Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Saturday, 10 September 2011

Ethical hackers battle to prevent 'information security apocalypse'





(CNN) -- Barely a day passes without news of another major computer security breach. Last week a hacking network named "Hollywood Leaks" began their attack on the personal data of celebrities, officially adding the glitterati to a roll of shame that already includes targets as diffuse as Sony, the Church of Scientology and PayPal.

However only a few days before the emergence of this latest hacking outfit, a far less conspicuous but similarly-skilled group met at a London hotel to discuss the other side of all matters of information security, otherwise known as "infosec".

The inaugural 44Con was Britain's first major conference for the good guys of infosec. Among the 300 delegates and speakers were a number of so-called "white hats", programmers and penetration testers specifically employed to discover businesses' weak spots.

Using information from these ethical hackers, manufacturers can remedy or "patch" the problem before its release and companies can take measures to safeguard their data.

Everybody had a look at the Sony thing and thought, 'Oh God, I hope I'm not next.'
Steve Lord, foudner 44Con

Although their more destructive brethren might continue to grab headlines, 44Con demonstrated that the fight against hackers, and other more traditional threats to information security, is also strong.

"The way people use and consume media and share information has drastically changed over the past ten years," said Steve Lord, a security professional and co-founder of 44Con.

"The information that we used to think would stay on a computer, in an increasingly networked world, it goes everywhere. So there is an increasing demand for people to secure that information because otherwise people won't put it there."

44Con attracted representatives from governments and members of the military, alongside risk managers, consultants and students. According to Lord, the roll call included "hackers, freaks, geeks, spooks and kooks," none of whom was required to identify themselves further than a first name.

"It's everyone around the table all looking at the same problems and hopefully coming up with some solutions," Lord said.

High-profile hacking is only one strand of the ongoing battle to protect electronic information from damage or infiltration.

Events at 44Con ran the gamut from workshops demonstrating old-fashioned lock-picking with a paperclip, through discussions of threats to iPads and smart phones and even a presentation of how NASA's transmissions to astronauts have recently been intercepted.

"We've got a serious problem here... like the global financial crisis," said Haroon Meer, a researcher at the infosec consultancy, Thinkst. But although Meer also referred to "our upcoming security apocalypse", others were focused on how intelligence can be used to predict attacks before they occur and, crucially, how to acquire boardroom backing for improved security measures.

We've got a serious problem here... like the global financial crisis.
Haroon Meer, infosec consultant

Infosec professionals often converse in a language that is not always immediately accessible to a layman (executives included), but the result of their endeavors can often be startlingly clear.

"Every single guy at boardroom level that I speak to says, 'Are we going to be the next Sony?'" said Lord, referring to the recent devastating hack on the electronics giant. "Everybody had a look at the Sony thing and thought, 'Oh God, I hope I'm not next.'"

Sony given 'epic fail' award from hackers

Several presentations at 44Con offered chilling demonstrations of the vulnerabilities of common business devices. Alex Plaskett, a consultant at MWR InfoSecurity, who described himself as someone who has been "professionally breaking things" for many years, performed a so-called "drive-by" exploit on a Windows 7 smart phone.

Independent security consultant, Neil Kettle, performed a take-down of the much garlanded online banking security software Trusteer Rapport, running a key-logging program that replicated on screen anything a user might be entering into supposedly secure password fields.

Another security expert Roelof Temmingh showcased the most recent version of Maltego, software that analyzes and compares freely available information from numerous social networking sites.

Using the website of the Executive Office of the President as an example, Temmingh was able to extract specific information such as favored restaurants among White House staffers, as well as other behavioral trends.

"Even if we don't want to attack, what can we learn?" Temmingh asked, before revealing that at least one member of the Bush administration was a fan of Moody's Diner, visited a psychic medium named "Rosemary the Celtic Lady" and was a keen editor of Wikipedia pages.

The examples were deliberately banal and outdated, but the implication was clear. Through similar paths, hackers of more nefarious intentions could determine what versions of browsers are being used in the White House, for instance, and probe specific vulnerabilities. "If you can exploit the browser of a leader, then you've exploited the PC of a president," Temmingh warned.

However it was left to Alexis Conran, a former confidence trickster who appeared in a British TV show called "The Real Hustle", to sum up the challenges still faced by the infosec sector.

"The general public will only take steps to protect themselves if they know what the dangers are," he said.

[CNN]

Thursday, 8 September 2011

Massive Hack Attack Plunges Netherlands Into the Stone Age


An attack on a company that certifies secure websites has forced the Dutch government to abandon email for faxes and snail mail. How long before frustrated citizens take to the streets and smash windows with postal scales and rolls of thermal paper?
A recent hack of the Dutch-based security company Diginotar has rendered many of the Dutch government's website's insecure and unusable for official business. According to the Wall Street Journal
In what is shaping up as one of the most damaging hacking cases for a single country, courts have advised lawyers to switch to fax and old-fashioned paper mail instead of email.
Lawyers can't access the Dutch Bar Association's Intranet, and have been told by courts to switch to fax machines and mail until the problems are solved.
So what's going on? While most of the world has been too bored by the details to really care, a huge hacking attack has rocked the system of certification many important websites rely on to assure their authenticity. A hacker broke into Digitnotar, one of the largest issuers of these certificates, and stole certificates allowing them to set up fraudulent websites and snoop on user's personal information and communication. For more than a week in July, fake certificates for sites like Google, Twitter—even the CIA—were in circulation.
According to a report by the security firm Fox-IT, the certificates were likely used to intercept communications in Iran. A notorious Iranian hacker named Comodohacker has claimed responsibility for the hack, hiding this understated message in the script he used to bust into Digitnotar.
"THERE IS NO ANY HARDWARE OR SOFTWARE IN THIS WORLD EXISTS WHICH COULD STOP MY HEAVY ATTACKS
MY BRAIN OR MY SKILLS OR MY WILL OR MY EXPERTISE"
As far as hacking attacks go, the Diginotar attack wasn't as obviously spectacular as, say, a massive dump of user names and passwords. But Dutch people now have to remember how to attach a stamp to a letter! And now that the U.S. postal service is going out of business at any moment, such an attack would basically send the U.S. back to the mid-1800s, all gas-lit lamps and Pony Express.

Friday, 1 April 2011

Hackers target business secrets

Filing cabinet, Eyewire Many net-savvy thieves are scouring corporate networks for saleable secrets


Intellectual property and business secrets are fast becoming a target for cyber thieves, a study suggests.

Compiled by security firm McAfee, the research found that some hackers are starting to specialise in data stolen from corporate networks.

McAfee said deals were being done for trade secrets, marketing plans, R&D reports and source code.
It urged companies to know who looks after their data as it moves into the cloud or third-party hosting centres.

"Cyber criminals are targeting this information based on what their clients are asking for," said Raj Samani, chief technology officer in Europe for McAfee.

He said some business data had always been scooped up when net thieves compromised PCs using viruses and trojans in a search for logins or credit card details.

The difference now was that there exists a ready market for the data they are finding. In some cases, said Mr Samani, thieves were running campaigns to get at particular companies or certain types of information.

The McAfee report mentioned cases in Germany, Brazil and Italy in which trade secrets were either stolen by an insider or cyber thieves tried to get hold of via a concerted attack.

In some cases, said the McAfee report, companies made the job of the criminals easier because they did little to censor useful information about a corporate's culture or structure revealed in e-mails and other messages.

Such information could prove key for thieves mounting a "social engineering" in which they pose as employees to penetrate networks.

The report detailed efforts by firms to watch casual and contract employees and the use of behavioural analysis software to spot anomalous activity on a corporate network.


Perimeter defences

Thefts of intellectual property or key documents could be hard to detect, said Mr Samani.

"You may not even know it's stolen because they just take a copy of it," he said.

Defending against these threats was getting harder, he said, because key workers with access to the most valuable information were out and about using mobile devices far from the defences surrounding a corporate HQ.

"Smartphones and laptops have crossed the perimeter," said Mr Samani.

The report comes in the wake of a series of incidents which reveal how cyber criminals are branching out from their traditional territory of spam and viruses.

2010 saw the arrival of the Stuxnet virus which targeted industrial plant equipment and 2011 has been marked by targeted attacks on petrochemical firms, the London Stock Exchange, the European Commission and many others.

Mr Samani said that, as firms start to use cloud-based services to make data easier to get at, they had to work hard to ensure they know who can see that key corporate information.

Otherwise, he warned, in the event of a breach, companies could find themselves losing the trust of customers or attracting the attention of regulators.

"You can transfer the work but you cannot transfer the liability," said Mr Samani.

[BBC]

Thursday, 24 March 2011

Serious cyber attack targets EU institutions on eve of summit

Today is the first day of the first EU summit that takes place under the Hungarian presidency, and European leaders have gathered in Brussels to discuss matters such as the rising European debt crisis and the Libyan unrest and the subsequent military action.



But on the very eve of the summit, an unexpected occurrence cast a dark shadow over the event. The BBC reports that the European Commission and the External Action Service - the Community's diplomatic arm - have been hit by a "serious" cyber attack.

So far, details about the attack have not been divulged.

"We are already taking urgent measures to tackle this. An inquiry's been launched. This isn't unusual as the commission is frequently targeted," said EU spokesman Anthony Gravali.

An anonymous source confirms: "We're often hit by cyber attacks but this is a big one." Other sources compare the attack to the recently revealed one that targeted the computers of the French Ministry of Finance, when more than 150 machines were compromised.

Even though Gravali says that the European Commission will not speculate on the origin of the attacks, the similarities raise the possibility that the attackers could be the same ones that targeted the French. At the time, internal sources said that some of the files were redirected to Chinese sites, but they conceded that this fact doesn't say much.

The entire European Commission staff has been asked to change their passwords and to make sure to exchange information via secure email systems. The Commission has also shut down external access to email and the Comission's intranet, so that unauthorized information doesn't leak out.

[Net-Security]

Monday, 21 March 2011

CSIS expert lists worst cyber security breaches since January 2010

According to Bank Info Security, testimony was given before the House Homeland Security Committee last week by James Lewis, senior fellow at the Center for Strategic and International Studies (CSIS).

Lewis's testimony included a list of serious security incidents that have taken place since January 2010.

This list is reproduced below, with thanks to Bank Info Security.

Lewis is reported to have stated that the list "is not a record of success". He added "Whatever we are doing is not working...While individual government agencies have made strenuous efforts to improve our cyberdefenses, as a nation, despite all the talk, we are still not serious about cybersecurity."

This looks really rather damning of today's security infrastructure. But, I can't help but wonder how many cyber attacks weren't successful, thanks to the security that is place today? While I would agree that no one should rest on their laurels when it comes to security, I also know that there is no silver bullet.

I wonder if Lewis will also be providing advice on what needs to be done to help better secure against attacks. No one wants to be a victim, and most companies out there are doing what they can to stave off attacks.
January 2010: Google announced that an attack had penetrated its networks, along with the networks of more than 80 other US high-tech companies. The goal of the penetrations, which Google ascribed to China, were to collect technology, gain access to activist G-mail accounts and to Google's password management system. 
January 2010: At the same time, Intel experienced a harmful cyberattack. 
January 2010: Global financial services firm Morgan Stanley experienced a "very sensitive" break-in to its network by the same hackers who attacked Google, according to leaked e-mails. 
March 2010: A number of successful cyberattacks against NATO and European Union networks have increased significantly over the past 12 months, the international organizations revealed. 
March 2010: Australian authorities say there were more than 200 attempts to hack into the networks of the legal defense team for executives from Australian energy company Rio Tinto, to gain inside information on the trial defense strategy. 
April 2010: Hackers break into classified systems at the Indian Defense Ministry and Indian embassies around the world, gaining access to Indian defense and armament planning.
May 2010: A leaked memo from the Canadian Security and Intelligence Service says, "Compromises of computer and combinations networks of the government of Canada, Canadian universities, private companies and individual customer networks have increased substantially. ... In addition to being virtually unattributable, these remotely operated attacks offer a productive, secure and low-risk means to conduct espionage."
October 2010: Stuxnet, a complex piece of malware designed to interfere with Siemens industrial control systems discovered in Iran, Indonesia and elsewhere, results in significant physical damage to the Iranian nuclear program. 
October 2010: The Wall Street Journal reports that hackers using Zeus malware, available in cybercrime black markets for about $1,200, were able to steal over $12 million from five banks in the United States and Britain. 
December 2010: British Foreign Minister William Hague reported last month attacks by a foreign power on the British Foreign Ministry, a defense contractor and other British interests. The attack succeeded by pretending to come from the White House. 
January 2011: The Canadian government reports a major cyberintrusion involving the Defense Research and Development Canada, a research agency for the departments of National Defense Finance and the Treasury Board, Canada's main economic agencies. The intrusions forced the Finance Department and the Treasury Board to disconnect from the Internet. 
March 2011: Hackers penetrate French government computer networks in search of sensitive information on upcoming G-20 meetings. 
March 2011: South Korea said that foreign hackers penetrated its defense networks in an attempt to steal information on the American-made Global Hawk unmanned aircraft, provided to Korea as it considers whether to buy the aircraft.
CSIS experts conduct research and analysis and develop policy initiatives grouped under three themes: defense and security policy, global trends, and world regions. James Andrew Lewis focuses on technology, national security, and the international economy. Before joining CSIS, he worked in the federal government as a foreign service officer and as a member of the senior executive service. His assignments involved Asian regional security, military intervention and insurgency, conventional arms negotiations, technology transfer, sanctions, Internet policy, and military space programs.

[NakedSecurity]

Sunday, 20 March 2011

US cyber war defences 'very thin', Pentagon warns

Battle map on screen US officials say government and private systems are attacked millions of times per day

The US military lacks the people and resources to defend the country adequately from concerted cyber attacks, the head of the Pentagon's cyber command has warned.

"We are very thin, and a crisis would quickly stress our cyber forces," Gen Keith Alexander told Congress.
The US says government systems are attacked millions of times a day.

Disputes over budgets are holding up a new cyber protection system ordered by the Department of Homeland Security.

However, some argue the threat of cyber warfare is greatly exaggerated.
'Potential adversaries'
Gen Alexander, head of the US Defence Department's Cyber Command, told a Congressional Committee that he would mark as a "C" the military's ability to protect Pentagon networks, although he acknowledged improvements in recent years.

"We are finding that we do not have the capacity to do everything we need to accomplish. To put it bluntly, we are very thin, and a crisis would quickly stress our cyber forces," he said.

"We cannot afford to allow cyberspace to be a sanctuary where real and potential adversaries can marshal forces and capabilities to use against us and our allies. This is not a hypothetical danger."

US officials say cyber criminals, terrorists and other nations are getting better at penetrating state and private networks, whether to spy, to steal data or damage critical infrastructure.

But speaking last month, leading security expert Bruce Schneier told the BBC that the emotive rhetoric around "cyber warfare" did not match the reality.

"What we are seeing is not cyber war but an increasing use of war-like tactics and that is what is confusing us. We don't have good definitions of what cyber war is, what it looks like and how to fight it," Mr Schneier said.

[BBC]

Hackers tackle secure ID tokens

SecurID token, RSA The SecurID tokens are widely used to grant access to sensitive information

Hackers have stolen data about the security tokens used by millions of people to protect access to bank accounts and corporate networks.

RSA Security told customers about the "extremely sophisticated cyber attack" in an open letter posted online.

The company is providing "immediate remediation" advice to customers to limit the impact of the theft
It also recommended customers take steps, such as hardening password policies, to help protect themselves.


Proof positive

In the open letter, written by RSA boss Art Coviello, the company said that the data stolen would not help a "direct" attack on the the SecurID tokens.

It did not disclose exactly what had been purloined and only said that the information "specifically related to RSA's SecurID two-factor authentication products".

RSA's SecurID tokens are used by millions of people alongside passwords to beef up security.
As its name suggests, two-factor authentication involves improving security using two methods of identifying a user. The first factor is usually the traditional login ID and password combination.
The second factor can be a SecurID token that is paired with back-end software that generates a new six digit number every minute.

A token paired with this software generates the same numbers so only the holder will be able to type in the right digits and get access.

RSA said the information stolen could reduce the effectiveness of this two-factor authentication system if a company came under a broader attack by malicious hackers.

This could potentially put a lot of people at risk as RSA claims to have millions of people using its security technology to secure online accounts and access to corporate systems.

RSA recommended that firms monitor social network sites to spot if hackers were trying to capitalise on what they now know about RSA's systems.

This could be because hackers have got information about who has which token and might try to exploit that to trick employees into giving them access.

RSA also recommended reminding users about the dangers of responding to suspicious e-mails, to limit who can access critical infrastructure systems and to reinforce all policies surrounding SecurID token use.

There could be "tremendous repercussions" if criminals piggy-backed on what they know to stealthily get at corporate and other critical systems, said Richard Stiennon, chief research analyst at security firm IT-Harvest.

"You'd never have a sign that you've been breached," he said.

[BBC]

Sunday, 13 March 2011

Assault on Westboro Baptist Church Website Continues

The denial of service (DoS) attack initiated by The Jester (th3j35t3r) on a website operated by the Westboro Baptist Church has now exceeded two full weeks in duration.

The sustained DoS attack, which began on February 21st, represents a record for the hactivist who is best known for repeated DoS attacks on militant Jihadi websites (video), as well as an attack on the WikiLeaks website in late November that forced the organization to shuffle Internet hosting providers.

According to data from NetCraft, Westboro Baptist Church's controversial "www.godhatesfags.com" website has shown no activity for over two weeks:

Jester WBC day 13-2

The Jester has tweeted several messages regarding the attack, the last (as of the writing of this article) was on March 6th and described the attack as being a "no holds barred assault".

Another of the tweets mentions that the strategy behind the sustained attacks differs from those aimed at jihadi sites because "Some people people just need to stay down, they have no value in intel terms".

Jester WBC day 13

In an interview in 2010, The Jester elaborated on his anti-jihadi methodology:

"By knocking out the jihadi sites for random short periods, it causes them to be unable to rely on the site for recruitment, or co-ordination, this in turn will have the effect of drawing them out into the open and in person to do the recruiting, where the CT agencies really come into their own doing what they do best, which is intercepting and apprehending suspects".

The Jester uses a DoS tool he calls XerXeS to perform an application level attack on the targeted servers.
Where traditional TCP-based DoS attacks require multiple machines sending a large number of packets, the XerXeS attack can be performed by a single low-spec machine with relatively few packets.

On the development of XerXeS, The Jester remarked that "the aim is to create a single cohesive attack platform that will knock out with precision and no side-effects anything it comes up against, for any specified period."


How long will the WBC operation carry on? For now, the answer looks to be indefinitely.

[InfoSecIsland]

BMI taken out by Anonymous

Hacktivists affiliated to Anonymous have taken out the website of Broadcast Music Incorporated in a protest against its stance against file-sharing.

The denial of service attack against the US-based performing rights society began late on Wednesday and remains ongoing, leaving its main bmi.com site difficult to access.

Anonymous claimed responsibility for the attack via a notice on a news site used by the loosely-knit 4Chan-spawned hacking collective.

The attack on an entertainment industry website represents a return to the type of attacks that were commonplace last year before the group turned its intention towards financial service firms that severed links with WikiLeaks and others seen as opposed to the whistle-blowing website. ®

[The Register]

Monday, 7 March 2011

Cyber attack on France targeted Paris G20 files

The French finance ministry has confirmed it came under a cyber attack in December that targeted files on the G20 summit held in Paris in February.

Budget Minister Francois Baron said an investigation had been launched, adding: "We have leads".
It follows a report in Paris Match magazine that claimed a sustained cyber attack sought documents related to the G20 and international economic affairs.

More than 150 computers at the ministry were affected.

'Determined professionals'


"We noted that a certain amount of the information was redirected to Chinese sites," an anonymous official was quoted by the French magazine. "But that [in itself] does not say very much."

An official complaint has been filed with French courts, and the matter has been taken up by the secret service.

"The actors were determined professionals and organised," Patrick Pailloux, director general of the French National Agency for IT Security told Paris Match.

"It is the first attack of this size and scale against the French state."

The summit agreed a list of targets for reducing imbalances in the global economy in order to head off future financial crises.

The topic was particularly contentious for the Chinese, who resisted calls to target exchange rate valuations, currency reserves and economic surpluses.

The US and other countries accuse China of buying up trillions of dollars in foreign reserves in order to hold down the value of the yuan and gain an unfair competitive advantage in trade.

[BBC]

Sunday, 6 March 2011

Man sentenced for breaching former employer's computers

A Texas man has been ordered to pay restitution of $16,600 and a $5,000 fine after admitting he breached the server of an engineering firm that fired him and deleted sensitive files.

Ismael Alvarez of Andrews, Texas, was also sentenced to five years of probation and one year of home confinement.

In December, federal prosecutors accused Alvarez of accessing a protected computer owned by Gray Wireline Service and deleting about 68 files, many of which contained proprietary reports related to oil and natural gas wells. During the breach, which happened a few weeks after Alvarez was fired, he created a directory titled “RENEGAGE RULES.” Renegade is the name of a Gray Wireline competitor.

FBI agents tracked down Alvarez through the IP address used to access the Gray Wireline server. It corresponded to the account his used with his ISP.

Alvarez, who had worked for the company for more than seven years, joins a long list of disgruntled employees who sought revenge by breaching their employees' computer systems. ®

[The Register]

Friday, 4 March 2011

South Korea hit by cyber attacks

South Korea has been hit by a series of cyber attacks which have targeted some of the country's leading websites.

Government ministries, the National Assembly, the military headquarters, US Forces in Korea and major banks were among those hit.

It is believed that the attackers injected malware into two peer-to-peer file-sharing websites.
The attacks are similar to those that targeted South Korean websites in July 2009.

Some 29 institutions were affected by so-called distributed denial-of-service attacks (DDoS) which overload a site with data causing it to fall over.

The web page of the Financial Services Commission, the country's financial regulator, was overloaded and an online stock trading system was shut down for a few minutes but both soon recovered, according to government sources.

North Korea


"There was a DDoS attack, but no damage was done," said an official from the presidential office.
South Korean security firm AhnLab expected another wave of attacks on Friday, targeting up to 40 government and corporate websites.

It estimates that up to 11,000 personal computers were infected by malware and recruited for the attack. It is distributing free software to clean PCs.

The South Korean cyber investigation unit has sent investigators to the two file-sharing sites that are believed to have spread the malicious code, according to the National Police Agency.

The cyber attacks against South Korea in 2009 were blamed on North Korea, although no link has been proven.

South Korean media outlets have, in the past, accused North Korea of running an internet warfare unit aimed at hacking into US and South Korean military networks.

[BBC]

Thursday, 3 March 2011

Five online criminals sentenced in UK

        You might remember our blog post from last August, discussing an online criminal who posted his bail sheet to an online forum.

He has been convicted today in London and received four years in prison. In the same sentencing, two other males and two females were convicted to jail sentences ranging from 18 months to four years and to community service.

Scotland Yard’s release follows:

A group of young internet fraudsters who set up an online ‘criminal
forum’ which traded unlawfully obtained credit card details and tools
to commit computer offences have today been jailed for a
total of 15.5 years.

[A] Gary Paul Kelly (14.04.89 – 21 yrs) unemployed of Clively Avenue,
Clifton, Swinton, Manchester;

[B] Nicholas Webber (10.10.91 – 19 yrs) a student of Cavendish Road,
Southsea;

[C] Ryan Thomas (8.7.92 – 18 yrs) a web designer of Howard Road, Seer
Green, Beaconsfield, Herts;

[D] Shakira Ricardo (14.11.89 – 21 yrs) unemployed of Flat 13, J Shed,
Kings Road, Swansea SA1;

were sentenced today (Wednesday 2 March) for computer misuse and fraud
offences following a two-day Newton Hearing at Southwark Crown Court.
All pleaded guilty at earlier hearings.

+ [E] Samantha Worley (30.09.88 – 22 yrs) unemployed of Flat 13, J
Shed, Kings Road, Swansea SA1 was sentenced on 14 December 2010 to 200
community service for acquiring criminal property.

The gang are believed to have been responsible for the largest
English-language online cyber crime forum and were all arrested on
various dates in 2009 and 2010, following a complex investigation by
officers the Metropolitan Police Service̢۪s Police Central e-Crime Unit
(PCeU).

During an eleven month investigation detectives uncovered evidence that
the defendants were directly involved in the global forum (used by over
8,000 members) which promoted and facilitated the electronic theft of
personal information; credit and debit card fraud; buying and selling
of personal information (including passwords and PIN numbers); the
creation and exchange of malicious computer programs (malware); the
establishment and maintenance of networks of infected personal
computers (BotNets);and tutorials offering advice on how to commit such
offences, including how to evade and frustrate law enforcement activity
and the exchange of details of vulnerable commercial sites and servers.

Founder of the forum was Webber. Having established a web site named
‘www.GhostMarket.net’, he acted as “administrator” and had overall
control of the site (meaning he was able to allow/ban members, remove
or edit their posts, and alter their status on the forum.)

An examination of the rebuilt forum and its database revealed many
thousands of data entries relating to individuals’ personal details
including names, dates of birth, bank details, passwords, paypal
accounts and social security numbers. Site members are believed to have
traded in compromised databases containing thousands of personal
details including bank account numbers, PIN numbers, passwords and
malware including the Zeus Trojan and other types of criminal software,
including credit card verification programs.

The forum included such topics as: ‘Phishing kits (post free phishing
kits and sell them)’; ‘Show off (show us your skills here)’; ‘Tutorials
(post some useful info here)’; and ‘Cardable (post sites you’ve carded
here)’. There was also advice and tutorials on various methods of
evading law enforcement, how to encode blank plastic with credit card
data, and how to hack into sites, and even recipes for controlled drugs
(crystal meth) and a tutorial on bomb making.

Members of the site communicated anonymously by the use of screen
nicknames. They were able to post messages in various forum topics on
the website and send/receive private secure messages to/from other site
members.

During the investigation detectives recovered from the defendants̢۪
computers more than 130,000 compromised credit card numbers, which at
an estimated industry loss of £120 per card, is a potential £15.8
million financial loss in relation to card numbers alone.

On 3 November 2009 detectives arrested Kelly after executing a search
warrant at his home address. A full search of the property was
conducted, with a number of computers and mobile phones removed from
the address for examination.

It was established that Kelly had independently constructed and
distributed across the web a sophisticated Zeus malicious computer
programme which enabled him to infect and compromise over 15,000
computers in over 150 countries, harvesting from them over 4 million
lines of data ­ including huge quantities of credit card numbers and
other confidential, personal information.

Having been provided with relevant passwords by Kelly, detectives were
able to rebuild the GhostMarket forum and its database using files from
his PC.

Prior to this, on 12 October Webber and Thomas were arrested at a five
star central London hotel for using stolen credit card details to pay
for accommodation in the penthouse suite. They claimed to have
responded to an online advert, saying they had paid money to an
anonymous individual.

Bailed to return whilst officers conducted further inquiries, items
including their laptops were seized. In addition they were found to be
in possession of business cards brandishing the ‘GhostMarket’ logo,
advertising it as “A new era in virtual marketing” with the byline
“I’m a carder, ask about me…”

The duo’s involvement in the ‘GhostMarket’ criminal forum was soon
established and inquiries were made to trace them after they fail to
return on bail in relation to the stolen credit card offence.

It was later discovered that on 31 October the pair had flown out to
Palma, Majorca, where they had been living in a rented flat in Port
D’andrax.

On 29 January 2010 they were arrested at Gatwick Airport as they flew
in from Palma.

The following day a search of Webber’s home address revealed a computer
containing a series of files outlining a step-by-step guide to
committing various criminal offences.

Owing to the volume of evidence to be examined and the complexities of
the case, the pair were released on police bail to return at a later
date.

Officers subsequently travelled to Spain and, accompanied by Spanish
Police, attended the flat Thomas and Webber had rented out. The
property was empty, but local enquiries established that the contents
had been posted back to their UK addresses.

Those items, as well as additional computer equipment, were
subsequently recovered.

Through the forensic examination of seized computers and other digital
storage devices, as well as evidence secured through the rebuilt
Ghostmarket site, officers identified Ricardo, a trusted member of the
forum, and she was traced to Swansea, South Wales. Initially joining
the site as a complete novice, over time Ricardo had progressed to
become directly engaged in card fraud and computer malware activity.
Financial enquiries identified a payment made from Ricardo into her
partner Worley’s bank account, incriminating her in the fraud.

Detective Inspector Colin Wetherill, Police Central eCrime Unit said:
“These defendants were accomplished cyber criminals, engaged in the
systematic mass infection of computers in homes and businesses in the
UK and overseas.

“They unlawfully harvested personal and financial information from
their victims to be exploited for financial gain.

“The GhostMarket crime forum was used by thousands of computer
criminals and fraudsters operating worldwide.

“Through it the defendants built an extensive criminal network to
facilitate the wholesale trade of compromised credit card details,
confidential financial and personal information, malicious computer
programmes, and other sophisticated tools and criminal services.

“The arrest, prosecution and conviction of these individuals represents
a significant step forward in our efforts to tackle cyber crime and
reduce the harm it causes.”

+ A full financial investigation into all four defendants is underway.

[ComputerSecurityArticles]

WordPress.com Suffers Largest DDoS Attack In Its History

You have no idea how hard it was to get this post up, as WordPress.com, our blog host, is currently under a denial of service attack. It’s been almost impossible to access the TechCrunch backend for the past 10 minutes (everything seems to be stable now) and users have been receiving a “Writes to the service have been disabled, we will be bringing everything back online ASAP” error message.

From the VIP blog post:
WordPress.com is currently being targeted by a extremely large Distributed Denial of Service attack which is affecting connectivity in some cases. The size of the attack is multiple Gigabits per second and tens of millions of packets per second.
We are working to mitigate the attack, but because of the extreme size, it is proving rather difficult. At this time, everything should be back to normal as the attack has subsided, but we are actively working with our upstream providers on measures to prevent such attacks from affecting connectivity going forward.
We will be making our VIP sites a priority in this endeavor, and as always, you can contact us via xxxxx@wordpress.com for the latest update. We will also update this post with more information as it becomes available
WordPress did not mention the origin of the attack (DDoS =! Anonymous) and I have contacted founder Matt Mullenweg for more information. WordPress.com currently serves 30 million publishers, including VIPs TED, CBS and TechCrunch, and is responsible for 10% of all websites in the world.

WordPress.com itself sees about 300 million unique visits monthly.

Update: Automattic and WordPress founder Matt Mullenweg tells us that this is the largest attack WordPress.com has ever seen, and is likely to be politically motivated:

“There’s an ongoing DDoS attack that was large enough to impact all three of our datacenters in Chicago, San Antonio, and Dallas — it’s currently been neutralized but it’s possible it could flare up again later, which we’re taking proactive steps to implement.


This is the largest and most sustained attack we’ve seen in our 6 year history. We suspect it may have been politically motivated against one of our non-English blogs but we’re still investigating and have no definitive evidence yet.”


You can check here for the latest status updates.

[TechCrunch]

Wednesday, 2 March 2011

iTunes users complain of account hacks

More than six months after reports of wide-scale compromises of  accounts at Apple's popular iTunes online store, there are fresh reports that suggest that the accounts of iTunes users are being used to make fraudulent purchases of music, games and other merchandise. Reports in the Apple forums suggest a pattern of fraudulent purchases of music and iPhone applications stretching back to November. In most cases, with one user reporting $980 in phony iTunes purchases.

Apple did not respond to Threatpost requests for information about the hacks.
The incidents, which have been on the increases since the beginning of February, bear similarities to an earlier rash of hacks that came to light in July, 2010. In that case, attackers used access to compromised iTunes accounts to buy up expensive applications from a number of iPhone application "farms," many based in China. An account of those attacks, reported by TheNextWeb.com, revealed a connection between application farms run associated with a specific developer, Thuat Nguyen, and fraudulent purchases. Many of the apps released by Nguyen became top ranked sellers in categories such as Book Apps on iTunes Appstore due to the fraudulent buys.

In the latest incidents, which affected iTunes users in the U.S., UK and other countries, there is also a rash of fraudulent purchases that share similarities. Visitors to the Apple Support forums report fraudulent in-game purchases of poker chips for a Texas Hold 'em application credited to the game's developer, one "Hongbin Sho." Others report fraudulent application purchases credited to a developer using the handle Lakoo and Gameislive Corporation Limited going back at least to October, 2010.

In all cases, the users report intrusions to their iTunes account that drain the balance of iTunes gift cards or, where accounts have credit cards attached to them, rack up false charges on the card. In other cases, attackers who have compromised the accounts use them as a front to make fraudulent purchases using a third party credit card account, wiping out the user's address and account information and replacing it with another cardholder's information and address, then making the bogus purchases using that.

Its unclear exactly what the connection is between the hacked accounts and the application makers, but the latter group is hardly hiding. The Gameislive.com domain resolves to Lakoo.cn which contains contact information and links to the various games promoted by Gameislive. The domain itself is registered to a "Lakoo" with a business address in Kowloon, Hong Kong.

The security of mobile application marketplaces has become a sore point for platform vendors like Apple and Google. Anxious to build large ecosystems of games to draw users to their handheld devices, the vendors have been accused of looking the other way at shady practices and shoddy work by developers.

At a recent forum hosted by the consulting firm SRA International, experts concluded that there was no easy fix for mobile security, and singled out mobile app stores as an Achilles heel.

Rob Smith, the Chief Technology Officer of Mobile Active Defense told the audience at the Mobile Security Symposium 2011 that mobile marketplaces encourage users to think that the applications they are downloading have been vetted and are reliable, when the opposite is often true. At stake is, potentially, access to corporate assets and data, he warned.

Forum users also took Apple to task for a lackluster response to incidents of fraud. In most cases, the company appears to have refunded monies that were lost through the fraudulent purchases. In other cases, however, Apple merely suggested the users change their password or contact the developer in question.

[ThreatPost]

Tuesday, 1 March 2011

The Cybercrime Blotter: High-Profile Websites Hacked in 2011

In only its first two months, 2011 has already been a banner year for cybercriminals, who've managed to hack into or disrupt the websites of several high-profile organizations.
Here is a roundup of every cyberattack that made headlines in 2011 so far. As cybercriminals find new targets, expect the list to (unfortunately) grow.

Feb. 24: Westboro Baptist Church
On Feb. 24, Anonymous took down several websites associated with the controversial Westboro Baptist Church. A small but vocal Christian group that loves publicity and hates almost everything else, the Westboro Baptist Church pickets military funerals with signs reading "God Hates Fags" and "Thank God for Dead American Soldiers."

Feb. 22: Voice of America
On Feb. 22, pro-Iran hackers went after Voice of America the official news service of the United States government. This one was by a group calling itself the Iranian Cyber Army (ICA). In its hack on www.voanews.com, the ICA denounced what it saw as U.S. involvement in the ongoing revolutions in the Muslim world. The ICA manipulated the VOA homepage to read: “Mrs. Clinton Do you want to hear the voice of oppressed nations from heart of USA? Islamic world doesn’t believe USA trickery. We call on you to stop interfering in Islamic countries.”

Feb. 18: Canada
In mid-February, it was revealed that the Treasury Board, Finance Department and Defence Research and Development — Defence Research and Development Canada is a civilian military agency — were all breached in January by hackers believed to be operating in China. The hackers were seeking confidential information pertaining to financial and weapons information and data about oil and gas resources.

Feb 11: Iran
As antigovernment protests spread throughout the Middle East, so did cyberattacks aimed at crippling oppressive government regimes. On Feb. 11, Anonymous took action against several Iranian government websites, standing in solidarity against what it called in a press release “the chains of oppression, tyranny and torture.” The distributed denial-of-service (DDoS) attacks were levied against the websites of IRNA, Iranian’s semi-official news agency, President Mahmoud Ahmedinejad and Ayotollah Ali Khomenei, but none were entirely successful.

Feb 6: HBGary Federal
Anonymous was involved in this next hack, and this one added a bit of intrigue and espionage to the mix. On Feb. 5, Aaron Barr, chief executive of the Washington, D.C.-based security firm HBGary Federal, announced that he had unmasked the members of Anonymous, and would reveal their identities at a security conference later in the month. Wasting no time, Anonymous the following day took down the website of Barr’s company, hijacked Barr’s personal Twitter account and his boss’s LinkedIn profile, and posted more than 70,000 of Barr’s personal e-mails. In a brazen show of defiance, Anonymous even posted the dossier of secret Anonymous identities Barr was planning to make public. While Anonymous was just flexing its muscles, it turned out those 70,000 e-mails told a scandalous story of espionage and dastardly closed-door dealings. Barr’s leaked e-mails revealed that his company was planning to launch cyberattacks and public smear campaigns of its own against WikiLeaks.

Feb. 5: Nasdaq
Next up to go down: the Nasdaq. As reported in a Feb. 5 Wall Street Journal article, hackers for the past year had been targeting computer networks belonging to the Nasdaq stock exchange. But these online crooks weren’t after money. The hackers’ real target was Directors Desk, a cloud application owned by Nasdaq that stores financial records and reports for hundreds of Fortune 500 companies and more than 10,000 corporate board members.

Jan. 26: Utah, Michigan, Albania, Italy, the U.S. Army, etc.
A few weeks passed before another high-profile organization was targeted, but when the next hit came, it was a big one. In late January, a hacker hijacked more than a dozen top military, government and education websites. Among the hacker’s haul were the websites of the states of Utah and Michigan, the Italian government, the Albanian military, Singhania University in India and the U.S. Army’s Communications-Electronic Command (CECOM). The hacked websites were being sold for $55-$499 each on an underground market.

Jan 26: Egypt
On Jan. 26, Anonymous struck again, this time against Egypt’s official government websites. The attacks on the websites of the cabinet, Ministry of the Interior and Ministry of Communications and Information Technology were carried out after then-President Hosni Mubarak blocked citizens’ access to Twitter. Following Egypt’s five-day Internet blackout, Anonymous launched a second wave of digital protests, taking down sites in Egypt as well as in Yemen.

Jan 2: Tunisia
The first notable digital disruption of the year occurred just two days in, when the hacktivist group Anonymous launched massive DDoS attacks against at least eight Tunisian government websites. The DDoS takedowns were in response to the Tunisian government’s decision to block its citizens from accessing WikiLeaks. Protests in Tunisia kicked off a surge of antigovernment opposition that spread quickly throughout the Middle East.

What’s next?
Unfortunately for prominent organizations — and even worse for controversial ones — the year is still young, and if the first two months are any indication, there are most certainly plenty of cyberattacks still to come.

[securitynewsdaily]

Monday, 28 February 2011

HBGary Federal CEO Aaron Barr steps down

Embattled CEO Aaron Barr says he is stepping down from his post at HBGary Federal to allow the company to move on after an embarassing data breach.

The announcement comes three weeks after Barr became the target of a coordinated attack by members of the online mischief making group Anonymous, which hacked into HBGary Federal's computer network and published tens of thousands of company e-mail messages on the Internet. HBGary did not respond to telephone and e-mail requests for comments on Barr's resignation.

In an interview with Threatpost, Barr said that he is stepping down to allow himself and the company he ran to move on in the wake of the high profile hack.

“I need to focus on taking care of my family and rebuilding my reputation," Barr said in a phone interview. "It’s been a challenge to do that and run a company. And, given that I’ve been the focus of much of bad press, I hope that, by leaving, HBGary and HBGary Federal can get away from some of that. I’m confident they’ll be able to weather this storm.”

The group conducted a preemptive strike on HBGary after Barr was quoted in a published article saying that he had identified the leadership of the group and planned to disclose their identities at the B-Sides Security Conference in San Francisco.

By combining a SQL injection attack on HBGary's Web site with sophisticated social engineering attacks, the group gained access to the company's Web- and e-mail servers as well as the Rootkit.com Web site, a site also launched by HBGary founder Greg Hoaglund. Ultimately, the group defaced HBGary's Web site and disgorged the full contents of e-mail accounts belonging to Barr, Hoglund and other company executives.

Though Barr and HBGary were the victims of the hack, the contents of the e-mail messages divulged plans that cast both in an unflattering light. Among them were data mining efforts and mentions of possible disinformation campaigns on behalf of a "large U.S. bank" and the law firm that represents the U.S. Chamber of Commerce that seem to run afoul of civil liberties and professional ethics.

HBGary counted many U.S. government agencies, including the Department of Defense, CIA and NSA as customers. The disclosure of e-mail messages from the company poses a major security risk to those organizations, as well as individuals who had corresponded with the firm.  The breach also raises troubling questions about the direction that HBGary and other Beltway firms have taken. Email exchanges published online revealed the firm to be at work on a variety of plans to do data mining and information operations on U.S. organizations and journalists on behalf of clients including law firms representing a large U.S. bank and the U.S. Chamber of Commerce. Most recently, the incident spilled into the mainstream, with comedian Stephen Colbert devoting a segment of his Colbert Report program on February 24 to the HBGary hack.

[ThreatPost]

Friday, 25 February 2011

Anon hacks Westboro Baptists during live interview

Denizens of Anonymous defaced a website run by the Westboro Baptist Church on Thursday during a live radio interview.

An ongoing spat between the controversial church of GodHatesFags fame and the loosely knit hacking collective began last weekend with a message threatening hacks against websites that, depending on who you believe, was posted either by the Church itself or a faction of Anonymous. Another faction of Anonymous distanced itself from the plan, categorising Westboro Baptist Church as trolls looking for attention.

Whatever the origins of the row, WBC's site has been subject to ongoing attacks over recent days, and the topic served as suitable fodder for an item on the David Pakman show. A member of Anonymous faced off against Shirley Phelps-Roper of the Westboro Baptist Church.

Anon said the supposed threat against WBC came from "nowhere" and didn't match its writing style. He said attacks against WBC sites were the work of Jester. Phelps-Roper, who kept interrupting the Anon member, said everyone for Anonymous was going to hell. After eight minutes into the interview the Anon member posted its own statement on downloads.westborobaptistchurch.com.

The statement, headed "This domain has been seized by Anonymous under section #14 of the rules of the Internet", derides the Church for attempting to "goad" Anonymous into attacking it for describing them as "crybaby hackers". The statement went on to say Anonymous had bigger fish to fry, such as campaigns involving Libya and managing the fallout from its hack against HBGary.

"Take this defacement as a simple warning: go away," the statement (screenshot here) concludes. "The world (including Anonymous) disagrees with your hateful messages, but you have the right to voice them. This does not mean you can jump onto Anonymous for attention."

Watching the duo square up was akin to watching two wrestlers trash talk each other prior to a carefully orchestrated fight, as can be seen from a video clip from the Pakman show below.

Phelps-Roper, probably like the wider Westboro Baptist Church, seems to revel in being "persecuted" while both she and the rep of Anon more or less admitted that they were enjoying the media attention brought about by the ongoing spat. ®

[The Register]

Thursday, 24 February 2011

Anonymous denies Westboro attack

Internet activist group Anonymous has said calls for it to attack the website of controversial anti-gay Westboro Baptist Church were a hoax.

The denial follows a publication on an Anonymous-affiliated website attacking the church.

In a new statement, Anonymous urged members not to participate in any denial-of-service attacks against the church's website.

Anonymous said it had "more pressing matters to deal with at the moment".

The new statement, which claimed to be authored by more than 20 members of Anonymous, said it didn't "remember sending" the original release.


Pimple-faced nerds

Anonymous has risen to fame in recent months for its "hacktivism", which has seen it launch denial-of-service attacks against firms it saw as pursuing policies that are in opposition to its freedom of the web ideals.

The group recently crashed a number of Egyptian government websites, in support of the country's pro-democracy protests.

It also attacked several online companies that it believed had helped clamp down on Wikileaks' activity, including Paypal and Amazon.

Anonymous's informal structure increases the chances that rogue elements can initiate action without widespread support, said Graham Cluley, of security firm Sophos.

Mr Cluley warned that its followers could potentially be led into mounting a major hack under false pretences.

"There are dangers in future that someone may pose as Anonymous and say that they want an attack".

In its latest statement, Anonymous warned its members not to participate in DDoS attacks against Westboro Baptist Church in case it was a trap.

Westboro Baptist Church has been widely condemned for its aggressive anti-homosexual campaigning.

A number of US states have passed legislation, banning members from protesting close to military funerals.

The church's leader, pastor Fred Phelps, was banned from entering the UK by the Home Office in 2009.

The church had issued a response to the original release, branding Anonymous "a puddle of pimple-faced nerds".

[BBC News]

Corporate espionage via social networks

We've all heard about HBGary Federal's COO Aaron Barr's claims that he leveraged the information gathered on various social networks to discover the identities of Anonymous' leaders, and about the repercussions this claim had upon the company.



In the end, we still don't know whether Barr's work in this case has allowed him to come to accurate conclusions regarding those identities, but what we should know is that he isn't the only one who thought about using social networks to dig up information that might be worth a lot to someone - and I don't mean advertisers or stalkers here.

At this years' edition of the RSA Conference in San Francisco, Abhilash Sonwane - VP of Product Management and Technology for Cyberoam - gave an interesting talk about the possibility of using social media to map out the organizational DNA of a company.

He demonstrated that by using information gathered on LinkedIn, Facebook, Twitter and other social networks, they were able to discover who the decision makers are, how activities are coordinated and how knowledge is transferred, what objectives and incentives do the employees have and what the overall organization model is in a number of randomly selected small and medium sized companies from around the world.


According to their research, 57 percent of Fortune 500 companies engage in some form of social media activity - bulletin boards, social networking, online videos, blogging, wikis, etc. And is good they do, since these activities give them the ability to communicate individually with each member of the audience and helps them gather direct feedback that allows them to fine tune their approach and efforts.

But there's also a downside to all of this, and that concerns the information that is prematurely shared - and especially that which wasn't intended to be shared in the first place. "Unlike the traditional media where there are very defined and controlled inlets of information, social media is free," explained Sonwane. "Organizations cannot control who communicates what about them and to what audience. The whole eco system of the organization is free to communicate. Employees, partners, customers, ex-employees - they all have the same resources and power available as the official spokesperson of the company."

Knowingly or unknowingly, they occasionally misuse that power, and share what shouldn't be shared with the public - making corporate espionage a feat that doesn't require a lot of expertise.

To prove their point, Cyberoam researchers spent almost six months monitoring 20 companies with an active social media presence with the intention of verifying the extent to which employees and organizations can leak information and of mapping their organizational DNA.

This was their general modus operandi:


"When we started out, Facebook did not have the same privacy settings it has today, and that made things easier for us," Sonwane shared. "But I guess that still does not make that much of a difference, since one can work around the privacy settings by using social engineering."

The companies in question were from all over the world: eight from the USA, four from India, two from Germany, seven from the UK and couple from Singapore and Australia. They were also a mixture of PR agencies, pharmaceutical companies, banking and financial institutions, consultancies, media and entertainment companies, manufacturers and IT/tech firms.

So, what did they find out?

One of the targets was a Singapore-based multimedia company selected because of an impressive list of clients. They monitored the private Twitter accounts of the sales director, department head and various designers, and found out that employees were not getting a salary, that there were cash flow problems in the organization, that salary checks bounced and that employees were looking for new jobs.

They also discovered that the department head and the sales director have resigned, that the owner is likely to wind up the business and that the company was actually a subsidiary of another company (meaning that the decision rights resided with managers of the parent company - information that was not available on the company's website or any other official literature).

The availability of all this information puts both the company and its employees at risk. These disclosures decreased its chances to bounce back since vendors and customers privy to that information can stop doing business with it and new employees might consider not joining the organization after all.

And current employees searching for another employment might have difficulties negotiating a good salary since prospective employers could be aware of the fact that the company is going down the drain and that its employees might be getting desperate for a new job.

While looking for information on another company, researchers discovered - through publicly available information about the employees - that the financial director was a divorcee. So, they created a dummy female profile on Facebook, befriended him and cultivated an online relationship that ended in him sharing confidential information about the company with "her".

Similar tactics were used with all targets, and the end result was this:
  • All 20 organizations monitored gave disclosure of at least one negative sentiment
  • 17 organizations talked about issues internal to the organization that would not have been available otherwise
  • 14 organizations disclosed the whole company profile of their organizations with information about employee demographics, business demographics and customers
  • 14 disclosed information about the personal profile of the top management
  • 14 disclosed information about their customers at one time or the other
  • Eight organizations disclosed information confidential to their companies, financial details, prior announcement of senior management moving out, etc.
In short, the full organizational DNA of almost half of the companies was decoded, and that's the disappointing and worrying conclusion of this experiment.

Sonwane ended his presentation with stressing how important it was for each company to be aware of this danger, and take proactive or corrective measures to minimize the risks associated with the use of social media.

"Companies must prepare and educate their employees not only about the benefits of using social computing, but also about the consequences of its misuse. This education process should involve every department in the company including the management team, human resources, legal, sales and marketing," he concluded.

[net-security.org]