Showing posts with label Defcon. Show all posts
Showing posts with label Defcon. Show all posts

June 26, 2008

ALERT:Credit Cards Able to Be Cloned!

It's a near ideal scene: a family riding a train, traversing hundreds of miles in a few hours. As the train chugs along at incredible speeds, they cross mountains,valleys, chug through forests and along beaches. The son begins to tug at his fathers curtail, accidentally knocking his dad into someone passing through the hallway.

No problem right?

Wrong. A group of hackers from the Netherlands used a technique that was popularized at DEFCON 15 to develop means to clone England's "Oyster" transit card. The cards use a microchip from the manufacturer "Mifare". A brief scan of a legitimate card reader (I.E, turnstiles to access the London Underground) reveal the cryptographic key that reads and authorizes a card to be used. Once the attacker uploads this key to his/her laptop, they are carrying a portable card reader wherever they go. This means that if the attacker is able to interrupt your cards RFID signature, they are able to clone your card onto a card of their choosing. This allows them to consume the balance of your card.

The Mifare chips are also used in numerous secure site authentication methods, which have drawn attention from the British government. When it was revealed that the same technology could be used to gain forged access to nuclear and governmental sites, they announced they would be replacing over 100,000 Mifare "Secure" RFID smart cards. At a cost of over 60 euros a piece, this security screw up could end up costing the British government over 3 million US dollars.

These events lead me wondering, how long before:
A.Credit Cards Have RFID
B.Hackers Crack It
C.Cloned Credit Cards
D.Aluminum Plated Wallets

June 4, 2008

HP Support Hacked! UPGRADE NOW!

A customer support application that comes bundled with HP PCs have been found to harbour multiple security vulnerabilities.

The pre-installed software is designed to make it easy for users to keep drivers and HP software automatically updated. But flaws in ActiveX components within HP Instant Support give rise to multiple vulnerabilties that lend themselves to drive-by download malware attacks in cases where Windows users running the vulnerable software stray onto insecure or hacker controlled websites, CSIS Security Group warns.

HP Instant Support HPISDataManager.dll version 1.0.0.22 and earlier are vulnerable. Users need to upgrade to version 1.0.0.24 as explained in a security bulletin from HP here.

A CSIS advisory containing proof of concept demos of the flaws can be found here. And there's an easy to digest bit from Secunia here.

It's not the first trouble HP has had with rogue ActiveX controls in its pre-installed utilities. In December last year two ActiveX bugs created a mechanism for hackers to either thrash or inject hostile code onto HP PCs running either HP Software Update or HP Info Center, respectively.

January 10, 2008

Calling All Hackers!

Digital Armaments January-February Hacking Challenge: Special 20.000$ Prize - Windows Vulnerabilities and Exploit
Challenge pubblication is 01.04.2008
http://www.digitalarmaments.com/challenge200801566321.html

I. Details
Digital Armaments officially announce the launch of January-February hacking challenge.
The challenge starts on January 1. For the January-february Challenge, Digital Armaments will give a SPECIAL PRIZE of 20.000$ for each submission that results in a Exploitable Vulnerability or Working Exploit for Windows or Windows Diffuse Application. This should include example and documentation.
The submission must be sent during the January/February months and be received by midnight EST on February 29, 2008. The 20.000$ PRIZE will be an extra added to the normal vulnerability payment (check the DACP scheme).