected website. 

The problem with anti-virus software 

In the face of this ever-present threat, computer security firms have made billions of dollars selling anti-virus software to consumers.
The major problem, says Concordia’s Mannan, is that anti-virus software is by nature reactive, which means that it responds to specific malware after it has been distributed. Should a malware writer change a few lines of code, however, that anti-virus solution suddenly becomes obsolete.
It’s the sheer number of malware variations that makes it impossible for anti-virus software to effectively combat the problem, says Mannan. To illustrate this, he points to the Storm botnet of 2007, a sophisticated piece of malware that affected millions of computers worldwide and generated 8,000 variations of itself every day.
“How many updates or variants are you going to catch, if you’re an anti-virus company?” Mannan asks.
But while anti-virus software isn’t foolproof, it’s “a long way from useless,” says Brian Bourne, co-founder of Toronto's annual SecTor cybersecurity conference.
He likens anti-virus software to locking the doors of your car.
“It doesn’t stop someone who's motivated from stealing your car, but it does force them to put a little bit of effort in and it does mean you’re not quite as easy [a target] as the unlocked car beside you,” he says.
Google’s Jaubert says that in recent years, some hackers have even taken to posing online as anti-virus companies with legitimate-looking websites, finding victims by ironically playing on their fear of malware. They offer "virus scans" that are actually malware.

Is ‘whitelisting’ the answer?

Given these overwhelming threats, Sjouwerman believes whitelisting is vital to keep web surfers safe.
The principle is similar to verified accounts on Twitter, which was a response to the proliferation of bogus accounts (usually ones pretending to belong to celebrities). Rather than identifying all the fake accounts, Twitter’s verification process simply certifies the legitimate one.
Whitelisting has been around for more than a decade, says Mannan, but only a few companies offer it right now.
The way it works is that anytime you surf the web, the whitelist prompt appears in your browser. If you go to a website that has been penetrated by hackers, the browser pops up a stern warning telling you not to proceed to the site.
Google’s Chrome browser “has this to a degree, but that’s all based on blacklists,” says Sjouwerman.
Whitelisting would keep a list of good sites on your workstation and in the cloud, which is a “sanity check” for the list on your computer.
Sjouwerman is convinced it’s the only way to deal with the growing malware threat.
“We need to do a 180, and we need to stop keeping the bad guys out, because you can’t keep up,” says Sjouwerman.
“That’s why I’m on an evangelizing rampage to tell people we need to go to whitelisting.”

Sunday, March 2, 2014

HOW TO MANUALLY CONFIGURE YOUR FREE VPN- VIRTUAL PRIVATE NETWORK WITH TEAMVIEWER

This tutorial is from SMART PC TRICKS,  and is wonderfully detailed, so i thought i might share it here
What is VPN? A virtual private network (VPN) is a network that uses Internet, to allow remote offices or individual users with secure access to their organization’s network just like in local area network. How to create free software VPN? Let’s start building free VPN.! The security achieved by tunneling like Layer Two Tunneling Protocol (L2TP). In VPN connections the sender encrypting data and receiver decrypting it at the receiving end thus creating a Tunnel.
Usually CISCO VPN routers are used for corporate VPN setup. We will discuss more about VPN and VPN configuration in detail on later articles.
Is it possible to create VPN without dedicated hardware like CISCO VPN router and leased line? Yes, with the help of VPN client softwares we can configure Virtual Private Network. In this article we will cover How to set up and configure free VPN using Team Viewer, they are providing VPN service.

Team+Viewer+vpn tunnel How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software

How VPN Protects from Hackers?

By encrypting the data VPN acts as a Virtual Tunnel between sender and receiver. Only the receiver can decrypt data. A Hacker can access the encrypted data thus unable to detect original data.
For example consider
  • I’m encrypting the word ‘SmartPCTricks’ using some digital algorithms and converting it in to another data like ‘*!&@^#%$’.
  • Sending the encrypted data packet over internet. Only the receiver can decrypt ‘*!&@^#%$’ to actual data ‘SmartPCTricks’.
  • If a Hacker try to access my network he may getting only ‘*!&@^#%$’. The encrypted data path is termed as Tunnel
How+VPN+Works How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software

How TeamViewer VPN Works?

We have already discussed with Team Viewer, the best Remote Desktop Software. But most of the peoples are unaware about the VPN client facility in Team Viewer.
Unknown+VPN How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software
We can create Virtual Private network via TeamViewer without any hardware (CISCO or other VPN routers).
The principle of TeamViewer Tunneling is same as normal VPN but the only difference is that the encrypting and decrypting is done in the computer itself. No hardware required for encryption and decryption. Encrypting carried by a Virtual Network Adapter and Team Viewer software.
How+TeamViewer+free+VPN+Works How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software

How to Setup a VPN using Team Viewer free VPN Service

TeamViewer has free VPN client, Here is the step by step procedure to VPN setup with TeamViewer.
Before the technical description let’s see my environment.
Problem: I want to access shared folder in my office computer, I don’t have VPN hardware. What to do?

(Start TeamViewer in both computers)
Step 1: Creating TeamViewer account Launch TeamViewer (Optional)
Go to Computers and Contacts, then Sign UP for a Free TeamViewer account.

Computers+and+Contacts+Sign+UP+In+TeamViewer+8 How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software
(Click on the image to Enlarge)
Step 2: Add computer to my Team Viewer account  (Optional)
Add new computer to my account by clicking the Add button,

Add+remote+Computer+to+Team+Viewer+account How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software
(Click on the image to Enlarge)
Here I added my Office PC. The green signal shows it is online now and ready to accept incoming connections.
Step 3: Install VPN Network Adapter
Click Extras >> Options >> Advanced Options

Team+Viewer+Options How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software
Scroll down to see Team viewer VPN Driver and click to Install
Install+Team+viewer+VPN+Network+Adapter How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software
(Click to Enlarge)
A popup window will appear for installing VPN network adapter. Install it.
Installation+of+TeamViewer+VPN+Network+Adapter How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software
After the VPN adapter now listed in the Network Sharing Center, but the status is disconnected.
TeamViewer+VPN+Adapter+Network+Sharing+Center How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software
Step 4: Obtaining IP for VPN
Now give the ID of remote computer and start VPN connection.

Team+viewer+VPN+Network+connection How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software
(Optional)
If you logged in to Team Viewer account, right click on the remote PC and select VPN,

Install+TeamViewer+VPN+Network+Adapter How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software
The TeamViewer provides automatic IP for your VPN adapter.
TeamViewer+automatic+IP How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software
Check the Adapter status now in the Network and Sharing Center!
Team+Viewer+VPN+Adapter+Status How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software
Yet, It is active!
Using the Test ping button you can ping to Remote computer for checking the connectivity.
Test+ping+Team+Viewer+VPN+Adapter How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software
(Please turn off firewall in both computer; otherwise you cannot access the remote PC and test ping will not work)
Step 5: Explore the remote PC
Now the remote computer connected as local computer to your PC, Click Minimize button,

Minimize+button+TeamViewer+automatic+IP How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software
Open Start >> Run, then type \\IP of Partner and hit Enter key,
Open+Remote+Computer+Team+Viewer+VPN How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software
For example \\172.16.12.55
Step 6: Authenticating Remote PC
Provide remote computer credentials, Type the User Name like

  • Domain Name\User Name (if the remote PC lies under a Domain) otherwise 
  • Computer Name\User Name (If remote PC not under a Domain
For example my Office computer not in the domain,
Computer Name: User-PC
My user name: User

So I provided User-PC\User.
Authenticating+Remote+PC+via+Team+Viewer+VPN How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software
NB: You must have a password protected user account on the remote PC
Yes, That’s it. Now we have done free VPN, you are able to access the remote PC just like in a local network. You can access file, Shared folders and Shared printers etc.

Access+Remote+PC+using+Team+Viewer+VPN+setup How to Setup & Configure Free VPN (Virtual Private Network) With Team Viewer VPN Client Software
Above figure shows that I’m exploring Remote PC just like in Local Network.

HOW TO EDIT YOUR BLOGGER WEBSITE IN HTML




HOW EDIT YOU BLOGGER WEBSITE
The Blooger web interface uses an xml file, for a newbie to blogger, to edit your website in html follow this simple steps, navigate to your blogger control panel, click on TEMPLATES


 

FIRST OF ALL, backup your current configuration, incase you mess up with your xml file, or tweak you blog beyond recognition, After backing up, then click on the edit html page (form image 1)





In this page you have the capability to edit the html code of your blog, if you are familiar with html or xml scripting, this will be no problem, but if you are not; please practice with caution.

Thursday, February 27, 2014

UNLOCK YOUR ANDROID DEVICE WITHOUT USB DEBUG ON, OR A GOOGLE ACCOUNT AND STILL RETAIN YOUR FILES, USING EMERGENCY CALLS OR SIM SWAP

WELCOME BACK PEOPLE, HAVEN'T BEEN BLOGGING FOR A WHILE 
In this tutorial, we are going to find out how to unlock android devices that have been locked out
1. I will illustrate the simple method that can be used by just anybody, thanks to some guys at the xda forum
2. illustrate the more techy method, where you enter command line and input some little adb commands, no big deal there, 
3. Methods that include the use of .apk files to gain access to android device
These methods will unlock the all patterns, password, backup pins, hand gestures and facial lock. 

http://downloadcustomrom.com/wp-content/uploads/2013/12/android-unlock-desire-vc.jpg
METHOD 1 : THE SCREEN LOCK BYPASS

Will work on:
All Android devices running Android 2.3.x or below. No matter whether rooted or not.

How to Use:
  • Extract the gingerbread_lock_bypass file anywhere on your PC.
  • Install drivers for your phone using pdanet.
  • Connect your device to the pc using USB cable.
  • Go to the extracted folder.
  • Run the Double_Click_Me.bat file and enter 1 to continue in the command window.
  • Try unlocking your device now. The screen lock will be bypassed.
METHOD 2
This will work on all android devices 4.0
How to Use:
  • Extract Password Reset tool by Droidiser (you really have to give it up to this guy) file anywhere on your PC.
  • Install drivers for your phone, you can search online using your phone model
  • Connect your device to the pc using USB cable.
  • Go to the extracted folder.
  • Run the Double_Click_Me.bat file and enter 1 to continue in the command window.
  • Try unlocking your device now. Any password/pin/gesture that had been currently stopping you from having access to your device have been cleared.

 YOUR FAIL SAFE METHOD 1
We now have the fantastic web based Android Market, Thomas cannon wrote about a few minor security findings here. One of the common responses I saw to articles talking about the threat of malware distribution was that when remotely installed, an application doesn't automatically run and the user would have to manually launch the malware. This is not actually correct, and to demonstrate I decided to create a legitimate utility which can be deployed to a locked phone, executed remotely, and set to disable the lock screen. This will yield access to a locked device so that the user may go in and backup their data.

HOW IT WORKS

Quite simple really. Android sends out a number of broadcast messages which an application can receive, such as SMS received or WiFi disconnected. An application has to register its receiver to receive broadcast messages and this can be done at run time, or for some messages, at install time. When a relevant message comes in it is sent to the application and if the application is not running it will be started automatically.
After testing out various broadcast messages the best one I found for the purpose of this utility was android.intent.action.PACKAGE_ADDED. This exists in all APIs since version 1 and is triggered when an application is installed. So to get the application to execute remotely, we first deploy it from the Android Market, then deploy any other application which will cause the first one to launch.
Once launched it is just a matter of calling the disableKeyguard() method in KeyguardManager
There is a legitimate APP on Play store to disable the screen lock when, say, an incoming phone call is detected, or when the dial an emergency number. After finishing the call the app ought to enable the screen lock again, but we just keep it disabled. Get the Screen Lock Bypass application https://play.google.com/store/apps/details?id=net.thomascannon.screenlockbypass.pro

Recently I saw this article on lifehacker. The article says that installing Screen Lock Bypass app from the web version of the Android Market (now called Play Store) followed by installing any other application from the play store itself will bypass the lock screen for you. As of now, the free version of this app has been removed from the Play Store at least I couldn't find it. I searched the internet for the apk of the free version of that file (you know, we hate piracy as much as the developers do ) and using the adb interface to install the Screen Lock Bypass app followed by another lightweight app (Marine compass in this case, chosen because it's just 14 kilobytes). That's it. This bypasses the screen lock everytime you press the unlock button on your device. To know how that app works, see this.

METHOD 2
Now if your android device is a dual sim mobile device, you might be lucky enough to be able to bypass the screen lock without any software, all you have to do is to remove one sim and input another, then restart the phone, have ADB driver already installed in your PC for the device and wait. once the phone startup, it will show a menu to configure the sim, for this test i used an LG optimusL7.    Immediately the option menu comes up, connect your device to pc and a window requesting for USB connectivity option will pop, since this is the settings menu, click back and you will be the settings tab. you wont be able to change any passwords in this mode, but you can 

*Add a new google account
*Set USB debug mode to unlock your phone through ADB
*Use File explorer as root to delete the gesture.key file or account.db

FAILSAFE METHOD 3: USE ADB COMMAND LINE

Will work on:
All Android devices that are rooted, and has USB debug mode on. But adb must be given root access. If you get permission denied error, then boot into recovery, and then try running this tool.

Follow these steps carefully

adb shell
cd /data/data/com.android.providers.settings/databases
sqlite3 settings.db
update system set value=0 where name='lock_pattern_autolock';
update secure set value=0 where name='lock_pattern_autolock'; (for most phone)
update system set value=0 where name='lockscreen.lockedoutpermanently';
update secure set value=0 where name='lockscreen.lockedoutpermanently';
.quit
exit
adb reboot (to reboot the device)

IF ABOVE DOESN'T WORK FOR YOUR DEVICE USE THESE

adb shell
adb shell rm /data/system/gesture.key
update system set value=0 where name='lock_pattern_autolock';
update secure set value=0 where name='lock_pattern_autolock'; (for most phone)
update system set value=0 where name='lockscreen.lockedoutpermanently';
update secure set value=0 where name='lockscreen.lockedoutpermanently';
.quit
exit
adb reboot 


YOUR FAILSAFE METHOD 4 

If none of the above things worked for you, then sadly only the official method can help you out. You have to factory reset device. This can be done by booting in to your recovery and selecting the Wipe Data/Factory Reset option. To know how you can boot into your recovery, search on google.




 

Copyright @ 2013 TECMIE iCENTER.

.