BLuebugging:Can Breach YOUR Mobile Security



BLuebugging was somewhat like bluesnarfing but the difference is that it is more harmful to your mobile from the prospective of security of your mobile. It was first invented in 2004 by German scientist. In the initial phase, it was necessary to pair devices via Bluetooth before the security breacher  try to breach your mobile with the bugger, but now a days its not needed to pair up the devices.[sintuhack]. It can also possible to break you mobile security via the Bluetooth enabled headset which is used to take call as per to free your hands.[sintuhack]

At early stage it was done with laptop but now a days such powerful PDA and mobile phones are available  in the market that it can be done without laptops .[sintuhack]. you may be happy that your mobile Bluetooth has only a small range so its not easy to pair up your device hence you mobile is secured. But did you know that in market antenna’s are available which can send and receive weak signal s and hence data can be transferred from range of even 200 meters.[sintuhack]

Bluesnarfing:Mobile Security Breach

Bluesnarfing refers to a the method in which one has gained access to data, which is stored on a Bluetooth enabled phone of other people.
Literally Bluesnarfing can be described as unauthorized access of information from a wireless device through a Bluetooth connection. The level of access depends from case to case, but, in general, it involves pretty much anything that's stored on the user's mobile device.
Bluesnarfing allows the using person to make phone calls, send and receive text messages, read and write phonebook contacts, eavesdrop on phone conversations, and connect to the Internet. he can also download the material in his mobile from the victim mobile.
The good news is, bluesnarfing requires advanced equipment and much advanace expertise


In this field. As bluejacking can be done at the range of 10 meters, in bluesnarfing the intruder must be present within a 30 ft. range.
If the phone is in non-discoverable mode, then its not true that you cant be a victim of this.
Its adds only some problem and makes it little bit more difficult for intruders to bluesnarf your phone.


It can be possible from phone and laptop both to bluesnarf a mobile. By just using some bluesnarfing tools (Bluesnarfer, Blooover)

on mobile phone or laptop, anyone can detect and access those vulnerable mobile phones to view and download entire phonebook, calendar, real time clock, business card and other important private data without alerting the phone owner(you).




There's little info on whether Bluesnarfing is possible without the targeted phone being paired with the computer running the aforementioned software application, but anyone cannot completely rule out this possibility, either.


So that’s all about bluesnarfing. Wait till next post to know about other mobile security breach methods………….

Mobile hacking via blutooth

In this post i will tell  you how actually  mobile phones are get hacked  . i will describe it step by step that how mobile get hacke but plz don’t utilize it and try . If you will try then it will your responsibility.


I mainly describe the process  of Bluejacking .
  
Friends there is a bluetooth hacking software , using bluetooth hacking software anyone can “hack any cell phones”
 the latest version of this software is Bluetooth Hack v 1.07.
anyone can easly download it from any file sharing site.
Like  Download via RapidSahre: http://rapidshare.com/files/XXXXXXX/Superbluetoothhack.zip






Disadvantages of this software.


if  anyone get connected to your phone via bluetooth :
- he can read your messagess
- he can read your contactss
-he can play your songs from your mobile 

- he can also play his/her ringtones even your phone is in silent
- he can switch off your mobile –

-he can change your profile
-he can restart his/her mobile
-he can restore your factory setings
- he can also change ringing volume of your mobile..

  - the worst  part of it is he can call from your mobile which also includes all call functions like hold on etc etc..



Mobile phone hacking work according to following   steps .
  • He will Go to Contacts.
  •  And will Create a new contact.
  • He will Write the short message he want to send on the line next to 'Last name'
  • And Save this contact.
  • Now he will Select your contact and send via Bluetooth because your bluetooth is on and you donot know about it.
  • His  phone will search for devices and that software will found your mobile.
  • He will Select any one  like you  and will  send.
  • Now Your phone  have been  bluejacked by someone.


This software is very much suitable for sony ericcsson and few Nokia mobiles.
So user of it be aware..
Warning this is only For educational purposesif any one use it it will totaly his resposiblity.




In next post i will describe others methods of  bluethooth hacking.

MOBILE HACKING:BLUTOOTH HACKING

Bluetooth is a very common thing for mobile technology and used frequntly by user to tranfer data. But as frequent they transfer the data , less they put attention on security . Even most of them donot think about  that their mobile can be hacked via blutooth.
So now from today i am going to describe about blutooth hackings and security and it will continue in upcoming post.

Bluejacking, Bluesnarfing, Bluebugging and Bluetoothing are the main type of bluetooth hacks.


Bluejacking is the simplest of the four.  It is an attempt to send a phone contact or business card to another nearby phone. The ‘name' field of the contact can be misused by replacing it with a suggestive text so that the target device reads it as a part of intimation query displayed on its screen. Tis is somewhat equivalent to spam e-mail because both are unsolicited messages displayed on recipients' end without consent, and by exploiting the inherent nature of communication.
These are the softwares available in the market which help in bluetooth hacking.


BlueScanner - It hunts out for Bluetooth devices and dig out much amount of information of the newly discovered device.

BlueSniff - Utility for discovering hidden Bluetooth devices.

BlueBugger -It simply exploits the BlueBug vulnerability of the bluetooth enabled devices. By exploiting these vulnerabilities and leakes, you can gain access to the phone-book, calls lists and other information of the bluetooth device.

BTBrowser - Is a Bluetooth Browser is a J2ME app. which can browse and explore all the surrounding Bluetooth devices.

BTCrawler -It is a Bluetooth scanner for Windows Mobile based devices. It can implement BlueJacking and BlueSnarfing attacks.


In the next post i will describe how hackers actually  use these softwares for the hacking..........

How does anti-virus software work?The Working mechanism of antivirus

An anti-virus software program is a computer program that can be used to scan files to identify and eliminate computer viruses and other malicious software (malware).......................

    * Examining files to look for known viruses by means of a virus   dictionary
    * Identifying suspicious behavior from any computer program    which might indicate infection


Most commercial anti-virus software uses both of these approaches, with an emphasis on the virus dictionary approach.

Virus dictionary approach
In the virus dictionary approach, when the anti-virus software examines a file, it refers to a dictionary of known viruses that have been identified by the author of the anti-virus software. If a piece of code in the file matches any virus identified in the dictionary, then the anti-virus software can then either delete the file, quarantine it so that the file is inaccessible to other programs and its virus is unable to spread, or attempt to repair the file by removing the virus itself from the file.

To be successful in the medium and long term, the virus dictionary approach requires periodic online downloads of updated virus dictionary entries. As new viruses are identified "in the wild", civically minded and technically inclined users can send their infected files to the authors of anti-virus software, who then include information about the new viruses in their dictionaries.

Dictionary-based anti-virus software typically examines files when the computer's operating system creates, opens, and closes them; and when the files are e-mailed. In this way, a known virus can be detected immediately upon receipt. The software can also typically be scheduled to examine all files on the user's hard disk on a regular basis.

Although the dictionary approach is considered effective, virus authors have tried to stay a step ahead of such software by writing "polymorphic viruses", which encrypt parts of themselves or otherwise modify themselves as a method of disguise, so as to not match the virus's signature in the dictionary.

Suspicious behavior approach
The suspicious behavior approach, by contrast, doesn't attempt to identify known viruses, but instead monitors the behavior of all programs. If one program tries to write data to an executable program, for example, this is flagged as suspicious behavior and the user is alerted to this, and asked what to do.

Unlike the dictionary approach, the suspicious behavior approach therefore provides protection against brand-new viruses that do not yet exist in any virus dictionaries. However, it also sounds a large number of false positives, and users probably become desensitized to all the warnings. If the user clicks "Accept" on every such warning, then the anti-virus software is obviously useless to that user. This problem has especially been made worse over the past 7 years, since many more nonmalicious program designs chose to modify other .exes without regards to this false positive issue. Thus, most modern anti virus software uses this technique less and less.

Other ways to detect viruses
Some antivirus-software will try to emulate the beginning of the code of each new executable that is being executed before transferring control to the executable. If the program seems to be using self-modifying code or otherwise appears as a virus (it immeadeatly tries to find other executables), one could assume that the executable has been infected with a virus. However, this method results in a lot of false positives.

Yet another detection method is using a sandbox. A sandbox emulates the operating system and runs the executable in this simulation. After the program has terminated, the sandbox is analysed for changes which might indicate a virus. Because of performance issues this type of detection is normally only performed during on-demand scans.

Issues of concern

Macro viruses, arguably the most destructive and widespread computer viruses, could be prevented far more inexpensively and effectively, and without the need of all users to buy anti-virus software, if Microsoft would fix security flaws in Microsoft Outlook and Microsoft Office related to the execution of downloaded code and to the ability of document macros to spread and wreak havoc.

User education is as important as anti-virus software; simply training users in safe computing practices, such as not downloading and executing unknown programs from the Internet, would slow the spread of viruses, without the need of anti-virus software.

Computer users should not always run with administrator access to their own machine. If they would simply run in user mode then some types of viruses would not be able to spread.

The dictionary approach to detecting viruses is often insufficient due to the continual creation of new viruses, yet the suspicious behavior approach is ineffective due to the false positive problem; hence, the current understanding of anti-virus software will never conquer computer viruses.

There are various methods of encrypting and packing malicious software which will make even well-known viruses undetectable to anti-virus software. Detecting these "camouflaged" viruses requires a powerful unpacking engine, which can decrypt the files before examining them. Unfortunately, many popular anti-virus programs do not have this and thus are often unable to detect encrypted viruses.

Companies that sell anti-virus software seem to have a financial incentive for viruses to be written and to spread, and for the public to panic over the threat. 

Why You Need Intrusion Detection

Expert Advice on Keeping Your Network Safe by Blocking Dangerous Hacker Attacks
The stories go on and on about another individual having their personal information stolen from their computer by some hacker. While it is true that hackers do get people's information, and they will keep on getting that information,
it is also true that having intrusion detection software can help. And even better, to be hacker safe intrusion prevention system is by the same software.
Why You Need Intrusion Detection
Doors can be opened to hackers in varied ways. Two of the most common ways by which they can gain access to your computer is simply through emails, or Web pages that you visit that have spyware, or trojans (a file which looks innocent, but actually will later open doors to a hacker) attached to them. Other ways are robot spiders sent out over the Internet to find unprotected computers, and open doors. Some say that every computer attached to the Internet may be attacked by such a spider as many as 50 times each day. So, if you do not have an intrusion prevention system in place, up-to-date, then you may have regular unexpected visitors - and you may not even know it. Others say that 9 out of 10 computers have some sort of spyware, or malware on them. Could you be one of them? This article will show you what is available on the market for your protection - and much of it can be obtained for free.

The spider robots work automatically - looking for and identifying computers on the Internet that have doors, or ports, open to them. This information is then reported back to the hacker - knowing which computers to target - and which port to use. For this reason, every now and then, Microsoft will come out with a new patch for Windows, in order to close some faulty door that hackers have discovered and been using.
What Is Intrusion Detection?
Network Intrusion detection software is a must-have these days. Each company's software will vary somewhat (for copyright and originality purposes), but you do need one for your own network, or home computer. It differs from a firewall in that the purpose of a firewall is to stop unauthorized external contacts with your system. These offer hacker prevention largely for contacts from outside the network. Most of these will now notify the owner or network controller of intrusion attempts. Network intrusion detection systems, on the other hand, will give you warnings about events that take place within the network itself.

HISTORY OF HACKING AND ITS SECURITY

                           Hacking is not limited to computers.
The real meaning of hacking is to expand the capabilities of any electronic device; to use them beyond the original intentions of the manufacturer. As a matter of fact, the first hackers appeared in the 1960's at the Massachusetts Institute of Technology (MIT), and their first victims were electric trains. They wanted them to perform faster and more efficiently. So, is hacking always bad? Not really. It only depends on how to use it. But it wasn't until a group of these hackers decided to exert their knowledge in the computer mainframes of the MIT.

During the 1970's, a different kind of hacker appeared: the phreaks or phone hackers. They learned ways to hack the telephonic system and make phone calls for free. Within these group of people, a phreaker became famous because a simple discovery. John Draper, also known as Captain Crunch, found that he could make long distance calls with a whistle. He built a blue box that could do this and the Esquire magazine published an article on how to build them. Fascinated by this discovery, two kids, Steve Wozniak and Steve Jobs, decided to sell these blue boxes, starting a business friendship which resulted in the founding of Apple.

By the 1980's, phreaks started to migrate to computers, and the first Bulletin Board Systems (BBS) appeared. BBS are like the yahoo groups of today, were people posted messages of any kind of topics. The BBS used by hackers specialized in tips on how to break into computers, how to use stolen credit card numbers and share stolen computer passwords.

It wasn't until 1986 that the US government realized the danger that hackers represented to the national security. As a way to counteract this menace, the Congress passed the Computer Fraud and Abuse Act, making computer breaking a crime across the nation.

During the 1990's, when the use of the internet widespread around the world, hackers multiplied, but it wasn't until the end of the decade that system's security became mainstream among the public.

Today, we are accustomed to hackers, crackers, viruses, Trojans, worms and all of the techniques we need to follow to combat them.

Top Ten Credit Card Safety/SECURITY Tips

There are hundreds of credit cards scams that enable the wrong people to gain your account and identity information. Identity theft is a major problem and can be avoided using these ten simple safety techniques for credit card use.

1. Watch where you shop. It is important to be aware of store policies when it comes to credit card use. How is your information protected? Are the systems used to process payment information secure?

2. Shred all information received from the credit card company. With the high instances of identity theft occurring throughout the country it is essential to take measures to avoid allowing others to view personal information.

3. When shopping online, ensure that only safe and secured websites are used for the purchases of gifts and other items. A locked padlock should be seen in the internet browser to ensure the maximum safety measures are being taken.

4. Use automated banking machines at the bank over machines located at convenience stores and within malls. Using these bank machines reduces the risk of identity theft from information being scanned as the card is swiped through the banking machine.

5. Report a card lost or stolen immediately after the card has been discovered lost or the information has been stolen. The credit card company can immediately place a hold on the account, as well as any purchases made through the account can be protected under purchase protection.

6. Ensure credit cards are signed the moment that they are received and activated. Signing the credit card reduces the chance of the card being used in a case of identity theft.

7. Keep account numbers written in a safe place that cannot be accessed by others. Credit card account numbers should not be written within the wallet, or any other area where they can be easily accessed.

8. Never lend credit cards to anyone or allow anyone to use the number to make purchases over the telephone or the internet. It is important to be aware of all credit card activity and prevent future use of card information.

9. Check your account statement each month for regular and periodic use. Customers that check the account statement are more likely to catch identity theft before it becomes devastating to the card holder.

10. Don’t keep extra copies of credit cards in the house, unless they are in a safe, under lock and key. An extra credit card can be couriered to the card holder in as little as a day – therefore it is important to avoid keeping excess copies of the credit card at home.

We can Trace a Stolen SIM Card of any mobile phone....

All information about your cell phone is stored on a SIM card inside your phone. This is the card cell phone companies
program when you first activate your cell phone. When your cell phone is stolen, the SIM card is often the only way to trace the phone’s location.

Tracking your stolen cell phone through the SIM card is mainly done through your cell phone provider. As soon as you realize the phone has been stolen, call your cell phone provider. Provide them with your account number, cell phone number and approximate time the phone was stolen. They can then track the phone’s activity. If the SIM card has not been changed out, this will help the cell phone company lead authorities to your phone’s location.

If GPS is enabled on your cell phone, you may be able to monitor your cell phone’s location from home. This will require the cell phone to be turned on and the SIM card active. Open the web page you use to access the GPS locator on your phone. Call authorities as soon as you have a set location.

Try calling your cell phone. Some thieves will actually answer the phone. The call will provide a way for your cell phone provider to track the last known location. Authorities may also be able to provide this service as well.

If the SIM card has already been changed out, finding the cell phone itself may be impossible. However, your cell phone provider can still attempt to trace the location of the SIM card. When the cell phone number assigned to the SIM card’s serial number no longer match, this alerts the provider to the theft. They will then be able to trace the stolen SIM card through the new cell phone number.

New applications are being created that work silently to track the SIM card and cell phone. These applications run quietly to prevent alerting the thief to their presence. One such application is Smart Phone Guard. The application hides itself the moment the SIM card is replaced. A message is then sent to friends’ numbers. The numbers are determined at the time the application is installed. The application also allows you to remotely delete any personal information such as photos and videos remotely through one of the friend’s numbers.

Check with your cell phone provider for other applications that may be able to trace the location of stolen SIM cards. These applications will give you peace of mind that no matter what happens to your phone, you’ll still have control. For older phones, newer applications may not be compatible.

In the event your SIM card or cell phone is stolen, report the incident immediately to your cell phone provider. This will prevent unauthorized calls and charges to your account. For many thieves, once the phone is deactivated, they simply discard the phone. Ask your provider to trace the SIM card if possible. GPS enabled phones can also be tracked through the SIM card and phone number. There are several different ways to trace a stolen SIM card with new methods being developed daily.

Pak criminals hack into 40-50 Indian sites a day'

New Delhi, Nov 12: Exposing the lack of cyber security  in India, an 'ethical hacker' has revealed the Pakistani cyber criminals manage
to deface 40 to 50 Indian sites every day.

In the war that has been on since 2001, the Pakistani criminals are able to easily break into Indian cyberspace, while their Indian counterparts can only deface about 10 to 15 Pak websites in retaliation, Ankit Fadia told Business Standard.


"Terrorists are using the most advanced technologies for communicating with each other, which include VoIP (voice-over Internet protocol), hiding messages inside photographs, draft emails and encrypted pen drives," the 18-year-old added.

Fadia pointed out that even though India is the global IT capital, the country has to still go a long way when it comes to cyber security.

"Though we have enacted cyber laws, there is not much awareness in the country about security risks arising from cyber attacks nor is there any proper training for law enforcing agencies to deal with the crime," Fadia said in another interview with a news agency.

Fadia is an independent computer security and digital intelligence consultant. He has also worked with the CBI to trace the addresses of 15 Pakistani hackers who posted anti-India messages on websites they broke into.

      SO PLEASE STOP SUCH ACTIVITY AND MAKE WORLD BEAUTIFUL IN ALL ASPECT----AJEET