Google Search

Showing posts with label Romanian. Show all posts
Showing posts with label Romanian. Show all posts

Monday, January 21, 2013

SSCC 100 - John McAfee, OS X malware, Swiss intel, NASA laptops and Romanian carders

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Featured, Podcast

Sophos Security Chet Chat logoChester finally brings up his century with Chet Chat Episode 100 - the Benjamin Franklin edition!

(For readers not familiar with US history and culture, Benjamin Franklin was not only one of America's Founding Fathers, but also also a tireless scientist, engineer and inventor. His likeness appears on the US $100 banknote, which is where the "century" connection comes in.)

Chet's guest in the 100th Chet Chat is Paul Ducklin.

The pair discuss a range of recent security issues:

• John McAfee and geolocation data - advice for non-fugitives.

• Website with Dalai Lama connection hit with Mac malware - making sense of the risk to OS X.

• Swiss intelligence agency in huge data theft - terabytes worth!

• NASA loses yet another laptop - find out what they're doing to prevent (yet another) repeat.

• Romanian carders hack 500,000 Australian credit cards - but law enforcement strikes back.

(07 December 2012, duration 15:37 minutes, size 11.3 MBytes)

You can also download this podcast directly in MP3 format: Sophos Security Chet Chat 100. And why not take a look at the back-catalogue of Sophos Podcasts in our archive? We have loads of interesting stuff for your listening pleasure.

http://twitter.com/duckblog

Tags: carding, chet chat, Dalai Lama, John McAfee, macfee, NASA, ncb, OS X, Podcast, Romania, sscc


View the original article here

Thursday, January 10, 2013

Romanian hackers busted with half a MILLION credit cards from Australia - how could THAT have happened?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

The Australian Federal Police (AFP) are cock-a-hoop this week, announcing the bust of a gang of Romanian credit card hackers.

According to reports, 200 Romanian cops pounced on 36 locations, detained 16 people and ultimately arrested seven of them.

The carding crew had allegedly made off with half a million Aussie credit card numbers, racking up charges averaging more than $1000 each on 30,000 of them.

At this point, I'm sure you're thinking what I am. "Half a MILLION cards from Australia. And the crooks didn't even need to leave Romania. How could THAT have happened?"

The answer, according to the Australian cops, is RDP.

Remote Desktop Protocol - or Routine Darkside Probe, as we dubbed it in a recent article advising you on how to secure it - is Microsoft's solution for remote administration of your computers.

RDP effectively mirrors the screen and keyboard of a remote system on your local device.

Move the mouse in the RDP client, and it moves on the remote system. Pop up a software dialog on the remote system and the screen updates are mirrored on your local desktop. It's almost as good as being right there.

Leaving RDP open to the internet is therefore a little bit like giving a visitor a seat in the corner of your server room and saying, "I'll just leave you here while I go for lunch. Don't touch anything, will you?"

In this case, a bunch of small Aussie retailers were targeted. It's not clear whether the hacking took place via IT infrastructure they all shared (a so-called cloud), so that the crooks were able to penetrate everyone in one shot, or if each retailer was probed and hacked individually.

Once you've got an RDP connection to the inside of a network, you can run pretty much any software you like, even GUI-only applications that weren't built with remote control in mind.

It seems that's what the crooks did, running up the retailers' Point of Sale (PoS) software and retrieving credit card numbers already collected by the retailers' own payment devices.

We've written about skimming a couple of times recently.

That's where you add a covert credit card reader in front of a real one.

Any card swiped or inserted gets read in twice: once by your data-siphon and once by the genuine device. Loosely speaking, you steal the card data individually from each card.

In this hack, the hackers didn't even need a skimmer. They let the official card reading devices handle that job, and stole the credit card data in bulk - straight from the horse's stomach, if you don't mind mixing your mixed metaphors.

The problem with this sort of hack is that there is very little consumers can do to protect themselves.

All the advice you'll hear about choosing decent passwords, wiggling the card slot to look for tampering, and avoiding phishing emails that invite you to initiate an on-line transaction? Those won't help here.

You can do everything right, but if your retailer - or your retailer's IT provider - does the wrong thing, invisibly to you somewhere in the back of the network, you may never know until it's too late.

(That, my friends, is why we need mandatory breach disclosure laws: so you can keep current with what's happened to your personally identifiable information.)

The take-aways from this story?

• If you're a cybercrook, the fact that you're sitting far away in a different jurisdiction makes it tougher for the cops to nab you. But not impossible!

• Don't leave RDP open across the internet. It ends in tears, for you and your customers.

Follow @duckblog

Fancy using the free Sophos UTM Home Edition?

You get web and email filtering, web application security, IPS, VPN and more for up to 50 IP addresses.

Yes, it can help you do RDP safely. so turn that spare PC into a full-on network security appliance!

(Note: registration required.)


View the original article here

Tuesday, November 22, 2011

Another Romanian Accused of Hacking into NASA - Wall Street Journal (blog)

Gaining access to N.A.S.A. servers is beginning to look as if it is almost a rite of passage for some hackers, especially from Romania. It may not yet quite be a regular occurrence, but it is not totally uncommon, as Information Week reports on the latest arrest:

According to Romania’s Directorate for Investigating Organized Crime and Terrorism (DIICOT), the man, Robert Butyka, hacked into several NASA servers on Dec. 12, 2010, modified and damaged data on the servers and restricted access to them.

He apparently goes by the online handle, “Iceman”, and he follows in others’ footsteps.

Victor Faur was charged in 2006 with 10 criminal counts for hacking into more than 150 government computers, including computers used for deep space research, and causing them to display messages indicating that they’d been hacked. He’s now appealing the verdict against him. Earlier this year, a hacker with the online pseudonym TinKode exposed a security flaw in NASA Goddard Space Center’s FTP site.

IT security company Sophos’ blog Naked Security adds:

This isn’t the first time NASA has been hacked, as many of our readers will recall this is what originally got British hacker Gary McKinnon in touch with the long arm of the law.

If NASA is repeatedly being hacked to the tune of half a million dollars plus each time, shouldn’t we be asking serious questions about the security of their systems?

Information Week: Romanian Accused Of NASA Hacks

Naked Security: NASA hacker arrested, perhaps it is time for some defense?


View the original article here