Wednesday, 26 April 2017

Backdoor In WhatsApp really?


Introduction

A security vulnerability that can be used to allow Facebook and others to intercept and read encrypted messages has been found within its WhatsApp messaging service.

Facebook claims that no one can intercept WhatsApp messages, not even the company and its staff, ensuring privacy for its billion-plus users. But new research shows that the company could in fact read messages due to the way WhatsApp has implemented its end-to-end encryption protocol.

Establishing the Case
Should I be worried about the WhatsApp encryption backdoor?
Privacy campaigners said the vulnerability is a “huge threat to freedom of speech” and warned it could be used by government agencies as a backdoor to snoop on users who believe their messages to be secure.

Recognize the Issue

WhatsApp has made privacy and security a primary selling point, and has become a go to communications tool of activists, dissidents and diplomats.

WhatsApp’s end-to-end encryption relies on the generation of unique security keys, using the acclaimed Signal protocol, developed by Open Whisper Systems, that are traded and verified between users to guarantee communications are secure and cannot be intercepted by a middleman.

However, WhatsApp has the ability to force the generation of new encryption keys for offline users, unbeknown to the sender and recipient of the messages, and to make the sender re-encrypt messages with new keys and send them again for any messages that have not been marked as delivered.

The recipient is not made aware of this change in encryption, while the sender is only notified if they have opted-in to encryption warnings in settings, and only after the messages have been re-sent. This re-encryption and rebroadcasting effectively allows WhatsApp to intercept and read users’ messages.

Addressing the Issue

The security loophole was discovered by Tobias Boelter, a cryptography and security researcher at the University of California, Berkeley. He told the Guardian: “If WhatsApp is asked by a government agency to disclose its messaging records, it can effectively grant access due to the change in keys.”

The vulnerability is not inherent to the Signal protocol. Open Whisper Systems’ messaging app, Signal, the app used and recommended by whistleblower Edward Snowden, does not suffer from the same vulnerability. If a recipient changes the security key while offline, for instance, a sent message will fail to be delivered and the sender will be notified of the change in security keys without automatically resending the message.

WhatsApp’s implementation automatically resends an undelivered message with a new key without warning the user in advance or giving them the ability to prevent it.

Boelter reported the vulnerability to Facebook in April 2016, but was told that Facebook was aware of the issue, that it was “expected behaviour” and wasn’t being actively worked on. The Guardian has verified the loophole still exists.

But Officals at whatsapp has denied of any loop hole in the whatsapp platform and said “Over 1 billion people use WhatsApp today because it is simple, fast, reliable and secure. At WhatsApp, we’ve always believed that people’s conversations should be secure and private. Last year, we gave all our users a better level of security by making every message, photo, video, file and call end-to-end encrypted by default. As we introduce features like end-to-end encryption, we focus on keeping the product simple and take into consideration how it’s used every day around the world.

Stay tune for more inside news from Hackers Underground and information security.

Please suscribe to blog and press the share button if you like it,

see you later.

Tuesday, 21 March 2017

Cheat sheet for Reverse Engineering for Malware Analysis


Download the original size here link  http://www.datafile.com/d/TWpVM01UWTNNekEF9/cheat sheet reverse v6.png


Sharing is Caring :)

Sunday, 5 March 2017

Introduction to vtechcoder point of sale (pos) Software

Introduction to vtechcoder point of sale (pos) Software


Most advance POS Project can be used in more than 170 countries and supports 17 international language. works on Windows,Linux and Mac and other touch enabled POS Hardware for Business Outlets .




here is a rough list of features that i have already in place in pos
Aside from complete Billing system. 
• Touch and Click User Interface.
• Bar Code Scanning
• Cancellation
• Coupons
• Credit Card Processing
• Customer History
• Customizable GUI
• Discounts
• Layaways & Quotes
• Mobile POS Capability
• Multi-System Integration
• Multiple Payment Forms
• Offline Transactions
• Print Reciepts
• Receipt Notes
• Refunds/Returns
• Revenue Totals
• Store Credit
• Tax Exemption
• Time-Limited Specials
• Transaction Hold/Recall
• Report generation.


GST Tax system implementation included for all the GST tax supporting market around the globe. 

Cash Flow Report - Basic list of order totals.
Cash Flow Report Extended - List of order totals with some more
information including customer name, transaction number, tender used.
Category Sales - Sales by category
Closed Cash Report - Shows sum of tenders for each POS by closed cash
period. Small update - Added number of no sales per sequence.
Closed Cash Export - Closed Cash Report in simple excel exportable
format.
Chart Sales - Sales by category.... in chart form!
Closed Products - Shows all items sold during closed cash periods by
register.Customer Diary - will show you customer payment activity for a date
range that you select, and can be filtered by customer. (a value of rupees
will show all customers in that date range)
Customer Report - this will show you a listing of your customers with
information
Products - Listing of Products in list view by category
Product Catalog - Changed the name from Sales Catalog to be clearer
on what this report is. This will create a report showing all items in your
database with item name, category, sell price, total price (sell price + tax)
and the item image if there is one in the database in a tile type view.
Product Sold - List of all items sold ordered by date/time.
Reservations Report - Will list reservations per day
Sales by Customer - Sales by Customer (Will only show sales that do not
have null for customer column)
Sales Taxes - List all sales tax.
Top 10 Sales - List top 10 sales with a handy chart (Gross amount not qty).




For free demo of the project and for Questions and Business Queries email us at vishwa@vtechcoder.com    -
vtechcoder@gmail.com


You can also buy source code for your organisation to modify it according to your needs or we will do that for you with small charge.

if you prefer business using third part here is the link for that 

Tuesday, 24 January 2017

Privacy is a Myth



People say we are not being monitored, well how about this example this product i was checking on my super secure android device, but some how facebook know and shows be add of this on my facebook feed on my workstation,



No i don't have any adware installed,


Reason is facebook app monitors all activities that you do on your devices including internet browser history so it make sense the facebook android app is installed on my phone too.


Generally people don't realise how these big corporates exploiting there privacy,
well sure people will say its convenient to see those ads so you buy stuff that you were looking for but if you look at it its a thought of lazy person, when you realise that privacy is myth,


This is not it websites collect lot more data about there users like

Users Location
IP addresses

Device information

Broweser details
and more

To get more details about users like there like and dislikes they go for your bookmarks and browser history also its a treat for those data hungry monster website when you install there browser plugin then they literally monitor your system until your browser is on.

On more dark side if you are in the target list of any state hired or independent hacker then things can go more worst all the browsers are exploitable if you visit deep web you can find them and buy them too they are called zero days.

Of you are running a older version of browser then things becomes as easy as cake walk for hackers,
they can exploit you system and gain admin access to your operating system in just few commands and then they can do more dangerous things like Ransomware and identity theft they can ruin your life.

Now we have some kid tech lover who consider them self expert and they will say we use adblocker those ad malware can't get to me
well here is a thing kids
there are so many tracking techniques that are not embedded in the websites to track users activity even if you block there ads.
they make there website a living tracking bot some of those techniques requires user permission that they achieve by technique called Clickjacking or Alerts of java scripts.

i will soon write article about how to prevent yourself from such threats but for now here is my goodnight advice
>Stay updated always update your system and application software

>Disable java script on your browsers and flash

>Don't click on random content.
>Only download software or app on devices from trust able resource like Appstore or Playstore.

>Don't use pirated Windows (Use Linux if you can't afford genuine version).

>Uninstall third party app like facebook use fb.com on browser.

i'm not bluffing about fb tracking you checkout this article in WSJ Link
Sharing is caring :)

Thursday, 1 September 2016

Facebook Reaction: a privacy attack for corporate benefit.


Recently Facebook launched many images to be added in there post so that user can express their feelings in different different moods and smile sad happy but no one understand the reason behind it
Welcomes to earning money both Facebook and Google goes in same Direction they both are different words of same reason to use uses data and they sell them in order to more revenue.



     Earlier Belgian police gave  a public warning about the use of Facebook reaction buttons instead of like button check here

what Facebook has done it is limiting the users response to a particular post to 6 reactions,
By limiting the responses to a post to six emotions: which the social networks calls “Like, Love, Haha, Wow, Sad and Angry”,

To use this reaction data for advertising Facebook developed some algorithms that are used to determine the liking and not liking of a user for particular post or product,

Facebook's algorithms are able to measure your reactions more effectively, this means Facebook can now surf personalized advertisements to its user for its benefit,
for example if you press "Like" or "woow" reaction on a pizza joint then its most likely you will see a offer on the product from that brand.

What this arrangement actually does is that it increase the effectiveness of use profile to the Facebook and its partner companies about how there users are behaving towards the content that is showing in there feeds and this helps them a lot than just showing million people about same ads.
because now when you see thing of his preferences in the feed he or she is most likely to show a reaction to it and plan to buy that service or offer in future time.

Corporate benefits more from this as now Facebook has more accurate data about there users then it can sell this data two its partners and show more accurate ads and post to its users.

so although this reaction function is killing privacy with one more dagger but what we can do,
people can't stop using this just because they gonna get more customized content in there feed,

And who knows Facebook may also planning to use the data collected from this reaction algorithms to develop its Artificial Intelligence Program and source point of human knowledge and behavior.
we all know CEO of Facebook is working on A.I. since many ears now.

i think users need to protest against this and ask Facebook to remove this from the functionality which is very impossible to happen in near future.

thanks for reading please subscribe and share.



Sunday, 21 February 2016

Updating and upgrading friends GNU/Linux system without internet

If you ever get stuck in a situation where you have to update / upgrade a system or server but you can not plug it directly to the network then here is easy solution for this problem.
just follow these steps:-
  1. First Insert live-cd/usb of GNU/Linux (in this case ubuntu 14.04) in your system . 
     (warning: Install synaptic package manager before doing all these steps in your target friends computer, otherwise later due to dependency error you won't be able to do it.)
  2. press ctrl+alt+delete for opening the terminal ,and run

    sudo apt-get update

    sudo apt-get install synaptic
  3. Open /var/cache/apt/archives and save the contents in safe directory (for example on Desktop, use sudo for it -sometime you need to be little wild superuser for even copying task :)
  4. Update your system(live cd/usb) using update manger
  5. Install some softwares if you wish :-),

    Ie ,if you want ubuntu-restricted-extras Install ubuntu-restricted-extras ,

    run sudo apt-get install ubuntu-restricted-extras in terminal
  6. Install aptoncdInstall aptoncd 


  7. Launch aptoncd and press create button, It will create an iso file
    from here either you can create iso file which you can transfer to friends computer via usb stick or you can burn them to a dvd / cd disk.
  8. Goto your friends home/office with Generated iso and directory made for step3
  9. Copy the directory and iso file to the desktop , Open the terminal and move to that directory

    cd /path/to/directory
  10. Run sudo dpkg -i *.deb ,It will install synaptic
     
  11. Open the synaptic and clickEdit->add cdrom It will display a dialog box , Don't click on it.
  12. Return to terminal and run

    sudo mkdir /media/cdrom

    sudo mount -o loop /path/to/iso /media/cdrom
  13. Now press ok button on the dialog generated from synaptic in step11 , 
  14. Press Mark all upgrades , Apply buttons ,respectively 

  15. Your friends GNU/Linux system is updated , Now sit back and relax for few minutes.


Monday, 11 January 2016

FBI crack Tor and catch 1,500 subscribers of child pornography website on the dark web

   FBI crack Tor and catch 1,500 subscribers of child pornography website on the dark web



Yeah you heard right fbi can hack the tor network, but how we don't know yet, it comes under the

the court order can be seen here link by which fbi conducted this raid.



The fbi hacking tool that can identify IP and MAC addresses of devices.

TOR Network
The Onion Router (Tor) is software that anonymises your internet trafficTor Network
At its peak, Playpen website had around 215,000 members. It had more than 117,000 posts and it received an average of 11,000 unique visitors a week. The FBI discovered many posts featuring extreme child abuse imagery, as well as providing advice on how potential child sex abusers could avoid detection online.
After seizing the computer server running Playpen from a web host in Lenoir, North Carolina, in February 2015, the FBI decided to run the child pornography web site from its own servers in Newington, Virginia, for an additional two weeks between 20 February and 4 March of that year.
When visitors accessed the website, the FBI deployed a network investigative technique (NIT) – a hacking tool – and used a single warrant to uncover 1,300 IP addresses, tracing these addresses back to actual individuals.
The FBI has used NITs before, but this is the first time that it has been reported that the NIT was able to get around the protections of Tor. When visitors accessed the website, although their traffic might have been encrypted, a Flash application was secretly installed on the user's computer that quietly sent important data about the user straight to the FBI so that it did not pass through the Tor network at all, according to Motherboard Vice.
The NIT was able to capture the actual IP address of the computer, the type of operating system the user's computer was using, the computer's architecture, the computer's MAC address, the computer's host name, the computer's active operating system username and was even able to issue a unique identifier to the user in order to distinguish all data collected from another user's IP address.
Even though the method has undoubtedly helped to bring down child pornographers, the American Civil Liberties Union is concerned that the FBI was able to hack into over 1,000 computers with just a single warrant, and believes that Congress and the public should play a role in evaluating whether law enforcement should be allowed to use NITs at all.
Over 1,500 cases have resulted from the investigation

Two men were indicted in New York in July 2015 on child pornography charges, the first of many who were arrested throughout 2015. Many of the arrested will see their cases heard throughout the first half of 2016, and the court documents showed that charges were filed against defendants in Connecticut, Massachusetts, Illinois, New York, New Jersey, Florida, Utah and Wisconsin.
"Fifteen-hundred or so of these cases are going to end up getting filed out of the same, underlying investigation," Colin Fieman, a federal public defender for the Western District of Washington who is handling several of the related cases, told Motherboard Vice.
"There will probably be an escalating stream of these [cases] in the next six months or so," he added. "There is going to be a lot in the pipeline."
I am not saying fbi should not stop any child pornography scam or site, but what my point is if they passes capability to de anonymize tor user then we loose the main concept of using tor at the first place, we use this tool for complete anonymity not just to reduce our internet speed by intentionally bouncing traffic to different tor circuit just to reduce internet speed.

Alert:-
to continue being anonymous online i advise you use tor over a trusted vpn

Let me know you comments upon it and please share it.


Saturday, 17 October 2015

Internet Company Continue to Oppose Cybersecurity Bill

 Government can ask for any personal info about any INTERNET user from INTERNET company in exchange of the breath for that respective company.


Here is another attack on netizens privacy world wide, this can be most dangerous attack on privacy of internet users after the Patriot Act.

The largest tech giants, including T-Mobile, Google, eBay, RedHat, Yahoo and Facebook have once again expressed their concern about a controversial cybersecurity bill, claiming that it fails to protect users’ privacy.

6100.th.jpg

The Computer and Communications Industry Association (CCIA), representing a number of major tech firms, published an open letter criticizing the Cybersecurity Information Sharing Act, also known as CISA. The latter would allow companies to share users’ personal details with the American government in exchange for immunity from regulators and the Freedom of Information Act. The bill is to pass through Senate later in October.

The tech firms point out that the mechanism for sharing of cyber threat information as described in the bill fails to sufficiently protect users’ privacy or limit the permissible uses of data shared with the authorities. Another cause for concern is that CISA authorizes entities to employ network defense measures that might cause collateral harm to innocent 3rd parties.

The legislation was initially meant to allow tech firms to share “anonymized” user data with the Department of Homeland Security, but the latter has itself come out against the bill, because in this case it would be compelled to share the data on to other entities. The cybersecurity bill has raised concerns about surveillance among many industry experts that simply gathering multiple corporate information sets in one place could be exploited to create profiles with personally identifying information.

The mater is that elaborate user data is organized – mostly by advertisers – in such a way that users are split up into several categories. For example, you may end up in a group scheduled to show adverts for cat lovers, a group likely to change shampoo brands, and a group of Toyota owners. At the same time, the companies are trying to make sure they don’t accidentally create individual digital dossiers. The problem is that with such legislation in place, one bad actor can reverse the process and gain unprecedented access to personal details.

On the other hand, some companies that would be eligible to participate decided to support the bill – for example, Experian, the data broker that was recently hacked and lost 15m sets of T-Mobile customer data, claimed that it supported legislation that would facilitate greater sharing of cyber threat information.


 Its time for an global awareness program for the people to spread the message that what are the bad effects of the government policy.



source- sam

Sunday, 27 September 2015

Facebook Accused of Spying on Belgian Users

The Belgian privacy commission (BPC) accused Facebook of acting like the NSA by spying on European users. The Belgian data protection body referred to Snowden’s revelations about surreptitious mass surveillance by the spy agency.

Its is official that the agency launched a lawsuit against the social networking site after accusing it of violating Belgian and European privacy law. The BPC accused Facebook of a number of breaches, including the tracking of non-users and logged-out Facebook users for advertising purposes, and is currently threatening the company with fine of €250,000 per day if it doesn’t stop which is equal to -
250000 Euro equals = 279862.50 US Dollar

In respond to this incident, Facebook has repeatedly denied the all claims, explaining that the data and conclusions of the Belgian agency are false. The company is going to demonstrate to the court how its technology protects people from spam, malware, and other attacks. Facebook also insists that its practices are consistent with European law and with the rules of the most popular Belgian online services.

The social network facebook also explained that its European operations and practices are governed by the Irish data protection agency, because its EU headquarters are located in Dublin. In the meantime, the case is being watched by the rest of the countries in the region, where data protection regulators also started to question Facebook’s privacy practices throughly.

Facebook announced immediately that the company has repeatedly offered to help resolve the Belgian agency’s concerns, but the BPC(
Belgian privacy commission) instead took the tech giant to court and seems to be trying to stop Facebook from using security technology because they misunderstand it.

The Belgian commission believes that Facebook is treating users’ private lives “without respect”, while Facebook offers to discuss these issues directly with Belgian Data Protection Authority rather than going through unnecessary litigation.


this is the beginning we don't know that where else such spying and pointed surveillance is being conducted.
Lets wait and watch.


Tuesday, 15 September 2015

What is Surveillance and What it should be!

My main motive for this article is to try to understand that what is surveillance is and what it has become. The surveillance meaning and what it is being actually implied nowadays.


Surveillance is a act of watching over a asset without there permission aiming to fetch the information in form of data. The huge majority of computer surveillance involves the monitoring of data and traffic on the Internet.
You can check the Wikipedia article surveillance for more info.
here is the link




Surveillance is very good fighting against terrorism, Cyber War, cyber terrorism etc etc... but when it comes to the right of spoof free Internet no one else is monitoring your connection then it becomes a human right. I believe every human on planet earth should have equal right of accessing Internet freely without any hesitation that his connection and his access point over the network is being monitored which later on can be aimed to any direction while any investigation done by any Federal Agencies for any other issue.


 Mass surveillance is being done all across the world is devastated it is clear now that most of the Agencies which are working on the ground are not taking user privacy seriously.
When this happened busy people coming out of their own organizations and making the confidential documents public which type thing should be know by all citizens, an act of doing so is called whistle-blowing.

Surveillance policy should be drafted in a way that every Surveillance request must be approved by some kind of jury before implementation.Surveillance without permission is like setting a wild horse free it can hurt somebody.

Example Edward Snowden one of the most famous whistle-blower he uncover the truth about the secret government mass surveillance program called prism.  and several other which were quality user privacy all across the world not only in United States.
Edward Snowden highlighted the key element facts that he disclosed and this segment of Ted Talk.


TED talk of Edward Snowden  here

Director of National Security Agency responded to the Ted Talk of Edward Snowden in this way you can see in this following video

NSA response to the TED talk with Edwards Snowden. here

We need to take back control over the Internet as we speak we cannot let anybody violate our privacy.

Here are things which we can do to fight against this kind of surveillance or Internet monitoring.


1- Every website and web service should implement SSL connection it is kind of Web encryption between the website and the user this connection is secure via public key the SSL is very very hard to break it will take millions of years for a normal computer to decode a message if he tries around 10,000 combinations of keys per second.

2- The second thing we can do we can use of VPN virtual private network for our Internet connection this is a secure tunnel for a secure channel between your computer and the  and the Internet server
This provider encrypted session between server and your system has no one can spoof hijack in between.
checkout torproject.org

3- Keep your operating system up to date for the latest security patch available.


4- Install the advanced antivirus and anti Malware softwares for example-Kaspersky, AVS.
     ( you don't need anti-virus no linux but still might need anti-malware.

5- Do not use torrent website over VPN because that disclose your real IP.

-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Note- All the ideas and information is generally available on web, this article about is collection of my own ideas and views and thought about surveillance. I do not represent any party.
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

Wednesday, 3 June 2015

Removing Ransomware



Over the past time several online ransomware incidents has took the sleep away of many users and security researcher in many organisations and industries.

But finally we have some good amo against this kind of problem that is ransomware removal kit
 
Several Security firm and FBI itself has released some ransomware removal kit that are free to download from there respective website.


 Just imagine a moment when all your important files are locked up by some strange program and asking you to pay to unlock the data that is already your.


                         "You should never pay to the Ransomware
                                because it make such attacks more
                                       stronger for further attacks"



The Ransomware Removal Kit includes abilities of the following ransomware removal tools:

  • CoinVault: CoinVault ransomware removal tools--link 
  • CryptoLocker: CryptoLocker removal tools and Threat Mitigation --link
  • CryptoLockerDecrypt: FireEye Tool to decrypt files encrypted by the CryptoLocker ransomware
  • FBIRansomWare: FBIRansomWare Removal ToolsTeslaCrypt: Tool for removing this variant of CryptoLocker ransomwareTrendMicro_Ransomware_RemovalTool: General ransomware removal   tool from TrendMicro

Here what you need to do in case your system get infected with any kind of ransomware:-
The first response to a ransomware infection consists in the disconnection of the machine from the internal network to prevent the diffusion of the malicious agent. Be sure to create a copy of the disk that could be restored in case of problems with the ransomware removal kit.

The second step is the identification of the strain of malware that caused the infection( it can be any file/program/even a fake anti-virus program), then the user can try to decrypt files and remove the malicious agent.

How to prevent yourself from such attacks
>Do not download any file from untrusted source.
>Do not download email attachment from strangers.
>Do not use thumb drive without scanning from up to date virus definition anti-virus security product(my recommendation is Kashpersky)

this article is inspired from research of famous security researcher of UK Pierluigi Paganini
thank you for your contribution.

Proper way to install nvidia 390 fix error

Proper way to install nvidia 390 if you see any error in the process look below; command  sudo apt purge --autoremove '*nvidia*...