Saturday, December 27, 2014

How To Hack Test Your WPA/WPA2 Wi-Fi With Kali Linux & Aircrack-ng

Kali Linux can be used for many things, but it probably is best known for its ability to penetration test, or “hack,” WPA and WPA2 networks. There are hundreds of Windows applications that claim they can hack WPA; don’t get them! They’re just scams, used by professional hackers, to lure newbie or want-to-be hackers into getting hacked themselves. There is only one way that hackers get into your network, and that is with a Linux-based OS, a wireless card capable of monitor mode, and aircrack-ng or similar. Also note that, even with these tools, Wi-Fi cracking is not for beginners. Playing with it requires basic knowledge of how WPA authentication works, and moderate familiarity with Kali Linux and its tools, so any hacker who gains access to your network probably is no beginner!
Important notice: Hacking into anyone’s Wi-Fi without permission is considered an illegal act or crime in most countries. We are performing this tutorial for the sake of penetration testing, hacking to become more secure, and are using our own test network and router.

Step One:

Start Kali Linux and login, preferably as root.



Step Two:

Disconnect from all wireless networks, open a Terminal, and type airmon-ng



This will list all of the wireless cards that support monitor (not injection) mode. If no cards are listed, try disconnecting and reconnecting the card and check that it supports monitor mode. You can check if the card supports monitor mode by typing ifconfig in another terminal, if the card is listed in ifconfig, but doesn’t show up in airmon-ng, then the card doesn’t support it.
You can see here that my card supports monitor mode and that it’s listed as wlan0.

Step Three:

Type airmon-ng start followed by the interface of your wireless card. mine is wlan0, so my command would be: airmon-ng start wlan0



The “(monitor mode enabled)” message means that the card has successfully been put into monitor mode. Note the name of the new monitor interface, mine is mon0.

Step Four:

Type airodump-ng followed by the name of the new monitor interface, which is probably mon0.


Step Five:

Airodump will now list all of the wireless networks in your area, and lots of useful information about them. Locate your network or the network that you have permission to penetration test. Once you’ve spotted your network on the ever-populating list, hit Ctrl + C on your keyboard to stop the process. Note the channel of your target network.


Step Six:

Copy the BSSID of the target network.



Now type this command:
airodump-ng –c [channel] –bssid [bssid] –w /root/Desktop/ [monitor interface]
Replace [channel] with the channel of your target network. Paste the network BSSID where [bssid] is, and replace [monitor interface] with the name of your monitor-enabled interface, (mon0).

A complete command should look like this:
airodump-ng -c 10 --bssid 00:14:BF:E0:E8:D5 -w /root/Desktop/ mon0
 

Now press enter.

Step Seven:

Airodump with now monitor only the target network, allowing us to capture more specific information about it. What we’re really doing now is waiting for a device to connect or reconnect to the network, forcing the router to send out the four-way handshake that we need to capture in order to crack the password.
Also, four files should show up on your desktop, this is where the handshake will be saved when captured, so don’t delete them!

But we’re not really going to wait for a device to connect, no, that’s not what impatient hackers do. We’re actually going to use another cool-tool that belongs to the aircrack suite called aireplay-ng, to speed up the process. Instead of waiting for a device to connect, hackers use this tool to force a device to reconnect by sending deauthentication (deauth) packets to the device, making it think that it has to reconnect with the router.

Of course, in order for this tool to work, there has to be someone else connected to the network first, so watch the airodump-ng and wait for a client to show up. It might take a long time, or it might only take a second before the first one shows. If none show up after a lengthy wait, then the network might be empty right now, or you’re to far away from the network.

You can see in this picture, that a client has appeared on our network, allowing us to start the next step. 


Step Eight:
leave airodump-ng running and open a second terminal. In this terminal, type this command:
aireplay-ng –0 2 –a [router bssid] –c [client bssid] mon0
The –0 is a short cut for the deauth mode and the 2 is the number of deauth packets to send.
-a indicates the access point (router)’s bssid, replace [router bssid] with the BSSID of the target network, which in my case, is 00:14:BF:E0:E8:D5.
-c indicates the clients BSSID, noted in the previous picture. Replace the [client bssid] with the BSSID of the connected client, this will be listed under “STATION.”
And of course, mon0 merely means the monitor interface, change it if yours is different.

My complete command looks like this:
aireplay-ng –0 2 –a 00:14:BF:E0:E8:D5 –c 4C:EB:42:59:DE:31 mon0


Step Nine:
Upon hitting Enter, you’ll see aireplay-ng send the packets, and within moments, you should see this message appear on the airodump-ng screen!


This means that the handshake has been captured, the password is in the hacker’s hands, in some form or another. You can close the aireplay-ng terminal and hit Ctrl + C on the airodump-ng terminal to stop monitoring the network, but don’t close it yet just incase you need some of the information later.

Step Ten:


This concludes the external part of this tutorial. From now on, the process is entirely between your computer, and those four files on your Desktop. Actually, the .cap one, that is important. Open a new Terminal, and type in this command:
aircrack-ng -a2 -b [router bssid] -w [path to wordlist] /root/Desktop/*.cap
-a is the method aircrack will use to crack the handshake, 2=WPA method.
-b stands for bssid, replace [router bssid] with the BSSID of the target router, mine is 00:14:BF:E0:E8:D5.
-w stands for wordlist, replace [path to wordlist] with the path to a wordlist that you have downloaded. I have a wordlist called “wpa.txt” in the root folder.
/root/Desktop/*.cap is the path to the .cap file containing the password, the * means wild card in Linux, and since I’m assuming that there are no other .cap files on your Desktop, this should work fine the way it is.

My complete command looks like this:
aircrack-ng –a2 –b 00:14:BF:E0:E8:D5 –w /root/wpa.txt  /root/Desktop/*.cap


Now press Enter.

Step Eleven:

Aircrack-ng will now launch into the process of cracking the password. However, it will only crack it if the password happens to be in the wordlist that you’ve selected. Sometimes, it’s not. If this is the case, then you can congratulate the owner on being “Impenetrable,” of course, only after you’ve tried every wordlist that a hacker might use or make!

Cracking the password might take a long time depending on the size of the wordlist. Mine went very quickly.

If the phrase is in the wordlist, then aircrack-ng will show it too you like this:






The passphrase to our test-network was “notsecure,” and you can see here that aircrack found it.

If you find the password without a decent struggle, then change your password, if it’s your network. If you’re penetration testing for someone, then tell them to change their password as soon as possible.

Wednesday, April 23, 2014

Banglore City Police website defaced by pakistani hackers

The official police website of the Bangalore City police was hacked and defaced by Pakistani hackers. The defacement contains a message about the Indian governments role in Kashmir. This defacement highlights the increased hacktivist activity in South Asia


Saturday, September 28, 2013

22 years old Chartered Accountant student hacks into Celebrities E-taxation Accounts



Last week a 21-year-old chartered accountant student from Hyderabad was arrested for hacking into E-taxation Account of Industrialist Anil Ambani.

During the probe Mumbai Police’s crime branch has emerged that Anil Ambani's account was also fraudulently accessed from Noida.

4 million US citizens personal data sold online by Hacker


An illegal service that sells personal data of US citizens online, which can then be used for identity theft hacked into the networks of three major data brokers and Hacker stole their databases.

Cyber attack has given them access to Social Security Numbers, dates of birth, and other personal details that could put all our finances at risk.

Friday, September 27, 2013

#OpSyria: Teamr00t Hack Syrian Government Site


The Syrian government is almost certainly responsible for a blackout Thursday that shut down virtually all Internet service in the country. However, The Syrian government blamed the outage in internet service and mobile coverage in some areas on the armed groups' sabotage acts against cellular broadcast centers.
Hacker with name Teamr00t has hacked and defaced Syrian government and showed their support for the people of Syria against President Bashaar Al-Assad's latest actions in shutting down the internet.

Deface message
President Bashaar Al-Assad You have taken a step too far in shutting down the internet so the outside world cannot see the horrific crimes you are committing upon your own people and this will not be tolerated by the world watching!

The Syrian people have the right to freedom of speech, the right to live a normal happy life and the right to have access to the internet to connect with the rest of the world. By shutting down the internet you have denied your people their rights, and this will no longer be tolerated.

We have seen too many massacres, too much corruption, too much brutality inflicted upon the Syrian people and enough is enough! By shutting down the internet you have taken a step too far and you will not escape justice nor will you escape Teamr00t!

To the people of Syria we would like to assure you that we will do everything in our power to help you. You will not be the forgotten minority nor will we sit back and allow the world to forget you the Syrian people who so desperately need our help. Stay strong for you are not alone. We will do whatever it takes to help you gain back your freedom.

"Teamr00t Has Arrived!!! We are the voice for the suppressed people of the world, and we will show you the truth!"

Hackers Target :

    http://www.experts-sy.org/
    http://www.syriaspin.org/user/?page=home
    http://www.qasyoun.edu.sy/


Anyway, The internet service in Syria has resumed Saturday after a two-day outage.

Thursday, September 26, 2013

Russian Hacker sale Android Firefox Zero-Day Exploit for $460 only


A Russian Exploit writer and underground Hacker who goes by the handle "fil9" put up an Android Firefox Zero-Day Exploit for Sale in an open Exploit Market.

Author claims a Zero Day vulnerability in Firefox for Android, which works on Firefox versions 23/24/26 (Nightly).

Wednesday, September 25, 2013

Android Device Manager allows user to Lock, Wipe and Locate device remotely


If you lose your device, Google lets you secure it instantly from afar through Android Device Manager, that let you locate and remotely wipe your phones and tablets.

The latest update to Android Device Manager enables remote password locking, overrides the built-in Pattern, PIN code, Face unlock or password-based security, making sure your data doesn’t fall into wrong hands.

To get started, go to google.com/android/devicemanager on your computer and go through your list of devices that are connected to your Google account.

I tried the process with my Samsung Galaxy S4, and it worked like a charm. Google’s new feature is a very useful one for those who don’t have a lock on their phone and want to make sure their data is protected.

A lock request will immediately secure any device connected to Wi-Fi or a cellular network, even if it's actively being used. If a thief has turned off a phone or enabled Airplane Mode, the lock will take effect as soon as a data connection is reestablished.

You can hit the Ring button, making your Android device ring at the maximum volume, even if it is on silent, so you can figure out where your phone is.

Are you already using Android Device Manager for your Android phone? What are your thoughts on this new remote lock feature that is now available? We always appreciate your comments.

Wednesday, May 2, 2012

Flashback malware Creater earning $10,000 per day from Google Ads


In a recent analysis of the business model behind the Flashback Trojan, Symantec security researchers reported that the main objective of the malware is revenue generation through an ad-clicking component. Security researchers at Symantec are estimating that the cyber-crimibals behind the Flashback Mac OS X botnet may have raked in about $10,000 a day.
 

Oracle Database new zero day exploit put users at risk


Oracle has recommended workarounds for a zero-day Oracle Database flaw that was not fixed in the company's April critical patch update. Oracle issued a security alert for Oracle TNS Poison, the vulnerability, disclosed by researcher Joxean Koret after he mistakenly thought it had been fixed by Oracle, allows an attacker to hijack the information exchanged between clients and databases.

Thursday, March 15, 2012

Anonymous Hacker Arrested After British Pregnancy Advisory Service (BPAS) Hack



According to a news release by Scotland Yard, officers from the Police Central e-Crime Unit (PeCU) arrested the man, who has been linked to the Anonymous hacktivist group, at an address in Wednesbury in the West Midlands. The suspect was a 27 Years old man who has been charged for defacing and hacking into the website of Britain's largest single abortion provider. Official website of The British Pregnancy Advisory Service (BPAS) was compromised yesterday, with a message from a hacker calling themselves "Pablo Escobar". The hacker claimed himself as a part of Anonymous. BPAS claimed that there were "about 26,000 attempts" to break into its website over a six-hour period. 

For a certain period of time yesterday, visitors to the BPAS website saw an anti-abortion message. In a series of tweets, someone using the name "Pablo Escobar" claimed that the names of women who had undergone abortions had been accessed from the BPAS site, and would be released today (Friday). It appears that the authorities moved quickly to reduce the possibility of personal details of people who had contacted the BPAS site being made public.

This month is going worse and worse for Anonymous and their supporters, 1st Operation Unmask by Interpol, then FBI arrested all the key members of Lulzsec with the help of former Anon leader Sabu and so on.

Thursday, March 1, 2012

Interpol #TangoDown, Suspected 25 Anonymous arrested



Interpol’s Web site (www.interpol.int) went down Tuesday just hours after the international police agency announced the arrest of 25 suspected members of the hacking collective Anonymous in Argentina, Chile, Colombia and Spain.

The authorities in Argentina, Chile, Colombia and Spain carried out the arrests and seized 250 items of IT equipment and mobile phones, Interpol says.Those arrested are aged between 17 and 40.

A National Police statement said two servers used by the group in Bulgaria and the Czech Republic had been blocked.It said the four included the alleged manager of Anonymous' computer operations in Spain and Latin America, who was identified only by his initials and the aliases "Thunder" and "Pacotron".

Authorities in Europe, North America and elsewhere have made dozens of arrests, and Anonymous has increasingly attacked law enforcement, military and intelligence-linked targets in retaliation. Earlier this month the group knocked the C.I.A. Web site offline. A week earlier, the group intercepted a conference call between the Federal Bureau of Investigation and Scotland Yard and released a 16-minute recording of the call.

Spanish police traced back IP addresses from server logs, leading to 10 suspects in Argentina, six in Chile and five in Colombia, responsible for defacement of websites and publishing confidential data, including the personal data of the security detail of unnamed top officials, according to Agence France Presse.

The group had set up a chat-room to help run computer attacks in Spain and Latin America.After the arrests, a call went out in chat-rooms affiliated with the suspects for supporters to attack the Spanish police website. The petition specifically asked for people from outside of Spain to carry out the attacks "so that the police would not have enough data to lead to new arrests", according to the statement.

Anonymous has become increasing politicised over the last year, particularly over issues of online rights and the international controversy over whistleblowing website WikiLeaks.

Wednesday, February 29, 2012

FBI Will Shutdown DNSChanger Name Servers On March 8 (Operation Ghost Click)



It is widely known to all that the FBI will shut down the DNSChanger name servers on the 8th March, so it can be expected that the Internet connection of many users over the whole spectrum will be hampered during this operation because the trojan named DNSChanger has occupied millions of computers in more than 100 countries. FBI has planned the whole stuff earlier in November 2011 & it was named Operation Ghost Click. What many people do not know is that the clean DNS servers which are operated by the Internet Systems Consortium (ISC) and used to replace the rogues will be shut down on March 8, 2012. From the start, the US District Court for the Southern District of New York permitted the ISC to operate these servers for a period of 120 days. However, on February 17, 2012 the US government requested this deadline be extended to July 9, 2012.

Barring an extension from the FBI, those systems still infected with DNSChanger will cease receiving DNS services from the ISC controlled name servers on this date.  In other words, they will not be able to properly access internet resources.  This gives information security professionals less than two weeks to detect, locate and remediate any systems on their networks that are still infected. The DNSChanger Working Group (DCWG) estimates there are still approximately 450,000 systems still infected as of January 28, 2012. Other statistics show that DNSChanger may be present in half of the Fortune 500 companies as well as at least 27 government organizations. In early February 2012 Internet Identity disclosed there were 3 million systems still infected globally. This is a relatively small number of systems when compared to other virus outbreaks.  Regardless it represents a challenge to security professionals. This can be a substantial undertaking for large enterprises.  The nature of DNSChanger was to redirect infected systems to malicious destinations.  Many of these sites in turn installed additional malware.  By finding a DNSChanger infected system you will be finding a system that has additional infections. This should justify the need for a thorough sweep for DNSChanger infections. Luckily there are many resources available to detect and remediate DNSChanger infections.  The easiest way is to utilize a network monitoring tool to isolate DNS traffic to the ISC operated DNS resolvers.

The Offending Netblocks Are:-
85.255.112.0/20 (85.255.112.0 through 85.255.127.255)
67.210.0.0/20 (67.210.0.0 through 67.210.15.255)
93.188.160.0/21 (93.188.160.0 through 93.188.167.255)
77.67.83.0/24 (77.67.83.0 through 77.67.83.255)
213.109.64.0/20 (213.109.64.0 through 213.109.79.255)
64.28.176.0/20 (64.28.176.0 through 64.28.191.255)

Tuesday, February 28, 2012

The GIFiles By Wikileaks Publishing: The Global Intelligence Files & Five Million E-mails From Stratfor



In the last month of 2011 U.S.-based security think tank Stratfor faced cyber attack from Hactvists. Anonymous claimed that they have stolen thousands of credit card numbers and other personal information belonging to clients of Stratfor’s confidential client list, which includes entities ranging from Apple Inc. to the U.S. Air Force to the Miami Police Department, and mining it for more than 4,000 credit card numbers, passwords and home addresses. But later in a press release Anonymous dines that attack so its quit difficult to figure out that who was really behind the hack.

But from this Monday Wikileaks has  planned to release over 5 Million emails from Stratfor Global Intelligence, whose website was hacked and emails and customer data stolen in December. 
According to official website Wikileaks:- 

"On Monday February 27th, 2012, WikiLeaks began publishing The Global Intelligence Files, over five million e-mails from the Texas headquartered "global intelligence" company Stratfor. The e-mails date between July 2004 and late December 2011. They reveal the inner workings of a company that fronts as an intelligence publisher, but provides confidential intelligence services to large corporations, such as Bhopal’s Dow Chemical Co., Lockheed Martin, Northrop Grumman, Raytheon and government agencies, including the US Department of Homeland Security, the US Marines and the US Defence Intelligence Agency. The emails show Stratfor’s web of informers, pay-off structure, payment laundering techniques and psychological methods..."

Wednesday, February 22, 2012

Iran will Develop their own security Software, No more foreign Solution



According to latest report, Iran's Information and Communications Technology Minister announce that - Iran has prohibited import of foreign computer security software.

Because International sanctions stopped Iran from obtaining anti-virus software. So, Iran stressed that no foreign software for computer security will be imported into the country, adding that Iran will rely on its own software, made by local developers. The Bonian Daneshpajouhan Institute has about 25 smaller firms that develop domestic security software of various nature, and country will rely on it. 

Three Hackers From Anonymous Arrested In Greece



Earlier this month Greece faced massive cyber attack from Anonymous and after investigation Greek police said they had arrested an 18-year-old suspected of hacking into the justice ministry's website. Also two other suspect aged 16 & 17 also being sought over the case.  In the February 2nd hackers from anonymous performed a cyber-attack on the Greek Ministry of Justice website, and warned of plans to target a further 300 ministry and media sites. The hack was apparently a protest against the Greek government's signing of the Anti-Counterfeiting Trade Agreement (ACTA), which is designed to reduce Internet piracy. After that Greek police confirmed via twitter that they have started investigation and all the countermeasures have been taken. Indeed the output is in-front of us, 3 teenagers from Greece are behind the bar. The authority also said- The three youths have been linked to dozens of cyber attacks against Greek websites, using the alias Greek Hacking Scene and the nicknames "delirium", "nikpa" and "extasy". Authority also confirmed that these teens may have to face 1 year of imprisonment.

This the second time of this year when hackers from Anonymous get busted by police. In January a 22 year aged student arrested in south-western Poland for allegedly hacking the prime minister's website and local authority said that he was a part of Hactivist Anonymous. 

Friday, February 10, 2012

Anonymous Exposed Personal Details Of Top Officers Of Oakland City



#OccupyOakland movement continues. Today top city official of Oakland confirms that their personal details has been stolen. Concerned with the continuous acts of police brutality perpetrated by law enforcement in Oakland, California, the online hacktivist group Anonymous has published the personal details of some of the city’s leading officials. All the hacked credentials including Full name, Address, Phone Number, Social Network Details and other personal details has been openly posted on pastebin by Anon hackers. 

In the #OccupyOakland Press Release Anonymous said:-

"Citizens of Oakland -
Anonymous has been watching. Since the inception of Occupy Oakland, We have been actively monitoring your behavior, and exposing the identities and sensitive information of Officers of the Oakland Police Department; as they have continued to act in an unprofessional and violent manner. You tear gassed Us. You shot Us with your weapons. You arrested Us. You beat Us. You also did this to Our Friends, and to Our Families. We watched as you cut budgets, cut Our jobs, closed Our schools, Our parks, and Our libraries, while leaving your own salaries alone. We laughed in disgust as Deanna Santana said she would need to speak to her attorney before discussing her pay cut. The people on this list are supposed to represent the best of what the City of Oakland has to offer. If they are the best, why is there so much trouble within the Police Department, and in the City of Oakland?
We are shocked and disgusted by your behavior. Before you commit atrocities against innocent people again, think twice.
You should have expected Us..."

#OccupyOakland Anonymous Performed DDoS Attack On Oakland Police & Exposed Confidential Data



Another Occupy Wall Street protest by Anonymous. Previously Anonymous Hacked IACP & Exposed 600 MB of Personal Data and this time the target was Oakland police. Members of the 'hacktivist' launched a DDOS attack that brought down the main web site of the Oakland Police Department for much of last night, cracked at least part of the security on an Oakland city government server and posted information on the names and data structure of Oakland city servers and the names, addresses and other personal data on Oakland police.

Members of the group have also put out the call for more hacked data and offered a $1,000 reward for specific data on the officer who fired the riot-control weapon that critically injured Iraq War veteran Scott Olsen. Olsen, a former Marine who participated in the protest Tuesday night, was apparently struck in the head by either a tear-gas canister or flash-bang grenade fired by Oakland riot police during a violent effort to drive OccupyOakland protesters off the streets.

In a Press Release Anon Said:-

"#OccupyOakland has come under attack from city police, who now appear to be calling in reinforcements from Palo Alto. A protester who did two tours in Iraq is in critical condition with fractured skull and brain injury after a cop shot him in the head with a "non-lethal" weapon. A crowd of protesters were deliberately hit with a flashbang while rendering first aid to an injured protester. Police claimed in a recent press release that "no injuries" have been reported so far.

These are among the most disturbing and criminal acts to be have been proven on the part of U.S. police since NYPD officers were outed as having routinely planted drugs on suspects earlier this month. The time has come to retaliate against Oakland police via all non-violent means, beginning with doxing of individual officers and particularly higher-ups involved in the department's conduct of late.
Those willing to assist in doxing should send any found materials to transistor@hushmail.com. To work with Anonymous, use an IRC client to join irc.anonops.li #anonops.
I'm offering a $1,000 reward, no questions asked, for the name of the officer who threw a flashbang at the injured Iraqi vet. "

To see the entire press release of Anonymous Click Here.

For more information and to see the server details and other confidential information leaked by Anon Click Here.

Exposed Names, Addresses and other Personal data of Oakland Police are Here.

Thursday, February 9, 2012

US Govt Sites are Targeted by DNSChanger Trojan



Security researcher suspecting that malware named "DNS Changer" still targeting US Govt sites. Even researcher said: "hundreds of Govt sites are infected with that particular malware."

About DNSChanger: 
The malware, known as the “DNSChanger Trojan” quietly alters the host computer’s Internet settings to hijack search results and to block victims from visiting security sites that might help scrub the infections. DNSChanger frequently was bundled with other types of malware, meaning that systems infected with the Trojan often also host other, more nefarious digital parasites.

Earlier few guys ware busted for using the Trojan to control more than four million computers in over 100 countries - including an estimated 500,000 in the United States. Investigators timed the arrests with a coordinated attack on the malware’s infrastructure. The two-pronged attack was intended to prevent miscreants from continuing to control the network of hacked PCs, and to give Internet service providers an opportunity to alert customers with infected machines. Computers still infected with DNSChanger are up against a countdown clock. As part of the DNSChanger botnet takedown, the feds secured a court order to replace the Trojan’s DNS infrastructure with surrogate, legitimate DNS servers. But those servers are only allowed to operate until March 8, 2012. Unless the court extends that order, any computers still infected with DNSChanger may no longer be able to browse the Web.

Wednesday, February 8, 2012

Symantec verifies stolen source code posted by Anonymous is "legitimate"



Symantec is in an ongoing fight against hackers in the group Anonymous that last January attempted to extort a payment of around $50,000 from Symantec in exchange for not publicly posting stolen Symantec source code they had stolen for various older Symantec security products dating to 2006.

Late yesterday, hackers did release the source code for an older version of Symantec's pcAnywhere and Norton Internet Security by uploading it to the Pirate bay website. Symantec confirms this is legitimate Symantec source code, and Symantec spokesman Chris Paden says the concern now is that other code that Anonymous claims to have in its possession will soon be posted as well.

Interesting story: US become victim of Indian spy agency...!



A recently leaked memo reveals that American and Canadian based company’s Apple, Research in Motion and Nokia may have helped the government of India spy on U.S. agencies in order to receive larger shares of the overall Indian cell phone market.

Last week, an Indian hacker crew successfully broke into a secured Indian military government network. The group, the Lords of Dharmaraja (who posted up outdated Norton security source code last week) posted documents that infer Apple, Nokia, and Research In Motion gave the Indian government backdoor access to their devices in exchange for mobile phone market rights.