Critical Port Fail Reveals Real IP Addresses of Users


A newly discovered flaw affecting all VPN protocols and operating systems has the capability to reveal the real IP-addresses of users' computers, including BitTorrent users, with relative ease.
The vulnerability, dubbed Port Fail by VPN provider Perfect Privacy (PP) who discovered the issue, is a simple port forwarding trick and affects those services that:
  • Allow port forwarding
  • Have no protection against this specific attack
Port Forwarding trick means if an attacker uses the same VPN (Virtual Private Network) as the victim, then the real IP-address of the victim can be exposed by forwarding Internet traffic to a specific port.
"The crucial issue here is that a VPN user connecting to his own VPN server will use his default route with his real IP address, as this is required for the VPN connection to work," Perfect Privacy wrote in a blog post on Thursday.

Port Fail affects all VPN protocols including…
  • OpenVPN
  • IPSec
…as well as applies to all operating systems, posing a huge privacy risk.

How Does 'Port Fail' Work?

A successful IP address leak attack requires an attacker to be on the same VPN network as the victim and to know the victim's VPN exit IP address, which could be discovered by tricking a victim into visiting a website control controlled by the attacker.
For example, an attacker with port forwarding enabled can see the request from the victim's actual IP addresses by tricking the victim into opening an image file.
The same attack is possible for BitTorrent users, but, in this case, there is no need for the attacker to redirect the victim to their page.
In this case, the attacker only with the activated port forwarding for the default BitTorrent port, can expose the real IP-address of a VPN user on the same network.
Affected VPN Providers

The flaw affected various large VPN providers. Perfect Privacy tested nine VPN providers out of which five were found to be vulnerable to this flaw and were alerted last week.
VPN providers including Private Internet Access (PIA), Ovpn.to and nVPN have fixed the issue before publication.
However, the company warned, "other VPN providers may be vulnerable to this attack as we could not possibly test all."
VPN aims to make you sure that your real identity remains anonymous on the Internet so that nobody could track the origin of your connection back to you, but this newly discovered flaw shows that it's quite easy to bypass this on some VPN providers.

Islamic State claims responsibility for attack on Bangladesh Shi'ite shrine; one dead!

 Islamic State has claimed responsibility for an attack on a Shi'ite Muslim mosque in Bangladesh on Thursday, killing one person and wounding three as they prayed, the second attack on the country's tiny Shia Muslim community in a month.

Witnesses said three young men stormed into the mosque in northwestern Bogra district and shot at worshippers indiscriminately.

"The attackers entered the mosque and opened fire on the devotees after locking the main gate and then fled immediately after the shooting," police official Ahsan Habib said.

Two people from two nearby villages had been picked up for questioning about the attack, another police officer Arifur Rahman said.

SITE monitoring service said that Islamic State had claimed responsibility for the attack, just as it did for the previous bombing on the biggest Shi'ite shrine in the country.







payback, deploys cutting-edge S-400 air defense system to base after Su-24 downing

Russia deploys cutting-edge S-400 air defense system to Syrian base after Su-24 downing

Edited time: 27 Nov, 2015.An S-400 air defence missile system is deployed for a combat duty at the Hmeymim airbase to provide security of the Russian air group's flights in Syria. © Dmitriy Vinogradov
 An S-400 air defence missile system is deployed for a combat duty at the Hmeymim airbase to provide security of the Russian air group's flights in Syria. © Dmitriy Vinogradov / Sputnik.
 Moscow has deployed its newest S-400 air defense missile system to Khmeimim in Syria as part of a security boost following the downing of a Russian jet by Turkey earlier this week.
 “In accordance with the decision of the Supreme Commander of the Russian Armed Forces, today (on Monday) an S-400 air defense missile system has been promptly delivered, deployed and already began combat duty to provide cover for the area around the Russian Khmeimim air base in Syria,” General-Major Igor Konashenkov, Russia’s Ministry of Defense spokesman, said.

Russian S-400 defense missile system deployed in Syria


Commenting on the decision, Russia's President Vladimir Putin said there was previously no need for such measures, because "no-one imagined the Russian aircraft could be in danger. Russia would've brought S-400s to Syria a long time ago to protect its warplanes, if it entertained the possibility of a traitorous backstab."
Putin reiterated, however, that the S-400 systems are not targeting Russia's partners, "with whom we fight terrorists in Syria together."
But the downing of the Russian Su-24 bomber by Turkey prompted Russia to “ensure the safety of our aircraft during their operations against IS [and] against terrorists LIH and other terrorist groups via more reliable means,” Defense Ministry spokesman Konahsenkov said in a media briefing.
The S-400 is the most advanced anti-aircraft defense system in Russia, and is unparalleled in the world.
It’s designed to ensure air defense using long- and medium-range missiles that can hit aerial targets, including tactical and strategic aircraft as well as ballistic and cruise missiles, at ranges of up to 400 kilometers.
The system consists of a set of radars, missile launchers and command posts, and is operated solely by the Russian military.
Earlier on Tuesday, the Russian Su-24 was shot down by a Turkish F-16 fighter jet near the Turkish-Syrian border.
One Russian pilot was killed by Syrian rebels while parachuting, with the other one was rescued and delivered to Khmeimim airbase.
Despite claims from Ankara, Moscow maintains that its jet, which crashed in Syria, didn’t violate Turkey's airspace.
Shortly after the incident, the MoD announced three steps which were to be taken following the attack on the Russian Su-24 bomber, including the provision of aerial cover by fighter jets for every airstrike, the boosting of air defense by deploying guided missile cruisers off the Latakia coast, and suspending all military-to-military contacts with Turkey.
Khmeimim airbase in Latakia, Syria, accommodates Russian Air Force squadrons of Su-27SM and Su-30 fighter jets, Su-34 and Su-24 tactical bombers, which are all taking part in airstrikes on Islamic State and other terror groups in the country.
The airbase is protected by state-of-the-art air defense systems and radars. Khmeimim also has a fully operational unit for maintaining fixed- and rotor-wing aircraft and providing logistical assistance to pilots.



ISIS website on the dark web is hacked and replaced with an advert for Viagra and prozac and a message telling its supporters to 'calm down' 

  • An ISIS propaganda website on the dark web has been hacked by activists
  • The site was replaced with an advert for service selling prozac and viagra 
  • A message also appeared telling ISIS supporters they need to 'calm down' 
  • Hacking group Ghost Sec say they were the ones who infiltrated the site
  • See full news coverage of ISIS at www.dailymail.co.uk/isis 

An ISIS propaganda website on the dark web has been hacked and replaced with an advert for a service selling prozac and viagra tablets which told extremists to 'calm down.'
The site for the terror group appeared on the Tor browser of the dark web last week in a bid to get extremists to join up.
However, less than a week later, the site had been hacked and visitors to the page were greeted with a message for the medication.
It read: 'Too much ISIS. Enhance your calm. Too many people are into this ISIS-stuff. Please gaze upon this lovely ad so we can upgrade our infrastructure to give you ISIS content you all so desperately crave.'
According to the IBT, the website was taken down by Ghost Sec, a group of hackers loosely affiliated to fellow hacking group Anonymous. 
It is believed to be the first time that a hacking group have taken down a website on the dark web.



Hacker group Anonymous claims ISIS is planning 'worldwide day of terror' TOMORROW

ANONYMOUS has claimed ISIS is planning a series of terror attacks around the world today after hacking into its secret data network.

 Man looks at Anonymous on screen
The cyber attackers declared war on the jihadis, also known as ISIL and Daesh, in the wake of the Paris attacks last week.
And now the group has released a statement claming the terrorists are planning up to EIGHT attacks on the same day - November 22.
Alongside the hashtags #22Daesh #OpParis, they published a list of events in France, the United States, Indonesia, Italy and Lebanon which are reportedly being targeted.
They include the WWE wrestling event at the Philips Arena in Atlanta, Georgia and a performance by an American heavy metal band in Milan. Their statement read: “This is a warning to anyone going to any of the events listed below or going to any event with a lot of people, church services included - but the risk of any churches outside Paris/France being targeted is low.”

“There will be big events worldwide on the 22nd, go at your own risk.”

The full list is as follows:

•    Cigales Electroniques with Vocodecks, RE-Play & Rawtor at Le Bizen (Paris)
•    Concrete Invites Drumcode: Adam Beyer, Alan Fitzpatrick, Joel Mull at Concrete (Paris)
•    Demonstration by Collectif du Droit des Femmes, group for women’s rights, (Paris)
•    Feast of Christ the King celebrations (Rome/Worldwide)
•    Al-Jihad, One Day One Juz (Indonesia)
•    Five Finger Death Punch (Milan)
•    University Pastoral Day (Holy Spirit University of Kaslik, Lebanon)
•    WWE Survival Series (US)


 The women’s rights demonstration has already been cancelled after French president François Hollande declared a state of emergency in the wake of the killings.

The French parliament voted to extend this to three months, and includes beefed up security measures such as banning demonstrations.

The hacking group, identified by a trademark mask, added some events are not '100% confirmed' as at-risk.

Anonymous claims to have passed on all intelligence to security services around the world, adding: “They have it and it is their responsibility to do something with it.

“But because they have not done anything with it yet and it's almost the 22nd, we have matters into our hands.

“We only take the responsibility of warning civilians (in case the authorities do not act well enough).”
The online crusaders are thought to be behind thousands of twitter accounts supposedly linked to ISIS removed in recent days.
Terrorists slaughtered 130 people on the streets of Paris last Friday.
Anonymous, also referred to as ‘hacktivists’, declared their opposition to the terror regime following the Charlie Hebdo attack in January, which left 12 dead. But they launched an all-out offensive following the latest French massacre.




Anonymous Hacks ISIS Darknet Website, Trolls By Replacing It With Viagra Ads

 Short Bytes: Anonymous hacktivist group has just hacked an ISIS propaganda website on the dark web. Trolling ISIS and its supporters, the group has replaced it with an advertisement of a website selling drugs like Viagra and Prozac.

 Just a couple of days ago, we reported that ISIS is spreading its operations to the Darknet to escape the hackers and surveillance agencies. However, security experts outlined multiple rookie flaws in the new website, that made it vulnerable to hacking.
Now, GhostSec, a group affiliated with Anonymous, has taken down an ISIS propaganda website on the dark web and replaced it with an advertisement of Viagra and a ‘calm down’ message for ISIS-supporting extremists.
Here’s the complete message posted on the hacked ISIS Darknet website:
Too Much ISIS. Enhance your calm. Too many people are into this ISIS-stuff. Please gaze upon this lovely ad so we can upgrade our infrastructure to give you ISIS content you all so desperately crave.
Along with the message, you can spot an advertisement of a site that calls itself “the number one bitcoin online pharmacy.”
For those who don’t know, darknet is the hidden part of the web that does not show up in the searches or social media. To access this, you need to use software suites like TOR.
It should be noted that Anonymous has now aimed to target the ISIS websites by DDoSing and other methods of hacking. The hacktivist group has faced lots of criticism as Twitter labelled its submitted lists of ISIS accounts as “wildly inaccurate”.
Well, for the time being, Anonymous has trolled the ISIS and its supporters in an epic manner.
