-->
#1 Trusted Cybersecurity News Platform
Followed by 5.40+ million
The Hacker News Logo
Subscribe – Get Latest News

The Hacker News | #1 Trusted Source for Cybersecurity News — Index Page

XSS Vulnerability in  Zapak(gaming portal) by Milan Milo [ZHC]

XSS Vulnerability in Zapak(gaming portal) by Milan Milo [ZHC]

Mar 26, 2011
XSS Vulnerability in   Zapak(gaming portal) by Milan Milo [ZHC]
Security Onion LiveDVD - Intrusion Detection for your Network !

Security Onion LiveDVD - Intrusion Detection for your Network !

Mar 26, 2011
Security Onion LiveDVD - Intrusion Detection for your Network ! The Security Onion LiveDVD is a bootable DVD that contains software used for installing, configuring, and testing Intrusion Detection Systems. Changelog: All Xubuntu 10.04 updates as of release date. Snort updated to 2.9.0.3. Suricata updated to 1.1beta1. Barnyard2 updated to 1.9 Stable. Vortex updated to 2.9.0. Installed OSSEC for host-based intrusion detection. Installed Squert web interface for Sguil. Installed Armitage GUI interface for Metasploit. Many improvements to Setup script for user-friendliness and capability Download Security Onion LiveDVD &  Presentation
Virus Attacks on Canadian Computer System

Virus Attacks on Canadian Computer System

Mar 26, 2011
Recently, Director of Information Technology, Per Kristensen stated that, a new type of the Qakbot virus appeared globally on March 15, 2011 and was observed in PCs in Nanaimo (Canada) at noon on March 16, 2011, as reported by Bclocal News on March 12, 2011. To safeguard important information about the city, the system was immediately put on a halt after the staff realized that the virus was swiftly circulating from PC to PC. Commenting on the matter, Per stated that, people can be sure that all their personal information and details are safe. He stated that, safeguarding their private information is their main concern. He added that, the city's system would not be turned on until they are sure that they sorted out the problem, as reported by Vancouver Sun on March 18, 2011. Kristensen stated that, the virus seems extremely complex, altering its signature to transfer through a computer various times. Kristensen stated that, the virus is classified as harmful and they are being ...
cyber security

Master High-Velocity Defense: SentinelOne's Virtual Cyber Threat Forum 2026

websiteSentinelOneCyber Resilience / Threat Intel
See Jayson E. Street deconstruct a bank breach and learn to hunt high-velocity threats at machine speed.
cyber security

99% of Mythos Findings Remain Unpatched. Defenders Are Building the Response

websitePicus SecurityAI Security / Security Validation
Autonomous Validation Summit, May 12 and 14. Register free and get 12 recommendations for the Mythos era.
10 pakistan  sites defaced by Hell Hax0r !

10 pakistan sites defaced by Hell Hax0r !

Mar 26, 2011
10 pakistan  sites defaced by Hell Hax0r ! Hacked sites : http://esonsind.com/ http://friendsofsialkot.com/ http://pakviewsports.com/ http://www.hard-safety.com/ http://www.badhawaind.com/ http://www.westwearco.com http://www.urbanwearintl.com http://www.kravmagasupplies.com http://lawsonsports.com/ http://www.tackisports.com/
The Open Pentest Bookmark Collection v1.4

The Open Pentest Bookmark Collection v1.4

Mar 25, 2011
We are pleased to announce the release of version 1.4 (yes 1.3 squeaked by without a blog post) of the Open Pentest Bookmarks Collection. They have added a  large  amount of community submissions, with the addition of  several new sections.  They have also moved around some of the bookmarks to better organize everything.  The new wiki entry should be a mirror of the file. To submit to the project, please use the wikipage at  http://code.google.com/p/pentest-bookmarks/wiki/BookmarksList / and post in the comments section. To download the file for import straight into Firefox or Chrome go here:  http://code.google.com/p/pentest-bookmarks/downloads/list
Google patches 6 serious Chrome bugs

Google patches 6 serious Chrome bugs

Mar 25, 2011
Google on Thursday patched six vulnerabilities in Chrome, and as usual, silently updated users' copies of the browser. The update to Chrome 10.0.648.204 also included two more blacklisted SSL certificates that may be related to last week's theft of nine digital certificates from a Comodo reseller. All six bugs were rated "high," Google's second-most-serious ranking in its threat scoring system. Of the half-dozen bugs, two were "use after free" flaws -- a type of memory management bug that can be exploited to inject attack code -- while a second pair were pegged by Google as "stale pointer" vulnerabilities, another kind of memory allocation flaw. As is Google's practice, the company locked down its bug-tracking database, blocking access to the technical details of the patched vulnerabilities. Google usually unlocks the bug entries several weeks, sometimes months later, to give users time to update before the information goes public. G...
Nasa HaCkeD By The 077 & DinelSon Tunisian HaCker

Nasa HaCkeD By The 077 & DinelSon Tunisian HaCker

Mar 25, 2011
Nasa HaCkeD By The 077 & DinelSon Tunisian HaCker Hacked link by The 077 :  http://blogs.nasa.gov/cm/resource/1015442 Hacked link by DinelSon :  http://blogs.nasa.gov/cm/resource/1015440
Delhi university's and Pakistani.pk site is vuln to XSS !

Delhi university's and Pakistani.pk site is vuln to XSS !

Mar 25, 2011
Delhi University 's & Pakistani.pk  site is vuln to XSS ! angel (4d0r4b13) Found Xss cross site scripting vulnerability in Delhi University Website, as shown. vulnerable Link :  : http://du.ac.in/index. php?id=276&sitesearch=du.ac. in&client=pub- 017673838153185424638% 3Aoxnjzwaqtce&cof=FORID%3A10& ie=UTF-8&q=%22%3E%3Cscript% 3Ealert%28%22Vuln+found+by+ 4ng31+4k4+4d0r4b13..!+angelws+ here..!+enjoy....!+delhi+ university..!+hehe..!+%3D%29+% 3D%29+%3B%29+%22%29%3C% 2Fscript%3E and  http://pakistani.pk/?s=%22%3E%3Cscript%3Ealert%28%22angel%20w45%20here..!%20heheheh%20pakistani.pk%20vuln%20to%20xss%20yup%20it%20is//!%20greets:Indian%20r00ting%20w1z4rd5..!%20vuln%20found%20n%20executed%20by%20angel%204k4%204d0r4b13%22%29%3C/script%3E
Anonymous Open Letter to Citizens of United States of America !

Anonymous Open Letter to Citizens of United States of America !

Mar 24, 2011
Anonymous Open Letter to Citizens of United States of America ! Just Now another Open Letter by Anonymous hackers released on Twitter m as below : Dear US Citizens,                           We, Anonymous, would like to offer you, America, the opportunity to join and support our movement.We are a group that formed on the internet--one that knows no constructs or absolutes, and one that has recently grown exponentially. We would like to introduce an Operation. An Operation that involves Americans getting our Natural Rights and dreams back. Right now, you can help by passing on the Information. Information is Power. Share the Power of the Information with other like-minded individuals. The more people we represent, the more Power we have, both as individuals and as Anonymous. Thank you for your time and your Power.                    ...
Hackers hack into TripAdvisor's members Database !

Hackers hack into TripAdvisor's members Database !

Mar 24, 2011
Hackers hack into TripAdvisor 's members Database ! Travel site TripAdvisor has warned subscribers to expect more spam following the theft of its member database. The travel review and information website said that an unspecified vulnerability allowed miscreants to make off with a portion of its email database. TripAdvisor does not collect members' credit card or financial information, and no passwords were obtained as a result of the breach. TripAdvisor has promised to tighten up its security in the wake of the incident, which is under investigation internally. The US-based website, which serves an international client base, has also reported the matter to police. Subscribers were notified of the breach by email, a copy of which was passed onto El Reg.. The incident comes days after ne'er-do-wells got their hands on the Play.com email list, sending targets links to a supposed Adobe software update that actually served up malware. Play.com blamed the incident on it...
XSS vulnerable on dmoz.org !

XSS vulnerable on dmoz.org !

Mar 24, 2011
XSS vulnerable on dmoz.org ! http://www.dmoz.org/search?q=%3Cimg%20src=%22http://lh4.ggpht.com/_bCYQxIvMQ2U/TRG6cWyFNjI/AAAAAAAAAW8/ZEHFUPXBmLk/hackernews.jpg%22/%3E View the compromised page
Iran Hackers targets Gmail and Skype with fake SSL hack !

Iran Hackers targets Gmail and Skype with fake SSL hack !

Mar 24, 2011
Iran has tricked a web firm into issuing fake security certificates for Gmail, Skype, Hotmail and more. Comodo Group, a US-based certificate authority firm with 15% of the market, admitted that one of its affiliate's accounts in Southern Europe had been hacked, letting the attackers create fake SSL security certificates for six websites. Such digital keys let websites offer secure services, and fake versions could be used to spoof sites, gather login details and watch user activity. The fake certificates target Microsoft's Live platform, Gmail and Google, Skype, Yahoo, and Mozilla Firefox extensions. The attack was quickly discovered, with the attacker still using the account when it was shut down. Comodo's CEO Melih Abdulhayogl said the attack appeared to originate in Iran, as it would have required access to the country's DNS infrastructure. "We believe these are politically motivated, state-driven/funded attacks," he said in a blog post, adding it wa...
Expert Insights Articles Videos
Cybersecurity Resources