Popular Posts

Blog Archive

Powered by Blogger.

Total Pageviews

Sunday, February 5, 2017

Anonymous Hacker took down over 10,000 Dark Web Sites; Leaked User Database

Dark Web is right now going through a very rough time.

Just two days ago, a hacker group affiliated with Anonymous broke into the servers of Freedom Hosting II and took down more than 10,000 Tor-based .onion dark websites with an alarming announcement to its visitors, which said:

"Hello, Freedom Hosting II, you have been hacked."

Freedom Hosting II is the single largest host of underground websites accessible only through Tor anonymising browser that hosts somewhere between 15 and 20 percent of all sites on the Dark Web, anonymity and privacy researcher Sarah Jamie Lewis estimated.Besides defacing all Dark Web sites hosted on Freedom Hosting II with the same message and stealing its database, the hackers also demanded a ransom for 0.1 Bitcoin (just over $100) to return the compromised data to the hosting service.

Now, it has been reported that the stolen database from Freedom Hosting II has publicly been released online to a site hosted on the Tor network, which includes the email details of nearly 381,000 users, 'Have I Been Pwned' tweeted.

According to the Anonymous hackers, more than 50 percent of all files hosted on Freedom Hosting II servers were related to child pornography.

Those illegal websites were using gigabytes of data when Freedom Hosting II officially allows no more than 256MB per site, the Anonymous hacker claimed.

In addition to dark sites user details, the data dump also contains backups of website database, most of which are based on popular, free, open source content management systems and forums like WordPress and PHPBB.In an interview with Motherboard, an Anonymous hacker who claimed responsibility for the hack said this was his first hack ever, and he never intended to take down the hosting provider.

But when he allegedly discovered several large child pornography websites using more than Freedom Hosting II's stated allowance, he decided to take down the service. The hacker claimed to have downloaded 74GB of files and a users database dump of 2.3GB.

Lewis has been analyzing the leaked data and reported that the database contains Dark Web users' numerous plain text emails, usernames, and hashed passwords from forum websites hosted by Freedom Hosting II.

While it's bad news for users who joined one of those forums providing their genuine personal details, law enforcement would be happy, as in a separate case, the FBI used location-tracking malware to infiltrate Dark Web porn sites and track individual users.


Source: Anonymous Hacker took down over 10,000 Dark Web Sites; Leaked User Database

Saturday, February 4, 2017

Dark web’s largest host ‘Freedom Hosting II’ hacked by Anonymous

Update — the database has now been leaked and my ongoing analysis can be found over here

Compromise

Earlier today a Reddit user running a dark web crawler reported that all websites hosted by Freedom Hosting II had been compromised and were now displaying the following message:

Hello Freedom Hosting II, you have been hacked

We are disappointed… This is an excerpt from your front page 'We have a zero tolerance policy to child pornography.' — but what we found while searching through your server is more than 50% child porn…

Moreover you host many scam sites, some of which are evidently run by yourself to cover hosting expenses.

All your files have been copied and your database has been dumped. (74GB of files and 2.3GB of database)

We are selling all data (excluding cp) for 0.1 BTC. Send 0.1 BTC to 14iCDyeCSp12AmhVfJGxtrzXDabFop4QtU and send your transaction id to fhosting@tt3j2x4k5ycaa5zt.onion or fhosting@danwin1210.me and We'll get back to you with a full dump.

Up to January 31st you were hosting 10613 sites. Private keys are included in the dump. Show full list

We are Anonymous. We do not forgive. We do not forget. You should have expected us.

Update

As of approximately 17:00 GMT the landing page has been updated to say:

Thanks for your patience, you don't have to buy data ;) we made a torrent of the database dump download here

You may still donate BTC to 14iCDyeCSp12AmhVfJGxtrzXDabFop4QtU and support us.

If you need to get in contact with us, our mail is fhosting@sigaint.org

Verification

Privacy researcher Sarah Jamie Lewis used a customised 'onion scan' tool in October last year and found that Freedom Hosting II represented 15-20% of active onion sites detected based on matching SSH fingerprints.

The hack appears to be genuine. Not only are the tested hosted sites compromised, the main customer portal is already compromised, as this too is displaying the same message. fhostingesps6bly.onion was one of the primary onion addresses of Freedom Hosting II, the un-hacked version can be seen via this archived capture.

Freedom Hosting II portal — when it was working

The Bitcoin address listed by the anonymous hackers 14iCDyeCSp12AmhVfJGxtrzXDabFop4QtU at the time of writing has not received any payments. Selling access to hacked data rather than giving it away is not typical behaviour for Anonymous.

Brand legacy and follow up

Freedom Hosting II is the brand successor to the original Freedom Hosting, formally run by Irishman Eoin Marques, similarly notorious for hosting child pornography and fraud sites.

The original Freedom Hosting was taken down by the FBI in conjunction with a JavaScript 0-day attack on its users back in 2013. It is reasonable to except that law enforcement will be highly interested in the hacked data as it must intersect with operations against the worst of the worst sites under active investigations. In many cases this will mean bringing investigations to a premature close with some suspects evading justice, but in other cases providing a wealth of data on serious criminal operations.

Update — the database has now been leaked and my ongoing analysis can be found over here


Source: Dark web's largest host 'Freedom Hosting II' hacked by Anonymous

Friday, February 3, 2017

Calgary launches 2026 Olympic exploration bid website; milliondollar hosting plan underway

A website called "Should Calgary Bid?" has been launched in order to update residents on the city's potential plans to host the 2026 Winter Olympic and Paralympic Games, listing areas of exploration including social development, economic opportunity, cost and risk.

READ MORE: Calgary mayor Naheed Nenshi says city's study of Olympic bid on track

A lot has changed since 1988, but most of the venues built for those Olympics are still standing and could be used again, such as the Olympic Oval, which has some of the fastest ice in the world almost 30 years later.

"A lot of the existing venues are in good shape," said Calgary's former police chief Rick Hanson, who is heading the bid exploration committee.

"Will they need some modifications? Some of them will. Others might need more work done than others."

Off the ice, the Oval is showing its age: the sight lines and seats could use a face lift. But other than those upgrades plus new ski jumps and a second arena, Calgary may be in a position to host again without having to buy other new venues.

"The benefit that will be derived from this can hopefully be monetized on one hand and be clearly evident to the people who have to make the decisions," he said.

Watch below from Dec. 21, 2016: Speaking in Calgary, Prime Minister Justin Trudeau said he looks forward to more discussion about a Calgary Olympic bid.

Three decades ago, the Games cost about $1 billion. In 2026, that could be the cost just to secure them. Some have pegged the total price tag at $5.3 billion–less than the $7.7 billion spent on Vancouver in 2010.

No provincial or federal funding has been promised as of yet.

"One of the things that we're very much aware of is the cost-overrun issue," Hanson said.

Watch below: On June 20, 2016, Kevin Smith spoke with young athletes who are dreaming of competing in a 2026 Calgary Olympics amid reports of a proposal put forward at city council.

At a press conference Thursday, Mayor Naheed Nenshi said most of the $5 million granted by city council for Olympic exploration work will go towards creating a "hosting plan."

"The hosting plan is very useful even if we choose not to bid on the Olympics, because it gives us a real sense of the city's ability to host very large-scale events in terms of: what hotel rooms do we have? What transportation networks do we have? As well as what facilities can fit modern standards, from conventions to sporting events?

"I understand they are certainly looking at coming in at or below their budget by the time they get here in July and resources are really focused on creating that content."

After the recommendation is presented in July, council will then decide on whether to move forward with a formal bid, which is required sometime next year.

While Hanson is looking at the prospects with enthusiasm, his focus is on being objective.

"We need to answer the question: why would we? What's the net benefit to Calgary, Alberta and Canada?"

With files from Erika Tucker


Source: Calgary launches 2026 Olympic exploration bid website; milliondollar hosting plan underway

Thursday, February 2, 2017

WEBMASTER/WEB ANALYST

WEBMASTER/WEB ANALYST - BNL Technical Services, LLC - Roadtechs.com Nuclear Job Board  

Posted by: BNL Technical Services, LLC <resume@bnltech.com> on February 02, 2017 at 13:42:51. Click here to reply to this post via Email.Click here for help with email link

Contract / Temp to Direct / Direct Hire: ContractCity: RichlandState: WashingtonCountry: United StatesZip or Postal Code: 99354

Only Resumes submitted in WORD FORMAT will be accepted - Resume@Bnltech.com

WEBMASTER/WEB ANALYST

CONTRACTOR/MSA #297071

CLOSING DATE: 2/14/2017

DESCRIPTION OF WORK SPECIFIC:

Webmaster/ Web Analyst will be responsible for webmaster responsibilities to ensure enterprise level configuration management, availability and security of production web content and supporting development and test sites as well as supporting the Hanford's enterprise web hosting environment and supporting infrastructure to ensure enterprise level performance, availability and security.

This includes working with IT professionals on various infrastructure components, systems and servers supporting hundreds of Hanford applications and systems. Including but not limited to:

1. Act as focal point for uploading new content to websites that require a separation of duties between developer and production websites2. Provide interface for performance issues with developers and web analysts3. Review statistics and monitor analytics4. Ensure websites adhere to web governance and standards5. Tier-3 troubleshooting support, working with the user support team and the operations staff to effectively manage and communicate issues and perform problem analysis to resolution on a 24/7 schedule. As such, leads problem-solving efforts often involving outside vendors and other support personnel and/or organizations.6. Additionally, the analyst will assist senior Web analysts in the performance of their duties which include:7. Manages the day-to-day technical operations and product management, monitoring system performance, configuration, maintenance and repair.8. Manage integration with other systems, capacity planning, system-wide operation control, task automation an d providing recommendations on innovative and/or cost-effective options for delivering and/or improving enterprise web hosting services.9. Apply revisions, upgrades, and patches to enterprise web host software.10. Develop new system implementation plans, custom scripts and testing procedures to ensure operational reliability, high availability and system security of enterprise web services.11. Establishes guidelines and methods for the installation and management of the host environment and client tools.12. Develops procedures and documentation for backup and restoration of host operating systems and host-based applications and Disaster Recover/ Continuity of Operations (DR/COOP) capabilities.13. Develops tools, procedures, and training sessions for operations and other customer support organizations.14. Stays current with technological developments and provide recommendations on how to take advantage of new advancements.15. Identifies methods, solutions, and provides project leader ship and management in order to provide a high level of service to customers.16. Ensure system security across enterprise web application services, including contribution to security best practices.17. Advise management of developments in the industry or on the Hanford Site that could affect the web environment, projects and client relations.18. Maintain and follow all MSA policies, procedures and guidelines.

QUALIFICATIONS:

Technical Skills:1. Familiarity with configuration and management of Internet Information Services (IIS) versions 7.0 and above.2. Attention to detail and strong configuration management skills.3. Demonstrated ability to manage multiple tasks simultaneously and effectively prioritize and execute tasks in a high-pressure environment.4. Experience with successfully resolving complex issues within a moderate to large web environment.5. Knowledge of industry best practices.6. Highly self-motivated with a keen attention to detail.

Desired Skills:MSA would prefer an Analyst that has prior experience in performing Web and Webmaster duties, with skills that are relative to the Hanford configuration and future plans, including:

1. Knowledge and experience with Cold-fusion.2. Knowledge and experience with website metrics and analytics.3. Knowledge and experience with Certificate Authority and Public Key Infrastructure (PKI).4. Experience with UNIX/Linux platforms.5. Hanford Local Area Network (HLAN) enterprise desktop and server environment, specifically HLAN web server environment.Knowledge of MSA and Hanford Site policies, procedures, and processes.6. Appropriate Technical certifications.

Management and Work Skills:The Analyst provided shall have proven ability to effectively prioritize and execute tasks in a high-pressure environment and the ability to interact effectively and professionally with all levels of management, employees and customers by email, phone and in person. The individual shall have the knowledge, skills and ability to communicate technical/complex information both verbally and in writing. The Analyst position requires an attention to details and strong analytical and problem solving skills. The individual shall be able to provide support during non-standard business hours and be on call 24 hours a day, 7 days a week as needed or as scheduled.

Formal Education and Certification:1. BA/BS degree with Information Technology experience or equivalent combination of education and experience.

Please submit a resume in Word format to resume@bnltech.com and include in the subject line: WEBMASTER/WEB ANALYST 297071.

BNL Technical Services, LLC is an Equal Opportunity Employer

18 page view(s)

Thinking about applying for this position?Please make sure that you meet the minimum requirements indicated for the job before you apply (see user agreement). If you are qualified, then use either the email link (near top of post) or the application link (near bottom of post) to apply, whichever is provided.

Roadtechs.com notice to workers thinking about a career in nuclear power:All nuclear power plant employees are subject to background, financial and criminal history checks before they are granted access to any nuclear power facility and these checks are repeated at regular intervals. Additionally, new hire drug and alcohol screening is mandatory and all sites perform random drug and alcohol screening.

© Copyright - Roadtechs®, LLC. All rights reserved. No reproduction of any part of this website may be sold ordistributed for commercial gain nor shall it be modified or incorporated in any other work, publication, or website.Use of this site implies compliance with the Roadtechs User Agreement.


Source: WEBMASTER/WEB ANALYST

Wednesday, February 1, 2017

6 Tips To Secure Your Ecommerce Website

Online security breaches and e-commerce website hacks have been a common theme in mainstream media for the past several months.

From the Dyn attack that took place in October to the alleged foreign hacking of the U.S. election that's been uncovered in the past few weeks, the tail end of 2016 has been rife with reminders of how vulnerable our online world truly is.

Here's how to protect your e-commerce website.

secure-ecommerce-website

If you're a website owner, the increased threats we've seen to online security are probably particularly troublesome as you map out your website strategy for 2017.

Fortunately, there are several simple ways you can increase your site's security to significantly decrease the chances it will fall victim to a cyber-attack in the New Year.

1. Invest in a secure hosting service

Website owners often underestimate the importance of the decision they have to make regarding which web hosting service will support their websites. Although it can be tempting to go with the cheapest option, there are several key details you need to look for in a hosting service beyond the price. Security is arguably the most important of these details.

Your hosting service must provide a secure platform that not only keeps hackers away from your site, but also has the proper backup systems in place to get your site back up and running quickly should a security breach occur.

A secure web host provides a high uptime guarantee, a secure data center, sufficient backup programs, RAID data protection, and manual reboot. Check with your current hosting provider to ensure their service provides each of these details. If not, it might be time to a more secure hosting platform.

PC Mag offers a guide to the top web hosting service providers for 2017 if you need a little help narrowing down your choices.

2. Encourage users to protect their information

One of the most vulnerable points of a website is its login portals. Once a hacker has access to admin information or a consumer login, they can do quite a bit of damage. This is why it's important to ensure that your site users are doing their part to keep your site secure as well.

Recommended for You

Webcast, February 2nd: Behavioral Marketing Tactics to Drive Sales and Retention

Obviously, keeping a close eye on who has admin access to your site and how they handle their login information will be important, but you'll also want to make sure consumers who visit your site and create logins are being cautious as well.

You can either automate this or send reminders, but automating this process so that your system requires users to change their passwords every couple months or so will undoubtedly be more effective.

You should also require secure passwords for all login credentials on your site. Be sure that each password for your site is a minimum of 8 characters and has at least a number, a symbol, a lower case letter, and an upper case letter.

As for your site admins, they should be certain to be even more careful with the way they handle their login information to your site as they actually have access to the CMS. Be sure to go over the essential steps your employees should take to keep their login information safe.

3. Update your e-commerce website to SSL/TLS

SSL stands for Secure Sockets Layer. TLS stands for Transport Layer Security. These are important security protocols every site should employ to secure their sites against hackers looking to intercept sensitive information as it is transported from the site to a server or another application.

SSL and TLS encrypt data between applications and servers to be sure that the information being processed remains secure as it is sent across an insecure network

If you're not sure whether or not your site has an integrated SSL certificate, you can start by using an SSL checker.

If it turns out your site does not have one, you will need to upgrade it to make sure you have SSL or TSL protocols protecting your site.

Google offers a guide for site owners that shows how this process works.

4. Don't store customer data you don't need

This is pretty simple: if you don't need to store customer information, don't!

To avoid the additional headache of consumer liability issues in the event of a hack, don't store sensitive information if you don't have to. Obviously, this will be a bit tricky for subscription-based sites, but most sites should try to avoid storing payment information or personal identification information.

By keeping sensitive information off of your site, you can more easily protect your consumers should your site be hacked.

5. Run site vulnerability tests

Identifying potential vulnerabilities on your site on a regular basis will help you maintain a secure site with as few points of entry as possible.

One of the best ways to make sure you keep up on vulnerability testing is to set up an automated process using scanning software. The right programs will scan your network and website to identify risks and generate prioritized lists that tell you which issues should be addressed and how you should go about fixing them.

Some systems are even capable of automating the process of fixing the issues identified in the scan on their own.

If you're not familiar with how vulnerability scanning works, check out a few free programs first to get started.

6. Encrypt operational communications

Encryption is key not only to protecting your site via SSL/TSL protocols, but it's also an important precaution you should take to secure any other online communications your company has.

For an e-commerce website, you should start by encrypting all emails between your company and its vendors – especially your credit card processor. Any information that might interest online thieves should be sent through an encrypted email, not a plain text email that could be easily accessed.

Windows IT Pro provides a pretty thorough write up to help guide you through the process of encrypting your emails.

Managing an e-commerce website in this age of online uncertainty can be a bit scary at times, but with the right tactics, you can significantly decrease your site's chances of getting hacked.

Hopefully, these tips will help you secure your site for a safe and successful 2017!

Have any e-commerce safety tips you'd like to share? Let us know in the comments section below.

Author: Cosette Jarrett

Cosette is a digital lifestyle expert and freelance writer located in SLC. She is currently contributing to several major tech and lifestyle blogs, helping her readers discover new tech tools and gadgets for ease and efficiency at work and on the go.… View full profile ›


Source: 6 Tips To Secure Your Ecommerce Website