Mostrando postagens com marcador Telegram. Mostrar todas as postagens
Mostrando postagens com marcador Telegram. Mostrar todas as postagens

sábado, 15 de junho de 2019

Telegram Sofre Poderoso Ataque DDoS Da China Durante Protestos De Hong Kong

Por Mohit Kumar em 13/06/19 no site The Hacker News

ataque de ddos ​​de telegrama de protesto de hong kong



O Telegram, um dos mais populares aplicativos de mensagens criptografadas, ficou brevemente offline ontem para centenas de milhares de usuários em todo o mundo depois que um poderoso ataque de negação de serviço distribuído (DDoS) atingiu seus servidores.


O fundador do telegrama, Pavel Durov, revelou mais tarde que o ataque estava principalmente vindo dos endereços IP localizados na China, sugerindo que o governo chinês poderia estar por trás disso para sabotar os manifestantes de Hong Kong.


Desde a semana passada, milhões de pessoas em Hong Kong estão lutando contra seus líderes políticos por causa das emendas propostas a uma lei de extradição que permitiria que uma pessoa detida em Hong Kong fosse julgada em outro lugar, inclusive na China continental.


Muitas pessoas a veem como uma ameaça fundamental às liberdades cívicas do território e ao estado de direito.


hong kong protest china extradição

Muitas pessoas em Hong Kong estão atualmente usando o serviço de mensagens criptografadas do Telegram para se comunicar sem serem espionadas, organizar o protesto e alertar umas às outras sobre as atividades no local.


De acordo com a Telegram, a empresa recebeu " GADZILLIONS de pedidos de lixo " que impedem seus servidores de processar solicitações legítimas, e o ataque "tamanho de ator de estado" foi rastreado até os endereços IP na China.


"Endereços IP vindos principalmente da China. Historicamente, todos os DDoS do tamanho de atores estaduais (200-400 Gb / s de lixo) que nós experimentamos coincidiram no tempo com protestos em Hong Kong (coordenados em @ telegram). Este caso não foi uma exceção, "O fundador do telegrama, Pavel Durov, twittou .


Embora seja evidente que um ataque DDoS não tenha nada a ver com a segurança dos dados armazenados nos servidores de destino; em vez disso, pretende levar um serviço offline, a empresa ainda garantiu que os dados do usuário são seguros.


No entanto, não é a primeira vez que o serviço Telegram é usado com força usando um ataque DDoS durante a agitação política para perturbar os ativistas.

sábado, 13 de janeiro de 2018

Malware infected fake Telegram Messenger app found in Play Store

por Wagas em 12/01/2018 no site HackRead


The Google Play Store is home to more than 3.5 million apps but at the same time, there are tons of apps that are malicious and infected with adware or some kind of malware targeting users who download them believing that Google is handling their security the same way it does with other platforms.
But the reality is far from the truth as the IT security researchers at Symantec have identified the presence of a fake Telegram Messenger app in Google Play Store that is, in reality, a malicious app infecting Android devices with malware and spamming them with ads.
The fake app is called “Teligram [New version updated]” in which attackers have replaced the letter “e” with “i” and changed its theme color from blue to black hoping that unsuspecting users will ignore the difference and tricked into downloading the malicious app.
Malware infected fake Telegram Messenger app found on Play Store
The difference is obvious (Credit: Symantec Via: PlayStore)
To make it a sophisticated scam, the fake app even functions as an instant messaging app, however, at the same time it contains advertisement libraries that spam users with ads to make money. Moreover, Symantec researchers have noted that the malware (Trojan.Gen.2) which Teligram installs on Android devices is built using the open source Telegram code, which is distributed to third-party app stores.

According to John Hou of Symantec’s Threat Intelligence, “While open source projects can be of huge benefit to developers and consumers, they can also be used by criminals to create convincing imitations of trusted apps.”
Furthermore, once the app is installed it executes the malware that ends up installing an ad clicker or a backdoor. Hou believes the main motive of this malware is to make money rather than stealing personal data from users however it is possible that attackers behind this scam can add features that may steal user data and perform other malicious activities in the future.
Malware infected fake Telegram Messenger app found on Play Store
Spamming devices with ads (Credit: Symantec)
At the time of publishing this article, Teligram app was booted off from Play Store.
Remember, hackers are becoming sophisticated in their attacks. On January 11th, Trend Micro researchers discovered first ever malware app in Play Store written Kotlin languageKotlin is used in writing Android apps and being used by prominent apps including Pinterest, Netflix, and Twitter.
Android users are advised to be vigilant, avoid downloading unnecessary apps and in case you are downloading APK files from a third party store make sure to scan it with an updated security software before installing it on your device.

sexta-feira, 14 de julho de 2017

Katyusha Scanner — Telegram-based Fully Automated SQL Injection Tool



sql-injection-tool-telegram
A new powerful hacking tool recently introduced in an underground forum is making rounds these days, allowing anyone to rapidly conduct website scans for SQL injection flaws on a massive scale — all controlled from a smartphone using the Telegram messaging application.


Dubbed Katyusha Scanner, the fully automated powerful SQLi vulnerability scanner was first surfaced in April this year when a Russian-speaking individual published it on a popular hacking forum.


Researchers at Recorded Future's Insikt Group threat intelligence division found this tool for sale on an underground hacking forum for just $500. Users can even rent the Katyusha Scanner tool for $200.

According to the researchers, Katyusha Scanner is a web-based tool that's a combination of Arachni Scanner and a basic SQL Injection exploitation tool that allows users to automatically identify SQLi vulnerable sites and then exploits it to take over its databases.


Arachni is an open source vulnerability scanning tool aimed towards helping users evaluate the security of their web applications.


What makes this tool stand out of line is its 'Infrastructure-as-a-Service' model.


Remotely Control Hacking Tool Via Telegram

sql-injection-tool
Katyusha Scanner is abusing the Telegram messaging application to control its operations, such as sending and receiving commands.


The Katyusha Scanner tool is quite easy to setup and use, allowing anyone to conduct large-scale penetration attacks against a large number of targeted websites simultaneously with the mere use of their smartphones.


The Pro version of the tool not just identifies vulnerable websites, but also allows hackers to establish a "strong foothold within vulnerable web servers" and automatically extract "privileged information such as login credentials."

Once the scan is complete, Katyusha Scanner sends a text message to the criminals with the vulnerable site name, its Alexa web ratings, helping criminals identify popular websites that would likely be more profitable for them to attack, and the number of databases.


The criminals, even with no technical knowledge, can download any exfiltrated data available by just clicking on their smartphones to issue commands.


Katyusha Scanner also allows for the automatic dumping of databases and can be used on both Linux as well as Windows machines.

"The availability of a highly robust and inexpensive tool...Katyusha Scanner to online criminals with limited technical skills will only intensify the compromised data problem experienced by various businesses, highlighting the importance of regular infrastructure security audits," researchers at Recorded Future wrote.
Many buyers praised the quality of the tool on the black market site, one of the satisfied customers who got immediate success in obtaining access to eight web servers wrote:

"Excellent support! The seller has configured the software for my server, which was failing before, however, right now it flies divinely! I highly recommend the software, and it has found eight SQL vulnerabilities in half a day, great automation of the routine. Very grateful to the seller."
Another wrote: "The author has helped with the product setup after the purchase, and (Katyusha) has immediately found SQL vulnerability. Thank you for the great product."


Initially, Katyusha Scanner was sold for $500, but due to unexpectedly high demand, a light version of the tool with slightly limited functionality was released on May 10, 2017, at just $250.


With the release of the most recent Katyusha 0.8 Pro update at the end of June, the author also made the scanner available for rent at $200 per month for the first time.