Israeli hackers Vs Saudi hackers


 Israeli hacker known as “0xOmer” has already made headlines after publishing hundreds of Saudi credit card numbers in retaliation against Arab hackers, claiming to be Saudis, who published tens of thousands of Israeli credit card details on the Internet last week.
“This is just the beginning,” 0xOmer told The Jerusalem Post Wednesday.
“We have over 300 Saudi credit card numbers in our possession... and the personal details of over 10,000 people in Saudi Arabia, including full names, e-mails and addresses. If they publish one more little detail on Israel, we will attack in full force and publish all of the credit card details.”
On Wednesday night, the Saudi hacker released what he said were 200 more Israeli credit card numbers, and called other anti-Israel online activists to step up web attacks.
Responding to the development, 0xOmer said he would release thousands of personal information accounts belonging to Saudis.
“They want force? No problem,” he wrote. “We have a further 300,000 working Saudi credit card numbers. We are seriously considering whether we should publicize them.”
The hacker provided a glimpse into how a developing cyber-war is being fought.
Last week, Israeli credit card companies and the Bank of Israel scrambled to cancel credit card numbers compromised by the actions of the anti-Israel hacker. Now, Saudi banks will have to take the same steps to protect their customers.
“I belong to a group of hackers named Israel Defenders,” 0xOmer said. The team, he added, is made up of four members who function like an organized cell with a clear division of labor.
“My role is to find and exploit security breaches at the highest levels,” he told the Post.
Another member of the team, code-named “7ukk1,” is in charge of defacing websites and handling foreign media relations; according to 0xOmer, he is an IDF soldier serving in Military Intelligence.
A third member specializes in breaking into servers. The fourth member helps 0xOmer identify security gaps.
“It’s very easy to be a hacker. It’s a matter of studying for two to three months and you can master the field,” he said. “The only difficulty is in finding Arab websites because they’re in a different language.”
But such websites have already been found in the form of a Saudi shopping website, where security breaches were identified.
The hackers are interested only in sending a warning to anti-Israel hackers at this stage, and stopped short of providing credit card information that can be used to make fraudulent purchases, 0xOmer added.
“I didn’t publicize the three-digit number on the back of the card [necessary for online shopping],” he explained. But if hostile Internet activists continue attacking Israeli targets, Israel Defenders will publish hundreds of credit card numbers, along with the three-digit code.
The four youths are taking up what they say is a deterrence posture in an online world that is increasingly being used as a battle arena.
The arena is dominated almost exclusively by the young.
“Many want to know how old I am, and some think I’m an adult. The right answer is that I’m 17,” 0xOmer said.
On his Twitter account he posted a link to a media report on the Israeli hacking group, adding, “Israeli pride!” He also directed expletives at “0xOmar,” the hacker who exposed the Israeli credit card numbers.
s:http://www.jpost.com/NationalNews/Article.aspx?id=253181

2012 Best Computer Protection Software Comparisons and Reviews

Today, it isn’t uncommon for one person to own a smartphone, tablet, laptop and a desktop. These devices keep us constantly connected to the web, and they house our media collections, documents, files, software and other personal information. Because these computing devices contain so much of our personal lives, they have become prime targets for cybercriminals or virus. With identity theft ,cybercrime and virus affecting increasingly more people, it is crucial that you protect all your devices from virus so you can keep your personal information personal. To save yourself from virus, the hassle of finding a different application for each of your computing devices, sintuhack guide  about all-in-one computer protection software.
             All-in-one computer protection provides one license to protect all the devices you need to secure: computers, tablets and smartphones from virus and from cyber crimnal as well as from malware. Having similar antivirus computer security keeps a familiar and user-friendly interface consistent throughout all of your devices and offers a much larger selection of features and protection technology.
Why Buy All-in-One Computer Protection Software?
With identity theft and cybercrime and virus  affecting increasingly more people, it is crucial that you protect all your devices from virus ,malware so you can keep your personal information personal. To save yourself from virus ,malware the hassle of finding a different application for each of your computing devices

Many of the best all-in-one computer virus protection apps can provide security for Apple products such as MacBooks, iMacs, iPhones and iPads. Even though Apple devices are less susceptible to being infected with malicious malware, it is better to be safe than sorry. Plus, having strong protection on your Apple product keeps you from inadvertently passing dangerous threats to other devices.
All-in-One Computer Protection Software: What to Look For
When it comes to keeping all your computing devices and the data stored within them safe from virus ,malware, your average computer security software will not do. You need to find an all-in-one application that will cover the wide range of devices you own and additionally shield your data from any known or unknown threat from virus ,malware. Antivirus software is only as good as the protection it offers from virus ,malware.
Devices Protected
The best computer protection offers security for both your PC and Mac from virus ,malware. You can install the application on all of your mobile devices including your Android tablet, iPad, iPhone or other smartphone platform. However, even if the software says it supports a device, make sure it is compatible with the operating systems on all your devices and that it will work when you update or upgrade your operating systems.
Performance
No matter how many features are included on the application or how easy it is to use, if the security software does not protect your devices from dangerous threats, it is simply taking up valuable space. The best applications will protect all of your computing devices from viruses, worms, Trojans and spam. There should also be strong antispyware and antiphishing tools featured on the software to protect your device from intruders.
Features
The features included with antivirus software add to its protection and security. The ability to protect your device on a wireless network, along with email and website protection are a few features offered on the best applications. Online backup is also an excellent tool and allows you to keep your data safe if something were to happen to your device. In addition, anti-lost and anti-theft features are must-have tools for protecting any data or personal information you have stored on your smartphone.
Tags-virus,hacking,virus protection,virus security,antyvirus,computer security,virus security,virus and malware,malware security,virus kill,virus protection,virus protection tool.

Scare Tactics of Anti-Virus Company


We've all seen the messages pop up on our screen. "Malware detected!" "Your computer is infected!" "Download this software now or cybercriminals will invade your privacy, steal your identity and obliterate your soul!" These are the tactics of third-rate scams, designed to have you click on them and - ironically - install viruses and malware on your machine, but I've always wondered how somewhat "trusted" antivirus companies got away with using similar methods. A new lawsuit alleges Symantec's Norton Antivirus performs scans that don't actually scan your computer but still warn of non-existent dangers in order to get you to pay $29.99 to upgrade. Further, the plaintiff James Gross contends that even if you pay the fee, Symentec's applications don't really do anything to help your computer at all.
"The scareware does not conduct any actual diagnostic testing on the computer," reads Gross's complaint filed in Northern California. "Instead, Symantec intentionally designed its scareware to invariably report, in an extremely ominous manner, that harmful errors, privacy risks, and other computer problems exist on the user's PC, regardless of the real condition of the consumer's computer."
Gross said he bought the upgrade based on the prompt and afterwards hired IT experts to look at his machine. They told him that the scans almost always returned a negative report and that the software could not fix what it said it could. The complaint continues, "The scareware does not, and cannot, provide the benefits promised by Symantec. Accordingly, consumers are duped into purchasing software that does not function as advertised, and in fact, has very little (if any) utility."
sourse-forbes

Facebook Calling Hackers for open Competition for keeping world secure

Call it Mavericks for geeks. But instead of surfing waves, hackers from all over the world will get a chance to show off their creative programming skills at Facebook's third annual Hacker Cup, which starts with a 72-hour online qualification round later this month.
"It's really a chance to compete against the world's best programmers," Facebook spokesman Jonathan Thaw said.
Registration is now open for the contest, which starts Jan. 20 with the first of four online elimination rounds. For the finals, Facebook will fly the 25 highest-scoring hackers to California on March 16-17 for the last, two-hour competition at its Menlo Park campus.
"It's very intense," Thaw said. "You're working against the clock, trying to come up with an elegant and correct solution. It's a challenge."
The top prize winner gets $5,000 and bragging rights; the second and third place finalists get $2,000 and $1,000, respectively. In addition to the free trip and a behind-the-scenes tour of Facebook's headquarters -- including tech talks with company engineers and meals at its famed cafeteria -- the other 22 finalists will each get a crisp $100 bill.
How tough is the competition? Last year, 11,768 people from across the globe attempted the contest's first round of algorithmic coding challenges. The top 25 finalists -- all men -- came from China, Germany, Japan, the Netherlands, Poland, Russia, Switzerland, Ukraine and the United States. In the end, 26-year-old
Advertisement.Russian developer Petr Mitrichev was declared the world champ.
While Thaw said he expects some of 2011's finalists will try again for the title this year, the growing popularity of hacking will entice some newcomers as well."There are some programmers that basically do these sorts of competitions as a sport," he said. "But we'll likely see some new faces too. Every year, there's a new supply of talented programmers.".Facebook employees and their immediate family members and roommates are not eligible to enter, according to the contest rules. Thaw said he doesn't know whether any former competitors ended up with jobs at Facebook.
source=www.facebook.com/hackercup

ATM malware spreading around the world

IDG News Service - Cash machines around the world are hosting malware that can harvest a person's card details for use in fraud, a situation that could worsen as the malware becomes more sophisticated, according to a security researcher.Analysts at Trustwave's SpiderLabs research group were surprised earlier this year when it obtained the ATM malware sample from a financial institution in Eastern Europe, said Andrew Henwood, vice president of SpiderLabs's Europe, Middle East and Africa operation. Trustwave does forensic investigations for major credit card companies and financial institutions as well as penetration tests.
"It's the first time we have come across malware of this type," Henwood said..[malware]
The malware records the magnetic stripe information on the back of a card as well as the PIN (personal identification number)..[malware] That data can be printed out on the ATM's receipt roll when a special master card is inserted into the ATM that launches a user interface. It can also be recorded on the magnetic stripe of that master control card."We were surprised at the level of sophistication," Henwood said..[malware] "It does make us generally pretty nervous.[malware]."Most ATMs run security software, but financial institutions haven't focused on their security as much as other systems, Henwood said."ATMs were kind of an afterthought and were considered to be fairly stable," Henwood said. "I'd say there's not been enough focus in the past on ATM infrastructure."
Those who wrote the malware have detailed knowledge about how ATMs work, Henwood said. The sample they tested ran on ATMs using Microsoft's Windows XP operating system.[malware].[malware]
The sample did not have networking capabilities, but that may be a natural evolution. That's particularly dangerous since most ATM machines in developed countries are networked. The danger is that the malware could be engineered into a worm that, once on one ATM, spreads through all ATMs on a network, Henwood said.To install the malware, a person would need access to the inside of the ATM or a port in which software could be uploaded. That means insiders could be involved, or cybercriminals have picked a lock on an ATM in order to install the software, Henwood said.
taken from computerworld.
[malware].[malware].[malware].[malware].[malware]

Cyber espionage


Cyber spying or Cyber espionage is the act or practice of obtaining secrets without the permission of the holder of the information (personal, sensitive, proprietary or of classified nature), from individuals, competitors, rivals, groups, governments and enemies for personal, economic, political or military advantage using illegal exploitation methods on the Internet, networks or individual computers through the use of cracking techniques and malicious software including Trojan horses and spyware. It may wholly be perpetrated online from computer desks of professionals on bases in far away countries or may involve infiltration at home by computer trained conventional spies and moles or in other cases may be the criminal handiwork of amateur malicious hackers and software programmers.
Cyber spying typically involves the use of such illegally gained access to secrets and classified information or illegally gained control of individual computers or whole networks for an unethical and illegal strategic advantage and for psychological, political and physical subversion activities and sabotage. More recently, cyber spying invovles analysis of public activity on social networking sites like Facebook and Twitter

Cyber espionage Threat of 2012 computer security


Cyber espionage (also spelled cyberespionage) involves the unauthorized probing to test a target computer’s configuration or evaluate its system defenses, or the unauthorized viewing and copying of data files.
Cyber-espionage, along with privacy violations and social networking attacks facilitated by the increased use of mobile and tablet devices, will be the source of increased security threats over the coming months, according to PandaLabs.
Cyber-espionage targeting companies and government agencies around the world will dominate corporate and national information security landscapes, with the integrity of classified and other protected information on the line. Trojans are expected to be the weapon of choice for hackers focused on these highly-sensitive targets.
According to Luis Corrons, technical director of PandaLabs, "We live in a world where all information is in digital form and is easily accessible if you know how. Today's spies no longer need to infiltrate a building to steal information. As long as they have the necessary computer skills, they can wreak havoc and access even the best-kept secrets of organizations without ever leaving their homes."
Consumers will continue to be targeted by cyber-criminals as they find ever more sophisticated ways to target social media sites for stealing personal data. Social engineering techniques exploiting users' naivete have become the weapon of choice for hackers targeting personally-identifiable information.
"Social networking sites provide a space where users feel safe as they interact with friends and family. The problem is that attackers are creating malware that takes advantage of that false sense of security to spread their creations," says Corrons. "It is very easy for cyber-criminals to trick users with generic messages like 'Look, you're on this video,' for example. Sometimes, curiosity can be our own worst enemy."


 major security trends of 2012:
Mobile malware: A year ago, PandaLabs predicted a surge in cyber attacks on mobile phones, and the fact that Android has become the number one mobile target for cyber-crooks in 2011 confirms that prediction. That trend will continue in 2012, with a new focus on mobile payment methods using Near-Field Communications (NFC) as these applications become increasingly popular.
Malware for tablets: Since tablets share the same operating system as smartphones, they are likely be targeted by the same malware. In addition, tablets might draw a special interest from cyber-crooks since people are using them for an increasing number of activities and are more likely to store sensitive data.
Mac malware: As the market share of Mac users continues to grow, the number of threats will grow as well. Fortunately, Mac users are now more aware that they are not immune to malware attacks and are increasingly using antivirus programs to protect themselves. The number of malware specimens for Mac will continue to grow in 2012, although still at a slower rate than for PCs.
PC malware: PC malware has grown exponentially over the past few years, and everything indicates that the trend will continue in 2012. Trojans, designed to sit silently on users' computers, stealing information and transmitting it back to their handlers, will continue to be cyber-crooks' weapon of choice; 75 percent of new malware strains in 2011 were Trojans.
SMBs under attack: Financial institutions are fairly well protected these days against malware. But smaller businesses are easier and cheaper targets to attack, and their customer databases can be a real treasure trove for hackers, particularly if credit card and other financial data is stored "in the clear." Unfortunately, many small to medium-sized companies do not have dedicated security teams, which makes them much more vulnerable.
Windows 8: While not scheduled until November 2012, the anticipated next version of Microsoft's operating system will offer cyber-crooks new opportunities to create malicious software. Windows 8 will allow users to develop malware applications for virtually any device (PCs, tablets and smartphones) running this platform, although this will likely not take place until 2013.
             Taken From Internet

Facebook---Sexbook Virus

Facebook get affected by orkut Type Virus so dont click if any post seen like following snapshot on your wall.If you click then it will automaticatlly post that link to all of yours friends wall.!!!!!!






                                                          Happy facebooking but be safe!!!!!!!
                                                                                             www.sintuhack.com

Computer Operations Security


Operations security and controls safeguard information assets while the data is resident in the computer or otherwise directly associated with the computing environment. The controls address both software and hardware as well as such processes as change control and problem management. Physical controls are not included and may be required in addition to operations controls.
Operations security and controls can be considered the heart of information security because they control the way data is accessed and processed. No information security program is complete without a thoroughly considered set of controls designed to promote both adequate and reasonable levels of security. The operations controls should provide consistency across all applications and processes; however, the resulting program should be neither too excessive nor too repressive.
Resource protection, privileged-entity control, and hardware control are critical aspects of the operations controls. To understand this important security area, managers must first understand these three concepts. The following sections give a detailed description of them.


RESOURCE PROTECTION
Resource protection safeguards all of the organization’s computing resources from loss or compromise, including main storage, storage media (e.g., tape, disk, and optical devices), communications software and hardware, processing equipment, standalone computers, and printers. The method of protection used should not make working within the organization’s computing environment an onerous task, nor should it be so flexible that it cannot adequately control excesses. Ideally, it should obtain a balance between these extremes, as dictated by the organization’s specific needs.
This balance depends on two items. One is the value of the data, which may be stated in terms of intrinsic value or monetary value. Intrinsic value is determined by the data’s sensitivity — for example, health- and defense-related information have a high intrinsic value. The monetary value is the potential financial or physical losses that would occur should the data be violated.
The second item is the ongoing business need for the data, which is particularly relevant when continuous availability (i.e., round-the-clock processing) is required.
When a choice must be made between structuring communications to produce a user-friendly environment, in which it may be more difficult for the equipment to operate reliably, and ensuring that the equipment is better controlled but not as user friendly (emphasizing availability), control must take precedence. Ease of use serves no purpose if the more basic need for equipment availability is not considered.
Resource protection is designed to help reduce the possibility of damage that might result from unauthorized disclosure and alteration of data by limiting opportunities for misuse. Therefore, both the general user and the technician must meet the same basic standards against which all access to resources is applied.
A more recent aspect of the need for resource protection involves legal requirements to protect data. Laws surrounding the privacy and protection of data are rapidly becoming more restrictive. Increasingly, organizations that do not exercise due care in the handling and maintenance of data are likely to find themselves at risk of litigation. A consistent, well-understood user methodology for the protection of information resources is becoming more important to not only reduce information damage and limit opportunities for misuse but to reduce litigation risks.


Accountability
Access and use must be specific to an individual user at a particular moment in time; it must be possible to track access and use to that individual. Throughout the entire protection process, user access must be appropriately controlled and limited to prevent excess privileges and the opportunity for serious errors. Tracking must always be an important dimension of this control. At the conclusion of the entire cycle, violations occurring during access and data manipulation phases must be reported on a regular basis so that these security problems can be solved.
Activity must be tracked to specific individuals to determine accountability. Responsibility for all actions is an integral part of accountability; holding someone accountable without assigning responsibility is meaningless. Conversely, to assign responsibility without accountability makes it impossible to enforce responsibility. Therefore, any method for protecting resources requires both responsibility and accountability for all of the parties involved in developing, maintaining, and using processing resources.
An example of providing accountability and responsibility can be found in the way some organizations handle passwords. Users are taught that their passwords are to be stored in a secure location and not disclosed to anyone. In some organizations, first-time violators are reprimanded; if they continue to expose organizational information, however, penalties may be imposed, including dismissal.

Defense in depth...IT SECURITY


Information security must protect information throughout the life span of the information, from the initial creation of the information on through to the final disposal of the information. The information must be protected while in motion and while at rest. During its lifetime, information may pass through many different information processing systems and through many different parts of information processing systems. There are many different ways the information and information systems can be threatened. To fully protect the information during its lifetime, each component of the information processing system must have its own protection mechanisms. The building up, layering on and overlapping of security measures is called defense in depth. The strength of any system is no greater than its weakest link. Using a defence in depth strategy, should one defensive measure fail there are other defensive measures in place that continue to provide protection.
Recall the earlier discussion about administrative controls, logical controls, and physical controls. The three types of controls can be used to form the basis upon which to build a defense-in-depth strategy. With this approach, defense-in-depth can be conceptualized as three distinct layers or planes laid one on top of the other. Additional insight into defense-in- depth can be gained by thinking of it as forming the layers of an onion, with data at the core of the onion, people the next outer layer of the onion, and network security, host-based security and application security forming the outermost layers of the onion. Both perspectives are equally valid and each provides valuable insight into the implementation of a good defense-in-depth strategy.
Security classification for information
An important aspect of information security and risk management is recognizing the value of information and defining appropriate procedures and protection requirements for the information. Not all information is equal and so not all information requires the same degree of protection. This requires information to be assigned a security classification.
The first step in information classification is to identify a member of senior management as the owner of the particular information to be classified. Next, develop a classification policy. The policy should describe the different classification labels, define the criteria for information to be assigned a particular label, and list the required security controls for each classification.
Some factors that influence which classification information should be assigned include how much value that information has to the organization, how old the information is and whether or not the information has become obsolete. Laws and other regulatory requirements are also important considerations when classifying information.
The type of information security classification labels selected and used will depend on the nature of the organisation, with examples being:
In the business sector, labels such as: Public, Sensitive, Private, Confidential.
In the government sector, labels such as: Unclassified, Sensitive But Unclassified, Restricted, Confidential, Secret, Top Secret and their non-English equivalents.
In cross-sectoral formations, the Traffic Light Protocol, which consists of: White, Green, Amber and Red.
All employees in the organization, as well as business partners, must be trained on the classification schema and understand the required security controls and handling procedures for each classification. The classification of a particular information asset has been assigned should be reviewed periodically to ensure the classification is still appropriate for the information and to ensure the security controls required by the classification are in place.