Breaking News

hacking news

internet

cyber crime

Showing posts with label internet. Show all posts
Showing posts with label internet. Show all posts

Friday, May 23, 2014

Internet libel in cyber crime law constitutional

MANILA, Philippines - Netizens will now have to be careful with what they post online.
The Supreme Court (SC) yesterday upheld the constitutionality of a key provision in the controversial Republic Act No. 10175 or Cybercrime Prevention Act that criminalizes online libel.
Justices of the high court voted in session to declare constitutional Section 4 (c) (4) of the law, which penalizes acts of libel as defined in Article 355 of the Revised Penal Code (RPC) committed through a computer system.
The SC ruled that imposition of cyber libel on the “original author of the post” is constitutional, but clarified the same is unconstitutional insofar as it penalizes those who simply receive the post and react to it.
This means only the source of a malicious e-mail, post on social media like Facebook or any website, tweet on Twitter can be held liable under RA 10175.
It was not, however, clarified whether forwarding, commenting, sharing or retweeting the item could be considered a crime under the law. 
SC spokesman Theodore Te said it would be best to wait for the issuance of the decision penned by Associate Justice Roberto Abad for the actual text used by the high court.
Petitioners went as far as asking the SC to void the libel provision in the Revised Penal Code, which the high tribunal did not allow.
“If it (libel under RPC) is not in the ruling, that means its constitutionality remains,” Te told reporters in a press conference.
The high court also declared constitutional the imposition of penalty on those aiding or abetting the commission of cybercrimes under Section 5 of the law.
But the SC declared unconstitutional its application on the crimes of child pornography, unsolicited commercial communications and online libel.
In other words, one who “willfully abets or aids” the author in posting a malicious online item cannot be held criminally liable.
The SC also voided Section 7 of the law, which allows prosecution of online libel and child pornography both under RA 10175 and RPC.
The court said such provision violates the constitutional right against double jeopardy. This means a netizen prosecuted for online libel under the cybercrime law could no longer be charged with a separate case for libel under the Revised Penal Code.
The high court dismissed the constitutional questions raised in the 15 consolidated petitions on 19 other provisions of RA 10175.
Among the key provisions declared constitutional by the SC were the sections penalizing illegal access, data interference, cybersquatting, computer-related identity theft, cybersex, child pornography and allowing search and seizure of computer data.
The SC, however, struck down as unconstitutional three other assailed provisions of the law: Section 4 (c) (3), which penalizes unsolicited commercial communication; Section 12, which authorizes the collection or recording of traffic data in real-time; and Section 19, which authorizes the Department of Justice (DOJ) to restrict or block access to suspected computer data.
The magistrates voted on each of the assailed provisions, but Te said he was not informed as to how the voting per provision went.
RA 10175 was supposed to take effect in October 2012 but its implementation was stopped by the SC through a 120-day temporary restraining order that was extended for an indefinite period in February last year.
With the SC ruling, Te explained the TRO has been automatically lifted. 
“That is functus officio (of no further legal efficacy) since the case is already done. As far as the provisions that were not declared unconstitutional, the presumption of course is that they will now be enforceable because they were not affected by the declaration of the Court,” Te said. – With Christina Mendez, Artemio Dumlao

Source:  http://www.philstar.com/headlines/2014/02/19/1292003/internet-libel-cyber-crime-law-constitutional

_____________________________________________________

Warning!
This page/news article is copyrighted. We do not claim any of this article.

_________________________________________________________________
Read more ...

Free Metro Manila WiFi Act of 2014 filed at the Senate

Senate President Pro Tempore Ralph Recto has filed Senate Bill No. 2232 or the “Free Metro Manila WiFi Act of 2014” which will mandate the government to provide free wireless internet access in key locations in the National Capital Region (NCR).
philippines wifi
“For the Philippines to further establish itself as an emerging economy, a public broadband internet infrastructure must be in place beginning with NCR. Providing free internet access to public buildings and facilities in the national capital will also ensure that our growing labor force will be updated with employment opportunities.” said Sen. Recto said in the bill’s explanatory note.
“Allowing free wireless internet access in key public places in NCR means providing access to the underserved in our society, including getting low-income people online.”
Areas that will be provided with broadband hotpots in NCR shall include, but not limited to the following:
• All national and local government offices;
• Public health centers and hospitals;
• Publick Elementary and High Schools, and State Colleges and Universities;
• Public Parks;
• Ninoy Aquino International Airport (Terminals I, II, II, and IV);
• Public Libraries;
• Tollways and Expressways (North Luzon Expressway, South Luzon Expressway, Metro Mnila Skyway, and Manila-Cavite Expressway);
• Epifanio de los Santos Avenue (EDSA) and other national roads;
• Public transport terminals;
• Port of Manila; and
• Rail Transit Stations (LRT Line 1, MRT Line 2, MRT Line 3, and PNR Southrail).

According to the bill, the WiFi hotspots will use existing commercial ISPs until such time that a national broadband system has been installed. Funds from the National Telecommunications Commission (NTC) and/or savings under the General Appropriations Act will be used for the project.

Source: http://www.yugatech.com/news/free-metro-manila-wifi-act-of-2014-filed-at-the-senate/ 

_____________________________________________________

Warning!
This page/news article is copyrighted. We do not claim any of this article.

_________________________________________________________________
Read more ...

Snowden leak bares US spying on Philippines' text messages


US National Security Agency whistleblower Edward Snowden, who has recently sought asylum in Russia as a fugitive from US laws. AP
MANILA, Philippines — The Philippines is among the countries being secretly monitored by a telecommunications spying program of the US National Security Agency (NSA), as revealed by whistleblower and fugitive Edward Snowden.
Online publication The Intercept, a platform releasing Snowden's leaks, alleged in a post on Tuesday (Manila time) that NSA's cutting-edge surveillance program MYSTIC collects "metadata" and content from mobile networks in the Caribbean, Mexico, Kenya, the Philippines and another unnamed country.
"All told, the NSA is using MYSTIC to gather personal data on mobile calls placed in countries with a combined population of more than 250 million people," The Intercept writers Ryan Devereaux, Glenn Greenwald and Laura Poitras said in the report.
What to read next: Binay, Mar ex-targets of US spying
Metadata are information revealing message or call's time stamp, source and destination--information collected by MYSTIC that may be authorized by the host country and even by the telecommunications firms. 
A 2013 budget justification of the US intelligence community cites the need to fund MYSTIC capable of providing "comprehensive metadata access and content against targeted communications in ___, Kenya, Caribbean, Mexico, and the Philippines."


An entry from the US intelligence community's 2013 budget justification pertaining to the MYSTIC program.
The program also offers "near real-time, complete access to the additional target country's GSM networks," according to the document leaked by Snowden.
Another classified document, provided by Snowden, provides a NSA Special Source Operations' description of MYSTIC as a "program for embedded collection systems overtly installed on target networks predominantly for collection and processing of wireless/mobile communications networks."


Snippet from an undated NSA Special Source Operations memo
"The overt purpose is for legitimate commercial services for the telco's themselves. Our covert mission is the provision of SIGINT," it continued, referring to signals intelligence.
There is no indication  whether MYSTIC also intercepts phone calls and voice data in the Philippines, but it does pull text messaging data.
A separate document reveals an alleged "DSD asset in a Philippine provider site" working on an operation collecting GSM, short message service of SMS and call detail records.


Definition of terms related to the MYSTIC program, from the NSA glossary
"It will soon become a source of lucrative intelligence for terrorist activities in southern Philippines," the document, providing an NSA glossary of cryptic terms.
The report said DSD refers to Defense Signals Directorate, "an arm of the Australian intelligence. (The Australian consulate in New York declined to comment)."
The Intercept also suspects that surveillance in the Philippines is part of the US' show of support for the country's campaign against armed Islam extremists in Mindanao.
The Intercept said it asked NSA to comment, but it only said it does not collect foreign intelligence in an arbitrary and unconstrained way as it follows protocols to protect people's privacy.
"Informed about the NSA’s spying, neither the Bahamian prime minister’s office nor the country’s national security minister had any comment. The embassies of Mexico, Kenya, and the Philippines did not respond to phone messages and emails," the report added.
Philippine laws prohibit wire tapping and related violations not authorized by all parties concerned. Republic Act No. 4200 or the Anti Wire-Tapping Law, however, only covers the monitoring and interception of content.
In February, the Supreme Court upheld penalties under the assailed Republic Act 10175 or the Cybercrime Prevention Act for those who aid and abet activities of illegal access, illegal interception, data interference and system interference, among others.

Source: http://www.philstar.com/headlines/2014/05/20/1325354/snowden-leak-bares-us-spying-philippines-text-messages 

_____________________________________________________

Warning!
This page/news article is copyrighted. We do not claim any of this article.

_________________________________________________________________
Read more ...

Worst Day for eBAY, Multiple Flaws leave Millions of Users vulnerable to Hackers

It's not been more than 36 hours since eBay revealed it was hacked and we just come to know about three more critical vulnerabilities in eBay website that could allow an attacker to compromise users' account once again, even if you have already reset your account password after the last announcement.

Yesterday eBay admitted to the massive data breach that affected 145 million registered users worldwide after its database was compromised. eBay urged its 145 million users to change their passwords after the cyber attack, but are passwords enough? eBay Data breach happened mainly because of their vulnerable infrastructure, not weak passwords.
I think eBay's morning just going to be bad to worse as today, three Security researchers came forward with three more different types of critical flaws in eBay website that leave its 145 million users vulnerable to hackers.


HACKER UPLOADED SHELL ON eBAY SERVER (UNPATCHED)
A critical security flaw in the eBay website for its employees could allow an attacker to upload a backdoor shell, claimed a security researcher, Jordan Jones who have unearthed the vulnerability.
Security researcher, Jordan Jones claims and tweeted from his account that he already reported the critical flaw to eBay, along with a proof-of-concept screenshot which shows that he has successfully uploaded a 'shell.php' file (as shown), a PHP script that allows the attacker to control the server - essentially a backdoor program.
ebay shell
At the time of writing, we confirmed that the file ‘shell.php’ is available on the Ebay server at given location: "https://dsl.ebay.com/wp-includes/Text/Diff/Engine/shell.php", but modified to a blank file.
In a blog post, Jordan has also reported about a cross site scripting vulnerability in the eBay Research Labs page (labs.ebay.com).
PERSISTENT XSS VULNERABILITY ON eBAY (UNPATCHED)
Michael E., another security researcher from Germany reported The Hacker News that he found a Persistent Cross-Site Scripting (XSS) vulnerability on eBay’s auction pages that allowed him to inject arbitrary HTML and Javascript code into the eBay website.
Each time a user visits any infected auction page created by the attacker, the reported persistent XSS vulnerability will execute the unauthorized Javascript code on the users’ browser with a payload to steal their account cookies, in an effort to hijack the user’s account.
ebay xss
Anyone with an appropriate technical knowledge can create an auction page with malicious javascript, as shown in a proof-of-concept link created by the Michael.
http://www.ebay.de/itm/script-script-alert-1-script-x-onfocus-alert-1-autofocus-onl-/281257333177
COOKIE RE-USE VULNERABILITY (UNPATCHED)
In a separate experiment, we have discovered that eBay accepts the same login cookies again and again, even if the victims have logged out or reset their passwords.
Which means by using Michael’s persistent XSS vulnerability, one can steal eBay users’ account cookies in order to get an unauthorized access to the users’ respective accounts, without knowing their previous or updated passwords.
ACCOUNT HIJACKING VULNERABILITY (CRITICAL AND  UNPATCHED)
An Egyptian security researcher ‘Yasser H. Ali’ informed The Hacker News about another critical vulnerability on the eBay website, that can seriously allow an attacker to hijack millions of user accounts in bulk and this exploit could be very successful in the targeted attacks.
For now we are keeping technical details of this vulnerability hidden from our readers, Sorry; because it has not been yet addressed by the eBay security team. But last evening, as a proof of concept Mr.Yasser privately demonstrated the vulnerability step-by-step to ‘The Hacker News’ team and we confirm - IT WORKS. We promise to share the technical details of this interesting flaw, once eBay team will patch it.
eBAY #FAILURE
eBay failed badly to protect its 145 million customers’ sensitive data from the previous data breach and yet has not learned any lesson. There are few points, we would like to highlight about eBay’s passive behaviour towards users’ security.
Two months ago hackers stole a database full of eBay users’ information, including customer names, account passwords, email addresses, physical addresses, phone numbers and birth dates, that can be passed on to other criminals. Such sensitive information could be used by a potential hacker to gather more details about the users by sending spam messages and phishing mails, that could lead to problems with identity fraud.
When companies are hacked, alerting customers is usually the first thing. But according to the media reports, even after 30 hours - eBay hasn't emailed all of its users to notify them that they must change their passwords. Also the company has also not made clear how many people were affected in the latest data breach.
According to a separate news on Daily mail, eBay could be fined £500,000 for breach of its data 18 million Britain users. The penalty can be imposed by the Information Commissioner's Office, ‘would amount to just 2p for each of the and 0.00002 per cent of the company's global annual turnover.’ BAD LUCK!
APPEAL TO eBAY
All the above listed vulnerabilities have been reported to the eBay Security team by each researcher, and we hope someone from eBay security team will definitely read this article to understand the threats they could face from malicious hackers.

eBay should be more concern about the security of its users and protective towards its users’ privacy, as the company is responsible for the hundreds of millions of users if it fails at any point.
Please share this article to aware as maximum users as you can.

Source: http://thehackernews.com/2014/05/worst-day-for-ebay-multiple-flaws-leave.html

_____________________________________________________

Warning!
This page/news article is copyrighted. We do not claim any of this article.

_________________________________________________________________
Read more ...

Philippines police and Interpol smash cyber extortion network

Multi-agency effort sees 58 Filipinos arrested in connection with gang who would dupe victims in to exposing themselves in front of webcams and then blackmail them using the recorded images

Man using webcam

The syndicate would secretly record the victims after tricking them into exposing their bodies or having cybersex Photo: Alamy
Philippine police, backed by Interpol, have arrested dozens of suspected members of an online extortion syndicate who duped hundreds of victims worldwide into exposing themselves in front of webcams, including a Scottish teenager who committed suicide after being blackmailed, officials said on Friday.
At least 58 Filipino suspects in the capital, Manila, and other cities were arrested recently after investigators from Interpol, the US Homeland Security Department and other police agencies traced online chats from some of the victims’ computers, said Philippine National Police Chief Allan Purisima.
Mr Purisima said the syndicate would secretly record the victims after tricking them into exposing their bodies or having cybersex, and later threaten to send the video to their relatives and friends unless they paid, usually from $500 to $2,000 (£300 to £1,200).
He said members of the “sextortion” group would create fake Facebook accounts of fictitious young and attractive women and entice and lure victims with pornographic material after striking up online chats with them.
Hong Kong police Inspector Louis Kwan Chung-yin said more than 470 people from Hong Kong were victimised last year and about 160 so far this year. 
 n one case, a victim paid the equivalent of $15,000 (£9,000). The victims were of various ages.
Sanjay Virmani, director the Interpol Digital Crime Center based in Singapore, said the victims were from Asia, Europe and the United States. He said that the extortionist had been tracked down using evidence from computers and intelligence information from police.
Warning those still engaged in cyber extortion in the Philippines and elsewhere in the world, Mr Virmani said: “You better be prepared for the consequences of your actions because as you can see we have made a commitment to work together. You will be caught and you will be held accountable for your actions.”
Scottish police officer Gary Cunningham said he was representing the 17-year-old boy’s family in tracking down those responsible for his death last year. He said the family was “extremely supportive ... in bringing to justice to individuals out there who have fallen victims to these crimes.”
Senior Superintendent Gilbert Sosa, chief of the Philippine National Police Anti-Cybercrime Group, said he could not specify the amounts extorted from the victims but said they ran into millions of pesos, or tens of thousands of pounds.
“This is not an issue directly involving the Philippines exclusively,” British Ambassador to Manila Asif Ahmad said. “Cybercrime is international, and is an international problem, it respects no nationality or borders. We are all potential victims of cybercrime, none of us are immune.” 

Source: http://www.telegraph.co.uk/news/worldnews/asia/philippines/10802940/Philippines-police-and-Interpol-smash-cyber-extortion-network.html

_____________________________________________________

Warning!
This page/news article is copyrighted. We do not claim any of this article.

_________________________________________________________________
Read more ...
© Copyright 2014, www.pinoysocialnews.com | Designed By