Showing posts with label Hacked. Show all posts
Showing posts with label Hacked. Show all posts

July 1, 2008

Mcafee's Spam Project.

Have you ever pondered to yourself, "What would happen if I left my computer without anti-virus, routine maintenance, or any care to be taken of it?" Do you imagine a zombie computer, revving its engine repeatedly in disgust of your lack of decent ownership?Well,Mcafee has released the results of its Spammed Persistently All Month campaign- So you do not have to wonder anymore.

The project asked a group of 70 users from 10 countries to surf the web unprotected and gather as much spam as possible.

The guinea pigs were able to amass a total of 104,000 spam messages, an average of 2,096 messages per person and 70 messages per day for each user.

Americans topped the spam haul, amassing 23,233 spam messages between five users. Brazil finished a distant second with 15,856 messages, and the UK was fifth with 11,965.

Participants in the study also noticed significant system slowdowns from unwanted software installations.

"In just 30 days there was quite a noticeable change in the performance of their computers," said McAfee Avert Labs senior vice president Jeff Green.

"This showed just how much malware was being installed without their knowledge, and that spam is much more than a nuisance. It is a very real threat. "

The US also led the study in the number of adult-oriented spam messages, while the UK received the highest number of Nigerian '419' messages. Brits received more than 23 per cent of the infamous money transfer scam attempts.

Financial services messages were the most popular spam topics, followed by advertisements and health and medicine messages. Adult emails were the fourth most-popular, while offers for free items were fifth and 419 scams tenth.

McAfee also noted an increasing number of location- and language-specific spam, particularly in France and Germany. The large spam loads in Brazil and Mexico also suggest a new focus on emerging economies.

"Our participants came from all walks of life, from all over the world and, given their interest to take part in the experiment, they were well aware of the problem," said McAfee chief executive Dave DeWalt.

"Despite this, they were all shocked by the sheer amount of spam they attracted in such a short time and the lengths the spammers would go to in order to achieve success."AA

June 25, 2008

Marshall Islands Attacked

The Marshall Islands, an island chain housing 55,000+ people came under attack today.
The attack didn't involve bombs, missiles, guns, or any invading forces. This attack was brought about by a small group of "Hackers", who executed a distributed denial of service attack on the National Telecommunications Authority. This attack did not destroy, or damage any property/infrastructure, rather, temporarily cut off communications with the outside world. Marshall Island residents were still able to communicate inside the NTA network. The attack was a generically low-tech one, consisting of a mass spamming of the mail servers. The incoming spam filled up all the routes for mail exiting, thus rendering the servers useless. These spam mails were sent via a series of zombie computers from around the world. Presumably an individual (Re: One Person) had complete control of all the zombies from a private IRC channel, and is still executing the attack from there.

As of Late, "Botnets" have become an increasingly lucrative business for hackers. While relatively easy to setup, Renting a Botnet out could net one upwards of 10,000 US dollars.

As of Wednesday, June 25, external communications with the nation have still not been restored.

Would it be wrong for me to point out that the Marshall Islands were also where we tested the Nuclear Bomb? Recently it came out that the US was working on developing a "Carpet Bombing" technique for shutting down a nations IT infrastructure. What motivation would any individual or group have at shutdown a national infrastructure?
I Believe this may be the first in an unfortunate series of internet militarization tests.

June 24, 2008

New Biometric Bank Protection

A voice biometric system for authorizing banking transactions was launched yesterday, and even Rory Bremner's impressions are not clever enough to fool it.

Voice Transact, which is the brainchild of Nick Ogden, the founder of the WorldPay remote payment system, uses a vocal signature that is matched against a pattern stored on file when the account it opened. It is designed to help reduce fraud, particularly phishing-related online scams.

"We are creating a global network for banks to use that is changing the way people confirm their transactions," Mr Ogden said. "Voice biometric signatures can enable consumers to have complete control over signing for financial transactions anywhere in the world."

The company is in talks with a major pan-European bank and expects to launch a service in the UK towards the end of the summer. It is also in discussion with MasterCard, and in six weeks' time, consumers at a participating Dubai bank will be able to take money out of a cash machine without their bank card. By selecting the "cardless transaction" option, and inputting the mobile phone number, the customer will be immediately rung back and asked to repeat a random string of numbers. Once the voice pattern has been matched, the cash machine will dispense money in the normal way.

The company invested $10m (£5m) in the technology, which works by creating a profile when a customer registers their account. Transactions are authorized by repetition of a random string of numbers that do not relate to the financial information but merely function as a way of getting the person to talk.

While a customer who has actually lost their voice could have problems, a normal cold should present no problems, and a three-hour test session was conducted with Rory Bremner last year to ensure that the system cannot be cracked. "We guarantee the integrity of the system so we will stand behind any transaction that is processed through the network," Mr Ogden said. If an authorization is rejected, the customer will immediately be contacted by a call centre as an alternative verification.

My thoughts? This system will not make a flipping difference in regards to limiting the amount of phishing. Nearly all phishing scams are geared towards the least technological savvy people, so harvesting authorization will be no problem. All that would be required is to get a person to "Verify Their Account" on a phishing server, including having a person say numbers 1-9. This would include verifying the account with their Voice authorization , which would be ftp'd to the Phishers records. The recording could be then played using any high grade audio output, thus bypassing the authorization. Yet another biometric meant to keep honest people honest.

June 20, 2008

ALERT: MAC OS-X New Exploits

Did you really think your precious Mac was immune? That you were exempt from the Warzone that is the interwebs? Well, unless you have the intelligence of a monkey, this alert doesn't apply. This requires you to actively allow the hacker access, however for easily manipulated clients- you may need to pay heed to this latest alert.

Security vendor SecureMac has discovered multiple variants of a Trojan capable of letting a hacker remotely commandeer a Mac computer.

The malicious code is being distributed from a hacker Web site, where there have been discussions on distributing the Trojan through iChat and LimeWire, said SecureMac, which has given the Trojan a "critical" security rating. The program can infect Mac OS X 10.4 and 10.5 machines.

A Trojan is a program that appears legitimate, but performs illicit activity when it is run, such as stealing passwords, making the system more vulnerable to future entry, or simply destroying programs or data on the hard disk. LimeWire is a popular peer-to-peer file-sharing program, and iChat is Apple's instant messaging client.

Besides offering a hacker remote access to the system, the Trojan discovered by SecureMac can transmit system and user passwords. Additionally, the application can log keystrokes, take pictures with the built-in camera on a Mac, take screenshots, and turn on file sharing.

The program takes advantage of a flaw within the Apple Remote Desktop Agent. The program avoids detection by opening ports in the firewall and turning off system logging.

The Trojan is distributed as AppleScript called Asthtv05 or as an application bundle called Astht_v06. The filed must be downloaded and opened in order to infect a machine.

Malicious code targeting the Mac isn't new. Apple in May released a patch for a serious vulnerability within its iCal calendar application. The flaw made it possible for an attacker to exploit the vulnerability by adding or modifying files on a CalDAV server. The code is distributed as an .ics calendar file in an e-mail attachment, or through a malicious Web site.

June 18, 2008

More Data Stolen

Finjan Inc., a leader in secure web gateway products, today announced its discovery of a server controlled by hackers (Crimeserver) containing more than 500Mb of premium
data. The data included healthcare and business related data, as well as
personal identifiable information (stolen Social Security Numbers). This
data is part of the premium offering that the cybercriminals operating the
Crimeservers were selling to the highest bidder online.

The compromised data came from all around the world and contained
information from individuals, businesses, airlines and healthcare
providers. The report contains examples of compromised data that Finjan
found on the Crimeserver, such as:

- Compromised medical related data of hospitals and publicly owned
healthcare providers

- Compromised business related data of a U.S. airline carrier

- Identity theft (stolen Social Security Numbers)

Some of the implications of stolen medical and patient data include:
illegal and/or bogus treatments; obtaining prescription drugs for the
purpose of selling them; loss of health coverage for the victimized
patient; inaccurate records of victimized patients, which could result in
incorrect and potentially harmful treatments. Healthcare providers could
also face potential HIPAA violations or breach of general data protection
legislation.

Finjan's Malicious Code Research Center (MCRC) detected a Crimeserver
operated by cybercriminals who used campaigns to steal data. These
campaigns consisted of highly sophisticated attacks, incorporating
Crimeware toolkits, Trojans and Command and Control (C&C) servers to drive
traffic from a specific region, with specific characteristics.

"This report illustrates the latest development in cybercrime. It shows
the business cycle of data collecting and trading by today's
cybercriminals. Crimeware infecting PCs is a serious business problem that
has far-reaching consequences, such as impacting the security of businesses
and patients around the world," said Yuval Ben-Itzhak, CTO of Finjan. "We
see that cybercriminals go after premium data that they can trade for
substantial profit. The increase in Web-based attacks is staggering.
Industry figures include a growth of more than 200% of Web-based malware,
with an increase of over 800% in backdoor and password-stealing malware,
illustrating that sensitive corporate and medical are at risk."

According to Finjan, the fact that sensitive business, patient and
personal data were compromised in a timeframe of less than one calendar
month underscores the necessity for enterprises and organizations to have a
comprehensive security technology in place that provides effective
protection against these sophisticated threats.

The compromised data and the Crimeserver applications were detected
using Finjan's patented active real-time code inspection technology while
diagnosing users' Web traffic.

June 11, 2008

I am controlling your PC via Bluetooth.

Microsoft's June Patch Tuesday release included a critical fix affecting all Windows Vista and XP systems, which could allow attackers to wirelessly steal confidential information from laptops by exploiting a flaw in the Bluetooth stack.

The Bluetooth stack flaw, detailed in Microsoft bulletin CVE-2008-1453 and rated 'critical', could allow an attacker to take complete control of an affected system, install programs, alter data or create new accounts with full user rights.

The MS08-030 patch modifies the way the Bluetooth stack handles a large number of service description requests.

Microsoft recommends applying the patch immediately and security experts advise users to turn off Bluetooth features until the patch has been applied.

Matthew Aburn, director of security consultancy Halcyon, said the flaw was particularly dangerous because hardware manufacturers usually set the factory default for Bluetooth as 'active'.

"Hardware-wise, most ship with Bluetooth on by default. I'd definitely recommend that if you're not using Bluetooth, you should turn it off," Aburn told ZDNet.com.au.

Rob Pregnall, Symantec's senior manager of Technical Product Management for Endpoint Security in Asia Pacific and Japan, agreed. He said hardware manufacturers should do this to make those features easier to access.

"When I look at a freshly bought machine from a reputable manufacturer, the first thing I notice is that every bell and whistle is turned on. I see it across different hardware manufacturers, including Macs," he said.

"All the different communication technologies are generally activated, so I think it's a move by manufacturers to ensure that everything is turned on so that minimal effort is needed to use the capabilities that users were sold on," Pregnall said.

In a blog, Microsoft admits that although in most cases an attacker would need to be in close range to exploit the vulnerability, there are ways to increase that distance.

"The standard range of Bluetooth is in the order of metres, although an attacker could use specialised antennas to increase this," the blog said.

This was backed up by Halcyon's Aburn.

"People look at the standard specifications for Bluetooth range of connectivity, which says you need to be so many metres away but using a directional antenna, people can target you from much further away," he said.

This month's Patch Tuesday includes fixes for a drive-by download weakness in Internet Explorer, as well as flaws in affecting Microsoft's multimedia.

The critical vulnerability affecting Internet Explorer described in CVE-2008-1442 and CVE-2008-1544 only affects Windows XP and Vista systems. The MS08-031 cumulative patch fixes a couple of vulnerabilities, including one that could allow remote code execution if a user viewed a specially crafted web page using Internet Explorer and another which could allow information disclosure if a similarly configured page was viewed using the browser.

The DirectX flaws affects all supported editions of Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. This update addresses the vulnerability detailed in CVE-2008-0011 and CVE-2008-1444. Microsoft says the vulnerability "could allow remote code execution if a user opens a specially crafted media file. An attacker who successfully exploited either of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights."

June 8, 2008

Students Hack Windows Cardspace

Students at the Ruhr University of Bochum, Germany, say they have found a way to steal security tokens in Microsoft's new CardSpace authentication framework. Attackers can apparently get access to protected, encrypted user data – such as passwords, credit card numbers, and delivery addresses – when they are transmitted. CardSpace (formerly InfoCard) is the successor to Passport. In both architectures, users' personal data are stored locally on the user's system. Depending on the web site, users can decide which data they want to transmit. CardSpace is designed to make classic passwords a thing of the past, by replacing them with digital certificates that may be self-signed or signed by an authoritative CA such as Verisign.


According to the report, anti-DNS pinning, DNS rebinding, DNS spoofing, and drive-by pharming are apparently all successful ways to steal transmitted tokens. Attackers basically need to manipulate the user system's name resolution so that the token for the browser-based CardSpace is sent to the attacker. To this end, attackers manipulate the DNS entries on a router, for instance by means of cross-site request forgery, and send the attacked user to a malicious name server. If the attacker manages to switch name resolution during an authentication process so that the victim lands both on a shop's genuine CardSpace website and on a malicious forgery, the attacker then gets the token. During the token's validity, attackers can then pretend to be the user in question when they go shopping.

The students have created a demo server that they claim demonstrates the problem. To reproduce the demonstration, you should change your own DNS settings and install an untrusted certificate. In our test at heise Security, we could not get the demonstration to run, however. Microsoft has apparently already been informed of the problem and is working on a solution. In their report, the students propose improving Same Origin Policy as a security function for browsers.

The Social Butterfly

In a world ripe with social networking sites such as Myspace, Facebook, LinkedIn, or any of the other 550,000 different sites allowing you to connect with people you are already friends with, there is bound to be a shady element. That underworld of exploitation, manipulation, and incredible social aptitude. Wait what?

Welcome to the world of the over-friendly and ‘single-minded' Trojan. Single-minded, as it seems to be inviting people to the site and start networking. A Trojan is a programme that appears to be desirable (like a free downloadable game or screen saver), but contains viruses or worms (self-replicating viruses) that can create havoc with the PC and the network.

However, in the case of these social networking sites, the Trojans that plant themselves on the users' computers and send invites to all mail IDs saved in the contact list, are harmless. The Trojan embeds itself in the user's computer when he/she logs on to a social networking site and sends invites to all listed in the contact list.

The receiver – believing it to be from a genuine friend – accepts the invitations and becomes a member of the social networking site. The sites use this to increase their membership, while hackers use the technique for their phishing attempts.

They do not crash the PC nor the network, an IT specialist with a leading BPO notes. But they sure can mar friendships, relationships or even lead to unwanted and unsolicited networking.

Internet Service Providers Association of India (ISPAI) president Rajesh Chharia says, "Even though these programmes only send spam and are quite harmless, at times it can lead to embarrassing situations".

"As most of these social networking sites are used for business networking and friendship, it is not possible for Internet Service Providers (ISPs) to block these sites. The best option is to put in good firewalls at the user's level," he said.
So the next time you log on to a social networking site, an invitation to join the site has gone to your super boss on your behalf. But without your knowledge!

June 7, 2008

British Beauty Queen Hijacked!

Am I being a little sensationalistic? I may be, however no one ever said that Beauty Queens were the brightest of the bunch. Cases like this are why I suggest that people be required to have a driver's license for the Internet.

Miss Scarborough has become the latest victim of online phishing fraudsters, with the the beauty contest winner having had £10,000 stolen from her bank account.

Jade Saunders, a 20-year-old student, was crowned Miss Scarborough in April this year, and is also a semi-finalist for Miss England 2008.

Saunders reportedly clicked on a link in an e-mail purporting to be from her bank, which took her to a genuine-looking, but fake, website. By entering her security log-in details on the fake site, Saunders provided the cybercriminals with all they needed to set up a standing order on her account for £10,000.

Alright, Here are a few checkpoints upon receiving an email from a seemingly legitimate source

[] IS IT FROM A LEGITIMATE SOURCE? LEGIT COMPANIES DO NOT USE FREE EMAIL ACCOUNTS
(Free Emails such as Yahoo, Hotmail, Gmail)
[] IS THE EMAIL GRAMMATICALLY INCORRECT
(Legit Companies typically don't spell words improperly)
[] IS THE EMAIL UNFORMATTED? (i.e No breaks, Paragraphs, Letterhead, Etc.)
(Companies will usually use some sort of professional formatting)
[] IS EMAIL STATING THAT YOU MUST ENTER PERSONAL INFORMATION?
(Companies do not ask for Passwords, SS #'s, or Bank Info)
[] DOES THE EMAIL STATE THAT CHARGES ARE BEING MADE TO YOUR ACCOUNT?
(If so, contact the companies customer support phone number immediately)
[] IS THERE A LINK? If you have checkmarks above, DO NOT CLICK!
(If so, hover your mouse over the link and a box will come up and say where it goes. If it Is not the company's website- Do Not Click!)

IF the email makes you feel uneasy at all, in general, don't click anything at all.
When you enter information on a phisher's website, he has all the information to take out a line of credit, transfer funds, or do any number of other unscrupulous things. Companies will not ask you to enter information in order to verify anything, and if you do recieve such an email- be sure to immediately contact the company in question on the phone support line.

BE SAFE ONLINE! IF NOT, YOU MAY SUFFER BIG LOSS IN THE REAL WORLD.

June 6, 2008

ALERT: IS YOUR VOTE COMPROMISED?

Despite millions of calls to switch back to strictly paper ballots, lawmakers have still not heeded the calls and warnings of computer experts. It came to my attention this friday that in Pinellas County, Florida- A duo of viruses were introduced to the network of ballot stations, bringing into question the validity of the vote.

Two pieces of malicious software were recently discovered on voting stations across Pinellas County.The two bugs, known as Flush.G and W32.SillyDC, work in tandem and go from computer to computer redirecting Internet browsers to sites the user hasn't selected, officials said. The worm is carried through removable media like USB drives, is easily detected and, officials say, rather harmless.

Pinellas Deputy Supervisor of Elections Rick Becker said the worm isn't the kind of Trojan horse that would be used to corrupt a computer voting system and was unsure just where it came from.

Many E-Voting companies love to market the security of their products, stating that since they are not connected to an external internet, that they are exempt from exploitation. However, a proof of concept attack was done by Princeton students against the DieBold voting machines. In this attack, they introduced a virus which self-propogated throughout the systems and switched votes from candidate A or candidate B, and gave them to candidate C.

Are you tired of feeling like your vote doesn't matter? Write to your state or local congressman and encourage them to switch to strictly paper voting.

June 4, 2008

University Students Scammed- Is your info secure?

A data breach at United Healthcare Services Inc. has led to a rash of identity-theft crimes at the University of California, Irvine.

So far, Nearly 155 medical students have had their information stolen. The attackers stole the social security numbers stolen from an internal database. This breach affects nearly 1300 students, putting them at risk for Credit Card fraud as well as Tax scams. So far, the spammers have stolen 155 students Tax returns.

"In February, the police began getting reports from graduate students that when they filed their income tax returns, they were being told that their returns had already been filed using their Social Security numbers," she said.

So all that the attacker needed was a simple set of numbers, and they took students for hundreds, even thousands of dollars. All because of crappy security measures.

This is why people, This is why.

Checklist To ask your school IT Department
[] What security measures do you have in place for physical IT Infrastructre?
[] What security measures are in place to ensure the confidentiality of my information
[] If there is a unapproved access of my information- How promptly will I be notified?
[] Do you have set guidelines for partners of the university to follow in virtual exchanges?
[] WHO has access to my information and WHEN/WHY can they access it?