Wednesday, December 17, 2014

Xiaomi back to sales in India, but only till January 8th


Following the ban of the OnePlus One, it seems like there might be some good news for phone fans in India! As you probably already know, Xiaomi was also banned from selling their products in India recently, but the Delhi High Court has now partially lifted the ban to allow the Chinese company to sell phones once again, but only until January 8th.
Xiaomi was banned from selling or importing handsets in India, due to a patent infringement Ericsson’s Standard Essential Patents (SEPs). Ericsson sued Xiaomi and had taken the matter up to the Delhi high court. For now though, Xiaomi has been allowed to sell or import their handsets once again, but only handsets based on Qualcomm chipsets. The Xiaomi Redmi 1S that was on sale in India runs on a Qualcomm Snapdragon processor, and so does the 4G variant of the Redmi Note. However the mediatek powered Redmi Note which was on sale before the ban, will not be available.
Xiaomi’s Hugo Barra posted on his Facebook account today, to clear things up for fans of the company:

** Resuming sales in India **
Dear Mi fans,
Last week, we were forced to suspend sales in India due to an order passed by the Delhi High Court. Thanks for the overwhelming support so many of you have shown to Mi India in response to that!
We are happy to announce that the Delhi High Court today issued a ruling in our favor, allowing us to resume sales in India subject to certain terms.
The good news is that Redmi 1S is coming back next week and we’ll be having our next sale on Tuesday, December 23. Registration will open shortly — keep an eye on the Mi India page for details!

Sunday, December 14, 2014

Still fighting with GIRL FRIEND , Lets hide in WhatsApp

Since WhatsApp introduced the blue tick as red status, we’ve all been trap into big trouble, Particularly who has girlfriend ;) . Now we see ourselves forced to reply to anyone whose message we accidentally opened ,sometime my boss :( .

We can say the blue tick now cornered us and force to screw us in more timing.Don't be worried we have simple trick that can save you from your girlfriend's smash.Lets see,

Maybe we just wanted to read girlfriend’s WhatsApp message but we cannot instantly reply, we want to think about what to say as to not make her angry, but there she goes, freaking out like “You read my message but you don’t reply?”.

Keep calm, lets play with our method for you to avoid giving the blue ticks to your girlfriend but still be able to read her messages ;) All you need to do is, receive all her messages calmly, then TURN OFF your mobile data or Wi-Fi or both, make sure you have no internet connection running, and kudos, read her messages and don’t reply, nothing will happen :D (Except she might be seeing you as online if you turn off the data while WhatsApp screen is open, so better turn it off while on your Home screen).

Lets hide in whatsApp ;)

Monday, December 8, 2014

Low cost smart phones stealing your data

Once again in this year low cost smart phones stealing your data. A security vendor warned pre-installed malwares are sell out with these cheap smart phones.And like the last time the manufactures of the mobiles are from Africa and Asia.

This time the criminals using a broad schema to make it work that is they shifted distribution of malware through supply chain :( .

What does it do ???

The malware can use the SMS and WAP services to push the data from the user. The malware haven't work at the beginning its starts it process when the mobile shut-down for the fifth time and rebooted its starts its game.

Which Phones are Affected ?


  • Counterfeit Samsung GS4/Note II Various TECNO devices
  • Gionee Gpad G1 
  • Gionee GN708W 
  • Gionee GN800 
  • Polytron Rocket S2350
  • Hi-Tech Amaze Tab 
  • Karbonn TA-FONE A34/A37
  • Jiayu G4S – Galaxy S4 Clone
  • Haier H7 
  • No manufacturer specified i9502+ Samsung Clone 


The main countries of concern are Vietnam, Indonesia, India, Nigeria, Taiwan, and China. 

Monday, November 17, 2014

17 ATMs hacked in Malaysia

$1.2 million stolen by hackers from 17 Atm Around Malaysia

Hackers steal more than $1.2 million from 17 automated teller machines (ATMs) in Malaysia

A Team of Latin American  cyber criminals were able to exploit a way to hack and steal millions of dollars from 17 automated teller machines (ATM) in Malaysia.

ATMs of at least 17 bank branches belonging to United Overseas Bank, Affin Bank, Al Rajhi Bank and Bank of Islam were reportedly hacked by the Latin American gang.
CCTV  footage from the banks showed that 2-3 Latin American men, who were involved in the crime, entered and withdraw money from these ATM’s one after another.
Bukit Aman Commercial Crime Investigation Department chief Comm Datuk Mortadza Nazarene told Bernama that the suspects used a computer malware known as “ulssm.exe” to hack into the ATMs. “The suspects were found to have opened the top panel of the machine without using a key and inserted a compact disc into the machine’s processing centre which caused the ATM’s system to reboot,” he told Bernama, Tuesday morning, The Star reported.
A Selangor Commercial Crime Investigation Department spokesman said that investigations is still going on. In the meantime police were able to recover one of the ATM cards which was used by the hackers to withdraw the money. 
Since it was the ATM which was rebooted to default, no customers data was compromised in the hack, police are investigating the scene and believes the gang members are still in the country.



Sunday, November 16, 2014

MeterSSH – Meterpreter over SSH

As penetration testers, it’s crucial to identify what types of attacks are detected and what’s not. After running into a recent penetration test with a next generation firewall, most analysis has shifted away from the endpoints and more towards network analysis. While there needs to be a mixture of both, MeterSSH demonstrates how easy it is to circumvent a lot of these signature based “next generation” product lines.
MeterSSH is an easy way to inject native shellcode into memory and pipe anything over SSH to the attacker machine through an SSH tunnel and all self contained into one single Python file. Python can easily be converted to an executable using pyinstaller or py2exe.
MeterSSH is easy – simply edit the meterssh.py file and add your SSH server IP, port, username, and password and run the script. It will spawn meterpreter through memory injection (in this case a windows/meterpreter/bind_tcp) and bind to port 8021. Paramiko (python SSH module) is used to tunnel meterpreter over 8021 and back to the attacker and all communications tucked within that SSH tunnel.


Here we launch our initial meterssh payload:

Next we launch monitor.py which monitors or the SSH connection and automatically launches Metasploit for you. Once it detects the SSH connection and shell, it kicks off Metasploit for you:


Next, Metasploit is launched and notice that we are tunneling through localhost to the victim machine.

There are two files, monitor.py and meterssh.py.
monitor.py – run this in order to listen for an SSH connection, it will poll for 8021 on localhost for an SSH tunnel then spawn Metasploit for you automatically to grab the shell.
meterssh.py – this is what you would deploy to the victim machine – note that most windows machines wont have Python installed, its recommended to compile Python with py2exe or pyinstaller.
Fields you need to edit inside meterssh.py
user = “sshuser”
# password for SSH
password = “sshpw”
# this is where your SSH server is running
rhost = “192.168.1.1”
# remote SSH port – this is the attackers SSH server
port = “22”
user – this is the user account for the attackers SSH server (do not use root, does not need root) password – this is the password for the attackers SSH server rhost – this is the attackers SSH server IP address port – this is the attackers SSH server port

Note that you DO NOT need to change the Metasploit shellcode, the Metasploit shellcode is simply an unmodified windows/meterpreter/bind_tcp that binds to port 8021. If you want to change this, just switch the shellcode out and change port 8021 inside the script to bind to whatever port you want to. You do not need to do this however unless you want to customize/modify.

Thursday, November 13, 2014

Ugandan 'revenge porn' victim Desire could be arrested

After their private nude photos were stolen and published online in September, some chastised Jennifer Lawrence and other celebrities for taking the photos in the first place. Others said the blame was misplaced, and considered publication of the photos a sex crime.
After nude photos of a Ugandan singer were published online and in newspapers – allegedly spread by a spurned ex-boyfriend who wanted to teach her a lesson – the Ugandan ethics minister called for her arrest. Singer Desire Luzinda, he said, should be prosecuted under a new anti-pornography law that punishes “indecent” behavior.
“I have directed the police to arrest her, but first they should investigate her,” ethics minister Simon Lokodo told the Monitor last week. “She should be locked up and isolated,” he added.
On Monday, Patricia Okiria, an ethics ministry official, told the Ugandan newspaper New Vision Luzinda might not be charged with a crime. “She will only be contacted to help in the investigations on this case. She will help us in establishing the motive of releasing the pornographic content,” Okiria said.
“Her answers will help us substantiate her role in this saga. We need to know whether she consented before these photos were taken,” he added.
Luzinda, 26, remains in hiding.
She addressed the controversy on her Facebook page: “These were photos taken in privacy with someone I loved. In our private moments, we all have our ‘moments of madness’. The bottom line is that I trusted this person and never hoped that something done in private would find its way to the public domain irrespective of our differences.” She added: 
“These images in no way should define who I am” — but then apologized for taking “such shameful pics” and took full responsibility for the incident.

Twitter wants to make money!!!!!

Twitter wants to make money when it grows up
No longer the fun-loving "Toys 'R' Us" kid, Twitter is all grown up now and it wants to make money. The social network released a statement on Wednesday outlining its strategy on the Internet, stating that it wants to bring in revenue, and lots of it, though it did not give any specifics on that plan. The confusing statement was met with some mockery on the social network itself.
In its statement, Twitter outlined its strategy as:
Reach the largest daily audience in the world by connecting everyone to their world via our information sharing and distribution platform products and be one of the top revenue generating Internet companies in the world.
One response to the statement on Twitter from user @dkberman calls out the strategy as wordy:
Twitter's new mission statement: 35 words, 62 syllables, 4 clauses, 2 grammatical errors.
For its part, Twitter is saying that this is its strategy and not its mission. Twitter's mission is:
To give everyone the power to create and share ideas and information instantly, without barriers.
As part of its plan to improve, Twitter will bring more functionality to private messaging, release more standalone apps like Vine, and introduce Instant Timeline that will make it easy for new users to get updates without having to first follow other users.

Source: Business InsiderWSJ