Searchable Database of 1.4 Billion Stolen Credentials Found On Dark Web

YVRGeek shares a report from IT World Canada: A security vendor has discovered a huge list of easily searchable stolen credentials in cleartext on the dark web, which it fears could lead to a new wave of cyber attacks. Julio Casal, co-founder of identity threat intelligence provider 4iQ, which has offices in California and Spain, said in a Dec. 8 blog his firm found the database of 1.4 billion username and password pairs while scanning the dark web for stolen, leaked or lost data. He said the company has verified at least a group of credentials are legitimate. What is alarming is the file is what he calls “an aggregated, interactive database that allows for fast (one second response) searches and new breach imports.” For example, searching for “admin, ” “administrator” and “root” returned 226, 631 passwords of admin users in a few seconds. As a result, the database can help attackers automate account hijacking or account takeover. The dump file was 41GB in size and was found on December 5th in an underground community forum. The total amount of credentials is 1, 400, 553, 869. Read more of this story at Slashdot.

Original post:
Searchable Database of 1.4 Billion Stolen Credentials Found On Dark Web

Samsung Left Millions Vulnerable To Hackers Because It Forgot To Renew a Domain

An anonymous reader writes: Samsung cellphones used to have a stock app called S Suggest. The company apparently discontinued the app recently, and then forgot to renew a domain that was used to control it. This snafu left millions of smartphone users vulnerable to hackers who could’ve registered the domain and installed malicious apps on the phones. Read more of this story at Slashdot.

Originally posted here:
Samsung Left Millions Vulnerable To Hackers Because It Forgot To Renew a Domain

Reddit Brings Down North Korea’s Entire Internet

After a North Korean system administrator misconfigured its nameserver allowing anyone to query it and get the list of the domains that exist for .kp, it was revealed that the secretive country only has 28 websites. That’s 28 websites for a country with nearly 25 million people. Naturally, the story was published all across the web, including on Reddit, which resulted in a high number of users visiting North Korea’s websites. Mirror.co.uk reports: When a list of North Korea’s available websites was posted on Reddit, the surge of visitors to the reclusive state’s online offering overloaded the servers. North Korea runs a completely locked-down version of the internet that consists of only 28 “websites” that the population is allowed to view. However, a technical slip-up allowed a GitHub user to work their way into the country’s computer network and view the websites from the outside. As the GitHub user puts it: “One of North Korea’s top level name servers was accidentally configured to allow global [Domain Name System] transfers. This allows anyone who performs [a zone transfer request] to the country’s ns2.kptc.kp name server to get a copy of the nation’s top level DNS data.” Pretty soon, links to all the websites were posted on Reddit, where thousands of visitors took the opportunity to see what the web looks like from Pyongyang. Reddit’s surge of traffic isn’t the first time North Korea’s internet has been knocked out. In 2014, the country suffered a distributed denial of service (DDoS) attack that was believed to have originated from the U.S. Redditor BaconBakin points out that while North Korea has 28 websites, GTA V has 83 websites. They added, “I think it’s safe to say that San Andreas is more technologically advanced than North Korea.” Read more of this story at Slashdot.

Read More:
Reddit Brings Down North Korea’s Entire Internet

GoDaddy Proposes New DNS Configuration Standard

GoDaddy has announced “an open set of APIs for DNS providers and web service providers, ” called Domain Connect. An anonymous Slashdot reader writes: “Once enabled, customers can quickly configure their domain to point to the web service of their choice with push button simplicity, ” according to the announcement, “streamlining and simplifying the process of connecting websites and domain names registered on different platforms.” GoDaddy’s submitted it for consideration as an IETF standard, where they have the support of Microsoft and Squarespace, as well as the other two largest registries, eNome and Name.com. But in the meantime, they told ProgrammableWeb, the specificaion is “out there in the public, open for feedback and adjustment.” “GoDaddy is seeking to take all the friction out of the process, ” the site reports, “by offering service providers like Squarepace, Wix, Google, Microsoft, WordPress and others a registrar-agnostic API that they can use to programmatically configure all the necessary DNS entries… in lieu of making end users laboriously crawl through a bunch of forms and then praying that they’ve done it all correctly.” Different access levels will be available based on the service being provided, and for GoDaddy’s implementation of the API their senior VP of Domains Engineering “said that the program will not be open to public developers and that any service providers wanting access will have to be approved by his team at GoDaddy.” Read more of this story at Slashdot.

Continued here:
GoDaddy Proposes New DNS Configuration Standard

After Years of Serving X11, X.Org Stands To Lose Its One-Letter Domain

An anonymous reader writes: The X.Org domain predates the X.Org Foundation. It was used in the ’90s as a destination by The Open Group around the X Window System. While many are expecting Mir and Wayland to eventually succeed the X.Org Server, it seems the X.Org/X11 Server may outlive the valuable domain. Thanks to poor management by the X.Org Foundation, they risk losing access to their one-letter domain. Procrastination, paired with not transferring the domain when forming the non-profit foundation, has led to a last-minute mess. They left the domain registered for years to a person who is no longer involved with X.Org — and doesn’t want to relinquish it. In the few days until the domain expires, they are hoping for a “Hail Mary.” Let this be a lesson for open-source projects to better manage their assets. Read more of this story at Slashdot.

See the original article here:
After Years of Serving X11, X.Org Stands To Lose Its One-Letter Domain

Copyright Holders Asked Google to Remove 345 Million Links Last Year 

Copyright holders were not shy about asking Google to remove pirated content in 2014. Last year, there were over 345 million requests to take down infringing content, according to a Torrent Freak summary of Google’s weekly transparency reports . That’s a 75 percent increase from 2013. Google honored most of the requests. Read more…

Read More:
Copyright Holders Asked Google to Remove 345 Million Links Last Year 

New York Judge OKs Warrant To Search Entire Gmail Account

jfruh writes While several U.S. judges have refused overly broad warrants that sought to grant police access to a suspects complete Gmail account, a federal judge in New York State OK’d such an order this week. Judge Gabriel W. Gorenstein argued that a search of this type was no more invasive than the long-established practice of granting a warrant to copy and search the entire contents of a hard drive, and that alternatives, like asking Google employees to locate messages based on narrowly tailored criteria, risked excluding information that trained investigators could locate. Read more of this story at Slashdot.

View original post here:
New York Judge OKs Warrant To Search Entire Gmail Account

Chinese Hackers Infiltrate Firms Using Malware-Laden Handheld Scanners

wiredmikey (1824622) writes “China-based threat actors are using sophisticated malware installed on handheld scanners to target shipping and logistics organizations from all over the world. According to security firm TrapX, the attack begins at a Chinese company that provides hardware and software for handheld scanners used by shipping and logistics firms worldwide to inventory the items they’re handling. The Chinese manufacturer installs the malware on the Windows XP operating systems embedded in the devices. Experts determined that the threat group targets servers storing corporate financial data, customer data and other sensitive information. A second payload downloaded by the malware then establishes a sophisticated C&C on the company’s finance servers, enabling the attackers to exfiltrate the information they’re after. The malware used by the Zombie Zero attackers is highly sophisticated and polymorphic, the researchers said. In one attack they observed, 16 of the 48 scanners used by the victim were infected, and the malware managed to penetrate the targeted organization’s defenses and gain access to servers on the corporate network. Interestingly, the C&C is located at the Lanxiang Vocational School, an educational institution said to be involved in the Operation Aurora attacks against Google, and which is physically located only one block away from the scanner manufacturer, TrapX said.” Read more of this story at Slashdot.

Taken from:
Chinese Hackers Infiltrate Firms Using Malware-Laden Handheld Scanners

Cheap Laser-Sintering Printers Are Coming Thanks To The Expiration Of A Key Patent

Today is a big day for 3D printing: Patent #US5597589 is set to expire and will open up the possibility for makers to use laser sintering — shooting a laser at a layer of nylon powder — in cheaper devices, essentially opening the technology to the small maker. The patent is fairly clear on what sintering is. It describes an “apparatus for selectively sintering a layer of powder to produce a part made from a plurality of sintered layers and the apparatus includes a computer controlling a laser to direct the laser energy onto the powder to produce a sintered mass.” This means anything that shoots a laser at powder could run afoul of this patent much as Form Labs bumped up against 3D Systems’ stereolithography patent. Most larger “professional-quality” printers use laser sintering and you can create homogenous, solid-looking objects with stable structures using the technique. Does this mean we’ll have sintering printers in our homes next year? Possibly, but given the materials needed and the components involved I could see prices going down but not dropping until there is mass acceptance of 3D printing. FDM printers that deposit layers of plastic is still the cheapest method, but sintered parts are almost seamless, creating a cohesive whole that is very useful in prototyping and engineering. In short, however, it’s a great day for makers. via 3Dprint

View post:
Cheap Laser-Sintering Printers Are Coming Thanks To The Expiration Of A Key Patent

New high-res maps of Earth’s surprisingly inconsistent gravity field

Though it seems hard to believe, Earth’s gravitational pull is not the same everywhere you go. And as these gorgeously detailed maps now show, these variances are much greater than we thought. Read more…        

Link:
New high-res maps of Earth’s surprisingly inconsistent gravity field