Friday, 31 March 2017

Why server side games generally can’t be hacked

Why server side games generally can't be hacked
We get many question daily asking us how to hack games such as Clash of Clans this article explains why server side games generally can’t be hacked
Overview –
• The Server – This party is responsible for serving content.
• The Client – This party requests content from the Server, and displays them to the user. In most cases, the client is a web browser.
Each side’s programming, refers to code which runs at the specific machine, the server’s or the client’s.
Server Side Code –
Server side is the code that resides at web server.
For every client request code is executed at server side and result is send to the client in simple HTML format.
Performance is lower than client side code due to server round trips.
Client cannot see the business logic though it is stored on server.
Client Side Code –
Client side code is reside at client’s browser itself. It is executed at
client side only. User can easily see the code by View – > Source option.
It is generally used in validation form like text field is empty or not, email address validation etc. It is faster than server side code
Server side code is responsible to execute and provide
the executed code to the browser at the client side. The executed code only have the
values or the results that are executed on the server.
There are many programs out there that claim to be able to hack games such as Clash of Clans, these are all fake, here’s why:
Any so called ‘gem hack’ will not work because the data is stored server side, so editing the data client side will then need to be confirmed server side.
In other words, there is no way to hack such a game. If there were a way, somebody would have figured it out, spread the information, and then it would have to have been patched rapidly. These kinds of games are specifically designed for people to not be able to hack into them. In order to do so you would have to gain access to the server and alter the information that contains things like how many gems you have. This in itself is a near impossible task because this information is sensitive and secure. It’s like if you were trying to gain credit card information off of a website like Amazon. It’s extremely unlikely and illegal that you’ll find a crack, but leaks do occur from time to 

Top 10 Cities in the World in Total Bot Population

top-10-cities-by-total-bot-population-emea-region
Data published by Symantec today reveals the most bot-infected cities and countries across the Europe, the Middle East, and Africa (EMEA) region.
The top 10 ranking was compiled using telemetry data gathered during 2015 from Symantec security products and includes details about bot-infected PCs, Macs, smartphones, tablets and connected smart devices.
Since malicious bot behavior is quite easy to pick up thanks to a constant communications stream originating from infected devices, Symantec had a harder time pinning down infections to each specific country and city.
Based on the number of total bots in one specific city, Istanbul, Turkey was the most infected city, with the largest number of detected bots, followed by another Turkish city, Ankara, the country’s capital.
Symantec says that these two cities accounted for around two-thirds of Turkey’s entire bot population, with Istanbul raking in 29 percent of all bots, and Akara with 28 percent.
The top ten is rounded up by Rome (Italy), Budapest (Hungary), Szeged (Hungary), Moscow (Russia), Petah Tiqwa (Israel), Madrid (Spain), Paris (France), and London (UK).
Grouping the data by country, the top ten reflected the cities ranking, with Turkey, Italy, and Hungary “winning” the first three spots, followed by Germany, France, Spain, the UK, Poland, Russia, and Israel.
Taking into account the number of Internet users in each country, and comparing this data with the number of detected bots, we get a “bot density” factor that provides a more accurate reflection of which countries do an appalling job at securing their computers and connected devices.
According to bot density, the top ten is led by Hungary, with one bot for every 393 users, followed by Monaco (1/457), Andorra (1/591), Israel (1/809), Turkey (1/1139), Latvia (1/1240), Kuwait (1/1373), Italy (1/1829), Cyprus (1/2283), and Poland (1/2330).
With botnets increasingly leveraged for spam and DDoS attacks, the CERT teams of each of these countries will likely be busy in the following months. Don’t forget to check out Symantec’s interactive EMEA Bots map.
Top ten cities by total bot population
1 Istanbul, Turkey
2 Ankara, Turkey
3 Rome, Italy
4 Budapest, Hungary
5 Szeged, Hungary
6 Moscow, Russia
7 Petah Tiqwa, Israel
8 Madrid, Italy
9 Paris, France
10 London, UK
Top ten countries by total bot population
1 Turkey
2 Italy
3 Hungary
4 Germany
5 France
6 Spain
7 United Kingdom
8 Poland
9 Russia
10 Israel

US ISPs can collect your Personal Data and use it for Advertising

us-isps-to-snub-users-privacy-758x426

US ISPs can collect your Personal Data and use it for Advertising

The US legislation is about to pass a law which allows the Internet service providers to collect your information and share your it with advertising agencies.
As per the reports, House of Representatives have voted for a bill which allows the internet service providers to share the user’s personal information to other third parties without the user’s consent. Only thing which is stopping them is a law passed in the Obama’s era, but with that law out of the picture, there is nothing holding them.
The repeal was very strongly backed by many major providers such as AT&T, Verizon and Comcast, who argued that the ISPs were being subject to way more strict privacy laws than companies like Google or Facebook.
The tech giants, including  AT&T, Comcast, Verizon and other were all in favor of this law – it is a no brainer really. They have also argued that these ISPs were being subject to very strict privacy laws compared t0 companies like Facebook and Google.
According to Ajit Pai who is the new head of FCC, this new law will level the online playing field.
This law allows the Internet providers to share personal data of its user’s with marketers and other third parties including exact geolocation, browsing data and much more without even needing anyone’s consent.
The Internet service providers are extremely happy about this all new law as it certainly helps them increase their revenue. The online privacy advocates are furious with the new development.
Evan Greer, campaign director from rights group Fight for the Future told BBC that:
“Today the Congress proved once again that they care lot more about the wishes of corporations that fund campaigns than they do about safety and security of their constituents. People from across the political spectrum are now outraged, and every lawmaker who votes to take away our privacy will regret it come election day.”

Top 10 Most Torrented Movies of this week

\
We are back on with the list of Top 10 Torrented movies of the Week, The Data is only for the Educational Reference Only.
Let’s Go into it

xXx: Return of Xander Cage

Xander Cage is left for dead after an incident, though he secretly returns to action for a new, tough assignment with his handler Augustus Gibbons.

Assassin’s Creed

When Callum Lynch explores the memories of his ancestor Aguilar and gains the skills of a Master Assassin, he discovers he is a descendant of the secret Assassins society.

Fantastic Beasts and Where to Find Them

The adventures of writer Newt Scamander in New York’s secret community of witches and wizards seventy years before Harry Potter reads his book in school.
A spacecraft traveling to a distant colony planet and transporting thousands of people has a malfunction in its sleep chambers. As a result, two passengers are awakened 90 years early.

When the CEO (Jennifer Aniston) tries to close her hard-partying brother’s (T.J. Miller) branch, he and his chief technical officer (Jason Bateman) must rally their co-workers and host an epic office Christmas party in an effort to impress a potential client and close a sale that will save their jobs.

Logan

In the near future, a weary Logan cares for an ailing Professor X somewhere on the Mexican border. However, Logan’s attempts to hide from the world and his legacy are upended when a young mutant arrives, pursued by dark forces.

Arrival

Linguistics professor Louise Banks (Amy Adams) leads an elite team of investigators when gigantic spaceships touch down in 12 locations around the world. As nations teeter on the verge of global war, Banks and her crew must race against time to find a way to communicate with the extraterrestrial visitors. Hoping to unravel the mystery, she takes a chance that could threaten her life and quite possibly all of mankind.

Sing

In a city of humanoid animals, a hustling theater impresario’s attempt to save his theater with a singing competition becomes grander than he anticipates even as its finalists’ find that their lives will never be the same.

Doctor Strange

Dr. Stephen Strange’s (Benedict Cumberbatch) life changes after a car accident robs him of the use of his hands. When traditional medicine fails him, he looks for healing, and hope, in a mysterious enclave. He quickly learns that the enclave is at the front line of a battle against unseen dark forces bent on destroying reality. Before long, Strange is forced to choose between his life of fortune and status or leave it all behind to defend the world as the most powerful sorcerer in existence.

Moana

In Ancient Polynesia, when a terrible curse incurred by the Demigod Maui reaches an impetuous Chieftain’s daughter’s island, she answers the Ocean’s call to seek out the Demigod to set things right.

Zero-Day in IIS 6.0 Affects More than 8 Million Websites

zero-day
Nearly 8 million websites are exposed to a buffer overflow vulnerability in the Internet Information Services (IIS) 6.0 which has been exploited in the wild from July last year, the researchers warn.
This bug was found in ScStoragePathFromUrl function of Web Distributed Authoring and the Versioning (WebDAV) service in the Windows Server 2003 R2’s IIS 6.0. This issue, tracked as CVE-2017-7269, resides in improper validation of an ‘IF’ header in PROPFIND request and can allow a hacker to cause denial-of-service or even allow him to run arbitrary code.
This is discovered by two researchers with the School of Computer Science & Engineering, Information Security Lab, South China University of Technology Guangzhou, China, the vulnerability was exploited in wild in July 2016. Earlier this week, the researchers have published a proof-of-concept on the GitHub and revealed that the Microsoft has already acknowledged the bug.
The exploit abuses PROPFIND method and the IF header. The former, as Trend Micro’s Virendra Bisht explains, “retrieves properties defined on resource identified by Request-URI” and is supported by all the WebDAV-Compliant resources, while the latter “handles state token as well as ETags.”
According to the Bisht, “this vulnerability could be exploited with an overly large ‘IF’ header in the ‘PROPFIND’ request with a minimum of two http resource in IF header.” The researcher also explained that, while successful attacks could lead to remote code execution, unsuccessful attacks could sometimes lead to denial of service conditions.
Data from W3Techs reveals that the Microsoft’s IIS is currently the third most popular web server technology out there, powering 11.4% of all websites. While newer versions of Microsoft’s technology are more popular, IIS 6.0 still accounts for 11.3% of the IIS-powered websites, which results in 1.3% of all websites out there being powered by this version.

90% Of Smart TVs Are Easily Hackable Via Malicious TV Signals

SmartTV-Attack1-scheel
Short Bytes: Do you know that your televisions can be easily hacked and used as a spying weapon by an attacker or government. A security researcher recently demonstrated a method that used rogue TV signals, DVB-T to be precise, to gain root access to smart TVs. Moreover, this attack is almost impossible to detect due to the uni-directional nature of TV signals.
When we wrote about the massive WikiLeaks’ release of  CIA’s hacking tools, we told you about a tool called Weeping Angel, which had the potential to control Samsung smart TVs and turn them into spying devices. But, to infect such TVs, CIA needed physical access to install the spyware.
Now, Rafael Scheel, a security researcher working with OneConsult, has developed his own smart TV attack that allows a hacker to use rogue DVB-T (Digital Video Broadcasting-Terrestrial) signals to get root access on the smart TVs. Getting root access means that the attacker would be able to use the device for all kinds of spying and notorious activities.
Scheel’s method was recently presented at a security conference. He showed that the attacker can execute the attack from a remote location without any user interaction. The attack operates in the background, which means that users won’t be able to notice the attack, according to Bleeping computer.
Scheel says that the center of this attack is Hybrid Broadcast Broadband TV (HbbTV). It’s an industry standard that supported by most TV manufacturers and cable providers. Different TV transmission technologies, like DVB-T, support HbbTV.
SmartTV-Attack1-scheel
Image: Rafael Scheel
Interestingly, any TV connects to a stronger signal. As the cable providers transmit signals from hundreds of miles away, the rogue DVB-T signals can be transmitted from a nearby house or city. The HbbTV standard helps the attacker send a command that instructs a smart TV to load a malicious website in the background.
Scheel developed two exploits for taking over a device. The first exploit was based on CVE-2015-3090, a zero-day leaked by Hacking Team in 2015. The second exploit helped him gain access to the user’s firmware.
Scheel also says that as DVB-T transmission method for HbbTV commands is uni-directional, which means data flows from attacker to TV only, the discovery of attack is tough. So, the attacker can only be caught transmitting the signals in real-time.
Also, any backdoor created using this technique is almost impossible to remove. In Scheel’s testing, the factory reset operation didn’t help.
You can see the video of the Scheel’s presentation here:

How To Open Any Windows App Using Keyboard Shortcuts?

Windows keyboard shortcut main
Short Bytes: If you use some Windows apps more frequent than others then you can create custom keyboard shortcuts for those apps in Microsoft Windows. This can save your valuable time when you use various Windows apps and software on a regular basis. The custom Windows keyboard shortcut for an app can be enabled by visiting the properties of the app’s shortcut file.
Keyboard shortcuts in Microsoft Windows, in fact, on every operating system, have made our lives easier. If there wouldn’t have been these helpful key combinations, then we would have to traverse longer paths to do various tasks.
Microsoft also provides its user’s the functionality to set custom Windows keyboard shortcuts which can be used to open individual apps and software in Windows. This relieves us from the hard work required to open the start menu, find the app, and then open it.
Even if you have saved your favorite apps on the Desktop, using keyboard shortcuts is much easier and faster because you don’t have to visit the desktop every time to open your desired software.

How to create custom keyboard shortcuts to open software in Windows 10?

It’s quite simple to set a custom keyboard shortcut to open a particular app in Windows 10 and previous versions. You can take the help of the following steps to enable custom shortcuts:
  1. Right-click the Windows app’s shortcut file for which you want to create the custom shortcut.
  2. Click Properties.
    Custom Keyboard Shortcut 1
  3. Under the Shortcuts tab, click the Shortcuts Key field.
    Custom Keyboard Shortcut 2
  4. Type any alphabet, symbol, or Numpad key according to your choice.
  5. Windows will set the custom shortcut for the app according to the key you’ve chosen. For instance, you can use the letter C for Chrome. So, the shortcut will become CTRL+ALT+C.
    Custom Keyboard Shortcut 3
  6. Click Apply and click Ok.
Now, you can open Google Chrome directly by pressing the keyboard shortcut. This method works only for shortcut files. So, if an app doesn’t have a shortcut, you can create one. You can’t use the characters which are activated using the shift key, i.e., the !, @, #, $, etc.
Custom Keyboard Shortcut 4
The /,*,-,+ keys that are part of the Numpad can work without pressing CTRL+ALT. So, if you set one these keys as the keyboard shortcut, you can launch a particular app by pressing that key alone.
If you want to remove the custom Windows keyboard shortcut at later stage, follow the above method till Step 4 and press the Backspace key in the Shortcuts field.
Also Read: How To Re-Enable “Backspace” Button To Go Back In Google Chrome?

Create shortcut file for Windows Store apps

You can also create custom Windows keyboard shortcuts for the modern apps present on the Windows store. Here are the steps to create a shortcut file for modern apps:
  1. Open Start Menu in Windows.
  2. Navigate to the modern app for which you want to create a shortcut file.
  3. Click and drag the app to the desktop.
Windows will automatically create a shortcut file for the modern app. Now, you can go to the properties and set a custom keyboard shortcut for the app.