-->
#1 Trusted Cybersecurity News Platform
Followed by 5.20+ million
The Hacker News Logo
Subscribe – Get Latest News
Security Service Edge

The Hacker News | #1 Trusted Source for Cybersecurity News — Index Page

Multiple vulnerabilities in IBM Tivoli Directory Server !

Multiple vulnerabilities in IBM Tivoli Directory Server !

Apr 04, 2011
Multiple vulnerabilities in IBM Tivoli Directory Server Multiple vulnerabilities have been reported in IBM Tivoli Directory Server, which can be exploited by malicious users to disclose sensitive information and by malicious people to cause a Denial of Service and compromise a vulnerable system, according to Secunia. 1. The application bundles a vulnerable version of IBM Java. 2 . An error within ibmslapd.exe when processing certain requests can be exploited to cause a stack-based buffer overflow. Successful exploitation of this vulnerability may allow execution of arbitrary code. 3. The TDS proxy server stores the user's password in cleartext in the audit log when the backend server is configured to audit extended operations. The vulnerabilities are reported in versions 6.1, 6.2, and 6.3.
Hackers Changes Millions of Passwords to "password" !

Hackers Changes Millions of Passwords to "password" !

Apr 04, 2011
 Hackers Changes Millions of Passwords to " password " ! Passwords from over 3,000,000 user accounts were apparently set to "password" late last night in a wide-spread hack that affected hundreds of news, retail and Web 2.0 sites. Most affected users are completely unaware of the attack. According to current statistics, 62% of affected users would not notice such a change as their password was already "password". Several sites have reported that they are taking steps to protect compromised accounts. In addition, many sites are creating a new rule to ban using the word "password" as a password. Users are reacting fiercely to the hack but even more so to the ban many sites are putting on one of the world's most popular passwords. Online riots are to be expected. The hacker group named "Obvious" has claimed credit for last evening's attack. Thousands of hacked Twitter and Facebook accounts posted the message "We are a...
HBA Crew (german carder forum) get hacked !

HBA Crew (german carder forum) get hacked !

Apr 04, 2011
Now it's official: HBA-crew v2, was hacked! Ip 'were logged, Database is public! An official statement is as early as the first April before. But was it so funny but not that it was serious: Hi, Now we can not hide it anymore. geloaded Since yesterday evening by a leak in the server the entire database of HBA, packaged and put on various public OCH's been. Because, unfortunately, still in some areas, no IP logging was disabled, we ask you immediately to secure your systems. It's just a matter of time. Starting with the great and stopped at the small. The forum is in the background already reorganized. According to the internals using Co.Admin TheSaint was - made possible the leak. No one can be trusted - unfortunately. Bitter ! be deceived by the private Co. Admin thereby. Well let's look at how the index looked like: "Hacked by a pro of the scene" The Happy Ninja's are the again the scene on its head: First of all, here is the plain tex...
cyber security

AI Security Board Report Template

websiteWizAI Security / Compliance
This template helps security and technology leaders clearly communicate AI risk, impact, and priorities in language boards understand.
cyber security

AI Security Isn’t Optional—Join the Conversation at SANS Security West

websiteSANSCybersecurity Training
SANS Fellow, Eric Johnson addresses emerging risks and tactical responses.
The Hindi Times Hacked by TriCk & RoCk - ZHC & TeaMp0isoN

The Hindi Times Hacked by TriCk & RoCk - ZHC & TeaMp0isoN

Apr 03, 2011
The Hindi Times Hacked by TriCk & RoCk - ZHC & TeaMp0isoN Site: http://www.thehinditimes.com/ Mirror: http://zone-h.org/mirror/id/13410390
Bh-News Has Been Hacked By Dinelson US

Bh-News Has Been Hacked By Dinelson US

Apr 03, 2011
Bh-News Has Been Hacked By Dinelson US  Hacked Users : Website : www.bh-news.com
Channel.facebook.com cross-site-scripting (XSS) vulnerability by Edgard Chammas

Channel.facebook.com cross-site-scripting (XSS) vulnerability by Edgard Chammas

Apr 03, 2011
Channel.facebook.com cross-site-scripting (XSS) vulnerability by Edgard Chammas Security researcher Edgard Chammas, has submitted on 02/04/2011 a cross-site-scripting (XSS) vulnerability affecting 1.61.channel.facebook.com, which at the time of submission ranked 2 on the web according to Alexa. It is currently unfixed. Link :  http://1.61.channel.facebook.com/iframe/11?r=http://static.ak.fbcdn.net/rsrc.php/1.js%22%3E%3C/script%3E%3Cscript%3Ealert(%22The%20Hacker%20News%22)%3C/script%3E%3Cscript%3E
Crif.org defaced by participants in #Anonymous

Crif.org defaced by participants in #Anonymous

Apr 03, 2011
Crif.org defaced by participants in # Anonymous The website of the Conseil Représentatif des Institutions Juives de France or the Representative Council for Jewish Institutions of France was defaced by the hackers on steroids over in Anonymous’ operation palestine or #oppalestine. At the time of this writing the website www.crif.org is still defaced. here’s a picture to immortalize the action.
Anonymous takes down Sony Pictures US and UK sites !

Anonymous takes down Sony Pictures US and UK sites !

Apr 03, 2011
Anonymous successfully taken down http://www.sonypictures.com/ and http://www.sonypictures.co.uk The Sony PS3 console was "hacked" or more appropriately, jail broken, by iPhone hacker, Geohot. Anonymous managed to reverse engineer his own PlayStation 3 to run home brew applications on it.And then later released the method to the public, through his site, geohot.com Sony hit Anonymous with a lawsuit and demanded social media sites, including YouTube to hand over IP addresses of people who visited Geohot's social pages/videos.Pay pal have granted access to Sony for them to view Geohot's Pay Pal account. The judge of the case has given permission to Sony to view the IP addresses of everyone who visited geohot.com Sony are also after another group of hackers for the same case. The PS3 hack which GeoHot released can be compared to the "unlocking" of a phone. i.e. Once you purchase the phone, it's yours, you can do whatever it is you want with it. L...
QNet confirmed that e-commerce portal was down due to DDoS attack

QNet confirmed that e-commerce portal was down due to DDoS attack

Apr 03, 2011
QNet confirmed that E -commerce portal was down due to DDoS attack QNet has confirmed that its e-commerce portal was recently the target of a Distributed Denial of Service (DDoS) attack. This caused its main website to be offline for over 36 hours. QI Group IT Director, TG Kintanar said, “As a global direct selling company with a busy trading portal, it is not unusual for QNet to become a target for such attacks, although this has never happened before.” QNet is a subsidiary of the QI Group of Companies. “Let me stress that the cyber-attack on our website was not the work of hackers. The DDoS merely blocked customers’ access to our services, causing them great inconvenience. However, as QNet's online security measures were in place, our customer database remained intact throughout the attack. Nothing was compromised.” Kintanar said. He added that upon noticing the attack on March 9, the QNet IT team immediately started working round-the-clock to set up an alternate transacti...
Kroger Customer Database Hacked !

Kroger Customer Database Hacked !

Apr 03, 2011
Kroger Customer Database Hacked ! The company announced in an e-mail to customers their system has been hacked by someone outside the company. This means the hacker had access to customer names and e-mail addresses contained in the Kroger database. Kroger stresses only the names and e-mail addresses of customers who voluntarily submitted those addresses to the company may be affected. Kroger says you may receive spam messages from senders you do not know. So, if you receive an e-mail from an unknown sender, do not open it. For more information, you can call Kroger customer service at 800-KROGERS.
Expert Insights Articles Videos
Cybersecurity Resources