Jump to content

Leaderboard

Popular Content

Showing content with the highest reputation on 05/31/17 in all areas

  1. Windows Server 2016 System Administration for Beginners https://www.udemy.com/windows-server-2016/?couponCode=FREEUCOUPONCOURSES
    2 points
  2. What if your laptop is listening to everything that is being said during your phone calls or other people near your laptop and even recording video of your surrounding without your knowledge? Sounds really scary! Isn't it? But this scenario is not only possible but is hell easy to accomplish. A UX design flaw in the Google's Chrome browser could allow malicious websites to record audio or video without alerting the user or giving any visual indication that the user is being spied on. AOL developer Ran Bar-Zik reported the vulnerability to Google on April 10, 2017, but the tech giant declined to consider this vulnerability a valid security issue, which means that there is no official patch on the way. How Browsers Works With Camera & Microphone Before jumping onto vulnerability details, you first need to know that web browser based audio-video communication relies on WebRTC (Web Real-Time Communications) protocol – a collection of communications protocols that is being supported by most modern web browsers to enable real-time communication over peer-to-peer connections without the use of plugins. However, to protect unauthorised streaming of audio and video without user's permission, the web browser first request users to explicitly allow websites to use WebRTC and access device camera/microphone. Once granted, the website will have access to your camera and microphone forever until you manually revoke WebRTC permissions. In order to prevent 'authorised' websites from secretly recording your audio or video stream, web browsers indicate their users when any audio or video is being recorded. "Activating this API will alert the user that the audio or video from one of the devices is being captured," Bar-Zik wrote on a Medium blog post. "This record indication is the last and the most important line of defense." In the case of Google Chrome, a red dot icon appears on the tab, alerting users that the audio or video streaming is live. How Websites Can Secretly Spy On You The researcher discovered that if any authorised website pop-ups a headless window using a JavaScript code, it can start recording audio and video secretly, without the red dot icon, giving no indications in the browser that the streaming is happening. This happens because Chrome has not been designed to display a red-dot indication on headless windows, allowing site developers to "exploit small UX manipulation to activate the MediaRecorder API without alerting the users." Bar-Zik also provided a proof-of-concept (PoC) code for anyone to download, along with a demo website that asks the user for permission to use WebRTC, launches a pop-up, and then records 20 seconds of audio without giving any visual indication. All you need to do is click on two buttons to allow the website to use WebRTC in the browser. The demo records your audio for 20 seconds and then provides you a download link for the recorded file. The reported flaw affects Google Chrome, but it may affect other web browsers as well. It's Not A Flaw, Says Google; So No Quick Patch! Bar-Zik reported the security issue to Google on April 10, 2017, but the company doesn't consider this as a valid security vulnerability. However, it agrees to find ways to "improve the situation" in the future. Google consider this a security vulnerability or not, but the bug is surely a privacy issue, which could be exploited by hackers to potentially launch more sophisticated attacks. In order to stay on the safer side, simply disable WebRTC which can be done easily if you don't need it. But if you require the feature, allow only trusted websites to use WebRTC and look for any other windows that it may spawn afterward on top of that. Edward Snowden leaks also revealed Optic Nerve – the NSA's project to capture webcam images every 5 minutes from random Yahoo users. In just six months, 1.8 Million users' images were captured and stored on the government servers in 2008. Following such privacy concerns, even Facebook CEO Mark Zuckerberg and former FBI director James Comey admitted that they put tape on their laptops just to be on the safer side. Although putting a tape over your webcam would not stop hackers or government spying agencies from recording your voice, at least, it would prevent them from watching or capturing your live visual feeds. Via thehackernews.com
    2 points
  3. Generator Streaming Google Drive pentru Video/Filme/Seriale url generator: https://yideo.ro Demo Video: https://goo.gl/zCYHMI Si las aici si un site cu filme si seriale in caz ca va uitati https://yideo.online
    1 point
  4. SHA256: 30766b93e32330aa9d8164a61969adcd2d4c11f5256acba277fa77183fef8690 File name: Setup.exe Detection ratio: 18 / 61 Analysis date: 2017-05-30 19:48:08 UTC ( 1 minute ago Ad-Aware Gen:Variant.Symmi.73171 20170530 AhnLab-V3 Trojan/Win32.Agent.C1915360 20170530 ALYac Gen:Variant.Symmi.73171 20170530 Arcabit Trojan.Symmi.D11DD3 20170530 BitDefender Gen:Variant.Symmi.73171 20170530 CrowdStrike Falcon (ML) malicious_confidence_100% (D) 20170420 Emsisoft Gen:Variant.Symmi.73171 (B) 20170530 Endgame malicious (high confidence) 20170515 ESET-NOD32 a variant of MSIL/PSW.CoinStealer.AA 20170530 F-Secure Gen:Variant.Symmi.73171 20170530 GData MSIL.Trojan-Ransom.Jigsaw.F 20170530 Invincea backdoor.win32.fynloski.a 20170519 Kaspersky HEUR:Trojan.Win32.Generic 20170530 eScan Gen:Variant.Symmi.73171 20170530 SentinelOne (Static ML) static engine - malicious 20170516 Symantec ML.Attribute.HighConfidence 20170530 Webroot W32.Trojan.Dynamer 20170530 ZoneAlarm by Check Point HEUR:Trojan.Win32.Generic 20170530 Post on this forum -> gloryholefoundation.com
    1 point
  5. Da frate ala este icq-ul meu de acord cu tine, dar arata`mi unde sa intamplat plata ? Tu ai intrat mai intrebat daca am mailuri de o anumita tara (numai tin minte tara exact) Am zis ok, le sortam le punem pe ams sa stergem dublicatele si vedem ce ramane. Ti-am dat screen-shot cu nr de mailuri si tu apoi mai intrebat pe mine de cele de USA. Ai zis ca vrei 10-15 milioane de mailuri de USA si ca faci plata prin BTC, plata nu sa intamplat iar tu automat nu ai avut ce sa primesti. Sa fim seriosi pana la capat daca suntem, nu pot fi eu acuzat aiurea. Tine-ti minte ca asa a mai zis si unu Antonio numai stiu cum ca l-am tapit eu si am pus pozele cu "money back" aici si pana la urma a recunoscut ca a mintit. De ce nu arati tot logul cand tu ai vrut sa ma arzi pe mine de emailuri ? Daca tot este vorba pe asa sunt destule persoane cu care am facut trade de aici si totul a fost ok. @atomixcj - pagina de facebook @n3curatu - grup facebook @TAJ - review facebook mai am mai vandut si mailuri de irlanda si totul a fost ok, dar numai retin numele. am fost contactat si am aratat tot ce am si totul cu dovada clara si lui @asparcilius (a ramas in stand-by) ca ma contacteaza el. acelasi lucru sa intamplat si cu @sTrEs si cu @nidermanalfred Unele lucruri poate sa le confirme si @Sandu Nu stiu unde si pana unde sa ajuns aici dar imi pare nespus de rau culmea este ca toti cei mentinati mai sus au facut plata primi fara nici o indoiala si totul sa finalizat cu sucess. Daca voi considerati ca e ceva gresit, ok sunt dispus sa primesc BAN. EDIT : si ca sa fie treaba treaba , o alta intrebare . Dupa cum se vede si pe screen-ul tau tu imi dai mesaj mie pe icq pe 4 aprilie timp care erai deja la block (asta inseamna ca tranzactia URMA sa fie facuta inainte de 4 aprilie) iar daca eu ti-as fi dat tie teapa, de ce postezi tu tocmai pe Posted April 29 ca ti-as fi dat eu tie teapa si nu atunci imediat? Adica dau teapa acuma dar spun peste 1 luna de ea ?
    1 point
  6. Cupon de la github student pack?
    0 points
  7. Salut, Vand cupon Digitalocean.com in valoare de $50 ca sa fie activat trebuie sa mai platiti $5 paypal sau credit card. (o sa ai in cont $55) functioneaza doar pentru conturi noi! pret $10 per cupon in stock: 10 cupoane https://t.me/nailui paypal/transfer bancar/si ce o mai fi
    -1 points
This leaderboard is set to Bucharest/GMT+02:00
×
×
  • Create New...