Showing posts with label Hacking News. Show all posts
Showing posts with label Hacking News. Show all posts

Malware Spreading Tool for the Masses

The police executed a bench warrant and arrested a 60-year-old man resident of Solana Beach, California. He is charged with computer intrusion and extortion and he is scheduled to appear in a federal court on October 31. Bruce Mengler is accused of hacking his way into a promotional website belonging to the US branch of car manufacturer Maserati and retrieving personal information about the company's potential customers.

Maserati hacked and blackmailed
Enlarge picture


The stolen personal data was gathered by Maserati as part of a promotion that was offering free gift certificates in exchange for participation in a test drive. The company distributed fliers to potential customers containing an invitation to test drive Maserati cars. The fliers contained a unique identification code intended to be used by the interested people on a promotional website in order to receive gift certificates usable at Omaha Steaks. Along with the code on the flier, people were asked on the website to also provide personal contact information.

The indictment does not specify exactly how Mengler accessed the information, but it suggests that he successfully downloaded the entire database, then blackmailed Maserati by asking money in return for his silence. He is supposed to have sent several letters from a “sol.beach@gmail.com” email address threatening to disclose the information and the incident publicly if he was not paid. To prove the authenticity of his claims, he included samples of the stolen information.

The company's losses are estimated at around $5,000, but the most important aspect of this incident is represented by the security policies adopted by companies in regard to customers’ personal data. 2008 has already been tagged by security researchers as “the data loss year” due to the increased number of cases where sensitive data was lost by employees, stolen by hackers or leaked through website security holes.

Graham Cluley, Senior Technology Consultant for security vendor Sophos, noted on his blog referring to the case that "if a hacker was able to gain access to customer information via the promotional website then there is a clear warning here to all companies that they need to properly secure their public websites". Undergoing such marketing campaigns where sensitive customer info is gathered is fine as long as they are performed in accordance to responsible security practices. “It’s all very well asking for potential customers to enter their names and addresses in exchange for free steaks, but you’ll be dealing with higher stakes (groan…) if your website is not properly defended,” Mr. Cluley adds.

[Source: softpedia]

BusinessWeek site hacked, serving drive-by exploits

BusinessWeek site hacked, serving drive-by malware downloadsMalicious hackers have broken into several sections of BusinessWeek.com and are now using the popular site to redirect visitors to malware-laden servers.

At the time of writing, hundreds of pages on BusinessWeek.com have been rigged with malicious JavaScript pointing to third-party servers. Visitors to the site execute the script, which attempts to launch drive-by malware downloads.

Firefox 3’s malware blocker is detecting some of the infection attempts but there are numerous malicious pages currently bypassing the browser’s blacklist-based filter.

BusinessWeek site hacked, serving drive-by malware downloads

[ SEE: Microsoft ships free code auditing tools to thwart SQL injection attacks ]

According to data from the Google Safe Browsing API, BusinessWeek.com has been flagged as malicious for a while:

  • Of the 2157 pages we tested on the site over the past 90 days, 214 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 09/15/2008, and the last time suspicious content was found on this site was on 09/11/2008.
  • Malicious software includes 721 scripting exploit(s), 4 trojan(s), 3 exploit(s). Successful infection resulted in an average of 2 new processes on the target machine.

SEE: SQL Injection attacks lead to wide-spread compromise of IIS servers ]

The use of legitimate Web sites in drive-by malware attacks has soared in recent months. According to expert estimates, at least 70 percent of all Web-based malware is now being hosted on legitimate Web sites. Some recent high-profile targets included Bank of India, China.com, and USA Today.

[Source: zdnet]

LHC HACKED,BEFORE IT COULD DESTROY THE EARTH

On 10 September 2008, a group identifying as the Greek Security Team managed to hack a computer system of the Large Hadron Collider charged to analyze the data from the Compact Muon Solenoid detector.In a web page of the CERN site, they described the technicians responsible for computer security as “schoolkids” and also expressed that they had no intention to disrupt the scientists’ work.

The hackers reportedly mounted an attack on the Large Hadron Collider, which has raised eyebrows over the security of this historic experiment in the world, as it surpasses a vital milestone.

Scientists say that it was a competition between two hacker groups - known in hacking circles as 2600 and 1337, that led them to break into the experiment just before it was to begin.

2600, also known as the Greek Security Team broke into the experiment and left a message saying, “We are 2600.. don’t mess with us…” The scientists who were behind the mammoth experiment had received threatening emails prior to the start.

Scientists working at Cern, the organisation that runs the vast smasher, were worried about what the hackers could do because they were ‘one step away’ from the computer control system of one of the huge detectors of the machine, a vast magnet that weighs 12,500 tons, measuring around 21 metres in length and 15 metres wide/high.

It appears that none of the experiments were adversely impacted by the security breach. But with “more than 110 different control systems” in place that run everything from building heating to radiation protection to the particle accelerators themselves, the idea of a security breach can seem frightening. Cern’s own Computing and Network Infrastructure for Controls group had previously produced a document that said, “recent events show that computer security issues are becoming a serious problem also at Cern.” The team refused to comment, however, on this week’s security breach.

Fortunately, only one file was damaged but one of the scientists firing off emails as the CMS team fought off the hackers said it was a “scary experience”. The hackers breached the CMSMON system, which monitors the CMS software system. CMS takes vast amounts of data during collisions.

[Source:rparmanik]

Hackers "Pwned" at DefCon

Two speakers proved that they hacked into the attendees' computers


Participants at the DefCon hacking conference, focusing on the latest methods of taking over end users' computers and corporate machines, found out that they had been subjects to a hijack themselves. According to an AFP report, the attendees at the conference were startled by the statements of Tony Kapela and Alex Pilosov, two "lecturers" at the conference, who said that they had silently intercepted data belonging to their colleagues.
Hackers at DefCon learned that their computers had also been hijacked
Enlarge picture

The method used by the two consisted in the exploitation of the paths on which data traveled along the network. Routing can be manipulated in such ways that owners of the affected computers can't tell that their online traffic is being tracked or that they receive other information than what they were waiting for. Instead of trying to break passwords or other security systems, hijackers who choose to use this type of approach only have to "convince" websites that the numbers corresponding to their computer defines the best path for these sites to deliver their data through.

The data traffic across the network is automatic, so websites choose, without verifying, the best path according to the numerical Internet address of the routes. The longer the address is, the higher the chances to be chosen. The hackers' job consists of adding some characters to the array to ensure that their computers are chosen as intermediaries between websites and other users. "Someone can passively intercept traffic," Kapela said. "We can store, drop, filter, mutilate, grope, or modify data heading to you."

And, in fact, this happened during DefCon, when some of the colleagues of the two hackers learned that their computers were not as safe as they thought. The two disclosed some email and search information intercepted while using the aforementioned method. In hackers' slang, some of the attendees, although also well-established hijackers, had been "pwned" by the two, meaning they were completely subdued to the actions of Kapela and Pilosov.

[Source: softpedia]

Russian Hacking Web Affects Hundreds of Thousands of Computers

Joe Stewart, Director of Malware Research at SecureWorks, discovered that a group of Russian hackers used a type of trojan that affected over 378,000 computers. The computers, all part of the same network, were infected via a genuine Microsoft application. Coreflood is the name of the trojan used to steal data from the affected machines, in ways that have never been employed before.

Russian hijackers spread their trojan to hundreds of thousands computers

The targeted companies reported a precise interval during which they felt the effects of the attack. SecureWorks observed some "infection events," with hundred of thousands of computers becoming infected on the same day. As trojans cannot spread all by themselves through a network, specialists took into account all the possibilities for that to happen. The team noticed that a Windows administration tool, PsExec, was used to infect all the computers in a network whose owners had domain administrator privileges. ie1823en.exe was then launched on every affected system.

The hackers, who were identified as being Russians, mostly used Coreflood to get information on bank accounts. They also had access to computers from major institutions, which means they could have gotten their hands on even more important data than previously estimated. Also, the hijackers had another advantage over the people and the institutions they attacked: Coreflood allowed them to get account details without having to log in, because the malicious software has the ability to read screen information. This is one of the reasons that make Coreflood so dangerous. Because of the free access to all data stored on a computer, investigators don't know yet the exact extent of incurred damages.

One of the most affected people was Joe Lopez, a businessman who lost $20,000 when this amount was withdrawn by an unauthorized person. After discovering that the money was missing, he also learned that his computer was infected with the trojan. Joe Stewart stated for the New York Times that the situation was under investigation and that, for this very reason, he could not give explicit details about the case.

Stewart also revealed that, while translating some blog posts that allegedly belonged to one of the members of the group of hackers, he found out that another one of them was dead. However, he also emphasized that, no matter the difficulties these hackers might come across, their illicit activity is still being carried on.

[Source: softpedia]

TV News Presenter Accused of Hacking an E-mail Account -

Larry Mendte, who used to work as a news presenter for a Philadelphia TV station, somehow managed to gain access to the e-mail of his co-presenter, Alycia Lane. The information he had access to for a period in excess of two years was later on leaked to abloids and resulted in
Lane's downfall. Since the start of this year and until the month of May, Mendte fraudulently accessed the e-mail account 537 times. The former newscaster is now under federal investigation and risks spending up to six months in jail if he is found guilty in a court of law.

Here is what U.S. attorney Laurie Magid comments on the case, "The mere accessing and reading of privileged information is criminal. This case, however, went well beyond just reading someone's e-mail. It's no different than someone stealing your locked briefcase, containing information from your lawyer, prying it open and helping themselves to the contents".

At the TV station in question, which is called KYW-TV and is an affiliate of CBS, Larry Mendte and Alycia Lane worked together over a period of four years, until this January. Mendte, aged 51, stopped working at the end of June, the current year, after the fact that the FBI was investigating him come to light. His last time on air was on the 29th of May.

Why would the aging newscaster resort to such actions? The reason seems to be envy. Mendte could not handle the fact that he was earning about $680,000 per year, about $100,000 less than his beautiful co-presenter. According to Paul Rosen, Lane's attorney, the fact that her career was going the right way determined Mendte to undermine her. Perhaps he would not have been able to hack her account if she had followed our advice on how to come up with a super strong password.

Michael Schwartz, legal council for Mendte, explains, "As we continually have said from day one, Larry has been cooperating fully with the investigators. He continues to cooperate and will accept full responsibility for his actions". Taking such a responsibility may very well get him a six-month incarceration sentence, according to the federal law.

KYW-TV had nothing to comment on the recent incident involving its former employee, but we can expect Lane to sue the TV station for "wrongful termination".

[Source: softpedia]

iPhone Hacker Wanted by Apple

Apple is looking to employ an iPhone hacker
Comments: Apple is looking to employ an iPhone hacker
Credits: ABC News
It seems that Apple, company that specializes in consumer electronics and software solutions, is looking for someone who is skilled enough so as to successfully hack the iPhone. Someone could in theory successfully attack an iPhone, since it has recently been revealed that even the newly launched iPhone 2.0 is vulnerable to URL spoofing.

Apple is currently advertising the fact that it wants to bring someone on board and offer that person the job of "iPhone Security Engineer", a full time job at the company's headquarters in Cupertino, California. So if you are a skilled hacker with a particular interest in mobile technology and you can deliver a "proof of concept" attack on the iPhone, then perhaps you could switch sides and work for the corporate world.

Kevin Mitnick, a former hacker turned security consultant, strongly supports the idea of putting one's hacking skills to good use to improve security for a company, rather than working illegally and possibly ending up in jail. Mitnick for example, who in his hacker years managed to break into the networks of renowned companies such as Nokia and Motorola, ended up serving a 5-year sentence in a federal prison after the law enforcement agencies caught up with him.

"Apple's CoreOS organization is looking for an exceptional individual to validate the security architecture for the iPhone. As an implementer of advanced technologies in OS X, you will have the opportunity to have a major impact on Apple's embedded operating system products. Our environment fosters product innovation, rapid product iteration, and a liberating amount of autonomy," says Apple.

The person best suited for the job must have a passion for security technologies, must be capable to come up with "proof of concept" attacks, must be able to deliver a result within a certain amount of time, and must maintain a professional attitude.

[Source: softpedia]

British Military Hacker to Be Extradited to the U.S. -

The British man accused of hacking 97 military and NASA webpages, which is considered to be world's biggest military hack of all time, has lost the appeal in front of the House of Lords. After he was convicted for the violation of top-secret online properties, Gary McKinnon, a 42-year-old unemployed network administrator, tried to stop his extradition to the United States.
Today, the highest British court rejected his plea, so soon he will have to face an American High Court. In order to prevent that from happening, McKinnon said that he already pleaded to the European Court of Human Rights.

Although the man claims that he just wanted to get some information on UFOs from a more reliable source, the U.S. Government accused him of not only entering some prohibited areas, but also of making changes and causing the malfunctioning of several computers.

"Having gained access to these computers the appellant deleted data from them including critical operating system files from nine computers, the deletion of which shut down the entire US Army’s Military District of Washington network of over 2000 computers for 24 hours, significantly disrupting Governmental functions," says the House of Lords document released after the verdict. In addition, the total amount of money necessary to clean up the damage reached up to $700.000.

McKinnon is advised to plead guilty, to get a 3-4 year penalty, with only 6-12 months to be spent in a U.S. prison. In case he refuses collaboration, the American Government could accuse him of terrorism. "If, however, the appellant chose not to cooperate, and were then extradited and convicted, he might expect to receive a sentence of 8-10 years, possibly longer, and would not be repatriated to the UK for any part of it. He would accordingly serve the whole sentence in a US prison (possibly high security) with at best some 15% remission." says the report of the High Court.
[Source: softpedia]

Hacked Data Used by Korean Loan Sharks -

Korean hacked data reseller wanted by the police
According to the Korean police, an unidentified Chinese hacker managed to get hold of 9 million credit records that were sold on for a profit in Korea. The person responsible for stealing these records is known only as Chun, and it seems that he managed to flee to China before the Korean law enforcement agencies had a chance to take him into custody. Another 29-year-old suspect related to this incident has evaded the authorities by going to China. The police did manage to arrest 6 people believed to be accomplices of Chun, but they have been all processed and released.

Out of the 9 million records the hacker got hold of, 4.8 million belong to banks, 260,000 to loan firms, 650,000 to online shopping malls, 5,300 to universities, and 3.2 million to various web pages.

Shin, 42 years of age, one of the people that the Chinese police took into custody, ran a so called "loan mediating company" that would contact people and offer to lend them money. The contact information of these potential customers was provided by a Chinese hacker who, back in May 2006, broke into Korean banks, loan firms and Internet shopping malls databases for the bargain price of $14,900. About 4.8 million records were obtained from banks alone, including info such as name, address, phone number, and credit card details.

Chun, Shin, and the other people involved in the case did not use the data provided by the hacker to fraudulently obtain credit cards or lines of credit. What they did instead was use that info to contact people and put them in touch with loan sharks. It is estimated that about 1,100 transactions were made, and for each one Chun charged a 5-15% commission. The Korean authorities also estimate that part of the records were sold on to an unscrupulous loan operation for a profit. Chun and his associates were so successful that they managed to bring in an estimated $2.67 million.

A warrant has been issued under the name of 42-year-old Chun, but the Seoul Metropolitan Police Agency's Cyber Crime Investigation Division will first have to track him down, then take him in custody. His six accomplices were arrested, but have not been detained.

This incident is very much similar to spam, except that instead of sending you messages that try to convince you to buy something, the Koreans in question phoned people and asked them whether they would like to borrow some money.

[Source: softpedia]

British Military Hacker to Be Extradited to the U.S. -

Internet users are no longer so naive as to open files that come from unknown senders and with the promise of revealing celebrities in compromising situations. However, they still open emails that seem to have been sent by their bosses or business partners, without taking any precaution or verifying who really is behind the "No work tomorrow for all the employees" message.

In order to prevent their data from being hijacked, users are advised by the SANS Institute to enable the Principle of Least Privilege, which allows every module to access only the information and resources that are necessary for its functioning. "We tend to operate desktops under the principle of most privilege. How many of you allow your users administrator rights in the workplace? At home, everyone has local administrator. This allows the ‘bad guys’ free reign." says John Bambenek of the SANS Institute.

A common mistake people make is that of considering an anti-virus solution a cure-all tool. Their confidence in it goes to such extents that they don't back it up with other applications, which can really work together with the anti-virus to create a malware shield. SANS also underlines the importance of a firewall, that can enhance the estimated 90% chances of an anti-virus to block an attack – all the more when anti-viruses don't always manage to keep the pace with malware spreaders and that they only remove known threats.

"For instance, the combination of AV protection with a good perimeter firewall brings you a little farther down the road of security. While there is a debate on whitelisting vs. blacklisting technologies for binaries, a good step would be to start digitally signing binaries and go to a ‘bayesian’ method of determining risk. Not perfect, but better." Bambenek advises.

Both end-users and developers have to acknowledge that data, identities and intellectual property are those in need of protection, and not the case that hosts the information, as hardware components are. By acknowledging that their privacy is at stake, people may become more careful when pressing the "next" and "are you sure?" buttons of their anti-virus without reading the text. With all that, the Institute does not hold people responsible. SANS recommends developers to be more careful when alerting users about malware, because they tend to "mash button" the questions and indications, which are often redundant or too difficult to understand.

[Source: softpedia]

Hacked Data Used by Korean Loan Sharks

According to the Korean police, an unidentified Chinese hacker managed to get hold of 9 million credit records that were sold on for a profit in Korea. The person responsible for stealing these records is known only as Chun, and it seems that he managed to flee to China before the Korean law enforcement agencies had a chance to take him into custody. Another 29-year-old suspect related to this incident has evaded the authorities by going to China. The police did manage to arrest 6 people believed to be accomplices of Chun, but they have been all processed and released.

Out of the 9 million records the hacker got hold of, 4.8 million belong to banks, 260,000 to loan firms, 650,000 to online shopping malls, 5,300 to universities, and 3.2 million to various web pages.

Shin, 42 years of age, one of the people that the Chinese police took into custody, ran a so called "loan mediating company" that would contact people and offer to lend them money. The contact information of these potential customers was provided by a Chinese hacker who, back in May 2006, broke into Korean banks, loan firms and Internet shopping malls databases for the bargain price of $14,900. About 4.8 million records were obtained from banks alone, including info such as name, address, phone number, and credit card details.

Chun, Shin, and the other people involved in the case did not use the data provided by the hacker to fraudulently obtain credit cards or lines of credit. What they did instead was use that info to contact people and put them in touch with loan sharks. It is estimated that about 1,100 transactions were made, and for each one Chun charged a 5-15% commission. The Korean authorities also estimate that part of the records were sold on to an unscrupulous loan operation for a profit. Chun and his associates were so successful that they managed to bring in an estimated $2.67 million.

A warrant has been issued under the name of 42-year-old Chun, but the Seoul Metropolitan Police Agency's Cyber Crime Investigation Division will first have to track him down, then take him in custody. His six accomplices were arrested, but have not been detained.

This incident is very much similar to spam, except that instead of sending you messages that try to convince you to buy something, the Koreans in question phoned people and asked them whether they would like to borrow some money.

[Source: softpedia]

TV News Presenter Accused of Hacking an E-mail Account

Larry Mendte, who used to work as a news presenter for a Philadelphia TV station, somehow managed to gain access to the e-mail of his co-presenter, Alycia Lane. The information he had access to for a period in excess of two years was later on leaked to abloids and resulted in
Lane's downfall. Since the start of this year and until the month of May, Mendte fraudulently accessed the e-mail account 537 times. The former newscaster is now under federal investigation and risks spending up to six months in jail if he is found guilty in a court of law.

Here is what U.S. attorney Laurie Magid comments on the case, "The mere accessing and reading of privileged information is criminal. This case, however, went well beyond just reading someone's e-mail. It's no different than someone stealing your locked briefcase, containing information from your lawyer, prying it open and helping themselves to the contents".

At the TV station in question, which is called KYW-TV and is an affiliate of CBS, Larry Mendte and Alycia Lane worked together over a period of four years, until this January. Mendte, aged 51, stopped working at the end of June, the current year, after the fact that the FBI was investigating him come to light. His last time on air was on the 29th of May.

Why would the aging newscaster resort to such actions? The reason seems to be envy. Mendte could not handle the fact that he was earning about $680,000 per year, about $100,000 less than his beautiful co-presenter. According to Paul Rosen, Lane's attorney, the fact that her career was going the right way determined Mendte to undermine her. Perhaps he would not have been able to hack her account if she had followed our advice on how to come up with a super strong password.

Michael Schwartz, legal council for Mendte, explains, "As we continually have said from day one, Larry has been cooperating fully with the investigators. He continues to cooperate and will accept full responsibility for his actions". Taking such a responsibility may very well get him a six-month incarceration sentence, according to the federal law.

KYW-TV had nothing to comment on the recent incident involving its former employee, but we can expect Lane to sue the TV station for "wrongful termination".

[Source: softpedia]

New Trojan Guaranteed to Bypass Detection

The Trojan in question has been named Limbo 2, and according to the people who came up with it, the best 10 security software solutions on the market today are not capable of detecting it. Acquiring this malware will set you back about $1,300, but for that amount of money you will get a software product that is unique, customized to your personal requirements, and guaranteed to run under the radar of most security solutions.

"Each variant sold is built anew and has to be customized to incorporate the domain of where all the information is to be sent back to. These are then sold on to websites or botnets to infect individuals," says Prevx, the security company that discovered the threat.

What does the Trojan do? Once it manages to infect a system, it goes to work whenever it detects that the user has accessed an online banking service. Not only does it record the regular login info, it also adds spoofed information boxes which ask you to provide additional information in regard to your bank account. All the gathered security credentials are then sent to the person that bought Limbo 2, so that it can be used for whatever malicious purpose that person has in mind.



"This is one of the most dangerous Trojans out there at the moment. The strength of this piece of malware lies in its versatility, even if it is recognized up by an anti-virus company it can be changed so as to be invisible again within hours. There are likely to be so many variants out there that they will never all be detected, which is a scary thought as it is designed to steal bank details," says Jacques Erasmus, Director of Malware Research with Prevx.

According to Erasmus, this is a very lucrative piece of software, earning the designer of Limbo 2 a few thousand pounds every day. Since it has not yet been detected how the malware propagates, it is safe to assume that the source of infection is a malware spreading site.

[Source: softpedia]

President of Georgia Web Page Down after Hacker Attack -

Over the weekend, the web page of Mikhail Saakashvili, the president of Georgia, has been under an intense DDOS (denial-of-service) attack, which caused it to temporarily shut down. According to the Shadowserver Foundation, the attack began on Saturday morning and rendered the web page unavailable for a period of about 24 hours. Here is an example of the commands the foundation has detected so far: "flood http www.president.gov.ge/".


The server that hosts the Presidential web page also harbors the Social Assistance and Employment State Agency website, as well as other sites that have become unavailable due to the attack.

Steven Adair from the Shadowserver Foundation comments: "Who else have these guys been attacking with this MachBot C&C server? The answer is no one. This server recently came online in the past few weeks and has not issued any other attacks that we have observed until recently. All attacks we have observed have been directed right at www.president.gov.ge."

What is the reason for this multi-pronged distributed denial of service attack? Since the Shadowserver Foundation has yet to provide a precise answer, we can only speculate. What we do know is that political relations between Georgia and Russia have been quite tense recently. There are reasons to believe the attack originates from Russia and, as the attack on Lithuania has proven, this is the usual manner in which Russian hackers respond to political tensions.

"We do not have any solid proof that the people behind this C&C server are Russian. However, the HTTP-based botnet C&C server is a MachBot controller, which is a tool that is frequently used by Russian bot herders. On top of that the domain involved with this C&C server has seemingly bogus registration information but does tie back to Russia," says Steven Adair.

The Shadowserver Foundation is made up of several security pros that voluntarily monitor online traffic in an effort to detect malware, botnet activity, and electronic fraud. People must be made aware of the threats they may encounter while surfing the web, threats that range from malware spreading sites to compromised servers.

[Source: softpedia]

Malaysian ISP Records Torrent Tracker Traffic

Shinjiru is an Internet service provider (ISP) from Malaysia that succumbed to pressure from the Government last month and consequently shut down the web pages of several BitTorrent trackers. Although most of these sites are now up and running as if nothing ever happened, TorrentFreak has discovered that Shinjiru is secretly monitoring the activity of several torrent sites.

A sysop from tbkresources.org became suspicious when he discovered that "an external disk was suddenly mounted on our box." Curious to find out the purpose of the disk, the sysop contacted Shinjiru's customer support, but they could not provide an explanation. It was later revealed that the Shinjiru legal team had installed the previously mentioned disk, but nobody seems to know the exact reason for that.

It would seem that Shinjiru believes these torrent trackers are in breach of current legislation, copyright infringement to be more precise, has launched an investigation, and copying data from the servers is part of said investigation. The curious thing is that the ISP is doing all of this in secrecy, trying not to draw any attention to its actions.


"This is important to get out as they are most probably doing this to every site they know about, and users are being recorded. We have destroyed the data on their USB connected disk, destroyed our site backups on it and truncated and deleted all tables, to ensure the protection of our users. As I have stated it was done with out warning nor consent," says the sysop as cited by TorrentFreak.

Because the Malaysian Government was to blame for the recent tracker shut down, it is believed that it is behind the current situation as well. But since the ISP is copying data from its own clients, it should have first issued a warning, or at least an informative note about its plans. An official reply from the Malaysian ISP has yet to be released to the public.

[Source: softpedia]

Iranian Hackers Try to Silence Malcolm Hoenlein

According to Ohad Rosen, the web page that he administrates has recently come under constant hacker attack, presumably of Iranian origin. The cause of the attack is a message posted on the site, from Malcolm Hoenlein, executive vice chairman of the Conference of Presidents of Major American Jewish Organizations, addressed to the Iranian people. In the message, which is subtitled in both Arabic and Persian, Hoenlein states that the Iranian Government does not have the best interests of the people at heart.


Here is an excerpt from the message, which is two and a half minutes long and was posted on the Israeli site on the 18th of June: "We want to work with you. It is regrettable that you have a leadership that does not care about your welfare, and the conditions under which you live, but rather exploits it in search of extremist goals," says Malcolm Hoenlein.

The web page in question is called Jersulameonline.com and Rosen says that in the short amount of time the message has been posted, a "dozen" hacker attacks have been recorded. Although these attacks have not been successful and the content on the web page has not been significantly altered, Google has labeled the site as "dangerous". The hackers did not manage to take down the message, but instead deleted pictures on the site and tampered with some links.

One of the main reasons the hackers have not been able to accomplish their goal, is the fact that Itai Green has set up tighter security measures. Itai is the site's director and according to him the security measures have been upgraded in order to prevent future hacker attacks to considerably damage the site. One thing is for sure, Itai is determined not to take down the message, no matter how many attacks are recorded.

The political relationships between Israel and Iran are quite tense, and have been like that for quite some time now. On numerous occasions Mahmoud Ahmadinejad, the President of Iran, has said "it should be wiped off the face of the earth" when talking about Israel.

It must be noted that no site is hack proof, as the recent attack on Kaspersky Malaysia has proven.

[Source: softpedia]

Kaspersky’s Malaysian site hacked by Turkish hacker

According to Zone-h.org, Kaspersky’s Malaysian site has been defaced by a Turkish hacker during the weekend, through a SQL injection, leaving the following message - “hacked by m0sted And Amen Kaspersky Shop Hax0red No War Turkish Hacker Thanx to Terrorist Crew all team members“.

The image “http://blogs.zdnet.com/security/images/kaspersky_malyasia_hacked1.JPG” cannot be displayed, because it contains errors.

“The official Malaysian Kaspersky Antivirus’s website has been hacked yesterday by a Turkish cracker going by the handle of “m0sted”. Along with it, the same cracker hacked also the official Kaspersky S.E.S. online shop and its several other subdomains. The attacker reported “patriotism” as the reason behind the attack and “SQL Injection” as the technical way the intrusion was performed.

Both websites has been home page defaced as well as several other secondary pages. The incident, though appearing a simple website defacement, might carry along big risks for end-users because from both the websites, evaluation copies of the Kaspersky Antivirus are distributed to the public. In theory, the attacker could have uploaded trojanized versions of the antivirus, infecting in this way the unaware users attempting a download from a trusted Kaspersky’s file repository (remember the trojan in the Debian file repository?).”

Are users at risk due to the compromise? Not in this case, however, the attack is a wake up call which if not taken seriously enough could result in an ironic situation where a security vendor’s site is infecting its visitors with malware. It has happened before, and it will definitely happen again.

This is not an isolated incident. According to Zone-h’s archive, since 2000 there have been 36 web site defacements of international Kaspersky sites, with Kaspersky’s French site getting hacked and re-hacked on an yearly basis. And while in none of the incidents there was any malicious software served, or a live exploit URL that could have been embedded into the legitimate site, there’s an ongoing trend related to web site defacements in regard to their interest in monetizing the access they have to the vulnerable sites, by injecting malware URLs, hosting phishing pages, and also, locally hosting blackhat SEO junk pages where they would eventually earn money through affiliate based networks.

In the time of blogging there’s no indication of a malware attack at the site, and kaspersky.com.my remains offline, presumably in an attempt to audit the site for web application vulnerabilities before putting it back online.

Related posts :

[Source: zdnet]

San Francisco Unable to Access Its Own Network


San Francisco IT admin puts network under total lockdown
Enlarge picture
San Francisco's multimillion-dollar FiberWAN network, which is used to handle delicate information in regard to law enforcement documents and city payroll files, was hijacked by a 43 year old disgruntled employee. Terry Childs used to work for the city of San Francisco as a computer network administrator and it seems that no other admin can access the network because Childs has locked them all out. The only password that still works is his own, but the SFPD have yet to convince him to give it up. Childs has been taken into custody and is charged with four separate counts of computer tampering.

Ron Vinson, CAO (Chief Administrative Officer) with the SF Department of Telecommunication Information Services, comments: "It was a little unnerving to discover that this person had created this fiefdom of access to our network. We continue to monitor the system to make sure that we do maintain the integrity of the network. The issue at hand is the access codes that we are trying to get our hands around."

Of course, the city of San Francisco is working hard to regain control of the network, but since Childs does not want to cooperate, it might take some time. The authorities also believe that Childs has provided 3rd parties with network passwords.

What spurred the IT admin to resort to such actions? It seems that he had installed on the network special software that would inform him whenever modifications would be made to his personnel file. Recently his work performance had been evaluated as poor and disciplinary measures would have ensued.

Terry Childs is scheduled to appear in a court of law on Thursday, the 17th of July. If he is found guilty as charged, the court may issue a 7 year sentence. His bail has been set at $5 million. Keep in mind though that for a person charged with murder the bail is of just $1 million. It would seem that Childs is considered a bigger danger to society than a murderer.

Ron Vinson again: "He had the trump card and he could have brought everything down if he wanted to."

[Source: softpedia]

Social Engineering Hacker Provides His Insight

Kevin Mitnick used to obtain security credentials not by using special hacking software or tools, but by using social engineering. This way he would manage to get passwords and code which he would later use to hack into company networks. His most prestigious hacks include Nokia, Sun Microsystems, Fujitsu Siemens and Motorola. After spending 5 years in a federal prison paying for his crimes, he decided to switch sides and he now works as a security consultant, willing to share with the world what he learned about IT security.

In the 70s, the law did not cover hacking, so there was no penalty for it. Even when a hacking law was issued in 1980, people involved with hacking were doing it for recognition, not with malicious intent. "There was no motive for money or malicious intent to use, disclose or destroy the data," he says as cited by CIO.

When Mitnick got into hacking, he never thought that he would end up in jail because of it. The current laws and ethics code should deter any would-be hacker from going down the wrong path and getting in trouble. Mitnick advises young users to learn from his mistakes.

The issue of security is taken incredibly lightly by some companies. Even after Mitnick discovers a vulnerability, a way of hacking into a corporation's network, the problem is not remedied right away. The law asks that all organizations do security audits, but it seems that some auditors do not get the company to solve the issue.


If you are skilled at hacking, try getting a legitimate job in IT security Mitnick advises. "Now, I do the same thing that got me in trouble, except I do it with authorization. Clients hand me their network and tell me to break in so they can fix security vulnerabilities. To me, it's the same act but it helps my clients and it's legal and ethical," he says.

"Penetrating a company’s security often starts with the bad guy obtaining some piece of information or some document that seems so innocent, so everyday and unimportant, that most people in the organization don’t see any reason why the item should be protected and restricted," says Mitnick in his book, "The Art of Deception."

[Source: softpedia]

Kaspersky to Simulate Successful Hacking Attack on Intel CPU

Kris Kaspersky, software engineering expert, security consultant and technical writer, will demonstrate at the upcoming HITB (Hack in the Box) Security Conference how an attacker can use JavaScript and TCP/IP packets to remotely exploit a flaw in the Intel processor. The conference will be held in Malaysia over a period of three days, from the 27th to the 30th of October. Kris is not to be confused with Eugene Kaspersky, the co-founder of the security software company Kaspersky Lab.


"In this presentation, I will share with the participants the finding of my CPU malware detection research which was funded by Endeavor Security. I will also present to the participants my improved POC code and will show participants how it’s possible to make an attack via JavaScript code or just TCP/IP packets storms against Intel based machine. Some of the bugs that will be shown are exploitable via common instruction sequences," says Kris Kaspersky.

According to Kris, as long as an attacker is familiar with JIT Java-compilers and the way they work, that compiler can be "persuaded" to perform several actions, such as crashing the system. Basically, any hacker with a particular set of skills can take over the compiler.

At the Malaysia security conference Kris will also let IT enthusiasts in on how a flawed CPU damages the HDD without the user even realizing it. Kris will also share info in regard to data recovery.

Did you know that Intel Core 2 is plagued by as many as 128 flaws and that Intel Itanium by 230? These bugs can affect you in several ways, from crashing your system when certain conditions are met, to granting an attacker complete access to your machine. These security vulnerabilities can be exploited locally or remotely, no matter what OS you have installed, what programs you are running, and how recently you patched your operating system.

The thing is that for the end-user there are no tools that one can use to check for these bugs, not to mention that even if there were such a tool, for numerous bugs there is no fix available.


[Source: softpedia]