Showing posts with label Bot. Show all posts
Showing posts with label Bot. Show all posts

June 25, 2008

Marshall Islands Attacked

The Marshall Islands, an island chain housing 55,000+ people came under attack today.
The attack didn't involve bombs, missiles, guns, or any invading forces. This attack was brought about by a small group of "Hackers", who executed a distributed denial of service attack on the National Telecommunications Authority. This attack did not destroy, or damage any property/infrastructure, rather, temporarily cut off communications with the outside world. Marshall Island residents were still able to communicate inside the NTA network. The attack was a generically low-tech one, consisting of a mass spamming of the mail servers. The incoming spam filled up all the routes for mail exiting, thus rendering the servers useless. These spam mails were sent via a series of zombie computers from around the world. Presumably an individual (Re: One Person) had complete control of all the zombies from a private IRC channel, and is still executing the attack from there.

As of Late, "Botnets" have become an increasingly lucrative business for hackers. While relatively easy to setup, Renting a Botnet out could net one upwards of 10,000 US dollars.

As of Wednesday, June 25, external communications with the nation have still not been restored.

Would it be wrong for me to point out that the Marshall Islands were also where we tested the Nuclear Bomb? Recently it came out that the US was working on developing a "Carpet Bombing" technique for shutting down a nations IT infrastructure. What motivation would any individual or group have at shutdown a national infrastructure?
I Believe this may be the first in an unfortunate series of internet militarization tests.

January 14, 2008

Hacker Safe?


Please, don't be lulled into a sense of false security just because a website has the hacker-safe logo on it. "Why not?" You ask me, BECAUSE- *DURRRRR* NOTHING IS HACKER SAFE. But why specifically? The hacker safe certification is a subscription program through various Companies, and although your favorite "Adult" website may be hacker safe when you register. This doesn't mean it will be two weeks down the road. What they companies do is they test each registered website every day using a automatic program, and if they find problems they will tell the website. Thats it, they dont fix it, force the website to take down the certification, nothing- they just say "Hey theres a problem." Dont Believe me?
Geeks.com is a $150 million company specializing in the sale of excess inventory and manufacturers' closeouts. Its Web site says that it is tested on a daily basis by ScanAlert Inc., which offers a service that constantly monitors sites for vulnerabilities.
But ScanAlert spokesman Nigel Ravenhill said via e-mail last week that the vendor, which is being acquired by McAfee Inc., had withdrawn its Hacker Safe certification from Geeks.com "several times" last year after finding vulnerabilities in the retailer's systems. Geeks.com fell out of compliance last June and again in December, he said.
The compromised information included names, addresses, telephone numbers and Visa credit card numbers, according to a copy of the letter posted on The Consumerist blog.
Now, What are the implications of this break in? Am I telling you that you should be a paranoid schizo when doing business on the internet? DUH. A wise man once told me "Putting your credit card on the Internet is like putting your naughty parts in a wood grinder." Although its not the most glamorous quote in the world, its true. Listen to the man, dont stick your wah-wah in the wood grinder.