It’s shockingly easy to hijack a Samsung SmartCam camera

Enlarge Smart cameras marketed under the Samsung brand name are vulnerable to attacks that allow hackers to gain full control, a status that allows the viewing of what are supposed to be private video feeds, researchers said. The remote code-execution vulnerability has been confirmed in the Samsung SmartCam SNH-1011, but the researchers said they suspect other models in the same product line are also susceptible. The flaw allows attackers to inject commands into a Web interface built into the devices. The bug resides in PHP code responsible for updating a video monitoring system known as iWatch. It stems from the failure to properly filter malicious input included in the name of uploaded files. As a result, attackers who know the IP address of a vulnerable camera can exploit the vulnerability to inject commands that are executed with unfettered root privileges. “The iWatch Install.php vulnerability can be exploited by crafting a special filename which is then stored within a tar command passed to a php system() call,” the researchers wrote in a blog post published to the Exploitee.rs website. “Because the webserver runs as root, the filename is user supplied, and the input is used without sanitization, we are able to inject our own commands within the achieve root remote command execution.” Read 5 remaining paragraphs | Comments

Read more here:
It’s shockingly easy to hijack a Samsung SmartCam camera

Windows is getting its own built-in book store in the Creators Update

Enlarge (credit: MSPoweruser ) The Windows Store—which already includes apps, games, movies, and TV shows—is going to include books in the Creators Update. This is according to pictures obtained by MSPoweruser . Based on images from an internal Windows 10 Mobile build, books will have their own dedicated section within the Store. The whole process will work much the same way as it does for any other purchase. It appears that Microsoft is not building a dedicated reading application for these purchases. Instead, the Edge browser in the Creators Update has been updated to include support for EPUB books, affording some customization of their appearance in the browser’s reading mode. This isn’t Microsoft’s first foray into the electronic book world. Long, long ago it had an app called Reader, which supported a proprietary HTML-based format. Reader was developed for Pocket PC and Windows Mobile, and notably, it was in Reader that Microsoft first used ClearType sub-pixel anti-aliasing. A Reader app was also available for desktop Windows, though not Windows Phone. The company even had its own online catalog of e-books using its proprietary format, which linked to third-party sites actually selling the books. Read 2 remaining paragraphs | Comments

View article:
Windows is getting its own built-in book store in the Creators Update

Obama pardons Stuxnet leak source James Cartwright

Chelsea Manning isn’t the only source of online leaks to get a new lease on life. President Obama has pardoned General James Cartwright, who pleaded guilty to lying to the FBI when it investigated leaks that revealed details of Stuxnet , the US-backed malware that sabotaged Iran’s nuclear program . He had denied slipping out classified details to two New York Times reporters (including book author David Sanger) in a 2012 interview with the Bureau, only to be caught out later on. He had been facing up to 5 years in prison and was due to be sentenced the same day as the pardon. At the moment, it’s not certain why Cartwright is receiving the pardon. He was the Vice Chairman of the Joint Chiefs of Staff from his nomination in 2007 through to his retirement from Marine Corps service in 2011, but he wasn’t Obama’s golden boy. Cartwright was denied the top Chairman spot in 2011 in part because of questions surrounding his staff management practices, including an alleged (though never punished) “unduly familiar relationship” with a female Captain. One theory is that the outgoing White House administration wants to put a lid on discussion of Stuxnet. The Washington Post claimed that the investigation into Cartwright ran aground when officials realized they might have to confirm details of the malware in order to secure a conviction. That would have been particularly problematic at the time, when the US was negotiating the eventual Iranian nuclear shutdown agreement — did it really want to admit to a cyberattack at such a critical moment? We wouldn’t rule out any motivations at this point, but the guilty plea and pardon might spare the government from disclosing secrets. Via: Charlie Savage (Twitter) Source: White House

More:
Obama pardons Stuxnet leak source James Cartwright

Check Out the Evolution of the US Dollar Bill

The US one dollar bill is still old school. In fact, it has the oldest design of all US currency being produced today. So that means it doesn’t have the flashy tech, or the colorful hues, or the wild looks that have leaked into the redesigns of the more valuable banknotes. But that doesn’t mean it hasn’t changed. Just… Read more…

Read the original:
Check Out the Evolution of the US Dollar Bill

For-Profit College Says Former Admin Demanded $200,000 to Reset School Password

According to a lawsuit by the online American College of Education (ACE), a former employee effectively held the company’s email system hostage after he was fired last spring, locking the for-profit college out and asking for $200, 000 before he would help it get back in. Read more…

Read more here:
For-Profit College Says Former Admin Demanded $200,000 to Reset School Password

The US Army successfully flies its hoverbike prototype

The Army has proven that the hoverbike its contractors are developing actually works during a flight demo with the Department of Defense. Dr. William Roper, director of the Strategic Capabilities Office for the Secretary of Defense, watched the large rectangular prototype quadcopter take off at the Aberdeen Proving Ground in Maryland on January 10th. The hoverbike began as a Kickstarter project by creator Malloy Aeronautics. Once Malloy secured a contract with the military, it teamed up with defense company Survice Engineering Co. to continue the bike’s development. It has since become a joint project between the Army and the US Marine Corps. Officially known as Joint Tactical Aerial Resupply Vehicle, or JTARV, the hoverbike could someday be used to carry supplies to soldiers on the field. Tim Vong, associate chief of the Army Research Lab’s Protection Division, said it’s like having “Amazon on the battlefield, ” since it’ll allow the military to deliver resupplies in less than 30 minutes. It’ll take some time before the military deploys JTARV, though. To start with, its developers are looking to make a hybrid propulsion system to give it a longer range (up to 125 miles) than it has today as an electric-powered prototype. Further, they want to increase the payload it can carry to 800 pounds, as well as to load it with an advanced navigation system and mission planning. Vong says they’re looking to “end up with a modular, stable platform that can be used for even more dynamic and challenging missions.” Source: US Army

Continue reading here:
The US Army successfully flies its hoverbike prototype

It Only Costs $400 to Build Your Own Cell Phone Network

Sometimes, owning a smartphone feels pricy. There’s the hefty chunk of change you’ll need to spend on the phone itself, and then the monthly fee you’ll need to fork over to operate it. But for just $400 and the cost of a few old Zack Morris-style brick phones, you can avoid those expenses and build your own damn 1G… Read more…

See the original post:
It Only Costs $400 to Build Your Own Cell Phone Network

The CIA Just Dumped 12 Million Declassified Documents Online

After years of fighting with FOIA requesters, the CIA has finally uploaded over 12 million documents to its website . While many of the documents have been declassified for some time, the pages were intentionally hard to access, and only available on a few computers sitting at the National Archives. But now, anyone can… Read more…

Originally posted here:
The CIA Just Dumped 12 Million Declassified Documents Online

AT&T no longer works with your 2G phone

We hope you weren’t planning to use your old-school iPhone or BlackBerry Pearl on AT&T’s network for nostalgia’s sake — unfortunately, you’re not going to get anywhere. As promised way back in 2012 , the carrier has confirmed that it shut down 2G services on January 1st, 2017. If your phone only makes GSM calls and uses EDGE for data, you’re stuck. The move won’t hurt very many people (even basic phones have been using 3G and LTE for years), but it’s hard not to shed a little tear for a technology that had been around for so long. As it stands, you probably won’t mind much given what AT&T has in store. It’ll repurpose that newly freed spectrum for LTE, and the move will ultimately create more headroom for 5G wireless . Just as with the end to analog cell service , the small sacrifice you make now will likely pay much larger dividends down the road. The shutdown is also a reminder of just how far mobile data has come since 2G hit the scene (in the US, at the turn of the millennium). EDGE was considered fine at a time when any mobile data was a relative novelty, and the most you did with it was check email or surf the most basic of websites. Now, even a modestly-sized app or photo download would absolutely crush 2G — the modern mobile internet depends on speeds that are orders of magnitude faster. We can only imagine what it’ll be like when 3G bites the dust and LTE is considered the baseline. Via: The Verge Source: AT&T

Read the original:
AT&T no longer works with your 2G phone