Showing posts with label Cyberthreats. Show all posts
Showing posts with label Cyberthreats. Show all posts

Romanian authorities arrest cybercrime suspects

Dave CullinaneWell, eight days, and a joint effort to help prevent phishing and two major arrests related to identity theft, and I feel like we’ve made a decent attack on the identity theft culture. Score one for the good guys for once.

Just a day after reading Dancho Danchev’s story on Owen Walker being arrested, and about eight days after Dancho covered a story on eBay, PayPal, and Google teaming up to combat phishing, we have a large group of about 20 people arrested in Romania on charges of running online fraud schemes. From Grant Gross of IDG News Service:


Authorities have arrested more than 20 people in Romania who are suspected of running online fraud schemes, according to media reports.

The Tuesday arrests were confirmed by the U.S. Federal Bureau of Investigation, which has been working with Romanian officials on cybercrime in recent months. The FBI would say only that the agency is aware of the arrests and because “this is an ongoing matter, we will have no further comment at this time.”

I’m wondering if the people responsible for bringing this group down have seen Billy Rios and Nitesh Dhanjani’s talk on phishing/identity theft that’s been at the last couple Black Hats and will be presented again at Vegas this year. It really takes the cake in analysis of the identity theft culture. I’m also curious to see if there are any tricky techniques that might be employed to catch criminals sleeping, such as the GMail name stealing trick… will be interesting to see if Rios and Nitesh’s research covers this at Black Hat Vegas. The story continues:

Romanian news reports suggested the number of people arrested there was between 21 and 24. Mediafax.ro reported that the suspects were accused of stealing identities online, in apparent phishing or auction-fraud schemes, and that they had taken US$640,000 from non-Romanians. Several U.S. Web sites, including eBay, were targets of the fraud, according to news reports.

The group’s alleged leader, Romeo Chita, was arrested in an apartment owned by a Romanian lawmaker, Mediafax.ro reported.

Gary Warner, director of research in computer forensics at the University of Alabama at Birmingham, applauded the arrests in a blog post Wednesday.

The arrests are “another example of the successful international cooperation” between the U.S. and Romanian law enforcement, he wrote.

“How long is the long arm of the law?” Warner wrote. “It’s at least long enough to reach from eBay headquarters to Romania.”

You know what? Cheers to eBay. I’ve had limited opportunities to work with them, but their CISO Dave Cullinane, and I had a very interesting discussion at the eBay Red Team event that eBay sponsors. We talked about the large amount of identity theft coming out of Romania that eBay was dealing with. I’m not entirely sure how, but somehow Dave and eBay have worked with authorities from both the US and Romania (as well as other countries) to really get a handle on how to catch these criminals.

Warner posted video of three of the arrests on his blog.

In May, U.S. and Romanian authorities announced that 38 people in the two countries had been charged with using complicated Internet phishing schemes to steal thousands of credit and debit-card numbers. Two related phishing schemes had ties to organized crime, the U.S. Department of Justice said then.

Wonderful. It’s great when things work. Let’s see if the trend continues.

Phishing involves sending e-mail messages that look like official correspondence from banks or credit-card vendors in an attempt to get recipients to go to a fake Web site and enter their account numbers.

This last piece of his story, just ignore that. Everyone knows what phishing is… phishing is not the major problem here. Identity theft is the major problem. You have to think of identity theft as a unique piece of commerce, with its own market fluctuations, etc. Phishing is just one method of filling supply for the demand to feed the identity theft market. Numerous others exist, such as targeted spear phishing attacks, scam calls, ATM skimmers, etc.

I will probably say this a hundred times on my blog, you MUST go see Nitesh Dhanjani and Billy Rios talk about phishing at this coming Black Hat. If you can’t, get their slides. You’ll laugh, you’ll cry, you’ll get angry… identity theft is a market supplied by tough to tackle problems like phishing. Let’s hope we see more work like that of eBay’s in taming identity theft.

[Source: zdnet]

Say it ain’t so AVG, say it ain’t so: AVG LinkScanner = Badware?

The Register covered a very interesting story about AVG. Apparently AVG is spamming the Internet with traffic that looks to be coming from Internet Explorer. AVG software pre-crawls search results to try to protect users, but uses a user agent that makes the software appear to be Internet Explorer. This pre-crawling is flooding websites with meaningless traffic (Slashdot claims it is up to 6% of their traffic, which given Slashdot’s load is CONSIDERABLE). More importantly, they’re apparently aware of this bad behavior and are changing their user agent to avoid filters. From the Register’s article:

Early last month, webmasters here at The Reg noticed an unexpected spike in our site traffic. Suddenly, we had far more readers than ever before, and they were reading at a record clip. Visits actually doubled on certain landing pages, and more than a few ho-hum stories attracted an audience worthy of a Pulitzer Prize winner. Or so it seemed.

DAMN! Why couldn’t it have happened here? I’m about to get married, the extra traffic would translate to extra dollars and help me out quite a bit! :) The Register article continues:

Read more it gets MUCH BETTER…

As it turns out, much of this traffic was driven by the new malware scanner from AVG Technologies.

Six months ago, AVG acquired Exploit Prevention Labs and its LinkScanner, a tool that automatically scans search engine results beforeyou click on them. If you search Google, for instance, and ten results turn up, it visits all ten links to ensure they’re malware free.

Then, in February, AVG paired LinkScanner with its anti-virus engine, which has about 70 million active users worldwide. The company estimates that 20 million machines have upgraded to its new security suite, AVG version 8, and this has already cooked up enough ghost clicks to skew traffic not only on The Reg but any number of other sites as well.

Adam Beale, who runs a UK-based internet consultancy, says that across his small stable of clients, traffic has spiked as much as 80 per cent on some sites. And this is more than just an inconvenience. After all, sites live and die by their traffic numbers. And net resources aren’t free.

This is ridiculous! On a site like ours, that feeds off of traffic, this is great (for me, not necessarily for ZDNet), but for most sites out there, this increase in traffic could lead to server downtime, network congestion, and might even force companies to by expensive load balancer devices and additional servers when the traffic really is NOT generating any more business for them. The Register continues:

“Although [the AVG LinkScanner] might be good for the security of users, it’s a real pain for website owners and webmasters,” Beale tells us, having blogged about this growing problem. “It’s causing people to think their traffic is increasing, costing those who pay for bandwidth, and wasting disk space with large amounts of unnecessary lines in log files.”

One of his clients, Beale says, normally pulls in 140GB of bandwidth a month, and for June, he predicts a 5 per cent jump.

When we spoke to AVG chief of research Roger Thompson earlier this week, he was unaware of these issues. But he defended the role of LinkScanner, which he designed while serving as CTO of Exploit Prevention Labs.

“There’s so much hacking activity going on the web. The only way to really tell what’s there is to go and have a look,” he told us. “I don’t want to sound flip about this, but if you want to make omelettes, you have to break some eggs.”

Holy crap, that is the single most irresponsible thing I have EVER heard a CTO of any company say. Unbelievable! On top of this, how much security is it really providing? It’s not like Anti-Virus or these fancy link scanners or anything like that have really lessened the impact of malware that much. We’ll see at DEFCON this year just how easy it is for attackers to morph malware into something that AVs do NOT pick up on. Funny… I just saw AVG’s corporate images:

AVG Logo

Maybe it should be the other way around?

Back to the Register article:

But what about webmasters?

Webmasters deal with robot traffic and other rogue visits all the time. But this is a little different. In an effort to fool even the sneakiest malware exploits, LinkScanner does its best to imitate real user clicks - which means most webmasters are completely unaware of the problem.

At the moment, there is a way of filtering AVG traffic from log files. But it’s unclear whether this method would bag legitimate traffic as well. And Thompson suggests that - in the name of high security - AVG may make changes that prevent such filtering.

Can you believe the cojones on this guy? He’s basically flooding our servers with illegitimate traffic and then telling you that in the high name of security, you should bend over, present, enjoy it, and then PAY HIM FOR IT!

[Source: zdnet]

McAfee S.P.A.M. experiment and more ridiculous HackerSafe failures

Stay with me here readers, I’m stringing two stories about McAfee together here, a little out of the ordinary, so I hope it makes sense. If you aren’t interested in the tech details (of which there are very little), please do read for a good laugh.

Network World reported that McAfee conducted an experiment into what would happen if computer users really did respond to all those spam emails and click all those free virus scan popups. The experiment, called S.P.A.M. (Spam Persistently All Month) took 50 volunteers, both male and female, from numerous countries and tried to determine what would really happen. Of course, the end result will be exactly what you’d expect, but hey, I’m game for an experiment, and the volunteers get free computers, so let’s read on!

The article states:

By the time it was all over, after every bank-account phishing scam, Nigerian bank scheme, and offer for medication, adult content and just plain free stuff had been pursued. “I was horrified,” says Mooney, a realtor by profession. “It’s all snake oil. I’m amazed at what true junk is out there when you’re clicking through on e-mail.”

Holy crap… so, what this article is telling me is that McAfee is actually pointing out snake oil to end users? Whoa, this goes against all their marketing campaigns for HackerSafe certifications and their PCI solutions, but hey, that’s cool I guess. Oh wait, sorry, they’re not pointing out their OWN snake oil.

[Author’s Note: Sorry guys and gals, this was like a slow-pitch Softball… I couldn’t help myself]

The article goes on:

McAfee is releasing the results Tuesday of its free-wheeling month-long S.P.A.M. experiment, done largely to illustrate — if you didn’t know already — how spam is connected to malware and criminal activity, not to mention some of the slimiest marketing ever devised.

Holy haberdashery, Batman! Can you believe it? Spam, popups, phishing, etc. actually lead to malware and criminal activity? Not to mention some of the slimiest marketing ever devised?

Yeah, so about that slimy marketing… HackerSafe is popping up on my news radar again, as once again fearless friends of the people Russ McRee and Rafal Los have posted some very interesting comments on HackerSafe issues. From McRee’s newest blog entry, entitled “XSS Comedy at McAfee Secure’s Expense“:

In celebration of the deadline for PCI Requirement 6.6 compliance as of June 30, 2008, I thought I’d share a little web app sec comedy at McAfee Secure’s expense. As well you should know by know, the existence of XSS vulnerabilities in a site that is required to meet PCI DSS standards means that the site IS NOT PCI COMPLIANT. Very simple, right?

Let’s consider the McAfee Secure/Hacker Safe-branded site for Organize-It.
A seemingly handy site, perfect for your HGTV types, likely with healthy credit card limits. Uh-oh, here it comes. Oh yes, Organize-It handles credit cards and is thus beholden to PCI DSS. Organize-It is also proudly displaying a current McAfee Secure badge, indicating that it’s tested daily. Given the focus of many a recent discussion it shouldn’t shock you that Organize-It is vulnerable to XSS.

By the way, Russ as always has included video evidence, but yeah, it would seem that the McAfee Secure badge has failed us again. It sort of reminds me of when children play peek-a-boo and hide behind their hands and actually believe that you can’t see them… except that, yeah, they’re children, so you can’t blame them. Oh and about that slimy marketing that they do? Yeah, just check out that blog posting by Russ.

I will continue to say, you’re better off with the cheaper “Nate McFeters Secure” certification, and I mean, come on, who doesn’t want this picture proudly displayed on their site:


Source: zdnet]

Opera ships security patches, adds malware blocker

June 12th, 2008

Opera issues security patchesOpera users, get your browser patching engine ready.

The Norwegian software maker has released version 9.5 as a recommended security and stability update that includes patches for at least three serious security vulnerabilities.

The update, available here for download, patches the following:

Vulnerability #1:  When a page address contains certain characters, they can cause the page address text to be misplaced. In some cases, this could make characters be indistinguishable from each other, allowing some site addresses to look like other site addresses.

Vulnerability #2:  HTML CANVAS elements can use images as patterns, and that image data is made available to scripts. When the images are retrieved from other Web sites, the image data should no longer be available to scripts. A flaw exists in the way that Opera checks for the source of these images. Suitable manipulation can cause Opera to reveal the image data to scripts.

Vulnerability #3:  Pages from different sources held on the same parent page should not be able to modify the locations of each other. In affected Opera versions, if a page contains frames from both a trusted but not secured, and an untrusted source, the untrusted page is able to replace the contents of a named trusted frame, causing it to display misleading information. Note that since the untrusted frame could also display misleading information as its own contents, authors of sites containing sensitive information should not place frames from untrusted sources on their pages, without offering the user some means to identify the content as untrusted.

[SEE: Ex-Softies launch anti-malware startup ]

The new version also introduces anti-malware protection (a partnership with Haute Secure), upgraded phishing detection technologies, support for EV (extended validation) certificates, improvements to certificate handling, and a new security notification scheme in the address field.


[Source: Zdnet]