How-to-Hack HackingTeam

A great write-up¹ of how the HackingTeam and more were hacked (I recommend that you download it as it may likely be gone soon enough) – 04/19. Let’s do a quick review of his (antisec)  document and remind you that the Italian Company name is http://www.hackingteam.it/ Some enterprising media or bloggers have changed the name to … Read more

Twilight Zone Friday – April15th

What is the worst nightmare of IT admins and users alike? Losing your data  – with no backup. So what did we learn? Sometimes it is not a hacker with some mechanism to get you to fork over money…In the following story some people are setting their phones to 1970, for which the phone or … Read more

All Ur Data Belong to US

IRS tax time — April 15th right?? Actually employers have to do taxes year-round and the “sophisticated” nature of the IRS causes them to issue 4 or 6 digit PIN numbers. Well the hackers know this so they buy some of your stolen data (from previous heists) on the Darknet¹&². Now hackers have some of your … Read more

Apache Jetspeed-2 Easy Hack & Exploit

Haxx.ml has the story¹ This is one of those moments where the latest version of the program(Jetspeed 2.3.0) is hackable using a SQL injection method from CVE-2016-0710. It behooves us to review CVE-2016-0710: “The Jetspeed User Manager service, part of the Jetspeed Administrative Portlets, is vulnerable to SQL injection. When performing a search in these tools, … Read more