Feedback Blowout #1 | TechSNAP 60

Feedback Blowout #1 | TechSNAP 60

Software that’s supposed to get you around censorship, could be logging your activities online, plus we’ve got a classic Social Engineering story for you.

And then we clear the decks and answer a ton of your questions, in our feedback blowout!

All that and so much more, in this week’s episode of, TechSNAP.

Thanks to:

Use our codes TechSNAP10 to save 10% at checkout, or TechSNAP20 to save 20% on hosting!

Limited time offer:

$1.99/mo economy hosting for 3 months – special offer!
Code:  199tech
Expires:  June 30, 2012

Direct Download:

HD Video | Mobile Video | MP3 Audio | Ogg Audio | YouTube | Torrent File

RSS Feeds:

HD Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feeds | Torrent Feed

 

Support the Show:

Show Notes:

Anti censorship application circulating with backdoor keylogger

  • The anti-censorship application Simurgh, used heavily in Iran and Syria to get around government internet censorship, has been spotted on P2P networks and download sites
  • The official version of the application from the official site is legitimate, however the version being propagated via P2P networks has been modified to log keystrokes and send the data back to a server in the USA on an IP block registered in Saudi Arabia
  • The infected version injects javascript into pages, and removes the windows navigation sounds to prevent the user noticing the automated activity
  • Anyone who has run a compromised version should consider all of their online accounts (email, IM, social networks, banking) compromised

WHMCS databases compromised via Social Engineering

  • WHMCS (Web Hosting Management Complete Solution) is a commonly used billing, help desk and client management system for web hosting companies
  • The attackers called the hosting company where WHMCS has their servers, managed to successfully answer the security questions and have the administrative passwords etc send to them
  • The attackers made off with 1.7GB of data including the usernames, email addresses, hashed passwords, and encrypted credit card details
  • The hashed passwords as not immediately vulnerable, however they can still be brute forced with time (especially if they are plain MD5 rather than salted MD5)
  • It is highly recommended that you change all of your passwords if you were a WHMCS customer
  • The attackers claim they targetted WHMCS because they refused to stop doing business with cyber criminals, specifically, script kiddies selling exploits, malware and running scams while using WHMCS to process the payments
  • Additional Coverage
  • Official Response
  • It seems the group that comprised the data, has since analyzed the source code for WHMCS and found a number of vulnerabilities
  • PHP Register Globals
  • SQL Injection

Cambridge Researchers find backdoor in US Military chips


Feedback:

KatsumeBlisk wrote:

The Blizzard thing is why I use their 2-factor authentication. There’s no reason not to when there’s an app for the major mobile OSes and the $6.50 physical one.

Wayne Merricks asks: How can I replace DFS

Justin Bates asks: Backing up Between two Windows Hosts

Chris Urie asks: How to Setup SSH Keys

Jono asks: Safely Storing Local Passwords

A few of you asked: WHY U NO MIRO?


Round-Up:

No tips yet.
Be the first to tip!

Like this episode? Tip with bitcoin!

1JDkJ8N3Wk9GEkiWg81tZcvdS68KkY3GsK

If you enjoyed this episode, found value or information from it, please consider contributing using Bitcoin. Each episode gets its own unique Bitcoin address so by tipping you're not only making our continued efforts possible but telling us what you liked.

  • http://www.facebook.com/people/Billy-Pride/100000085900748 Billy Pride

    Hey guys,

    Really appreciate the show.  Always informed and insightful.  Real information and Allan actually knows his stuff.  Kudos to you chris for a broadcast partner who has information and thought instead of a constant barage of poorly thought through narcissistic opinion masquerading as fact.
    Aussie from Blacktown

  • SyrinxPriest

    RE: the gent with the SSH question, if you need help above and beyond Alan’s great explanation, Hak5 did an exhaustive set of shows on SSH with great visual examples and explanations including creating keys on Windows and Linux. http://hak5.org/category/episodes/season_11

  • Christopher Urie

    Hey Chris and Allan thanks for answering the question. Just a quick note my Name is spelled wrong in the Show Notes, and in the question i meant my Parents have a mint 13 desktop and i have a Mint 13 and a win 7 laptop (which is only for college)

  • Christopher Urie

    Thanks i will check that out.