Google Search

Showing posts with label PCWorld. Show all posts
Showing posts with label PCWorld. Show all posts

Monday, March 5, 2012

Concern Rises Over the Capabilities of Anonymous Hacktivists - PCWorld

When a few members of the politically motivated hacking group Anonymous floated a plan recently to cripple the Internet's core address system, the idea was roundly dismissed by other members of the group.

Trying to disable the Internet by attacking servers critical to the Domain Name System -- the Internet's address look-up system -- would be counter to the group's actions, which depend on a constant online presence, they said.

In any case, experts have said an attack against the root servers that deliver address information for top-level domains would be extremely difficult because of the redundancy built into the system.

"Anonymous understands the strength of these servers and would never have any intention of touching them," said Raven, the screen name for a 23-year-old, U.S.-based member of Anonymous, who is active on its IRC channels. "Same goes for the power grid," he said in an interview via email.

But as Anonymous continues to flex its hacking muscle, it is making officials increasingly nervous. Its actions lately have included the theft of millions of emails from analyst firm Stratfor Global Intelligence, to the recording last month of a conference call between U.S. and British law enforcement agencies.

The director of the U.S. National Security Agency, Gen. Keith Alexander, has warned the White House that Anonymous might have the capability to cause a limited power outage within a year or two, according to a recent report in the Wall Street Journal.

Assessing the motives of Anonymous is difficult since it comprises several groups of hackers and activists and has no central leadership, said Joshua Corman, director of security intelligence for Akamai Technologies, who studies the group.

Cybercriminals motivated by profit are unlikely to try to take down the Internet because it would be contrary to their financial interests, Corman said. But within Anonymous are some "chaotic actors" who can have a "real nasty streak," he said.

"When you don't have centralized leadership, it doesn't matter what most will do, it matters what one of them will do," Corman said.

Only a small core of Anonymous is thought to have the technical know-how to carry out such advanced hacking operations. Like most grassroots organizations, its strength comes from the masses who join its cause, whether through electronic attacks or in physical protests wearing the Guy Fawkes masks that have become a hallmark of the group.

For example, Anonymous encouraged its supporters to download a Web-based tool in November 2010 to conduct distributed denial-of-service attacks against financial companies that turned off payment processing for the whistle-blowing site WikiLeaks.

But security analysts said the crude tool left activists' IP addresses exposed, which could provide a way for authorities to try to track them down.

"There's really only a few hackers out in the movement that really deserve the term 'hackers,'" said Barrett Brown, a writer and activist who works closely with Anonymous and the affiliated AntiSec group and is the founder of Project PM.

While Anonymous could develop the skills to damage power plants within a year or so, attacks on large-scale infrastructure "don't really serve our purposes," Brown said.

Anonymous' decentralized structure also has a big disadvantage: Other groups of hackers, for example from China or Russia, could strike critical targets and then blame Anonymous in an attempt to confuse investigators, a so-called "false flag" attack.

"I see the benefit for others who would want to sow fear and use the Anonymous name as the shield to do whatever they like, and it will be blamed on Anonymous," said Scot A. Terban, an independent information security and open-source intelligence analyst.

If something happened to a water or power plant and was attributed to Anonymous, the "group will be branded a terrorist organization quicker than you can blink an eye," Terban said.

Brown said U.S. officials are already edging close to conflating Anonymous with terrorist groups such as al-Qaida, which could push Anonymous in the direction of wanting to become more accountable in order to credibly deflect false flags.

But the rapidly changing make-up of the group makes it hard even for people within Anonymous to keep current, Brown said. It also makes it harder to coordinate a unified voice for the group.

"It's really a lot of work to keep up with what's going on, even if you're in Anonymous. I wouldn't want to be in law enforcement right now. It's a difficult job," he said.

Send news tips and comments to jeremy_kirk@idg.com


View the original article here

Wednesday, July 13, 2011

Meet the Hackers with a Cause - PCWorld

Hacker groups that attack or steal -- some estimates say there are as many as 6000 of such groups online with about 50,000 "bad actors" around the world drifting in and out of them -- are a threat, but the goals, methods, effectiveness of these groups varies widely.

security online networks hackersMalicious activity alert: Anonymous hack-school grads come online in 30 days

When they're angry, they hack into business and government systems to steal confidential data in order to expose information about their targets, or they simply disrupt them with denial-of-service attacks. These are the hackers with a cause, the "hacktivists" like the shadowy but well-publicized Anonymous or the short-lived Lulz Security group (which claimed to have just six members and just joined forces with Anonymous).

Over the years, Anonymous is believed to have hit targets that include the Church of Scientology, the Support Online Hip Hop website, the No Cussing Club website, and posted pornographic videos disguised as children's videos onto YouTube. It's said to have joined with Iranians protesting the results of the June 2009 Iranian presidential election. It's tied to taking down the Australian prime minister's website in 2009 because of the government's plans there to have ISPs censor porn on the Internet. Anonymous has taken up the cause of piracy activists fighting copyright law by launching denial-of-service attacks against anti-piracy groups and law firms. The group is supporting WikiLeaks, which publishes confidential information, including the U.S. State Department cables allegedly leaked by U.S. Army soldihackers anonymouser Bradley Manning, now in a military jail awaiting trial.

Anonymous, perhaps tied to the Sony hacking incidents, has launched distributed DoS attacks against Amazon, PayPal, MasterCard, Visa and others when the card-payment groups refused to process donations to WikiLeaks. Anonymous has sprung into conflicts, such as this year's uprisings in the Mideast, hitting the websites of the Tunisian, Egyptian and Libyan governments. The group recently let the world know its chief focus these days is going to be targeting governments and corporations.

But hacktivists like Anonymous are just one type of hacker group. Others are out for financial gain, well-organized to steal payment-card numbers and personal financial data, or pillage bank accounts. And there are groups that focus on intellectual-property theft or steal valuable information for national interests, or money, or both.

Here's a look at what's known about some of them -- including the ones that unlike the hacktivists, seldom "Tweet" the world about what they do.

The Zeus gangs

The malware called ZeuS is designed to plunder victims' PCs to steal financial information and execute fraudulent high-dollar Automated Clearinghouse (ACH) transfers in corporate bank accounts, resulting in many millions of dollars in fraud against businesses, church groups and government agencies.

The Federal Bureau of investigation (FBI) and international law-enforcement partners in the United Kingdom, the Netherlands and the Ukraine managed to disrupt one of the six main ZeuS hacker groups last fall in a sweep that netted about 100 suspects tied to $70 million in U.S. bank heists. But the leader of what's called "JabberZeus" (because the specific variant of ZeuS used Jabber instant message to tell gang members when a victim's online banking credentials were stolen) is still believed to remain at large. And according to Don Jackson, senior security researcher at Dell SecureWorks. which has worked with business and the FBI, there are still five other separate ZeuS hacker groups very active across the world. These Zeus hacker groups have now been connected to "a billion dollars in losses," says Jackson.

Dogma Millions

This group, largely Russian, runs what's known as a "pay-per-install" operation to get victims to download malware they've designed and it's believed to have hundreds of "affiliates" that get paid when a malicious file is installed on a victim's machine. The group is known to have developed specialized software packers and protectors to ensure its malware, such as rootkits, which remain undetected by antivirus products.

The Chinese Hacker Puzzle

With a growing number of cyberattacks traced back to mainland China, there's a lot of interest in knowing about hacker groups there, with speculation there are many dozens of them. Security firm McAfee earlier this year released a report called "Night Dragon" which claimed hacker groups from China work regular hour shifts to try and break into oil companies to steal data.

security online networks hackersOver the years, the more famous China hacker groups have included Janker, founded by Wang Xianbing, and the Green Army Corps, founded by Gong Wei, according to researcher Scott Henderson, who runs the website Dark Visitor. Although there is no shortage of suspicion in the U.S. that Chinese hackers have at times worked for the Chinese government to steal secrets from U.S.-based businesses and the government, there are also times when Chinese authorities have taken steps to shut down hacker groups. For instance, reports said police last year in Hubei province went after hacker group "Black Hawk Safety Net" and its website that was providing Trojan-based malware.

Over the years, others such as the Network Crack Program Hacker Group based out of Zigong have been identified. The group used a rootkit called GinWui in attacks on the U.S. Department of Defense, other U.S. agencies and Japan about five years ago. GinWui is thought to have been developed by the group's leader, Tan Dailin, who has used the handle "Wicked Rose" and later "Withered Rose."

The Network Crack Program Hacker Group is believed to have transmitted a large amount of documents to China from the U.S. But when Dailin launched denial-of-service attacks against other Chinese hacker groups, including Hackbase, 3800hk and HackerXfiles, these hacker groups went to Chinese authorities, which arrested Dailin in 2009. He now faces over seven years in prison.

Hackers in the News: Inj3ct0r Team

Some hacker groups, particularly the hacktivists, are inclined to make their exploits public by announcing them online in some way or dumping contents they've stolen as proof of their prowess. This week a group called "Inj3ct0r Team" claimed they'd compromised a server belonging to the North Atlantic Treaty Organization (NATO).

When contacted by IDG, the group said the files were a "server backup, confidential data."

According to IDG, "inside the files was a notepad document dated July 3 that said: "NATO lamers! I've been watching you day and night since then! W00t! Your Machines rooted! Servers restored to default! what else! [Expletive deleted] you and your crimes! And soon enough all your stupid ideas will be published on WikiLeaks!"One industry source asked about Inj3ct0r Team says it started as one individual who began finding vulnerabilities in websites and publicizing them, who then attracted a following.

Hacker groups have a long history. The predecessors to today's had names like "The Legion of Doom" and "Masters of Deception" and in the 1980's they mainly struck phone networks, where "they did a lot of damage," says Dell SecureWorks researcher Jackson. Today's groups, he adds, are more "self-mobilizing, they drop in and drop out," and the big groups "always have a mastermind of two."

Read more about wide area network in Network World's Wide Area Network section.

For more information about enterprise networking, go to NetworkWorld. Story copyright 2011 Network World Inc. All rights reserved.


View the original article here