Saturday, October 31, 2015

Google, WhatsApp, Facebook accused of breaching user's privacy

Cyber security firm Avast has alleged that Google, WhatsApp and Facebook spy on their users to find out their interest for serving targeted advertisements but their users are well aware about this.

"Google is an advertising company. Google revenue is basically from AdWords. Spying on users, getting what they are interested in and serving them advertisement is what their business model is. There is nothing inherent wrong with it. Users know what's going on, I think," Avast CEO Vincent Steckler told reporters today.

He was talking on the sidelines of release of Avast findings on cyber security issues and unveiling of anti-theft mobile security software. Steckler also said that WhatsApp too breaches data privacy of users.

"Did you ask all of your friends and colleague to share their personal and private information with Facebook. That's another biggest user of privacy. WhatsApp is a data collector to serve you advertising inside Facebook. ... you get advertisement on Facebook based on conversation you had on WhatsApp," Steckler said.

When asked for comments, a Google spokesperson said, "As a policy, we cannot comment on this without looking at specific report."

The privacy policy page of Google says, "When you use our services, you trust us with your information. Data enables us to provide our services like Search, Gmail, and Maps. Data also helps us show relevant ads, so we can make our services free for everyone."

No comments were received from Facebook on the issue. Steckler said that users also breach privacy of their acquaintances by sharing contact details to use applications on mobile phones.

"In order to use WhatsApp, you have to share your entire contact database. Which means you provided all your friends and colleagues contact details to Facebook. Do you have right to do that?" Steckler said.

Avast CEO shared analysis done by company of top 100 applications on Android in the month of September.

As per the analysis, 99 per cent of these applications have entire control of mobile phone which means they remotely operate phone as a user does and 92 per cent can view network connections.

One out of 10 of top 100 applications can record audio and take pictures and videos and 9 out of 10 are able to read storage content which can modify or delete, as per the report.

Adware and porn clicker malware on Google Play has infected millions of users this year.

"One group of hackers managed to return more than 50 times into the store with the same strategy in just three months their apps posed as games, but did nothing but click on porn," Steckler said. 

Friday, October 30, 2015

Xbox One to Get Windows 10 Upgrade on November 12th

Microsoft today announced that the Xbox One will get the Windows 10 upgrade on November 12th. There are currently users who are testing out the new features via the Preview program, and it’s all coming together next month.


The announcement was made by Microsoft on Twitter this evening:

Windows 10 Coming to Xbox One

If you’re currently using Xbox One, you’re probably not too happy with the lag time when switching between apps or settings using the dashboard. This new upgrade promises to provide faster performance, an improved gaming experience, vertical scrolling instead of horizontal (which takes longer to get to items), and expanded social features.

Also, in what is arguably the biggest update: you’ll be able to play Xbox 360 games! This will be accomplished using the Hyper-V virtualization technology that’s built into Windows 10.

At first, the number of 360 games will be limited at first, though. Microsoft says: “Now you can play a growing number of your Xbox 360 games on Xbox One at no additional cost. With over 100 titles slated for this fall, and hundreds more in the months to come…”

Something else that’s interesting is that all 360 games you get for free with the Games with Gold subscription will be compatible, too.

Other improvements will be a new guide for notifications, friends, and messages, and optimized store, and much more.

Microsoft is taking another step in the right direction and getting Windows 10 on virtually every device including PCs, tablets, Xbox One, Windows Phone, tablets, and Internet of Things (IoT) devices.

For a quick look at what the new Xbox One experience will be like, check out the video below.



For a full look at all of the new features coming to Xbox One with Windows 10, check out this Xbox.com site.

Get Started with a Free Month of YouTube Red

Google launched its new YouTube Red service (U.S. only) this week, and it offers a free 30-day trial. Here’s a look at how to get started with it and how to cancel the subscription to make sure you don’t get charged after the trial is over.

What is YouTube Red?

YouTube Red is a subscription service ($9.99/month) that offers access to all videos ad-free. It comes with other perks as well.

It lets you download videos for offline viewing or listening. A lot of people listen to their music via YouTube. The offline viewing and listening supports background play so you can keep the music going while using other apps or while on the go.

To download, tap the down arrow icon on the screen and then choose the quality you want to download it at.


Starting in 2016, YouTube Red subscribers will also have access to original content including TV series and movies. For more on what’s on tap for next year and the companies producing the shows, read Introducing YouTube Red Original Series and Movies from your favorite stars on the official YouTube blog.

Another benefit is a free monthly subscription to Google Play Music, which also costs $9.99/month. It’s also worth noting that if you’re already a subscriber to Play Music, you have access to YouTube Red for no additional charge.

In addition to iOS and Android, YouTube Red also works with Chromecast, Android TV, Apple TV, Xbox, PlayStation, Roku, and select Smart TVs. One glaring omission, at the time of this writing, it’s not available on Amazon Fire TV.

Free Month of YouTube Red

First, sign up for YouTube Red here. Then I recommend you cancel your membership at the same time you sign up…wait, what? You can cancel at any time before the trial period is over and still access all the benefits of YouTube Red for the month.

Cancelling right away lets you use the service for the full month, and not have to worry about your credit card being charged after the trial period if you don’t want it anymore.

According to YouTube Red terms:

“Cancellations: You can cancel your YouTube Red membership at any time. If you cancel, you’ll still have access to YouTube Red benefits until the end of your billing period.”

After signing up, head to the YouTube Red Cancellation page and select Cancel membership. Then click Yes, cancel to the verification message that comes up.

Next you’ll get verification that your membership is cancelled. But do note that it says you’ll have the YouTube Red benefits available until the end of the billing period.

If you listen to your music via YouTube or spend a lot of hours on it watching videos, this is something you should check out. Even if you don’t spend a whole lot of time on YouTube, it’s still worth checking out if nothing else, for an ad-free viewing experience for 30 days.





After signing up for YouTube Red, nothing on your customized YouTube page will change. You’ll still have all of your favorites, playlists, and subscriptions.

I’ve been testing it out a bit since it launched yesterday, but to me there’s not much to see here other than the benefit of no ads. One thing that seems strange is that it lets you play music via the app on you phone. The music will continue to play while your screen is locked, which current music subscriptions like Spotify already do. And, why would you use YouTube Red to listen to music from videos, when you get Google Play Music that is a more powerful music service?

There’s also problems with content creators who make a ton of money from their videos from ads, have to move to YouTube Red. Otherwise, their content will be removed. And they no longer will get that profit? If content creators don’t agree to the YouTube Red agreement, their content will be withdrawn from regular YouTube. In fact, ESPN has already had content pulled due to rights issues surrounding its content and the deal.

Coming to a satisfactory agreement with content creators will inevitably be a deciding factor in whether this new service is a success or not.

Thursday, October 29, 2015

Make your computer untraceable – Hacker’s Guide to Anti-Forensics

Removing or Hiding traces is most important thing that every hacker should know otherwise you will be busted in less than 5 minutes. In our previous article we have learned about how to remove traces over Network. Today we will learn how to make your computer almost untraceable, so that you cannot be tracked or monitored by anyone. This will not only help you in hiding your identity during hacking attempts but also make you anonymous over the network. Hiding or removing traces sometimes also referred as Anti-forensics.

Let’s get started… How to make your computer untraceable i.e. Leaving no traces behind any hack attempt. Hackingloops presents you complete Anti-Forensics hacker’s step by step guide to hide traces or logs.

Anti-Forensics Guide for Hacker’s :

1. Encrypt Your Keystrokes

You need to protect yourself from keyloggers/Rats. As strange as it may sound even the government/ security agencies/ windows/Hackers all has keyloggers, which records the users IP address, Mac address, open ports, operating system, installed applications, default web browser, visited URLs, logged in user, etc…

In order to protect yourself from keyloggers, you should encrypt your keystrokes. You can do this using a software called ‘Keyscrambler’.

2. Making Encryption Secure

Encryption is pointless if it can be easily bypassed or overcome. You need to make sure that the encryption is secure too.

Step 1 – Make Sure Your Password Is Strong

Even with your computer encrypted, it is still vulnerable. Make sure your password is good (for optimal security, your password should be twenty or more characters, with symbols, numbers, and random capitals, and a special symbol (like ALT+1456) really increase security). Norton password generator is great for this.

Step 2 – Create A Locked Screen Saver

Encryption is pointless if the Forensic Team get to your computer while its running. They can use live forensic tools that don’t require the movement or shutdown of a computer.
A very simple technique to overcome this is to create a locked screen saver. To create a locked screen saver in Windows Vista or Windows 7; Right click your desktop and click on ‘Personalize’. In the bottom left or right hand corner you should see ‘Screen Saver’, click that. Now, check ‘On Resume, Display Logon Screen’, and set ‘Wait’ to 5. Now, underneath that you may set what you want your screen saver to be.

Now you must go to your Control Panel. Click on System and Security now click on ‘Power Options’ find your selected plan and click ‘Change plan settings.’ Now, set ‘Turn Off Display’ to 5 minutes. That’s it! You have now created a locked screen saver.

Step 3 – Get Some Good Antivirus

This may seem obvious, but all this is pointless if you get infected with a keylogger that takes screen shots. Having a good anti-virus is one of the most important things you can do. Now, listen up. AVG, Avast, McCafe, Norton? They all SUCK. The only Anti-Virus you should even consider are BitDefender, ESET, Nod32 and Kaspersky is also pretty good. Advance System Care Ultimate is Good To it uses BitDefender Anti virus engine but is also a utility tool i.e Registry fix/defrag disk defrag privacy sweep security fix etc.

You rarely even need anti-virus software when using Linux, as most viruses are built to infect Windows systems, given these make up the majority of computers, but it’s best to be safe.

3. Disabling Windows Hibernation

You may as well hand your computer over to the feds if they raid your house and your computer is in hibernation. Also, putting your computer into hibernation is pretty much just taking a screen shot of your RAM that gets saved to your hard drive.

To disable hibernation in Windows Vista/7/10:
a. Open your Control Panel.

b. Click System and Security, then click ‘Power Options’.

c. Click ‘Change plan settings’ for you current power plan.

d. Now click ‘Change advanced power settings’. Expand ‘Sleep’, then expand ‘Hibernate After’. Enter “0″ for ‘Setting:’ to set hibernate to ‘Never’. Hibernation is now disabled.

4. Disable and Remove USB Logs

Next on the list of Anti-Forensics in to disable logs of USB activity, flash drives, etc…
This can be valuable if you have a flash drive with sensitive data and you don’t want any logs of it ever being plugged it to your computer.

Step 1 – Delete the USBSTOR Registry Setting

The USBSTOR setting contains history of plugged in USB devices.
To delete it, hit the WINDOWS Home Button + R at the same time. This will open up ‘Run’; type: “Regedit” (without quotes). Browse to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR
Now, right click ‘USBSTOR’ and hit ‘Delete’, then confirm that you want to delete the key. Now, the key has been deleted.

Step 2 – Delete The Setupapi.log File

The Setuppapi.log is a plain-text file that stores the list of installed USB devices and their drivers. We will delete it with a program called CCleaner.
CCleaner is actually one of the best anti-forensic tools out there, and its free.

5. Disabling Time Stamps

Using Time Stamps, forensic experts can build a ‘digital time-line’, this can be very compelling evidence when cross-referenced with other known evidence. In order to strengthen security, we must disable these logs.

Step 1- User Assist File

There is a registry setting that keeps logs and dates of all launch programs, forensic experts can use this to build a digital timeline, we must disable this for computer security. Navigate to HKEY_Current_User\Software\Microsoft\Windows\Currentversion\Explorer\User assist. Do this by hitting the Windows button on your keyboard and R at the same time and typing regedit in). You should see two subkeys called Count, delete both these keys. Now right-click the UserAssist key and create a new key named ‘Settings’. In this key (right clicking on it) create DWORD value named NoLog, set the value to 1.

Windows will no longer store hidden logs of the exact times you have been accesing files, therefore forensics experts can no longer use these hidden logs to create a digital timeline.

Step 2 – Last Access Logs


Next we will disable the last access in Windows. What last access is is a setting on Windows that allows you to see when you opened, modified, and/or created files on your computer and is similar to the UserAssist registry key. By disabling this forensic
experts won’t as easily be able to tell when you’ve been accessing programs or files on your computer.

To disable last access open command prompt on your computer, if on Vista or Windows 7 make sure to run as administrator. In command prompt type the following:
fsutil behavior set disablelastaccess 1

Last access has now been disabled, in order for it to take effect you must restart your computer. (You have to have admin rights to do this).

6. Windows Security Miscellaneous

This is for the shit that has to do with windows anti-forensic security, but wasn’t big enough to have its own section. That does NOT mean this section isn’t important, the stuff in here may actually be the most important in the whole guide.

Step 1 – Disable System Restore Points

System Restore points can be used to bring your computer back to a date when it wasn’t secure and can also be used to restore overwritten files.
To disable System Restore points, right click ‘Computer’ and click ‘Properties’. Now click ‘Advanced System Settings’. Under ‘System Protection’ click ‘Configure’.
Now, select ‘Turn Of System Protection’ and apply it.

Step 2 – Disable ‘Send Error Report to Microsoft

This is self-explanatory, we obviously don’t want Microsoft having logs of all our crashed programs. To do this, go to your start menu and search ‘problem reporting settings’ and then click on ‘Choose How To Report Problems’. Click ‘Change Report Settings For All
Users’ and then set it to ‘Never check for solutions’.

Step 3 – Wipe With CCleaner

This is the heart of Anti-Forensics right here. CCleaner is actually one of the most powerful Anti-Forensic tools, -IF- used correctly.
As it turns out, when deleting files, you DO NOT need to do multiple overwrites. With modern hard-drives, one overwrite really is enough to delete a file beyond repair, even though it is popular belief that you need several overwrites to be secure.
With CCleaner, I would recommend three overwrites, just in-case it misses something the first time around (remember, it is a free software).

Once you have CCleaner installed, run it (AS ADMIN), go to ‘Settings’ and make sure you have it set to overwrite deleted data with three passes. Go back to ‘Cleaner’ and check EVERYTHING. I mean EVERYTHING, and hit ‘Run Cleaner’. You might want to leave this on overnight.

Do this every time you are done with a major hacking job. When using normally (what should be every time you are done with your computer), uncheck ‘Wipe Free Space’, this will cut down the time from hours to a few minutes.

Step 4 – Disable Debugging Upon Failure

This keeps logs of your computers failures and blue screen info.
To disable it, right click ‘Computer’ and go to ‘Advanced System Settings’, now go to ‘Start Up and Recovery’. Now, set ‘Debugging Information’ to ‘None’.

Step 5 – Disable Windows Event Logging

Windows keeps logs of all events on the computer. First, before we disable, we must clear all the logs.
To disable it, go to Control Panel then System and Security. Now, click Administrative Tools, and then Event Viewer. In either pane of the Event Viewer window, right-click System and then select Clear All Events, you will get a window that says: “Do you want to save ‘System’ before clearing it?”, click ‘No’.

Now we must disable Windows Event Logging. Go to ‘Run’ and type in ‘msconfig’, then go to ‘Services’ and make sure ‘Hide all Microsoft Services’ is UNCHECKED. Now scroll down until you find ‘Windows Event Logging’, and UNCHECK it.

Now restart your computer right away.

7. Online Anonymity Guide

Hiding online identity and anonymity is essential; because it prevents you from getting traced or tracked down.

Proxies : Proxies are used mainly for security purposes and IP Address, it may be also used to speed up the loading of resources by caching, bypass parental controls and open blocked sites.

Web Proxies : Web Proxies are services that provides proxy access using a website, the function is, when you request a webpage, the server will contact the website indirectly and will server the resource to your web browser.

VPNs : VPNs are similar to proxies, it hides your IP address but the advantage is, it encrypts your traffic so that it would not be intercepted by data sniffing tools, it is useful for public wifi hotspots and for home/office use.

User-Agent Switcher : Spoofs and mimics a user-agent to hide the browsers’ identification.

IPFuck/IPFlood : Used for hiding IP address by using multiple proxies simultaneously, which obfuscates the user’s IP address.

8. Anonymity Tips

a. Do not post private information in the web, including your address, birth date and contact info, including on your registration details, if the authorities found one, they will use it to track you.
b. Do not engage private activities while on public places, other people might see you.
c. Always use anonymity tools so your IP address is masked, if in case they found it out, the IP is fake.
d. Do not brag or talk about hacking, obviously, if you brag/talk about it with your friends, they might report you to the police.
e. Hide your files in an encrypted container, encrypting data on the USB is better.
f. Always use SSL when its available; it encrypts your details so that it would be safe.
g. Use SSH (Secure Shell) when connecting to a remote system, one good example is PuTTy.
h. Never trust anyone; and rely on your instincts.
i. Try “proxy chaining”, or using of multiple proxies.
j. Use a VPN together with a high-anonymity proxy so that there would be an increased privacy advantage.



That’s all friends!! This is must for all Hackers. Keep Learning !! Keep Connected!!

How Hackers Target You

Hackers are all around us !  We are paranoid when it comes to our cyber security , Online account Passwords etc !!! In any hack , Human element is the weakest link . Social engineering is a technique where the hacker might trick the victim of the attack to make the attack successful either by downloading/running a malware file or clicking on a link or what so ever the hack requires .

In this post we see how hackers obtain valuable information about you . Obtaining this information is not very difficult for the hackers. They can do this by a simple google search or by visiting your social network profile . Here is how you are helping the hackers :

How Hackers Obtain Information About You

Facebook Profiles

As the largest social network, Facebook profile is the first thing you need to secure. Go, check it out from the outside. Log out of your Facebook then look your account up, from an outsider’s point of view.

If your Facebook profile shows too much information, you will likely victimize yourself.

Account Recovery Hack on Facebook

Let’s do an experiment. Pretend you forgot your password, then go into Facebook. Facebook may ask you for your email address, your user name or your mobile number. You can provide that How Hackers Target Youinformation, and it will send you an email with instructions to reset your password.

Previously, there was a method employed by Facebook to reset the password, and that method had your trusted friends involved for the purpose. It sounds foolproof unless you accept a lot of friend requests on Facebook. Picture this: You get a friend request from a few people that you don’t know. If you are the friendly type, you’d probably accept those four requests.

One thing you don’t know is that those accounts may be operated by one or more hackers. What they will do is simply raise a password reset request on your account, and select three of those four accounts as your “trusted friends”. Facebook emails security codes to those trusted accounts, and boom, the hacker takes over your Facebook account. If you have problems with that, then you should take a look at this post of mine to figure out what to do.

Fortunately, Facebook no longer uses this particular method. It also doesn’t rely on security questions any more. Right now, in order to gather access to a Facebook account, the only way is by securing access to the original email address.

Hence, a hacker needs access to your email account to get into your Facebook account.

Email Security

Which email service are you using? Depending on that, the security differs. If it is Gmail, I would extremely recommend that you start using the two-factor authentication.

Here are the steps:

1. Go to your Google Account settings (not Gmail settings) and go to theSecurity option.

2. You will see 2-Step verification option. Turn the status ON

3. Add your phone number. Select to receive the codes by text messages or voice call.

4. Enter the code received to verify your account. Make sure you update the records if you change your phone number.

Another important thing on Gmail is notifications about suspicious login attempts. You can opt for email as well as phone notifications if any suspicious login is detected on your Gmail account.

The Truth About Security Questions

Google has a security question that you need to set. Make sure it is set properly. While I was working with email security for AT&T, I have encountered elderly customers answering security questions very truthfully. Even though I took time in explaining to them what a security question is and why they needn’t submit the true answer all the time, most of them did not quite understand it.

Most people don’t realize the fact that a security question answer works exactly like a password, only less secure depending on how you through your information about. Talking about your pet Rover on Facebook a lot then setting it it as your Security question maybe risking it a little. Anybody can access your account, whether or not they know the password, just by making educated guess about your preferences, which would work if you are truthful with your security questions.

Customer Service

If you are using the customer service option to reset your password for your email, the customer service executive may ask you your security question. Within AT&T, we used to use security questions to verify customers, questions like “Who is your favorite hero?”, and answers like “Batman”.

Not only that, we were authorized to provide the first letter of the answer if the customer gets it wrong the first time. A hacker can easily fake it since the random operator cannot identify the voice of the caller, and is supposed to divulge a password if the caller gives the correct answer.

How to Use an Android device as Second Monitor for your PC or MAC

How to Use an Android device as Second Monitor for your PC or MAC!! 💠 The method is quite simple and easy and you just need to follow...