Showing posts with label Hacked. Show all posts
Showing posts with label Hacked. Show all posts

Monday, 30 July 2012

Hackers steal personal details of 8.7 million mobile subscribers


Hackers steal personal details of 8.7 million mobile subscribers



Hackers have accessed the personal details of 8.7 million mobile phone subscribers to South Korea's second largest telecommunications company.
Police have arrested two people for allegedly hacking into the network system of KT Corporation, formerly Korea Teleco, and selling the data.
The suspects are believed to have stolen the personal information of more than half of KT's 16 million subscribers since February, according to local reports.
South Korea's National Police Agency's cyber terror response team said seven others were charged with buying the leaked data for telemarketing purposes.
Police suspect the telemarketers used the data to contact customers whose contracts were close to expiration or were considered likely to change mobile phone plans.
"It took nearly seven months to develop the hacking program and (the suspects) had very sophisticated hacking skills," an official at the cyber response team is quoted as saying.
KT has apologised for the data breach, saying it has taken steps to prevent further leakage.
"In light of this incident, we will strengthen the internal security system and raise awareness of security among all employees to prevent causing inconvenience to customers," the company said.
Highlighting the reputational damage caused by data breaches, market commentators have said angry subscribers may mount a class action lawsuit against the company.
The KT data breach comes a year after a spate of hacking attacks which targeted South Korean government departments, financial firms and a social networking site and web services portal run by SK Telecom.
In the worst breach in South Korea to date, hackers accessed 35 million user accounts in the attack on SK Telecom, which has links to the state monopoly phone company, Korea Telecom.
The breach was revealed by the Korean Communications Commission, which claimed to have traced the source of the incursion back to computer IP addresses based in China.

Monday, 16 July 2012

Apple In-App Store Hacked


Apple In-App Store Hacked 


Hacker finds way to loot in-app store items and posts a how-to on YouTube.


A Russian hacker has managed to find a way around the security checks in Apple's in-app purchasing system to make content sold in iOS apps available for free.
The hacker, identifying himself as ZonD80, has posted a YouTube videode monstrating how he was able to create an in-app proxy that authorizes in-app purchases at no cost.
"To buy in-app content," he says in the video,"you must install two certificates and set the IP address of the DNS to a specific IP."
On a Blogger hosted site, he has asked for donations to support the development of his project. The PayPal email address he provides for receipt of funds is a Me.com address, a domain owned by Apple. Presumably this will simplify Apple's effort to identify the hacker, though doing so won't stop the spread of his code: ZonD80 notes on his blog that he has sent the source code and control of the hosting server to someone else.
[ Is Apple environmentally conscious? Read Apple Clean Cloud More Talk Than Walk: Greenpeace. ]
In-app purchasing has become one of the leading sources of revenue for app developers. ABI Research in February predicted that revenue from sale of content in apps will outpace revenue from selling the apps themselves in 2012.
Apple appears to be taking steps to limit the damage. Russian blog i-ekb.ru includes a note, purportedly from ZonD80, indicating that Apple has filed a takedown notice with the service provider of his website.
It's doubtful that Apple will ask Google to remove the hacker's Blogger site--it isn't hosting any code so there might not be any legal foundation to request that Google remove it, unless Apple claims that the domain, in-appstore.com, violates its trademarks.
The hack appears to work on iOS versions 3.0 through 6.0, presently available only in beta form to iOS developers. But not all apps with in-app purchasing are vulnerable. Apple provides a mechanism to validate in-app purchases, in order to allow purchases to be restored on erased or new devices. Developers who have implemented receipt verification, which requires tracking in-app sales using a separate server, can query Apple to confirm the authenticity of purchased items.
Black Hat USA Las Vegas, the premiere conference on information security, features four days of deep technical training followed by two days of presentations from speakers discussing their latest research around a broad range of security topics. At Caesars Palace in Las Vegas, July 21-26. Register today.