Wednesday, February 27, 2013


Further 5GB+ Release from Bank of America by Anonymous...



Anonymous today have released further data from the Bank of America which comes in the form of a major update to the main data leak of 400+ emails and a huge list of people they are watching with a partnership with TEKsystems.
The most recent release was announced by @AnonymousIRC not to long ago and contains well over 5GB of source codes, research data and other related information.




The source codes that have been leaked appear to be apart of the custom warning and monitoring system that TEKsystems has created for bank of America. The files are on Potentially Alarming Research: Anonymous Intelligence Agency and they have created a PDF press release for the updated files. Your browser should support iFrame to view this PDF document
  1. BofA data archive (100mb, tgz) ·
    1. ( first released data, )
  2. Executive Data (500mb, zip) ·
    1. And as a very special bonus we present you with 4.8 Gigabyte data containing detailed information about top executives around the world, including detailed career, salary, bonuses. As an example check out the entry for Google’s Eric Schmidt.
  3. Bofa Source Code (115mb, zip) folder named LiorFolder
    1. “Additionally we received what appears to be a specific trimmed down version for Bank of America’s purposes. These were in a folder called “Lior” which is probably referring to Lior Weintraub, Team Leader at ClearForest. This folder contains Bank of America specific source code as well as datasets ready to use: Check out this directory containing several thousand tweets from Anonymous accounts or tweets related to Anonymous. LiorFolder.zip contains all subdirectories and is 116mb compressed.
  4. OneCalais software (5.8GB, zip)
    1. And as a very special bonus we present you with 4.8 Gigabyte data containing detailed information about top executives around the world, including detailed career, salary, bonuses. As an example check out the entry for Google’s Eric Schmidt. (Original in the file Officers_64700.xml).
      As these files were found in a directory called Bloomberg it is reasonable to assume that this data is related to Bloomberg L.P. There are about 90.000 xml files in total but they contain more than one entry so in total there is information on over 200.000 executives and employees of various corporations all aroud the world. Since the data is plaintext (xml) it compresses nicely into a 500mb zip file for convenient download.

From a quick look it appears there is the development copy’s of a research and monitoring tool they have been creating which can be found in the LiorFolder archive.Due to the size of this release it will need some firm going over to see if there is anything further that is worthy of announcing.
Full report to come shortly.

Privacy of Millions of HTC devices at risk..


Privacy of Millions of HTC devices at risk..








More than 18 million smartphones and other mobile devices made by HTC are at risk vulnerable to many security and privacy issue.

The Federal Trade Commission charged HTC with customizing the software on its Android- and Windows based phones in ways that let third-party applications install software that could steal personal information.


The vulnerabilities placed sensitive information about millions of consumers at risk and potentially permitted malicious applications to send text messages, record audio and install additional malware without a user’s knowledge or consent.

FTC identify many vulnerabilities including, insecure implementation of two logging applications i.e Carrier IQ and HTC Loggers. The agency also found programming flaws that let third-party apps bypass Android's permission-based security model.

Flaws in the security system could also give third-party apps access to phone numbers, contents of text messages, browsing history and information like credit card numbers and banking transactions.

The Federal Trade Commission said HTC agreed to develop and release software patches to fix vulnerabilities found in millions of HTC devices.

The company didn’t design its products with security in mind,” Lesley Fair, a senior lawyer in the commission’s Bureau of Consumer Protection, wrote in a blog post.

HTC didn't test the software on its mobile devices for potential security vulnerabilities, didn't follow commonly accepted secure coding practices and didn’t even respond when warned about the flaws in its devices.

It also said the settlement also requires HTC America to set up a comprehensive security program when it is developing its devices, in order to avoid security risks.

Two new Java zero-day vulnerabilities reported to Oracle..!


Two new Java zero-day vulnerabilities reported to Oracle..!









A Polish security firm 'Security Explorations' reported two new Java zero-day vulnerabilities, as “issue 54” and “issue 55,” with proof of concept code to Oracle.


Oracle's security team is currently investigating the issue, but the status flaws not yet confirmed by Oracle. Less than a week after Oracle released its latest Java critical patch update, Researcher and Security Explorations's CEO Adam Gowdiak have found two previously unknown security issues affecting Java 7.

Security experts generally advise users to disable the Java browser plugin, which was exploited in recent targeted attacks on developers at Facebook, Apple and Microsoft.

Java has faced an increasing number of zero-day vulnerabilities, bugs that are exploited by criminals before those flaws are patched, or even known by the vendor.

Gowdiak confirmed that these newest vulnerabilities can be combined to circumvent Java's anti-exploit sandbox technology and used to attack machines whose browsers have the Java plug-in installed...


Unlock I Phone Screen Like This...!

Unlock I Phone Screen Like This...!






  • Connect your device with itunes and the appstore to make sure the code lock is activated
  • Push the power button (top|right)
  • The mobile will be activated and the iOS code lock will be visible
  • Now, you click on the emergency call
  • Try to dail any random emergency call number from a public listing (we used 911, 110 and 112)
  • Call the number and cancel the call directly after the dail without a direct connection to the number
  • Push again the power button and push after it the iphone button (square) in the middle
  • In the next step you push the power button 3 secounds and in the third secound you push also with one finger the
  • square and with another the emergency call button
  • After pushing all 3 buttons you turn your finger of the square (middle) button and after it of the power button
  • The display of the iOS will be black (blackscreen)
  • Take our your usb plug and connect it with the iOS device in black screen mode
  • All files like photos, contacts and co. will be available directly from the device harddrive without the pin to access.
Note : There is a limitation in this method also, that is actually not mentioned by hackers. The file system of iOS is in encrypted form. So, when your pass code protected iPhone is connected to a new computer, it must first be unlocked before it can be accessed by the computer. Smooth way connectivity is only possible only if the computer used to gain access to your file system has been successfully connected to your iPhone before.



Ps. It's not clear if the company is aware of this flaw or if a fix for it is also inbound.

Bank of America, TEKsystems exposed by Anonymous, more to come...


Bank of America, TEKsystems exposed by Anonymous, more to come...


Anonymous vs Bank of america aka boFa has been a on going battle the past few years and now anonymous has struck back with a huge release of logs and evidence that ties a lot of the research and Intel gathering that bank of America has been doing on them.




The data, depending where you are located was announced on the 24th/25th of February 2013 and first came in the format of “teaser” release files that contained personal information from staff at TEKsystems who anonymous says is being hired by Bank of America to watch and infiltrate them.


It appears that all the teasers have since been removed but in total there 10 teaser files, 7 main and 3 extra then the announcement that the leak was coming was made.

 
 Anonymous have made the claim that TEKsystems is being hired by Bank of America for some time now and it even goes on to explain and show logs of well known IRC and twitter users be listed as TEKsystems employees or other.

Quote:
TEKsystems is a subsidiary of Allegis Group, the largest private talent management firm in the world. Through our IT staffing solutions, talent management insight and suite of IT services, we make it easier to get IT done. Our longstanding history and industry-leading position speak to our success in helping clients meet their business targets. more
The archive contains hundreds of files and its going to take some time to get a decent report out to show what exactly is going on and to be able to confirm all the claims by Anonymous.
Anonymous have uploaded the information which totals 266 MB compressed and 319 MB when uncompressed to well known site Potentially Alarming Research: Anonymous Intelligence Agency with the following press release statement.
Quote:
Welcome to our special #BungaBungaBoABoA special edition
Teh Utterly Lulz jackhammerbuttraeps Bank of America

countdown for tutu and shoe on the head started.
Bank of America, sorry you started this shit alone on you.

Anonymous are revealing details that implicates the Bank of America with
spying on the public, a topic normally associated with the FBI and CIA.
yep fucking creepy shit…

Under the guise of business intelligence and fraud prevention the BoA
have been gathering personal information on the public as part of its
risk assessment process. This blatant breach of privacy is a shocking
insight into the spying tactics used by the banking system.

BoA has been using these tactics for a long time and have a well
developed strategy for information retrieval employing military and
IT contractors to provide tools and logic with powerful(exhaggerated lol)
algorithms to focus unrelated data into usable info.

In light of Intel gathering, we finally have a small piece of the puzzle
on how they are spying on perceived “threats” while making big business
moves to profit off this old technology. Is this being used for the %1
to make more profits judging on what the general public is discussing?

@ChetUber, @NealRauhauser and Emick were threesomefapping to this in the
bed wearing their feds clothes.
@aaronbarr was sexually loved by t-asshurtmacfags

lol, we bet adrian chen will say we’re trolling and he’ll beg for penis
later for this. xD
At the bottom of the press release is further information detailing what’s in the data package as well as a one line note hinting there is more to come in part 2. The package also contains a list of keywords which BOA was using to monitor certain social media and IRC servers and a close look at that list shows keywords like YamaTough, LulzSec, Anonymous as well as many personal names, company names and some appear to be put into category.

ROFL .. Bank of America (and their lackeys)

ROFL .. Bank of America (and their lackeys)

Bank of America (and their lackeys)


We have anchored at U.S. shores again to accept a consignment of a data package that probably belongs to our dear friends at Bank of America, though lots of contractors and subsidiaries (aka lackeys) are involved as usual.
It is a known fact that Bank of America is paying contractors to discredit journalist and sabotage their work as well as spying on the Occupy Movement and Anonymous ever since. It was to be expected that these efforts continue and it was also expected that their security remains - at best - lousy.
To start with, we present you about 320mb of internal reports and and emails assembled for Bank of America by a sub-contractor named TEKSystems (who in turn are a subsidiary of the Allegio Group whose founder also owns the Baltimore Ravens). These reports and emails assembled "intelligence" from sources like public channels on Anonymous and other IRC networks like Anonops, Voxanon and Cryto, as well as other social media.
We were geniously amused by the fact that there are actually paid analysts sitting somewhere, reading the vast amount garbage that scrolls by in large public channels like #anonops and #voxanon. Even more amusing is the keyword list that was found, containing trigger words like "Jihad" or "Homosexual".
Additionally about 12 Gigabyte of source code was looted, which is currently under assessment. We can tell so far that this software belongs to ClearForest, a company specializing on text and social network analysis. It is reasonable to assume that this code is the base system for what was used to categorize and store the acquired information. We will add the complete source code once we have finshied the initial assessment.
In the meantime, amuse yourself with the incredibly sensitive and important intelligence that BofA has gathered on Anonops and Voxanon (*smirk*). Please also note that the source has provided an accompanying release statement with the data.

ABC Australia Hacked, 49,561 Moderator and User Credentials leaked..


ABC Australia Hacked, 49,561 Moderator and User Credentials leaked

By Lee J on Wednesday 27th of February 2013 at 4:29:57 am







Tonight a hacker using the handle @Phr0zenM has announced a leak of data from the Official Australian ABC website.

The announcement came on twitter about 1.50 am AEST and the attack is said to be on a subdomain of the main official site ABC.net.au but its unknown exactly which domain this is.




The hackers twitter account appears to be about as old as the first tweet and original posting on pastebin suggesting this profile was created for the leak and attack has been carried out in the name of #OpWilders for the this video on the abc website which the hacker says allows Dutch politician Geert wilders to spread hatred. The leaked data has been posted to anonpaste.me in 10 parts with a main index of them links posted to pastebin.
Quote:
Australia’s ABC ABC.net.au subdomain hacked for giving Geert Wilders a platform to voice anti-Islam anti-Muslim hatred. #OpWilders

The information in the leak is personal credentials such as emails, names, genders, site positions, user passwords, ips, post codes, address, location and other information. A lot of the emails appear to be Australian related and in total 49,561 with about 5,000 credentials with emails being located in each part (exact number below).
All the passwords are encrypted but the other information relates to exact locations so this in turn is fairly critical that each user is alert to the situation asap and that ABC get to fixing the problem at hand.
The video which has a transcript below starts of with “Geert Wilders is the Dutch anti-immigration and anti-Islam MP. He’s the founder of the right wing Party For Freedom” which gives a really good insight to why this attack has been done as we have seen this trend in the past where media sites will be attacked due to posting news that some one does not agree with.
Quote:
Founded in 2005 as the successor to Geert Wilders‘ one-man party in the House of Representatives, it won nine seats in the 2006 general election, making it the fifth largest party in parliament.


As it always goes contact is made shortly after.
Anyways, the subdomain will not be disclosed at this current time with hints it may be disclosed later.
Below is Exact credentials with emails found by part id:
4993
4998
5003
5001
5000
5000
4998
4998
4997
4573
source: pastebin