2013年9月15日 星期日

黑客扮維修員 銀行裝遙控器謀偷錢

文匯報

英國警方偵破嚴重科技騙案,有匪徒假扮維修員潛入倫敦東南部一間桑坦德銀行分行,暗中在一部電腦安裝市值10 英鎊(約123港元)的KVM(鍵盤、屏幕及滑鼠)切換器,企圖遙距入侵銀行網絡偷錢,幸有人及時發現並關掉遙控器。當局上周四拘捕12名男疑犯,其中4 人被控串謀爆竊罪,案件昨日提堂。桑坦德銀行指無職員涉案。

 當地有不少公司安裝這款遙控器,可讓多人在數千公里外控制同一部電腦。匪徒在電腦背面安裝遙控器,可透過互聯網傳送電腦所有資料,遙距控制銀行電腦。科技罪案組探員雷蒙德指,匪徒犯案手法精密,銀行可能一下子損失數百萬英鎊。不過亦有互聯網安全專家指,即使匪徒成功入侵和控制銀行系統,取得敏感資料前,仍要破解多種保安關卡,才能從系統偷錢。 

 疑犯介乎23至50歲,來自英國、印度、葡萄牙、伊拉克和伊朗。當局在6處地方搜出多部電腦和大量犯案裝備,將交由專家檢驗。 

■《每日鏡報》/《每日郵報》/綜合外電消息

2013年9月13日 星期五

40萬危害軟件襲Android

蘋果日報

【本報訊】智能手機功能多,使其成為黑客最新「戰場」。網絡保安公司指,今年1月錄得17萬種針對Android的危害軟件,7月已跳升至逾40萬種,近半夾雜間諜軟件和廣告軟件等,惟用戶防範意識不高,個人及企業用戶的資料隨時被盜。

F-secure保安實驗室經理吳樹謙表示,Android智能手機系統是主要攻擊目標,其中版本較舊的Gingerbread2.3.3至2.3.7的入侵比率達36.4%,ICS4.0.3至4.0.4有25.6%,最新版本的Jelly bean4.2.1則只有4%。

香港電腦保安事故協調中心今年7月開始,對香港地區Google Play商店可下載的應用程式,進行惡意及可疑行為檢測,8月份對184個程式的檢測當中,發現六款高風險程式,其中三款至8月20日仍然在架。蘋果的 iOS系統也不一定與危害軟件絕緣,F-secure發現,過去半年其病毒種子已由1月份只有兩個,累計至6月已有33個。

2013年9月11日 星期三

Google地圖升呢 室內都睇埋

蘋果日報

【本報訊】港版Google地圖「升呢」推出四項新功能,用戶可利用「地圖製作工具」修改地圖或新增地標,通過審核便可加入地圖。Google首次利用衞星圖片及街景圖,繪製香港地圖,如原本只顯示一片綠色的維園,現可仔細看見園內小路。Google會為拍到的面孔「打格」,免侵私隱。
記者:袁樂婷

Indoor Maps加添商場平面圖

港版Google地圖本只支援街道圖,新推的Indoor Maps室內地圖創新加港澳逾70個地點的室內平面圖,包括香港國際機場、九龍香格里拉酒店、山頂凌霄閣、海港城及時代廣場。用戶只需拉大地圖,便可自動 轉換至平面圖(圖),再透過右側的樓層切換工具,可瀏覽不同樓層。平面圖除顯示商舖,亦有自動櫃員機、洗手間及升降機等。

Indoor Maps已在16個地區推出,香港是繼日本及新加坡後,第3個引入的亞洲城市。Google香港銷售總監張蔓詩笑指,大型商場範圍太大,要找特定商戶不容易,甚至會迷路,「依家入到商場唔使再周圍搵directory(商場指南)」。

2013年8月9日 星期五

瀏覽器保安漏洞 Chrome儲密碼不保密

蘋果日報

Google瀏覽器Chrome被揭發存在保安漏洞。Chrome容許用戶儲存不同網站的登入密碼,省卻每次瀏覽都重複輸入一次密碼的功夫,但軟件工程師肯伯(Elliot Kember)發現,只要數個步驟,任何人都可以看到用戶儲存在Chrome的密碼。
肯伯表示,只要在Chrome主欄目,由「選項」和「進階設定」中,點選幾項設置,再按下「管理系統儲存的密碼」,用戶儲存了密碼的網頁就會在清單中出現,再按下顯示密碼就會以文字顯示出來,密碼不再是密碼。

關密碼儲存功能防洩密

如果用戶要與別人共用一部電腦,或在公司使用的電腦卻沒有設定上鎖密碼,其他人就能得到用戶儲存的網站密碼,例如銀行網頁或電郵密碼。肯伯表示,要解決這個問題,只好關閉Chrome預設的密碼儲存功能。
肯伯批評Google這個漏洞「極愚蠢」,Chrome只要提供「主密碼」(master password)設置,每次瀏覽儲存了密碼的網頁時必須輸入「主密碼」驗證,就能堵塞這個漏洞。

美國哥倫比亞廣播公司

熄WiFi照追蹤定位 Android系統涉侵私隱

文匯報

科技網站Android Police發現,互聯網巨擘Google最新推出的Android 4.3流動作業系統,具有「Scanning always available」功能,即使用家關掉WiFi網絡,作業系統仍可自動掃描網絡,追蹤用家位置,私隱問題引起關注。

 根據Google指,該功能用於改善定位的準確性和其他用途。透過確認附近的WiFi網絡,流動裝置能確定用家位置,作用類似全球定位系統(GPS)。掃描所得的位置和其他資料,Google及其他安裝於流動裝置內的應用程式(app)都可分享。 

■《每日郵報》

蘋果日報

今季Google正式推出Android4.3操作系統,被發現即使關閉了wifi功能,電話仍會尋找網絡和追蹤用家位置,引起不少用家擔心行蹤被洩露。記者:梁海威

我們使用一部已升級至Android4.3的Nexus7作測試,證實就算關上wifi,同樣能進行定位。其實用家可自行關閉此功能,只要於wifi設定裡,把「一律執行掃描」此選項關上,便可停止這個「被追蹤」的功能。

Google就回應指,由於不少App都需要確定用家位置,用wifi定位比GPS省電,才會有此設定。至於會否好像斯諾登聲稱,有組織靜悄悄地追蹤全球用戶,便沒法證實了。 

2013年7月28日 星期日

六色帽子 分辨各路黑客

蘋果日報

黑客人多勢眾又良莠不齊,就如魔法故事裏的巫師世界,因應黑客的品性和專長分成很多種類,黑帽黑客是奸惡罪犯、白帽黑客代表光明磊落的專家。道不同 有時也會走在一起,即將於美國召開的「黑帽大會」雖名為黑帽,但出席的不一定全是壞蛋,紅白藍灰綠各路黑客都會參與交流一番。

黑帽 奸惡罪犯

黑客界的壞人,非法入侵網絡盜取個人資料,為了金錢或純粹惡意搞破壞,屬電腦罪犯

白帽 道德專家

受聘於某公司專門測試網絡系統是否安全,或受聘於保安公司設計保安軟件,是道德黑客

灰帽 黑白之間

介乎黑帽與白帽之間,愛非法入侵網絡但沒有惡意,有時只為提醒該公司注意安全漏洞,事後會主動通知,收取象徵式費用後負責修復系統

紅帽 邀進分子

白帽黑客的「激進版」,多數受聘於政府部門,專門入侵其他政府的電腦主機網絡,癱瘓系統

藍帽 貪玩報復

通常不受僱於電腦保安公司,為了貪玩或者報復,針對特定人士或公司而入侵網絡。相對較被動,除非被招惹激怒,否則多數不會主動出手

綠帽 聽話新手

綠帽是黑客界的「菜鳥」,多數指缺乏經驗、技巧生澀的新手,他們熱衷學習,肯聽命於有經驗的黑客

2013年6月23日 星期日

Open Source Workshop #15 開源工作坊 (2013/07/06)

下一次 Open Source Hong Kong 和 HKLUG 合辦的開源工作坊,訂於 7 月 6 日 (星期六) 在城大舉行。

今 次除了新鮮開源消息分享外,你也可以跟我們一起透過連場 Lightning Talks 閃電講, 五分鐘內講解你的 open source projects, 程式開發, 用家經驗或 idea 等等,讓大家了解和學習不同 open source projects ,繼而在緊接的 Hacking / Discussion Session 進行有關實作或討論。

第 15 次開源工作坊 (2013年7月)

日期: 2013 年 7 月 6 日 (星期六)
時間: 14:30 - 17:45
地點: 香港城市大學一號教學樓 5/F Y5-203 課室。
報名: http://opensourcehk201307.eventbrite.hk/
聯絡: Sammy Fung sammy@opensource.hk

Agenda
  1. Open Source News & Updates.
  2. Lightning Talks - your open source project ideas / updates
  3. Open discussion and hacking session.
Lightning Talks
  • Sammy Fung - hk0weather open source weather data project
  • Wan Leung Wong - Raspberry Pi
  • Pockey Lam - Digital Freedom Foundation (DFF) (10 min)
  • 你也告訴我們你的題目吧
特別鳴謝: 香港城市大學電腦系. (場地提供)

(English)

Next Open Source Workshop co-organized by Open Source Hong Kong and HKLUG, will be hosted again at CityU in 2013/7/6 Saturday.

Open Source news updates will be shared by co-organizers.

At lightning talk session, you can demostrate or express your open source projects, user experiences, and brainstom ideas to others in 5 minutes, then we will form some hacking / discussion groups to continue  works or discussions on your topics after lightning talks.

Open
Source Workshop #15 (2013 July)


Date: 6 July 2013, Saturday
Time: 14:30 - 17:45
Venue: Classroom Y5-203, Academic 1, City University of Hong Kong, Tat Chee Road, Kowloon Tong.
RSVP: http://opensourcehk201307.eventbrite.hk/
Contact: Sammy Fung sammy@opensource.hk

Agenda
  1. Open Source News & Updates.
  2. Lightning Talks - your open source project ideas / updates
  3. Open discussion and hacking session.
Lightning Talks
  • Sammy Fung - hk0weather open source weather data project
  • Wan Leung Wong - Raspberry Pi
  • Pockey Lam - Digital Freedom Foundation (DFF) (10 min)
  • Tell us your topics if you got any.
Special Thanks: Department of Computer Science, City University of Hong Kong (Venue Provider)

--
Yours Sincerely,
Sammy Fung
Community Manager
Open Source Hong Kong
http://opensource.hk

2013年5月24日 星期五

Open Source Workshop #14 (2013/6/1)

開源工作坊 #14 (2013年6月)
日期: 2013 年 6 月 1 日 (六)
時間: 下午 2:30-5:45 (最早可在 2pm 到場)
地點: 香港城市大學一號教學樓 5/F Y5-303 課室
請到 http://registrano.com/events/01332d 登記

議程:
* Open Source News & Updates by sammyfung and haggen.
* Introduction of Mozilla Webmaker and Firefox OS by sammyfung.
* Kernel-based Virtual Machine (KVM) talk by wanleung.
* Open discussion and hacking session.

語言: 廣東話
(除了英語講者以英語演講外)

人數: 40.

主辦:
* Hong Kong Linux User Group.
* Mozilla Hong Kong Community.
* Open Source Hong Kong.

(English)
Next workshop will be hosted on June 1st at CityU.
Open Source Workshop #14 (June 2013)
Date: 1 June 2013 (Saturday)
Time: 2:30-5:45pm (door open at 2pm)
Venue: Classroom Y5-303, 5/F Academic 1, City University of Hong Kong, Tat Chee Road, Kowloon Tong.
Please RSVP at http://registrano.com/events/01332d

Agenda:
* Open Source News & Updates by sammyfung and haggen.
* Introduction of Mozilla Webmaker and Firefox OS by sammyfung.
* Kernel-based Virtual Machine (KVM) talk by wanleung.
* Open discussion and hacking session.

Language: Cantonese
(except English for English speakers if any)

Capacity: 40.

Organizers:
* Hong Kong Linux User Group.
* Mozilla Hong Kong Community.
* Open Source Hong Kong.





--
Yours Sincerely,
Sammy Fung
Community Manager
Open Source Hong Kong
http://opensource.hk

2013年5月17日 星期五

Skype with care – Microsoft is reading everything you write

www.h-online.com

Anyone who uses Skype has consented to the company reading everything they write. The H's associates in Germany at heise Security have now discovered that the Microsoft subsidiary does in fact make use of this privilege in practice. Shortly after sending HTTPS URLs over the instant messaging service, those URLs receive an unannounced visit from Microsoft HQ in Redmond.

A reader informed heise Security that he had observed some unusual network traffic following a Skype instant messaging conversation. The server indicated a potential replay attack. It turned out that an IP address which traced back to Microsoft had accessed the HTTPS URLs previously transmitted over Skype. Heise Security then reproduced the events by sending two test HTTPS URLs, one containing login information and one pointing to a private cloud-based file-sharing service. A few hours after their Skype messages, they observed the following in the server log:
65.52.100.214 - - [30/Apr/2013:19:28:32 +0200]
"HEAD /.../login.html?user=tbtest&password=geheim HTTP/1.1"
 
They too had received visits to each of the HTTPS URLs transmitted
over Skype from an IP address registered to Microsoft in Redmond. URLs
pointing to encrypted web pages frequently contain unique session data
or other confidential information. HTTP URLs, by contrast, were not
accessed. In visiting these pages, Microsoft made use of both the login
information and the specially created URL for a private cloud-based
file-sharing service.
In response to an enquiry from heise Security, Skype referred them to a passage from its data protection policy:
"Skype may use automated scanning within Instant Messages and SMS to (a) identify suspected spam and/or (b) identify URLs that have been previously flagged as spam, fraud, or phishing links."
A spokesman for the company confirmed that it scans messages to filter out spam and phishing websites. This explanation does not appear to fit the facts, however. Spam and phishing sites are not usually found on HTTPS pages. By contrast, Skype leaves the more commonly affected HTTP URLs, containing no information on ownership, untouched. Skype also sends head requests which merely fetches administrative information relating to the server. To check a site for spam or phishing, Skype would need to examine its content.
Back in January, civil rights groups sent an open letter to Microsoft questioning the security of Skype communication since the takeover. The groups behind the letter, which included the Electronic Frontier Foundation and Reporters without Borders expressed concern that the restructuring resulting from the takeover meant that Skype would have to comply with US laws on eavesdropping and would therefore have to permit government agencies and secret services to access Skype communications.
In summary, The H and heise Security believe that, having consented to Microsoft using all data transmitted over the service pretty much however it likes, all Skype users should assume that this will actually happen and that the company is not going to reveal what exactly it gets up to with this data.
 

2013年5月12日 星期日

International Space Station to boldly go with Linux over Windows

www.telegraph.co.uk

Computers aboard the International Space Station are to be switched from Windows XP to the Linux operating system in an attempt to improve stability and reliability. 

Dozens of laptops on the ISS's 'opsLAN' network - which provides the ship's crew with vital capabilities for day-to-day operations, from telling the astronauts where they are to interfacing with onboard cameras - will be switched, removing Windows entirely from the ISS.
“We migrated key functions from Windows to Linux because we needed an operating system that was stable and reliable – one that would give us in-house control. So if we needed to patch, adjust or adapt, we could," said Keith Chuvala of the United Space Alliance, which runs opsLAN for NASA.
Astronauts using the system were trained on specific courses tailored by the non-profit Linux Foundation.
Linux is already used to run various systems aboard the ISS, including the world's first 'Robonaut', sent to the Space Station in 2011. 'R2' can be manipulated by astronauts as well as ground controllers and is designed to carry out tasks "too dangerous or mundane" for astronauts in microgravity, according to the Linux Foundation.
Tailored versions of Linux are widely used in scientific projects, including CERN’s Large Hadron Collider.

“Linux Foundation had it all, and provided the trainer on-site at our headquarters, which was a huge plus,” said Chuvala. “On top of that, the cost was very good, so it was overall a great value.”
The ISS computers were previously infected by a virus while running Windows. In 2008 the W32.Gammima.AG worm was found aboard, having reportedly been carried on a Russian astronaut's laptop. The Windows-based worm was classed as low risk by anti-virus software manufacturer Symantec.
Reports from Russian officials today reveal that the ISS is suffering a "very serious" ammonia leak that may require astronauts to perform an emergency spacewalk