Hacking

Pierluigi Paganini May 02, 2015
New Google Password Alert extension already hacked

A few hours after the presentation of the Google Password Alert extension a researcher already have developed two methods to bypass it. A few hours ago, Google released the Password Alert extension that was designed to warn users when they are submitting their Google credentials to fraudulent websites. “Here’s how it works for consumer accounts. Once you’ve […]

Pierluigi Paganini May 01, 2015
Password for systems at a London rail station revealed during a TV documentary

The passwords for the signal system of the control room at the Waterloo rail station in London were disclosed during a TV documentary. We cannot think of lock down the house if we leave the keys in the lock outside, something of similar occurred recently to at French network TV5Monde. Following the successful attack against the network […]

Pierluigi Paganini May 01, 2015
Why hackers target background investigation databases

Foreign hackers are targeting background investigation databases to blackmail US government personnel or to try to bribe them. It is not a mystery that Chinese hackers continuously target US companies and government offices, the attackers usually backed by the Government of Bejing mainly run cyber espionage campaigns to steal intellectual property and any kind of information related to person […]

Pierluigi Paganini April 30, 2015
Flawed password reset procedure exposes Betfair accounts

Experts demonstrated the presence of critical vulnerabilities in the password recovery procedure of the website of the online betting exchanges Betfair. A security expert discovered a flaw in the password recovery process on the website of online betting exchanges Betfair. Betfair is one of the world’s largest online betting exchanges, and this vulnerability represents a […]

Pierluigi Paganini April 30, 2015
A flaw in Realtek SDK exposes SOHO routers to the attack

A flaw affecting Realtek SDK exposes SOHO routers to remote code execution attacks. List of vulnerable devices include D-Link and TRENDnet products. The security expert from DVLabs security researcher and content developer at HP Enterprise Security Ricky Lawshae discovered a (CVE-2014-8361) vulnerability that affects Realtek SDK used for RTL81xx chipsets. The exploitation of the vulnerability allows a […]

Pierluigi Paganini April 29, 2015
Hacker Implants NFC Chip to Bypass Military Security Scans

A security researcher implanted an NFC Chip in his Hand to bypass security scanners in high-security environment and exploit Android mobile devices. I confess that I’m curious about some news, but at the same time I’m worried about the “penetration” of technology in our lives.  This is the case of a security researcher that used an […]

Pierluigi Paganini April 29, 2015
Hacking PayPal server by exploiting a Remote Code Execution flaw

Security expert discovered a way to hack a PayPal server by exploiting a Remote Code Execution flaw affecting the Java Debug Wire Protocol (JDWP) protocol. Security researcher Milan A Solanki discovered a new critical remote code execution vulnerability in PayPal platform. An attacker could exploit the vulnerability to execute arbitrary code on the PayPal  Marketing online-service […]

Pierluigi Paganini April 29, 2015
How to exploit flaws in InFocus IN3128HD Projector to hack host network

The firmware running on the InFocus IN3128HD Projector is affected by an authentication bypass flaw which allows the hack of the host network. Another smart object was found vulnerable by security experts, it is a popular projector commonly used in classrooms. The manufacturer has discovered several authentication flaws affecting the firmware running on the projector, the vulnerabilities could be […]

Pierluigi Paganini April 28, 2015
Almost 90% of Java black hats migrate to softer footling Flash targets after MS Patch or die policy

The stricken-scum now deal with an option: work harder in order to find Java zero days or simply abandon dispatch and begin exploiting older Flash-bugs. Redmond’s security heads trust – Matt Miller, Tim Rains and David Watson – claim its patch wrecking-ball, employed only to out of the date Java installations previous year, which forced […]

Pierluigi Paganini April 27, 2015
WordPress fixed a Zero Day a few hours after its disclosure

WordPress has just released a critical update to fix a serious XSS vulnerability that allows attackers to easily hijack websites based on the popular CMS. A cross-site scripting vulnerability is threatening WordPress content management system platforms worldwide. The popular CMS is used by nearly 186,700 of the top one million websites. An attacker can exploit the […]