Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

How hackers hack your facebook account

Facebook is, undoubtedly, the most popular social networking website with more than 500 million active users. Due to its popularity, many hackers (or should I say crackers?) are actively involved in hacking Facebook accounts of unsuspecting users. This article outlines the many strategies that such hackers use to gain access to Facebook accounts of hundreds of users each day and how you can stop them from hacking your account.

hacker facebook email address hack

Email Address Hack

I have always been puzzled by Facebook's leniency in this matter. All a hacker needs to do is know your name and he will be conveniently shown your email address at your profile. How easily a hacker can then hack your Facebook account (and everything else associated with that email id) if he 'guesses' your password (if you use a weak password) or answers your security question! This is something I hope Facebook improves on quickly. Until Facebook does so, here are some tricks you can use to protect yourself from this vulnerability.

How to safeguard your Email Address?

Just follow these steps:-

Hide your Email Address from everyone by going to Edit Profile>Contact Information>Clicking on the icon beside your email address> checking 'Only Me'.
Change your primary email address to a one that is only known to you by going to Account Settings>Email> and changing your primary email to the new one (known only to you) and removing your previous email address.
For additional security, when in Account Settings, check 'Secure browsing' and 'Send me an email when a new computer or mobile device logs into this account' and click Save.


Phishing

Phishing is one of the easiest ways to trick users into giving out their login credentials. All a hacker does is set up a webpage similar in design to that of the Facebook homepage, attach a server sided script to track the username and password entered and store it in a log. Sending people emails stating that someone tagged a photo of them on Facebook in the same format as Facebook and giving a link below to the phishing website further reduces the chances of it being detected as a fake. Sometimes, spam Facebook apps, like those promising to tell who viewed your Facebook profile, automatically post links to phishing websites. A new trend amongst phishers is creating Facebook look-a-like widgets for stealing user's login credentials.

How to prevent yourself from being phished?
At all costs, avoid clicking on suspicious links. Moreover, always check the URL in the address bar before signing in. Avoid logging in through various "Facebook widgets" offered by websites and blogs. Instead, use Facebook's homepage to sign in. Always try to use Safe Search while searching. If you do manage to get phished, report the website so that others may get a warning before visiting it.

Keylogging through Keyloggers


Keylogger is a type of computer virus that tracks keystrokes. Keyloggers can be installed remotely on a computer system by a cracker to record all the activity that is going on the victim's computer. Keylogging gets more easy if the hacker has physical access to the victim's computer.

How to stop keyloggers?
Install a good antivirus and update it frequently. Do not click on suspicious links and avoid downloading illegal software. Also, avoid installing free toolbars and other such spam software. Always scan third-person's flash and pen drives before using them on your computer.

Social Engineering


Social engineering involves using any trick to fool the user into making himself vulnerable to exploits. This could involve anything from sending spoof emails, pretending to be from Facebook, telling you to change your password to 12345678 to a hacker maliciously getting out the answer to your security question in a friendly chat or discussion.

How to prevent yourself from being socially engineered?
Stay aware during chats and discussions. Use a tough security question, preferably one whose answer you would never disclose to anyone. Moreover, Facebook, or any other company for that matter, will never ask you to change your password to 12345678 or do something as silly as asking you to send out your login details to prove that you are an active user. Always think before taking actions and your e-life on Facebook will be safe from hackers looking to hack Facebook accounts.

The Story of Kali Linux


If you've ever tried to crack Wi-FI passwords or test for security vulnerabilitieson your network, then you're likely familiar with Kali Linux. It's a security-focused version of Linux that offers a multitude of tools to seek out weaknesses and secure your network.
It began out of necessity for lead Kali developer Mati Aharoni (known as muts in the community). While doing professional security work he needed a variety of security tools without being able to install any software on his client's systems, and so he took to Linux. We spoke with Mati to learn more about how it started and how the community-driven project has grown and evolved over the years into one of the leading security-focused Linux distributions.

Where did the idea for Kali come from? Were you trying to solve a problem you'd experienced, or did the inspiration come from somewhere else?

Mati Aharoni: The idea for a Live Linux distribution which contains a bunch of security tools was born out of necessity many years ago, when I faced a perplexing dilemma on a security engagement. I was not allowed to bring any hardware to the engagement—and what's more, I was only allowed to use onsite computers on the condition that I would not touch their hard disks or modify them in any way. (I actually was allowed to bring a laptop onsite, however it would be taken on exit).
After thinking long and hard, I figured that these seemingly impossible work conditions could be met by adding a few tools to an existing bootable Live Linux CD (Knoppix 2.0, to those familiar with ancient history). Once created, I would be able to bring in the CD to the engagement, boot an onsite computer with the CD, and work directly out of RAM. At the end of the engagement, I would be able to destroy the CD without too much heart-ache. And so I started a Linux Security based Distribution, ten years ago!

After you came up with the idea, what was the next step?

I will take the liberty to apply this question to our recently released Kali Linux distribution, the 3rd iteration of the Matrix.
Kali Linux was born out of our understanding that we need to take our eight years of experience in building Linux Security Distributions and apply them to a new, clean canvas. This meant tearing down everything we had done to that point, and starting afresh. This process was both terrifying and liberating—on one hand we had let go of our beloved BackTrack distribution, but on the other, we had the opportunity to rebuild and expand our current systems to create something better.
Once this hard decision was made, we figured that the next step should involve people who actually know what they are doing, and we brought in a Debian developer who helped us build our development infrastructure from the ground up. His assistance proved to be invaluable to our project and crucial to the success of the distribution.

How did you choose which platforms to target and which to ignore or wait on?

I'll answer this in regards to our Kali Linux ARM images.
One of our goals with Kali is to provide images of the operating system for all sorts of exotic hardware—mainly ARM based. This includes everything from Raspberry Pi's to tablets, to Android TV devices, with each piece of hardware having some unique property. For example, the MK808 has a dual-core CPU with a whopping 1GB of RAM, while having the form factor of a medium-sized USB dongle. Imagine that: a powerful hacking computer, battery-powered, in your pocket.
So how do we decide what type of ARM hardware to target ? That depends on several things—availability being the main obstacle. We try to identify interesting hardware that could be used in interesting ways for security assessments—and if such is found, we try to build Kali for it. By now, we have a wide array of hardware supported by Kali, and this list keeps on growing every month.

What was your biggest roadblock and how did you overcome it?

One of our biggest concerns with the move from BackTrack to Kali was the rebranding we had to do. After so many years of being a major force in the security community, "BackTrack" was known by all. To suddenly change this around would undoubtedly be hectic and confusing for our users. I thought long and hard at other major rebranding feats in the open source world, and thought to myself, "Didn't Wireshark rebrand a few years ago? What was their name beforehand?" After having to think for two long minutes before coming to the right answer, I figured that rebranding would be tough, but not impossible.

What was launch like for you?

The launch of Kali Linux went better than we could ever have hoped for. We had good friends to support the effort, and a proper infrastructure to support the mind-boggling amounts of traffic required to allow the gazillion downloads we experienced in the first few days.
We had the good sense to create a knowledge source before the release, as well as some community outlets like forums and a bug tracker.

How do you handle user requests and criticisms effectively?

Over the years we have become much more patient with opinionated users and criticism at large. I think we've learned that sometimes a seemingly silly bug report can actually be a symptom of a serious underlying problem. Treating all of these reports with the respect they deserve is something we are getting better and better at as time goes by.

Now, how do you split time between developing new features and managing existing ones?

In Kali, this question can be applied to the tools and features we provide in our distribution. We don't have a specific methodology for this. If we see a useful security tool, or a relevant security feature we think may be useful, we simply add it. A good example for this was the LUKS NUKE feature in Kali, which allows the user to "self destruct" their hard drive.

What advice would you give to others that want to take on a similar project?

In the world of Unix-derived operating systems, we all stand on the shoulders of giants. Going back to the original Berkeley source, to the initial Linux kernel, to the GNU toolset, to the modern Debian distribution, in all cases every Linux distribution is a true community effort. The biggest advice I would have is "don't be afraid to leverage existing infrastructure where possible." Why recreate the wheel unless you have to, especially when you can take an existing one and simply modify it for your purposes.

Facebook and Netflix reset passwords after data breaches




With vast swathes of data being sold on the dark web in recent weeks following high-profile 
breaches, many sites are encouraging users to change their passwords, even if they weren't directly affected.


Facebook and Netflix appear to be taking this a step further with reports a number of users are being forced to update their credentials.

According to security researcher Graham Cruelly, Facebook users are being shown a warning message that reads: "Recently, there was a security incident on another website unrelated to Facebook. Facebook was not directly affected by the incident but your Facebook account is at risk because you were using the same password in both places."

It then goes on to say that to secure their account, the user will need to answer security questions and change their password. It also adds: "For your protection, no one can see you on Facebook until you finish."

By comparison, Netflix is emailing members claiming: "We believe that your Netflix account credentials may have been included in a recent release of email addresses and passwords from an older breach at another company. Just to be safe, we’ve reset your password as a precautionary measure."


Neither Facebook, nor Netflix, are saying they have been hacked or suffered data breaches and the other website referred to is likely to be LinkedIn.

In 2012, a rumoured 167 million account details were stolen from LinkedIn. Initially the data was being sold on the dark web for five bitcoin, this amounts to around $2,200 (£1,500). It has since dropped in price and is at around half of this value.


Facebook and Netflix are being cautious because many people - including Facebook's own Mark Zuckerberg it transpired earlier this week - use the same passwords on multiple accounts.

Security blogger Brian Krebs was sent one of the Netflix emails, and he said he believes more sites may follow suit in the coming weeks.

Experts are advising people change their passwords on their accounts, or make each password unique, to protect themselves. They should also enable two-factor authentication where available.

how hackers hack sites (the stages that they follow)

how hackers hack sites

Phase I: Reconnaissance.

It is the stage where hackers gather information and sufficient data to hack began the process, beginning with the IP Adress, and information about Hosting reliable target site. And also programming languages ​​and the quality of supported database at the site, and other information that can be accessed by following some of the roads only Balmokhtrgin himself, and whenever collect more information on the target site, whenever they hack easier and faster process, and vice versa!

        Phase II: Scanning & Enumeration

 At this stage, hackers start to look for gaps or ports that can be exploited to initiate the process of penetration, the more the site is protected and free from vulnerabilities, the more difficult it hackers Implementation This phase, which is considered a sensitive and fateful, Laket that if he could not find any loophole you will not be able to pass to the other advanced stages of the piece he employs all its capabilities and skills to gain access to one of the gaps in the security system will employ the website target regardless of its importance this gap.

      Phase III: Gaining Access.

After the completion of the scanning process successfully and discover the largest possible number of gaps in the target site, hackers at this stage trying to access the control interface for the site, so it becomes has some powers that enable him to check out some of the sensitive data of the site, and no requirement at this stage to reach to the powers of the administration, you as much as they care about the transition from being a regular user of the site to the stage of a person controlled to some extent by!

      Stage IV: Maintaining Access!

Now after he had managed to enter the site and controlled to some extent by and access to its database, in various ways trying to hackers at this stage to build a link or several of its own links can which later access interface for the site to control the spectrum in the case of what has been discovered that gap by site managers and downloaded bridging or in the case of what has been discovered is a breakthrough for the site by these managers, because the piece is rushing to do this step so as not to waste his effort in vain and can later easily enter the site, which has breaking through in spite of bridging that gap officials from party site, called the control program upon which hackers in these client b Shell.

      The last stage: Covering Tracks.

Managers of large sites, which are heavily exposed to penetrate, they periodically checks the activities that occur on the site by users, therefore, if we detect suspicious activity or raises doubts it inevitably increases the procedures and security precautions by them, and also they can in state whether they discovered that someone had infiltrated the site, they will punished for the attack in some way, or at least prevented the possibility of renewed access to the interface for the site and a high price what they fail to control this in the case of whether the hackers hack installed on the site. And frankly this stage is marked by professional hackers from other hackers, if the hackers hacked site or certain security system and left some breakthrough triggered it remains in permanent fear and concern reached.

The Pro 2 Tech blog has been released

The Pro 2 Tech

31/5/2016 

About us

An informative blog includes a number of articles in which we address the

Various global technical topics and the latest news about new technologies and

Multiple inventions and information about information technology, as well as

Some educational videos that attract fanatics, but new technologies and

Penetrate and programming, and others. Blog founded in 2016 by Islam Masoud

And Nasouh Al Rayes and we bloggers of Arab origin, as the headquarters of

.Palestine and the blog has nothing to do with politics

The Pro 2 Tech blog delivers information, news and advice about new tech, computer
facebook, google, internet, Technology, high tech, softwares and etc.