Kalinga province website defaced urging netizens to join Million Mask March

Early this morning  kalinga province website defaced by manila pride urging netizens to join Million Mask March On November 5, 2013


kalingaprovince.com/index.htm

Can you Join Million Mask March?



Critical vulnerability in Twitter allows attacker to upload Unrestricted Files




Unrestricted File upload vulnerability. Such flaws allow an attacker to upload and execute arbitrary code on the target system
which could result in execution of arbitrary HTML and script code or system compromise.
According to Ebrahim, when a developer creates a new application for Twitter i.e. dev.twitter.com - they have an option to
upload an image for that application.
While uploading the image, the Twitter server will check for the uploaded files to accept certain image extensions only, like
PNG, JPG and other extensions won’t get uploaded.
But in a Video Proof of Concept he demonstrated that, a vulnerability allowed him to bypass this security validation and an
attacker can successfully upload .htaccess and .PHP files to twimg.com server.
Twimg.com is working as a CDN (content delivery network) which mean that every time attacker will upload a file, it will be
hosted on a different server or subdomain of twimg.com.
In CDN's usually scripting engines are not allowed to run. So, in normal scenarios a successful Exploitation of uploading
htaccess & PHP files to a server that supports the PHP i.e. Remote Code Execution on that server.
But in the case of Twitter:
Vulnerability could be used to make twimg.com as a Botnet Command server by hosting a text file with commands,
so infected machines would connect to that file to take its commands. Since twimg.com is a trusted domain by
users so it won’t grab the attention.
For hosting of malicious files.
At least it could be used to upload a text page with a defacement content and then add the infected sub-domains
of twimg.com as a mirror to Zone-h.org which would affect the reputation of Twitter.
Twitter recognized the criticality of the Unrestricted File Upload Vulnerability and added Hegazy
name to their Hall of Fame . I
personally reached Ebrahim Hegazy that revealed me that he has also found an Open redirection Vulnerability in Twitter on
15th Sept. that has also been fixed.
I conclude with a personal consideration, it's shame Twitter hasn't a bounty program, in my opinion is fundamental to
incentive hackers to ethical disclosure of the bug. An attack against a social media could have serious repercussion on the
users and on the reputation of the platform, if hackers sell the knowledge of the flaw on the black market a growing number of
cyber criminals could benefit from it.
Source : THN

Gloria.gov.ph defaced

Hackers from Magdalo Cyber Army defaces the official website of Gloria municipality ( www.gloria.gov.ph ) for the second time since last month.





Telling netizens to help the earthquake victims in bohol.


MCA added Clifford trigo's info for those who want's to help.

Techzone-ph defaced!

Techzone-ph at new community forum was hacked by "zyber" from strawhat pirates crew. (Techzone-ph.com)


Base on the defaced page zyber want's to tell the administrator to secure their website.



Bacoor Website Hacked!

Bacoor website was hacked and defaced by "invectus" of "madleets"


As shown on this picture the login page of bacoor was defaced by invectus.





We were trying to contact invectus for his statement.


Purefoods & Magnolia Ice Cream Website Defaced

Purefoods.ph and magnoliaicecream.com.ph website hacked and defaced by "invictus" of "Phantom Hackers.PH"


According to invictus He Defaced it for "Security Purpose"

Here's a screenshot of the defaced website



Garena Portal Defaced

"Garena portal was hacked and defaced yesterday by unknown hacker (portal.garena.ph)"


Here's the screenshot of the defaced site yesterday




Now Garena portal website was working properly.

Indian Server Rooted and Mass Defaced

Indian server got rooted and mass defaced by "The Hackers Army" THA




" # b 0 x 3 d by THA RuDe &
THA X
# I was trying my Skills on your Server ,and it g 0 t b0 x 3 d up like a Cheap Bitch : P
# Where is the Security ` Bitch?
# Safe_Mode = OFF
# We are Back with destruction Hell
Yeah .
# TO give a single message to the citizens of the world
# Go back to 1947 ,The begining of indian Oppression , That led to destruction and illegal occupation of KASHMIR.
# Lies have been covered up ,Truth echoes SAMEER , a martyr at age 9 ,They killed him by kicking his jawline ,Forced a bamboo right down his throat ,And his soul went afloat .
# NEELOFAR and ASIYA, my sisters
drowned to death , Molestated and raped till their last breath.
# Ask a MOTHER how her son died, a SISTER how she cried, A FATHER left torn up inside .
# We are with you Brothers ,A brother who fought for right ,A brother who threw stones with all his might , A brother smothered and slayed ,A brother who had
faith in freedom all the way .
# We say enough! to the brutality beingcommitted to the innocent civilians in KASHMIR by Political Administration for power .
# We are TheHackersArmy "
The hackers Army has a message to all the netizens of the world
List Of Mass Defaced Websites!
http://simplifiedsuccess.com/
http://www.abhomepackersmovers.com/
http://ahmedabadpackersandmovers.com/
http://www.aplindiapackers.com/
http://bangaloremovers.com/Rhiza.php
http://clolawoffices.com/Rhiza.php
http://corewebtech.com/Rhiza.php
http://fcipackersandmovers.com/
http://gblmanagementconsultants.com/
http://www.hyderabadpackersmovers.com/
http://jacair.com/
http://jnanapravaha.org/
http://kolkatapackersmovers.com/
http://localpackersmovers.com/
http://masararesort.com/
http://masseducationbed.org/
http://meptti.org/
http://mithilasanskritikparishad.com/
http://moversandpackersjaipur.com/
http://www.moverspackersquotes.com/
http://ominfotechindia.com/
http://www.packersandmoverchennai.com/
http://packersandmoversdelhincr.com/
http://www.packersandmoversin.net/
http://packersandmoversinbangalore.in/
http://www.packersandmoversinnoida.in/
http://www.packersandmoverslucknow.in/
http://packersmoversbhubaneswar.in/
http://packersmoversguwahati.com/
http://packersmoversinbhopal.com/
http://packersmoversingoa.com/
http://www.packersmoversjamsedpur.com/
http://packersmoversmumbai.net/
http://www.packersmoversquotes.com/
http://packersmoversreview.com/
http://punepackers.com/
http://servicesutra.com/
http://spakhoj.com/
http://swastikprojectionscreen.com/
http:/swastiktelonprojectionscreen.com/
http://www.nccsdindia.org/
http://surendranagar.biz/
http://www.vankar.in/
http://www.ravibhan.in/
http://www.vedhasnaturecare.in/
http://dudhrejvadwala.com/
http://omcomputersnr.com/
http://ngoassociation.in/index.php
http://mehndiorder.com/index.php
http://hiramohanvidhyalaya.org/
http://gujaratmap.in/
http://androidapkdownload.in/index.php
----------------------------------------------
---
Mirrors on hold:-
[#] http://www.add-attack.com/attacker/0/TheHackersArmy

Skinwhite Philippines Hacked and Defaced

Skinwhite website was hacked and defaced by "Falcon"  urging netizens to help the victims in Visayas earthquake, particularly in Bohol that cost more than a hundred lives and most of victims were left hungered .

“Unknown to the public – some areas on bohol are not reached by the RELIEF OPERATIONS,conducted by the GOVERNMENT. I, FALCON, am extending my hands to help in a manner that I know how; and I have come into a decision – to extend my help, by extending the willingness to help and giving others the ability to help. ” reads a message in the hacked page.
Aside from the hacker’s message, we can also observe the ‘anonymous’ Philippines hacker collective logo on the bottom part of the hacked page.

The page also appears, it has the same set up with the defaced pages by anonymous Philippines few weeks ago.
We can assume, Falcon which is new to us is a supporter of the hacker collective.




Until Now skinwhite's website is still defaced!


Install linux from USB

First Download Universal USB Installer









Then set the boot order to ur usb.

HMR.PH Admin accounts Leaked

A pinoy web hacker with handle “w4k4.DoTz” from
Phantom Hacker.PH claims leakage of user credentials, allegedly taken from hmr philippines  website
( www.hmr.ph)

As what we can see on the leak, portrayed screen grab, it is composed of  usernames and passwords



As of now I'm trying to contact waka dotz for his statement about this leakage.
Stay tuned!
According to Waka dotz , Its just only the beginning , More attacks will come on november 5!

This is the link of leaked accounts
 Click Here

12-year-old plead guilty of hacking gov sites, traded info to anonymous for video games

In Montreal, Canada, a 12-year-old boy
pleads guilty to hacking government and
police websites that occurred last year
according to Toronto Sun.
The damage made by the Grade 5
student whose named was not revealed
has been estimated to reach $60,000.
Hacked websites are those of Montreal
police, the Quebec Institute of Public
Health, Chilean government and some
non-public websites.
He attacked the mentioned websites by
Distributed Denial of Service, exploiting
to successful defacement and leakage of
confidential information from its servers.
The hacking is not politically motivated,
as according to further report by Toronto
Sun, the young hacker exchanged
information to ‘anonymous’ hacker
collective in return for video games.
He was nine years old when
first fascinated about computers.

User details from DENR website leaked



A pinoy web hacker with handle “Schema” from Strawhat Pirates crew claims leakage of user credentials, allegedly taken from Department of Environment and Natural Resources website ( www.denr.gov.ph).



As what we can see on the leak, portrayed screen grab, it is composed of email addresses, passwords, usernames, first and last names.



Is Schema Ready for the Million Mask March ?


According to "Schema" He Just Want To Tell The Netizens that he is ready for nov 5th.

40-YEAR-OLD man was hacked by his father-in-law



A 40-YEAR-OLD man was hacked by his father-in-law after they argued in a drinking session in barangay Dakit, Bogo City, northern Cebu.

Bobby Suico Verallo was wounded in the right forearm after he was hacked by Ernesto Piape, 62, Thursday night.

Police said the two men were drinking when they suddenly argued.

Police said Verallo was about to attack Piape when he was hacked.

Verallo was treated at the Cebu Provincial Hospital in Bogo.

Piape was arrested after the incident but was released yesterday after he and Verallo settled the case amicably.

AT LEAST four motorcycle accidents injuring five persons took place yesterday noon along Osmeña Boulevard in downtown Cebu City when crude oil was accidentally spilled.

The latest victims were a couple after their motorcycle crashed near the corner of V. Urgello Street, said Ilustrisimo Alberto Jr, traffic enforcer of Cebu City Traffic Operations Management (Citom).

Alberto said a fire truck went to the area to spray water and wash out the crude oil.

Alberto said it could be possible that the spill may have come from a tanker which passed by the area.

Citom head Rafael Yap said that Osmeña Boulevard is designated only for light vehicles. He said drivers of big vehicles caught using the road will be arrested.

Traces of crude oil were found in the middle lane of Osmeña Boulevard fronting the Community Hospital.

ISOHUNT Website Got Shutdown

IsoHunt, a popular website offering BitTorrents and P2P of mostly pirated material, is to shut down following acourt settlement.

The site's owner, Canadian Gary Fung, has agreed to pay $110m (£68m) to the Motion Picture Association of America (MPAA).
MPAA chairman Chris Dodd said the move was a "major step forward" for legitimate commerce online.
In a blog post, Mr Fung said: "It's sad to see my baby go."
The site is currently still online, but will soon be shut. It is one of the most popular sites of its kind on the internet.

Despite efforts to minimize piracy, vast numbers still illegally downloaded TV series The Walking Dead


                     

Initiating Self Destruct

This is it. We are shutting down isoHunt services a little early. I'm told there was this Internet archival team that wants to make historical copy of our .torrent files, I'm honoured that people think our site is worthy of historical preservation. But the truth is about 95% of those .torrent files can be found off Google regardless and mostly have been indexed from other BitTorrent sites in the first place. So I might as well do a proper send-off to you dear isoHunt users, before final shutdown sequence on Tuesday. It's been an adventure in the last 10.5 years working on isoHunt, a privilege working with some of the smartest guys I've worked with, and my life won't be the same without this journey. For what I'm working on next, please look up my blog on Google and follow me there. Because as the Terminator would say with a German accent,

I'll be back.

- Gary Fung




Hacker Stole $100,000 from Users of California ISP Using SQL Injection





In 2013 we have seen a dramatic increase in the number of hack attacks attempted against banks, credit unions and utility companies using various techniques including DDoS attack, SQL injection, DNS Hijacking and Zero-Day Flaws.


SQL Injection is one of the most common security vulnerabilities on the web and is successful only when the web application is not sufficiently secured.

Recently a hacking Group named 'TeamBerserk' claimed on Twitter that, they have stolen $100,000 by leveraging user names and passwords taken from a California ISP Sebastian (Sebastiancorp.com)to access victims' bank accounts.


A video proof was uploaded on the Internet, shows that how hackers used a SQL injection attack against the California ISP Sebastian to access their customers' database includes e-mail addresses, user names and clear text passwords and then using the same data to steal money from those customers.


Let's see what SQL Injection is and how serious an attack like this actually can be.


SQL Injection is a type of web application vulnerability in which the attacker adds Structured Query Language (SQL) code to web inputs to gain access to an organization's resources. Using this technique, hackers can determine the structure and location of key databases and can download the database or compromise the database server



Hackers took just 15 minutes to hack into the website using SQLmap (Automated SQL Injection Tool) -- stole customers' database and then immediately accesses the victim's Gmail account, linked PayPal accounts and Bank accounts also.


It's so hard to remember multiple passwords, some people just use the same one over and over. Is your Facebook password the same as your Twitter password? How about the password for your bank's website?


Now the hack explains that this us why it's extremely dangerous to use the same password on more than one Web site. In the POC video, hacker randomly chooses one Sebastian username and his relative password against Paypal, Gmail and even Citibank account logins and seriously that actually worked, because the victim is using the same passwords for all websites.







Now that you've control of the situation, don't let this happen again! If you have a bank account, a few credit cards, and several other important sensitive accounts, conduct a thorough security audit on them. Be sure that you know when you last logged in. Be sure to keep using different and Strong passwords for each website.

source:THN


Blogger's Republiq Facebook Page Has Arrived


Blogger's Republiq Official Facebook Page Was Created By The Owner at around 6:00 PM GMT (+8:00)
You can Now Check Our Blog Updates On Our Official Facebook Page.

Blogger's Republiq Page Link : Bloggersrepubliq.blogspot.com

Microsoft rewarded $100,000 to an Australian white hat hacker

A hacker from Australia, James Forshaw, reported a serious flaw in Microsoft’s windows. It was accordingly eligible to the company’s bug bounty program "Mitigation Bypass"

Because his entry of the bug bounty program was qualified, the head of vulnerability research at Melbourne , Will have the first ever $100,000 reward.


The serious flaw he found was a new “exploitation technique” in Windows which will allow it to develop defences against an entire class of attacks.


Friday last week, the same hacker was also rewarded for a separate bounty, $9,400. So, his total amount of compensation is now $109,400.






Microsoft said in a statement, the company is thrilled of the qualification of that “mitigation bypass” as it help them improve its security.


“We’re thrilled to receive this qualifying Mitigation Bypass Bounty submission within the first three months of our bounty offering,” Katie Moussouris, senior security strategist lead of Microsoft Trustworthy Computing, said in a statement.


“James’ entry will help us improve our platform-wide defenses and ultimately improve security for customers, as it allows us to identify and protect against an entire class of issues.”


Source : TheNextWeb.

Garena Philipppines website hacked and defaced

A Sub domain of Garena Philippines Website (esports.garena.ph) was hacked and defaced by shadowfiend haxor early morning today.
The hacker wrote "You Got Owned" on the wordpress powered page where it was calculated to be up for 4 hours.
Approximately 10:45 am today (+8:00) the website is already fixed by the web administrator but images are not displaying and links are showing "Page not found" messages.





A mirror of the defacement can be found on Zone-H as shown in quick google search " esports.garena.ph hacked"

After 8 Hours, images of the website are already displaying properly but it appear 'permalinks' are still not.


Source:PinoyHackNews

Fresh Paint For Windows 8.1

Today we are announcing new versions of Fresh Paint for Windows 8.1 and Windows Phone.
You will find the new Fresh Paint in the Windows Store on October 18.
Microsoft Announce the New Fresh Paint more realistic painting and drawing experience possible.

The new Fresh Paint will launch in tandem with Windows 8.1 on October 18 and that we’ll also have new features coming to the Windows Phone version on October 14. Best of all, Fresh Paint will continue to be free, and everyone who updates to Windows 8.1 will get the improved experience

Included in the new Fresh Paint are all the features we announced in the preview like watercolor, a new graphite pencil set, and a new clean, modern user interface. We are also adding the ability to make high quality canvas prints, new ways to work with photos, improvements to stylus pressure, more realistic rendering for watercolor, in addition to a large refresh for Fresh Paint on Windows Phone.


                                             Introducing CanvasPop!


One thing we’ve heard from people over and over is the desire to make high-quality canvas prints of their paintings and sketches. We’re thrilled to share that we’ve partnered with CanvasPop to make this possible. CanvasPop provides high-quality canvas prints using the best materials and craftsmanship, from archival grade canvas to hand-stretching by skilled workers.

Fresh Paint is the first painting app to integrate CanvasPop’s new printing API. We believe in pushing the boundaries of what is possible with art in the digital age. We’re bringing that to life by helping you turn your digital paintings and drawings into amazing physical pieces that you can hang in your living room or give as gifts. This new functionality is a direct result of user feedback. And, we’re making it easy.

After putting the finishing touches on your painting in Fresh Paint, just swipe up from the bottom of your canvas and tap print. You’ll get a customized page where you can select your size and framing options, and we’ll take care of everything from there including handing off a special, high quality version of your painting. CanvasPop then prints your piece, hand frames it, and ships it to you.




Our team and the folks at CanvasPop worked hard to make this experience seamless and simple. One of the challenges we tackled was how to make it possible to print large, high-quality prints from small devices. With many graphics programs the user needs to choose the file size before beginning. We felt that would interrupt the user experience, make the product more complex, and knew it would be challenging for small devices to handle very large files.

Instead, we developed a way to scale the paintings after they were completed. We do this by analyzing the painting pixel by pixel using bilinear filtering, and then smoothing out pixels as it scales. It is the equivalent of zooming in very close to the painting, taking a ton of pictures of it, and then stitching all of them together to make a giant rendering of the painting. This allows us to render very large prints even from small devices in a way that keeps the user experience simple, magical, and fun.

I’m also pleased to share that we are making some special offers available for our fan base. Check out our Facebook and Twitter feeds for special offers the week of Oct 18, or visit canvaspop.com/freshpaintoffer.

New Features On Fresh Paint For Windows 8.1


We’ve also been hard at work on a number of new features and improvements to Fresh Paint for Windows 8.1.

First, we know that sometimes it can be tough to know where to get started, or maybe you just need a little inspiration. That’s where the new Inspire Me feature comes in. Just click on the Inspire Me tile in your gallery home page, and you’ll find inspirational images you can then import, apply a filter to, and paint. Because this image search is powered by Bing you can even type in your own query to find amazing, inspirational pieces. And, of course, we’ve tuned the search to be safe for everyone in the family.




We’ve improved our image filters too. The Oil Daub has been improved to highlight unique oil textures, and we’ve added a filter that turns your photo into a watercolor wash. Just add water and watch the painting come to life.

Beyond photos, we’ve been really focused on the details. We’ve improved pen and stylus input to better work with pressure and the eraser (pick up a Surface to try out a great stylus experience). We’ve added the ability to save custom palettes, so if you have a favorite set of colors you can keep them handy. And, we’ve made dozens of other little changes throughout the product–such as adding the ability to import a painting directly from SkyDrive.

New Features for Windows Phone Too
We love Windows Phone and are making some significant updates that will be available early next week. You’ll now have the option to draw with pencil in the Windows Phone version of the app. We know many of you love sketching, and the addition of the pencil will allow you to draw from anywhere. This is the same, highly realistic graphite pencil we use in Fresh Paint for Windows 8.1.






Pencil sketch created on a Surface Pro by artist Jenny Vorwaller.

You’ll also see new photo filters and an updated user interface that makes the Fresh Paint experience more consistent whether you are on a PC or phone.

We’re also really excited about the possibilities with SkyDrive. Now you can start a painting or capture a moment on your phone, save it to SkyDrive, and finish it on your PC by simply selecting the “Save To” icon in Fresh Paint for Windows Phone and importing it into your Fresh Paint gallery on your PC.


Painted in Fresh Paint on a Windows Phone.

Across Windows 8.1 and Windows Phone

You will find the new Fresh Paint in the Windows Store on October 18.

If you have Windows 8, you’ll automatically be updated to the new Fresh Paint when you upgrade to Windows 8.1. Your paintings will all be preserved, and you’ll get all the new features I mentioned above. Windows Phone users can get all the improvements in Fresh Paint beginning October 14—just look for the app update.

We’ve been on a mission to make the most realistic, simple, and fun painting and drawing app out there. Thanks again for all of your feedback. It has been invaluable. Be sure and follow our Facebook and Twitter feeds to learn more and to find special offers I mentioned.

We can’t wait to see what you create next!

Credits to the one who post this article