Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×

Submission + - USBdriveby: The $20 Device That Installs a Backdoor in a Second

Trailrunner7 writes: Samy Kamkar has a special talent for turning seemingly innocuous things into rather terrifying attack tools. First it was an inexpensive drone that Kamkar turned into a flying hacking platform with his Skyjack research, and now it’s a $20 USB microcontroller that Kamkar has loaded with code that can install a backdoor on a target machine in a few seconds and hand control of it to the attacker.

Kamkar has been working on the new project for some time, looking for a way to install the backdoor without needing to use the mouse and keyboard. The solution he came up with is elegant, fast and effective. By using code that can emulate the keyboard and the mouse and evade the security protections such as local firewalls, Kamkar found a method to install his backdoor in just a couple of seconds and keep it hidden on the machine. He loaded the code onto an inexpensive Teensy USB microcontroller.

Kamkar’s USBdriveby attack can be executed in a matter of seconds and would be quite difficult for a typical user to detect once it’s executed. In a demo video, Kamkar runs the attack on OS X, but he said the code, which he’s released on GitHub, can be modified easily to run on Windows or Linux machine. The attack inserts a backdoor on the target machine and also overwrites the DNS settings so that the attacker can then spoof various destinations, such as Facebook or an online banking site, and collect usernames and passwords. The backdoor also goes into the cron queue, so that it runs at specified intervals.

Submission + - New Zeus Variant Targets Users Of 150 Banks

An anonymous reader writes: A new variant of the infamous Zeus banking and information-stealing Trojan has been created to target the users of over 150 different banks and 20 payment systems in 15 countries, including the UK, the US, Russia, Spain and Japan. Chthonic, as the variant has been named by Kaspersky Lab researchers, shares a lot of similarities with previous Zeus variants. The malware is capable of collecting system information, stealing saved passwords, logging keystrokes, recording video and sound via the computer's webcam and microphone, grabbing the contents of online forms, injecting web pages and fake windows, and allows criminals to connect to the infected computer remotely and use it to carry out transactions.
The Media

Skeptics Would Like Media To Stop Calling Science Deniers 'Skeptics' 719

Layzej writes: Prominent scientists, science communicators, and skeptic activists, are calling on the news media to stop using the word "skeptic" when referring to those who refuse to accept the reality of climate change, and instead refer to them by what they really are: science deniers. "Not all individuals who call themselves climate change skeptics are deniers. But virtually all deniers have falsely branded themselves as skeptics. By perpetrating this misnomer, journalists have granted undeserved credibility to those who reject science and scientific inquiry."
Science

Scientists Discover That Exercise Changes Your DNA 56

HughPickens.com writes The human genome is astonishingly complex and dynamic, with genes constantly turning on or off, depending on what biochemical signals they receive from the body. Scientists have known that certain genes become active or quieter as a result of exercise but they hadn't understood how those genes knew how to respond to exercise. Now the NYT reports that scientists at the Karolinska Institute in Stockholm have completed a study where they recruited 23 young and healthy men and women, brought them to the lab for a series of physical performance and medical tests, including a muscle biopsy, and then asked them to exercise half of their lower bodies for three months. The volunteers pedaled one-legged at a moderate pace for 45 minutes, four times per week for three months. Then the scientists repeated the muscle biopsies and other tests with each volunteer. Not surprisingly, the volunteers' exercised leg was more powerful now than the other, showing that the exercise had resulted in physical improvements. But there were also changes within the exercised muscle cells' DNA. Using technology that analyses 480,000 positions throughout the genome, they could see that new methylation patterns had taken place in 7,000 genes (an individual has 20–25,000 genes).

In a process known as DNA methylation, clusters of atoms, called methyl groups, attach to the outside of a gene like microscopic mollusks and make the gene more or less able to receive and respond to biochemical signals from the body. In the exercised portions of the bodies, many of the methylation changes were on portions of the genome known as enhancers that can amplify the expression of proteins by genes. And gene expression was noticeably increased or changed in thousands of the muscle-cell genes that the researchers studied. Most of the genes in question are known to play a role in energy metabolism, insulin response and inflammation within muscles. In other words, they affect how healthy and fit our muscles — and bodies — become. Many mysteries still remain but the message of the study is unambiguous. "Through endurance training — a lifestyle change that is easily available for most people and doesn't cost much money," says Sara Lindholm, "we can induce changes that affect how we use our genes and, through that, get healthier and more functional muscles that ultimately improve our quality of life."

Submission + - Nicholas Negroponte on the Future of Learning: Nanobots Will Hack the Brain (hacked.com)

giulioprisco writes: Nicholas Negroponte describes future nanobots hacking our neurons to make us learn faster and better. Able to communicate wirelessly with each other and with the external world, the nanobots would hack the brain like read/write computer memory. Negroponte says: '[I]n theory you could load Shakespeare into your bloodstream and as the little robots get to the various part of the brain they deposit little pieces of Shakespeare or the little pieces of French if you want to learn how to speak French. So in theory you can ingest information.'

Comment Maybe they could re-shoot it, varying the script - (Score 0) 230

- so that it's set in Cuba instead.

(I am not kidding. In fact, call it THE INTERVIEW II: HAVANA GILA MONSTER" and make frequent in-joke references to the previous one, even though -- especially because! -- nearly no one has seen it.)

But this time, assassinate Castro, instead.

 

AI

Ars Reviews Skype Translator 71

Esra Erimez writes Peter Bright doesn't speak a word of Spanish but with Skype Translator he was able to have a spoken conversation with a Spanish speaker as if he was in an episode of Star Trek. He spoke English. A moment later, an English language transcription would appear, along with a Spanish translation. Then a Spanish voice would read that translation.
Hardware Hacking

Extracting Data From the Microsoft Band 51

An anonymous reader writes The Microsoft Band, introduced last month, hosts a slew of amazing sensors, but like so many wearable computing devices, users are unable to access their own data. A Brown University professor decompiles the app, finds that the data is transmitted to the Microsoft "cloud", and explains how to intercept the traffic to retrieve the raw minute-by-minute data captured by the Band.
Censorship

"Team America" Gets Post-Hack Yanking At Alamo Drafthouse, Too 230

Slate reports that even old movies are enough to trigger a pretty strong knee jerk: Team America, World Police, selected as a tongue-in-cheek replacement by Dallas's Alamo Drafthouse Theater for the Sony-yanked The Interview after that film drew too much heat following the recent Sony hack, has also been pulled. The theater's tweet, as reprinted by Slate: "due to circumstances beyond our control,” their Dec. 27 Team America screening has also been canceled." If only I had a copy, I'd like to host a viewing party here in Austin for The Interview, which I want to see now more than ever. (And it would be a fitting venue.)

Submission + - Extracting Data from the Microsoft Data (jeffhuang.com)

An anonymous reader writes: The Microsoft Band introduced last month hosts a slew of amazing sensors, but like so many wearable computing devices, users are unable to access their own data. A Brown University professor decompiles the app, finds that the data is transmitted to the Microsoft "cloud", and explains how to intercept the traffic to retrieve the raw minute-by-minute data captured by the Band.
Security

Grinch Vulnerability Could Put a Hole In Your Linux Stocking 118

itwbennett writes In a blog post Tuesday, security service provider Alert Logic warned of a Linux vulnerability, named grinch after the well-known Dr. Seuss character, that could provide attackers with unfettered root access. The fundamental flaw resides in the Linux authorization system, which can inadvertently allow privilege escalation, granting a user full administrative access. Alert Logic warned that Grinch could be as severe as the Shellshock flaw that roiled the Internet in September. Update: 12/19 04:47 GMT by S : Reader deathcamaro points out that Red Hat and others say this is not a flaw at all, but expected behavior.

Submission + - Wikileaks.org users at risk due to a Web vulnerability (wikileaks-forum.com)

An anonymous reader writes: We have been made aware of a potential security risk with open source software Wikileaks is utilizing which uses a flash library to display PDF files in .swf format. Two vulnerabilities XSS and content spoofing can be used by malicious users. Whether to affect the privacy of users of wikileaks. eg: Using Flash components specifically to decloack behind Tor network users OR link to external content to discredit Wikileaks, something Wikileaks should avoid given the nature of the content published on Wikileaks servers. Given the fact that most browsers use plugins to enable the reading of PDF's, we strongly urge Wikileaks to link directly to PDF files instead of using third party software that could put users at risk

Submission + - Woz on being Aussie, and escaping Steve Jobs 'dogma' (afr.com)

Techy77 writes: Apple co-founder Steve Wozniak has become an Aussie permanent resident. Wide-ranging interview on how Apple is escaping Steve Jobs' "dogma", why Google Glass is an admirable failure and why he isn't universally liked within Apple.
Toys

Ask Slashdot: What Can I Really Do With a Smart Watch? 232

kwelch007 writes I commonly work in a clean-room (CR.) As such, I commonly need access to my smart-phone for various reasons while inside the CR...but, I commonly keep it in my front pocket INSIDE my clean-suit. Therefore, to get my phone out of my pocket, I have to leave the room, get my phone out of my pocket, and because I have a one track mind, commonly leave it sitting on a table or something in the CR, so I then have to either have someone bring it to me, or suit back up and go get it myself...a real pain. I have been looking in to getting a 'Smart Watch' (I'm preferential to Android, but I know Apple has similar smart-watches.) I would use a smart-watch as a convenient, easy to transport and access method to access basic communications (email alerts, text, weather maps, etc.) The problem I'm finding while researching these devices is, I'm not finding many apps. Sure, they can look like a nice digital watch, but I can spend $10 for that...not the several hundred or whatever to buy a smart-watch. What are some apps I can get? (don't care about platform, don't care if they're free) I just want to know what's the best out there, and what it can do? I couldn't care less about it being a watch...we have these things called clocks all over the place. I need various sorts of data access. I don't care if it has to pair with my smart-phone using Bluetooth or whatever, and it won't have to be a 100% solution...it would be more of a convenience that is worth the several hundred dollars to me. My phone will never be more than 5 feet away, it's just inconvenient to physically access it. Further, I am also a developer...what is the best platform to develop for these wearable devices on, and why? Maybe I could make my own apps? Is it worth waiting for the next generation of smart-watches?

Slashdot Top Deals

"More software projects have gone awry for lack of calendar time than for all other causes combined." -- Fred Brooks, Jr., _The Mythical Man Month_

Working...